* fix(windows): read agent command lines without PROCESS_VM_READ
Windows process command lines were read by opening each process with
PROCESS_VM_READ and walking its PEB. Hardened runtimes (Electron/Node) and
security products deny that access, so those processes resolved to a bare
`node.exe`/`bun.exe` name with no argv, argv0, or cmdline. A runtime-wrapped
agent launched from such a process was then indistinguishable from an
unrelated runtime process, and the pane stayed on the shell with
`agent_status: unknown`.
Prefer `NtQueryInformationProcess` with `ProcessCommandLineInformation`
(Windows 8.1+), which needs only `PROCESS_QUERY_LIMITED_INFORMATION`, and keep
the existing PEB read as a fallback for processes that do not expose a stored
command line. The fallback still requires `PROCESS_VM_READ`, so this only
widens coverage.
refs #4579
* fix(windows): handle growing command lines before failure test
The retry added for a command line that grows between the size probe and the
read was unreachable. NTSTATUS is signed, so STATUS_BUFFER_OVERFLOW,
STATUS_BUFFER_TOO_SMALL, and STATUS_INFO_LENGTH_MISMATCH are all negative and
were treated as failures by the earlier `status < 0` check.
Check the growth statuses first and retry once with the reported size. Also read
the returned UNICODE_STRING header unaligned, since a Vec<u8> buffer only
guarantees byte alignment.
* test(windows): keep command-line marker test process alive
Passing the marker as a second argument to `ping` let `ping` exit as soon as it
saw one target, so the command-line query could race the process exit. Move the
marker into a `rem` after `&` so it stays in cmd.exe's own command line and
`ping -n 11` keeps the process alive for the read.
* feat: support multiple prefix keys
keys.prefix accepts an array in addition to a single string so one
config can define several prefix keys. Every configured prefix enters
the same prefix mode, and the help panel lists them all.
Published keybinding profiles keep the primary prefix as a scalar and
carry the rest in an optional extra_prefixes field so older clients
keep working with the primary prefix.
* fix: reject an empty prefix list on reload
An explicitly empty keys.prefix array now stays empty through config
parsing so validation rejects it and a reload keeps the current
keybindings instead of silently falling back to ctrl+b.
The interactive-shell idle test sent SIGINT as soon as it observed the
shell was busy. That condition can be true before the shell finishes
moving the command into its own foreground process group, so the
interrupt could arrive before the command reset its signal dispositions.
The command then survived in a stale foreground group while the shell
showed a prompt, and the pane was never observed idle again.
Run cat and end it with EOF instead. cat blocks on stdin, so the busy
state is stable, and EOF avoids the interrupt/job-control race.
`git apply` by default expects `-p1`, which is the default behavior of
`git diff`, but this can be overridden by config. Specify it explicitly
so it works regardless.
* feat: default machine add label to the ssh host
`herdr machine add <ssh-target>` no longer requires `--label`. Without
one, the machine is named after the SSH host with any `user@` prefix
removed, so `herdr machine add dev@workbox` shows up as `workbox`.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* Apply suggestion from @greptile-apps[bot]
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
* fix: make default machine labels unique per session and handle ssh urls
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
Co-authored-by: Ogulcan Celik <ogulcancelik@gmail.com>
* fix: create a symlink on non-elevated windows in docs test
Windows terminals without Developer Mode or elevation cannot create file
symlinks, so the versions publishing integration test failed with EPERM
before it could reach the non-ordinary-file rejection. Fall back to a
directory junction, which is creatable without elevation and hits the
same rejection path.
* fix: detect docs snapshot reparse points with lstat
Classify entries with lstat instead of the readdir dirent so symlinks and
Windows junctions are rejected regardless of how a runtime classifies
them. This keeps the versions integration test's non-ordinary-file
assertion meaningful on non-elevated Windows, where the fixture can only
create a directory junction.
Panes whose app has not enabled the kitty keyboard protocol received
ctrl+shift+letter as the same C0 byte as ctrl+letter. Encode the chord as
CSI-u instead, matching Ghostty's legacy encoder.
refs #4581
Co-authored-by: ain3sh <ainesh.chatterjee@gmail.com>
* fix: report partial Windows input coverage and clear clipboard for tests
* fix: require evidence from each Windows input channel
* fix: reject clipboard format count errors