Git of record moves to git.hanzo.ai; GitHub becomes a mirror.
- .gitea/workflows/{ci,publish}.yml — native pipeline on hanzo-build-linux-amd64
act_runners. publish.yml pulls Chrome Web Store + Firefox AMO + npm creds from
KMS via the machine identity (no store cred in any Actions secret store).
- deploy/kms/extension-publish-kms-sync.yaml — KMSSecret CR; canonical KMS path
hanzo:/extension-publish (env prod) for the store creds.
- .github/workflows/sync.yml — mirror main+tags to git.hanzo.ai (the only thing
GitHub does as system of record; no-op until HANZO_GIT_TOKEN seeded).
- .github/workflows/publish.yml — remove store-publish steps (CWS/AMO/VSCE/OVSX/
JetBrains — all no-ops today, those secrets never existed on GitHub). Keep the
live npm publish (interim) + the downloadable GitHub Release.
- docs: PUBLISHING.md + LLM.md rewritten to the native topology.
Non-breaking: npm publish (@hanzo/browser-extension) untouched. No store publish
in this pass. Gated on operator: seed KMS store values, Gitea secrets, mirror.
3.8 KiB
Hanzo Extension
Browser extension (packages/browser) that joins the shared local zapd fabric.
One native primitive — no WebSocket, no localhost port, no mDNS, no CDP bridge.
Ships Chrome / Firefox / Safari. Build: esbuild (src/build.js, pnpm build);
tests: vitest.
Architecture (native ZAP)
extension ─connectNative("ai.hanzo.zap")─► native host ─UDS─► zapd ◄─ hanzo-mcp
shared/native-zap.ts— the ONE transport:connectNativeZap()opens the native port (singleton — one port; the router does evict-and-replace), registers as providerbrowser:<engine>/<host>/default, dispatches inbound ROUTE commands. Cross-browser (browser ∥ chrome).background.ts(Chrome) — dispatch viachrome.debugger(CDP→tab; shows the "debugging this browser" banner; WebKit-incompatible). To be removed — see WXT plan.background-firefox.ts— nativebrowser.*dispatch (no banner). The correct model.browser-dispatch.ts—chrome.debuggeractuation (Chrome-only).shared/evaluable.ts— the ONE evaluate rule:pickEvaluable(code-param aliases) +wrapEvaluable(bare expression passes through; statement bodies → async IIFE with the trailing value auto-returned). Both dispatch paths consume it, so Chrome and Firefox accept identical caller JS.
Wire to zapd: the binary ZAP router envelope (zap-proto/zapd/src/frame.rs); the
browser↔host hop is native-messaging JSON, base64'd, quarantined in the host. Host +
per-browser manifests come from zapd install-host (zap-proto/zapd).
Versioning
Patch only (X.Y.Z+1), never major. package.json is the source of truth; build.js
stamps it into every manifest (chrome/firefox/safari).
CI/CD (native — Hanzo Git, KMS, act_runner)
Git of record is git.hanzo.ai/hanzoai/extension; GitHub is a mirror.
.gitea/workflows/*— native pipeline onhanzo-build-linux-amd64act_runners:ci.yml(amd64 test + build),publish.yml(Chrome Web Store + Firefox AMO + npm).- Secrets are KMS only. The pipeline logs in with the KMS machine identity
(
KMS_CLIENT_ID/KMS_CLIENT_SECRET) and pulls store creds fromhanzo:/extension-publish(envprod). CR:deploy/kms/extension-publish-kms-sync.yaml. No store cred in any Actions secret store. .github/workflows/mirrors + degrades gracefully:sync.ymlpushes main+tags to Hanzo Git;ci.yml/cross-platform-e2e.ymlkeep the macOS(Safari)/Windows/matrix lanes that still need GitHub-hosted runners;publish.ymlkeeps only the GitHub Release + the interim npm publish (store-publish removed → native). See PUBLISHING.md.
Cross-platform — WXT migration (canonical plan, not yet executed)
One WebExtension codebase, every engine. WXT = build/SDK layer (build matrix,
manifest gen, targets, MV3, Vite/TS); webextension-polyfill / @wxt-dev/browser =
browser.* normalization. Custom (keep): shared/native-zap.ts, and the Safari
SafariWebExtensionHandler.swift → ~/.zap/run/zapd.sock bridge. WXT builds Safari
but does NOT give WebKit chrome.debugger — so dispatch must become portable
browser.* (the Firefox model is already correct).
- Adopt WXT build matrix (chrome/firefox/safari) — replaces
build.js. - Collapse forks → one
background.ts; deletebackground-firefox.ts; runtimebrowseradapter. - Collapse dispatch → delete
chrome.debugger/browser-dispatch.ts; actuate overtabs/scripting/webNavigation/browser.*(portable, no banner, Safari-capable). - Transport stays per-platform: Chrome/Firefox
connectNative→ host →zapd.sock; SafariSafariWebExtensionHandler.swift→zapd.sock. - CI guards (last; go red until 1–4 land): fail if
chrome.debugger, thedebuggerpermission, orbackground-firefox.tsappears.
Large, multi-phase — do it as a focused pass, never half-merged.