Skip to content

fix(desktop): isolate blocking folder reveal from Tokio - #2399

Draft
richiemcilroy wants to merge 1 commit into
mainfrom
fix/linux-folder-reveal
Draft

richiemcilroy wants to merge 1 commit into
mainfrom
fix/linux-folder-reveal

Conversation

@richiemcilroy

@richiemcilroy richiemcilroy commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Showing a file in its folder on Linux can panic because the opener plugin runs blocking zbus inside an async Tauri command. Move the reveal operation onto a blocking worker and propagate both backend errors and worker failures.

Vendor the already-locked opener 2.5.0 source because current upstream still has the same direct synchronous call. Keep the IPC name, arguments, permission definitions, path canonicalization, native backends, and all four frontend callers unchanged. Apply the same boundary to diagnostic-report reveal after its existing path validation; this is an adjacent hazard, not an established source of the reported event. No runtime dependency upgrades.

Related: CAP-DESKTOP-2C2.

Validation:

  • macOS: all five opener regressions and all ten diagnostics tests passed; the desktop crate compiled.
  • Both current-thread and multi-thread Tokio regressions fail with the original nested-runtime panic when the blocking boundary is removed, then pass with the fix restored.
  • Opener tests cover exact paths, backend errors, worker failures, and validation of every path before native reveal. Existing diagnostics containment tests pass.
  • Strict desktop and opener Clippy (including test targets), Cargo formatting, scoped Biome formatting, and whitespace checks passed. The upstream generated JavaScript bundles retain their pre-existing Biome lint findings (7 errors and 12 warnings); no lint rules were disabled.
  • Verified the application capability file, upstream permission definitions, and all four frontend callers are unchanged. The formatted upstream JS bundle preserves scalar/multiple-path IPC calls.
  • Added the real Linux zbus regression to existing Linux CI, with its Tokio feature enabled. A missing bus/file manager is permitted; a worker panic is not.

CI completed for exact head 7a32ccae67d3efcbe20c5748c1f85a23655b9294: 19 checks passed, 4 failed, and Rust cache was skipped. CI run completed on its first attempt; no workflows were rerun.

  • Native CI opener regressions passed: Linux 6/6 (including the real zbus backend from Tokio), macOS 5/5, and Windows 5/5.
  • All three desktop build jobs passed the GPUI build, then failed the unchanged assets::tests::every_embedded_icon_is_referenced test. The same five unreferenced icons are present on the base commit; GPUI is a separate workspace unaffected by the opener patch. The later Tauri app build steps were not reached.
  • Windows Clippy failed on unchanged MemoryPressure::Normal / Warning dead-code warnings in crates/utils/src/export_resources.rs. macOS Clippy passed. No baseline fixes are included here.
  • Formatting, typechecking, mobile, plugin-version verification, native Windows discovery, CodeQL, and security checks passed. The existing Biome lint CI step tolerates findings; the upstream JavaScript findings disclosed above remain.

Linux and Windows execution were verified in CI, not locally. Graphical file selection and complete Tauri desktop builds remain unverified by this CI run. The Linux test permits missing session-bus/file-manager errors and checks that the blocking worker does not panic. Keep this PR draft pending platform review and resolution of the baseline CI blockers.

This branch was successfully deployed

1 active deployment
Preview — 7a32ccae Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant