feat: add privacy-preserving presentation identity kernel - #229
feat: add privacy-preserving presentation identity kernel#229seonghobae wants to merge 39 commits into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (5)
🚧 Files skipped from review as they are similar to previous changes (3)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough
Changes프레젠테이션 정체성 커널
Estimated code review effort: 4 (복잡) | ~45분 Merge Risk: 🔵 Low · up to The PR adds the presentation-identity kernel and related documentation, but the changelog currently presents a future-dated inventory as already observed. This is a bounded documentation accuracy issue that should receive owner follow-up before or alongside merge. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Review follow-up on exact head eae6ccd: format_ratio now exhaustively matches DevicePixelRatio, and explicit replay accepts only the enumerated language classes. I did not add the suggested set_size == 0 return: returning index 0 would still panic when derive indexes the empty eligible vector, so it is not a valid fail-closed fix. The private derivation sets retain a regression that proves every screen admits at least one enumerated viewport width and height. Full workspace tests, strict Clippy, rustdoc, 144 documentation tests, and 100% production function/line/region/branch coverage pass locally. |
seonghobae
left a comment
There was a problem hiding this comment.
Current-head finding: the ownership repair correctly restored the protected-main CHANGELOG to remove volatile queue ownership, but the branch now has no narrow Unreleased entry for its own presentation-identity product delta. The PR body already identifies this as a prerequisite to returning to Ready. Repair this in the feature lane without reintroducing repository-inventory counts: add a focused documentation contract that requires a stable presentation-identity changelog statement, observe the pre-fix absence as RED, then add only the feature-local Unreleased entry. Keep the statement explicit that this is a pure Rust control-plane kernel and does not claim Chromium application/effectiveness.
seonghobae
left a comment
There was a problem hiding this comment.
Current-head verification: the test-first changelog contract from ffd91290479c77ff1d675d4520e1776c990ba4d5 is now satisfied by exact repair head 7ae426e760e8351ee792ce9df4266d7e7483d0d4. The test-only → repair compare is exactly CHANGELOG.md +1/-0. The new entry is feature-local, contains no volatile repository counts, and preserves the boundary that Chromium application/page-observed effectiveness remains adapter/E2E work. This is source-level verification only; CI/security/current-head execution remains non-terminal, so keep Draft and do not transfer predecessor GREEN.
Fail closed before mobile model values reach later UA-CH serialization boundaries. Signed-off-by: Seongho Bae <me@seonghobae.me>
…e-model-token Signed-off-by: Seongho Bae <me@seonghobae.me>
|
Current-main reconciliation and its observed documentation-contract repair are pushed at exact head |
Signed-off-by: Seongho Bae <me@seonghobae.me>
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head verification after the repository-contract failure: predecessor 7aa30c57a4af724eb4e601c52c1eaf68f27d1712 CI 33890032169 executed on a hosted runner. Production coverage 101079177501 passed exact enforcement, while Rust contracts 101079177340 failed only in test_presentation_identity_documentation_contract.py before Rust formatting/tests/Clippy/rustdoc. The failure was a stale exact-sentence assertion: the current feature-local changelog entry legitimately inserts including control-safe mobile UA-CH model values before the unchanged ; applying those profiles to Chromium ... separate adapter and browser-E2E work. maturity boundary.
Current commit 3772d6eddfd556b24397afc80780ef3cc980791e repairs the test rather than deleting the newer product fact or weakening the maturity contract. It requires exactly one presentation-identity changelog entry by the stable feature prefix and still requires the exact Chromium/page-observation non-shipment suffix. Protected main@4ed08bfa7c063fc7f2ef9278ee8d281887b8296b is the merge base and the branch is 36 ahead / 0 behind. Fresh CI/security workflows are non-terminal, so this review is COMMENT only and does not claim current-head GREEN or approval.
…rent-main Signed-off-by: Seongho Bae <me@seonghobae.me>
Signed-off-by: Seongho Bae <me@seonghobae.me>
…ty' into codex/adopt-pr229-current-main # Conflicts: # tests/test_presentation_identity_documentation_contract.py
|
Current protected main was adopted non-destructively at exact head 024f636. The stale local tracking ref initially reproduced the presentation changelog contract RED; integrating the actual remote head preserved its existing clause-based repair, and the final tree passed 157 Python contracts, cargo fmt, all workspace/all-target Rust tests, all-target Clippy with warnings denied, rustdoc with warnings denied, and 100% production function/line/region/branch coverage. All 29 review threads are resolved. Marked Ready to regenerate hosted exact-head evidence; queued/absent checks and approval remain non-passing, and Chromium application/page-observed behavior remains separate unreleased adapter/E2E work. |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head review on 024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6: the protected-main reconciliation is 39 ahead / 0 behind with merge base exactly main@87c4daa1830bac5a5228b6036752ad5633232085, and the effective delta remains product/docs/tests only with no .github/** mutation. The earlier Ready-transition CI 33930571288 completed skipped; this is not GREEN and independently reproduces the #286 Ready-event admission defect already observed on #287 and #272. Ordinary synchronize has materialized current-head CI 33930580462, Security 33930571275, Semgrep 33930571261, and CodeQL 33930571229, all still non-terminal at review time. Do not transfer predecessor results. Product maturity remains kernel-only: real Chromium application, page-observed cross-surface post-condition evidence, and crash/cleanup/security E2E are still required before browser-presentation compatibility is claimed.
|
Fresh independent exact-tree review on |
|
Next buyer-visible adapter slice now has a canonical owner: #292. Fresh standards check against the current 2026 WebDriver BiDi Working Draft shows that BiDi can cover viewport/DPR, screen area, locale, reduced-motion, timezone and User-Agent, but not the complete current profile (notably |
Buyer-visible boundary
This PR adds a pure Rust presentation-identity bounded context for explicit, internally consistent browser-visible profiles and credential-free replay digests. The active delta includes bounded presentation surfaces, fail-closed required-surface admission, bounded User-Agent Client Hints values including control-safe mobile model metadata, and privacy-oriented Canvas/WebGL/WebAudio/WebRTC normalization contracts.
This remains control-plane metadata. It does not inspect the host, patch Chromium, apply a profile to a browser, choose an evidence-free default identity, bypass CAPTCHA/bot-management/access controls, or prove that a page observes the requested values. A pinned real-Chromium adapter plus cross-surface pre-script/post-observation evidence remains required before browser-presentation compatibility can be claimed.
Current protected-main lineage
Protected
mainis exact87c4daa1830bac5a5228b6036752ad5633232085through #286. Exact current head is024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6, open, Ready, and mergeable. Fresh compare is 39 ahead / 0 behind with merge base exactly current protected main. The effective delta contains 29 product/docs/test paths and no.github/**, provider/model, secret, browser-launch, network-authority, ruleset, or coverage-denominator mutation.Current
024f636...is a non-destructive parent-adoption/reconciliation generation. The conflict was limited totests/test_presentation_identity_documentation_contract.py; the resolution preserves the earlier causal repair that checks exactly one stable presentation-identity changelog entry while separately pinning the truthful boundary that Chromium application and page-observed effectiveness remain future adapter/browser-E2E work.Hosted repository-contract RED and causal repair
Exact predecessor
7aa30c57a4af724eb4e601c52c1eaf68f27d1712received hosted CI33890032169: Production coverage succeeded while Rust contracts failed in Python repository contracts before formatting/Rust/Clippy/rustdoc. The failing contract had frozen an older complete CHANGELOG sentence and rejected a valid newer product fact. Commit3772d6eddfd556b24397afc80780ef3cc980791emade the narrow repair: require exactly one presentation-identity entry by stable feature prefix and independently require the exact non-shipment suffix. The browser-application boundary therefore cannot silently disappear when the product description gains a truthful new fact.Exact-current hosted evidence
The first CI emitted by the Ready transition on this exact head,
33930571288, completed skipped under the #286 lifecycle behavior and remains diagnostic evidence only. A subsequent ordinary synchronize on the unchanged Ready head materialized terminal current-head evidence:33930580462: success;33930571275: success;33930571261: success;33930571229: failure.The CodeQL failure is the same organization central-dispatch/verdict control-plane pattern seen on #50 and #37, not an observed presentation-identity source finding. Detect-languages job
101208143940succeeded. Javascript-typescript101241595259, actions101241595274, and python101241595306each successfully requested current-head scan dispatch and then failed atRelease runner or enforce current-head CodeQL verdict. The exact recurrence is handed to canonical organization issueContextualWisdomLab/.github#712in comment5555411125. Keep the repository leaf fail-closed and do not substitute the skipped Ready-transition run, duplicate central scanning, or blind-rerun the unchanged head.All currently returned inline review threads are resolved. Exact-current eligible independent approval and live ruleset satisfaction remain separate; no predecessor, skipped, absent, model-only, author-only, or status-only result is promoted to passing acceptance.
Product truth and next slice
The presentation-identity kernel is active-PR evidence, not protected-main shipment and not proof of Chromium/page-observed behavior. The next buyer-visible boundary remains a real Chromium adapter that deterministically applies an admitted profile before page script execution, observes the declared surfaces from the page, verifies the post-condition rather than treating protocol acknowledgement as success, and proves crash/cleanup/security behavior on a pinned Chromium generation. No separate open PR currently owns that adapter slice, but it should not be rushed ahead of the governed browser/runtime prerequisites or used to duplicate Chromium/policy authority already owned elsewhere in OriginWeave.
Protected-main
AGENTS.mdand live governance remain authoritative. Keep Ready but unmerged until central verdict/review/ruleset gates are satisfied. This scheduled product lane does not merge, self-approve, bypass, force-push, destructively rebase, alter workflows/rulesets/secrets, weaken checks, tag, release, or publish.