Conversation
|
This was referenced Aug 28, 2026
shrey150
changed the base branch from
agent/browse-v4-4-runtime
to
agent/browse-v4-cli-cursor-overlay
August 31, 2026 21:41
This was referenced Aug 31, 2026
shrey150
force-pushed
the
agent/browse-v4-network-sidecar
branch
from
September 11, 2026 17:38
61cc82f to
7dd1978
Compare
shrey150
force-pushed
the
agent/browse-v4-network-sidecar
branch
from
September 11, 2026 18:23
7dd1978 to
adbe80d
Compare
shrey150
marked this pull request as ready for review
September 11, 2026 20:13
Contributor
There was a problem hiding this comment.
All reported issues were addressed across 7 files
Architecture diagram
sequenceDiagram
participant User as Browse CLI User
participant CLI as Browse Command Handler
participant Manager as Driver Session Manager
participant Stagehand as Stagehand V4 Client
participant Browser as Remote Browser
participant Sidecar as CLI CDP Sidecar
participant Capture as Network Capture Writer
participant Files as Private Network Files
Note over User,Files: Browse V3-compatible network capture on Stagehand V4
User->>CLI: browse network on
CLI->>Manager: Get active page
Manager-->>CLI: V4 page with pageId
CLI->>Manager: Get browser CDP debugger URL
Manager->>Stagehand: Read browserWebSocketDebuggerUrl
Stagehand-->>Manager: Signed browser WebSocket endpoint
Manager-->>CLI: Endpoint kept internal
CLI->>Capture: enable(pageId, endpoint)
Capture->>Sidecar: attach(endpoint, pageId)
Sidecar->>Browser: Open one browser-level CDP WebSocket
Browser-->>Sidecar: WebSocket connected
Sidecar->>Browser: Target.attachToTarget(flatten, pageId)
Browser-->>Sidecar: CDP sessionId
Sidecar-->>Capture: Network CDP session
Capture->>Sidecar: Network.enable
Capture->>Sidecar: Register request and response listeners
CLI-->>User: enabled=true, network path
Note over Browser,Files: CDP events are routed through the flattened page session
Browser-->>Sidecar: Network.requestWillBeSent
Sidecar-->>Capture: Request event
Capture->>Files: Write request.json and allocate counter directory
Browser-->>Sidecar: Network.responseReceived
Sidecar-->>Capture: Response metadata
Capture->>Sidecar: Network.getResponseBody
Sidecar->>Browser: Fetch response body
Browser-->>Sidecar: Body or CDP error
Sidecar-->>Capture: Response body result
Capture->>Files: Write response.json when available
alt Concurrent network on requests
User->>CLI: browse network on
CLI->>Capture: enable(...)
Capture-->>CLI: alreadyEnabled=true
else CDP sidecar connection failure
Sidecar-->>Capture: Connection or command error
Capture-->>CLI: network sidecar error
CLI-->>User: Capture enable failed
end
User->>CLI: browse network off
CLI->>Capture: disable()
Capture->>Sidecar: Remove registered listeners
Capture->>Sidecar: Network.disable
Sidecar->>Browser: Disable Network domain
Capture->>Sidecar: Target.detachFromTarget
Sidecar->>Browser: Detach page session
Sidecar-->>Capture: Page session detached
Note over Sidecar,Browser: Browser-level WebSocket remains open across off/on cycles
Capture-->>CLI: enabled=false, retained network path
CLI-->>User: Capture stopped
opt Later network on in the same Browse session
User->>CLI: browse network on
CLI->>Capture: enable(next pageId, same endpoint)
