Repository navigation
feat(desktop): Computer History for macOS, Windows, and Linux - #6668
sheehanmunim wants to merge 138 commits into
Conversation
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
One convention issue found: a compatibility re-export shim was added for the new Computer History service module. Everything else in the touched Effect service code (namespace subpath imports, inline Context.Service interface, make + layer exports, environment-acquired dependencies, Effect.catchTags) matches the conventions.
Posted via Macroscope — Effect Service Conventions
ApprovabilityVerdict: Needs human review 1 blocking correctness issue found. Diff is too large for automated approval analysis. A human reviewer should evaluate this PR. You can customize Macroscope's approvability policy. Learn more. |
02174c1 to
c04c7d9
Compare
12f47ca to
4609222
Compare
Match website filters against page host/path only, drop cross-window browser context fallback, keep AppleScript agent windows across brief AX gaps, and exact-match numeric app names that are not live PIDs. Co-authored-by: Cursor <cursoragent@cursor.com>
Strip query/fragment per URL candidate so title punctuation like ? or # cannot truncate the real page URL before host extraction. Co-authored-by: Cursor <cursoragent@cursor.com>
Keep exclusions working for http://[::1] and <https://host> haystacks. Co-authored-by: Cursor <cursoragent@cursor.com>
Outline/link URLs must not drive includeOnly or exclude matching. Co-authored-by: Cursor <cursoragent@cursor.com>
Prevent includeOnly path needles from matching substring paths on unrelated hosts. Co-authored-by: Cursor <cursoragent@cursor.com>
Preserve absolute path needles, accept full-URL rules, match localhost host/path filters, and require path segment boundaries. Co-authored-by: Cursor <cursoragent@cursor.com>
example.com/ and https://example.com match every page on that host, and trailing slashes no longer break full-URL path filters. Co-authored-by: Cursor <cursoragent@cursor.com>
Trim leading and trailing slashes so //private matches across platforms. Co-authored-by: Cursor <cursoragent@cursor.com>
Address open High/Medium review threads: nonblocking bridge writes, focused-window titles and segment rotation for History, owner-only agent-cursor sockets, no WAYLAND_DISPLAY env mutation, Wayland type_text/X11 cookie checks, private-mode and outline URL hardening, create-first bridge binding, and inert browser when disabled. Co-authored-by: Cursor <cursoragent@cursor.com>
Use MSG_DONTWAIT instead of O_NONBLOCK so NativeHost reads stay blocking, revalidate the bridge fd under writeLock, stop fabricating FRONTMOST apps, propagate Shift release errors, and never resurrect enabled from control.json. Co-authored-by: Cursor <cursoragent@cursor.com>
Codex already received recent history on sendTurn; load the same block for Claude, Cursor, and Grok so enabled History works regardless of harness. Co-authored-by: Cursor <cursoragent@cursor.com>
Stop the server from rewriting control.json, treat intentional History stops as stopped, and harden shared Computer Use paths (socket ownership, Int traps, AppleScript escaping, scroll/click targeting, bridge writes, AT-SPI retry). Co-authored-by: Cursor <cursoragent@cursor.com>
Use a transparent circular badge (no black square crop) and rounded-full clipping so the Computer Use settings row matches the pointer favicon. Co-authored-by: Cursor <cursoragent@cursor.com>
Point the Computer Use settings icon at the same soft-glow cursor-112 artwork as the desktop overlay, on a transparent canvas with no rounded crop. Co-authored-by: Cursor <cursoragent@cursor.com>
Match Computer Use tip so the lavender radial glow does not square-crop at settings row size. Co-authored-by: Cursor <cursoragent@cursor.com>
Keep the original pointer art and fade the glow into the badge rim so Settings and Chrome tab favicons no longer show a nested square crop. Co-authored-by: Cursor <cursoragent@cursor.com>
…ters Reject overlapping cross-window element drags, refuse symlink bridge dirs, recognize Safari TP/Edge Canary for private sticky, and ignore empty app-filter needles. Co-authored-by: Cursor <cursoragent@cursor.com>
92c688d to
2978695
Compare
Map press_key, harden Linux/Windows click/type paths, clear stale Chrome window cache, escape app-list brackets, recognize Mozilla Firefox, and honor in-memory mirror settings on clear/status. Co-authored-by: Cursor <cursoragent@cursor.com>
Only clear the daemon child after confirmed exit (or failed signal delivery), so a timed-out stop cannot report success while capture continues. Co-authored-by: Cursor <cursoragent@cursor.com>
| persisted: ComputerHistorySettings, | ||
| patch: Partial<ComputerHistorySettings>, | ||
| ): Promise<ComputerHistorySettings> => { | ||
| const base = lastMergedSettings ?? persisted; |
There was a problem hiding this comment.
🟠 High computerHistory/ComputerHistoryManager.ts:328
After the first patch, mergePatchSettingsImpl and the getStatus, clear, and removeMemory handlers keep using lastMergedSettings instead of newly persisted settings. A later partial patch therefore resurrects obsolete fields and can report or apply incorrect enabled, paused, filter, or Codex-mirroring values until restart. Reconcile or invalidate the optimistic snapshot against current persisted settings before using it.
🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/computerHistory/ComputerHistoryManager.ts around line 328:
After the first patch, `mergePatchSettingsImpl` and the `getStatus`, `clear`, and `removeMemory` handlers keep using `lastMergedSettings` instead of newly persisted settings. A later partial patch therefore resurrects obsolete fields and can report or apply incorrect `enabled`, `paused`, filter, or Codex-mirroring values until restart. Reconcile or invalidate the optimistic snapshot against current persisted settings before using it.
…ail-closed Close app-list ids at the first unescaped bracket, and only fall back from AT-SPI to X11 when there is no match — not when the query is ambiguous. Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit d9b242d. Configure here.
| timer = setTimeout(() => { | ||
| // Failsafe if the OS never emits `exit` after SIGKILL. | ||
| finish(); | ||
| }, 3_000); |
There was a problem hiding this comment.
Stop clears before exit
Medium Severity
The new SIGKILL path can call finish() (via !signaled or the 3s failsafe) and clear state.stopping before the child’s exit event runs. Disable then writes stopped via writeStoppedStatus, but a late exit handler still sees state.stopping === null and overwrites status with unavailable, so an intentional stop can look like a daemon crash and surface lastError even when Computer History is disabled.
Additional Locations (2)
Reviewed by Cursor Bugbot for commit d9b242d. Configure here.


Summary
Depends on #6537 (
mac/computer-use). This branch is stacked on that work — for a Computer History–only diff, compare againstmac/computer-use.Demo
computer-use-demo.mp4
Settings → Computer Use:
Test plan
running; events collected; summaries + Codex mirrorsample.frontmostevents; memory written; Dev coexists with Nightly (phase=running, events continuing)t3-desktop-mcp; Xvfb + Openbox recordssample.frontmostfor XTerm (reconfirmed after PR open)packages/shared/src/computerHistory/store.test.ts(6/6 passing)Note
Add Computer History recording and Desktop MCP server for macOS, Windows, and Linux
native/t3-desktop-mcp-rs) for Windows and Linux, and a Swift-based server (native/t3-desktop-mcp) for macOS, exposing accessibility-driven computer-use tools over stdio JSON-RPC.native/t3-chrome-extension) with a native messaging bridge that connects the browser to the desktop MCP server, enabling browser control tools./settings/computer-useand/settings/computer-historyroutes and settings UI, with IPC channels for permissions querying, history status/timeline, patching settings, and clearing history.CanonicalRequestTypeand approval handling across providers to supporttool_approvalandpermissions_approvalrequest kinds, with distinct UI labels and timeline icons.Macroscope summarized d9b242d.
Note
High Risk
Spawns native binaries with desktop automation, continuous local activity recording when enabled, and broad provider/MCP integration across auth-adjacent approval flows.
Overview
Computer Use and Computer History are wired end-to-end: settings pages, desktop IPC, a spawned
t3-desktop-mcprecorder daemon, and optional injection of recent history into agent turns.Computer Use adds settings for enabling desktop control, agent cursor overlay, and Chrome browser control. The desktop app exposes macOS accessibility/screen-recording status and Chrome extension detection via IPC. When enabled, Claude, Codex, Cursor, and Grok sessions attach a stdio
t3-desktopMCP server (alongside existingt3-code), resolved per session fromdesktopControlsettings. Codex advertises form elicitation; the runtime maps MCP permission and generic tool approvals intopermissions_approval/tool_approvalwith matching UI in the composer and timeline. macOSInfo.plistgainsNSAppleEventsUsageDescriptionso Automation prompts work for spawned MCP tools.Computer History adds a
ComputerHistoryManagerthat writescontrol.json, spawnscomputer-historyon the desktop MCP binary at bootstrap (if already enabled) and stops it cleanly on quit. Server-side background work syncs control and summarizes segments every minute; Codex turns can append loaded history to developer instructions. Settings cover enable/pause, Codex mirror, privacy exclusions, timeline clear/reveal/delete, with status polls that do not respawn the daemon after disable.Reviewed by Cursor Bugbot for commit e4775dc. Bugbot is set up for automated code reviews on this repo. Configure here.
Note
Replaces #6579. Same commits/HEAD intent; opened fresh because Macroscope UI Consistency on #6579 was stuck failing with retained findings that no longer match HEAD (check kept claiming only native commit
e1f85f3changed web UI).Made with Cursor
Note
Replaces #6664 (which replaced #6579). Same branch tip intent. Opened fresh because Macroscope Effect Service Conventions on #6664 retained a stale finding against deleted
apps/desktop/src/computerHistory/manager.tswhile UI Consistency, Correctness, and Bugbot were already green with 0 open review threads.Made with Cursor