Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@
{"timestamp":"2026-07-13T12:00:00.000Z","type":"event_msg","payload":{"type":"agent_message","message":"Event-only prose /tmp/parity/CODEX-event-agent.png","phase":"commentary"}}
{"timestamp":"2026-07-13T12:00:00.000Z","type":"event_msg","payload":{"type":"exec_command_begin","call_id":"event-exec","command":"cat /tmp/parity/CODEX-event-command.txt"}}
{"timestamp":"2026-07-13T12:00:00.000Z","type":"event_msg","payload":{"type":"exec_command_end","call_id":"event-exec","stdout":"saved /tmp/parity/CODEX-event-output.txt","stderr":"","exit_code":0}}

Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,6 @@ public protocol ControlCommandContext:
ControlSurfaceContext,
ControlSystemContext,
ControlProjectContext,
ControlPerformanceContext,
ControlDebugContext,
ControlSidebarContext,
ControlBrowserPanelContext
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -81,7 +81,6 @@ public final class ControlCommandCoordinator {
if let result = handleSurface(request) { return result }
if let result = handleSystem(request) { return result }
if let result = handleProject(request) { return result }
if let result = handlePerformance(request) { return result }
if let result = handleDebug(request) { return result }
// The v2 browser.* domain stays app-side: PR 5778 moved its
// JS-evaluating methods onto the socket-worker lane (nonisolated
Expand Down

Large diffs are not rendered by default.

This file was deleted.

Original file line number Diff line number Diff line change
Expand Up @@ -38,13 +38,6 @@ public protocol ControlDebugContext: AnyObject {
/// unavailable (the legacy `unavailable` error).
func controlDebugSessionSnapshotSeedScrollback(charactersPerTerminal: Int) -> JSONValue?

/// Reads the DEBUG-only process enumeration, filtering, apply, and lsof
/// counters without mutating app or focus state.
func controlDebugReadProcessPerformanceMetrics() -> JSONValue?

/// Resets the DEBUG-only process counters and returns the zeroed snapshot.
func controlDebugResetProcessPerformanceMetrics() -> JSONValue?

// MARK: - v1-shared command forwards (raw v1 response strings)

/// Runs the shared v1 `set_shortcut` body for `debug.shortcut.set`.
Expand Down

This file was deleted.

This file was deleted.

Original file line number Diff line number Diff line change
@@ -1,10 +1,8 @@
public import Darwin

/// Authorizes one peer connection for cmux-only control socket requests.
public struct SocketClientAuthorization: Sendable {
private var cachedAncestryAuthorization: (peerProcessID: pid_t, isAllowed: Bool)?

/// Creates an authorization helper for one accepted socket connection.
/// Authorizes peer processes for cmux-only control socket requests.
public struct SocketClientAuthorization {
/// Creates an authorization helper with no retained process state.
public init() {}

/// Returns whether a peer process is allowed to use cmux-only socket operations.
Expand All @@ -31,36 +29,11 @@ public struct SocketClientAuthorization: Sendable {
return false
}

/// Evaluates and caches process ancestry for one peer PID.
///
/// Call this when connection admission must fall back to ancestry before
/// the first command is available. Later command authorization reuses the
/// cached result and does not walk the process tree again.
///
/// - Parameters:
/// - peerProcessID: The PID reported by the accepted socket.
/// - isDescendant: Predicate that verifies current process ancestry.
/// - Returns: The cached or newly evaluated ancestry result.
public mutating func cacheAncestryAuthorization(
peerProcessID: pid_t?,
isDescendant: (pid_t) -> Bool
) -> Bool {
guard let peerProcessID else { return false }
if let cachedAncestryAuthorization,
cachedAncestryAuthorization.peerProcessID == peerProcessID {
return cachedAncestryAuthorization.isAllowed
}
let peerIsDescendant = isDescendant(peerProcessID)
cachedAncestryAuthorization = (peerProcessID, peerIsDescendant)
return peerIsDescendant
}

/// Returns the command carried by an authorized cmux-only request.
///
/// A valid same-user capability is accepted before process ancestry is
/// evaluated. Ordinary clients retain process-tree authorization, with one
/// ancestry result cached for the lifetime of this authorization helper.
/// Reusing a helper with a different peer PID invalidates that cache.
/// Descendants retain the existing process-tree authorization. The
/// capability parameters form the runtime seam for terminals whose
/// process trees are later reparented by a multiplexer.
///
/// - Parameters:
/// - command: The raw command line received from the client.
Expand All @@ -69,24 +42,22 @@ public struct SocketClientAuthorization: Sendable {
/// - capabilityAuthority: The authority that verifies inherited tokens.
/// - isDescendant: Predicate that verifies current process ancestry.
/// - Returns: The unwrapped command when authorized, otherwise `nil`.
public mutating func authorizedCommand(
public func authorizedCommand(
_ command: String,
peerProcessID: pid_t?,
peerHasSameUID: Bool,
capabilityAuthority: SocketClientCapabilityAuthority,
isDescendant: (pid_t) -> Bool
) -> String? {
let envelope = SocketClientCapabilityCommand(command)
if peerHasSameUID,
let envelope,
capabilityAuthority.verifies(envelope.capability) {
return envelope.command
if let peerProcessID, isDescendant(peerProcessID) {
return envelope?.command ?? command
}

guard cacheAncestryAuthorization(
peerProcessID: peerProcessID,
isDescendant: isDescendant
) else { return nil }
return envelope?.command ?? command
guard peerHasSameUID,
let envelope,
capabilityAuthority.verifies(envelope.capability) else {
return nil
}
return envelope.command
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -97,13 +97,6 @@ public enum ControlCommandExecutionPolicy: Sendable, Equatable {
"mobile.terminal.set_font",
"system.top",
"system.memory",
// Owner attribution performs a fresh process + listener capture and
// awaits utility tasks. It never touches UI state, so running it on the
// main actor would contaminate the latency path it exists to prove.
"performance.metrics.exercise_process",
// Uses an isolated temporary Git repository and in-memory PR host. Git
// scanning stays off-main; only the PR state machine hops to MainActor.
"performance.metrics.exercise_git_pr",
// `surface.read_text` reads a terminal's visible or full-scrollback
// text and formats it (line tailing, candidate scoring, base64
// encoding). On the main actor that formatting stalls the run loop
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,8 +11,6 @@ import Foundation
extension ControlDebugContext {
func controlDebugSessionSnapshotBenchmark(includeScrollback: Bool, persist: Bool) -> JSONValue? { nil }
func controlDebugSessionSnapshotSeedScrollback(charactersPerTerminal: Int) -> JSONValue? { nil }
func controlDebugReadProcessPerformanceMetrics() -> JSONValue? { nil }
func controlDebugResetProcessPerformanceMetrics() -> JSONValue? { nil }
func controlDebugSetShortcut(arguments: String) -> String { "ERROR: not implemented" }
func controlDebugSimulateShortcut(combo: String) -> String { "ERROR: not implemented" }
func controlDebugActivateApp() -> String { "ERROR: not implemented" }
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,13 +17,6 @@ private final class FakeDebugV1ControlCommandContext: ControlCommandContext {
var rightSidebarResolution: ControlDebugRightSidebarFocusResolution = .windowNotFound
var remoteTmuxSizingPayload: JSONValue?

var processMetrics = JSONValue.object([
"process_snapshots": .object(["capture_started": .int(3)])
])
var processMetricsReadCount = 0
var processMetricsResetCount = 0
var typedTexts: [String] = []

func controlDebugSetShortcut(arguments: String) -> String {
setShortcutArguments = arguments
return setShortcutResponse
Expand All @@ -39,24 +32,6 @@ private final class FakeDebugV1ControlCommandContext: ControlCommandContext {
return rightSidebarResolution
}

func controlDebugReadProcessPerformanceMetrics() -> JSONValue? {
processMetricsReadCount += 1
return processMetrics
}

func controlDebugResetProcessPerformanceMetrics() -> JSONValue? {
processMetricsResetCount += 1
processMetrics = .object([
"process_snapshots": .object(["capture_started": .int(0)])
])
return processMetrics
}

func controlDebugTypeText(_ text: String) -> ControlDebugTypeResolution {
typedTexts.append(text)
return .inserted
}

func controlDebugRemoteTmuxSizingSettled() -> JSONValue? {
remoteTmuxSizingPayload
}
Expand Down Expand Up @@ -146,42 +121,5 @@ struct ControlCommandCoordinatorDebugV1Tests {
let reply = coordinator.handleDebugV1(command: "debug_right_sidebar_focus", args: "split")
#expect(reply == "ERROR: mode=split active= visible=0 context=0 state=0 focus=0")
}

@Test func processMetricsReadAndResetUseSharedDebugDomain() {
let (coordinator, context) = makeCoordinator()
let read = coordinator.handle(ControlRequest(
id: .int(1),
method: "debug.process_metrics.read",
params: [:]
))
#expect(read == .ok(.object([
"process_snapshots": .object(["capture_started": .int(3)])
])))
#expect(context.processMetricsReadCount == 1)

let reset = coordinator.handle(ControlRequest(
id: .int(2),
method: "debug.process_metrics.reset",
params: [:]
))
#expect(reset == .ok(.object([
"process_snapshots": .object(["capture_started": .int(0)])
])))
#expect(context.processMetricsResetCount == 1)
}

@Test func typingDoesNotReadOrResetProcessMetrics() {
let (coordinator, context) = makeCoordinator()
let result = coordinator.handle(ControlRequest(
id: .int(1),
method: "debug.type",
params: ["text": .string("typing workload")]
))

#expect(result == .ok(.object([:])))
#expect(context.typedTexts == ["typing workload"])
#expect(context.processMetricsReadCount == 0)
#expect(context.processMetricsResetCount == 0)
}
}
#endif

This file was deleted.

Original file line number Diff line number Diff line change
Expand Up @@ -30,8 +30,6 @@ struct ControlCommandExecutionPolicyTests {
for method in [
"system.ping", "system.capabilities", "auth.status", "auth.sign_in_url",
"feed.push", "browser.download.wait", "system.top", "system.memory",
"performance.metrics.exercise_process",
"performance.metrics.exercise_git_pr",
"workspace.remote.pty_bridge", "workspace.env", "sidebar.custom.reload",
"sidebar.custom.open",
"debug.sidebar.simulate_drag", "mobile.attach_ticket.create",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -52,20 +52,14 @@ struct SocketCapabilityRebindTests {
}

let command = "hooks claude prompt-submit"
var authorization = SocketClientAuthorization()
var ancestryEvaluationCount = 0
let authorized = authorization.authorizedCommand(
let authorized = SocketClientAuthorization().authorizedCommand(
envelope.wrap(command),
peerProcessID: reboundConnection.peerProcessID,
peerHasSameUID: true,
capabilityAuthority: authority,
isDescendant: { _ in
ancestryEvaluationCount += 1
return false
}
isDescendant: { _ in false }
)
#expect(authorized == command)
#expect(ancestryEvaluationCount == 0)
}

private func connect(to path: String) -> Int32 {
Expand Down
Loading
Loading