Skip to content

Prefer a provisioned Lightpanda for qualified LinkedIn profile reads in v0.18.83 - #560

Merged
0thernet merged 1 commit into
mainfrom
lightpanda-contained-sessions
Oct 5, 2026
Merged

0thernet merged 1 commit into
mainfrom
lightpanda-contained-sessions

Conversation

@0thernet

@0thernet 0thernet commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Summary

  • createBrowserSession accepts a browser-engine selection: "auto" resolves to Lightpanda only for cookie-yielding realms with an explicitly provisioned 1.0.0 executable, "chrome" keeps the existing lane, "lightpanda" requires both.
  • The LinkedIn profile transport defaults to "auto" for its qualified reads — identity, personal stats, connections, organizations. Contact reads stay on Chromium (their overlay harvests live network requests bindings Lightpanda has not been proven to report); article/comment/post/feed/search and all other providers keep the unqualified Chromium default.
  • Under durable cleanup admission, a CDP-attached Lightpanda session publishes prepared → launch-intent (never the Chromium control witness) and proves quiescence from daemon-observed inactivity after the owned serve child is reaped. "auto" with a publisher runs a throwaway preflight — spawn, open about:blank, one stdin cookie import, close, reap, production convergence proof — before the durable identity exists, so a protocol incompatibility still resolves to Chromium and a post-publish failure fails closed.
  • Fallback is limited to a recognized LightpandaCompatibilityError raised before target navigation inside the original deadline; assertions, denials, identity drift, cleanup failures, and timeouts never fall back.
  • Rebased onto current main (which had already shipped 0.18.80–0.18.82): version bump to 0.18.83 with changelog, skill/install docs, version-pinned surfaces, dist rebuild, and re-measured package budget (638 entries, 12,237,548 packed / 24,524,887 unpacked bytes, SHA-256 34a0261f…, byte-identical across two clean packs).

Validation

  • Typecheck clean; focused suites green on the rebased tree: browser.test.ts 77, lightpanda-browser.test.ts 100, LinkedIn runtime/profile suites, admission tests — 260 tests in the combined focused run.
  • test:npm-release 50 pass; verify:claims 142 pass; verify:oracles 35 pass; standalone package smoke green.
  • Broad bun run check local run on the pre-rebase tree: 5231 pass / 62 fail — every failure triaged: concurrency-window flakes caused by a concurrent full check triggered by npm pack's prepack, missing native-derive fixture (provisioned since), and one fixture cold-start; all affected files verified green standalone afterward.
  • Three independent review rounds; all majors fixed (cleanup-admission bind, AggregateError-wrapped compat, proxy leak, teardown under-bound, close-ack ordering, batch close exemption, abort-aware converge) and the final round found no blockers (one minor: one-shot rewrite flag consumed by stdin-free invokes — fixed with a regression test).
  • Live publisher-enabled round trip verified: prepared → launch-intent → journal-quiescent → root-removal journals → private roots deleted; unprovisioned "auto" resolves to Chromium.
  • Residual: one provider-200 LinkedIn read through the integrated path is pending — the saved session is dead across all transports (HTTP 401 identical), so re-authentication is required for that live evidence. Artifact admission does not depend on it.

Test plan

  • Focused unit suites for engine selection, preflight, fallback, custody, cleanup journals, stdin secrecy
  • Provider engine-forwarding and contact Chrome-pin tests
  • Release-workflow and package-budget pins re-measured and green
  • Live publisher round trip and unprovisioned fallback probe
  • Required CI on this PR head
  • Post-relogin provider-200 LinkedIn read through the integrated path (follow-up)

Generated with Devin

@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
ghostget Ready Ready Preview Oct 5, 2026 8:31am UTC

Request Review

…in v0.18.83

createBrowserSession accepts a browser-engine selection: "auto" resolves
to Lightpanda only for cookie-yielding realms with an explicitly
provisioned 1.0.0 executable, "chrome" keeps the existing lane, and
"lightpanda" requires both eligibility and provisioning. The LinkedIn
profile transport defaults to "auto" for identity, stats, connections,
and organization reads; contact reads stay pinned to Chromium because
their overlay harvests live network-request bindings that Lightpanda has
not been proven to report, and every other transport keeps the
unqualified default.

Under durable cleanup admission a CDP-attached Lightpanda session cannot
bind the Chromium control witness, so it publishes prepared and
launch-intent and proves quiescence from daemon-observed inactivity
after the owned serve child is reaped. The auto path runs a throwaway
preflight — spawn, open about:blank, one stdin cookie import, close,
reap, inactivity proof — before the durable identity exists, so a
protocol incompatibility still resolves to Chromium within the original
deadline and a post-publish failure fails closed rather than registering
a second identity.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@0thernet 0thernet changed the title Prefer a provisioned Lightpanda for qualified LinkedIn profile reads in v0.18.80 Prefer a provisioned Lightpanda for qualified LinkedIn profile reads in v0.18.83 Oct 5, 2026
@0thernet
0thernet force-pushed the lightpanda-contained-sessions branch from 848f789 to d3e7ea1 Compare October 5, 2026 08:30
@0thernet
0thernet merged commit 0137e55 into main Oct 5, 2026
27 checks passed
@0thernet
0thernet deleted the lightpanda-contained-sessions branch October 5, 2026 08:44
0thernet added a commit that referenced this pull request Oct 5, 2026
## Summary

- Flips `kb/plans/lightpanda-semantic-capture.md` to `status: completed`
- Records the v0.18.83 delivery (PR #560, merge `0137e55b`, immutable
Release + npm admission) in `## Result`
- `wordcell refresh` + `check` clean

#### Test plan

- [x] Knowledge-base catalog/check green
- [ ] Required CI

Generated with [Devin](https://devin.ai)

Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

This branch was successfully deployed

1 active deployment
Preview — d3e7ea15 Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant