Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion docs/feature-checklist.md
Original file line number Diff line number Diff line change
Expand Up @@ -195,6 +195,7 @@ Flagship feature. C++ services + `dao://dao-agent` WebUI + vendor runtime.
| ☐ | Agent WebUI host allowed to make network requests (LLM API) | `webui/chrome_web_ui_controller_factory.cc.patch` (`origin.host()=="agent"`) | 🟢 | `dao://agent` reaches external LLM endpoints |
| ☐ | Named, collapsible Agent tool calls | `resources/agent/dao_tool_renderer.ts`, `resources/agent/agent.css` | 🟢 | Run `dao_tool_renderer.test.ts`; verify regular, search, and fetch calls always show the stable tool name, keep parameters/output collapsed by default, and expand when requested |
| ☐ | Unified Profile-scoped Agent settings and legacy migration | `src/dao/.../agent/dao_agent_settings_handler.{h,cc}`, `resources/agent/agent_settings_{sync,native_bridge}.ts`, `resources/settings/dao_page/dao_agent_page*.patch`, `webui/settings/settings_ui.cc.patch` | 🟡 | Run `agent_settings_sync.test.ts`, `dao_agent_app.test.ts`, `DaoAgentPage`, and `DaoAgentSettingsHandlerTest`; verify legacy `dao://agent` local-storage values migrate once without overwriting Settings values, partial usage dictionaries receive validated defaults and derived totals, malformed/non-finite fields fail closed, canonical stored snapshots still require the complete schema, both WebUIs receive `dao-agent-settings-changed`, rapid tool toggles serialize cumulative disabled-tool arrays and resync after failure, the resume window defaults to 3 and accepts 0, and runtime-only state is not migrated. With no active Agent turn, the gear opens exactly one foreground `dao://settings/agent` tab through its fixed native command; success closes the sidebar and failure leaves it open |
| ☐ | Experimental shared Jev browser subtask plugin | `agent/dao_agent_plugins.h`, `resources/agent/agent_plugins.ts`, `automation/dao_jev_task.cc`, `automation/dao_page_tools.cc`, Settings Agent page patches | 🟡 | Run `jev.test.ts`, `compact_snapshot.test.ts`, `browser_tool_catalog.test.ts`, Agent bridge/settings/adapter tests, `npm run rebuild`, and `node scripts/checks/jev-plugin.mjs`; verify both switches default off, masked credentials and independent persistence, no settings-triggered requests, invalid configuration unavailable, underlying permissions enforced, no editable drafts or nested controls in compact snapshots (empty/true/plaintext-only, including uppercase), choices stay within 255 options at 150 fields and 20 inputs without dropping candidates, native input/ARIA button names and matching action guards, atomic refs and locally verified completion, fast/delayed form navigation without duplicate submissions, obsolete decisions discarded after navigation, task deadlines while navigation is pending, bounded recovery/no-progress/budget errors with partial evidence, cancellation on stop/config changes/target loss, rejection of late responses and credentialed redirects, reloading the Agent during a pending native wait preserves the browser and allows a new turn, MCP discovery hides `run_browser_task` when disabled/unconfigured and includes it only with valid configuration and permission, without requests or approval prompts, approved MCP tasks run with the Agent panel closed, MCP cancellation and revocation abort native requests, partial failures preserve structured progress, exact target remains pinned across focus changes, ordinary tools unaffected when unregistered, English/Chinese labels and keyboard access. With a configured compatible service, compare bilingual representative tasks against the ordinary Agent before claiming a speedup. |
| ☐ | Settings Agent management summaries and limited native facade | `src/dao/.../agent/dao_agent_settings_handler.{h,cc}`, `resources/settings/dao_page/dao_agent_page*.patch`, `resources/agent/agent_settings_native_bridge.ts` | 🟡 | Verify legacy `dao_agent_stats` migration preserves existing counters once; persona reset removes the override and restores the runtime default; manual Dream generation remains disabled until Memory and Dream analysis are enabled, then reports success and failure without duplicate submissions; a Settings-side usage reset updates an already-open Agent WebUI; Memory clear requires confirmation and refreshes aggregate counts; Workspace reveal works without registering workspace mutation messages; configuration loading/error/retry is independent, including when `getSettings()` fails; Memory, Workspace, and Usage remain visible, independently loadable inset cards with 16px desktop spacing, 12px narrow spacing, compact rows, the shared content inset, and visible keyboard focus in light and dark themes; and the existing Skills, Memory, and Dream secondary links still open |
| ☐ | 7 Dao WebUI configs registered (agent, dream, index, memory, sidebar, skills, welcome) | `webui/chrome_web_ui_configs.cc.patch` | 🟡 | All 7 pages load; confirm upstream `SkillsUIConfig` still exists (dao takes over `dao://skills`) |
| ☐ | Agent tab helpers, guarded cursor overlay, lock banner | `ui/tab_helpers.cc.patch` + `src/dao/.../agent/`, `dao_agent_cursor_view.*`, `dao_agent_*_view.*` | 🟢 | Run `DaoAgentCursorViewBrowserTest.*` and the focused cursor cases in `DaoMcpPageToolsBrowserTest`; verify the cursor uses a black fill, white outline, blue glow, direction-aware tilt/compression, damped arrival wobble, and the existing Dao ripple; verify visuals render only for the pinned target when it is the active tab of a visible, non-minimized, active window, background moves succeed without visuals, background clicks skip animation and remain pinned, changing tabs during a move cannot leak a ripple, short foreground moves are direct, long moves are bounded curves, and hiding a move completes its callback |
Expand All @@ -204,7 +205,7 @@ Flagship feature. C++ services + `dao://dao-agent` WebUI + vendor runtime.
| ☐ | Session-scoped Agent/MCP DevTools tools | `src/dao/.../automation/dao_devtools_tools.{h,cc}`, `dao_devtools_client.{h,cc}`, `dao_browser_automation_session.{h,cc}`, `dao_agent_ui.cc`, `agent_bridge.ts`, `browser_tool_catalog.json` | 🟡 | Run `DaoMcpDevToolsBrowserTest.*`, the Page/Tab MCP regression filters, `agent_bridge_call_native.test.ts`, `pi_tool_adapter.test.ts`, and `dao_chat_view.test.ts`; verify enable-window staging commits only after a matching generation/host success, cancellation/failure/rebinding drops pending staging, clear removes committed and pre-clear staged events while preserving the pending attempt and later events, monotonic same-binding domain confirmation across reordered success/failure, aggregate network/console byte budgets below entry caps, UTF-8-safe truncation, strict current-tree `(frame, URL)` size preflight before content fetch, an independent response-size backstop, exact in-budget base64, failed/oversized Script and Document search incompleteness, item/URL-byte/depth/dedup/source/4 MiB scan limits, re-entrant resolver/command destruction, exactly-once cancellation, and target/host/origin/document rebinding |
| ☐ | Default-off process-global local MCP server | `src/dao/.../mcp/dao_mcp_{service,transport,connection,protocol,runtime_files}.*`, `dao_pref_names.*`, `browser_prefs_mcp.cc.patch`, `chrome_browser_main_extra_parts_profiles.cc.patch` | 🔴 | Run `DaoMcpServiceBrowserTest.*`, `DaoMcpProtocolTest.*`, and `DaoMcpRuntimeFilesTest.*`; verify browser-IO-thread listener ownership, owner-only runtime permissions, nonce rotation, same-UID authentication, protocol/version/line limits, 64-request/8 MiB per-connection and bounded aggregate unconsumed-ingress credits, terminal-request logical closing before later same-batch tools, aggregate write backpressure, bounded graceful-close drains, 32-client admission with least-recently-active idle eviction that releases leases (`EvictsLeastRecentlyActiveIdleClientAtCapacity`, `EvictsIdleApprovedClientAndReleasesLease`) and `TOO_MANY_CLIENTS` rejection when every admitted client is busy (`RejectsHelloWithTooManyClientsWhenAllAreBusy`), serialized approval prompts, concurrent different-tab control, same-tab exclusion, idle hello/catalog discovery beyond the approval timeout without a prompt or disconnect, exact last-active-window selection and approval on the first tool call, required first-call `reason` in every MCP tool schema, missing/blank/invalid/oversized reason rejection before approval, optional subsequent reasons stripped before execution, pre-approval catalog access even when connection begins on Dao Settings, re-entrant approval cancellation denial, approval plus lease ordering, cancellation, optional non-tab `tab_id` schema/routing, isolated concurrent tab contexts, default-target compatibility after MCP switch/open, unknown-target fail-closed behavior, and complete per-connection lease/runtime cleanup after disconnect, disable, and shutdown |
| ☐ | Settings MCP master switch, connection, usage, quick setup, and Stop | `src/dao/.../mcp/dao_mcp_settings_handler.{h,cc}`, `resources/settings/dao_page/dao_page.{html,ts}.patch`, `webui/settings/settings_ui.cc.patch` | 🟡 | Run `DaoMcpInstallCommandTest.*`, `DaoMcpSettingsHandlerTest.*`, `DaoMcpSettingsPageBrowserTest.*`, and `DaoPage`; verify one header/connection/usage/enabled-only-setup card, responsive selector/copy alignment, and text status updates through `dao-mcp-status-changed`. The switch must write process-global Local State rather than `prefs.dao`; profile-scoped usage lists total and per-tool calls, sorts by count, resets independently, counts successful and failed executor entries, and excludes validation, denial, unknown-tool, and pre-execution target failures. Client details and Stop appear only for an active authorized lease. Confirm setup is absent while disabled; when enabled it defaults to Codex and switches to user-scoped Claude Code or Generic MCP. CLI previews stay single-line, Generic MCP preview and clipboard are identical Chromium-native three-space pretty JSON, and malformed Generic JSON fails closed without changing the clipboard. Also verify option-specific feedback, POSIX-safe helper and current user-data-directory arguments, Debug/custom-profile endpoint binding, stale preview rejection, listener cleanup, and absence of the standalone configuration button. |
| ☐ | Native MCP stdio helper and macOS app bundling | `src/dao/.../mcp/helper/`, `dao_mcp_helper_browsertest.cc`, `dao_version.gni`, `chrome/BUILD_mcp_helper.gn.patch` | 🔴 | Run `DaoMcpHelperBrowserTest.*`; verify all 33 tools survive catalog adaptation, MCP `2025-11-25` and Codex-compatible `2025-06-18` negotiation with initialized gating, the `codex/tool-catalog-cache.cacheable=false` compatibility capability, server-wide instructions that prefer Dao MCP, establish the initial target with `list_tabs`, preserve it across follow-ups, route ambiguous open/click/select requests through `query_elements` and guarded `click_by_ref`, and reserve `switch_tab` for explicit browser-tab navigation; verify adapted per-tool descriptions do not repeat tab-discovery guidance, plus string/numeric IDs, object/scalar/list `structuredContent`, real screenshot MIME, `isError` failures, cancellation with no late response, disabled-browser stderr determinism, JSON-only stdout, and executable copies at both the build output and `Dao.app/Contents/Helpers/dao-mcp` |
| ☐ | Native MCP stdio helper and macOS app bundling | `src/dao/.../mcp/helper/`, `dao_mcp_helper_browsertest.cc`, `dao_version.gni`, `chrome/BUILD_mcp_helper.gn.patch` | 🔴 | Run `DaoMcpHelperBrowserTest.*`; verify all 34 tools survive catalog adaptation, MCP `2025-11-25` and Codex-compatible `2025-06-18` negotiation with initialized gating, the `codex/tool-catalog-cache.cacheable=false` compatibility capability, server-wide instructions that prefer Dao MCP, establish the initial target with `list_tabs`, preserve it across follow-ups, route ambiguous open/click/select requests through `query_elements` and guarded `click_by_ref`, and reserve `switch_tab` for explicit browser-tab navigation; verify adapted per-tool descriptions do not repeat tab-discovery guidance, plus string/numeric IDs, object/scalar/list `structuredContent`, real screenshot MIME, `isError` failures, cancellation with no late response, disabled-browser stderr determinism, JSON-only stdout, and executable copies at both the build output and `Dao.app/Contents/Helpers/dao-mcp` |
| ☐ | Local MCP approval, controlled-tab indicator, Stop, and peer-agent busy UX | `dao_mcp_approval_dialog.{h,cc}`, `dao_mcp_control_banner_view.{h,cc}`, `dao_address_bar_view.{h,cc}`, `dao_mcp_service.{h,cc}`, `ui/webui/dao_sidebar_ui.{h,cc}`, `resources/sidebar/{dao_tab_item.ts,sidebar_bridge.ts}`, `dao_agent_ui.{h,cc}`, `pi_tool_adapter.ts` | 🔴 | Run `DaoMcpApprovalDialogTest.*`, `DaoMcpControlBannerTest.*`, `DaoMcpPeerLeaseTest.*`, `tab_item.test.ts`, `pi_tool_adapter.test.ts`, and `dao_chat_view.test.ts`; verify serialized localized prompts with reported client/version, browser-recorded localized request date/time with time zone, sanitized client-provided reason, window, and Profile rendering, preserved reason/time while queued, and bounded scrolling for long reasons, exact native Browser activation when a prompt arrives behind another application, the 60-second unanswered-request timeout, no default Allow action, deny/close/parent destruction exactly once and fail closed, address-bar robot visibility only for the active controlled tab in the authorized normal Browser, a sidebar robot for every controlled tab with the close action revealed on pointer hover or keyboard focus without layout shift, prompt target add/removal updates after switch/open, popup client/target/latest accepted tool/count details with live call updates, no process-ID row in approval dialogs or control popups, no extra page-content row, clickable per-connection Stop, lease release/disconnect transitions without disturbing other clients, chat continuity, different-tab parallelism, and same-tab pre-CDP `AGENT_CONTROL_BUSY` browser-tool failures |
| ☐ | MCP isolated-target eligibility and lifecycle | `automation/dao_browser_target_policy.{h,cc}`, `mcp/dao_mcp_session_lifecycle_monitor.{h,cc}`, `dao_mcp_end_to_end_browsertest.cc`, `dao_mcp_service.{h,cc}` | 🔴 | Run `DaoMcpEndToEndBrowserTest.*` and the lifecycle filters in `DaoMcpServiceBrowserTest.*`; verify HTTP/HTTPS/literal blank/web-hosted PDF allow, popup/OTR/Guest/internal/extension/DevTools/Agent WebUI/file/data/custom rejection for execution without blocking catalog discovery, exact-owner `TARGET_GONE`, no active-tab fallback, pre-mutation forbidden switch rejection, per-target cancellation and cleanup without disturbing sibling contexts, last-target/Browser/Profile terminal cleanup, no Ready/Disabled status during enabled logical closing, and connection-slot release only after the affected socket disconnects |
| ☐ | MCP startup, packaging, protocol, UI, and rebinding regression sweep | `browser_prefs_mcp.cc.patch`, `chrome_browser_main_extra_parts_profiles*.patch`, `chrome/BUILD_mcp_helper.gn.patch`, `mcp/`, `dao_mcp_approval_dialog.*`, `dao_mcp_control_banner_view.*`, `dao_address_bar_view.*`, Settings Dao page patches | 🔴 | After Chromium upgrades, verify Local State registration and clean startup/shutdown, owner-only Unix socket/metadata plus helper executable packaging, protocol framing/version/8 MiB and ingress/write bounds, per-tab DevTools attach/cancel/detach, approval and address-bar indicator/popup layout, Settings switch/status/enabled-only quick setup/Copy/Stop, stable tab identity across reorder/restore/WebContents replacement, optional `tab_id` routing, and complete target rebinding/cleanup |
Expand Down
Loading
Loading