Skip to content

fix(desktop): isolate blocking folder reveal from Tokio - #2399

Open
richiemcilroy wants to merge 5 commits into
mainfrom
fix/linux-folder-reveal
Open

richiemcilroy wants to merge 5 commits into
mainfrom
fix/linux-folder-reveal

Conversation

@richiemcilroy

@richiemcilroy richiemcilroy commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Showing a recording or screenshot in its folder on Linux can panic. The opener plugin's reveal_item_in_dir IPC command is async and calls the opener's Linux backend directly on a Tokio worker. That backend uses blocking zbus, and Cap builds zbus with its tokio feature, so the blocking call starts its own runtime inside the async task and panics.

Change

  • cap_utils::run_on_dedicated_thread runs blocking native work on a new named thread outside every Tokio runtime and returns its result. A thread that panics becomes an error instead of taking down the task.
  • New Cap command reveal_item_in_dir(path) calls the opener's existing reveal_item_in_dir through that helper. The four frontend callers (editor header, editor error screen, screenshot editor menu, recording "open folder") use it instead of the plugin's JS revealItemInDir. Same paths, same native backends, same canonicalization, same rejection on error.
  • The diagnostic report reveal uses the same helper after its existing path validation.
  • The webview no longer has the opener:allow-reveal-item-in-dir permission, so the panicking plugin command is unreachable.
  • No vendored plugin, no [patch], no Cargo.lock or workflow changes. The earlier vendored copy of tauri-plugin-opener is removed.

macOS and Windows still call the same native APIs (NSWorkspace, SHOpenFolderAndSelectItems). They now run on a short-lived thread rather than a shared Tokio worker, which also keeps the Windows CoInitialize call off pooled threads.

Related: CAP-DESKTOP-2C2.

Verification

  • cargo test -p cap-utils --lib dedicated_thread: helper starts its own runtime from current-thread and multi-thread Tokio contexts, returns work errors unchanged, and turns worker panics into errors. Both runtime tests fail with the nested-runtime panic when the helper calls the work inline.
  • Linux: a real zbus::blocking::Connection::session() regression runs in the existing Linux CI cap-utils step (a missing session bus is allowed, a thread failure is not).
  • cargo clippy -p cap-desktop -- -D warnings, cargo clippy -p cap-utils --all-targets -- -D warnings, cargo fmt --check, desktop tsc --noEmit, vitest run src/utils/recording.test.ts, Biome, and scripts/check-tauri-plugin-versions.js pass locally on macOS.
  • Not verified by hand: clicking "Open folder" in a Linux desktop session.

RetriggerConfidence Score: 5/5

The PR appears safe to merge; no actionable new issue or outstanding previous finding was identified.

Summary

The PR moves folder reveal work from the opener plugin’s async IPC path to a dedicated native thread, updates desktop callers and diagnostics, and removes the plugin reveal permission.

  • The new command and frontend binding are aligned.
  • Dedicated-thread tests cover Tokio runtime isolation, errors, panics, and the Linux blocking-zbus path.

Reviews (3) · Last reviewed commit: "revert(desktop): drop the vendored opene..."

@richiemcilroy

Copy link
Copy Markdown
Member Author

hey @greptileai, please re-review the PR

@richiemcilroy

Copy link
Copy Markdown
Member Author

hey @greptileai, please re-review the PR

This branch was successfully deployed

1 active deployment
Preview — e06f285f Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant