Repository navigation
Add bounded selector actions with checked target identity - #55
Conversation
There was a problem hiding this comment.
P2 — coherent public mutation-surface feature, so merge timing needs maintainer sign-off.
Blocking: selector resolution can cross a document replacement after the revision check and mutate the replacement page.
Maintainer call: after that race is closed, is selector-addressed mutation intended for the 2.0 surface?
Thanks for the scoped split and contract coverage.
| } | ||
| } | ||
| const resolvedBackendNodeId = hasSelector | ||
| ? await this.backendNodeIdFromSelector(tabId, String(action.selector), String(action.kind)) |
There was a problem hiding this comment.
blocking: act() checks expected_page_revision on line 569, then awaits DOM.getDocument/DOM.querySelectorAll here and executes the returned backend node without revalidating the document identity. If a navigation replaces the document during those awaits before the asynchronous tabs.onUpdated revision bump is observed, this selector resolves in the replacement page and performAction() mutates that new page; ref-addressed actions instead fail when their old backend node disappears. This violates the documented invariant that document replacement rejects rather than selects a new target. Capture/compare the page identity around selector resolution (and cover the in-flight replacement case) before executing or staging it.
Summary
Verification
Workspace typechecks, SDK build, extension action contracts, adapter contracts, and rendering regressions passed.