Commit Graph
1570 Commits
Author SHA1 Message Date
Adam HitchcockandClaude Opus 5.5 b65a3e4efc test(git): pin status.showUntrackedFiles in the tests' scratch repositories (#1091)
Five tty7-core tests and two tty7-server conformance checks failed on a
machine with a global `status.showUntrackedFiles=no`: git hid the files
they had just written. PINS (and so pin_repo_config) now carries
`status.showUntrackedFiles=normal`, the worktree tests' temp_repo pins
its repository, and the host conformance suite's git_repo sets the key
itself, since other crates run it.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-04 16:12:16 +08:00
l0ng-ai e60bf9f12c fix(mobile): resolve relays behind DNS that sets an EDNS Z flag (#1092)
simple-dns 0.12.0 reads the EDNS OPT record's TTL at the wrong offsets: it
takes the extended RCODE from the low byte, where RFC 6891 puts the DO/Z
flags. A resolver that sets a Z bit -- a Clash-style fake-IP DNS on the
router does -- turns every NOERROR answer into RCODE 16, so iroh resolves
nothing. The gateway never reaches a relay, pairing codes carry none, and
a phone off the LAN cannot connect ("It didn't answer").

Vendor simple-dns 0.12.0 with the offsets fixed and patch it in for both
the desktop and the mobile workspace. tests/edns_z_flag.rs drives iroh's
resolver against a nameserver that sets the flag, from the root package so
CI's default `cargo test` runs it and fails if the patch stops applying.
2026-10-04 16:10:36 +08:00
l0ng-ai 54978409c2 chore(mobile): 0.1.4 (#1088) mobile-v0.1.4 2026-10-04 08:27:41 +08:00
l0ng-ai c5fe474125 fix(mobile): typing into a pane shows its cursor and what is being composed (#1084)
Tapping the terminal to type into it showed no cursor: xterm reports its
cursor as shown and in place, but leaves it undrawn on the phone. And an
input method's composing text — pinyin before a candidate is picked,
dictation before it is done — lived only in the hidden field typing goes
through, so nothing showed until it was committed, often only on Return.

While the pane has the keys, the app draws the cursor itself, a blinking
block at the pane's cursor cell, with the composing text underlined in
front of it. A program that hides the terminal's cursor to draw its own
(an agent's input box) gets only the composing text, where it lands.
2026-10-04 08:27:08 +08:00
d3f7dadd5d feat(agents): Muse Code and jcode support, native hooks for Empryo, Muse Code and jcode (#1071)
* feat(agents): recognise Muse Code and jcode

Muse Code's `muse` launcher execs a versioned `muse-bin-<version>`
binary, so detection also maps that name to Muse. Muse resumes with
`muse resume <id>` (root options on either side of the subcommand);
jcode with `jcode --resume <id>`.

* feat(agents): install native Empryo and jcode hooks

* feat(agents): add jcode lifecycle hooks

* fix(agents): preserve jcode hooks and correct Empryo removal contract

* feat(agents): install Muse native plugin hooks

* docs(agents): list Empryo, Muse Code and jcode as hook-backed

* fix(i18n): translate Empryo, Muse Code and jcode search keywords

* fix(agents): read jcode hook payload from env, route its reports like Codex, bound muse CLI calls

jcode runs hooks with stdin closed and puts session_id/cwd in
JCODE_HOOK_PAYLOAD, so reports carried no session and resume never
learned an id. Its shared server also runs every session's hooks with
the first client's TTY7_PANE, so reports go through the same
session/directory routing as Codex. muse plugins calls now time out
after 30s and surface stderr. Adds ru strings for the new keys and
reattaches Kimi's doc comment to KIMI_HOOK_EVENTS.

* docs: count Muse Code and jcode in the README agent totals

---------

Co-authored-by: kalpakprod <307643502+kalpakprod@users.noreply.github.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-03 20:47:25 +08:00
l0ng-ai 73cd393590 docs(readme): back to the minimal keyword layout
Revert the prose-first structure from #1046 to the earlier feature list
and keyword table, keeping its two factual fixes: shells survive quitting
the app (after a reboot the layout, screen, and supported agent
conversations come back), and the agent matrix has a past-sessions column.
2026-10-03 20:43:10 +08:00
l0ng-ai 162a8e971a chore(mobile): 0.1.3 (#1083) mobile-v0.1.3 2026-10-03 20:37:36 +08:00
85b739650c feat(terminal): an OSC 8 link rests under a faint dotted underline (#1078)
* feat(terminal): an OSC 8 link rests under a faint dotted underline

A hyperlink a program emits (OSC 8, which panes ask for via
FORCE_HYPERLINK) looked like plain text until the pointer found it.
It now carries iTerm2's faint dotted underline, drawn by the SGR 4:4
dotted painter, and swaps to the hovered link's solid line under the
pointer. A cell the program underlined or gave an underline colour
keeps its own.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): an OSC 8 link's dots stay faint under the block cursor

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-03 20:36:45 +08:00
02620cfa48 feat(ui): add ru-RU locale with CLDR few/many plurals (#1072)
* feat(ui): add ru-RU locale with CLDR few/many plurals

Russian joins English, Simplified Chinese and Japanese.

- `gui_language` accepts `ru-RU`; the picker shows the endonym «Русский»
  in every locale, as for 简体中文 and 日本語.
- `PluralCategory` gains `few` and `many`, chosen by the CLDR rule for
  the active locale (1 файл, 2 файла, 5 файлов, 11 файлов, 21 файл).
  en, zh and ja never select them, so their output is unchanged.
- `ru.rs` translates every key and every plural form; the exhaustiveness
  test now covers ru as well.
- Style follows Russian VS Code / Windows: infinitive verbs on buttons
  and menu items, imperative in hints, Git terms as in VS Code ru.

