* feat(shell): add process group spawn option (fix#1332)
Add a `processGroup` boolean option to the shell plugin's spawn command.
When enabled, the child process is spawned in its own process group (POSIX)
or job object (Windows) using the `process-wrap` crate, so that killing
the child also kills the entire process tree.
This fixes the issue where programs like PyInstaller wrappers spawn a
child process that gets orphaned when Tauri kills the parent.
* test(shell): add PyInstaller simulation tests for process group kill
Add end-to-end tests that reproduce the exact scenario from issue #1332:
a wrapper process (like PyInstaller's bootloader) spawns a grandchild.
- Without process_group: killing the wrapper orphans the grandchild
- With process_group: killing the wrapper also kills the grandchild
* refactor(shell): drop redundant cfg gates, trim process-wrap features
Address review feedback on #3351:
- Remove `#[cfg(any(unix, windows))]` gates on `ChildKind::ProcessGroup`,
the kill/pid match arms, and the spawn block, plus the now-dead
`#[cfg(not(any(unix, windows)))]` fallback. That cfg only excluded wasm,
which this plugin never builds for.
- Set `default-features = false` on process-wrap and enable only the
features actually used: std, process-group (unix), creation-flags and
job-object (windows). Drops kill-on-drop, process-session, and tracing.
* fix(shell): enable process-wrap tracing feature, fix CI formatting and changefile
- Add `tracing` feature to process-wrap: with default-features = false its
Windows job_object.rs calls `debug\!` unconditionally while the import is
gated behind `#[cfg(feature = "tracing")]`, failing the Windows build with
"cannot find macro `debug`".
- Reformat process/mod.rs assertions to satisfy `cargo fmt --check`.
- Reindent the process-wrap features array to 2 spaces for taplo.
- Use covector package keys (`shell` / `shell-js`) in the change file so the
check-change-files and covector status jobs pass.
* refactor(shell): unify child handling on process-wrap, drop SharedChild
Collapse the ChildKind enum and the per-platform GroupChild types into a
single process-wrap-backed child. The command always spawns through
StdCommandWrap; the process_group flag is now just an optional wrapper
rather than a switch into a separate child type.
This drops the shared_child dependency and resolves two review notes:
the Unix path no longer hand-rolls killpg, and kill() now goes through
process-wrap's kill (start_kill + wait), which reaps the entire process
group instead of only signalling it.
A background thread polls try_wait to surface the exit status, since
process-wrap's wrappers only expose &mut self wait methods (the reason
SharedChild was used on Unix in the first place).
* chore(example): add process group toggle to shell view
* fix(shell): pass typed creation flags to process-wrap on Windows
`process_wrap::std::CreationFlags` is a newtype over the `windows` crate's
`PROCESS_CREATION_FLAGS`, not a raw `u32`, so the Windows build failed to
compile. Depend on `windows` (already in the tree via `tauri`, pinned to the
same 0.61 that `process-wrap` links against) and use its `CREATE_NO_WINDOW`
constant, which drops the hand-rolled magic number.
The wrap is still required: `JobObject::pre_spawn` calls `creation_flags` and
would otherwise clobber the `CREATE_NO_WINDOW` set at construction.
* perf(shell): block on child exit instead of polling try_wait
The switch from `SharedChild` to `process-wrap` moved the child behind a
mutex, since `StdChildWrapper`'s wait methods take `&mut self` while both
the wait thread and `CommandChild::kill()` need access. A blocking wait
would hold the lock for the child's whole lifetime and starve `kill()`,
so the wait thread polled `try_wait` every 10ms instead.
Block on the raw process outside the lock using a wait that does not reap
(`waitid` with `WNOWAIT` on unix, `WaitForSingleObject` on windows), then
take the lock once to let process-wrap collect the exit status. This is
the same technique shared_child uses internally, applied on top of
process-wrap's kill/reap semantics. No new dependencies or Cargo features
are required.
`kill()` reaps the child while holding the lock, so the raw wait can lose
that race and return ECHILD. That means the exit status is already cached
in the wrapper, so it is treated as success and the status is collected
via `try_wait`. Without this guard, a stress test of 300 spawn+kill
cycles produced 36 Error events in place of Terminated; with it, none in
900 cycles. The `try_wait` loop stays as a defensive fallback, though in
practice the first call succeeds immediately.
Mean latency for `Command::output()` on macOS (debug, 30 iterations of
`echo`) drops from 13.22ms to ~1.8ms, and 10 idle 5s children cost ~11ms
CPU total instead of ~75ms with the poll loop.
* fix(shell): keep CREATE_NO_WINDOW on process-group children (windows)
process-wrap's CreationFlags/JobObject coordination is broken during
spawn (watchexec/process-wrap#35): JobObject::pre_spawn cannot see the
CreationFlags wrapper, so it overwrote our flags with just
CREATE_SUSPENDED and process-group children flashed a console window.
Register CreationFlags(CREATE_SUSPENDED | CREATE_NO_WINDOW) after
JobObject so its pre_spawn runs last and wins. CREATE_SUSPENDED is kept
so the child cannot spawn grandchildren before job assignment; the same
upstream bug keeps wrap_child's resume check from seeing it, so the
child is still resumed.
* test(shell): run the process-tree kill tests on windows
Add a powershell variant of the pyinstaller simulation script and lift
the unix-only gates on the process-group tests, so the windows job in
test-rust exercises the job-object spawn/kill path instead of skipping
it. Both pyinstaller tests now also assert that a Terminated event is
still delivered after kill().
* Update plugins/shell/src/process/mod.rs
Co-authored-by: Fabian-Lars <30730186+FabianLars@users.noreply.github.com>
* Update .changes/shell-process-group.md
Co-authored-by: Fabian-Lars <30730186+FabianLars@users.noreply.github.com>
* Update plugins/shell/src/process/mod.rs
Co-authored-by: Fabian-Lars <30730186+FabianLars@users.noreply.github.com>
* Delete .changes/shell-wait-no-poll.md
* refactor(shell): replace process-wrap with shared_child and an inlined job object
Use std process groups on unix and a job object on windows, with
shared_child handling wait and kill on all platforms.
* fix(shell): kill the process group even after its leader exited
CommandChild::kill returned early once the direct child had been reaped,
so killpg/TerminateJobObject never ran and anything the child left running
in its process group or job object survived, including on app exit.
Adds a launcher-style test (the child starts a grandchild and exits) that
runs on Windows, Linux and macOS.
* fix(shell): restore Debug on CommandChild
Dropping the derive was a breaking change for downstream types that derive
Debug and hold a CommandChild.
* fix(shell): don't block the main thread in the kill command
CommandChild::kill now waits for the child to exit, and the sync kill
command ran it on the main thread while still holding the children lock.
Make the command async and release the lock before killing.
---------
Co-authored-by: Fabian-Lars <30730186+FabianLars@users.noreply.github.com>
Co-authored-by: Lucas Nogueira <lucas@tauri.app>
* feat(notification): report actions on desktop
A click on a notification (tap) or on one of the actions of its action
type now reaches the JavaScript onAction listeners on desktop, and the
new Rust Notification::on_action on every platform. On Linux and the
BSDs the click comes from the notification server's ActionInvoked
signal; on Windows and macOS from notify-rust's wait_for_response,
which needs notify-rust 4.18.
register_action_types, remove_active (Linux and the BSDs) and the
listener commands are implemented for desktop, so they no longer fail
with "command not found".
The api example sends a notification with two actions and shows the
action it hears.
Closes#2150, closes#1903.
* fix(notification): complete desktop action API
* cleanup
---------
Co-authored-by: Haex <hexxx@ok.de>
Co-authored-by: Lucas Nogueira <lucas@tauri.app>
* feat(updater): option to not restart after install
* More platform cfg
* Add the same function for `UpdaterBuilder`
* Fix missing `#[cfg(windows)]`
* Mark `current_exe_args` cfg(windows)
* Mark `on_before_exit` cfg(windows)
* Mark `installer_args` cfg(windows)
* Note about `installer_arg` apply to both
* Remove current args and restart together
* Only build needed bundle on windows as well
* Remove `/NS` since it breaks the msi updater
* Add launch updater debug log
* Add a folder to test updates
* Remove unused `#[allow(unused)]`
* Format
* messed up git stage
* Add change file
* Clean up
* Disable NSIS compression for API example
* Bump wry for v1 test to pull in https://github.com/tauri-apps/wry/pull/1703
* format
* Make typescript happy
* Close new update on destroy
* chore(deps): update dependency @tauri-apps/cli to v2.11.4
* Use workspace dependencies in example
* Bump tauri
* Leftover
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tony <legendmastertony@gmail.com>
* Fix example insets
* Add app-region: drag
* Use `Theme.Material3.DayNight.NoActionBar`
* Re-generate some kotlin files
* Use MaterialAlertDialogBuilder
* Add change file
* Revert back to margin-top: 0.5rem
* Re-generate outdated gradle wrapper from #3039
* Move title bar to its own file
* Fix cancel message
* chore(dialog): reuse `message` command for confirm
* Add change file
* Remove ask and confirm from default permissions
* Format
* Remove extra `toString`
* Point `allow-confirm` to `allow-message`
* feat(dialog) - Support fileAccessMode for open dialog (#3030)
On iOS, when trying to access a file that exists outside of the app sandbox, one of 2 things need to happen to be able to perform any operations on said file:
* A copy of the file needs to be made to the internal app sandbox
* The method startAccessingSecurityScopedResource needs to be called.
Previously, a copy of the file was always being made when a file was selected through the picker dialog.
While this did ensure there were no file access exceptions when reading from the file, it does not scale well for large files.
To resolve this, we now support `fileAccessMode`, which allows a file handle to be returned without copying the file to the app sandbox.
This MR only supports this change for iOS; MacOS has a different set of needs for security scoped resources.
See discussion in #3716 for more discussion of the difference between iOS and MacOS.
See MR #3185 to see how these scoped files will be accessible using security scoping.
* fmt, clippy
* use enum
---------
Co-authored-by: Lucas Nogueira <lucas@tauri.app>