Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,9 +24,10 @@ Plugin cards nobody can see are paused with their state kept, hidden browser tab

### Changes

- **Browser engines for agents' background tabs.** A plugin can contribute a lighter browser engine (`browser:engine`, see [plugins](docs/plugins.md#browser-engines-browserengine)); `browser_new_tab` takes `engine` (`auto` by default, `chromium`, or the engine's id). With an engine installed and running, an agent's new tab opens in it in the background and the person's active tab stays; the person's own tabs always use Chromium. Engines without real layout get clicks by DOM. The tab moves to Chromium under the same tab id, with a `notice` for the agent, for screenshots, drags, downloads, bot walls, text too thin for the page, a missing CDP method, a crashed engine, or when it is shown, and the site is remembered for the session. Commands without a tab id go to the tab the agent opened last. The engine gets no cookies or profile. Example engine: the separate `canvastty-plugin-lightpanda`. Screenshots of background tabs work while the Browser card is off-screen.
- **Launch modes.** Auto is now the default. Manual, Accept edits, Plan and Bypass (YOLO) are offered only where the CLI has them: Accept edits and Plan for Claude Code, Codex, Grok and OpenCode, Plan also for Cursor; Auto for a CLI without an auto mode of its own is its approval bypass and exists only inside agent isolation. Bypass is acknowledged once per CLI, checked in the main process and never given to a subagent.
- **Delegation rules.** A subagent never gets more than its orchestrator (plan < manual < accept edits < auto, never Bypass), works only inside its orchestrator's project folder, and stays within the depth (2) and live-subagent (8) limits the person sets in Settings → Agents. A decision plugin's "ask" is a deny with the reason for CLIs that cannot ask.
- **Agent isolation.** An OS layer (macOS `sandbox-exec`, Linux bubblewrap) around subagents, plugin-started agents and every agent not in Manual: writes only in the project, the launch's temporary folder and the CLI's own folders; keys, other CLIs' credentials and CanvasTTY's tokens unreadable; fails closed. Windows has no layer yet, so subagents run in Manual there. Turning it off is the person's opt-in.
- **Agent isolation.** An OS layer (macOS `sandbox-exec`, Linux bubblewrap) around subagents, plugin-started agents and every agent not in Manual: writes only in the project, the launch's temporary folder and the CLI's own folders; keys, other CLIs' credentials and CanvasTTY's tokens unreadable; fails closed. Windows has no layer yet, so subagents run in Manual there; so they do on Linux where bubblewrap cannot create a user namespace (Ubuntu 24.04's AppArmor restriction), with the reason on the card and [how to allow it](docs/installing-and-security.md#linux-when-bubblewrap-cannot-start). Turning it off is the person's opt-in.
- **Git audit.** After an isolated session ends, CanvasTTY checks the repositories it touched for git settings and files that would run programs outside isolation and offers **Neutralize** or **Keep as is**.
- **Native agent helper.** `canvastty-helper` (Go) runs the MCP servers, the permission gate and the lifecycle hook on macOS and Linux; Windows keeps the JavaScript helpers by default and `CANVASTTY_HELPERS=node` forces them. Building from source needs Go 1.21 or newer for it (`npm run build:helpers`); without Go the JavaScript helpers are used.
- **Performance.** Only what the main process and preload load is packaged, built-in skins ship as AVIF; the canvas camera lives outside React; off-screen DOM terminals are not rebuilt on scroll; summary and HOME-hidden terminal screens stop painting and defer selection redraws, while their parsers still receive complete output in bounded pieces so terminal state and history stay exact; the window loads while services start and Settings loads on demand; hidden native browser tabs, plugin frames nobody can see and closed Settings stop polling.
Expand Down
3 changes: 2 additions & 1 deletion CHANGELOG.ru.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,9 +24,10 @@ A/B против 1.7.0 в первоначальном замере всей с

### Изменения

- **Браузерные движки для фоновых вкладок агентов.** Плагин может добавить более лёгкий браузерный движок (`browser:engine`, см. [плагины](docs/plugins.ru.md#браузерные-движки-browserengine)); `browser_new_tab` принимает `engine` (`auto` по умолчанию, `chromium` или id движка). Если движок установлен и запущен, новая вкладка агента открывается в нём в фоне, а активная вкладка человека остаётся; вкладки самого человека всегда в Chromium. Движки без настоящей раскладки получают клики через DOM. Вкладка переходит в Chromium с тем же id и `notice` для агента при скриншоте, перетаскивании, загрузке, защите от ботов, слишком малом тексте для страницы, отсутствующем методе CDP, падении движка или когда её показывают; сайт запоминается до конца сессии. Команды без id вкладки идут во вкладку, которую агент открыл последней. Движок не получает cookies и профиль. Пример движка — отдельный `canvastty-plugin-lightpanda`. Скриншоты фоновых вкладок работают, даже когда карточка браузера за пределами экрана.
- **Режимы запуска.** «Авто» теперь по умолчанию. «Вручную», «Правки», «План» и «Обход» (YOLO) предлагаются только там, где их поддерживает CLI: «Правки» и «План» — Claude Code, Codex, Grok и OpenCode, «План» ещё и Cursor; «Авто» для CLI без собственного авторежима — это обход подтверждений, и он есть только внутри изоляции агентов. «Обход» человек подтверждает один раз для каждого CLI, он проверяется в main-процессе и никогда не передаётся субагенту.
- **Правила делегирования.** Субагент получает не больше оркестратора (план < вручную < правки < авто, никогда «Обход»), работает только в папке проекта своего оркестратора и в пределах глубины (2) и числа живых субагентов (8), которые человек задаёт в Настройки → Агенты. Ответ «спросить» от плагина решений для CLI, которые не умеют спрашивать, становится запретом с причиной.
- **Изоляция агентов.** Слой ОС (macOS — `sandbox-exec`, Linux — bubblewrap) вокруг субагентов, агентов, запущенных плагинами, и любого агента не во «Вручную»: запись только в проект, временную папку запуска и папки своего CLI; ключи, учётные данные других CLI и токены CanvasTTY недоступны; при сбое запуск отклоняется. В Windows слоя пока нет, поэтому субагенты там работают во «Вручную». Выключить изоляцию — явный выбор человека.
- **Изоляция агентов.** Слой ОС (macOS — `sandbox-exec`, Linux — bubblewrap) вокруг субагентов, агентов, запущенных плагинами, и любого агента не во «Вручную»: запись только в проект, временную папку запуска и папки своего CLI; ключи, учётные данные других CLI и токены CanvasTTY недоступны; при сбое запуск отклоняется. В Windows слоя пока нет, поэтому субагенты там работают во «Вручную»; так же и в Linux, где bubblewrap не может создать пространство имён пользователя (ограничение AppArmor в Ubuntu 24.04): причина видна на карточке, [как разрешить](docs/installing-and-security.ru.md#linux-если-bubblewrap-не-запускается). Выключить изоляцию — явный выбор человека.
- **Аудит git.** После окончания изолированной сессии CanvasTTY проверяет затронутые репозитории на настройки и файлы git, которые запустят программы вне изоляции, и предлагает **Обезвредить** или **Оставить как есть**.
- **Нативный хелпер агентов.** `canvastty-helper` (Go) обслуживает MCP-серверы, проверку разрешений и хук жизненного цикла на macOS и Linux; Windows по умолчанию остаётся на JavaScript-хелперах, `CANVASTTY_HELPERS=node` включает их везде. Для сборки из исходников нужен Go 1.21 или новее (`npm run build:helpers`); без Go используются JavaScript-хелперы.
- **Производительность.** В пакет попадает только то, что загружают main-процесс и preload, встроенные скины — в AVIF; камера холста живёт вне React; DOM-терминалы вне экрана не перестраиваются при прокрутке; терминалы в режиме миниатюр и при редактировании HOME прекращают отрисовку и откладывают перерисовку выделения, а их парсеры получают полный вывод ограниченными порциями, сохраняя состояние и историю; окно загружается, пока стартуют сервисы, а Настройки грузятся по требованию; скрытые вкладки браузера, невидимые фреймы плагинов и закрытые Настройки перестают опрашивать.
Expand Down
3 changes: 2 additions & 1 deletion CHANGELOG.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,9 +24,10 @@

### 变更

- **用于 agent 后台标签页的浏览器引擎。** 插件可以提供更轻量的浏览器引擎(`browser:engine`,见[插件](docs/plugins.zh-CN.md));`browser_new_tab` 接受 `engine`(默认 `auto`、`chromium` 或引擎 id)。安装并运行引擎后,agent 的新标签页在后台用它打开,用户的活动标签页保持不变;用户自己的标签页始终使用 Chromium。没有真实布局的引擎通过 DOM 点击。在截图、拖拽、下载、机器人验证墙、文字相对页面过少、缺少 CDP 方法、引擎崩溃或标签页被显示时,标签页以相同 id 转到 Chromium,并给 agent 一个 `notice`;该网站在本次会话中被记住。没有标签页 id 的命令发往 agent 最后打开的标签页。引擎不会得到 cookie 或配置文件。示例引擎:独立的 `canvastty-plugin-lightpanda`。 浏览器卡片在屏幕外时,后台标签页的截图也能正常工作。
- **启动模式。** 现在默认是 Auto。Manual、Accept edits、Plan 与 Bypass(YOLO)只在 CLI 支持时提供:Accept edits 与 Plan 适用于 Claude Code、Codex、Grok 和 OpenCode,Plan 还适用于 Cursor;没有自带自动模式的 CLI,其 Auto 就是跳过审批,且只在智能体隔离内存在。Bypass 需要用户为每个 CLI 确认一次,由主进程检查,且绝不交给子智能体。
- **委派规则。** 子智能体的权限不超过其编排者(plan < manual < accept edits < auto,绝不为 Bypass),只在编排者的项目文件夹内工作,并受用户在 Settings → Agents 中设定的深度(2)与存活子智能体数(8)限制。对于无法询问的 CLI,决策插件的「ask」会变成附带原因的拒绝。
- **智能体隔离。** 操作系统层(macOS 用 `sandbox-exec`,Linux 用 bubblewrap)包裹子智能体、插件启动的智能体以及所有非 Manual 模式的智能体:只能写入项目、本次启动的临时目录和其 CLI 自己的目录;密钥、其他 CLI 的凭据和 CanvasTTY 的 token 不可读;无法建立时拒绝启动。Windows 暂无隔离层,子智能体在那里以 Manual 运行。关闭隔离需由用户主动选择。
- **智能体隔离。** 操作系统层(macOS 用 `sandbox-exec`,Linux 用 bubblewrap)包裹子智能体、插件启动的智能体以及所有非 Manual 模式的智能体:只能写入项目、本次启动的临时目录和其 CLI 自己的目录;密钥、其他 CLI 的凭据和 CanvasTTY 的 token 不可读;无法建立时拒绝启动。Windows 暂无隔离层,子智能体在那里以 Manual 运行;在 bubblewrap 无法创建用户命名空间的 Linux 上(Ubuntu 24.04 的 AppArmor 限制)也是如此,卡片会显示原因,并说明[如何允许](docs/installing-and-security.zh-CN.md#linuxbubblewrap-无法启动时)。关闭隔离需由用户主动选择。
- **Git 审计。** 隔离会话结束后,CanvasTTY 会检查它触及的仓库中是否有会在隔离外运行程序的 git 设置和文件,并提供 **Neutralize** 或 **Keep as is**。
- **原生智能体 helper。** `canvastty-helper`(Go)在 macOS 和 Linux 上运行 MCP 服务器、权限检查和生命周期 hook;Windows 默认仍使用 JavaScript helper,`CANVASTTY_HELPERS=node` 可在任何系统上强制使用它们。从源码构建需要 Go 1.21 或更高版本(`npm run build:helpers`);没有 Go 时使用 JavaScript helper。
- **性能。** 只打包主进程和 preload 实际加载的内容,内置皮肤改用 AVIF;画布镜头放在 React 之外;屏幕外的 DOM 终端不再在滚动时重建;摘要模式和 HOME 编辑中隐藏的终端停止绘制并推迟选区重绘,解析器仍按有界批次接收完整输出以保留终端状态和历史;窗口在服务启动的同时加载,Settings 按需加载;隐藏的浏览器标签页、无人可见的插件帧以及关闭的 Settings 停止轮询。
Expand Down
2 changes: 2 additions & 0 deletions agent/browser/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,8 @@ Use this skill when the task needs the visible CanvasTTY browser. The browser is
4. Re-observe after navigation, dialogs, meaningful DOM changes, or any action whose result matters.
5. If the result contains `STALE_REF`, never retry the old ref. Call `browser_observe`, choose the replacement ref from the new revision, and retry once.

`browser_new_tab` may open your tab in the background, in a lighter engine the user installed (`engine: "auto"`, the default). Pass the returned `tabId` to every later call: commands without one go to the tab you opened last. Such a tab reads, observes, types and clicks by element, but has no screenshots; when a screenshot, a bot check or an unreadable page needs Chromium, the tab moves there by itself with the same tab ID, the result carries a `notice`, and old refs are stale. Use `engine: "chromium"` when the task is visual from the start.

Element refs belong to one tab, frame, and document revision. Do not copy a ref between tabs or reuse it after reload/navigation. The user or another agent may change the shared page between your calls; if the document revision changes, re-observe and continue from the new revision instead of guessing what changed.

## Reading and artifacts
Expand Down
2 changes: 2 additions & 0 deletions docs/browser.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,8 @@ Agent mutations are ordered FIFO per tab, deduplicated by request ID, revision-c

If the browser view has zero width or height, `browser_observe` returns `VIEWPORT_UNAVAILABLE` instead of a misleading empty list of controls. `browser_screenshot` returns the same retryable error for an empty capture. Bring the Browser card into view, then observe or capture again; reopening the tab is unnecessary. `browser_read_page` can still read document text while no drawable view is available.

An agent's `browser_new_tab` may open its tab in the background in a browser engine a plugin contributes (`engine: "auto"`, the default, when one is installed and running; `"chromium"` forces a normal tab). Such a tab is listed with its `engine`, is never shown, gets no cookies or profile, and moves to Chromium under the same tab id when a screenshot, a bot wall, thin text, a missing capability, an engine crash or showing the tab needs it; the agent's result says so. Tabs the person opens always use Chromium. See [Browser engines](plugins.md#browser-engines-browserengine). A background tab (an agent's own, or one that moved from an engine) can be captured while the Browser card is off-screen; only the tab shown in the card needs the card in view.

## Website and file boundaries

- Remote pages run sandboxed with context isolation and no Node.js or CanvasTTY preload.
Expand Down
2 changes: 2 additions & 0 deletions docs/browser.ru.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,8 @@

Agent mutations выполняются FIFO внутри вкладки, дедуплицируются по request ID, проверяют document revision до side effect, ограничены rate limit и timeout и блокируются, если обязательную запись audit attempt нельзя сохранить. Reads могут выполняться параллельно; у разных вкладок независимые mutation lanes.

`browser_new_tab` агента может открыть вкладку в фоне в браузерном движке, который добавил плагин (`engine: "auto"` по умолчанию, если движок установлен и запущен; `"chromium"` даёт обычную вкладку). Такая вкладка видна в списке со своим `engine`, никогда не показывается, не получает cookies и профиль и переходит в Chromium с тем же id, когда нужен скриншот, встретилась защита от ботов, текста слишком мало, движку чего-то не хватает, он упал или вкладку показывают; результат агента об этом сообщает. Вкладки, которые открывает человек, всегда в Chromium. См. [Браузерные движки](plugins.ru.md#браузерные-движки-browserengine). Фоновую вкладку (собственную вкладку агента или переехавшую из движка) можно снять скриншотом, даже когда карточка браузера за пределами экрана; только вкладке, показанной в карточке, нужна видимая карточка.

## Границы сайтов и файлов

- Удалённые страницы работают в sandbox с context isolation, без Node.js и preload CanvasTTY.
Expand Down
Loading
Loading