proto: freeze the wire contract at 1.0.0

Schemas for the whole v1 surface: 38 methods, 9 events, 25 named types and the
JSON-RPC envelope, with x-privileged / x-transports / x-deadlineMs / x-errors
annotations that both generators emit as data rather than prose.

Four generators over one IR (contracts/codegen/schema_ir.py), so the C++ structs,
the TypeScript types and the OpenRPC document cannot disagree about what the
contract says:

  gen_cpp.py             -> core/generated/velox_proto.{hpp,cpp}
  gen_ts.py              -> extension/src/shared/protocol/
  gen_openrpc.py         -> contracts/openrpc.json
  gen_cpp_conformance.py -> tests/conformance/cpp/fixture_dispatcher.hpp

Inbound parsing never throws: parse<T>() returns std::expected<T, ParseError> and
nlohmann's throwing ADL from_json is deliberately not emitted. Schema constraints
(minimum, maxLength, pattern, ...) become real runtime checks in both languages —
the daemon does not trust the extension and the extension does not trust the
daemon.

59 golden fixtures: a success case per method, 12 error cases, 9 events. Replayed
by tests/conformance/ against both the generated C++ and a live server over both
transports. tools/mockd serves the same fixtures with unhappy-path flags so the
GUI and EXT lanes never wait for veloxd.

run.sh also proves capture.offer fails open: with a daemon answering slower than
750 ms the client gives up and lets Firefox take the download.

core/generated/ is libveloxproto, a separate target from libveloxcore, which
still never sees JSON — see docs/adr/0009.

Co-Authored-By: Claude Opus 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_012fgjnqFCS5h5L7gZTZo3rV
This commit is contained in:
2026-09-09 19:55:54 +04:00
co-authored by Claude Opus 5
parent a40585f419
commit 53421d6cb8
171 changed files with 29275 additions and 51 deletions
@@ -0,0 +1,67 @@
{
"name": "media.listVariants \u2014 an HLS master playlist",
"description": "The daemon parses the manifest; the extension never does. Keeping that logic in one language is the whole point.",
"request": {
"jsonrpc": "2.0",
"id": 61,
"method": "media.listVariants",
"params": {
"manifestUrl": "https://cdn.example.org/v/master.m3u8",
"headers": {
"Referer": "https://example.org/watch/42"
}
}
},
"response": {
"jsonrpc": "2.0",
"id": 61,
"result": {
"variants": [
{
"variantId": "v-1080p",
"kind": "video",
"resolution": "1920x1080",
"bitrateBps": 5000000,
"codec": "avc1.640028",
"container": "ts",
"frameRate": 25.0,
"language": null,
"sizeEstimate": 1875000000,
"drm": false
},
{
"variantId": "v-720p",
"kind": "video",
"resolution": "1280x720",
"bitrateBps": 2800000,
"codec": "avc1.4d401f",
"container": "ts",
"frameRate": 25.0,
"language": null,
"sizeEstimate": 1050000000,
"drm": false
},
{
"variantId": "a-en",
"kind": "audio",
"resolution": null,
"bitrateBps": 128000,
"codec": "mp4a.40.2",
"container": "ts",
"frameRate": null,
"language": "en",
"sizeEstimate": 48000000,
"drm": false
}
],
"manifestType": "hls",
"durationSec": 3000.0,
"title": "Episode 42",
"drmProtected": false
}
},
"assertions": [
"sizeEstimate is bitrate x duration and must be labelled as approximate in the UI",
"a DRM-protected variant is reported with drm true and greyed out, never attempted"
]
}