Skip to main content

rightkit_control/
lib.rs

1//! rightkit-control: drive a real desktop app like a human, in the background.
2//!
3//! macOS: input is posted to the target pid with `CGEventPostToPid` (never the
4//! global HID tap), so the frontmost app and the user's cursor are untouched.
5//! State is read through the Accessibility API and window captures.
6//!
7//! Control-plane guarantees (CodeRight EFF-001 / PTY-002):
8//! - [`admission::EffectGate`]: every effectful request is validated, approved
9//!   by a host [`admission::AdmissionHook`], executed, and settled; a denial
10//!   happens before any side effect.
11//! - [`lease::InputLease`]: input carries `(epoch, sequence)`; stale epochs are
12//!   fenced, duplicates are deduplicated, unacknowledged input must be
13//!   explicitly reconciled. [`lease::ControlSession`] composes both.
14//! - [`events::ControlEvent`]: content-free lifecycle events for the journal.
15//!
16//! - [`lease_store`]: optional durable lease state (store trait plus an
17//!   atomic file store), execution identity and `Running | Exited | Unknown`.
18//!
19//! Every effectful entry point routes through the gate: `webdriver::Server`,
20//! the `tauri-plugin` server, `mac::Gated` and the `rightkit-control` CLI
21//! ([`cli`]). The raw macOS primitives are reachable only through the
22//! explicitly named `mac::unsafe_ungated` opt-in.
23pub mod admission;
24pub mod cli;
25#[cfg(feature = "tauri-plugin")]
26pub mod embedded;
27pub mod events;
28pub mod json;
29pub mod keys;
30pub mod lease;
31pub mod lease_store;
32#[cfg(target_os = "macos")]
33pub mod mac;
34pub mod webdriver;