mirror of
https://github.com/l0ng-ai/tty7.git
synced 2026-10-04 00:02:04 +00:00
420aa33cac69a092c19e85587f16f4f00a0ed891
309
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
e66fa4d881 |
fix(ssh): never restore an SSH tab as a local shell; show a reattached one as connected
After the server restarted, a native SSH tab's old pane id was attached to, the attach failed, and the fallback spawned a local shell in its place: the tab that had been another machine was now this one, still titled and grouped like the remote. An SSH leaf is now only reattached when the server lists its pane; otherwise the host is dialled again. A window reattaching to a live SSH pane also never learned its phase, since status frames only went to whoever was attached when they were sent. The pane keeps the last one and replays it, so the tab keeps its connected dot and warn-before-closing still applies. |
||
|
|
f99fff93fd |
fix(ssh): log in as this machine's user when a host leaves User blank
The form says a blank User is resolved at connect, and the host card shows $USER, but the empty string went to the server as the user name. sshd refused it as an invalid user and tty7 reported every key as rejected. |
||
|
|
a35800b96d |
fix(config): read a shell entry with no program as the login shell
`shell` was the one structured field still read strictly, so a hand-edited
{"args": [...]} without a program failed the whole file. It was
quarantined and every other setting fell back to its default, and changes
made in Settings afterwards were never saved.
|
||
|
|
1aa6e1e35b |
fix(daemon): set up integration for the shell a pane actually runs
Launched from a terminal, the daemon spawns the shell it was started from rather than the login shell. The name handed to shell integration still came from get_shell(), which is always the login shell, so tty7 started from bash with zsh as the login shell ran bash with zsh's ZDOTDIR and no rcfile: no prompt marks, no prompt editor, no completion. |
||
|
|
24cf458e3b |
feat(mobile): a phone app to watch and drive tty7 panes (#983)
* feat(mobile): a gateway that lets a paired phone reach this machine over iroh
The first half of the mobile app: everything on the desktop side, plus the
client library the app will link.
- tty7-mobile-proto: the phone<->gateway wire protocol. One stream per purpose
(pair, control, pane), framed like the daemon's frames, with raw terminal
bytes kept out of JSON. No tty7-core, so it cross-compiles for iOS/Android.
- tty7-gateway: dials nothing, accepts phones over iroh (hole punching, relay
fallback, end-to-end encrypted), checks the peer's key against the paired
device list, and bridges to the daemon. Panes are observed, not attached,
and keystrokes go in through SendInput, so a phone never resizes a pane or
takes it away from the desktop window. `pair` prints a one-time QR code.
- tty7-mobile-client: the phone side (pair, tree, pane streams, direct/relay
and RTT for the link), plus a `probe` example that stands in for a phone.
Verified against a real, isolated daemon: pair, tree, and typing into a pane
over a direct path, ~0.8 ms median echo on loopback.
* feat(mobile): the Tauri app — pair, browse the machine, drive a pane
The phone half, as a Tauri 2 app in mobile/ (its own cargo workspace, so the
desktop build and CI never compile a WebView stack).
- Rust side: the phone's iroh endpoint and key, paired machines, and every
live stream, behind eight commands. Terminal output crosses to the WebView
as raw ArrayBuffers on a Tauri channel, batched per frame, in order with the
pane's JSON events.
- Frontend: vanilla TS + xterm.js. Paired machines and pairing; one machine's
workspaces, tabs and panes with agents that need you pinned on top and the
link's direct/relay path and RTT in the header; a terminal that fits the
desktop pane's width, with an esc/tab/ctrl/arrows key bar. Coming back from
the background re-watches and re-opens, relying on the daemon's replay.
Verified as a macOS build against a live gateway and an isolated daemon:
paired from the app, tree rendered on a direct path, keystrokes and key-bar
arrows reached the pane. iOS/Android builds need Xcode / the Android NDK,
neither of which is on this machine; mobile/README.md has the steps.
* fix(gateway): one serve per machine, and say how to start a missing server
- `serve` takes an exclusive lock on <config dir>/mobile/serve.lock. A second
gateway on the same key is a second endpoint answering to one address, so a
phone reached whichever the network picked. It is now refused, naming the
pid that holds the lock.
- With no tty7 server running, phones and the terminal both hear "tty7 isn't
running on <host> — open tty7 there, or run `tty7 server start`" instead of
"lost the tty7 server: No such file or directory". `serve` checks once at
startup, and still starts, since tty7 may be opened after it.
* feat(mobile): redesign the app as a native-feeling, minimal UI
The first cut read as a web page of bordered boxes. This rebuilds it the way a
phone app moves and reads, in the desktop tty7's own look:
- Screens push and pop with View Transitions; large titles fold into the bar.
- Grouped inset lists on a tinted canvas, following the system Light/Dark with
the desktop presets, accent and ANSI palettes. Hack for code and terminal.
- Panes are listed by tab, one card per workspace, with the desktop's agent
avatars and status badges (Waiting hollow, Working blinking) and its words.
- Pairing is its own screen, with steps, a Paste button and inline errors.
- A machine that stays silent for 10 s says so and offers to pair again; an
offline notice says what to check.
- The terminal header shows live/offline in words. A pane too wide to read is
shown at a readable size and pans to follow the cursor, with a toggle to fit
the whole width. The key bar has drawn icons, puts left/right first, and
has a keyboard toggle.
PRODUCT.md and DESIGN.md record the product facts and the design system.
* feat(mobile): open a new tab from the phone
Each workspace on a machine's screen gets a "New tab" action. It starts a
shell at the end of that workspace, in the directory its last tab is in, and
opens it straight away.
- Protocol: a one-shot `Open::NewTab { workspace_id, cwd, size }` stream,
answered with `Ok` and a `TabCreated { tab_id, pane_id }`, or `Denied`.
It is additive, so the protocol version stays. A gateway from before this
drops the stream unanswered, and the app says to update it.
- Gateway: takes the same two steps as `tty7 tab new`, spawning a shell owned
by the workspace and then TabCreate. The shell starts at the grid the phone
asked for, because no desktop window is showing it yet. Sizes are clamped.
- App: a `tab_new` command, with the size worked out from the screen at the
readable font size.
- probe: `newtab <workspace-id> [cwd]`.
* feat(mobile): reach the machines the desktop is linked to over SSH
A machine's screen now lists, under its own workspaces, every machine its
tty7 holds an SSH link to, with that machine's workspaces. Panes there open,
take input and get new tabs like local ones. "Needs you" gathers panes from
all of them.
- The gateway routes through the local server over links it already holds,
the same way `tty7 -m <machine>` does. It never dials a down link, because
that would guess at credentials the phone does not have. A down link
shows as "Link down", with a note to reconnect it on the desktop.
- Protocol, additive: `Tree.remotes`, and an optional `machine` (the link
key) on `Open::Pane` and `Open::NewTab`. A local pane is asked for exactly
as before, so older gateways still understand it.
- Rebuilding a route target from a link key moves from the CLI into
tty7-core as `RouteInfo::target` / `RouteInfo::host`, so the CLI and the
gateway share one rule. The CLI now calls it.
* perf(gateway): read linked machines in parallel, never waiting on a slow one
Linked machines were read one after another on every tree poll. One slow
SSH link, whose requests can take 10 s, stalled the whole tree for every
phone, local workspaces included. It also held a lock that queued pane
opens, input and new tabs on every other link.
- Each linked machine is read on its own thread (`poller::Poller`). A poll
waits at most 250 ms. A machine that has not answered is reported as it
last was, and its read lands for the next poll. Only one read is in flight
per machine, however many phones are watching. A machine that drops off and
comes back cannot receive a stale read, because each slot has a generation.
- Routed control connections are locked per machine, not all together.
- A link that is up but has not answered its first read is sent as
`RemoteView.pending` (additive). The app shows "Reading…" with skeleton
rows instead of claiming the machine has no workspaces.
* fix(mobile): keep reaching the computer after the gateway restarts
Every `serve` bound a random port, so a restart left each phone holding
addresses that no longer answered. Where the n0 relays are unreachable, which
is common behind the Great Firewall, the phone had no other way to find the
gateway until it was paired again.
- `serve` listens on the same UDP port every time. It picks one on first run,
keeps it in `<config dir>/mobile/port`, and moves only if the port is taken.
IPv6 binding may fail, as in iroh's own defaults.
- Both ends add mDNS lookup (`iroh-mdns-address-lookup`, service `_tty7._udp`).
On the same network a phone finds the gateway by key when its addresses are
stale, such as after a new DHCP lease or a new IPv6 prefix. The gateway
advertises and the phone only listens. If multicast is refused, each side
starts without it and says so, rather than failing.
- iOS: `Info.ios.plist` declares the local-network use and the Bonjour
service, without which iOS blocks multicast.
- An ignored test (`--test mdns`) connects by key alone over mDNS, for a
machine that allows multicast.
* feat(mobile): run the gateway in the desktop daemon, paired from Settings
Phone access no longer needs `tty7-gateway serve` in a terminal.
Settings → Mobile switches it on, and the local daemon runs the gateway from
then on, with every window closed as well. That is where the panes a phone
reaches live anyway.
- Settings → Mobile, in all three locales:
- an "Allow phone access" switch;
- a status line (running, starting, off, or why it failed);
- "Show code", which draws the QR code and the tty7pair: code with a
Copy button, and closes on its own once a phone uses it;
- the paired phones, each with Unpair.
The section is in search, including by its config key `mobile_access`.
- The daemon (`tty7-app --daemon`) runs a supervisor (`core::mobile`). It
watches `mobile_access` in config.json, re-reading only when the file
changes, and starts or stops the gateway. A failed start is retried every
30 s and logged once.
- tty7-gateway grows a `service` module: `start()` returns a stoppable
handle, and `pair_code()` makes a code. The CLI's `serve` and `pair` are
thin wrappers over them now. The gateway logs through `log`, so the
daemon's output lands in its log file, and it reports itself in
`mobile/status.json`. `State::serving()` checks the lock, which a crash
cannot leave stale. A gateway that cannot take the lock leaves the
status alone, because it belongs to the one holding the lock.
- iroh is linked into the GUI binary only. tty7-server stays the lean static
binary pushed to remote machines.
* feat(mobile): serve phones whichever daemon is running
A daemon started by `tty7 server start` is the lean tty7-server, which
carries no gateway. With phone access on, the Settings status stayed on
"Starting…" and no phone could connect.
The GUI now checks, 5 s after it starts and whenever phone access is
switched on. If nothing is serving, it starts `tty7-app --mobile-gateway`,
detached the same way as the daemon (`spawn::detach_helper`). The helper
serves until the switch goes off, and exits at once if another process
already holds the gateway lock. When the daemon's own gateway is up, no
helper is started. The helper logs under its own role, "mobile".
* refactor(mobile): the daemon owns the gateway, as a child, whoever started it
There were two ways of running the gateway: a thread inside `tty7-app
--daemon`, and a detached helper the GUI started when the daemon could not.
That is now one way.
Every daemon, whether `tty7-app --daemon` or `tty7-server`, runs
`tty7_core::daemon::mobile::supervise` from `run_with`. While
`mobile_access` is on it keeps the gateway running as a child process, and
stops it when the switch goes off.
- Which program: `tty7-app` runs itself as `--mobile-gateway`. `tty7-server`
runs a `tty7-gateway serve --exit-with-stdin` from beside it or on PATH,
and links nothing new. Without one, it writes the reason into
`mobile/status.json` for Settings to show, instead of "Starting…" forever.
- Lifetime: the child's stdin is a pipe from the daemon, and the gateway
exits when it closes. A stopped, crashed or handed-off daemon (the pipe
is close-on-exec) takes its gateway with it, and the next daemon starts
one from its own binary. No gateway from an older build survives an
update.
- Isolation: iroh no longer runs inside the process that holds every pane.
- `Status` moves to tty7-core, the one definition that the daemon, the
gateway and the GUI all share.
- Gone: the GUI's helper check (`core::mobile` in the app) and the in-daemon
gateway thread.
* fix(mobile): stop and reap the gateway before a daemon handoff
Found by running a real `tty7 server restart`. The old gateway did exit,
because the new image's supervisor started its own gateway and the old one
lost the lock. But it was left as a zombie: the image after the exec never
reaps a child it did not start, so each handoff leaked a process entry.
`hand_over` now calls `daemon::mobile::stop_for_handoff` before the exec,
which closes the gateway's stdin and waits for it. A flag keeps the
supervisor from starting another in the moments before the exec, and
`handoff_failed` clears the flag if the exec never happens, so the daemon
goes on serving.
Checked with two handoffs in a row (tty7-app → tty7-server → tty7-server):
- each old gateway was reaped, with no zombies system-wide;
- exactly one fresh gateway was running after each handoff;
- the pane's shell and its environment survived;
- the probe phone kept working.
* feat(mobile): the switch shows whether phones can reach you, not a status row
Settings → Mobile had an "Allow phone access" switch that showed intent and a
separate Status row that showed reality. That is one thing shown twice, and
the switch could sit on while nothing was running.
- The switch is the state. Switching on holds it at "Starting…", disabled,
until a gateway is actually serving. If the daemon reports a failure, or
nothing comes up within 15 s, the switch goes back off, `mobile_access`
is reverted, and a notification says why.
- If the page opens on a failure the daemon is still retrying, the switch
shows off with the reason in its description, and switching it on
retries.
- The Status row is removed, with its four strings. There are two new
strings for the failure, in en, zh and ja.
Also fixes the Settings window never showing notifications. It is a `Root`
like the workspace window but did not draw the notification layer, so any
toast pushed from Settings was queued and never shown. That included the
existing "Set as Default Terminal" result.
Checked in a dev instance. On a tty7-server daemon with no tty7-gateway:
Starting… first, then off, with "Phone access could not start: … no
tty7-gateway beside it or on PATH". On a tty7-app daemon: on, with Show
code enabled and no toast.
* feat(mobile): drop the "Needs you" section
The machine screen gathered every pane whose agent was waiting or done into
a "Needs you" section above the workspaces. Done lasts until the next prompt,
so the section grew with every finished agent and mostly held panes that
needed nothing.
Panes now appear once, in their own workspace. Each keeps its status badge
and words ("Needs input", "Working", "Done") and the agent's message.
PRODUCT.md and the design sidecar are updated to match.
* fix(mobile): say when typing doesn't reach the pane
The gateway's input thread gave up silently on a failed send_input, and
the app's input task did the same on a failed write, so the phone kept
showing a live pane while keystrokes went nowhere. Both now report the
failure as a pane error. Keys after it are dropped rather than ending
the stream, which the phone would read as the pane closing.
* feat(mobile): a compose box, paste and Shift+Tab on the terminal
Replying to an agent meant typing into xterm a character at a time,
without autocorrect, dictation or a usable IME. The compose box is a
real text field: Send types the text and then Enter, as its own write,
and several lines go in as one bracketed paste when the program asked
for it. Drafts survive leaving the pane and a send that failed. An
agent's pane opens on the box with the keyboard down.
The key bar gains Shift+Tab (Claude Code's mode switch) and a paste key.
A failed keystroke now takes the pane offline with a Reconnect banner
instead of being swallowed.
* feat(mobile): reconnect on its own, and select text to copy
A dropped pane or machine stream is retried with backoff (1s, 2s, 4s …
15s) and at once when the network comes back, rather than waiting for a
tap on Reconnect. The pane keeps its last screen up until the new
replay starts, and output or errors from a replaced stream are ignored.
Touch selection does not work in xterm, so a copy key lays the whole
buffer out as plain text over the pane, wrapped to the phone and joined
where the terminal wrapped, for the phone's own selection and Copy.
* feat(daemon): size leases, and Take Back on the desktop
An observer can now run a pane at its own size (ClientMsg::Lease, feature
size-lease). The pty and every observer go to that size. The controller
keeps its grid, its resizes are remembered rather than applied, and the
pane goes back to the last of them when the lease ends: the observer lets
go, its connection closes, or the controller takes it back.
A controller hears about leases only after asking (Watch), since an older
client cannot decode DaemonMsg::Lease. The desktop asks on every attach,
spawn and relink where the daemon advertises the feature, locally or
through the host hello for remote workspaces, and shows the pane as in
use on the phone with a Take Back button.
* feat(mobile): take a pane over at the phone's size
The terminal's phone button asks the gateway to run the pane at the
phone's grid (PaneRequest::TakeOver), which it turns into a size lease on
the observer connection, named after the paired device. The grid follows
the keyboard and rotation; leaving the pane, or the connection dropping,
gives it back. When the desktop takes it back the app says so and offers
to take it over again, never doing it on its own. A daemon too old for
leases is reported, and the pane keeps working.
* fix(mobile): link SystemConfiguration and install a rustls provider on iOS
The first iOS build failed to link: netdev and system-configuration, pulled
in by iroh, need SystemConfiguration.framework, which the generated Xcode
project does not list. bundle.iOS.frameworks adds it on `tauri ios init`.
Once linked, the app panicked at launch: iroh builds its reqwest client with
`rustls-no-provider`, so a process-wide crypto provider must be installed
before any client is built. Install ring's, which is already in the tree.
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(mobile): keep the terminal's scrollbar on screen while panning
Panning a pane wider than the phone scrolled xterm's own box sideways with
the text. The box was only the view's width, so its vertical scrollbar
panned off with the columns and its scrollback stopped taking touches past
the first screen. The box now spans every column, and the bar is shifted
to the visible right edge as the view pans.
The bar is also drawn like the indicator WebKit shows for the pan, thin,
rounded and translucent, instead of VS Code's 14px square slider, so the
two axes match.
Co-Authored-By: Claude <noreply@anthropic.com>
* feat(mobile): pair by scanning the QR code, and Enter and quick-answer keys
Pairing took a pasted `tty7pair:` code, which on a real phone means getting
text off the desktop somehow. A Scan button next to Paste now reads the QR
code tty7 shows, through tauri-plugin-barcode-scanner, and pairs straight
away. The camera runs behind the WebView with our own viewfinder and Cancel,
since the plugin's full-screen view has no way out. The plugin is registered
on phones only, so the desktop dev build is unchanged.
The key bar gains Enter, so an agent's highlighted choice can be confirmed
without raising the keyboard, and 1 2 3 y n for numbered choices and y/n
prompts.
Co-Authored-By: Claude <noreply@anthropic.com>
* chore(mobile): sign for the App Store and declare exempt encryption
Sets the development team so `tauri ios init` writes it into the Xcode
project, and marks the app's encryption (standard TLS/QUIC only) as exempt
so TestFlight uploads skip the export-compliance question.
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(mobile): count the iOS safe areas once
The WKWebView's scroll view inset its content by the safe areas, and the
page, laid out with viewport-fit=cover, padded by env(safe-area-inset-*)
as well. The viewport came out 778pt tall on an 874pt screen: everything
sat a status bar's height too low, with a blank band under it. The scroll
view's automatic inset adjustment is now off, so the page runs edge to
edge and its CSS alone keeps clear of the status bar and home indicator.
Co-Authored-By: Claude <noreply@anthropic.com>
* feat(mobile): the Terminal Mobile redesign
The app takes the desktop's neutral greys, light and dark, with ink rather
than a system blue for what is pressed or chosen.
- Machines: pairing's "+" moves to a floating bar at the bottom beside a
search field. Each machine shows its link, round trip and tab count as
last seen.
- A machine: tabs grouped by workspace with a count; round agent glyphs;
a dot on the right for running or waiting on you. The per-group New tab
buttons give way to one "+" in the same floating bar, beside tab search.
- New tab: a sheet to pick Claude Code, Codex or a shell, and the
workspace. An agent's command is typed into the new tab once it is live.
- A pane: the bar keeps only back, the title with its state, and a menu
for selecting text, the fit and the phone's size. Under it, one row of
equal keys, a page at a time, and a message box that is always there;
its round button sends, or when empty hands the keyboard to the
terminal.
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(mobile): the tty7 mark as the iOS app icon
The phone showed Tauri's default icon: `tauri ios init` filled the Xcode
project with it. The committed icons/ios set was drawn on the macOS grid,
a rounded tile inset on transparency, which iOS would shrink inside its own
mask with a pale border. icons/app-icon-ios.svg is the same Duo mark full
bleed, rendered without alpha as the App Store requires.
Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
* fix(mobile): typing, scrolling and pairing on a real phone
- Typing into a pane: an input method's text never reached it, since iOS
never commits a candidate into xterm's hidden textarea. Tapping the
terminal now focuses a plain field of our own, whose committed text goes
to the pane as it is committed. Backspace on the empty field, Enter, Tab
and the arrows go as the terminal's keys.
- xterm sends nothing itself any more (disableStdin). That also stops the
phone answering a program's colour and device queries: the desktop
answers those, and the phone's late second answer landed in the shell as
typed text.
- Scrolling the scrollback: xterm 6 has no working touch scrolling. A
mostly vertical swipe now scrolls the buffer a row at a time and coasts;
a sideways one is left to the native pan.
- Pairing: the steps name the desktop's Settings -> Mobile, Allow phone
access and Show code, not a command-line gateway, and so do the notices
when a machine cannot be reached.
Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
* fix(mobile): room for the keyboard, and smoother vertical scrolling
- The keyboard: the WebView runs edge to edge and is not resized for it,
so it covered the dock and the pane's last lines. The app now takes the
size of the visual viewport, drops the home indicator's gap while the
keyboard is up, and keeps the cursor's line in sight.
- Scrolling: the terminal draws with xterm's WebGL renderer, which a
scroll does not make lay every row out again. A swipe is applied once a
frame, and moves the view by pixels: xterm scrolls whole rows, and the
rest of a row is a GPU shift of the drawn screen, put on together with
the rows it goes with.
Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
* feat(mobile): settings, message history, and a tighter home screen
- Settings, from beside the Machines title: appearance (automatic, light,
dark; the status bar and keyboard follow through the window's interface
style), terminal text size, how a pane wider than the phone first shows,
clearing the message history, and the version.
- The message box keeps what it sends on the phone. As a message is
written, past ones that match take the key row's place; with the box
empty, a History button opens them all, searchable. A line that asks for
a password is sent but not kept.
- ^R on the third key page, for the shell's own history search.
- A top-level screen's bar floats over the list, clear until the title
scrolls under it, so the large title sits just under the status bar.
Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
* fix(mobile): a fitted pane fills the view, and its scrollbar drags
- A pane shorter than the view (a wide one, fitted) no longer leaves the
bottom of the screen blank: the terminal here runs as many rows as fill
the view, the extra ones holding the pane's earlier lines, and what is
left over goes above so the prompt stays next to the keys. The pane on
the desktop keeps its size.
- A drag that starts on the scrollbar is left to xterm. The swipe handler
took it too, the other way round, and the two cancelled out.
Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
* fix(mobile): errors say what to do in the app, not on the command line
The messages a phone shows, and the two Settings → Mobile can, named the
gateway process, the CLI's `tty7 server start`, the transport and a lock
file's path. They now speak of tty7 on the computer and of pairing: open
it there, update it, pair again, quit the other copy.
Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
* style: rustfmt the gateway and mobile client
Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
---------
Co-authored-by: Claude <noreply@anthropic.com>
|
||
|
|
eec9350ff8 |
test(git): compare repo roots in one spelling so Windows passes (#1013)
canonicalize answers \\?\C:\... on Windows while git prints C:/...; the production path already folds the first into the local spelling in probe_repo, only the test compared them raw. |
||
|
|
12ec0c92a9 |
fix(sidebar): stop ungrouping tabs when a git probe fails (#1011)
A tab's auto group comes from probing its cwd for a repository. Any failure of that probe - git failing to spawn, the macOS /usr/bin/git shim dying while Xcode is mid-switch, a remote link dropping - came back as "not a repository", overwrote the tab's remembered group, and was never re-checked while the pane sat idle. Tabs in perfectly good repositories dropped into Ungrouped and stayed there. - Read root, home and branch in-process on this machine with gix-discover instead of three git processes. Only the line counts still come from `git diff --numstat`, so they keep matching the diff views; a detached HEAD is still named by git for the same reason. - Remote hosts keep asking their own git (a new control request would force a dialect bump), but the probe now tells "not a repository" (exit 128, or the directory is gone) apart from a failure. - A failed probe leaves the cache as it was, so a tab keeps its remembered group, and an unanswered cwd is retried every 10s. |
||
|
|
8cf31c718d |
feat(worktree): setup, .worktreeinclude, agent launch, recoverable removal, and a worktree CLI (#1009)
* feat(worktree): setup script, .worktreeinclude, fresh base, recoverable removal - Start new worktrees from the remote default branch, fetched first, with --no-track; fall back to the current branch without a remote. - Carry gitignored files listed in .worktreeinclude over from the main checkout, copy-on-write (clonefile on macOS, copy_file_range elsewhere); remote hosts copy through the Host trait under a size budget. - Run .tty7/setup in the first pane before the agent, with TTY7_ROOT_PATH, TTY7_WORKTREE_PATH, TTY7_WORKTREE_NAME and a per-worktree TTY7_PORT block. The script only runs once its exact content is approved for the repo. - The New Worktree dialog picks what the first pane starts (Shell or a recent agent) and takes a task for agents that open on a first message. - Removal snapshots the checkout, uncommitted work included, under refs/tty7/trash/<name> first; the ref also retires the name. A branch git refuses to delete is reported instead of silently kept. - Hide .tty7/worktrees via info/exclude rather than a catch-all .tty7/.gitignore, so .tty7/setup can be committed. * feat(cli): tty7 worktree new/ls/rm - worktree new: the GUI dialog's worktree from the command line — create, carry .worktreeinclude, open a tab named after the branch, and type .tty7/setup && <agent> [task] into it. Prints the path first. - worktree ls: every checkout of the repo, tty7's marked, with the live panes working in each. - worktree rm: refuses while panes are inside unless --close-panes, and a dirty checkout unless --force; reports the snapshot ref and a kept branch. - Move shell_quote and the first-line builders into tty7-core so the GUI and the CLI type the same line. - Docs: CLI reference and the Worktrees page cover .worktreeinclude, .tty7/setup, TTY7_PORT and recoverable removal. * fix(worktree): run setup and the agent inside the worktree; Start is a dropdown - The first line now opens with cd into the worktree: a shell's startup files can move the pane, and setup then ran in (and wrote into) the main checkout. - The Start choice is a dropdown listing Shell and every agent this machine offers, instead of a segmented switch capped at three. |
||
|
|
9c1961de39 |
fix(agent-hooks): make the OpenCode plugin load on OpenCode 2.x (#999) (#1007)
OpenCode 2.x only loads a default export shaped { id, setup | effect } and
rejects the file otherwise ("Plugin must export a default definition with
an id and an effect or setup function"). The generated tty7.js only had a
named export, so every 2.x user got a load error.
- Export default { id, server, setup }: 1.x (>= 1.3.4) reads `server`,
2.x reads `setup`; the named Tty7Presence export stays for older 1.x.
- 2.x: subscribe via ctx.event.subscribe(), read event.data, map
permission.asked, and treat session.created with a parentID as a child
session. Stay inert inside the shared --service process, whose sessions
belong to no single pane.
- Spawn the emitter directly with node:child_process instead of
`sh -c`, which does not exist on Windows.
|
||
|
|
7f66f69674 |
fix(ssh): pin russh to our fork with the zlib truncation fixes (#997) (#1006)
A host with `Compression yes` (every one imported from an ssh config that sets it) negotiated zlib@openssh.com, and the pinned ayamir/russh rev cut every packet that inflated past 2x its compressed size. The zlib stream desynced right after auth: the session showed as connected and never printed a byte. - Move the [patch.crates-io] pin to l0ng-ai/russh (branch tty7): ayamir's gssapi-with-mic commit plus Eugeny/russh 58886f4d and 24e2c374. - Add an end-to-end test that runs a zlib session against an in-process russh server and checks every byte of a compressible + incompressible payload arrives (0 of 270336 bytes on the old pin). - Re-importing an ssh config now updates `algorithms` on hosts that already exist, so dropping `Compression yes` and re-importing takes effect. |
||
|
|
7016fdb7ed |
feat(editor): IDE-level code editor — multi-cursor, LSP, git gutter, symbols, split (#1002)
* fix(keymap): let the code editor's multi-cursor chords beat the pane keys
gpui-component now binds secondary-d, secondary-shift-l and
secondary-alt-up/down in the Input context for multiple cursors. A
context-free binding ranks as deep as the focused context and ties go to
the one added last, so tty7's SplitRight and FocusPaneUp/Down took those
keys inside the editor. Re-add the editor bindings after tty7's table; other
text fields have no handler for them and fall through to the pane keys.
* feat(editor): show the selection count in the status bar
With several cursors the Ln/Col readout (the primary caret's) is followed
by "(N selections)".
* feat(editor): git change markers in the gutter
Diff each buffer against its file's index version (what VS Code's quick
diff and the SCM panel's Changes compare with) and hand the hunks to the
editor as gutter markers: added, modified, and a wedge where lines were
deleted. The base is read with `git show :./name` through the buffer's own
host, so remote workspaces work too; SFTP buffers and untracked files get
no markers. It is re-read when the repository's SCM epoch moves, on save
and when the path changes; the diff itself is a line-level Myers diff run
off the UI thread shortly after each edit.
Next/previous change and Revert Change (one undo step, also in the
right-click menu) are commands; clicking a marker opens a peek of the
staged lines with a Revert button. The editor watch now also follows the
repository the gutter found, so a stage or checkout refreshes the markers.
The `editor_git_gutter` config (default on) is flipped by the
ToggleEditorGitGutter command.
* feat(editor): go to symbol, breadcrumbs, and back/forward navigation
Go to Symbol (Cmd-Shift-O in the editor) lists the file's outline on a new
Symbols tab of Search Everywhere: indented by nesting while browsing, ranked
flat with the containing symbols as a subtitle while searching. Arrowing
through the rows previews each symbol; Escape puts the caret and the scroll
back, Return keeps it.
The outline comes from the tree the highlighter already parsed, with a small
query per language (Rust, Go, Python, JavaScript, TypeScript/TSX, C, C++,
Java, Markdown, Ruby, shell). Tty7App::editor_set_document_symbols lets a
language server's documentSymbol answer replace it per buffer.
A breadcrumb row over the text shows the file's path from its project root
and the symbols around the caret; the symbols open Go to Symbol.
Back and forward (Ctrl-- / Ctrl-Shift-- on macOS, Alt-Left/Right elsewhere)
walk a per-tab history. Jumps are noticed by sampling the caret whenever the
editor draws: a change of file, or a move of ten lines or more without an
edit, records where the caret was. Quick open, go to line, file links and
anything that goes through open_file_in_editor_at are therefore captured
without hooks of their own; a place in a closed file reopens it.
* feat(editor): bind next/previous change to Alt+F5 in the code editor
Bind EditorNextChange / EditorPrevChange to alt-f5 / shift-alt-f5 in the
Input context only, after tty7's own table, so a terminal never loses the
function key. Mark the hunks stale right after a revert, before the
input's Change event lands, and cover the whole loop (markers, stepping,
revert as one undo) with a window test.
* feat(editor): line commands in the editor's right-click menu
Toggle Comment, Move Line Up/Down, Duplicate Line, Delete Line and Go to
Matching Bracket, dispatched to gpui-component's new editing actions so
each row shows its chord. Strings in en, zh and ja.
* feat(editor): language servers for the code editor
A new ui::lsp module runs language servers for local files the editor
opens: rust-analyzer, typescript-language-server, pyright (or pylsp),
gopls and clangd, from a registry table. Each server is keyed by
(server, project root), found from markers such as a Cargo workspace,
package.json, go.work/go.mod or pyproject.toml, and shared by every buffer
under that root. A server missing from PATH (which tty7 already fills from
the login shell) means no LSP for that language and a one-line hint in the
status bar.
The JSON-RPC client frames Content-Length messages over the server's stdio
on dedicated threads, holds everything back until initialize is answered,
cancels requests nobody waits for any more, and answers the server's own
requests (configuration, capability registration, applyEdit). Documents
use full-text sync, debounced, and flushed before every request. A server
whose last file closed shuts down after a grace period, every server exits
with the app, and one that crashes is restarted a few times before it is
left down.
Features: diagnostics as underlines with hover messages and an error and
warning count in the status bar; completion (snippets flattened to plain
text); hover; go to definition by secondary-click or F12, across files
through open_file_in_editor_at; code actions on the editor's own menu
(cmd-.), resolved and executed as the server needs; Format Document
(shift-alt-f); and Rename Symbol (F2) in the editor's bar, applied to open
buffers and to files on disk. The key bindings sit in the Input context so
F2 and F12 stay with terminal programs.
Positions are converted at the boundary: servers count UTF-16 units,
gpui-component counts chars, and the rope counts bytes.
The new editor_lsp setting (default on) turns it all off.
* fix(editor): clear the change markers when the file loses its base
A file that becomes untracked or leaves its repository kept the markers
of its last diff; clear them when the base goes away. Guard the base read
against a panic, which would otherwise leave the fetch flagged forever,
and test the read against a real repository: the base is the staged
version, and untracked files have none.
* test(keymap): the editor's navigation chords win inside the editor, not in a terminal
* fix(keymap): let the code editor's line commands beat the app's chords
The editor binds toggle comment, move/copy/delete line, insert line, select
line and go-to-bracket on its CodeEditor key context. A context-free app
binding ranks as deep as the focused context and wins the tie by being
added later, so ⌘/ (shortcut sheet), ⌘↵ (fullscreen), ⌘⇧↵ (maximize) and,
off macOS, ⌥↑/⌥↓ (pane focus) took those keys inside the editor. Re-add
them in fixed_bindings on CodeEditor, which only a multi-line code editor
declares, so plain text fields and the terminal keep the app's keys.
* fix(keymap): route cmd-K cmd-D to the code editor's skip-occurrence
The chord starts with ClearScrollback's key on macOS, and gpui drops a
pending chord that ranks below a complete match, so the fork's binding
never got its second key. Re-add it after tty7's table, in the CodeEditor
context only, so other text fields don't wait on cmd-K.
* feat(editor): history follows edits, and paging is not a jump
Places in the back/forward history now move with lines inserted or deleted
above them, read from the editor's line-edit log on every change. The caret
move a Page Up/Down, paste, undo or redo makes is heard through the
keystroke that caused it and is not recorded as a jump.
* feat(editor): Problems list, keyboard change peek, Editor settings
- Problems: every error, warning and note the language servers published
for the open files, grouped by file, at the foot of the code panel.
The status bar's counts and ToggleEditorProblems (Cmd/Ctrl+Shift+M)
open it; a row opens its file at the line and column. Read through a
new LspStore::diagnostics_snapshot, mapped to editor columns.
- EditorPeekChange (Alt+F3 in the editor) peeks the change under the
caret, or goes to the next one. The peek now takes the keyboard from
a click too: Enter reverts, Escape closes and hands focus back.
- Settings > General gains an Editor group: git change markers,
language servers, soft wrap and rendered Markdown, searchable and
resettable like every other row.
* feat(lsp): outline, references, workspace symbols, signature help
- documentSymbol feeds the editor's outline (breadcrumbs, Go to Symbol)
through editor_set_document_symbols, refreshed 500 ms after typing
pauses. Flat answers are nested by range; an empty answer from a server
still indexing leaves the tree's outline in place.
- Find All References (shift-F12) and a definition with several answers
open a Locations tab in the search. Arrowing through it previews a place
in the file in front, and Return goes there, into any file.
- Go to Symbol in Workspace (secondary-T inside the editor) asks the
server's workspace/symbol as the query is typed, into the same list.
- Completion items are resolved for their documentation and auto-import
edits, which are applied on accept (with the gpui-component fork).
- Signature help opens on the server's trigger characters (or on '(' and
','), stays current while typing in the call, and closes when the server
says the cursor has left it or on Escape.
- Diagnostics are replaced wholesale on publish; between publishes the
fork now carries them through edits instead of dropping them.
