Skip to content

feat(desktop): open one item through the native app handler - #143

Merged
iamnbutler merged 2 commits into
mainfrom
codex/desktop-open
Oct 6, 2026
Merged

iamnbutler merged 2 commits into
mainfrom
codex/desktop-open

Conversation

@iamnbutler

@iamnbutler iamnbutler commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Add desktop_open for one existing absolute file/folder/app path or one complete URL, optionally choosing an application with the existing launch selector. macOS chooses the default handler when no application is given. Opening uses the signed native launch route and global mutation lane, binding the entire request and receiving process generation.

Accepted item delivery reports dispatched_unverified with delivery_accepted: macOS accepted the request, but loading or rendering remains unverified. Existing app-only launch behavior stays intact. Failures after submission remain uncertain, with no automatic replay, fallback, extra instance, default-handler change, or dialog handling. Refs #8 and #73.

Validation at 2aea91a928ad4f649a8fda2e0a5edb5be8424847:

  • Types, formatting/lint, Swift parse, native patch integration, signed development build, strict app/client/dylib/launcher signatures, independent source/helper review, and GitHub CI pass.
  • Real signed native checks refused relative/missing paths, a malformed URL, and pre-dispatch cancellation without a receiver callback. One explicit-app Unicode document open and one default-handler custom URL each produced exactly one callback and the accepted/unverified receipt for the exact receiver generation.
  • One real pi/Anthropic claude-opus-5-5 channel opened a second public document using the bundle-ID selector. Exact result, usage, execution counts, and the three-callback total survived actual worker exit and reopen under a different worker, without another opening.
  • All owned fixture, worker, launcher, app and host processes exited; the temporary channel, project catalog entry, preferences, port and socket were cleaned up. No clipboard access.

The first document verifier expected byte-identical file URLs, but macOS returned a canonically decomposed Unicode filename. Its original successful delivery and failed verifier are preserved; read-only checks proved the requested and returned URLs resolve to the same device/inode. Only the remaining URL/model/reopen cases continued on the revalidated runtime; the document open was not repeated. Evidence: /tmp/ace-open-smoke.vERdhu/{result.json,unicode-readback.json}, /tmp/ace-open-remaining-smoke.ZW62dM/result.json, /tmp/ace-open-live-XduwLD/cleanup-final.json. Document/page rendering, opening-specific in-flight interruption, hosted routing, other OS handlers and another Mac remain unverified.

Built in Ace

Used Codex's terminal and source-editing tools for implementation, independent review, the signed build, and finite real native/model validation under Nate's explicit exception for #8. Ace was missing this native item-opening capability; broader native workflow gaps remain tracked in #8 under dogfooding #5. The model proof ran through an actual Ace channel, signed desktop client and app bridge.

# Conflicts:
#	apps/desktop/scripts/helper.ts
#	docs/desktop-tools.md
@iamnbutler
iamnbutler marked this pull request as ready for review October 6, 2026 19:50
@iamnbutler
iamnbutler merged commit b2a400b into main Oct 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant