test(e2e): cover a macOS system key remap reaching the terminal (#11170) (#13314)

* fix(terminal): show a preedit the IME resumes without a compositionstart

Typing 2-Set Korean shows committed syllables but not the in-progress jamo, so
the user composes each syllable blind. Long-standing hole in the vendored
terminal library, not a regression: the same test fails identically against the
bundle this branch starts from.

The `.active` class that CSS keys `display: block` off is added only in
`compositionstart` and dropped in `_finalizeComposition`. Some IMEs (observed on
Windows/WSL Korean) resume a composition with a bare `compositionupdate` and no
second `compositionstart`, by which point `compositionend` has already hidden the
overlay, so the resumed preedit is written into a hidden element and never
positioned. `updateCompositionElements` also early-returned on `!_isComposing`,
so it would not lay the overlay out either.

Re-show the overlay on an update that carries data, and key the layout guard on
the shown overlay instead. `_isComposing` is deliberately left alone, so no
commit bookkeeping changes and `onData` stays byte-identical. The two guards are
equivalent on every pre-existing path: `compositionstart` sets both,
`_finalizeComposition` clears both.

The bundle hunks are the same two edits applied to the shipped minified output;
the sourcemaps are carried through unchanged.

* test(terminal): prove the resumed-preedit fix against a recorded Windows capture

The synthetic test pins the shape; this replays events a real Microsoft Korean
IME emitted on Windows/WSL. The capture holds three compositionupdates that
resume a composition with no second compositionstart — the exact ordering that
wrote the preedit into a hidden overlay.

Without the fix all three report shown:false; with it all three are visible.
Fixture derived from the sealed 11919-windows-wsl-current capture, which is
read-only and unmodified.

Co-authored-by: Orca <help@stably.ai>

* test(terminal): stop the recorded Hangul fixture pinning a derivation artifact

The capture logs each event twice — a dispatch record and a batched next-frame
re-log. Deriving from both replayed every event twice, which made three
compositionupdates appear to land after a session had ended. Filtered to
dispatch records the capture holds zero resumes and 11 balanced sessions, so
the previous toHaveLength(3) was pinning an artifact of the derivation.

Re-scoped to what the capture does prove: the preedit stays visible across all
37 real updates. Verified by reverting the patch that this passes either way,
so it is coverage and the synthetic test remains the discriminator. Both facts
are now stated in the file.

Co-authored-by: Orca <help@stably.ai>

* fix(terminal): restore the preedit visibility patch onto its own branch

The previous commit accidentally reverted it: checking main's patch and lockfile
into the worktree to test whether a test discriminates also stages them, so the
commit that followed swept them up.

Co-authored-by: Orca <help@stably.ai>

* fix(terminal): claim printable keydowns structurally so committed text survives

Co-authored-by: Orca <help@stably.ai>

* chore(reliability-gates): retarget the IME forwarding gate after the allowlist removal

The gate listed terminal-ime-input-source.test.ts, which went with the
input-source allowlist. Points at the substituted-text commit test instead,
which covers what the gate is actually protecting: text committed outside a
composition session reaching the pty exactly once.

Co-authored-by: Orca <help@stably.ai>

* docs(terminal): record why withholding a claimed keydown needs no timer

The predicate withholds a keydown's byte until the commit arrives, so a key the
IME eats without committing would be dropped. Measured across the recorded
corpus that case does not occur, and the browser marks IME-owned presses on the
keydown itself. Both facts belong next to the predicate rather than only in a
handoff note, since the obvious fix for the imagined gap is a timer, and a timer
here once wrote a newline the user never typed.

Co-authored-by: Orca <help@stably.ai>

* test(terminal): pin the kitty all-keys-as-escape-codes hole explicitly

Flag 8 asks for every printable key as an escape code; this path sends the
committed text raw instead. That is a deliberate trade, not an oversight, but it
was untested — the suite only covered the disambiguate flag. Pinning it makes
the choice visible and records the gate to use if it ever needs closing.

Co-authored-by: Orca <help@stably.ai>

* fix(terminal): keep the kitty key-release report for presses that reached the pty

Claiming the keyup unconditionally suppressed xterm's release report. That was
sized for the old design, which claimed only a short punctuation list; the
structural claim takes every printable keydown, so on macOS an app that
negotiated kitty report_event_types stopped seeing releases for ordinary typing
and would treat every printable key as held down.

Suppress the release only when the press put nothing on the wire — swallowed by
the input source, or owned by a composition transaction. xterm emits nothing
from keyup unless kitty report_event_types (or win32 input mode) is on, so
letting it through is inert everywhere else.

Co-authored-by: Orca <help@stably.ai>

* test(e2e): assert IME preedit geometry headlessly for Korean and CJK input

Both IME defects that shipped and were reverted walked through a suite of ~3000
passing assertions, because every one of them was about bytes reaching the PTY.
A preedit rendered into a hidden overlay satisfies all of them while the user
composes blind. The real-geometry coverage that would have caught it existed but
was headful, env-gated and macOS-only, so it never ran in CI.

Drives composition through CDP Input.imeSetComposition instead of a native input
source, which removes the accessibility grant and the system input source that
forced the headful gate. The suite runs in the normal headless project in about
55s serially, and asserts the composition overlay's real bounding rect — the one
property an overlay clipped to max-width:0 cannot fake and a DOM emulator cannot
produce.

Three tests are red on main and marked test.fail() so they stay visible in CI and
flip loud when their fix lands: the preedit resumed by a bare compositionupdate,
and full-width punctuation and digits committed from a keydown that still carries
the ASCII layout key.

Co-authored-by: Orca <help@stably.ai>

* test(e2e): drop the known-broken markers now the stack closes all three

Validated on real macOS hardware: with the two fixes below this layer, all
three report "Expected to fail, but passed". Korean preedit renders at
non-zero geometry through every jamo, and an Apple pinyin source sends
ef bc 8c e3 80 82 to the pty where main sends ASCII.

Worth recording why the punctuation case looked green on main once: an input
source whose id happens to contain an allowlist term, as Sogou's does, satisfies
the old gate. Correctness there depended on which IME the user had selected.

Co-authored-by: Orca <help@stably.ai>

* test(e2e): cover the Linux and Windows IME ownership shapes headlessly

The ten headless IME specs on this branch all decided ownership through a macOS
user-agent override, so the two platforms whose failure mode is a *dropped*
character rather than a downgraded one had no coverage at all, and the one
Windows-recorded trace already in the suite was replayed under whichever policy
the runner happened to report — macOS locally, Linux on the CI shards.

Adds four Linux specs and two Windows specs, every one of them replaying a
native capture rather than a hand-authored ordering:

- IBus/X11 Hangul mixed with literal ASCII. Its `compositionend` is EMPTY and
  the syllable arrives afterwards as a bare `insertText`, so reading the commit
  off `compositionend.data` — which the Windows capture rewards — drops every
  syllable on this framework.
- fcitx5/Wayland Hangul. No keydown at all for a composing key, not even 229,
  and physically wrong `code` values on the literal keys. Any ownership rule
  reading 229 or `code` fails here.
- Numeric pinyin candidate selection under both frameworks, with the ordinary
  digit kept as the negative control, so the two directions are pinned against
  each other rather than separately.
- Windows Microsoft Korean captured with real scan codes, including the two
  lines committed with Shift held.

Each asserts both sides of the boundary: the preedit's real geometry at every
frame the user would see, and the exact byte stream the native run put on the
PTY. The recorded `onData` the Windows/WSL fixture already carried is now
asserted instead of sitting unused.

Chinese moves up to first-class alongside Korean: pinyin preedit width is now
pinned the way the Japanese phrase already was, and full-width punctuation is
covered in the composition-session shape the Windows and Linux frameworks use,
not only the macOS insertText shape.

Two harness fixes fell out of the recorded traces and are why the IBus one
passes. The replay applied each event's recorded textarea state *after*
dispatch, one event too late for the handlers that read `textarea.value`; and
it left a task boundary between `compositionend` and the `input` carrying the
commit, which Chromium never inserts, letting xterm's deferred finalizer settle
against a textarea the committed text had not reached yet.

Co-authored-by: Orca <help@stably.ai>

* test(e2e): replay the recorded macOS IME shapes instead of only synthesising them

The macOS coverage on this branch drives Chromium composition through CDP, which
is genuine but hand-ordered, so it could not assert the one property that
decides the macOS rule: a composing keydown arrives with keyCode 229 while `key`
is still the single translated character the input source produced — `ㅎ`, not
`Process` — which is indistinguishable by length from an ordinary printable key.
Three native captures were sitting unused in the evidence set.

Adds a recorded 2-Set Korean session, including the syllable boundary where one
composition closes and the next opens with no keydown between them, asserted
against its own recorded byte stream.

Adds the third failure mode, which had no coverage in any shape: an abandoned
preedit leaking to the shell. Pinyin and Cangjie both backspace a composition
away to nothing, and the assertion is not "the right bytes" but "no bytes".

Both cancellation captures continue with a literal `ordinary` typed as bare
keydowns, the recorder's own negative control. That tail carries no `input`
events because the build it was captured on produced the byte from the keydown
itself, so replaying it would measure the recorder rather than the product; the
specs cut at the `compositionend` and say so.

Co-authored-by: Orca <help@stably.ai>

* test(e2e): promote the non-allowlist input-source punctuation spec to the suite

Qingg matches none of the terms the pre-structural build enumerated, so on that
build its bypass never installs. It is the one arm no headless spec can express,
and the only test here that the pre-structural build cannot pass.

Promoted from scratch with four changes, each forced by a measurement rather than
by taste:

- A non-attached input method is a refusal, not a negative result. macOS attaches
  per app instance and the attach can simply fail — 3 of 6 instances under
  exclusive host access, and re-selecting the source did not recover one of them
  across 9 keystrokes. That is now `test.skip()` with a reason naming the rerun,
  not a thrown error, and the suite does not gate on a fully green session.
- Attachment is probed with a LETTER. Punctuation substitution emits no
  compositionstart and no keyCode 229 even under a fully attached source, so at
  the keydown it is indistinguishable from having no source at all. The
  punctuation arms are judged on PTY bytes alone.
- The ASCII-layout control is now part of the spec rather than a side experiment.
  Without it a build that rewrote every `.` into `。` unconditionally would pass
  the Qingg arm and be badly wrong.
- The assertion runs by default instead of behind a strict-mode flag, and gained
  a non-vacuity check: the input source must have committed something. That is
  the sharp end of the mechanism — on the old build the DOM carries only keydown
  and keyup, so nothing is committed at all and the character is destroyed before
  the source is asked.

The verdict stays an equality between two measurements, never a comparison
against a hardcoded glyph, so it holds whatever punctuation mode the operator's
input source happens to be in. It reads `beforeinput`, not `input`: the forwarder
consumes `input` in the capture phase on the pane element, so a probe on the
helper textarea never sees it and a strict run fails with correct bytes
underneath.

Co-authored-by: Orca <help@stably.ai>

* feat(terminal): encode IME commits as CSI-u under the all-keys kitty flag

A pane that negotiates `report_all_keys_as_escape_codes` (bit 3) asked for every
printable key as a CSI-u report. The commit path wrote IME-committed text raw,
so such a pane got a legacy byte stream it had declined. That predicate has no
IME-specific condition, so it affected every macOS user in such a pane, not just
CJK users.

Encode the press that produced the commit instead, reusing xterm's own kitty
encoder rather than hand-rolling CSI-u.

`claimKeyEvent` is untouched: still unconditional, still structural, still no
kitty read on the keydown. The flag read happens once per commit.

The gate is bit 3 alone. Flags 1/2/4/16 leave printable keys as text, so panes
negotiating only those keep receiving substituted characters; gating on "kitty
active" would strip the substitution from every pane that negotiates anything.

Known limit, pinned by test: the report carries the physical key's codepoint,
not the committed glyph. Bit 3 is the app declaring it does not want text, and
bit 4 is how it asks for text back — but xterm's encoder derives that text field
from the same `key` it derives the keycode from, so carrying the committed glyph
needs an encoder change, not a wider gate.

