User Tools

Site Tools


provenance:privacy:privacy_sandbox

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
provenance:privacy:privacy_sandbox [2026/09/01 16:59] – Refresh the query table, folding residue and embedded report output after the fold fixes; add the three-pass review log with every finding and its disposition. Authored by Claude. karel.kubicek.claudeprovenance:privacy:privacy_sandbox [2026/09/01 17:36] (current) – Remove a literal citation marker the bibtex plugin picked up through its nowiki escape, and stop asserting self-referential heading and table counts for this page. Authored by Claude. karel.kubicek.claude
Line 235: Line 235:
  
 == CDP events received (7) == == CDP events received (7) ==
-  Storage.interestGroupAuctionEventOccurred            {"eventTime":1788280668.965319,"type":"started","uniqueAuctionId":"49E0BB9B63C9BD64E47335ECBF4728D0","auctionConfig":{"auctionSignals":{"pending":false,"value":null},"decisionLogicURL":"https://probe.example:8444/decide. +  Storage.interestGroupAuctionEventOccurred            {"eventTime":1788282880.844885,"type":"started","uniqueAuctionId":"BAA2639A8868AB941264DB3DB6CB5BED","auctionConfig":{"auctionSignals":{"pending":false,"value":null},"decisionLogicURL":"https://probe.example:8444/decide. 
-  Storage.interestGroupAuctionNetworkRequestCreated    {"type":"bidderJs","requestId":"96FF20B838C9A062BFC9B2D1EB2074F6","auctions":["49E0BB9B63C9BD64E47335ECBF4728D0"]} +  Storage.interestGroupAuctionNetworkRequestCreated    {"type":"bidderJs","requestId":"06A218F8B3F436C7E8D3F44A2D2806C3","auctions":["BAA2639A8868AB941264DB3DB6CB5BED"]} 
-  Storage.interestGroupAuctionNetworkRequestCreated    {"type":"sellerJs","requestId":"E700229B68625D5ED4A44112015F90EE","auctions":["49E0BB9B63C9BD64E47335ECBF4728D0"]} +  Storage.interestGroupAuctionNetworkRequestCreated    {"type":"sellerJs","requestId":"C09A1952CA56CC58940B85D959CCD3A3","auctions":["BAA2639A8868AB941264DB3DB6CB5BED"]} 
-  Storage.sharedStorageAccessed                        {"accessTime":1788280669.021785,"scope":"window","method":"set","mainFrameId":"9EE9B30C8B76A15625E274C35BD01EC1","ownerOrigin":"https://probe.example:8444","ownerSite":"https://probe.example","params":{"key":"k","value": +  Storage.sharedStorageAccessed                        {"accessTime":1788282880.902479,"scope":"window","method":"set","mainFrameId":"B3037C0FA13BA8CE8A07D1020A778F25","ownerOrigin":"https://probe.example:8444","ownerSite":"https://probe.example","params":{"key":"k","value": 
-  Storage.sharedStorageAccessed                        {"accessTime":1788280669.02439,"scope":"window","method":"addModule","mainFrameId":"9EE9B30C8B76A15625E274C35BD01EC1","ownerOrigin":"https://probe.example:8444","ownerSite":"https://probe.example","params":{"scriptSource +  Storage.sharedStorageAccessed                        {"accessTime":1788282880.904117,"scope":"window","method":"addModule","mainFrameId":"B3037C0FA13BA8CE8A07D1020A778F25","ownerOrigin":"https://probe.example:8444","ownerSite":"https://probe.example","params":{"scriptSourc 
-  Storage.sharedStorageAccessed                        {"accessTime":1788280669.033277,"scope":"window","method":"run","mainFrameId":"9EE9B30C8B76A15625E274C35BD01EC1","ownerOrigin":"https://probe.example:8444","ownerSite":"https://probe.example","params":{"operationName":"+  Storage.sharedStorageAccessed                        {"accessTime":1788282880.912412,"scope":"window","method":"run","mainFrameId":"B3037C0FA13BA8CE8A07D1020A778F25","ownerOrigin":"https://probe.example:8444","ownerSite":"https://probe.example","params":{"operationName":"
-  Storage.sharedStorageWorkletOperationExecutionFinished {"finishedTime":1788280669.033894,"executionTime":847,"method":"run","operationId":"0","workletTargetId":"383073F2489DBB30E78E8E91A9CF2429","mainFrameId":"9EE9B30C8B76A15625E274C35BD01EC1","ownerOrigin":"https://probe.ex+  Storage.sharedStorageWorkletOperationExecutionFinished {"finishedTime":1788282880.913208,"executionTime":1050,"method":"run","operationId":"0","workletTargetId":"EBB22A0151158B1D33AB96EBCA57DF2F","mainFrameId":"B3037C0FA13BA8CE8A07D1020A778F25","ownerOrigin":"https://probe.e
 </file> </file>
  
Line 266: Line 266:
 | ''privacysandbox.google.com/blog/update-on-plans-for-privacy-sandbox-technologies'' | The 2025-10-17 retirement of ten technologies | Fetched; the list and the CHIPS/FedCM/PST carve-out quoted **verbatim**; page footer reads "Last updated 2025-10-17 UTC" | **Used**, quoted | | ''privacysandbox.google.com/blog/update-on-plans-for-privacy-sandbox-technologies'' | The 2025-10-17 retirement of ten technologies | Fetched; the list and the CHIPS/FedCM/PST carve-out quoted **verbatim**; page footer reads "Last updated 2025-10-17 UTC" | **Used**, quoted |
 | ''privacysandbox.google.com/overview/status'' | Per-feature status: Continue to support / Deprecate and remove / Discontinue / Do not launch; CHIPS default in Chrome 114; Storage Access default in Chrome 119 | Fetched; page states "Last updated: August 14, 2026" | **Used** | | ''privacysandbox.google.com/overview/status'' | Per-feature status: Continue to support / Deprecate and remove / Discontinue / Do not launch; CHIPS default in Chrome 114; Storage Access default in Chrome 119 | Fetched; page states "Last updated: August 14, 2026" | **Used** |
-| ''privacysandbox.google.com/private-advertising/enrollment'' | "We will no longer accept new account creation and enrollment" | Fetched, quoted verbatim | Used in provenance; the page states the consequence rather than the quote |+| ''privacysandbox.google.com/private-advertising/enrollment'' | "We will no longer accept new account creation and enrollment" | Fetched, quoted verbatim | **Used, quoted on the content page.** A first draft only implied the consequence; a review pass pointed out the sentence was never actually written, so the quote and the ''%%--privacy-sandbox-enrollment-overrides%%'' workaround are now both on the page |
 | ''chromestatus.com/api/v0/features/<id>'' × 19 | Ship milestones (M114/M115/M116/M108) and removal milestones (M152/M153/M155), all with status ''Proposed'' | Fetched individually through the JSON API | **Used** | | ''chromestatus.com/api/v0/features/<id>'' × 19 | Ship milestones (M114/M115/M116/M108) and removal milestones (M152/M153/M155), all with status ''Proposed'' | Fetched individually through the JSON API | **Used** |
 | ''chromiumdash.appspot.com/fetch_releases'' and ''fetch_milestone_schedule'' | Chrome stable = M152 since 2026-08-25; M153 stable_date 2026-09-08; M114 2023-05-30; M115 2023-07-18; M116 2023-08-15 | Fetched, parsed | **Used** | | ''chromiumdash.appspot.com/fetch_releases'' and ''fetch_milestone_schedule'' | Chrome stable = M152 since 2026-08-25; M153 stable_date 2026-09-08; M114 2023-05-30; M115 2023-07-18; M116 2023-08-15 | Fetched, parsed | **Used** |
 | ''gov.uk/cma-cases/investigation-into-googles-privacy-sandbox-browser-changes'' | Case opened 2021-01-07, **closed 2025-10-17** | Fetched; "Case state: Closed" read off the page | **Used** | | ''gov.uk/cma-cases/investigation-into-googles-privacy-sandbox-browser-changes'' | Case opened 2021-01-07, **closed 2025-10-17** | Fetched; "Case state: Closed" read off the page | **Used** |
 | ''github.com/GoogleChrome/related-website-sets'' → ''related_website_sets.JSON'' | **70 sets, 320 member domains, 66 (94.3%) with an associated site** | Fetched and counted in this run | **Used** | | ''github.com/GoogleChrome/related-website-sets'' → ''related_website_sets.JSON'' | **70 sets, 320 member domains, 66 (94.3%) with an associated site** | Fetched and counted in this run | **Used** |
 +| GitHub API on ''privacysandbox/attestation'' and ''patcg-individual-drafts/topics'' | Both ''archived: true''; last pushes **2026-01-22** and **2025-11-07** | Fetched 2026-09-01 after a review pass flagged that the page treated these as live feeds | **Used.** The archival of the topics repo is also the reason there is no taxonomy v3 |
 +| ''ChromeDevTools/devtools-protocol'' commit history, bisected | The CDP ''Storage'' domain carried ''setAttributionReportingTracking'', ''setAttributionReportingLocalTestingMode'', ''sendPendingAttributionReports'' and four ''attributionReporting*'' events. Present in the descriptor at **2026-04-01**, absent at **2026-04-08** | Fetched five dated snapshots (2026-01-01, 02-01, 03-01, 03-15, 04-01) and four in April, resolving each date to a commit SHA through the GitHub commits API and pulling ''json/browser_protocol.json'' at that SHA | **Used.** This changed the page's advice: Attribution Reporting is measurable with first-class CDP events on a pre-April-2026 build, which the first draft denied |
 +| ''chromiumdash.appspot.com/fetch_milestone_schedule'' for M146–M151 | Branch points: M147 2026-03-09, M148 **2026-04-06** | Fetched | **Used as an inference, labelled as one.** M147 should carry the ARA surface; M148 branched inside the removal window and is a coin flip. **Not tested** — this run had only Chromium 151 |
 +| blink-dev, "Intent to Deprecate and Remove: Topics API" (thread ''_R85yctz4Rs'') | "Deprecate in M144 and then remove in M150"; "The Topics API was deprecated in Chrome-144 with a plan to remove it in Chrome-150. Currently the usage is 4.9% of page loads"; the phased M150 field-trial / M152 stub plan, quoted verbatim on the page | Fetched 2026-09-01. Thread opened 2025-11-07; the phased-plan message is dated 2026-06-12; later messages 2026-06-25 and 2026-07-08 | **Used.** A first draft asserted "the removal dates have already slipped twice" on a sub-agent's word; the primary source shows something more precise — deprecation landed at M144 **on schedule**, and it is the removal that moved M150 → M152 → M153. The page was rewritten to say that. It also turned the speculative field-trial hedge into a sourced fact |
 +| Chrome Platform Status ''motivation'' fields for Topics, Shared Storage, Protected Audience, RWS, Attribution Reporting | Chrome's own usage telemetry: Topics 13% then 4.9% of page loads; Shared Storage ~11% of page loads; Protected Audience ''joinAdInterestGroup()'' down ~100x and ''runAdAuction()'' down >10x with "virtually none" of auctions having winners; RWS 71 sets and ''requestStorageAccessFor'' ~0.95% of page loads; ARA no figure | Fetched 2026-09-01 through the JSON API | **Used, with the caveat foregrounded.** These are unaudited vendor telemetry with no stated methodology and a //page load// unit. They are on the page because they are the only post-April-2025 adoption numbers in existence, and the page says exactly that. The 71-vs-70 RWS discrepancy is published rather than reconciled |
 +| MDN header reference pages for ''Attribution-Reporting-Eligible'', ''Attribution-Reporting-Register-Source'', ''Attribution-Reporting-Register-Trigger'', ''Sec-Browsing-Topics'', ''Observe-Browsing-Topics'' | All five exist; ''Sec-Browsing-Topics'' "fails silently" and is deleted for an unenrolled caller | All five fetched, HTTP 200; the silent-failure sentence quoted verbatim from the ''Sec-Browsing-Topics'' page | **Used.** ''Sec-Shared-Storage-Writable'' was checked and returns 404 on MDN, so it is not on the page |
 | GitHub API on ''GoogleChrome/related-website-sets'' and ''GoogleChrome/ip-protection'' | Both ''archived: true''; last pushes 2025-11-21 and 2025-11-03 | Fetched | **Used** | | GitHub API on ''GoogleChrome/related-website-sets'' and ''GoogleChrome/ip-protection'' | Both ''archived: true''; last pushes 2025-11-21 and 2025-11-03 | Fetched | **Used** |
 | ''github.com/privacysandbox/attestation'' → ''enrollment_report.csv'' | **326 rows**; Topics 249, Protected Audience 237, Attribution Reporting 228, Shared Storage 205, Private Aggregation 193; 25 rows with no Chrome API | Fetched and counted in this run | **Used** | | ''github.com/privacysandbox/attestation'' → ''enrollment_report.csv'' | **326 rows**; Topics 249, Protected Audience 237, Attribution Reporting 228, Shared Storage 205, Private Aggregation 193; 25 rows with no Chrome API | Fetched and counted in this run | **Used** |
Line 296: Line 302:
 ===== What the corpus does not establish ===== ===== What the corpus does not establish =====
  
-  * **Nothing about Attribution Reporting in deployment.** of 5,869 papers name it, none instrument it. +  * **Nothing about Attribution Reporting in deployment.** of 5,869 papers name it, none instrument it. 
-  * **No adoption measurement after February 2025.** The two crawl-based papers are from 2023 and February 2025; the retirement was announced in October 2025. Chrome's own removal notes claim usage collapsed; this corpus cannot confirm or refute that.+  * **No //independent// adoption measurement after February 2025.** The two crawl-based papers are from 2023 and February 2025; the retirement was announced in October 2025. Chrome's own removal notes claim usage collapsed and give numbers, now quoted on the page; this corpus cannot confirm or refute them, and the party that produced them is the party being measured.
   * **No CHIPS adoption study inside the seven venues.** ''rasaii2025_crumbs'' gives a 1.3% figure as a side measurement; the dedicated study is a PAM 2025 paper outside the corpus.   * **No CHIPS adoption study inside the seven venues.** ''rasaii2025_crumbs'' gives a 1.3% figure as a side measurement; the dedicated study is a PAM 2025 paper outside the corpus.
   * **Regional gating of the ads APIs.** Both Google availability pages 404. A DMA-driven gate is plausible but plausible is not measured. A first draft asserted that FLoC's 2021 origin trial excluded the EEA; that came from a sub-agent citing Wikipedia, no primary source for it could be found in this run, and it was removed from the page. What ''berke2022_privacy'' does say, and what the page now carries instead: the trial ran Chrome 89 to 91, spring to autumn 2021, for users with at least seven domains in their history, with //k// = 2000 giving 33,872 cohorts of which 2.3% were deemed sensitive. Published on the page as an explicit unknown with an instruction to test it rather than assume.   * **Regional gating of the ads APIs.** Both Google availability pages 404. A DMA-driven gate is plausible but plausible is not measured. A first draft asserted that FLoC's 2021 origin trial excluded the EEA; that came from a sub-agent citing Wikipedia, no primary source for it could be found in this run, and it was removed from the page. What ''berke2022_privacy'' does say, and what the page now carries instead: the trial ran Chrome 89 to 91, spring to autumn 2021, for users with at least seven domains in their history, with //k// = 2000 giving 33,872 cohorts of which 2.3% were deemed sensitive. Published on the page as an explicit unknown with an instruction to test it rather than assume.
Line 309: Line 315:
   * **The retirement is the page's lead, not a footnote.** A reader who takes only one sentence away should take "these are being removed and your browser version is the measurement". The alternative — leading with the API descriptions — would have reproduced the 2022 roadmap, which is the failure mode the task spec warns about.   * **The retirement is the page's lead, not a footnote.** A reader who takes only one sentence away should take "these are being removed and your browser version is the measurement". The alternative — leading with the API descriptions — would have reproduced the 2022 roadmap, which is the failure mode the task spec warns about.
   * **Removal milestones are reported as //proposed//, not as fact.** They are the ''desktop'' milestone on a Chrome Platform Status entry whose status string is ''Proposed''. Two of them (M144, M150) had already slipped once before landing on M152/M153. The page dates them and does not promise them.   * **Removal milestones are reported as //proposed//, not as fact.** They are the ''desktop'' milestone on a Chrome Platform Status entry whose status string is ''Proposed''. Two of them (M144, M150) had already slipped once before landing on M152/M153. The page dates them and does not promise them.
-  * **Published the "8.1% of recent web crawls" silence figure** even though it is a keyword proxy, because the direction is unambiguous at that magnitude and the confound (a paper can measure the platform without naming an API) can only inflate the //true// figure slightly, not reverse it. The page names the proxy.+  * **Published the "7.7% of recent web crawls" silence figure** even though it is a keyword proxy, because the direction is unambiguous at that magnitude and the confound (a paper can measure the platform without naming an API) can only inflate the //true// figure slightly, not reverse it. The page names the proxy, and now also names the opposite confound a review pass raised: the denominator includes crawls with no reason to touch an ads API, so the figure is an upper bound on non-engagement rather than a defect rate.
   * **Did not publish the "Privacy Budget" or "k-anonymity" counts** at all: both regexes are dominated by generic differential-privacy usage and no qualified version was found that was worth the space.   * **Did not publish the "Privacy Budget" or "k-anonymity" counts** at all: both regexes are dominated by generic differential-privacy usage and no qualified version was found that was worth the space.
   * **Did not publish a figure from the PAM 2025 CHIPS paper.** It is outside the corpus, Springer would not serve its abstract to this run, and nobody here read it.   * **Did not publish a figure from the PAM 2025 CHIPS paper.** It is outside the corpus, Springer would not serve its abstract to this run, and nobody here read it.
Line 322: Line 328:
 Generated with ''scripts/bibgen.mjs''. Two needed hand-completion because PETS and USENIX index records carry no authors: the PoPETs authors came from ''petsymposium.org/popets/2023/popets-2023-0101.php'' and the USENIX authors from the venue landing page, both fetched with a browser User-Agent. Reused without change: ''jha2023_topics'', ''beugin2024_interest'', ''ali2023_navigating'', ''lin2024_browsing'', ''rasaii2025_crumbs'', ''bahrami2025_cookieguard'', ''kancherla2025_least''. Generated with ''scripts/bibgen.mjs''. Two needed hand-completion because PETS and USENIX index records carry no authors: the PoPETs authors came from ''petsymposium.org/popets/2023/popets-2023-0101.php'' and the USENIX authors from the venue landing page, both fetched with a browser User-Agent. Reused without change: ''jha2023_topics'', ''beugin2024_interest'', ''ali2023_navigating'', ''lin2024_browsing'', ''rasaii2025_crumbs'', ''bahrami2025_cookieguard'', ''kancherla2025_least''.
  
-After saving, ''literature:bibliography'' and the page were purged (''?purge=true'') and the rendered DOM checked: **58 ''bibtex_citekey'' markers, 13 rendered references for 13 distinct keyszero unresolved citation markers, 10 tables, 22 headings, 4 WRAP boxes.**+After each save, ''literature:bibliography'' and the page were purged (''?purge=true'') and the rendered DOM re-checked, counting only inside the ''%%<!-- wikipage start -->%%'' … ''%%<!-- wikipage stop -->%%'' markers so that the theme's own chrome is not counted. 
 + 
 +Counts below are for [[privacy:privacy_sandbox]] only. This page's own heading and table counts are deliberately not asserted, because every edit to this paragraph changes them and a self-referential count can never be right for long; what //is// asserted about this page is that it renders **7** downloadable file blocks and **zero** red links. 
 + 
 +^ Count ^ [[privacy:privacy_sandbox]] ^ 
 +| citation markers in the wiki source | **33** | 
 +| distinct citekeys among them | **13** | 
 +''bibtex_citekey'' spans in the rendered DOM | **66** | 
 +| ''%%<dt>%%'' entries in the rendered ''bibtex_references'' list | **13** | 
 +| ''%%<table>%%'' in the rendered body | **12** | 
 +| ''%%<h1>%%''–''%%<h4>%%'' in the rendered body | **23** | 
 +| ''%%<WRAP>%%'' boxes | **5** | 
 +| ''wikilink2'' (red links) | **0** | 
 +| downloadable ''%%<file>%%'' blocks | **1** | 
 + 
 +**Read the first three rows togetherbecause two reviewers independently got them wrong and then disagreed with each other.** The bibtex plugin emits **two** ''bibtex_citekey'' spans per source marker — an anchor and a link — so 33 markers render as 66 spansand neither number is the reference count: 33 markers over 13 distinct keys give 13 entries in the reference list. The rendered heading count is one higher than the source heading count because ''%%~~DISCUSSION~~%%'' contributes its own heading. And a source-side count is not a substitute for a rendered one on either page: the embedded script output here contains ''%%==%%''- and ''%%##%%''-prefixed lines that a naive source-side heading regex picks up as headings (44 against a real 22). 
 + 
 +Two earlier versions of this paragraph were wrong — first 58/22then 60/21/4, both counted with an unscoped grep and both before the last round of edits. A review pass could not reproduce either. It is recorded rather than quietly corrected because a provenance page whose own self-check does not reproduce is worse than one that has none, and because getting a trivial count wrong twice is the honest illustration of why the rest of the page is scripted.
  
 ===== Folding script ===== ===== Folding script =====
Line 1376: Line 1399:
  
 ==== fable — generic ==== ==== fable — generic ====
 +
 +Run after the three focused passes and their fixes, with no checklist. It found more than the other three combined, and two of its findings were substantive enough to change what the page tells a reader to do.
  
 ^ Finding ^ Disposition ^ ^ Finding ^ Disposition ^
-| (pending) | |+**"Topics and Attribution Reporting have no CDP surface at all, in any Chromium version checked" is misleading, and it misdirects the page's own headline call to action.** "Any version checked" was two versions. ARA had a full CDP ''Storage'' surface until it was removed from the protocol in April 2026 | **Accepted, fixed, and this was the most valuable finding of the whole review.** Verified independently by bisecting the ''devtools-protocol'' history (present 2026-04-01, absent 2026-04-08). The page now carries a box saying the gap is closable with first-class instrumentation on a pre-April-2026 build, with a one-line check for whether a given binary has it. The CDP table has a new row. The two dead ARA listeners in the published script now carry a comment saying why they are there | 
 +**HTTP headers are missing entirely as an observation surface**, and they are arguably the //primary// one for Attribution Reporting and Topics | **Accepted, fixed.** New subsection with all five headers, verified against MDN. Added to the "What to Report" list | 
 +| **Wrapping the ''attributionSrc'' IDL setter misses server-rendered ''%%attributionsrc%%'' content attributes**, because the parser does not invoke IDL setters | **Accepted, fixed.** The page now says not to do it and gives three alternatives. This was a genuine instrument bug in advice the page was giving | 
 +| ''privacysandbox/attestation'' **and** ''patcg-individual-drafts/topics'' **are also archived**; the page marked only the RWS repo, and said "two of the three" artefacts are frozen | **Accepted, fixed.** Verified through the GitHub API: archived, last pushes 2026-01-22 and 2025-11-07. All three rows now carry the archive date, and the "two of the three" sentence is rewritten — with the distinction that the ''.dat'' inside a Chromium install still moves with the component updater | 
 +| **The enrollment-closure "consequence" this log claimed the page stated was never actually written on the page** | **Accepted, fixed.** The quote and the ''%%--privacy-sandbox-enrollment-overrides%%'' workaround are now both on the content page. This log's own claim has been corrected | 
 +| Two stale figures in **this log's prose**: "4 of 5,869 papers name Attribution Reporting" and "the 8.1% silence figure", both pre-fold-fix | **Accepted, fixed.** This is the known failure mode where a correction reaches the page but not the log; recording that it happened here too | 
 +| **The removal-date slip history is only in this log, not where the reader decides.** "Measured in days" is stated as if M153 were firm | **Accepted, fixed.** The slip history (M144 → M150 → M152/M153/M155) is now a bullet in the top box, and "days" is hedged | 
 +| **"They have not been removed yet" rests on a Chromium 151 probe while stable is M152** | **Accepted, fixed.** The box now says so in one clause | 
 +| **Missing hedge: field trials.** A code-removal milestone is the //latest// end of the window; Chrome ramps features down server-side first, and an automation Chromium has no variations seed | **Accepted, added**, flagged as not established for these specific features | 
 +| **The measured-results table has no written inclusion rule**, and two of its rows are not Privacy Sandbox measurements | **Accepted, fixed.** The rule is now stated above the table and the two exceptions are named and justified. The precision sentence in [[#Folding and residue]] counts the same 11 | 
 +| **Missing: user-side gating.** Real users hold heterogeneous "Ad privacy" toggle states; a crawler profile is one | **Accepted, added** to the pitfalls list | 
 +| "A dozen papers … over sixteen years", after showing 43/67/9 and an 11-row table; and self-referential prose about its own placement; and "the re-identification numbers everyone cites" in a page that proves almost nobody cites them | **All three accepted, fixed** | 
 +| The silence figure's denominator includes crawls with no reason to touch an ads API | **Accepted.** The defence was in this log only; half a sentence of it is now on the content page, framing the figure as an upper bound on non-engagement | 
 +| Bounce-tracking dating differs in phrasing from [[privacy:browser_storage]] | **Accepted, fixed** by naming both the milestone and the later default-on, and cross-linking | 
 +| The provenance page is honest in tone; its overclaims are the three concrete ones above | **Noted.** All three fixed | 
 + 
 +**Rejected: nothing.** Every finding from this pass was accepted. That is unusual and is recorded as such: it is evidence the generic slot earns its place, and also that the three focused passes, by having checklists, all missed the same class of defect — advice that is well-sourced and wrong. 
