Pup - the AI's own browser
Public Made by Adomby adom
pup gives your AI a real browser on your desktop that it drives completely, in the background, signed in as you: windows that never jump in front of your work, one shared profile that learns your logins, and every window labeled on the taskbar with its AI thread's name.
Releases 1153
Standalone per-platform binaries to download and run, no tools needed. The newest is pinned on top.
Annotate's quick colors are red, blue and green: the muddy yellow/orange third color is gone from the trio and from Multi's automatic cycle (red, blue, green, purple), so every mark has a color anyone can name to the AI. Yellow stays in the More flyout, and every swatch shows its color name on hover (John, 2026-10-07).
Stable link for websites and docs: /download/adom/pup-bridge/latest
All releases showing 461-480 of 1153
- v2.0.237: Window targeting gets a real second chance before its last-ditch title guess: when the cached handle is missing and bounds resolution comes up empty, pup asks the OS for the largest visible window of that session's browser process tree, which fixes the long-standing failure where a healthy window reported that no window carried a session title tag that is switched off by default. (John Lauer)
- v2.0.236: A second cleanup pass removes about three hundred and sixty more lines of duplication: the eight legacy curl endpoints that shadowed pup verbs without ownership checks or recovery now answer with a gone status naming the verb to use, the two superseded send-to-back implementations give way to the park every internal caller already shared, the crash race is event-driven instead of polling four times a second for the lifetime of every operation, the twin recording listers and six copies of the session-resolution preamble collapse into one each, and per-session maps are finally reaped on teardown. (John Lauer)
- harness: T5 derives the expected thread slug from ADOM_AI_THREAD (a hardcoded name produced a false 'stamp path broken'), failing checks print their evidence, and mode-ralph derives aumid/tiles expectations from live sessions and retries the whole verdict (names AND pixels) so a switch still landing is not read as a failure (John Lauer)
- v2.0.235: The overlay-badge apply loop lived in two copies and a progress-tracker edit only declared its variable in one of them, so every pup_configure toggle threw an unhandled ReferenceError; both call sites now share a single implementation that takes the progress entry as a parameter. (John Lauer)
- v2.0.234: A port blocked by a Windows reservation no longer kills the bridge: instead of exiting into a respawn loop that ends in backoff, pup stays alive, explains which reserved range swallowed its assigned port and how to release it, and retries that same port every fifteen seconds so it comes back by itself the moment the range frees, with no respawn and no human in the loop. (John Lauer)
- v2.0.232: The bridge pins its port to 8851 instead of letting ab choose from the ephemeral band, because ab picked 64230 and Windows had reserved that whole block for Hyper-V, which left every spawn failing on EACCES and the bridge permanently down with no non-elevated recovery. (John Lauer)
- pin the bridge port to 8851: ab was assigning 64230, which Windows reserved (Hyper-V exclusion 64160-64259), leaving the bridge in a permanent EACCES crash-loop (ab#83) (John Lauer)
- v2.0.231: A bind failure on the assigned port now explains itself instead of crash-looping invisibly: pup reads the Windows excluded port ranges, names the range that swallowed its port, prints the elevated WinNAT restart that releases it, and binds a fallback port so its dashboard and health surface stay reachable while recording the real port in its discovery file. (John Lauer)
- v2.0.230: A first cleanup pass on the bridge: the four-second sweep now makes one CDP round-trip per tab instead of three and no longer runs a title blob that was a measured no-op, the sixty-second forced badge repaint stretches to five minutes since real clears already trigger a repaint by event, window-alive verdicts are cached so a single stuck session can no longer pin a PowerShell C-sharp recompile every eight seconds, the idle process sweeps skip PowerShell entirely when nothing could have leaked, dashboard icon endpoints serve from an mtime-keyed cache instead of decoding an ICO per window per two seconds, screencast frames write asynchronously instead of blocking the event loop sixty times a second, and about two hundred and forty lines of dead and unreachable code are gone. (John Lauer)
- mode-ralph: expectations derive from LIVE session owners, not a hardcoded thread list (a stale list failed every tiles round while the bar was perfect) (John Lauer)
- pup-icon-audit dev skill: an audit request means detect, fix the code, reapply every AUMID, and prove it with red-boxed pixels (John Lauer)
- v2.0.229: A page with no favicon stops retrying forever: the generic-glyph fallback now backs off over three attempts and goes quiet until the page navigates, and the repeating no-favicon and both-rails-failed lines collapse to one per URL, because a single example.com window was flooding the log ring hard enough to erase the icon-audit trail it was meant to leave behind. (John Lauer)
- v2.0.228: Taskbar icon drift now heals itself: a new audit compares pup's model against the shell's own button names, classifies every drift we have shipped (no button, pending rebuild, and art the shell baked before the thread tile existed), repairs each by re-registering and re-stamping and rebuilding the button, then repaints the badges; it runs after every mode switch and brand sweep, twelve seconds after a thread tile first renders, and every four minutes in steady state, and pup_audit_icons exposes it on demand. (John Lauer)
- ship.sh moves into the repo (it kept evaporating from /tmp); taskbar-states: the foreground skip is now a bounded retry, not a permanent leak; selftest: the icon-audit procedure (John Lauer)
- v2.0.227: A taskbar button nudge skipped because its window happened to be focused is no longer a dead end: the skip becomes a pending state with bounded backoff retries, so a window stamped while the user was looking at it stops keeping its previous button name and art indefinitely, and the dashboard now turns that button red with an explanation instead of reporting a green match while the taskbar visibly disagrees. (John Lauer)
- freshness check: ISO timestamps for -newermt (the box's find is now bfs, which rejects relative forms) (John Lauer)
- mode-ralph: coordMap-true mapping, capture freshness gate, tight #00b8b1 classifier, multi-target sampling, overlay-off plain measurement; skills: the two-CfT-buttons saga lessons (plain = converge to Chrome's native AUMID) (John Lauer)
- The plain-mode batch rebuild now includes the foreground window with immediate focus restore: exempting it left its taskbar button alive through the batch hide, Explorer re-associated that surviving button with its old art baked in to the native group, and every other window joined it, so the whole grouped Chrome button wore stale pup art; a sub-second blink of the active window during an explicit user-initiated mode switch is the right trade. (John Lauer)
The plain-mode batch rebuild now includes the foreground window with immediate focus restore: exempting it left its taskbar button alive through the batch hide, Explorer re-associated that surviving button with its old art baked in to the native group, and every other window joined it, so the whole grouped Chrome button wore stale pup art; a sub-second blink of the active window during an explicit user-initiated mode switch is the right trade.
The plain-mode convergence now batch-nudges: hiding all non-foreground windows together destroys the grouped taskbar button so it rebuilds with clean art, because Windows bakes a group button's icon at creation and per-window nudges never destroy a group that other members keep alive, which let a rapid tiles-to-plain race leave the thread-tile art baked onto the Chrome for Testing group button indefinitely.
Icon and thread-tile generations bump to i8 and t7 so every identity re-registers under virgin app ids: the registry-sweep era deleted the on-disk AUMID keys while ab's registration cache still marked them done by app id, so stamps skipped the registry re-write and tiles and aumid buttons came back with correct names and missing art.
The plain-mode registry sweep is removed: registry keys with no window property pointing at them are inert and were never what split the taskbar groups, while deleting them broke re-entry into tiles and aumid modes because ab caches icon registration by app id and skipped the registry re-write, leaving buttons with names but no art; the native-AUMID convergence from 2.0.221 remains the whole plain-mode story.
Identity stamps carry a strip-epoch suffix in their icon cache keys so ab re-writes the AUMID registry icon entries after a plain-mode registry sweep instead of trusting its handle cache, which had been leaving re-entered tiles and aumid buttons with the right name but no art.
Plain mode now converges every Chrome for Testing window onto Chrome's own native per-profile AUMID instead of wiping identities to empty: Chrome lazily re-asserts its native id on windows, so wiped windows and re-tagged windows drifted into two separate taskbar groups both labeled Google Chrome for Testing, and the convergence approach is idempotent against Chrome's re-assertions so the group can never split again; the fix also covers orphan windows pup no longer manages, corrects a 16-byte PROPVARIANT marshaling bug that made property reads silently return zeros, and remembers the learned native id across restarts.
Jump-list attachment is now gated on AUMID icons being on: in plain mode no window wears a pup identity, yet every window birth was silently registering a bare per-session AUMID registry key purely to have something to commit a jump list to, which the mode-aware selftest caught as a strip hole.
The live settings snapshot actually rides the pup_status verb this time; the 2.0.218 insert had landed in the health endpoint payload instead of the verb, so harness mode reads came back empty.
pup_status now reports the live taskbar identity mode and related settings so test harnesses assert against what pup is actually in at check time rather than assuming a mode, which matters on a live machine where the user legitimately clicks the Settings matrix while tests run.