Skip to content

Native raster entry capture serves the comp to the page it grades #893

Description

@pbakaus

Problem

The native hero and responsive gates capture comp-led pages through CdpEntryRenderer (crates/cli/src/entry_capture.rs). For a spec with at least one raster region, the raster path freezes the project with served: static_inventory(root). That inventory includes every static browser file outside hidden directories and node_modules, so it also includes the approved comp whenever the comp sits at a normal project path (for example comp.png or assets/comp.png).

That means the page being graded can show the reference itself. A page that paints <img src="comp.png"> (or a copy of it, a data URI of it, or a CSS background using it) behind or instead of its code layers is compared against the same pixels it displays, so the overall score, palette check and region readings can pass without the viewport being built. The raster presence checks don't stop this: they ask whether each declared plate paints in its box, not whether anything else also paints there.

This predates #892. That PR closes the same bypass for first viewports with no raster region only, and leaves the raster path byte-identical on purpose.

Proposed fix

Bring the raster path in line with the text-only path from #892:

  1. Keep the spec and comp bound (hashed, re-verified) but take them out of the served set in HtmlSnapshot::freeze for entry capture, so a request for the comp fails as an undeclared dependency.
  2. Refuse a capture when a file the page loads is a byte copy of the comp, or of the approved first-viewport screenshot when a review is accepted, or inlines either as a base64 data URI (with whitespace ignored). The asset receipts already list the responses the page loaded.
  3. For re-encoded copies, measure image coverage outside the declared raster regions: images whose rendered boxes cover a large share of the viewport outside every raster region's box contradict the spec the same way a large image does on a text-only page. Capture code-only first viewports for the native hero gate #892 uses 15% of the viewport as the text-only threshold, and the same measurement (crates/cli/src/raster_coverage.js) can take the region boxes as exclusions.

This changes raster gate evidence (served set, receipts), so it needs oracle review and DELTAS entries if any browser-free output moves, plus a docs/CLI-CONTRACT.md update.

AI assistance: filed by Claude Code for the maintainer.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs triageNew or reopened issue awaiting maintainer triage

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions