Skip to content

Isolate browser bridge cleanup - #16

Merged
nicodes merged 2 commits into
mainfrom
issue-148-diagnostics-policy
Sep 13, 2026
Merged

nicodes merged 2 commits into
mainfrom
issue-148-diagnostics-policy

Conversation

@nicodes

@nicodes nicodes commented Sep 12, 2026 •

Copy link
Copy Markdown
Member

Production diagnostics policy and browser-verification layer for https://github.com/aviorstudio/fieldsofrevik/issues/148. Native stack #17; depends on #15.

Acceptance evidence

Source head after the native-stack replay onto merged #15: a8b89a1f705ccca82cea27087600ad5b82ad49ba (tree-identical to pre-replay 8582a7898676f88eff7bf4e9d683344de30e3e67).

Criterion Evidence
Preserve debug consumers while ordinary production exports expose no bridge Godot policy tests pass. The exact packaged ZIP was installed into a clean fixture and exported with Godot 4.7.2; playwright-cli observed no godotElements, godotEvents, godotTestState, or owner global despite enabled/test-mode settings.
Explicit production diagnostics feature and distinct artifact identities Diagnostic export uses custom feature gd_playwright_diagnostics. Exact-head CI release-export identities were distinct: ordinary 62aa0cf7037d062be4d53058f0c00146a1c25807dab0ea84e7379013d62cbcfb; diagnostic 4ef999af717bb25da97c867833baa25a6754ec80ee89a00b38409da9097bc757.
Safe read-only data contract Exact/prefix element rules and event/state field rules default deny in diagnostic releases. Browser assertions accepted start_button/route, rejected undeclared entries and nested token, and rejected non-JSON values in focused Godot tests. This is bounded validation, not a confidentiality guarantee.
Bridge cleanup/isolation and ordinary Playwright input Browser assertions proved stale/disposable owners cannot clear a newer owner, owner cleanup removed globals, and a normal canvas click changed the allowlisted observed state without adding gameplay setters.
CI/release gate Common CI and both release targets now install SHA-512-verified Godot 4.7.2 export templates, pinned playwright-cli 0.1.18/Playwright Chromium, export both release artifacts from the exact ZIP, run browser assertions, and upload screenshots/identities. Replayed exact-head CI: PASS — https://github.com/aviorstudio/gd-playwright/actions/runs/34732370313; downloaded CI screenshots and identities were personally inspected.

Ordinary release artifact

Ordinary release artifact: bridge globals absent

Diagnostic release artifact

Diagnostic release artifact: allowlist, cleanup/isolation, and normal input pass

Local verification

  • Go 1.24.13: go test ./... — PASS.
  • Bun 1.2.23: bun test — 5 tests, 14 assertions, PASS.
  • Godot 4.7.2: four addon scripts, payload policy tests, and 8 runner controls — PASS.
  • Exact ZIP lifecycle: enable/restart/disable/restart and consumer-owned settings/autoload preservation — PASS.
  • Exact ZIP SHA-256: 43b086fe617324dae171336b13a552affa496aa5a8ea1016ba0d22e3f44a8969.
  • Installed-tree SHA-256: 2b665e540e9f5069088e0c15ca637921e8c3ded30c8b0cd0e1611c9adda58ba3.
  • Browser: playwright-cli 0.1.18, ordinary and diagnostic Godot 4.7.2 release exports — PASS; named session closed.
  • actionlint 1.7.7, ShellCheck 0.11.0, and git diff --check — PASS.

No reviewer is requested under Team No Review.

@nicodes
nicodes added this pull request to stack #17 September 13, 2026 01:07
Base automatically changed from issue-148-studio-engineering to main September 13, 2026 02:09
@nicodes
nicodes force-pushed the issue-148-diagnostics-policy branch from 8582a78 to abc548b Compare September 13, 2026 02:09
@nicodes
nicodes force-pushed the issue-148-diagnostics-policy branch from abc548b to a8b89a1 Compare September 13, 2026 02:10
@nicodes
nicodes merged commit 0445627 into main Sep 13, 2026
3 checks passed
@nicodes
nicodes deleted the issue-148-diagnostics-policy branch September 13, 2026 02:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant