Skip to content

feat(desktop): launch explicitly selected applications - #136

Merged
iamnbutler merged 2 commits into
mainfrom
codex/desktop-launch
Oct 5, 2026
Merged

iamnbutler merged 2 commits into
mainfrom
codex/desktop-launch

Conversation

@iamnbutler

@iamnbutler iamnbutler commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Adds desktop_launch for an explicit absolute .app path or exact bundle ID. Launch requests foreground activation and readiness through Peekaboo's existing global mutation lane, verifies the signed selector/process receipt, and returns fresh inventory. Native confirmation survives a later inventory failure; uncertain launches warn that the app may still open and are never replayed.

Real validation found that an unregistered bundle ID was incorrectly reported as an indeterminate mutation. A narrow native patch now classifies synchronous selector-preparation failures as refused before dispatch, using the existing signed targetless refusal contract. Opening, activation, readiness, and errors after dispatch retain their existing behavior.

Path selection chooses that app copy; bundle-ID selection follows LaunchServices registration. No app names, PIDs, documents/URLs, relaunch, extra-instance, or background-launch options are exposed. Related: #8, #73.

Validation:

  • Type checks, formatting/lint, GitHub CI, signed desktop build, and deep/strict signature checks pass on 5dc9371; independent product and finite-helper reviews pass.
  • Real exact-path launch, reopening the running instance with the same PID/generation, invalid-path refusal, and pre-cancel refusal passed before the preparation-only correction. Their original results are preserved.
  • On the final build, unregistered and nonexistent exact bundle IDs both return refused, target_unavailable, and no dispatch. The original incorrect unknown is preserved as before/after evidence.
  • A byte-identical signed fixture with a legal no-dot bundle ID resolved after registration outside macOS's temporary directory. Exact bundle-ID launch returned its signed PID/generation and confirmed foreground outcome.
  • A real pi channel launched that exact fixture path once. A new worker reopened the same durable store with identical result, usage, execution records, and fixture events; no second launch or model call occurred.
  • Normal quit cleaned both fixture generations. All owned runtimes/workers exited, the temporary channel/project and socket were removed, the port closed, and fixture registration was removed and verified absent.

Built in Ace

Codex's direct file, terminal, build, and review tools were used under Nate's explicit exception to Ace-only development for #8 so the computer-use work could proceed faster. Validation used Ace's actual source host, signed desktop bridge, real model, and disposable fixture. The relevant native tool and dogfooding gaps are tracked in #8 and #5.

@iamnbutler
iamnbutler force-pushed the codex/desktop-launch branch from c156156 to 5dc9371 Compare October 5, 2026 22:44
@iamnbutler
iamnbutler marked this pull request as ready for review October 5, 2026 22:56
@iamnbutler
iamnbutler merged commit 0c18f31 into main Oct 5, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant