Compare commits
8
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a7d398ad6a | ||
|
|
a55a7a9170 | ||
|
|
8ddfe1b3e1 | ||
|
|
cc724f894b | ||
|
|
4f57cfacba | ||
|
|
8c39e8db4e | ||
|
|
2c0b8b021e | ||
|
|
7827ef3ad2 |
@@ -0,0 +1,24 @@
|
||||
# Normalize line endings. Unix artifacts MUST stay LF: a shell script or
|
||||
# desktop/udev/spec file checked out with CRLF (e.g. on Windows with
|
||||
# core.autocrlf=true) fails to run on Linux — `#!/usr/bin/env bash\r` is a
|
||||
# "bad interpreter" error, and .desktop/.rules parsers choke on trailing \r.
|
||||
* text=auto eol=lf
|
||||
|
||||
*.sh text eol=lf
|
||||
*.desktop text eol=lf
|
||||
*.rules text eol=lf
|
||||
*.spec text eol=lf
|
||||
*.xml text eol=lf
|
||||
control.in text eol=lf
|
||||
*.js text eol=lf
|
||||
*.mjs text eol=lf
|
||||
*.cjs text eol=lf
|
||||
*.json text eol=lf
|
||||
*.md text eol=lf
|
||||
launcher.sh text eol=lf
|
||||
|
||||
# Binary assets must never be line-ending converted.
|
||||
*.png binary
|
||||
*.ico binary
|
||||
*.gz binary
|
||||
*.traineddata binary
|
||||
@@ -30,7 +30,7 @@ jobs:
|
||||
|
||||
- uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: 20
|
||||
node-version-file: .nvmrc
|
||||
cache: npm
|
||||
|
||||
- name: Install dependencies
|
||||
|
||||
@@ -1,3 +1,36 @@
|
||||
# After action report
|
||||
|
||||
## Done — 10 PRs implemented, merged, and CI-green on both forges
|
||||
I worked through ai_prompts/prompt4.md and shipped PRs 1–10 of the plan's recommended sequence. Each was a focused branch, opened on both GitHub (Twest2/StepForge #5–#14) and Gitea (Tyler/autodoc #21–#30), verified green on GitHub CI (Ubuntu + Windows + dependency audit), merged with the same SHA to both forges, and the Gitea mirror closed with a merge note. Final state: main is byte-identical across local, GitHub, and Gitea (cc724f8), main CI is green, no open PRs, 289 unit tests pass (0 fail).
|
||||
|
||||
## PR What it fixed
|
||||
1 Pinned Node ≥22.12 (.nvmrc/engines); removed all runtime npm self-repair; refuse silent --no-sandbox; CI on pull_request + prod/full audits; made the click E2E stop hiding startup crashes as "SKIPPED"; remediated the form-data/undici advisories
|
||||
2 Closed the renderer privilege boundary: navigation/popup denial, sandboxed windows, per-channel IPC sender+argument validation, deny-by-default permissions (display capture only for the capture worker), intent-specific shell access replacing arbitrary shell:openPath
|
||||
3 Truthful local-first AI/privacy contract: raw keystroke capture off by default, AbortController timeouts + cancellation + concurrency + image-size limits, loopback-only Ollama unless explicitly opted in, honest docs + new docs/PRIVACY.md
|
||||
4 Optimistic revision fields + compare-and-swap (stale AI responses can't clobber edits), autosave keeps dirty state on failed saves, corrupt guides/steps quarantined instead of silently vanishing
|
||||
5 Region-capture nested-result + listener-leak bugs, single-owner power blocker, explicit click-source reporting (evdev fix), strict-mode skips instead of storing post-click shots, pathToFileURL, shutdown drain
|
||||
6 ZIP-bomb limits, transactional archive import, atomic snapshot restore, exclusive locks (O_EXCL + token), search index reconcile at startup, implemented the dead automatic-backup settings
|
||||
7 Platform adapter layer — window-context detection extracted to app/platform/{windows,linux,darwin}/; shared code no longer branches on process.platform; Linux capability diagnostics
|
||||
8 Production .deb (runtime-only staging, no dev tree, detected arch, desktop/MIME/icons, original generated icon set), apt setup scripts, real launcher; retired the old broken packager
|
||||
9 Production .rpm + dnf setup, shared stage-runtime.sh so both formats never drift
|
||||
10 Honest Wayland triggers (never promises per-click coordinates it can't deliver) + a least-privilege mouse-only udev rule replacing the broad input group keylogging surface; .gitattributes so Unix scripts don't break on CRLF
|
||||
I verified real behavior where possible: built and inspected an actual 107 MB .deb, ran the click self-test (markers 3/3, burst 8/8), and confirmed the sandboxed app boots.