 + 
 +==== Work done after the generic pass, and the second round ==== 
 + 
 +Verifying the generic pass's "removal dates have already slipped twice" finding against the blink-dev thread turned up more than the finding itself, and the content page gained a section that no reviewer had seen: **"The only post-2025 adoption numbers that exist are Chrome's own"**, five rows of Chrome Platform Status ''motivation'' telemetry. It is recorded here rather than folded silently into the page because it postdates every review, and because it is exactly the kind of late addition that escapes an audit trail. Its sources are in [[#External sources, verified and rejected]]; two subsequent re-review passes checked all five quotes verbatim and found no error in them. 
 + 
 +Two ''sonnet'' re-review passes were then run over the edited pages, one on figures and one on currency and citations, both told the earlier fixes might themselves be wrong. 
 + 
 +^ Finding ^ Disposition ^ 
 +| **The DOM self-check numbers in [[#Bibliography]] are still wrong** — "60 citation markers, 10 tables, 21 headings, 4 WRAP boxes" against actual 33 source markers / 12 tables / 23 headings / 5 boxes. Found independently by both re-reviewers, who then disagreed with each other (33 vs 60 markers, 21 vs 22 headings) | **Accepted, fixed, and the disagreement diagnosed.** The whole paragraph is now a table with the counting method stated, and it explains the trap that caught both of them: the plugin emits two spans per source marker, and ''%%~~DISCUSSION~~%%'' adds a heading. Third time | 
 +| **"Every call returned a benign empty value rather than throwing" is contradicted by the page's own committed probe output** — ''sharedStorage.worklet.addModule()'' throws ''OperationError'' in all four configurations, and the illustrative code box on the page had silently dropped that line | **Accepted, fixed.** The eighth call is back in the box, with the reason (the probe server returns ''text/html'' for every path, so the worklet module fails a MIME check — an artefact of the probe, not of the API) and a note that it was trimmed for one revision | 
 +| **The headers table overclaims**: ''Attribution-Reporting-Register-Source'' names a ''destination'' field; MDN documents no "reporting origin" field, which is implicit in the sending origin | **Accepted, fixed** | 
 +| **The bisect window is wider than necessary.** The removal landed in one commit, ''96e032552f'', 2026-04-02, "Roll protocol to r1608973"; the last commit with the symbols is ''1abe750809'', 2026-03-25 | **Accepted, fixed.** Both re-reviewers found the same commit independently. The page now names it | 
 +| The page's "which partition by default" gloss on Firefox and Safari is not literally in ''bahrami2025_cookieguard'' | **Accepted, fixed.** The gloss is now marked as ours and attributed to [[privacy:browser_storage]] instead | 
 +| The new telemetry section had no provenance trail | **Accepted, fixed** — this subsection | 
 +| ''%%--privacy-sandbox-enrollment-overrides%%'' could not be confirmed against Chromium source (code search needed auth); corroborated only by Google's own docs and by the fact that this run's own probe passes it without error | **Accepted as a limitation, recorded.** The switch is used in ''sandbox/ps_call_probe.mjs'' and Chromium does not reject it, which is weaker than a source citation | 
 +| ''w3.org/TR/attribution/'' returns 403 to ''curl'' but 200 to a browser-grade fetch; Bugzilla rejects bare ''HEAD'' | **Noted.** Neither is a dead link; recorded for future link-checkers | 
 + 
 +Everything else in both re-reviews checked out: the fold fix lost exactly the one true positive already admitted and no more (179 of 180 case-insensitive extras in the Protected Audience family are "full-fledged"), every regenerated table matches a fresh script run byte for byte, the published code block is byte-identical to the committed script and reproduces its seven events, the mutation test still drops it to three, and all 34 external claims re-fetched today were confirmed verbatim.
  
 ====== References ====== ====== References ======
provenance/privacy/privacy_sandbox.1788281989.txt.gz · Last modified: by karel.kubicek.claude

Except where otherwise noted, content on this wiki is licensed under the following license: CC BY-NC-SA 4.0
CC BY-NC-SA 4.0 Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki