Files
claude-code-haha/native/cu-helper/Tests/CuHelperTests/PhysicalInputEpochMonitorTests.swift
程序员阿江(Relakkes) f3a6e02903 fix(computer-use): refuse to act through a window that cannot receive input
Three failures shared one root cause: the engine reported success for input it
had no way to deliver or verify.

A fully covered Chromium/CEF window stops drawing, so every screenshot returns
the last frame it painted while each action still answers "Action completed".
One session read a frozen image for three and a half minutes, pressed play four
times, and reported a song playing that the final capture showed paused.
Mutating commands now fail closed with `window_occluded` instead.

The physical-input monitor counted `.mouseMoved`, so moving the cursor anywhere
on screen aborted background automation — the one thing the feature exists to
allow. Movement is not an interaction with any app; presses, drags, keys and
scroll still are.

Focus notifications went out on NSEvent type 13 alone. The target accepted them,
ignored them, and reported nothing: 24 actions, 1 effective. Key-focus subtypes
travel on type 21, and `keyFocusReturned` (0x8000) needs a sign-preserving
truncation or it collapses to subtype 0 — a notification the target accepts and
discards.

The stale-capture notice claimed input does not depend on visibility. Measured
behaviour contradicts it, so it now says actions are refused while covered, and
says it without asking the model to consult the user about window management —
an earlier wording did, and the model handed back a three-step task after one
action.

Claude-Session: https://claude.ai/code/session_015j1yxxaoonyAS2iZ7qGnTS
2026-08-23 18:24:47 +08:00

139 lines
6.1 KiB
Swift
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
import CoreGraphics
import XCTest
@testable import cc_haha_computer_use
/// The monitor is a permission-free read over the session's HID event
/// counters. What must hold:
/// - the epoch is the sum over the DECLARED physical set, so any single
/// counter moving changes the epoch;
/// - identical reads produce identical epochs (stability is meaningful);
/// - the source is constitutively available with constant continuity, because
/// a counter read cannot be disabled or interrupted — this is the property
/// that fixed "every action fails focus_isolation_unavailable on a fresh
/// install" (the old listen-only tap needed an Input Monitoring grant that
/// onboarding never requested).
final class PhysicalInputEpochMonitorTests: XCTestCase {
/// Injected events still carry the helper marker. The counter monitor does
/// not need it (postToPid events do not reach the HID counters at all),
/// but the marker remains the provenance stamp that lets ANY observer —
/// diagnostics, external taps, future filters — tell agent input from
/// human input.
@MainActor
func testEveryHelperEventSourceCarriesOneStableNonzeroMarker() throws {
XCTAssertNotEqual(HelperEventMarker.value, 0)
let injectionSource = try XCTUnwrap(Injection.source)
let actionSource = try XCTUnwrap(AXAction.eventSource)
XCTAssertEqual(injectionSource.userData, HelperEventMarker.value)
XCTAssertEqual(actionSource.userData, HelperEventMarker.value)
XCTAssertEqual(injectionSource.userData, actionSource.userData)
}
/// Fixed counters → fixed epoch, and reading twice changes nothing.
func testStableCountersProduceAStableEpoch() {
let monitor = PhysicalInputEpochMonitor(counterReader: { _ in 7 })
let first = monitor.snapshot
let second = monitor.snapshot
XCTAssertEqual(first.epoch, second.epoch)
XCTAssertEqual(
first.epoch,
UInt64(PhysicalInputEpochMonitor.physicalEventTypes.count) * 7
)
}
/// One keystroke = one counter bump = a different epoch. This is the whole
/// interference signal.
func testAnySingleCounterBumpChangesTheEpoch() {
for bumped in PhysicalInputEpochMonitor.physicalEventTypes {
let before = PhysicalInputEpochMonitor(counterReader: { _ in 3 })
let after = PhysicalInputEpochMonitor(counterReader: { type in
type == bumped ? 4 : 3
})
XCTAssertNotEqual(
before.snapshot.epoch,
after.snapshot.epoch,
"bump of \(bumped) must be observable"
)
}
}
/// The physical set covers every input class the old tap mask watched
/// except plain motion: presses, releases, drags, keys, modifiers, and
/// scroll. `.mouseMoved` is deliberately excluded because moving the cursor
/// is not an interaction with any app, and counting it aborted background
/// automation whenever the user moved their mouse.
func testPhysicalSetCoversAllInputClasses() {
let set = Set(PhysicalInputEpochMonitor.physicalEventTypes.map(\.rawValue))
let required: [CGEventType] = [
.leftMouseDown, .leftMouseUp,
.rightMouseDown, .rightMouseUp,
.otherMouseDown, .otherMouseUp,
.leftMouseDragged, .rightMouseDragged, .otherMouseDragged,
.keyDown, .keyUp, .flagsChanged,
.scrollWheel,
]
for type in required {
XCTAssertTrue(set.contains(type.rawValue), "missing \(type)")
}
// And nothing extra: a type outside this set would break the
// "equal epochs ⇔ no physical input" equivalence the lease relies on.
XCTAssertEqual(set.count, required.count)
XCTAssertFalse(
set.contains(CGEventType.mouseMoved.rawValue),
"plain mouse movement must not count as interference"
)
}
/// Counter reads cannot fail, so availability is constant and continuity
/// never advances. `ForegroundLease.acquire` consumes exactly these fields.
func testSourceIsConstitutivelyAvailable() {
let monitor = PhysicalInputEpochMonitor(counterReader: { _ in 0 })
let snapshot = monitor.snapshot
XCTAssertTrue(snapshot.available)
XCTAssertEqual(snapshot.continuityGeneration, 0)
}
/// Extreme counters must not trap: 13 × UInt32.max fits comfortably in
/// UInt64, so the sum is exact — no overflow, no saturation.
func testMaximumCountersDoNotOverflow() {
let monitor = PhysicalInputEpochMonitor(counterReader: { _ in .max })
XCTAssertEqual(
monitor.snapshot.epoch,
UInt64(PhysicalInputEpochMonitor.physicalEventTypes.count)
* UInt64(UInt32.max)
)
}
/// Call-site compatibility: startAndWait returns a live snapshot and stop
/// is an idempotent no-op — the daemon and one-shot paths call both.
func testLifecycleShimsAreHarmless() {
let monitor = PhysicalInputEpochMonitor(counterReader: { _ in 5 })
let started = monitor.startAndWait()
XCTAssertTrue(started.available)
XCTAssertEqual(started.epoch, monitor.snapshot.epoch)
monitor.stop()
monitor.stop()
XCTAssertEqual(monitor.snapshot.epoch, started.epoch)
}
/// The production reader targets `.hidSystemState` — hardware input. This
/// is load-bearing twice: no Input Monitoring grant is needed to read it,
/// and (measured on-device) `CGEvent.postToPid` injection does not move
/// these counters, so the agent can never trip its own detector. Counters
/// must never run backwards between two consecutive reads.
func testSystemReaderReturnsMonotonicallyPlausibleValues() {
let read = PhysicalInputEpochMonitor.systemCounterReader
for type in PhysicalInputEpochMonitor.physicalEventTypes {
let first = read(type)
let second = read(type)
XCTAssertGreaterThanOrEqual(
second,
first,
"counter for \(type) went backwards"
)
}
}
}