-
Notifications
You must be signed in to change notification settings - Fork 3
plat 401
github-actions[bot] edited this page Oct 3, 2026
·
2 revisions
| Coordination | Value |
|---|---|
| State | fixed on main; Excellence has the launcher installed (proved with the matrix); deploy to the other servers pending |
| Date | 2026-10-03 |
| Owner | browser |
| Related | PLAT-374 (mount-namespace fallback removed), PLAT-364 |
After PLAT-374 the Code/Crew project browser ran Chrome as the service account under Landlock. Three separate causes, found with Chrome's own stderr through the isolator on Excellence:
- HOME (
/srv/agents/home) is not writable in the sandbox; Chrome died at start ("exited early ... without writing DevToolsActivePort": crashpad--database is required, SIGTRAP)./usr/bin/google-chromealso writes under HOME. - Excellence ran the system Chrome directly (no
AGENT_BROWSER_EXECUTABLE_PATH, no launcher). - Through the
chrome -> /opt/google/chrome/chromesymlink Chrome looks forlibvulkanbeside the path it was started as; SwANGLE failed to initialise and the browser died (SIGTRAP) on the first screenshot or screencast: agent-browser "CDP response channel closed".
-
chrome-agentworks: writable HOME/XDG under its private temp dir; runs the resolved Chrome binary. -
install-managed-chrome.sh(called bybuild-and-activate.sh) installs it beside the host Chrome (<app>/tools/chrome/current, system Chrome getstools/chrome/system);runtime_profile.jsonsetsAGENT_BROWSER_EXECUTABLE_PATHfor every product. - Regression tests:
workspace/security/chrome_devtools_linux_test.go(DevTools reached, PNG screenshot; both fail with the earlier launchers). -
deploy/rootless-linux/verify-browser-matrix.py: full matrix through the real/api/executepath with multi-user headers (55 rows: start/open https+http, interaction, tabs, screenshots viewport/full/annotated/element, PDF, live-view JPEG frames, upload/download, console, page errors, network requests, HAR, trace, profiler, capture API, persistence, heavy page, two concurrent sessions, kill -9 recovery, crash recovery, idle timeouts, close, 20 open/close cycles).verify-managed-chrome.pynow sends the app's headers too.
- Deploy to Confida (same script) and, if it uses the rootless deploy, Dominion; re-run the matrix there.
- Matrix findings: an
openright afterclosecan fail once ("Failed to connect": the app already retries three times); the live stream's console messages arrive but no console panel uses them. The crashed-tab and tall-screenshot findings moved to PLAT-414.
Auto-synced from docs/ on main. Edit there, not here.