docs: integrate agent browser background debugging contract

This commit is contained in:
2026-09-27 15:32:24 +08:00
parent a52e747a00
commit 0eed70fa63
7 changed files with 55 additions and 8 deletions

View File

@@ -92,7 +92,7 @@ Main 在接收带图消息时立即将上传 attachment id 放入 optimistic use
| AI 编程上下文压缩 | Renderer compact action / Pi compaction events | correlated compact RPC → target projector → Snapshot/Patch timeline | Pi `0.84.2` 的手动 compact 不发 `agent_settled`;RPC success 或权威 compaction failure 终结 compact 并 exactly-once 释放对应 ownership,不提前结算普通 prompt |
| AI 编程 Provider 错误 | Pi logical-thread Provider 请求 | selected thread-local credential store → Main AI proxy → Works 模型上游 → projector safe error | 确定性的 Works user-context 缺失使缓存 gateway credential 过期、返回非重试认证失败且不重放请求;Renderer 只看到固定 Provider-auth 提示,不能把它解释为 Pi 崩溃 |
| AI 编程子 Agent | parent logical thread `subagent.v1` tool call | explicit extension → authenticated Main bridge → scheduler → independent ephemeral Pi child process | child 并发最多 4、单次最多 8、禁止递归;child 使用 FIFO 进程预算 8,shared parent 逻辑线程不各占一个 process lease;coding child 与 parent 共用项目 write lease,父 abort/crash/generation 失效必须清理 child 与 permit |
| 共享开发浏览器 | 用户面板打开或 parent Agent `agent_browser open` | 当前项目身份 → Main-owned browser route/module → sandboxed `WebContentsView` + bounded CDP → 同一 Renderer 右侧 viewport/Console/Network | Agent 发起打开后先通知 Renderer 展示并最多等待 5 秒取得当前 generation 的可见 bounds;项目 id 仅允许具备 Renderer capability 的请求使用。非 Web、文件注入、跨目标及宿主级 CDP 被拒绝;诊断 owner 释放到零后停止采集。 |
| 共享开发浏览器 | 用户打开作品或 parent Agent `agent_browser open` | 当前项目身份 → Main-owned browser route/module → sandboxed `WebContentsView` + bounded CDP → 同一作品 viewport/Console/Network | 新浏览器首次打开通知 Renderer 展示,最多等待 5 秒取得当前 generation 的可见 bounds;之后切回操作对话保留工具访问,重复 open/导航只发布 state、不请求 show。隐藏截图通过原生 capture 请求一帧后执行原 CDP 命令,不抢标签或焦点。项目 id 仅允许具备 Renderer capability 的请求使用;非 Web、文件注入、跨目标及宿主级 CDP 被拒绝;诊断 owner 释放到零后停止采集。 |
| 客户端更新检查 | 设置页 | Renderer update store → IPC → Main AppUpdater → 目标 feed | Main 记录并重抛原始错误;Renderer 只显示去重、脱敏的单条提示,稳定源缺包不伪装为最新版 |
| Design Workspace load | Canvas 中央区与右侧 Works rail | Renderer Host API → Main-owned Works Square V2 adapter → current Workspace/Direction/Living Form projection | 一个 Workspace 公开一个 current Direction 与 persistent Agent Session;右 rail 只选择/创建/删除 Workspace,conversation timeline 是交互历史,不是独立 authority object |
| Design input and reconciliation | Chat/direct edit/decision/proposal/lock/Asset binding/restore | Renderer draft → Main → `design.input.apply` → canonical Direction projection | 全部进入同一 reducer;accepted 前 draft 保持本地,revision conflict 刷新权威投影,unknown result 复用原 command/operation identity |

View File

@@ -23,8 +23,8 @@
| `electron/services/project-release-builder.ts` | Main-owned 安全快照、本地 npm/Vite 构建、source+built 双归档与 v1 contract | 固定 npm 11.6.2;项目 Vite 由 lockfile 决定;Vite config/plugins 以桌面用户权限执行 |
| `electron/services/publish-runtime.ts` | 安装包内 npm 闭包定位与 Electron Node 执行 | 不回退全局 npm/PATH;缺失或版本不符 fail closed |
| `electron/services/static-release-server.ts` | 用内存 built snapshot 建立一次性 loopback origin | 预检和最终上传归档必须来自相同文件字节;总是清理临时服务 |
| `electron/agent-browser/module.ts`, `electron/api/routes/agent-browser.ts`, `src/lib/agent-browser.ts`, and `src/pages/Chat/AgentBrowserPanel.tsx` | 项目级共享开发浏览器、可见 viewport 协调、Console/Network 诊断与 built artifact 临时预检 | 用户和 parent Agent 共享同一 sandboxed 页面;Main 校验当前项目、generation、bounds 与 CDP method。诊断按 owner 引用计数,关闭/切换/隐藏/休眠会释放 view 与 debugger;发布预检仍只是 UX fail-fast,不生成可信 receipt。 |
| `electron/agent-browser/electron-adapter.ts` | Electron WebContents/CDP 设备指标、事件与临时 partition 适配 | probe 不挂载 UI,并在结束后销毁视图、清理隔离存储 |
| `electron/agent-browser/module.ts`, `electron/api/routes/agent-browser.ts`, `src/lib/agent-browser.ts`, and `src/pages/Chat/AgentBrowserPanel.tsx` | 项目级共享开发浏览器、首次 viewport 初始化、Console/Network 诊断与 built artifact 临时预检 | 用户和 parent Agent 共享同一 sandboxed 页面;Main 校验当前项目、generation、bounds 与 CDP method。首次打开等待可见 bounds;切回操作对话只隐藏 view,保留调试能力,重复 open/导航不强制切页。诊断按 owner 引用计数;明确关闭浏览器、切换项目/模块、隐藏窗口或休眠仍释放 view 与 debugger。发布预检仍只是 UX fail-fast,不生成可信 receipt。 |
| `electron/agent-browser/electron-adapter.ts` | Electron WebContents/CDP 设备指标、事件与临时 partition 适配 | 隐藏页面截图先用 stayHidden 原生 capture 请求一帧,再执行原 CDP 截图,保留参数且不展示页面、不转移焦点、不持续关闭后台节流。发布 probe 不挂载 UI,并在结束后销毁视图、清理隔离存储 |
| `electron/services/project-packager.ts` | 受控项目扫描、静态 ZIP 生成和敏感/历史控制文件排除 | 只允许可发布 `ProjectType`,不提供 Compose 或手工 ZIP 路径 |
| `electron/services/works-submission-binding.ts` | submission binding v2 持久化与旧 schema 迁移 | 旧中间态终止为 `legacy_retired`;文件名暂作安装兼容 |
| `electron/api/works-play-url.ts` | 公共播放 URL 的共享安全校验 | 公共 `play_url` 必须同源 HTTPS 且精确匹配 App 路径 |

