Was 7/16 of tools/testserver/README.md's mode table covered by engine_test.cpp. Adds the rest: - engine_expiring_signed_url_recovers_via_refresh_url: an expired signed URL 403s, the engine asks (paused, decision_calls >= 1) rather than failing terminally, and DownloadHandle::refresh_url() with a freshly signed URL completes it -- exercises both do_refresh_url() fixes and the probe-level referrer retry's second-403 path from the previous commit. - engine_403_without_referer_retries_with_origin: no spec.referrer set, the automatic single retry (previous commit) recovers with zero decisions asked. - engine_redirect_chain_follows_to_completion: 5 hops of a plain 302. No core-side change needed -- documents that CURLOPT_FOLLOWLOCATION/ MAXREDIRS (already on, RequestOptions::follow_redirects) cover both the probe's and every worker's own request, not just one of the two. - engine_slow_loris_stall_timeout_fires: proves curl's stall detector (CURLOPT_LOW_SPEED_LIMIT/_TIME, download_task.cpp's hardcoded 1024 B/s for 30s) actually fires rather than hanging. Needed a real fix, not just a test: every other test in this file relies on TestServer's short 1s loris dribble to keep runtime down, but 1s of trickle followed by full-speed streaming never accumulates curl's required 30 CONSECUTIVE seconds under the floor, so it would never actually abort -- a test built on the default dribble would pass by the download merely finishing a bit late, not by observing the stall timeout fire. testserver_fixture.hpp's TestServer gained an explicit-loris-seconds constructor (default ctor unchanged, still 1s) so this one test can ask for a dribble (40s) that genuinely outlasts the threshold. - engine_401_digest_then_provide_auth_completes: same shape as the existing 401-basic test: http_client.cpp already asks libcurl for CURLAUTH_ANY regardless of net::AuthScheme, so this needed no core change -- it passed on the first run and is here to prove that's true end-to-end, not just at the http_client unit level. - engine_chunked_no_length_completes_single_segment: Transfer-Encoding: chunked, no Content-Length anywhere (including HEAD). No core change needed -- takes the same size-agnostic "unknown size, one plain-GET segment" path as the existing no-range test. - utf8/legacy-content-disposition: already covered end-to-end by probe_reads_utf8_content_disposition and probe_reads_legacy_content_disposition in probe_test.cpp (probe-level, as these modes only affect the initial request) -- verified passing, no new test needed. All 20 engine_test.cpp cases and all 10 probe_test.cpp cases pass. Every testserver.py spawned while writing and running this was reaped by TestServer's destructor; verified no stragglers with `ps aux` after each run. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01Q3QrF7rCt21bkAjt9BCDFQ
Velox Download Manager (VDM)
An IDM-class download manager for Ubuntu 26.04 LTS: multi-segment accelerated HTTP(S) downloading, resume, categories and automatic file distribution, queues and scheduler, speed limiter, a Firefox extension that captures downloads automatically, and clipboard link capture.
Name is a placeholder. Binaries are
veloxd,velox-gui,velox,velox-nmhost. Rename before first release if you want something else — do it in M0, never later.
Status
Phase M0 — scaffolding. No implementation code exists yet. This repository currently contains the architecture, the wire contract, the roadmap, and one brief per build lane so that several agents can work in parallel without colliding.
Start here:
| Document | What it answers |
|---|---|
| docs/01-architecture.md | Process model, why four binaries, framework choices and why |
| docs/02-roadmap.md | Milestones M0–M7, what runs in parallel, exit gates |
| docs/03-gui-spec.md | IDM-parity UI: every window, dialog, column, menu |
| docs/04-engine-design.md | Segmentation, resume, buffers, rate limiting, disk I/O |
| docs/05-extension-spec.md | Firefox capture, transports, pairing, media grabber |
| docs/06-risks-and-spikes.md | Snap Firefox, Wayland clipboard, and the other landmines |
| docs/07-packaging.md | .deb/PPA, Flatpak, AMO signing, install layout |
| contracts/README.md | The interface. Both sides build against this |
| CLAUDE.md | Rules of engagement for agents working in this repo |
Per-lane briefs live in docs/agents/ — one per agent, each with an owned directory list, a definition of done, and the files it must never touch. To dispatch the agents, use docs/agents/PROMPTS.md — six copy-paste prompts plus the worktree commands and the wave order.
Architecture in one picture
┌────────────────────┐ native messaging (stdio JSON) ┌──────────────┐
│ Firefox extension │◄───────────── or ──────────────►│ velox-nmhost │
│ (MV3, TS) │ loopback WS 127.0.0.1 + token └──────┬───────┘
└────────────────────┘ │
│
┌────────────────────┐ ▼
│ velox-gui (Qt 6) │◄──── JSON-RPC 2.0 over Unix socket ──► ┌─────────────┐
└────────────────────┘ $XDG_RUNTIME_DIR/velox/velox.sock │ veloxd │
│ (daemon) │
┌────────────────────┐ │ │
│ velox (CLI) │◄───────────────────────────────────────┤ libveloxcore│
└────────────────────┘ └──────┬──────┘
│
SQLite + sparse files
The daemon owns all state and all sockets. The GUI is a view — closing it does not stop a download. The extension never touches the disk; it hands URL + headers + cookies to the daemon and gets a task id back.
Repository layout
vdm/
├── contracts/ ⭐ Wire contract: JSON Schema, fixtures, codegen. Frozen per version.
├── core/ C++23 libveloxcore — engine. No UI, no RPC, no SQL.
├── daemon/ C++23 veloxd — RPC server, scheduler, queues, SQLite store.
├── gui/ C++23 velox-gui — Qt 6 Widgets, IDM-parity UI.
├── cli/ C++23 velox — scriptable client.
├── nmhost/ C++23 velox-nmhost — Firefox native-messaging bridge (thin pipe).
├── extension/ TS Firefox MV3 WebExtension.
├── tools/
│ ├── mockd/ TS mock daemon — lets GUI + extension work before veloxd exists.
│ ├── testserver/ Deliberately hostile HTTP server (no Range, flaky, redirects, auth).
│ ├── bench/ Throughput and CPU benchmarks.
│ └── fuzz/ libFuzzer targets for parsers.
├── tests/
│ ├── conformance/ Protocol suite. Every lane must pass it. Gate for merging.
│ ├── integration/ veloxd + testserver.
│ └── e2e/ Playwright: real Firefox + real daemon + real file on disk.
├── packaging/ debian/, flatpak/, appimage/, native-host manifests.
└── docs/ Everything above, plus adr/ and agents/.
Toolchain bootstrap
Surveyed on this machine 2026-09-09 — most of it is already installed:
| Present | Version |
|---|---|
| git · cmake · ninja · g++ · gdb | 2.53.0 · 4.2.3 · — · 15.2.0 (C++23 ready) |
| qt6-base-dev · qt6-tools-dev · qt6-tools-dev-tools | ✓ |
| libcurl4-openssl-dev · libsqlite3-dev · nlohmann-json3-dev · libssl-dev | ✓ |
| libavformat-dev · libavcodec-dev · ffmpeg | ✓ |
| clang-format · clang-tidy · python3 · pkg-config | ✓ |
| python3-jsonschema · python3-referencing (conformance static runner) | ✓ |
Only these four are missing:
sudo apt update && sudo apt install -y \
qt6-svg-dev \ # GUI: SVG icon rendering
libsecret-1-dev \ # DAEMON: Secret Service for site logins
nodejs npm \ # EXT + PROTO: extension build, mockd, conformance runner
clang # optional: libFuzzer targets in M7
Node in the 26.04 archive may lag; if the extension toolchain needs 22+, use nvm.
Verify with cmake --preset dev && cmake --build --preset dev once lane CORE lands its
first target. Note CMake 4.2.3 is installed — newer than the 3.28 floor in
CMakeLists.txt, and it hard-errors on cmake_minimum_required below 3.5, so no
dependency may ship a pre-3.5 CMake file.