Skip to content

feat(desktop): bundle Cua Driver for Computer Use - #5611

Closed
Astro-Han wants to merge 8 commits into
apache:mainfrom
Astro-Han:feat/computer-use-bundle-cua-driver
Closed

Astro-Han wants to merge 8 commits into
apache:mainfrom
Astro-Han:feat/computer-use-bundle-cua-driver

Conversation

@Astro-Han

@Astro-Han Astro-Han commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Maka's macOS Computer Use path selected maka-cu, but that executor has no distributable signed artifact. Replace it with the pinned Cua Driver 0.28.2 universal CLI behind the existing CuDispatchBackend and Runtime Host. The CLI runs as a private embedded stdio child; users will not install Cua separately, and the agent continues to see only maka_computer.

Actions default to background delivery. When Cua reports background_unavailable, Maka returns foreground_required and tells the agent to explain the app, window, and exact action in conversation and wait for an explicit user reply. The agent must observe again and request foreground for only that action. This PR does not add a second Maka approval store or an automatic foreground retry.

Remove the retired maka-cu service, protocol, backend, and its dedicated test harnesses. Pin the Cua archive and executable digests, verify the upstream Developer ID signature, preserve that signature during packaging, and check the packaged binary again during macOS release verification. The source archive does not include the downloaded executable.

Verification

  • Clean Desktop workspace dependency and app builds; Storybook typecheck and build.
  • @maka/computer-use tests (18), Runtime Computer Use tests (255), focused Desktop host/copy tests (11), packaged resource tests (22), and product release tests (33) passed.
  • npm run format, npm run lint, staged ASF header audit, and git diff --check passed.
  • License audit follow-up: verified source tag and Cargo.lock, scanned both locked macOS dependency graphs, matched the embedded Inter font bytes, copied upstream OFL/CDLA texts byte-for-byte, and generated bundled notices for all 349 external crates. Thirty-five crates missing license files in their crates.io archives now use license texts from their exact upstream VCS revisions. The checked-in notice is reproducible with node scripts/generate-cua-driver-notices.mjs --check.
  • Rebuilt an unsigned macOS arm64 .app; its Cua binary matches the pinned digest, its packaged Cua notices match the checked-in files byte-for-byte, and assertPackagedResources passes. The signed/notarized build remains unverified.
  • Focused package, product release, and ASF policy tests passed (98 total); Desktop main, renderer, Storybook typecheck, and Storybook build passed. The packaged macOS AboutRelease story finished its browser play assertions, CDP accessibility audit, and light/dark visual inspection.
  • Direct read-only Cua CLI probe confirmed the pinned binary's tool schemas and bundle-ID window observation. A no-change window-frame operation confirmed the direct native route.
  • Storybook PermissionCenterDiagnosticsExpanded finished its play assertions in light and dark modes for both revisions.

Permission Center light before and after

Permission Center dark before and after

About page light before and after

About page dark before and after

Release blockers

  • Package third-party license texts and provide a prominent user-facing label. The pinned macOS inventory covers 356 x86_64 / 354 arm64 normal and build dependencies; the app now ships a deduplicated notice for all 349 external entries. The macOS About page names Cua Driver, MIT, UniFFI MPL-2.0, and Inter OFL-1.1, with an upstream link. ASF Legal classified the graph's CDLA-Permissive-2.0 certificate data as Category A in LEGAL-732.
  • Review the objc2 SDK-binding question against the actual packaged artifact. Upstream questions distributing SDK-derived binding crates as source; Maka distributes the compiled CLI, not those sources or Apple SDK files. Apple's Xcode agreement §2.4 permits compliant macOS app and library distribution, while §2.7 prohibits Apple Software redistribution. The ASF platform FAQ permits targeting a platform unless its terms change the Apache product's licensing, without authorizing redistribution of platform code. The packaged Cua files contain the CLI and notices; inspection found no Apple SDK headers or libraries. otool -L confirms only the dynamic system-framework references, not the contents of statically compiled objc2 code. The notices preserve upstream objc2 license text and MIT permission text. No concrete objc2 licensing blocker was found. The prebuilt executable has no upstream SBOM or source-to-binary attestation, so its exact linked set remains an evidence limit.
  • Qualify the signed and notarized Maka app on a real macOS host, including host-attributed Accessibility/Screen Recording permissions, background action behavior, service restart, and one consented foreground escalation.
  • Requalify historical maka-cu guarantees that the Cua adapter does not yet provide, especially menu expansion, text selection, minimize, and WebContent generation handling. The current tool description reports these capability gaps.

AI use

  • No generative tool made a substantive contribution
  • Generative tooling made a substantive contribution

Tool(s) and scope: Codex implemented the adapter, packaging and release checks, tests, documentation, and dependency license audit. The commits include Generated-by trailers.

Checklist

  • Tests cover the new background refusal and explicit foreground call path, binary integrity, and release gate.
  • Lint, format, typecheck, and affected suites pass locally.

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No

@github-actions github-actions Bot added the effort/XXL Over 2500 readable lines label Sep 23, 2026
@Astro-Han Astro-Han closed this Sep 23, 2026
@Astro-Han
Astro-Han deleted the feat/computer-use-bundle-cua-driver branch September 25, 2026 12:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/XXL Over 2500 readable lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant