Skip to content

[PRF.11] Blazor WebAssembly production build and generated C# SDK proof (offline units and local live run) - #39

Merged
deku2026 merged 22 commits into
mainfrom
task/prf-11
Oct 10, 2026
Merged

deku2026 merged 22 commits into
mainfrom
task/prf-11

Conversation

@deku2026

Copy link
Copy Markdown
Contributor

Claim: PRF.11 epoch 1 (w-deku-20261009-prf-11)

Task record: runtime-proofs lane, task-prf-11. Authority:

  • brief S20(d): offline units, plus the local opt-in live run against the proof origin once CLOUD.85 is deployed. Parts needing CLOUD.21 or CLOUD.22 are "blocked on CLOUD.21/CLOUD.22, not proven";
  • S25, S27(b) (base href "/"), S28(i) (the successor of the WEB.40 app-proof row), and S36;
  • plan defaults D1 to D12; D3 is resolved by fix6.

This PR delivers the Blazor WebAssembly production build and generated C# SDK proof on its offline units U1 to U9, plus the local opt-in live run.

Offline (U1-U9)

  • the start record;
  • the exact CSP token set and the profile serving contract on the published output;
  • exact int64, uint64 and decimal fixtures, and the CON.92 decode limits;
  • server-stream framing fixtures and the transport decision record: binary first, with no choice made before an observed run;
  • the Site no-script reading and determinism evidence;
  • the AL-06 budgets re-baseline: ceilings stay at the WEB.40 values, interactionBudgets stays re-baseline-pending (D8), and the largest file (dotnet.native.wasm, 3,001,422 bytes) is recorded;
  • the inline-style audit and the in-browser CSP check;
  • the live proof specs, which are opt-in and skip in CI;
  • the proof record and handoff. U8 (admission) is not needed: the NuGet closure is unchanged.

S36 resolution. PRF.11's review found the profile CSP base-uri 'none' defect. Web #38 fixed it, and this branch merges main and pins base-uri 'self' in its exact-policy tests.

Live run (local opt-in)

  • Target: https://proof.arcforges.com.
  • Deployment: the CLOUD.85 follow-up Cloud #82; proof deploy run 38009326285; web-0.1.0-ci.117.1.
  • Browser: the installed Chrome 156.0.8078.12 by path, with no download. Only anonymous GETs were made.

Result: 4 specs, 2 passed and 2 skipped. On /account/ and /chat/ the shell specs confirmed:

  • the exact profile CSP;
  • one <base href="/">;
  • the root framework path returns 200;
  • 0 CSP violations;
  • the app heading rendered.

The greeting and INP specs are blocked on CLOUD.21/CLOUD.22, not proven, and so are the exact-value calls, typed failures, cancellation, session and CSRF, and the binary server stream. This record cites CLOUD.85 as its deployed proof-origin same-origin and base-href evidence.

Validation (author, and independent reviewer under CI conditions)

  • locked restores; Release builds with 0 warnings;
  • tests: Tooling 56, Site 76 (1 skip by design), Ui 15, App 96, Operations 6, Policy 108;
  • format; publish;
  • the twice-built candidate is identical and verifies (20 members); the profile bundle (175 members) verifies; budgets pass;
  • npm test 94/94; audit 0; gitleaks 0; actionlint pass.

Mutation checks: the exact-policy pins and the HelloProbe send bound discriminate. The receive bound equals the library default and is recorded as a value pin, not proven.

Not run locally: npm run policy, which stops at the Node 24.20 vs 24.21 pin (hosted is authoritative).

Status

delivered (offline plus live shells). Completion waits on CLOUD.21 and CLOUD.22.

🤖 Generated with Claude Code

deku2026 and others added 22 commits October 9, 2026 19:43
…pletion edges

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
The emitted policy is pinned as one string on both profile paths: script-src exactly 'self' and 'wasm-unsafe-eval', style-src 'self', and no unsafe-inline, unsafe-eval or unsafe-hashes. The host page declares exactly one base element at the root ("/", CLOUD.85 D1). The emitted bundle test builds the profile bundle from a publish whose shell is the real host page, and checks the served Account and Chat shells and the headers file.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
The exact int64, uint64 and decimal checks use the pinned Contracts Foundation helpers (ExactInteger, ExactDecimal) on canonical text, including the int64 edges and values above 2^53. The CON.92 registry bounds (4 MiB unary, 256 KiB inline page, 32 KiB stream frame, 64 MiB large projection, 100 nested levels) are pinned, and the generated parser is exercised at each exact bound and one byte over, with truncated, bare-tag and reserved-wire-type frames refused as malformed. The Hello greeting now sets the gRPC channel's send and receive limits to the unary class. This commit also carries the CSP section of the proof record (U2), which the U2 commit left out.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
The binary application/grpc-web+proto and the grpc-web-text server-stream framings are tested as fixtures only: frames decode in order with the trailers status, the text body decodes to the same bytes, a data frame over the 32 KiB stream bound is refused, and truncated, short-header and malformed base64 bodies are malformed. The transport decision stays open with binary first and grpc-web-text only if the observed run fails. Its sources conflict (brief section 5, item 12), and no deployed stream is claimed.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
The Site output carries no script, module or WebAssembly file, offline, and the local opt-in no-JavaScript read of the public pages skips cleanly without its opt-in. The determinism gate builds the Site twice and diffs the trees. The one local opt-in run used the installed Chrome by path (no download) against a loopback static server and passed; it is claimant-reported and is not a deployed-origin observation.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
… count

The asset baseline of the Account and Chat profiles is re-baselined to the measured local publish, with the superseded React ceiling and the WEB.40 baseline recorded in docs/prf-11-budgets.md. The 10 percent regression gate is unchanged, and the interaction budgets stay re-baseline-pending (owner PRF.11). The static asset file count is 174 served files, 116 of them precompressed, against the Workers platform limit of 20,000 files per Worker version on Free. The non-virtualised chat transcript is bounded at 20 entries by construction, and no numeric sustained-memory budget was found in the Design authority, so that costing is open.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
The live PRF.11 specs are test-only and skip without the explicit opt-in, an https proof origin and a non-CI host; the cloud parts also skip as blocked on CLOUD.21 and CLOUD.22 until the cloud switch is set. The inline-style audit of the Razor components in use is clean. A local emulation of the served CSP logs a base-uri 'none' violation that blocks the shells' base href. That is a Ui policy decision outside the PRF.11 write scope, so the proof stops for a decision and no policy is changed here.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
…ntory

The source inventory must name every tracked and non-ignored first-party file, so the PRF.11 documents, the App and Tooling test files, and the browser opt-in specs are appended to firstParty. Reused material and records are unchanged.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
PRF.11 is recorded as delivered on its offline units U1 to U9 and not complete. The record lists the offline receipt, the local gate results with their environment gaps, the open base-uri decision for the in-browser CSP check, the blocked completion edges (CLOUD.21, CLOUD.22 and CLOUD.85), the CLOUD.71 history note, and the not-claimed list. It supersedes PRF.08 and is the successor of the WEB.40 app-proof row.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
…S25 review fields

The served policy's base-uri 'none' stops the Account and Chat shells from starting. Observed locally in four of four
headless runs with the installed Chrome: the base-uri violation is logged, the framework loader resolves under /account/
and returns 404, and the heading never renders. The record now states that outcome, not "not established". The Ui
policy is outside the PRF.11 write scope and is not changed; the decision is listed for the coordinator.

The profile proof and the stream transport records carry the pre-assigned reviewer, decision: approved and reviewedOn
at their head (brief S25). The budgets record already carried them.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
Re-ran the PR job steps that can run locally at b84e2e3 from a clean state under CI conditions (GITHUB_ACTIONS, CI,
GITHUB_REPOSITORY, a fresh NuGet folder). Restores, format, build, all six test projects, the App and Operations
publishes, the Site built twice, the candidate job, the profile budgets and bundle, the npm source and quality steps,
actionlint, and the pinned gitleaks in WSL Docker all pass. The policy script fails only at its Node version assertion
(environment gap). The gate table records these results and the local conditions that had to be corrected.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
…mal bound and the TooDeep nesting refusal

The int64 and decimal refusals assert the parser's FormatException, not any exception. The decimal bound (nine fractional and twenty-eight significant digits) is tested at its edges and over it. Nesting of 100 unknown groups decodes, and 101 is refused as TooDeep.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
The Status now states the task is stopped pending the coordinator's Ui decision on base-uri 'none' and is not delivered. The fix2 review section lists the dispositions and the cases not covered.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
The fix2 gates (C# restore, format, build, test, publish and Site, the candidate and bundle, the Source and quality legs, and gitleaks in WSL Docker) passed from a clean state at 792af5a with a fresh NuGet folder. The policy step still fails only on the local Node pin, which is an environment gap.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
The profile policy now admits the shells' base element (WEB.40 follow-up, Web #38), so the exact-policy pins move
from base-uri 'none' to base-uri 'self' in the App, Tooling and browser test projects. The Site policy keeps
base-uri 'none'.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
…under CI conditions

The profile base-uri stop from fix1 and fix2 is resolved by S36 and WEB.40 follow-up Web #38 (base-uri 'self' for the
profiles, 'none' kept for the Site). PRF.11 is delivered on its offline units U1 to U9. Completion stays blocked on
CLOUD.21 and CLOUD.22 (not proven), and the local opt-in live run follows the CLOUD.85 follow-up proof redeploy.

The record now carries the fix3 merge of origin/main (049f6a5), the fix3 gate re-run at code head 2038716 under CI
conditions (npm policy stops at the local Node pin and is recorded as hosted), and the fix3 S36 review section.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
…med kinds (review fixes 2 and 3)

- HelloProbeTests: add a send-bound test. A request one byte over the unary class must not reach the transport. The library default send bound is null, so removing the explicit MaxSendMessageSize line fails the test (mutation run checked).
- The receive bound equals the library default (4,194,304 bytes), so its explicit line is not observable offline. The test comments and the profile proof say so; the explicit receive line is recorded as a value pin, not as proven.
- StreamFramingTests: every case whose name says Malformed asserts FailureKind.Malformed, through one helper.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
The runbook names the pre-assigned reviewer w-deku-20261008-rev-prf-11, decision approved and reviewedOn 2026-10-09, as the other PRF.11 records do. The fields are a proposal that only the named reviewer's exact-head approval ratifies.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
…0 ceilings (review fixes 1 and 6)

The U6 baseline raised every ceiling above the pre-PRF.11 WEB.40 ceiling, although every head value fits under the WEB.40 ceiling. The head was re-measured at 006b4b8 under CI conditions. The baseline of both profiles is the WEB.40 baseline (eng/policy/profile-budgets.json is byte-identical to c5a5f2e), so no ceiling is looser than the WEB.40 ceiling and no loosening remains. The head values are recorded in docs/prf-11-budgets.md beside the ceilings, with each headroom.

The largest single static file, dotnet.native .wasm at 3,001,422 bytes (11.4 percent of the 25 MiB single-file limit), is recorded in the budgets doc (review fix 6).

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
…run-to-run variation

The budgets record now states the figures of the gate chain of record at 31888e1, with the 006b4b8 values in brackets. The earlier statement that the publish output does not change between the two heads was wrong: two clean publishes of the same product code differ by 2 to 15 bytes on the wasm and JS metrics. Every ceiling still holds with a wide margin. No budget value or ceiling is changed by this commit.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
… and the gate chain at 31888e1

The live run used the installed Chrome 156.0.8078.12 with Microsoft.Playwright 1.62.0 by path, no download, and no CI markers. The four LivePrf11Specs ran against https://proof.arcforges.com/: the two shell specs passed (the exact profile CSP on /account/ and /chat/, one base href at /, the root framework path 200, no CSP violation, and the app heading rendered on both shells). The two cloud specs were skipped as blocked on CLOUD.21 and CLOUD.22, not proven. The binary server stream, INP and the exact-value, typed-failure, cancellation and session calls are recorded as blocked, not proven, and nothing is claimed for them.

The record also states the gate chain at 31888e1 under CI conditions, the review dispositions (findings 1 to 6), and the operational note on the dotnet test trx form. The runbook command is corrected to the form that ran the specs.

This record cites CLOUD.85 as its deployed proof-origin same-origin and base-href evidence.

Co-Authored-By: Claude Haiku 5.5 <noreply@anthropic.com>
@deku2026

Copy link
Copy Markdown
Contributor Author

Reviewed 7c668b8 for [PRF.11] epoch 1: approved. This is an independent exact-head review over the full change, with a delta focus on the live round.

Reviewer: independent session w-deku-20261008-rev-prf-11. Approvals are comments under one GitHub account, so independence is by session only.

Rounds:

At 7c668b8, re-run independently:

  • Gates under CI conditions: Tooling 56, Site 76 + 1 skip, Ui 15, App 96, Operations 6, Policy 108; format; Release builds with 0 warnings; publish; budgets pass (head values listed in the record); the twice-built candidate is identical and verifies; the bundle (175 members) verifies; npm test 94; audit 0.
  • Mutations:
    • removing the explicit send bound fails the new test;
    • removing the receive bound changes nothing (the library default), as the record states;
    • the framing kind assertion discriminates.
  • Live specs against https://proof.arcforges.com with Chrome 156 by path: 2 passed and 2 skipped, matching the author's run. An anonymous GET confirms base-uri 'self' on the profiles and 'none' on the Site.
  • The record claims nothing that needs CLOUD.21 or CLOUD.22.

Non-blocking, carried:

  • the budgets doc line 62 wording;
  • the S25 reviewedOn pre-fill date (2026-10-09; ratified by this review, S25);
  • the StreamFramingTests line 25 comment.
  • npm run policy stops at the local Node pin (hosted is authoritative).

@deku2026
deku2026 merged commit dd0a5de into main Oct 10, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant