Commit Graph
567 Commits
Author SHA1 Message Date
Zhang GH 62ba1bb2c7 Merge pull request #310 from Tencent/feat/skill-reference-bundles
Split skill bundles into on-demand references with safe upgrades
2026-09-22 10:12:41 +08:00
Zhang GH c1e5052735 Merge pull request #183 from MaxFreedomPollard/fix/dsh-plugin-runner-settles-without-close
fix(dsh-plugin): settle runner promises when the child never emits close
2026-09-21 21:55:48 +08:00
drakezhang 6f6e09e04c fix(dsh-plugin): preserve results while exited commands drain
Interrupting a command after exit could truncate its JSON and report a
parse failure. Output arriving during the drain could also extend the wait
past the execution timeout and turn a completed command into a timeout.

Only interrupt still-running children and count those matches in killFor.
Keep exited children draining, stop the execution timer on exit, and retain
the existing idle drain window and 2-second cap. An explicit AbortSignal
still cancels the caller's wait immediately during drain.

Clarify the execution timeout and separate output collection limit in the
runner options, plugin configuration and README. Preserve the existing
platform-specific cancellation grace, kill fallback and resource cleanup.

Validation: 10 regression checks failed before the fix and now pass; all
351 DSH plugin tests in 19 files pass, including real-process inherited-pipe
cleanup. Biome, Stylelint, TypeScript and git diff --check also pass.
Windows cancellation cases use simulated platforms on macOS.
2026-09-21 21:48:36 +08:00
drakezhang dc806259e4 fix(ci): verify DSH npm packages on Windows 2026-09-21 21:44:42 +08:00
drakezhang 82734dbac9 Merge main into PR #183 and resolve runner conflicts
Preserve the contributor's original commits and bounded settlement, pipe
cleanup, renewable output drain, and killAll/killFor fallback paths.

Reconcile the overlapping main runner fix by retaining its 1s drain grace,
referenced drain timers, cancellation timer cleanup, and listener ordering.
Keep the PR's 2s total drain cap and platform-specific kill deadlines.

Adapt the affected runner tests to the retained grace and update the
session-start regression fixture for main's prepare/start/claim lifecycle.
No unrelated feature changes.

Validation: all 345 DSH plugin tests across 19 files pass, including the
real-process inherited-pipe regression; Biome, Stylelint, TypeScript and
git diff --check pass. Windows cancellation is covered by simulated-platform
tests; no Windows host was used.
2026-09-21 20:54:05 +08:00
drakezhang bbada7b2e8 fix(ci): normalize Cargo package paths on Windows 2026-09-21 20:50:12 +08:00
drakezhang 240bf1dd7a fix(skill): guard incomplete installs and parse CRLF metadata 2026-09-21 20:44:24 +08:00
drakezhang 47f5765cb3 fix(skill): preserve source links and migrate CRLF legacy skills
Isolate harness path tests from host environment settings and verify Windows defaults. Cover real historical LF/CRLF fixtures, custom intent, local edits, reference collisions, and exact checksum baselines.
2026-09-21 19:56:46 +08:00
drakezhang 45a3bf1c42 feat(skill): ship reference bundles with safe upgrades 2026-09-21 18:57:44 +08:00
Zhang GH 5f48564bbc Merge pull request #291 from lyingbug/fix/navigation-response-deadline
fix(daemon): let navigation timeout results outlive the transport deadline
2026-09-21 16:00:13 +08:00
Zhang GH 9f12c10e4b Merge pull request #307 from MaxFreedomPollard/fix/select-visible-option-labels
fix(extension): return visible labels from select
2026-09-21 14:29:30 +08:00
Max Freedom Pollard 46800bd0ff fix(extension): return visible labels from select 2026-09-20 22:59:49 -07:00
Zhang GH 926809bd66 Merge pull request #184 from MaxFreedomPollard/fix/record-reload-step
fix(record): record a page reload instead of dropping it as a same-URL navigation
2026-09-21 12:59:56 +08:00
Zhang GH 65cbee1690 ci: sync main fixes and keep skill instructions within budget
Bring in the existing status and doctor fixture isolation from main. Condense repeated DSH skill wording without relaxing the prompt-size assertions or changing the recording fix.
2026-09-21 12:35:54 +08:00
Zhang GH 0225683ad8 Merge pull request #298 from Tencent/fix/profile-bound-sessions-219
fix: improve explicit browser profile selection across CLI and DSH
2026-09-20 20:54:38 +08:00
Zhang GH a17383af95 Merge pull request #289 from basil-k-aji-dev/docs/untrusted-page-content
docs(skill): say that page content is data, never instructions
2026-09-20 20:42:48 +08:00
Zhang GH 88718fd6b9 fix: align DSH profile selection guidance and coverage 2026-09-20 20:22:23 +08:00
drakezhang 1e58dd114d docs(skill): fit guidance within the merged prompt budget
Condense the DSH guidance while preserving its authorization boundary and recovery behavior. Keep the existing 7000-character limit after combining the PR with main's recovery instructions.
2026-09-20 19:51:46 +08:00
drakezhang 3274e64135 docs(skill): trim guidance and fix CLI tool references
Keep the DSH guidance within the existing prompt budget and use CLI action names in the CLI skill.
2026-09-20 17:23:34 +08:00
Zhang GH 907b455ea6 Merge pull request #293 from lyingbug/fix/harness-env-test-lock
test(skill-install): serialize harness tests around the home env vars
2026-09-20 17:16:36 +08:00
Zhang GH 5147c945e1 fix: bind profile-specific tasks to extension instances 2026-09-20 17:10:36 +08:00
Zhang GH c6c888e178 Merge pull request #283 from drakeo338/fix/269-rearm-lazy-tools-after-plugin-reload
fix(dsh-plugin): re-arm lazy tools from history after a plugin reload
2026-09-20 17:04:00 +08:00
drakezhang 963f694be3 fix(dsh): retry lazy tool registration once per session batch 2026-09-20 16:40:26 +08:00
drakezhang a4ac06e48e fix(dsh): avoid retrying tool registration on streamed events
Retain successful invocation proof after failures and defer retries to turn/session boundaries or new skill invocations. Add regression coverage for sustained streaming and next-turn recovery.
2026-09-20 16:04:13 +08:00
drakezhang e1a4018445 fix(dsh): recover lazy tools without rescanning streaming history
Parse current durable tool results and support both session history APIs. Scan each session once, process later events incrementally, and retry recovery when services or history become available.

