feat(cu): complete verified background semantic execution - #1263

Closed
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr
Closed

feat(cu): complete verified background semantic execution#1263
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Summary

  • execute observed AX semantic actions on visible background windows without foreground activation
  • bind press_key and other semantic mutations to the exact observed element identity and presentation center
  • allow covered, window-scoped zoom capture while preserving coordinate-input occlusion gates
  • add real Desktop qualification scenarios for covered zoom and background set_value → press_key → click_element flows
  • harden launcher ownership evidence for zoom and camelCase observation projections

Rebase status

PR1 (#1262) merged on 2026-07-20. This branch has been rebased onto current main, so the diff now contains only this PR's four commits.

Because #1262 landed as a squash merge, a plain git rebase main would have replayed PR1's commits against their own already-merged content. The rebase was therefore performed as:

git rebase --onto origin/main codex/cu-semantic-contract-pr codex/cu-background-qualified-pr

This applied cleanly with zero conflicts, and the resulting diff is byte-identical in scope to the pre-rebase delta (11 files, +552/-141).

Excluded scope

The old cursor-size experiments from the source worktree were deliberately excluded. Cursor visuals are handled separately by #1255.

Validation

Re-run after the rebase:

  • Biome lint and format across the touched packages — clean (409 / 456 files)
  • @maka/computer-use — 138/138 passed, including all six cua-driver suites (backend, release contract, service lifecycle, snapshot coordinate authority, AX hit testing)
  • npm run test:scripts — 121/121 passed, covering the four modified scripts
  • @maka/runtime — 2503/2512 passed. The two failures (macOS filesystem worker smoke, builtin Bash streaming output) are load-sensitive timing tests in files this PR does not touch; both pass on re-run under normal load (55/55).

Carried over from before the rebase (code unchanged by the rebase, so these remain applicable):

  • real Desktop qualification for covered zoom and background set_valuepress_keyclick_element

Not re-run after the rebase: the real-machine qualification above. CI is expected to cover the automated surface.

@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 0d71cba to 1a02146CompareJuly 20, 2026 12:12
@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 1a02146 to 20990b4CompareJuly 25, 2026 16:55
@hqhq1025
hqhq1025 marked this pull request as ready for review July 25, 2026 16:56

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One more P2 is not inline because the description line was unchanged: the model-facing tool text still says press_key is disabled by default, while this PR makes element-bound press_key a required successful action in the L2 scenario. Update the description and add a contract assertion.

The new scenario labels for focus and cursor safety and zoom crop also need evaluators. Today the validator checks the labels, not foreground pid, cursor movement, z-order, or crop coordinates.

@@ -1973,16 +1893,28 @@ export function createCuaDriverBackend(opts: CuaDriverBackendOptions): CuDispatc
);
if ('outcome' in validated) return validated;
if (action.type === 'press_key') {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] This branch removed both physicalInputFailure() and the compatibility gate, but the pinned driver implements press_key by focusing the AX element and posting a keyboard CGEvent to the target pid. A user typing at the same time can still be interrupted or redirected. Restore the physical-input fence before dispatch; the current test even sets physicalInputRecentlyActive: () => true and expects success, so it locks in the unsafe behavior.

tool: 'press_key',
pid: validated.pid,
windowId: validated.windowId,
address: 'ax',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] address: 'ax' is not the driver's evidence. The pinned driver returns path: 'key_events', verified: false, effect: 'unverifiable' for press_key; hard-coding AX lets a CGEvent path satisfy the provider matrix's safe-dispatch gate. Derive the trace address from the normalized driver result and keep this path out of AX qualification.

return deliveredVerificationFailure(action.type, 'ax');
}
if (action.type === 'set_value') {
const exactIndexElement = fresh.elements.find(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] element_index belongs to one snapshot and can be reassigned after the AX tree changes. Preferring the same numeric index in the fresh snapshot can verify a different element with the same role and label, even when the original target did not change. Match a stable identity, or require a unique role, label, and frame match and return outcome_unknown when identity cannot be proven.

: matchingElements.length === 1
? matchingElements[0]
: undefined;
if (!readbackElement || readbackElement.value !== action.value) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This equality makes valid writes unverifiable for supported inputs. Empty AX text values are omitted from the structured snapshot, and numeric slider or stepper values are not exposed as strings, so a successful clear or numeric set always becomes outcome_unknown. Use target-specific readback that distinguishes empty, numeric, and unreadable values, or reject roles that cannot be verified before delivery.

{ ...context, boundAction: boundElementAction(observation, '7') },
);

assert.equal(result.outcome.ok, true);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This test double reports evidence the pinned driver never returns for press_key: ax/verified/confirmed instead of key_events/unverifiable. It also never asserts the normalized tier or evidence, so the production contract can be wrong while this test stays green. Make the fixture return the pinned shape and assert the result and trace.

@hqhq1025
hqhq1025 marked this pull request as draft July 28, 2026 08:38
Review raised two P1s on this branch and both hold up against the driver's
actual behaviour.
**press_key is not an AX dispatch.** The trace hardcoded `address: 'ax'`
before the call even happened. Verified against cua-driver v0.12.6 with an
element-bound call, the driver returns:
{"effect": "unverifiable", "path": "key_events", "verified": false}
It resolves the element through AX and then posts keyboard CGEvents to the
pid. Labelling that as AX let a synthetic key path pass the safe-dispatch
gate that exists to keep pixel/event delivery out of AX qualification. The
trace address is now derived from the driver's own evidence, and the
delivered-but-unverified path reports `key_events` instead of `ax`.
**The physical-input fence still applies to it.** This branch removed the
fence for the whole semantic path. That is correct for `click_element` and
`set_value`, which are pure AX mutations, but not for `press_key`: keyboard
CGEvents interleave with — and can be redirected by — a user typing at the
same time. Element-bound addressing does not remove that hazard. The fence
is restored on this path only.
The test that pinned the old behaviour asserted success with
`physicalInputRecentlyActive: () => true`, welding the unsafe behaviour in
place. It now asserts the opposite, and a second test covers the trace
address. The test double also returned `path: 'ax', verified: true,
effect: 'confirmed'` for press_key — values the real driver never emits —
so it now mirrors the verified response.
Verified: `cua-driver-backend` suite 91 passed, 0 failed.
@hqhq1025hqhq1025 closed this Aug 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(cu): complete verified background semantic execution - #1263

Closed
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr
Closed

feat(cu): complete verified background semantic execution#1263
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Summary

  • execute observed AX semantic actions on visible background windows without foreground activation
  • bind press_key and other semantic mutations to the exact observed element identity and presentation center
  • allow covered, window-scoped zoom capture while preserving coordinate-input occlusion gates
  • add real Desktop qualification scenarios for covered zoom and background set_value → press_key → click_element flows
  • harden launcher ownership evidence for zoom and camelCase observation projections

Rebase status

PR1 (#1262) merged on 2026-07-20. This branch has been rebased onto current main, so the diff now contains only this PR's four commits.

