Expand description
rightkit-control: drive a real desktop app like a human, in the background.
macOS: input is posted to the target pid with CGEventPostToPid (never the
global HID tap), so the frontmost app and the user’s cursor are untouched.
State is read through the Accessibility API and window captures.
Control-plane guarantees (CodeRight EFF-001 / PTY-002):
admission::EffectGate: every effectful request is validated, approved by a hostadmission::AdmissionHook, executed, and settled; a denial happens before any side effect.lease::InputLease: input carries(epoch, sequence); stale epochs are fenced, duplicates are deduplicated, unacknowledged input must be explicitly reconciled.lease::ControlSessioncomposes both.events::ControlEvent: content-free lifecycle events for the journal.
The raw mac primitives are ungated building blocks; host-facing surfaces
(webdriver::Server, the tauri-plugin server) route through the gate.
Modules§
- admission
- EFF-001 effect admission: every effectful control request traverses one authority, validate → (policy) → approval → execute → settle, and a denial is final before any side effect.
- events
- Content-free lifecycle events for the caller’s journal.
- json
- Minimal JSON helpers for the WebDriver wire (flat string extraction only).
- keys
- US-layout virtual keycodes for named keys (typed text uses Unicode events).
- lease
- PTY-002 input lease: epoch fencing plus monotonic, acknowledged input sequence so a stale controller can never inject input.
- webdriver
- W3C-WebDriver-shaped session bridge over a native
Backend.