Cover official DSH messages, reloads, long conversations, failed reads, and explicit history access counts.
2026-09-20 14:18:12 +08:00
drakezhang 58b7dabdd2 Merge PR #283 with current main 2026-09-20 14:08:58 +08:00
wizardchen 02e802f2e3 test(skill-install): serialize harness tests around the home env vars
hermes_skills_dir_honors_hermes_home_env overrode the process-wide
HERMES_HOME without any lock, while detects_hermes_from_home_layout and
skills_dirs_match_harness_spec resolved Hermes through that variable on
other libtest threads: the detection test read the override's temp
directory and failed about six times in thirty runs. The Kimi tests took
kimi_env_lock, but skills_dirs_match_harness_spec read KIMI_CODE_HOME
without it, leaving the same failure latent there.

Widen that lock to harness_env_lock, take it in every test that reads or
writes HERMES_HOME or KIMI_CODE_HOME, and replace the two SAFETY comments
whose invariant did not hold: the hazard is a concurrent reader, not only
another writer.
2026-09-20 13:25:29 +08:00
basil-k-aji-dev f10c72a615 docs(skill): judge injection by authorization, not by action type
Raised in review by @iuyo5678, and the objection is right.

The first wording listed actions - send data somewhere, approve something,
install something, visit another site - and called any page mentioning them an
injection attempt. Those are ordinary parts of authorized work. An agent
following that rule would refuse to submit a form the user asked it to submit,
or to follow a documentation link the user asked it to read, and would report
the page as hostile for containing a button.

The test is whether the page is trying to change what the agent may do, not
what kind of action it names. The text now says that, and says explicitly that
navigation guidance, controls and quoted examples are not by themselves
evidence of injection.

AGENT_INSTALL.md also claimed "a page cannot redirect the agent". That reads as
a technical guarantee and none exists: nothing stops a page carrying text aimed
at an agent. It now describes what the agent is required not to do - let page
content override its instructions, grant it permission, or widen its task - and
names the guidance as behavioural.

Both skill files carry the same wording, as before.
2026-09-20 10:40:41 +05:30
wizardchen 214b1ebca2 fix(daemon): let navigation timeout results outlive the transport deadline
navigate, navigate_back, navigate_forward, reload and wait_for_navigation
resolve with a structured result at their own timeout_ms: reached "timeout",
the URL the page actually reached and the last observed lifecycle. The daemon
dispatched them with a transport deadline equal to that same timeout, so the
extension's reply still had to cross the socket after the deadline had fired.
The reply then took the TimedOutAfterResponse path, which preserves completed
results only for session_stop, tab_borrow, request_help and the effect-aware
transfers, so the caller received a bare "tool RPC timed out" instead.

Grant these five methods the EXTENSION_RESPONSE_GRACE that upload, download
and request_help already use. They are the complete set of tools whose
extension handler resolves with "reached: timeout" at a caller-supplied
deadline; every other tool is unchanged.
2026-09-20 12:24:23 +08:00
Zhang GH 2a4ecacb43 Merge pull request #284 from dvd233/codex/fix/request-help-cleanup-timeout-277
fix(extension): bound request-help cleanup wait
2026-09-20 12:18:59 +08:00
Zhang GH d247cb7895 fix(extension): decouple help overlay and notification cleanup
Start tab and notification cleanup concurrently so a stalled notification
cannot prevent cancellation messages from reaching the page overlays.

Cover content completion, timeout, and cancellation across multiple tabs.
2026-09-20 11:48:12 +08:00
Zhang GH d04c7526f4 Merge pull request #290 from Tencent/fix/recoverable-session-starts
fix: make browser session starts recoverable
2026-09-20 09:58:04 +08:00
drakezhang 2fc2704f85 fix: expose stop request targets in the public tool schema
Share optional stop target parameters between browser_session and its internal
stop handler. Document exact request targeting, mutual exclusion, and default
stop retry behavior in the model-visible contract.

Add a public schema regression covering requestId, optional targets, and retry
guidance. Lifecycle execution remains unchanged.

Validation: 95 tool and stop recovery tests passed; TypeScript and formatting
checks passed. The new schema test reproduced the omission before the fix.
2026-09-20 09:50:49 +08:00
Zhang GH c2d0c7ed9b Merge pull request #282 from Tencent/iuyo5678/fix-windows-daemon-detach
fix(cli): detach Windows daemons from caller pipes and jobs
2026-09-20 09:42:31 +08:00
drakezhang abf0d3a74d fix: unify durable session stop recovery
Route tool, overlay, archive, unload, and recovery cleanup through one lifecycle
owner and one job per request. Persist explicit stop intent before making a
session unusable; caller cancellation only ends its wait after admission.

Retain durable completion receipts independently of the current session so a
retry cannot stop another working session, even after background cleanup or
restart. Preserve failed default callers' retries across concurrent successful
waiters. Support exact request targeting and reject ambiguous stop targets.

Cover failed normal stops, queued and in-flight cancellation, concurrent entry
points, timer and disk recovery, persistence failures, anonymous starts, reused
IDs, unconfirmed replies, and completion receipt capacity accounting.

Validation: 303 plugin tests passed, including 31 stop recovery tests;
TypeScript checking, production build, and formatting passed.
Package lint was unavailable because publint is not installed in this environment.
2026-09-20 01:00:46 +08:00
Zhang GH 58eb44b306 fix(cli): preserve shared daemons after launcher timeout
Do not terminate a running child when its launcher cannot confirm startup.
A different client may already be using it, or publication may race the
launcher's deadline. Retain cleanup only before a Windows child resumes.

Add deterministic lifecycle regressions for reuse before timeout, delayed
publication and port mismatch. Run Windows success-path and updater tests
in a same-user WMI test host that verifies it is outside all Jobs, and keep
restricted-host rejection tests in the normal CI runner.

Refs #268
2026-09-20 00:38:54 +08:00
drakezhang bfa5e521f8 fix: preserve startup ownership and isolate pending cleanup
Capture initial tab identities when creating an Agent Window and retain them
through failed startup compensation. Retry cleanup through the production
stop handler, preserving later user tabs and keeping ownership if agent tabs
still cannot close.

Separate owned starting and cleanup resources from active sessions. Publish
sessions only after initialization and claim succeed, preserve the working
current session on failure, and reject ordinary operations and captures for
resources awaiting cleanup. Recheck queued operations before execution.

Add regression coverage for production stop retries, mixed windows, delayed
claims, current-session fallback, recovery, capacity, and queued operations.
Update window API fixtures for the creation result's initial tab identities.

Validation: extension 1862 passed (103 skipped), plugin 276 passed; both
TypeScript checks and production builds passed.
2026-09-20 00:04:52 +08:00
basil-k-aji-dev 2ba4629498 docs(skill): say that page content is data, never instructions
Both skills tell the agent to read arbitrary pages — observe, get-html,
snapshot, screenshot, console, network — inside the user's real, logged-in
profile, and neither says that what comes back is untrusted. A repo-wide search
found no prompt-injection guidance in any markdown; the only place page data is
labelled untrusted is a protocol comment in bsk-protocol that the agent never
sees.

The absence stands out because the skills already constrain behaviour
elsewhere: never extract credentials, never evaluate secrets, never record
banking or SSO pages. Untrusted page content is the same class of rule and was
simply missing.

States it where the reading happens, in both skills, with a pointer from the
standing rules at the top of each. Names the read commands and the element
names and labels that get passed back to click/fill/select, since those carry
page text too, and says what to do instead: stop, tell the user what the page
tried, do not comply.

AGENT_INSTALL.md asks the installing agent to repeat it to the user, because
the person granting access to their logged-in browser should know a page cannot
redirect the agent, and that an agent appearing to follow one has been injected
rather than instructed.

Documentation only; no behavioural or technical mitigation. The reporter's
further suggestions — delimiting tool output, a domain allowlist, a
consent-to-consequence step — are deliberately left out of scope.

Fixes #286
2026-09-19 17:41:59 +05:30
dvd233 eb9143308e fix(extension): bound request-help cleanup wait 2026-09-18 13:45:43 -07:00
drakeo338 2eee76f78b fix(dsh-plugin): re-arm lazy tools from history after a plugin reload
After a daemon restart that reloads the plugin, browser_* calls fail with
unknown tool "browser_session" until the model happens to invoke the skill
again, even though the session's durable history already proves it ran.

None of the three triggers covers that case. The live tools/result hook needs
a fresh invocation. session/created never fires for a session that already
exists. The boot scan runs once during apply(), and ctx.get("sessions") yields
nothing when the sessions service is registered after this plugin, so it covers
nothing at all.

session/event already receives the session and ignored it. Reading its history
when nothing else has revealed the suite closes the gap, and is guarded so the
scan stops once revealed — these events are frequent and re-deriving on each
one after the reveal is waste.

Keeps the reveal derived from durable history rather than adding a persisted
flag, so there is no new state to migrate or keep consistent.
2026-09-18 17:53:34 +00:00
Zhang GH 6a97ac0f9a fix(cli): isolate Windows daemon startup from caller jobs
Use an explicit standard-handle inheritance list for daemon startup and the
Windows update helper. Require and verify breakaway before resuming a
background daemon, with an actionable error for restrictive host Jobs.

Share direct startup and its readiness deadline across explicit and
automatic entry points, retain child ownership through startup, and reap
Unix children after handoff.

Add native Windows EOF, Job lifetime, concurrency and failure regressions
to CI, and document persistent host setup.

Refs #268
2026-09-18 23:00:57 +08:00
drakezhang 8e357f3a02 fix: make browser session starts recoverable
Track prepared starts with stable request handles, durable plugin ownership, monotonic cancellation, and retryable cleanup. Retain delayed and failed startup resources until cleanup is confirmed, without touching other sessions.

Add regression coverage for lost replies, killed CLI processes, delayed creation, failed cleanup, restart recovery, archive and unload, capacity accounting, and reused session IDs.

Fixes #245
2026-09-18 22:50:52 +08:00
Zhang GH fa953dc6fc Merge pull request #253 from Tencent/fix/background-full-page-screenshots
fix(bsk): support full-page screenshots of controlled background tabs | 支持受控后台标签页的整页截图
2026-09-18 21:17:44 +08:00
drakezhang 2766a22672 Merge main and reconcile background screenshot guidance
Preserve the streamlined skill workflow and document background support for both viewport and full-page screenshots. Keep Canvas capture guidance and remove the outdated visibility requirement for Agent full-page capture.
2026-09-18 21:10:30 +08:00
Zhang GH 64ea064cde Merge pull request #250 from Tencent/fix/background-tab-screenshots
fix(bsk): capture controlled tabs without activating them | 支持无需激活的受控后台标签页的视口截图
2026-09-18 21:03:09 +08:00
Zhang GH 66bcf8c05a Merge pull request #249 from Tencent/fix/background-tab-execution
fix(bsk): keep controlled tabs progressing in background | 支持受控标签页在后台持续执行
2026-09-18 20:57:24 +08:00
Zhang GH 5ef23e74b2 Merge pull request #280 from Tencent/fix/preserve-pending-navigation-progress
fix(navigation): preserve readiness across cancelled redirects
2026-09-18 20:49:55 +08:00
drakezhang 237667bd51 fix(navigation): preserve readiness across cancelled redirects 2026-09-18 18:54:30 +08:00
Zhang GH d1356fd216 Merge pull request #278 from Tencent/iuyo5678/fix-runner-exit-drain
fix(dsh-plugin): bound output draining after child exit
2026-09-18 17:09:56 +08:00
Zhang GH d947823664 fix(dsh-plugin): bound output draining after child exit 2026-09-18 16:47:02 +08:00