Keep authority on failed or malformed tab snapshots. Exercise headless terminal file links through line-addressed hosted previews, since renderer-backed file tabs require a Desktop renderer. Record the observed native tap and host resolution evidence.
Label standalone toolbar actions, match WebView accessibility values, and fence workspace return checks by pathname. Reuse Android labelled navigation and support adversarial journeys without native screenshot baselines. Record passing iOS file parity and the unresolved terminal file-link gate on both platforms.
Reuse host file methods behind Desktop-owned identity redaction and move list/text presentation into the hosted page. Preserve older shells and Desktop versions through legacy fallback, without changing the generic bridge contract.
Advertise page-safe file reads from Desktop and project their raw results in the hosted page. Preserve legacy handlers and fallback for older shells and oversized replies. Track the remaining long-lived shell implementation and platform evidence.
The hybrid WebView required a recent native-observed touch before a bridge
capability could run. A scroll armed the window, so it gated nothing an
attacker on the first-party page could not already reach, and no peer hybrid
framework (Capacitor, Cordova, RN WebView) gates bridge calls this way.
Removes the gesture module, its React authority hook, the shared requirement
and its census, and all 20 gate sites: native.alert, clipboard write, external
link open, terminal text-scale and custom-key updates, dictation start and
model management, account select and reset-credit consume, agent-history
resume, terminal clipboard paste and image attach, navigation reconnect,
removeHost and terminal-settings route, and both workspace-creation writes.
Each operation now just runs.
The AppState foreground reporting the gesture hook also carried moves to
use-mobile-web-app-foreground-authority. permission_required stays in the
bridge error enum: it parses inbound responses, so narrowing it would break a
new page paired with an older shell.
Drops the G3 gesture-window e2e probe and renames its runner to
run-hosted-ios-webview-app-bound-probe.mjs, which keeps the app-bound probe.
Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb
The audit record claimed a declarative registry prototype covered Tasks, Files,
and Session and proved metadata, grants, and typed calls can be generated. No
prototype existed: bridge-operation-registry.ts was an operation-name list with
a capability enum and a membership check, consumed only by bridge-contract.ts
and one test. Withdraw the claim, reopen the checklist item, and add a
2026-09-01 addendum recording the cleanup this branch landed, referenced by
merge subject.
Also correct three factual conflicts with the code:
- The rollback runbook told support to direct users to the retained native
workspace route while its own Safety Invariants said the hybrid candidate has
no such fallback. Scope that step to the native-default build, since
isRetiredNativeWorkspaceRoute redirects every /h/... workspace route to
/hybrid in a hybrid build.
- The architecture reference described the Android network fence as load
blocking only, omitted that a sub-threshold WebView process restart now
retires the capability broker, and did not say that the Android bridge
accepts a message on the origin host derived from activeSessionId with the
fragment as a secondary check. Name the build scripts that run each delivery
step while there.
- The remaining-work tracker did not record that the native store suites now
run in CI, or that hosted-mobile-webview-ssh.spec.ts is excluded from the
ubuntu e2e lane because no hosted runner has a simulator and Docker at once.
mobile/README.md needed no change: every entrypoint in its e2e and native store
tables resolves to a real script.
Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb