Real native validation for #65 / #67 found that inserting from an unused snapshot after moving focus to another editable field produces an unknown outcome even though the native error describes a stale focused-element preflight rejection.
Reproduction in a real signed AppKit form:
- Inspect the focused document, retaining snapshot A.
- Inspect again to obtain independent snapshot B, then click a different editable field with B.
- Verify the other field really has focus.
- Call desktop_insert with unused snapshot A.
Observed: DESKTOP_ACTION_FAILED reports that the exact focused-element receipt is stale because the selected element no longer reports AXFocused=true. Its native outcome is indeterminate/may_have_dispatched, so Ace conservatively returns unknown. The result correctly warns against blind replay, but does not expose a known pre-delivery refusal if the native service can prove one.
Investigate the native typeActions preflight and outcome propagation. Preserve unknown whenever input may have been dispatched; do not classify by parsing an error string or weaken focus checks. If rejection is provably before delivery, return refused with the native evidence, and verify that both the original and newly focused fields stay unchanged. This is part of #8's input/outcome validation and #5 dogfooding.
Implementation and validation
Fixed in draft #67, commit d04c8c4. A narrow patch to the pinned native dependency converts only the initial validator's typed invalid-input refusal before any unit is emitted. It preserves cancellation, the exact target receipt, and uncertainty for continuation failures after input may have been delivered; no error-string classification or weakened focus check is used.
Type checks, lint, signed build/signature verification, patch applicability, and independent review pass. A real signed AppKit run now reports refused after moving focus away from an unused snapshot, and verifies that both editable fields remain unchanged through the app's real Save callback. The PR remains a draft for its remaining keyboard validation; this issue stays open until it lands.
Real native validation for #65 / #67 found that inserting from an unused snapshot after moving focus to another editable field produces an
unknownoutcome even though the native error describes a stale focused-element preflight rejection.Reproduction in a real signed AppKit form:
Observed:
DESKTOP_ACTION_FAILEDreports that the exact focused-element receipt is stale because the selected element no longer reports AXFocused=true. Its native outcome is indeterminate/may_have_dispatched, so Ace conservatively returns unknown. The result correctly warns against blind replay, but does not expose a known pre-delivery refusal if the native service can prove one.Investigate the native typeActions preflight and outcome propagation. Preserve unknown whenever input may have been dispatched; do not classify by parsing an error string or weaken focus checks. If rejection is provably before delivery, return refused with the native evidence, and verify that both the original and newly focused fields stay unchanged. This is part of #8's input/outcome validation and #5 dogfooding.
Implementation and validation
Fixed in draft #67, commit d04c8c4. A narrow patch to the pinned native dependency converts only the initial validator's typed invalid-input refusal before any unit is emitted. It preserves cancellation, the exact target receipt, and uncertainty for continuation failures after input may have been delivered; no error-string classification or weakened focus check is used.
Type checks, lint, signed build/signature verification, patch applicability, and independent review pass. A real signed AppKit run now reports refused after moving focus away from an unused snapshot, and verifies that both editable fields remain unchanged through the app's real Save callback. The PR remains a draft for its remaining keyboard validation; this issue stays open until it lands.