Capture->>Sidecar: Attach a new flattened page session
Sidecar->>Browser: Target.attachToTarget(flatten, pageId)
Capture->>Files: Continue from highest existing request counter
CLI-->>User: Capture resumed without overwriting files
end
User->>CLI: browse stop
CLI->>Manager: Close Browse session
Manager->>Capture: close()
Capture->>Sidecar: Disable and detach active page session
Capture->>Sidecar: Close browser-level WebSocket
Sidecar->>Browser: Close auxiliary CDP connection
Manager->>Stagehand: Close Stagehand client
CLI-->>User: Session stopped
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
shrey150
force-pushed
the
agent/browse-v4-network-sidecar
branch
from
September 15, 2026 23:10
9887732 to
6f3096e
Compare
shrey150
added a commit
that referenced
this pull request
Sep 15, 2026
## Summary Import `packages/cli/**` exactly from the published `browse@0.9.6` V3 release, without changing its source or runtime behavior. This is intentionally a provenance checkpoint, not a line-by-line feature review. The imported source is kept runnable by a root, version-scoped pnpm override that resolves its unchanged Stagehand dependency to `3.7.1`. #2834 removes that override and starts the V4 migration. ## Exact-source provenance - Annotated tag: `browse@0.9.6` (`548c56407431db27823a212f53475443c7e8358d`) - Release commit: `1d49a95c0c230c346f8d50647e10303d6310fcd2` - Authoritative CLI tree: `b4048badce921cf54f199f96033d9a014ef977ec` - This PR's `HEAD:packages/cli` tree: `b4048badce921cf54f199f96033d9a014ef977ec` The tag's ignored README whitespace is retained too; formatting the import would invalidate the tree proof. ## Verification - Current remote head: `a77e1507b85e3c02553f36ead6ebd0237b0cccc6`, based on current `main`. - `HEAD:packages/cli` exactly equals the published V3 tree hash above. - pnpm 11 frozen install and the repository supply-chain release-age policy pass. - Browse lint, typecheck, and build pass; the full baseline suite passes: 25 files / 366 tests. - A fresh extension build still exactly matches the Go-embedded archive: SHA-256 `8efc7d171a625cca95c02d02d369b59435fae776cae6c7dd2f6fe72eb19785c0` on both files. This specifically verifies that adding the V3 dependency graph does not perturb the current V4 extension artifact. - This layer intentionally exercises V3 through the scoped Stagehand 3.7.1 override. V4 behavior starts in #2834. ## Stack (#2872) 1. **#2833 — exact Browse V3 baseline import** 2. #2834 — Stagehand V4 runtime and standard command parity 3. #2869 — CLI-owned cursor overlay 4. #2849 — CLI-private CDP sidecar; V3 network parity 5. #2835 — remove `--return-xpath`; supported V3 parity/release checkpoint 6. #2838 — eval and packaging integration 7. #2839 — managed Context names (fast-follow) 8. #2701 — shared Functions core consumer (fast-follow) ## Review and landing boundary Review this PR by verifying the tree hashes, dependency pin, root package wiring, and changeset—not by treating the imported V3 source as newly authored code. This head deliberately imports V3 code into the V4 repository and is not independently publishable. It lands only as the base of the complete stack. The framework network-event schema proposal in #2832 is intentionally outside this landing stack.
shrey150
force-pushed
the
agent/browse-v4-network-sidecar
branch
from
September 15, 2026 23:31
6f3096e to
3f2c701
Compare
shrey150
added a commit
that referenced
this pull request
Sep 16, 2026
…2834) ## Summary Migrate Browse's browser lifecycle and standard command surface together from Stagehand V3 to V4. - Replace the V3 constructor/init lifecycle with V4 browser factories and `Stagehand.create()`. - Support managed local, Browserbase remote, and attached CDP connection targets. - Preserve owned-versus-attached cleanup, daemon persistence, Browserbase session identity, and timeout handling. - Restore navigation, page information, deterministic locator actions, keyboard/mouse input, viewport/screenshot, snapshot, eval, and tab commands on V4 APIs. - Keep click/fill/select deterministic; this does not add a model-free structured `act()` path. - Make the remaining cursor, network, and coordinate-XPath gaps fail explicitly for the stack layers that restore or remove them. ## Stack (#2872) 1. #2833 — exact Browse V3 baseline import 2. **#2834 — Stagehand V4 runtime and standard command parity** 3. #2869 — CLI-owned cursor overlay 4. #2849 — CLI-private CDP sidecar; V3 network parity 5. #2835 — remove `--return-xpath`; supported V3 parity/release checkpoint 6. #2838 — eval and packaging integration 7. #2839 — managed Context names (fast-follow) 8. #2701 — shared Functions core consumer (fast-follow) ## Review shape The lifecycle and command migration remain two ordered implementation commits: 1. `389e2dae6` — V4 browser/session foundation and lifecycle ownership. 2. `b45167462` — standard command translation on that foundation. They are one PR because both commits rewrite the same nine command/test files. Reviewing their combined final diff avoids temporary deletion/stubbing followed by reimplementation, while the commits still provide useful lifecycle-versus-command checkpoints. Review follow-up `24178275f` adds narrowly scoped ownership, error-sanitization, and timeout guards. The resulting PR diff is 23 files, +988/−436. Cursor DOM injection and private CDP network transport remain separate because they are independently reviewable mechanisms and cleanly additive diffs. The legacy coordinate `returnXPath` request is still accepted here but fails explicitly until #2835 removes the option. This remains an intentionally non-publishable intermediate head. ## E2E Test Matrix Fresh post-flatten verification used the actual built CLI at final head `6f7e9c209`. Every daemon command used an isolated owner-only runtime directory. | Command / flow | Observed output | Confidence / sufficiency | | --- | --- | --- | | `pnpm install --frozen-lockfile` | Lockfile passed supply-chain policy, was already up to date, and installation completed | Proves the flattened stack resolves exactly from the committed lockfile | | `pnpm exec turbo run build --filter=browse` | Protocol, extension, Stagehand SDK, and Browse CLI built successfully (4/4 tasks) | Proves the CLI was tested against this head's protocol/extension/SDK artifacts, not stale workspace `dist` files | | Compare the rebuilt extension with `packages/sdk-go/internal/extensionassets/stagehand-extension.zip` | Exact byte match; both SHA-256 `8efc7d171a625cca95c02d02d369b59435fae776cae6c7dd2f6fe72eb19785c0`; archive manifest and package version both `1.0.2` | Confirms the TypeScript/CLI build and Go-embedded extension are synchronized | | Built CLI: `browse open <synthetic-data-url> --remote`; `browse status` | Remote browser connected and initialized; deterministic fixture loaded | Exercises production Browserbase provisioning plus the V4 daemon/session lifecycle on the exact final head | | `browse get text //h1`; `fill`; `select`; `click`; `is checked`; `wait selector`; `highlight`; `viewport`; `screenshot`; `snapshot --full` | XPath returned `Ready`; input became `Ada`; select became `b`; click produced `Clicked`; checkbox was true; PNG was 17,761 bytes; snapshot contained the fixture | Covers deterministic V4 reads, actions, waits, state, and rendering without an LLM | | Set a page marker; `tab new`; `tab list`; `tab close`; read the marker from a new CLI process | Tab count changed to 2 and the original page returned marker `yes` | Proves daemon persistence, active-tab handling, and state reuse across invocations | | Inspect the isolated runtime directory/PID; `browse stop`; poll the Browserbase session | Modes were `0700` / `0600`; the owned remote session reached `COMPLETED` | Proves owner-only daemon files and owned Browserbase resource cleanup | | `browse cursor`; `browse network on`; `browse mouse hover ... --return-xpath` | Each exited 1 with the intended explicit layer-boundary error | Confirms this intermediate layer fails honestly until the cursor, network, and flag-removal layers land | | `pnpm --filter browse test` | 25 files / 385 tests passed | Full Browse unit/integration suite on the exact final head | The runner has no Chrome/Chromium installation, so a fresh attached-CDP ownership smoke was not possible. Attached-browser non-ownership remains covered by the focused suite and is not claimed as a fresh live result here.
shrey150
force-pushed
the
agent/browse-v4-network-sidecar
branch
from
September 16, 2026 00:23
3f2c701 to
eb42f45
Compare
shrey150
force-pushed
the
agent/browse-v4-network-sidecar
branch
from
September 16, 2026 21:50
eb42f45 to
d8dbfd0
Compare
shrey150
added a commit
that referenced
this pull request
Sep 17, 2026
## Summary
Restore Browse's visible cursor as a CLI-owned DOM overlay, without
adding a cursor API to core Stagehand V4.
- Keep the overlay implementation in one dedicated `cursor-overlay.ts`
file.
- Install it idempotently for the current document through
`page.evaluate(CURSOR_OVERLAY_SCRIPT)` and for future navigations
through `page.addInitScript(...)`.
- Retry installation on `DOMContentLoaded` when the init script runs
before the document root exists.
- Keep injection in the top frame and update the marker from coordinate
input, including when input lands inside a child frame.
- Treat visual position updates as best-effort so they cannot block or
invalidate real mouse input.
- Preserve the V3 `browse cursor` JSON response: `{ "cursor": "enabled"
}`.
## Stack (#2872)
1. #2833 — exact Browse V3 baseline import
2. #2834 — Stagehand V4 runtime and standard command parity
3. **#2869 — CLI-owned cursor overlay**
4. #2849 — CLI-private CDP sidecar; V3 network parity
5. #2835 — remove `--return-xpath`; supported V3 parity/release
checkpoint
6. #2838 — eval and packaging integration
7. #2839 — managed Context names (fast-follow)
8. #2701 — shared Functions core consumer (fast-follow)
## Why this is separate
The cursor is a self-contained optional visual feature with different
review concerns from the combined V4 runtime/command migration: injected
DOM/CSS, idempotency, event handling, and screenshot behavior. Keeping
it additive on #2834 lets this feature be reviewed or reverted without
disturbing browser lifecycle or commands.
## E2E Test Matrix
Review-feedback verification compared the exact prior head `6a9d6aa09`
with fixed implementation head `1035fbbf5` through the built CLI and
real Browserbase browsers. Final head `68f6fcb2c` only expands automated
coverage and does not change runtime code. Targets were the public
`example.com` and `example.org` pages.
| Command / flow | Observed output | Confidence / sufficiency |
| --- | --- | --- |
| Prior head: enable cursor, alternate 20 cross-origin navigations,
inspect `#__browse_cursor_overlay__` before any mouse input | Overlay
count was `0` after 20/20 navigations | Reproduces the DOM-readiness bug
raised in review |
| Fixed head: repeat the same 20-navigation flow | Overlay count was `1`
after 20/20 navigations (0 misses) | Proves the `DOMContentLoaded` retry
restores the overlay after navigation in the real browser path |
| Prior head: replace the page's cursor-position callback with a
throwing function, then run `browse mouse click 200 200` against an
oversized synthetic button | Command exited `1`; the page's click state
remained `null` | Reproduces the visual-update failure blocking real
mouse input |
| Fixed head: repeat the same forced overlay failure and click | CLI
returned `{ "clicked": true }`; page click state became `"yes"` | Proves
overlay rendering is best-effort while real input still executes |
| Built CLI: `browse cursor` | `{ "cursor": "enabled" }` (prior head
returned `{ "enabled": true }`) | Confirms V3-compatible output for
existing scripts |
| `pnpm --filter browse lint` | Passed formatting, ESLint, and
TypeScript checks | Static validation on the final head |
| `pnpm --filter browse test:cli` | 26 files / 393 tests passed | Full
Browse suite, including DOM readiness, safe styling, idempotency,
top-frame isolation, cursor positioning/clamping, and all four
coordinate input commands |
| `browse stop` after each live run | Completed successfully | Covers
Browserbase session and daemon cleanup |
The already-uploaded screenshot below remains representative visual
proof of the same overlay behavior.

No LLM path or customer data was involved.
shrey150
force-pushed
the
agent/browse-v4-network-sidecar
branch
from
September 17, 2026 03:20
d8dbfd0 to
99fe4ca
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Restore Browse V3 network-capture behavior on Stagehand V4 through a CLI-private CDP sidecar, without committing core Stagehand, its protocol, or generated SDKs to a public network-event schema.
Stack (#2872)
--return-xpath; supported V3 parity/release checkpointArchitecture
on/off/sendsession shape.network off, remove listeners, sendNetwork.disable, and detach the page target.The request correlation and request/response JSON writer are inherited from the V3 CLI. No public protocol schema, extension, SDK, or generated-client changes are included. #2832 remains open outside the landing stack for that separate API-design discussion.
User-visible behavior
The V3 command and file surface is retained:
Each request directory contains
request.jsonand, when available,response.json, including the existing treatment of POST bodies, response bodies, failures, redirects, cache hits, and binary responses.E2E Test Matrix
Full post-propagation implementation verification ran against exact clean #2849 head
adbe80d8bbfc337fea9dc38e41a88da18c287046. Its seven-file network patch has the same stable patch ID (f062ac789108ddf640bc912776dafa210411f50c) as the previously stress-tested head, so the deterministic V3/V4 and MSN/CNN evidence below applies unchanged. Frozen install, fresh builds, focused/full tests, and the real Browserbase lifecycle were rerun onadbe80d8b. Current review-fix head9887732b6f0c32cdef0966ebfd2ac2c454321d4bchanges only the test helper timeout diagnostic; on that exact head, the targeted network-capture tests passed 2/2 and Browse formatting, ESLint, and TypeScript checks passed. The comparison CLI was the exact built V3 implementation at7365a20d52955c10d72606f2e6ddd74791609d13. Every CLI flow used a unique daemon directory; no pre-existing daemon was reused or stopped.pnpm install --frozen-lockfile; build extension, local Stagehand SDK, thenbrowsedistoutput.open → network on → eval(GET, cached GET twice, POST, redirect, binary, abort) → path → off → path → clear → stop[]; clear left 0 entries for both.Date, and fixture origin/port.browse network onsubprocesses launched together, followed by one marked navigation{ enabled: true }; the other returned{ alreadyEnabled: true, enabled: true }. The marked navigation produced exactly 1 request record with 1 unique request ID.network oncalls serialize and attach listeners once rather than duplicating capture.on → navigate → off → on → navigate → offwithout clearing000and001; both URLs remained present, and the SHA-256 of the firstrequest.jsonwas unchanged after the second cycle.0700;request.jsonandresponse.jsonwere0600;network clearleft 0 entries;browse stopreported stopped.network on → open Example Domain → offcycles in one session, then navigation with capture offopen --wait networkidleworked; final status was connected, initialized, and remote; stop completed.on → path → open → scroll → collect 12s → off → path → navigate while off → status → clearpnpm --filter browse lintadbe80d8b; passed again at current review-fix head9887732b6.pnpm --filter browse testwith isolated daemon directoryadbe80d8b: 27 files / 390 tests passed; focused network subset: 3 files / 30 tests passed. At current review-fix head9887732b6: targeted network-capture tests passed 2/2.The deterministic artifact comparison includes method, URL/path, request/response headers and bodies, status/status text, MIME type, resource type, error shape, counter naming, and file modes. The live stress test also observed GET/POST/OPTIONS, failures, base64 bodies, cross-origin documents, and request-only records for traffic still in flight at the bounded
offpoint.This matrix does not claim WebSocket-frame, SSE-message, service-worker, or every out-of-process-iframe edge-case coverage; those are outside the V3 JSON request/response file contract proven here.