返回 DeepSeek-Reasonix
BROWSER_RUNTIME_UPGRADE.md
根目录 / docs / BROWSER_RUNTIME_UPGRADE.md
1 # Browser runtime upgrade / 浏览器运行时升级
2
3 ## Contract / 契约
4
5 Go owns task/session grants, cancellation, write outcomes and artifact delivery.
6 Electron owns pages, document epochs, viewport revisions and rendering leases.
7 The independently built page runtime owns DOM observations. React owns presentation
8 intent and unsent drafts; it never infers readiness from visibility.
9
10 Go 管理任务授权、取消、写入结果及产物;Electron 管理页面、文档代际、视口与渲染租约;
11 独立构建的页面脚本管理 DOM 观察;React 只管理展示意图与草稿。
12
13 Async results revalidate grant generation, task/session, tab/page identity, document
14 epoch and viewport revision. Takeover, cancellation and shutdown release only
15 their own resources. Unknown writes are never replayed. Shared/temporary login
16 partitions and the existing provider-visible tool schemas remain unchanged.
17
18 异步结果重新校验授权代际、任务/会话、标签/页面身份、文档代际及视口版本;接管和取消只释放
19 自身资源;未知写入不得重放。登录分区及现有模型工具 schema 保持不变。
20
21 ## Delivery / 交付顺序
22
23 1. P0: independent page bundle, PNG validation at both boundaries, structured errors
24 and production-bundle regression. 独立页面脚本、双端图片校验和生产构建回归。
25 2. P1: same-page background rendering leases, cancellation, identity validation and
26 first-open presentation without focus stealing. 同页面后台渲染、取消和首次展示。
27 3. P2: semantic observation/query/wait, responsive viewports, operation feedback,
28 element attachments and bounded diagnostics. 语义定位、响应式、元素附件和诊断。
29 4. P3: bounded WebM recording, lazy tab recovery, tab limits and negotiated remote
30 capabilities. 有界录制、懒恢复、资源限制和远程协商。
31
32 ## Acceptance / 验收
33
34 No empty, invalid, stale or mismatched image is a successful artifact. Capture
35 preparation proves a nonzero compositor surface within five seconds. Temporary
36 capture layout never persists preferences. Current-task first open reveals the pane;
37 dismissal suppresses reopening in that turn. New tools are on-demand. Recording
38 defaults to silent 25 fps/20 seconds, capped at 90 seconds/64 MiB, one per app.
39 Recovery stores navigation metadata, not forms, grants, refs or pending writes.
40 At most 32 logical tabs per window; live pages are not silently evicted.
41
42 空图、损坏图、过期图及尺寸不符均返回失败;准备渲染最多五秒且验证原生表面。临时布局不写
43 偏好。当前任务首次打开显示面板,本轮手动关闭后不重开。录制默认无声、25 帧、20 秒,上限
44 90 秒与 64 MiB。恢复不保存表单、授权、引用或待执行操作。每窗口最多 32 个标签。
45
46 Production-bundle and native tests cover open/snapshot/input/capture, background
47 and hidden windows, takeover, cancellation, delayed replies and resource cleanup.
48 Unit tests, hosted CI and native package/platform evidence are reported separately.
49 Unqualified platforms return a clear background-capture error, never steal focus.
50
51 生产与原生验证覆盖完整工具链、后台和隐藏窗口、接管、取消、迟到回执及清理。单测、CI 和
52 原生平台证据分别报告;未经验证的平台明确拒绝后台捕获,不抢焦点。
53
54 ## Implementation evidence / 实施证据(2026-09-21)
55
56 - P0: production-minified host executes the packaged page bundle in a clean
57 JavaScript realm; no injected bundler helper. PNG validation precedes publication
58 in Electron and model delivery in Go. Packager requires both runtime resources.
59 - P1 in progress: same-WebContents native capture lease, serialized capture queue,
60 deadline/cancel propagation, grant revocation and document/viewport revalidation.
61 Foreground-turn first-open subscription is independent of the lazy browser panel.
62 - Electron: 243 tests passed; TypeScript passed. Desktop Go browser tests and root
63 `internal/browser/...` passed. Native macOS/Electron 44.2.0 production-minification
64 smoke produced 1600×1200 PNG from an 800×600 hidden page, with unchanged page ID,
65 JS variable and input value; no focused window. This is not installed-package,
66 Windows/Linux, remote, recording, or vision-model acceptance evidence.
67 - Native reproducer: `cd desktop/electron && node scripts/browser-runtime-smoke.mjs`.
68 Background capture remains unavailable outside macOS pending native qualification.
69 - P2/P3 and the remaining P1 acceptance cases are not completed by the above tests.
70
70 lines MARKDOWN