a hidden child realm lays text out exactly as the page does
The same element measured in the page and in a hidden same-origin child frame produces identical text advance, identical box dimensions and the same resolved font-family.
What a detector infers
A deployed commercial agent does not run most of its collectors in the page. It creates ONE hidden iframe, runs them inside it behind a visibilitychange listener and a timeout race, and reports a distinct status code when the frame does not answer in time — seven of its signals are gathered that way. What it reads there is not navigator values but LAYOUT: element bounding boxes, text advance widths, scroll geometry, resolved font-family.
That distinction is why this row exists next to iframe-coherence rather than inside it. The older row compares navigator and screen values across the same realm boundary and catches a spoof scoped to the top window; nothing in this audit compared layout across realms, which is the half the hidden frame is actually used for.
The assertion needs no reference value and no population: both realms belong to one document, are laid out by one engine and resolve against one font stack, so an identical element measured in each is one measurement described twice. Text advance in particular is compared exactly rather than with a tolerance, because there is no legitimate source of disagreement — one string in one font has one advance width.
A metric perturbation installed on the page's prototypes does not follow into a frame created afterwards, so the frame keeps reporting the real geometry and the pair separates.
How to resolve it
Apply metric-level changes below the realm boundary. A patch installed on the top document does not reach a same-origin iframe created later, and collecting layout through exactly such a frame is a deployed technique rather than a hypothetical one.
Nearby checks in Render & GPU
- the WebGL2 element-count limits are reported beside the renderer that claims them
webgl-max-elements-readoutMAX_ELEMENTS_INDICES and MAX_ELEMENTS_VERTICES are hints the driver publishes about how many indices and vertices it draws efficiently in… - the WebGPU preferred canvas format is reported beside the claimed platform
webgpu-canvas-format-readoutnavigator.gpu.getPreferredCanvasFormat() returns the texture byte order the platform's compositor wants to be handed — and that preference… - drawing the same scene twice produces the same pixels
canvas-repeat-render-determinismCanvas noise is usually reasoned about as a trade: give up a stable hash, gain an unlinkable one. - reading the same framebuffer twice returns the same bytes
webgl-repeat-readback-determinismThe same assertion as the canvas row beside it, asked one layer down the graphics stack, and separate from it because a build can be… - MathML scripts are shaped with real metrics, not flattened to text
mathml-metrics-vs-osMathML metrics sit in the long tail of a deployed collector's signal inventory, read through an <mmultiscripts> element. - the time a hidden frame takes to be created and measured in is reported
hidden-iframe-completion-budgetThe second failure mode of the hidden-frame modality, and one nothing in this audit could previously report: not a wrong answer, but no… - GPU-side pass timing is reported beside the wall clock
webgpu-timestamp-vs-wallclockA deployed commercial agent's GPU collector is not a pixel hash. - the same surfaces sampled twice in one page return the same answers
answer-stability-across-passesThis is the two repeat-render rows generalised across every surface at once, and the argument for it comes from how detector scores actually…
Clearcote is a browser built for fingerprint coherence
It is a Chromium fork, maintained by the same people who wrote this reference. It ships as a compiled browser rather than as a stealth script injected into someone else's — which is a description of how it is built, and is not an argument about how it behaves on this check.
This audit takes no position on how Clearcote scores on Render & GPU checks, on this one, or anywhere else. It has no baseline corpus of other people's fingerprints to rank you against and no vendor scoreboard — nearly every check is self-referential, asking one browser the same question through two independent APIs and reporting whether both answers can be true at once. It runs identically on any browser, including ours. Run it on yours and read the result yourself.
See the other checks in Render & GPU — the family hidden-iframe-layout-agreement belongs to.
