Repository navigation
Add browser location bridge and lease convergence - #399
Open
tnsardesai wants to merge 11 commits into
Open
tnsardesai wants to merge 11 commits into
tnsardesai wants to merge 11 commits into
Conversation
tnsardesai
force-pushed
the
hypeship/browser-location-bridge
branch
from
September 18, 2026 01:49
0608b50 to
e1d16f9
Compare
tnsardesai
force-pushed
the
hypeship/browser-location-bridge
branch
from
October 9, 2026 07:29
a7d8253 to
9755de8
Compare
…owser location Send Chromium a monotonic browser generation per accepted bundle and mark a bundle applied only after Chromium reports renderer, worker, host-timezone and network-context acknowledgements for that generation. A Chromium restart clears applied state until the new process acknowledges. Explicit locales and timezones are validated against a capability manifest generated from the Chromium 154 browser in the image instead of ICU component-locale readback.
TestBrowserTimezoneFollowsLocaltime starts Chromium with the production TZ and KERNEL_BROWSER_TIMEZONE environment, checks Chromium runs without TZ, and replaces /etc/localtime A to B at runtime without a restart. TestBrowserLocationCapabilities regenerates or checks the capability manifest. TestBrowserLocationRuntimeUpdate drives reset, configure, retries, stale generations, Chromium restart and a new lease on a kernel-browser image.
…ed live The launcher initializes /etc/localtime from the accepted bundle the image API persisted, so a restarted Chromium starts in the session's timezone instead of the VM's startup zone. GET /browser/location reports a bundle applied only after the running Chromium confirms that generation with every component acknowledged, so a restarted or unreachable browser is never reported as applied while the upstream change is still being detected. The runtime e2e posts to /configure, the image's configure route.
tnsardesai
marked this pull request as ready for review
October 9, 2026 22:54
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit b743ced. Configure here.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

summary
GET /browser/locationconfirmsappliedlive against the running Chromium, so a restarted or unreachable browser is never reported applied/etc/localtimefrom the persisted accepted bundle, elseKERNEL_BROWSER_TIMEZONE, elseTZ, and execs Chromium withoutTZso Chromium's Linux watcher follows runtime changes; a restarted Chromium starts in the session's current timezonelib/browserlocation/capabilities.json(Chromium/154.0.8037.97+tzdata-2026c+a1a4f3e6807fb867, 412 locales, 598 timezones), generated byTestBrowserLocationCapabilities: a locale is listed whenIntl.DateTimeFormatandIntl.NumberFormatresolve exactly that tag andIntl.Collatorresolves it or a parent; a timezone when the image ships it andIntlaccepts it. The status reportscapabilities_version500with configure stepbrowser_location, which is part of theChromiumConfigureError.stepenum;lib/oapi/oapi.gois regenerated withmake oapi-generate, which also adds the multipartbrowser_locationfielddependency
Provisioning needs no API change: when
KERNEL_BROWSER_TIMEZONEis absent the launcher usesTZ(the variable production already sets), so kernel #4204 was closed as superseded.Runtime application requires the kernel-browser #92 artifact at
368c6172de4d4b4c5e9aae74e32fc8f61f456f81.Based on
kernel/kernel-images@e970762ff809eff9da680b1c3792e85ab60bef15(currentmain).tests
go test ./cmd/... ./lib/oapi/..., including a test that every configure step is a validChromiumConfigureError.stepand that a persistence failure returns a validbrowser_locationstepmake build;go test,go test -race,go veton./cmd/api/api ./cmd/chromium-launcher ./lib/browserlocation ./lib/cdpclient ./lib/devtoolsproxy ./lib/metricsTestBrowserLocationCapabilities(check mode): manifest matches the artifact exactlyTestBrowserLocationRuntimeUpdate(3/3): Chromium runs withoutTZ; lease reset LA→Singapore, configure →Berlin, same-value retry, stale generation 409, no restart (PID and start time unchanged), Chromium restart returns to the accepted bundle, new lease epoch →New York. At eachapplied, the page, its already-running worker anddate(withoutTZ) report the new timezone and locale without pollingTestBrowserTimezoneFollowsLocaltime(productionTZ+KERNEL_BROWSER_TIMEZONEenvironment, raw/etc/localtimereplacement): the first replacement after start needs rewrites (~1.8 s); later changes converge in 3–58 mslimitations
TestBrowserLocationRuntimeUpdateneedsE2E_KERNEL_BROWSER=1and a kernel-browser image, so stock CI images skip itUPDATE_BROWSER_LOCATION_CAPABILITIES=1) whenever the browser or image tzdata changes, and copied to kernelpackages/api/lib/browserlocation/capabilities.jsonNote
Medium Risk
New lease-ordered control-plane state, host
/etc/localtimemutation, and dependency on kernel-browser CDP; mitigated by validation, auth on reset, and blocking internal CDP on the public proxy.Overview
Adds runtime control of browser timezone, locale, and languages without restarting Chromium. Callers send generation-ordered bundles tied to a lease epoch; the API persists state, rewrites
/etc/localtime, and reconciles via custom CDP (Browser.setKernelBrowserLocation/getKernelBrowserLocation) until Chromium reports timezone, browser, renderer, and network-context convergence.New surfaces:
browser_locationon Chromium configure (async accept, 409 on stale/conflict/wrong epoch),GET /browser/location(live-checksappliedagainst running Chromium), andPOST /internal/browser-location/reset(instance JWT or trusted control-plane header). Lease resets bump a monotonic browser generation separate from per-epoch bundle generations.Supporting pieces: embedded
lib/browserlocationcapability manifest for validation, Prometheus metrics, DevTools proxy blocking of internal location CDP from customer WebSockets, and launcher startup that applies persisted timezone and dropsTZfrom Chromium’s environment so/etc/localtimeupdates propagate.Reviewed by Cursor Bugbot for commit 76e7bfb. Bugbot is set up for automated code reviews on this repo. Configure here.