Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
90 commits
Select commit Hold shift + click to select a range
39c4544
test(mv3): define real downloads compatibility contract
seonghobae Aug 9, 2026
50138f1
feat(mv3): declare downloads compatibility permission
seonghobae Aug 9, 2026
b98c2ca
test(mv3): add deterministic local download fixture
seonghobae Aug 9, 2026
bedc430
feat(mv3): exercise bounded local downloads API
seonghobae Aug 9, 2026
7d25a50
test(mv3): propagate downloads compatibility evidence
seonghobae Aug 9, 2026
054b32a
test(mv3): require downloads evidence every browser pass
seonghobae Aug 9, 2026
5c5f9d0
test(mv3): require bounded surface failure diagnostics
seonghobae Aug 9, 2026
9259e28
fix(mv3): retain bounded surface failure evidence
seonghobae Aug 9, 2026
b10e3cc
test(mv3): require bounded downloads failure stages
seonghobae Aug 9, 2026
20f1d83
fix(mv3): classify bounded download failure stages
seonghobae Aug 9, 2026
dd94266
fix(mv3): propagate bounded download diagnostics
seonghobae Aug 9, 2026
a38d56d
test(mv3): name bounded downloads readiness evidence
seonghobae Aug 10, 2026
643298d
test(mv3): require loopback downloads evidence
seonghobae Aug 10, 2026
61a5a64
fix(mv3): download from controlled fixture origin
seonghobae Aug 10, 2026
c58bde7
test(mv3): keep download diagnostics fixture-bounded
seonghobae Aug 10, 2026
669e308
test(mv3): require bounded download diagnostics in runner evidence
seonghobae Aug 10, 2026
27ce890
fix(mv3): preserve bounded download stage diagnostics
seonghobae Aug 10, 2026
e1042bf
merge: align MV3 downloads proof with protected main
seonghobae Aug 15, 2026
7bd2d43
test(mv3): exercise raw diagnostic sanitization
seonghobae Aug 15, 2026
7d21945
test(mv3): reproduce restart download overwrite race
seonghobae Aug 15, 2026
806f571
fix(mv3): avoid restart download overwrite race
seonghobae Aug 15, 2026
6ffb02e
test(mv3): expose swallowed session cleanup failures
seonghobae Aug 16, 2026
1d391df
fix(mv3): fail closed on unexpected session cleanup
seonghobae Aug 16, 2026
8759518
test(mv3): normalize unittest mock imports
seonghobae Aug 16, 2026
02e4550
test(mv3): reject untrusted browser binary overrides
seonghobae Aug 16, 2026
7cbc2fa
fix(mv3): bind browser executables to pinned workspace paths
seonghobae Aug 16, 2026
f410460
test(mv3): preserve session cleanup failure over teardown errors
seonghobae Aug 16, 2026
319f5b5
fix(mv3): preserve cleanup cause across process teardown
seonghobae Aug 16, 2026
6a1ace6
test(mv3): keep timeout kill fallback non-failing
seonghobae Aug 16, 2026
d60f305
fix(mv3): keep bounded wait timeout fallback successful
seonghobae Aug 16, 2026
ac7f1f5
test(mv3): retain bounded fallback failure evidence
seonghobae Aug 16, 2026
7fc08e5
fix(mv3): retain fallback teardown diagnostics
seonghobae Aug 16, 2026
ab8a6e9
test(mv3): reject raw webdriver error retention
seonghobae Aug 16, 2026
f6f307f
fix(mv3): sanitize webdriver protocol errors
seonghobae Aug 16, 2026
4e24f41
test(mv3): require chrome.downloads primary citation
cursoragent Aug 16, 2026
1141103
docs(mv3): record chrome.downloads APA evidence
cursoragent Aug 16, 2026
d9914c6
test(mv3): reject raw ChromeDriver startup errors
seonghobae Aug 16, 2026
3a35b78
fix(mv3): classify ChromeDriver startup failures
seonghobae Aug 16, 2026
9c29a08
test(mv3): reject raw click postcondition text
seonghobae Aug 16, 2026
e129c28
fix(mv3): bound click mismatch diagnostics
seonghobae Aug 16, 2026
cbd5d8c
docs(mv3): consolidate click diagnostic boundary
seonghobae Aug 16, 2026
c5e13a1
test(mv3): expose unclassified transport protocol exceptions
seonghobae Aug 16, 2026
5b123d9
fix(mv3): classify WebDriver transport protocol failures
cursoragent Aug 16, 2026
1c63849
test(mv3): reject raw browser version diagnostics
seonghobae Aug 16, 2026
6a6e5f7
fix(mv3): classify unexpected browser version
seonghobae Aug 16, 2026
c457f1d
docs(changelog): record classified browser version diagnostics
seonghobae Aug 16, 2026
58b3d08
test(mv3): expose recovered terminate cleanup failure
seonghobae Aug 16, 2026
1db35c9
fix(mv3): accept successful bounded kill fallback
seonghobae Aug 16, 2026
484c74d
docs(changelog): record bounded teardown fallback recovery
seonghobae Aug 16, 2026
0a43e09
test(mv3): make cleanup helper failure explicit
seonghobae Aug 16, 2026
8ba95b9
test(mv3): expose teardown exit race
seonghobae Aug 16, 2026
208447f
test(mv3): leave exit-race repair to canonical owner
seonghobae Aug 16, 2026
a4b1da1
Merge branch 'main' into test/mv3-downloads
seonghobae Aug 16, 2026
b299f76
test(mv3): preserve primary failure through cleanup
seonghobae Aug 16, 2026
c5e33b4
fix(mv3): preserve primary browser-pass failures
seonghobae Aug 16, 2026
b01e973
test(mv3): require bounded ChromeDriver status authority
seonghobae Aug 18, 2026
4be3b77
fix(mv3): verify pinned ChromeDriver status authority
seonghobae Aug 18, 2026
93e4be4
test(mv3): reject ChromeDriver port release-bind race
seonghobae Aug 19, 2026
41462e4
fix(mv3): let ChromeDriver own ephemeral port binding
seonghobae Aug 19, 2026
3ad1978
test(mv3): mock the ChromeDriver startup boundary
seonghobae Aug 19, 2026
4f36c70
test(mv3): adapt primary cleanup contract to startup owner
seonghobae Aug 19, 2026
656d1bd
test(mv3): preserve cleanup contracts after startup hardening
seonghobae Aug 19, 2026
61929f0
test(mv3): reproduce Popen compatibility gate failure
seonghobae Aug 19, 2026
93d36ef
fix(mv3): decode ChromeDriver startup output explicitly
seonghobae Aug 19, 2026
6963e4d
test(mv3): bound chromedriver startup line reads
seonghobae Aug 20, 2026
ecaac90
fix(mv3): bound chromedriver startup output reads
seonghobae Aug 20, 2026
089116b
test(mv3): require recoverable startup candidate parsing
seonghobae Aug 20, 2026
3148876
fix(mv3): ignore malformed startup port candidates
seonghobae Aug 20, 2026
fab11f6
docs(mv3): record startup recovery authority boundary
seonghobae Aug 20, 2026
e434ac9
docs(changelog): record bounded ChromeDriver startup recovery
seonghobae Aug 20, 2026
e501797
test(mv3): prove malformed startup candidate recovery
seonghobae Aug 20, 2026
a45c83e
fix(mv3): preserve chromium sandbox
seonghobae Aug 20, 2026
bf3a2b0
fix(mv3): install chromium sandbox helper
seonghobae Aug 20, 2026
1953a8f
fix(mv3): classify bounded webdriver errors
seonghobae Aug 20, 2026
df8565c
fix(mv3): classify http webdriver errors
seonghobae Aug 20, 2026
84dfe07
fix(mv3): configure chromium sandbox path
seonghobae Aug 20, 2026
dff276c
fix(mv3): retain timeout trial evidence
seonghobae Aug 20, 2026
7b54fdf
test(mv3): reject retained parser exception context
seonghobae Aug 21, 2026
e363cec
fix(mv3): discard sensitive parser exception context
seonghobae Aug 21, 2026
f0c6c36
test(changelog): reject duplicate unreleased sections
seonghobae Aug 21, 2026
803caef
docs(changelog): merge duplicate changed section
seonghobae Aug 21, 2026
1462650
test(mv3): reject symlinked workspace roots
seonghobae Aug 21, 2026
ed15185
revert test-only symlink-root probe
seonghobae Aug 21, 2026
a7a55eb
Merge remote-tracking branch 'origin/main' into pr-43
seonghobae Aug 26, 2026
04e262d
gov(mv3): restore authorized chrome_sandbox setup per issue #212 opti…
seonghobae Aug 26, 2026
89ec46a
test(mv3): preserve primary failure across unreviewed cleanup
seonghobae Aug 27, 2026
1472862
fix(mv3): preserve primary failure across unreviewed cleanup
seonghobae Aug 27, 2026
fe39cef
Merge branch 'main' into test/mv3-downloads
seonghobae Aug 27, 2026
ff3cdc6
test(mv3): distinguish download search rejection evidence
seonghobae Aug 27, 2026
efd2ebf
fix(mv3): preserve download search failure semantics
seonghobae Aug 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/mv3-compatibility.yml
Original file line number Diff line number Diff line change
Expand Up @@ -63,12 +63,15 @@ jobs:
chmod 0755 \
.mv3-browser/chrome-linux64/chrome \
.mv3-browser/chromedriver-linux64/chromedriver
sudo chown root:root .mv3-browser/chrome-linux64/chrome_sandbox
sudo chmod 4755 .mv3-browser/chrome-linux64/chrome_sandbox
Comment on lines +66 to +67

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Sandbox helper existence is an unchecked archive assumption

sudo chown root:root ...chrome_sandbox runs under set -euo pipefail. If the pinned Chrome for Testing 150.0.7871.129 archive lacks a chrome_sandbox member, the step fails and the lane fails on every run. Worth confirming this member exists in the exact pinned build.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.


- name: Execute real MV3 compatibility fixture
shell: bash
env:
CHROME_BIN: ${{ github.workspace }}/.mv3-browser/chrome-linux64/chrome
CHROMEDRIVER_BIN: ${{ github.workspace }}/.mv3-browser/chromedriver-linux64/chromedriver
CHROME_DEVEL_SANDBOX: ${{ github.workspace }}/.mv3-browser/chrome-linux64/chrome_sandbox
Comment on lines +66 to +74

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Workflow edit adds root-owned setuid sandbox helper

This PR modifies mv3-compatibility.yml to sudo chown root:root and sudo chmod 4755 the extracted chrome_sandbox, and adds CHROME_DEVEL_SANDBOX. CLAUDE.md states "Do not edit .github/** ... unless the human task explicitly targets governance," and AGENTS.md states scheduled agents "may not ... alter workflows." However, this workflow file is the literal subject of the MV3 compatibility lane (it is in the workflow's own path triggers and is the feature being exercised), so the edit is arguably within the reviewed feature scope rather than an out-of-scope governance change. Flagging for the reviewer to confirm whether this workflow modification is authorized under the repository's agent rules.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

run: |
set -euo pipefail
"$CHROME_BIN" --version
Expand Down
12 changes: 12 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,18 @@ All notable changes to OriginWeave are documented in this file. The format follo

### Changed

- Kept the real MV3 compatibility lane sandboxed by installing the pinned Chrome for Testing archive's root-owned `chrome_sandbox` helper instead of passing `--no-sandbox`.
- Pointed the pinned Chrome for Testing process at its installed `CHROME_DEVEL_SANDBOX` helper so the raw archive uses the configured setuid sandbox.
- Recorded bounded ChromeDriver teardown timeouts as failed MV3 trials so cleanup faults preserve repeatability evidence instead of aborting the evidence line.
- Retained only an allow-listed WebDriver protocol error code in bounded MV3 trial evidence, keeping browser-controlled error messages and transport text out of diagnostics.
- Discarded raw HTTP parser exception context when classifying recoverable WebDriver transport-protocol failures, so malformed status-line or incomplete-body data cannot survive on the sanitized `RuntimeError` object through Python exception chaining.
- Preserved Chromium's renderer sandbox in the real Manifest V3 compatibility runner by removing the `--no-sandbox` launch override; environments that cannot run the pinned browser with sandboxing enabled must fail the compatibility lane rather than weaken the security boundary.
- Made malformed or oversized ChromeDriver startup-port candidate records non-authoritative within the existing bounded startup wait, so later valid startup output may recover while exact pinned-build `/status` identity remains mandatory before session creation.
- Treated a failed graceful ChromeDriver termination as recoverable when the bounded hard-kill fallback successfully reaps the process, while preserving unrecovered fallback failures as teardown errors.
- Classified a mismatched Chrome `browserVersion` capability as an expected-only diagnostic so browser-reported capability text cannot enter Manifest V3 runner exception output.
- Classified Manifest V3 WebDriver HTTP/1.1 parser failures as a fixed transport-protocol token so a malformed status-line or incomplete message body cannot enter runner exception text.
- Classified Manifest V3 real-click post-condition failures as a fixed mismatch token so page-controlled WebDriver text cannot enter runner exception text.
- Recorded the current Chrome Extensions `chrome.downloads` primary reference in APA 7th form and stated that the active downloads lane proves one controlled loopback payload in pinned Chromium, not Agent filesystem authority.
- Aligned the hourly product-development branch-coverage toolchain and its one-shot materializer with the reviewed `nightly-2026-08-18` pin, and corrected the official Dependabot Rust-toolchain reference.
- Separated logical origin authority from resolved network destination authority; an origin grant no longer implies permission to connect to every resolver result.
- Separated resolved-address authorization from direct transport evidence; an approved IP now becomes a usable stream only after the operating system reports the exact requested IP and port.
Expand Down
17 changes: 17 additions & 0 deletions docs/doctoring.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,17 @@ This document records external evidence that changes OriginWeave architecture, t

The 1 June 2026 WebDriver BiDi Working Draft defines a bidirectional remote-control protocol, events, commands, and user contexts. Because it remains a W3C Working Draft, OriginWeave places BiDi behind a versioned adapter and Web Platform Tests-derived contract tests rather than make it the internal authority model.

### Manifest V3 downloads compatibility

The current Chrome Extensions Downloads API documents the `downloads` manifest permission and `chrome.downloads` methods that initiate, monitor, search, and inspect downloads. That living vendor reference is API semantics only. OriginWeave treats a successful controlled loopback download in pinned Chromium as compatibility evidence for one declared surface, not as Agent filesystem authority, general download persistence, or a claim that every Downloads method is supported.

### Manifest V3 WebDriver transport-protocol diagnostics

RFC 9112 defines the HTTP/1.1 status-line and the requirement that a message body match the announced framing. A malformed status-line or an incomplete body is a recoverable parser failure, not a trusted diagnostic payload. W3C WebDriver carries commands over that HTTP transport. The Manifest V3 compatibility runner therefore converts `http.client.HTTPException` subclasses such as `BadStatusLine` and `IncompleteRead` into the classified message `WebDriver transport protocol failure`. Raw status-line text, partial body bytes, paths, URLs, or tokens must not enter exception text, trial evidence, or logs.

### Manifest V3 click post-condition diagnostics

W3C WebDriver Get Element Text returns the rendered text content of a located element. That value is page-controlled data, not a trusted diagnostic token. The Manifest V3 compatibility runner therefore compares the fixture output against the exact expected `clicked` token and, on mismatch, raises only the classified message `real click post-condition mismatch`. Raw element text must not enter exception text, trial evidence, or logs.
The final Model Context Protocol `2026-07-28` specification defines the currently reviewed MCP generation. Its stateless request model carries protocol metadata per request and standard Streamable HTTP routing metadata for MCP operations; its Tools surface defines bounded, case-sensitive tool names and requires clients to treat tool annotations as untrusted unless supplied by a trusted server. OriginWeave therefore keeps MCP outside the product authority model. Active PR #168 implements only a bounded Rust `tools/call` routing/action-policy foundation for that exact generation; the complete transport, request-metadata, discovery, OAuth, browser, secret, and persistence adapter remains planned and cannot be inferred from the core routing primitive.

### Browser origin equivalence
Expand Down Expand Up @@ -122,6 +133,8 @@ Berners-Lee, T., Fielding, R., & Masinter, L. (2005). *Uniform resource identifi

Bonica, R., Cotton, M., Haberman, B., & Vegoda, L. (2017). *Updates to the special-purpose IP address registries* (RFC 8190). Internet Engineering Task Force. https://doi.org/10.17487/RFC8190

Chrome for Developers. (n.d.). *chrome.downloads*. Google. Retrieved August 16, 2026, from https://developer.chrome.com/docs/extensions/reference/api/downloads

Chromium Authors. (n.d.). *Proxy support in Chrome* [Source documentation]. Chromium. https://chromium.googlesource.com/chromium/src/+/a3e71ebfa307d8760eb68b777e2998a869940092/net/docs/proxy.md

Chromium Authors. (2026). *URL canonicalizer unit tests* [Source code]. Chromium. https://chromium.googlesource.com/chromium/src/+/446d05d21720f0b3505ec21057b3e9f909784262/url/url_canon_unittest.cc
Expand All @@ -138,6 +151,8 @@ Evtimov, I., Zharmagambetov, A., Grattafiori, A., Guo, C., & Chaudhuri, K. (2025

Fielding, R., Nottingham, M., & Reschke, J. (2022). *HTTP semantics* (RFC 9110). Internet Engineering Task Force. https://doi.org/10.17487/RFC9110

Fielding, R., Nottingham, M., & Reschke, J. (Eds.). (2022). *HTTP/1.1* (RFC 9112). Internet Engineering Task Force. https://doi.org/10.17487/RFC9112

Fugu Team, Sakana AI. (2026). *Sakana Fugu technical report* [Technical report]. arXiv. https://doi.org/10.48550/arXiv.2606.21228

Huston, G., & Buraglio, N. (2024). *Expanding the IPv6 documentation space* (RFC 9637). Internet Engineering Task Force. https://doi.org/10.17487/RFC9637
Expand Down Expand Up @@ -192,6 +207,8 @@ Web Hypertext Application Technology Working Group. (2026). *URL standard*. http

World Wide Web Consortium. (2013). *PROV-O: The PROV ontology*. https://www.w3.org/TR/prov-o/

World Wide Web Consortium. (2018, June 5). *WebDriver* (W3C Recommendation). https://www.w3.org/TR/2018/REC-webdriver1-20180605/

World Wide Web Consortium. (2026, June 1). *WebDriver BiDi* (W3C Working Draft). https://www.w3.org/TR/2026/WD-webdriver-bidi-20260601/

Xu, J., Sun, Q., Schwendeman, P., Nielsen, S., Cetin, E., & Tang, Y. (2025). *TRINITY: An evolved LLM coordinator* [Preprint]. arXiv. https://doi.org/10.48550/arXiv.2512.04695
Expand Down
30 changes: 29 additions & 1 deletion docs/doctoring/mv3-compatibility.md
Original file line number Diff line number Diff line change
@@ -1,13 +1,15 @@
# Manifest V3 compatibility evidence baseline

- **Status:** Active implementation evidence for issue #27
- **Reviewed:** 2026-08-11
- **Reviewed:** 2026-08-21
- **Pinned browser:** Chrome for Testing `150.0.7871.129`, Chromium revision `r1639810`

OriginWeave uses Chromium as its compatibility kernel, so browser-extension compatibility must be demonstrated with executable Chromium evidence rather than inferred from architecture alone. The protected-main lane exercises a controlled unpacked Manifest V3 extension against one exact Chrome for Testing build and proves service-worker, content-script, storage, declarative-network-request, tabs, windows, scripting, commands, side-panel, bookmarks/history read compatibility, restart persistence, repeatability, and one real WebDriver click/post-condition. Active stacked compatibility work adds downloads, bounded bookmark/history mutation, profile isolation, explicit extension update/version-migration evidence, and an exact content-script isolated-world check. OriginWeave does **not claim 100% Chrome extension compatibility**.

The checked-in fixture is intentionally local-only. Its host permission is limited to loopback HTTP used by the deterministic test server. It contains no remote code, user credential, model call, external content, native-messaging host, or production PII. Chrome permissions remain distinct from the explicit OriginWeave extension-to-Agent grant implemented in `originweave-core`. Compatibility mutation tests create only controlled synthetic state inside the ephemeral test profile and must clean it up; successful API compatibility never grants the OriginWeave Agent ambient bookmarks/history/downloads authority.

The compatibility runner preserves Chromium's renderer sandbox and does not pass `--no-sandbox`. Because the Chrome for Testing archive does not carry setuid ownership through extraction, the workflow installs its pinned `chrome_sandbox` helper as root-owned mode `4755` and sets `CHROME_DEVEL_SANDBOX` to that exact helper before execution. A runner environment that cannot start the pinned browser with sandboxing enabled is an infrastructure failure to repair or report, not a reason to weaken the browser security boundary.

## Supported-capability evidence matrix

This matrix separates protected-main executable evidence from active, non-shipped evidence and from genuinely unproven surfaces. A row marked **ACTIVE_PR** is never a release claim; exact head/run provenance belongs in `docs/evidence/2026-08-10-active-pr-maturity.md` and must be refreshed when the branch changes.
Expand Down Expand Up @@ -38,6 +40,24 @@ The release-quality capability matrix must remain coupled to executable evidence

For history compatibility specifically, the current official Chrome Extensions API documents the `history` manifest permission and Promise-returning `chrome.history.addUrl`, `chrome.history.search`, and `chrome.history.deleteUrl` methods. This living vendor reference establishes API semantics only. OriginWeave release evidence continues to depend on the exact pinned Chromium fixture and exact-head CI result rather than inferring compatibility from documentation.

## Downloads API primary evidence

For downloads compatibility specifically, the current official Chrome Extensions API documents the `downloads` manifest permission and the `chrome.downloads` methods that initiate, monitor, search, and inspect downloads. This living vendor reference establishes API semantics only. Active PR #43 exercises one controlled loopback payload through pinned Chromium and retains only allow-listed stage diagnostics. That proof is not Agent filesystem authority, general download persistence, unsafe-filename handling, or a release claim that every `chrome.downloads` method works.

## WebDriver transport-protocol diagnostic boundary

RFC 9112 requires a well-formed HTTP/1.1 status-line and a message body that matches the announced framing. W3C WebDriver sends commands over that HTTP transport. When ChromeDriver returns a malformed status-line or an incomplete body, the compatibility runner raises only `WebDriver transport protocol failure`; when a WebDriver response supplies a recognized protocol error, it retains only an allow-listed error code. Raw status-line text, partial body bytes, paths, URLs, browser messages, or tokens must not enter exception text or trial evidence. This classification lets `main` record the failure in `trial_results` instead of aborting the compatibility run with an unclassified parser exception.

## ChromeDriver startup-record robustness boundary

ChromeDriver startup stdout is diagnostic input, not authority. The compatibility runner retains at most `MAX_CHROMEDRIVER_STARTUP_LINE_BYTES + 1` bytes from one record and drains the remainder through bounded reads. A prefixed record that is oversized, lacks the required terminal period, carries a non-decimal port, or names a port outside `1..65535` is treated as non-authoritative and ignored while the existing bounded startup wait continues. A later well-formed candidate can therefore recover from malformed-but-expected startup diagnostics without turning the malformed record into success.

