Deliver the full Chrome Debugger Bridge architecture through a critical-path authorized single-target MVP, then grow it through independently delegable vertical slices into the first synchronized public release.
-
Compose a standalone Node host with pairing and artifact reads — Node hosts can now own a loopback bridge with one-use pairing, separated endpoints, per-client artifact grants, and deterministic shutdown.
-
Embed the broker with an in-process client and custom adapters — Hosts can now embed a structured-clone broker/client boundary with injected policy, diagnostics, ID, clock, and artifact adapters.
-
Use the broker from a generic browser client — Browser-native WebSocket and authenticated artifact readers now provide the complete facade with bounded reconnect and subscription restoration.
-
Persist artifacts with quotas, expiry, and cleanup — Node hosts can now select an opaque, quota-bounded filesystem store with atomic persistence and deterministic recovery cleanup.
-
Stream artifacts over WebSocket and authenticated HTTP — Opaque artifacts now transfer by bounded ordered binary frames or header-authenticated range HTTP reads, with common integrity-checked readers.
-
Validated protocol schemas — Zod Mini supplies strict Standard Schema validators, generated Draft 2020-12 JSON Schema, and the validated in-process round trip.
-
Pairing proof and credential boundary — a Vite/Devframe-shaped one-time-code flow provisions broker-scoped credentials used only through nonce-bound mutual HMAC/HKDF proofs, with strict pre-authentication limits and live rotation/revocation.
-
Publish one explicitly selected tab under an opaque identity — the extension owns one selected tab attachment and emits only a policy-redacted UUID target through a transport-neutral broker/client directory.
-
Execute one leased read-only CDP command from a generic Node client — bounded leases and correlated commands are checked by both broker and extension, with cancellation, expiry, and debugger-error redaction.
-
Reconcile published-target lifecycle across Chrome events — Chrome event transitions, stale-safe reconciliation, and snapshot-first lifecycle watchers are proven through unit and MV3 tests.
-
Share a target through expiring read and control leases — target generations now arbitrate compatible shared reads and one exclusive controller, with renewal, release, expiry, and grant-reduction invalidation.
-
Approve the initial capability and CDP classification catalogue — a pinned generated catalogue classifies 580 client-facing CDP commands and events across cumulative observe-to-unsafe levels, with exact-name overrides and native payload pass-through.
-
Enforce target grants and hierarchical CDP capabilities — broker and extension independently enforce catalogue-backed target grants, compatible lease authority, and kernel-owned CDP exclusions.
-
Multiplex filtered subscriptions with bounded backpressure — each subscriber gets isolated filtered event delivery, bounded buffering, overflow telemetry, and client-plane streaming.
-
Route recursive flat child sessions under opaque identities — Recursive Chrome flat-session setup now keeps eligible child identities opaque and invalidates them with the published root.
-
Recover after service-worker, transport, and broker interruption — The extension now reconnects through explicit generation-bound states, mandatory reconciliation, bounded backoff, heartbeat failure handling, and MV3 interruption coverage.
-
Publish dynamic selector scopes with redacted metadata — Extension-local explicit, group, window, active-tab, and URL-pattern scopes fail closed and revoke a published target immediately when it leaves scope.
-
Reassign a tab safely between paired brokers — Root-tab assignment is serialized and revokes the prior broker publication before publishing for a different broker.
-
Verify generic host and client examples from packed packages — Every private example now verifies against isolated packed tarballs; generic browser and Node client flows cover reconnect, cancellation, event delivery, and artifact retrieval.
-
Call the broker client through Devframe birpc — An existing Devframe or Vite server can host explicit authenticated WebSocket endpoints plus a typed birpc client facade without leaking adapter stream types into core.
-
Bootstrap a direct agent connection from an expiring Devframe offer — An origin-bound one-shot offer now reaches the extension only as validated non-secret metadata; locator and pairing policy open the direct agent transport before every relay listener and nonce state is discarded.
-
Dispose and reconnect the Devframe integration cleanly — Devframe mounts, streams, offers, and direct connections now dispose deterministically with safe lifecycle diagnostics.
-
Serve target discovery and leased inspection through MCP Streamable HTTP — Official MCP SDK v2.0.0 now exposes the 2026-07-28 Streamable HTTP boundary with target, lease, and inspection tools while leaving broker lifecycle external.
-
Request exclusive interact authority for browser.evaluate — browser.evaluate now uses an exclusive interact lease, with cancellation and exact-once cleanup across all command outcomes.
-
Make leases principal-owned with a configurable reconnect grace — Leases are principal-owned across a bounded reconnect grace, while commands and subscriptions remain connection-owned.
-
Terminate and safely restore subscriptions across authority and transport changes — Subscriptions now end with authority and restore independently across a retained-principal reconnect.
-
Honor bounded byte ranges in the filesystem artifact store — Filesystem artifacts now validate and bounded-read the same byte ranges as the memory store.
-
Restore the public client-facade adapter boundary after authority hardening — Public facades now require explicit branded adapters, preventing direct authority-bearing broker composition.
-
Preserve broker frames while storing a newly paired credential — Authenticated frames now remain bounded, ordered, and lossless across credential persistence, with deterministic cleanup on failure or closure.
