Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .github/workflows/ci-guards.yml
Original file line number Diff line number Diff line change
Expand Up @@ -1207,6 +1207,12 @@ jobs:
python3 tests/test_ci_cli_contract_verb_guard.py
python3 scripts/check-cli-contract-verbs.py

- name: Validate socket capability parity
if: ${{ matrix.group == 'quality-determinism' }}
run: |
python3 tests/test_ci_socket_capability_guard.py
Comment thread
teamleaderleo marked this conversation as resolved.
python3 scripts/check-socket-capabilities.py

- name: Validate test determinism gate
if: ${{ matrix.group == 'quality-determinism' }}
run: |
Expand Down
63 changes: 61 additions & 2 deletions Sources/TerminalController+Capabilities.swift
Original file line number Diff line number Diff line change
Expand Up @@ -64,9 +64,14 @@ extension TerminalController {
"mobile.panel.artifact.stat",
"mobile.panel.artifact.thumbnail",
"mobile.workspace.list",
"mobile.workspace.changes.files",
Comment thread
teamleaderleo marked this conversation as resolved.
"mobile.workspace.changes.file_diff",
"mobile.workspace.changes.file_stat",
"mobile.workspace.changes.file_fetch",
"mobile.terminal.create",
"mobile.terminal.input",
"mobile.terminal.paste",
"mobile.terminal.paste_image",
Comment thread
teamleaderleo marked this conversation as resolved.
"mobile.terminal.replay",
"mobile.browser.list",
"mobile.browser.create",
Expand All @@ -83,12 +88,15 @@ extension TerminalController {
"mobile.browser.back",
"mobile.browser.forward",
"mobile.browser.reload",
"mobile.terminal.viewport", "mobile.events.subscribe", "mobile.events.unsubscribe",
"mobile.terminal.viewport", "mobile.terminal.scroll", "mobile.terminal.mouse",
"mobile.events.subscribe", "mobile.events.unsubscribe",
"mobile.status.cycle",
"terminal.create",
"terminal.input",
"terminal.paste",
"terminal.paste_image",
"terminal.replay",
"terminal.viewport",
"terminal.viewport", "terminal.scroll", "terminal.mouse",
"auth.login",
"auth.status",
"auth.sign_in_url",
Expand Down Expand Up @@ -117,11 +125,18 @@ extension TerminalController {
"vm.stats",
"vm.resize",
"vm.rename",
"vm.pause",
"vm.resume",
"vm.snapshot",
"vm.snapshot_list",
"vm.snapshot_delete",
"vm.fork",
"vm.restore",
"vm.destroy",
"vm.exec",
"vm.env_set",
"vm.file_put",
"vm.reflection",
"vm.open_port",
"vm.attach_info",
"vm.cmux_remote_info",
Expand All @@ -143,6 +158,8 @@ extension TerminalController {
"vm.terminal_write",
"vm.terminal_read",
"vm.terminal_wait",
"vm.terminal_output",
"vm.terminal_wait_exit",
"vm.desktop_open",
"vm.port_open",
"vm.link_socket",
Expand All @@ -158,6 +175,7 @@ extension TerminalController {
"current.list",
"surface.project",
"surface.new_terminal",
"surface.ssh_session_attach.resolve",
"aiAccounts.list",
"aiAccounts.upload",
"aiAccounts.remove",
Expand Down Expand Up @@ -190,7 +208,20 @@ extension TerminalController {
"workspace.select",
"workspace.current",
"workspace.close",
"workspace.move",
"workspace.move_to_window",
"workspace.status.get",
"workspace.status.set",
"workspace.status.cycle",
"workspace.todo.list",
"workspace.todo.add",
"workspace.todo.edit",
"workspace.todo.remove",
"workspace.todo.move",
"workspace.todo.open",
"workspace.todo.set",
"workspace.todo.set_state",
"workspace.todo.clear",
"workspace.reorder",
"workspace.reorder_many",
"workspace.prompt_submit",
Expand All @@ -214,6 +245,7 @@ extension TerminalController {
"workspace.group.set_icon",
"workspace.group.move",
"workspace.group.focus",
"workspace.group.action",
"workspace.action",
"extension.sidebar.snapshot",
"workspace.next",
Expand All @@ -231,6 +263,11 @@ extension TerminalController {
"workspace.remote.terminal_session_launching",
"workspace.remote.terminal_session_connected", "workspace.remote.terminal_session_end",
"remote.tmux.sessions", "remote.tmux.attach", "remote.tmux.detach", "remote.tmux.state", "remote.tmux.mirror", "remote.tmux.window", "remote.tmux.pane_grids", "remote.tmux.pane_surfaces",
"remotes.list", "remotes.add", "remotes.remove",
"layout.save", "layout.list", "layout.get", "layout.open", "layout.delete",
"canvas.align", "canvas.break", "canvas.info", "canvas.join", "canvas.new_pane",
"canvas.overview", "canvas.reveal", "canvas.select_tab", "canvas.set_frame",
"canvas.set_mode", "canvas.set_viewport", "canvas.zoom",
"session.restore_previous",
"session.agent_recovery.list",
"session.agent_recovery.restore",
Expand Down Expand Up @@ -312,6 +349,10 @@ extension TerminalController {
"notification.mark_read",
"notification.open",
"notification.jump_to_unread",
"notification.feed.list",
"notification.feed.mark_read",
"notification.feed.mark_unread",
"notification.feed.mark_all_read",
"app.focus_override.set",
"app.simulate_active",
"file.open",
Expand Down Expand Up @@ -381,6 +422,13 @@ extension TerminalController {
"browser.storage.get",
"browser.storage.set",
"browser.storage.clear",
"browser.profiles.list",
"browser.profiles.create",
"browser.profiles.rename",
"browser.profiles.clear",
"browser.profiles.delete",
"browser.import.cookies",
"browser.import.dialog",
"browser.tab.new",
"browser.tab.list",
"browser.tab.switch",
Expand Down Expand Up @@ -415,6 +463,17 @@ extension TerminalController {
]
methods.removeAll { taskComposerMethods.contains($0) }
}
// Discovery runs off-main; read the same flag snapshot as mobile host
// capabilities rather than crossing to the main-actor flag store.
if !CmuxFeatureFlags.offMainEffectiveValue(for: CmuxFeatureFlags.mobileWorkspaceChangesFlag) {
let workspaceChangesMethods: Set<String> = [
"mobile.workspace.changes.files",
"mobile.workspace.changes.file_diff",
"mobile.workspace.changes.file_stat",
"mobile.workspace.changes.file_fetch",
]
methods.removeAll { workspaceChangesMethods.contains($0) }
}
methods.append(contentsOf: ControlCommandExecutionPolicy.simulatorMethods)
#if DEBUG
methods.append(contentsOf: Self.v2DebugMethodNames)
Expand Down
36 changes: 36 additions & 0 deletions cmuxTests/TerminalControllerSocketSecurityTests.swift
Original file line number Diff line number Diff line change
Expand Up @@ -1179,6 +1179,42 @@ final class TerminalControllerSocketSecurityTests {
"mobile.panel.artifact.thumbnail",
"mobile.events.subscribe",
"mobile.events.unsubscribe",
// Cloud VM methods used by the CLI must stay discoverable so
// capability-aware agents do not reject valid operations.
"vm.env_set",
Comment thread
teamleaderleo marked this conversation as resolved.
"vm.file_put",
"vm.pause",
"vm.resume",
"vm.reflection",
"vm.snapshot_list",
"vm.snapshot_delete",
"vm.terminal_output",
"vm.terminal_wait_exit",
"browser.profiles.list",
"browser.profiles.create",
"browser.profiles.rename",
"browser.profiles.clear",
"browser.profiles.delete",
"browser.import.cookies",
"browser.import.dialog",
"workspace.move",
"workspace.status.get",
"workspace.status.set",
"workspace.status.cycle",
"workspace.todo.list",
"workspace.todo.add",
"workspace.todo.edit",
"workspace.todo.remove",
"workspace.todo.move",
"workspace.todo.open",
"workspace.todo.set",
"workspace.todo.set_state",
"workspace.todo.clear",
"notification.feed.list",
"notification.feed.mark_read",
"notification.feed.mark_unread",
"notification.feed.mark_all_read",
"surface.ssh_session_attach.resolve",
]
XCTAssertTrue(
expectedMethods.isSubset(of: advertisedMethods),
Expand Down
Loading
Loading