fix(desktop): open conversation MP4 attachments with the system player - #1123
Merged
Merged
Conversation
Conversation MP4 attachments reach the host file tab, where bounded text preview reports binary or oversized content without a playback action. Carry attachment MIME through chat resolution and offer a user-initiated OS handoff for MP4 files. Validate realpath containment before opening and give extensionless stored blobs a private .mp4 alias. Cover pasted scratch files, blob refs, spoofed MIME, and the representative Electron path. Refs vastsa#1093
The English E2E traceability rows changed with the MP4 fix, but the Chinese mirror kept the old table shape and failed docs:check. Sync the scenario and related IPC and interaction descriptions across locales. Refs vastsa#1093
The shared MP4 attachment branch must include the latest protected main before its Draft PR can be reviewed for landing. Preserve its existing commits and integrate the upstream attachment-history changes without rewriting published history.
Keep the published MP4 fix branch aligned with the PR target after upstream runtime and host changes. Preserve the existing fix commits without rewriting shared history.
yuxino
marked this pull request as ready for review
September 27, 2026 06:07
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
问题与修复
对话中发送 MP4 后,点击附件会进入内置文件页。该页把较大的 MP4 判为“文件过大”、较小的 MP4 判为二进制文件,因而没有可用的打开入口。现在文件页为 MP4 提供“用系统默认应用打开”。
对话附件的 MIME 会随文件引用传到文件页。主进程打开前重新校验真实路径与普通文件类型;无后缀的内容寻址 MP4 使用应用私有目录中的
.mp4软链接交给系统,不复制视频字节。伪造video/mp4MIME 的脚本不会获得该入口。验证
5c82c9271890;PR 目标main:b14caaabe9e1;环境:macOS arm64。共享分支通过合并提交纳入新基线,未重写历史。pnpm build:js、桌面 typecheck、pnpm lint、以b14caaabe9e1为基线的pnpm check:pr-base:通过。pnpm docs:check、pnpm check:agent-policy已在此前的532c5e30c349候选通过,本次基线合入未修改对应文件。pnpm test:e2e:composer-paste:通过。覆盖大 MP4 粘贴,以及大、小两种无后缀附件的对话 chip → 文件页 → 系统打开请求;伪造 MIME 不会为脚本显示打开按钮。E2E 在系统打开边界记录交给 OS 的路径;隔离开发版已人工确认 QuickTime 打开并识别两段视频。下方录屏对比的是旧基线
78caf97795ee与此前修复候选532c5e30c349;此次上游合入只涉及 Host 配置同步、计划任务、用户技能和 Agent Runtime 的 shell 路径文案,未修改 MP4 实现。新候选已重跑相关 E2E,正式安装包尚未验收。此 PR 保持 Draft,供审阅与原生验收。实际桌面录制
pi-desktop-pr1123-mp4-before-after-1080p.mp4
在隔离的 macOS Electron 实例中,使用系统文件选择器发送 936.8 KB 和 16.3 KB 的合成 MP4。旧版点击附件分别显示“File is too large to preview”和“Binary file — preview unavailable”,没有系统打开入口;候选版两种情况均显示“Open with default application”。点击后 QuickTime 分别打开隔离数据目录中的 6 秒和 2 秒 MP4。模型回复由 localhost fixture 提供;视频末尾 2 秒是实录帧定格,方便审阅。
Refs #1093