Two things the async rewrite let slip.
The search walk bakes the dotfile setting in — hidden and ignored entries
never reach the hits — so the eye toggle did nothing while a query was up:
`retarget` only compared the query string, and the query hadn't moved. It
now compares the setting too, and flipping it re-walks.
`file_tree_refresh_roots` returning early on an unchanged root set also
skipped the watcher rebuild, which spans *every* tab's roots — so closing a
tab left its root watched for the rest of the session. The cache-drop still
hangs off the per-tab check; the rebuild now compares the union itself.
The tree did its filesystem work inside the paint. `ensure_loaded` ran a
`read_dir` plus a `.gitignore` chain compile for every root and every
expanded directory that wasn't cached, and a non-empty search box replaced
that with a breadth-first walk of up to 2000 directories — re-run on every
keystroke, because the search input notifies per `InputEvent::Change`. On
a cold cache or a large repo that is a visibly stalled frame.
Render now only reads caches. A miss becomes a queued load that runs on
the background executor and lands with a `cx.notify()`, so a
just-expanded directory fills in on the next frame rather than blocking
this one — the same trade every editor makes.
- `TreeLoader` owns the filesystem half, including its own `.gitignore`
matchers (`Arc`, not `Rc`, so they can cross threads). It is seeded from
the UI thread's compiled matchers and hands back the ones it compiled,
so the cache still warms. The ignore semantics are unchanged: deepest
match wins, `!` whitelists un-ignore, `.git` is always ignored.
- `Loads` tracks what is in flight and what a watcher event superseded
while it flew, so a repaint can't spawn a second load for the same
directory and a listing that predates a change can't install itself.
- The search is debounced 200ms, walks on the background executor, and
carries a generation so a slow walk can't overwrite a newer query's
answer. Previous hits stay on screen while the next walk flies rather
than blanking per keystroke.
- `file_tree_refresh_roots` returns early when the root set is unchanged.
It is called from render whenever the roots are empty, and it clears the
caches and notifies — so a tab that can produce no roots spun the
render loop.
Watcher events deliberately do *not* restart an open search. Doing so
starves it: the watcher's own debounce delivers a batch about as often as
the search debounce waits, so under sustained churn (a build writing into
`target/`, which the watcher reports because it knows nothing about
gitignore) every walk bowed out before reading a single directory and the
list stayed empty. A snapshot that is stale until the next keystroke is
the better failure.
`winproc::Proc` names the parent link `parent`, not `ppid` — the
Windows arm of `process_table` had never been compiled, so it took a CI
run to find it.
The branch had `gpui-component` pointed at a sibling checkout by absolute
path, which is why every CI job failed at manifest load. Point it back at
the fork's `tty7` branch (now carrying the custom-button label-color fix
the chrome tiles depend on) with the `tree-sitter-languages` feature, and
re-lock.
Review fixes on top:
- **Changes tab churned.** `right_panel_invalidate` dropped the cached
diff on every `GitStatusCache` notification — including unrelated
repos' — so the list blanked to "Loading…" and spawned a fresh
`git diff` several times a second while a pane produced output.
Replaced by `right_panel_refresh_changes`, which compares branch and
totals first and re-probes in place, mirroring the diff overlay.
- **Changes tab could wedge on "Loading…".** A probe dropped because the
cwd changed mid-flight left `diff_cwd` set and `diff` empty, and the
render path only spawns when the cwd *changes* — so nothing re-probed.
Spawn when nothing is cached and nothing is in flight.
- **Find references blocked the UI thread.** `cx.spawn_in` runs on the
main thread; the up-to-200 `read_to_string`s for the row previews now
run on the background executor, as the comment already claimed.
- **LSP frames could be lost or reordered at startup.** `send` checked
`ready` outside the `queued` lock, so a frame could park behind a
handshake that had just finished and never go out. `ready` now flips
under that lock in `mark_ready_and_flush`.
- `MarkScanner`'s ESC-in-payload branch bypassed the payload cap, so a
stream of bare ESCs inside an unterminated OSC grew the buffer without
bound.
- The file tree's search frontier used `Vec::remove(0)`; a wide tree made
that quadratic. `VecDeque`.
- `procs()` documented a pane check it didn't make; it takes the pane id
and makes it.
- Four doc comments had been orphaned onto newly inserted functions
(`pty`, `smooth_scroll`, `foreground_agent`, `file_expanded`).
Rework the detail panel's four tabs and the window chrome to read as a
deliberate, commercial-grade surface while keeping the terminal's calm.
