|
1 | 1 | use crate::config::defaults::{DEFAULT_UPDATER_STATE_FILENAME, MAX_UPDATER_SNOOZE_HOURS}; |
2 | 2 | use crate::updater::poller; |
3 | | -use crate::updater::state::{UpdaterSnapshot, UpdaterState}; |
| 3 | +use crate::updater::state::{SnoozeSidecar, UpdaterSnapshot, UpdaterState}; |
| 4 | +use crate::updater::tcc_reset; |
4 | 5 | use std::path::PathBuf; |
5 | 6 | use std::time::{SystemTime, UNIX_EPOCH}; |
6 | 7 | use tauri::{AppHandle, Manager, State}; |
@@ -107,6 +108,121 @@ fn sidecar_path(app: &AppHandle) -> Result<PathBuf, String> { |
107 | 108 | Ok(dir.join(DEFAULT_UPDATER_STATE_FILENAME)) |
108 | 109 | } |
109 | 110 |
|
| 111 | +/// Stores `service` on `sidecar` so the post-restart launch can resume the |
| 112 | +/// grant flow. Returns `Err` when the service string is not one of the |
| 113 | +/// values Thuki resets at click time, so callers cannot smuggle arbitrary |
| 114 | +/// strings into a later `tccutil reset` invocation. |
| 115 | +pub fn prepare_pending_reregister( |
| 116 | + sidecar: &mut SnoozeSidecar, |
| 117 | + service: &str, |
| 118 | +) -> Result<&'static str, String> { |
| 119 | + let canonical = tcc_reset::validate_click_time_service(service) |
| 120 | + .ok_or_else(|| format!("unsupported tcc service: {service}"))?; |
| 121 | + sidecar.pending_reregister = Some(canonical.to_string()); |
| 122 | + Ok(canonical) |
| 123 | +} |
| 124 | + |
| 125 | +/// Removes `pending_reregister` from `sidecar` and returns its previous |
| 126 | +/// value. The caller is responsible for persisting the cleared sidecar so |
| 127 | +/// the resume flow does not loop on the next restart. |
| 128 | +pub fn take_pending_reregister(sidecar: &mut SnoozeSidecar) -> Option<String> { |
| 129 | + sidecar.pending_reregister.take() |
| 130 | +} |
| 131 | + |
| 132 | +/// Pure decision helper. Returns `true` when the click-time reset can be |
| 133 | +/// skipped because the startup path already cleared TCC for the running |
| 134 | +/// version. The marker survives A's reset+restart by being persisted to |
| 135 | +/// the sidecar, which is why the comparison is meaningful even though |
| 136 | +/// `was_reset_at_startup` would always be `false` on a freshly relaunched |
| 137 | +/// process. |
| 138 | +pub fn click_time_reset_can_skip( |
| 139 | + last_reset_for_version: Option<&str>, |
| 140 | + running_version: &str, |
| 141 | +) -> bool { |
| 142 | + last_reset_for_version == Some(running_version) |
| 143 | +} |
| 144 | + |
| 145 | +/// Click-time grant flow: persist a "resume after restart" marker, clear |
| 146 | +/// the stale TCC entry for the requested service, and relaunch. The |
| 147 | +/// frontend hands the service string straight in, so the validator inside |
| 148 | +/// `prepare_pending_reregister` is the trust boundary. |
| 149 | +/// |
| 150 | +/// Returns `true` when a relaunch has been scheduled and `false` when the |
| 151 | +/// running process already has a clean TCC slate (the startup path's most |
| 152 | +/// recent reset matches the running version). In the `false` case the |
| 153 | +/// frontend should run the in-line open-Settings + polling flow without |
| 154 | +/// expecting a relaunch. |
| 155 | +/// |
| 156 | +/// Sequencing matters when a relaunch is scheduled. Sidecar must be saved |
| 157 | +/// BEFORE `tccutil reset` runs so a crash between the two does not leave |
| 158 | +/// the user with a cleared grant and no resume marker. The restart is |
| 159 | +/// deferred so Tauri can finish dispatching the IPC reply (otherwise the |
| 160 | +/// frontend sees a disconnect error rather than a clean relaunch). |
| 161 | +#[cfg_attr(coverage_nightly, coverage(off))] |
| 162 | +#[tauri::command] |
| 163 | +pub fn reset_and_relaunch_for_grant( |
| 164 | + app: AppHandle, |
| 165 | + state: State<'_, UpdaterState>, |
| 166 | + service: String, |
| 167 | +) -> Result<bool, String> { |
| 168 | + // Validate first so a hostile string never reaches `tccutil` even when |
| 169 | + // the startup-clean path skips the reset. |
| 170 | + let canonical = tcc_reset::validate_click_time_service(&service) |
| 171 | + .ok_or_else(|| format!("unsupported tcc service: {service}"))?; |
| 172 | + |
| 173 | + let running = app.package_info().version.to_string(); |
| 174 | + let snooze = state.snooze_clone(); |
| 175 | + if click_time_reset_can_skip(snooze.last_reset_for_version.as_deref(), &running) { |
| 176 | + // Startup path already reset TCC for this exact version, so the |
| 177 | + // running binary's csreq already owns whatever TCC entries (if |
| 178 | + // any) System Settings will display. A second reset+relaunch |
| 179 | + // would only add a jarring quit on every grant click. |
| 180 | + return Ok(false); |
| 181 | + } |
| 182 | + |
| 183 | + let mut snooze = snooze; |
| 184 | + prepare_pending_reregister(&mut snooze, canonical)?; |
| 185 | + |
| 186 | + let path = sidecar_path(&app)?; |
| 187 | + snooze.save(&path).map_err(|e| e.to_string())?; |
| 188 | + state.set_pending_reregister(Some(canonical.to_string())); |
| 189 | + |
| 190 | + let bundle_id = app.config().identifier.clone(); |
| 191 | + tcc_reset::tccutil_reset_service(&bundle_id, canonical); |
| 192 | + |
| 193 | + let app_handle = app.clone(); |
| 194 | + tauri::async_runtime::spawn(async move { |
| 195 | + tokio::time::sleep(std::time::Duration::from_millis(150)).await; |
| 196 | + eprintln!( |
| 197 | + "thuki: [updater] relaunching after click-time TCC reset \ |
| 198 | + to refresh tccd PID tracking" |
| 199 | + ); |
| 200 | + app_handle.restart(); |
| 201 | + }); |
| 202 | + |
| 203 | + Ok(true) |
| 204 | +} |
| 205 | + |
| 206 | +/// Frontend-facing companion to `reset_and_relaunch_for_grant`. Reads the |
| 207 | +/// `pending_reregister` flag, clears it (in memory and on disk), and |
| 208 | +/// returns the value so PermissionsStep can resume the right step on a |
| 209 | +/// fresh launch without forcing the user to click a second time. |
| 210 | +#[cfg_attr(coverage_nightly, coverage(off))] |
| 211 | +#[tauri::command] |
| 212 | +pub fn consume_pending_grant_resume( |
| 213 | + app: AppHandle, |
| 214 | + state: State<'_, UpdaterState>, |
| 215 | +) -> Result<Option<String>, String> { |
| 216 | + let mut snooze = state.snooze_clone(); |
| 217 | + let value = take_pending_reregister(&mut snooze); |
| 218 | + if value.is_some() { |
| 219 | + let path = sidecar_path(&app)?; |
| 220 | + snooze.save(&path).map_err(|e| e.to_string())?; |
| 221 | + state.set_pending_reregister(None); |
| 222 | + } |
| 223 | + Ok(value) |
| 224 | +} |
| 225 | + |
110 | 226 | #[cfg(test)] |
111 | 227 | mod tests { |
112 | 228 | use super::*; |
@@ -144,4 +260,66 @@ mod tests { |
144 | 260 | fn snooze_deadline_zero_hours_is_now() { |
145 | 261 | assert_eq!(snooze_deadline(1_700_000_000, 0), 1_700_000_000); |
146 | 262 | } |
| 263 | + |
| 264 | + #[test] |
| 265 | + fn prepare_pending_reregister_accepts_accessibility() { |
| 266 | + let mut sidecar = SnoozeSidecar::default(); |
| 267 | + let canonical = prepare_pending_reregister(&mut sidecar, "Accessibility").unwrap(); |
| 268 | + assert_eq!(canonical, "Accessibility"); |
| 269 | + assert_eq!(sidecar.pending_reregister.as_deref(), Some("Accessibility")); |
| 270 | + } |
| 271 | + |
| 272 | + #[test] |
| 273 | + fn prepare_pending_reregister_accepts_screen_capture() { |
| 274 | + let mut sidecar = SnoozeSidecar::default(); |
| 275 | + let canonical = prepare_pending_reregister(&mut sidecar, "ScreenCapture").unwrap(); |
| 276 | + assert_eq!(canonical, "ScreenCapture"); |
| 277 | + assert_eq!(sidecar.pending_reregister.as_deref(), Some("ScreenCapture")); |
| 278 | + } |
| 279 | + |
| 280 | + #[test] |
| 281 | + fn prepare_pending_reregister_rejects_unsupported_service() { |
| 282 | + let mut sidecar = SnoozeSidecar::default(); |
| 283 | + let err = prepare_pending_reregister(&mut sidecar, "Camera").unwrap_err(); |
| 284 | + assert!(err.contains("Camera"), "error must surface offending value"); |
| 285 | + // Sidecar must remain untouched on rejection so a hostile call |
| 286 | + // cannot pollute the persisted resume marker. |
| 287 | + assert!(sidecar.pending_reregister.is_none()); |
| 288 | + } |
| 289 | + |
| 290 | + #[test] |
| 291 | + fn take_pending_reregister_returns_and_clears_value() { |
| 292 | + let mut sidecar = SnoozeSidecar { |
| 293 | + pending_reregister: Some("Accessibility".to_string()), |
| 294 | + ..SnoozeSidecar::default() |
| 295 | + }; |
| 296 | + assert_eq!( |
| 297 | + take_pending_reregister(&mut sidecar), |
| 298 | + Some("Accessibility".to_string()), |
| 299 | + ); |
| 300 | + assert!(sidecar.pending_reregister.is_none()); |
| 301 | + } |
| 302 | + |
| 303 | + #[test] |
| 304 | + fn take_pending_reregister_returns_none_when_unset() { |
| 305 | + let mut sidecar = SnoozeSidecar::default(); |
| 306 | + assert!(take_pending_reregister(&mut sidecar).is_none()); |
| 307 | + } |
| 308 | + |
| 309 | + #[test] |
| 310 | + fn click_time_reset_can_skip_when_versions_match() { |
| 311 | + assert!(click_time_reset_can_skip(Some("0.8.5"), "0.8.5")); |
| 312 | + } |
| 313 | + |
| 314 | + #[test] |
| 315 | + fn click_time_reset_does_not_skip_when_versions_differ() { |
| 316 | + assert!(!click_time_reset_can_skip(Some("0.8.4"), "0.8.5")); |
| 317 | + } |
| 318 | + |
| 319 | + #[test] |
| 320 | + fn click_time_reset_does_not_skip_when_marker_is_absent() { |
| 321 | + // No prior startup reset for this binary recorded: a stale csreq |
| 322 | + // grant could still be on disk, so the click MUST clean it up. |
| 323 | + assert!(!click_time_reset_can_skip(None, "0.8.5")); |
| 324 | + } |
147 | 325 | } |
0 commit comments