Browse documentation

Operate and contribute

Frontend qualification

Separate source observations from candidate, browser, WebView, assistive-device, and release evidence.

On this page

Snapshot: 2026-08-12 documentation reconciliation.

source_present means the relevant implementation/check exists in source. local_pass means the gate passed on the uncommitted 2026-08-12 working tree with supported Node 24.19.0; it improves implementation confidence but is not release evidence. pass is reserved for evidence bound to one branch, commit, lockfile digest, profile, toolchain, artifact digest, command, exit code, and timestamp. deferred_platform_validation means the check has not been run yet. It is not a pass.

Local automated validation was run after the source-only reconciliation. It does not create a release approval because the tree is uncommitted and native, device, live-provider, installer, signing, and rollback gates remain open.

SurfaceSource observationCandidate gateRelease/device gate
Contracts and clientssource_present: registered operations, runtime codecs, typed transportslocal_pass: workspace TypeScript build and consolidated vectors; 331 passed, 0 failed, 2 intentional skipscommit-bound supported Node/pnpm evidence
Async statesource_present: project generations, cancellation, idempotency, reconciliationlocal_pass: race, stale-result, polling, idempotency, and outcome-unknown vectorsoffline/resume/reconnect soak
Browser authoritysource_present: bootstrap, cookie/CSRF, rotation, project bindinglocal_pass: Host/Origin/session matrix; headless Edge confirmed the UI reports a missing daemon accurately at startuplive supported Chrome/Edge authority flow
Native desktopsource_present: Rust-owned daemon/credential and one invoke commandlocal_pass: six Rust unit tests plus Tauri compile/package mechanics with inert sidecar fixturedeferred_platform_validation: real packaged Windows WebView/daemon sidecar, signing, and installer smoke
Privacy and agent projectionsource_present: schemas, visibility policy, result projectionlocal_pass: canaries, operation matrix, ownership races, and projection completenessproduction-composed MCP daily loop
Provider egresssource_present: write-only secret store and destination policylocal_pass: non-exposure, DNS, redirect, private-address, and bounded-output vectorsapproved loopback and remote provider smokes
Destructive effectssource_present: intents and frontend wrappers; confirmation bypass removedlocal_pass: prepare/commit/cancel/replay/expiry/race vectorsdisposable packaged destructive flow
Recovery and diagnosticssource_present: closed errors, layered boundaries, local diagnosticslocal_pass: recovery contracts and headless Edge startup-recovery smokeoffline/locked/crash packaged flows
Accessibilitysource_present: primitives, tokens, source checker, manual protocollocal_pass: source contract, 30 contrast pairs, semantic/keyboard/focus vectorsdeferred_platform_validation: zoom/forced-colors, NVDA/VoiceOver/WebView/touch/physical device
Routing and graphsource_present: typed registry, recovery/focus, adapters, structured fallbacklocal_pass: route/graph and desktop contractsdeep-link/back-forward live browser and WebView flow
Public docssource_present: generator/checker and progressive sourcelocal_pass: 43 direct guides, default-visible navigation, bounded sanitized searchphysical mobile/keyboard walkthrough
Artifacts and releasesource_present: budgets, secret scan, evidence and SBOM scriptslocal_pass: production build, unchanged budgets, source/fixture guards, isolated synthetic-secret scan; evidence/SBOM not promotedsigning, promotion, installer, rollback drill
Migration/compatibilitysource_present: profile migration and dated registerlocal_pass: source and emitted reachability contractsoperator migration and rollback walkthrough

Required integrated order#

  1. Bind candidate identity and verify a clean source boundary.
  2. Validate the V2 execution ledger with its canonical orchestrator.
  3. Run source-artifact check, workspace typecheck, and deterministic tests.
  4. Build/check generated public docs and run accessibility source checks.
  5. Build browser assets; run budgets, fixture/forbidden-import, source-map, and secretless emitted-byte scans.
  6. Generate evidence manifest and SBOM/checksums for those exact assets.
  7. Run supported browser and Rust/Tauri gates.
  8. Execute the declared manual assistive/device/profile/rollback matrix.
  9. Record unavailable gates and unexpected skips without relabeling them.

Claim rules#

  • Source implementation complete: integrated source is independently reviewed, every locally reproducible required gate passes, and all residual paths/gaps are explicit.
  • Release/device qualification complete: every gate required for the selected release target passes against the same artifact and profile.
  • A post-build or deployed smoke cannot replace a missing pre-release gate.
  • Evidence from a rebuilt artifact, different profile, old lockfile, or older commit cannot be reused.

See Testing, Developer preview, Migration, and Compatibility register.