Files
claude-code-haha/native/cu-helper/Tests/CuHelperTests/OverlayPolicyTests.swift
程序员阿江(Relakkes) b8a90626ce feat(computer-use): native macOS engine, on top of main and nothing else
Rebuilt against main so the branch carries the Computer Use work and no other
divergence. Three unrelated efforts had been sitting uncommitted in this
worktree and were swept into an earlier commit; they are preserved on
cu-worktree-full-backup and belong on their own branches — adapter control
credentials, Electron asar sealing, and the sidecar code-loading audit. Every
file outside Computer Use now matches main exactly.

The engine
  A Swift helper drives apps through the accessibility tree, with coordinate
  actuation for the Chromium and Electron apps whose tree is a bare window
  frame. Ten primitives matching the shape Codex uses, so an app's guidance and
  the model's habits transfer.

  Coordinate actions resolve their target window once and refuse when none can
  be named. The unbound event they used to fall back to is discarded by custom
  renderers, so a minimized target produced a whole session of "Action
  completed" with nothing behind it.

  Input acceptance is established for typing and key presses as well as clicks:
  each MCP call is seconds apart, so the keyboard cannot inherit the focus a
  click established. The synthetic focus notification is gated on the target
  not already being active — sent unconditionally it names window 0 at an app
  that already owns a key window, and nine window-bound clicks were discarded
  with the traffic lights fully lit.

State the model can trust
  An off-screen target says so, and says which tools still reach it: element
  actions need no on-screen geometry, so an app with a real tree can still be
  driven from the Dock. A fully covered window is recovered once, then left
  alone — burying it again is the user wanting their screen back. A repeated
  capture is reported with the cause that actually applies rather than both,
  because coverage is something we compute.

Signing
  The helper is signed under a stable identity before electron-builder sees it,
  and excluded from re-signing: macOS ties Accessibility and Screen Recording
  grants to the signing identity, so rotating it drops both on every update.

Discoverability
  The desktop slash menu falls back to a directory scan while a session's CLI
  has not started, which is when the menu is first opened. Built-ins and
  bundled skills live in the binary, so /computer-use was absent until after
  the first message.
2026-08-05 22:06:23 +08:00

234 lines
8.6 KiB
Swift

import Darwin
import XCTest
@testable import cc_haha_computer_use
final class OverlayPolicyTests: XCTestCase {
private let processA = AXTreeProcessIdentity(
bundleID: "com.example.a",
executablePath: "/Applications/A.app/Contents/MacOS/A",
launchTime: 100
)
/// The product's primary mode is BACKGROUND pid-targeted operation (the
/// helper never foregrounds the target). An exposed background window —
/// e.g. the target sitting alone on another display — must show the
/// cursor, or the "watch the AI work" layer never exists in exactly the
/// scenario the product is built for.
func testExposedBackgroundTargetIsVisibleWithActionDelay() {
let decision = OverlayPolicy.decision(
targetPid: 41,
frontmostPid: 99,
overlayRequested: true,
targetWindowExposed: true
)
XCTAssertTrue(decision.visible)
XCTAssertGreaterThan(decision.actionDelay, 0)
XCTAssertFalse(decision.shouldClearTransientVisuals)
}
/// A buried background target stays hidden: drawing a cursor above the
/// OCCLUDING window's content would point at something unrelated.
func testCoveredBackgroundTargetIsHiddenWithZeroActionDelay() {
let decision = OverlayPolicy.decision(
targetPid: 41,
frontmostPid: 99,
overlayRequested: true,
targetWindowExposed: false
)
XCTAssertFalse(decision.visible)
XCTAssertEqual(decision.actionDelay, 0)
XCTAssertTrue(decision.shouldClearTransientVisuals)
}
/// Frontmost target is visible regardless of the exposure probe — the
/// window-server evidence is redundant when macOS already says the target
/// owns the screen.
func testForegroundRequestedTargetIsVisibleWithShortActionDelay() {
let decision = OverlayPolicy.decision(
targetPid: 41,
frontmostPid: 41,
overlayRequested: true,
targetWindowExposed: false
)
XCTAssertTrue(decision.visible)
XCTAssertGreaterThan(decision.actionDelay, 0)
XCTAssertLessThanOrEqual(decision.actionDelay, 0.12)
XCTAssertFalse(decision.shouldClearTransientVisuals)
}
/// Exposure alone can never conjure visuals for a missing/invalid/
/// unrequested target — identity comes first, always.
func testNilInvalidAndUnrequestedTargetsStayHiddenEvenWhenExposed() {
let decisions = [
OverlayPolicy.decision(targetPid: nil, frontmostPid: 41, overlayRequested: true, targetWindowExposed: true),
OverlayPolicy.decision(targetPid: 0, frontmostPid: 41, overlayRequested: true, targetWindowExposed: true),
OverlayPolicy.decision(targetPid: -1, frontmostPid: 41, overlayRequested: true, targetWindowExposed: true),
OverlayPolicy.decision(targetPid: 41, frontmostPid: 41, overlayRequested: false, targetWindowExposed: true),
]
XCTAssertTrue(decisions.allSatisfy { !$0.visible && $0.actionDelay == 0 })
}
// MARK: - firstOrdinaryWindowOwner (pure exposure core)
private func windowInfo(
layer: Int,
x: CGFloat,
y: CGFloat,
w: CGFloat,
h: CGFloat,
pid: pid_t
) -> [CFString: Any] {
[
kCGWindowLayer: layer,
kCGWindowBounds: ["X": x, "Y": y, "Width": w, "Height": h] as [String: CGFloat],
kCGWindowOwnerPID: pid,
]
}
/// Front-to-back: the FIRST ordinary window containing the point owns it.
func testFrontmostOrdinaryWindowAtPointWins() {
let list = [
windowInfo(layer: 0, x: 0, y: 0, w: 500, h: 500, pid: 7),
windowInfo(layer: 0, x: 0, y: 0, w: 500, h: 500, pid: 8),
]
XCTAssertEqual(
OverlayPolicy.firstOrdinaryWindowOwner(at: CGPoint(x: 10, y: 10), in: list),
7
)
}
/// Non-zero layers (our own overlay panels, menu bar, Dock) are invisible
/// to the exposure probe — the overlay must never occlude its own target.
func testNonZeroLayersAreIgnored() {
let list = [
windowInfo(layer: 2_000, x: 0, y: 0, w: 500, h: 500, pid: 7),
windowInfo(layer: 0, x: 0, y: 0, w: 500, h: 500, pid: 8),
]
XCTAssertEqual(
OverlayPolicy.firstOrdinaryWindowOwner(at: CGPoint(x: 10, y: 10), in: list),
8
)
}
/// Windows not containing the point do not participate; over empty desktop
/// there is no owner at all.
func testPointOutsideAllWindowsHasNoOwner() {
let list = [
windowInfo(layer: 0, x: 100, y: 100, w: 50, h: 50, pid: 7)
]
XCTAssertEqual(
OverlayPolicy.firstOrdinaryWindowOwner(at: CGPoint(x: 120, y: 120), in: list),
7
)
XCTAssertNil(
OverlayPolicy.firstOrdinaryWindowOwner(at: CGPoint(x: 10, y: 10), in: list)
)
}
/// Malformed window-server entries (missing keys, empty bounds) are
/// skipped rather than trusted.
func testMalformedEntriesAreSkipped() {
let malformed: [[CFString: Any]] = [
[kCGWindowLayer: 0],
[kCGWindowLayer: 0, kCGWindowBounds: ["X": CGFloat(0), "Y": CGFloat(0), "Width": CGFloat(0), "Height": CGFloat(0)] as [String: CGFloat], kCGWindowOwnerPID: pid_t(9)],
windowInfo(layer: 0, x: 0, y: 0, w: 100, h: 100, pid: 10),
]
XCTAssertEqual(
OverlayPolicy.firstOrdinaryWindowOwner(at: CGPoint(x: 5, y: 5), in: malformed),
10
)
}
// MARK: - WindowExposure cache
/// Within the TTL the window list is read once; pid or point changes and
/// TTL expiry each force a fresh read. An unreadable list fails closed.
@MainActor
func testExposureCacheAndFailClosed() {
WindowExposure.resetForTests()
defer { WindowExposure.resetForTests() }
var reads = 0
let list = [windowInfo(layer: 0, x: 0, y: 0, w: 500, h: 500, pid: 7)]
let point = CGPoint(x: 10, y: 10)
XCTAssertTrue(
WindowExposure.targetWindowExposed(at: point, targetPid: 7, now: 100) { reads += 1; return list }
)
XCTAssertTrue(
WindowExposure.targetWindowExposed(at: point, targetPid: 7, now: 100.05) { reads += 1; return list }
)
XCTAssertEqual(reads, 1, "second read inside TTL must hit the cache")
XCTAssertTrue(
WindowExposure.targetWindowExposed(at: point, targetPid: 7, now: 100.05 + WindowExposure.cacheTTL) { reads += 1; return list }
)
XCTAssertEqual(reads, 2, "TTL expiry must re-read")
XCTAssertFalse(
WindowExposure.targetWindowExposed(at: point, targetPid: 8, now: 100.05 + WindowExposure.cacheTTL) { reads += 1; return list },
"different pid is a different question"
)
XCTAssertEqual(reads, 3)
WindowExposure.resetForTests()
XCTAssertFalse(
WindowExposure.targetWindowExposed(at: point, targetPid: 7, now: 200) { nil },
"unreadable window list must read as NOT exposed"
)
}
// MARK: - Lifecycle (unchanged semantics)
func testTransientHidePreservesActiveTrackingAndCanRevealAgain() {
var lifecycle = OverlayLifecycleState()
lifecycle.startTracking()
XCTAssertTrue(lifecycle.isActive)
XCTAssertFalse(lifecycle.isVisible)
lifecycle.showWindow()
XCTAssertTrue(lifecycle.isActive)
XCTAssertTrue(lifecycle.isVisible)
lifecycle.hideWindow()
XCTAssertTrue(lifecycle.isActive)
XCTAssertFalse(lifecycle.isVisible)
lifecycle.showWindow()
XCTAssertTrue(lifecycle.isVisible)
}
func testTerminalStopBecomesInactive() {
var lifecycle = OverlayLifecycleState()
lifecycle.startTracking()
lifecycle.showWindow()
lifecycle.stopTracking()
XCTAssertFalse(lifecycle.isActive)
XCTAssertFalse(lifecycle.isVisible)
}
func testStaleResolvedPairWithReusedPIDCannotRebindVisuals() throws {
let stale = try XCTUnwrap(ProvenProcessTarget(pid: 41, identity: processA))
let replacement = AXTreeProcessIdentity(
bundleID: "com.example.b",
executablePath: "/Applications/B.app/Contents/MacOS/B",
launchTime: 200
)
XCTAssertNil(stale.validatedPid(currentIdentity: replacement))
}
func testNewExplicitResolvedPairCanBindMatchingProcessLifetime() throws {
let resolved = try XCTUnwrap(ProvenProcessTarget(pid: 41, identity: processA))
XCTAssertEqual(resolved.validatedPid(currentIdentity: processA), 41)
}
}