samiandClaude Sonnet 5 4e177ec809 proto: stop conformance from downloading real files, ADR the null-clearing gap
1. download.add.json had startMode "now" against a real, large (~6 GB)
   Ubuntu ISO with saveDir hardcoded to /home/sami/Downloads/Programs.
   Against a real veloxd (tests/conformance/run.sh) that's a real
   download into the real user's real home, every single run — it had
   already happened twice. startMode -> "later" (exercises the add path,
   hands nothing to the engine) and saveDir is dropped entirely (resolves
   to saveTo.defaultDir instead, checked against allowedRoots the same
   way). Documented the rule this fixture was breaking in
   contracts/fixtures/README.md so it doesn't happen a third time.

   Auditing the rest for the same shape (now real: capture.offer, D7)
   found a second, subtler instance: capture.offer.take.json's "take"
   admits a real, immediately-started task the same way download.add
   does, and the "Programs" category's saveDir is a migration-seeded
   builtin (~/Downloads/Programs) that no isolated test setup can
   redirect -- so even after pointing the URL at example.org (RFC 2606),
   a real ~6 GB sparse .veloxpart still landed in the real home on the
   declared Content-Length alone. Shrunk to a plausible-but-small 5 MiB.
   Also scoped to "transport": "uds" -- a real "take" persists an active
   task, so replaying the same fixture again on the second live transport
   against the same shared daemon was hitting capture.offer's own
   dedupe-by-URL and failing on a missing taskId, not a bug.
   download.add's other real-URL siblings (errors/*.invalid-path,
   *.invalid-params, *.disk-full) all fail before admission or are
   requires-gated; left alone.

2. ADR 0018: DAEMON can set a nullable field through download.update /
   settings.set but never clear it back to null, because the generated
   C++ parser collapses "absent" and "explicit null" to the same
   std::nullopt for every optional field (contracts/codegen/gen_cpp.py,
   on purpose, and correct for create-style params -- just wrong for
   patch-style ones, which is the only place the schema documents
   "explicit null clears"). Decision: an opt-in x-clearable schema
   annotation makes just those fields std::optional<std::optional<T>> in
   C++ (TS already round-trips this natively); not a blanket rule
   (would retype response fields like TaskSummary.effectiveUrl that have
   no clear-vs-absent distinction to make), not an explicit clear-list
   field (would redesign a wire contract DAEMON already built against
   just to route around a generator gap). Recorded, not implemented here
   -- that's its own PROTO PR (schema annotations + gen_cpp.py + gen_ts.py
   + regeneration + a minor VERSION bump per ADR 0015), not bundled into
   a fixture-safety pass. Left a pointer to the ADR at the generator
   comment it concerns.

3. Re-verified every xfail entry against current deferrals.md rather
   than trust the reasons already on file: D7/D8 (capture.offer/
   getRules), D3d/e/f/g/h/i (rules, queue.reorder, schedule, limiter,
   download.update/refreshUrl) and D9 (settings) have all closed since
   the list was last pruned, so most of it was stale. Removed everything
   that now cleanly passes; kept and re-reasoned everything that doesn't:
   - errors/download.provideAuth.not-found.json stays, as asked: real
     bug, on_download_provideAuth never checks the task exists.
   - category.list.json (mimeTypes -- documented D3a gap), schedule.set.json
     (nextRunAt -- documented D3f gap): unchanged in substance, reason
     text was already accurate.
   - download.probe/get/list/update.json, session.hello.json,
     queue.start/reorder.json, category.remove.json: not bugs -- each
     golden depicts a richer lifecycle/config state (a probed download,
     real queue or category membership, media/grabber capabilities) than
     this harness's fresh, never-started bound tasks and empty isolated
     DB can produce.
   - limiter.get.json: real fixture bug, not a daemon one -- applyToRunning
     is a write-only instruction on limiter.set, on_limiter_get never
     returns it; the golden shouldn't have had it either. Fixed the
     fixture and tools/mockd's own limiter.get, which had the same field
     hardcoded into its in-memory state independent of the fixture file.
   - grabber.*/media.*: still genuinely stub (M4 territory).
   Only remaining unexpected-pass surfaced while re-verifying
   (errors/capture.offer.ignore.json, always "take" instead of "ignore")
   traced to capture.minSizeBytes defaulting to 0 on a fresh daemon,
   making its below-minimum-size scenario unreachable -- not a bug, so
   raised the setting in run.sh's isolated seeding instead of xfailing it.

ctest -L conformance: green, 100% (2/2), ~87s.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01SFeUKLbdHizrJjLBeK7ffz
2026-09-12 16:56:35 +04:00

Velox Download Manager (VDM)

An IDM-class download manager for Ubuntu 26.04 LTS: multi-segment accelerated HTTP(S) downloading, resume, categories and automatic file distribution, queues and scheduler, speed limiter, a Firefox extension that captures downloads automatically, and clipboard link capture.

Name is a placeholder. Binaries are veloxd, velox-gui, velox, velox-nmhost. Rename before first release if you want something else — do it in M0, never later.


Status

Phase M0 — scaffolding. No implementation code exists yet. This repository currently contains the architecture, the wire contract, the roadmap, and one brief per build lane so that several agents can work in parallel without colliding.

Start here:

Document What it answers
docs/01-architecture.md Process model, why four binaries, framework choices and why
docs/02-roadmap.md Milestones M0M7, what runs in parallel, exit gates
docs/03-gui-spec.md IDM-parity UI: every window, dialog, column, menu
docs/04-engine-design.md Segmentation, resume, buffers, rate limiting, disk I/O
docs/05-extension-spec.md Firefox capture, transports, pairing, media grabber
docs/06-risks-and-spikes.md Snap Firefox, Wayland clipboard, and the other landmines
docs/07-packaging.md .deb/PPA, Flatpak, AMO signing, install layout
contracts/README.md The interface. Both sides build against this
CLAUDE.md Rules of engagement for agents working in this repo

Per-lane briefs live in docs/agents/ — one per agent, each with an owned directory list, a definition of done, and the files it must never touch. To dispatch the agents, use docs/agents/PROMPTS.md — six copy-paste prompts plus the worktree commands and the wave order.


Architecture in one picture

  ┌────────────────────┐   native messaging (stdio JSON)   ┌──────────────┐
  │  Firefox extension │◄─────────────  or  ──────────────►│ velox-nmhost │
  │       (MV3, TS)    │   loopback WS 127.0.0.1 + token   └──────┬───────┘
  └────────────────────┘                                          │
                                                                  │
  ┌────────────────────┐                                          ▼
  │  velox-gui (Qt 6)  │◄──── JSON-RPC 2.0 over Unix socket ──► ┌─────────────┐
  └────────────────────┘      $XDG_RUNTIME_DIR/velox/velox.sock │   veloxd    │
                                                                │  (daemon)   │
  ┌────────────────────┐                                        │             │
  │   velox (CLI)      │◄───────────────────────────────────────┤ libveloxcore│
  └────────────────────┘                                        └──────┬──────┘
                                                                       │
                                                              SQLite + sparse files

The daemon owns all state and all sockets. The GUI is a view — closing it does not stop a download. The extension never touches the disk; it hands URL + headers + cookies to the daemon and gets a task id back.


Repository layout

vdm/
├── contracts/          ⭐ Wire contract: JSON Schema, fixtures, codegen. Frozen per version.
├── core/               C++23  libveloxcore — engine. No UI, no RPC, no SQL.
├── daemon/             C++23  veloxd — RPC server, scheduler, queues, SQLite store.
├── gui/                C++23  velox-gui — Qt 6 Widgets, IDM-parity UI.
├── cli/                C++23  velox — scriptable client.
├── nmhost/             C++23  velox-nmhost — Firefox native-messaging bridge (thin pipe).
├── extension/          TS     Firefox MV3 WebExtension.
├── tools/
│   ├── mockd/          TS mock daemon — lets GUI + extension work before veloxd exists.
│   ├── testserver/     Deliberately hostile HTTP server (no Range, flaky, redirects, auth).
│   ├── bench/          Throughput and CPU benchmarks.
│   └── fuzz/           libFuzzer targets for parsers.
├── tests/
│   ├── conformance/    Protocol suite. Every lane must pass it. Gate for merging.
│   ├── integration/    veloxd + testserver.
│   └── e2e/            Playwright: real Firefox + real daemon + real file on disk.
├── packaging/          debian/, flatpak/, appimage/, native-host manifests.
└── docs/               Everything above, plus adr/ and agents/.

Toolchain bootstrap

Surveyed on this machine 2026-09-09 — most of it is already installed:

Present Version
git · cmake · ninja · g++ · gdb 2.53.0 · 4.2.3 · — · 15.2.0 (C++23 ready)
qt6-base-dev · qt6-tools-dev · qt6-tools-dev-tools
libcurl4-openssl-dev · libsqlite3-dev · nlohmann-json3-dev · libssl-dev
libavformat-dev · libavcodec-dev · ffmpeg
clang-format · clang-tidy · python3 · pkg-config
python3-jsonschema · python3-referencing (conformance static runner)

Only these four are missing:

sudo apt update && sudo apt install -y \
  qt6-svg-dev \       # GUI: SVG icon rendering
  libsecret-1-dev \   # DAEMON: Secret Service for site logins
  nodejs npm \        # EXT + PROTO: extension build, mockd, conformance runner
  clang               # optional: libFuzzer targets in M7

Node in the 26.04 archive may lag; if the extension toolchain needs 22+, use nvm.

Verify with cmake --preset dev && cmake --build --preset dev once lane CORE lands its first target. Note CMake 4.2.3 is installed — newer than the 3.28 floor in CMakeLists.txt, and it hard-errors on cmake_minimum_required below 3.5, so no dependency may ship a pre-3.5 CMake file.

S
Description
a download manager for ubuntu
Readme
1.4 MiB
Languages
C++ 69.9%
TypeScript 20.5%
Python 6.1%
CMake 1.9%
Shell 1.1%
Other 0.4%