docs: audit the Computer Use documentation group - #5172
Conversation
Audit the nine Computer Use documents against current source: - foundation-contract: the layer-3 verification description still named apps/desktop/e2e/accessibility-coverage.spec.ts, which apache#4803 retired with the broad route inventories; the section now records that the coverage is carried by the ax-tree-audit rules and the Storybook smoke at their owning boundaries. - The other eight documents verified clean: command names and lab fixture variables (evidence-classes), outcome types and the deterministic harness (host-events-contract), the maka_computer action surface and fail-closed coordinate policy (model-loop), provenance paths and bundled-tools pinning (provenance, cursor-provenance), report classes and sanitizer scripts (provider-evidence), and the story manifest (ui-coverage). - All nine gain the standard frontmatter with last_verified dates. Refs apache#3522 Generated-by: GLM-5.3-Flash (ZCode)
Astro-Han
left a comment
There was a problem hiding this comment.
I re-checked every claim in this PR against main's source, plus a sample of assertions the body didn't list.
Six documents were genuinely verified, and some of it is excellent work. computer-use-cursor-provenance.md holds to the decimal — all thirty CURSOR_MOTION fields, SCORE_SAMPLES = 33, the five score weights, size:20 / shadowBlur:3 / boundsMargin:23, the glyph tuple, the 1725ms → 2100ms deadline. evidence-classes, host-events-contract, model-loop-foundation and the path/pin portions of provenance and provider-evidence all check out, including the bundled-tools.json commit and sha cited in provider-evidence, which match byte for byte. Scope discipline is clean: the diff is nine frontmatter blocks plus one hunk, no silent rewording.
The problems cluster in the one place the audit claimed a win, and they share a cause: the anchors listed in the body were checked and the surrounding prose was not.
P1 — The one drift fixed is replaced with a claim #4803 explicitly refused
Reachability ①. This is the document's verification contract.
computer-use-foundation-contract.md:129-133 now says the retired broad route inventory is carried by ax-tree-audit.mjs (layer 2) and the Storybook smoke (layer 4) at their owning boundaries. Checked against source: scripts/ax-tree-audit.mjs has exactly one consumer, scripts/storybook-visual-smoke.mjs:25, never runs against Electron, and is a generic rule set (ACTIONABLE_AX_ROLES, NAMED_SCOPE_ROLES) containing no route inventory. The Storybook side is a hand-maintained 29-entry story list, not the retired spec's dynamic enumeration of settings navigation.
More to the point, #4803's own body says the opposite: "Exhaustive menu/page inventory, particular copy, and click-through route sweeps are intentionally retired, not claimed as equivalent coverage … Generic AX auditing is no longer described as equivalent to all seven deleted AX journeys." This PR restores precisely the equivalence #4803 declined to make. A rewrite that swaps one false statement for another leaves the document worse than the drift did, because it now carries a last_verified stamp.
The untouched context line at :126 is caught by the same check: it calls ax-tree-audit.mjs the "Storybook 与 Electron E2E 共用的测试侧 AX 规则源", and no spec under apps/desktop/e2e/ references it.
Say what is true instead: layer 3 is gone, the route inventory was retired rather than relocated, and layer 2 is Storybook-only.
P2 — The same drift is still in computer-use-ui-coverage.md, which this PR marks verified
A miss rather than an introduced error, which is why it sits below the one above.
ui-coverage describes the retired spec in its prose: :61-63 "The Electron accessibility test dynamically enumerates settings navigation, then covers modules, global overlays, conversations and all workbar entry points"; :50 "Every current top-level navigation entry is enumerated from the running UI"; :80-82 "Overlay journeys wait for the specifically named prior dialog to close before opening and auditing the next one." None of that exists — the 19 surviving specs contain no AX audit.
foundation-contract:137 points here for the full inventory, so after this PR the two documents contradict each other. "Documents in the group do not contradict each other" is one of the checks #3522 exists to make, and both documents are in this group.
This is the failure mode worth naming for the remaining audit tracks: checking the anchors you listed is not the same as reading the document.
P2 — translation_status is wrong on all nine
On main, a single-language document with no counterpart takes source-only — 14 occurrences (cli-distribution, code-origin-audit, skill-catalog-policy, windows-support, workspace-privacy-context, permission-onboarding-plan, web-search-provider-capability, the astryx-* set). synced (19 occurrences) is for paired documents, as #3522 states. All nine here are unpaired; eight get synced, and computer-use-foundation-contract.md:8 gets original, a value that appears nowhere else in the repository. (model-metadata-firstscreen-optimization.md is the one synced-without-counterpart outlier — one precedent against fourteen.) All nine should be source-only.
P2 — Two more stale claims the pass didn't reach
codex-pip-reverse-engineering.mdis listed as having "no in-repo anchors to verify". It has at least three, and:251citesapps/desktop/src/main/__tests__/computer-use-pip-motion.test.ts, deleted by #2478 — offered as the verification route for the physics and anchor scoring, so a reader following it finds nothing. The other two (:198,:238) resolve. Same class of drift the PR fixed elsewhere, in the document declared exempt from checking.computer-use-provenance.md:138-140contradicts its sibling. It still lists "Exact cursor geometry, center hotspot, motion configuration, close-enough thresholds, path measurement, and core scoring weights" as binary-recovered facts informingcursor-engine.ts, present tense, and:127-128says they "were transcribed into the cursor implementation". Butcomputer-use-cursor-provenance.md:42-45records that #3293 removed every one of them, and the current hotspot is the glyph tip, not its centre — confirmed incursor-engine.ts. On a provenance document the standing claim is that proprietary-derived constants are in shipped source; that is the one place a stale statement actually costs something.
P3 — Smaller drifts in documents marked clean
computer-use-provider-evidence.md:53says "three evidence classes" and lists four;fault-injectionwas added without updating the count, andevidence-classesdefines four.computer-use-foundation-contract.md:91lists five permission lease classes includingpointer mutation.packages/core/src/computer-use.ts:338-341defines four:metadata_read,screenshot_read,keyboard_mutation,semantic_mutation. No pointer class exists.computer-use-foundation-contract.md:269says 协议里没有窗口管理动词.window_action(move/resize/minimize) is in the strict union, andcomputer-use-tools.ts:137uses "moving a window to the left edge of a screen" as its worked example — the exact task the section calls unsolvable. The section reads as a retrospective lesson record and #1952 landed both together, so it is defensible as history; resolving that ambiguity is what a verification pass is for.codex-pip-reverse-engineering.mdcarriesimplementation_status/document_status: current.mainhas precedent forhistoricalon snapshots (astryx-full-surface-audit.md,frontend-architecture-astryx-review-2026-08-09.md,settings-astryx-deep-review.zh-CN.md). Its "where Maka does something else" section does describe current behaviour, socurrentis arguable — which reading did you intend?
What this means for the stamp
last_verified: 2026-09-11 turns a partial pass into standing authority. On six documents it is earned. On ui-coverage, provenance §3 and codex-pip it currently certifies text that is wrong, which makes them less trustworthy after this PR than before it. Worth fixing those three and the translation_status value before the stamps land.
中文
我把本 PR 的每条声称都对 main 的源码重新核了一遍,另外抽查了正文没列的一批断言。
六篇是真查了,其中有做得很好的部分:computer-use-cursor-provenance.md 精确到小数——三十个 CURSOR_MOTION 字段、SCORE_SAMPLES = 33、五个评分权重、size:20/shadowBlur:3/boundsMargin:23、字形元组、1725ms → 2100ms 的 deadline,全部对上。evidence-classes、host-events-contract、model-loop-foundation,以及 provenance 和 provider-evidence 里路径与 pin 的部分也都成立,包括 provider-evidence 引的 bundled-tools.json commit 和 sha,逐字节吻合。范围也干净:diff 就是九个 frontmatter 块加一个 hunk,没有暗改措辞。
问题集中在这次审计声称的那一处胜利上,而且同源:正文列出的锚点查了,锚点周围的正文没读。
P1 — 唯一修掉的漂移,被换成了 #4803 明确拒绝过的说法(可达①)
computer-use-foundation-contract.md:129-133 现在说退役的路由清单由 ax-tree-audit.mjs(层 2)和 Storybook smoke(层 4)在各自的 owning boundary 承担。对源码核实:scripts/ax-tree-audit.mjs 只有一个消费者 scripts/storybook-visual-smoke.mjs:25,从不跑 Electron,内容是一套通用规则(ACTIONABLE_AX_ROLES、NAMED_SCOPE_ROLES),里面没有任何路由清单;Storybook 那边是人工维护的 29 条 story 列表,不是被退役的 spec 那种对 settings 导航的动态枚举。
更要紧的是 #4803 自己的正文写着相反的话:"Exhaustive menu/page inventory, particular copy, and click-through route sweeps are intentionally retired, not claimed as equivalent coverage … Generic AX auditing is no longer described as equivalent to all seven deleted AX journeys."。本 PR 恰好把 #4803 拒绝作出的那个等价声明装了回去。用一个假说法替换另一个假说法,比原来的漂移更糟,因为它现在还带着 last_verified 戳。
同一次检查也照到 :126 那行未改的上下文:它称 ax-tree-audit.mjs 是"Storybook 与 Electron E2E 共用的测试侧 AX 规则源",而 apps/desktop/e2e/ 下没有任何 spec 引用它。
改成实话:层 3 没了,路由清单是被退役而不是被搬走,层 2 只在 Storybook。
P2 — 同一处漂移在 computer-use-ui-coverage.md 里原样还在,而本 PR 把它标成已核
这是漏查,不是主动写错,所以排在上一条之下。
ui-coverage 的正文仍在描述那个已退役的 spec::61-63"The Electron accessibility test dynamically enumerates settings navigation, then covers modules, global overlays, conversations and all workbar entry points";:50"Every current top-level navigation entry is enumerated from the running UI";:80-82"Overlay journeys wait for the specifically named prior dialog to close before opening and auditing the next one."。这些都不存在——存活的 19 个 spec 里没有任何 AX 审计。
foundation-contract:137 正是指向这里取完整清单,所以本 PR 之后两篇文档互相矛盾。"组内文档不得互相矛盾"正是 #3522 要做的检查之一,而两篇都在这一组里。
这个失败模式值得为后续审计批次点明:查你列出的锚点,不等于读了这篇文档。
P2 — translation_status 九篇全错
main 上,没有对应译文的单语文档用 source-only,共 14 处(cli-distribution、code-origin-audit、skill-catalog-policy、windows-support、workspace-privacy-context、permission-onboarding-plan、web-search-provider-capability,以及 astryx-* 那组)。synced(19 处)用于成对文档,#3522 里也是这么写的。这九篇都没有对应译文;八篇写了 synced,computer-use-foundation-contract.md:8 写了 original——这个值在全仓别处一次都没出现过。(model-metadata-firstscreen-optimization.md 是唯一一个无对应却写 synced 的例外,一比十四。)九篇都应该是 source-only。
P2 — 这次检查没够到的另外两条陈旧说法
codex-pip-reverse-engineering.md被列为"无仓内锚点需要核实"。它至少有三个,其中:251引的apps/desktop/src/main/__tests__/computer-use-pip-motion.test.ts已被 #2478 删除——而它正是被当作物理与锚点评分的验证路径给出的,读者照着找会一无所获。另两个(:198、:238)有效。和本 PR 在别处修掉的是同一类漂移,却出现在被宣布免检的那篇里。computer-use-provenance.md:138-140和它的姊妹篇矛盾。它仍以现在时把"Exact cursor geometry, center hotspot, motion configuration, close-enough thresholds, path measurement, and core scoring weights"列为影响cursor-engine.ts的二进制还原事实,:127-128说它们"were transcribed into the cursor implementation"。而computer-use-cursor-provenance.md:42-45记录 #3293 已把这些全部移除,当前的 hotspot 是字形尖端而非中心——我在cursor-engine.ts里确认了。在一篇 provenance 文档上,这条未撤回的声称是说"专有来源的常量在已发布源码里",那恰恰是陈旧说法唯一真正有代价的地方。
P3 — 被标为 clean 的文档里的小漂移
computer-use-provider-evidence.md:53写"three evidence classes"却列了四个;fault-injection加进列表时没改数字,而evidence-classes定义的就是四类。computer-use-foundation-contract.md:91列了五种权限租约类别,含pointer mutation。packages/core/src/computer-use.ts:338-341定义的是四种:metadata_read、screenshot_read、keyboard_mutation、semantic_mutation,没有 pointer 类。computer-use-foundation-contract.md:269说"协议里没有窗口管理动词"。window_action(move/resize/minimize)就在严格联合类型里,而computer-use-tools.ts:137的工具描述用"moving a window to the left edge of a screen"当示例——正是该节宣称无解的那个任务。该节读起来像回溯性的经验记录,且 #1952 把小节和动词一起落地,所以当历史记录看是说得通的;把这个歧义解决掉正是一次核查该做的事。codex-pip-reverse-engineering.md的implementation_status/document_status是current。main上对快照类文档有historical的先例(astryx-full-surface-audit.md、frontend-architecture-astryx-review-2026-08-09.md、settings-astryx-deep-review.zh-CN.md)。它的"Maka 在哪里做了别的选择"一节确实描述当前行为,所以current也讲得通——你本来想表达哪一种?
这个戳意味着什么
last_verified: 2026-09-11 把一次部分核查变成了长期权威。在六篇上它是挣来的;在 ui-coverage、provenance 第 3 节和 codex-pip 上,它目前认证的是错的文字,使这三篇在本 PR 之后比之前更不可信。建议把这三篇和 translation_status 的取值一起修掉,再让戳落地。
Four follow-ups from the review of the A10 audit: - foundation-contract layer 3 now says what apache#4803 actually did: the broad route inventory was retired rather than relocated, nothing enumerates routes against a running Electron app, and layer 2's ax-tree-audit.mjs runs Storybook-only. The old text claimed equivalent coverage that apache#4803 explicitly declined to make, and the adjacent "Storybook 与 Electron E2E 共用" line said the same thing. - ui-coverage: the three prose passages still describing the retired Electron spec (dynamic settings-navigation enumeration, named-dialog overlay sequencing, running-UI inventory) are corrected the same way, so the two documents no longer contradict each other. - translation_status is source-only on all nine documents: none has a counterpart, and main's convention reserves synced for pairs. - provenance §3 marks the binary-recovered cursor facts as removed by apache#3293 (hotspot is now the glyph tip); codex-pip notes that the pip-motion test it cited as exact coverage was deleted by apache#2478; provider-evidence says four evidence classes; the lease-class list matches computer-use.ts's four classes; the window-action lesson is annotated with its date. Refs apache#3522 Generated-by: GLM-5.3-Flash (ZCode)
88167b1 to
aa4bfca
Compare
|
All findings addressed at P1 — layer 3 now says what #4803 actually did. The section records that the broad route inventory was retired rather than relocated, that nothing enumerates routes against a running Electron app, and that the gap is intentional per #4803's own "not claimed as equivalent coverage". The adjacent line calling P2 — ui-coverage's three passages on the retired spec. The dynamic settings-navigation enumeration sentence, the Settings table row's "enumerated from the running UI", and the overlay-journey sequencing paragraph are each corrected to attribute that coverage to the retired spec (#4803) and to name what the surviving journeys actually cover. The two documents no longer contradict each other. P2 — P2 — the two unreached stale claims. P3s. provider-evidence says "four evidence classes"; the lease-class list now names The named failure mode — checking listed anchors is not reading the document — is taken; the corrected passages were all found by reading the prose rather than grepping anchors, and that's how the remaining audit batches will run. 中文:五组全部处理(aa4bfca02)——layer3 按 #4803 原意改写(退役而非迁移、缺口是有意接受);ui-coverage 三处退役描述同改,两文档不再矛盾;九篇 translation_status 全改 source-only;codex-pip 的已删测试引用与 provenance §3 的过时事实(#3293 已移除、hotspot 现为字形尖端)均已标注;P3 三处小漂移修正。"查锚点不等于读文档"这个教训已记入工作记忆,后续审计批次按通读执行。 |
There was a problem hiding this comment.
PR 5172 Review
结论
APPROVE
Computer Use 文档组审计:唯一实质 drift(layer 3 指向已退役的 accessibility-coverage.spec.ts)修正且与源码核实一致——该 spec 在 HEAD 不存在,ax-tree-audit.mjs 当前唯一消费者是 storybook-visual-smoke.mjs:25。lease 四类名与 packages/core/src/computer-use.ts:338-341(metadata_read/screenshot_read/keyboard_mutation/semantic_mutation,无 pointer_mutation)一致;"four evidence classes" 与文档内列出的四个 bullet 一致;window_action 已在严格动作集(computer-use.ts:176);MAKA_CU_AX_MODEL_LAB_ROOT 存在于 scripts/computer-use/lab-root.mjs。其余 8 份文档仅加 frontmatter。
me2seeks
left a comment
There was a problem hiding this comment.
Maka auto review
Requesting one factual correction before merging: the new PiP verification paragraph attributes a change to the cursor replacement that did not change PiP motion. The other reviewed corrections, including the explicit retirement of broad Electron AX route coverage, are supported by the source and #4803's stated tradeoff.
中文
合并前请修正一处事实错误:新加入的画中画验证段落把光标参数替换误写成画中画运动参数变化。其余已核对的主要更正,包括 Electron 广域 AX 路由覆盖明确退役而非等价迁移,与源码及 #4803 的决策相符。
| `apps/desktop/src/main/__tests__/computer-use-pip-motion.test.ts`. | ||
| The physics and the anchor scoring were covered without a desktop in | ||
| `apps/desktop/src/main/__tests__/computer-use-pip-motion.test.ts` (deleted by | ||
| #2478); after #3293 replaced the transcribed constants, that exact-coverage |
There was a problem hiding this comment.
[P2] Separate PiP test retirement from the cursor replacement
This paragraph discusses PiP physics and anchor scoring, but #3293 was implemented by #3456 (047567c) for the agent cursor, not the PiP window's motion model. I compared apps/desktop/src/main/computer-use/pip-motion.ts before that commit, after it, and at this PR head: all three contents are byte-identical. The current module still defines the attributed PiP springs (dragging 900/55, settling 320/42) and throw constants (0.55/5000/0.45); pip-window.ts imports and uses them. The replacement updated the cursor engine and related glyph assets, including the PiP glyph, without replacing the PiP springs or anchor scoring.
The deleted test reference is correctly identified as #2478. Please state that its removal ends the claim that this particular test provides current coverage, and remove the causal claim that #3293 replaced the PiP motion constants. Link to cursor provenance only with an explicit distinction between the agent cursor and PiP window motion. Otherwise this new audit text misrecords the current implementation's provenance and contradicts this document's own “What Maka copies” section.
Validation: the two retired test paths are absent; the PiP source comparison above was performed against Git objects; all nine metadata blocks and diff whitespace were checked; 11 AX-rule tests passed. No new native/provider qualification or legal conclusion is claimed.
中文
本段讨论画中画的物理运动和停靠点评分,但 #3293 对应的 #3456(047567c4b)替换的是代理光标参数,并非画中画窗口的运动模型。我比较了该提交前、提交后和本 PR head 的 pip-motion.ts,三者逐字节相同。当前仍保留并由 pip-window.ts 使用弹簧参数 900/55、320/42 和投掷参数 0.55/5000/0.45。替换涉及光标引擎及相关字形资产(包括画中画里的光标图形),没有替换画中画弹簧或停靠评分。
测试由 #2478 删除这一点正确。建议只说明该测试已退役,不能再据其声称当前覆盖;删除“#3293 替换画中画运动常量”的因果描述。如引用光标来源文档,需要明确区分代理光标和画中画窗口运动,否则新的审计文字会误记当前实现来源,并与本文 What Maka copies 段冲突。
已核验退役路径、Git 对象内容、九篇元数据及 diff 空白检查,11 项 AX 规则测试通过。此处不声称新增原生/真实模型验证,也不作法律判断。
|
Pushed 8de10b2: the PiP paragraph no longer claims #3293 replaced the PiP motion constants. I re-verified the reviewer's core fact before writing: |
Review follow-up on apache#5172. The audit paragraph attributed the PiP window's motion constants to the apache#3293 cursor replacement, but `pip-motion.ts` is byte-identical before apache#3456, after it, and at this head — the replacement rebuilt the agent cursor engine and glyphs, not the PiP springs or anchor scoring. The paragraph now says the apache#2478 deletion only ends the retired test's coverage, records that the motion module is untouched, and scopes the cursor-provenance link to the agent cursor explicitly. Generated-by: GLM-5.3-Flash (ZCode)
Summary
Audits the nine Computer Use documents (audit track A10 of #3522) against current source, per the established group-audit process.
One drift found and fixed:
computer-use-foundation-contract.mdstill namedapps/desktop/e2e/accessibility-coverage.spec.tsas verification layer 3. That spec was retired by test(desktop): reduce P1 Electron coverage at owning boundaries #4803 ("explicitly retire broad route inventories") on 2026-09-06 — 354 lines removed. The section now records that the broad route inventory is carried by theax-tree-audit.mjsrules (layer 2) and the Storybook smoke (layer 4) at their owning boundaries, with Electron E2E retaining the boundary-internal journeys test(desktop): reduce P1 Electron coverage at owning boundaries #4803 kept.The other eight verified clean, spot-checked against source:
computer-use-evidence-classes.md: command names (real-ax/real-model/restart-soak), theMAKA_CU_AX_MODEL_LAB_ROOTfixture variable, and theuser_intervenedinjection all matchscripts/computer-use.mjsand the backend.computer-use-host-events-contract.md: typed outcome names (screen_locked,blocked_url,outcome_unknown) and the deterministic cross-layer harness tests exist.computer-use-model-loop-foundation.md: themaka_computertool surface (click_element,set_value, …) and the fail-closed coordinate policy matchcomputer-use-tools.ts.computer-use-provenance.md/computer-use-cursor-provenance.md: all ten referenced repo paths exist;bundled-tools.jsonstill pinsdistributionReady: false.computer-use-provider-evidence.md: report classes and the sanitizer/harness/matrix scripts match.computer-use-ui-coverage.md: the required Computer Use story manifest anchor exists instorybook-visual-smoke.mjs.codex-pip-reverse-engineering.md: a historical record of external-binary inspection; no in-repo anchors to verify.All nine documents gain the standard frontmatter with
last_verified: 2026-09-11.Verification
git log --all -- apps/desktop/e2e/accessibility-coverage.spec.ts→ removed in 8336c40 (#4803)REQUIRED_COMPUTER_USE_STORY_IDSpresent in the smoke runnerdistributionReady: falsepresentzh-CNoriginal)AI use
Implemented with ZCode (GLM-5.3-Flash): per-document read + source cross-check following the group-audit process used for the earlier #3522 groups,
Generated-bytrailer in the commit.Checklist