Commit Graph
1129 Commits
Author SHA1 Message Date
l0ng-ai 3990a05795 Mobile: an iOS pass from a user's seat (#1075)
* fix(mobile): draw a prompt's icons

Prompts built with Powerline and Nerd Font glyphs (branch, folder, git
status) showed as empty boxes: a phone has no such font to fall back on.
Ship the symbols-only Nerd Font, one cell wide, behind Hack.

* fix(gateway): send a phone the screen the desktop shows

A phone opening a pane was sent its raw output, ring segment by segment,
and read it with xterm.js. Across the pane's resizes that emulator wraps
and reflows unlike the desktop's, so shells' SIGWINCH redraws landed on
the wrong rows: prompts twice, old output under new prompts. Leaving a
full-screen program left stale lines behind the same way.

The gateway now reads the pane with the desktop's emulator and, on
opening, after a resize, and when the main screen comes back, sends the
phone that screen drawn afresh: scrollback, colours, cursor and modes.
Output in between still goes straight through.

* fix(mobile): the message box rides the keyboard on iOS

On iOS 26 the WebView, run edge to edge, does not say how much the
keyboard covers, so the message box and the dock stayed under it. The
app now hears the keyboard's frame natively and lays out above its top
edge, on iOS as on Android.

- WebKit's previous/next/Done bar over the keyboard is gone; a tap on
  nothing in particular, or on the pane, puts the keyboard away.
- Return sends however the keyboard delivers it.
- A shell's message box no longer capitalises or corrects: ls stays ls.
  An agent's keeps both, as a chat would.

* fix(gateway): a tab opened from the phone joins its repository's group

The desktop files a tab under its repository as its sidebar draws it, so
a tab opened from the phone while that window was out of sight stayed in
Ungrouped. The gateway now reads, for a tab the desktop has not filed,
which repository its directory is in, the way the desktop would.

* feat(mobile): close a tab from the phone

Swipe a tab's row left for Close, or use Close tab in a pane's menu. The
tab goes where the desktop puts a closed tab, onto the workspace's
recently-closed list, so tty7 on the computer can reopen it. A tab whose
agent is at work asks first.

A new CloseTab stream carries it; a machine that keeps no closed tabs
closes it for good and its panes are ended, as tty7 tab close does.

* feat(mobile): a machine's list reads at a glance, and the app opens where it was left

- The app reopens the machine it was last on; leaving for the list of
  machines is what makes it start there.
- A tab named after its directory goes by the directory's own name, its
  parent underneath, rather than a path cut off at the end that matters.
  An agent's row says where it works too.
- New tab asks which folder, from those the workspace has tabs in, the
  tab in front first; Workspace is asked only when there is a choice.
- The back button names where it goes in full until the title folds in.
- Search fields have a clear button; a few machines need no search.
- Rows swipe left to close their tab, and a pane's menu has Close tab.

* fix(mobile): agents' marks draw, and Return sends a sentence

- Claude Code's ⏺ and ⎿, ⏵⏵, ⚙, ⏰, ✔, braille spinners and the like
  showed as empty boxes: the phone's fonts do not reach a canvas for
  them. Noto's symbols and outline emoji ship, cut down to those blocks
  (about 80 KB), behind Hack and the prompt icons.
- The phone's keyboard reports Shift with Return whenever it has armed
  a capital — at the start, after a full stop — so a message ending in a
  sentence got a new line instead of being sent. Shift-Return starts a
  line only on a keyboard with a real Shift; Return delivered as typed
  text sends as well.

* fix(mobile): an agent's choices become buttons wherever they are on screen

The answers were looked for in the bottom 24 rows of the terminal, which
can be taller than the pane: Claude Code's question sat higher up and no
buttons came. The whole screen is read now.

* fix(mobile): a pane on its side keeps room for the pane

In landscape the bar, the key row, the page dots and the message box
left three lines of terminal. The bar slims and the keys and the message
box share a row, for eight. A message box's hint stays on one line, and
a row's hidden Close names its tab to VoiceOver.

* fix(mobile): Settings names the ⋯ menu with its own mark, and asks before clearing history

The phone's text font has no ⋯, so the note showed an empty box; the
menu button's icon stands in. Clearing the message history, which cannot
be undone, now asks first.

* fix(mobile): Changes shows the changed files, not just the untracked ones

The files' blocks shrank to nothing under a long list of untracked ones:
flex items that clip their overflow give up their height. They keep it
now, and the sheet scrolls. The untracked list sits flush and compact,
the top line totals the change, and lock files start folded.

* feat(mobile): pull a sheet down to put it away

Sheets showed a grabber but only closed from their × or the dimmed screen
around them. Pulled down — from the top, or from anywhere while their
content is scrolled to the start — they go; let go short of the way,
they settle back.

* fix(mobile): a machine that went away says so within seconds

The connection kept QUIC's default 30-second idle timeout, so a laptop
gone to sleep stayed "Direct · 1 ms" on the phone for half a minute, and
typing into it went nowhere without a word. The phone now gives up on a
silent machine after 12 seconds, a few keep-alives missed, says it
cannot reach it, and reconnects on its own once it is back.

* feat(mobile): keys and answers are felt

The key row, an agent's answer buttons and Send give the light tap the
phone's own keyboard does, and a row swiped far enough to open ticks as
it passes the point. Through the Tauri haptics plugin; nothing is felt
where there is no engine for it.

* feat(mobile): pair by pointing the phone's camera at the desktop's code

The pairing QR code reads tty7pair:…, and the app now answers to that
scheme: the phone's own Camera offers to open it in tty7, which pairs
straight away, as its Scan button does. No hunting for the button first.

* fix(settings): the pairing code can be read by the phone's camera

The phone app now opens from its tty7pair: link, so Show code says to
point the phone's camera at it first.

* fix(mobile): Android opens tty7pair: links too

The deep-link plugin's intent filter, written into the manifest by the
Android build.

* fix(mobile): pairing links without the deep-link plugin, cold launches included

The deep-link plugin's build script rewrites the iOS entitlements while
Xcode builds, which Xcode refuses ("modified during the build"), and a
link that launched the app was lost on the way in any case: UIKit hands
it to the first scene as it connects, and the event loop only passes on
links that come later.

- The tty7pair scheme is declared in Info.ios.plist and the Android
  manifest, and links are heard as Tauri's own Opened event.
- The scene delegate's connect is wrapped, before UIKit starts, to keep
  a launching link; the page asks for it once it listens, so neither
  order of arrival loses it.

* feat(mobile): another agent waiting or done says so over the pane you are in

Inside one pane, nothing told you another agent on the machine had
stopped for an answer or finished its turn; you had to back out and
look. The pane now watches the machine's tree too, and such a change
drops a card over the top of the pane, felt as it comes — the agent,
what it says or which tab — that opens that pane when tapped. What was
already so when the pane opened is not news.

* fix(mobile): with the lock on, the app switcher shows no panes

The phone keeps a picture of an app as it leaves, for its app switcher.
With the lock on, that picture showed whatever pane was open. The app is
now covered as it goes, and uncovered — or locked — as it comes back.

* fix(mobile): turning the lock off takes Face ID too

Anyone holding the phone, unlocked, could switch the app lock off from
Settings. Off now asks for Face ID or the passcode, as on does.

* fix(mobile): a pane that is not running says so, with a way on

After the machine's server restarted, panes no window had opened since
were gone, and the phone tried to watch them forever: "Daemon refused
Observe: no such pane 9. Reconnecting…". The gateway now marks panes
its server is not running; the list shows them as Not running, without
their last agent status, and opening one says what is going on and
offers a new tab in the same folder.

* feat(mobile): a workspace not on screen shows when an agent in it needs you

The switcher's chip for another workspace carries the status dot a
folded group does, so an agent waiting there is not hidden behind the
one you are looking at.

* fix(mobile): a new tab's agent starts, instead of waiting at the prompt

Opening a tab for Claude Code or Codex typed the command as soon as the
pane was live, while the shell was still printing its greeting; the
Enter was eaten and the command sat at the prompt unrun. It is typed once
the shell's output has gone quiet now, or after six seconds whatever.

Rows also say where a tab is the same way whatever it is named.

* fix(mobile): the first screen says how to pair in one step

With no machine paired yet, it now says where the code is on the
computer and that the phone's camera reads it.

* fix(mobile): a tap that closes a pane's menu does only that

Closing the ⋯ menu by tapping the pane also brought the keyboard up for
typing into it. The tap that puts a menu away is the menu's now.

* fix(mobile): second pass from a phone user's seat

- Chinese, Japanese and Korean text rendered as boxes in the terminal:
  the glyph atlas does not fall back past the web fonts, so the system's
  CJK fonts are named in the stack.
- A tab opened from the phone was drawn at the desktop's width first and
  then squeezed: the gateway now holds it at the phone's size from before
  the desktop hears of it, until the phone's own view takes over.
- A tab opened with no folder started wherever the server did; it starts
  at home, and the new-tab sheet offers Home.
- Going back to a machine showed a skeleton every time; its last tree is
  drawn at once and refreshed when the watch reports.
- Errors said the transport's chain, repeated: each part is said once, and
  an unreachable machine is explained in words.
- Wide panes say once that they can run at the phone's size; a pane taken
  over is taken over again on return.
- Back in a pane's history, a button jumps to the latest output.
- Find hides the key bar and message box and keeps the match clear of the
  bar; Copy keeps the pane's lines and offers Copy all.
- The message box pans a wide pane back to the cursor; Changes outside a
  repository says so plainly; machine rows count waiting agents; the back
  pill folds to a chevron with the title; filled reds use the system red.

* feat(mobile): attachments wait as chips beside the message box

A sent file used to drop its full temporary path into the box, five lines
of /var/folders/... underlined by the spell checker. It now waits as a
chip with its picture and name, can be taken back before sending, and its
path goes after the message when it is sent.

* fix(mobile): pairing says what went wrong, and leaves the code alone

The code field offered word suggestions over the keyboard; it is a code.
A wrong, expired or unreachable code is explained with what to do next
rather than the gateway's lower-case reason.

* feat(mobile): hold a tab's row for what can be done with it

A long press used to open the pane like a tap. It now brings up the
row's actions: open, open at the phone's size, Changes, a new tab in the
same folder, copy the folder's path, and close.

* fix(mobile): a pane on its way shows that it is coming

Opening a pane over a slow link left an empty screen until its replay
arrived. After a quarter second without it, three dots say it is coming.

* fix(mobile): agent menus, stopped panes and new tabs, as used

- An agent's arrow-key menu with no numbers (Claude Code's 'trust this
  folder?') now gets answer buttons too; picking one moves to it and
  presses Enter.
- A pane that is not running greys out its keys and message box instead
  of taking typing that goes nowhere.
- Suggestions match where a word starts, so 'ls' no longer offers every
  message that mentions tools.
- A new tab's starting size counted neither the status bar nor the home
  indicator, so its last rows sat under the key bar.
- A tab opened on the phone keeps the phone's size on later visits, so it
  follows the keyboard instead of hiding behind it.

* fix(mobile): another agent waiting is not missed, and dismissing is only that

- The card for another agent that needs you stays until it is answered or
  put away (it went after 15 seconds); a finished one still goes on its
  own. While any other agent waits, the back button carries a dot.
- The card's dismiss, a banner's action and Jump to latest took themselves
  away under the finger, and the same tap then reached the pane and
  brought up its keyboard; a clear cover takes that tap now.
- A row's Current tag no longer gets cut to 'C...' by a long name.

* fix(mobile): Changes lists a new folder once, by name

The untracked list walked into every new directory — a generated folder
filled the sheet with thirty truncated paths. New directories come as one
entry, as git status shows them, and each entry reads as a name with the
end of its folder beside it.

* fix(mobile): bar buttons answer a 44pt square

Back, More, Close and the pane's round buttons are drawn at 38pt and took
taps only there, under the 44pt a finger is owed. Each now answers a 44pt
square around the same drawing.
2026-10-03 20:28:29 +08:00
l0ng-ai 99b9327fab feat(mobile): the desktop sidebar's groups, and the tab it has in front (#1073)
* feat(mobile): the desktop sidebar's groups, and the tab it has in front

A machine's tabs on the phone were one flat list per workspace. They now come in the desktop's groups, in its order: pinned groups, then one per repository or SSH host, then Ungrouped, each folding as on the desktop. The tab the desktop has in front reads Current.

The gateway places each tab as the sidebar does, from what the machine tree already keeps: a tab's pinned group, or else the repo the desktop last filed it under. The naming rules moved from the sidebar into tty7-core so both name groups alike. An older gateway sends no groups and the phone shows one list, as before.

* fix(mobile): group headers lead, and folded ones stack close

A group's header read the same as the workspace label above it, and a folded one kept the gap meant for rows under it, so folded groups sat far apart. Headers are now the darker, larger line at a tap target's height; only an open group keeps room after its rows.
2026-10-03 20:27:02 +08:00
l0ng-ai e38f450d1e feat(terminal): a message composer that covers agent CLIs' own input (#1066)
* feat(terminal): dock a message composer under agent panes

A multi-line text box docked at the bottom of a pane whose foreground is a
coding agent, for writing a prompt with the platform's own editing keys, mouse
selection and an in-place IME, then handing it over whole. Toggle with
Cmd+I (Ctrl+Shift+I off macOS) or "Toggle Message Composer" in the palette.

- Docks below the grid instead of floating over it, so the agent reflows into
  the remaining rows and nothing it draws is hidden.
- Enter sends, Shift+Enter inserts a newline, Esc hands focus back to the
  terminal without closing (so the next Esc still interrupts the agent).
- A message is written as text, then Enter as a separate write after a short
  settle. Multi-line text goes as one bracketed paste; Codex is always pasted
  (its burst detector swallows the Enter otherwise); a leading `!` reaches
  Claude Code as its own key so it switches to shell mode.
- Nothing is sent while the agent is waiting on a permission prompt or
  question; the box turns amber and keeps the message.
- Writes queue per pane and stop if the agent exits mid-send, so an Enter can
  never land in the shell.
- Pasted screenshots, copied files and dropped files reuse the terminal's
  existing path-pasting routes and land in the box when it has focus.
- Drafts and the open state survive the view being rebuilt.

Refs #842

* feat(terminal): give the composer a chat-box layout with attachments and / @ menus

- A rounded, tinted frame whose hairline darkens on focus and on a file drag,
  a toolbar row with an attach button and a round send button that fills in
  once there is something to send. The key hints move into the send button's
  tooltip; the placeholder names the agent and what / and @ do.
- Files become chips instead of words in the text: the attach button, a drop
  on the box, a pasted screenshot or copied file, and remote uploads all go
  through one paste_paths route that attaches while the box has focus.
  Backspace at the start of an empty caret removes the last chip. On send the
  paths follow the text as the shell words a drop would have typed.
- `/` at the start of the message opens the agent's built-in commands (Claude
  Code, Codex, Gemini) plus Claude's custom commands from .claude/commands;
  `@` at the start of any word opens files from the pane's project, reusing
  the quick-open walk so it works on remote hosts too, spelled relative to the
  pane's directory. Up/Down move, Enter/Tab pick, Esc dismisses.
- Shift+Tab is passed through to the agent to cycle its permission mode.
- Enter with nothing to send no longer sends a bare Enter.

No model picker, mode label or context meter: tty7 has no source for them
that would stay true, and /model is one keystroke away in the menu.

* feat(terminal): lay the composer over the agent's own input, with its toolbar

The composer now stands in for the agent's input instead of sitting under
it, so the pane has one input rather than two.

- For Claude Code, Codex and Gemini the box is laid over the input area it
  finds on the grid (Claude's ruled prompt block and the status rows under it,
  Codex's `›` line, Gemini's framed prompt), painted in the grid's background.
  When the agent puts something else there — a permission prompt, a picker —
  the area stops reading as an input; after a 250ms grace the box steps aside
  and the keyboard goes to the TUI, and both come back with the input. Other
  agents keep the docked layout.
- Over the input, Esc is the agent's (it interrupts), Ctrl+C clears the box or
  reaches the agent when the box is empty, and text typed at the grid lands in
  the box.
- The toolbar: permission mode (read off the status row the box covers, falling
  back to the hooks' permission_mode; click or Shift+Tab to cycle), model
  (click opens Claude's picker), Think (Claude's thinking toggle), and a context
  ring. Labels come only from what the agent reported.
- Claude hooks now carry an AgentReadout — permission_mode from the hook
  payload, the model and context size of the last main-thread reply from the
  transcript, the context window (1M for a [1m] model or past 200k), and
  alwaysThinkingEnabled — worked out in the hook so remote panes get it too.
- Visual pass against the design: 13.5px text with the design's padding
  (the input's own padding subtracted), a 40px toolbar of 28px buttons, a dark
  round send button, image chips with their own glyph.

* feat(terminal): replace the composer's Think toggle with an effort picker

The toolbar's thinking toggle is gone; reasoning effort is what the
agent actually exposes as a per-session dial. The button shows the level
Claude Code is set to (CLAUDE_CODE_EFFORT_LEVEL, else effortLevel from its
settings, reported by the hook) and opens a menu of low / medium / high /
xhigh / max. Picking one sends the agent's own /effort command, and the
label follows the pick until the next hook event confirms it.

* feat(terminal): open the composer's model and effort lists over their buttons, and seat the box where the agent's input starts

* style(terminal): align the composer with the design: bottom inset, hairline ring, effort label

* style(ui): draw the sidebar dividers as one-device-pixel hairlines

* fix(terminal): keep the composer's contents still when its ring thickens

* fix(terminal): let a click outside the composer keep the keyboard

* fix(terminal): a click beside the covering composer leaves it, as one on the grid does

* fix(terminal): paint the composer's lists over its ring, and give Effort its chevron

* fix(terminal): show the effort level alone, close toolbar lists on an outside click, read per-model effort

* fix(core): take the effort level Claude reports in the hook payload

* feat(core): send a Claude turn's context size once its transcript catches up

* Revert "feat(core): send a Claude turn's context size once its transcript catches up"

This reverts commit 3544bc6b172901977749c6d6041650ae3795be37.

* refactor(terminal): drop the composer's context gauge until there is an exact source for it

* fix(terminal): a paste at the grid goes into the composer covering the input

With the box laid over the agent's input, typing at the grid already went
into the box, but a paste (Cmd+V, a dropped or copied file) still went to
the pty — into the agent's own input, out of sight under the box, where the
next Enter would send it unseen. A paste now lands in the box the way
typing does, files as attachments, and takes the keyboard with it.

* fix(terminal): cover the agent's input from its top rule at any pane height

The covering layer measured its height up from the pane's bottom edge in
whole rows plus the padding, but the grid's rows start at the top: whatever
part of a row the pane's height leaves over sits between the last row and
the padding. At most heights that left the top of the covered area — Claude
Code's upper rule — showing above the box. The grid now records that
leftover and the layer counts it in.

* fix(core): report Claude's model and effort only when they are this turn's

The hook filled in the model from the transcript's last reply on every
event. That reply is the previous turn's: after a `/model`, or a resume
under another `--model` (a resumed session's SessionStart names none), the
toolbar showed the old model — and at `Stop` too, since Claude Code runs
the hook before the turn's reply is always on disk. The model now comes
from SessionStart, or at Stop from the reply that turn wrote: found after
the prompt the payload names, matching the words it carries, waited for
briefly. Nothing exact means nothing reported.

Effort likewise: the settings fallback only runs for a model the event
names (it may be set per model), and a turn that ends without a level ran
on a model that takes none, which the toolbar now shows as no level rather
than the settings' general one. A level picked from the toolbar gives way
to the agent's report once that changes, as a picked model does.

* fix(terminal): offer Fable in the composer's model list

Claude Code's `/model` list has Fable between Opus and Sonnet, and
`/model fable` takes it by that alias, but the toolbar's list left it out:
it could not be picked there, and a session running it had no row checked.

* fix(terminal): a toolbar pick holds only until the agent's next finished turn

A model or effort picked from the toolbar was shown until the agent
reported a different value. When the pick did not take — Claude asks
before switching a cached conversation's model, and "No, go back" keeps
the old one — the report never changed and the toolbar showed the refused
model for good; after the agent quit and a new session started on the
model the pick was made from, the stale pick came back.

A pick now stands until the next finished turn, which reports what the
agent actually ran on, and is dropped when the agent session changes.

* fix(core): keep agent hook sequences short

A hook reports to the pane by writing an OSC 777 sequence to the tty the
agent draws on. macOS does not keep a tty write whole: under output
pressure the kernel parks the writer mid-sequence and lets the other
writer in, so the agent's redraw lands inside our sequence, the OSC
breaks, and the rest of the JSON is printed on screen. The longer the
sequence, the likelier that is.

The prompt a turn starts with was the bulk of it on `prompt-submit` (up
to 200 characters, three bytes each for CJK), and nothing reads it any
more since the conversation outline went away. Stop sending it, and cap
the agent's message at a status line's worth.

* fix(core): hand agent hook reports to the daemon over its socket

An agent hook reported by writing an OSC 777 sequence to the tty the
agent draws on. A tty write is not atomic: on macOS the kernel parks a
writer whenever the output queue is over its high-water mark, which is
exactly when the agent is busy redrawing, and lets the other writer in.
The agent's output then lands inside our sequence, the OSC breaks, and
the rest of the JSON is printed on screen. A pty test with a busy
writer next to a small one splits even 100-byte writes, at arbitrary
offsets, so no size keeps the sequence whole.

The hook now sends the same JSON to the daemon that owns its pane
(`$TTY7_PANE`, over the pane socket `$TTY7_CONFIG_DIR` leads to), which
applies it exactly as if its reader had found it in the output. The
pane id comes from the environment, which a detached tmux server or
the like carries out of the pane, so the daemon applies a report only
from a process that runs under the pane's shell. Anything else — no
daemon, one that predates the message, a refusal — falls back to the
tty as before, which is still how a hook with no daemon beside it
reports.

* fix(terminal): offer /effort in the composer's command menu for Claude

The toolbar's effort picker types `/effort`, but the `/` menu did not
list it. Bring the list in line with current Claude Code while at it:
`/usage` replaces `/cost`, which is now only its alias, `/rewind` joins,
and `/agents`, which Claude Code has removed, goes.

* fix(terminal): step aside for Codex's own lists instead of covering them

Codex marks the selected row of its lists -- the approval prompt,
/model, /permissions, the hook review and the update offer at launch --
with the same `›` that starts its input line. The composer took that row
for the input and laid the box over the list, hiding the options the
user had to pick from. A `›` row that is a numbered option with sibling
options around it is now read as a list, and the box steps aside.

* fix(terminal): offer Codex's /permissions, not the retired /approvals

Current Codex no longer knows /approvals; the command that chooses what
it may do without asking is /permissions. Also offer /resume.

* fix(core): install Codex hooks into CODEX_HOME when it is set

Codex reads hooks.json from its home, which CODEX_HOME moves. tty7
always wrote and checked ~/.codex/hooks.json, so for such a user the
hooks it installed never ran, and the state it reported described a file
Codex does not read. Local-only, like the other config-dir overrides.

* fix(core): find the pane a Codex hook reports on from the report itself

Codex runs its hooks in its app-server, one background process every
Codex session on the machine talks to. The first session starts it, and
it outlives that session, detached. Its hooks therefore carry the first
session's $TTY7_PANE and run under that pane's shell only while that
session lasts. Once it ended, the daemon refused every Codex report as
coming from outside the pane -- and the tty fallback has no terminal in
a detached process -- so a Codex pane never showed working, waiting or
done. While the first session was still running, a second pane's
reports were taken as the first pane's.

A Codex report is now matched to its pane by what it says: the pane
that already reported its session, else the one pane running Codex in
its directory (the one yet to report a session, and the named pane on a
tie). Other agents' reports are unchanged.

* fix(core): install Gemini hooks under GEMINI_CLI_HOME when it is set

Gemini CLI roots its user-level .gemini directory at GEMINI_CLI_HOME in
place of the home directory. tty7 always wrote and checked
~/.gemini/settings.json, so for such a user the hooks it installed never
ran, and the state it reported described a file Gemini does not read.
Local-only, like the other config-dir overrides.

* fix(terminal): find Gemini's input in the shaded block it draws now

Gemini CLI no longer frames its input in a rounded box: it shades the
prompt line between a row of lower half blocks and a row of upper half
blocks, and with shading off it draws a rule over the prompt instead. The
composer looked only for the old frame, so over a current Gemini it
stayed stepped aside for good and never covered the input.

A message already sent is shaded the same way in the transcript, so the
block counts only with nothing but the footer under it; a permission
prompt or a list in the input's place leaves the last message above more
than that, and the box steps aside for it. The old frame is still found
for older versions, and the shell, YOLO and history-search marks count as
a prompt as well as `>`.

* fix(terminal): give Gemini time to read a paste before pressing Enter

Gemini CLI takes an Enter that comes within 40ms of a bracketed paste as
a line break. It starts that window once it has read the whole paste, so
the 50ms the composer left between the paste and the Enter was not
enough for a long message: a 41-line message sat in Gemini's input as
"[Pasted Text: 41 lines]" plus an empty line, hidden under the box, and
was never sent. Gemini now waits as long after a paste as Copilot does;
a 400-line, 32KB message goes through whole and is submitted once.

* fix(terminal): hand Gemini its attachments and mentions so it reads them

Three things kept files from reaching a Gemini turn from the composer:

- Attachments went after the text as shell words. Gemini turns a drop
  into @ mentions itself, but only a paste that is nothing but paths;
  after the message's text a path is just words, and the model never saw
  the file. Gemini now gets its attachments as the mentions it would have
  made.
- A mention picked from the @ menu was spelled raw. Gemini ends a mention
  at the first unescaped space, so "my notes.txt" became "@my". Mentions
  for Gemini are escaped the way its own escapePath does it.
- With the caret at the end of an @ word Gemini lists matching files, and
  Enter takes the list's pick instead of sending, so a message closed by
  a mention - every message with an attachment - sat in the input under
  the box, unsent. A message with a mention now ends in a space, which
  closes the list; slash commands are left alone.

* fix(terminal): offer Gemini's current commands in the composer's menu

Gemini CLI now names its session browser /resume, with /chat kept as an
alias, and /clear starts a new session rather than only clearing the
screen. Offer /resume under its own name, say what /clear does now, and
add /model and /init, which the menu left out.

* fix(terminal): paste messages to Gemini instead of typing them

Gemini CLI judges each key of a typed burst against its input as it was
before the burst, so to it the input is still empty at every key. A "?"
anywhere in a typed line is taken for the key that opens its shortcuts
on an empty input and dropped ("what? yes" arrived as "what yes"), and a
"!" for the one that switches it into shell mode, which also clears what
came before it: "hi! there" became a shell command " there", one Enter
away from running.

Gemini now gets every message as a bracketed paste, like Codex, with a
leading "!" still sent as a key of its own - as for Claude Code - so a
message that starts with one keeps opening shell mode.

* fix(terminal): spell a mention with a space the way Claude and Codex read it

A file picked from the composer's @ menu went in raw for Claude Code and
Codex, so "my notes.md" came out as "@my notes.md":

- Claude Code ends a bare mention at the first whitespace, so it looked
  for "my" and the file never reached the turn. A path with a space now
  goes in double quotes, @"my notes.md", the form Claude's own list puts
  in and its parser reads back as one file.
- Codex hands mentions to the model as plain text, and its own list puts
  in the path alone: without the @, in double quotes when it has a space
  in it. The composer now does the same.

Checked for real: Claude 2.1.286 with no tools answers from @"my notes.md"
and not from @my notes.md or @my\ notes.md; Codex 0.158's list inserts
"my notes.md". Attachments are unchanged; both agents read one with a
space in its path.

* fix(core): name tty7's Gemini hooks so Gemini shows "tty7" while they run

While a hook runs Gemini CLI shows "Executing Hook: <name>" above its
input, and a hook without a name is shown by its whole command - the
quoted path of the tty7 binary and its arguments. tty7's Gemini entries
now carry "name": "tty7".

An install from before reads as outdated - its hooks' names are checked
along with their commands - so the launch-time refresh and the settings
page's Update rewrite it in place, one entry per event as before. Other
agents' entries get no name and are judged as before.

* fix(core): show no effort level for a Claude model that takes none

A new Claude session names its model but not its effort level, so the
hook fell back to the settings' level - and a session started on Haiku
showed "High" until its first turn ended. The hook now checks Claude
Code's own model catalog (its cache, read only) first: a model it lists
without effort options is reported with an empty level. A model it does
not list, or no catalog at all, falls back to the settings as before.

* fix(terminal): paste messages to OpenCode and Amp instead of typing them

OpenCode reads a burst of typed keys against the input as it was before
the burst, the way Gemini does: the `!` in "PONG! ok" switched it into
shell mode and the rest of the line ran as a shell command. Amp takes a
typed leading `?` for its shortcuts key and drops it, and a typed
leading `/` opens its command palette while the rest of the burst lands
in the input underneath, so Enter ran whatever the palette listed first.

Both now get every message as one bracketed paste, which each reads
intact and sends on the Enter that follows. A leading `!` still reaches
OpenCode as a key of its own, the only way it switches into shell mode;
Amp reads its `$` shell prefix off a paste.

* fix(terminal): stand the docked composer as far in from the bottom as from the sides

Docked under the grid, the box sits inside the pane's padding, and only
the side inset took it off: the box stood 20px up from the pane's bottom
and 16px in from its sides, where it covers an agent's input 16px from
all three.

* fix(terminal): offer OpenCode's commands in the composer's menu

OpenCode takes slash commands typed at its input, pasted ones included,
but the composer's `/` menu listed none for it and its placeholder left
out the commands hint. List the ones its own menu opens with, in its
words. Amp keeps an empty list: its `/` opens a command palette that a
message cannot drive.

* fix(terminal): hand OpenCode and Amp their attachments as pastes of their own

Both attach an image only from a paste that is nothing but its path; a
path after the message's text stays words, so an image attached in the
composer never reached the model. They now get the text, then each path
as a paste by itself after a typed space, and Enter once the last one has
had time to land. OpenCode shows the file as a part of the message and
Amp lists it under Images, as a drop onto their own input would.

* fix(terminal): don't answer pixel-size queries from a replayed pane

A reattach replays the pane's ring through the grid with query replies
muted, but the mute list missed `TextAreaSizeRequest`: alacritty hands
`CSI 14t` to the listener as its own event (the view owns the pixel
size) rather than as a `PtyWrite`. Every `CSI 14t` a TUI had sent was
answered again on each app restart, and the `CSI 4;h;w t` replies landed
on whatever reads the pane now — at a shell prompt, after the TUI that
asked had quit, zsh printed them as `;840;873t;840;873t...`.

Mute it with the other replies; live queries are still answered.

* fix(core): don't let a hook wait on a terminal whose pane has gone

An agent's session-end hook that falls back to the tty after its pane
closed opened the terminal device blocking. With the pty's other end gone
that open waits for a carrier that never comes, and on macOS it waits
holding the lock every lookup under /dev needs: the hook never exits, the
agent cannot finish exiting, and every new shell, ps and tty on the machine
hangs behind them until the hook is killed.

Open the device without waiting, then switch it back to blocking writes so
a busy terminal still gets the whole sequence; a terminal with no other end
fails the write at once.

* fix(terminal): paste messages to Copilot instead of typing them

Typed into Copilot's empty input, a leading `?` is the key that opens its
help: "?why" went out as "why". Paste every message, as for Codex and
Gemini. Copilot still reads a pasted leading `!` as its shell mode, and
already got the longer wait before Enter that a paste needs.

* fix(terminal): speak to Qwen Code the way Gemini is spoken to

Qwen Code is a fork of Gemini CLI and kept its input, but the composer
treated it as an agent with none of Gemini's traps:

- a typed leading `?` opened its shortcuts and was lost;
- a message closing on an `@` mention sat in the input, its Enter taken
  by the file list;
- a mention or attachment with a space in its path went out as words it
  cannot read back.

Give it Gemini's handling: pasted, with the shell-mode `!` as a key of its
own, a space after a closing mention, the longer wait before Enter, and
attachments and `@` picks spelled with Gemini's escaping, plus the comma
Qwen escapes too.

* fix(terminal): leave Copilot's file list behind before pressing Enter

With the caret at the end of an `@` word Copilot lists matching files, and
Enter takes the list's pick instead of sending, so a message that closed on
a mention (one picked from the composer's own `@` menu ends that way) sat in
Copilot's input unsent. End such a message with a space, as for Gemini.

* fix(terminal): hand CodeBuddy a leading `!` as a key of its own

CodeBuddy switches into bash mode only on a `!` typed into its empty input
by itself, as Claude Code does. Arriving in one burst with the rest of the
line it is just a character, so "!git status" went to the model as a
request to run the command, behind a permission prompt.

* fix(terminal): paste messages to Kimi Code so they are sent

Kimi Code takes keys arriving faster than anyone types for an unbracketed
paste, and the Enter right behind a typed line for one of its newlines: a
one-line message from the composer sat in Kimi's input with an empty line
under it, never sent. Paste every message instead. Kimi knows a bracketed
paste for one, sends on the Enter after it at once, and still reads a
pasted leading `!`, `?` or `/` as typed.

* fix(terminal): spell a mention with a space the way Kimi Code does

Kimi Code's own `@` list puts in a path with a space as `@"my notes.md"`,
the way Claude Code spells it. The composer's menu put in `@my notes.md`,
which Kimi reads as a mention of `my` followed by a word.

* fix(terminal): offer Copilot's, Qwen Code's, CodeBuddy's and Kimi Code's commands

All four take typed slash commands, but the composer knew none of them: `/`
opened no menu and the placeholder offered only `@` files. List each one's
everyday commands as its installed version names them: Copilot CLI 1.0,
Qwen Code 0.24, CodeBuddy Code 2.161 and Kimi Code 2.1, which has `/new`
rather than `/clear` and `/permission` in the singular.

* fix(terminal): hand Copilot and CodeBuddy their attachments as mentions

Copilot and CodeBuddy attach a file only from an `@` mention, and a path
after the message's text is just words to them: an attached image reached
neither model, which had to go and read it with a tool, behind a prompt.
Send each attachment as an `@` mention instead, which both attach to the
turn, an image as an image. Neither reads a mention back past a space, so
a path with one still goes as quoted words.

* fix(core): import Pi's extension types from its current package

Pi moved from @mariozechner/pi-coding-agent to
@earendil-works/pi-coding-agent. Current Pi resolves both names for
extensions, and the bridge's import is type-only, so it is erased before
an older Pi that knows only the old name loads it. A bridge already
written with the old name reads as stale and launch's refresh rewrites it.

* fix(core): keep Pi and Oh My Pi panes working through retries and approvals

agent_end closes every attempt, so a run Pi retries after a provider
error read as done while it was still retrying. The bridge now takes
Pi's agent_settled as the end of a run when the build sends it, and
Oh My Pi's auto_retry_start puts the pane back to working.

Oh My Pi asks before running a tool through tool_approval_requested and
tool_approval_resolved, not Pi's UI-prompt pair, so its pane said
working while the approval dialog waited. Those now report waiting and
restore the turn.

* fix(core): take Prime Agent's hook reports from its background daemon

Prime Agent runs each session in a detached daemon, started by the first
session and outliving it, and the daemon runs tty7's bridge there with
the environment of the TUI that asked for the session. The report names
the right pane, but its process never runs under that pane's shell, so
the daemon turned every one away and a Prime Agent pane never left idle.

A report about Prime Agent is now taken by the pane it names when that
pane is running Prime Agent.

* fix(terminal): lay the composer over Pi's own input

The box docked under Pi's pane, so Pi's own ruled editor and its status
rows stayed on screen above it: two inputs. Pi now gets the covering box
Claude, Codex and Gemini have. Its editor is the lowest pair of
full-width rules — the upper one carries the spinner while a turn runs —
with the directory and usage rows under it, and the box covers from the
upper rule down. Pi's selectors take the editor's place between the same
rules but open on a blank row (or, for /settings, on a `>` search line)
and run on for several, so the box steps aside for them and comes back
once they close.

* fix(terminal): offer Pi's, Oh My Pi's, Prime Agent's and Grok Build's commands

All four take typed slash commands, but the composer knew none of them:
`/` opened no menu and the placeholder offered only `@` files. List each
one's everyday commands as its installed version names them — Pi 0.99,
Oh My Pi 18.4 (`/exit`, `/retry`, `/todo`), Prime Agent 0.9 (`/effort`
rather than Pi's `/thinking`) and Grok Build 1.0 (`/mcps`, `/recap`).

* fix(terminal): lay the composer over Oh My Pi's own input

The box docked under Oh My Pi's pane, so its own input stayed on screen
above the box. Oh My Pi now gets the covering box too. In its default
status-band shape, and in the rounded box, the input's first line opens
with `╰─ ` under the status line, and the box covers from that line
down; a dialog frame closes with `╰──…╯` and a tool approval or picker
takes the input's place, so the box steps aside for those. Its Pi and
Claude Code shapes are ruled like Pi's input and found the same way.

That input is two rows, where the box is about five, so laid over it the
box hid the last lines of the reply. For Oh My Pi the grid now gives up
the rows the box needs beyond the input, measured off the box as drawn
empty, and the agent draws its input that much higher.

* fix(terminal): lay the composer over Prime Agent's own input

The box docked under Prime Agent's pane, so its own shaded input block
stayed on screen above the box. Prime Agent now gets the covering box
too: its input is a blank row, the ` >` prompt line with any further
lines indented under it, and another blank row, right over the footer
that ends the screen. The model picker draws its own ` >` search line
between rules, away from the footer, so the box steps aside for it.

The block and footer are a row shorter than the box, which cut the hint
line above it in half; the grid makes room for that row as it does for
Oh My Pi.

* fix(terminal): lay the composer over Grok Build's own input

The box docked under Grok Build's pane, so its own framed input stayed on
screen above the box. Grok Build now gets the covering box too: its input
is the rounded frame whose first line opens with `❯`, with the key hints
under it. Its `/` and `/model` lists open over the frame between two
rules, and its dialogs are drawn across the frame's top edge; the box
steps aside for both, since they take the keys the box would send.

Grok Build keeps a command whose list was dismissed in its input, where
under the box nobody sees it and the next message was typed on after it:
`/modelReply …`. With text left there, the box now clears it with Ctrl+U
before sending.

* fix(terminal): spell mentions the way Pi and its forks read them

Pi, Oh My Pi and Prime Agent end a bare `@` mention at the first space,
and their own `@` lists put a path with one in double quotes,
`@"my notes.md"`; the composer put it in bare, so the mention named a
file that does not exist. Grok Build's list puts the path in as it is,
which the composer already did.

Oh My Pi reads a mentioned file — an image included — into the turn
itself, where a path in the message is just words for the model to go
and read, so its attachments now go as mentions.

* fix(terminal): send Oh My Pi, Grok Build and Prime Agent messages that end in a mention

Oh My Pi's and Grok Build's `@` lists open on a mention at the caret and
take the Enter that follows, so a message whose attachments or mention
closed it sat in their input, under the box, unsent. Like Gemini's and
Copilot's, their messages with an `@` now go with a space after them.

Prime Agent's list opens as a typed mention is typed and stays open past
the space after it: "read @a.txt " went out as "read @a.txt .git/". A
paste it reads whole, `!` and `/` included, so its messages are pasted.

* fix(terminal): stop a Grok Build turn with its own interrupt key

Esc in the box covering an agent's input is that agent's Esc, the key
that stops a turn. Grok Build's Esc leaves a running turn running — its
stop key is Ctrl+C — and the daemon, reading any Esc during a turn as
an interrupt, then called the pane done while Grok still worked. The
box now sends Grok Build Ctrl+C, and the daemon no longer counts an Esc
as stopping a Grok Build turn.

* fix(core): don't start a turn from a notification's waiting status

Before an agent's first hook, a desktop notification marks its pane
waiting. Crush raises one after every turn ("Agent's turn completed"), and
its only hook, PreToolUse, is reported as a finished tool, which moves a
waiting pane back to working: from the first tool of a session on, the
pane read as working for good, as Crush has no Stop to end it.

A status set by a notification now gives way to idle when the first hook
report arrives, so the report only records the session and its activity.

* fix(terminal): take only a hook's word that the agent is asking

The box stands aside and sends nothing while the pane's agent is waiting,
since whatever it sent would answer the question on screen. For an agent
without hooks — Amp, or Crush before its first tool — the pane is marked
waiting by any desktop notification, "Agent is ready" at the end of a turn
among them, and it stays marked. From the first finished turn on the box
stood aside for good, and messages went into the agent's own input
instead.

Waiting now holds the box back only when hooks reported it. Those agents'
own dialogs take their input's place on screen, and the box steps aside
for them off the screen as for any other.

* fix(terminal): offer Goose's commands in the composer's menu

Goose takes typed slash commands — /model, /mode, /compact, /clear and
the rest of what its /help lists — but the box's `/` menu was empty for
it. It now lists them, as Goose 1.52 names them.

* fix(terminal): stop a Crush turn with the two Escs it asks for

Crush takes a first Esc during a turn as a question — "esc press again to
cancel", in its key help — and stops only on a second one. Over its input
the box's Esc sent one, the question sat in the help under the box where
nobody read it, and the turn ran on. For Crush the box now sends both,
as separate writes: in one read the two are a single key to it.

* fix(terminal): lay the composer over Crush's, Goose's and Amp's own input

The box docked under these agents' panes, so their own inputs stayed on
screen above it: two inputs. They now get the covering box too.

- Crush's editor opens on its `> ` prompt (`!` in yolo mode, `:::` while
  the chat has the keys) with each further line on `:::`, over a blank row
  and its key help. Its dialogs — the command palette, the model and
  session lists, a permission request — are framed over the screen with the
  editor left standing under them, and take the keys, so with a frame on
  screen the box steps aside.
- Goose prints its `> ` prompt under its context gauge, as the last thing
  on the screen, wherever its output ended. A turn's spinner and output,
  and a tool approval, are printed under the line sent, and the box steps
  aside for them until the next gauge and prompt. Its input is two rows
  where the box is about five, so the grid gives up the rest, as it does
  for Oh My Pi.
- Amp frames its input at the bottom of the screen, its mode in the top
  edge and the directory in the bottom one. Its palette and file list open
  framed and indented over the screen, and a notice in the input's place
  (out of credits) is a frame with nothing in its bottom edge; the box
  steps aside for both.

Text typed into one of these inputs before the box was opened over it
stays there, unseen, and the next message would run on after it. With
text left there the box now empties it first, a line at a time with
Ctrl+U and Backspace, as it empties Grok Build's with Ctrl+U.

* test(core): keep the closed-terminal write test from racing other tests' children

`a_terminal_with_its_other_end_gone_fails_the_write_at_once` failed about
one run in three alongside the other hook tests (never on its own): its
pty came from `openpty`, whose descriptors are inherited, and the Qoder,
CodeBuddy and Crush config tests spawn children on threads of their own.
A child that took a copy of the pane's end kept it open after the test
closed it, and the write went through.

Open both ends close-on-exec from the start, and since a child forked a
moment earlier still holds a copy until it gets to exec, retry a write
that went through after a short pause; every attempt must still return
within the timeout, which is what the test is for. 50 runs of the hook
tests in parallel now pass, where 13 of 40 failed before.

* fix(terminal): lay the composer over Copilot's, Qwen Code's, CodeBuddy's, Kimi Code's and OpenCode's own input

The box docked under these agents' panes, so their own inputs stayed on
screen above it: two inputs. They now get the covering box too.

- Copilot, Qwen Code and CodeBuddy rule their input off top and bottom,
  the prompt (`❯`; `>`, `*` or `!`; `>`) on the line right under the upper
  rule and the status rows under the lower one. Their approvals and
  pickers come framed or between rules of their own with the question on
  the first line, and their `/` and `@` lists open under the lower rule or,
  Copilot's, right over the upper one; the box steps aside for them. Qwen
  Code is drawn as Gemini's ruled input once was, but Gemini's looser test
  takes the `> model` row of Qwen Code's own `/` list for the prompt, so
  it gets the stricter one.
- With true colour Copilot shades its input instead — a `╻▄▄▄` and a
  `╹▀▀▀` edge around lines on a `┃` bar — and draws its lists shaded over
  it, the selected row opening with `❯ /`; a sent message has the time at
  its end.
- Kimi Code frames its input over its model line and context gauge. Its
  lists open under the frame, its approvals take the frame's place, and
  its welcome banner is a frame far up the screen.
- OpenCode draws its input on a bar closed by a `╹▀▀▀` edge over its key
  hints, in the middle of its home screen and at the bottom of a session.
  Its lists open on the same bar, each row closed by a `┃` at its right,
  and a permission request takes the input's place with no edge.

Text typed into one of these inputs before the box was laid over it is
emptied first, a line at a time with Ctrl+U and Backspace, placeholders
and offered suggestions not counted. CodeBuddy takes keys that arrive
together for a paste and does none of them, so it is sent them one at a
time.

* fix(terminal): take Qwen Code and CodeBuddy out of shell mode before a plain message

A `!` message is a shell command to Qwen Code and CodeBuddy, and both stay
in their shell mode after it has run, their prompt a `!`, until Esc takes
them out. The next message from the box ran as a command too
(`bash: ?: command not found`), and a second `!` message toggled the mode
off and went to the model.

With the box over the input, the prompt says which mode it is in: a plain
message now leaves shell mode with Esc first, and a `!` message sent in
it drops the `!` that would toggle it off. CodeBuddy's `!` prompt counts
as its input, so the box no longer steps aside for it.

* fix(terminal): paint the layer under the covering composer in the agent's own background

The layer laid over an agent's input was painted in the theme's
background. Grok Build, OpenCode and other agents that paint the screen
in a colour of their own were left with a strip of the theme's colour
around the box — a light band under Grok Build's dark screen.

The layer now takes the colour the agent paints the row over its input
in (the one most of its cells have), over the grid's columns only; the
pane's padding around them keeps the theme's. An agent that leaves the
terminal's own background, as Claude Code, Codex, Kimi Code and Copilot
do, keeps the layer as it was.

The box's own fill was a faint tint of the text colour, which showed
whatever was under it: on Grok Build's dark layer the box went dark and
its text could not be read. It is now that tint laid over the theme's
background, the same colour as before on the theme's own background.

* fix(terminal): lay the composer over Qoder's own input and speak to it the way Gemini is spoken to

Qoder (both the global and the CN build) docked the box under its pane,
its own input left standing above it: two inputs.

- Its input sits between the last two full-width rules, opening with
  ` > ` (` * ` in YOLO mode, ` ! ` in shell mode), with only its model line
  under the lower rule. Over the upper rule its mode line has a rule of its
  own, with the `? for shortcuts` hint above it; the box covers those too.
  Its `/` and `@` lists open under the lower rule with the selected row
  opening with `❯`, and its trust and sign-in prompts, `/model` and `/help`
  open under a single rule with no prompt; the box steps aside for them.
- It is a Gemini CLI fork and kept that input: keys in a burst are read
  against the input before the burst (`echo hi` typed came out
  `echo hiecho hi`), a typed leading `?` opens its shortcuts, the Enter
  right behind a paste is a newline, its `@` list takes an Enter that comes
  right after a mention, and its list spells a path with a space
  `@my\ notes.md`. It now gets Gemini's handling of all of these.
- Like Qwen Code it stays in shell mode after a `!` command; a plain
  message leaves it with Esc first. Text left in its input is cleared with
  Ctrl+U and Backspace. Its `/` menu offers its current commands.

* fix(terminal): pick OpenCode's mentions from its own @ list so the files are attached

OpenCode attaches a file to a message only when it was picked from its
own `@` list (or handed over by an editor); the text of a mention is just
words to it. `@my notes.md` from the box, and `@plain.md` as well, reached
the model as text, which went looking for the file with its tools — and
the one with a space it had to find by globbing.

A message for OpenCode in a local pane is now cut at its `@` mentions of
paths that exist under the pane's directory (the longest run of up to four
words that names one), and each is sent the way a pick is made: a typed
`@`, the path pasted as the query with its spaces left out (a space would
close the list), and Enter once the list has had time to search. OpenCode
then shows `File  my notes.md` under the message. A space typed after it
closes a list that found nothing, so the Enter that sends is not taken by
it. An `@` that names nothing, commands and shell lines go as before.

* fix(terminal): cover Gemini's mode line and shortcuts hint along with its input

Gemini CLI 0.62 draws a mode line ("Shift+Tab to accept edits", "shell
mode enabled") over its input, with a rule of its own over it and the
`? for shortcuts` hint above that. The box covered the input from its
shaded block (or the rule right over its prompt) down, so the hint, the
rule and the mode line were left standing over the box.

The box now covers from the rule over that mode line, and from the hint
when it is there — the way it already does for Qoder, which draws the
same block; the two share the lookup. An input without a mode line over
it is covered from its own top as before.

* style(core): settle the clippy warnings the interrupt-key reader brought in

`is_interrupt_key` is only asked by the tests since the Grok Build change
went through `interrupts`, and two `let … else { return None }` read the
kitty-protocol key; the first is test-only now and the other two use `?`.

* fix(terminal): a screenshot pasted into the composer becomes an attachment

* fix(terminal): keep the composer's reserved rows, pastes and screen scans in line with the box

Scrolling back no longer resizes the pane, outside pastes land in the box
when it covers the input, the screen is scanned only while the box is open,
the command scan stops 8 directories deep, effort labels capitalise by
character, and two doc comments sit on their own items again.

* fix(core): route Codex reports past /new and codex -C, trust agent_settled only once seen

A session /new started goes to the Codex pane that had one; a report from
a directory no pane runs Codex in is matched among every Codex pane instead
of falling back to the app-server's. The Pi bridge no longer reads a
returned function from on() as proof agent_settled will come, and the Stop
hook re-reads the transcript only once it has grown.

* refactor: carry a session's source on AgentEvent and tidy the review fixes

The Codex router reads source off the parsed event instead of parsing the
hook body again. The command scan reads each real directory once rather than
capping depth, labels capitalise through one helper (alias_label no longer
slices bytes), the live input rows are set where Covering is decided, and
the transcript is opened once per poll.

* fix(terminal): read Claude's custom commands through Host

The scan reached std::fs directly, which the host-boundary check rejects;
it now walks the pane's host, joining and canonicalizing through it, and its
test covers a link back up the commands tree.
2026-10-01 23:46:26 +08:00
c361bd71e8 feat(panel): CPU% and memory per process, and a total, in Info → Processes (#1064)
* feat(panel): CPU% and memory per process, and a total, in Info → Processes

The daemon adds rss, cpu_ns and a start stamp to each ProcEntry (serde
default, so an old daemon or GUI skips them). The GUI turns two CPU-time
samples into a ps-style % and sums both into a Total line. `tty7 procs`
gains an RSS column.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(panel): no CPU% across a poll gap, and test CPU time is in ns

A new poll chain starts after the panel was shut or the pane changed;
comparing against the sample from before the gap showed a long-run average
as the current figure. Reset the tracker so the first round shows a dash.

Replace the self-usage test's cpu_ns > 0 (fails on Linux before the first
10 ms tick, passes unconverted mach ticks) with a check that the process's
CPU time covers this thread's own burned CPU time.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-01 15:18:27 +08:00
e1f93704fe fix(sidebar): Move to Group is a submenu listing every sidebar group (#1063)
* fix(sidebar): Move to Group is a submenu listing every sidebar group

The tab menu's Move to Group listed only pinned groups, laid out flat on
the grounds that there are never many. A sidebar that auto-groups by repo
holds dozens of groups, none of which could be picked. It is now a submenu
with every group the sidebar draws, in sidebar order, the tab's current one
checked, then Ungrouped (back to auto grouping) and New Group. Picking an
auto group pins it, as its header's pin does, and keeps the tab there.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(sidebar): Move to Group review fixes

- Ungrouped row replaced by Remove from Group, enabled only for a tab kept
  in a group; move_targets is pure (no locale lookup) over GroupKey.
- move_tab_to: an auto group is pinned with the tab in one edit
  (pin_auto_group_with), gpui-tested.
- A separator splits pinned from auto groups; targets are taken before the
  submenu borrows cx.
- No CHANGELOG hunk; the description carries it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(sidebar): Move to Group comment and pin_auto_group_with tidy

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(sidebar): Move to Group's labels line up with the tab menu

One left-checked row makes gpui_component reserve a check column on every
row of that menu, so the whole submenu sat an icon's width right of the tab
menu it hangs off. Putting the check on the right keeps the labels at the
parent's inset.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(sidebar): pinning a repo whose folder is kept joins the kept group

A tab dragged out of a folder group while still in the repo is drawn
under the repo's auto group, beside the folder group keeping the same
directory. Move to Group lists both; picking the auto one (or its
header's pin) pushed a second folder group on the same path, two
identical headers splitting the folder's tabs by list order. Join the
kept group instead, as pin_folder already does.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-01 15:18:06 +08:00
384a329df7 feat(terminal): program notifications follow the policy; read kitty OSC 99 (#1062)
* feat(terminal): program notifications follow the policy; read kitty OSC 99

OSC 9/777 notifications used to post from the reader thread regardless of
focus or the Never setting, and clicking one revealed nothing. They now queue
for the view, which applies notify_on_command_finish (Unfocused holds one back
only while its pane is focused in the key window), posts it clickable for the
pane, and titles it with the agent's name when it brings none. A pane whose
agent reports through tty7's hooks skips the copies the hooks already cover.

Kitty's OSC 99 is read too, chunked by i= with d=/p=/e=, in the client and in
the daemon sniffer, so a hookless agent's kitty notification marks it Waiting.
Claude Code's ghostty, kitty and iterm2 Notifications channels all land here;
its default, auto, sends nothing under TERM_PROGRAM=tty7.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(terminal): agent hook notices follow the per-pane rule

An agent's Waiting and Done notices from tty7's hooks were only posted while
the window was in the background, so an agent in another tab of the front
window never reached you. They now share shows_notification with program
notifications: Never posts nothing, When unfocused holds a notice back only
while its pane is focused in the key window, Always always posts. A hooked
pane still skips its program's own copies, so nothing doubles.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Revert "feat(terminal): agent hook notices follow the per-pane rule"

This reverts commit 7df400043c. The hook
notice change is a behaviour change of its own and moves to the stacked
branch upstream/hook-notices-per-pane.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* refactor(terminal): NotifyMode::allows, a Note type, and a cap on queued notes

One rule for every notification path: a mode allows a notice unless it is
Unfocused and the reader is watching. Kitty's pending chunks and a
finished note get names instead of tuples, and a pane whose view is not
polling keeps only its newest eight notes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(changelog): drop the Unreleased entry; the release notes carry it

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): a burst of program notes shows its newest three, and an exiting shell's are shown

`take_osc_notes` hands over the newest three queued notes and drops the
rest, so a program that writes a burst doesn't spray the desktop. The view
shows them ahead of `poll_foreground`'s exit check, so what a program said
just before its shell exited still gets through.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* refactor(terminal): one cap on queued program notes, three

The queue kept 8 and `take_osc_notes` then handed over the newest 3: two
caps for one rule. The queue now keeps 3 and `take_osc_notes` drains it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(terminal): at most five program notes per pane every ten seconds

The queue cap applies between polls, so a pane that keeps writing
notifications still posted a few every 300ms. Each pane now has a
NoteBudget: at most five notes per ten seconds reach the desktop, and the
rest are dropped and said once, as "More notifications from this pane
weren't shown", when the window turns over. The budget is asked on every
poll, held-back ones included, so that note comes even after the flood
stops and never for a count gone stale.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): kitty control payloads and id-less chunks don't build a note; OSC 9;10-12 aren't notes

A p=close, p=alive or p=? with the id of an unfinished OSC 99 note
finished and posted it. They are commands about notifications, so they
now leave pending notes alone. Chunks without an i= are each their own
notification per the spec, and no longer join an earlier id-less d=0
chunk. ConEmu's OSC 9;10, 9;11 and 9;12 (a prompt mark some shells emit
every prompt) were posted as notifications; they are subcommands like
9;1-9;9.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-01 15:17:44 +08:00
1d76051959 feat(terminal): tell a pane's program when the theme turns light or dark (DEC 2031) (#1061)
* fix(terminal): tell a pane's program when the theme turns light or dark (DEC 2031)

Claude Code's `theme: auto` reads OSC 11 at startup and re-reads it only
when the terminal sends `CSI ? 997 ; 1|2 n`, which it asks for with
`CSI ? 2031 h`. tty7 ignored 2031, so a running Claude kept its light diff
colours after a flip to dark. Track 2031 per pane (and across reattach),
push a 997 when the theme's background changes, and answer `CSI ? 996 n`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(terminal): report the colour scheme on reattach; review cleanups for DEC 2031

A pane reattached with 2031 on now hears the current scheme once the
replay is folded, so a theme flip while it was detached still reaches
the program. report() uses the presets' is_dark, watch reads
view.terminal directly, TRACKED lists 2031 inline, and the gpui test
moves into view.rs's gpui_tests harness with a reattach case.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(changelog): drop the Unreleased entry; the release notes carry it

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): one scheme report per reattach, not one per replayed frame

A replay is a modes Snapshot plus one Snapshot per ring segment, and each
sent its own 997. The Snapshot arm now only folds and flags; the report
goes out once, on the first frame after the replay. The tests use the
harness's next_input_until_timeout instead of a reader thread, and the
reattach test replays two Snapshots.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): send the reattach scheme report when the replay has been read

It went out on the first frame after the replay, so an idle pane, with no
live frame coming, never heard it. It is now sent once the reader's buffer
drains. TRACKED keeps its one line and names `COLOR_SCHEME_UPDATES` rather
than repeating 2031. The reattach test replays Snapshot, Size, Snapshot,
Snapshot with nothing after.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): a shell prompt ends DEC 2031, so a dead program's mode never reports into the shell

A program that switched 2031 on and died without `?2031l` left the mode on
in the pane's tracked modes, its ring, and the client's fold. A reattach
replay then still ended with 2031 on, so the reader sent its post-replay
report, and every theme flip sent another, into the shell's command line.

`TerminalModes` now drops 2031 on an OSC 133 `A`, `B` or `D` mark: the
shell owns the terminal again, so whatever asked for reports is gone.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): send the reattach scheme report after the replay, not at a read boundary

The reattach report went out whenever the reader drained what it had read.
An 8 MiB ring arrives over many reads, so a read that ended after the ring
segment holding a dead program's `?2031h` and before the one holding the
shell prompt that ended it typed `CSI ? 997 ; n` into the shell. The report
now waits for the first frame past the ring (the replayed Prompt, Cwd and
the rest, or live Output once it is folded).

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-01 15:17:22 +08:00
Adam HitchcockandClaude Opus 5.5 ac5f20dfa7 fix(themes): accept integer colour components in .itermcolors files (#1059)
* fix(themes): accept integer colour components in .itermcolors files

iTerm2 and plistlib write exact 0 and 1 as <integer>, which the loader
rejected, dropping the whole theme.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(changelog): drop the Unreleased entry; the release notes carry it

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 15:17:01 +08:00
b63a4ebbe0 fix(ui): selecting a sidebar tab scrolls only as far as the nearest edge (#1060)
* fix(ui): selecting a sidebar tab no longer scrolls the list

activate() called sidebar_scroll.scroll_to_item(tab_index), but the
sidebar list's children are group blocks and dividers, not tab rows, so
the index named some other group and a click on a lower row jumped the
list. The row now brings itself into view when it is drawn: a row with
any part on screen stays put, one out of view scrolls in to the nearest
edge.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(ui): key the sidebar reveal by tab id and drop it when the row is not drawn

An index went stale when tabs were reordered or closed before the next
frame, and a reveal aimed at a row in a folded group fired whenever the
group was opened, long after the tab was selected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(changelog): drop the Unreleased entry; the release notes carry it

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(ui): a first row revealed from above brings its group header

When the sidebar scrolled a row in from above, the row landed on the top
edge with its group's heading still cut off above it, so the tab came into
view without the name of the group it is in. The first row of a group that
draws a header now counts the header (and the gap under it) as part of
itself when coming in from above. Rows on screen and rows below are
unchanged.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-01 14:58:11 +08:00
l0ng-ai 4e4789a045 fix(links): peel a CJK label off a path glued behind it (#1053)
An agent reporting a file it wrote prints `原型:/tmp/a.html` or
`原型:/tmp/a.html` with no space. The label rule only accepted ASCII
labels behind an ASCII colon, so the whole token was read as a relative
path and the click reported it missing under the pane's directory.

Accept any alphabetic label, one character long when it is not ASCII,
behind either colon. A single ASCII letter stays a Windows drive.
2026-10-01 00:17:43 +08:00
l0ng-ai 7e918f3a89 fix(editor): ⌘W on an empty editor closes the editor, not the terminal (#1056)
Closing the last file left nothing in the editor panel to hold the focus,
so it fell back to the terminal pane and the next ⌘W closed the terminal
instead of the empty editor.

The empty panel now has its own focus handle: it takes the focus over in
the frame after its last file closes (only for the tab whose editor had
it), and a click on it focuses it. ⌘W from there, or from the file tree
an empty ⌘⇧E hands the focus to, hides the panel and returns the focus to
the terminal. With the focus in the terminal, ⌘W is still the terminal's.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-10-01 00:17:39 +08:00
l0ng-ai fa3d777c29 feat(release): ship a native Windows ARM64 build (#1043)
Release and nightly now build the desktop app for aarch64-pc-windows-msvc
alongside x64, publishing tty7-<version>-windows-arm64-setup.exe and
tty7-<version>-windows-arm64.zip.

- Cross-compiled on the x64 Windows runner, like server-windows' ARM64
  leg, and marked experimental until it has shipped once: a failure drops
  the ARM64 packages instead of holding up the release.
- Vendors Microsoft's arm64 ConPTY pair from the same package version as
  the x64 one, so ARM64 panes keep the OSC 11 fix (#345).
- Each Windows package bundles the WSL server for its own architecture.
- The installer's architecture comes in as a define: x64compatible for the
  x64 build (still installable on ARM64 under emulation), arm64 for the
  native one. One AppId, so either upgrades the other.
- The in-app updater on an ARM64 build asks for the arm64 packages; an x64
  build under emulation keeps taking x64 ones.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 22:04:46 +08:00
l0ng-ai d40233b572 feat(tabs): keep recently closed tabs in the machine tree, and a confirm-before-closing setting (#1037)
* feat(tree): keep each workspace's recently closed tabs in the machine tree

A workspace now keeps the tabs closed from it in its machine tree
(`Workspace::closed`), so reopening one no longer depends on the window
that closed it still being open.

- `TabCloseRemembered` closes a tab into that list: the tab leaves the
  workspace as a close takes it (other windows hear `TabClosed`), its panes
  are stopped with their last screens kept on disk, and their records stay
  in the pane list. Panes the client held that the tree never recorded are
  ended outright.
- `TabReopen` takes the named or newest entry off the list and answers it
  with its pane records, for the client to rebuild on fresh shells that
  open on the old screens. The records it leaves behind are claimed by the
  successors' seeds instead of being refused as duplicates.
- Entries last 24 hours and a workspace keeps the newest 20. The daemon's
  scrollback keeper expires them on its existing timer, and an entry that
  goes takes its records and stored screens with it.
- Both requests are gated on a new `closed-tabs` hello feature, offered only
  by a peer that serves a tree and panes, so an older daemon or remote
  server is never sent them.

The field is `#[serde(default)]` and skipped while empty, so older trees
load unchanged and an older build reads this one's.

Refs #1021

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* feat(tabs): reopen closed tabs from the machine, and a setting for when closing asks

Closing a tab now closes it into its workspace's recently-closed list on the
machine that holds the workspace, instead of into a list that ended with the
window. ⌘⇧T asks that machine for the newest entry, so a closed tab comes
back after quitting and relaunching the app, from any window of the
workspace, and in remote workspaces whose server keeps the list.

- The explicit close (⌘W, the tab's close button, bulk closes) registers the
  tab with the window's next sync, which turns that tab's `TabClose` into a
  `TabCloseRemembered`. The machine stops the panes and keeps their screens;
  the window no longer kills them itself. A tab dragged to another window or
  never rebuilt still goes out as a plain close.
- If the close cannot reach the machine (no `closed-tabs` feature, a window
  that has not pulled its layout, a sync that fails or is thrown away), the
  window falls back to what it did before: the tab goes on its own list and
  its panes are killed from here.
- Reopening waits briefly for this window's queued edits to land, so an
  immediate ⌘⇧T undoes the close it means, then rebuilds the tab through the
  existing restore: each pane a fresh shell in its old cwd, opening on its
  last screen, with its shell, SSH target and agent resume facts. The tab
  keeps its id. The window's own list is used when the machine has nothing.
- The home screen offers the next tab ⌘⇧T would reopen, read from the
  machine mirror, which now tracks this window's remembered closes.

A new setting, `confirm_close` (General > Tabs, "Confirm before closing"),
decides when closing a tab or pane asks first: `never`, `when-busy` (the
default and the old behaviour) or `always`. The SSH "Warn before closing"
opt-in is honoured under every mode. Under `always`, Close Other Tabs and
Close Tabs to the Right ask once for the whole batch.

Refs #1021

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(tree): a remembered close marks its panes' records as no longer live

The records stay in the pane list for the reopen, but the panes are stopped
right after the close. Left at live: true, `tty7 wait` on a pane of a
closed tab read it as a running agentless shell and waited forever instead
of reporting it exited.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 16:40:28 +08:00
l0ng-ai f0f2b83b6e feat(workspace): the machine's own window takes part in workspace takeover (#1042)
One workspace is driven by one window at a time, whether that window runs on
the machine itself or on a remote client. The local GUI used to connect to its
daemon without ever claiming a workspace, so a remote client and a local
window could drive the same panes at once and fight over their size.

- The local link now claims (WorkspaceAttach) every local workspace a window
  shows. Opening one on purpose (switcher, tty7 open, a new window onto it,
  switching in place) takes it over; restore, relaunch and reconnect only
  claim a workspace nobody else holds, and otherwise open taken over.
- Preempted events for this computer put the window in the same taken-over
  state remote workspaces use: panes detached (processes untouched), the
  status strip naming the holder, the input pill, Take Back, and the
  switcher's 'taken over' badge.
- A hydration of a local workspace another client holds does not attach its
  panes, so a restored window never resizes them under the holder.
- A reconnect re-claims what the window held and leaves what it was pushed
  off alone. Nothing but Take Back or an explicit open reclaims.
- The local hello carries the machine's hostname instead of the literal
  'this computer', which is what a displaced remote client displays.
2026-09-30 16:36:10 +08:00
l0ng-ai ab029f5ea1 fix(ssh): start a redialled SSH pane in the remote directory it was in (#1035)
* fix(ssh): start a redialled SSH pane in the remote directory it was in

A native SSH pane dialled again (restore after a daemon restart, Reconnect,
a split, ⌘T on an SSH tab, waking a sleeping tab) always landed in the login
directory. The client already sent the pane's remote cwd as
`SpawnNativeSsh.cwd`, but the daemon dropped it on the floor.

The daemon now threads it through `Pane::spawn_native_ssh` and
`SshManager::run_session` into the shell-integration bootstrap, whose first
line becomes `builtin cd -- '<dir>' 2>/dev/null` (fish-quoted for fish). It
is never typed at the prompt, never lands in history, and a directory that
is gone leaves the shell in the login directory without a word. Sessions
without integration take the plain shell request as before, so jump-host
menus never see it. The per-host probe cache still holds only the shell.
Only absolute paths are honoured. No wire or protocol change.

Callers now say what they mean: a saved host or quick connect passes no
start dir instead of the local cwd of whatever tab was in front; ⌘T and a
split on an SSH pane pass that pane's remote cwd; a sleeping SSH tab keeps
its remote cwd in the session layout. The daemon's replay now sends the
remote context before the cwd, so a window that reattaches to an SSH pane
does not wipe the remote directory it was just told.

Refs #1028

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(ssh): a local shell standing in for a restored SSH leaf starts locally

pane_to_session now keeps a native SSH leaf's far directory, so the
session_to_pane fallback that brings such a leaf back as a local shell
(the redial failed, or its daemon pane is gone on reattach) would hand
that remote path to a local spawn. Pass no cwd there for an SSH leaf.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 15:02:22 +08:00
l0ng-ai 0277ca67dc Centre the title-bar search box; bring back auto-hiding title-bar buttons as an Appearance option (#1036)
* feat(settings): an Appearance option to show the title-bar buttons only under the pointer

26.9.2 painted the new-tab and sidebar tiles only while the pointer was
over the bar they sit in; 26.9.3 took that out so the buttons would stay
discoverable. Both are fair, so it comes back as a choice: Appearance >
"Show title bar buttons on hover" (`auto_hide_titlebar_buttons`), off by
default, which keeps today's always-visible bar for everyone who has not
asked otherwise. A config written before the key existed reads as off.

With it on, the rail's two tiles follow the rail, and the collapsed
rail's pair and the trailing panel toggle follow the tab strip. The
window mark stays put, the tiles keep their layout slot so a reveal
never shifts anything, and the title-bar search box is always drawn.
The trailing toggle stays painted while the detail panel is open, as
before, since the panel's own tab row beside it always is.

The reveal is the hover sheet from 26.9.2 — a transparent last child
over each region, because `group_hover` loses the region the moment the
pointer reaches an occluding tile. Resting tiles go to zero opacity
rather than `invisible()`: gpui skips a hidden element's paint pass,
which is where its click and accessibility actions are registered, so a
screen reader could find a hidden tile by label and then not press it.
Shortcuts are actions and never depended on the tiles.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(titlebar): centre the search box on the window, not the bar after the traffic lights

On macOS `TitleBar` leaves an 80pt lead for the traffic lights before
the tab strip — whether or not the rail stands in front of them — and
the Search Everywhere box was centred on the strip. So it sat 40pt right
of the terminal column's middle: with the rail collapsed, 40pt right of
the window's (#1033). Fullscreen added the bar's own inset on top.

The band the box centres in now reaches back over that lead, so its left
edge is the terminal column's on every platform (12pt elsewhere). Its
right edge is unchanged: the strip's end on macOS, the terminal column's
end beside a docked panel or document off it.

Reaching back puts the collapsed rail's tiles inside the band, so the
box now keeps an equal clearance at both ends — two springs with a
minimum width either side of it. In a narrow column it shrinks instead
of sliding under New Tab or the panel toggle, and stays centred while
it does. The geometry is a pure `search_band`, tested for the macOS
rail-collapsed, rail-open and fullscreen cases and off macOS.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(titlebar): clear a hover flag whose sheet is not on screen; document the key

A title-bar hover flag is written only by its sheet, and only when the
sheet sees the pointer cross its edge. Hide the rail from its own tile, or
turn the switch off mid-hover, and the sheet leaves the tree with its flag
still set: the next time it is built the tiles came back painted with
nobody pointing at them, until the pointer happened to pass through and
out again. Clear the flag of any sheet not built this frame.

Also list auto_hide_titlebar_buttons in the configuration reference.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 14:59:53 +08:00
l0ng-ai c0c6f90284 fix(chrome): the workspace tile points like the switcher rows it opens 2026-09-30 14:14:35 +08:00
l0ng-ai e1ee74a379 fix(tabs): ⌘T on an SSH tab stays on its host; Switcher says Offline in words (#1031)
* feat(switcher): say Offline in words and dim the avatar; drop the link dot for a reachable workspace

The normal case carries nothing extra. An offline machine's row reads
"Offline" under the tab count, where Open and This window go, and its
avatar is dimmed. A dot stays only for states that want attention:
connecting, reconnecting, failed, or taken over by another client.

* fix(tabs): ⌘T on an SSH tab dials the same host and files the tab under it

A new tab from an SSH pane used to open a local shell in the default
directory, which landed in Ungrouped instead of under the host the user
was on. A native SSH pane now dials again with its spec, as ⌘D already
did; a shell that ssh'd onward from a local prompt gets a local tab that
types the same ssh command at its first prompt. Either way the tab is
seeded into the host's auto group before its pane reports in.
2026-09-30 12:29:56 +08:00
l0ng-ai 8db94666f0 fix(remote): fast, stable remote workspaces with more than ten panes (#1034)
* fix(ssh): a connection at the server's session limit is full, not dead

sshd allows ten sessions per connection by default and every remote pane is
one of them. The eleventh was refused with ConnectFailed, and the connection
was marked dead for it: taken out of the cache while all ten panes on it were
still using it. Every pane after that dialled its own fresh link, paying a full
handshake and server probe, and so did every short-lived route afterwards,
because nothing held the replacement and it went away as soon as that route
closed.

The cache now keeps a pool per destination. A refusal marks that connection
saturated for a while instead of dead; the pool hands out the first live one
with room and dials another beside them only when all are full. A route or a
native SSH pane that lands on a connection that turns out to be full goes back
to the pool for another.

* perf(remote): prove a server that is already running in one round trip

Every new connection to a machine tty7 had been to before spent six
sequential round trips proving what it already had: uname, a home lookup and
a stat over SFTP, a control probe and a process scan. The SFTP session it
opened also stayed open for the life of the connection, one of the handful of
sessions the server allows it.

One `sh -c` script now answers the common case: this dialect's server is
installed, answers the bridge probe, and is the one running (or a build of the
same dialect). Anything else falls through to the full install path unchanged.

* fix(remote): don't replace a pane that could not be reached with a fresh shell

Reattaching a restored pane treated every failure other than silence as "the
pane is gone on its machine" and spawned a fresh shell in its place. That
includes the link never opening at all — the server refusing another session,
a transport error — when the pane is still running over there. The tab lost
its session, and the old shell was left orphaned on the remote daemon; one
workspace had accumulated 53 shells for 17 panes.

Only the daemon's explicit "no such pane" now means gone. For a remote pane,
any other failure leaves it pending, and a pane that stands in for a running
one retries on its own a few times (2s, 4s, 8s, 16s, 16s) before leaving it to
Try Again. Local panes keep their previous behavior.

* perf(remote): ask a machine which panes are live over its control link

The pane liveness probe opened a pane route every ten seconds, which is an SSH
session channel on the remote side — one of the few the server allows per
connection. Once panes had taken them all, each probe dialled a whole new
connection. Ask over the control link that is already up instead: the
machine tree's pane records carry the daemon's own liveness.

* fix(scm): stop two windows from trading one repository watch every frame

Who holds a repository open is a global, reconciled by every window every
frame, but it was keyed by watcher kind alone. Two windows whose file trees or
panels sat in different repositories took the hold from each other each
frame, and every hand-over dropped the watch and opened it again. On a remote
workspace that is four round trips per cycle — about 28 control requests a
second for as long as both windows were open.

Holds are now keyed by window as well, and a closed window gives back what it
held.

* perf(ssh): open channels on one connection concurrently

The russh handle sat behind a tokio mutex held across every request on it,
and each request waits a full network round trip for its reply. So every
pane on a connection opened its channel after the one before it: on a link
with a few hundred milliseconds of latency, a workspace of twenty tabs came
back one tab at a time over about ten seconds.

Every call on the handle takes `&self` and waits on a reply channel of its
own, so the lock bought nothing. Drop it.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 12:29:48 +08:00
b26c26ca66 fix(palette): an open palette keeps workspace keys, and ⌘P answers from the Settings window (#1026)
* fix(palette): an open palette keeps workspace keys, and ⌘P answers from the Settings window

While the palette was open, any app binding it did not handle — ⌘1–9,
⌘D, ⌘W — fell through to the workspace behind it. The Settings window
has no palette listener, so the palette chord did nothing there. A
keystroke interceptor, which gpui runs before matching any binding,
now handles both.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(palette): shifted editing letters are not the query field's

The modal rule let every secondary+A/C/V/X/Z chord through as the query
field's own, shift included, so on macOS Cmd+Shift+A (New Agent Tab)
still opened a tab behind the open palette. Only redo keeps its shift.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-09-30 09:38:43 +08:00
2b94fddedc fix(ui): refocus the app when focus is lost so global shortcuts answer (#1023)
* fix(ui): refocus the app when focus is lost so global shortcuts answer

With focus on nothing, or on a handle whose element is no longer drawn (a
closed file panel, a dismissed menu), gpui dispatches keys on the window root
alone, one level above Tty7App's listeners. TogglePalette, ToggleSwitcher,
OpenSettings and every other tty7-root action went dead. on_focus_lost now
hands focus back via focus_active.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(ui): refocus settings only in the window that draws it

Settings opens in a window of its own, but focus_active handed focus to
the page's handle whenever settings was up, including in the workspace
window. There that handle is not drawn, so the refocus on focus loss
parked focus on nothing and the workspace shortcuts stayed dead while the
settings window was open. Focus the page only when this window draws it,
and fall through to the workspace's own panes otherwise.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-09-30 09:36:50 +08:00
802f9e0792 fix(agents): a Claude resume that finds no conversation starts fresh under its id (#1024)
* fix(agents): a Claude resume that finds no conversation starts fresh under its id

A tab opened and never used, or run with transcript saving off, has no
saved conversation, and `claude --resume` then stops at an error.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(agents): only chain the fresh Claude start where the pane's shell has ||

Windows PowerShell 5.1 and nu reject a line containing `||` outright, so
the fallback took the resume down with it there. The restore line now
chains the fresh start only for shells known to have the operator, judged
by the pane's own shell: its spawn spec, else the configured or login
shell for a local pane. A workspace pane with no explicit shell stays
unknown and gets the plain resume, since its default lives on its host.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-09-30 09:35:32 +08:00
l0ng-ai 0896404634 fix(switcher): require a name for a new workspace, and give the form buttons
The New Workspace form prefilled a random codename and offered no button,
only an "Enter to create" hint. The name box now starts empty and must be
filled; the footer carries Cancel and Create, with Create disabled (and
Enter inert) while the name is blank.
2026-09-30 09:12:39 +08:00
l0ng-ai ef203821b0 feat(a11y): name the icon buttons and search toggles
Bumps gpui-component to the tty7 branch commit that gives Button and
Input a role and a name and exposes popup menu items, and names the icon
buttons whose tooltips are elements rather than text (New Tab, the
sidebar and detail-panel toggles, Switch Workspace) and the file search
toggles (Match case, Match whole word, Use regular expression).
2026-09-30 08:43:52 +08:00
l0ng-ai bb0089f43d feat(a11y): label the remaining lists and let VoiceOver open files from the tree
Editor tabs are tabs named by file (and unsaved state) with a named close
button; Info rows read as 'label, value'; keyboard shortcut rows as
'action, keys'; SSH hosts as 'name, address' with their expanded state.
File-tree rows open on the press, which assistive tech cannot send, so
they take its press action directly: a screen reader could select a file
but never open it.
2026-09-30 03:09:48 +08:00
l0ng-ai cdd3f3c2cd feat(a11y): read Settings rows as named groups with their switches' state
Each row is a group named by its title and description, so the control in
it is heard with its setting's name; switches report on or off, the reset
link is a button, and the Modified only switch has a name of its own.
2026-09-30 02:56:02 +08:00
l0ng-ai 6d07ca41b0 feat(a11y): announce the app's own dialogs as dialogs, named by their title
The SSH sheet, the worktree form and the in-app alert are dialogs to a
screen reader, titled with the question they ask.
2026-09-30 02:48:54 +08:00
l0ng-ai 4ae1c86290 feat(a11y): expose the Changes panel's groups and files to screen readers
Group headers are buttons named with their count and expanded state; files
are tree items named by path and group; directories by name with their
expanded state.
2026-09-30 02:41:01 +08:00
l0ng-ai 420aa33cac feat(a11y): expose Search Everywhere's results to screen readers
Each row is a list option named by its title and subtitle, with the
highlighted one selected.
2026-09-30 02:23:14 +08:00
l0ng-ai 8efbbc4a38 feat(a11y): expose Settings navigation and file-tree rows; title the Settings window
Settings sections are tabs with their names and selected state, file-tree
rows are tree items named by file with selection and expansion, and the
Settings window carries a title for VoiceOver and the Window menu.
2026-09-30 02:19:08 +08:00
l0ng-ai 8f044924ab feat(a11y): expose the sidebar's tabs and the detail panel's tabs to screen readers
Each is a tab with its full title and selected state, and pressable by
assistive tech. Before, VoiceOver saw the window, its buttons and the
terminal, and nothing between them.
2026-09-30 02:12:13 +08:00
l0ng-ai e96cad4858 fix(agents): type a fork or launch command at the new shell's first prompt
Sent the moment the pane was up, the line was echoed by the tty above
everything the shell printed while starting, then read after it. It now
waits for the first prompt, for at most three seconds.
2026-09-30 02:01:04 +08:00
l0ng-ai bbc13279e7 fix(settings): drop 'Paired with …' once that phone is unpaired
Unpairing the phone just paired left 'Paired with probe.' above an empty
'No phones paired yet.'
2026-09-30 01:55:38 +08:00
l0ng-ai e66fa4d881 fix(ssh): never restore an SSH tab as a local shell; show a reattached one as connected
After the server restarted, a native SSH tab's old pane id was attached
to, the attach failed, and the fallback spawned a local shell in its
place: the tab that had been another machine was now this one, still
titled and grouped like the remote. An SSH leaf is now only reattached
when the server lists its pane; otherwise the host is dialled again.

A window reattaching to a live SSH pane also never learned its phase,
since status frames only went to whoever was attached when they were
sent. The pane keeps the last one and replays it, so the tab keeps its
connected dot and warn-before-closing still applies.
2026-09-30 01:39:32 +08:00
l0ng-ai f99fff93fd fix(ssh): log in as this machine's user when a host leaves User blank
The form says a blank User is resolved at connect, and the host card shows
$USER, but the empty string went to the server as the user name. sshd
refused it as an invalid user and tty7 reported every key as rejected.
2026-09-30 01:22:02 +08:00
l0ng-ai 4880171974 fix(ui): show macOS's /private/tmp paths as /tmp
git and canonicalize hand back /private/tmp/… for anything under /tmp, and
the workspace switcher and the worktree form drew that spelling, which no
shell or pane title uses. Only what is drawn changes.
2026-09-30 01:11:18 +08:00
l0ng-ai 31f5d38f3d fix(sidebar): back a tab's hover close button for the row's full height
On a two-line row the diff count sits below the close button's band, and
the bottom of '+2' showed under the ×.
2026-09-30 00:53:59 +08:00
l0ng-ai c3fdbe5c77 fix(settings): focus a new host's first field; name tty7-defined hosts plainly
Add host opened a blank form with nothing focused, so typing went
nowhere. A host saved in tty7 read 'Defined in: In tty7'; the label is
now 'tty7 settings', as a group heading and after 'Defined in' alike.
2026-09-30 00:50:10 +08:00
l0ng-ai 6f29cac8bf fix(switcher): put the workspace the query names above ones matched by tabs
The list was ordered by current-then-recent whatever the query, so typing
'qa' and Enter reopened this window's workspace (its tabs are under
/tmp/t7qa) instead of the workspace named qa.
2026-09-30 00:28:15 +08:00
l0ng-ai 7e9225e6b0 fix(search): match a command's description by the words typed
Any subsequence of a long description counted as a hit, so 'theme' listed
Git: Discard All Changes second, through the letters of 'Throws away every
uncommitted change'.
2026-09-30 00:24:24 +08:00
l0ng-ai 6ac8d3fd64 fix(switcher): select the suggested workspace name so typing replaces it
The New Workspace form opened with the generated name and the caret in
front of it, so typing a name produced 'qadusky-raven'.
2026-09-30 00:20:43 +08:00
l0ng-ai e1ab8e26fc fix(panel): name the shell a default-shell pane is actually running
The Info tab named the login shell for any pane on the default shell, but
a server started from a terminal spawns the shell it was started from.
The root of the pane's process tree is that shell.
2026-09-30 00:16:08 +08:00
l0ng-ai e0308bd54f fix(terminal): keep output without a trailing newline through a resize
zsh's PROMPT_SP pads dangling output until it wraps onto the prompt's row.
The grid took that wrap for the prompt's own first row, so the next resize
at the prompt cleared the output and widening joined it onto the prompt.
At the prompt marks, a padded wrap after dangling output is turned back
into a hard break.

Also: editor breadcrumbs, breadcrumb reveal and Problems labels match
files against the project root's real path, so a project under a symlink
(macOS /tmp) no longer shows the absolute path; the terminal font size
setting says points, which is what its stepper shows.
2026-09-29 23:34:32 +08:00
l0ng-ai 5ba588f6d2 fix(mobile): let Settings renew a pairing code, and say when one is spent (#1019)
While a code was on screen the Show code button was disabled, so the only
way to a fresh code was Cancel then Show code. Worse, any attempt at a
code closes the offer, so after a mistyped paste or a dropped connection
the page kept showing a dead code for up to ten minutes with no hint.

- The button reads "New code" while a code is up, and replaces it.
- A code that can no longer pair stays on screen faded, saying why
  (expired, tried, or replaced by a newer offer), with New code beside it.
- The validity note counts down instead of saying "10 minutes".
- Cancel, and switching phone access off, now withdraw the offer on disk;
  before, a dismissed code could still pair until it expired. Only our own
  offer is withdrawn, never one opened elsewhere since.

The gateway's pair_code now returns the offer's secret alongside the code,
and State gains pairing_is_open / has_open_pairing / close_pairing.

Claude-Session: https://claude.ai/code/session_01BDVpJ78s7RQVcj57vjTcfA
2026-09-29 22:50:59 +08:00
l0ng-ai 9f44feed29 fix(scm): don't hand a new history page the previous page's rows (#1020)
The graph's row cache keyed on the page's address. Once the old page
was freed, the next one could land in the same allocation, match the
key, and be served the old, longer index list - so rendering indexed
past the end of the new page's commits and panicked (seen as
'index out of bounds: the len is 1 but the index is 1').

Key the cache on a Weak to the page instead: while the cache holds it,
the allocation can't be reused, so ptr_eq only matches the same page.
2026-09-29 22:50:57 +08:00
l0ng-ai d1b96e1346 feat(panel): show the author on a hovered GitHub row (#1018)
The author was already fetched for every issue and pull request but only
the detail view showed it. A hovered row now shows it between the labels
and the age.

In a narrow panel the author is what gives: it is capped, then truncated
down to nothing, while the labels and the age keep their width and the
title keeps a stub, so the meta no longer pushes past the row's edge.
2026-09-29 19:32:07 +08:00
l0ng-ai 8e9f55173b fix(agents): fork agent sessions in remote workspaces (#1016)
Forking from a pane in a remote workspace always failed with "the pane is
still connecting": a remote workspace's new pane is dialled asynchronously,
and the fork path demanded a ready terminal to type into. It now hands the
fork line to `run_when_ready`, the same land-then-run path quick launch uses.

The new pane also opens in the source's directory on its own host
(`spawnable_cwd`) rather than only a local one. Agents key their history by
directory, so a fork started in the remote home would find nothing to branch.

Panes that have ssh'd or entered WSL themselves stay excluded (tty7 holds no
link to that machine), and the notification now says exactly that instead of
"local panes only".
2026-09-29 19:31:59 +08:00
l0ng-ai 230a023ebf fix(terminal): stop the git retry check from redrawing every poll tick (#1015)
The retry added in #1011 went through update_global on every 300ms poll
while a pane's repo was unanswered, even when the probe was still in
flight or throttled and nothing was claimed. Each mutable touch of the
GitStatusCache global wakes its observers, so the window redrew about
three times a second for as long as a probe was pending or failing.
That is what a_commit_detail_reads_its_own_files_and_draws_them caught
on Linux CI (2 idle frames where 0 are expected).

Ask whether a retry is due read-only (GitStatusCache::probe_due) and
only touch the global when one is.
2026-09-29 19:31:55 +08:00
l0ng-ai 8c75722466 fix(sidebar): elide branch names from the end only (#1014)
The sidebar branch (group header and row git line) was front-elided,
but its width budget was a few pixels short: the line paints with
tabular figures while it was measured with proportional ones, and the
separator was measured as " · " though it is drawn as a bare "·"
between two gaps. The front-elided branch then overflowed and CSS
truncation cut its tail too, leaving "…nd-error-classificati…".

- Measure the git line and header with the same tabular font they paint
  with, and measure the separator as drawn.
- Elide the branch from the end, the plain cut a reader expects; the
  CSS backstop now cuts in the same direction.
2026-09-29 19:31:51 +08:00
l0ng-ai 3f9ae33a28 style(ui): lighter, tint-keeping selection and hover on the side panels
The tab rail's current row read as a dark slab. Both side panels (the tab
rail and the docked right panel) now step on their own lighter rungs,
1.07:1 for hover and 1.12:1 for selected, and step toward the panel's own
shade instead of the foreground, so a warm panel keeps its tint rather
than turning into a grey patch. On the default light theme that lands on
#ededec / #e8e8e7.

The settings page's nav sits on the same rail fill, so it now paints with
the rail's rungs instead of its own alpha tokens.
2026-09-29 19:27:16 +08:00