Skip to content

Preserve native preflight refusal evidence after focus changes #69

Description

@iamnbutler

Real native validation for #65 / #67 found that inserting from an unused snapshot after moving focus to another editable field produces an unknown outcome even though the native error describes a stale focused-element preflight rejection.

Reproduction in a real signed AppKit form:

  1. Inspect the focused document, retaining snapshot A.
  2. Inspect again to obtain independent snapshot B, then click a different editable field with B.
  3. Verify the other field really has focus.
  4. Call desktop_insert with unused snapshot A.

Observed: DESKTOP_ACTION_FAILED reports that the exact focused-element receipt is stale because the selected element no longer reports AXFocused=true. Its native outcome is indeterminate/may_have_dispatched, so Ace conservatively returns unknown. The result correctly warns against blind replay, but does not expose a known pre-delivery refusal if the native service can prove one.

Investigate the native typeActions preflight and outcome propagation. Preserve unknown whenever input may have been dispatched; do not classify by parsing an error string or weaken focus checks. If rejection is provably before delivery, return refused with the native evidence, and verify that both the original and newly focused fields stay unchanged. This is part of #8's input/outcome validation and #5 dogfooding.

Implementation and validation

Fixed in draft #67, commit d04c8c4. A narrow patch to the pinned native dependency converts only the initial validator's typed invalid-input refusal before any unit is emitted. It preserves cancellation, the exact target receipt, and uncertainty for continuation failures after input may have been delivered; no error-string classification or weakened focus check is used.

Type checks, lint, signed build/signature verification, patch applicability, and independent review pass. A real signed AppKit run now reports refused after moving focus away from an unused snapshot, and verifies that both editable fields remain unchanged through the app's real Save callback. The PR remains a draft for its remaining keyboard validation; this issue stays open until it lands.

Activity

  1. iamnbutler commented on Oct 6, 2026

    @iamnbutler
    ContributorAuthor

    Closing as completed. This issue's body records the fix (d04c8c4) and its signed AppKit validation: insertion from a stale-focus snapshot now returns refused, and both editable fields stayed unchanged. The remaining condition was for #67 to land. It merged as 8fb8ccf, and both commits are ancestors of main 5194bf7. The similar pre-dispatch misclassification for moved-window coordinate clicks is a separate path, tracked in #155.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions