Skip to main content

Crate rightkit_control

Crate rightkit_control 

Source
Expand description

rightkit-control: drive a real desktop app like a human, in the background.

macOS: input is posted to the target pid with CGEventPostToPid (never the global HID tap), so the frontmost app and the user’s cursor are untouched. State is read through the Accessibility API and window captures.

Control-plane guarantees (CodeRight EFF-001 / PTY-002):

Every effectful entry point routes through the gate: webdriver::Server, the tauri-plugin server, mac::Gated and the rightkit-control CLI (cli). The raw macOS primitives are reachable only through the explicitly named mac::unsafe_ungated opt-in.

Modules§

admission
EFF-001 effect admission: every effectful control request traverses one authority, validate → (policy) → approval → execute → settle, and a denial is final before any side effect.
cli
rightkit-control command-line dispatch. Every effectful subcommand is admitted through one EffectGate (EFF-001); read-only subcommands (trusted, frontmost, windows, ax, find) are not effects.
events
Content-free lifecycle events for the caller’s journal.
json
Minimal JSON helpers for the WebDriver wire (flat string extraction only).
keys
US-layout virtual keycodes for named keys (typed text uses Unicode events).
lease
PTY-002 input lease: epoch fencing plus monotonic, acknowledged input sequence so a stale controller can never inject input.
lease_store
PTY-002 durable lease state: execution identity, Running | Exited | Unknown execution state, and a store that lets an InputLease survive a host restart or crash without its epoch going backwards or its unacknowledged input being silently forgotten.
webdriver
W3C-WebDriver-shaped session bridge over a native Backend.