Destination
Deliver the full Chrome Debugger Bridge architecture through a critical-path authorized single-target MVP, then grow it through independently delegable vertical slices into the first synchronized public release.
Notes
Decisions so far
Compose a standalone Node host with pairing and artifact reads — Node hosts can now own a loopback bridge with one-use pairing, separated endpoints, per-client artifact grants, and deterministic shutdown.
Embed the broker with an in-process client and custom adapters — Hosts can now embed a structured-clone broker/client boundary with injected policy, diagnostics, ID, clock, and artifact adapters.
Use the broker from a generic browser client — Browser-native WebSocket and authenticated artifact readers now provide the complete facade with bounded reconnect and subscription restoration.
Persist artifacts with quotas, expiry, and cleanup — Node hosts can now select an opaque, quota-bounded filesystem store with atomic persistence and deterministic recovery cleanup.
Stream artifacts over WebSocket and authenticated HTTP — Opaque artifacts now transfer by bounded ordered binary frames or header-authenticated range HTTP reads, with common integrity-checked readers.
Validated protocol schemas — Zod Mini supplies strict Standard Schema validators, generated Draft 2020-12 JSON Schema, and the validated in-process round trip.
Pairing proof and credential boundary — a Vite/Devframe-shaped one-time-code flow provisions broker-scoped credentials used only through nonce-bound mutual HMAC/HKDF proofs, with strict pre-authentication limits and live rotation/revocation.
Publish one explicitly selected tab under an opaque identity — the extension owns one selected tab attachment and emits only a policy-redacted UUID target through a transport-neutral broker/client directory.
Execute one leased read-only CDP command from a generic Node client — bounded leases and correlated commands are checked by both broker and extension, with cancellation, expiry, and debugger-error redaction.
Reconcile published-target lifecycle across Chrome events — Chrome event transitions, stale-safe reconciliation, and snapshot-first lifecycle watchers are proven through unit and MV3 tests.
Share a target through expiring read and control leases — target generations now arbitrate compatible shared reads and one exclusive controller, with renewal, release, expiry, and grant-reduction invalidation.
Approve the initial capability and CDP classification catalogue — a pinned generated catalogue classifies 580 client-facing CDP commands and events across cumulative observe-to-unsafe levels, with exact-name overrides and native payload pass-through.
Enforce target grants and hierarchical CDP capabilities — broker and extension independently enforce catalogue-backed target grants, compatible lease authority, and kernel-owned CDP exclusions.
Multiplex filtered subscriptions with bounded backpressure — each subscriber gets isolated filtered event delivery, bounded buffering, overflow telemetry, and client-plane streaming.
Route recursive flat child sessions under opaque identities — Recursive Chrome flat-session setup now keeps eligible child identities opaque and invalidates them with the published root.
Recover after service-worker, transport, and broker interruption — The extension now reconnects through explicit generation-bound states, mandatory reconciliation, bounded backoff, heartbeat failure handling, and MV3 interruption coverage.
Publish dynamic selector scopes with redacted metadata — Extension-local explicit, group, window, active-tab, and URL-pattern scopes fail closed and revoke a published target immediately when it leaves scope.
Reassign a tab safely between paired brokers — Root-tab assignment is serialized and revokes the prior broker publication before publishing for a different broker.
Verify generic host and client examples from packed packages — Every private example now verifies against isolated packed tarballs; generic browser and Node client flows cover reconnect, cancellation, event delivery, and artifact retrieval.
Call the broker client through Devframe birpc — An existing Devframe or Vite server can host explicit authenticated WebSocket endpoints plus a typed birpc client facade without leaking adapter stream types into core.
Bootstrap a direct agent connection from an expiring Devframe offer — An origin-bound one-shot offer now reaches the extension only as validated non-secret metadata; locator and pairing policy open the direct agent transport before every relay listener and nonce state is discarded.
Dispose and reconnect the Devframe integration cleanly — Devframe mounts, streams, offers, and direct connections now dispose deterministically with safe lifecycle diagnostics.
Serve target discovery and leased inspection through MCP Streamable HTTP — Official MCP SDK v2.0.0 now exposes the 2026-07-28 Streamable HTTP boundary with target, lease, and inspection tools while leaving broker lifecycle external.
Request exclusive interact authority for browser.evaluate — browser.evaluate now uses an exclusive interact lease, with cancellation and exact-once cleanup across all command outcomes.
Make leases principal-owned with a configurable reconnect grace — Leases are principal-owned across a bounded reconnect grace, while commands and subscriptions remain connection-owned.
Terminate and safely restore subscriptions across authority and transport changes — Subscriptions now end with authority and restore independently across a retained-principal reconnect.
Honor bounded byte ranges in the filesystem artifact store — Filesystem artifacts now validate and bounded-read the same byte ranges as the memory store.
Restore the public client-facade adapter boundary after authority hardening — Public facades now require explicit branded adapters, preventing direct authority-bearing broker composition.
Preserve broker frames while storing a newly paired credential — Authenticated frames now remain bounded, ordered, and lossless across credential persistence, with deterministic cleanup on failure or closure.
Not yet specified
Out of scope