915 downloads in the last 30 days
2026-09-09: 4 downloads2026-09-10: 18 downloads2026-09-11: 20 downloads2026-09-12: 23 downloads2026-09-13: 43 downloads2026-09-14: 35 downloads2026-09-15: 20 downloads2026-09-16: 8 downloads2026-09-17: 26 downloads2026-09-18: 21 downloads2026-09-19: 28 downloads2026-09-20: 13 downloads2026-09-21: 17 downloads2026-09-22: 13 downloads2026-09-23: 11 downloads2026-09-24: 2 downloads2026-09-25: 5 downloads2026-09-26: 4 downloads2026-09-27: 5 downloads2026-09-28: 2 downloads2026-09-29: 22 downloads2026-09-30: 66 downloads2026-10-01: 31 downloads2026-10-02: 18 downloads2026-10-03: 30 downloads2026-10-04: 23 downloads2026-10-05: 28 downloads2026-10-06: 202 downloads2026-10-07: 73 downloads2026-10-08: 103 downloads

Releases 1153

Standalone per-platform binaries to download and run, no tools needed. The newest is pinned on top.

Compare →
Latest release v2.0.705

Annotate's quick colors are red, blue and green: the muddy yellow/orange third color is gone from the trio and from Multi's automatic cycle (red, blue, green, purple), so every mark has a color anyone can name to the AI. Yellow stays in the More flyout, and every swatch shows its color name on hover (John, 2026-10-07).

Stable link for websites and docs: /download/adom/pup-bridge/latest

All releases showing 441-460 of 1153

v2.0.258 2026-08-20
  • selftest T10: name the window that took foreground. Running on John's own laptop while he worked, every click on his Edge window reported '#56 REGRESSED' — a false alarm against a shipped fix. Only a pup window taking focus can support that accusation. (John Lauer)
  • pup-user-foreground: record the 2026-08-20 window-destruction incident (lock-file orphan kill + refCount kills) and the target_not_found diagnosis trap (John Lauer)
  • v2.0.257: Never kill a profile's Chrome to free its lock while pup has live sessions on that profile. This is what actually destroyed three of John's windows today. The pre-launch cleanup kills whatever holds the profile lock, authorized by an INFERENCE: a lock exists and I could not reconnect just now, therefore the holder is a dead orphan from an unclean shutdown. The reconnect gives up after a 3s probe plus a 5s puppeteer.connect, and on a loaded machine a healthy Chrome misses those deadlines, so pup declared the LIVE shared adom-you Chrome an orphan and killed it, taking two other threads' dashboards and the ab web-demo window John was actively using; pup then relaunched them and reconciled them away as closed, so from his side they vanished. Ground truth beats inference: if any live session is bound to the profile, that process is serving the user's windows, so pup now retries the reconnect patiently (20s) and adopts it, and if that fails it fails THIS launch honestly instead of destroying work that is not ours to destroy. A failed launch costs a retry; a wrong kill costs windows the user cannot get back. (John Lauer)
v2.0.257 2026-08-20
  • v2.0.256: Never let a refcount authorize killing a shared Chrome. #434 established the rule (decide from ground truth, not the cached refCount) but converted only ONE of four call sites; the other three still ran 'if (--refCount <= 0) kill'. That counter is provably wrong right after a restart: recovery re-creates the browser entry with refCount 0 and does not count the sessions it just restored. Measured on AdomLapper today: three recovered windows (fusion-dashboard, kicad-maint, and the ab web-demo window John was actively using) sat on the shared adom-you Chrome at refCount 0, the next path decremented 0 to 0 and force-killed the process hosting all three, and pup then relaunched and reconciled them away as closed. All four sites now go through one primitive, killProfileBrowserIfUnused, which refuses while ANY other session is bound to that profile or any verb is in flight; the refcount is telemetry only. (John Lauer)
v2.0.256 2026-08-20
  • v2.0.255: Fix adom/pup-bridge#65: pup_evaluate ran the HOVER handler. Its alias label was written as a switch fallthrough above case 'pup_hover' instead of above case 'pup_eval', so every pup_evaluate call returned 'pup_hover needs selector, or x + y' / hover_target_missing while the _hint stayed pup_evaluate's own — right docs plus wrong error, the tell for a misdispatch. That made the only verb that can READ the DOM unusable, so a page could be driven but never asserted on. Also accepts expr/expression/script/js/code (John probed all four, none of which ever reached the handler) and documents them in the catalog. Second bug from the same report: PUP_ISSUES_REF, pasted into every response's _reportIssues hint, still named the pre-rename slug adom/adom-desktop-puppeteer-bridge, which 404s — so the one string whose job is routing bug reports sent them nowhere. Now adom/pup-bridge, in the hint and in the dashboard link. (John Lauer)
v2.0.255 2026-08-20
  • v2.0.254: Stop re-fetching a favicon that does not exist. 2.0.229 bounded the SUMMARY log line but not the work or the two rail-failure lines beneath it, so every overlay re-assert on a faviconless page re-ran BOTH network rails (a 5s-timeout node fetch plus a CDP fetch) and logged two more lines, forever. Measured live on ConfRoomROG: those three lines filled the entire log tail and degraded a real investigation, the exact trap the icon-audit skill warns about. Adds a per-origin negative cache (30 min, capped at 500 origins), cleared the moment an origin serves a real icon. (John Lauer)
v2.0.254 2026-08-20
  • pup-user-foreground: add the VISIBILITY INVARIANT (rule 7) after John's 'why can't i open this pup window' - the doctrine only covered demotions, so a nudge that HID the window slipped past every guard (John Lauer)
  • v2.0.253: Visibility invariant, third cut: assert it over the POPULATION by owning process instead of per session. Verified live that the per-session versions repaired nothing, because they had to find a session's handle first and a window in trouble is exactly the window that lacks one: the enumerating resolver only sees VISIBLE windows (circular), a park-failed window never persisted a handle, and a pup restart clears the birth capture. The property that matters needs no session mapping: no titled top-level window of a pup-owned Chrome process may be hidden. One enumeration now repairs every stranded window including ones pup has lost track of, for one PowerShell per sweep instead of one per session. (John Lauer)
v2.0.253 2026-08-20
  • v2.0.252: Make the 2.0.251 visibility invariant actually fire. Verified live that it repaired nothing: the sweep resolved handles via windowHwnd, whose fallback enumerates and wiggle-matches VISIBLE windows, so asking it to find a HIDDEN window is circular (28 straight NOT-resolved misses on a window sitting right there, hidden). The sweep now uses the cached or birth-captured handle, which needs no enumeration, and proves ownership by PID (GetWindowThreadProcessId answers for hidden windows too). (John Lauer)
v2.0.252 2026-08-20
  • v2.0.251: Fix a pup window that a human click could not open (John's report). The taskbar button nudge HIDES the window for 80ms to force the shell to rebuild its button; the re-show was a separate statement in a PowerShell process node kills at 20s, so any interruption in that gap left the window IsWindowVisible=false with a live taskbar button that revealed nothing, until some later audit happened to nudge again. Reproduced live on AdomLapper. The re-show is now in a finally, the caller verifies it landed (a killed process runs no finally), and a new 120s VISIBILITY SWEEP asserts the invariant for every standing window: a human can minimize a window but never hide one, so a hidden pup window is always pup's to repair. Second bug in the same line: the re-show was always SW_SHOWNOACTIVATE, which RESTORES a minimized window, so pup silently un-minimized windows the user had put away; it now re-shows in the state it found (SW_SHOWMINNOACTIVE when minimized). (John Lauer)
v2.0.251 2026-08-20
  • selftest T10: a foreground of 0 (nothing focused) is INCONCLUSIVE, not a pass — the guard must not bank a vacuous result (John Lauer)
  • v2.0.250: Taskbar identity survives a bridge restart intact: the registry prune now seeds its live set from the sessions persisted on disk, by the identity each window was wearing and by the thread name it belongs to, so reloaded windows are no longer treated as orphans and stripped before their first stamp lands, and a thread whose tile art was not ready when it was registered retries on a bounded backoff instead of waiting for unrelated churn to brand it. (John Lauer)
v2.0.250 2026-08-19
  • selftest T10: foreground-steal guard for #56 (focus a window we own, cold the dashboard profile, assert a cold pup_dashboard never changes the foreground) (John Lauer)
  • v2.0.249: Three of the four flagged dependency advisories are closed: sharp moves to the patched line directly since it is our own optional dependency, while js-yaml and ip-address are pinned through overrides because they arrive transitively under puppeteer, and the remaining extract-zip advisory is documented in the manifest as unreachable here since it only unpacks the Chrome archive pup itself downloads from Google over HTTPS. (John Lauer)
v2.0.249 2026-08-19
  • tools/not_intercepted.py: the SDK NOT-INTERCEPTED audit for pup (direct-to-port vs routed key-set diff, envelope-aware, refuses to call a failed probe a pass) (John Lauer)
  • v2.0.248: The page-health probe waits briefly for the document to finish loading before judging images, so the check both fires on real failures and stays quiet about placeholder slots, rather than declining to judge on nearly every page because it sampled while the document was still interactive. (John Lauer)
v2.0.248 2026-08-19
  • v2.0.247: The page-health check judges images only once the document has finished loading, so it stops calling placeholder slots broken and stops missing real failures it sampled too early, and it declines to judge rather than guessing while a page is still loading. (John Lauer)
v2.0.247 2026-08-19
  • v2.0.246: The page-health probe waits a bounded moment for in-flight images before judging them, so a genuine broken image is actually caught instead of being sampled while it was still loading, which was the mirror of the placeholder false alarm the same check just stopped producing. (John Lauer)
v2.0.246 2026-08-19
  • v2.0.245: The page-health check counts an image as broken only when it has a real non-empty source that failed to load, because placeholder slots with no source report zero natural width in Chrome and were making the verb announce that a perfectly healthy page was broken. (John Lauer)
v2.0.245 2026-08-19
  • v2.0.244: The progress-bar verb paints even in minimal-touch mode, because a caller asking for a progress bar is an explicit request rather than pup's automatic machinery, and its response now reports whether anything was actually drawn instead of answering ok while having made no shell call at all. (John Lauer)
v2.0.244 2026-08-18
  • v2.0.243: An explicitly requested taskbar alert is no longer swallowed by minimal-touch mode, which is meant to suppress pup's automatic machinery rather than a caller asking for a nudge, and a flash that does get skipped or fail now names the actual reason instead of blaming a window title that pup no longer resolves by. (John Lauer)
v2.0.243 2026-08-18
  • v2.0.242: Window flashing resolves by the handle pup captured when it created the window instead of falling through to a title lookup that cannot match, fixing the reported failure where a taskbar alert stopped working after a tab switch rewrote the window title even though flashing that same window directly by handle worked. (John Lauer)
v2.0.242 2026-08-18
  • v2.0.241: An unrecognised wiki view value is rejected with the accepted list instead of being silently treated as the public view, which had let a caller asking for a signed-in view receive the public one alongside a response that technically said so and completely misled. (John Lauer)
v2.0.241 2026-08-18
  • selftest T4: longer settle on a heavy page, one retry, and it prints what it saw on failure (an empty screenshot result used to report 'could not capture the scroll pair' with no evidence) (John Lauer)
  • v2.0.240: More duplication retired: the Chrome-style generic globe and PDF glyphs are built by one function instead of being written out as SVG literals in two different no-favicon paths, the PowerShell regex escape used by the process scans lives in one helper, and four more copies of the session-resolution guard now call the shared one. (John Lauer)
v2.0.240 2026-08-18
  • v2.0.239: The three status surfaces now share one core payload builder instead of each pasting the same version, enum accounting and identity settings, which is why the icon-audit field had landed on only one of them, and the raise verb builds its PowerShell from a single shared typedef rather than two copies of the same ten-line C-sharp helper. (John Lauer)
v2.0.239 2026-08-18
  • v2.0.238: Parking a window no longer fails when its shell handle is unknown: the CDP placement that already positioned it stands as the park and the shell re-bottom is skipped with one explanatory log line, instead of sending a title query that cannot match while title tagging is off and surfacing that as a failed lower. (John Lauer)