gui/docs/pkg-qa-requests-m1.md R3, filed by the previous session: three GUI M1 DoD items (10k rows at 60 fps, flat RSS over 10 minutes, --slow/--flaky/--drop-connection recovery) had nowhere to run in CI. This is the harness — `gui/tests/dod/run.sh <gate> [--json <path>]`, exactly the path/invocation contract tests/integration/README.md already specified — plus `gui/tests/dod/dod_harness.cpp`, the Qt/RpcClient-driven binary that actually runs each gate against a real mockd run.sh starts and tears down itself. - scroll-60fps: an eased scripted scroll over the whole loaded table, timing each step's synchronous repaint; p99 against a 16.6 ms budget (auto-scaled 4x under a sanitized build — ASan/UBSan overhead, not a loosened bar, see the harness's isSanitizedBuild()). - rss-flat: samples this process's own VmRSS at 1 Hz across the run, discards a warm-up window, checks post-warm-up growth against a stated 20 MiB slack. - unhappy-path: three phases (slow/flaky/drop-connection), each its own mockd instance; passes when the client reaches and holds Connected with no crash or hang. A watchdog (the harness's own QTimer, backstopped by run.sh's external `timeout`) turns a genuine hang into a bounded non-zero exit rather than needing the CI caller to timeout(1) around it. Every gate honours the exit-code and --json contract PKG/QA's pre-drafted CI job expects unchanged (one addition needed: the build step must also build the `gui-dod-harness` target, noted in the R3 update). No leaked mockd processes on any exit path (`trap cleanup EXIT INT TERM`); no writes outside a tempdir except the caller's own --json path. Verified live end-to-end (not just unit-level): all three gates run against a real mockd under the exact `ASAN_OPTIONS=detect_leaks=1:halt_on_error=1` `.github/workflows/ci.yml`'s sanitizers job already sets, all pass, and scroll-60fps was forced red once on purpose (VELOX_DOD_FRAME_BUDGET_MS=1) to prove the fail path and exit code actually work. Building this is also what surfaced the two RpcClient bugs fixed in the previous commit, and one real gap in mockd itself — --drop-connection never worked over the Unix socket transport (only WebSocket) — filed as gui/docs/proto-requests-m1.md since tools/mockd is PROTO's file. gui/docs/pkg-qa-requests-m1.md R3 and R4 (an unrelated, non-blocking Qt6::DBus CMake hygiene note filed while wiring the clipboard global-shortcut path) are updated with the concrete findings above. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01NSCdCWFXBTSBBK3MzWtJiC
Velox Download Manager (VDM)
An IDM-class download manager for Ubuntu 26.04 LTS: multi-segment accelerated HTTP(S) downloading, resume, categories and automatic file distribution, queues and scheduler, speed limiter, a Firefox extension that captures downloads automatically, and clipboard link capture.
Name is a placeholder. Binaries are
veloxd,velox-gui,velox,velox-nmhost. Rename before first release if you want something else — do it in M0, never later.
Status
Phase M0 — scaffolding. No implementation code exists yet. This repository currently contains the architecture, the wire contract, the roadmap, and one brief per build lane so that several agents can work in parallel without colliding.
Start here:
| Document | What it answers |
|---|---|
| docs/01-architecture.md | Process model, why four binaries, framework choices and why |
| docs/02-roadmap.md | Milestones M0–M7, what runs in parallel, exit gates |
| docs/03-gui-spec.md | IDM-parity UI: every window, dialog, column, menu |
| docs/04-engine-design.md | Segmentation, resume, buffers, rate limiting, disk I/O |
| docs/05-extension-spec.md | Firefox capture, transports, pairing, media grabber |
| docs/06-risks-and-spikes.md | Snap Firefox, Wayland clipboard, and the other landmines |
| docs/07-packaging.md | .deb/PPA, Flatpak, AMO signing, install layout |
| contracts/README.md | The interface. Both sides build against this |
| CLAUDE.md | Rules of engagement for agents working in this repo |
Per-lane briefs live in docs/agents/ — one per agent, each with an owned directory list, a definition of done, and the files it must never touch. To dispatch the agents, use docs/agents/PROMPTS.md — six copy-paste prompts plus the worktree commands and the wave order.
Architecture in one picture
┌────────────────────┐ native messaging (stdio JSON) ┌──────────────┐
│ Firefox extension │◄───────────── or ──────────────►│ velox-nmhost │
│ (MV3, TS) │ loopback WS 127.0.0.1 + token └──────┬───────┘
└────────────────────┘ │
│
┌────────────────────┐ ▼
│ velox-gui (Qt 6) │◄──── JSON-RPC 2.0 over Unix socket ──► ┌─────────────┐
└────────────────────┘ $XDG_RUNTIME_DIR/velox/velox.sock │ veloxd │
│ (daemon) │
┌────────────────────┐ │ │
│ velox (CLI) │◄───────────────────────────────────────┤ libveloxcore│
└────────────────────┘ └──────┬──────┘
│
SQLite + sparse files
The daemon owns all state and all sockets. The GUI is a view — closing it does not stop a download. The extension never touches the disk; it hands URL + headers + cookies to the daemon and gets a task id back.
Repository layout
vdm/
├── contracts/ ⭐ Wire contract: JSON Schema, fixtures, codegen. Frozen per version.
├── core/ C++23 libveloxcore — engine. No UI, no RPC, no SQL.
├── daemon/ C++23 veloxd — RPC server, scheduler, queues, SQLite store.
├── gui/ C++23 velox-gui — Qt 6 Widgets, IDM-parity UI.
├── cli/ C++23 velox — scriptable client.
├── nmhost/ C++23 velox-nmhost — Firefox native-messaging bridge (thin pipe).
├── extension/ TS Firefox MV3 WebExtension.
├── tools/
│ ├── mockd/ TS mock daemon — lets GUI + extension work before veloxd exists.
│ ├── testserver/ Deliberately hostile HTTP server (no Range, flaky, redirects, auth).
│ ├── bench/ Throughput and CPU benchmarks.
│ └── fuzz/ libFuzzer targets for parsers.
├── tests/
│ ├── conformance/ Protocol suite. Every lane must pass it. Gate for merging.
│ ├── integration/ veloxd + testserver.
│ └── e2e/ Playwright: real Firefox + real daemon + real file on disk.
├── packaging/ debian/, flatpak/, appimage/, native-host manifests.
└── docs/ Everything above, plus adr/ and agents/.
Toolchain bootstrap
Surveyed on this machine 2026-09-09 — most of it is already installed:
| Present | Version |
|---|---|
| git · cmake · ninja · g++ · gdb | 2.53.0 · 4.2.3 · — · 15.2.0 (C++23 ready) |
| qt6-base-dev · qt6-tools-dev · qt6-tools-dev-tools | ✓ |
| libcurl4-openssl-dev · libsqlite3-dev · nlohmann-json3-dev · libssl-dev | ✓ |
| libavformat-dev · libavcodec-dev · ffmpeg | ✓ |
| clang-format · clang-tidy · python3 · pkg-config | ✓ |
| python3-jsonschema · python3-referencing (conformance static runner) | ✓ |
Only these four are missing:
sudo apt update && sudo apt install -y \
qt6-svg-dev \ # GUI: SVG icon rendering
libsecret-1-dev \ # DAEMON: Secret Service for site logins
nodejs npm \ # EXT + PROTO: extension build, mockd, conformance runner
clang # optional: libFuzzer targets in M7
Node in the 26.04 archive may lag; if the extension toolchain needs 22+, use nvm.
Verify with cmake --preset dev && cmake --build --preset dev once lane CORE lands its
first target. Note CMake 4.2.3 is installed — newer than the 3.28 floor in
CMakeLists.txt, and it hard-errors on cmake_minimum_required below 3.5, so no
dependency may ship a pre-3.5 CMake file.