You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Native raster entry capture serves the comp to the page it grades #893
The native hero and responsive gates capture comp-led pages through CdpEntryRenderer (crates/cli/src/entry_capture.rs). For a spec with at least one raster region, the raster path freezes the project with served: static_inventory(root). That inventory includes every static browser file outside hidden directories and node_modules, so it also includes the approved comp whenever the comp sits at a normal project path (for example comp.png or assets/comp.png).
That means the page being graded can show the reference itself. A page that paints <img src="comp.png"> (or a copy of it, a data URI of it, or a CSS background using it) behind or instead of its code layers is compared against the same pixels it displays, so the overall score, palette check and region readings can pass without the viewport being built. The raster presence checks don't stop this: they ask whether each declared plate paints in its box, not whether anything else also paints there.
This predates #892. That PR closes the same bypass for first viewports with no raster region only, and leaves the raster path byte-identical on purpose.
Proposed fix
Bring the raster path in line with the text-only path from #892:
Keep the spec and comp bound (hashed, re-verified) but take them out of the served set in HtmlSnapshot::freeze for entry capture, so a request for the comp fails as an undeclared dependency.
Refuse a capture when a file the page loads is a byte copy of the comp, or of the approved first-viewport screenshot when a review is accepted, or inlines either as a base64 data URI (with whitespace ignored). The asset receipts already list the responses the page loaded.
For re-encoded copies, measure image coverage outside the declared raster regions: images whose rendered boxes cover a large share of the viewport outside every raster region's box contradict the spec the same way a large image does on a text-only page. Capture code-only first viewports for the native hero gate #892 uses 15% of the viewport as the text-only threshold, and the same measurement (crates/cli/src/raster_coverage.js) can take the region boxes as exclusions.
This changes raster gate evidence (served set, receipts), so it needs oracle review and DELTAS entries if any browser-free output moves, plus a docs/CLI-CONTRACT.md update.
AI assistance: filed by Claude Code for the maintainer.
Problem
The native hero and responsive gates capture comp-led pages through
CdpEntryRenderer(crates/cli/src/entry_capture.rs). For a spec with at least one raster region, the raster path freezes the project withserved: static_inventory(root). That inventory includes every static browser file outside hidden directories andnode_modules, so it also includes the approved comp whenever the comp sits at a normal project path (for examplecomp.pngorassets/comp.png).That means the page being graded can show the reference itself. A page that paints
<img src="comp.png">(or a copy of it, a data URI of it, or a CSS background using it) behind or instead of its code layers is compared against the same pixels it displays, so the overall score, palette check and region readings can pass without the viewport being built. The raster presence checks don't stop this: they ask whether each declared plate paints in its box, not whether anything else also paints there.This predates #892. That PR closes the same bypass for first viewports with no raster region only, and leaves the raster path byte-identical on purpose.
Proposed fix
Bring the raster path in line with the text-only path from #892:
HtmlSnapshot::freezefor entry capture, so a request for the comp fails as an undeclared dependency.crates/cli/src/raster_coverage.js) can take the region boxes as exclusions.This changes raster gate evidence (served set, receipts), so it needs oracle review and DELTAS entries if any browser-free output moves, plus a
docs/CLI-CONTRACT.mdupdate.AI assistance: filed by Claude Code for the maintainer.