feat: extract broker orchestration and Devframe integration - #72
Merged
Merged
Conversation
dvcolomban
marked this pull request as ready for review
September 8, 2026 14:41
dvcolomban
force-pushed
the
dvcol/cdb-orchestration
branch
from
September 9, 2026 08:45
dad329e to
595af2d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Background
Embedding hosts currently compose provider pairing, grants, recovery and browser management themselves. This adds a public broker runtime and a Devframe adapter so hosts can reuse that flow while retaining their own process lifecycle, tool registry and approval policy.
Changes
Add
@dvcol/cdb-brokerwith declarative configuration, persistent identity storage, authoritative grant coordination and per-principal browser tools. Add@dvcol/cdb-devframeas a context-lifetime service that carries provider traffic and cancellation over an existing authenticated RPC peer. Its panel consumes an existing broker connection.Add the optional Chrome adapter and notification controller to
@dvcol/cdb-extension. The standalone example demonstrates the service, native MCP tools, panel and a trusted extension-popup approval channel on Devframe 0.9.10 and DevTools Kit 0.6.1. Both new packages join the fixed release train; publication remains pending npm bootstrap and trusted-publisher setup.Notification updates preserve message registrations and use the existing Devframe update API. The workspace backports upstream toast removal through the pinned hub-ui patch. Independent frame discovery reads run with bounded concurrency while retaining complete ambiguity checks and fresh actionability checks. Authenticated WebSocket requests now wait for the host’s first listener during asynchronous session setup, preserving order within the existing pending-message limit.
Verification
Affected lint and type checks pass. Final validation reproduced a WebSocket startup race where the initial request was discarded before asynchronous host setup attached its listener. The regression failed before the fix; all 21 focused WebSocket tests and both original Chromium approval/group tests pass afterward. This does not establish the cause of all earlier intermittent stalls. Regression tests cover pairing continuity, principal isolation, approval replay, concurrent membership, navigation policy, recovery and shutdown. A real Devframe RPC test verifies that cancelling browser input leaves ordinary host traffic usable. The patched embedded and standalone notification browser tests pass locally.
The Chromium E2E runs extension → Devframe RPC → broker → native MCP with 10,000 DOM nodes, 200 levels, 20 closed shadow roots and three cross-origin frame levels. It also exercises overlapping grants, live group membership, provider reconnect, generation replacement, cross-origin navigation and the hosted panel. Full
pnpm verifypasses on commit85f75efin CI run 34695125827.Live staging and local-shell control previously passed, including a successful non-persisting interaction inside the Zoning iframe. That interaction required an explicit longer deadline and does not establish a passing latency gate. Live Reject and notification updates during group membership changes remain to be completed on the final integration. Earlier QA Helper proof used a branch containing the separately parked handshake and build fixes; it does not establish independent adoption without them.
The experimental release retains performance and intermittent stalls as follow-ups. The latest snapshot gates failed and the final repeated lifecycle run was incomplete. The manual Browser diagnostics workflow runs transports and lifecycle suites sequentially, retains partial summaries after failures, and writes full measurements to logs and bounded job summaries. Generated benchmark CSVs are removed; historical summaries retain failed results. Full MVP validation requires passing latency gates and the complete lifecycle matrix.