v1.90.0.0 feat: make browser cookie imports explicit and safe (#2964)

* fix(browse): prepare reliable cookie import wave for validation

* ci: sequence quality and behavior for validation branch

* fix(browse): isolate Windows qualification and preserve native diagnostics

* test(browse): cover cookie workflow quality and isolate Windows user paths

* test(browse): trace native member startup and initialize fresh folders

* fix(browse): keep Windows member stdin alive through EOF

* fix(browse): latch native timeouts and compare contained Edge startup

* test(browse): verify native version metadata and actual Windows argv

* test(browse): qualify Dia import on isolated macOS CI

* fix(browse): require picker origin for session mutations

* fix(browse): bound credential reads through stream completion

* test(browse): inspect owned Windows process arguments natively

* test(evals): preserve passing coverage during cookie repair reruns

* test(browse): isolate Dia qualification in a fresh macOS account

* test(browse): pass bounded integer timeouts to native Mac probes

* test(browse): distinguish Windows profile initialization from containment

* test(browse): await descendant pipe readiness before parent exit

* test(browse): initialize and restore isolated macOS Keychain state

* test(browse): initialize Windows fixture folders before qualification

* test(ci): pin the same Node runtime across Windows checks

* test(browse): distinguish native macOS browser preflight stages

* test(browse): isolate Windows descendant console lifetime

* test(browse): preserve native receipts and identify fixture lock holders

* test(browse): prepare dependency resolution before native Mac worker startup

* test(ci): include lock and close checks in native diagnostics

* test(browse): preserve native owner probe stages and subprocess deadlines

* fix(browse): classify Chromium profile-in-use exit precisely

* test(browse): retain Mac qualification evidence through cleanup failures

* test(browse): bound Mac fixture paths and retire its owned user domain

* test(browse): accept vanished fixture entries without weakening cleanup

* test(browse): identify probe-created macOS user domains safely

* test(browse): observe Mac user domains without targeting them first

* test(browse): use passive fresh-user ownership throughout Mac qualification

* test(browse): distinguish profile and registered-home Keychain lookups

* test(browse): qualify Dia under one registered account home

* test(browse): identify Dia startup and owned process-group failures

* test(browse): classify bounded Dia startup diagnostics without leaking output

* fix(test): preserve native Mac sandboxing and reap owned browser children

* fix(browse): preserve Chromium sandboxing for native profile imports

* test(browse): inspect signed Mach-O architecture without launching Xcode tools

* test(browse): sample pending Dia startup and reap on all cleanup paths

* test(browse): compare protected Dia launches in fresh Bun and Node accounts

* test(browse): inspect isolated Mac GUI readiness without browser access

* v1.90.0.0 fix: bind cookie picker actions to their document

* test: validate cookie guards and fit nested launch fixtures

* ci: configure the bundled Chromium sandbox helper

* fix(browse): classify Playwright authentication timeouts

* test: retain bounded Windows lifecycle diagnostics

* test(cso): reuse bounded NTFS precision candidates

* test(review): handle explicit preservation choices safely

* test(browse): remove owned fixture directories with explicit primitives

* test(review): distinguish descriptive reuse from edit commitments

* test: admit only the approved unscored cookie workflow refusal

* test: keep the Office Hours judge mock export-complete

* fix: keep dependency-free CI planners independent of the model SDK

* test: observe the exact holder after a native fixture unlink failure

* fix: start seeded PTY observations at owned readiness

* test: acquire identity-bound Windows deletion admission before profile resets

* test: preserve qualified Git index bits without authorizing mutations
This commit is contained in:
Garry Tan authored and GitHub committed 2026-09-25 12:06:45 -04:00
1 parent 730a1017d1
commit a84b0b5b6d
111 files changed
+14996 -1057

No files matched your search

+33 -2
View File
@@ -13,7 +13,8 @@ import Anthropic from '@anthropic-ai/sdk';
import type { JSONOutputFormat } from '@anthropic-ai/sdk/resources/messages';
import { setTimeout as delay } from 'node:timers/promises';
import { CLAUDE_FRONTIER_EVAL_MODEL, resolveEvalModel } from '../../lib/eval-model';
import { CLAUDE_FRONTIER_EVAL_MODEL, DEFAULT_JUDGE_MAX_TOKENS, resolveEvalModel } from '../../lib/eval-model';
export { DEFAULT_JUDGE_MAX_TOKENS } from '../../lib/eval-model';
export interface JudgeScore {
clarity: number; // 1-5
@@ -22,6 +23,35 @@ export interface JudgeScore {
reasoning: string;
}
export interface JudgeRefusalEvidence {
stop_reason: 'refusal';
response_id: string | null;
request_id: string | null;
model: string | null;
input_tokens: number | null;
output_tokens: number | null;
text_blocks: number;
}
export class JudgeRefusalError extends Error {
readonly refusal: JudgeRefusalEvidence;
constructor(response: { id?: unknown; _request_id?: unknown; model?: unknown;
usage?: { input_tokens?: unknown; output_tokens?: unknown }; content: Array<{ type: string }> }) {
super('Judge provider refused the evaluation; no automated score');
this.name = 'JudgeRefusalError';
this.refusal = {
stop_reason: 'refusal',
response_id: typeof response.id === 'string' ? response.id : null,
request_id: typeof response._request_id === 'string' ? response._request_id : null,
model: typeof response.model === 'string' ? response.model : null,
input_tokens: typeof response.usage?.input_tokens === 'number' ? response.usage.input_tokens : null,
output_tokens: typeof response.usage?.output_tokens === 'number' ? response.usage.output_tokens : null,
text_blocks: response.content.filter(block => block.type === 'text').length,
};
}
}
export interface OutcomeJudgeResult {
detected: string[];
missed: string[];
@@ -89,7 +119,7 @@ export async function callJudge<T>(
// Thinking and answer text share max_tokens. The old 1024-token budget
// could be exhausted before a frontier judge emitted any JSON.
const resolvedModel = resolveEvalModel('judge', model);
const maxTokens = opts?.max_tokens ?? 8192;
const maxTokens = opts?.max_tokens ?? DEFAULT_JUDGE_MAX_TOKENS;
const client = new Anthropic();
const makeRequest = () => client.messages.create({
@@ -134,6 +164,7 @@ export async function callJudge<T>(
.map(block => block.text)
.join('\n');
try {
if (response.stop_reason === 'refusal') throw new JudgeRefusalError(response);
if (opts?.jsonSchema !== undefined) {
if (response.stop_reason !== 'end_turn') throw new Error(`Structured judge did not complete: stop_reason=${response.stop_reason}`);
return JSON.parse(text) as T;