View File

@@ -48,7 +48,7 @@ Makelore 是 Electron 桌面客户端。Renderer 负责项目操作与状态展
| Pi Conversation Runtime | 一个长驻 Pi `0.84.2` Agent Server 承载每条 active/warm Conversation 的隔离逻辑 Runtime/Session/JSONL channel | 严格 LF JSONL RPC、generation recovery、Snapshot hydration;正式包从 staged `pi-runtime` manifest/root 定位并校验 Pi 包入口;top-level 逻辑 turn 并发 4、warm idle LRU 8;Server 退出统一使旧 channel 失效并按需单实例重启 |
| Pi Provider & Managed Resources | Provider catalog、thread-local secret projection、model/resource revision、Prompt/Skill/extension materialization、selected-model tools | Works `model_capabilities_v2` 由 Main 归一化并持久化,作为受管模型图片/思考能力唯一依据;未知不回退本地 profile。Main 保存原生 reasoningChoice 并冻结供应商字段,经 Pi 请求钩子发送。父/子凭据仍限于目标执行上下文;Web Search 保持独立适配器、所选模型及普通模型计费,不回退 agent_browser;secret 不进入 argv、catalog 或 Renderer |
| Pi Extension, Subagents & Lifecycle | 必需的生成式 Makelore extension、Main 显式选定的已安装 extensions、UI interaction、ephemeral child、write lease 与 background run lease | Makelore bridge 固定为首个 extension,其余选定 extension 全部经 Pi 的 explicit additional paths 加载且 ambient discovery 关闭;child 并发 4、单次最多 8、禁止递归;active/uncertain run 不因页面隐藏或 confirmation timeout 被停止,replacement/stop 必须可解释并清理所有 ownership |
| Shared Agent Browser | Project-scoped sandboxed `WebContentsView`、Renderer 右侧面板与 Main-owned CDP bridge | 用户和 Agent 操作同一页面;Renderer 必须先提供可见 bounds,Agent `open` 最多等待 5 秒取得可见 viewport。Console/Network 诊断按 owner 引用计数;关闭面板、切换项目/模块、隐藏窗口或后台休眠会清理 view、debugger 与轮询。 |
| Shared Agent Browser | Project-scoped sandboxed `WebContentsView`、作品页与 Main-owned CDP bridge | 用户和 Agent 操作同一页面;新浏览器首次打开最多等待 5 秒取得 Renderer 提供的可见 bounds。已初始化页面切回操作对话后仍可调试;重复 open/导航只更新状态,不强制切页。隐藏截图按需请求一帧,不展示页面或转移焦点。Console/Network 诊断按 owner 引用计数;明确关闭浏览器、切换项目/模块、隐藏窗口或后台休眠仍清理 view、debugger 与轮询。 |
| Code-owned Official Project Plugins | Existing Account acquisition or system-included delivery → project enablement → effective parent snapshot | Data Service、Game Resource 与 Project Scaffold 都不要求 Agent assignment,项目启用后自动进入每个父 Agent;child 不继承 Plugin。三者不经过设备下载、更新、Beta 或 artifact 签名;Game Resource 的一次确认由 Main 提交一次、内部轮询并把全部终态输出自动写入冻结的原项目,恢复本地交付不得重新生成或计费;Project Scaffold 的 `.mjs` 仍只来自签名客户端固定资源。需要分配的 Marketplace 下载包保持原规则。 |
| Device Packages | Conversation install tools → Main-owned inspect/preview/confirm/commit → immutable local generation → parent Skill/Pi-extension resources | 支持 npm、Git、绝对本地 Plugin 目录与 loose `SKILL.md`;没有可见安装入口、Account Library、Release、Admission 或 Marketplace Package Store。可执行 extension 与非空 Skill `scripts/` 拥有桌面用户权限,必须披露并独立确认;生命周期脚本禁用。每个 generation 包含所有显式安装且当前启用的 Skill/extension;新/idle parent 自动刷新,active parent 在 turn settled 后刷新,child 始终为空。 |
| Unified Plugin Workspace | Project Configuration 的 `插件` ResourceCard → `/project-config/plugins` same-page wide sheet | 复用统一 Plugin controller 与生命周期;Project Configuration 保持挂载,Code 侧栏不再提供独立入口;`/plugins` 和旧 Plugin URL 仅做保留查询条件的兼容重定向 |