- Chrome icons: filled-block panel toggles; Outline gets a list glyph,
Changes a git-branch, Info a redrawn mark; glyphs go to 18px on the full
foreground instead of the faint 15px secondary tone.
- Panel body: labelled Session / Processes / Ports bands, mono values,
pid/port pills, status dots on Outline, neutral M/U badges on Changes,
live counts in the headers, and roomier rows. Hue only ever lands on the
git add / remove / fail semantics, everything else stays neutral grey.
- Fixes: the corner "…" no longer jumps a pixel when the panel opens (the
top strip mirrors the TitleBar's hidden bottom border); that strip now
drags the window and double-click zooms, like the rail's; and the process
list stops flickering — the poll guard now spans the whole 2s cycle
instead of being restarted by every repaint between ticks.
The settings page's `×` sits at the window's top-right corner — the spot
the native window controls own, whose tiles are 34px. As a `small` icon
button it was 24px, which reads undersized standing there alone once the
overlay has covered the real title bar.
Give it the shape the title bar's own corner button already uses: 30px
square, a 15px glyph, `rounded_lg` (see the "⋯" in `tab_strip`). Matching
that beats the component's medium default (32px) — it is the size this
app already puts in this corner. `top` drops 6 → 5 so the taller button
still centres in the title bar's band.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The settings overlay covers the real title bar, so it lays its own drag
band across the top 40px -- absolute, full width, tagged
`WindowControlArea::Drag`. The theme panel docks to the window's top edge
beside it, which puts its header's `×` inside that band.
On Windows the band is `HTCAPTION`. gpui resolves the control area in
`Window::hit_test` by walking hitboxes top-down and stopping only at a
`HitboxBehavior::BlockMouse`; a plain `Button` isn't one, so the band's
hitbox stayed in `mouse_hit_test.ids`, the hit-test callback answered
`Drag`, and the OS took every press on the `×` as a window-drag. The
button's `on_click` never fired.
`occlude()` on the button ends the walk there, which is the same fix the
tab-strip chips carry and the one the page's own `×` has had since it was
written. Scoped to the button so the rest of the header still drags the
window. No-op on macOS and Linux.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The group header is drag-only -- it does nothing on click -- so it hovered
under `cursor_grab()`, an open hand that says "pick me up". gpui's Windows
backend has no mapping for `CursorStyle::OpenHand`: `load_cursor` matches
IBeam, Crosshair, PointingHand, the resize family and OperationNotAllowed,
then falls everything else through to `IDC_ARROW`. Win32 has no open-hand
system cursor to map it to either.
So on Windows the one affordance the header has read as "nothing to do
here", while the rows beside it (`cursor_pointer()` -> `IDC_HAND`) looked
interactive. Point there instead: not as apt as the open hand, but it is
the same cursor the rows use and it does say the header responds. macOS
and Linux keep the hand -- both backends implement OpenHand.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add a right-hand detail column showing what the active pane is, not what
it prints: session facts plus its process tree and listening ports
(daemon-side procinfo, pull-based via QueryProcs), the working-tree diff,
and the file tree. Tab row lives in the title bar, body in right_panel.
Also record OSC 133 command marks client-side so the panel's Outline can
list a pane's commands and scroll back to one, keyed on row text since
absolute scrollback indices drift once history fills.
In vertical tab-bar mode the sidebar is a full-height left column and
the real TitleBar only spans the right column, so the rail's
title-bar-height top strip was dead space — you couldn't grab the window
by it. Give it the title bar's behaviour: drag to move, double-click to
zoom, driven the same way TitleBar (and the settings overlay's stand-in
strip) does it, so a plain click and a double-click still land intact.
On Windows a bare `bash` resolves through PATH to
`C:\Windows\System32\bash.exe` — the WSL launcher, not a shell. With no
distro installed it exits non-zero with an empty stderr, which is
indistinguishable from "the shell rejected this script", so the checks
failed the Windows job while reporting nothing to explain why.
`is_msys_bash` guards the production path against the same trap; the test
had no such guard.
Nothing is lost by gating them to unix: these scripts are destined for a
remote POSIX host, so their syntax has nothing to do with the platform
running the test, and the macOS and Linux jobs already exercise them.
A remote pane passes no local cwd, and the argument-position branch answered
that by returning nothing at all. The reasoning in its comment only covered
filesystem paths — offering this machine's filenames for a remote command line
— but the code took `complete_signature` down with them, and a signature's
subcommands and flags are static text describing the *command*, not the
machine. `git push` is just as true over SSH.
The cost was not merely a missing menu. A position with no candidates hands
the line to the shell (`handoff_tab_to_shell`, #136), which clears the inline
editor for the rest of that prompt — so every `git <Tab>` in a remote pane
looked like the editor had crashed. Every git position measured as a handoff:
`git `, `git c`, `git checkout `, `git status`.
Generators stay disabled without a cwd, and that exclusion matters more than
the path one: a generator is a local `/bin/sh -c`, so `git checkout <Tab>`
would have offered the branches of whatever repo tty7's own cwd sat in. A
wrong filename fails loudly when it runs; a wrong branch name is plausible
enough to be accepted. Positions that are generator-only now yield nothing and
hand the Tab to the remote's own compsys, which can actually see that host.
Native-SSH panes reported no OSC 133, so the inline line editor, exit-code
marks and cwd tracking were all inert there — the daemon's OSC sniffer was
already wired up for them and simply never received anything.
Every existing integration configures a *local* process spawn (ZDOTDIR, a
bash --rcfile, fish's -C). An SSH channel offers no spawn to configure, only
the string an `exec` request carries, so the remote path recreates those same
files on the remote side and execs through them. The integration bodies are
reused verbatim rather than forked.
The bootstrap can't be shell-agnostic: sshd runs it as `$SHELL -c <string>`,
so a POSIX script is parsed by fish and a fish script by zsh. Rather than
contort one expression into parsing identically everywhere, spend a probe
round-trip (`echo __tty7_shell; echo $SHELL` — no substitution, assignment or
grouping, so it is valid in all of them) and then emit the dialect we know we
are talking to. The probe is memoized on the connection key, so extra tabs to
an open host cost nothing.
The probe's negative answer is load-bearing: a remote whose login shell is
unrecognized — or that isn't POSIX at all, where `$SHELL` echoes back
unexpanded — falls through to the plain shell request it always used.
Every arm ends by exec'ing the user's own shell, including the failure paths,
so a remote with a read-only $TMPDIR loses the integration and not the session.
zsh only gets ZDOTDIR pointed at the throwaway dir once all four redirectors
are confirmed written; a half-populated dir would silently cost the user their
dotfiles. The dir removes itself on the first precmd, by which point every
startup file has been read.
Add a per-profile switch, on by default and defaulting to on for profiles
saved before it existed, for remotes we *can* integrate but shouldn't.
Reordering used to be a swap on release: gpui's floating drag card followed
the cursor and `on_drop` moved the tab to whichever slot it landed on, with
the list itself frozen for the whole drag. Replace it with a reorder the list
performs live, and add repo group blocks as a second draggable surface.
The new `ui::reorder` module owns the geometry. A drag freezes every slot's
measured bounds and the grab point; each frame the surface reads the pointer,
asks which slot the held item now belongs in, and renders the list in that
order. The held item stays in the list (dimmed, painted over its neighbours)
and tracks the cursor pixel for pixel; the items it displaces slide 140ms.
Slot selection uses half-overlap — the held item's trailing edge past a
neighbour's centre going forward, its leading edge going back — so a tall
group block and a short one swap symmetrically.
Commit no longer goes through `on_drop`, which only fires when the pointer is
over that element at release: every frame the surface records the whole-tab
permutation a release would produce, and the root applies it when the drag
ends, wherever the cursor is. `apply_tab_order` becomes the single commit
path, replacing `move_tab`/`move_group`; it also lays every group out
contiguously, which fixes group-order corruption when a group's tabs were
non-contiguous in the tab vector.
The counts a probe produces are repo-wide — `git diff --numstat HEAD`
ignores the subdirectory it ran in — so panes at `repo/`, `repo/src` and
`repo/docs` were three ways of asking one question, and a window
activation spent one full-repo diff on each.
Count the throttle against the work-tree root once a probe has resolved
one for the cwd, and stamp the clock when the probe is *claimed* rather
than when it lands: without that, panes claiming in the same instant all
pass a throttle nothing has answered yet, which is exactly the shape a
window activation has. In-flight dedup stays keyed by cwd, since it
brackets a specific spawn that finish_probe has to release.
The release workflow is a plain checkout of the tag — nothing rewrites
Cargo.toml there, so the lockfile guard the CI build just gained applies
just as well, and a release is the build you least want silently
re-resolving dependencies. Only nightly stays unlocked: it stamps
Cargo.toml's version, which makes the lock's own root entry stale by
design.
Two lockfile-only dependabot bumps (#139, #140) raised resvg to 0.47.0 and
sha2 to 0.11.0 in Cargo.lock without touching Cargo.toml, which asks for
`resvg = "0.45"` and `sha2 = "0.10"`. Under cargo's 0.x rules the minor
version is the major, so neither requirement accepts the locked version and
the lockfile has been self-contradictory ever since:
$ cargo metadata --locked
error: cannot update the lock file ... because --locked was passed
Nothing failed loudly — CI never passed `--locked` — so the cost landed on
contributors instead: every local cargo invocation rewrote the lock, leaving
a permanently dirty working tree to discard before each commit.
