Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (7)
🚧 Files skipped from review as they are similar to previous changes (2)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe pull request adds a Unity Editor window listing and screenshot tool, with MCP server and CLI commands. It adds capture scaling and readback logic, selection and focus handling, optional PNG file and inline image output, tests, and usage documentation. ChangesEditor window screenshots
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~50 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant MCPClient
participant manage_editor_windows
participant UnityTransport
participant ManageEditorWindows
participant EditorWindowScreenshotUtility
MCPClient->>manage_editor_windows: Submit list or screenshot request
manage_editor_windows->>UnityTransport: Dispatch validated command
UnityTransport->>ManageEditorWindows: Invoke Unity tool
ManageEditorWindows->>EditorWindowScreenshotUtility: Capture selected window pixels
EditorWindowScreenshotUtility-->>ManageEditorWindows: Return captured texture
ManageEditorWindows-->>UnityTransport: Return metadata and optional PNG
UnityTransport-->>manage_editor_windows: Return Unity response
manage_editor_windows-->>MCPClient: Return metadata and optional image
Merge Risk: ⚪ Minimal · up to The window screenshot feature has no identified merge-blocking issue after normal checks. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Screenshot access now includes private Editor tabs, potentially exposing displayed source code, paths, logs or credentials to trusted clients. Existing authentication and instance selection remain in place, and capture has bounded dimensions and lifecycle cleanup. Saved screenshots require separate retention management. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Description
Agents can capture cameras and Scene View viewports, but cannot inspect arbitrary
open Editor tabs. This adds
manage_editor_windowsto list windows and captureone Inspector, Console, custom tool window or inactive docked tab from Unity's
own buffer.
The default result is one PNG image for model inspection plus metadata, with no
saved file. Its assistant-audience annotation is a client hint; it cannot enforce
hiding, attachment display or privacy.
Type of Change
Changes Made
plus CLI
editor windowsandeditor screenshot.excluding dock tabs/borders. Share graphics-API orientation correction between
Editor windows and Scene View, with the gamma-correct downscaler. No desktop
fallback or
EditorApplication.Steploop.ToolParamsfor snake_case and camelCase batch parameters; reject invalidexplicit selectors instead of falling back to the focused window.
resize. Restore tab/focus, preserve later user focus changes, bound image size,
reject concurrent captures, and handle closure, reload and shutdown.
Library/McpEditorScreenshotsonly when requested;reuse encoded bytes for unscaled file/image output. The CLI requests file-only
output. Declare
destructiveHint=falseandreadOnlyHint=false.Compatibility / Package Source
Unity tested on Windows: 2021.3.38f1, 2022.3.44f1, 6000.0.51f1, 6000.3.7f1.
Package source: local
file:reference to this checkout'sMCPForUnityfolder.Package lock source:
local; resolved Git lock commit: not applicable.Validated base:
8be7d96d95aa3e262894c64412f0df3b432efa05onbeta.Runtime/Editor semantic compilation passed for Windows/macOS/Linux symbols on
all four installed editor versions. macOS/Linux graphical runtime and the
exact pinned CI patches remain untested locally.
Prepare metadata/inline pixels before optional PNG persistence. Remove
incomplete output on write failure; if cleanup fails, return its path and
cleanup status. Server image-conversion errors also retain saved-path metadata
without exposing encoded pixels. A lost connection after success does not
roll back a requested file save.
Document capture ownership, focus/lifecycle invariants and fixture contracts.
Testing/Screenshots/Recordings
Latest local follow-up validation: 2026-10-02, source committed as
51f11ee0a59f26486d469180c280d3d1c533b5b7. The persistence/error-handling follow-up has fresh headlessvalidation; the graphical checks below are explicitly earlier results.
injected image-conversion regression cases failed before the fix and pass
afterward; errors retain saved-path metadata without returning encoded pixels.
on each of 2021.3.38f1, 2022.3.44f1, 6000.0.51f1 and 6000.3.7f1
(1,287 cases per Editor). All five new persistence cases pass on each: late
inline-processing failure leaves no PNG, file-only/combined success preserves
bytes, write failure removes incomplete output, and Windows cleanup failure
reports its retained path. The partial-file cleanup case injects an argument
failure with an existing owned partial file; it does not simulate a disk-full
short write. The locked-file case uses a real Windows sharing violation.
installed Editor reference versions and Windows/macOS/Linux symbols.
reference drift check and website production build passed.
CLI help, image annotations and saved-path error checks passed. No persistent
install, artifact upload or user Editor interaction was used.
CodeRabbit's automatic review of this head completed: 92.31% docstring
coverage, passing its 80% threshold (91 functions / 10 files, one
unsupported function skipped). No actionable or inline review comments were
generated. This result is separate from the local scoped inventory.
Earlier graphical validation (2026-10-01, source
6e005a10)These checks were not rerun for this follow-up, to preserve the active user's
mouse/keyboard and graphical Editor session. Buffer geometry, orientation,
selection/focus code, dependencies and packaging configuration are unchanged.
per combination. Includes 2px colored edges / 6px black interior, four-corner
orientation, dark downscaling, direct camelCase/real batch selectors, invalid
selectors, resized docks, focus restoration, file bytes, cancellation, closure,
assembly reload, actual Game View PlayMode and minimized completion/recovery.
Direct3D11 and Direct3D12 after the fixture compatibility adjustment.
image bytes, target/camelCase/batch routing, invalid-selector rejection,
cancelled request then retry, and focus restoration.
2026-09-30 records; no new PlayMode or live-client rerun is claimed here.
Runtime limits remain macOS/Linux graphics, Metal/Vulkan, other DPI scales,
mixed-monitor transitions and exact pinned CI patch versions. Compile symbols
do not establish platform runtime behavior. Minimized tests establish bounded
completion/recovery, not fresh pixels. Headless skips are reported as skips.
Upstream fork workflows currently require repository approval (
action_required);local checks are not a claim that those workflows ran or passed.
Documentation Updates
Related Issues
The window-buffer path avoids the stepping used in the separate composited Game
View path discussed in #1289; this change does not repair that existing path.
Additional Notes
CodeRabbit's remaining moderate security-architecture note describes the intended
opt-in capability: admitted clients can read unredacted Editor tabs, including
private displayed data. Audience hints do not restrict disclosure. Existing
instance authentication and tool enablement remain in place; no authentication
bypass was identified. The guide documents trusted-client use and manual
retention of explicitly saved files. Per-window allowlists/consent and automatic
retention would be additional product controls, outside this contribution.
The combined smoke-then-PlayMode harness times out after smoke marks an unsaved
scene dirty and Unity cancels its save dialog in batch mode. A clean upstream-base
control reproduced the same failure; separate smoke and clean PlayMode legs pass.
Batch pixel capture and native OS dialogs are unsupported. Minimized windows can
return stale buffers; tests verify completion/recovery, not fresh minimized pixels.
macOS/Linux graphics, Metal/Vulkan, DPI scales other than 150%, mixed-monitor
transitions and exact pinned CI patches remain untested. Claude/Codex-specific
image display remains untested; image audience annotations are client hints.
Captures may expose private Editor data to the configured MCP client.
No project-specific adapter/defaults, credentials, screenshots, reference DLLs or
local reports are included in the contribution.
Summary by CodeRabbit