Because #1262 landed as a squash merge, a plain git rebase main would have replayed PR1's commits against their own already-merged content. The rebase was therefore performed as:

git rebase --onto origin/main codex/cu-semantic-contract-pr codex/cu-background-qualified-pr

This applied cleanly with zero conflicts, and the resulting diff is byte-identical in scope to the pre-rebase delta (11 files, +552/-141).

Excluded scope

The old cursor-size experiments from the source worktree were deliberately excluded. Cursor visuals are handled separately by #1255.

Validation

Re-run after the rebase:

  • Biome lint and format across the touched packages — clean (409 / 456 files)
  • @maka/computer-use — 138/138 passed, including all six cua-driver suites (backend, release contract, service lifecycle, snapshot coordinate authority, AX hit testing)
  • npm run test:scripts — 121/121 passed, covering the four modified scripts
  • @maka/runtime — 2503/2512 passed. The two failures (macOS filesystem worker smoke, builtin Bash streaming output) are load-sensitive timing tests in files this PR does not touch; both pass on re-run under normal load (55/55).

Carried over from before the rebase (code unchanged by the rebase, so these remain applicable):

  • real Desktop qualification for covered zoom and background set_valuepress_keyclick_element

Not re-run after the rebase: the real-machine qualification above. CI is expected to cover the automated surface.

@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 0d71cba to 1a02146CompareJuly 20, 2026 12:12
@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 1a02146 to 20990b4CompareJuly 25, 2026 16:55
@hqhq1025
hqhq1025 marked this pull request as ready for review July 25, 2026 16:56

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One more P2 is not inline because the description line was unchanged: the model-facing tool text still says press_key is disabled by default, while this PR makes element-bound press_key a required successful action in the L2 scenario. Update the description and add a contract assertion.

The new scenario labels for focus and cursor safety and zoom crop also need evaluators. Today the validator checks the labels, not foreground pid, cursor movement, z-order, or crop coordinates.

@@ -1973,16 +1893,28 @@ export function createCuaDriverBackend(opts: CuaDriverBackendOptions): CuDispatc
);
if ('outcome' in validated) return validated;
if (action.type === 'press_key') {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] This branch removed both physicalInputFailure() and the compatibility gate, but the pinned driver implements press_key by focusing the AX element and posting a keyboard CGEvent to the target pid. A user typing at the same time can still be interrupted or redirected. Restore the physical-input fence before dispatch; the current test even sets physicalInputRecentlyActive: () => true and expects success, so it locks in the unsafe behavior.

tool: 'press_key',
pid: validated.pid,
windowId: validated.windowId,
address: 'ax',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] address: 'ax' is not the driver's evidence. The pinned driver returns path: 'key_events', verified: false, effect: 'unverifiable' for press_key; hard-coding AX lets a CGEvent path satisfy the provider matrix's safe-dispatch gate. Derive the trace address from the normalized driver result and keep this path out of AX qualification.

return deliveredVerificationFailure(action.type, 'ax');
}
if (action.type === 'set_value') {
const exactIndexElement = fresh.elements.find(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] element_index belongs to one snapshot and can be reassigned after the AX tree changes. Preferring the same numeric index in the fresh snapshot can verify a different element with the same role and label, even when the original target did not change. Match a stable identity, or require a unique role, label, and frame match and return outcome_unknown when identity cannot be proven.

: matchingElements.length === 1
? matchingElements[0]
: undefined;
if (!readbackElement || readbackElement.value !== action.value) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This equality makes valid writes unverifiable for supported inputs. Empty AX text values are omitted from the structured snapshot, and numeric slider or stepper values are not exposed as strings, so a successful clear or numeric set always becomes outcome_unknown. Use target-specific readback that distinguishes empty, numeric, and unreadable values, or reject roles that cannot be verified before delivery.

{ ...context, boundAction: boundElementAction(observation, '7') },
);

assert.equal(result.outcome.ok, true);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This test double reports evidence the pinned driver never returns for press_key: ax/verified/confirmed instead of key_events/unverifiable. It also never asserts the normalized tier or evidence, so the production contract can be wrong while this test stays green. Make the fixture return the pinned shape and assert the result and trace.

@hqhq1025
hqhq1025 marked this pull request as draft July 28, 2026 08:38
Review raised two P1s on this branch and both hold up against the driver's
actual behaviour.
**press_key is not an AX dispatch.** The trace hardcoded `address: 'ax'`
before the call even happened. Verified against cua-driver v0.12.6 with an
element-bound call, the driver returns:
{"effect": "unverifiable", "path": "key_events", "verified": false}
It resolves the element through AX and then posts keyboard CGEvents to the
pid. Labelling that as AX let a synthetic key path pass the safe-dispatch
gate that exists to keep pixel/event delivery out of AX qualification. The
trace address is now derived from the driver's own evidence, and the
delivered-but-unverified path reports `key_events` instead of `ax`.
**The physical-input fence still applies to it.** This branch removed the
fence for the whole semantic path. That is correct for `click_element` and
`set_value`, which are pure AX mutations, but not for `press_key`: keyboard
CGEvents interleave with — and can be redirected by — a user typing at the
same time. Element-bound addressing does not remove that hazard. The fence
is restored on this path only.
The test that pinned the old behaviour asserted success with
`physicalInputRecentlyActive: () => true`, welding the unsafe behaviour in
place. It now asserts the opposite, and a second test covers the trace
address. The test double also returned `path: 'ax', verified: true,
effect: 'confirmed'` for press_key — values the real driver never emits —
so it now mirrors the verified response.
Verified: `cua-driver-backend` suite 91 passed, 0 failed.
@hqhq1025hqhq1025 closed this Aug 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(cu): complete verified background semantic execution - #1263

Closed
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr
Closed

feat(cu): complete verified background semantic execution#1263
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Summary

  • execute observed AX semantic actions on visible background windows without foreground activation
  • bind press_key and other semantic mutations to the exact observed element identity and presentation center
  • allow covered, window-scoped zoom capture while preserving coordinate-input occlusion gates
  • add real Desktop qualification scenarios for covered zoom and background set_value → press_key → click_element flows
  • harden launcher ownership evidence for zoom and camelCase observation projections

Rebase status

PR1 (#1262) merged on 2026-07-20. This branch has been rebased onto current main, so the diff now contains only this PR's four commits.

Because #1262 landed as a squash merge, a plain git rebase main would have replayed PR1's commits against their own already-merged content. The rebase was therefore performed as:

git rebase --onto origin/main codex/cu-semantic-contract-pr codex/cu-background-qualified-pr

This applied cleanly with zero conflicts, and the resulting diff is byte-identical in scope to the pre-rebase delta (11 files, +552/-141).

Excluded scope

The old cursor-size experiments from the source worktree were deliberately excluded. Cursor visuals are handled separately by #1255.

Validation

Re-run after the rebase:

  • Biome lint and format across the touched packages — clean (409 / 456 files)
  • @maka/computer-use — 138/138 passed, including all six cua-driver suites (backend, release contract, service lifecycle, snapshot coordinate authority, AX hit testing)
  • npm run test:scripts — 121/121 passed, covering the four modified scripts
  • @maka/runtime — 2503/2512 passed. The two failures (macOS filesystem worker smoke, builtin Bash streaming output) are load-sensitive timing tests in files this PR does not touch; both pass on re-run under normal load (55/55).

Carried over from before the rebase (code unchanged by the rebase, so these remain applicable):

  • real Desktop qualification for covered zoom and background set_valuepress_keyclick_element

Not re-run after the rebase: the real-machine qualification above. CI is expected to cover the automated surface.

@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 0d71cba to 1a02146CompareJuly 20, 2026 12:12
@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 1a02146 to 20990b4CompareJuly 25, 2026 16:55
@hqhq1025
hqhq1025 marked this pull request as ready for review July 25, 2026 16:56

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One more P2 is not inline because the description line was unchanged: the model-facing tool text still says press_key is disabled by default, while this PR makes element-bound press_key a required successful action in the L2 scenario. Update the description and add a contract assertion.

The new scenario labels for focus and cursor safety and zoom crop also need evaluators. Today the validator checks the labels, not foreground pid, cursor movement, z-order, or crop coordinates.

@@ -1973,16 +1893,28 @@ export function createCuaDriverBackend(opts: CuaDriverBackendOptions): CuDispatc
);
if ('outcome' in validated) return validated;
if (action.type === 'press_key') {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] This branch removed both physicalInputFailure() and the compatibility gate, but the pinned driver implements press_key by focusing the AX element and posting a keyboard CGEvent to the target pid. A user typing at the same time can still be interrupted or redirected. Restore the physical-input fence before dispatch; the current test even sets physicalInputRecentlyActive: () => true and expects success, so it locks in the unsafe behavior.

tool: 'press_key',
pid: validated.pid,
windowId: validated.windowId,
address: 'ax',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] address: 'ax' is not the driver's evidence. The pinned driver returns path: 'key_events', verified: false, effect: 'unverifiable' for press_key; hard-coding AX lets a CGEvent path satisfy the provider matrix's safe-dispatch gate. Derive the trace address from the normalized driver result and keep this path out of AX qualification.

return deliveredVerificationFailure(action.type, 'ax');
}
if (action.type === 'set_value') {
const exactIndexElement = fresh.elements.find(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] element_index belongs to one snapshot and can be reassigned after the AX tree changes. Preferring the same numeric index in the fresh snapshot can verify a different element with the same role and label, even when the original target did not change. Match a stable identity, or require a unique role, label, and frame match and return outcome_unknown when identity cannot be proven.

: matchingElements.length === 1
? matchingElements[0]
: undefined;
if (!readbackElement || readbackElement.value !== action.value) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This equality makes valid writes unverifiable for supported inputs. Empty AX text values are omitted from the structured snapshot, and numeric slider or stepper values are not exposed as strings, so a successful clear or numeric set always becomes outcome_unknown. Use target-specific readback that distinguishes empty, numeric, and unreadable values, or reject roles that cannot be verified before delivery.

{ ...context, boundAction: boundElementAction(observation, '7') },
);

assert.equal(result.outcome.ok, true);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This test double reports evidence the pinned driver never returns for press_key: ax/verified/confirmed instead of key_events/unverifiable. It also never asserts the normalized tier or evidence, so the production contract can be wrong while this test stays green. Make the fixture return the pinned shape and assert the result and trace.

@hqhq1025
hqhq1025 marked this pull request as draft July 28, 2026 08:38
Review raised two P1s on this branch and both hold up against the driver's
actual behaviour.
**press_key is not an AX dispatch.** The trace hardcoded `address: 'ax'`
before the call even happened. Verified against cua-driver v0.12.6 with an
element-bound call, the driver returns:
{"effect": "unverifiable", "path": "key_events", "verified": false}
It resolves the element through AX and then posts keyboard CGEvents to the
pid. Labelling that as AX let a synthetic key path pass the safe-dispatch
gate that exists to keep pixel/event delivery out of AX qualification. The
trace address is now derived from the driver's own evidence, and the
delivered-but-unverified path reports `key_events` instead of `ax`.
**The physical-input fence still applies to it.** This branch removed the
fence for the whole semantic path. That is correct for `click_element` and
`set_value`, which are pure AX mutations, but not for `press_key`: keyboard
CGEvents interleave with — and can be redirected by — a user typing at the
same time. Element-bound addressing does not remove that hazard. The fence
is restored on this path only.
The test that pinned the old behaviour asserted success with
`physicalInputRecentlyActive: () => true`, welding the unsafe behaviour in
place. It now asserts the opposite, and a second test covers the trace
address. The test double also returned `path: 'ax', verified: true,
effect: 'confirmed'` for press_key — values the real driver never emits —
so it now mirrors the verified response.
Verified: `cua-driver-backend` suite 91 passed, 0 failed.
@hqhq1025hqhq1025 closed this Aug 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(cu): complete verified background semantic execution - #1263

Closed
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr
Closed

feat(cu): complete verified background semantic execution#1263
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Summary

  • execute observed AX semantic actions on visible background windows without foreground activation
  • bind press_key and other semantic mutations to the exact observed element identity and presentation center
  • allow covered, window-scoped zoom capture while preserving coordinate-input occlusion gates
  • add real Desktop qualification scenarios for covered zoom and background set_value → press_key → click_element flows
  • harden launcher ownership evidence for zoom and camelCase observation projections

Rebase status

PR1 (#1262) merged on 2026-07-20. This branch has been rebased onto current main, so the diff now contains only this PR's four commits.

Because #1262 landed as a squash merge, a plain git rebase main would have replayed PR1's commits against their own already-merged content. The rebase was therefore performed as:

git rebase --onto origin/main codex/cu-semantic-contract-pr codex/cu-background-qualified-pr

This applied cleanly with zero conflicts, and the resulting diff is byte-identical in scope to the pre-rebase delta (11 files, +552/-141).

Excluded scope

The old cursor-size experiments from the source worktree were deliberately excluded. Cursor visuals are handled separately by #1255.

Validation

Re-run after the rebase:

  • Biome lint and format across the touched packages — clean (409 / 456 files)
  • @maka/computer-use — 138/138 passed, including all six cua-driver suites (backend, release contract, service lifecycle, snapshot coordinate authority, AX hit testing)
  • npm run test:scripts — 121/121 passed, covering the four modified scripts
  • @maka/runtime — 2503/2512 passed. The two failures (macOS filesystem worker smoke, builtin Bash streaming output) are load-sensitive timing tests in files this PR does not touch; both pass on re-run under normal load (55/55).

Carried over from before the rebase (code unchanged by the rebase, so these remain applicable):

  • real Desktop qualification for covered zoom and background set_valuepress_keyclick_element

Not re-run after the rebase: the real-machine qualification above. CI is expected to cover the automated surface.

@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 0d71cba to 1a02146CompareJuly 20, 2026 12:12
@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 1a02146 to 20990b4CompareJuly 25, 2026 16:55
@hqhq1025
hqhq1025 marked this pull request as ready for review July 25, 2026 16:56

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One more P2 is not inline because the description line was unchanged: the model-facing tool text still says press_key is disabled by default, while this PR makes element-bound press_key a required successful action in the L2 scenario. Update the description and add a contract assertion.

The new scenario labels for focus and cursor safety and zoom crop also need evaluators. Today the validator checks the labels, not foreground pid, cursor movement, z-order, or crop coordinates.

@@ -1973,16 +1893,28 @@ export function createCuaDriverBackend(opts: CuaDriverBackendOptions): CuDispatc
);
if ('outcome' in validated) return validated;
if (action.type === 'press_key') {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] This branch removed both physicalInputFailure() and the compatibility gate, but the pinned driver implements press_key by focusing the AX element and posting a keyboard CGEvent to the target pid. A user typing at the same time can still be interrupted or redirected. Restore the physical-input fence before dispatch; the current test even sets physicalInputRecentlyActive: () => true and expects success, so it locks in the unsafe behavior.

tool: 'press_key',
pid: validated.pid,
windowId: validated.windowId,
address: 'ax',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] address: 'ax' is not the driver's evidence. The pinned driver returns path: 'key_events', verified: false, effect: 'unverifiable' for press_key; hard-coding AX lets a CGEvent path satisfy the provider matrix's safe-dispatch gate. Derive the trace address from the normalized driver result and keep this path out of AX qualification.

return deliveredVerificationFailure(action.type, 'ax');
}
if (action.type === 'set_value') {
const exactIndexElement = fresh.elements.find(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] element_index belongs to one snapshot and can be reassigned after the AX tree changes. Preferring the same numeric index in the fresh snapshot can verify a different element with the same role and label, even when the original target did not change. Match a stable identity, or require a unique role, label, and frame match and return outcome_unknown when identity cannot be proven.

: matchingElements.length === 1
? matchingElements[0]
: undefined;
if (!readbackElement || readbackElement.value !== action.value) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This equality makes valid writes unverifiable for supported inputs. Empty AX text values are omitted from the structured snapshot, and numeric slider or stepper values are not exposed as strings, so a successful clear or numeric set always becomes outcome_unknown. Use target-specific readback that distinguishes empty, numeric, and unreadable values, or reject roles that cannot be verified before delivery.

{ ...context, boundAction: boundElementAction(observation, '7') },
);

assert.equal(result.outcome.ok, true);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This test double reports evidence the pinned driver never returns for press_key: ax/verified/confirmed instead of key_events/unverifiable. It also never asserts the normalized tier or evidence, so the production contract can be wrong while this test stays green. Make the fixture return the pinned shape and assert the result and trace.

@hqhq1025
hqhq1025 marked this pull request as draft July 28, 2026 08:38
Review raised two P1s on this branch and both hold up against the driver's
actual behaviour.
**press_key is not an AX dispatch.** The trace hardcoded `address: 'ax'`
before the call even happened. Verified against cua-driver v0.12.6 with an
element-bound call, the driver returns:
{"effect": "unverifiable", "path": "key_events", "verified": false}
It resolves the element through AX and then posts keyboard CGEvents to the
pid. Labelling that as AX let a synthetic key path pass the safe-dispatch
gate that exists to keep pixel/event delivery out of AX qualification. The
trace address is now derived from the driver's own evidence, and the
delivered-but-unverified path reports `key_events` instead of `ax`.
**The physical-input fence still applies to it.** This branch removed the
fence for the whole semantic path. That is correct for `click_element` and
`set_value`, which are pure AX mutations, but not for `press_key`: keyboard
CGEvents interleave with — and can be redirected by — a user typing at the
same time. Element-bound addressing does not remove that hazard. The fence
is restored on this path only.
The test that pinned the old behaviour asserted success with
`physicalInputRecentlyActive: () => true`, welding the unsafe behaviour in
place. It now asserts the opposite, and a second test covers the trace
address. The test double also returned `path: 'ax', verified: true,
effect: 'confirmed'` for press_key — values the real driver never emits —
so it now mirrors the verified response.
Verified: `cua-driver-backend` suite 91 passed, 0 failed.
@hqhq1025hqhq1025 closed this Aug 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(cu): complete verified background semantic execution - #1263

Closed
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr
Closed

feat(cu): complete verified background semantic execution#1263
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Summary

  • execute observed AX semantic actions on visible background windows without foreground activation
  • bind press_key and other semantic mutations to the exact observed element identity and presentation center
  • allow covered, window-scoped zoom capture while preserving coordinate-input occlusion gates
  • add real Desktop qualification scenarios for covered zoom and background set_value → press_key → click_element flows
  • harden launcher ownership evidence for zoom and camelCase observation projections

Rebase status

PR1 (#1262) merged on 2026-07-20. This branch has been rebased onto current main, so the diff now contains only this PR's four commits.

Because #1262 landed as a squash merge, a plain git rebase main would have replayed PR1's commits against their own already-merged content. The rebase was therefore performed as:

git rebase --onto origin/main codex/cu-semantic-contract-pr codex/cu-background-qualified-pr

This applied cleanly with zero conflicts, and the resulting diff is byte-identical in scope to the pre-rebase delta (11 files, +552/-141).

Excluded scope

The old cursor-size experiments from the source worktree were deliberately excluded. Cursor visuals are handled separately by #1255.

Validation

Re-run after the rebase:

  • Biome lint and format across the touched packages — clean (409 / 456 files)
  • @maka/computer-use — 138/138 passed, including all six cua-driver suites (backend, release contract, service lifecycle, snapshot coordinate authority, AX hit testing)
  • npm run test:scripts — 121/121 passed, covering the four modified scripts
  • @maka/runtime — 2503/2512 passed. The two failures (macOS filesystem worker smoke, builtin Bash streaming output) are load-sensitive timing tests in files this PR does not touch; both pass on re-run under normal load (55/55).

Carried over from before the rebase (code unchanged by the rebase, so these remain applicable):

  • real Desktop qualification for covered zoom and background set_valuepress_keyclick_element

Not re-run after the rebase: the real-machine qualification above. CI is expected to cover the automated surface.

@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 0d71cba to 1a02146CompareJuly 20, 2026 12:12
@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 1a02146 to 20990b4CompareJuly 25, 2026 16:55
@hqhq1025
hqhq1025 marked this pull request as ready for review July 25, 2026 16:56

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One more P2 is not inline because the description line was unchanged: the model-facing tool text still says press_key is disabled by default, while this PR makes element-bound press_key a required successful action in the L2 scenario. Update the description and add a contract assertion.

The new scenario labels for focus and cursor safety and zoom crop also need evaluators. Today the validator checks the labels, not foreground pid, cursor movement, z-order, or crop coordinates.

@@ -1973,16 +1893,28 @@ export function createCuaDriverBackend(opts: CuaDriverBackendOptions): CuDispatc
);
if ('outcome' in validated) return validated;
if (action.type === 'press_key') {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] This branch removed both physicalInputFailure() and the compatibility gate, but the pinned driver implements press_key by focusing the AX element and posting a keyboard CGEvent to the target pid. A user typing at the same time can still be interrupted or redirected. Restore the physical-input fence before dispatch; the current test even sets physicalInputRecentlyActive: () => true and expects success, so it locks in the unsafe behavior.

tool: 'press_key',
pid: validated.pid,
windowId: validated.windowId,
address: 'ax',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] address: 'ax' is not the driver's evidence. The pinned driver returns path: 'key_events', verified: false, effect: 'unverifiable' for press_key; hard-coding AX lets a CGEvent path satisfy the provider matrix's safe-dispatch gate. Derive the trace address from the normalized driver result and keep this path out of AX qualification.

return deliveredVerificationFailure(action.type, 'ax');
}
if (action.type === 'set_value') {
const exactIndexElement = fresh.elements.find(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] element_index belongs to one snapshot and can be reassigned after the AX tree changes. Preferring the same numeric index in the fresh snapshot can verify a different element with the same role and label, even when the original target did not change. Match a stable identity, or require a unique role, label, and frame match and return outcome_unknown when identity cannot be proven.

: matchingElements.length === 1
? matchingElements[0]
: undefined;
if (!readbackElement || readbackElement.value !== action.value) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This equality makes valid writes unverifiable for supported inputs. Empty AX text values are omitted from the structured snapshot, and numeric slider or stepper values are not exposed as strings, so a successful clear or numeric set always becomes outcome_unknown. Use target-specific readback that distinguishes empty, numeric, and unreadable values, or reject roles that cannot be verified before delivery.

{ ...context, boundAction: boundElementAction(observation, '7') },
);

assert.equal(result.outcome.ok, true);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This test double reports evidence the pinned driver never returns for press_key: ax/verified/confirmed instead of key_events/unverifiable. It also never asserts the normalized tier or evidence, so the production contract can be wrong while this test stays green. Make the fixture return the pinned shape and assert the result and trace.

@hqhq1025
hqhq1025 marked this pull request as draft July 28, 2026 08:38
Review raised two P1s on this branch and both hold up against the driver's
actual behaviour.
**press_key is not an AX dispatch.** The trace hardcoded `address: 'ax'`
before the call even happened. Verified against cua-driver v0.12.6 with an
element-bound call, the driver returns:
{"effect": "unverifiable", "path": "key_events", "verified": false}
It resolves the element through AX and then posts keyboard CGEvents to the
pid. Labelling that as AX let a synthetic key path pass the safe-dispatch
gate that exists to keep pixel/event delivery out of AX qualification. The
trace address is now derived from the driver's own evidence, and the
delivered-but-unverified path reports `key_events` instead of `ax`.
**The physical-input fence still applies to it.** This branch removed the
fence for the whole semantic path. That is correct for `click_element` and
`set_value`, which are pure AX mutations, but not for `press_key`: keyboard
CGEvents interleave with — and can be redirected by — a user typing at the
same time. Element-bound addressing does not remove that hazard. The fence
is restored on this path only.
The test that pinned the old behaviour asserted success with
`physicalInputRecentlyActive: () => true`, welding the unsafe behaviour in
place. It now asserts the opposite, and a second test covers the trace
address. The test double also returned `path: 'ax', verified: true,
effect: 'confirmed'` for press_key — values the real driver never emits —
so it now mirrors the verified response.
Verified: `cua-driver-backend` suite 91 passed, 0 failed.
@hqhq1025hqhq1025 closed this Aug 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(cu): complete verified background semantic execution - #1263

Closed
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr
Closed

feat(cu): complete verified background semantic execution#1263
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Summary

  • execute observed AX semantic actions on visible background windows without foreground activation
  • bind press_key and other semantic mutations to the exact observed element identity and presentation center
  • allow covered, window-scoped zoom capture while preserving coordinate-input occlusion gates
  • add real Desktop qualification scenarios for covered zoom and background set_value → press_key → click_element flows
  • harden launcher ownership evidence for zoom and camelCase observation projections

Rebase status

PR1 (#1262) merged on 2026-07-20. This branch has been rebased onto current main, so the diff now contains only this PR's four commits.

Because #1262 landed as a squash merge, a plain git rebase main would have replayed PR1's commits against their own already-merged content. The rebase was therefore performed as:

git rebase --onto origin/main codex/cu-semantic-contract-pr codex/cu-background-qualified-pr

This applied cleanly with zero conflicts, and the resulting diff is byte-identical in scope to the pre-rebase delta (11 files, +552/-141).

Excluded scope

The old cursor-size experiments from the source worktree were deliberately excluded. Cursor visuals are handled separately by #1255.

Validation

Re-run after the rebase:

  • Biome lint and format across the touched packages — clean (409 / 456 files)
  • @maka/computer-use — 138/138 passed, including all six cua-driver suites (backend, release contract, service lifecycle, snapshot coordinate authority, AX hit testing)
  • npm run test:scripts — 121/121 passed, covering the four modified scripts
  • @maka/runtime — 2503/2512 passed. The two failures (macOS filesystem worker smoke, builtin Bash streaming output) are load-sensitive timing tests in files this PR does not touch; both pass on re-run under normal load (55/55).

Carried over from before the rebase (code unchanged by the rebase, so these remain applicable):

  • real Desktop qualification for covered zoom and background set_valuepress_keyclick_element

Not re-run after the rebase: the real-machine qualification above. CI is expected to cover the automated surface.

@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 0d71cba to 1a02146CompareJuly 20, 2026 12:12
@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 1a02146 to 20990b4CompareJuly 25, 2026 16:55
@hqhq1025
hqhq1025 marked this pull request as ready for review July 25, 2026 16:56

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One more P2 is not inline because the description line was unchanged: the model-facing tool text still says press_key is disabled by default, while this PR makes element-bound press_key a required successful action in the L2 scenario. Update the description and add a contract assertion.

The new scenario labels for focus and cursor safety and zoom crop also need evaluators. Today the validator checks the labels, not foreground pid, cursor movement, z-order, or crop coordinates.

@@ -1973,16 +1893,28 @@ export function createCuaDriverBackend(opts: CuaDriverBackendOptions): CuDispatc
);
if ('outcome' in validated) return validated;
if (action.type === 'press_key') {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] This branch removed both physicalInputFailure() and the compatibility gate, but the pinned driver implements press_key by focusing the AX element and posting a keyboard CGEvent to the target pid. A user typing at the same time can still be interrupted or redirected. Restore the physical-input fence before dispatch; the current test even sets physicalInputRecentlyActive: () => true and expects success, so it locks in the unsafe behavior.

tool: 'press_key',
pid: validated.pid,
windowId: validated.windowId,
address: 'ax',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] address: 'ax' is not the driver's evidence. The pinned driver returns path: 'key_events', verified: false, effect: 'unverifiable' for press_key; hard-coding AX lets a CGEvent path satisfy the provider matrix's safe-dispatch gate. Derive the trace address from the normalized driver result and keep this path out of AX qualification.

return deliveredVerificationFailure(action.type, 'ax');
}
if (action.type === 'set_value') {
const exactIndexElement = fresh.elements.find(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] element_index belongs to one snapshot and can be reassigned after the AX tree changes. Preferring the same numeric index in the fresh snapshot can verify a different element with the same role and label, even when the original target did not change. Match a stable identity, or require a unique role, label, and frame match and return outcome_unknown when identity cannot be proven.

: matchingElements.length === 1
? matchingElements[0]
: undefined;
if (!readbackElement || readbackElement.value !== action.value) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This equality makes valid writes unverifiable for supported inputs. Empty AX text values are omitted from the structured snapshot, and numeric slider or stepper values are not exposed as strings, so a successful clear or numeric set always becomes outcome_unknown. Use target-specific readback that distinguishes empty, numeric, and unreadable values, or reject roles that cannot be verified before delivery.

{ ...context, boundAction: boundElementAction(observation, '7') },
);

assert.equal(result.outcome.ok, true);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This test double reports evidence the pinned driver never returns for press_key: ax/verified/confirmed instead of key_events/unverifiable. It also never asserts the normalized tier or evidence, so the production contract can be wrong while this test stays green. Make the fixture return the pinned shape and assert the result and trace.

@hqhq1025
hqhq1025 marked this pull request as draft July 28, 2026 08:38
Review raised two P1s on this branch and both hold up against the driver's
actual behaviour.
**press_key is not an AX dispatch.** The trace hardcoded `address: 'ax'`
before the call even happened. Verified against cua-driver v0.12.6 with an
element-bound call, the driver returns:
{"effect": "unverifiable", "path": "key_events", "verified": false}
It resolves the element through AX and then posts keyboard CGEvents to the
pid. Labelling that as AX let a synthetic key path pass the safe-dispatch
gate that exists to keep pixel/event delivery out of AX qualification. The
trace address is now derived from the driver's own evidence, and the
delivered-but-unverified path reports `key_events` instead of `ax`.
**The physical-input fence still applies to it.** This branch removed the
fence for the whole semantic path. That is correct for `click_element` and
`set_value`, which are pure AX mutations, but not for `press_key`: keyboard
CGEvents interleave with — and can be redirected by — a user typing at the
same time. Element-bound addressing does not remove that hazard. The fence
is restored on this path only.
The test that pinned the old behaviour asserted success with
`physicalInputRecentlyActive: () => true`, welding the unsafe behaviour in
place. It now asserts the opposite, and a second test covers the trace
address. The test double also returned `path: 'ax', verified: true,
effect: 'confirmed'` for press_key — values the real driver never emits —
so it now mirrors the verified response.
Verified: `cua-driver-backend` suite 91 passed, 0 failed.
@hqhq1025hqhq1025 closed this Aug 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(cu): complete verified background semantic execution - #1263

Closed
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr
Closed

feat(cu): complete verified background semantic execution#1263
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Summary

  • execute observed AX semantic actions on visible background windows without foreground activation
  • bind press_key and other semantic mutations to the exact observed element identity and presentation center
  • allow covered, window-scoped zoom capture while preserving coordinate-input occlusion gates
  • add real Desktop qualification scenarios for covered zoom and background set_value → press_key → click_element flows
  • harden launcher ownership evidence for zoom and camelCase observation projections

Rebase status

PR1 (#1262) merged on 2026-07-20. This branch has been rebased onto current main, so the diff now contains only this PR's four commits.

Because #1262 landed as a squash merge, a plain git rebase main would have replayed PR1's commits against their own already-merged content. The rebase was therefore performed as:

git rebase --onto origin/main codex/cu-semantic-contract-pr codex/cu-background-qualified-pr

This applied cleanly with zero conflicts, and the resulting diff is byte-identical in scope to the pre-rebase delta (11 files, +552/-141).

Excluded scope

The old cursor-size experiments from the source worktree were deliberately excluded. Cursor visuals are handled separately by #1255.

Validation

Re-run after the rebase:

  • Biome lint and format across the touched packages — clean (409 / 456 files)
  • @maka/computer-use — 138/138 passed, including all six cua-driver suites (backend, release contract, service lifecycle, snapshot coordinate authority, AX hit testing)
  • npm run test:scripts — 121/121 passed, covering the four modified scripts
  • @maka/runtime — 2503/2512 passed. The two failures (macOS filesystem worker smoke, builtin Bash streaming output) are load-sensitive timing tests in files this PR does not touch; both pass on re-run under normal load (55/55).

Carried over from before the rebase (code unchanged by the rebase, so these remain applicable):

  • real Desktop qualification for covered zoom and background set_valuepress_keyclick_element

Not re-run after the rebase: the real-machine qualification above. CI is expected to cover the automated surface.

@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 0d71cba to 1a02146CompareJuly 20, 2026 12:12
@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 1a02146 to 20990b4CompareJuly 25, 2026 16:55
@hqhq1025
hqhq1025 marked this pull request as ready for review July 25, 2026 16:56

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One more P2 is not inline because the description line was unchanged: the model-facing tool text still says press_key is disabled by default, while this PR makes element-bound press_key a required successful action in the L2 scenario. Update the description and add a contract assertion.

The new scenario labels for focus and cursor safety and zoom crop also need evaluators. Today the validator checks the labels, not foreground pid, cursor movement, z-order, or crop coordinates.

@@ -1973,16 +1893,28 @@ export function createCuaDriverBackend(opts: CuaDriverBackendOptions): CuDispatc
);
if ('outcome' in validated) return validated;
if (action.type === 'press_key') {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] This branch removed both physicalInputFailure() and the compatibility gate, but the pinned driver implements press_key by focusing the AX element and posting a keyboard CGEvent to the target pid. A user typing at the same time can still be interrupted or redirected. Restore the physical-input fence before dispatch; the current test even sets physicalInputRecentlyActive: () => true and expects success, so it locks in the unsafe behavior.

tool: 'press_key',
pid: validated.pid,
windowId: validated.windowId,
address: 'ax',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] address: 'ax' is not the driver's evidence. The pinned driver returns path: 'key_events', verified: false, effect: 'unverifiable' for press_key; hard-coding AX lets a CGEvent path satisfy the provider matrix's safe-dispatch gate. Derive the trace address from the normalized driver result and keep this path out of AX qualification.

return deliveredVerificationFailure(action.type, 'ax');
}
if (action.type === 'set_value') {
const exactIndexElement = fresh.elements.find(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] element_index belongs to one snapshot and can be reassigned after the AX tree changes. Preferring the same numeric index in the fresh snapshot can verify a different element with the same role and label, even when the original target did not change. Match a stable identity, or require a unique role, label, and frame match and return outcome_unknown when identity cannot be proven.

: matchingElements.length === 1
? matchingElements[0]
: undefined;
if (!readbackElement || readbackElement.value !== action.value) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This equality makes valid writes unverifiable for supported inputs. Empty AX text values are omitted from the structured snapshot, and numeric slider or stepper values are not exposed as strings, so a successful clear or numeric set always becomes outcome_unknown. Use target-specific readback that distinguishes empty, numeric, and unreadable values, or reject roles that cannot be verified before delivery.

{ ...context, boundAction: boundElementAction(observation, '7') },
);

assert.equal(result.outcome.ok, true);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This test double reports evidence the pinned driver never returns for press_key: ax/verified/confirmed instead of key_events/unverifiable. It also never asserts the normalized tier or evidence, so the production contract can be wrong while this test stays green. Make the fixture return the pinned shape and assert the result and trace.

@hqhq1025
hqhq1025 marked this pull request as draft July 28, 2026 08:38
Review raised two P1s on this branch and both hold up against the driver's
actual behaviour.
**press_key is not an AX dispatch.** The trace hardcoded `address: 'ax'`
before the call even happened. Verified against cua-driver v0.12.6 with an
element-bound call, the driver returns:
{"effect": "unverifiable", "path": "key_events", "verified": false}
It resolves the element through AX and then posts keyboard CGEvents to the
pid. Labelling that as AX let a synthetic key path pass the safe-dispatch
gate that exists to keep pixel/event delivery out of AX qualification. The
trace address is now derived from the driver's own evidence, and the
delivered-but-unverified path reports `key_events` instead of `ax`.
**The physical-input fence still applies to it.** This branch removed the
fence for the whole semantic path. That is correct for `click_element` and
`set_value`, which are pure AX mutations, but not for `press_key`: keyboard
CGEvents interleave with — and can be redirected by — a user typing at the
same time. Element-bound addressing does not remove that hazard. The fence
is restored on this path only.
The test that pinned the old behaviour asserted success with
`physicalInputRecentlyActive: () => true`, welding the unsafe behaviour in
place. It now asserts the opposite, and a second test covers the trace
address. The test double also returned `path: 'ax', verified: true,
effect: 'confirmed'` for press_key — values the real driver never emits —
so it now mirrors the verified response.
Verified: `cua-driver-backend` suite 91 passed, 0 failed.
@hqhq1025hqhq1025 closed this Aug 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(cu): complete verified background semantic execution - #1263

Closed
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr
Closed

feat(cu): complete verified background semantic execution#1263
hqhq1025 wants to merge 5 commits into
apache:mainfrom
hqhq1025:codex/cu-background-qualified-pr

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Summary

  • execute observed AX semantic actions on visible background windows without foreground activation
  • bind press_key and other semantic mutations to the exact observed element identity and presentation center
  • allow covered, window-scoped zoom capture while preserving coordinate-input occlusion gates
  • add real Desktop qualification scenarios for covered zoom and background set_value → press_key → click_element flows
  • harden launcher ownership evidence for zoom and camelCase observation projections

Rebase status

PR1 (#1262) merged on 2026-07-20. This branch has been rebased onto current main, so the diff now contains only this PR's four commits.

Because #1262 landed as a squash merge, a plain git rebase main would have replayed PR1's commits against their own already-merged content. The rebase was therefore performed as:

git rebase --onto origin/main codex/cu-semantic-contract-pr codex/cu-background-qualified-pr

This applied cleanly with zero conflicts, and the resulting diff is byte-identical in scope to the pre-rebase delta (11 files, +552/-141).

Excluded scope

The old cursor-size experiments from the source worktree were deliberately excluded. Cursor visuals are handled separately by #1255.

Validation

Re-run after the rebase:

  • Biome lint and format across the touched packages — clean (409 / 456 files)
  • @maka/computer-use — 138/138 passed, including all six cua-driver suites (backend, release contract, service lifecycle, snapshot coordinate authority, AX hit testing)
  • npm run test:scripts — 121/121 passed, covering the four modified scripts
  • @maka/runtime — 2503/2512 passed. The two failures (macOS filesystem worker smoke, builtin Bash streaming output) are load-sensitive timing tests in files this PR does not touch; both pass on re-run under normal load (55/55).

Carried over from before the rebase (code unchanged by the rebase, so these remain applicable):

  • real Desktop qualification for covered zoom and background set_valuepress_keyclick_element

Not re-run after the rebase: the real-machine qualification above. CI is expected to cover the automated surface.

@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 0d71cba to 1a02146CompareJuly 20, 2026 12:12
@hqhq1025
hqhq1025force-pushed the codex/cu-background-qualified-pr branch from 1a02146 to 20990b4CompareJuly 25, 2026 16:55
@hqhq1025
hqhq1025 marked this pull request as ready for review July 25, 2026 16:56

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One more P2 is not inline because the description line was unchanged: the model-facing tool text still says press_key is disabled by default, while this PR makes element-bound press_key a required successful action in the L2 scenario. Update the description and add a contract assertion.

The new scenario labels for focus and cursor safety and zoom crop also need evaluators. Today the validator checks the labels, not foreground pid, cursor movement, z-order, or crop coordinates.

@@ -1973,16 +1893,28 @@ export function createCuaDriverBackend(opts: CuaDriverBackendOptions): CuDispatc
);
if ('outcome' in validated) return validated;
if (action.type === 'press_key') {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] This branch removed both physicalInputFailure() and the compatibility gate, but the pinned driver implements press_key by focusing the AX element and posting a keyboard CGEvent to the target pid. A user typing at the same time can still be interrupted or redirected. Restore the physical-input fence before dispatch; the current test even sets physicalInputRecentlyActive: () => true and expects success, so it locks in the unsafe behavior.

tool: 'press_key',
pid: validated.pid,
windowId: validated.windowId,
address: 'ax',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] address: 'ax' is not the driver's evidence. The pinned driver returns path: 'key_events', verified: false, effect: 'unverifiable' for press_key; hard-coding AX lets a CGEvent path satisfy the provider matrix's safe-dispatch gate. Derive the trace address from the normalized driver result and keep this path out of AX qualification.

return deliveredVerificationFailure(action.type, 'ax');
}
if (action.type === 'set_value') {
const exactIndexElement = fresh.elements.find(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] element_index belongs to one snapshot and can be reassigned after the AX tree changes. Preferring the same numeric index in the fresh snapshot can verify a different element with the same role and label, even when the original target did not change. Match a stable identity, or require a unique role, label, and frame match and return outcome_unknown when identity cannot be proven.

: matchingElements.length === 1
? matchingElements[0]
: undefined;
if (!readbackElement || readbackElement.value !== action.value) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This equality makes valid writes unverifiable for supported inputs. Empty AX text values are omitted from the structured snapshot, and numeric slider or stepper values are not exposed as strings, so a successful clear or numeric set always becomes outcome_unknown. Use target-specific readback that distinguishes empty, numeric, and unreadable values, or reject roles that cannot be verified before delivery.

{ ...context, boundAction: boundElementAction(observation, '7') },
);

assert.equal(result.outcome.ok, true);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] This test double reports evidence the pinned driver never returns for press_key: ax/verified/confirmed instead of key_events/unverifiable. It also never asserts the normalized tier or evidence, so the production contract can be wrong while this test stays green. Make the fixture return the pinned shape and assert the result and trace.

@hqhq1025
hqhq1025 marked this pull request as draft July 28, 2026 08:38
Review raised two P1s on this branch and both hold up against the driver's
actual behaviour.
**press_key is not an AX dispatch.** The trace hardcoded `address: 'ax'`
before the call even happened. Verified against cua-driver v0.12.6 with an
element-bound call, the driver returns:
{"effect": "unverifiable", "path": "key_events", "verified": false}
It resolves the element through AX and then posts keyboard CGEvents to the
pid. Labelling that as AX let a synthetic key path pass the safe-dispatch
gate that exists to keep pixel/event delivery out of AX qualification. The
trace address is now derived from the driver's own evidence, and the
delivered-but-unverified path reports `key_events` instead of `ax`.
**The physical-input fence still applies to it.** This branch removed the
fence for the whole semantic path. That is correct for `click_element` and
`set_value`, which are pure AX mutations, but not for `press_key`: keyboard
CGEvents interleave with — and can be redirected by — a user typing at the
same time. Element-bound addressing does not remove that hazard. The fence
is restored on this path only.
The test that pinned the old behaviour asserted success with
`physicalInputRecentlyActive: () => true`, welding the unsafe behaviour in
place. It now asserts the opposite, and a second test covers the trace
address. The test double also returned `path: 'ax', verified: true,
effect: 'confirmed'` for press_key — values the real driver never emits —
so it now mirrors the verified response.
Verified: `cua-driver-backend` suite 91 passed, 0 failed.
@hqhq1025hqhq1025 closed this Aug 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han