-
-
Notifications
You must be signed in to change notification settings - Fork 2
Contributing a Native Capability
itsmylab edited this page Aug 4, 2026
·
1 revision
Generated from
docs/contributions/native-capability.md. Edit the canonical source through a pull request.
Use this playbook for filesystem, process, operating-system, network, Git, LSP, browser, or other privileged work. Rust owns the resource; the WebView receives a typed projection. Read Core Rust System for the full module, managed-state, concurrency, persistence, and security map.
sequenceDiagram
participant UI as React feature
participant IPC as src/ipc.ts
participant Cmd as Tauri command
participant Owner as Rust manager/module
participant OS as OS, process, disk, or network
UI->>IPC: typed call
IPC->>Cmd: invoke or Channel
Cmd->>Owner: validate and delegate
Owner->>OS: bounded native operation
OS-->>Owner: result or stream
Owner-->>UI: result, Channel data, or event
src-tauri/src/<owner>.rs resource owner and command implementation
src-tauri/src/lib.rs managed state and command registration
src/ipc.ts typed frontend wrapper
src/<caller>.ts(x) feature use
Also inspect fsx.rs for path scope, blocking.rs for synchronous system work,
and the lib.rs exit handler for cleanup patterns.
| Operation | Shape |
|---|---|
| One bounded request and result | Tauri invoke
|
| Ordered/high-volume stream opened by a request | Tauri Channel
|
| Independent lifecycle or invalidation | Tauri event with one frontend listener |
- Write Rust tests for validation and failure behavior.
- Put ownership in the domain module or a managed service, not in the command function itself.
- Validate and canonicalize path, URL, identifier, and size inputs.
- Route ordinary paths through
WorkspaceManager. - Move synchronous system work through the existing blocking boundary.
- Bound queues, output, request bodies, retained history, and timeouts.
- Define cancellation and teardown before exposing the command.
- Register managed state with
.manage(...)when required. - Register the command in
tauri::generate_handler!. - Add one typed
src/ipc.tswrapper. - Use a result for a caller-owned request, a
Channelfor a stream, or an event for independent lifecycle state. - Add frontend behavior tests with mocked commands.
- Keep the capability unavailable to Remote unless separately designed and granted.
flowchart LR
Start[Resource starts]
Manager[Manager stores handle]
Close[Tab/project/app closes]
Signal[Cancel or terminate]
Drain[Drain and join/reap]
Remove[Remove state and credentials]
Start --> Manager --> Close --> Signal --> Drain --> Remove
cargo test --manifest-path src-tauri/Cargo.toml --no-default-features <module>::tests
npm run test -- src/<caller>.test.ts
npm run typecheck- One Rust owner exists.
- Inputs are scoped and bounded.
- Blocking/async boundary is correct.
- Cancellation, timeout, and app-exit cleanup exist.
- Command is registered and wrapped once.
- Events are invalidations or lifecycle signals, not hidden RPC.
- Remote remains denied unless explicitly reviewed.
- Rust and frontend tests cover failure behavior.
Generated from FluidWorksApp/canopy-ide. Canonical documentation changes belong in the main repository.
Canopy Architecture
- Home
- Architecture
- Core Rust System
- LLM Context
- Integration Guide
- Contribution Playbooks
- Testing and Coverage
- Publish the Wiki
Playbooks