Additional
Browser parity gaps and delivery plan
Synced from github.com/CoWork-OS/CoWork-OS/docs
Updated 1 October 2026. This is the consolidated execution backlog for the existing W0–W9 plan. It does not replace or narrow that plan.
Desktop isolation gate
Browser work must not change native desktop behavior or presentation merely to make the opt-in preview work. A shared composer notice escaped that boundary after merge. The local correction restored the native desktop behavior. The original readiness pass did not establish whole-PR desktop neutrality. Native compatibility remains open until shared runtime changes and installed artifacts have independent regression evidence, including desktop runs with browser hosting both disabled and enabled.
Current evidence
The browser entry uses the shared desktop React App. Bounded disposable host/UI smoke covers pairing and core task admission, decisions, files, terminal, Git, settings navigation, projects, agents, disabled scheduled-job CRUD, notifications, Memory facts/imports/approvals/promotion, and workspace kits. These checks do not prove real-model execution or full desktop parity.
The checked-in API inventory reports 799 directly referenced renderer bridge names: 68 with explicit preview evidence, 212 with browser handler source but no explicit UI acceptance, and 504 unreviewed. The remaining names have separate classifications such as native-only. This inventory predates the awareness increment and is a triage baseline, not a completion percentage. An unreviewed method is a classification gap; it is not automatically an absent implementation. Re-run the generator and review runtime manifests before assigning implementation work.
Awareness config/belief adapters and persist-before-publication changes are implemented. Eight focused tests passed. The corrected expanded host/UI acceptance passed on 30 September: config readback, deletion denial, Private Mode save/restore, Confirm and authorized Forget. Device collectors, real-task prompt use, restart and load acceptance remain open.
Port 18789 was verified to belong to the installed /Applications/CoWork OS.app; it returned HTTP 404 for /app/ and its manifest. That audit used an isolated preview branch at 18989 with the separate Browser QA profile. After PR #272 merged, local main was rebuilt and used for both the source desktop and QA browser host; installed bundles were not replaced. This closes build identification, not the entire control audit.
Point 2 and 3 checkpoint
The latest source build contains the shared desktop UI and a corrected pairing screen: desktop typography and colors, a compact branded card, stacked styled controls, keyboard focus, disabled/loading states and actionable errors. Empty-code, invalid-code and successful pairing were checked in the live browser. Screenshot: /tmp/cowork-pairing-ui-fixed.png.
Point 2 has real-provider artifact evidence: the Node CSV report produced East 30, West 12 and total 42; Node follow-up bytes changed from alpha to beta. The latest Electron file task and follow-up both completed with truthful plain-text confirmations, inspected alpha → beta bytes, and unchanged token guards. History, files and provider settings survived Electron host restart/re-pair. Browser usage counters retain real numeric values. Standalone quality-pass prompts no longer inherit a tool-execution prompt. The recovery harness now includes actual in-flight provider cancellation, lost replies, durable admission/follow-up receipts, attachment recovery, two authenticated sessions and same-profile restart.
Point 3's portable settings, MCP lifecycle/registry review, Skill Store imports/progress, managed accounts, gateway configuration and bounded subscriptions are implemented through real host managers. Node and freshly compiled Electron integration smoke passed for local skill import, synthetic account CRUD, encrypted disabled-channel storage, redaction and restart readback. ChatGPT subscription login remains unverified; OpenRouter supplies the real-model evidence.
The real MCP fixture call exposed two defects now fixed: built-in tools displaced an explicitly requested integration tool, and a reporting-only reference incorrectly required another call. The latest real-provider browser task displayed External service → Allow once, called mcp_qa_echo exactly once, returned qa_echo:browser-tool-connected, and completed its reporting step with zero extra tool calls. The fixture was disconnected and disabled afterward. Focused manager tests verify disconnected calls are denied.
The bounded pre-merge PR readiness pass completed; its desktop coverage was limited and the subsequent UI regression required a local isolation correction. Points 2 and 3 have source-checkout acceptance for the workflows above; full release acceptance remains open for structured-input recovery, real multi-tab network interruption, the provider/browser matrix, and installed artifacts. Points 4–10 remain deferred. This branch is an opt-in preview, not a completed parity release.
Gaps, repairs, and exit tests
| Order | Gap | Concrete repair | Required exit evidence |
|---|---|---|---|
| 1 | The open browser can be stale, and UI reuse does not guarantee that its controls work. | Identify its host process, profile, checkout, and build. Load the current isolated artifacts without replacing user data. Audit every visible route and actionable control against the authenticated method/capability manifest. Wire portable actions to real services; native actions get a precise reason or a meaningful browser equivalent. | A route/control ledger with each control classified and tested; no unexplained inert button; the actual refreshed browser displays the shared desktop layout and completed actions. |
| 2 | Core model execution and recovery are not yet proven end to end. | Execute an authorized disposable task with the configured host provider: upload input, answer approval/input, inspect output, follow up, cancel, and exercise two tabs, reply loss, refresh, disconnect and host restart. Fix recovery defects through the existing task engine and durable receipts. | One admitted task per operation; coherent committed history; no duplicated side effect; recovered queued follow-ups and attachments; pending decisions correct across tabs; documented PTY restart limitations. Repeat against Node and Electron hosts. |
| 3 | Portable settings and integrations remain incomplete. | Classify remaining preferences, protected credentials, managed accounts, MCP install/connect/update, Skill Store install/import, gateway channels and supported OAuth/device flows. Reuse existing managers, enforce current owner/workspace policy, expose bounded progress, and surface failures. | Save/readback/restart for settings; install or connect one supported integration, execute an authorized task, revoke it and prove access fails. Verify secrets absent from normal DTOs, events and logs. Host-specific integrations have explicit limits. |
| 4 | Memory, awareness and autonomy are only partially delivered. | Finish awareness UI acceptance; add supported external-memory setup/test, file imports, authorized Chronicle deletion/configuration, and autonomy config/state/decisions/actions/evaluation. Separate portable controls from host device collectors. | Browser clicks persist; refused storage leaves prior live state; stale workspace replies are ignored; deletion honors stored ownership and delete permission. A subsequent real task demonstrates edited/promoted memory use; autonomy evaluation and external memory run through real host services. |
| 5 | Automation and agent CRUD do not prove execution or team parity. | Complete missing routine, trigger, bot, team, lineage, pause/resume/stop and execution controls, including Node service initialization and event subscriptions. | One intended scheduled run produces output; pause prevents the next run; host restart does not duplicate a scheduler or run. Team run/cancel preserves ownership, lineage and approvals. |
| 6 | Devices, environments and managed sessions need workflow proof. | Review missing adapters and host registrations; make target host identity explicit and apply existing access/approval policy to remote actions. | An operation affects the selected disposable host only; another target is rejected; disconnect/reconnect and session lifecycle work; credentials stay on the host. |
| 7 | Canvas, generated artifact media, spreadsheet editing and interactive host-browser control remain incomplete or unverified. | Adapt artifact viewers and workbook operations; isolate active previews from app origin. Implement authenticated browser streaming/input with explicit session ownership when supported by the host. Preserve the existing session rather than create a parallel browser engine. | View/export/edit a generated artifact; save/reopen a workbook; sandbox escape attempts fail; reconnect to the same host browser session and prove input ownership/policy checks. Host limitations remain explicit. |
| 8 | Reports, usage, budgets and broad data panels need full action and load acceptance. | Review handler-only reads/writes, export/delete paths, pagination and subscriptions. Replace swallowed errors or fabricated empty defaults on exposed flows. | Representative queries and exports work; a budget edit affects a subsequent task; context switches do not leak data; large reads do not starve active streaming. |
| 9 | Browser conveniences and compatibility are unfinished. | Implement supported clipboard, microphone/voice, notifications, shortcuts and responsive behavior. Validate Chrome, Firefox, Safari and the selected mobile matrix, including permission denial, secure contexts, background tabs, sleep/wake and network changes. | Keyboard/focus/accessibility checks pass on advertised combinations; permission denial is actionable; core task work remains usable while backgrounded and after reconnect. Record performance against agreed W0 budgets. |
| 10 | Installed release, native compatibility and rollback gates are incomplete. | Repeat the complete workflow from fresh npm, packaged macOS and packaged Linux artifacts; validate visible desktop UI and existing native clients. Exercise older database upgrade, base-path deployment, proxy/origin/session expiry, web disable and rollback. Migrate legacy web consumers before removing compatibility paths. | Fresh artifact-specific real-workflow evidence; supported native workflows remain functional; upgrade and rollback rehearsed without losing task data; full required build/test/format/inventory/release gates pass. |
Delivery sequence
- Establish a trustworthy running build and finish the control ledger. Finish the in-flight awareness check; fix failures in that flow before marking it accepted.
- Prove the core real-model workflow and failure recovery. This is the release-critical gate; stop adding peripheral families if it reveals a correctness defect.
- Deliver the portable families in rows 3–8 as bounded increments. Each increment includes service/Node parity, closed request validation, current authorization, capability publication, shared UI wiring, durable error behavior and its browser acceptance workflow. A handler alone does not close an item.
- Run browser convenience, compatibility, accessibility and performance checks; fix the observed defects.
- Run installed-artifact, native regression, upgrade and rollback gates. Only then claim the complete browser release or portable parity.
Progress reporting
Use this backlog plus the generated capability matrix as the single source of status. Record each item as Unclassified, Missing implementation, Implemented but unverified, Verified in source checkout, or Verified in installed artifact. Link each verification to its command/result and exact host/build/profile. Do not turn unreviewed method counts into completion percentages.
At each delivery checkpoint report only: gaps closed with evidence, failing checks, remaining gap groups, and the next exit test. Avoid repeated broad smoke runs unless a relevant change or failure justifies them. Keep test scenarios disposable and preserve the user's primary checkout/profile.
Definition of done
All portable controls have real behavior with accepted workflows, or a specific documented host/provider limitation. There are no unexplained inert controls, hidden failures, or success stubs. The complete W0–W9 requirements, core recovery invariants, native compatibility, installed-artifact workflows, browser matrix and rollback gates remain required. Native OS window controls can remain host-only; missing portable adapters cannot be relabeled native-only to close the plan.