Skip to content

conformance(ipc): pinned v44.4.5 entries for the draw.io IPC path — send/on/once, ipcMain.on/once/removeListener, event.reply, senderFrame, webContents.send delivery, IpcRendererEvent, structured-clone throws, contextBridge value rows, navigation-gen #464

Description

@0monish

Generated by an AI agent (Claude Code) on behalf of @0monish during Wayfinder charting of the Electron compatibility program; rewritten 2026-10-07 by the doctrine-audit repair pass (change log at the end). Planning only — no implementation is authorized by this issue.

Parent

Epic #463 · Map #391 · Unit F04 · Kind: conformance · Tier: Tier 1 · Maturity target: L2 · Size: M · Milestone: first-proof

What to build

Land red-until-implemented KEL-74 cells for the draw.io first-proof IPC path. Doc-sentence entries (ipc-renderer.md, ipc-main.md, ipc-main-event.md, ipc-renderer-event.md, context-bridge.md at v44.4.5): (1) ipcRenderer.send args reach an ipcMain.on listener by structured clone; (2) send throws synchronously for Function, Promise, Symbol, WeakMap, WeakSet; (3) ipcMain.once fires once and ipcMain.removeListener stops delivery; (4) event.reply reaches the sending frame and webContents.send reaches an ipcRenderer.on listener of that WebContents; (5) senderFrame.url equals the loaded document URL and senderFrame is null after the frame navigated or was destroyed; (6) IpcRendererEvent.sender is the ipcRenderer instance and ports is an empty list when nothing was transferred; (7) contextBridge rows: functions proxied (argument position, including a callback nested in an object argument, called N times from the preload world), other values copied and frozen, Symbol dropped, Error copied with message. Observed-only entries (no v44.4.5 doc sentence states them, so under the X01-T3 uncited-cell rule they land with expected status unknown; the recorded-oracle comparison is F04-T20's, next milestone): (8) per-channel order of N sends; (9) webContents.send with no renderer listener is dropped, not queued for a later listener; (10) stale event.reply after cross-document navigation is dropped without throwing; (11) a hash change during a pending request does not drop the reply; (12) a cancelled renderer-initiated navigation keeps IPC usable; (13) reply with unserializable args throws, and reply after render-frame disposal throws (drop-versus-throw boundary recorded as ▲). Doc-sentence entries are red-until-implemented cells in the X01-T3 representation (expected fail, implementing-ticket key named: entries 1, 3, 4 and 5 F04-T3, entry 2 F04-T11, entries 6 and 7 F04-T4) validated by the X01-T4 manifest owner.

Acceptance criteria

  • Every doc-sentence entry is a red-until-implemented KEL-74 cell in the X01-T3 representation: expected status fail with its implementing-ticket key, a mapped test that asserts the current behaviour and passes, and a flip to pass in the implementing change; the required gate stays green; no entry is skipped, ignored, retried or silently red
  • Every doc-sentence entry quotes the pinned Electron v44.4.5 sentence it asserts with the sentence digest; every entry without a sentence (8–13) is labelled observed-only and carries expected status unknown
  • Every cell's oracle revision equals the corpus pin fixed by the X01-T3 pin rule (the v44.4.5 tag commit), the manifest passes the X01-T4 validator, and no cell cites Electron 44.3.0 or the KEL-75 snapshot commit
  • The three navigation-generation entries required by the F04-A4 resolution (entries 10, 11, 12) are present
  • No entry asserts a timing value or a performance number
  • No sendSync, returnValue, invoke/handle or exposeInIsolatedWorld entry is in this set (owned by F04-T15, F04-T14, F04-T5)

Negative controls (each names the one mutation that must fail)

  • Changing a cell's runner assertion from an expected status to skip makes the X01-T4 manifest validator fail
  • Setting an observed-only entry (for example entry 8) to expect pass without a doc citation makes the X01-T4 validator reject the manifest
  • Removing the implementing-ticket key from a red-until-implemented entry makes the X01-T4 validator reject the manifest
  • Deleting the mapped test of entry 5 (senderFrame) makes execution admission fail because the cell names an unregistered test target

External predecessors (outside this tracker)

Ownership and gates

The authoritative agent contract is the latest Agent Brief comment on this issue (triage skill); this body is the planning record.

Out of scope

Implementation; Zettlr-only entries (invoke/handle, sendSync, function-valued returns) which land as the first acceptance criterion of F04-T14, F04-T15 and F04-T16; recorded Electron transcripts and BEHAVIOR_MATCH comparison of observed-only entries 8–13 (F04-T20, after the X01-T1 two-arm harness).

Notes

Startable once X01-T3 and X01-T4 land and the KEL-80 reference link exists. Agents cite the #517 owner record as the documented exception to the Linear-only claim protocol in root AGENTS.md and the workflow until the .agents/instructions.md amendment lands (the owner record names that gap itself).

Change log (doctrine-audit repair, 2026-10-07)

  • Narrowed to the draw.io first-proof path; removed sendSync, returnValue, invoke/handle, handleOnce/removeHandler entries (critic yagni F04-T1; critic duplicates sync cluster; X06-D2 pull order)
  • Added the three navigation-generation entries required by the closed F04-A4 resolution
  • Stated the red-entry mechanism as KEL-74 expected-status cells flipped in the implementing PR (critic invariant_violations F01-T1..F06-T1)
  • Relabelled per-channel send order, stale-reply drop and listener-less drop as observed-only recorded-oracle cells because no v44.4.5 doc sentence states them (critic ambiguity F04-EPIC; my read of the pinned docs 2026-10-07)
  • Added IpcRendererEvent, webContents.send no-listener drop, reply drop-versus-throw boundary and nested-callback rows (critic coverage_gaps IpcRendererEvent; refuter semantics extra findings on renderer drop, A4 drop-versus-throw; X06-D3 semantics P3 rows)
  • Moved oracle pin ownership to X01-T1 and added edge F04-T1 ← X01-T1 (critic duplicates F04-T5/X01-T1; refuter pin-drift findings)
  • Replaced KEL-237 as owner with a missing-owner blocker because KEL-237 non-goals exclude compat-surface expansion (X06-D3 invariants item 2; X06-D6 semantics; KEL-237 description, Linear fetched 2026-10-07)
  • Changed ready_state from ready-for-agent to needs-owner (X06-D6)
  • Replaced the non-deterministic negative control with transcript mutations, one per key entry (rule 8)
  • Replaced blocker X01-T1 (next, needs-info) with X01-T3 (pin, citation and red-until-implemented rules) and X01-T4 (shared manifest validator); AC1–AC3 and key_interfaces now cite X01-T3/X01-T4 (cross-checker finding 'first-proof slices gated on next-milestone X01-T1')
  • Observed-only entries 8–13 now carry expected status unknown because X01-T3 permits an uncited cell only as unknown; their recorded-transcript comparison and the two transcript-mutation negative controls moved to new F04-T20 (next, blocked by X01-T1); negative controls replaced with X01-T4 validator mutations; each doc-sentence entry names its one implementing ticket (cross-checker finding 'first-proof slices gated on next-milestone X01-T1')
  • Entry 4 now names webContents.send delivery explicitly, because F04-T3 and F04-T10 flip a 'webContents.send delivery' cell the entry list did not define (consequence of the same substitution)
  • Owner: GitHub conformance(ipc): pinned v44.4.5 entries for the draw.io IPC path — send/on/once, ipcMain.on/once/removeListener, event.reply, senderFrame, webContents.send delivery, IpcRendererEvent, structured-clone throws, contextBridge value rows, navigation-gen #464 is the tracker of record under the Linear owner for repo-writing Electron-compat slices (owner decision: align to nearest Linear issue, else GitHub is the tracker of record) #517 owner decision comment (D adopted, verified on GitHub 2026-10-07), Linear reference on KEL-80; ready_state needs-owner → ready-for-agent; notes no longer cite X06-D6 (cross-checker finding X06-D7 tracker-of-record contradiction)

Activity

  1. added theissue type on Oct 6, 2026
  2. added
    electron-compatElectron compatibility program area
    compat:tier-1Electron compat Tier 1 (arch 04 §4)
    ready-for-agentFully specified; an AFK agent can take it
    on Oct 6, 2026
  3. added
    milestone:first-proofNeeded for the first migration proof (drawio-desktop on macOS, explicit legacy profile)
    on Oct 6, 2026
  4. 0monish commented on Oct 6, 2026

    @0monish
    MemberAuthor

    Generated by an AI agent (Claude Code, Fable 5.1) on behalf of @0monish, 2026-10-06, under the map's execution doctrine. Statements are labelled FACT / INFERENCE / UNKNOWN by their author; nothing here authorizes implementation.

    Doctrine audit findings for this issue

    YAGNI classification: first-proof — Conformance-first for send/on ordering, event.reply, senderFrame and the contextBridge value table used by the draw.io preload. Park the sendSync entry (0 draw.io sites) and invoke/handle (0 draw.io sites; Zettlr).

    Disposition: each finding stays open on this issue until its fix is applied to the body or refuted with evidence.

  5. changed the title [-]conformance(ipc): pinned entries for invoke/handle, send/on ordering, reply/senderFrame semantics, error envelope and sendSync contract[/-] [+]conformance(ipc): pinned v44.4.5 entries for the draw.io IPC path — send/on/once, ipcMain.on/once/removeListener, event.reply, senderFrame, webContents.send delivery, IpcRendererEvent, structured-clone throws, contextBridge value rows, navigation-gen[/+] on Oct 6, 2026
  6. 0monish commented on Oct 6, 2026

    @0monish
    MemberAuthor

    This was generated by AI during triage.

    Agent Brief

    Category: enhancement
    Summary: conformance(ipc): pinned v44.4.5 entries for the draw.io IPC path — send/on/once, ipcMain.on/once/removeListener, event.reply, senderFrame, webContents.send delivery, IpcRendererEvent, structured-clone throws, contextBridge value rows, navigation-generation cases

    Current behavior:
    No IPC conformance entries exist; the only Electron cells are the lifecycle corpus, pinned to Electron 44.3.0.

    Desired behavior:
    Land red-until-implemented KEL-74 cells for the draw.io first-proof IPC path. Doc-sentence entries (ipc-renderer.md, ipc-main.md, ipc-main-event.md, ipc-renderer-event.md, context-bridge.md at v44.4.5): (1) ipcRenderer.send args reach an ipcMain.on listener by structured clone; (2) send throws synchronously for Function, Promise, Symbol, WeakMap, WeakSet; (3) ipcMain.once fires once and ipcMain.removeListener stops delivery; (4) event.reply reaches the sending frame and webContents.send reaches an ipcRenderer.on listener of that WebContents; (5) senderFrame.url equals the loaded document URL and senderFrame is null after the frame navigated or was destroyed; (6) IpcRendererEvent.sender is the ipcRenderer instance and ports is an empty list when nothing was transferred; (7) contextBridge rows: functions proxied (argument position, including a callback nested in an object argument, called N times from the preload world), other values copied and frozen, Symbol dropped, Error copied with message. Observed-only entries (no v44.4.5 doc sentence states them, so under the X01-T3 uncited-cell rule they land with expected status unknown; the recorded-oracle comparison is F04-T20's, next milestone): (8) per-channel order of N sends; (9) webContents.send with no renderer listener is dropped, not queued for a later listener; (10) stale event.reply after cross-document navigation is dropped without throwing; (11) a hash change during a pending request does not drop the reply; (12) a cancelled renderer-initiated navigation keeps IPC usable; (13) reply with unserializable args throws, and reply after render-frame disposal throws (drop-versus-throw boundary recorded as ▲). Doc-sentence entries are red-until-implemented cells in the X01-T3 representation (expected fail, implementing-ticket key named: entries 1, 3, 4 and 5 F04-T3, entry 2 F04-T11, entries 6 and 7 F04-T4) validated by the X01-T4 manifest owner.

    Key interfaces:

    • KEL-74 cell schema; fixture triplet (main, preload, page) run under Keld;
    • X01-T3 pin, citation and red-until-implemented rules;
    • X01-T4 shared manifest validator and execution admission.

    Acceptance criteria:

    • Every doc-sentence entry is a red-until-implemented KEL-74 cell in the X01-T3 representation: expected status fail with its implementing-ticket key, a mapped test that asserts the current behaviour and passes, and a flip to pass in the implementing change; the required gate stays green; no entry is skipped, ignored, retried or silently red
    • Every doc-sentence entry quotes the pinned Electron v44.4.5 sentence it asserts with the sentence digest; every entry without a sentence (8–13) is labelled observed-only and carries expected status unknown
    • Every cell's oracle revision equals the corpus pin fixed by the X01-T3 pin rule (the v44.4.5 tag commit), the manifest passes the X01-T4 validator, and no cell cites Electron 44.3.0 or the KEL-75 snapshot commit
    • The three navigation-generation entries required by the F04-A4 resolution (entries 10, 11, 12) are present
    • No entry asserts a timing value or a performance number
    • No sendSync, returnValue, invoke/handle or exposeInIsolatedWorld entry is in this set (owned by F04-T15, F04-T14, F04-T5)
    • Negative control: Changing a cell's runner assertion from an expected status to skip makes the X01-T4 manifest validator fail
    • Negative control: Setting an observed-only entry (for example entry 8) to expect pass without a doc citation makes the X01-T4 validator reject the manifest
    • Negative control: Removing the implementing-ticket key from a red-until-implemented entry makes the X01-T4 validator reject the manifest
    • Negative control: Deleting the mapped test of entry 5 (senderFrame) makes execution admission fail because the cell names an unregistered test target

    Out of scope:

    • Implementation; Zettlr-only entries (invoke/handle, sendSync, function-valued returns) which land as the first acceptance criterion of F04-T14, F04-T15 and F04-T16; recorded Electron transcripts and BEHAVIOR_MATCH comparison of observed-only entries 8–13 (F04-T20, after the X01-T1 two-arm harness).

    Tracker of record and claim location: see "Ownership and gates" in the issue body.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    compat:tier-1Electron compat Tier 1 (arch 04 §4)electron-compatElectron compatibility program areaenhancementNew feature or requestmilestone:first-proofNeeded for the first migration proof (drawio-desktop on macOS, explicit legacy profile)ready-for-agentFully specified; an AFK agent can take it

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions