Guard stale app execution against feature contract changes

This commit is contained in:
Jonathan Sykes
2026-10-08 09:18:51 +08:00
parent 3505dc3c0e
commit c4a512bea6
7 changed files with 143 additions and 8 deletions

View File

@@ -76,3 +76,12 @@ all samples. Full-harness configurations now reset to the base tree before each
browser/profile, preventing a preceding synthetic update from contaminating the
next cold build. The historical invalid media fixture remains unchanged: home
launch only, not autoplay/audio latency.
Self-review added explicit N-1 app boot after eviction: verify the retained body
and use its exact classic URL through the controlling worker. It never fills the
new key with old bytes. Stale core execution additionally requires every group
contract to match the running shell's expectations; a core or feature contract
change rejects it. Both-engine lazy smoke now changes app bytes, evicts the new
entry, boots N-1 offline, then repairs the current entry before the existing
feature pinning/contract/playback checks. No source in app.js changed.