Metadata filtering from native-api-usage.json - #20
Merged
Merged
Conversation
…d iOS An app (and its plugins) can now limit the native API it uses with App_Resources/Windows/native-api-usage.json. The CLI already writes it out as whitelist.mdg / blacklist.mdg in platforms/windows; nothing read them. Same format and rules as the Android and iOS metadata generators: one `namespace:type` pattern per line, `*` and `?` wildcards, a bare namespace covers every type in it; a whitelist is exclusive, the blacklist wins. - metadata-filter: the parser and matcher, shared by the runtime and the build tools. NativeScript.* (the runtime's widgets, sbg's proxies) is always whitelisted, as Android always allows com.tns.gen*. - Runtime: both engines load the files from next to the exe at startup. A type the filter leaves out is not there for JS (undefined), as it isn't in the Android/iOS metadata; namespaces stay traversable, and the runtime's own lookups (return types, bases, an instance's runtime class) are not filtered. Each type's verdict is computed once. - dotnet-tool no longer takes names that can't be types (minified `Ua.$`) for extensions, drops extensions of bases the filter leaves out, and publishes dotnet-bridge only for .NET usage or an extension that is surely real (named, or of a Windows/Microsoft/System/NativeScript base). A bundled library's classes (babylon.js, phaser) made it publish on every build. A stale sbg_metadata.json is removed when nothing is found. - sbg skips extensions whose base the filter leaves out (SBG_WHITELIST / SBG_BLACKLIST) and shares the base check with dotnet-tool. - Template: copies the .mdg files next to the exe (and removes a copy the app no longer has), and passes them to sbg.
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Apps and plugins can now limit the native API they use with
App_Resources/Windows/native-api-usage.json, as on Android and iOS. The CLI already writes it out aswhitelist.mdg/blacklist.mdginplatforms/windows(metadata-filtering-service.ts), but nothing on Windows read them.The format and rules are those of the Android and iOS metadata generators:
namespace:typepattern per line, with*and?wildcards; a bare namespace covers every type in it;#and//start comments;NativeScript.*(the runtime's widgets and sbg's proxies) is always whitelisted, as Android always allowscom.tns.gen*.Android and iOS enforce the filter by leaving types out of build-time metadata. Windows resolves types from
.winmdat run time, so it's enforced where JS reaches a type by name, and in the build's extension scan.metadata-filter(new crate, no dependencies): the parser and matcher, shared by the runtime and the build tools.undefinedto JS; namespaces stay traversable. The runtime's own lookups (return types, bases, interfaces, an instance's runtime class) are not filtered, so an allowed API still returns objects of filtered types. Each type's verdict is computed once and cached.dotnet-tool:Ua.$) for extensions.Windows/Microsoft/System/NativeScriptbase. Before, any bundled library's classes (babylon.js, phaser) made it rundotnet publishon every build. The template's own incrementalPublishDotNetBridgetarget is unchanged.sbg_metadata.jsonwhen nothing is found.sbg: skips extensions whose base the filter leaves out (SBG_WHITELIST/SBG_BLACKLIST), and shares the base check withdotnet-tool..mdgfiles next to the exe (removing a copy the app no longer has) and passes them to sbg.Testing
cargo test -p metadata-filter(8),-p sbg(4, one new),-p dotnet-tool(3, new: a minified class, a library class, a WinUI extension and a named proxy); ametadatatest that a filtered type resolves for the runtime but not for JS, and its namespace still does.cargo test -p runtime --lib: 148/159. The same 11 fail onmain(UI-dispatcher, XAML-thread, composition and PropertySet tests).apps/demowith this branch'snativescript.dll, sbg and dotnet-tool (classic engine):dotnet-toolwrites the bundle's library classes for sbg to skip, but no longer publishes the bridge for them. WebGL spec 81/81.native-api-usage.jsonwhitelisting 500 patterns (the matching ones last) and blacklistingWindows.Storage.Pickers:FileOpen*. The CLI writes the.mdgfiles; the build copies them next to the exe;dotnet-toolwrites no metadata and publishes nothing.FileOpenPickerisundefinedwhileFileSavePickerandStorageFilework, and the spec still passes 81/81.Windows.Foundation.Uriresolutions took 112–121 ms with and without the filter, and 20k constructions 413–440 ms: no measurable difference.