Repository navigation
Conversation
Generated-by: Codex
Generated-by: Codex
Generated-by: Codex
Generated-by: Codex
Generated-by: Codex
Generated-by: Codex
Generated-by: Codex
Generated-by: Codex
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Maka's macOS Computer Use path selected
maka-cu, but that executor has no distributable signed artifact. Replace it with the pinned Cua Driver 0.28.2 universal CLI behind the existingCuDispatchBackendand Runtime Host. The CLI runs as a private embedded stdio child; users will not install Cua separately, and the agent continues to see onlymaka_computer.Actions default to background delivery. When Cua reports
background_unavailable, Maka returnsforeground_requiredand tells the agent to explain the app, window, and exact action in conversation and wait for an explicit user reply. The agent must observe again and request foreground for only that action. This PR does not add a second Maka approval store or an automatic foreground retry.Remove the retired
maka-cuservice, protocol, backend, and its dedicated test harnesses. Pin the Cua archive and executable digests, verify the upstream Developer ID signature, preserve that signature during packaging, and check the packaged binary again during macOS release verification. The source archive does not include the downloaded executable.Verification
@maka/computer-usetests (18), Runtime Computer Use tests (255), focused Desktop host/copy tests (11), packaged resource tests (22), and product release tests (33) passed.npm run format,npm run lint, staged ASF header audit, andgit diff --checkpassed.node scripts/generate-cua-driver-notices.mjs --check..app; its Cua binary matches the pinned digest, its packaged Cua notices match the checked-in files byte-for-byte, andassertPackagedResourcespasses. The signed/notarized build remains unverified.AboutReleasestory finished its browser play assertions, CDP accessibility audit, and light/dark visual inspection.PermissionCenterDiagnosticsExpandedfinished its play assertions in light and dark modes for both revisions.Release blockers
objc2SDK-binding question against the actual packaged artifact. Upstream questions distributing SDK-derived binding crates as source; Maka distributes the compiled CLI, not those sources or Apple SDK files. Apple's Xcode agreement §2.4 permits compliant macOS app and library distribution, while §2.7 prohibits Apple Software redistribution. The ASF platform FAQ permits targeting a platform unless its terms change the Apache product's licensing, without authorizing redistribution of platform code. The packaged Cua files contain the CLI and notices; inspection found no Apple SDK headers or libraries.otool -Lconfirms only the dynamic system-framework references, not the contents of statically compiledobjc2code. The notices preserve upstreamobjc2license text and MIT permission text. No concreteobjc2licensing blocker was found. The prebuilt executable has no upstream SBOM or source-to-binary attestation, so its exact linked set remains an evidence limit.maka-cuguarantees that the Cua adapter does not yet provide, especially menu expansion, text selection, minimize, and WebContent generation handling. The current tool description reports these capability gaps.AI use
Tool(s) and scope: Codex implemented the adapter, packaging and release checks, tests, documentation, and dependency license audit. The commits include
Generated-bytrailers.Checklist
Does this PR entail a change in behavior?