- workspace/configuration answers from per-server settings, with an empty
object for a section tty7 sets nothing for. rust-analyzer gets
checkOnSave with cargo check, also as initializationOptions, and every
server gets didChangeConfiguration after initialized.
* feat(editor): text commands in the palette and keymap
Transform to Upper/Lower/Title Case, Trim Trailing Whitespace, Join Lines
and Remove Surrounding Brackets, as tty7 actions (bindable on the
Keybindings page, unbound by default) and as palette rows offered while a
buffer is open. Both run gpui-component's editing action on the active
buffer. Join Lines gets VS Code's ctrl-j as a fixed CodeEditor binding on
macOS, where the terminal keeps it as a line feed. Strings in en, zh, ja.
* feat(editor): split the editor into two groups
Cmd-\ (Ctrl-\ off macOS, bound only inside the editor so the terminal keeps
SIGQUIT) opens the file in front in a second group on the right. Each group
has its own file in front and, for different files, its own caret and
scroll; Cmd-Alt-Left/Right (Ctrl-Alt off macOS) or a click moves the focus
between them, and a group whose last file closes goes away. The split is
saved with the tab's other editor state.
The focused group is always TabCode's own files/active and the other waits
beside it, so everything that acts on the file in front - saving, go to
line, language servers, change markers, multiple cursors, history - follows
the focus unchanged. A file shown in both groups is drawn once, in the
focused one; the other shows a placeholder that brings the focus over. A
second InputState kept in sync would have needed every hook attached twice.
Also: palette rows and View menu items for Go to Symbol, Back, Forward and
Split; Cmd-Shift-O closes Go to Symbol when it is open; the status bar no
longer repeats the path the breadcrumbs show (a rendered Markdown file keeps
its breadcrumb path); change markers are kept current in both groups.
* test(keymap): the editor group chords win inside the editor
* fix(lsp): close a window's documents when the window closes
Documents were only closed by sync_window, which runs when a window's
buffer set changes. Closing a window never ran it, so no didClose was
sent, the idle shutdown never started, and a language server lived on
until quit (forever, with the app retired to the tray).
* fix(editor): restore a split whose left group had no recorded files
The recorder writes files: [] with a split when the left group held only
untitled or remote buffers, but restore returned early on an empty left
list and dropped the right group too.
* fix(editor): forget a swept orphan buffer's navigation state
The orphan sweep dropped clean buffers without calling forget_buffer, so
each one's outline cache (a full copy of its text), LSP symbols and
edit-log cursor stayed in EditorNav for the life of the window.
* fix(lsp): owner-only sync, stale-edit checks, request timeouts, re-enable
- Only the buffer that owns a document may use its server. The same file
open in another window used to send its own text as didChange on F12,
rename, references or signature help, swapping the document under the
owner. LspStore::context now takes the requester and refuses a
non-owner quietly, before anything is sent.
- apply_workspace_edit checks every open buffer an edit touches against
a baseline: the texts when a rename was asked for or the code-action
menu was filled, or the text the server last heard for its own
workspace/applyEdit (which then answers applied: false). A buffer typed
in, opened or closed since means nothing is applied.
- A request made after the server's output closed fails at once instead
of waiting forever. Requests time out after 10 s (initialize after 60 s,
shutdown after 2 s) and cancel themselves on the server.
- Turning editor_lsp back on asks every window for its open files again,
which starts their servers. Windows register how to be asked; closed
ones are forgotten.
* test(nav): spell out LineEdit's new at_line_start field
gpui-component's LineEdit now records an insertion at column 0, which
moves the whole line down. The literal edits in this test are mid-line.
* fix(editor): a restore merges into the tab, and commands follow the group focus
Session restore used to assign the recorded groups over whatever the tab
held when its files finished loading, so a file opened or a split made in
the meantime was lost. TabCode::restore_groups keeps a split made meanwhile
as it is, and otherwise lays out the recorded groups and puts the files
opened meanwhile back into the focused group, the last of them in front. A
restore the reader has moved on from no longer takes the keyboard, and never
hides a panel they opened.
The group focus only followed the keyboard when the editor drew. Keys are
safe - gpui draws a window whose focus moved before dispatching the next
key - but a command from the menu bar or a context menu is dispatched
without a draw, and acted on the group that had the focus before. A
capture-phase listener for every editor command on the editor's element now
settles the group first, wherever the command's handler sits.
* fix(editor): leave cmd-T to New Tab; offer workspace symbols from the palette
Inside the code editor cmd-T was rebound to Go to Symbol in Workspace,
which made tty7's most-used chord mean two things depending on focus.
It is New Tab everywhere again. Workspace symbols stay reachable as an
Editor palette row and as a rebindable, unbound action.
* build: pin gpui-component to the fork's editor work (0e7541fb)
* fix(search): let the editor's pickers stand alone in Search Everywhere
Go to Symbol, a language server's places and Go to Symbol in Workspace
opened on hidden tabs, so the window-wide scope row (All, Terminals,
Sessions, Hosts, Commands) sat over them with nothing selected, and Tab
swapped the list for the terminals. They now show a heading in place of
the row (References / Definitions / Symbols / Workspace Symbols, with a
count), Tab stays put, and the footer drops the scope hint.
* fix(search): Go to File stands alone like the editor's pickers
Go to File (cmd-O) is reached only by its chord, yet it sat under the
scope row with nothing lit and offered Tab to leave for the terminals.
Every tab outside the row now stands alone the same way: its name in
place of the row, Tab stays put, no scope hint in the footer.
* feat(search): give the editor its own scope row — Files, Symbols, Workspace Symbols
Go to File, Go to Symbol and Go to Symbol in Workspace were three
separate pickers, each on its own chord. They now share a second scope
row, the editor's, next to the window's: cmd-O and cmd-shift-O open on
it and Tab walks it. Only tabs that can answer show: Symbols needs a
file in front, Workspace Symbols a language server that searches the
project. A row of one shows as a heading. Each tab is opened the way its
chord opens it, so it arrives set up; references and definitions still
stand alone.
* feat(search): fold Workspace Symbols into Symbols
Symbols and Workspace Symbols answered the same question at two scopes.
Symbols now does both: with nothing typed it is the file's outline; once
a query is typed, the front file's language server is asked across the
project and its answers are listed after the file's own, each under a
heading when both have rows (the front file's own hits are dropped from
the project's). The separate tab, action and palette row are gone.
* fix(search): call the language server's project results Project, not Workspace
LSP's workspace/symbol searches the server's project root, which has
nothing to do with a tty7 workspace (a group of tabs). The Symbols tab's
second section said Workspace, reading as if it searched those. It says
Project now, and the tty7-facing names follow (project_symbols,
set_project_symbols, lsp_project_symbol_query); only code that speaks
the protocol keeps its word.
* ci(host-boundary): allow the language servers' local reads
ui::lsp only ever holds local buffers (OpenFile::local refuses any other
host) and runs its servers on this machine, so the files it reads to
measure a column, apply a rename to disk or find a project root are on
this disk. Each call is allowlisted with that reason.
* test(editor): spell test paths so they hold on Windows
The language-server tests used /p/... paths, which are not absolute on
Windows and so have no file:// URI; they now build platform paths
(lsp::test_path) or spell the URI out. The gutter and split tests
canonicalized their temp dirs to get past macOS's /private symlink,
which on Windows yields the \\?\ form no editor path is ever in; they
share a helper that canonicalizes everywhere but Windows.
* test(editor): resolve temp dirs the way the editor does
On the Windows runner the temp dir is an 8.3 short name (RUNNER~1),
which the editor's load expands through Host::canonicalize. The split
tests now resolve their fixtures through that same call instead of
guessing per platform.
|
||
|
|
3ef692b353 |
feat(agents): infer interrupted and stale turns, report permission prompts first-hand (#1003)
- Interrupts: an Esc / Ctrl+C (legacy, kitty and modifyOtherKeys forms) on a pane whose agent is mid-turn arms a 1s settle; if no hook event arrives, the turn is assumed over and goes Done. Claude's Stop skips user interrupts, so panes used to stay on working until the next prompt. - Stale turns: a daemon sweep moves a turn that has been Working with no hook event for 30 minutes to Idle. - Both set `inferred` on the session; the next real event clears it, and a tool finishing after a guess puts the turn back on Working. Inferred states raise no finish notification and no unread badge. - Claude and Codex now hook PermissionRequest, and PreToolUse for their ask-the-user tools (AskUserQuestion / request_user_input), so Waiting shows the moment the prompt opens. Codex also gains PostToolUse, so it leaves Waiting once the approved tool has run. - The "finished" desktop notification waits 1.5s and is dropped if the next turn starts first (queued message, Stop hook sending it back). |
||
|
|
2e0d4de136 |
feat(github): show a pull request's checks, reviews and merge state (#1000)
The PR detail now leads with what it is usually opened to find out:
- Checks: check runs and commit statuses on the head commit, failures
first, with durations and links to their logs. A section with more
than five folds the passed and skipped ones into one row.
- Reviews: one row per reviewer (approved, changes requested,
commented, requested), folding the way GitHub's sidebar reads them.
- A merge-state line under the branches ("Waiting on 1 check",
"1 check failing", "Merge conflicts", "Ready to merge", ...).
Checks and reviews that cannot be read are left out instead of failing
the whole detail. While a check is running, just the checks are re-read
every 20 seconds (signed in only); once every verdict is in, the detail
is read again for the new merge state.
The list pins the pull request of the pane's branch under the repo row,
looked up through the branch's upstream so a fork's branch is found
under the fork's owner.
Long sections fold: comments past four keep the first and the latest
two, long descriptions and comments are clamped behind "Show full text",
and reviewers and changed files show a few with a "show all" row.
|
||
|
|
643e0f7d95 |
feat(agents): add Qoder CN CLI integration (#988)
* feat(agents): add Qoder CN CLI integration * fix(agents): spell Qoder CN's config override QODERCN_CONFIG_DIR The China build of Qoder resolves its configuration through QODERCN_CONFIG_DIR. The first pass invented QODER_CN_CONFIG_DIR instead, so an install that set the real one was treated as unrelocated: hooks went to ~/.qoder-cn and history was scanned from a directory the CLI never writes to. The test that should have caught it set the same invented name, so it only proved the name agreed with itself. Picks up the rest of the review as well — detect the `qoder-cn` dispatcher beside the other two binaries, call it the mainland-China build rather than a different vendor, and drop the QODER_CN_HOOK_EVENTS alias for the table it only pointed at. The serialized enums keep their variants appended; only the independent ALL arrays moved QoderCLICn next to QoderCLI. |
||
|
|
39776012e2 |
feat(github): read a repository with whichever gh account can see it (#987)
The GitHub panel borrowed only gh's active account, so a private repository owned by an organisation another signed-in account belongs to read as a 404. When the active account gets a 404, 401 or 403, retry with gh's other github.com accounts and remember, per owner, the one that got through. The other accounts are listed lazily (gh auth status checks each online), and a token from GH_TOKEN/GITHUB_TOKEN keeps its no-fallback meaning. |
||
|
|
bf5149bea0 |
fix(editor): stop losing edits, share buffers, add file strip, quick open and go to line (#984)
* fix(host): save local files atomically via a temp file and rename LocalHost::write_file truncated the target in place, so a crash, a full disk or a killed process mid-save destroyed the user's file. It now writes a hidden sibling temp file, syncs it, keeps the old file's mode and renames it over the target, removing the temp file on any error. It still writes in place where a rename would change something visible: a non-regular target (symlink, directory, FIFO), a read-only file, and on Unix a hard-linked file or one owned by another user, or when the temp file cannot be created (e.g. a read-only directory). * feat(editor): add editor_text for encodings, line endings, indentation and EditorConfig A pure module the code editor will use when loading and saving files: decode detects BOMs, binary files, UTF-8, GB18030 and a lossless Windows-1252 fallback and normalises CRLF; encode restores the exact bytes and names the first unrepresentable character; detect_indent infers tabs or a 2/4/8 space width with language defaults; and editorconfig_for resolves .editorconfig sections with save-time rules. * feat(editor): share buffers across tabs, guard unsaved work, add a file strip - One buffer per file per window; tabs list which buffers they show. The same file open in two tabs is no longer two diverging copies. - Closing a tab, its last pane, the window, or quitting asks about unsaved files (Save / Cancel / Discard) instead of dropping them. Bulk closes skip tabs with unsaved files; a tab that vanishes any other way hands its unsaved buffers to the tab in front. - File tree rename/delete now retarget or flag the open buffer, so a save no longer recreates the old path. - Saves check the file's mtime first and ask before overwriting a change made elsewhere; this is the only detection SFTP buffers get. - Dirty is a comparison with the saved text, so undoing back clears it. - Reloads replace only the changed span as an ordinary edit, keeping undo. - Load/save go through editor_text: encoding, BOM and CRLF round-trip, indentation is detected, .editorconfig is honoured. - Header shows a strip of open files; New File, Save As (native panel locally, a path bar remotely), Go to Line (Ctrl+G), and the status bar shows indentation, encoding and a clickable line ending. - Open files are remembered per tab across restarts. * feat(search): quick open a file by name from a Files tab Search Everywhere gains a Files tab that finds any file in the active tab's project by fuzzy name and opens it in the built-in editor, with `name:line[:col]` jumping to that spot. The list comes from one walk of the project through the host (Host::search with an empty query), so it works the same on local, SSH and WSL workspaces and skips what the tree hides: dotfiles, .git and gitignored paths. The walk is capped at 50k entries / 20k directories, kept between openings and revalidated in the background each time the search opens. Files join the All tab once a query finds them. Go to File... is bound to Cmd+O on macOS (Cmd+P is already Search Everywhere) and ships unbound elsewhere, where every obvious chord is taken or owed to the shell. * chore(editor): allowlist the editor session file, tidy lints * fix(editor): keep restored file order, drop stale close waits, carry files through tab merges - Background arrivals (restore, merge, rescue) append to the strip in order instead of inserting beside the active file, which reversed them. - A cancelled Save As, a dismissed path bar, or a dropped buffer cancels any close that was waiting on that save. - Merging a tab into another carries its open files along. - A shell exiting closes its tab without a prompt it could not honour; unsaved buffers move to the tab in front. - Tabs rebuilt under the same id (server restart) restore their files. * fix(host): only fall back to an in-place write when the rename is refused On Windows every failure of the atomic save fell back to fs::write, including a failure while staging the temp file. A full disk would then truncate the original in place, the very loss the temp file prevents. Staging errors now return as-is; only a refused rename (a file held open elsewhere) takes the in-place path. |
||
|
|
b063ba97a0 |
refactor(settings): fold Window & Tabs into General, drop two settings (#982)
The Window & Tabs page is gone. Its three remaining tab settings (new tab position, tab bar position, auto grouping) are a Tabs group on General, below Startup & restore, so the nav has seven sections. Removed outright: - SSH tab title (`ssh_tab_title`, #726, unreleased). The sidebar already groups SSH tabs under their host, and renaming a tab pins its name. - Open diff preview from sidebar counts (`sidebar_diff_preview`, #247). The sidebar counts and the Info panel's changes row always open the diff overlay; the large-tree stall it worked around is bounded. An old config.json that still carries either key loads as before. The now-unused window settings icon goes with the page. |
||
|
|
fd2c4f7d4e |
feat(panel): Search and GitHub tabs in the right panel (#978)
* feat(panel): add Search and GitHub tabs to the right panel The right panel grows from three tabs to five. Five word labels do not fit the panel's 280px resting width, so the tab row now draws a glyph per tab and names it in a tooltip. Both new panes are placeholders here; the content search and the GitHub issues/PR browser land on top of this. * feat(panel): find in files in the right panel's Search tab The Search tab replaces its placeholder with a content search over the active tab's project -- the same roots the Files tab shows -- on the host that project lives on. Hits arrive as you type (debounced, with a generation counter so a stale answer never lands), grouped by file with a count, each line excerpted with its matches highlighted. Clicking a hit opens the built-in editor at that line and column; Enter searches again. Match-case, whole-word and regex toggles sit at the end of the field, and the tab focuses its field whenever it is brought forward. Host::search_content is new on the Host trait, implemented once in host::content_search (ignore walk + regex) and run by LocalHost directly and by tty7-server over a new SearchContent control request. The walk honours .gitignore with or without a repository, skips dot-entries, binary files and files over 1 MB, and reports a capped search as truncated. The request is gated on a new `content-search` hello feature, so a server that predates it is never sent it; the panel says the server needs updating instead of showing no results. Conformance cases cover local and the stdio server alike. * feat(panel): browse GitHub issues and pull requests in the right panel The GitHub tab follows the focused pane's repository: its root is resolved the way the Source Control tab does, its remotes are read through the Host (the tree may be on another machine), and the github.com remote is bound, upstream over origin in a fork, with a menu to pick another. The list switches between issues and pull requests, open and closed, 50 rows a page with Load more; rows carry a state glyph distinct by shape, labels (click one to filter by it) and relative times. A row opens the detail in place: title, state, author, labels, description and comments as Markdown, and for a pull request its branches, size and changed files. A file opens in the diff overlay through a new supplied-patch DiffSource, so GitHub's patch renders exactly like a local one without a git probe. Read-only, and sign-in reuses the GitHub CLI: GH_TOKEN, GITHUB_TOKEN, then `gh auth token`, found on PATH or at the Homebrew locations a Finder launch cannot see. Signed out, public repositories still work; 401, 403, 404 and rate limits are told apart and explained. Requests go out from this machine over the installer's ureq stack and proxy settings, on threads of their own, cached per repository with background revalidation. Remote images in issue text become links instead of loading, and non-web link targets are disarmed. The Info tab gains a GitHub row that opens the branch on the remote it tracks, or the repository for a branch never pushed. * docs: list ShowRightPanelGitHub with the other panel actions * feat(panel): one-line GitHub rows, a pill for the current tab - GitHub list rows are one line: state glyph, #number, title. Labels and the age of the last update appear on hover, from state rather than a group_hover display switch, which gpui cannot paint. - The current right panel tab sits on the sidebar's selected fill; ink alone could not tell five same-weight glyphs apart. - The GitHub glyph is a 1.8px outline like the other tab icons, not the filled mark. - The detail byline names both times (opened / updated) so it no longer reads as disagreeing with the list's update age. * feat(github): show screenshots pasted into issues Images GitHub hosts itself (github.com/user-attachments, a repo's /assets, *.githubusercontent.com) now render in issue and PR text, each in a paragraph of its own so the text view draws it at its size rather than at line height. Images from any other host stay links, so opening an issue still tells no third party that you read it. gpui held a null HTTP client, so no remote image could load; the app now installs the update check's reqwest client (same user agent and proxy) at launch. * fix(github): load private-repo screenshots, give inline code a neutral fill - Pasted attachments (github.com/user-attachments/assets/<uuid>) want a browser session on a private repository, which an API token is not. The detail and comment requests now ask for the full media type, and each attachment is swapped for the signed private-user-images URL the rendered body_html carries for the same uuid. - Inline code in rendered Markdown (the GitHub tab and the editor's preview) sits on a faint neutral fill instead of the theme accent, which is also the selection colour. Needs gpui-component 6af19d91 for TextViewStyle::inline_code_background. * style(panel): tidy the GitHub and Search tabs' top rows - GitHub drops its heading row on macOS. It existed only to hold the refresh tile, and no other tab has one; refresh now sits with the repository's other actions, in the repo row and a detail's header. - Search's Aa / ab / .* toggles are muted while off instead of body ink. - Search's idle note puts the folder on its own line, spelled ~/…, so the narrow column no longer breaks the path at a slash. * feat(panel): order the right panel's tabs Info, Files, Search, Changes, GitHub Info stays first as the default and the pane's overview; after it come two pairs, the project's files (Files, Search) and its version control from local to remote (Changes, GitHub), where Changes and GitHub were split by the file tabs before. The palette, the Keybindings list and the docs follow the same order. * style(panel): drop the change count from the Changes tab Beside one glyph of five, the number read as a badge on that tab alone, and the Changes tab already leads with the same count under its own heading. right_panel_tabs no longer needs the row's width, which it only measured to decide whether the count fit. * style(icons): fit the GitHub glyph to the other tab icons' size The Lucide mark filled its whole 24px box, edge to edge, where tty7's own icons keep about 3.5px clear, so at 15px it drew a size larger than the four tabs beside it. Scale it to 0.9 about the centre, and raise the stroke to 2.0 so it still renders at the others' 1.8. * style(icons): a simpler GitHub glyph Drop the Lucide mark's tail and redraw the head and legs on tty7's own grid: the same ~15px live area and 1.8 stroke as the other tab icons, no scale transform. The legs keep it reading as the Octocat; a head alone read as any cat. * test(github): find gh on PATH in the blank-variable token test The test placed gh only at /opt/homebrew/bin/gh, which gh_candidates never offers on Windows, so the Windows CI job panicked at unwrap. Put gh on a PATH directory spelled with the platform's exe name instead. * fix(github): close image and link bypasses in the issue Markdown sanitiser Checked against markdown-rs (the parser TextView uses), several inputs got past the line-based rewrite: - is_github_hosted cut the host only at `/`, so `https://evil.io?.githubusercontent.com/x.png` (and `#`, `\`, `/`) counted as GitHub-hosted and was fetched from evil.io. The host now ends at the first of `/?#\` and may hold only DNS characters. - `<img src>` values were written into `` unescaped, so a `)` in the value closed the image and opened a second one from any host. Written destinations are now percent-encoded. - `<image>` (which the HTML parser reads as `<img>`) passed as an ordinary tag and loaded its src. - A kept link target was copied without scanning; when the parser ended the link elsewhere (open title, unbalanced paren) a `` inside it came alive. Markup characters in it are now encoded. - `file:///...` and similar character references passed is_safe_target and decoded to a `file:` link. References are decoded before judging. The rewrite still cannot see every construct the way the parser does (code spans inside tag attributes, fences the parser rejects, multi-line link definitions), so the detail view now also checks the parsed tree: a block containing a non-GitHub image, an unsafe link or definition, or raw `<img>` is drawn as its plain source instead. * fix(github): hide gh's console, bound Retry-After, and reject URL authorities with ?#\ - run gh through proc::output_within with hide_console, so a Windows GUI launch does not flash a console window and stdout is drained while gh runs. - saturating_add a hostile Retry-After instead of overflowing i64. - parse_github_url no longer accepts `https://evil.io#@github.com/o/r`. * fix(search): no panic on an unbounded time budget, and read files through the size cap ContentLimits arrive off the wire on a server; Instant + u64::MAX ms panicked. A file that grew between the size check and the read was read whole; it is now read through a take() at the cap. * fix(panel): keep Load more on an empty filtered page, and drop another host's hits - /issues pages filtered to one kind can come back empty while later pages hold matches; the GitHub list said "No issues" and hid Load more. It now reads on through up to five such pages and keeps Load more offered. - While a new search runs, the previous hits stay on screen; if they came from another host, a click opened their path on the active host. They are now kept only when the host is the same. |
||
|
|
ed939bbc26 |
feat(search): browse every agent's past sessions, locally and on remote workspaces (#977)
* feat(search): list more agents' past sessions, and fork, copy or hide one The Sessions tab listed Claude Code and Codex only, and a row could only be resumed. - Past sessions of Gemini CLI, Qwen Code, Pi, Oh My Pi, Kimi Code, Copilot CLI, Droid, Qoder CLI and CodeBuddy are read from where each keeps them (honouring QWEN_HOME, COPILOT_HOME, KIMI_CODE_HOME, …), with the name the agent or user gave the session, else the first prompt. Context blocks agents prepend (<system-reminder> and kin) no longer hide a prompt. - Cmd/Ctrl-E on a session row opens its actions: Resume, Fork Session (agents that can fork, with the configured launch flags), Copy Session ID, and Remove from List. Removing keeps the search open, drops the row at once and remembers it in `hidden_agent_sessions`; the agent's own history is not touched. OpenCode and Cursor keep sessions in SQLite and are not read yet. Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM * feat(search): list remote workspaces' sessions, and OpenCode and Cursor The Sessions tab only ever read this computer, and left out the two agents that keep their history in SQLite. - agent_history moves into tty7-core, and the scan goes through the Host: a local workspace reads this machine in-process, a remote one asks its server (new ControlRequest::AgentSessions; CONTROL_VERSION 11 -> 12, so each remote host takes one Update Server). Resumed or forked sessions open on that machine, in the directory they ran in. The last answer is kept per host so the tab does not open empty. - OpenCode: top-level, unarchived sessions from opencode*.db (or $OPENCODE_DB); a placeholder title gives way to the first prompt. - Cursor CLI: chats under ~/.cursor/chats (or $CURSOR_CONFIG_DIR), named from meta.json or store.db. Cursor files a chat only under the md5 of its directory, so it is placed by matching open tabs' and other sessions' directories; chats nothing matches are left out, since they could not be resumed anywhere. - SQLite is bundled (rusqlite), opened read-only, falling back to an immutable read when the writer's WAL cannot be shared. Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM * test(search): wait for the real scan before seeding sessions The search's own scan runs on a real thread. On CI it landed after the test seeded its rows and replaced them, so the edit gesture found no row. The test now waits for the scan first. Assertion messages no longer print session ids (CodeQL rust/cleartext-logging). Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM * fix(search): harden the past-session scan and note it in the changelog - Honour CLAUDE_CONFIG_DIR for Claude Code's projects, as the hooks installer already does. - Read a Codex rollout's head as bytes: the 2 MiB cap can split a multi-byte character, and read_line then dropped the whole session. - Escape `%` and `#` (not only `?`) in the immutable SQLite URI fallback, so a database under such a directory still opens. - Refuse a session id starting with `-`: ids now come from file and directory names on disk, and one would be read as a flag by the resume or fork command. - Update the unreleased Sessions changelog entry for the new agents, remote workspaces, the Cmd-E actions and the v12 dialect bump. * fix(search): spell the immutable SQLite fallback as file:///C:/ on Windows SQLite reads file:C:/x as a relative path, so the fallback open (and its test) failed on Windows. An empty authority and a leading slash name the file on every platform. * test(search): keep ? out of the fixture directory name on Windows Windows file names cannot hold a '?', so the fixture's create_dir_all failed there before the fallback was ever opened. |
||
|
|
84935813d5 |
feat(terminal): the mouse wheel no longer zooms the font by default
mouse_zoom_modifier now defaults to none. The platform modifier is cmd on macOS, held for so much else that the font jumped size mid-scroll (#668). Picking a modifier in Settings brings the wheel zoom back; cmd+/cmd- are unchanged. |
||
|
|
572bfc014b |
feat(ui): v4 redesign, including a rebuilt settings window (#973)
* feat(ui): restyle the right panel after the v4 design - Tab row: 12.5/16rem word tabs 22px in and 18px apart, the current one in body ink at medium weight; no hover pill, no underline bar, no hairline under the row. - Info: Session, Processes and Ports are spaced 16px apart with no rules; 28px medium muted headings, 28px Session rows on a 76px label floor with values in body ink, 26px process rows with a tree elbow for children, and an explicit empty line for Ports. - Files: the search sits in a 28px filled well; tree rows are 26px with a disclosure chevron column, ignored entries dim their icon instead of going italic, and a folder's change dot is 5px. - docs/design-system.md updated to match. * feat(switcher): restyle the workspace switcher after the v4 design - Card: 112px from the top, 12px corners, 48px search row with an esc keycap, 420px body split 340px / preview, 40px footer. - Workspace rows are 52px: a 26px initial disc carrying the link state as a ringed dot (live green, faint when offline, amber while connecting, red on failure), a medium name with its stable number, a machine · path · time line, and the tab count over the state word. - Preview rows are 44px with the sidebar's 18px brand disc, an all-muted branch · diff line, a Current label and a 5px dot that blinks with the sidebar while an agent is working. - Footer: ghost New workspace button and keycap hints for navigate, open and new window; the unused click-for-new-window string is dropped. * feat(scm): restyle the Changes tab after the v4 design - Pinned block keeps 8/10/14 rhythm; branch name medium, 26px sync tile. - Commit message box rests at 56px with a 7px radius. - Split commit control: inverted neutral fill when committable, faint fill otherwise; 6px radius and an inset 0.5px seam. - Change groups sit 16px apart under 22px sentence-case medium headers; file names take width first and directories right-align, eliding from the start. - History: 32px header, 26px rows inset with rounded hover, 1px lines and 7px beads (HEAD filled, others hollow), neutral inks on a single-lane page, age column always shown, faint HEAD pill. * feat(ui): restyle the rail and palette after the v4 design - Default Light/Dark take warm neutrals (#fcfcfb/#1c1c1e, #18181a/#ececed); Git added/modified seeds follow v4 green and amber. - The left rail gets its own tinted fill again (Neutrals.rail, 3% toward the ink) with its own surface ladder; the right panel keeps the content fill. Captions and hairlines are floored on the rail too. - Title bar is 48px; the bar over the terminal centres the active tab's title in caption ink when tabs live in the rail. - Rail header: 26px new-tab and collapse tiles, then the workspace chip and search field (28px, 7px radius). - Groups sit 16px apart under a 22px caption heading with 'branch · +a −d' in tabular numerals. - Rows are 30px (42px with a branch line), 16px avatars, medium weight when current, branch cut from the front, and a trailing 5px status dot (blinks while working, hollow while waiting, unread count as a pill). - docs/design-system.md updated. * docs(design-system): note the commit button's inverted neutral fill * fix(panel): align the right panel's insets with the v4 design - Rows pad 8px inside lists inset 12px, so text sits on a 20px column in every tab and hover fills start 12px in with a 6px radius. Headings, empty states and the Ports line move to the same column. - Tab labels 18px apart; the panel row's chrome tiles are 26px, 4px apart, 12px from the edge. Default panel width 280. - Info: label column floor keeps values at x=88; Ports add tile 22px. - Changes: 8px top gap on macOS, pinned block on 14px edges with the branch at 22, 12px sync glyph, 8px group chevron, 10px status cell, 1px between rows. - History: compact gutter for single-lane pages, filtered rows on the text column, 10px row gap, 24px age floor, header on 20px insets, 4/12 padding when expanded (heights re-counted in commits). - Files: search well at 12px with an 11px glyph, 10px before the tree, 16px indent step, 16px bottom padding. * feat(diff): restyle the diff overlay and commit detail after the v4 design Carry the v4 language into the diff overlay and the commit detail view: 0.5px hairlines at 8% ink, 26px row pills with a 6px radius, the rem type ladder from right_panel.rs, neutral chips instead of accent washes, the shared git_badge for status letters, and tabular figures on counts. Layout, spacing, type and colour only; no behaviour or i18n changes. * feat(ui): restyle the dialogs, notices and home page after the v4 design - New ui::dialog module holds the shared modal chrome, taken from the workspace switcher: a 12px card, a 48px title row with an esc keycap, 18px insets, a 40px hairline footer, 28px borderless field wells on the faint fill, 11.5px medium muted labels, and 18px keycaps. - Buttons: the primary is the inverted neutral fill, the Commit button's paint, instead of the accent. Secondary buttons are transparent with the surface's hover rung. Override on a changed host key stays the one red button. A disabled button sinks to the faint fill and drops its click handler. - SSH sheet: host and fingerprint lines sit in a mono detail well, and keyboard-interactive prompts become field labels. Banners match the sheet's width and card shape. - Worktree prompt: moves to the same card, with the path preview hung off the Name field. - Notice pill: severity moves from a tinted edge to a 6px leading dot. - Home: shortcut rows are 28px with a hover fill and keycap chords, and the remote strip's action uses the secondary button. * fix(panel): start Info and Changes flush under the tab row Their first line is text centred in a 28px row, so the extra 8px step put it visibly lower than the Files tab's search well. Only Files keeps it. * fix(scm): put the commit detail on the right panel's 20px text column * feat(palette): restyle the command palette after the v4 design - Card: the switcher's 12px corner, 112px drop from the top (shorter windows still scale it up), 600px max width. - Search row keeps the list's own field; an esc keycap sits in its trailing corner while the field is empty. - Rows are 32px with an 8px corner, 8px list inset and 10px padding. The keyboard row takes the popover's neutral selected step and a medium title instead of the accent wash, via a palette row element in place of ListItem. - Section headings: 28px, 11.5/16rem medium caption ink, on the rows' text column. Shortcuts are per-key 18px faint keycaps from ui::dialog. - New 40px footer with the switcher's keycap hints (navigate, open). - Empty state: headline in body ink, hint in caption ink. * feat(ui): carry the v4 chrome into panes, the file viewer and SFTP - theme: additive helpers for a device-pixel hairline, tabular figures and an inverted neutral button variant. - Pane splits rest as a device-pixel hairline in the divider tone; hover and drag keep the accent at 1px like the other resize edges. - File viewer header: medium file name, 5px unsaved dot, 26px/6px close tile with its glyph on the content inset, divider hairline under it. Status bar: divider hairline, caption size, tabular line/column. - SFTP browser: file-tree rows (26px, 6px corner, 16px caption glyphs), breadcrumb and notes on the 20px text column, a borderless edit well, inverted OK button, and ink-on-track transfer progress. - Forward rows line up with the process and port rows (text at 20px, 6px corner); Add and Reconnect use the inverted neutral fill. * docs(design-system): note the v4 palette, pane, viewer and SFTP chrome * feat(settings): restyle the settings page after the v4 design - Nav: the rail's tinted fill and surface ladder behind a divider hairline; a 28px filled search well; 28px rows in 7px pills, the current one on the selected rung at medium weight instead of the accent; match counts in muted ink; the modified-only filter toggles like a nav row. - Pages: the title sits in the 48px title-bar band at 16/16rem; group headings are 11.5/16rem medium muted on a 28px line; sections are split by a 0.5px divider with 16px either side. - Rows: labels in body ink at regular weight, descriptions at 12/16rem muted, 28px floor with 8px padding; a search hit wears the faint neutral fill rather than the accent tint. - Controls: text fields and dropdowns are 28px filled pills with no outline; buttons, segmented tracks and steppers are 26px with a 6px radius on the same fill. The one primary action per view (save theme draft, connect, install update) is the inverted neutral fill of the commit button. Switches and sliders keep the accent. - SSH: host list header with 26px tiles and a filled search, 22px group headings, 42px two-line host rows; the form's labels are a muted, right-aligned column level with 28px fields; disclosure headers use a chevron on a 28px band. - Theme cards are filled and unoutlined, taking the selected rung while open; the theme panel keeps the content fill with a divider edge and its title in the title-bar band. Keycaps are filled with no outline and shortcut rows are divided by 0.5px hairlines. - right_panel::SECTION_GAP is now shared; docs/design-system.md updated. * feat(ui): spell tab titles out in full in the rail and title bar The rail's rows and the centred title have room to spare, so they take the whole label from a new full_tab_label rather than tab_label's three-segment cut; only the width they have decides what gets elided. * fix(settings): even out the page rhythm and line up the columns - Nav header: drop the min_h(ROW_H)/min_h(0) pair on the heading, which measured ~46pt taller than it painted and opened a hole under the search. - Page titles sit under the title-bar band, level with the nav heading, instead of jammed against the window's top edge. - Headings get a 22pt group-header row and hug their rows; rules keep more air, so a heading reads as its rows' rather than floating between. - SSH: the host list gives width before the nav, so the nav no longer narrows on that page; its header, search well and detail title run level with the nav's; the empty note starts on the host-title column. - Window & Tabs no longer opens on a stray rule. - Integrations: status leads the buttons on one line, in the meta ink. - Terminal: the shell footnote stays close to its rows. * fix(ui): stop eliding branches that fit, and seat the SCM branch on the text column - elide_tail_clusters returned "…" plus the whole string when nothing needed cutting, so the rail's group header printed …feat/v4-redesign with room to spare. Return the text as-is when it fits. - The group header only reserves the chevron's width when it draws one. - The Changes tab's branch name no longer stacks a small button's padding on the row gap; it starts on the file names' column. * fix(ui): keep a tab's name in place when an inline rename starts gpui-component's Input keeps 12px of inner padding even with appearance(false), so the name jumped sideways as the rail row, the group header and the top-strip chip swapped their label for the field. Claude-Session: https://claude.ai/code/session_01Q9vsQSxAZjkwT7nRAiFF1J * revert(settings): restore the page rhythm from before |
