v2.5.2
Ankita 2.5.2 — Desktop startup hotfix
Read release notes
Fixed
- Blank desktop startup in development and packaged builds. Shared browser progress metadata imported a host-only DOM probe that compiles a function at module initialization. The renderer's Content Security Policy correctly refused it before React mounted. The form-field limit now lives in the pure operation-policy module, and the ref module re-exports it for compatibility. Browser batching is preserved; the security policy still refuses
unsafe-eval.
Verification and limits
- New startup regressions exercise both complete renderer entry points with their shipped HTML and CSP, rather than an isolated component without CSP. The focused startup/progress/browser recovery suite passes 33/33, including real Playwright and connected-Chrome form batches and stale-ref recovery.
- The full serial local suite reports 1,121 passed, zero failures, one existing POSIX permission skip on Windows. TypeScript/Vite builds pass. Hidden native Electron checks mount both complete entries through the shipped preload and real IPC in dev and built-file mode, with offline engine fixtures, disposable profiles, zero renderer exceptions and the security policy unchanged.
- The packaged ASAR also mounts both entries in native Electron with the actual packaged preload and offline engine fixture. All 23 audited runtime/guide files match source bytes; the executable reports 2.5.2 and includes the native browser bridge and capture helper.
- This hotfix does not address the connected-Chrome Windows CI navigation/cart failures recorded for 2.5.1. Publication uses the locally checked Windows package; no exact-commit remote CI pass is claimed, and the normal workflow's required tests remain unchanged. See the [desktop startup findings](docs/desktop-startup-findings.md) for the full before/after traces, packaging checks and remaining verification limits.