Skip to content

Read bounded clipboard image previews - #135

Merged
iamnbutler merged 5 commits into
mainfrom
codex/desktop-clipboard-image
Oct 5, 2026
Merged

iamnbutler merged 5 commits into
mainfrom
codex/desktop-clipboard-image

Conversation

@iamnbutler

@iamnbutler iamnbutler commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Extend desktop_clipboard_read with optional format: "image" for #72 and #8. The default plain-text path keeps its existing result and limits. Image reads return one generation-consistent PNG/JPEG/TIFF representation as an oriented preview, with separate source and preview metadata.

The GUI checks silent clipboard permission, one complete frame, a 10 MiB source limit, and 64 million pixels. Rendering runs off the GUI actor and preserves transparency with PNG when possible, using an explicitly white-composited JPEG only when needed to fit the 1,600-pixel/900 KB preview limits. The existing tool image result carries the preview directly. Reads neither change the clipboard nor release a pending paste reservation. A format parameter on clipboard-write is refused.

Validation at c6bd49d42a20cac963eb3c87272a12fb921ab46f:

  • Type checks, formatting/lint, Swift syntax parsing, signed build, and strict app/client/dylib signature verification passed. Independent product and finite-helper source reviews passed; GitHub CI is green.
  • Ten real GUI cases passed: transparent PNG; 2,400→1,600-pixel resize; EXIF orientation6 checked by both dimensions and red-above-blue pixels; TIFF→white JPEG preview (627,317 bytes); absent image; and unchanged-generation refusals for multiple items, multiple frames, malformed PNG, oversized data, and unsupported GIF.
  • A real OpenAI gpt-6-sol channel used one image-read tool call. After its worker closed and reopened, exact text/image results, provider usage, tool logs, and clipboard generation were unchanged. The owned channel/project was then removed.
  • The user's complete prior clipboard stayed only in the fixture's GUI memory and was restored only while the fixture still owned its generation. Both phases confirmed no retained backup, owned processes, listening port, or desktop socket.

Local evidence: /tmp/ace-clipboard-image-check.PZS6Xk/result.json, /tmp/ace-clipboard-image-check.aB0564/result.json, and the corresponding exact-cleanup.json files under /tmp/ace-clipboard-image-live.jkbmSv and /tmp/ace-clipboard-image-live.ZUlS1O. Image writes, files, and temporary paste remain separate slices of #72.

Built in Ace

Codex used external source, Git, build, and temporary-helper tools under the user's explicit temporary exception while #8 is implemented. Ace cannot yet host this Codex harness (#9) and has no File tab for direct source editing (#22). Runtime checks used Ace's actual signed GUI bridge, host adapter, channel worker, tool result/history path, and real provider credentials; the temporary vault preserved the clipboard privately.

…rd-image

# Conflicts:
#	apps/desktop/scripts/helper.ts
@iamnbutler
iamnbutler marked this pull request as ready for review October 5, 2026 22:42
@iamnbutler
iamnbutler merged commit 9c561ba into main Oct 5, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant