Commit Graph
1450 Commits
Author SHA1 Message Date
l0ng-ai 4e8a76261b fix(terminal): call the right-click menu's clear item just Clear 2026-09-28 13:45:04 +08:00
l0ng-ai ee817bae01 feat(ui): v5 modal cards, and an IME crash fix in the code editor (#993)
* fix(deps): gpui-component keeps highlight boundaries on char boundaries

Typing Chinese through the IME in the code editor could panic the app:
after a sync parse ran past its 2ms budget, the stale injection layers
put a style boundary inside the committed glyph and the text system split
the line mid-character. Debug builds miss the budget often enough to hit
it; the fork now snaps every style range to the current text.

* feat(ui): bring the modal cards onto the v5 design

- Confirmations take v5's alert shape: title and detail as one
  paragraph, answers beneath, no header row or footer rule, 360px wide
  and set lower, at eye height.
- Dialog buttons take the field's 7px corner and 14px padding; a
  secondary answer rests on the well's faint fill instead of bare text.
- The scrim dims rather than blacks out: 45% dark, 14% light.
- The New Workspace form joins the other cards: 12px corner, borderless
  wells for its fields, an esc cap and the shared 40px footer.
2026-09-28 13:35:53 +08:00
l0ng-ai f647a19746 feat(editor): draw the editor's right-click menus like the rest of the window (#992)
* feat(editor): draw the editor's right-click menus like the rest of the window

The text's menu was gpui-component's native OS menu: another font and
material, no shortcuts, and Go to Definition / Show Code Actions that no
language server ever enables. It is now a PopupMenu with Attach to Agent
(the selected lines ride along as #L3-9), Undo/Redo, the clipboard,
Find, Go to Line, and the file's own items: Open in Browser for web
files or Open with Default App, Reveal, Copy Path, Copy Relative Path.

The file tabs get a menu too: Close, Close Others, Close to the Right,
and the same file items. Closing several asks once about unsaved edits.

* chore(deps): gpui-component moves the caret on right-click under a host menu
2026-09-28 13:35:15 +08:00
ARNO 643e0f7d95 feat(agents): add Qoder CN CLI integration (#988)
* feat(agents): add Qoder CN CLI integration

* fix(agents): spell Qoder CN's config override QODERCN_CONFIG_DIR

The China build of Qoder resolves its configuration through QODERCN_CONFIG_DIR.
The first pass invented QODER_CN_CONFIG_DIR instead, so an install that set the
real one was treated as unrelocated: hooks went to ~/.qoder-cn and history was
scanned from a directory the CLI never writes to. The test that should have
caught it set the same invented name, so it only proved the name agreed with
itself.

Picks up the rest of the review as well — detect the `qoder-cn` dispatcher
beside the other two binaries, call it the mainland-China build rather than a
different vendor, and drop the QODER_CN_HOOK_EVENTS alias for the table it only
pointed at. The serialized enums keep their variants appended; only the
independent ALL arrays moved QoderCLICn next to QoderCLI.
2026-09-28 13:35:10 +08:00
l0ng-ai 388ddf4303 fix(search): label the search entry point "Search…" (#990)
"Everywhere" added nothing: the modal's tabs already say what it covers.
2026-09-28 13:35:06 +08:00
e94c0d39cb fix(path): read the interactive shell's PATH, not just the login shell's (#989)
* fix(path): read the interactive shell's PATH, not just the login shell's

The GUI starts with launchd's bare PATH and refills it by running the login
shell. A login shell reads .zprofile/.bash_profile and never .zshrc/.bashrc,
so every directory exported there was invisible to the app: agent quick
launch found only what /opt/homebrew/bin and /usr/local/bin happened to hold,
and an agent_launch override could not bring a missing program back, since
the override's program is looked up on the same PATH.

Probe with -i as well (fish unchanged: it reads its config in every mode) and
take the last non-empty line, so an rc that prints a greeting above the
echo $PATH cannot be mistaken for the value.

* fix(path): bound the interactive PATH probe and bracket its output

Running .zshrc/.bashrc on the startup path needs guards the login-only
probe could do without:

- Read the PATH between markers instead of the last line, so an exit
  hook that prints after it cannot be taken for the PATH.
- Return as soon as the closing marker arrives rather than at EOF: an rc
  that backgrounds a daemon hands it the pipe, which then never closes.
- Give up after 5s and kill the shell, so a slow or stuck rc delays
  startup instead of preventing it.
- Probe after forwarding an open path to a running window, which has no
  use for the PATH.

* docs(changelog): describe the bounded PATH probe

---------

Co-authored-by: stevelliu <stevelliu@tencent.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-09-28 12:12:55 +08:00
l0ng-ai bc08fc49f4 fix(deps): gpui-component paints text selection under the glyphs (#991) 2026-09-28 11:41:11 +08:00
l0ng-ai 39776012e2 feat(github): read a repository with whichever gh account can see it (#987)
The GitHub panel borrowed only gh's active account, so a private repository
owned by an organisation another signed-in account belongs to read as a 404.

When the active account gets a 404, 401 or 403, retry with gh's other
github.com accounts and remember, per owner, the one that got through. The
other accounts are listed lazily (gh auth status checks each online), and a
token from GH_TOKEN/GITHUB_TOKEN keeps its no-fallback meaning.
2026-09-28 10:59:25 +08:00
l0ng-ai ce76de975c fix(search): keep the empty note clear of the scope row
The empty view replaces the rows, so the list's top padding the scope row
is laid over never reached it and the row sat on top of "No results". It
now keeps its own clearance and sits left-aligned on the rows' column.

Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 09:11:09 +08:00
l0ng-ai 1ba9159408 feat(panel): drop the GitHub row from the Info tab
The GitHub tab one over already names the repository and opens it; the
row only repeated it. Its upstream lookup goes with it.

Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 09:00:55 +08:00
l0ng-ai 23e4ea79f5 chore(deps): gpui-component with v5 menus
Picks up l0ng-ai/gpui-component bce0d8ec: popup and context menus take
the v5 popover look — a neutral hover step, 28px rows, a hairline ring
and v5's long shadow.

Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 08:45:02 +08:00
l0ng-ai 689517a632 feat(search): call the Actions scope Commands
Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 08:45:02 +08:00
l0ng-ai 99e626db7a fix(ui): the title bar search takes the left rail's fill
Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 08:42:24 +08:00
l0ng-ai 83c659d8bf fix(ui): paint the title bar search on the sidebar's surface
Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 08:34:01 +08:00
l0ng-ai 57384032d5 fix(ui): the title bar search toggles like the switcher, on v5's field fill
Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 08:33:05 +08:00
l0ng-ai d7eece6cf9 feat(ui): v5 search — Search Everywhere without Files, one Files search for names and text, word tabs
- Search Everywhere follows the v5 design: the scope row sits under the
  field, Files leaves the row, Tab and the All tab (Go to File still opens
  it), the scopes run All, Terminals, Sessions, Hosts, Commands, matches are
  picked out in the title, subtitles move to the right edge, and the footer
  leads with Next scope.
- The right panel's Files field searches file names and file contents at
  once, in two sections. The Search tab folds into it; a stored "search"
  tab and Show Search open Files with the field focused.
- The right panel's tab row is words again: Info, Files, Changes, GitHub.

Claude-Session: https://claude.ai/code/session_01Aeskbok7Ah7dvKWnaaJFEg
2026-09-28 01:49:55 +08:00
l0ng-ai bcd0a2939d fix(panel): give the GitHub tab's header room to breathe (#986)
The repo row, the two segmented switches and the list sat flush against
each other. The list now starts 10px below the header, the gap the Files
and Search tabs leave under their search field, and the switches get more
space between them when a narrow panel wraps them onto two lines.
2026-09-28 01:30:12 +08:00
l0ng-ai 28c6f6b11a fix(ui): centre the title bar search over the terminal column off macOS
With a document or the detail panel docked, the title bar spans the
workspace on Windows and Linux, and the Search Everywhere box centred on
all of it landed under the document's hoisted header, which has no fill
to hide it.
2026-09-28 01:06:59 +08:00
l0ng-ai ed9b8b0a90 fix(ui): one dialog for every confirmation, titled failure toasts, aligned settings controls (#985)
* fix(ui): draw every confirmation as the app's own dialog card

window.prompt fell through to NSAlert on macOS and TaskDialog on Windows,
so closing a busy tab threw up a system alert with a centred app icon and
stacked grey buttons while every other question the app asks is a
ui::dialog card. The Linux fallback card had drifted too (accent buttons,
its own padding).

TextPrompt is now built from ui::dialog on all three platforms: the 12px
card at the switcher's top offset, a wrapping title row with an esc cap,
a hairline footer and ink-filled primary. Return and Escape keep the
native meanings; the scrim occludes the window and backs out; a lone OK
answers Escape; an answer listed after Cancel in a prompt of three stands
apart at the footer's left, and an action behind a Cancel-first default
is painted red.

SCM's discard and destructive-op prompts passed Cancel as a bare label,
which gpui only recognises as a cancel when it is the English word; they
now mark it explicitly.

* fix(ui): show the settings window's toasts and title git failures

The settings window is a gpui Root of its own but never rendered the
notification layer, so everything the page reported (an ssh_config
import, a passphrase it could not store) was pushed into a layer nobody
drew.

A failed git op was toasted as one bare stderr line
('push: fatal: ...'). It is now an error toast titled 'git push failed'
with git's reason, severity prefix dropped, beneath it.

* fix(settings): one control language down the right-hand column

The page had drifted from the design system: dropdowns and secondary
buttons were raised white with a drop shadow, fields had a half-pixel
inset ring that anti-aliased to nothing on a 1x display (the shell and
proxy rows read as loose monospace text), and dropdowns sized to their
value beside fixed-width fields, so the column's left edge zig-zagged.

Fields, dropdowns, secondary buttons, steppers and search fields now all
stand on the theme's muted well with no outline or shadow; a field shows
a ring only for focus (accent) or error. Fields and dropdowns are 28px
and one width (kit::CONTROL_W); only path and command fields are wider.
Field text is sized on the Input itself, since its own text_sm outranked
the size set around it. A host saved under its own address no longer
repeats it as a subtitle.

* fix(ui): tidy menus, the switcher and the editor's conflict strip

- New Tab menu: host endpoints elide against fixed caps instead of being
  clipped mid-glyph at the panel edge; notes are right-aligned again.
- Switcher: a workspace's tab count reads '1 tab', not a bare 1 beside
  the slot number.
- Editor 'changed on disk' strip: neutral with an amber dot and dialog
  buttons, Keep mine as the safe primary, instead of an amber wash with a
  library-default outlined button.
- Title bar search keeps its full label with a document docked.

* fix(search): a command named in the query leads over a session that says it

'worktree' then Return resumed a past agent session instead of opening
New Worktree Tab. Two causes:

- The fuzzy scorer matched greedily from the left, so the query's first
  letter was spent on any earlier occurrence ('New') and the rest
  scattered: a title containing the whole word scored as a poor match.
  It now tries every position the first letter occurs and keeps the
  best; the leftmost alignment is one of those, so no score drops.
- Session titles are whatever was first typed to an agent, and those
  often open with a command's name, taking the prefix bonus. On the All
  tab the Sessions section now stands back by a little more than that
  bonus when sections are ordered; a session still leads when it is
  plainly the better answer, and the Sessions tab ranks untouched.

* fix(ui): dialog wells and mono detail that hold up in the dark

Dialog fields, info wells, keycaps and disabled filled buttons used the
theme's muted fill, a step off the window. Cards sit on the popover
surface, which a dark theme lifts to about the same value, so every
field on a dialog lost its shape. They now take the card's own next
rung.

The host-key fingerprint and the worktree path preview asked for the
'monospace' family, which gpui resolves as a literal family name and
falls back from; they use the theme's mono family.

* fix(ui): one way to draw a shortcut

- Every chord is one cap per key. The home page and the switcher's
  footer packed theirs into a single cap (⇧⌘T, ⌘↵) beside Search
  Everywhere's ⌘ T; dialog::chord is the one spelling now, and the
  switcher's private copy of dialog::keycap is gone.
- On macOS modifiers are listed ⌃ ⌥ ⇧ ⌘ whatever order the binding was
  written in, as the menu bar lists them; the palette read ⌘ ⇧ D.
- Return is ↵ everywhere; key_tokens alone drew ⏎.

* fix(ui): file errors as titled error toasts; say a delete is for good

HostOps::notify_err ran its context and the reason together as one
plain line ('Could not delete a.txt: You do not have permission.').
Every context it is given is already a sentence about what failed, so
it is now the title of an error toast and the reason sits under it. The
'{context}: {error}' template is gone with its last caller.

The delete confirmation's detail repeated its title ('The file will be
deleted.'). The remove is permanent, not a move to the Trash, and that
is the one thing worth saying there.

* fix(ui): every failure toast says what failed, why, and that it failed

About twenty toasts reported failures as one plain line with no
severity: 'Could not open a terminal: <why>', 'Couldn't forward :3000 —
<why>', 'SSH reconnect failed: <why>'. host_ops::failure turns such a
sentence into an error toast, taking what failed as the title and the
reason beneath it. It splits the formatted text rather than the
templates, because some of them are also shown whole (the home screen
keeps the start-up failure on screen), and a reason that is not at the
end leaves the sentence whole.

Waking a tab and reopening one are errors too; tabs that could not be
restored are a warning.

* fix(settings): a primary with nothing to do rests on the well

A disabled or not-yet-dirty primary (the host form's Save) was the ink
button faded to 45-55%: a washed-out black button that still looked
like the thing to press. It now sinks to the well with secondary text,
the fall the dialogs' Create and the Git panel's Commit take, and turns
ink once there is something to save.

* fix(settings): the shortcuts page's way back is drawn, and its title lines up

The back link to Keyboard & Mouse was pulled up out of the page column
with negative margins, above the scroll area's clip, so it was never
drawn - the page had no visible way back - while the rest of its height
pushed the title 16px below every other page's. It now sits in the
title-bar band, and the title is where the others are.

* fix(settings): searchable dropdowns say they can be searched

The filter field shared by the page's searchable dropdowns (themes,
shells) had no placeholder, so it read as a stray caret between the
preview and the list.

* fix(i18n): no stray space before the default shell in zh and ja

The shell intro put a space before {default}, meant for a Latin shell
name, but the default is the localized 'your login shell', so zh read
'留空则使用 你的登录 shell'. The ja sentence also ended on the bare
noun.

* fix(settings): action menus don't reserve a column for a tick

Every settings menu kept an empty tick column, so a menu of actions
(an agent's Reinstall / Reveal / Uninstall) set its labels 24px in from
a 12px right edge. The column is kept only when some entry is ticked -
a choice menu - and an action menu is padded evenly.

* refactor(settings): drop the raised-control paint nothing uses now

Tk::btn and Tk::raised_hover lost their last callers when the page's
controls moved onto the well. Also corrects two comments that described
the old field ring and claimed more than was observed.

* revert(settings): keep the v4 Settings design's controls

The earlier commits on this branch moved the settings page's dropdowns,
buttons, steppers and fields onto flat outline-less wells, following
docs/design-system.md. That paragraph predates the v4 Settings design
the page was rebuilt to on 2026-09-26 (raised controls, hairline-ringed
fields) and was never updated to it, so the change took the page away
from the design rather than toward it. The raised controls, 26px
heights and the faded disabled primary are back as v4 drew them, and
the design-system edits are withdrawn.

Kept, as fixes within the design:
- dropdowns and fields share one width (kit::CONTROL_W);
- the field's value is sized on the Input, which otherwise beat it;
- the field hairline is one device pixel: v4's half point is one pixel
  on Retina and nothing at all on a 1x display.

* fix(settings): a primary with nothing to do falls to the faint fill

A disabled or not-yet-dirty primary (the host form's Save) was the ink
button faded to half opacity - still a black button that looked like
the thing to press. It now takes the fall v4 already gives the Commit
button and the dialogs' Create: faint fill, secondary text, ink again
once there is something to do.

* fix(settings): tab position rows are dropdowns again

#982 moved New tab position and Tab bar position into General with the
segmented control they had before #979 made every pick-one setting a
dropdown, so General mixed the two again. Both use settings_choice.

* fix(scm): the Changes list sits on the same rhythm as the Files tab

- The filter was appended to the pinned block without the pause the
  blocks above carry, and the list starts flush, so the first group
  header sat on the field's edge (0px) while 14px stood above it. It
  now leaves the Files tab's 10px under its search.
- File rows (working tree and commit detail) padded 3px above and below
  a 23px line box, standing 29 tall - 30px pitch - beside the tree's
  26px directory rows and the Files tab's 26px rows. They are ROW_H,
  26, as v4 specifies.
2026-09-28 00:36:42 +08:00
l0ng-ai bf5149bea0 fix(editor): stop losing edits, share buffers, add file strip, quick open and go to line (#984)
* fix(host): save local files atomically via a temp file and rename

LocalHost::write_file truncated the target in place, so a crash, a full
disk or a killed process mid-save destroyed the user's file. It now
writes a hidden sibling temp file, syncs it, keeps the old file's mode
and renames it over the target, removing the temp file on any error.

It still writes in place where a rename would change something visible:
a non-regular target (symlink, directory, FIFO), a read-only file, and on
Unix a hard-linked file or one owned by another user, or when the temp
file cannot be created (e.g. a read-only directory).

* feat(editor): add editor_text for encodings, line endings, indentation and EditorConfig

A pure module the code editor will use when loading and saving files:
decode detects BOMs, binary files, UTF-8, GB18030 and a lossless
Windows-1252 fallback and normalises CRLF; encode restores the exact
bytes and names the first unrepresentable character; detect_indent
infers tabs or a 2/4/8 space width with language defaults; and
editorconfig_for resolves .editorconfig sections with save-time rules.

* feat(editor): share buffers across tabs, guard unsaved work, add a file strip

- One buffer per file per window; tabs list which buffers they show. The
  same file open in two tabs is no longer two diverging copies.
- Closing a tab, its last pane, the window, or quitting asks about unsaved
  files (Save / Cancel / Discard) instead of dropping them. Bulk closes skip
  tabs with unsaved files; a tab that vanishes any other way hands its
  unsaved buffers to the tab in front.
- File tree rename/delete now retarget or flag the open buffer, so a save
  no longer recreates the old path.
- Saves check the file's mtime first and ask before overwriting a change
  made elsewhere; this is the only detection SFTP buffers get.
- Dirty is a comparison with the saved text, so undoing back clears it.
- Reloads replace only the changed span as an ordinary edit, keeping undo.
- Load/save go through editor_text: encoding, BOM and CRLF round-trip,
  indentation is detected, .editorconfig is honoured.
- Header shows a strip of open files; New File, Save As (native panel
  locally, a path bar remotely), Go to Line (Ctrl+G), and the status bar
  shows indentation, encoding and a clickable line ending.
- Open files are remembered per tab across restarts.

* feat(search): quick open a file by name from a Files tab

Search Everywhere gains a Files tab that finds any file in the active
tab's project by fuzzy name and opens it in the built-in editor, with
`name:line[:col]` jumping to that spot. The list comes from one walk of
the project through the host (Host::search with an empty query), so it
works the same on local, SSH and WSL workspaces and skips what the tree
hides: dotfiles, .git and gitignored paths. The walk is capped at 50k
entries / 20k directories, kept between openings and revalidated in the
background each time the search opens.

Files join the All tab once a query finds them. Go to File... is bound to
Cmd+O on macOS (Cmd+P is already Search Everywhere) and ships unbound
elsewhere, where every obvious chord is taken or owed to the shell.

* chore(editor): allowlist the editor session file, tidy lints

* fix(editor): keep restored file order, drop stale close waits, carry files through tab merges

- Background arrivals (restore, merge, rescue) append to the strip in order
  instead of inserting beside the active file, which reversed them.
- A cancelled Save As, a dismissed path bar, or a dropped buffer cancels any
  close that was waiting on that save.
- Merging a tab into another carries its open files along.
- A shell exiting closes its tab without a prompt it could not honour;
  unsaved buffers move to the tab in front.
- Tabs rebuilt under the same id (server restart) restore their files.

* fix(host): only fall back to an in-place write when the rename is refused

On Windows every failure of the atomic save fell back to fs::write,
including a failure while staging the temp file. A full disk would then
truncate the original in place, the very loss the temp file prevents.
Staging errors now return as-is; only a refused rename (a file held open
elsewhere) takes the in-place path.
2026-09-28 00:32:18 +08:00
l0ng-ai b063ba97a0 refactor(settings): fold Window & Tabs into General, drop two settings (#982)
The Window & Tabs page is gone. Its three remaining tab settings (new tab
position, tab bar position, auto grouping) are a Tabs group on General,
below Startup & restore, so the nav has seven sections.

Removed outright:
- SSH tab title (`ssh_tab_title`, #726, unreleased). The sidebar already
  groups SSH tabs under their host, and renaming a tab pins its name.
- Open diff preview from sidebar counts (`sidebar_diff_preview`, #247).
  The sidebar counts and the Info panel's changes row always open the
  diff overlay; the large-tree stall it worked around is bounded. An old
  config.json that still carries either key loads as before.

The now-unused window settings icon goes with the page.
2026-09-27 19:11:45 +08:00
l0ng-ai fd2c4f7d4e feat(panel): Search and GitHub tabs in the right panel (#978)
* feat(panel): add Search and GitHub tabs to the right panel

The right panel grows from three tabs to five. Five word labels do not
fit the panel's 280px resting width, so the tab row now draws a glyph
per tab and names it in a tooltip.

Both new panes are placeholders here; the content search and the
GitHub issues/PR browser land on top of this.

* feat(panel): find in files in the right panel's Search tab

The Search tab replaces its placeholder with a content search over the
active tab's project -- the same roots the Files tab shows -- on the host
that project lives on. Hits arrive as you type (debounced, with a
generation counter so a stale answer never lands), grouped by file with a
count, each line excerpted with its matches highlighted. Clicking a hit
opens the built-in editor at that line and column; Enter searches again.
Match-case, whole-word and regex toggles sit at the end of the field, and
the tab focuses its field whenever it is brought forward.

Host::search_content is new on the Host trait, implemented once in
host::content_search (ignore walk + regex) and run by LocalHost directly
and by tty7-server over a new SearchContent control request. The walk
honours .gitignore with or without a repository, skips dot-entries, binary
files and files over 1 MB, and reports a capped search as truncated. The
request is gated on a new `content-search` hello feature, so a server that
predates it is never sent it; the panel says the server needs updating
instead of showing no results. Conformance cases cover local and the
stdio server alike.

* feat(panel): browse GitHub issues and pull requests in the right panel

The GitHub tab follows the focused pane's repository: its root is resolved
the way the Source Control tab does, its remotes are read through the Host
(the tree may be on another machine), and the github.com remote is bound,
upstream over origin in a fork, with a menu to pick another.

The list switches between issues and pull requests, open and closed, 50 rows
a page with Load more; rows carry a state glyph distinct by shape, labels
(click one to filter by it) and relative times. A row opens the detail in
place: title, state, author, labels, description and comments as Markdown,
and for a pull request its branches, size and changed files. A file opens in
the diff overlay through a new supplied-patch DiffSource, so GitHub's patch
renders exactly like a local one without a git probe.

Read-only, and sign-in reuses the GitHub CLI: GH_TOKEN, GITHUB_TOKEN, then
`gh auth token`, found on PATH or at the Homebrew locations a Finder launch
cannot see. Signed out, public repositories still work; 401, 403, 404 and
rate limits are told apart and explained. Requests go out from this machine
over the installer's ureq stack and proxy settings, on threads of their own,
cached per repository with background revalidation. Remote images in issue
text become links instead of loading, and non-web link targets are disarmed.

The Info tab gains a GitHub row that opens the branch on the remote it
tracks, or the repository for a branch never pushed.

* docs: list ShowRightPanelGitHub with the other panel actions

* feat(panel): one-line GitHub rows, a pill for the current tab

- GitHub list rows are one line: state glyph, #number, title. Labels and
  the age of the last update appear on hover, from state rather than a
  group_hover display switch, which gpui cannot paint.
- The current right panel tab sits on the sidebar's selected fill; ink
  alone could not tell five same-weight glyphs apart.
- The GitHub glyph is a 1.8px outline like the other tab icons, not the
  filled mark.
- The detail byline names both times (opened / updated) so it no longer
  reads as disagreeing with the list's update age.

* feat(github): show screenshots pasted into issues

Images GitHub hosts itself (github.com/user-attachments, a repo's
/assets, *.githubusercontent.com) now render in issue and PR text, each
in a paragraph of its own so the text view draws it at its size rather
than at line height. Images from any other host stay links, so opening
an issue still tells no third party that you read it.

gpui held a null HTTP client, so no remote image could load; the app now
installs the update check's reqwest client (same user agent and proxy)
at launch.

* fix(github): load private-repo screenshots, give inline code a neutral fill

- Pasted attachments (github.com/user-attachments/assets/<uuid>) want a
  browser session on a private repository, which an API token is not.
  The detail and comment requests now ask for the full media type, and
  each attachment is swapped for the signed private-user-images URL the
  rendered body_html carries for the same uuid.
- Inline code in rendered Markdown (the GitHub tab and the editor's
  preview) sits on a faint neutral fill instead of the theme accent,
  which is also the selection colour. Needs gpui-component 6af19d91 for
  TextViewStyle::inline_code_background.

* style(panel): tidy the GitHub and Search tabs' top rows

- GitHub drops its heading row on macOS. It existed only to hold the
  refresh tile, and no other tab has one; refresh now sits with the
  repository's other actions, in the repo row and a detail's header.
- Search's Aa / ab / .* toggles are muted while off instead of body ink.
- Search's idle note puts the folder on its own line, spelled ~/…, so
  the narrow column no longer breaks the path at a slash.

* feat(panel): order the right panel's tabs Info, Files, Search, Changes, GitHub

Info stays first as the default and the pane's overview; after it come
two pairs, the project's files (Files, Search) and its version control
from local to remote (Changes, GitHub), where Changes and GitHub were
split by the file tabs before. The palette, the Keybindings list and the
docs follow the same order.

* style(panel): drop the change count from the Changes tab

Beside one glyph of five, the number read as a badge on that tab alone,
and the Changes tab already leads with the same count under its own
heading. right_panel_tabs no longer needs the row's width, which it only
measured to decide whether the count fit.

* style(icons): fit the GitHub glyph to the other tab icons' size

The Lucide mark filled its whole 24px box, edge to edge, where tty7's
own icons keep about 3.5px clear, so at 15px it drew a size larger than
the four tabs beside it. Scale it to 0.9 about the centre, and raise the
stroke to 2.0 so it still renders at the others' 1.8.

* style(icons): a simpler GitHub glyph

Drop the Lucide mark's tail and redraw the head and legs on tty7's own
grid: the same ~15px live area and 1.8 stroke as the other tab icons, no
scale transform. The legs keep it reading as the Octocat; a head alone
read as any cat.

* test(github): find gh on PATH in the blank-variable token test

The test placed gh only at /opt/homebrew/bin/gh, which gh_candidates never
offers on Windows, so the Windows CI job panicked at unwrap. Put gh on a PATH
directory spelled with the platform's exe name instead.

* fix(github): close image and link bypasses in the issue Markdown sanitiser

Checked against markdown-rs (the parser TextView uses), several inputs got
past the line-based rewrite:

- is_github_hosted cut the host only at `/`, so
  `https://evil.io?.githubusercontent.com/x.png` (and `#`, `\`, `&#47;`)
  counted as GitHub-hosted and was fetched from evil.io. The host now ends
  at the first of `/?#\` and may hold only DNS characters.
- `<img src>` values were written into `![..](..)` unescaped, so a `)` in
  the value closed the image and opened a second one from any host. Written
  destinations are now percent-encoded.
- `<image>` (which the HTML parser reads as `<img>`) passed as an ordinary
  tag and loaded its src.
- A kept link target was copied without scanning; when the parser ended
  the link elsewhere (open title, unbalanced paren) a `![..](..)` inside it
  came alive. Markup characters in it are now encoded.
- `file&#58;///...` and similar character references passed is_safe_target
  and decoded to a `file:` link. References are decoded before judging.

The rewrite still cannot see every construct the way the parser does
(code spans inside tag attributes, fences the parser rejects, multi-line
link definitions), so the detail view now also checks the parsed tree: a
block containing a non-GitHub image, an unsafe link or definition, or raw
`<img>` is drawn as its plain source instead.

* fix(github): hide gh's console, bound Retry-After, and reject URL authorities with ?#\

- run gh through proc::output_within with hide_console, so a Windows GUI
  launch does not flash a console window and stdout is drained while gh runs.
- saturating_add a hostile Retry-After instead of overflowing i64.
- parse_github_url no longer accepts `https://evil.io#@github.com/o/r`.

* fix(search): no panic on an unbounded time budget, and read files through the size cap

ContentLimits arrive off the wire on a server; Instant + u64::MAX ms
panicked. A file that grew between the size check and the read was read
whole; it is now read through a take() at the cap.

* fix(panel): keep Load more on an empty filtered page, and drop another host's hits

- /issues pages filtered to one kind can come back empty while later pages
  hold matches; the GitHub list said "No issues" and hid Load more. It now
  reads on through up to five such pages and keeps Load more offered.
- While a new search runs, the previous hits stay on screen; if they came
  from another host, a click opened their path on the active host. They are
  now kept only when the host is the same.
2026-09-27 19:04:42 +08:00
l0ng-ai d6c223751d fix(i18n): proofread the Chinese UI copy (#980) (#981)
Fix half-width punctuation, unify terminology (passphrase, Finder,
server), quotes and dash styles, and rewrite the most literal
translations. Point every language and the CLI at Settings →
Integrations, the page's actual name, instead of Settings → Agents.
2026-09-27 18:32:56 +08:00
l0ng-ai ed939bbc26 feat(search): browse every agent's past sessions, locally and on remote workspaces (#977)
* feat(search): list more agents' past sessions, and fork, copy or hide one

The Sessions tab listed Claude Code and Codex only, and a row could only
be resumed.

- Past sessions of Gemini CLI, Qwen Code, Pi, Oh My Pi, Kimi Code,
  Copilot CLI, Droid, Qoder CLI and CodeBuddy are read from where each
  keeps them (honouring QWEN_HOME, COPILOT_HOME, KIMI_CODE_HOME, …), with
  the name the agent or user gave the session, else the first prompt.
  Context blocks agents prepend (<system-reminder> and kin) no longer
  hide a prompt.
- Cmd/Ctrl-E on a session row opens its actions: Resume, Fork Session
  (agents that can fork, with the configured launch flags), Copy Session
  ID, and Remove from List. Removing keeps the search open, drops the row
  at once and remembers it in `hidden_agent_sessions`; the agent's own
  history is not touched.

OpenCode and Cursor keep sessions in SQLite and are not read yet.

Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM

* feat(search): list remote workspaces' sessions, and OpenCode and Cursor

The Sessions tab only ever read this computer, and left out the two
agents that keep their history in SQLite.

- agent_history moves into tty7-core, and the scan goes through the
  Host: a local workspace reads this machine in-process, a remote one
  asks its server (new ControlRequest::AgentSessions; CONTROL_VERSION
  11 -> 12, so each remote host takes one Update Server). Resumed or
  forked sessions open on that machine, in the directory they ran in.
  The last answer is kept per host so the tab does not open empty.
- OpenCode: top-level, unarchived sessions from opencode*.db (or
  $OPENCODE_DB); a placeholder title gives way to the first prompt.
- Cursor CLI: chats under ~/.cursor/chats (or $CURSOR_CONFIG_DIR), named
  from meta.json or store.db. Cursor files a chat only under the md5 of
  its directory, so it is placed by matching open tabs' and other
  sessions' directories; chats nothing matches are left out, since they
  could not be resumed anywhere.
- SQLite is bundled (rusqlite), opened read-only, falling back to an
  immutable read when the writer's WAL cannot be shared.

Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM

* test(search): wait for the real scan before seeding sessions

The search's own scan runs on a real thread. On CI it landed after the
test seeded its rows and replaced them, so the edit gesture found no
row. The test now waits for the scan first. Assertion messages no
longer print session ids (CodeQL rust/cleartext-logging).

Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM

* fix(search): harden the past-session scan and note it in the changelog

- Honour CLAUDE_CONFIG_DIR for Claude Code's projects, as the hooks
  installer already does.
- Read a Codex rollout's head as bytes: the 2 MiB cap can split a
  multi-byte character, and read_line then dropped the whole session.
- Escape `%` and `#` (not only `?`) in the immutable SQLite URI fallback,
  so a database under such a directory still opens.
- Refuse a session id starting with `-`: ids now come from file and
  directory names on disk, and one would be read as a flag by the
  resume or fork command.
- Update the unreleased Sessions changelog entry for the new agents,
  remote workspaces, the Cmd-E actions and the v12 dialect bump.

* fix(search): spell the immutable SQLite fallback as file:///C:/ on Windows

SQLite reads file:C:/x as a relative path, so the fallback open (and its
test) failed on Windows. An empty authority and a leading slash name the
file on every platform.

* test(search): keep ? out of the fixture directory name on Windows

Windows file names cannot hold a '?', so the fixture's create_dir_all
failed there before the fallback was ever opened.
2026-09-27 18:18:05 +08:00
l0ng-ai c103a57c01 feat(settings): every pick-one setting is a dropdown (#979)
Single choices were drawn two ways — segmented buttons for most, a
dropdown for a few — and the segmented rows ran to their labels' width,
so the right-hand column never lined up. settings_choice now renders a
dropdown; an off-preset value shows as a checked "Custom (N)" row.
The SSH strip's forward form keeps the segmented control: it lives
outside the settings window and has no popover state to use.
2026-09-27 17:12:03 +08:00
l0ng-ai d0e42fa49b feat(tabs): drop the New Tab menu's Launch Agent row
Agents stay one search away: type agent in Search Everywhere's Terminals
tab, or use New Agent Tab.
2026-09-27 10:48:09 +08:00
l0ng-ai 84935813d5 feat(terminal): the mouse wheel no longer zooms the font by default
mouse_zoom_modifier now defaults to none. The platform modifier is cmd on
macOS, held for so much else that the font jumped size mid-scroll (#668).
Picking a modifier in Settings brings the wheel zoom back; cmd+/cmd- are
unchanged.
2026-09-27 10:42:02 +08:00
l0ng-ai 8cdbff99e2 feat(search): show recent then the rest on the empty All tab
Before anything was typed, All showed only each tab's highlights: this
window's other tabs, actions already used, and sessions from this directory.
A fresh window had next to nothing to show. Each tab now leads with its
recent rows, is topped up from the rest of the tab to five, and ends with a
row into the tab for whatever did not fit.
2026-09-27 10:37:07 +08:00
l0ng-ai 31b0d3a937 feat(ui): put Search Everywhere in the middle of the title bar
With the tabs in the sidebar, the title bar's centred path repeated what the
rail already says. It is now a field-shaped button that opens Search
Everywhere, with its chord. The trailing ... menu, which only held Search
Everywhere and Settings, is gone: both stay on their shortcuts, the macOS
menu bar and the search itself.
2026-09-27 10:25:02 +08:00
l0ng-ai 2c0403c75e fix(ui): tidy the v4 merge with Search Everywhere and pinned groups (#976)
- The changed-files filter keeps its view toggle inside the panel's content
  inset, beside the field, so it lines up with the commit row above.
- A group heading's hover buttons are backed with the rail's own fill and
  centred on the v4 heading line, instead of a white patch over the counts.
- Shorten the prompt cursor and SSH tab title descriptions to one line.
2026-09-27 10:01:40 +08:00
l0ng-ai 572bfc014b feat(ui): v4 redesign, including a rebuilt settings window (#973)
* feat(ui): restyle the right panel after the v4 design

- Tab row: 12.5/16rem word tabs 22px in and 18px apart, the current one in
  body ink at medium weight; no hover pill, no underline bar, no hairline
  under the row.
- Info: Session, Processes and Ports are spaced 16px apart with no rules;
  28px medium muted headings, 28px Session rows on a 76px label floor with
  values in body ink, 26px process rows with a tree elbow for children, and
  an explicit empty line for Ports.
- Files: the search sits in a 28px filled well; tree rows are 26px with a
  disclosure chevron column, ignored entries dim their icon instead of
  going italic, and a folder's change dot is 5px.
- docs/design-system.md updated to match.