||
|
|
39ceb35fdd |
feat(cursor): give the shell prompt its own cursor shape (#963)
A new prompt_cursor_style setting (follow, block, bar, underline) shapes the caret while the shell waits at a prompt, whether tty7's inline editor or the shell's own line editor draws it. `follow`, the default, keeps cursor_style everywhere, so nothing changes until it is set. Any other value leaves cursor_style to the programs the shell runs: bar here with cursor_style block gives kitty and ghostty's bar at the prompt and a block inside a TUI that never sets a shape, such as Claude Code. A vi-mode prompt keeps the shell's own insert/normal shapes. Settings shows both cursor shapes as dropdowns, kept in step with resets, language switches and config edits made outside the window. Closes #958 |
||
|
|
7a32e7dbbc |
feat(agents): recognise Empryo and Prime Agent, add Antigravity status hooks (#975)
* feat(agents): recognise Empryo and Prime Agent Prime Agent (PrimeIntellect-ai/prime-agent) is a Pi fork: detected as `prime-agent`, resumes with `--resume <id>`, forks with `--fork <id>`, `--no-session` opts out, and reports status through the shared Pi extension bridge at ~/.prime/agent/extensions/tty7/index.ts. Empryo is detected as `empryo` and resumes with `empryo --session <id>`. No hook installer yet: Empryo filters TTY7* variables out of hook processes, so `tty7-app agent-hook` would stop at the missing marker. * feat(agents): Antigravity status hooks Antigravity CLI (`agy`) now installs a `tty7` hook set in ~/.gemini/config/hooks.json, next to the user's own sets: PreInvocation -> prompt-submit, PostToolUse -> tool-complete, Stop -> stop. Only the first PreInvocation of a turn (invocationNum 0) counts as a new prompt, later ones keep the turn working; a Stop with fullyIdle false is ignored. conversationId and workspacePaths feed the session id and cwd. PreToolUse is left alone because it must answer with a decision. * fix(agents): index Prime Agent and Antigravity in settings, scope conversationId alias - Add settings titles, search keywords (en/ja/zh) and Agents index entries for the two new HookAgents; agent_rows_are_in_the_search_index requires one per HookAgent::ALL. - Read Antigravity's conversationId as the session id only for antigravity: the alias table is last-write-wins, so a global alias could replace another agent's session id. - Drop the stray .empryo/ job records. --------- Co-authored-by: kalpak <you@example.com> Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com> |
||
|
|
cf0e8f02e6 |
feat(sidebar): pinned groups above auto groups (#962)
* feat(sidebar): keep pinned groups on the workspace and derive the rest Replace the sidebar's hand-made groups with the model from #955: the sidebar groups tabs by repo automatically, and you pin what you want to keep. - Pinned groups (`PinnedGroup`: id, optional name, optional folder, fold) are stored on the workspace in the machine tree, in display order, and a tab points at one by `GroupId`. Everything else is an auto group worked out every frame and never stored: by repo home, or by `user@host` for an SSH pane — native or a shell that ssh'd onward — so `/home/ubuntu` on two machines no longer lands under one header. - A tab whose cwd *enters* a pinned folder joins it (deepest folder wins; a repo home equal to the folder counts, which keeps worktrees with their repo). It is edge-triggered through `EntryWatch`, so a tab dragged out while still inside the folder stays out until it leaves and comes back, and a tab restored at launch is not pulled in by where it already sits. - Groups sync as one `WorkspaceSetGroups` / `GroupsChanged`, pushed only from an edit and adopted from every pull, so a fresh window can never push an empty set over the workspace's. The machine hands tabs naming a dropped group back to auto grouping in the same mutation. Control dialect → v11. - Config: `sidebar_grouping` (three modes) and `sidebar_collapsed_groups` give way to one `sidebar_auto_grouping` toggle; folds live with the workspace. - `tty7 tab ls` reports the pinned group a tab is in (name or folder leaf; JSON carries id, name and folder). * feat(sidebar): draw pinned groups above a divider, with their own gestures The sidebar now reads as two halves: the groups you keep, in the order you put them, then a divider, then the groups it works out (Arc-style). - Pinned headers drag-reorder among themselves (their own reorder surface, so a pinned header cannot be dropped among the derived ones); the order lands on the workspace's group list, not on the tabs. - An auto header carried above the divider is pinned when let go. With nothing pinned yet the divider appears during that drag as a "Drop here to pin" zone, since a hairline at the top of the list is nothing to aim at. - A tab kept in a pinned group and dropped anywhere below the divider goes back to auto grouping; the divider lights to say so. - An empty pinned group stays, with a "+ New Tab" row that opens a tab in its folder (or where ⌘T would, for a label group) and files it there. - Folder groups carry a pin mark that unpins on click and a tooltip with the folder; auto headers show pin and "+" on hover. - Header menus: pinned — Rename, Set Folder… (local workspaces), Use Current Tab's Folder, Clear Folder, New Tab, Unpin (folder groups), Delete. Auto — Pin Group, New Tab. Nothing renames an auto group; nothing pins implicitly. * feat(sidebar): open folders as pinned groups from Finder, the file tree and the palette Every way into a pinned group the design calls for: - Drop a folder from Finder or Explorer onto the sidebar to pin it (a local workspace only — a dropped path is this machine's, and a folder group keeps a directory on the workspace's host). Files are let fall. - "Pin as Group" on a folder in the file tree, on local and remote workspaces alike, since the tree and the group are both on the workspace's host. - Palette "New Group" makes an empty label group and opens its name for typing; "Open Folder as Group…" picks a folder with the system picker, pins it and opens a tab in it. The picker browses this computer, so that one is not offered on a remote workspace. - Tab right-click "Move to Group" lists the pinned groups plus "New Group…", which files the tab in a fresh label group with its name open for typing. Pinning a folder already pinned hands back the group that keeps it rather than making a second one to split its tabs with. * fix(sidebar): let groups that arrive from elsewhere pull no tab into a folder A window draws its first frames before its copy of the workspace's groups lands, so every tab's entry watch recorded "in no folder" — and the groups landing then read as each tab walking into its folder. A restored tab, or one dragged out of its folder group, was pulled back in on every launch. Groups adopted from a pull or from another window's `GroupsChanged` now start every tab's watch over from where it is; only this window's own pin gathers the tabs inside the folder, and says so tab by tab. A tab also goes up with the group it names even when the window does not know that group yet, so a sync in that same gap cannot send every kept tab back to auto grouping. * docs(sidebar): describe pinned and auto groups, and log the change Rewrite the sidebar page's grouping section around "grouped by repo automatically; pin what you want to keep": the divider, folder and label groups, the edge-triggered join, every way to pin, and the header menus. The configuration reference swaps `sidebar_grouping` for `sidebar_auto_grouping`, the CLI reference describes the GROUP column as the pinned group, and the changelog gains an Unreleased entry (#955). * fix(sidebar): file a tab opened by the CLI in a pinned folder into it A tab that reaches a window as TabCreated — from `tty7 tab new` or another window — started its entry watch as a restored tab, so opening one inside a pinned folder left it in the auto group below. It is as new as a tab opened here, and now joins the folder like one; every window that hears of it reaches the same answer. * test(machine): build the group sets in their initializers Clippy's field_reassign_with_default on the two WorkspaceGroups the set-groups test assembles. * fix(sidebar): draw restored tabs in their auto group, and title by repo again Auto groups are not stored, so after a restart every tab sat in Ungrouped until its own repo probe came back, then jumped; before pinned groups the stored repo key put it in place on the first frame. Each tab now carries `last_auto`, the auto group it last resolved to, as a hint: stored with the tab, sent up alongside its group in `TabSetGroup` whenever the live answer moves, and used to draw the tab until the probe answers. The probe always wins and rewrites the hint, and the hint never outranks a pinned group or the folder-entry rule. Another window's hint only fills a gap, so two windows can never bounce a disagreement between them. The workspace's fallback title regained the repo majority it lost: the most common pinned folder first, then the repo most unpinned tabs were last filed under (a worktree counting toward its repo home), then a pane's cwd. * refactor: drop what the new sidebar left unused, and two clippy findings - `TerminalView::native_ssh_cwd` and its helper existed for the sidebar's old folder grouping of native SSH panes; an SSH tab now groups by host, and nothing else read it. - The file tree's context menu takes `cx` instead of `danger` and the new groups flag, back to the argument count it had on main. - A title test builds its workspace in the initializer. |
||
|
|
afcb8aa2dd |
feat(agents): quick launch for detected CLI agents (#961)
* feat(agents): quick launch for detected CLI agents (#955) Every agent whose launch program is on PATH becomes a palette command, "Agent: <name>", ordered by frecency and bindable as LaunchAgent:<slug>. "New Agent Tab" (Cmd+Shift+A on macOS; unbound elsewhere, where Ctrl+Shift+A is select-all) launches the most recently used one, and the New Tab menu gains a single "Launch Agent..." row that opens the palette pre-filtered to them. A launch always opens a new pane (a tab in the active tab's cwd, or a split when picked from the palette with Alt held) and types the command into that pane's shell once it exists - immediately for a local pane, on landing for a remote one via PendingSpawn::run_on_land - never into a pane that was already there. Detection, status and resume then work as for a hand-typed agent. The command is the agent's bare binary unless the new `agent_launch` config map overrides it. A wrapper named there is detected as its agent without an `agent_commands` entry: the daemon folds the programs `agent_launch` runs into its alias map (interpreters, shells and real agent names excepted), reloaded when config.json changes instead of once per process, and a mapped script run under its interpreter (`bash ~/bin/cc`, `node cc.js`) is now recognised too. A running agent's pane menu gets "Set Current Launch Args as Default", which writes its launch argv - minus session flags and positional prompts, joined with the settings' quoting - into `agent_launch`. Remote workspaces cannot be asked for their PATH through the Host trait, so they offer the agents previously seen running in that workspace (WindowView::seen_agents). * fix(agents): count only agents that start under a view, not ones reattached to A view rebuilt over a running pane - every agent tab after an app restart, or a workspace switched back to - saw its agent appear from nothing and reported it as detected, bumping that agent's frecency once per launch of the app. The terminal now remembers whether its link was an attach, and such a view only reports agents once its shell has been seen back at the prompt with no agent in front. Also pins down that the agents seen in a remote workspace, its quick launch list, persist in views.json with the rest of the workspace. * fix(daemon): probe the foreground as soon as a new program takes it The foreground probes ran on output only, at most once per 500ms interval. A quick launch types the agent's command the moment the shell is up, so the agent drew its whole first screen inside the interval of the prompt it was typed at and then waited for a key: the pane never learned it was running an agent until something else printed. Seen in a dev instance, where a launched Claude Code stayed undetected at its trust prompt. The reader now asks the pty for its foreground process group on every read (one ioctl) and probes immediately when it changes. |
||
|
|
27483e893d |
feat(ui): collapse the New Tab menu's shell list to three by frecency (#960)
The + menu listed every shell the machine reports (nine on a stock macOS box)
above the SSH hosts. The Local section now names the default shell, always
first, then only shells that have actually been opened, by frecency, three rows
at most, the same way the SSH section caps its hosts.