Resyncing drops the duplicates too. gpui-component already pulls resvg
0.45.1, so the tree no longer builds two copies each of resvg, usvg,
tiny-skia, tiny-skia-path, kurbo, svgtypes, roxmltree, imagesize and
polycool.
CI now builds and tests with `--locked` so the next such drift fails in the
PR rather than in a working tree. The release and nightly workflows keep
their unlocked builds on purpose: both stamp Cargo.toml's version and depend
on cargo refreshing the lock's root entry.
The sidebar's `+N -N` only refreshed on three rare edges: the pane changing
directory, a command ending, and an agent turn ending. Edits made anywhere
else produced no signal at all, so the counts sat stale — a long agent turn
showed nothing until it finished minutes later, and a file edited in another
editor never registered until the user happened to run a command in the pane.
Two new triggers close the gap:
- Window activation re-probes every pane. Coming back to the window is the
only cue we get that the tree moved while the user was elsewhere, and the
sidebar lists every tab, so refreshing just the focused pane isn't enough.
- An agent's tool completions re-probe mid-turn. `AgentSessionState` gains an
`activity` counter because `ToolComplete` is deliberately a status no-op
during normal work, leaving status-watchers unable to see it.
Both go through a new throttled claim on `GitStatusCache` that drops triggers
instead of queueing them, so a busy agent or a window full of panes collapses
into one shell-out per repo per 1.5s rather than a `git` storm.
Also: fold the probe's two `rev-parse` calls into one (it now asks for
toplevel, git-dir and common-dir together), which makes `repo_home` a pure
function and unit-testable; and land probe results in the shared cache
independently of the pane entity, so a pane closed mid-probe can't wedge the
cwd-keyed in-flight claim for every other pane in that directory.
Closing the window with zero tabs took the early-return path in
on_window_should_close, which skipped the cx.quit() the confirmed path
runs. gpui does not quit on last-window-close and no on_reopen handler is
registered, so the process stayed alive with no window and clicking the
Dock icon did nothing (#147). Defer the quit onto the next tick so the
close completes first, matching the confirmed path.
Three fixes for tty7's Tab completion:
- Tab is no longer swallowed when the engine has no candidates: the
locally edited line is handed off to the shell (text shipped raw,
cursor walked back, Tab sent) and the local editor suspends until the
next prompt cycle, so shell-native completion (compsys, fzf-tab, ...)
answers instead. The handoff release keys off a new entered-prompt
cycle counter rather than the raw Prompt-frame seq, so same-prompt
redraws (PS1-embedded 133;B re-emissions) cannot re-engage the editor
while zle still holds the handed-off text.
- cd/pushd/popd/rmdir complete directories only in the no-signature
path fallback; Fig 'folders' templates narrow signature slots the
same way. Symlinks now classify by their target.
- New tab_completion config field (default true) plus a Settings ->
Terminal -> Keyboard toggle; when off every Tab goes to the shell.
The sidebar row kept a permanent in-flow slot for the hover-only close
button, so titles and branch names truncated while an empty column sat
at the rail's right edge. Move the close affordance out of flow, same
Safari-style float the strip's chips already use: on hover the x sits
over the title line's right end on a solid backing (the row's hover
fill, flattened against the sidebar surface) with a short gradient
run-in, so covered text fades out instead of hard-cutting.
Pinned to the row top rather than vertically centered: on a two-line
row a centered x would straddle both lines and cover the branch line's
+n/-n counts, which are the diff-overlay click target. The cmd-N hint
badge keeps its in-flow slot (deliberate all-rows modal reflow).
Resume-after-restart replayed a hardcoded per-agent command
(claude --resume <id>), dropping whatever flags the agent was
originally launched with (--dangerously-skip-permissions, --model).
The daemon's foreground poll already reads the agent's argv for
detection; keep it, stream it to the client inside AgentSessionState
(serde-default, wire-compatible both ways), persist it in the session
Leaf, and splice a conservatively-gated flag tail into the resume
command. The gate refuses anything that is not a plain flag-shaped
token sequence and falls back to the bare table command.
The Windows 133;C typed-command capture is forgeable by terminal
output, so it contributes identity only, never flags. Copilot gains a
resume entry (copilot --resume <id>, hooks already report its session
id) and Amp's threads continue verified to accept global flags.