* feat(switcher): restyle the workspace switcher after the v4 design

- Card: 112px from the top, 12px corners, 48px search row with an esc
  keycap, 420px body split 340px / preview, 40px footer.
- Workspace rows are 52px: a 26px initial disc carrying the link state as
  a ringed dot (live green, faint when offline, amber while connecting,
  red on failure), a medium name with its stable number, a machine ·
  path · time line, and the tab count over the state word.
- Preview rows are 44px with the sidebar's 18px brand disc, an all-muted
  branch · diff line, a Current label and a 5px dot that blinks with the
  sidebar while an agent is working.
- Footer: ghost New workspace button and keycap hints for navigate, open
  and new window; the unused click-for-new-window string is dropped.

* feat(scm): restyle the Changes tab after the v4 design

- Pinned block keeps 8/10/14 rhythm; branch name medium, 26px sync tile.
- Commit message box rests at 56px with a 7px radius.
- Split commit control: inverted neutral fill when committable, faint
  fill otherwise; 6px radius and an inset 0.5px seam.
- Change groups sit 16px apart under 22px sentence-case medium headers;
  file names take width first and directories right-align, eliding
  from the start.
- History: 32px header, 26px rows inset with rounded hover, 1px lines
  and 7px beads (HEAD filled, others hollow), neutral inks on a
  single-lane page, age column always shown, faint HEAD pill.

* feat(ui): restyle the rail and palette after the v4 design

- Default Light/Dark take warm neutrals (#fcfcfb/#1c1c1e, #18181a/#ececed);
  Git added/modified seeds follow v4 green and amber.
- The left rail gets its own tinted fill again (Neutrals.rail, 3% toward
  the ink) with its own surface ladder; the right panel keeps the content
  fill. Captions and hairlines are floored on the rail too.
- Title bar is 48px; the bar over the terminal centres the active tab's
  title in caption ink when tabs live in the rail.
- Rail header: 26px new-tab and collapse tiles, then the workspace chip
  and search field (28px, 7px radius).
- Groups sit 16px apart under a 22px caption heading with
  'branch · +a −d' in tabular numerals.
- Rows are 30px (42px with a branch line), 16px avatars, medium weight
  when current, branch cut from the front, and a trailing 5px status dot
  (blinks while working, hollow while waiting, unread count as a pill).
- docs/design-system.md updated.

* docs(design-system): note the commit button's inverted neutral fill

* fix(panel): align the right panel's insets with the v4 design

- Rows pad 8px inside lists inset 12px, so text sits on a 20px column in
  every tab and hover fills start 12px in with a 6px radius. Headings,
  empty states and the Ports line move to the same column.
- Tab labels 18px apart; the panel row's chrome tiles are 26px, 4px
  apart, 12px from the edge. Default panel width 280.
- Info: label column floor keeps values at x=88; Ports add tile 22px.
- Changes: 8px top gap on macOS, pinned block on 14px edges with the
  branch at 22, 12px sync glyph, 8px group chevron, 10px status cell,
  1px between rows.
- History: compact gutter for single-lane pages, filtered rows on the
  text column, 10px row gap, 24px age floor, header on 20px insets,
  4/12 padding when expanded (heights re-counted in commits).
- Files: search well at 12px with an 11px glyph, 10px before the tree,
  16px indent step, 16px bottom padding.

* feat(diff): restyle the diff overlay and commit detail after the v4 design

Carry the v4 language into the diff overlay and the commit detail view:
0.5px hairlines at 8% ink, 26px row pills with a 6px radius, the rem type
ladder from right_panel.rs, neutral chips instead of accent washes, the
shared git_badge for status letters, and tabular figures on counts.
Layout, spacing, type and colour only; no behaviour or i18n changes.

* feat(ui): restyle the dialogs, notices and home page after the v4 design

- New ui::dialog module holds the shared modal chrome, taken from the
  workspace switcher: a 12px card, a 48px title row with an esc keycap,
  18px insets, a 40px hairline footer, 28px borderless field wells on the
  faint fill, 11.5px medium muted labels, and 18px keycaps.
- Buttons: the primary is the inverted neutral fill, the Commit button's
  paint, instead of the accent. Secondary buttons are transparent with the
  surface's hover rung. Override on a changed host key stays the one red
  button. A disabled button sinks to the faint fill and drops its click
  handler.
- SSH sheet: host and fingerprint lines sit in a mono detail well, and
  keyboard-interactive prompts become field labels. Banners match the
  sheet's width and card shape.
- Worktree prompt: moves to the same card, with the path preview hung off
  the Name field.
- Notice pill: severity moves from a tinted edge to a 6px leading dot.
- Home: shortcut rows are 28px with a hover fill and keycap chords, and the
  remote strip's action uses the secondary button.

* fix(panel): start Info and Changes flush under the tab row

Their first line is text centred in a 28px row, so the extra 8px step put
it visibly lower than the Files tab's search well. Only Files keeps it.

* fix(scm): put the commit detail on the right panel's 20px text column

* feat(palette): restyle the command palette after the v4 design

- Card: the switcher's 12px corner, 112px drop from the top (shorter
  windows still scale it up), 600px max width.
- Search row keeps the list's own field; an esc keycap sits in its
  trailing corner while the field is empty.
- Rows are 32px with an 8px corner, 8px list inset and 10px padding. The
  keyboard row takes the popover's neutral selected step and a medium
  title instead of the accent wash, via a palette row element in place
  of ListItem.
- Section headings: 28px, 11.5/16rem medium caption ink, on the rows'
  text column. Shortcuts are per-key 18px faint keycaps from ui::dialog.
- New 40px footer with the switcher's keycap hints (navigate, open).
- Empty state: headline in body ink, hint in caption ink.

* feat(ui): carry the v4 chrome into panes, the file viewer and SFTP

- theme: additive helpers for a device-pixel hairline, tabular figures
  and an inverted neutral button variant.
- Pane splits rest as a device-pixel hairline in the divider tone; hover
  and drag keep the accent at 1px like the other resize edges.
- File viewer header: medium file name, 5px unsaved dot, 26px/6px close
  tile with its glyph on the content inset, divider hairline under it.
  Status bar: divider hairline, caption size, tabular line/column.
- SFTP browser: file-tree rows (26px, 6px corner, 16px caption glyphs),
  breadcrumb and notes on the 20px text column, a borderless edit well,
  inverted OK button, and ink-on-track transfer progress.
- Forward rows line up with the process and port rows (text at 20px,
  6px corner); Add and Reconnect use the inverted neutral fill.

* docs(design-system): note the v4 palette, pane, viewer and SFTP chrome

* feat(settings): restyle the settings page after the v4 design

- Nav: the rail's tinted fill and surface ladder behind a divider hairline;
  a 28px filled search well; 28px rows in 7px pills, the current one on the
  selected rung at medium weight instead of the accent; match counts in
  muted ink; the modified-only filter toggles like a nav row.
- Pages: the title sits in the 48px title-bar band at 16/16rem; group
  headings are 11.5/16rem medium muted on a 28px line; sections are split
  by a 0.5px divider with 16px either side.
- Rows: labels in body ink at regular weight, descriptions at 12/16rem
  muted, 28px floor with 8px padding; a search hit wears the faint neutral
  fill rather than the accent tint.
- Controls: text fields and dropdowns are 28px filled pills with no
  outline; buttons, segmented tracks and steppers are 26px with a 6px
  radius on the same fill. The one primary action per view (save theme
  draft, connect, install update) is the inverted neutral fill of the
  commit button. Switches and sliders keep the accent.
- SSH: host list header with 26px tiles and a filled search, 22px group
  headings, 42px two-line host rows; the form's labels are a muted,
  right-aligned column level with 28px fields; disclosure headers use a
  chevron on a 28px band.
- Theme cards are filled and unoutlined, taking the selected rung while
  open; the theme panel keeps the content fill with a divider edge and its
  title in the title-bar band. Keycaps are filled with no outline and
  shortcut rows are divided by 0.5px hairlines.
- right_panel::SECTION_GAP is now shared; docs/design-system.md updated.

* feat(ui): spell tab titles out in full in the rail and title bar

The rail's rows and the centred title have room to spare, so they take
the whole label from a new full_tab_label rather than tab_label's
three-segment cut; only the width they have decides what gets elided.

* fix(settings): even out the page rhythm and line up the columns

- Nav header: drop the min_h(ROW_H)/min_h(0) pair on the heading, which
  measured ~46pt taller than it painted and opened a hole under the search.
- Page titles sit under the title-bar band, level with the nav heading,
  instead of jammed against the window's top edge.
- Headings get a 22pt group-header row and hug their rows; rules keep more
  air, so a heading reads as its rows' rather than floating between.
- SSH: the host list gives width before the nav, so the nav no longer
  narrows on that page; its header, search well and detail title run level
  with the nav's; the empty note starts on the host-title column.
- Window & Tabs no longer opens on a stray rule.
- Integrations: status leads the buttons on one line, in the meta ink.
- Terminal: the shell footnote stays close to its rows.

* fix(ui): stop eliding branches that fit, and seat the SCM branch on the text column

- elide_tail_clusters returned "…" plus the whole string when nothing
  needed cutting, so the rail's group header printed …feat/v4-redesign
  with room to spare. Return the text as-is when it fits.
- The group header only reserves the chevron's width when it draws one.
- The Changes tab's branch name no longer stacks a small button's padding
  on the row gap; it starts on the file names' column.

* fix(ui): keep a tab's name in place when an inline rename starts

gpui-component's Input keeps 12px of inner padding even with
appearance(false), so the name jumped sideways as the rail row, the
group header and the top-strip chip swapped their label for the field.

Claude-Session: https://claude.ai/code/session_01Q9vsQSxAZjkwT7nRAiFF1J

* revert(settings): restore the page rhythm from before 08497d57

The title in the title-bar band, full-row headings, SECTION_GAP rules and
the shell footnote's spacing read better than the tightened version. The
bug fixes from that commit stay: the nav gap under the search, the stray
rule on Window & Tabs, the SSH column alignment and nav width, and the
one-line Integrations rows.

Claude-Session: https://claude.ai/code/session_01Q9vsQSxAZjkwT7nRAiFF1J

* revert(settings): restore the pre-v4 settings layout, on the rail's fill

The v4 restyle (541a887a) and the follow-ups crowded the page. Bring
settings.rs back to main's layout and give its sidebar the main window's
tab-rail fill, so the two sidebars read as one surface.

Claude-Session: https://claude.ai/code/session_01Q9vsQSxAZjkwT7nRAiFF1J

* feat(settings): rebuild the settings window after the v4 design

Rewrites the settings page to the Settings design: a sidebar with search,
per-page modified counts and a "Modified only" switch; quiet grouped rows
with an inline Reset; and the design's own controls (switch, segmented,
stepper, slider, text field, dropdown and popover menus) in a new
`settings/kit.rs`.

- Appearance: Light / Dark / System cards and a theme menu per slot with a
  live preview, search, keyboard navigation and swatches. Font menus are
  searchable and draw each family in itself.
- Keyboard shortcuts: back link, search, "Restore N changed", Default/tmux.
  A recorded chord another action already has now asks Replace / Cancel
  instead of taking it over silently.
- SSH: one column of recent hosts, "Show all" by source, search; details and
  a six-field editor open in place. Auth, jump/proxy, forwarding and
  advanced sections are no longer shown; saved values are kept.
- Integrations: machine menu, agent search, install summary, agent icons,
  and a per-row menu (Reinstall, Reveal hook file, Uninstall).
- General gains startup and restore; updates and the server move to About.
- Search results group live rows by page; a Modified view lists changes.

The page code moves out of settings.rs into src/ui/settings/.

* fix(ui): lay truncating names out at their full width

Moves the gpui fork to 5d366e6, which stops a size measured under
truncation from answering the later whole-text measure. Before it, a
truncating name beside other content in a flex_1 column read as just its
ellipsis with the whole column free. Adds a switcher test that fails
without the fork change.

* fix(scm): seat the History chevron on the change groups' column

The History header now draws its chevron in the change groups' own box
and size, so its title starts where Staged Changes and Untracked do.
Folded, the header drops to 24px with even padding instead of the
expanded section's taller band.

* chore: ignore local design mockups and Impeccable state

* fix(macos): show enter and tab shortcuts correctly in menus

Moves the gpui fork to 5c390b9, which maps enter and tab to their native
key equivalents. A menu item bound to secondary-enter, like
ToggleFullscreen, read as ⌘E.
2026-09-27 09:48:25 +08:00
l0ng-ai 6fcf659e04 feat(search): tabbed Search Everywhere with a Sessions tab to resume agent sessions (#969)
* feat(search): replace the command palette with tabbed Search Everywhere

The palette was one flat list that every new kind of row had to be squeezed
into: tabs and SSH hosts rode along as "Switch to Tab: …" and "SSH: …"
commands, and the only way to narrow to one kind was a magic seed word.

Search Everywhere splits it into sources behind one trait — All, Actions,
Terminals, Hosts — each with its own empty-query layout and ranking. The All
tab shows each source's top rows, ordered by best match, with a row that
opens the full tab. Tab / Shift-Tab walk the tabs and keep the query.

- Terminals lists every open tab of every workspace (reusing the switcher's
  tab rows) and jumps to it wherever it lives, plus the shells and agents.
- Hosts replaces the separate "Add Connection" input: a typed address or
  full `ssh …` line offers to connect.
- Fixes Return doing nothing after a search that found nothing, or when the
  search opens pre-filtered: gpui-component re-picks the row from a stale
  frame; the delegate now re-arms the first row.
- Fixes `ssh -p 2222 me@box` being offered as a quick-connect address with
  user `ssh -p 2222 me`.

The keymap action stays `TogglePalette` so custom bindings keep working.

* feat(search): a Sessions tab to resume past agent sessions

Search Everywhere gains a Sessions tab listing the Claude Code and Codex
sessions on this computer, read from ~/.claude/projects and
~/.codex/sessions ($CODEX_HOME). Sessions that ran in the focused tab's
directory lead; the All tab offers the last three of them before anything
is typed. Return opens a new tab in the session's directory and runs the
agent's resume command with its configured launch flags.

- Only each transcript's head and tail are read, off the window thread,
  and cached by path, size and mtime: ~170ms cold for 50 sessions,
  under 1ms warm. The search opens on the cached list and fills in.
- Titles: /rename name, then the agent's own title (ai-title, Codex's
  session_index.jsonl), then the first thing typed, skipping harness
  injections. Codex rollouts it ran for itself (subagent/internal) and
  sessions never asked anything are left out.
- A session whose directory is gone is refused with a notice rather than
  resumed where the agent cannot find it.
2026-09-27 09:38:31 +08:00
l0ng-ai 39ceb35fdd feat(cursor): give the shell prompt its own cursor shape (#963)
A new prompt_cursor_style setting (follow, block, bar, underline) shapes
the caret while the shell waits at a prompt, whether tty7's inline editor
or the shell's own line editor draws it. `follow`, the default, keeps
cursor_style everywhere, so nothing changes until it is set. Any other
value leaves cursor_style to the programs the shell runs: bar here with
cursor_style block gives kitty and ghostty's bar at the prompt and a block
inside a TUI that never sets a shape, such as Claude Code. A vi-mode
prompt keeps the shell's own insert/normal shapes.

Settings shows both cursor shapes as dropdowns, kept in step with resets,
language switches and config edits made outside the window.

Closes #958
2026-09-27 09:35:18 +08:00
l0ng-ai 334734b0b6 feat(links): make Windows file paths clickable (#971)
* feat(links): make Windows file paths clickable

Drive-letter paths with either separator and UNC shares resolve as file
links, including when CJK prose or a Markdown link is glued onto them.
Windows paths are spelled with backslashes and an upper-case drive so
Explorer can open and reveal them, the Windows join is textual so a Mac
asking a Windows host sends one spelling, and a POSIX pane looks a drive
path up under /mnt/<drive> for WSL. Drive-relative tokens (a:b, C:,
C:notes.txt) are never probed.

Closes #965

* feat(links): quoted paths with spaces and Open with Default App

A path enclosed in matching double quotes, single quotes or backticks is
read as one candidate even when it contains spaces, with a line:column
location inside the quotes or right after the closing one. The quoted
span must look like a path (a separator, no space at either end, at most
260 chars) and yields a single reading, so quoted prose costs one lookup.
Unquoted spaces still end a path.

The file-link context menu gains Open with Default App, which always
uses the OS association. It is shown only for local files and hidden when
link_file_open is already system. The OS opener and Reveal now spell
Windows paths with backslashes before handing them to Explorer.
2026-09-27 09:31:58 +08:00
l0ng-ai b5cb6efe7a style(sidebar): mark pinned groups with ◆ instead of a pin icon, drop the divider (#972)
The pin icon read as a smudge at header size. Kept groups now carry a small
◆ beside their name — every kept group, label groups too, since with the
divider gone it is the one thing that tells kept from derived. On a folder
group the mark is still the click that unpins it, and the hover button that
pins an auto group shows the same character.

The divider is no longer drawn at rest. It keeps its (smaller) place in the
layout and its recorded bounds, so pinning a header by dragging it up and
handing a tab back by dropping it below behave exactly as before, and it
still shows as a line while it is the drop target.
2026-09-27 09:31:49 +08:00
l0ng-ai 03c24514b2 fix(editor): ghost suggests the newest match, not the most frecent (#968)
The inline suggestion now takes the newest history entry that extends
the line, preferring one run in the current directory and falling back
to the newest anywhere, and skips commands whose last run failed. It
used to be the top frecency match, where run count and the directory
bonus outweighed recency. Ctrl+R keeps ranking by frecency.

Re-submitting a command now drops its older copy, matching the global
dedup applied when history loads, so up-arrow steps onto each command
once.
2026-09-27 09:31:43 +08:00
l0ng-ai a6e4235d27 fix(render): stop a blank IME preedit hiding the cell under the cursor (#970)
paint_marked blanks the cursor's cell to the theme background before laying
an IME composition down. A composition with nothing visible in it (Windows
IMEs can leave one behind) therefore painted a background-coloured hole with
an underline over the character and the block cursor on every cell the
cursor visited. Skip painting a preedit that has no ink.

Fixes #966
2026-09-27 09:31:35 +08:00
7a32e7dbbc feat(agents): recognise Empryo and Prime Agent, add Antigravity status hooks (#975)
* feat(agents): recognise Empryo and Prime Agent

Prime Agent (PrimeIntellect-ai/prime-agent) is a Pi fork: detected as
`prime-agent`, resumes with `--resume <id>`, forks with `--fork <id>`,
`--no-session` opts out, and reports status through the shared Pi
extension bridge at ~/.prime/agent/extensions/tty7/index.ts.

Empryo is detected as `empryo` and resumes with `empryo --session <id>`.
No hook installer yet: Empryo filters TTY7* variables out of hook
processes, so `tty7-app agent-hook` would stop at the missing marker.

* feat(agents): Antigravity status hooks

Antigravity CLI (`agy`) now installs a `tty7` hook set in
~/.gemini/config/hooks.json, next to the user's own sets:
PreInvocation -> prompt-submit, PostToolUse -> tool-complete,
Stop -> stop. Only the first PreInvocation of a turn (invocationNum 0)
counts as a new prompt, later ones keep the turn working; a Stop with
fullyIdle false is ignored. conversationId and workspacePaths feed the
session id and cwd. PreToolUse is left alone because it must answer
with a decision.

* fix(agents): index Prime Agent and Antigravity in settings, scope conversationId alias

- Add settings titles, search keywords (en/ja/zh) and Agents index entries
  for the two new HookAgents; agent_rows_are_in_the_search_index requires
  one per HookAgent::ALL.
- Read Antigravity's conversationId as the session id only for antigravity:
  the alias table is last-write-wins, so a global alias could replace
  another agent's session id.
- Drop the stray .empryo/ job records.

---------

Co-authored-by: kalpak <you@example.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-09-27 09:30:11 +08:00
migegeandl0ng-ai e6009636b5 feat(tabs): reorder the active tab from the keyboard (MoveTabLeft / MoveTabRight) (#974)
* feat(tabs): MoveTabLeft / MoveTabRight — keyboard tab reordering

The drag that reorders a tab now has a keyboard form: the active tab trades
places with its neighbour in visual order, wrapping past either end. Ships
unbound like the pane-swap pair; bindable from config.json and the Keybindings
page, and listed in the palette and the docs.

* fix(tabs): keep a keyboard tab move inside its sidebar group

On a left tab bar the move stepped along the flat visual order, so a
step out of a group reordered self.tabs without moving anything on
screen (still saved, still synced as TabMove, and visible later on a
top bar), and a wrap through another group landed the tab at its own
group's far end by accident. The move now reassigns only the slots of
the tab's own sidebar section, and wraps at that section's ends.

---------

Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-09-27 09:29:30 +08:00
l0ng-ai cf0e8f02e6 feat(sidebar): pinned groups above auto groups (#962)
* feat(sidebar): keep pinned groups on the workspace and derive the rest

Replace the sidebar's hand-made groups with the model from #955: the sidebar
groups tabs by repo automatically, and you pin what you want to keep.

- Pinned groups (`PinnedGroup`: id, optional name, optional folder, fold) are
  stored on the workspace in the machine tree, in display order, and a tab
  points at one by `GroupId`. Everything else is an auto group worked out
  every frame and never stored: by repo home, or by `user@host` for an SSH
  pane — native or a shell that ssh'd onward — so `/home/ubuntu` on two
  machines no longer lands under one header.
- A tab whose cwd *enters* a pinned folder joins it (deepest folder wins; a
  repo home equal to the folder counts, which keeps worktrees with their
  repo). It is edge-triggered through `EntryWatch`, so a tab dragged out
  while still inside the folder stays out until it leaves and comes back, and
  a tab restored at launch is not pulled in by where it already sits.
- Groups sync as one `WorkspaceSetGroups` / `GroupsChanged`, pushed only from
  an edit and adopted from every pull, so a fresh window can never push an
  empty set over the workspace's. The machine hands tabs naming a dropped
  group back to auto grouping in the same mutation. Control dialect → v11.
- Config: `sidebar_grouping` (three modes) and `sidebar_collapsed_groups` give
  way to one `sidebar_auto_grouping` toggle; folds live with the workspace.
- `tty7 tab ls` reports the pinned group a tab is in (name or folder leaf;
  JSON carries id, name and folder).

* feat(sidebar): draw pinned groups above a divider, with their own gestures

The sidebar now reads as two halves: the groups you keep, in the order you
put them, then a divider, then the groups it works out (Arc-style).

- Pinned headers drag-reorder among themselves (their own reorder surface, so
  a pinned header cannot be dropped among the derived ones); the order lands
  on the workspace's group list, not on the tabs.
- An auto header carried above the divider is pinned when let go. With
  nothing pinned yet the divider appears during that drag as a "Drop here to
  pin" zone, since a hairline at the top of the list is nothing to aim at.
- A tab kept in a pinned group and dropped anywhere below the divider goes
  back to auto grouping; the divider lights to say so.
- An empty pinned group stays, with a "+ New Tab" row that opens a tab in its
  folder (or where ⌘T would, for a label group) and files it there.
- Folder groups carry a pin mark that unpins on click and a tooltip with the
  folder; auto headers show pin and "+" on hover.
- Header menus: pinned — Rename, Set Folder… (local workspaces), Use Current
  Tab's Folder, Clear Folder, New Tab, Unpin (folder groups), Delete. Auto —
  Pin Group, New Tab. Nothing renames an auto group; nothing pins implicitly.

* feat(sidebar): open folders as pinned groups from Finder, the file tree and the palette

Every way into a pinned group the design calls for:

- Drop a folder from Finder or Explorer onto the sidebar to pin it (a local
  workspace only — a dropped path is this machine's, and a folder group keeps
  a directory on the workspace's host). Files are let fall.
- "Pin as Group" on a folder in the file tree, on local and remote workspaces
  alike, since the tree and the group are both on the workspace's host.
- Palette "New Group" makes an empty label group and opens its name for
  typing; "Open Folder as Group…" picks a folder with the system picker, pins
  it and opens a tab in it. The picker browses this computer, so that one is
  not offered on a remote workspace.
- Tab right-click "Move to Group" lists the pinned groups plus "New Group…",
  which files the tab in a fresh label group with its name open for typing.

Pinning a folder already pinned hands back the group that keeps it rather
than making a second one to split its tabs with.

* fix(sidebar): let groups that arrive from elsewhere pull no tab into a folder

A window draws its first frames before its copy of the workspace's groups
lands, so every tab's entry watch recorded "in no folder" — and the groups
landing then read as each tab walking into its folder. A restored tab, or one
dragged out of its folder group, was pulled back in on every launch.

Groups adopted from a pull or from another window's `GroupsChanged` now start
every tab's watch over from where it is; only this window's own pin gathers
the tabs inside the folder, and says so tab by tab. A tab also goes up with
the group it names even when the window does not know that group yet, so a
sync in that same gap cannot send every kept tab back to auto grouping.

* docs(sidebar): describe pinned and auto groups, and log the change

Rewrite the sidebar page's grouping section around "grouped by repo
automatically; pin what you want to keep": the divider, folder and label
groups, the edge-triggered join, every way to pin, and the header menus. The
configuration reference swaps `sidebar_grouping` for `sidebar_auto_grouping`,
the CLI reference describes the GROUP column as the pinned group, and the
changelog gains an Unreleased entry (#955).

* fix(sidebar): file a tab opened by the CLI in a pinned folder into it

A tab that reaches a window as TabCreated — from `tty7 tab new` or another
window — started its entry watch as a restored tab, so opening one inside a
pinned folder left it in the auto group below. It is as new as a tab opened
here, and now joins the folder like one; every window that hears of it
reaches the same answer.

* test(machine): build the group sets in their initializers

Clippy's field_reassign_with_default on the two WorkspaceGroups the
set-groups test assembles.

* fix(sidebar): draw restored tabs in their auto group, and title by repo again

Auto groups are not stored, so after a restart every tab sat in Ungrouped
until its own repo probe came back, then jumped; before pinned groups the
stored repo key put it in place on the first frame. Each tab now carries
`last_auto`, the auto group it last resolved to, as a hint: stored with the
tab, sent up alongside its group in `TabSetGroup` whenever the live answer
moves, and used to draw the tab until the probe answers. The probe always wins
and rewrites the hint, and the hint never outranks a pinned group or the
folder-entry rule. Another window's hint only fills a gap, so two windows can
never bounce a disagreement between them.

The workspace's fallback title regained the repo majority it lost: the most
common pinned folder first, then the repo most unpinned tabs were last filed
under (a worktree counting toward its repo home), then a pane's cwd.

* refactor: drop what the new sidebar left unused, and two clippy findings

- `TerminalView::native_ssh_cwd` and its helper existed for the sidebar's old
  folder grouping of native SSH panes; an SSH tab now groups by host, and
  nothing else read it.
- The file tree's context menu takes `cx` instead of `danger` and the new
  groups flag, back to the argument count it had on main.
- A title test builds its workspace in the initializer.
2026-09-25 16:53:26 +08:00
l0ng-ai afcb8aa2dd feat(agents): quick launch for detected CLI agents (#961)
* feat(agents): quick launch for detected CLI agents (#955)

Every agent whose launch program is on PATH becomes a palette command,
"Agent: <name>", ordered by frecency and bindable as LaunchAgent:<slug>.
"New Agent Tab" (Cmd+Shift+A on macOS; unbound elsewhere, where
Ctrl+Shift+A is select-all) launches the most recently used one, and the
New Tab menu gains a single "Launch Agent..." row that opens the palette
pre-filtered to them.

A launch always opens a new pane (a tab in the active tab's cwd, or a
split when picked from the palette with Alt held) and types the command
into that pane's shell once it exists - immediately for a local pane, on
landing for a remote one via PendingSpawn::run_on_land - never into a
pane that was already there. Detection, status and resume then work as
for a hand-typed agent.

The command is the agent's bare binary unless the new `agent_launch`
config map overrides it. A wrapper named there is detected as its agent
without an `agent_commands` entry: the daemon folds the programs
`agent_launch` runs into its alias map (interpreters, shells and real
agent names excepted), reloaded when config.json changes instead of
once per process, and a mapped script run under its interpreter
(`bash ~/bin/cc`, `node cc.js`) is now recognised too.

A running agent's pane menu gets "Set Current Launch Args as Default",
which writes its launch argv - minus session flags and positional
prompts, joined with the settings' quoting - into `agent_launch`.

Remote workspaces cannot be asked for their PATH through the Host
trait, so they offer the agents previously seen running in that
workspace (WindowView::seen_agents).

* fix(agents): count only agents that start under a view, not ones reattached to

A view rebuilt over a running pane - every agent tab after an app
restart, or a workspace switched back to - saw its agent appear from
nothing and reported it as detected, bumping that agent's frecency once
per launch of the app. The terminal now remembers whether its link was
an attach, and such a view only reports agents once its shell has been
seen back at the prompt with no agent in front.

Also pins down that the agents seen in a remote workspace, its quick
launch list, persist in views.json with the rest of the workspace.

* fix(daemon): probe the foreground as soon as a new program takes it

The foreground probes ran on output only, at most once per 500ms
interval. A quick launch types the agent's command the moment the shell
is up, so the agent drew its whole first screen inside the interval of
the prompt it was typed at and then waited for a key: the pane never
learned it was running an agent until something else printed. Seen in
a dev instance, where a launched Claude Code stayed undetected at its
trust prompt.

The reader now asks the pty for its foreground process group on every
read (one ioctl) and probes immediately when it changes.
2026-09-25 16:47:59 +08:00
l0ng-ai 27483e893d feat(ui): collapse the New Tab menu's shell list to three by frecency (#960)
The + menu listed every shell the machine reports (nine on a stock macOS box)
above the SSH hosts. The Local section now names the default shell, always
first, then only shells that have actually been opened, by frecency, three rows
at most, the same way the SSH section caps its hosts.

Shell usage is recorded in a new `shell_frecency` config map, keyed by the
inventory label, bumped from both the menu row and the palette. Every shell is
now a palette command titled "Shell: {label}" (same word in every locale), and
an "Other Shells…" row opens the palette pre-filtered to them. That row is
hidden when the menu already names the whole inventory. Running a shell command
from the palette respects the ⌥/Alt split modifier like the menu row.
2026-09-25 16:44:32 +08:00
l0ng-ai bd0dd22bfa feat(tabs): hibernate a tab to free its memory and wake it later (#954)
A tab can be put to sleep from its context menu or the command palette:
its panes are stopped (screens kept on disk), the tab keeps its place in
the sidebar, and selecting it wakes it through the same restore a reboot
runs, resuming a supported agent's session. The sleep mark lives on the
machine tree, so it survives app and daemon restarts.

Closes #762
2026-09-25 16:41:12 +08:00
l0ng-ai 9f034558c0 feat(ssh): switch a port forward off without losing its rule (#953)
A forward could only be removed, so pointing one local port at another
remote target meant deleting the rule and retyping the other one (#439).

Forward rules gain an `enabled` flag (serde default on, so saved profiles
and older peers keep every rule live) and the daemon a SetForwardEnabled
op for panes and workspaces. Off releases the listener and keeps the
entry; on rebinds it from the rule it was made from, and is refused by
name when another switched-on forward of the same owner holds the port.
The Ports panel and the Settings rules editor each get a switch; a
switch flipped in the panel on a rule from a saved host is written back
to that host.

Closes #439
2026-09-25 16:38:00 +08:00
l0ng-ai de15f9b0ab feat(ssh): keep saved hosts in servers.json and add an SSH tab title setting (#952)
Saved SSH hosts and their usage counts move out of config.json into
servers.json beside it, so config.json can be synced between machines
without carrying a server list (#911). An older config.json is split on
first load: servers.json is written first (0600), then only the two keys
are removed from config.json, leaving every other key as it was. When
both files hold hosts, servers.json wins and the stale copy falls out of
config.json at its next save. A servers.json that does not parse is kept
aside and blocks saves, as config.json does; hand edits hot-reload.

Settings -> Window & Tabs -> SSH tab title (`ssh_tab_title`) pins an SSH
tab to the profile name (saved host name, ~/.ssh/config alias, or the
address typed for a quick connect) or the hostname, on the OSC title's
rung of the existing label ladder: a renamed tab still wins, OSC titles
are still tracked, local panes are untouched (#726).
2026-09-25 16:34:38 +08:00
l0ng-ai 02d8611e33 feat(cli): add exec, and send --stdin/--from-file/--paste (#951)
`tty7 exec %N -- CMD` types a line at an existing pane's shell prompt,
follows the shell integration's OSC 133 marks to the command's end, prints
what it printed (rendered to text by default, `--raw` for the bytes) and
exits with its exit code. `--timeout` exits 124 and leaves the command
running. A pane with no prompt marks, or one not at a prompt, is refused
before anything is typed.

`tty7 send` can take its text from `--stdin` or `--from-file`, sent byte
for byte and never echoed in --json, so a secret stays out of `ps` and
shell history. `--paste` frames the text the way the GUI's paste does:
bracketed when the pane has mode 2004 on, unframed otherwise, reported in
--json. The framing moves into tty7-core (`core::paste`) so the GUI's
clipboard paste, the agent prompt and the CLI share one construction, and
the daemon now reports each pane's bracketed-paste mode in PaneContext.

Closes #839
Closes #838
2026-09-25 16:32:19 +08:00
l0ng-ai 23948bcdda fix(render): draw fallback Nerd Font icons at the text's size (#949)
* fix(render): scale fallback-font icons up to fill their cell

A lone Private Use Area glyph supplied by a fallback face is drawn at the
primary's font size on the fallback's own metrics, so Nerd Font icons came
out about two thirds of the cell. Grow such a glyph, aspect ratio kept,
until it fills the width of its cells or the height of the row (at most
2x), and centre it there. Overflow is still shrunk as before, text from a
fallback face keeps its metrics, and the primary's own icons are untouched.

Closes #866

* fix(render): fit fallback icons to their cells, borrowing a same-colour blank

Checked in the running app with Symbols Nerd Font Mono behind Menlo: its
icons ink a full em (1.6 cells), so growth alone never fired. What made
them small was the one-cell budget an icon gets when the space after it
paints a background, which is every icon in a coloured prompt segment.

Fit a fallback icon to its cells and one em of height instead, letting it
take the blank after it when that blank paints no background or the
icon's own, and only when that makes it bigger. Leave the Powerline
separators to the existing rule.

* docs(render): name icon_fit in the fit_scale test's comment
2026-09-25 16:28:49 +08:00
l0ng-ai 455e74dc2c feat(scm): filter changed files and show them as a tree (#950)
* feat(scm): filter changed files and show them as a tree

* test(scm): key the tree test's settle on the panel's own root
2026-09-25 13:53:44 +08:00
575d2cd68e fix(agents): drop the previous session id when the foreground agent changes (#957)
同一 pane 里前台从 Claude 换成 omp,或别的 agent 的 hook 写进这个 TTY 时,旧的 session id 会留在新 agent 上,Fork 就会拿错 id。

Co-authored-by: stevelliu <stevelliu@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-25 13:52:36 +08:00
l0ng-ai 3a52e34b02 fix(linux): wrap the confirmation dialog's text instead of clipping it (#948)
Linux has no native prompt, so every window.prompt fell through to gpui's
fallback renderer, which sets the message and the detail as unbreakable
single lines in a fixed-width box with overflow hidden. The quit-and-stop
warning was cut off mid-sentence. Install a prompt builder on platforms
without a native dialog that lays the same prompt out as a card whose text
wraps, in the app's own surfaces, with Return taking answer 0 and Escape
the cancel answer.

Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM
2026-09-25 13:50:39 +08:00