Shell usage is recorded in a new `shell_frecency` config map, keyed by the
inventory label, bumped from both the menu row and the palette. Every shell is
now a palette command titled "Shell: {label}" (same word in every locale), and
an "Other Shells…" row opens the palette pre-filtered to them. That row is
hidden when the menu already names the whole inventory. Running a shell command
from the palette respects the ⌥/Alt split modifier like the menu row.
|
||
|
|
bd0dd22bfa |
feat(tabs): hibernate a tab to free its memory and wake it later (#954)
A tab can be put to sleep from its context menu or the command palette: its panes are stopped (screens kept on disk), the tab keeps its place in the sidebar, and selecting it wakes it through the same restore a reboot runs, resuming a supported agent's session. The sleep mark lives on the machine tree, so it survives app and daemon restarts. Closes #762 |
||
|
|
9f034558c0 |
feat(ssh): switch a port forward off without losing its rule (#953)
A forward could only be removed, so pointing one local port at another remote target meant deleting the rule and retyping the other one (#439). Forward rules gain an `enabled` flag (serde default on, so saved profiles and older peers keep every rule live) and the daemon a SetForwardEnabled op for panes and workspaces. Off releases the listener and keeps the entry; on rebinds it from the rule it was made from, and is refused by name when another switched-on forward of the same owner holds the port. The Ports panel and the Settings rules editor each get a switch; a switch flipped in the panel on a rule from a saved host is written back to that host. Closes #439 |
||
|
|
de15f9b0ab |
feat(ssh): keep saved hosts in servers.json and add an SSH tab title setting (#952)
Saved SSH hosts and their usage counts move out of config.json into servers.json beside it, so config.json can be synced between machines without carrying a server list (#911). An older config.json is split on first load: servers.json is written first (0600), then only the two keys are removed from config.json, leaving every other key as it was. When both files hold hosts, servers.json wins and the stale copy falls out of config.json at its next save. A servers.json that does not parse is kept aside and blocks saves, as config.json does; hand edits hot-reload. Settings -> Window & Tabs -> SSH tab title (`ssh_tab_title`) pins an SSH tab to the profile name (saved host name, ~/.ssh/config alias, or the address typed for a quick connect) or the hostname, on the OSC title's rung of the existing label ladder: a renamed tab still wins, OSC titles are still tracked, local panes are untouched (#726). |
||
|
|
02d8611e33 |
feat(cli): add exec, and send --stdin/--from-file/--paste (#951)
`tty7 exec %N -- CMD` types a line at an existing pane's shell prompt, follows the shell integration's OSC 133 marks to the command's end, prints what it printed (rendered to text by default, `--raw` for the bytes) and exits with its exit code. `--timeout` exits 124 and leaves the command running. A pane with no prompt marks, or one not at a prompt, is refused before anything is typed. `tty7 send` can take its text from `--stdin` or `--from-file`, sent byte for byte and never echoed in --json, so a secret stays out of `ps` and shell history. `--paste` frames the text the way the GUI's paste does: bracketed when the pane has mode 2004 on, unframed otherwise, reported in --json. The framing moves into tty7-core (`core::paste`) so the GUI's clipboard paste, the agent prompt and the CLI share one construction, and the daemon now reports each pane's bracketed-paste mode in PaneContext. Closes #839 Closes #838 |
||
|
|
455e74dc2c |
feat(scm): filter changed files and show them as a tree (#950)
* feat(scm): filter changed files and show them as a tree * test(scm): key the tree test's settle on the panel's own root |
||
|
|
575d2cd68e |
fix(agents): drop the previous session id when the foreground agent changes (#957)
同一 pane 里前台从 Claude 换成 omp,或别的 agent 的 hook 写进这个 TTY 时,旧的 session id 会留在新 agent 上,Fork 就会拿错 id。 Co-authored-by: stevelliu <stevelliu@tencent.com> Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
f852629ba1 |
fix(procinfo): read proc_listallpids' answer as a pid count, not bytes (#947)
libproc's proc_listallpids takes its buffer size in bytes but answers with the number of pids, and the macOS process table read that number as bytes twice: once sizing the buffer (count / 4 + 64 slots) and once reading back how much was filled (count / 4 again). On a Mac with ~700 processes only the first ~60 pids reached the table. The kernel lists its newest processes first, so what survived was whatever started most recently. A `go run` server launched a moment ago was in; the pane's shell, started long before, usually was not, and a walk from a root missing from the table returns nothing: no processes, no ports, and a probe state of Ok. A freshly built parent/child chain, which is what a quick check of the probe builds, is exactly the case that happened to work. The listing now goes through list_all_pids, which takes the call as a closure so the size arithmetic is tested off a Mac against an emulation of libproc's convention. Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM |
||
|
|
d18f797a6c |
Merge pull request #945 from l0ng-ai/fix/942-wsl-files-panel
fix(files): keep a WSL tree in step with its distro (#942) |
||
|
|
8fa9651814 |
fix(files): keep a WSL tree in step with its distro (#942)
Three things went wrong with a Files panel rooted on a distro's \\wsl$ share: - A drop brought a `name:Zone.Identifier` file along with every downloaded file. fs::copy is CopyFileEx on Windows, which copies the NTFS alternate data streams, and the share has no streams to keep one in, so it lands as a file of its own. A copy onto a WSL share now moves the contents only; one onto NTFS still goes through fs::copy and keeps the mark. - A file removed from the shell in the distro stayed in the tree. The share accepts a ReadDirectoryChangesW and never reports a change, so the watch looked healthy and was deaf. Directories on a WSL share are now watched by a notify PollWatcher every 2s instead, made the first time one is needed. - Right-clicking a row did not select it, so nothing marked the row the menu was about. A right click now selects the row without opening it. |
||
|
|
439f19ff85 |
Stop waiting on remote round trips from the UI thread
Dropping a RemoteWatch sent WatchClose with a blocking call, and the last handle is usually let go on the UI thread: from Tty7App::render via scm_sync_watchers, and from scm_watch_opened when an open lands after its subscription moved on. Every window froze for a round trip each time, up to WatchClose's 5 s deadline on a quiet link. Sampling a live instance caught ~1.1 s of such stalls in 10 s. - ControlClient::post sends a request without registering for its reply; the reader already drops replies nobody is waiting for. - RemoteWatch::drop posts WatchClose instead of calling it. - pane_workspace_for built the full SSH spec, keychain lookups included, only to strip the secrets again. It now builds it from NoCredentials, which takes the securityd trips off pane_liveness::sweep. Claude-Session: https://claude.ai/code/session_01YX786Hyr4ivijWxv66zVkf |
||
|
|
7666e2fd83 |
Merge pull request #941 from l0ng-ai/feat/852-portable-mode
feat(windows): portable mode keeps data beside the executable |
||
|
|
386ccc3d81 |
Merge pull request #939 from l0ng-ai/feat/720-font-smoothing
feat(fonts): make macOS stroke thickening configurable |
||
|
|
296a8a3c3f |
Merge pull request #938 from l0ng-ai/feat/760-stable-workspace-numbers
feat(workspaces): number workspaces in a stable order (#760) |
||
|
|
a012321542 |
Merge pull request #936 from l0ng-ai/feat/892-741-codebuddy-cursor-hooks
feat(agents): CodeBuddy CLI support and Cursor CLI hooks |
||
|
|
3d4c158278 |
fix(agents): open Cursor turns on beforeSubmitPrompt, count tool calls as activity
The interactive cursor-agent TUI fires beforeSubmitPrompt and stop; only print mode (-p) lacks them. Mapping postToolUse to prompt-submit froze the activity counter (opportunistic git refresh, agents --changed), shortened turn timing and hid tool-less turns. Map it to tool-complete instead. |
||
|
|
f5a97ed68c |
feat(windows): portable mode keeps data beside the executable (#852)
A portable ZIP install whose folder has both the .tty7-portable marker and a data\ folder next to tty7-app.exe now uses <exe dir>\data as its config directory, so settings, sessions, scrollback and the daemon's socket travel with the program. --config-dir and TTY7_CONFIG_DIR still win. The folder is an explicit opt-in because the marker has shipped in every portable ZIP since the in-app updater arrived: keying on it alone would move existing users onto an empty directory at their next update. The portable directory is not the machine's config dir, so a portable copy never adopts the installed tty7's legacy tree. An updater test pins that data\ is not a managed root and survives an in-place update. |
||
|
|
57ca21dd68 |
feat(workspaces): number workspaces in a stable order (#760)
SelectWorkspace1-9 and the Window menu numbered workspaces by most recent use, so switching to one moved it to slot 1 and reshuffled the rest. Number them by the order this client first had them instead (the append-only views list), skipping synced remote references until they are opened; opening one moves it to the end so it takes the next free number. The switcher keeps its MRU list and shows each row's number. |
||
|
|
592058acc7 |
feat(fonts): make macOS stroke thickening configurable (#720)
Add a macOS-only `font_thicken` key (default true) and a Settings row under Appearance > Terminal text. When off, AppleFontSmoothing is pinned to 0 in this process's NSArgumentDomain before gpui's text system first reads it, so glyphs render at the face's own weight. The volatile domain is in-memory only: nothing is persisted and no other app is affected. gpui caches the preference in a OnceLock, so a change applies after a restart; no gpui fork change is needed. |
||
|
|
fe7b6e0b76 |
feat(agents): wire Cursor CLI (cursor-agent) into agent hooks (#741)
Cursor's ~/.cursor/hooks.json is a flat hook map — `command` directly on each entry under `hooks.<event>` — so it reuses the flat writer Crush introduced. Two things are Cursor-specific: - The file needs `"version": 1` at its root or Cursor ignores it. tty7 now writes it when it creates the file or finds it missing, never overwrites a version the user set, and reports a versionless file that holds our hooks as Outdated so refresh repairs it. - Payloads name the session `conversation_id` (only sessionStart repeats it as `session_id`), and most events carry `workspace_roots` instead of `cwd`. Both are now read as aliases, which is what Copy Session ID and resume were missing. Events: sessionStart, beforeSubmitPrompt, postToolUse, stop, sessionEnd. cursor-agent does not fire beforeSubmitPrompt today (a known gap on Cursor's side), so postToolUse also reports prompt-submit: the first tool call opens the turn and Cursor's stop, which the CLI does fire, closes it. A turn with no tool calls never shows as working. None of Cursor's permission hooks are installed, since those would block on the empty stdout tty7's hook prints. |
||
|
|
9f842975ce |
feat(editor): add ToggleDocumentPreview / ToggleDocumentWrap actions (#754)
The code panel's Preview/Edit and Wrap buttons only toggled state in their click handlers, so there was no way to reach them from the keyboard. Register both as actions, unbound by default like ToggleDocumentFill and the DocumentWidth* actions, list them in the command palette and the Keybindings page, and route the buttons through the same methods. Instead of config keys for the initial state, the last-used state is remembered (editor_soft_wrap / editor_markdown_preview), the way diff_view and scm_graph_expanded already are. A file opened at a line target always opens as source so the cursor is visible. |
||
|
|
0d0dc597ee |
feat(agents): add CodeBuddy CLI integration (#892)
CodeBuddy Code takes Claude Code's hooks as-is: the same nested
`hooks.<Event>[].hooks[{type, command}]` shape in ~/.codebuddy/settings.json
(or $CODEBUDDY_CONFIG_DIR/settings.json), the same event names, and the same
session_id/cwd payload fields. So it rides the shared hook-map installer and
needs no payload aliases.
The event table follows Qoder rather than Claude: CodeBuddy has a
first-class PermissionRequest and Elicitation, so it gets no Notification
hook, and StopFailure ends a turn like Stop. CodeBuddy also emits
SessionStart with source "compact" mid-turn, which is filtered out the same
way Qoder's is so the pane does not drop back to idle.
Detection covers all three npm bins (codebuddy, codebuddy-code, cbc).
Resume is `codebuddy --resume <id>` and fork appends --fork-session; stale
session and worktree flags are dropped from the replayed launch argv, and
--no-session-persistence disables both commands.
Icon, en/ja/zh names and search keywords, and docs are updated.
|
||
|
|
d534c085b9 |
Merge pull request #930 from l0ng-ai/chore/bump-control-dialect
chore(control): bump the dialect to v10 so remote hosts pick up daemon fixes |
||
|
|
611c87af0c |
Merge pull request #931 from l0ng-ai/feat/palette-update-server
feat(palette): add "Update tty7 server" for this computer and the remote host |
||
|
|
4ee61bb09d |
Merge origin/main into fix/857-stream-escape-split
Claude-Session: https://claude.ai/code/session_01YX786Hyr4ivijWxv66zVkf |