|
||||
|
||||
## One blocking item I did not act on — the license (needs your decision)
|
||||
The plan calls this a legal release blocker that an implementation agent must not guess, and I agree. The repo currently contradicts itself:
|
||||
|
||||
package.json → MPL-2.0 and CONTRIBUTING requires MPL-2.0 + DCO sign-off (permits commercial use)
|
||||
docs/LICENSE + README §License → Creative Commons Attribution-NonCommercial (forbids commercial use; also not a software license)
|
||||
there is no root LICENSE file
|
||||
MPL-2.0 and CC-BY-NC are mutually exclusive, and contributors have been signing off under a license the project doesn't actually ship. You need to pick one, then I can reconcile the SPDX field, root LICENSE, README, CONTRIBUTING, package payloads, and the About view in a single follow-up PR.
|
||||
|
||||
## What remains (plan PRs 11–14 — larger, several need your input)
|
||||
Canonical blocks/callout-placement schema-v2 migration; lazy exports + Unicode font vendoring (needs a licensed-font choice); editor modularization + accessibility; and the signed reproducible release pipeline (needs signing keys). Also still open: the click self-test's arm/debounce scenarios fail on Linux — a pre-existing capture defect I surfaced honestly in PR 1 but didn't chase down (it needs on-device Linux capture debugging).
|
||||
|
||||
Tell me your license choice and I'll do the reconciliation PR; tell me which of 11–14 to prioritize and I'll take it next.
|
||||
|
||||
|
||||
|
||||
# StepForge comprehensive improvement plan
|
||||
|
||||
This document is an implementation handoff for another coding agent. It is based on a repository-wide audit of commit `534a28e` on 2026-07-03. It is a plan, not authorization to make all changes in one unreviewable patch.
|
||||
|
||||
+8
-2
@@ -900,8 +900,14 @@ function setupIpc() {
|
||||
platform: process.platform,
|
||||
}));
|
||||
// Platform capture-capability profile (session type, portal/PipeWire,
|
||||
// xinput, click source, actionable messages) for the diagnostics UI.
|
||||
h('platform:capabilities', () => require('./platform').detectCapabilities());
|
||||
// xinput, click source, actionable messages) for the diagnostics UI, plus
|
||||
// the honest active trigger for this machine and settings.
|
||||
h('platform:capabilities', () => {
|
||||
const platform = require('./platform');
|
||||
const caps = platform.detectCapabilities();
|
||||
const activeTrigger = platform.chooseCaptureTrigger(caps, settings.get('capture.fallbackTrigger') || 'interval');
|
||||
return { ...caps, activeTrigger };
|
||||
});
|
||||
}
|
||||
|
||||
// ---- lifecycle --------------------------------------------------------------
|
||||
|
||||
+16
-1
@@ -63,4 +63,19 @@ function detectCapabilities({ platform = process.platform, env = process.env } =
|
||||
};
|
||||
}
|
||||
|
||||
module.exports = { detectPlatform, createWindowContextProvider, detectCapabilities };
|
||||
/**
|
||||
* The honest capture-trigger decision for the current capabilities. On Linux
|
||||
* this defers to the diagnostics helper (which never promises per-click
|
||||
* capture with coordinates on Wayland); other platforms have a fixed answer.
|
||||
*/
|
||||
function chooseCaptureTrigger(capabilities, userTriggerPreference = 'interval') {
|
||||
if (capabilities && capabilities.os === 'linux') {
|
||||
return require('./linux/diagnostics').chooseCaptureTrigger(capabilities, userTriggerPreference);
|
||||
}
|
||||
if (capabilities && capabilities.os === 'windows') {
|
||||
return { trigger: 'click', clickSource: 'windows-hook', coordinates: true, marker: true, note: '' };
|
||||
}
|
||||
return { trigger: 'click', clickSource: capabilities ? capabilities.os : 'unavailable', coordinates: true, marker: true, note: '' };
|
||||
}
|
||||
|
||||
module.exports = { detectPlatform, createWindowContextProvider, detectCapabilities, chooseCaptureTrigger };
|
||||
|
||||
@@ -96,4 +96,61 @@ function detectLinuxCapabilities({
|
||||
};
|
||||
}
|
||||
|
||||
module.exports = { detectLinuxCapabilities, detectSessionType };
|
||||
/**
|
||||
* Decide the honest capture trigger for a Linux capability profile. StepForge
|
||||
* must never *promise* per-click capture with coordinates on Wayland, because
|
||||
* the platform does not expose pointer position to apps. Returns the trigger,
|
||||
* whether clicks carry coordinates, whether a marker can be drawn, and a
|
||||
* user-facing note. `userTriggerPreference` is the capture.fallbackTrigger
|
||||
* setting ('interval' | 'hotkey') used only when no click source exists.
|
||||
*/
|
||||
function chooseCaptureTrigger(capabilities, userTriggerPreference = 'interval') {
|
||||
const caps = capabilities || {};
|
||||
const click = caps.clickCapture;
|
||||
|
||||
if (click === 'x11-xinput') {
|
||||
return {
|
||||
trigger: 'click',
|
||||
clickSource: 'x11',
|
||||
coordinates: true,
|
||||
marker: true,
|
||||
note: 'Per-click capture with an accurate marker (X11 + xinput).',
|
||||
};
|
||||
}
|
||||
if (click === 'evdev-x11') {
|
||||
return {
|
||||
trigger: 'click',
|
||||
clickSource: 'evdev-x11',
|
||||
coordinates: true,
|
||||
marker: true,
|
||||
note: 'Per-click capture via kernel input devices (X11, no xinput).',
|
||||
};
|
||||
}
|
||||
if (click === 'evdev-wayland') {
|
||||
// Wayland exposes button presses (via evdev, if permitted) but NOT pointer
|
||||
// position, so a step is captured per click but without a marker. This is
|
||||
// only reached when the user opted into the least-privilege device rule.
|
||||
return {
|
||||
trigger: 'click',
|
||||
clickSource: 'evdev-wayland',
|
||||
coordinates: false,
|
||||
marker: false,
|
||||
note: 'Per-click capture on Wayland has no pointer position, so no marker is drawn.',
|
||||
};
|
||||
}
|
||||
|
||||
// No global click source: the safe baseline is the user's chosen fallback.
|
||||
const trigger = userTriggerPreference === 'hotkey' ? 'hotkey' : 'interval';
|
||||
return {
|
||||
trigger,
|
||||
clickSource: trigger,
|
||||
coordinates: false,
|
||||
marker: false,
|
||||
note: caps.isWayland
|
||||
? 'Wayland does not expose global clicks; recording uses your ' + trigger + ' trigger. '
|
||||
+ 'Screen sharing is requested once per recording via the portal.'
|
||||
: 'No global click source available; recording uses your ' + trigger + ' trigger.',
|
||||
};
|
||||
}
|
||||
|
||||
module.exports = { detectLinuxCapabilities, detectSessionType, chooseCaptureTrigger };
|
||||
|
||||
@@ -186,6 +186,11 @@ async function promptText({ title, label = 'Value', value = '', placeholder = ''
|
||||
});
|
||||
|
||||
field.addEventListener('keydown', (e) => {
|
||||
if (multiline && e.key === 'Enter') {
|
||||
// Let the textarea keep the Enter key for a new line.
|
||||
e.stopPropagation();
|
||||
return;
|
||||
}
|
||||
if (!multiline && e.key === 'Enter') {
|
||||
e.preventDefault();
|
||||
close();
|
||||
|
||||
+36
-18
@@ -105,6 +105,19 @@ function isEditableTarget(target) {
|
||||
);
|
||||
}
|
||||
|
||||
const ZOOM_IN_KEYS = new Set(['=', '+', 'Add']);
|
||||
const ZOOM_OUT_KEYS = new Set(['-', '_', 'Subtract']);
|
||||
|
||||
function zoomShortcutFromEvent(e) {
|
||||
if (!(e.ctrlKey || e.metaKey)) return null;
|
||||
|
||||
const { key, code } = e;
|
||||
if (key === '0' || code === 'Digit0' || code === 'Numpad0') return 'fit';
|
||||
if (ZOOM_IN_KEYS.has(key) || code === 'Equal' || code === 'NumpadAdd') return 'in';
|
||||
if (ZOOM_OUT_KEYS.has(key) || code === 'Minus' || code === 'NumpadSubtract') return 'out';
|
||||
return null;
|
||||
}
|
||||
|
||||
class GuideEditor {
|
||||
constructor({ root, onMetaChange = () => {}, onToast = toast, onBack = () => {} } = {}) {
|
||||
this.root = root;
|
||||
@@ -1182,7 +1195,6 @@ class GuideEditor {
|
||||
const typeSelect = makeSelect(selected.type, [
|
||||
'rect', 'oval', 'line', 'arrow', 'text', 'tooltip', 'number', 'blur', 'highlight', 'magnify', 'cursor',
|
||||
].map((type) => ({ value: type, label: ANNOTATION_TYPE_LABELS[type] || type })));
|
||||
const textInput = el('input', { type: 'text', value: selected.text || '', placeholder: 'Annotation text' });
|
||||
const valueInput = el('input', { type: 'number', value: Number.isFinite(selected.value) ? selected.value : '', placeholder: 'Value' });
|
||||
const strokeInput = el('input', { type: 'color', value: style.stroke || '#E5484D' });
|
||||
const fillInput = el('input', { type: 'color', value: style.fill && style.fill !== 'transparent' ? style.fill : '#ffffff' });
|
||||
@@ -1218,9 +1230,17 @@ class GuideEditor {
|
||||
const fields = new Set(ANNOTATION_FIELDS[selected.type] || []);
|
||||
const strokeLabel = (selected.type === 'text' || selected.type === 'number') ? 'Color' : 'Stroke';
|
||||
const typeLabel = ANNOTATION_TYPE_LABELS[selected.type] || selected.type;
|
||||
const textInput = fields.has('text')
|
||||
? el('textarea', {
|
||||
rows: Math.max(3, Math.min(8, String(selected.text || '').split('\n').length)),
|
||||
placeholder: 'Annotation text',
|
||||
spellcheck: true,
|
||||
})
|
||||
: el('input', { type: 'text', value: selected.text || '', placeholder: 'Annotation text' });
|
||||
if (fields.has('text')) textInput.value = selected.text || '';
|
||||
|
||||
const rows = [labeledRow('Type', typeSelect)];
|
||||
if (fields.has('text')) rows.push(labeledRow('Text', textInput));
|
||||
if (fields.has('text')) rows.push(labeledRow('Text', textInput, { stacked: true }));
|
||||
if (fields.has('value')) rows.push(labeledRow('Value', valueInput));
|
||||
if (fields.has('stroke')) rows.push(labeledRow(strokeLabel, strokeInput));
|
||||
if (fields.has('fill')) rows.push(labeledRow('Fill', fillInput));
|
||||
@@ -2178,9 +2198,10 @@ class GuideEditor {
|
||||
ann.text = value;
|
||||
step.annotations = clone(step.annotations || []);
|
||||
this.pendingSave = true;
|
||||
await this.flushStep(step);
|
||||
this.canvas.setAnnotations(step.annotations || []);
|
||||
this.renderAnnotationPanel();
|
||||
this.emitMeta();
|
||||
await this.flushStep(step);
|
||||
}
|
||||
|
||||
formatDescription(command, block = null) {
|
||||
@@ -2227,6 +2248,18 @@ class GuideEditor {
|
||||
|
||||
onDocumentKeyDown(e) {
|
||||
if (!this.active || !this.guide) return;
|
||||
const zoomShortcut = zoomShortcutFromEvent(e);
|
||||
if (zoomShortcut) {
|
||||
e.preventDefault();
|
||||
if (zoomShortcut === 'in') {
|
||||
this.setZoom(Math.min(3, (Number(this.currentZoom) || 1) + 0.25));
|
||||
} else if (zoomShortcut === 'out') {
|
||||
this.setZoom(Math.max(0.25, (Number(this.currentZoom) || 1) - 0.25));
|
||||
} else {
|
||||
this.setZoom('fit');
|
||||
}
|
||||
return;
|
||||
}
|
||||
if ((e.ctrlKey || e.metaKey) && e.key === '/' && !e.shiftKey) {
|
||||
e.preventDefault();
|
||||
this.openQuickActions();
|
||||
@@ -2270,21 +2303,6 @@ class GuideEditor {
|
||||
if (next) this.selectStep(next.stepId);
|
||||
return;
|
||||
}
|
||||
if ((e.ctrlKey || e.metaKey) && (e.key === '=' || e.key === '+')) {
|
||||
e.preventDefault();
|
||||
this.setZoom(Math.min(3, (Number(this.currentZoom) || 1) + 0.25));
|
||||
return;
|
||||
}
|
||||
if ((e.ctrlKey || e.metaKey) && e.key === '-') {
|
||||
e.preventDefault();
|
||||
this.setZoom(Math.max(0.25, (Number(this.currentZoom) || 1) - 0.25));
|
||||
return;
|
||||
}
|
||||
if ((e.ctrlKey || e.metaKey) && e.key === '0') {
|
||||
e.preventDefault();
|
||||
this.setZoom('fit');
|
||||
return;
|
||||
}
|
||||
// Copy / paste the selected annotation.
|
||||
if ((e.ctrlKey || e.metaKey) && e.key.toLowerCase() === 'c' && this.selectedAnnotationId) {
|
||||
e.preventDefault();
|
||||
|
||||
@@ -13,10 +13,11 @@ difference, how to get the best experience, and how to enable per-click capture.
|
||||
|
||||
| | **X11 / "Ubuntu on Xorg"** | **Wayland (default on Ubuntu)** |
|
||||
|---|---|---|
|
||||
| Screenshot per click | ✅ Yes | ✅ Yes (needs `input` group) |
|
||||
| Screenshot per click | ✅ Yes | ⚙️ Optional (least-privilege mouse rule) |
|
||||
| Red circle on the click | ✅ Yes | ❌ No (Wayland hides the cursor position) |
|
||||
| "Share your screen" prompt | Never | Once per recording session |
|
||||
| Setup needed | None | Add yourself to the `input` group |
|
||||
| Default trigger | Per click | Global hotkey or timed interval |
|
||||
| Setup needed | None | None (per-click is opt-in, mice only) |
|
||||
|
||||
**If you want the full Windows-like experience (click capture *with* the red
|
||||
marker), use an Xorg session — see [Option A](#option-a-best-experience--use-xorg).**
|
||||
@@ -67,27 +68,30 @@ stream stays open until you stop recording.
|
||||
> If you never see steps appear, make sure you actually picked a screen and
|
||||
> clicked **Share** in that dialog.
|
||||
|
||||
### Per-click capture (requires the `input` group)
|
||||
### Per-click capture (optional, least-privilege)
|
||||
|
||||
By default on Wayland, StepForge cannot see your clicks, so it falls back to
|
||||
**capturing a screenshot every few seconds** (timed capture).
|
||||
By default on Wayland, StepForge cannot see your clicks, so it uses a **global
|
||||
hotkey or a timed interval** to capture (see below). This is the recommended,
|
||||
no-extra-permissions path.
|
||||
|
||||
To get a screenshot **on every click** instead, give your user read access to
|
||||
the mouse devices by joining the `input` group:
|
||||
If you want a screenshot **on every click**, you can grant StepForge read
|
||||
access to your **mouse** devices. Do **not** use `sudo usermod -aG input`:
|
||||
joining the `input` group grants your user access to *all* input devices —
|
||||
**including keyboards** — permanently, on every session. That is a keylogging
|
||||
surface StepForge does not need.
|
||||
|
||||
Instead, install the least-privilege udev rule, which grants your active
|
||||
session read access to **mouse devices only** (never keyboards), scoped to
|
||||
whoever is physically logged in:
|
||||
|
||||
```bash
|
||||
sudo usermod -aG input "$USER"
|
||||
bash scripts/linux/enable-click-capture.sh
|
||||
```
|
||||
|
||||
Then **log out and log back in** (group membership only applies to new sessions).
|
||||
Verify it took effect:
|
||||
|
||||
```bash
|
||||
groups | tr ' ' '\n' | grep input # should print: input
|
||||
```
|
||||
|
||||
Now StepForge reads mouse buttons directly from the kernel (`/dev/input`) and
|
||||
captures a screenshot on each click.
|
||||
It shows you the exact rule and asks for confirmation before installing. Under
|
||||
the hood it uses a systemd `uaccess` ACL restricted to `ID_INPUT_MOUSE`
|
||||
devices — see [packaging/linux/common/60-stepforge-input.rules](../packaging/linux/common/60-stepforge-input.rules).
|
||||
Re-log in (or replug a USB mouse) for it to apply.
|
||||
|
||||
> **No red marker on Wayland.** Even with per-click capture working, Wayland
|
||||
> does not tell apps *where* the pointer is, so StepForge cannot draw the circle
|
||||
@@ -114,10 +118,16 @@ On launch StepForge chooses the best available click source:
|
||||
1. **Windows** — low-level mouse hook (position + timing).
|
||||
2. **X11** — `xinput` (position + timing → full red marker).
|
||||
3. **Linux evdev** (`/dev/input`) — button presses on X11 *and* Wayland, no
|
||||
position on Wayland. Used when `xinput` can't see clicks (i.e. Wayland), if
|
||||
you're in the `input` group.
|
||||
4. **Timed capture** — the always-works fallback (a screenshot every N seconds)
|
||||
when no click source is available.
|
||||
position on Wayland. Used when `xinput` can't see clicks (i.e. Wayland) and
|
||||
only if you opted into the least-privilege mouse rule
|
||||
(`scripts/linux/enable-click-capture.sh`).
|
||||
4. **Hotkey / timed capture** — the always-works fallback (the Capture hotkey,
|
||||
or a screenshot every N seconds) when no click source is available. On
|
||||
Wayland this is the default, and StepForge reports it honestly instead of
|
||||
pretending clicks are captured.
|
||||
|
||||
Open **Settings → Diagnostics** to see the detected session type, portal/
|
||||
PipeWire status, and the active capture trigger for your machine.
|
||||
|
||||
Screen frames come from a single long-lived capture stream per recording, so
|
||||
clicks/timer ticks never re-open the screen-share dialog.
|
||||
@@ -149,7 +159,9 @@ STEPFORGE_CAPTURE_LOG=1 npm start
|
||||
|
||||
- `[stepforge] screen-capture stream active …` — the stream is up.
|
||||
- `[stepforge] per-click capture via evdev on N device(s) …` — clicks are wired up.
|
||||
- `[stepforge] no readable mouse input devices …` — you need the `input` group (see above).
|
||||
- `[stepforge] no readable mouse input devices …` — per-click capture is not
|
||||
enabled; run `scripts/linux/enable-click-capture.sh` for the least-privilege
|
||||
mouse rule, or just use the hotkey/interval trigger.
|
||||
|
||||
**Harmless console noise.** Lines like `vaInitialize failed`, `Frame latency is
|
||||
negative`, and `StatusNotifierItem … already exported` come from Chromium/GNOME,
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
# StepForge least-privilege input access (OPTIONAL, opt-in).
|
||||
#
|
||||
# Grants the user at the ACTIVE local session read/write access to MOUSE input
|
||||
# devices only, via systemd-logind's `uaccess` ACL. This is the least-privilege
|
||||
# alternative to joining the broad `input` group, which would grant access to
|
||||
# ALL input devices — including keyboards — for the user permanently, on every
|
||||
# session. StepForge never needs keystrokes, so this rule deliberately EXCLUDES
|
||||
# keyboards.
|
||||
#
|
||||
# Scope of what this grants:
|
||||
# * only devices udev classifies as a mouse (ID_INPUT_MOUSE=1),
|
||||
# * only when they are NOT also a keyboard (ID_INPUT_KEYBOARD!=1),
|
||||
# * only to whoever is logged in at the physical seat (uaccess is
|
||||
# session-scoped, not a permanent group membership).
|
||||
#
|
||||
# StepForge uses this only for the optional Wayland per-click *trigger* (button
|
||||
# presses, no coordinates). It is not required — the safe default is a global
|
||||
# hotkey or interval capture.
|
||||
SUBSYSTEM=="input", KERNEL=="event*", ENV{ID_INPUT_MOUSE}=="1", ENV{ID_INPUT_KEYBOARD}!="1", TAG+="uaccess"
|
||||
Executable
+52
@@ -0,0 +1,52 @@
|
||||
#!/usr/bin/env bash
|
||||
# OPTIONAL: enable per-click capture on Wayland (or X11 without xinput) using a
|
||||
# LEAST-PRIVILEGE udev rule instead of the broad `input` group.
|
||||
#
|
||||
# Security tradeoff (read before running):
|
||||
# * This grants your ACTIVE local session read access to MOUSE devices only.
|
||||
# * It deliberately EXCLUDES keyboards — StepForge never needs keystrokes.
|
||||
# * Access is session-scoped (systemd `uaccess` ACL), not a permanent group.
|
||||
# * It is NOT required: the safe default is a global hotkey or interval
|
||||
# capture. Only enable this if you want a screenshot on every click.
|
||||
#
|
||||
# Compare to `sudo usermod -aG input "$USER"`, which grants access to ALL input
|
||||
# devices (including keyboards) for your user on every session — a much larger
|
||||
# surface. This script does not do that.
|
||||
set -euo pipefail
|
||||
|
||||
RULE_SRC="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)/packaging/linux/common/60-stepforge-input.rules"
|
||||
RULE_DEST="/etc/udev/rules.d/60-stepforge-input.rules"
|
||||
|
||||
if [ ! -f "$RULE_SRC" ]; then
|
||||
echo "error: rule file not found at $RULE_SRC" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "This installs a least-privilege udev rule granting your session read"
|
||||
echo "access to MOUSE devices only (never keyboards):"
|
||||
echo
|
||||
sed 's/^/ /' "$RULE_SRC"
|
||||
echo
|
||||
printf 'Install it to %s? [y/N] ' "$RULE_DEST"
|
||||
read -r reply
|
||||
case "$reply" in
|
||||
y|Y|yes|YES) ;;
|
||||
*) echo "Aborted. No changes made."; exit 0 ;;
|
||||
esac
|
||||
|
||||
SUDO=""
|
||||
if [ "$(id -u)" -ne 0 ]; then SUDO="sudo"; fi
|
||||
|
||||
$SUDO install -m 0644 "$RULE_SRC" "$RULE_DEST"
|
||||
$SUDO udevadm control --reload-rules
|
||||
$SUDO udevadm trigger --subsystem-match=input --action=change || true
|
||||
|
||||
cat <<'MSG'
|
||||
|
||||
Installed. You may need to unplug/replug a USB mouse or re-log in for the ACL
|
||||
to apply to already-connected devices.
|
||||
|
||||
To remove it later:
|
||||
sudo rm /etc/udev/rules.d/60-stepforge-input.rules
|
||||
sudo udevadm control --reload-rules
|
||||
MSG
|
||||
@@ -6,7 +6,8 @@ const fs = require('node:fs');
|
||||
const path = require('node:path');
|
||||
|
||||
const ROOT = path.resolve(__dirname, '..', '..');
|
||||
const read = (rel) => fs.readFileSync(path.join(ROOT, rel), 'utf8');
|
||||
// Strip CR so /^...$/m assertions are robust to CRLF checkouts on Windows CI.
|
||||
const read = (rel) => fs.readFileSync(path.join(ROOT, rel), 'utf8').replace(/\r\n/g, '\n');
|
||||
const exists = (rel) => fs.existsSync(path.join(ROOT, rel));
|
||||
|
||||
// These are structural checks that run in the normal (cross-platform) unit
|
||||
|
||||
@@ -0,0 +1,90 @@
|
||||
'use strict';
|
||||
|
||||
const test = require('node:test');
|
||||
const assert = require('node:assert/strict');
|
||||
const fs = require('node:fs');
|
||||
const path = require('node:path');
|
||||
|
||||
const { chooseCaptureTrigger, detectLinuxCapabilities } = require('../../app/platform/linux/diagnostics');
|
||||
const platform = require('../../app/platform');
|
||||
|
||||
const ROOT = path.resolve(__dirname, '..', '..');
|
||||
// Strip CR so assertions are robust to CRLF checkouts on Windows CI.
|
||||
const read = (rel) => fs.readFileSync(path.join(ROOT, rel), 'utf8').replace(/\r\n/g, '\n');
|
||||
const exists = (rel) => fs.existsSync(path.join(ROOT, rel));
|
||||
|
||||
// ---- honest trigger decisions ----------------------------------------------
|
||||
|
||||
test('X11 + xinput promises per-click capture with a marker', () => {
|
||||
const t = chooseCaptureTrigger({ os: 'linux', isWayland: false, clickCapture: 'x11-xinput' });
|
||||
assert.equal(t.trigger, 'click');
|
||||
assert.equal(t.coordinates, true);
|
||||
assert.equal(t.marker, true);
|
||||
});
|
||||
|
||||
test('Wayland evdev captures per click but never promises coordinates or a marker', () => {
|
||||
const t = chooseCaptureTrigger({ os: 'linux', isWayland: true, clickCapture: 'evdev-wayland' });
|
||||
assert.equal(t.trigger, 'click');
|
||||
assert.equal(t.coordinates, false, 'Wayland exposes no pointer position');
|
||||
assert.equal(t.marker, false);
|
||||
});
|
||||
|
||||
test('Wayland without a click source falls back to the user trigger, honestly', () => {
|
||||
const interval = chooseCaptureTrigger({ os: 'linux', isWayland: true, clickCapture: 'hotkey-or-interval-only' }, 'interval');
|
||||
assert.equal(interval.trigger, 'interval');
|
||||
assert.equal(interval.coordinates, false);
|
||||
assert.match(interval.note, /Wayland does not expose global clicks/i);
|
||||
|
||||
const hotkey = chooseCaptureTrigger({ os: 'linux', isWayland: true, clickCapture: 'hotkey-or-interval-only' }, 'hotkey');
|
||||
assert.equal(hotkey.trigger, 'hotkey');
|
||||
});
|
||||
|
||||
test('the platform facade wires the Linux trigger decision from real capabilities', () => {
|
||||
const caps = detectLinuxCapabilities({
|
||||
env: { XDG_SESSION_TYPE: 'wayland', WAYLAND_DISPLAY: 'wayland-0' },
|
||||
hasBinary: () => false,
|
||||
existsSync: () => false,
|
||||
readdirSync: () => [],
|
||||
});
|
||||
const t = platform.chooseCaptureTrigger(caps, 'interval');
|
||||
assert.equal(t.trigger, 'interval');
|
||||
assert.equal(t.marker, false);
|
||||
});
|
||||
|
||||
test('Windows always reports per-click capture', () => {
|
||||
const t = platform.chooseCaptureTrigger({ os: 'windows' });
|
||||
assert.equal(t.trigger, 'click');
|
||||
assert.equal(t.coordinates, true);
|
||||
});
|
||||
|
||||
// ---- least-privilege input access -------------------------------------------
|
||||
|
||||
test('the udev rule grants mouse-only access and excludes keyboards', () => {
|
||||
assert.ok(exists('packaging/linux/common/60-stepforge-input.rules'));
|
||||
const rule = read('packaging/linux/common/60-stepforge-input.rules');
|
||||
assert.match(rule, /ID_INPUT_MOUSE\}=="1"/);
|
||||
assert.match(rule, /ID_INPUT_KEYBOARD\}!="1"/, 'must exclude keyboards');
|
||||
assert.match(rule, /TAG\+="uaccess"/, 'session-scoped ACL, not a permanent group');
|
||||
});
|
||||
|
||||
test('the enable script is opt-in and installs the least-privilege rule, not the input group', () => {
|
||||
assert.ok(exists('scripts/linux/enable-click-capture.sh'));
|
||||
const script = read('scripts/linux/enable-click-capture.sh');
|
||||
assert.match(script, /read -r reply/, 'must confirm before installing');
|
||||
assert.match(script, /60-stepforge-input\.rules/, 'installs the least-privilege udev rule');
|
||||
// usermod may only appear in a comment (warning), never as an executed
|
||||
// command. Check command position (line start, optional sudo) so this is
|
||||
// robust to CRLF vs LF line endings across platforms.
|
||||
assert.doesNotMatch(script, /^\s*(sudo\s+)?usermod\b/m, 'must not run the broad input-group command');
|
||||
});
|
||||
|
||||
// ---- docs no longer push the broad input group ------------------------------
|
||||
|
||||
test('Linux docs recommend the least-privilege path and warn against the input group', () => {
|
||||
const doc = read('docs/GETTING_STARTED_WITH_LINUX.md');
|
||||
assert.match(doc, /enable-click-capture\.sh/);
|
||||
assert.match(doc, /least-privilege/i);
|
||||
// The broad group is now presented as a warning ("Do not use ..."), not a
|
||||
// recommended step.
|
||||
assert.match(doc, /Do \*\*not\*\* use `sudo usermod/);
|
||||
});
|
||||
Reference in New Issue
Block a user