Repository navigation
Conversation
added 3 commits
October 7, 2026 05:51
…denied (LOOM TASK-009) 2.0.1/2.0.2 shipped zero capability files, so Tauri 2's ACL rejected every plugin:* call (event.listen, window.hide, window.set_position) while app commands still answered — the UI looked healthy and the wheel was deaf. All e2e mocked window.__TAURI__, so nothing caught it. - capabilities/default.json covers main + wheel-panel with the exact surface the JS layer calls (core:default + allow-set-position + allow-hide) - probeIpcEnvironment() distinguishes no-bridge vs acl-denied; boot shows a persistent bilingual banner instead of a transient toast; the wheel window renders a visible error card instead of an invisible always-on-top overlay - guards: scripts/check_capabilities.mjs in frontend CI, a cargo test in main.rs, release.yml verifies the resolved capabilities are non-empty - new e2e tests/e2e/no_tauri_e2e.py runs with NO __TAURI__ mock
Haaaiawd
pushed a commit
that referenced
this pull request
Oct 7, 2026
Owner
Author
|
已通过 squash 合并入 master(commit 330e7c4),PR 忘记关闭,非废弃。 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
__TAURI__在 2.0.x 其实注入了(withGlobalTauri: true控制注入,与 capabilities 无关)。真正死掉的是plugin:*命令:仓库没有任何capabilities/文件 → Tauri 2 的 ACL 把plugin:event|listen、plugin:window|hide/set_position全部拒绝,而 app command 直通 → 界面正常、提示词正常、轮盘永远聋掉。Rust 照样show()出 320px 透明 always-on-top 窗口——比"没反应"更糟,它还会吞点击。capabilities/default.json:单 capability 覆盖main+wheel-panel,只授 JS 层真实调用的面(拆分理由与完整映射见.loom/design/task-brief-capabilities-fix.mdTASK-009 节)。probeIpcEnvironment()区分no-bridge/acl-denied(实探event.listen),boot 时失败 → 主窗口顶部持久双语 banner;轮盘 init 失败 → 窗口内可见错误卡(不再是隐形覆盖层)。window.__PK_IPC_ENV__留存探针结果供诊断引用。scripts/check_capabilities.mjs(frontend job,纯 Node 校验窗口覆盖 + 权限 identifier 对照acl-manifests.json+ 解析出必需 allow 集)、main.rs里的cargo test断言、release.yml 构建后验证gen/schemas/capabilities.json非空且覆盖两窗。apply_settings/check_hotkeys是 app command,不走 ACL——提交被拒是commitHotkey看到注册非 ok 后的回滚(真实注册失败被正确表面化)。capabilities 与此无关;若升级后仍复现,请用「链路诊断」按钮发回 JSON。withGlobalTauri保留(JS 直接用全局对象);security.csp: null合法(无 CSP,本地应用可接受);#[tauri::command]+generate_handler!仍是正确机制;named pipe(ipc_listener.rs/inject_pipe_client.rs)是应用自有 IPC,不需要 capability;未发现其他 v1 残留。Test plan
python tests/e2e/no_tauri_e2e.py— 13/13(新增无-mock 用例:no-bridge + acl-denied × 主窗/轮盘)python tests/e2e/hotkey_status_e2e.py— 10/10python tests/e2e/hotkey_recorder_e2e.py— 22/22node scripts/check_capabilities.mjs— 正向通过;去掉 wheel-panel 或 mutating 权限 → 正确失败cargo check/clippy/cargo test(本机无 cargo 未编译——测试仅读 JSON 文件,风险极低)不合并,等真机验证轮盘热键。
Generated with Devin