← Commit history

withdraw the CfT-version causal claim: the 148-vs-152 comparison was uncontrolled (raw Chrome launches vs pup); analog.com renders in pup on 152 on both warm and fresh profiles

John Lauer ·6b556627a3 ·22d ago ·parent 060c455
1 file changed +15−12
gen.py+15−12
@@ -141,7 +141,7 @@ SITES = [   dict(slug="analog", name="Analog Devices (incl. Maxim, Linear)", domains=["www.analog.com"],   what="Manufacturer. Product pages, datasheets, LTspice models, eval boards.",-  defense="Akamai Bot Manager, strict. The single hardest case in this pack and the one that drove the 2026-09-14 investigation (see the root skill). TWO stacked causes, both measured: (1) browser VERSION - on CfT 148 the edge answered HTTP 403 (AkamaiGHost) with a static Access Denied page; on CfT 152, matched to the installed Chrome, the same URL serves the real page. The 403 is decided at the HTTP layer before any page JavaScript runs, so this is a CONNECTION-fingerprint refusal, not a sensor failure (CfT 148 runs JS fine; typeof bmak undefined on a deny page is a symptom, the deny page has no sensor script); (2) egress IP - even on 152, loads from a VPN/Azure egress and denies from the bare office LAN NAT.",+  defense="Akamai Bot Manager, strict. The single hardest case in this pack and the one that drove the 2026-09-14 investigation (see the root skill). TWO stacked causes, both measured: (1) WITHDRAWN - an earlier revision blamed the CfT build (148 denied, 152 loaded). That was not a controlled comparison: the denied trials were raw hand-rolled Chrome launches without pup's flag set, the passing ones were pup. Re-measured 2026-09-14 with screenshots, analog.com renders in pup on CfT 152 on both a warm and a brand-new isolated profile, so neither the build nor the cookie jar is the established discriminator; what works is driving it through pup's own launch path, and which part of that matters has not been isolated; (2) egress IP - even on 152, loads from a VPN/Azure egress and denies from the bare office LAN NAT.",   lanes={    "WebFetch": ("BLOCKED", "Akamai edge"),    "curl": ("BLOCKED", "curl (92) HTTP/2 INTERNAL_ERROR in ~100 ms"),@@ -383,7 +383,7 @@ PACED = {  "mouser":        "HOME PAGE loads paced on CfT 152 (was 'Access to this page has been denied' on 148). DataDome still scores CRAWLS: use the API for data, do not walk the catalog",  "digikey":       "loads paced on CfT 152",  "arrow":         "loads paced on CfT 152. Earlier BLOCKED readings came from the 20-tab burst, not from arrow",- "analog":        "loads paced on CfT 152 (bmak:object, i.e. the real page with the sensor on it was served). On CfT 148 the edge answered HTTP 403 before any JS ran: the version match is the fix, and the refusal was on the connection fingerprint, not a sensor failure",+ "analog":        "loads in pup on CfT 152, verified by screenshot 2026-09-14 on BOTH the warm shared profile and a brand-new isolated jar. The earlier claim that the CfT 148 to 152 bump was the fix is WITHDRAWN: those 148 trials were raw hand-rolled Chrome launches without pup flags, not a controlled comparison",  "ti":            "loads paced on CfT 152",  "microchip":     "loads paced on CfT 152",  "nordic":        "loads paced on CfT 152",@@ -488,14 +488,17 @@ Browser Extension 0.16.14 (Chrome 152).  Two independent discoveries this date, each measured, that reframe the hardest Akamai sites: -**1. The Chrome-for-Testing VERSION is itself a bot signal.** pup pinned CfT 148 while the user's-real Chrome was 152. On 148, analog.com answered **HTTP 403 (AkamaiGHost)** with a static Access Denied-page; on CfT **152** (matched to the installed Chrome) the same URL serves the real page. Be precise-about where that is decided: a 403 arrives at the HTTP layer, so the edge refused the REQUEST and no-page JavaScript ever ran. CfT 148 executes JavaScript fine; that was never the issue. The discriminator-is the CONNECTION fingerprint (the TLS ClientHello measurably differs between CfT builds). Which exact-element flips the verdict has NOT been isolated. `typeof bmak === "undefined"` on a denied page is a-SYMPTOM, because the Access Denied page carries no sensor script at all. Keep CfT within ~1 milestone of the installed Chrome. Several sites+**1. WITHDRAWN: "the Chrome-for-Testing VERSION is a bot signal".** An earlier revision of this pack+claimed that pinning CfT 148 against a Chrome 152 desktop is what made analog.com answer HTTP 403, and+that bumping to CfT 152 fixed it. **That comparison was not controlled and the claim is withdrawn.**+Every denied trial was a raw hand-rolled Chrome launch carrying a copied flag list; every passing trial+was pup itself. Those differ in infobar suppression, the feature-disable set and the identity shim, not+only in the build number. Re-measured 2026-09-14 with screenshots: analog.com renders fully in pup on+CfT 152 on the warm shared profile AND on a brand-new isolated jar, so neither profile state nor cookie+history is the discriminator either. What IS established: these sites load when driven through pup's+own launch path, and WHICH element of that path is decisive has not been isolated. Keep the CfT pin+near the installed Chrome as cheap hygiene, not as an explanation. `typeof bmak === "undefined"` on a+denied page is a SYMPTOM, because the Access Denied page carries no sensor script at all. Keep CfT within ~1 milestone of the installed Chrome. Several sites that were pup-BLOCKED on 148 (st.com among them) load on 152. Diagnostic on a denial: `typeof bmak` `undefined` = rejected upstream (version or IP); `object` = the sensor ran and failed you (IP/behaviour). @@ -700,7 +703,7 @@ def main():                {"label": "Which browser for DigiKey", "prompt": "which browser lane do I need to read a DigiKey product page"},                {"label": "Mouser 200 but denied", "prompt": "why does Mouser return HTTP 200 with access denied and what do I do"},                {"label": "Add a site", "prompt": "add an electronics-sites skill for nxp.com and verify its lanes"}]-    pkg = {"name": PACK, "slug": PACK, "version": "2.2.0", "type": "skill", "title": TITLE, "description": BRIEF,+    pkg = {"name": PACK, "slug": PACK, "version": "2.3.0", "type": "skill", "title": TITLE, "description": BRIEF,            "license": "MIT", "files": files, "scripts": {"install": "./install.sh", "uninstall": "./uninstall.sh"},            "dependencies": {}, "tags": TAGS, "keywords": TAGS, "discovery_triggers": TRIGGERS, "discovery_pitch": PITCH,            "sample_prompts": PROMPTS, "hero": {"path": "docs/hero.png"}}@@ -748,7 +751,7 @@ No captcha solving, no fingerprint spoofing: this pack routes around walls, it d """     write("README.md", readme)     page = json.load(open(os.path.join(ROOT, "page.json")))-    page.update({"slug": PACK, "version": "2.2.0", "title": TITLE, "brief": BRIEF, "readme": readme, "license": "MIT",+    page.update({"slug": PACK, "version": "2.3.0", "title": TITLE, "brief": BRIEF, "readme": readme, "license": "MIT",                  "tags": TAGS,                  "hero": {"type": "image", "path": "docs/hero.png"},                  "sample_prompts": PROMPTS, "discovery_triggers": TRIGGERS, "discovery_pitch": PITCH,