Commit Graph
1477 Commits
Author SHA1 Message Date
l0ng-ai 12ec0c92a9 fix(sidebar): stop ungrouping tabs when a git probe fails (#1011)
A tab's auto group comes from probing its cwd for a repository. Any
failure of that probe - git failing to spawn, the macOS /usr/bin/git shim
dying while Xcode is mid-switch, a remote link dropping - came back as
"not a repository", overwrote the tab's remembered group, and was never
re-checked while the pane sat idle. Tabs in perfectly good repositories
dropped into Ungrouped and stayed there.

- Read root, home and branch in-process on this machine with
  gix-discover instead of three git processes. Only the line counts
  still come from `git diff --numstat`, so they keep matching the diff
  views; a detached HEAD is still named by git for the same reason.
- Remote hosts keep asking their own git (a new control request would
  force a dialect bump), but the probe now tells "not a repository"
  (exit 128, or the directory is gone) apart from a failure.
- A failed probe leaves the cache as it was, so a tab keeps its
  remembered group, and an unanswered cwd is retried every 10s.
2026-09-29 16:55:03 +08:00
l0ng-ai 8cf31c718d feat(worktree): setup, .worktreeinclude, agent launch, recoverable removal, and a worktree CLI (#1009)
* feat(worktree): setup script, .worktreeinclude, fresh base, recoverable removal

- Start new worktrees from the remote default branch, fetched first, with
  --no-track; fall back to the current branch without a remote.
- Carry gitignored files listed in .worktreeinclude over from the main
  checkout, copy-on-write (clonefile on macOS, copy_file_range elsewhere);
  remote hosts copy through the Host trait under a size budget.
- Run .tty7/setup in the first pane before the agent, with TTY7_ROOT_PATH,
  TTY7_WORKTREE_PATH, TTY7_WORKTREE_NAME and a per-worktree TTY7_PORT block.
  The script only runs once its exact content is approved for the repo.
- The New Worktree dialog picks what the first pane starts (Shell or a
  recent agent) and takes a task for agents that open on a first message.
- Removal snapshots the checkout, uncommitted work included, under
  refs/tty7/trash/<name> first; the ref also retires the name. A branch
  git refuses to delete is reported instead of silently kept.
- Hide .tty7/worktrees via info/exclude rather than a catch-all
  .tty7/.gitignore, so .tty7/setup can be committed.

* feat(cli): tty7 worktree new/ls/rm

- worktree new: the GUI dialog's worktree from the command line — create,
  carry .worktreeinclude, open a tab named after the branch, and type
  .tty7/setup && <agent> [task] into it. Prints the path first.
- worktree ls: every checkout of the repo, tty7's marked, with the live
  panes working in each.
- worktree rm: refuses while panes are inside unless --close-panes, and a
  dirty checkout unless --force; reports the snapshot ref and a kept branch.
- Move shell_quote and the first-line builders into tty7-core so the GUI
  and the CLI type the same line.
- Docs: CLI reference and the Worktrees page cover .worktreeinclude,
  .tty7/setup, TTY7_PORT and recoverable removal.

* fix(worktree): run setup and the agent inside the worktree; Start is a dropdown

- The first line now opens with cd into the worktree: a shell's startup
  files can move the pane, and setup then ran in (and wrote into) the main
  checkout.
- The Start choice is a dropdown listing Shell and every agent this machine
  offers, instead of a segmented switch capped at three.
2026-09-29 16:54:59 +08:00
l0ng-ai 241b91d70b chore(release): v26.9.4 v26.9.4 2026-09-29 12:58:21 +08:00
l0ng-ai 4e97498e2c fix(editor): ⌘R / ⌘⌥F no longer crash the app
Bumps gpui-component to d4ad0c10: opening the replace row from the
shortcut read the editor back while it was being updated, and panicked.
2026-09-29 10:35:51 +08:00
l0ng-ai c5cdf5382b feat(editor): redesigned find bar with a replace shortcut
Bumps gpui-component to e9dd0538:
- The find bar is one filled pill (search glyph, field, case, replace,
  "3 of 6" count, up/down, close) with no border or rule, and it no
  longer stacks its own padding on the editor's.
- The current match is amber, the other hits a neutral wash, so Enter
  visibly moves between them in any theme.
- ⌘⌥F / ⌘R (Ctrl+H elsewhere) opens find with the replace row.

The breadcrumb row drops to 22px and sets the symbol in the code font.
2026-09-29 10:00:08 +08:00
l0ng-ai ff456165e6 docs: drop the Customization row from the README feature table 2026-09-29 08:58:26 +08:00
l0ng-ai 4b1336b089 fix(prompt): set the text prompt in the Interface font (#1008)
gpui paints a prompt as a root of its own, beside the window's Root, so it
inherits nothing Root sets: the card fell back to gpui's .SystemUIFont
instead of the Interface font the rest of the chrome uses. Also add a test
that the quit-and-stop question never falls through to the platform dialog
(gpui's unthemed single-line fallback on Linux, #920).
2026-09-28 23:15:36 +08:00
l0ng-ai 9c1961de39 fix(agent-hooks): make the OpenCode plugin load on OpenCode 2.x (#999) (#1007)
OpenCode 2.x only loads a default export shaped { id, setup | effect } and
rejects the file otherwise ("Plugin must export a default definition with
an id and an effect or setup function"). The generated tty7.js only had a
named export, so every 2.x user got a load error.

- Export default { id, server, setup }: 1.x (>= 1.3.4) reads `server`,
  2.x reads `setup`; the named Tty7Presence export stays for older 1.x.
- 2.x: subscribe via ctx.event.subscribe(), read event.data, map
  permission.asked, and treat session.created with a parentID as a child
  session. Stay inert inside the shared --service process, whose sessions
  belong to no single pane.
- Spawn the emitter directly with node:child_process instead of
  `sh -c`, which does not exist on Windows.
2026-09-28 23:15:31 +08:00
l0ng-ai 7f66f69674 fix(ssh): pin russh to our fork with the zlib truncation fixes (#997) (#1006)
A host with `Compression yes` (every one imported from an ssh config that
sets it) negotiated zlib@openssh.com, and the pinned ayamir/russh rev cut
every packet that inflated past 2x its compressed size. The zlib stream
desynced right after auth: the session showed as connected and never
printed a byte.

- Move the [patch.crates-io] pin to l0ng-ai/russh (branch tty7): ayamir's
  gssapi-with-mic commit plus Eugeny/russh 58886f4d and 24e2c374.
- Add an end-to-end test that runs a zlib session against an in-process
  russh server and checks every byte of a compressible + incompressible
  payload arrives (0 of 270336 bytes on the old pin).
- Re-importing an ssh config now updates `algorithms` on hosts that already
  exist, so dropping `Compression yes` and re-importing takes effect.
2026-09-28 23:07:49 +08:00
l0ng-ai 4f8237f361 docs: fix the landing page for real — no JS comments in export bodies
The hosted Mintlify build fails to parse any page with a JS comment (line
or block) inside an export body and serves a parse-error placeholder
instead; mint dev and mint validate accept the same page. Confirmed with
diagnostic pages: the prefix with the sidebar's // comment fails, the
same prefix without it renders, and turning it into /* */ still fails.

Move both comments to top-level MDX comments, note the rule in the file,
undo the earlier % escaping (that guess was wrong), and remove the
diagnostic pages.
2026-09-28 22:15:50 +08:00
l0ng-ai 9e05627ff2 docs: drop // comments from the landing page; add diagnostic pages
The % fix did not bring the hosted landing page back. The first // line
comment in the file sits in the range that breaks, so turn the two into
block comments, and add temporary unlinked pages that isolate the
remaining suspects. They are removed once the cause is confirmed.
2026-09-28 22:14:25 +08:00
l0ng-ai 9cabeddb14 feat(editor): v6 chrome — recency-capped file strip, open-files list, Dock/Fill switch (#1005)
The header keeps only the most recently fronted files (3 docked, 7 filled,
fewer with side panels open) in their strip order; the rest sit behind a +N
button that lists every open file with a filter, keyboard navigation and
Close saved / Close others. A two-cell Dock/Fill switch replaces the header's
right-click menu, and a filled editor leads with a pill naming the terminal
it covers that docks it back.

Breadcrumbs lose their rule and use chevrons, with only the file name in body
ink. The status bar is 28px, leads with a missing language server, and reads
cursor, indent, encoding, line ending, language; the actionable readouts
answer hover and the cursor opens Go to Line.
2026-09-28 22:12:50 +08:00
l0ng-ai 591a50a9c1 docs: fix the landing page failing to parse on the hosted build
The hosted Mintlify build percent-decodes page content before parsing
it, so the pane id "%22" in the demo became a bare quote and the whole
page fell back to the parse-error placeholder. Local mint dev/validate
do not decode, so they never saw it. Spell the pane ids' % as \u0025.

Also drop the temporary diagnostic pages used to bisect this.
2026-09-28 22:08:27 +08:00
l0ng-ai 7d3cee4d71 feat(editor): v6 chrome — recency-capped file strip, open-files list, Dock/Fill switch
The header keeps only the most recently fronted files (3 docked, 7 filled,
fewer with side panels open) in their strip order; the rest sit behind a +N
button that lists every open file with a filter, keyboard navigation and
Close saved / Close others. A two-cell Dock/Fill switch replaces the header's
right-click menu, and a filled editor leads with a pill naming the terminal
it covers that docks it back.

Breadcrumbs lose their rule and use chevrons, with only the file name in body
ink. The status bar is 28px, leads with a missing language server, and reads
cursor, indent, encoding, line ending, language; the actionable readouts
answer hover and the cursor opens Go to Line.
2026-09-28 22:08:27 +08:00
l0ng-ai 7e23dd6ff1 fix(ui): widen three-answer prompts so the update dialog's buttons fit
The alert card is a fixed 360px and its buttons never shrink, so the update
prompt's three answers (Update and relaunch / Install on Next Launch / Later)
ran past the edge and were clipped. Prompts with three or more answers now
use a 460px card, and the answer row wraps (still flush right) as a fallback
for locales with longer labels.
2026-09-28 21:58:44 +08:00
l0ng-ai 5d8e454949 docs: temporary diagnostic pages for the landing page parse error
Hidden, unlinked pages holding prefixes of index.mdx, to find which part
the hosted Mintlify build fails to parse. Removed in the follow-up fix.
2026-09-28 21:55:06 +08:00
l0ng-ai 5e2b28be67 ci(host-boundary): allow the local stat on paste/drop upload sources
#1004 stats the source of a paste or drop upload to decide whether to
upload recursively. That path comes from this machine's clipboard or
desktop, so it is a local read by construction.
2026-09-28 21:25:51 +08:00
l0ng-ai afe24f0afc feat(terminal): upload pasted and dropped files to remote panes (#1004)
Copying a file in Finder and pasting it into an SSH pane, or dropping one
onto it, used to paste this machine's path — which the remote program
cannot open. Only clipboard images were uploaded first.

Every local path a pane is handed now goes through one route: uploaded
into its own directory under ~/.cache/tty7/clipboard on an SSH host (so it
keeps its real name), rewritten for WSL, and pasted as-is locally. Folders
upload recursively, a transfer is only abandoned once it stops moving, and
staged pastes older than a week are pruned.

Rows of a remote Files tree now drag as their own type instead of
ExternalPaths, so no drop target mistakes a far-side path for a local file.
2026-09-28 20:47:13 +08:00
l0ng-ai 7016fdb7ed feat(editor): IDE-level code editor — multi-cursor, LSP, git gutter, symbols, split (#1002)
* fix(keymap): let the code editor's multi-cursor chords beat the pane keys

gpui-component now binds secondary-d, secondary-shift-l and
secondary-alt-up/down in the Input context for multiple cursors. A
context-free binding ranks as deep as the focused context and ties go to
the one added last, so tty7's SplitRight and FocusPaneUp/Down took those
keys inside the editor. Re-add the editor bindings after tty7's table; other
text fields have no handler for them and fall through to the pane keys.

* feat(editor): show the selection count in the status bar

With several cursors the Ln/Col readout (the primary caret's) is followed
by "(N selections)".

* feat(editor): git change markers in the gutter

Diff each buffer against its file's index version (what VS Code's quick
diff and the SCM panel's Changes compare with) and hand the hunks to the
editor as gutter markers: added, modified, and a wedge where lines were
deleted. The base is read with `git show :./name` through the buffer's own
host, so remote workspaces work too; SFTP buffers and untracked files get
no markers. It is re-read when the repository's SCM epoch moves, on save
and when the path changes; the diff itself is a line-level Myers diff run
off the UI thread shortly after each edit.

Next/previous change and Revert Change (one undo step, also in the
right-click menu) are commands; clicking a marker opens a peek of the
staged lines with a Revert button. The editor watch now also follows the
repository the gutter found, so a stage or checkout refreshes the markers.
The `editor_git_gutter` config (default on) is flipped by the
ToggleEditorGitGutter command.

* feat(editor): go to symbol, breadcrumbs, and back/forward navigation

Go to Symbol (Cmd-Shift-O in the editor) lists the file's outline on a new
Symbols tab of Search Everywhere: indented by nesting while browsing, ranked
flat with the containing symbols as a subtitle while searching. Arrowing
through the rows previews each symbol; Escape puts the caret and the scroll
back, Return keeps it.

The outline comes from the tree the highlighter already parsed, with a small
query per language (Rust, Go, Python, JavaScript, TypeScript/TSX, C, C++,
Java, Markdown, Ruby, shell). Tty7App::editor_set_document_symbols lets a
language server's documentSymbol answer replace it per buffer.

A breadcrumb row over the text shows the file's path from its project root
and the symbols around the caret; the symbols open Go to Symbol.

Back and forward (Ctrl-- / Ctrl-Shift-- on macOS, Alt-Left/Right elsewhere)
walk a per-tab history. Jumps are noticed by sampling the caret whenever the
editor draws: a change of file, or a move of ten lines or more without an
edit, records where the caret was. Quick open, go to line, file links and
anything that goes through open_file_in_editor_at are therefore captured
without hooks of their own; a place in a closed file reopens it.

* feat(editor): bind next/previous change to Alt+F5 in the code editor

Bind EditorNextChange / EditorPrevChange to alt-f5 / shift-alt-f5 in the
Input context only, after tty7's own table, so a terminal never loses the
function key. Mark the hunks stale right after a revert, before the
input's Change event lands, and cover the whole loop (markers, stepping,
revert as one undo) with a window test.

* feat(editor): line commands in the editor's right-click menu

Toggle Comment, Move Line Up/Down, Duplicate Line, Delete Line and Go to
Matching Bracket, dispatched to gpui-component's new editing actions so
each row shows its chord. Strings in en, zh and ja.

* feat(editor): language servers for the code editor

A new ui::lsp module runs language servers for local files the editor
opens: rust-analyzer, typescript-language-server, pyright (or pylsp),
gopls and clangd, from a registry table. Each server is keyed by
(server, project root), found from markers such as a Cargo workspace,
package.json, go.work/go.mod or pyproject.toml, and shared by every buffer
under that root. A server missing from PATH (which tty7 already fills from
the login shell) means no LSP for that language and a one-line hint in the
status bar.

The JSON-RPC client frames Content-Length messages over the server's stdio
on dedicated threads, holds everything back until initialize is answered,
cancels requests nobody waits for any more, and answers the server's own
requests (configuration, capability registration, applyEdit). Documents
use full-text sync, debounced, and flushed before every request. A server
whose last file closed shuts down after a grace period, every server exits
with the app, and one that crashes is restarted a few times before it is
left down.

Features: diagnostics as underlines with hover messages and an error and
warning count in the status bar; completion (snippets flattened to plain
text); hover; go to definition by secondary-click or F12, across files
through open_file_in_editor_at; code actions on the editor's own menu
(cmd-.), resolved and executed as the server needs; Format Document
(shift-alt-f); and Rename Symbol (F2) in the editor's bar, applied to open
buffers and to files on disk. The key bindings sit in the Input context so
F2 and F12 stay with terminal programs.

Positions are converted at the boundary: servers count UTF-16 units,
gpui-component counts chars, and the rope counts bytes.

The new editor_lsp setting (default on) turns it all off.

* fix(editor): clear the change markers when the file loses its base

A file that becomes untracked or leaves its repository kept the markers
of its last diff; clear them when the base goes away. Guard the base read
against a panic, which would otherwise leave the fetch flagged forever,
and test the read against a real repository: the base is the staged
version, and untracked files have none.

* test(keymap): the editor's navigation chords win inside the editor, not in a terminal

* fix(keymap): let the code editor's line commands beat the app's chords

The editor binds toggle comment, move/copy/delete line, insert line, select
line and go-to-bracket on its CodeEditor key context. A context-free app
binding ranks as deep as the focused context and wins the tie by being
added later, so ⌘/ (shortcut sheet), ⌘↵ (fullscreen), ⌘⇧↵ (maximize) and,
off macOS, ⌥↑/⌥↓ (pane focus) took those keys inside the editor. Re-add
them in fixed_bindings on CodeEditor, which only a multi-line code editor
declares, so plain text fields and the terminal keep the app's keys.

* fix(keymap): route cmd-K cmd-D to the code editor's skip-occurrence

The chord starts with ClearScrollback's key on macOS, and gpui drops a
pending chord that ranks below a complete match, so the fork's binding
never got its second key. Re-add it after tty7's table, in the CodeEditor
context only, so other text fields don't wait on cmd-K.

* feat(editor): history follows edits, and paging is not a jump

Places in the back/forward history now move with lines inserted or deleted
above them, read from the editor's line-edit log on every change. The caret
move a Page Up/Down, paste, undo or redo makes is heard through the
keystroke that caused it and is not recorded as a jump.

* feat(editor): Problems list, keyboard change peek, Editor settings

- Problems: every error, warning and note the language servers published
  for the open files, grouped by file, at the foot of the code panel.
  The status bar's counts and ToggleEditorProblems (Cmd/Ctrl+Shift+M)
  open it; a row opens its file at the line and column. Read through a
  new LspStore::diagnostics_snapshot, mapped to editor columns.
- EditorPeekChange (Alt+F3 in the editor) peeks the change under the
  caret, or goes to the next one. The peek now takes the keyboard from
  a click too: Enter reverts, Escape closes and hands focus back.
- Settings > General gains an Editor group: git change markers,
  language servers, soft wrap and rendered Markdown, searchable and
  resettable like every other row.

* feat(lsp): outline, references, workspace symbols, signature help

- documentSymbol feeds the editor's outline (breadcrumbs, Go to Symbol)
  through editor_set_document_symbols, refreshed 500 ms after typing
  pauses. Flat answers are nested by range; an empty answer from a server
  still indexing leaves the tree's outline in place.
- Find All References (shift-F12) and a definition with several answers
  open a Locations tab in the search. Arrowing through it previews a place
  in the file in front, and Return goes there, into any file.
- Go to Symbol in Workspace (secondary-T inside the editor) asks the
  server's workspace/symbol as the query is typed, into the same list.
- Completion items are resolved for their documentation and auto-import
  edits, which are applied on accept (with the gpui-component fork).
- Signature help opens on the server's trigger characters (or on '(' and
  ','), stays current while typing in the call, and closes when the server
  says the cursor has left it or on Escape.
- Diagnostics are replaced wholesale on publish; between publishes the
  fork now carries them through edits instead of dropping them.
- workspace/configuration answers from per-server settings, with an empty
  object for a section tty7 sets nothing for. rust-analyzer gets
  checkOnSave with cargo check, also as initializationOptions, and every
  server gets didChangeConfiguration after initialized.

* feat(editor): text commands in the palette and keymap

Transform to Upper/Lower/Title Case, Trim Trailing Whitespace, Join Lines
and Remove Surrounding Brackets, as tty7 actions (bindable on the
Keybindings page, unbound by default) and as palette rows offered while a
buffer is open. Both run gpui-component's editing action on the active
buffer. Join Lines gets VS Code's ctrl-j as a fixed CodeEditor binding on
macOS, where the terminal keeps it as a line feed. Strings in en, zh, ja.

* feat(editor): split the editor into two groups

Cmd-\ (Ctrl-\ off macOS, bound only inside the editor so the terminal keeps
SIGQUIT) opens the file in front in a second group on the right. Each group
has its own file in front and, for different files, its own caret and
scroll; Cmd-Alt-Left/Right (Ctrl-Alt off macOS) or a click moves the focus
between them, and a group whose last file closes goes away. The split is
saved with the tab's other editor state.

The focused group is always TabCode's own files/active and the other waits
beside it, so everything that acts on the file in front - saving, go to
line, language servers, change markers, multiple cursors, history - follows
the focus unchanged. A file shown in both groups is drawn once, in the
focused one; the other shows a placeholder that brings the focus over. A
second InputState kept in sync would have needed every hook attached twice.

Also: palette rows and View menu items for Go to Symbol, Back, Forward and
Split; Cmd-Shift-O closes Go to Symbol when it is open; the status bar no
longer repeats the path the breadcrumbs show (a rendered Markdown file keeps
its breadcrumb path); change markers are kept current in both groups.

* test(keymap): the editor group chords win inside the editor

* fix(lsp): close a window's documents when the window closes

Documents were only closed by sync_window, which runs when a window's
buffer set changes. Closing a window never ran it, so no didClose was
sent, the idle shutdown never started, and a language server lived on
until quit (forever, with the app retired to the tray).

* fix(editor): restore a split whose left group had no recorded files

The recorder writes files: [] with a split when the left group held only
untitled or remote buffers, but restore returned early on an empty left
list and dropped the right group too.

* fix(editor): forget a swept orphan buffer's navigation state

The orphan sweep dropped clean buffers without calling forget_buffer, so
each one's outline cache (a full copy of its text), LSP symbols and
edit-log cursor stayed in EditorNav for the life of the window.

* fix(lsp): owner-only sync, stale-edit checks, request timeouts, re-enable

- Only the buffer that owns a document may use its server. The same file
  open in another window used to send its own text as didChange on F12,
  rename, references or signature help, swapping the document under the
  owner. LspStore::context now takes the requester and refuses a
  non-owner quietly, before anything is sent.
- apply_workspace_edit checks every open buffer an edit touches against
  a baseline: the texts when a rename was asked for or the code-action
  menu was filled, or the text the server last heard for its own
  workspace/applyEdit (which then answers applied: false). A buffer typed
  in, opened or closed since means nothing is applied.
- A request made after the server's output closed fails at once instead
  of waiting forever. Requests time out after 10 s (initialize after 60 s,
  shutdown after 2 s) and cancel themselves on the server.
- Turning editor_lsp back on asks every window for its open files again,
  which starts their servers. Windows register how to be asked; closed
  ones are forgotten.

* test(nav): spell out LineEdit's new at_line_start field

gpui-component's LineEdit now records an insertion at column 0, which
moves the whole line down. The literal edits in this test are mid-line.

* fix(editor): a restore merges into the tab, and commands follow the group focus

Session restore used to assign the recorded groups over whatever the tab
held when its files finished loading, so a file opened or a split made in
the meantime was lost. TabCode::restore_groups keeps a split made meanwhile
as it is, and otherwise lays out the recorded groups and puts the files
opened meanwhile back into the focused group, the last of them in front. A
restore the reader has moved on from no longer takes the keyboard, and never
hides a panel they opened.

The group focus only followed the keyboard when the editor drew. Keys are
safe - gpui draws a window whose focus moved before dispatching the next
key - but a command from the menu bar or a context menu is dispatched
without a draw, and acted on the group that had the focus before. A
capture-phase listener for every editor command on the editor's element now
settles the group first, wherever the command's handler sits.

* fix(editor): leave cmd-T to New Tab; offer workspace symbols from the palette

Inside the code editor cmd-T was rebound to Go to Symbol in Workspace,
which made tty7's most-used chord mean two things depending on focus.
It is New Tab everywhere again. Workspace symbols stay reachable as an
Editor palette row and as a rebindable, unbound action.

* build: pin gpui-component to the fork's editor work (0e7541fb)

* fix(search): let the editor's pickers stand alone in Search Everywhere

Go to Symbol, a language server's places and Go to Symbol in Workspace
opened on hidden tabs, so the window-wide scope row (All, Terminals,
Sessions, Hosts, Commands) sat over them with nothing selected, and Tab
swapped the list for the terminals. They now show a heading in place of
the row (References / Definitions / Symbols / Workspace Symbols, with a
count), Tab stays put, and the footer drops the scope hint.

* fix(search): Go to File stands alone like the editor's pickers

Go to File (cmd-O) is reached only by its chord, yet it sat under the
scope row with nothing lit and offered Tab to leave for the terminals.
Every tab outside the row now stands alone the same way: its name in
place of the row, Tab stays put, no scope hint in the footer.

* feat(search): give the editor its own scope row — Files, Symbols, Workspace Symbols

Go to File, Go to Symbol and Go to Symbol in Workspace were three
separate pickers, each on its own chord. They now share a second scope
row, the editor's, next to the window's: cmd-O and cmd-shift-O open on
it and Tab walks it. Only tabs that can answer show: Symbols needs a
file in front, Workspace Symbols a language server that searches the
project. A row of one shows as a heading. Each tab is opened the way its
chord opens it, so it arrives set up; references and definitions still
stand alone.

* feat(search): fold Workspace Symbols into Symbols

Symbols and Workspace Symbols answered the same question at two scopes.
Symbols now does both: with nothing typed it is the file's outline; once
a query is typed, the front file's language server is asked across the
project and its answers are listed after the file's own, each under a
heading when both have rows (the front file's own hits are dropped from
the project's). The separate tab, action and palette row are gone.

* fix(search): call the language server's project results Project, not Workspace

LSP's workspace/symbol searches the server's project root, which has
nothing to do with a tty7 workspace (a group of tabs). The Symbols tab's
second section said Workspace, reading as if it searched those. It says
Project now, and the tty7-facing names follow (project_symbols,
set_project_symbols, lsp_project_symbol_query); only code that speaks
the protocol keeps its word.

* ci(host-boundary): allow the language servers' local reads

ui::lsp only ever holds local buffers (OpenFile::local refuses any other
host) and runs its servers on this machine, so the files it reads to
measure a column, apply a rename to disk or find a project root are on
this disk. Each call is allowlisted with that reason.

* test(editor): spell test paths so they hold on Windows

The language-server tests used /p/... paths, which are not absolute on
Windows and so have no file:// URI; they now build platform paths
(lsp::test_path) or spell the URI out. The gutter and split tests
canonicalized their temp dirs to get past macOS's /private symlink,
which on Windows yields the \\?\ form no editor path is ever in; they
share a helper that canonicalizes everywhere but Windows.

* test(editor): resolve temp dirs the way the editor does

On the Windows runner the temp dir is an 8.3 short name (RUNNER~1),
which the editor's load expands through Host::canonicalize. The split
tests now resolve their fixtures through that same call instead of
guessing per platform.
2026-09-28 20:47:07 +08:00
l0ng-ai 3ef692b353 feat(agents): infer interrupted and stale turns, report permission prompts first-hand (#1003)
- Interrupts: an Esc / Ctrl+C (legacy, kitty and modifyOtherKeys forms)
  on a pane whose agent is mid-turn arms a 1s settle; if no hook event
  arrives, the turn is assumed over and goes Done. Claude's Stop skips
  user interrupts, so panes used to stay on working until the next prompt.
- Stale turns: a daemon sweep moves a turn that has been Working with no
  hook event for 30 minutes to Idle.
- Both set `inferred` on the session; the next real event clears it, and
  a tool finishing after a guess puts the turn back on Working. Inferred
  states raise no finish notification and no unread badge.
- Claude and Codex now hook PermissionRequest, and PreToolUse for their
  ask-the-user tools (AskUserQuestion / request_user_input), so Waiting
  shows the moment the prompt opens. Codex also gains PostToolUse, so it
  leaves Waiting once the approved tool has run.
- The "finished" desktop notification waits 1.5s and is dropped if the
  next turn starts first (queued message, Stop hook sending it back).
2026-09-28 20:47:01 +08:00
l0ng-ai ae38747f69 feat(terminal): follow links a table wrapped inside its cell (#1001)
Markdown tables (Claude Code's among them) wrap a long cell by hand: each
row is a hard newline framed by box-drawing borders, with the next cell's
text in between. Hovering or clicking a URL wrapped that way only ever got
the fragment on one row, so the link opened truncated.

Link lookup now reads a table cell the way it already reads a wrapped row,
just inside the cell's own columns: a row carries on into the next when its
text reaches the right border and the next row's starts at the left one,
with link characters on both sides and the borders lined up. Only `│┃║`
count as borders; a bare `|` is too often a pipe. Cells that fit on one row
and double-click selection are unchanged.

The hover underline is now a run per row instead of one start..end span, so
a stitched link underlines just its cell rather than the borders and
neighbouring cells between its rows.
2026-09-28 20:46:55 +08:00
l0ng-ai 2e0d4de136 feat(github): show a pull request's checks, reviews and merge state (#1000)
The PR detail now leads with what it is usually opened to find out:

- Checks: check runs and commit statuses on the head commit, failures
  first, with durations and links to their logs. A section with more
  than five folds the passed and skipped ones into one row.
- Reviews: one row per reviewer (approved, changes requested,
  commented, requested), folding the way GitHub's sidebar reads them.
- A merge-state line under the branches ("Waiting on 1 check",
  "1 check failing", "Merge conflicts", "Ready to merge", ...).

Checks and reviews that cannot be read are left out instead of failing
the whole detail. While a check is running, just the checks are re-read
every 20 seconds (signed in only); once every verdict is in, the detail
is read again for the new merge state.

The list pins the pull request of the pane's branch under the repo row,
looked up through the branch's upstream so a fork's branch is found
under the fork's owner.

Long sections fold: comments past four keep the first and the latest
two, long descriptions and comments are clamped behind "Show full text",
and reviewers and changed files show a few with a "show all" row.
2026-09-28 20:46:49 +08:00
dependabot[bot] 2938a41a1c deps: bump the cargo-minor-patch group with 6 updates (#998)
Bumps the cargo-minor-patch group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [encoding_rs](https://github.com/hsivonen/encoding_rs) | `0.8.35` | `0.8.42` |
| [uuid](https://github.com/uuid-rs/uuid) | `1.26.0` | `1.26.1` |
| [plist](https://github.com/ebarnard/rust-plist) | `1.10.0` | `1.10.1` |
| [clap](https://github.com/clap-rs/clap) | `4.6.6` | `4.6.7` |
| [toml_edit](https://github.com/toml-rs/toml) | `0.25.13+spec-1.1.0` | `0.25.15+spec-1.1.0` |
| [ureq](https://github.com/algesten/ureq) | `3.4.0` | `3.4.2` |


Updates `encoding_rs` from 0.8.35 to 0.8.42
- [Commits](https://github.com/hsivonen/encoding_rs/compare/v0.8.35...v0.8.42)

Updates `uuid` from 1.26.0 to 1.26.1
- [Release notes](https://github.com/uuid-rs/uuid/releases)
- [Commits](https://github.com/uuid-rs/uuid/compare/v1.26.0...v1.26.1)

Updates `plist` from 1.10.0 to 1.10.1
- [Release notes](https://github.com/ebarnard/rust-plist/releases)
- [Changelog](https://github.com/ebarnard/rust-plist/blob/master/CHANGELOG.md)
- [Commits](https://github.com/ebarnard/rust-plist/compare/v1.10.0...v1.10.1)

Updates `clap` from 4.6.6 to 4.6.7
- [Release notes](https://github.com/clap-rs/clap/releases)
- [Changelog](https://github.com/clap-rs/clap/blob/main/CHANGELOG.md)
- [Commits](https://github.com/clap-rs/clap/compare/clap_complete-v4.6.6...clap_complete-v4.6.7)

Updates `toml_edit` from 0.25.13+spec-1.1.0 to 0.25.15+spec-1.1.0
- [Commits](https://github.com/toml-rs/toml/compare/v0.25.13...v0.25.15)

Updates `ureq` from 3.4.0 to 3.4.2
- [Changelog](https://github.com/algesten/ureq/blob/main/CHANGELOG.md)
- [Commits](https://github.com/algesten/ureq/compare/3.4.0...3.4.2)

---
updated-dependencies:
- dependency-name: encoding_rs
  dependency-version: 0.8.42
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-minor-patch
- dependency-name: uuid
  dependency-version: 1.26.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-minor-patch
- dependency-name: plist
  dependency-version: 1.10.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-minor-patch
- dependency-name: clap
  dependency-version: 4.6.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-minor-patch
- dependency-name: toml_edit
  dependency-version: 0.25.15+spec-1.1.0
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-minor-patch
- dependency-name: ureq
  dependency-version: 3.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-28 20:46:43 +08:00
LiuSirandstevelliu e06ba47017 feat(tabs): name the agents you run in the New Tab menu (#994)
The + menu lists up to three agents that have actually been run, beside
Local and SSH. Other Agents… opens Search Everywhere already filtered to
agent. New Agent Tab still starts the one used last.

Refs #955

Co-authored-by: stevelliu <stevelliu@tencent.com>
2026-09-28 16:31:39 +08:00
l0ng-ai 18109018ce docs: add a landing page with a live v5 demo
The docs root becomes a custom-mode landing page modelled on the Claude
Design "Terminal Redesign v5" window. The hero is an HTML/CSS rebuild of
that window that autoplays five chapters taken from the promo storyboard:
agent status and notifications, one agent driving another through the
tty7 CLI, the editor prompt, Search Everywhere, and sessions outliving
the window. It follows the docs light/dark theme and pauses off screen.

Agent avatars use the app's own marks and brand colours (CLIAgent::
accent_rgb / icon_path), and status dots use AgentStatus::dot_rgb.

The previous introduction moves to /introduction, and the navbar logo
now links to the landing page instead of GitHub. All landing-page CSS
is scoped under .t7h / .t7w, since Mintlify loads it on every page.
2026-09-28 15:14:30 +08:00
l0ng-ai 2a9c662ad5 docs(readme): cover the side panel, tab hibernation and session resume; resync the Chinese README 2026-09-28 14:41:00 +08:00
l0ng-ai 33d7da60f9 fix(sidebar): even group spacing, a pin icon, and a menu under the tabs
The rule between kept and derived groups sat in the list as a child of
its own, between two GROUP_GAPs, so kept groups stood more than twice as
far from the rest as groups stand from each other. It now takes up the
one gap instead of adding another.

The kept-group mark is a drawn pin rather than a diamond glyph, on the
header and on the pin button an auto header shows on hover.

Right-clicking the empty sidebar under the tabs did nothing. The room
below the last row now opens New Tab and New Group.
2026-09-28 14:00:50 +08:00
l0ng-ai 4e8a76261b fix(terminal): call the right-click menu's clear item just Clear 2026-09-28 13:45:04 +08:00
l0ng-ai ee817bae01 feat(ui): v5 modal cards, and an IME crash fix in the code editor (#993)
* fix(deps): gpui-component keeps highlight boundaries on char boundaries

Typing Chinese through the IME in the code editor could panic the app:
after a sync parse ran past its 2ms budget, the stale injection layers
put a style boundary inside the committed glyph and the text system split
the line mid-character. Debug builds miss the budget often enough to hit
it; the fork now snaps every style range to the current text.

* feat(ui): bring the modal cards onto the v5 design

- Confirmations take v5's alert shape: title and detail as one
  paragraph, answers beneath, no header row or footer rule, 360px wide
  and set lower, at eye height.
- Dialog buttons take the field's 7px corner and 14px padding; a
  secondary answer rests on the well's faint fill instead of bare text.
- The scrim dims rather than blacks out: 45% dark, 14% light.
- The New Workspace form joins the other cards: 12px corner, borderless
  wells for its fields, an esc cap and the shared 40px footer.
2026-09-28 13:35:53 +08:00
l0ng-ai f647a19746 feat(editor): draw the editor's right-click menus like the rest of the window (#992)
* feat(editor): draw the editor's right-click menus like the rest of the window

The text's menu was gpui-component's native OS menu: another font and
material, no shortcuts, and Go to Definition / Show Code Actions that no
language server ever enables. It is now a PopupMenu with Attach to Agent
(the selected lines ride along as #L3-9), Undo/Redo, the clipboard,
Find, Go to Line, and the file's own items: Open in Browser for web
files or Open with Default App, Reveal, Copy Path, Copy Relative Path.

The file tabs get a menu too: Close, Close Others, Close to the Right,
and the same file items. Closing several asks once about unsaved edits.

* chore(deps): gpui-component moves the caret on right-click under a host menu
2026-09-28 13:35:15 +08:00
ARNO 643e0f7d95 feat(agents): add Qoder CN CLI integration (#988)
* feat(agents): add Qoder CN CLI integration

* fix(agents): spell Qoder CN's config override QODERCN_CONFIG_DIR

The China build of Qoder resolves its configuration through QODERCN_CONFIG_DIR.
The first pass invented QODER_CN_CONFIG_DIR instead, so an install that set the
real one was treated as unrelocated: hooks went to ~/.qoder-cn and history was
scanned from a directory the CLI never writes to. The test that should have
caught it set the same invented name, so it only proved the name agreed with
itself.

Picks up the rest of the review as well — detect the `qoder-cn` dispatcher
beside the other two binaries, call it the mainland-China build rather than a
different vendor, and drop the QODER_CN_HOOK_EVENTS alias for the table it only
pointed at. The serialized enums keep their variants appended; only the
independent ALL arrays moved QoderCLICn next to QoderCLI.
2026-09-28 13:35:10 +08:00
l0ng-ai 388ddf4303 fix(search): label the search entry point "Search…" (#990)
"Everywhere" added nothing: the modal's tabs already say what it covers.
2026-09-28 13:35:06 +08:00
e94c0d39cb fix(path): read the interactive shell's PATH, not just the login shell's (#989)
* fix(path): read the interactive shell's PATH, not just the login shell's

The GUI starts with launchd's bare PATH and refills it by running the login
shell. A login shell reads .zprofile/.bash_profile and never .zshrc/.bashrc,
so every directory exported there was invisible to the app: agent quick
launch found only what /opt/homebrew/bin and /usr/local/bin happened to hold,
and an agent_launch override could not bring a missing program back, since
the override's program is looked up on the same PATH.

Probe with -i as well (fish unchanged: it reads its config in every mode) and
take the last non-empty line, so an rc that prints a greeting above the
echo $PATH cannot be mistaken for the value.

* fix(path): bound the interactive PATH probe and bracket its output

Running .zshrc/.bashrc on the startup path needs guards the login-only
probe could do without:

- Read the PATH between markers instead of the last line, so an exit
  hook that prints after it cannot be taken for the PATH.
- Return as soon as the closing marker arrives rather than at EOF: an rc
  that backgrounds a daemon hands it the pipe, which then never closes.
- Give up after 5s and kill the shell, so a slow or stuck rc delays
  startup instead of preventing it.
- Probe after forwarding an open path to a running window, which has no
  use for the PATH.

* docs(changelog): describe the bounded PATH probe

---------

Co-authored-by: stevelliu <stevelliu@tencent.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-09-28 12:12:55 +08:00
l0ng-ai bc08fc49f4 fix(deps): gpui-component paints text selection under the glyphs (#991) 2026-09-28 11:41:11 +08:00
l0ng-ai 39776012e2 feat(github): read a repository with whichever gh account can see it (#987)
The GitHub panel borrowed only gh's active account, so a private repository
owned by an organisation another signed-in account belongs to read as a 404.

When the active account gets a 404, 401 or 403, retry with gh's other
github.com accounts and remember, per owner, the one that got through. The
other accounts are listed lazily (gh auth status checks each online), and a
token from GH_TOKEN/GITHUB_TOKEN keeps its no-fallback meaning.
2026-09-28 10:59:25 +08:00
l0ng-ai ce76de975c fix(search): keep the empty note clear of the scope row
The empty view replaces the rows, so the list's top padding the scope row
is laid over never reached it and the row sat on top of "No results". It
now keeps its own clearance and sits left-aligned on the rows' column.

Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 09:11:09 +08:00
l0ng-ai 1ba9159408 feat(panel): drop the GitHub row from the Info tab
The GitHub tab one over already names the repository and opens it; the
row only repeated it. Its upstream lookup goes with it.

Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 09:00:55 +08:00
l0ng-ai 23e4ea79f5 chore(deps): gpui-component with v5 menus
Picks up l0ng-ai/gpui-component bce0d8ec: popup and context menus take
the v5 popover look — a neutral hover step, 28px rows, a hairline ring
and v5's long shadow.

Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 08:45:02 +08:00
l0ng-ai 689517a632 feat(search): call the Actions scope Commands
Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 08:45:02 +08:00
l0ng-ai 99e626db7a fix(ui): the title bar search takes the left rail's fill
Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 08:42:24 +08:00
l0ng-ai 83c659d8bf fix(ui): paint the title bar search on the sidebar's surface
Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 08:34:01 +08:00
l0ng-ai 57384032d5 fix(ui): the title bar search toggles like the switcher, on v5's field fill
Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 08:33:05 +08:00
l0ng-ai d7eece6cf9 feat(ui): v5 search — Search Everywhere without Files, one Files search for names and text, word tabs
- Search Everywhere follows the v5 design: the scope row sits under the
  field, Files leaves the row, Tab and the All tab (Go to File still opens
  it), the scopes run All, Terminals, Sessions, Hosts, Commands, matches are
  picked out in the title, subtitles move to the right edge, and the footer
  leads with Next scope.
- The right panel's Files field searches file names and file contents at
  once, in two sections. The Search tab folds into it; a stored "search"
  tab and Show Search open Files with the field focused.
- The right panel's tab row is words again: Info, Files, Changes, GitHub.

Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 01:49:55 +08:00
l0ng-ai bcd0a2939d fix(panel): give the GitHub tab's header room to breathe (#986)
The repo row, the two segmented switches and the list sat flush against
each other. The list now starts 10px below the header, the gap the Files
and Search tabs leave under their search field, and the switches get more
space between them when a narrow panel wraps them onto two lines.
2026-09-28 01:30:12 +08:00
l0ng-ai 28c6f6b11a fix(ui): centre the title bar search over the terminal column off macOS
With a document or the detail panel docked, the title bar spans the
workspace on Windows and Linux, and the Search Everywhere box centred on
all of it landed under the document's hoisted header, which has no fill
to hide it.
2026-09-28 01:06:59 +08:00
l0ng-ai ed9b8b0a90 fix(ui): one dialog for every confirmation, titled failure toasts, aligned settings controls (#985)
* fix(ui): draw every confirmation as the app's own dialog card

window.prompt fell through to NSAlert on macOS and TaskDialog on Windows,
so closing a busy tab threw up a system alert with a centred app icon and
stacked grey buttons while every other question the app asks is a
ui::dialog card. The Linux fallback card had drifted too (accent buttons,
its own padding).

TextPrompt is now built from ui::dialog on all three platforms: the 12px
card at the switcher's top offset, a wrapping title row with an esc cap,
a hairline footer and ink-filled primary. Return and Escape keep the
native meanings; the scrim occludes the window and backs out; a lone OK
answers Escape; an answer listed after Cancel in a prompt of three stands
apart at the footer's left, and an action behind a Cancel-first default
is painted red.

SCM's discard and destructive-op prompts passed Cancel as a bare label,
which gpui only recognises as a cancel when it is the English word; they
now mark it explicitly.

* fix(ui): show the settings window's toasts and title git failures

The settings window is a gpui Root of its own but never rendered the
notification layer, so everything the page reported (an ssh_config
import, a passphrase it could not store) was pushed into a layer nobody
drew.

A failed git op was toasted as one bare stderr line
('push: fatal: ...'). It is now an error toast titled 'git push failed'
with git's reason, severity prefix dropped, beneath it.

* fix(settings): one control language down the right-hand column

The page had drifted from the design system: dropdowns and secondary
buttons were raised white with a drop shadow, fields had a half-pixel
inset ring that anti-aliased to nothing on a 1x display (the shell and
proxy rows read as loose monospace text), and dropdowns sized to their
value beside fixed-width fields, so the column's left edge zig-zagged.

Fields, dropdowns, secondary buttons, steppers and search fields now all
stand on the theme's muted well with no outline or shadow; a field shows
a ring only for focus (accent) or error. Fields and dropdowns are 28px
and one width (kit::CONTROL_W); only path and command fields are wider.
Field text is sized on the Input itself, since its own text_sm outranked
the size set around it. A host saved under its own address no longer
repeats it as a subtitle.

* fix(ui): tidy menus, the switcher and the editor's conflict strip

- New Tab menu: host endpoints elide against fixed caps instead of being
  clipped mid-glyph at the panel edge; notes are right-aligned again.
- Switcher: a workspace's tab count reads '1 tab', not a bare 1 beside
  the slot number.
- Editor 'changed on disk' strip: neutral with an amber dot and dialog
  buttons, Keep mine as the safe primary, instead of an amber wash with a
  library-default outlined button.
- Title bar search keeps its full label with a document docked.

* fix(search): a command named in the query leads over a session that says it

'worktree' then Return resumed a past agent session instead of opening
New Worktree Tab. Two causes:

- The fuzzy scorer matched greedily from the left, so the query's first
  letter was spent on any earlier occurrence ('New') and the rest
  scattered: a title containing the whole word scored as a poor match.
  It now tries every position the first letter occurs and keeps the
  best; the leftmost alignment is one of those, so no score drops.
- Session titles are whatever was first typed to an agent, and those
  often open with a command's name, taking the prefix bonus. On the All
  tab the Sessions section now stands back by a little more than that
  bonus when sections are ordered; a session still leads when it is
  plainly the better answer, and the Sessions tab ranks untouched.

* fix(ui): dialog wells and mono detail that hold up in the dark

Dialog fields, info wells, keycaps and disabled filled buttons used the
theme's muted fill, a step off the window. Cards sit on the popover
surface, which a dark theme lifts to about the same value, so every
field on a dialog lost its shape. They now take the card's own next
rung.

The host-key fingerprint and the worktree path preview asked for the
'monospace' family, which gpui resolves as a literal family name and
falls back from; they use the theme's mono family.

* fix(ui): one way to draw a shortcut

- Every chord is one cap per key. The home page and the switcher's
  footer packed theirs into a single cap (⇧⌘T, ⌘↵) beside Search
  Everywhere's ⌘ T; dialog::chord is the one spelling now, and the
  switcher's private copy of dialog::keycap is gone.
- On macOS modifiers are listed ⌃ ⌥ ⇧ ⌘ whatever order the binding was
  written in, as the menu bar lists them; the palette read ⌘ ⇧ D.
- Return is ↵ everywhere; key_tokens alone drew ⏎.

* fix(ui): file errors as titled error toasts; say a delete is for good

HostOps::notify_err ran its context and the reason together as one
plain line ('Could not delete a.txt: You do not have permission.').
Every context it is given is already a sentence about what failed, so
it is now the title of an error toast and the reason sits under it. The
'{context}: {error}' template is gone with its last caller.

The delete confirmation's detail repeated its title ('The file will be
deleted.'). The remove is permanent, not a move to the Trash, and that
is the one thing worth saying there.

* fix(ui): every failure toast says what failed, why, and that it failed

About twenty toasts reported failures as one plain line with no
severity: 'Could not open a terminal: <why>', 'Couldn't forward :3000 —
<why>', 'SSH reconnect failed: <why>'. host_ops::failure turns such a
sentence into an error toast, taking what failed as the title and the
reason beneath it. It splits the formatted text rather than the
templates, because some of them are also shown whole (the home screen
keeps the start-up failure on screen), and a reason that is not at the
end leaves the sentence whole.

Waking a tab and reopening one are errors too; tabs that could not be
restored are a warning.

* fix(settings): a primary with nothing to do rests on the well

A disabled or not-yet-dirty primary (the host form's Save) was the ink
button faded to 45-55%: a washed-out black button that still looked
like the thing to press. It now sinks to the well with secondary text,
the fall the dialogs' Create and the Git panel's Commit take, and turns
ink once there is something to save.

* fix(settings): the shortcuts page's way back is drawn, and its title lines up

The back link to Keyboard & Mouse was pulled up out of the page column
with negative margins, above the scroll area's clip, so it was never
drawn - the page had no visible way back - while the rest of its height
pushed the title 16px below every other page's. It now sits in the
title-bar band, and the title is where the others are.

* fix(settings): searchable dropdowns say they can be searched

The filter field shared by the page's searchable dropdowns (themes,
shells) had no placeholder, so it read as a stray caret between the
preview and the list.

* fix(i18n): no stray space before the default shell in zh and ja

The shell intro put a space before {default}, meant for a Latin shell
name, but the default is the localized 'your login shell', so zh read
'留空则使用 你的登录 shell'. The ja sentence also ended on the bare
noun.

* fix(settings): action menus don't reserve a column for a tick

Every settings menu kept an empty tick column, so a menu of actions
(an agent's Reinstall / Reveal / Uninstall) set its labels 24px in from
a 12px right edge. The column is kept only when some entry is ticked -
a choice menu - and an action menu is padded evenly.

* refactor(settings): drop the raised-control paint nothing uses now

Tk::btn and Tk::raised_hover lost their last callers when the page's
controls moved onto the well. Also corrects two comments that described
the old field ring and claimed more than was observed.

* revert(settings): keep the v4 Settings design's controls

The earlier commits on this branch moved the settings page's dropdowns,
buttons, steppers and fields onto flat outline-less wells, following
docs/design-system.md. That paragraph predates the v4 Settings design
the page was rebuilt to on 2026-09-26 (raised controls, hairline-ringed
fields) and was never updated to it, so the change took the page away
from the design rather than toward it. The raised controls, 26px
heights and the faded disabled primary are back as v4 drew them, and
the design-system edits are withdrawn.

Kept, as fixes within the design:
- dropdowns and fields share one width (kit::CONTROL_W);
- the field's value is sized on the Input, which otherwise beat it;
- the field hairline is one device pixel: v4's half point is one pixel
  on Retina and nothing at all on a 1x display.

* fix(settings): a primary with nothing to do falls to the faint fill

A disabled or not-yet-dirty primary (the host form's Save) was the ink
button faded to half opacity - still a black button that looked like
the thing to press. It now takes the fall v4 already gives the Commit
button and the dialogs' Create: faint fill, secondary text, ink again
once there is something to do.

* fix(settings): tab position rows are dropdowns again

#982 moved New tab position and Tab bar position into General with the
segmented control they had before #979 made every pick-one setting a
dropdown, so General mixed the two again. Both use settings_choice.

* fix(scm): the Changes list sits on the same rhythm as the Files tab

- The filter was appended to the pinned block without the pause the
  blocks above carry, and the list starts flush, so the first group
  header sat on the field's edge (0px) while 14px stood above it. It
  now leaves the Files tab's 10px under its search.
- File rows (working tree and commit detail) padded 3px above and below
  a 23px line box, standing 29 tall - 30px pitch - beside the tree's
  26px directory rows and the Files tab's 26px rows. They are ROW_H,
  26, as v4 specifies.
2026-09-28 00:36:42 +08:00
l0ng-ai bf5149bea0 fix(editor): stop losing edits, share buffers, add file strip, quick open and go to line (#984)
* fix(host): save local files atomically via a temp file and rename

LocalHost::write_file truncated the target in place, so a crash, a full
disk or a killed process mid-save destroyed the user's file. It now
writes a hidden sibling temp file, syncs it, keeps the old file's mode
and renames it over the target, removing the temp file on any error.

It still writes in place where a rename would change something visible:
a non-regular target (symlink, directory, FIFO), a read-only file, and on
Unix a hard-linked file or one owned by another user, or when the temp
file cannot be created (e.g. a read-only directory).

* feat(editor): add editor_text for encodings, line endings, indentation and EditorConfig

A pure module the code editor will use when loading and saving files:
decode detects BOMs, binary files, UTF-8, GB18030 and a lossless
Windows-1252 fallback and normalises CRLF; encode restores the exact
bytes and names the first unrepresentable character; detect_indent
infers tabs or a 2/4/8 space width with language defaults; and
editorconfig_for resolves .editorconfig sections with save-time rules.

* feat(editor): share buffers across tabs, guard unsaved work, add a file strip

- One buffer per file per window; tabs list which buffers they show. The
  same file open in two tabs is no longer two diverging copies.
- Closing a tab, its last pane, the window, or quitting asks about unsaved
  files (Save / Cancel / Discard) instead of dropping them. Bulk closes skip
  tabs with unsaved files; a tab that vanishes any other way hands its
  unsaved buffers to the tab in front.
- File tree rename/delete now retarget or flag the open buffer, so a save
  no longer recreates the old path.
- Saves check the file's mtime first and ask before overwriting a change
  made elsewhere; this is the only detection SFTP buffers get.
- Dirty is a comparison with the saved text, so undoing back clears it.
- Reloads replace only the changed span as an ordinary edit, keeping undo.
- Load/save go through editor_text: encoding, BOM and CRLF round-trip,
  indentation is detected, .editorconfig is honoured.
- Header shows a strip of open files; New File, Save As (native panel
  locally, a path bar remotely), Go to Line (Ctrl+G), and the status bar
  shows indentation, encoding and a clickable line ending.
- Open files are remembered per tab across restarts.

* feat(search): quick open a file by name from a Files tab

Search Everywhere gains a Files tab that finds any file in the active
tab's project by fuzzy name and opens it in the built-in editor, with
`name:line[:col]` jumping to that spot. The list comes from one walk of
the project through the host (Host::search with an empty query), so it
works the same on local, SSH and WSL workspaces and skips what the tree
hides: dotfiles, .git and gitignored paths. The walk is capped at 50k
entries / 20k directories, kept between openings and revalidated in the
background each time the search opens.

Files join the All tab once a query finds them. Go to File... is bound to
Cmd+O on macOS (Cmd+P is already Search Everywhere) and ships unbound
elsewhere, where every obvious chord is taken or owed to the shell.

* chore(editor): allowlist the editor session file, tidy lints

* fix(editor): keep restored file order, drop stale close waits, carry files through tab merges

- Background arrivals (restore, merge, rescue) append to the strip in order
  instead of inserting beside the active file, which reversed them.
- A cancelled Save As, a dismissed path bar, or a dropped buffer cancels any
  close that was waiting on that save.
- Merging a tab into another carries its open files along.
- A shell exiting closes its tab without a prompt it could not honour;
  unsaved buffers move to the tab in front.
- Tabs rebuilt under the same id (server restart) restore their files.

* fix(host): only fall back to an in-place write when the rename is refused

On Windows every failure of the atomic save fell back to fs::write,
including a failure while staging the temp file. A full disk would then
truncate the original in place, the very loss the temp file prevents.
Staging errors now return as-is; only a refused rename (a file held open
elsewhere) takes the in-place path.
2026-09-28 00:32:18 +08:00
l0ng-ai b063ba97a0 refactor(settings): fold Window & Tabs into General, drop two settings (#982)
The Window & Tabs page is gone. Its three remaining tab settings (new tab
position, tab bar position, auto grouping) are a Tabs group on General,
below Startup & restore, so the nav has seven sections.

Removed outright:
- SSH tab title (`ssh_tab_title`, #726, unreleased). The sidebar already
  groups SSH tabs under their host, and renaming a tab pins its name.
- Open diff preview from sidebar counts (`sidebar_diff_preview`, #247).
  The sidebar counts and the Info panel's changes row always open the
  diff overlay; the large-tree stall it worked around is bounded. An old
  config.json that still carries either key loads as before.

The now-unused window settings icon goes with the page.
2026-09-27 19:11:45 +08:00
l0ng-ai fd2c4f7d4e feat(panel): Search and GitHub tabs in the right panel (#978)
* feat(panel): add Search and GitHub tabs to the right panel

The right panel grows from three tabs to five. Five word labels do not
fit the panel's 280px resting width, so the tab row now draws a glyph
per tab and names it in a tooltip.

Both new panes are placeholders here; the content search and the
GitHub issues/PR browser land on top of this.

* feat(panel): find in files in the right panel's Search tab

The Search tab replaces its placeholder with a content search over the
active tab's project -- the same roots the Files tab shows -- on the host
that project lives on. Hits arrive as you type (debounced, with a
generation counter so a stale answer never lands), grouped by file with a
count, each line excerpted with its matches highlighted. Clicking a hit
opens the built-in editor at that line and column; Enter searches again.
Match-case, whole-word and regex toggles sit at the end of the field, and
the tab focuses its field whenever it is brought forward.

Host::search_content is new on the Host trait, implemented once in
host::content_search (ignore walk + regex) and run by LocalHost directly
and by tty7-server over a new SearchContent control request. The walk
honours .gitignore with or without a repository, skips dot-entries, binary
files and files over 1 MB, and reports a capped search as truncated. The
request is gated on a new `content-search` hello feature, so a server that
predates it is never sent it; the panel says the server needs updating
instead of showing no results. Conformance cases cover local and the
stdio server alike.

* feat(panel): browse GitHub issues and pull requests in the right panel

The GitHub tab follows the focused pane's repository: its root is resolved
the way the Source Control tab does, its remotes are read through the Host
(the tree may be on another machine), and the github.com remote is bound,
upstream over origin in a fork, with a menu to pick another.

The list switches between issues and pull requests, open and closed, 50 rows
a page with Load more; rows carry a state glyph distinct by shape, labels
(click one to filter by it) and relative times. A row opens the detail in
place: title, state, author, labels, description and comments as Markdown,
and for a pull request its branches, size and changed files. A file opens in
the diff overlay through a new supplied-patch DiffSource, so GitHub's patch
renders exactly like a local one without a git probe.

Read-only, and sign-in reuses the GitHub CLI: GH_TOKEN, GITHUB_TOKEN, then
`gh auth token`, found on PATH or at the Homebrew locations a Finder launch
cannot see. Signed out, public repositories still work; 401, 403, 404 and
rate limits are told apart and explained. Requests go out from this machine
over the installer's ureq stack and proxy settings, on threads of their own,
cached per repository with background revalidation. Remote images in issue
text become links instead of loading, and non-web link targets are disarmed.

The Info tab gains a GitHub row that opens the branch on the remote it
tracks, or the repository for a branch never pushed.

* docs: list ShowRightPanelGitHub with the other panel actions

* feat(panel): one-line GitHub rows, a pill for the current tab

- GitHub list rows are one line: state glyph, #number, title. Labels and
  the age of the last update appear on hover, from state rather than a
  group_hover display switch, which gpui cannot paint.
- The current right panel tab sits on the sidebar's selected fill; ink
  alone could not tell five same-weight glyphs apart.
- The GitHub glyph is a 1.8px outline like the other tab icons, not the
  filled mark.
- The detail byline names both times (opened / updated) so it no longer
  reads as disagreeing with the list's update age.

* feat(github): show screenshots pasted into issues

Images GitHub hosts itself (github.com/user-attachments, a repo's
/assets, *.githubusercontent.com) now render in issue and PR text, each
in a paragraph of its own so the text view draws it at its size rather
than at line height. Images from any other host stay links, so opening
an issue still tells no third party that you read it.

gpui held a null HTTP client, so no remote image could load; the app now
installs the update check's reqwest client (same user agent and proxy)
at launch.

* fix(github): load private-repo screenshots, give inline code a neutral fill

- Pasted attachments (github.com/user-attachments/assets/<uuid>) want a
  browser session on a private repository, which an API token is not.
  The detail and comment requests now ask for the full media type, and
  each attachment is swapped for the signed private-user-images URL the
  rendered body_html carries for the same uuid.
- Inline code in rendered Markdown (the GitHub tab and the editor's
  preview) sits on a faint neutral fill instead of the theme accent,
  which is also the selection colour. Needs gpui-component 6af19d91 for
  TextViewStyle::inline_code_background.

* style(panel): tidy the GitHub and Search tabs' top rows

- GitHub drops its heading row on macOS. It existed only to hold the
  refresh tile, and no other tab has one; refresh now sits with the
  repository's other actions, in the repo row and a detail's header.
- Search's Aa / ab / .* toggles are muted while off instead of body ink.
- Search's idle note puts the folder on its own line, spelled ~/…, so
  the narrow column no longer breaks the path at a slash.

* feat(panel): order the right panel's tabs Info, Files, Search, Changes, GitHub

Info stays first as the default and the pane's overview; after it come
two pairs, the project's files (Files, Search) and its version control
from local to remote (Changes, GitHub), where Changes and GitHub were
split by the file tabs before. The palette, the Keybindings list and the
docs follow the same order.

* style(panel): drop the change count from the Changes tab

Beside one glyph of five, the number read as a badge on that tab alone,
and the Changes tab already leads with the same count under its own
heading. right_panel_tabs no longer needs the row's width, which it only
measured to decide whether the count fit.

* style(icons): fit the GitHub glyph to the other tab icons' size

The Lucide mark filled its whole 24px box, edge to edge, where tty7's
own icons keep about 3.5px clear, so at 15px it drew a size larger than
the four tabs beside it. Scale it to 0.9 about the centre, and raise the
stroke to 2.0 so it still renders at the others' 1.8.

* style(icons): a simpler GitHub glyph

Drop the Lucide mark's tail and redraw the head and legs on tty7's own
grid: the same ~15px live area and 1.8 stroke as the other tab icons, no
scale transform. The legs keep it reading as the Octocat; a head alone
read as any cat.

* test(github): find gh on PATH in the blank-variable token test

The test placed gh only at /opt/homebrew/bin/gh, which gh_candidates never
offers on Windows, so the Windows CI job panicked at unwrap. Put gh on a PATH
directory spelled with the platform's exe name instead.

* fix(github): close image and link bypasses in the issue Markdown sanitiser

Checked against markdown-rs (the parser TextView uses), several inputs got
past the line-based rewrite:

- is_github_hosted cut the host only at `/`, so
  `https://evil.io?.githubusercontent.com/x.png` (and `#`, `\`, `&#47;`)
  counted as GitHub-hosted and was fetched from evil.io. The host now ends
  at the first of `/?#\` and may hold only DNS characters.
- `<img src>` values were written into `![..](..)` unescaped, so a `)` in
  the value closed the image and opened a second one from any host. Written
  destinations are now percent-encoded.
- `<image>` (which the HTML parser reads as `<img>`) passed as an ordinary
  tag and loaded its src.
- A kept link target was copied without scanning; when the parser ended
  the link elsewhere (open title, unbalanced paren) a `![..](..)` inside it
  came alive. Markup characters in it are now encoded.
- `file&#58;///...` and similar character references passed is_safe_target
  and decoded to a `file:` link. References are decoded before judging.

The rewrite still cannot see every construct the way the parser does
(code spans inside tag attributes, fences the parser rejects, multi-line
link definitions), so the detail view now also checks the parsed tree: a
block containing a non-GitHub image, an unsafe link or definition, or raw
`<img>` is drawn as its plain source instead.

* fix(github): hide gh's console, bound Retry-After, and reject URL authorities with ?#\

- run gh through proc::output_within with hide_console, so a Windows GUI
  launch does not flash a console window and stdout is drained while gh runs.
- saturating_add a hostile Retry-After instead of overflowing i64.
- parse_github_url no longer accepts `https://evil.io#@github.com/o/r`.

* fix(search): no panic on an unbounded time budget, and read files through the size cap

ContentLimits arrive off the wire on a server; Instant + u64::MAX ms
panicked. A file that grew between the size check and the read was read
whole; it is now read through a take() at the cap.

* fix(panel): keep Load more on an empty filtered page, and drop another host's hits

- /issues pages filtered to one kind can come back empty while later pages
  hold matches; the GitHub list said "No issues" and hid Load more. It now
  reads on through up to five such pages and keeps Load more offered.
- While a new search runs, the previous hits stay on screen; if they came
  from another host, a click opened their path on the active host. They are
  now kept only when the host is the same.
2026-09-27 19:04:42 +08:00
l0ng-ai d6c223751d fix(i18n): proofread the Chinese UI copy (#980) (#981)
Fix half-width punctuation, unify terminology (passphrase, Finder,
server), quotes and dash styles, and rewrite the most literal
translations. Point every language and the CLI at Settings →
Integrations, the page's actual name, instead of Settings → Agents.
2026-09-27 18:32:56 +08:00