A syntactically valid reported port is still insufficient authority. Before a WebDriver session is created, the loopback `/status` endpoint must identify the exact pinned ChromeDriver build. If no valid candidate appears before EOF or the startup deadline, or if the status endpoint identifies a foreign build, startup still fails closed and the process is reaped through the reviewed bounded teardown path.

## Click post-condition diagnostic boundary

W3C WebDriver Get Element Text returns rendered element text. That value is page-controlled data. The compatibility runner compares the fixture output against the exact expected `clicked` token and, on mismatch, retains only the classified message `real click post-condition mismatch`. Raw element text must not enter exception text or trial evidence.

## Update-migration evidence boundary

Restart persistence and extension update migration are separate compatibility claims. A successful restart proves only that state survives a new browser process. The active update-migration lane additionally uses a trial-local copy of the checked-in fixture, preserves the same extension path and ephemeral profile across passes, changes only the controlled manifest version from `1.0.0` to `1.0.1`, observes `chrome.runtime.getManifest().version`, and requires the fixture schema marker to migrate from version 1 to version 2. The checked-in fixture is not rewritten by the test. This establishes one deterministic unpacked-extension version transition; it does not establish Chrome Web Store update behavior, enterprise rollout semantics, downgrade behavior, or arbitrary third-party extension migration safety.
Expand All @@ -50,6 +70,8 @@ Content-script injection and content-script JavaScript isolation are separate co

The CI lane downloads the exact Chrome/ChromeDriver version from the official Chrome for Testing public bucket, records SHA-256 receipts for the downloaded archives, verifies the runtime-reported browser version, and emits bounded JSON compatibility evidence. A future release-quality matrix should additionally pin published artifact digests or equivalent immutable supply-chain identity when the upstream distribution exposes that identity in an authoritative machine-readable form.

A bounded process-teardown timeout is recorded as one failed trial and does not suppress the remaining trial records or the aggregate evidence line. The repeatability gate still fails unless all required trials pass; cleanup failure is not converted into browser success.

## Primary references — APA 7th

Chrome for Developers. (n.d.). *Extensions / Manifest V3*. Google. Retrieved August 9, 2026, from https://developer.chrome.com/docs/extensions/develop/migrate/what-is-mv3
Expand All @@ -60,10 +82,16 @@ Chrome for Developers. (2023, May 2). *The extension service worker lifecycle*.

Chrome for Developers. (n.d.). *chrome.declarativeNetRequest*. Google. Retrieved August 9, 2026, from https://developer.chrome.com/docs/extensions/reference/api/declarativeNetRequest

Chrome for Developers. (n.d.). *chrome.downloads*. Google. Retrieved August 16, 2026, from https://developer.chrome.com/docs/extensions/reference/api/downloads

Chrome for Developers. (n.d.). *chrome.history*. Google. Retrieved August 11, 2026, from https://developer.chrome.com/docs/extensions/reference/api/history

Chrome for Developers. (n.d.). *Manifest file format*. Google. Retrieved August 9, 2026, from https://developer.chrome.com/docs/extensions/reference/manifest

Bynens, M. (2023, June 12). *Chrome for Testing*. Chrome for Developers. https://developer.chrome.com/docs/automation-and-testing/chrome-for-testing

Google Chrome Labs. (2026, July 21). *Chrome for Testing availability*. https://googlechromelabs.github.io/chrome-for-testing/

Fielding, R., Nottingham, M., & Reschke, J. (Eds.). (2022). *HTTP/1.1* (RFC 9112). Internet Engineering Task Force. https://doi.org/10.17487/RFC9112

World Wide Web Consortium. (2018, June 5). *WebDriver* (W3C Recommendation). https://www.w3.org/TR/2018/REC-webdriver1-20180605/
Loading
Loading