* fix(terminal): report a held key's repeats as REPEAT under the kitty flags

The commit encoder never passed an event type, so xterm's encoder applied its
PRESS default to every auto-repeat keydown. A pane negotiating report_event_types
alongside bit 3 saw one held key as N separate strikes.

Carry the keydown's `repeat` on the claimed press and map it to the protocol's
REPEAT. The event type only reaches the wire when report_event_types is
negotiated, so this is inert for panes that asked only for bit 3.

Co-authored-by: Orca <help@stably.ai>

* test(e2e): cover a macOS system key remap reaching the terminal (#11170)

Co-authored-by: Orca <help@stably.ai>

* chore: drop non-mergeable IME e2e scratch files

---------

Co-authored-by: Orca <help@stably.ai>
This commit is contained in:
Neil
2026-08-09 16:07:29 -07:00
committed by GitHub
co-authored by Orca
parent 050ad3b32f
commit 9aa9d45467
@@ -0,0 +1,158 @@
/**
* Headless end-to-end coverage for a macOS system-wide key remap reaching the terminal.
*
* macOS lets a user rewrite what a physical key inserts by declaring it in
* `~/Library/KeyBindings/DefaultKeyBinding.dict`. The reported case is a Korean-source user who
* remaps the ₩ key back to a backquote:
*
* { "₩" = ("insertText:", "`"); "~₩" = ("insertText:", "₩"); }
*
* The remap is honoured by every other app on the system — browsers, native apps, and this app's
* own text inputs — and ignored only inside the terminal, which delivers the raw layout character
* to the PTY. The cause is the same one the rest of this suite is about: the substitution lives in
* the text system's `insertText:` callback, so a terminal that produces its byte from the
* **keydown** and then calls `preventDefault()` cancels the pipeline before the substitution can
* arrive.
*
* Byte-wise this is the full-width-punctuation shape with a different producer — a keydown still
* carrying the physical layout character, no composition session anywhere, and the real character
* arriving only in the following `insertText` input event — so it is dispatched through the same
* helper and pinned to the same macOS ownership policy.
*
* Two layout variants of the same physical key are covered, and the second is why this spec is not
* redundant. Korean layouts disagree about what the backquote position produces: 두벌식 and
* 세벌식 390 put ₩ there, 세벌식 최종 puts `*`. A character allowlist can only honour the remap for
* the characters someone remembered to list, so it fixes the reported ₩ and silently drops the
* identical remap for a 세벌식 최종 user. Deciding on the event's shape instead of on the character
* covers both, which is what the variant arm pins.
*
* The paired control matters as much as the positive case. A "fix" that special-cased the layout
* character into a backquote would satisfy the remap arm and be wrong for every Korean user who has
* no remap, so the unremapped key is asserted to still deliver its own character — once in the
* shape macOS produces with no remap at all (the keydown carries the glyph), and once through the
* remap path with the substitution set to that character itself, which is the config's second line.
*/
import type { CDPSession } from '@stablyai/playwright-test'
import { expect, test } from './helpers/orca-app'
import { closeTerminalImePaneArena, openTerminalImePaneArena } from './terminal-ime-pane-arena'
import { readTerminalImeBoundaryTrace } from './terminal-ime-boundary-probe'
import {
dispatchImeRewrittenPrintableKey,
dispatchImeSubstitutedTextKey,
dispatchPlainEnter,
type ImeKeyIdentity
} from './terminal-ime-cdp-composition'
import {
createTerminalImeByteReader,
removeTerminalImeByteReader,
startTerminalImeByteReader,
waitForTerminalImeBytes
} from './terminal-ime-byte-reader'
import { applyImePlatformPolicy, expectImePlatformPolicy } from './terminal-ime-platform-policy'
const BACKQUOTE = '`'
/** What the physical backquote position inserts, per Korean layout, before any remap. */
const LAYOUT_VARIANTS = [
{ label: '두벌식', character: '₩' },
{ label: '세벌식 최종', character: '*' }
] as const
type RemapArm = {
name: string
slug: string
/** What the text system commits for the keystroke. */
committed: (layoutCharacter: string) => string
dispatch: (session: CDPSession, key: ImeKeyIdentity, committed: string) => Promise<void>
}
const REMAP_ARMS: readonly RemapArm[] = [
{
// The reported bug. The keydown carries the layout character and the backquote exists only in
// the `insertText` event the remap produces, so anything that emits bytes from the keydown
// sends the layout character and the user's system-wide remap is dropped at the terminal.
name: 'a system remap rewrites it to a backquote',
slug: 'remapped-to-backquote',
committed: () => BACKQUOTE,
dispatch: (session, key, committed) => dispatchImeSubstitutedTextKey(session, key, committed)
},
{
// Control. With no remap the text system commits the layout character itself and macOS puts it
// straight on the keydown. A rewrite that mapped the key to a backquote unconditionally fails
// here.
name: 'no remap is installed',
slug: 'unremapped',
committed: (layoutCharacter) => layoutCharacter,
dispatch: (session, key) => dispatchImeRewrittenPrintableKey(session, key)
},
{
// Control on the substitution path itself, which is the config's second line: the remap is
// present and commits the layout character. Same `insertText` route as the first arm, opposite
// expected byte, so a fix that keys on the route rather than on what was committed cannot pass
// both.
name: 'a system remap substitutes it for itself',
slug: 'remapped-to-itself',
committed: (layoutCharacter) => layoutCharacter,
dispatch: (session, key, committed) => dispatchImeSubstitutedTextKey(session, key, committed)
}
]
test.describe('Terminal macOS system key remap', () => {
for (const layout of LAYOUT_VARIANTS) {
// keyCode 192 is the backquote position itself, unchanged by which character the layout puts
// on it — the remap targets the key, not the character.
const layoutKey: ImeKeyIdentity = { key: layout.character, code: 'Backquote', keyCode: 192 }
for (const arm of REMAP_ARMS) {
const committed = arm.committed(layout.character)
const forbidden = committed === BACKQUOTE ? layout.character : BACKQUOTE
test(`sends ${committed} for the ${layout.label} backquote key when ${arm.name}`, async ({
orcaPage,
testRepoPath
}, testInfo) => {
await applyImePlatformPolicy(orcaPage, 'mac')
await expectImePlatformPolicy(orcaPage, 'mac')
const arena = await openTerminalImePaneArena(orcaPage)
const reader = createTerminalImeByteReader(testRepoPath, 1)
let completed = false
try {
await startTerminalImeByteReader(orcaPage, arena.ptyId, reader)
await arm.dispatch(arena.session, layoutKey, committed)
await orcaPage.waitForTimeout(60)
await dispatchPlainEnter(arena.session)
const trace = await readTerminalImeBoundaryTrace(orcaPage)
// A remap is not an IME. Nothing here may open a composition session, and a spec that
// accidentally replayed one would be testing a path the suite already covers.
const compositionEvents = trace.dom
.map((event) => event.type)
.filter((type) => type.startsWith('composition'))
expect(compositionEvents).toEqual([])
// Pins the producer: the physical backquote position, carrying the layout's character.
// What was committed is asserted on the wire below rather than on the DOM, because the
// commit's `input` event is consumed before this probe sees it once a forwarder owns it.
const keydowns = trace.dom.filter(
(event) => event.type === 'keydown' && event.code === 'Backquote'
)
expect(keydowns).toHaveLength(1)
expect(keydowns[0].key).toBe(layout.character)
const sent = trace.onData.join('')
expect(sent, `${forbidden} reached the PTY instead of ${committed}`).not.toContain(
forbidden
)
expect(sent).toBe(`${committed}\r`)
const received = await waitForTerminalImeBytes(orcaPage, reader)
expect(received).toEqual([Buffer.from(`${committed}\n`).toString('hex')])
completed = true
} finally {
await closeTerminalImePaneArena(arena, testInfo, `${arm.slug}-${layout.label}`, !completed)
removeTerminalImeByteReader(reader)
}
})
}
}
})