Skip to content

feat(desktop): consume native desktop tools from githubnext/desktop-tools - #213

Merged
iamnbutler merged 2 commits into
mainfrom
codex/desktop-tools-extraction
Oct 8, 2026
Merged

iamnbutler merged 2 commits into
mainfrom
codex/desktop-tools-extraction

Conversation

@iamnbutler

@iamnbutler iamnbutler commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Ace now gets its native desktop tools from the standalone public package githubnext/desktop-tools. The package is pinned to one immutable commit, 8efe67f, in the root desktop catalog. This implements the extraction proposed in #188 (tracked by #8).

What moved to the package (unchanged apart from neutral names):

  • the 15 Peekaboo 4.8.0 patches and pins, byte-identical
  • the embedded Bridge runtime
  • the signed client CLI
  • the signing identity check
  • the patched build with its license copy
  • the request/result contract, as @githubnext/desktop-tools/protocol, with no imports so the hosted Worker bundle still builds
  • the Node client

What stays in Ace:

  • pi tool names, schemas, guidance, the durable unknown record and unsafe/sequential replay
  • the channel desktop gate and hosted forwarding
  • the Bun FFI wrapper
  • the project picker, now its own libAceProject.dylib built from apps/desktop/native/project.swift
  • Helper, updater and signing

apps/host/src/desktop.ts becomes a thin wrapper. It passes Ace's explicit client and socket paths and forwards only text, image, outcome and isError, so hosted links and pi rows don't change size.

Native identity is unchanged:

  • The package's desktop-tools-client is staged as ace-desktop-client and signed with the same <app-id>.desktop-client identifier.
  • The Bridge still runs inside Ace's UI process, so macOS grants still belong to the Ace app.
  • The shared Peekaboo coordination paths aren't touched: ~/.peekaboo and ~/Library/Application Support/Peekaboo/clipboard-paste-transaction.lock.

New behavior: the runtime advertises the host capability dev.githubnext.desktop-tools.protocol.1 (a compatibility epoch). Before sending any request, the client refuses hosts that don't advertise it, returning refused for actions.

Small wording changes: model-facing error text now says "native desktop client" where it said "Ace native client". The missing-client error now names the path instead of mentioning ACE_DESKTOP_CLIENT; docs/desktop-tools.md still documents that variable.

Validation

Ran:

  • bun types and bun run ci pass, and Ace CI is green.
  • A wrangler deploy --dry-run of services/channel bundles the protocol export.
  • Package CI at 8efe67f is green: a Linux check that dist/ matches source plus a portable import, and an unsigned macOS native build with a second build into the same output.
  • Signed Ace-dev from this branch (profile 9a1288a1, port 4731, app dev.ace.desktop.dev, team 8S43JJMN6B):
    • The UI process (PID 10589) loaded the package's libDesktopTools.dylib (sha256 7e299e105bf84a03…) and libAceProject.dylib (8c8ad8e7f2034dcb…).
    • The client ace-desktop-client (21b86767bc8bf202…) is signed as dev.ace.desktop.dev.9a1288a1.desktop-client.
  • Real anthropic/claude-haiku-4-5 run through that host, channel extraction-smoke (worker PID 12034):
    • desktop_apps and desktop_windows returned an owned fixture app's inventory.
    • desktop_inspect reported that capture is unavailable because the macOS GUI session is locked.
    • desktop_activate came back refused, with dispatch_state: none, from the signed client's lock check before any Bridge mutation, so no mutation receipt exists.
    • The fixture recorded zero Increment effects.
  • Reopen after stopping the dev run:
    • A distinct worker (PID 15298) reopened the channel.
    • Usage was unchanged: 65,799 tokens, $0.0246.
    • The channel log shows exactly 4 tool.start events, all from worker 12034, and none from 15298.
    • Pi's store holds 11 entries, and the activate result entry records refused.
    • No pre-reopen snapshot was taken, so this isn't a complete entry-by-entry comparison.
  • Package probes against a signed standalone reference host (dev.githubnext.desktop-tools.reference), from plain Node consumers:
    • With an npm-packed build of the package (earlier commits, same client and protocol code):
      • The standalone build ran.
      • Handshake, inventory, and clipboard read worked.
      • A host without the protocol capability got refused.
      • A wrong client identifier and an ad-hoc signature both failed the handshake.
    • With a fresh Git install of githubnext/desktop-tools#8efe67f:
      • npm added one package and ran no build.
      • Both exports imported.
      • The clipboard read and an application inventory went through the installed exports.
      • Window inventory was refused for missing grants.

Pending live input validation:

  • Live inspect, fresh click, stale refusal, host restart, and cancellation of a held operation.
  • Blockers: the Mac's GUI session was locked, and the reference host is still waiting for its Accessibility and Screen Recording grants.
  • Finish native window, menu, and dialog workflows #73's picker failure is baseline.

Built in Ace

Implementation, builds, and GitHub writes ran in Ace, including creation of the public package repository. Coordination and read-only source and evidence reviews used Codex because its harness is not yet available inside Ace (#9).

@iamnbutler
iamnbutler marked this pull request as ready for review October 8, 2026 15:12
@iamnbutler
iamnbutler merged commit ebddef6 into main Oct 8, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant