Execute reviewed Browser fixture plans with independent Host authority - #854
Merged
Merged
Conversation
YueZh127
marked this pull request as ready for review
September 23, 2026 12:25
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PQL Browser Bundle v2 currently cannot reach the existing hard-coded Browser-title executor without losing its reviewed navigation, target and catalog semantics. This adds an explicitly versioned, unpublished fixture route for one fixed navigation, an exact role/name/visible target and catalog-backed title equality.
Testing compiles and executes the plan; the reference Host supplies independent policy and a single-use grant binding the Case, candidate, catalog, targets, exact repository commit, network policy and execution identity. The route reuses the existing CDP client and durable Host store. It produces canonical CaseResultSet/EvidenceManifest artifacts, verifies retained intent/effect/completion on replay, and cannot promote or gate PQL assets. Existing executor and agentic contracts are unchanged.
The Chromium fixture is a private owned process/profile. Only the exact loopback document request and pinned HTML bytes are admitted; other requests, redirects, scripts, secrets, selectors and unsupported actions fail closed. Cleanup checks recorded process identity/group membership and profile device/inode. Unknown effects terminalize lost without repeat navigation.
Closes #853. Downstream integration: https://github.com/YueZh127/product-quality-loop/pull/94, tracking https://github.com/YueZh127/product-quality-loop/issues/88.
Validation: final real Chromium and related Node tests: 47 passed, zero skipped. The normal
scripts/run.sh test testing-runnerinvocation passed all 394 Lua tests and the then-current 46 Node tests; the only subsequent additions are the explicit sentinel-rejection test and its documentation. Canonical context/reducer tests cover pass, fail, lost, timeout and assertion-authority mismatch. All four fixtures validate against existing schemas. Cross-repository PQL integration passed both real Browser outcomes, and the full PQL suite passed 2037 tests with zero skips.Independent review corrected process-group/profile ownership and completed-result intent validation; final re-review found no remaining P0/P1 or scope/overengineering issue. The bracketed mismatch sentinel is excluded by the existing expected-title alphabet; its fully rebound negative regression proves rejection before store/effects. Canonical contextual tests use existing Lua contracts/reducer; the fixture implementation itself remains a Node implementation, not runtime delegation to the Lua executor.
The earlier full local suite reached its 15-minute bound in unchanged testing-design tests. Final complete CI and CodeQL passed at reviewed head
01fa6d02d03f518729a45b4d452bc4da36554f23: https://github.com/ChronoAIProject/fkst-packages-testing/actions/runs/35851441993. Merged as1bc1affa4bdd3e7f4944928c5ce654ec7ed3ec40; its Git tree759ea95198910b8695501c3ad07325ddd9643fd7exactly matches the reviewed head. No production Runtime, signed package release, authenticated product execution, model integration, or Promotion is claimed.