From 9aa9d454672b46994fdd3abb6e842fe3a012abc7 Mon Sep 17 00:00:00 2001 From: Neil <4138956+nwparker@users.noreply.github.com> Date: Sun, 9 Aug 2026 16:07:29 -0700 Subject: [PATCH] test(e2e): cover a macOS system key remap reaching the terminal (#11170) (#13314) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * fix(terminal): show a preedit the IME resumes without a compositionstart Typing 2-Set Korean shows committed syllables but not the in-progress jamo, so the user composes each syllable blind. Long-standing hole in the vendored terminal library, not a regression: the same test fails identically against the bundle this branch starts from. The `.active` class that CSS keys `display: block` off is added only in `compositionstart` and dropped in `_finalizeComposition`. Some IMEs (observed on Windows/WSL Korean) resume a composition with a bare `compositionupdate` and no second `compositionstart`, by which point `compositionend` has already hidden the overlay, so the resumed preedit is written into a hidden element and never positioned. `updateCompositionElements` also early-returned on `!_isComposing`, so it would not lay the overlay out either. Re-show the overlay on an update that carries data, and key the layout guard on the shown overlay instead. `_isComposing` is deliberately left alone, so no commit bookkeeping changes and `onData` stays byte-identical. The two guards are equivalent on every pre-existing path: `compositionstart` sets both, `_finalizeComposition` clears both. The bundle hunks are the same two edits applied to the shipped minified output; the sourcemaps are carried through unchanged. * test(terminal): prove the resumed-preedit fix against a recorded Windows capture The synthetic test pins the shape; this replays events a real Microsoft Korean IME emitted on Windows/WSL. The capture holds three compositionupdates that resume a composition with no second compositionstart — the exact ordering that wrote the preedit into a hidden overlay. Without the fix all three report shown:false; with it all three are visible. Fixture derived from the sealed 11919-windows-wsl-current capture, which is read-only and unmodified. Co-authored-by: Orca * test(terminal): stop the recorded Hangul fixture pinning a derivation artifact The capture logs each event twice — a dispatch record and a batched next-frame re-log. Deriving from both replayed every event twice, which made three compositionupdates appear to land after a session had ended. Filtered to dispatch records the capture holds zero resumes and 11 balanced sessions, so the previous toHaveLength(3) was pinning an artifact of the derivation. Re-scoped to what the capture does prove: the preedit stays visible across all 37 real updates. Verified by reverting the patch that this passes either way, so it is coverage and the synthetic test remains the discriminator. Both facts are now stated in the file. Co-authored-by: Orca * fix(terminal): restore the preedit visibility patch onto its own branch The previous commit accidentally reverted it: checking main's patch and lockfile into the worktree to test whether a test discriminates also stages them, so the commit that followed swept them up. Co-authored-by: Orca * fix(terminal): claim printable keydowns structurally so committed text survives Co-authored-by: Orca * chore(reliability-gates): retarget the IME forwarding gate after the allowlist removal The gate listed terminal-ime-input-source.test.ts, which went with the input-source allowlist. Points at the substituted-text commit test instead, which covers what the gate is actually protecting: text committed outside a composition session reaching the pty exactly once. Co-authored-by: Orca * docs(terminal): record why withholding a claimed keydown needs no timer The predicate withholds a keydown's byte until the commit arrives, so a key the IME eats without committing would be dropped. Measured across the recorded corpus that case does not occur, and the browser marks IME-owned presses on the keydown itself. Both facts belong next to the predicate rather than only in a handoff note, since the obvious fix for the imagined gap is a timer, and a timer here once wrote a newline the user never typed. Co-authored-by: Orca * test(terminal): pin the kitty all-keys-as-escape-codes hole explicitly Flag 8 asks for every printable key as an escape code; this path sends the committed text raw instead. That is a deliberate trade, not an oversight, but it was untested — the suite only covered the disambiguate flag. Pinning it makes the choice visible and records the gate to use if it ever needs closing. Co-authored-by: Orca * fix(terminal): keep the kitty key-release report for presses that reached the pty Claiming the keyup unconditionally suppressed xterm's release report. That was sized for the old design, which claimed only a short punctuation list; the structural claim takes every printable keydown, so on macOS an app that negotiated kitty report_event_types stopped seeing releases for ordinary typing and would treat every printable key as held down. Suppress the release only when the press put nothing on the wire — swallowed by the input source, or owned by a composition transaction. xterm emits nothing from keyup unless kitty report_event_types (or win32 input mode) is on, so letting it through is inert everywhere else. Co-authored-by: Orca * test(e2e): assert IME preedit geometry headlessly for Korean and CJK input Both IME defects that shipped and were reverted walked through a suite of ~3000 passing assertions, because every one of them was about bytes reaching the PTY. A preedit rendered into a hidden overlay satisfies all of them while the user composes blind. The real-geometry coverage that would have caught it existed but was headful, env-gated and macOS-only, so it never ran in CI. Drives composition through CDP Input.imeSetComposition instead of a native input source, which removes the accessibility grant and the system input source that forced the headful gate. The suite runs in the normal headless project in about 55s serially, and asserts the composition overlay's real bounding rect — the one property an overlay clipped to max-width:0 cannot fake and a DOM emulator cannot produce. Three tests are red on main and marked test.fail() so they stay visible in CI and flip loud when their fix lands: the preedit resumed by a bare compositionupdate, and full-width punctuation and digits committed from a keydown that still carries the ASCII layout key. Co-authored-by: Orca * test(e2e): drop the known-broken markers now the stack closes all three Validated on real macOS hardware: with the two fixes below this layer, all three report "Expected to fail, but passed". Korean preedit renders at non-zero geometry through every jamo, and an Apple pinyin source sends ef bc 8c e3 80 82 to the pty where main sends ASCII. Worth recording why the punctuation case looked green on main once: an input source whose id happens to contain an allowlist term, as Sogou's does, satisfies the old gate. Correctness there depended on which IME the user had selected. Co-authored-by: Orca * test(e2e): cover the Linux and Windows IME ownership shapes headlessly The ten headless IME specs on this branch all decided ownership through a macOS user-agent override, so the two platforms whose failure mode is a *dropped* character rather than a downgraded one had no coverage at all, and the one Windows-recorded trace already in the suite was replayed under whichever policy the runner happened to report — macOS locally, Linux on the CI shards. Adds four Linux specs and two Windows specs, every one of them replaying a native capture rather than a hand-authored ordering: - IBus/X11 Hangul mixed with literal ASCII. Its `compositionend` is EMPTY and the syllable arrives afterwards as a bare `insertText`, so reading the commit off `compositionend.data` — which the Windows capture rewards — drops every syllable on this framework. - fcitx5/Wayland Hangul. No keydown at all for a composing key, not even 229, and physically wrong `code` values on the literal keys. Any ownership rule reading 229 or `code` fails here. - Numeric pinyin candidate selection under both frameworks, with the ordinary digit kept as the negative control, so the two directions are pinned against each other rather than separately. - Windows Microsoft Korean captured with real scan codes, including the two lines committed with Shift held. Each asserts both sides of the boundary: the preedit's real geometry at every frame the user would see, and the exact byte stream the native run put on the PTY. The recorded `onData` the Windows/WSL fixture already carried is now asserted instead of sitting unused. Chinese moves up to first-class alongside Korean: pinyin preedit width is now pinned the way the Japanese phrase already was, and full-width punctuation is covered in the composition-session shape the Windows and Linux frameworks use, not only the macOS insertText shape. Two harness fixes fell out of the recorded traces and are why the IBus one passes. The replay applied each event's recorded textarea state *after* dispatch, one event too late for the handlers that read `textarea.value`; and it left a task boundary between `compositionend` and the `input` carrying the commit, which Chromium never inserts, letting xterm's deferred finalizer settle against a textarea the committed text had not reached yet. Co-authored-by: Orca * test(e2e): replay the recorded macOS IME shapes instead of only synthesising them The macOS coverage on this branch drives Chromium composition through CDP, which is genuine but hand-ordered, so it could not assert the one property that decides the macOS rule: a composing keydown arrives with keyCode 229 while `key` is still the single translated character the input source produced — `ㅎ`, not `Process` — which is indistinguishable by length from an ordinary printable key. Three native captures were sitting unused in the evidence set. Adds a recorded 2-Set Korean session, including the syllable boundary where one composition closes and the next opens with no keydown between them, asserted against its own recorded byte stream. Adds the third failure mode, which had no coverage in any shape: an abandoned preedit leaking to the shell. Pinyin and Cangjie both backspace a composition away to nothing, and the assertion is not "the right bytes" but "no bytes". Both cancellation captures continue with a literal `ordinary` typed as bare keydowns, the recorder's own negative control. That tail carries no `input` events because the build it was captured on produced the byte from the keydown itself, so replaying it would measure the recorder rather than the product; the specs cut at the `compositionend` and say so. Co-authored-by: Orca * test(e2e): promote the non-allowlist input-source punctuation spec to the suite Qingg matches none of the terms the pre-structural build enumerated, so on that build its bypass never installs. It is the one arm no headless spec can express, and the only test here that the pre-structural build cannot pass. Promoted from scratch with four changes, each forced by a measurement rather than by taste: - A non-attached input method is a refusal, not a negative result. macOS attaches per app instance and the attach can simply fail — 3 of 6 instances under exclusive host access, and re-selecting the source did not recover one of them across 9 keystrokes. That is now `test.skip()` with a reason naming the rerun, not a thrown error, and the suite does not gate on a fully green session. - Attachment is probed with a LETTER. Punctuation substitution emits no compositionstart and no keyCode 229 even under a fully attached source, so at the keydown it is indistinguishable from having no source at all. The punctuation arms are judged on PTY bytes alone. - The ASCII-layout control is now part of the spec rather than a side experiment. Without it a build that rewrote every `.` into `。` unconditionally would pass the Qingg arm and be badly wrong. - The assertion runs by default instead of behind a strict-mode flag, and gained a non-vacuity check: the input source must have committed something. That is the sharp end of the mechanism — on the old build the DOM carries only keydown and keyup, so nothing is committed at all and the character is destroyed before the source is asked. The verdict stays an equality between two measurements, never a comparison against a hardcoded glyph, so it holds whatever punctuation mode the operator's input source happens to be in. It reads `beforeinput`, not `input`: the forwarder consumes `input` in the capture phase on the pane element, so a probe on the helper textarea never sees it and a strict run fails with correct bytes underneath. Co-authored-by: Orca * feat(terminal): encode IME commits as CSI-u under the all-keys kitty flag A pane that negotiates `report_all_keys_as_escape_codes` (bit 3) asked for every printable key as a CSI-u report. The commit path wrote IME-committed text raw, so such a pane got a legacy byte stream it had declined. That predicate has no IME-specific condition, so it affected every macOS user in such a pane, not just CJK users. Encode the press that produced the commit instead, reusing xterm's own kitty encoder rather than hand-rolling CSI-u. `claimKeyEvent` is untouched: still unconditional, still structural, still no kitty read on the keydown. The flag read happens once per commit. The gate is bit 3 alone. Flags 1/2/4/16 leave printable keys as text, so panes negotiating only those keep receiving substituted characters; gating on "kitty active" would strip the substitution from every pane that negotiates anything. Known limit, pinned by test: the report carries the physical key's codepoint, not the committed glyph. Bit 3 is the app declaring it does not want text, and bit 4 is how it asks for text back — but xterm's encoder derives that text field from the same `key` it derives the keycode from, so carrying the committed glyph needs an encoder change, not a wider gate. * fix(terminal): report a held key's repeats as REPEAT under the kitty flags The commit encoder never passed an event type, so xterm's encoder applied its PRESS default to every auto-repeat keydown. A pane negotiating report_event_types alongside bit 3 saw one held key as N separate strikes. Carry the keydown's `repeat` on the claimed press and map it to the protocol's REPEAT. The event type only reaches the wire when report_event_types is negotiated, so this is inert for panes that asked only for bit 3. Co-authored-by: Orca * test(e2e): cover a macOS system key remap reaching the terminal (#11170) Co-authored-by: Orca * chore: drop non-mergeable IME e2e scratch files --------- Co-authored-by: Orca --- .../terminal-macos-system-key-remap.spec.ts | 158 ++++++++++++++++++ 1 file changed, 158 insertions(+) create mode 100644 tests/e2e/terminal-macos-system-key-remap.spec.ts diff --git a/tests/e2e/terminal-macos-system-key-remap.spec.ts b/tests/e2e/terminal-macos-system-key-remap.spec.ts new file mode 100644 index 00000000000..711b7a6b602 --- /dev/null +++ b/tests/e2e/terminal-macos-system-key-remap.spec.ts @@ -0,0 +1,158 @@ +/** + * Headless end-to-end coverage for a macOS system-wide key remap reaching the terminal. + * + * macOS lets a user rewrite what a physical key inserts by declaring it in + * `~/Library/KeyBindings/DefaultKeyBinding.dict`. The reported case is a Korean-source user who + * remaps the ₩ key back to a backquote: + * + * { "₩" = ("insertText:", "`"); "~₩" = ("insertText:", "₩"); } + * + * The remap is honoured by every other app on the system — browsers, native apps, and this app's + * own text inputs — and ignored only inside the terminal, which delivers the raw layout character + * to the PTY. The cause is the same one the rest of this suite is about: the substitution lives in + * the text system's `insertText:` callback, so a terminal that produces its byte from the + * **keydown** and then calls `preventDefault()` cancels the pipeline before the substitution can + * arrive. + * + * Byte-wise this is the full-width-punctuation shape with a different producer — a keydown still + * carrying the physical layout character, no composition session anywhere, and the real character + * arriving only in the following `insertText` input event — so it is dispatched through the same + * helper and pinned to the same macOS ownership policy. + * + * Two layout variants of the same physical key are covered, and the second is why this spec is not + * redundant. Korean layouts disagree about what the backquote position produces: 두벌식 and + * 세벌식 390 put ₩ there, 세벌식 최종 puts `*`. A character allowlist can only honour the remap for + * the characters someone remembered to list, so it fixes the reported ₩ and silently drops the + * identical remap for a 세벌식 최종 user. Deciding on the event's shape instead of on the character + * covers both, which is what the variant arm pins. + * + * The paired control matters as much as the positive case. A "fix" that special-cased the layout + * character into a backquote would satisfy the remap arm and be wrong for every Korean user who has + * no remap, so the unremapped key is asserted to still deliver its own character — once in the + * shape macOS produces with no remap at all (the keydown carries the glyph), and once through the + * remap path with the substitution set to that character itself, which is the config's second line. + */ +import type { CDPSession } from '@stablyai/playwright-test' +import { expect, test } from './helpers/orca-app' +import { closeTerminalImePaneArena, openTerminalImePaneArena } from './terminal-ime-pane-arena' +import { readTerminalImeBoundaryTrace } from './terminal-ime-boundary-probe' +import { + dispatchImeRewrittenPrintableKey, + dispatchImeSubstitutedTextKey, + dispatchPlainEnter, + type ImeKeyIdentity +} from './terminal-ime-cdp-composition' +import { + createTerminalImeByteReader, + removeTerminalImeByteReader, + startTerminalImeByteReader, + waitForTerminalImeBytes +} from './terminal-ime-byte-reader' +import { applyImePlatformPolicy, expectImePlatformPolicy } from './terminal-ime-platform-policy' + +const BACKQUOTE = '`' + +/** What the physical backquote position inserts, per Korean layout, before any remap. */ +const LAYOUT_VARIANTS = [ + { label: '두벌식', character: '₩' }, + { label: '세벌식 최종', character: '*' } +] as const + +type RemapArm = { + name: string + slug: string + /** What the text system commits for the keystroke. */ + committed: (layoutCharacter: string) => string + dispatch: (session: CDPSession, key: ImeKeyIdentity, committed: string) => Promise +} + +const REMAP_ARMS: readonly RemapArm[] = [ + { + // The reported bug. The keydown carries the layout character and the backquote exists only in + // the `insertText` event the remap produces, so anything that emits bytes from the keydown + // sends the layout character and the user's system-wide remap is dropped at the terminal. + name: 'a system remap rewrites it to a backquote', + slug: 'remapped-to-backquote', + committed: () => BACKQUOTE, + dispatch: (session, key, committed) => dispatchImeSubstitutedTextKey(session, key, committed) + }, + { + // Control. With no remap the text system commits the layout character itself and macOS puts it + // straight on the keydown. A rewrite that mapped the key to a backquote unconditionally fails + // here. + name: 'no remap is installed', + slug: 'unremapped', + committed: (layoutCharacter) => layoutCharacter, + dispatch: (session, key) => dispatchImeRewrittenPrintableKey(session, key) + }, + { + // Control on the substitution path itself, which is the config's second line: the remap is + // present and commits the layout character. Same `insertText` route as the first arm, opposite + // expected byte, so a fix that keys on the route rather than on what was committed cannot pass + // both. + name: 'a system remap substitutes it for itself', + slug: 'remapped-to-itself', + committed: (layoutCharacter) => layoutCharacter, + dispatch: (session, key, committed) => dispatchImeSubstitutedTextKey(session, key, committed) + } +] + +test.describe('Terminal macOS system key remap', () => { + for (const layout of LAYOUT_VARIANTS) { + // keyCode 192 is the backquote position itself, unchanged by which character the layout puts + // on it — the remap targets the key, not the character. + const layoutKey: ImeKeyIdentity = { key: layout.character, code: 'Backquote', keyCode: 192 } + + for (const arm of REMAP_ARMS) { + const committed = arm.committed(layout.character) + const forbidden = committed === BACKQUOTE ? layout.character : BACKQUOTE + + test(`sends ${committed} for the ${layout.label} backquote key when ${arm.name}`, async ({ + orcaPage, + testRepoPath + }, testInfo) => { + await applyImePlatformPolicy(orcaPage, 'mac') + await expectImePlatformPolicy(orcaPage, 'mac') + const arena = await openTerminalImePaneArena(orcaPage) + const reader = createTerminalImeByteReader(testRepoPath, 1) + let completed = false + try { + await startTerminalImeByteReader(orcaPage, arena.ptyId, reader) + await arm.dispatch(arena.session, layoutKey, committed) + await orcaPage.waitForTimeout(60) + await dispatchPlainEnter(arena.session) + + const trace = await readTerminalImeBoundaryTrace(orcaPage) + + // A remap is not an IME. Nothing here may open a composition session, and a spec that + // accidentally replayed one would be testing a path the suite already covers. + const compositionEvents = trace.dom + .map((event) => event.type) + .filter((type) => type.startsWith('composition')) + expect(compositionEvents).toEqual([]) + // Pins the producer: the physical backquote position, carrying the layout's character. + // What was committed is asserted on the wire below rather than on the DOM, because the + // commit's `input` event is consumed before this probe sees it once a forwarder owns it. + const keydowns = trace.dom.filter( + (event) => event.type === 'keydown' && event.code === 'Backquote' + ) + expect(keydowns).toHaveLength(1) + expect(keydowns[0].key).toBe(layout.character) + + const sent = trace.onData.join('') + expect(sent, `${forbidden} reached the PTY instead of ${committed}`).not.toContain( + forbidden + ) + expect(sent).toBe(`${committed}\r`) + + const received = await waitForTerminalImeBytes(orcaPage, reader) + expect(received).toEqual([Buffer.from(`${committed}\n`).toString('hex')]) + completed = true + } finally { + await closeTerminalImePaneArena(arena, testInfo, `${arm.slug}-${layout.label}`, !completed) + removeTerminalImeByteReader(reader) + } + }) + } + } +})