Conversation
dangzitou
force-pushed
the
fix/agent-window-home-tab-guard
branch
from
September 27, 2026 18:09
21a04d2 to
58a2fe2
Compare
`ensureActiveTab` trusts any tab whose id came from the `chrome.windows.create` result. A new-tab hijacker can move that tab onto its own `chrome-extension://` options page before initialization runs; the session then bootstraps on a page it can never drive — CDP attachment to a foreign extension page fails with "Cannot access a chrome-extension:// URL of different extension", poisoning the session target (Tencent#129). Validate the creation tab's URL (and in-flight `pendingUrl`) before adopting it: `chrome://`, `chrome-extension://`, `edge://`, `devtools://` and `view-source:` pages are undrivable, so a fresh `about:blank` home tab is created instead. The foreign tab is left untouched — it lives in the session-owned Agent Window and is inert to the session, which only addresses its home tab.
dangzitou
force-pushed
the
fix/agent-window-home-tab-guard
branch
from
September 27, 2026 18:12
58a2fe2 to
32df576
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What problem this solves
Fixes #129.
ensureActiveTabadopts any tab whose id came from thechrome.windows.createresult, on the assumption that the tab it askedfor (
about:blank) is still there. A new-tab hijacker can move thattab onto its own
chrome-extension://options page before windowinitialization runs. The session then bootstraps on a page it can never
drive: DevTools attachment to a foreign extension page fails with
"Cannot access a chrome-extension:// URL of different extension", and
every CDP-backed call on the session target fails afterwards. The
reporter reproduced this with Edge + a hijacking extension; the same
class of failure can hit any browser whenever the creation tab's
content is replaced before the first CDP command.
How this fixes it
Validate the creation tab's URL — and its in-flight
pendingUrl—before adopting it as the session home.
chrome://,chrome-extension://,edge://,brave://,opera://,vivaldi://,devtools://andview-source:pages are undrivable, so a freshabout:blankhome tab is created in the Agent Window instead andactivated. The foreign tab is left untouched: it sits inside the
session-owned window, is inert to the session (which only addresses
its home tab), and disappears with the window on session stop — so the
fix never closes or moves a page the user or another extension owns.
chrome://pages are included even though the interface doc alreadynoted they reject
Page.navigate: the creation tab could be sitting onchrome://newtab/when a browser's new-tab override fires.User impact
Sessions always bootstrap on a drivable home tab, so the first
navigate/snapshot/observeaftersession startcannot fail witha cross-extension access error. No behavior change when the creation
tab is healthy, and adoption still happens when the tab's URL is
unknown (no
tabspermission).Validation
pnpm exec biome checkclean on the changed file.pnpm ext:test— 2348 passed, 122 skipped, 0 failed(no new tests included in this PR).
extension):
session start→navigate https://example.com→observeall succeed with the fix loaded. I could not reproduce thepoisoning itself end-to-end on macOS — the reporter's trigger is
Edge-specific — so the wrong-tab condition is covered by the existing
session-manager suite plus the e2e sanity run rather than a
browser-level repro.