Skip to content

[WEB.40] Profile CSP base-uri 'self' and plain profile stylesheets (completion follow-up) - #38

Merged
deku2026 merged 2 commits into
mainfrom
task/web-40
Oct 9, 2026
Merged

deku2026 merged 2 commits into
mainfrom
task/web-40

Conversation

@deku2026

@deku2026 deku2026 commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Claim: WEB.40 epoch 2 (w-deku-20261008-web-40), completion follow-up (DLV-41)

This fixes two defects in the delivered WEB.40 profiles, found during PRF.11's independent review (coordinator rulings S36 and S37).

  • S36, profile CSP base-uri: the profile policy emitted base-uri 'none'. That blocks the shells' required <base href="/">, so /account/ and /chat/ never started in a browser.
    • The profile policy now uses base-uri 'self', and every other token is unchanged.
    • The Site policy keeps base-uri 'none'.
    • Tests pin both. The Design does not specify base-uri, so no planning change is needed.
  • S37, vestigial Tailwind preamble: the profile stylesheets kept the React-era @import "tailwindcss", @source and @theme lines, which nothing compiles. Each load caused a /tailwindcss 404 and a refused stylesheet, and --font-sans was undefined.
    • The @import and @source lines are removed, and the @theme values move into :root unchanged.
    • A test keeps Tailwind at-rules out of the profile stylesheets.

Browser boot check (installed Chrome 156 headless; profile bundle served with its own _headers; no download):

  • On the parent c8588681: 1 CSP violation per shell, and both shells stay on Loading.
  • At this head: 0 CSP violations, no static-asset 404, no refused stylesheet, the Segoe UI font stack, and both app roots rendered.
  • The only non-2xx is /session/v1/bootstrap, a session API outside this static check (CLOUD.21 and CLOUD.22).

Local gates under CI conditions (build slot):

  • locked restores; Release build with 0 warnings;
  • tests: Tooling 52, Site 76, Ui 15, App 73, Operations 6, Policy 108;
  • format; publish;
  • the twice-built Site and candidate are identical, and the candidate verifies;
  • the profile bundle (172 members) and budgets pass;
  • npm test 94/94; gitleaks 0.

Not run locally: npm run policy, which stops at the local Node 24.20 vs the 24.21 pin; actionlint (not installed). Hosted CI is authoritative for both.

Downstream: the CLOUD.85 verifier pins the old profile policy. Its follow-up moves the expected policy and the pins to this release, then the proof origin is redeployed.

🤖 Generated with Claude Code

deku2026 and others added 2 commits October 9, 2026 22:48
The WebAssembly profile policy emitted base-uri 'none', which blocks the
<base href="/"> of the Account and Chat shells. The relative framework
loader then resolves under the shell path and the shells never start.
Profiles now emit base-uri 'self'; the Site policy keeps base-uri 'none'.
The Ui, App and Operations policy tests and the profile bundle doc pin the
new token, and the Site test pins base-uri 'none'.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
The profile stylesheets began with React-era Tailwind v4 lines (an
@import of tailwindcss, two @source lines and an @theme block). Nothing
compiles them, so each profile requested a missing /tailwindcss stylesheet
and --font-sans was undefined. The @theme variables now live on :root with
the same names and values, and the rest of each stylesheet is unchanged.

Each profile test project asserts that its stylesheet carries no
@import "tailwindcss", @source, @theme, @apply or @tailwind and defines
--font-sans on :root.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
@deku2026

deku2026 commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Reviewed 6795f18 for [WEB.40] epoch 2 (completion follow-up): approved. The review was an exact-head review at 2523056 plus a delta review at 6795f18.

Reviewer: independent session w-deku-20261008-rev-web-40. Approvals are comments under one GitHub account, so independence is by session only.

  • 2523056 (S36): the only policy change is base-uri 'none' to 'self' in WasmContentSecurityPolicy, and the Site policy is untouched. Tests pin profile 'self' and Site 'none'. Every file is inside the WEB.40 writes.
    • Browser boot check, installed Chrome 156 headless: the parent shows 1 violation per shell and stays on Loading; the head shows 0 violations and renders both roots.
    • Gates under CI conditions: tests Tooling 52, Site 75 + 1 skip, Ui 15, App 72, Operations 5, Policy 108; the twice-built candidate is identical and verifies; the profile bundle verifies; npm test 94; audit 0; gitleaks 0.
  • 6795f18 (S37): only the Tailwind preamble is removed, and :root carries the same values. The new tests fail on the parent's app.css, as intended.
    • Boot check: 0 CSP violations, no static-asset 404, no refused stylesheet, the Segoe UI stack, and both roots rendered.
    • App 73, Operations 6, Ui 15, format, budget, bundle and npm test 94 pass.

Non-blocking: npm run policy was not run locally (Node 24.20 vs the 24.21 pin; hosted is authoritative), and actionlint was not run (not installed). The /session/v1/bootstrap 404 is a session API call outside the static check.

@deku2026
deku2026 merged commit 049f6a5 into main Oct 9, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant