Skip to content

Add temporary clipboard paste and lifecycle validation #72

Description

@iamnbutler

Status (Oct 6): persistent text, image and file-reference read/write are complete through #122, #135, #139, #142 and #147 (merge note). Remaining here: safe temporary image/file paste, image export, and the lifecycle (Stop, client death/disconnect, graceful shutdown) and hosted validation below. Draft #75 was closed as superseded; its timed 150 ms restoration must not ship. Unresolved-paste ownership validation is #78.

Complete the clipboard part of #8's input slice through Ace's embedded native bridge, under the channel owner's desktop-tools setting (see #8 and the current architecture).

Progress: Plain-text read/write landed in #122 (2c36c49). Bounded image reads landed in #135 (9c561ba): generation-consistent PNG/JPEG/TIFF previews, explicit orientation/transparency/size metadata, and the existing tool image result. Both have real native and model/durable-reopen proof. Image validation covered ten native cases (including rotation direction, transparent PNG, resizing, white JPEG fallback, absence and bounded refusals), exact persisted text/image results without new calls or usage, and private clipboard restoration with complete owned-runtime cleanup. Persistent text writes use #67’s existing unresolved-paste reservation gate; they do not preserve or restore prior contents. Literal text insertion’s temporary paste already landed in #67. Read-only file-list access landed in #139 (aa48e892): desktop_clipboard_read({format: "files"}) returns at most 32 ordered advertised local file URLs and decoded paths in a complete 24,000-byte JSON result, without opening files, checking existence, canonicalizing paths, or fetching resources. Nine actual native cases and one real model/durable-reopen check passed with private clipboard restoration and full owned-runtime cleanup. macOS filtered three unsupported URL forms before Ace could see them; these correctly returned absent and do not count as native guard coverage. AppKit rejected the legacy-format fixture before a product read, so that guard has source review only. Persistent image writes landed in #142 (a8417c9), validated at exact head 86e0c1e: one bounded execution-host image file, GUI validation, original PNG/JPEG/TIFF bytes and UTI, and the existing unresolved-paste reservation gate. Four exact-byte native cases and nine refusals passed, plus one real Claude Opus 5.5 write/read with distinct-worker durable reopen and one actual delayed-paste reservation refusal followed by admission after the exact receiver exited. All phases restored the original clipboard privately and cleaned every owned runtime. File-reference writes landed in #147 (f24257b). Safe temporary paste (including temporary image/file paste), image export, and the remaining lifecycle/hosted validation below stay open.

Expose explicit clipboard read/write and targeted temporary paste for text, images, and real file URL items. The clipboard belongs to the execution host. Keep clipboard access and the full temporary-paste lifecycle in Ace's long-lived GUI process, where OS clipboard permission applies; a short-lived native client cannot own reliable cleanup after Stop or disconnect.

Reuse Peekaboo's native clipboard transaction gate and generation claim. Capture all prior items/representations within a bounded preservation budget before writing, retain the exact focused-target receipt and snapshot lease, dispatch the guarded paste, and clean up even after caller cancellation. Restore prior contents only when both hold: no paste input was dispatched or meaningful consumption was observed, and the temporary generation is still current. Otherwise keep the replacement and its unresolved ownership (#78); a current generation alone is not enough, because a delayed paste may still be pending. Preserve a newer human update. Report delivery uncertainty and cleanup outcome separately, and verify the resulting target rather than claiming that dispatch proves consumption. A crash/force-kill cannot promise restoration; never restore stale persisted clipboard contents on a later launch.

The typed text clipboard extension added in #122 uses the existing authenticated Bridge transport and operation coordination. Extend that same boundary for images and files. Do not create another clipboard authority, authentication scheme, agent approval, or parallel message/history store. File-content payloads are not file-reference clipboard support: implement real multi-item file URLs. Return bounded text/image previews and file metadata; keep prior clipboard contents out of history unless explicitly read.

Done when real native and pi workflows read/write/copy/paste text, images, and files; temporary paste preserves previous multi-item contents and newer human changes; Stop, client death/disconnect, and graceful Ace shutdown exercise cleanup; local and hosted workspace behavior is verified. Handle native clipboard access refusal through Ace's existing OS permission experience. Keep unverified routes and inevitable cross-process clipboard races explicit.

Activity

  1. iamnbutler commented on Oct 5, 2026

    @iamnbutler
    ContributorAuthor

    Implementation is in draft PR #75, stacked on the keyboard/selection branch for #8.

    The source now includes typed text/image/multi-file clipboard read/write, a GUI-owned temporary paste transaction, generation-checked preservation of newer contents, separate input and cleanup outcomes, existing unsafe/no-replay handling, and content-free clipboard policy in Settings.

    Type checks, lint, Swift compilation, complete signed desktop packaging, strict signature verification, pinned patch checks, and Ace diff review passed. The real host FIFO input refusal passed before native dispatch; React Doctor found no issues in changed files.

    The PR intentionally remains draft. The Mac is locked, so native text/image/file paste and readback, complete restoration and newer-generation cases, Stop/client-disconnect cleanup, local/hosted real-model and replay checks, and actual Settings permission behavior are still unrun. A real AppKit receiver was compiled/signed but not launched; no native clipboard calls or desktop interaction were made while locked.

  2. iamnbutler commented on Oct 5, 2026

    @iamnbutler
    ContributorAuthor

    Extracted the first focused slice into draft #122 at 3aff2bf: explicit plain-text read/write, with complete bounded reads and persistent writes admitted by the existing pending-paste gate. It does not add temporary paste, image data or file references. Existing literal-insertion ownership code remains unchanged.

    The old #75 branch is preserved for reference; its timed 150 ms restoration must not ship because it can expose private prior contents to a delayed paste. Image/file access and temporary paste will be separate follow-ups using meaningful consumption and ownership.

    Types/lint, Swift parsing, independent source reviews, signed build/signature checks and real patch-stack application/repeat-build/drift checks pass. #122 remains draft while runtime permission, clipboard preservation, reservation, model and replay checks are completed. No live clipboard write has been performed for this candidate yet.

  3. iamnbutler commented on Oct 5, 2026

    @iamnbutler
    ContributorAuthor

    Merged #122 as 2c36c49: GUI-owned plain-text clipboard read/write on the channel’s execution host. Reads return complete generation-checked text within 24 KB and distinguish empty from absent; writes persist up to 8,192 UTF-16 units and do not paste or restore prior contents. Existing unresolved-paste ownership refuses a competing write.

    Real checks covered Unicode/CRLF with alternate representations, empty/absent text, clean refusals for unsupported/oversized/unreadable content, and write boundaries. A real pi/OpenAI write/read kept exact results after durable reopen without added usage, calls, or clipboard generation. One real delayed paste proved that reading retained its reservation, a competing write made no change, and normal write admission resumed after the exact receiver exited. Private prior contents stayed in GUI memory and were restored only at verified ownership; all fixtures/apps/hosts/workers and the disposable channel/project are cleaned up.

    The merged head includes normal quit #132 and passed type/lint checks, independent integration review, signed native build/signatures, and CI. Runtime provenance is explicit in the PR; unchanged passing cases were not repeatedly executed after unrelated merges. Image/file clipboard access, broader temporary paste, and interruption/remote-host coverage remain open.

  4. iamnbutler commented on Oct 5, 2026

    @iamnbutler
    ContributorAuthor

    Landed bounded read-only file references in #139 (aa48e89242ce5bdfa1e207f931e2f51d2f640966). The new format: "files" returns up to 32 ordered advertised local URLs/decoded paths within a complete 24 KB JSON result. It performs no file-content/existence access, path resolution, clipboard mutation, or reservation admission.

    Validation passed for real Unicode/spaces/directory/duplicate references, 32 entries, a complete 23,277-byte result, absence, and typed mixed/promise/unreadable/count/size refusals. A real pi model read the known public list once; store reopen preserved exact results, usage and tool counts without another read. Every original clipboard was preserved privately and restored only while fixture-owned; all owned runtimes and channel/project data were cleaned up.

    Coverage remains explicit: macOS filtered the remote/malformed/file-reference examples before exposing them to Ace, so those absent results do not exercise the native rejection guards. The legacy fixture was rejected by AppKit before a product call. The final integrated signed build and CI passed; image/file writes and broader temporary paste remain open here.

  5. iamnbutler commented on Oct 6, 2026

    @iamnbutler
    ContributorAuthor

    #142 is ready for review with persistent image clipboard writes. The original representation is preserved after GUI validation, and the existing pending-paste reservation gate controls admission.

    All finite validation passed at 86e0c1e: four exact-byte/UTI cases (PNG alpha, oriented JPEG, TIFF, exact 10 MiB input), nine pre-mutation refusals, a real Claude Opus 5.5 write/read with unchanged durable results and usage after restarting the worker, and an actual delayed-paste case that refused the image write until the exact receiver exited. The original clipboard was restored privately after every phase; all owned apps, workers, channel/project, ports, and reservation were cleaned up.

    This remains a local validation result. File-reference writes, broader temporary paste, and the lifecycle/hosted matrix in this issue remain open. PR142 has not merged yet.

  6. iamnbutler commented on Oct 6, 2026

    @iamnbutler
    ContributorAuthor

    Merged #142 (a8417c9f5a7201156a44f7a0123ac07142840e37): desktop_clipboard_write now accepts one execution-host image path, preserving its original PNG/JPEG/TIFF representation through the existing clipboard ownership gate. Input is bounded to 10 MiB and 64 million pixels; the result contains metadata, and an image preview requires an explicit read.

    Exact head 86e0c1e passed four native byte/type/image-fidelity cases, nine no-mutation refusals, and one real Claude Opus 5.5 write/read with exact result/image/usage preserved after a distinct-worker reopen. A real delayed paste kept its reservation: the image write refused before mutation, the receiver consumed its original public payload once, and a later write succeeded after exact receiver termination. Original clipboard contents were restored privately after each phase. All 21 owned processes, channel/project, sockets/ports, settings and pending reservation were cleaned up. CI, signed build/signatures and independent review passed.

    File-reference writes, general temporary paste, broader interruption/hosted/second-machine coverage remain open in #72/#8. This is merged on main, not a new Canary release.

  7. iamnbutler commented on Oct 6, 2026

    @iamnbutler
    ContributorAuthor

    File-reference writes are implemented and validated in draft #147, ready for final review on 7c2262d330ca87327bdd5ec63b6eeca59f75cf11.

    desktop_clipboard_write({format: "files", paths: [...]}) accepts 1–32 absolute execution-host paths. The host checks metadata only; the native writer publishes one ordered public.file-url item per path through the existing gate, preserving duplicate references and literal paths. Output reports native outcome and requested count without reading file contents or promising a receiver's symlink/copy behavior.

    Real proof completed:

    • Four exact native publication/readback cases, including symlink/duplicate references, 32 items, 23,277-byte output, and literal Unicode/URL-special paths; nine pre-publication refusals preserved clipboard generation.
    • Real Opus 5.5 write → explicit file read, then actual distinct-worker reopen with exact durable results, unchanged usage, and no replay.
    • Actual unresolved paste reservation refused the new write, and admission resumed after the exact receiver exited.
    • One Finder Paste copied the intended public file and directory into a fresh owned destination with matching contents. The original phase's later window-close assertion failed on an unknown result; no input was repeated. That separate behavior is recorded in #73, and the exact window was subsequently observed absent.

    The private clipboard was restored through the guarded GUI vault after the owned native runtime exited. All owned fixtures/runtime processes are gone, the paste gate is empty, and no private clipboard contents were persisted or sent to the model. Static checks, CI, the signed build, strict signatures, and the full native patch stack passed. #147 remains draft for final review; #8 tracks the broader work.

  8. iamnbutler commented on Oct 6, 2026

    @iamnbutler
    ContributorAuthor

    Merged #147 as f24257b7d6175fcaed97838a2c59ea28e49e04aa from validated head 7c2262d330ca87327bdd5ec63b6eeca59f75cf11. Persistent text, image and file-reference read/write are now on main. The real native/model/reopen/reservation evidence and separately preserved Finder-close uncertainty are recorded above and in the PR; private restoration and all owned runtime cleanup are complete. Broader temporary paste and the remaining lifecycle/hosted validation keep this issue open.

  9. changed the title [-]Add GUI-owned clipboard access and temporary paste transactions[/-] [+]Add temporary clipboard paste and lifecycle validation[/+] on Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions