IPC catalog

The webview calls Rust through Tauri invoke() commands. Names are contracts. A command should not be renamed or moved without updating every frontend bridge, registration site and test.

Terminal and processes

Area Main commands
PTY pty_spawn, pty_write, pty_resize, pty_kill, pty_has_foreground_job
Shell shell_run_command, shell_session_run, shell_session_close, shell_bg_spawn, shell_bg_logs, shell_bg_kill, shell_bg_list
Agent hooks agent_enable_hooks, agent_hooks_status

PTY output is streamed through a Tauri Channel<PtyEvent>. One-shot shell execution is separate from persistent PTY sessions and from background process capture.

Area Main commands
Tree fs_read_dir, list_subdirs
File fs_read_file, fs_write_file, fs_stat, fs_canonicalize
Mutation fs_create_file, fs_create_dir, fs_rename, fs_delete, fs_copy
Search fs_search, fs_list_files, fs_grep, fs_glob
Watches fs_watch_add, fs_watch_remove

Every filesystem command must enforce the secret-path deny-list and the workspace authorization boundary where applicable.

Git

The Git command family includes git_status, git_diff, git_diff_content, git_stage, git_unstage, git_discard, git_commit, git_fetch, git_pull_ff_only, git_push, git_log, git_show_commit, git_commit_files, git_commit_file_diff, git_panel_snapshot, git_resolve_repo and remote URL resolution. Git commands are authorized against the resolved repository root.

Workspace and integrations

Area Main commands
Workspace workspace_authorize, workspace_current_dir, wsl_list_distros, wsl_default_distro, wsl_home
Secrets secrets_get, secrets_set, secrets_delete
Network ai_http_request, ai_http_stream, lm_ping
Serial serial_list_ports, serial_open, serial_write, serial_close, serial_set_signals
Remote remote_open, remote_request, remote_close, remote watcher commands
LSP lsp_detect, lsp_host_pid, lsp_resolve_root, lsp_spawn, lsp_send, lsp_kill
Extensions extensions_list, extensions_read_code, extensions_open_dir, extensions_delete

Adding a command

  1. Put the implementation in the owning Rust module.
  2. Register it in src-tauri/src/lib.rs.
  3. Add capability entries if a plugin API is involved.
  4. Create a typed frontend bridge under the owning src/modules/<area>/ module.
  5. Validate every input at the Rust boundary.
  6. Add a pure logic or integration test for the contract and its deny path.

See Two-process model for the full boundary rules.