Claude-Session: https://claude.ai/code/session_01NnVhn11H75iA699hvPsiH3

* docs(config): list ru-RU among gui_language values

---------

Co-authored-by: kalpakprod <307643502+kalpakprod@users.noreply.github.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-03 20:36:31 +08:00
l0ng-ai 24c479c636 feat(mobile): close a pane; scroll full-screen programs; fix pinyin in the pane (#1065)
* fix(mobile): a swipe scrolls a full-screen program

A swipe over the terminal scrolled xterm's scrollback, and the alternate
screen keeps none, so over Claude Code's full-screen view, less or vim
it did nothing. On the alternate screen a swipe now turns the mouse
wheel instead, a notch a row, as on the desktop: a wheel report at the
finger for a program that asked for the mouse (SGR or the legacy
encoding, whichever it chose), arrow keys for one that did not.

* fix(mobile): pinyin keeps going when typing straight into the pane

Typing on the terminal itself goes through a hidden field, which was
emptied after every committed piece of text. iOS keeps its own copy of
the field's text, and a field cleared under it left the input method
stuck after the first character a pinyin composition committed. The
field now keeps its text while it has the keys and the pane is sent
what changed since the last send: characters taken off as DEL, then
what is new. It is emptied on blur.

While the field has the keys the pane's cursor is drawn solid, so a tap
on the terminal shows that it is ready to type into.

* feat(mobile): close a pane from the phone

The app could watch and drive a pane but never close one. Hold a pane's
row in the list, or pick Close pane from the terminal's menu: a sheet
says what will be stopped and on which machine, and only its danger
button closes it. From the terminal the app goes back to the list, which
drops the pane when the next tree arrives.

On the wire this is a new one-shot Open::ClosePane { pane_id, machine },
answered Ok or Denied. The gateway does what `tty7 pane close` does:
finds the workspace holding the pane, sends PaneClose, and hangs up the
panes it reports removed, on the gateway's machine or through the
desktop's existing link to a remote one. A gateway that predates the
variant drops the stream, which the app reports as "too old to close
panes from the phone".
2026-10-03 20:36:25 +08:00
528bd12c86 fix(panel): light the side panel's current tab; clicking it no longer closes the panel (#1079)
* fix(panel): light the side panel's current tab; clicking it no longer closes the panel

The current tab differed from the others only in ink and weight, which read
as no selection at all; it now sits on a pill. Clicking it used to put the
panel away, so a stray click on the tab you were on hid the panel. ⌘J and
the title-bar panel tile still do.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(panel): spell the hide shortcut as a key, like the line above it

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-03 20:35:43 +08:00
l0ng-ai aadd80d4ae fix(macos): timestamp whenever notarizing; always scrub the ASC key, written 0600 (#1082)
A login-keychain identity with notary credentials signed without a secure timestamp, which notarization rejects. The ASC key's cleanup trap was only set when a certificate was imported, so a local build left the key behind in /tmp, world-readable. TTY7_BUNDLE_ONLY=0 now means off, like TTY7_PACKAGE_UPDATE_ZIP.
2026-10-03 20:31:52 +08:00
Adam HitchcockandClaude Opus 5.5 5be29e5cf2 test(scrollback): the sweep test sweeps a directory of its own (#1077)
saving_twice_replaces_rather_than_appends flaked in CI: every on-disk
scrollback test shares one pinned config dir, and the sweep test's
sweep() deleted every snapshot but its own, including one another test
had just saved and was about to load. sweep() now delegates to
sweep_in(dir, keep), as history.rs's does, and the test sweeps a temp dir
of its own. Looping the module's tests 300 times: 11 failures before, 0
after.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-03 20:31:23 +08:00
Adam HitchcockandClaude Opus 5.5 3602daff5b build(macos): bundle name, id and paths overridable; notarize with an App Store Connect key (#1067)
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-03 20:31:18 +08:00
Adam HitchcockandClaude Opus 5.5 dd4bd806c6 fix(github): a multibyte char after < no longer panics the markdown sanitizer (#1076)
`starts_with_tag` sliced `rest[..name.len()]` by bytes, so an issue or
PR body with `<` followed by a multibyte char (e.g. `<日本`) panicked the
GitHub panel's render and quit the app. It now uses `str::get`, so a
non-boundary is just "not a tag". A regression test fails on the old
code and passes now.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-03 20:29:57 +08:00
l0ng-ai 3990a05795 Mobile: an iOS pass from a user's seat (#1075)
* fix(mobile): draw a prompt's icons

Prompts built with Powerline and Nerd Font glyphs (branch, folder, git
status) showed as empty boxes: a phone has no such font to fall back on.
Ship the symbols-only Nerd Font, one cell wide, behind Hack.

* fix(gateway): send a phone the screen the desktop shows

A phone opening a pane was sent its raw output, ring segment by segment,
and read it with xterm.js. Across the pane's resizes that emulator wraps
and reflows unlike the desktop's, so shells' SIGWINCH redraws landed on
the wrong rows: prompts twice, old output under new prompts. Leaving a
full-screen program left stale lines behind the same way.

The gateway now reads the pane with the desktop's emulator and, on
opening, after a resize, and when the main screen comes back, sends the
phone that screen drawn afresh: scrollback, colours, cursor and modes.
Output in between still goes straight through.

* fix(mobile): the message box rides the keyboard on iOS

On iOS 26 the WebView, run edge to edge, does not say how much the
keyboard covers, so the message box and the dock stayed under it. The
app now hears the keyboard's frame natively and lays out above its top
edge, on iOS as on Android.

- WebKit's previous/next/Done bar over the keyboard is gone; a tap on
  nothing in particular, or on the pane, puts the keyboard away.
- Return sends however the keyboard delivers it.
- A shell's message box no longer capitalises or corrects: ls stays ls.
  An agent's keeps both, as a chat would.

* fix(gateway): a tab opened from the phone joins its repository's group

The desktop files a tab under its repository as its sidebar draws it, so
a tab opened from the phone while that window was out of sight stayed in
Ungrouped. The gateway now reads, for a tab the desktop has not filed,
which repository its directory is in, the way the desktop would.

* feat(mobile): close a tab from the phone

Swipe a tab's row left for Close, or use Close tab in a pane's menu. The
tab goes where the desktop puts a closed tab, onto the workspace's
recently-closed list, so tty7 on the computer can reopen it. A tab whose
agent is at work asks first.

A new CloseTab stream carries it; a machine that keeps no closed tabs
closes it for good and its panes are ended, as tty7 tab close does.

* feat(mobile): a machine's list reads at a glance, and the app opens where it was left

- The app reopens the machine it was last on; leaving for the list of
  machines is what makes it start there.
- A tab named after its directory goes by the directory's own name, its
  parent underneath, rather than a path cut off at the end that matters.
  An agent's row says where it works too.
- New tab asks which folder, from those the workspace has tabs in, the
  tab in front first; Workspace is asked only when there is a choice.
- The back button names where it goes in full until the title folds in.
- Search fields have a clear button; a few machines need no search.
- Rows swipe left to close their tab, and a pane's menu has Close tab.

* fix(mobile): agents' marks draw, and Return sends a sentence

- Claude Code's ⏺ and ⎿, ⏵⏵, ⚙, ⏰, ✔, braille spinners and the like
  showed as empty boxes: the phone's fonts do not reach a canvas for
  them. Noto's symbols and outline emoji ship, cut down to those blocks
  (about 80 KB), behind Hack and the prompt icons.
- The phone's keyboard reports Shift with Return whenever it has armed
  a capital — at the start, after a full stop — so a message ending in a
  sentence got a new line instead of being sent. Shift-Return starts a
  line only on a keyboard with a real Shift; Return delivered as typed
  text sends as well.

* fix(mobile): an agent's choices become buttons wherever they are on screen

The answers were looked for in the bottom 24 rows of the terminal, which
can be taller than the pane: Claude Code's question sat higher up and no
buttons came. The whole screen is read now.

* fix(mobile): a pane on its side keeps room for the pane

In landscape the bar, the key row, the page dots and the message box
left three lines of terminal. The bar slims and the keys and the message
box share a row, for eight. A message box's hint stays on one line, and
a row's hidden Close names its tab to VoiceOver.

* fix(mobile): Settings names the ⋯ menu with its own mark, and asks before clearing history

The phone's text font has no ⋯, so the note showed an empty box; the
menu button's icon stands in. Clearing the message history, which cannot
be undone, now asks first.

* fix(mobile): Changes shows the changed files, not just the untracked ones

The files' blocks shrank to nothing under a long list of untracked ones:
flex items that clip their overflow give up their height. They keep it
now, and the sheet scrolls. The untracked list sits flush and compact,
the top line totals the change, and lock files start folded.

* feat(mobile): pull a sheet down to put it away

Sheets showed a grabber but only closed from their × or the dimmed screen
around them. Pulled down — from the top, or from anywhere while their
content is scrolled to the start — they go; let go short of the way,
they settle back.

* fix(mobile): a machine that went away says so within seconds

The connection kept QUIC's default 30-second idle timeout, so a laptop
gone to sleep stayed "Direct · 1 ms" on the phone for half a minute, and
typing into it went nowhere without a word. The phone now gives up on a
silent machine after 12 seconds, a few keep-alives missed, says it
cannot reach it, and reconnects on its own once it is back.

* feat(mobile): keys and answers are felt

The key row, an agent's answer buttons and Send give the light tap the
phone's own keyboard does, and a row swiped far enough to open ticks as
it passes the point. Through the Tauri haptics plugin; nothing is felt
where there is no engine for it.

* feat(mobile): pair by pointing the phone's camera at the desktop's code

The pairing QR code reads tty7pair:…, and the app now answers to that
scheme: the phone's own Camera offers to open it in tty7, which pairs
straight away, as its Scan button does. No hunting for the button first.

* fix(settings): the pairing code can be read by the phone's camera

The phone app now opens from its tty7pair: link, so Show code says to
point the phone's camera at it first.

* fix(mobile): Android opens tty7pair: links too

The deep-link plugin's intent filter, written into the manifest by the
Android build.

* fix(mobile): pairing links without the deep-link plugin, cold launches included

The deep-link plugin's build script rewrites the iOS entitlements while
Xcode builds, which Xcode refuses ("modified during the build"), and a
link that launched the app was lost on the way in any case: UIKit hands
it to the first scene as it connects, and the event loop only passes on
links that come later.

- The tty7pair scheme is declared in Info.ios.plist and the Android
  manifest, and links are heard as Tauri's own Opened event.
- The scene delegate's connect is wrapped, before UIKit starts, to keep
  a launching link; the page asks for it once it listens, so neither
  order of arrival loses it.

* feat(mobile): another agent waiting or done says so over the pane you are in

Inside one pane, nothing told you another agent on the machine had
stopped for an answer or finished its turn; you had to back out and
look. The pane now watches the machine's tree too, and such a change
drops a card over the top of the pane, felt as it comes — the agent,
what it says or which tab — that opens that pane when tapped. What was
already so when the pane opened is not news.

* fix(mobile): with the lock on, the app switcher shows no panes

The phone keeps a picture of an app as it leaves, for its app switcher.
With the lock on, that picture showed whatever pane was open. The app is
now covered as it goes, and uncovered — or locked — as it comes back.

* fix(mobile): turning the lock off takes Face ID too

Anyone holding the phone, unlocked, could switch the app lock off from
Settings. Off now asks for Face ID or the passcode, as on does.

* fix(mobile): a pane that is not running says so, with a way on

After the machine's server restarted, panes no window had opened since
were gone, and the phone tried to watch them forever: "Daemon refused
Observe: no such pane 9. Reconnecting…". The gateway now marks panes
its server is not running; the list shows them as Not running, without
their last agent status, and opening one says what is going on and
offers a new tab in the same folder.

* feat(mobile): a workspace not on screen shows when an agent in it needs you

The switcher's chip for another workspace carries the status dot a
folded group does, so an agent waiting there is not hidden behind the
one you are looking at.

* fix(mobile): a new tab's agent starts, instead of waiting at the prompt

Opening a tab for Claude Code or Codex typed the command as soon as the
pane was live, while the shell was still printing its greeting; the
Enter was eaten and the command sat at the prompt unrun. It is typed once
the shell's output has gone quiet now, or after six seconds whatever.

Rows also say where a tab is the same way whatever it is named.

* fix(mobile): the first screen says how to pair in one step

With no machine paired yet, it now says where the code is on the
computer and that the phone's camera reads it.

* fix(mobile): a tap that closes a pane's menu does only that

Closing the ⋯ menu by tapping the pane also brought the keyboard up for
typing into it. The tap that puts a menu away is the menu's now.

* fix(mobile): second pass from a phone user's seat

- Chinese, Japanese and Korean text rendered as boxes in the terminal:
  the glyph atlas does not fall back past the web fonts, so the system's
  CJK fonts are named in the stack.
- A tab opened from the phone was drawn at the desktop's width first and
  then squeezed: the gateway now holds it at the phone's size from before
  the desktop hears of it, until the phone's own view takes over.
- A tab opened with no folder started wherever the server did; it starts
  at home, and the new-tab sheet offers Home.
- Going back to a machine showed a skeleton every time; its last tree is
  drawn at once and refreshed when the watch reports.
- Errors said the transport's chain, repeated: each part is said once, and
  an unreachable machine is explained in words.
- Wide panes say once that they can run at the phone's size; a pane taken
  over is taken over again on return.
- Back in a pane's history, a button jumps to the latest output.
- Find hides the key bar and message box and keeps the match clear of the
  bar; Copy keeps the pane's lines and offers Copy all.
- The message box pans a wide pane back to the cursor; Changes outside a
  repository says so plainly; machine rows count waiting agents; the back
  pill folds to a chevron with the title; filled reds use the system red.

* feat(mobile): attachments wait as chips beside the message box

A sent file used to drop its full temporary path into the box, five lines
of /var/folders/... underlined by the spell checker. It now waits as a
chip with its picture and name, can be taken back before sending, and its
path goes after the message when it is sent.

* fix(mobile): pairing says what went wrong, and leaves the code alone

The code field offered word suggestions over the keyboard; it is a code.
A wrong, expired or unreachable code is explained with what to do next
rather than the gateway's lower-case reason.

* feat(mobile): hold a tab's row for what can be done with it

A long press used to open the pane like a tap. It now brings up the
row's actions: open, open at the phone's size, Changes, a new tab in the
same folder, copy the folder's path, and close.

* fix(mobile): a pane on its way shows that it is coming

Opening a pane over a slow link left an empty screen until its replay
arrived. After a quarter second without it, three dots say it is coming.

* fix(mobile): agent menus, stopped panes and new tabs, as used

- An agent's arrow-key menu with no numbers (Claude Code's 'trust this
  folder?') now gets answer buttons too; picking one moves to it and
  presses Enter.
- A pane that is not running greys out its keys and message box instead
  of taking typing that goes nowhere.
- Suggestions match where a word starts, so 'ls' no longer offers every
  message that mentions tools.
- A new tab's starting size counted neither the status bar nor the home
  indicator, so its last rows sat under the key bar.
- A tab opened on the phone keeps the phone's size on later visits, so it
  follows the keyboard instead of hiding behind it.

* fix(mobile): another agent waiting is not missed, and dismissing is only that

- The card for another agent that needs you stays until it is answered or
  put away (it went after 15 seconds); a finished one still goes on its
  own. While any other agent waits, the back button carries a dot.
- The card's dismiss, a banner's action and Jump to latest took themselves
  away under the finger, and the same tap then reached the pane and
  brought up its keyboard; a clear cover takes that tap now.
- A row's Current tag no longer gets cut to 'C...' by a long name.

* fix(mobile): Changes lists a new folder once, by name

The untracked list walked into every new directory — a generated folder
filled the sheet with thirty truncated paths. New directories come as one
entry, as git status shows them, and each entry reads as a name with the
end of its folder beside it.

* fix(mobile): bar buttons answer a 44pt square

Back, More, Close and the pane's round buttons are drawn at 38pt and took
taps only there, under the 44pt a finger is owed. Each now answers a 44pt
square around the same drawing.
2026-10-03 20:28:29 +08:00
l0ng-ai 99b9327fab feat(mobile): the desktop sidebar's groups, and the tab it has in front (#1073)
* feat(mobile): the desktop sidebar's groups, and the tab it has in front

A machine's tabs on the phone were one flat list per workspace. They now come in the desktop's groups, in its order: pinned groups, then one per repository or SSH host, then Ungrouped, each folding as on the desktop. The tab the desktop has in front reads Current.

The gateway places each tab as the sidebar does, from what the machine tree already keeps: a tab's pinned group, or else the repo the desktop last filed it under. The naming rules moved from the sidebar into tty7-core so both name groups alike. An older gateway sends no groups and the phone shows one list, as before.

* fix(mobile): group headers lead, and folded ones stack close

A group's header read the same as the workspace label above it, and a folded one kept the gap meant for rows under it, so folded groups sat far apart. Headers are now the darker, larger line at a tap target's height; only an open group keeps room after its rows.
2026-10-03 20:27:02 +08:00
l0ng-ai e38f450d1e feat(terminal): a message composer that covers agent CLIs' own input (#1066)
* feat(terminal): dock a message composer under agent panes

A multi-line text box docked at the bottom of a pane whose foreground is a
coding agent, for writing a prompt with the platform's own editing keys, mouse
selection and an in-place IME, then handing it over whole. Toggle with
Cmd+I (Ctrl+Shift+I off macOS) or "Toggle Message Composer" in the palette.

- Docks below the grid instead of floating over it, so the agent reflows into
  the remaining rows and nothing it draws is hidden.
- Enter sends, Shift+Enter inserts a newline, Esc hands focus back to the
  terminal without closing (so the next Esc still interrupts the agent).
- A message is written as text, then Enter as a separate write after a short
  settle. Multi-line text goes as one bracketed paste; Codex is always pasted
  (its burst detector swallows the Enter otherwise); a leading `!` reaches
  Claude Code as its own key so it switches to shell mode.
- Nothing is sent while the agent is waiting on a permission prompt or
  question; the box turns amber and keeps the message.
- Writes queue per pane and stop if the agent exits mid-send, so an Enter can
  never land in the shell.
- Pasted screenshots, copied files and dropped files reuse the terminal's
  existing path-pasting routes and land in the box when it has focus.
- Drafts and the open state survive the view being rebuilt.

Refs #842

* feat(terminal): give the composer a chat-box layout with attachments and / @ menus

- A rounded, tinted frame whose hairline darkens on focus and on a file drag,
  a toolbar row with an attach button and a round send button that fills in
  once there is something to send. The key hints move into the send button's
  tooltip; the placeholder names the agent and what / and @ do.
- Files become chips instead of words in the text: the attach button, a drop
  on the box, a pasted screenshot or copied file, and remote uploads all go
  through one paste_paths route that attaches while the box has focus.
  Backspace at the start of an empty caret removes the last chip. On send the
  paths follow the text as the shell words a drop would have typed.
- `/` at the start of the message opens the agent's built-in commands (Claude
  Code, Codex, Gemini) plus Claude's custom commands from .claude/commands;
  `@` at the start of any word opens files from the pane's project, reusing
  the quick-open walk so it works on remote hosts too, spelled relative to the
  pane's directory. Up/Down move, Enter/Tab pick, Esc dismisses.
- Shift+Tab is passed through to the agent to cycle its permission mode.
- Enter with nothing to send no longer sends a bare Enter.

No model picker, mode label or context meter: tty7 has no source for them
that would stay true, and /model is one keystroke away in the menu.

* feat(terminal): lay the composer over the agent's own input, with its toolbar

The composer now stands in for the agent's input instead of sitting under
it, so the pane has one input rather than two.

- For Claude Code, Codex and Gemini the box is laid over the input area it
  finds on the grid (Claude's ruled prompt block and the status rows under it,
  Codex's `›` line, Gemini's framed prompt), painted in the grid's background.
  When the agent puts something else there — a permission prompt, a picker —
  the area stops reading as an input; after a 250ms grace the box steps aside
  and the keyboard goes to the TUI, and both come back with the input. Other
  agents keep the docked layout.
- Over the input, Esc is the agent's (it interrupts), Ctrl+C clears the box or
  reaches the agent when the box is empty, and text typed at the grid lands in
  the box.
- The toolbar: permission mode (read off the status row the box covers, falling
  back to the hooks' permission_mode; click or Shift+Tab to cycle), model
  (click opens Claude's picker), Think (Claude's thinking toggle), and a context
  ring. Labels come only from what the agent reported.
- Claude hooks now carry an AgentReadout — permission_mode from the hook
  payload, the model and context size of the last main-thread reply from the
  transcript, the context window (1M for a [1m] model or past 200k), and
  alwaysThinkingEnabled — worked out in the hook so remote panes get it too.
- Visual pass against the design: 13.5px text with the design's padding
  (the input's own padding subtracted), a 40px toolbar of 28px buttons, a dark
  round send button, image chips with their own glyph.

* feat(terminal): replace the composer's Think toggle with an effort picker

The toolbar's thinking toggle is gone; reasoning effort is what the
agent actually exposes as a per-session dial. The button shows the level
Claude Code is set to (CLAUDE_CODE_EFFORT_LEVEL, else effortLevel from its
settings, reported by the hook) and opens a menu of low / medium / high /
xhigh / max. Picking one sends the agent's own /effort command, and the
label follows the pick until the next hook event confirms it.

* feat(terminal): open the composer's model and effort lists over their buttons, and seat the box where the agent's input starts

* style(terminal): align the composer with the design: bottom inset, hairline ring, effort label

* style(ui): draw the sidebar dividers as one-device-pixel hairlines

* fix(terminal): keep the composer's contents still when its ring thickens

* fix(terminal): let a click outside the composer keep the keyboard

* fix(terminal): a click beside the covering composer leaves it, as one on the grid does

* fix(terminal): paint the composer's lists over its ring, and give Effort its chevron

* fix(terminal): show the effort level alone, close toolbar lists on an outside click, read per-model effort

* fix(core): take the effort level Claude reports in the hook payload

* feat(core): send a Claude turn's context size once its transcript catches up

* Revert "feat(core): send a Claude turn's context size once its transcript catches up"

This reverts commit 3544bc6b172901977749c6d6041650ae3795be37.

* refactor(terminal): drop the composer's context gauge until there is an exact source for it

* fix(terminal): a paste at the grid goes into the composer covering the input

With the box laid over the agent's input, typing at the grid already went
into the box, but a paste (Cmd+V, a dropped or copied file) still went to
the pty — into the agent's own input, out of sight under the box, where the
next Enter would send it unseen. A paste now lands in the box the way
typing does, files as attachments, and takes the keyboard with it.

* fix(terminal): cover the agent's input from its top rule at any pane height

The covering layer measured its height up from the pane's bottom edge in
whole rows plus the padding, but the grid's rows start at the top: whatever
part of a row the pane's height leaves over sits between the last row and
the padding. At most heights that left the top of the covered area — Claude
Code's upper rule — showing above the box. The grid now records that
leftover and the layer counts it in.

* fix(core): report Claude's model and effort only when they are this turn's

The hook filled in the model from the transcript's last reply on every
event. That reply is the previous turn's: after a `/model`, or a resume
under another `--model` (a resumed session's SessionStart names none), the
toolbar showed the old model — and at `Stop` too, since Claude Code runs
the hook before the turn's reply is always on disk. The model now comes
from SessionStart, or at Stop from the reply that turn wrote: found after
the prompt the payload names, matching the words it carries, waited for
briefly. Nothing exact means nothing reported.

Effort likewise: the settings fallback only runs for a model the event
names (it may be set per model), and a turn that ends without a level ran
on a model that takes none, which the toolbar now shows as no level rather
than the settings' general one. A level picked from the toolbar gives way
to the agent's report once that changes, as a picked model does.

* fix(terminal): offer Fable in the composer's model list

Claude Code's `/model` list has Fable between Opus and Sonnet, and
`/model fable` takes it by that alias, but the toolbar's list left it out:
it could not be picked there, and a session running it had no row checked.

* fix(terminal): a toolbar pick holds only until the agent's next finished turn

A model or effort picked from the toolbar was shown until the agent
reported a different value. When the pick did not take — Claude asks
before switching a cached conversation's model, and "No, go back" keeps
the old one — the report never changed and the toolbar showed the refused
model for good; after the agent quit and a new session started on the
model the pick was made from, the stale pick came back.

A pick now stands until the next finished turn, which reports what the
agent actually ran on, and is dropped when the agent session changes.

* fix(core): keep agent hook sequences short

A hook reports to the pane by writing an OSC 777 sequence to the tty the
agent draws on. macOS does not keep a tty write whole: under output
pressure the kernel parks the writer mid-sequence and lets the other
writer in, so the agent's redraw lands inside our sequence, the OSC
breaks, and the rest of the JSON is printed on screen. The longer the
sequence, the likelier that is.

The prompt a turn starts with was the bulk of it on `prompt-submit` (up
to 200 characters, three bytes each for CJK), and nothing reads it any
more since the conversation outline went away. Stop sending it, and cap
the agent's message at a status line's worth.

* fix(core): hand agent hook reports to the daemon over its socket

An agent hook reported by writing an OSC 777 sequence to the tty the
agent draws on. A tty write is not atomic: on macOS the kernel parks a
writer whenever the output queue is over its high-water mark, which is
exactly when the agent is busy redrawing, and lets the other writer in.
The agent's output then lands inside our sequence, the OSC breaks, and
the rest of the JSON is printed on screen. A pty test with a busy
writer next to a small one splits even 100-byte writes, at arbitrary
offsets, so no size keeps the sequence whole.

The hook now sends the same JSON to the daemon that owns its pane
(`$TTY7_PANE`, over the pane socket `$TTY7_CONFIG_DIR` leads to), which
applies it exactly as if its reader had found it in the output. The
pane id comes from the environment, which a detached tmux server or
the like carries out of the pane, so the daemon applies a report only
from a process that runs under the pane's shell. Anything else — no
daemon, one that predates the message, a refusal — falls back to the
tty as before, which is still how a hook with no daemon beside it
reports.

* fix(terminal): offer /effort in the composer's command menu for Claude

The toolbar's effort picker types `/effort`, but the `/` menu did not
list it. Bring the list in line with current Claude Code while at it:
`/usage` replaces `/cost`, which is now only its alias, `/rewind` joins,
and `/agents`, which Claude Code has removed, goes.

* fix(terminal): step aside for Codex's own lists instead of covering them

Codex marks the selected row of its lists -- the approval prompt,
/model, /permissions, the hook review and the update offer at launch --
with the same `›` that starts its input line. The composer took that row
for the input and laid the box over the list, hiding the options the
user had to pick from. A `›` row that is a numbered option with sibling
options around it is now read as a list, and the box steps aside.

* fix(terminal): offer Codex's /permissions, not the retired /approvals

Current Codex no longer knows /approvals; the command that chooses what
it may do without asking is /permissions. Also offer /resume.

* fix(core): install Codex hooks into CODEX_HOME when it is set

Codex reads hooks.json from its home, which CODEX_HOME moves. tty7
always wrote and checked ~/.codex/hooks.json, so for such a user the
hooks it installed never ran, and the state it reported described a file
Codex does not read. Local-only, like the other config-dir overrides.

* fix(core): find the pane a Codex hook reports on from the report itself

Codex runs its hooks in its app-server, one background process every
Codex session on the machine talks to. The first session starts it, and
it outlives that session, detached. Its hooks therefore carry the first
session's $TTY7_PANE and run under that pane's shell only while that
session lasts. Once it ended, the daemon refused every Codex report as
coming from outside the pane -- and the tty fallback has no terminal in
a detached process -- so a Codex pane never showed working, waiting or
done. While the first session was still running, a second pane's
reports were taken as the first pane's.

A Codex report is now matched to its pane by what it says: the pane
that already reported its session, else the one pane running Codex in
its directory (the one yet to report a session, and the named pane on a
tie). Other agents' reports are unchanged.

* fix(core): install Gemini hooks under GEMINI_CLI_HOME when it is set

Gemini CLI roots its user-level .gemini directory at GEMINI_CLI_HOME in
place of the home directory. tty7 always wrote and checked
~/.gemini/settings.json, so for such a user the hooks it installed never
ran, and the state it reported described a file Gemini does not read.
Local-only, like the other config-dir overrides.

* fix(terminal): find Gemini's input in the shaded block it draws now

Gemini CLI no longer frames its input in a rounded box: it shades the
prompt line between a row of lower half blocks and a row of upper half
blocks, and with shading off it draws a rule over the prompt instead. The
composer looked only for the old frame, so over a current Gemini it
stayed stepped aside for good and never covered the input.

A message already sent is shaded the same way in the transcript, so the
block counts only with nothing but the footer under it; a permission
prompt or a list in the input's place leaves the last message above more
than that, and the box steps aside for it. The old frame is still found
for older versions, and the shell, YOLO and history-search marks count as
a prompt as well as `>`.

* fix(terminal): give Gemini time to read a paste before pressing Enter

Gemini CLI takes an Enter that comes within 40ms of a bracketed paste as
a line break. It starts that window once it has read the whole paste, so
the 50ms the composer left between the paste and the Enter was not
enough for a long message: a 41-line message sat in Gemini's input as
"[Pasted Text: 41 lines]" plus an empty line, hidden under the box, and
was never sent. Gemini now waits as long after a paste as Copilot does;
a 400-line, 32KB message goes through whole and is submitted once.

* fix(terminal): hand Gemini its attachments and mentions so it reads them

Three things kept files from reaching a Gemini turn from the composer:

- Attachments went after the text as shell words. Gemini turns a drop
  into @ mentions itself, but only a paste that is nothing but paths;
  after the message's text a path is just words, and the model never saw
  the file. Gemini now gets its attachments as the mentions it would have
  made.
- A mention picked from the @ menu was spelled raw. Gemini ends a mention
  at the first unescaped space, so "my notes.txt" became "@my". Mentions
  for Gemini are escaped the way its own escapePath does it.
- With the caret at the end of an @ word Gemini lists matching files, and
  Enter takes the list's pick instead of sending, so a message closed by
  a mention - every message with an attachment - sat in the input under
  the box, unsent. A message with a mention now ends in a space, which
  closes the list; slash commands are left alone.

* fix(terminal): offer Gemini's current commands in the composer's menu

Gemini CLI now names its session browser /resume, with /chat kept as an
alias, and /clear starts a new session rather than only clearing the
screen. Offer /resume under its own name, say what /clear does now, and
add /model and /init, which the menu left out.

* fix(terminal): paste messages to Gemini instead of typing them

Gemini CLI judges each key of a typed burst against its input as it was
before the burst, so to it the input is still empty at every key. A "?"
anywhere in a typed line is taken for the key that opens its shortcuts
on an empty input and dropped ("what? yes" arrived as "what yes"), and a
"!" for the one that switches it into shell mode, which also clears what
came before it: "hi! there" became a shell command " there", one Enter
away from running.

Gemini now gets every message as a bracketed paste, like Codex, with a
leading "!" still sent as a key of its own - as for Claude Code - so a
message that starts with one keeps opening shell mode.

* fix(terminal): spell a mention with a space the way Claude and Codex read it

A file picked from the composer's @ menu went in raw for Claude Code and
Codex, so "my notes.md" came out as "@my notes.md":

- Claude Code ends a bare mention at the first whitespace, so it looked
  for "my" and the file never reached the turn. A path with a space now
  goes in double quotes, @"my notes.md", the form Claude's own list puts
  in and its parser reads back as one file.
- Codex hands mentions to the model as plain text, and its own list puts
  in the path alone: without the @, in double quotes when it has a space
  in it. The composer now does the same.

Checked for real: Claude 2.1.286 with no tools answers from @"my notes.md"
and not from @my notes.md or @my\ notes.md; Codex 0.158's list inserts
"my notes.md". Attachments are unchanged; both agents read one with a
space in its path.

* fix(core): name tty7's Gemini hooks so Gemini shows "tty7" while they run

While a hook runs Gemini CLI shows "Executing Hook: <name>" above its
input, and a hook without a name is shown by its whole command - the
quoted path of the tty7 binary and its arguments. tty7's Gemini entries
now carry "name": "tty7".

An install from before reads as outdated - its hooks' names are checked
along with their commands - so the launch-time refresh and the settings
page's Update rewrite it in place, one entry per event as before. Other
agents' entries get no name and are judged as before.

* fix(core): show no effort level for a Claude model that takes none

A new Claude session names its model but not its effort level, so the
hook fell back to the settings' level - and a session started on Haiku
showed "High" until its first turn ended. The hook now checks Claude
Code's own model catalog (its cache, read only) first: a model it lists
without effort options is reported with an empty level. A model it does
not list, or no catalog at all, falls back to the settings as before.

* fix(terminal): paste messages to OpenCode and Amp instead of typing them

OpenCode reads a burst of typed keys against the input as it was before
the burst, the way Gemini does: the `!` in "PONG! ok" switched it into
shell mode and the rest of the line ran as a shell command. Amp takes a
typed leading `?` for its shortcuts key and drops it, and a typed
leading `/` opens its command palette while the rest of the burst lands
in the input underneath, so Enter ran whatever the palette listed first.

Both now get every message as one bracketed paste, which each reads
intact and sends on the Enter that follows. A leading `!` still reaches
OpenCode as a key of its own, the only way it switches into shell mode;
Amp reads its `$` shell prefix off a paste.

* fix(terminal): stand the docked composer as far in from the bottom as from the sides

Docked under the grid, the box sits inside the pane's padding, and only
the side inset took it off: the box stood 20px up from the pane's bottom
and 16px in from its sides, where it covers an agent's input 16px from
all three.

* fix(terminal): offer OpenCode's commands in the composer's menu

OpenCode takes slash commands typed at its input, pasted ones included,
but the composer's `/` menu listed none for it and its placeholder left
out the commands hint. List the ones its own menu opens with, in its
words. Amp keeps an empty list: its `/` opens a command palette that a
message cannot drive.

* fix(terminal): hand OpenCode and Amp their attachments as pastes of their own

Both attach an image only from a paste that is nothing but its path; a
path after the message's text stays words, so an image attached in the
composer never reached the model. They now get the text, then each path
as a paste by itself after a typed space, and Enter once the last one has
had time to land. OpenCode shows the file as a part of the message and
Amp lists it under Images, as a drop onto their own input would.

* fix(terminal): don't answer pixel-size queries from a replayed pane

A reattach replays the pane's ring through the grid with query replies
muted, but the mute list missed `TextAreaSizeRequest`: alacritty hands
`CSI 14t` to the listener as its own event (the view owns the pixel
size) rather than as a `PtyWrite`. Every `CSI 14t` a TUI had sent was
answered again on each app restart, and the `CSI 4;h;w t` replies landed
on whatever reads the pane now — at a shell prompt, after the TUI that
asked had quit, zsh printed them as `;840;873t;840;873t...`.

Mute it with the other replies; live queries are still answered.

* fix(core): don't let a hook wait on a terminal whose pane has gone

An agent's session-end hook that falls back to the tty after its pane
closed opened the terminal device blocking. With the pty's other end gone
that open waits for a carrier that never comes, and on macOS it waits
holding the lock every lookup under /dev needs: the hook never exits, the
agent cannot finish exiting, and every new shell, ps and tty on the machine
hangs behind them until the hook is killed.

Open the device without waiting, then switch it back to blocking writes so
a busy terminal still gets the whole sequence; a terminal with no other end
fails the write at once.

* fix(terminal): paste messages to Copilot instead of typing them

Typed into Copilot's empty input, a leading `?` is the key that opens its
help: "?why" went out as "why". Paste every message, as for Codex and
Gemini. Copilot still reads a pasted leading `!` as its shell mode, and
already got the longer wait before Enter that a paste needs.

* fix(terminal): speak to Qwen Code the way Gemini is spoken to

Qwen Code is a fork of Gemini CLI and kept its input, but the composer
treated it as an agent with none of Gemini's traps:

- a typed leading `?` opened its shortcuts and was lost;
- a message closing on an `@` mention sat in the input, its Enter taken
  by the file list;
- a mention or attachment with a space in its path went out as words it
  cannot read back.

Give it Gemini's handling: pasted, with the shell-mode `!` as a key of its
own, a space after a closing mention, the longer wait before Enter, and
attachments and `@` picks spelled with Gemini's escaping, plus the comma
Qwen escapes too.

* fix(terminal): leave Copilot's file list behind before pressing Enter

With the caret at the end of an `@` word Copilot lists matching files, and
Enter takes the list's pick instead of sending, so a message that closed on
a mention (one picked from the composer's own `@` menu ends that way) sat in
Copilot's input unsent. End such a message with a space, as for Gemini.

* fix(terminal): hand CodeBuddy a leading `!` as a key of its own

CodeBuddy switches into bash mode only on a `!` typed into its empty input
by itself, as Claude Code does. Arriving in one burst with the rest of the
line it is just a character, so "!git status" went to the model as a
request to run the command, behind a permission prompt.

* fix(terminal): paste messages to Kimi Code so they are sent

Kimi Code takes keys arriving faster than anyone types for an unbracketed
paste, and the Enter right behind a typed line for one of its newlines: a
one-line message from the composer sat in Kimi's input with an empty line
under it, never sent. Paste every message instead. Kimi knows a bracketed
paste for one, sends on the Enter after it at once, and still reads a
pasted leading `!`, `?` or `/` as typed.

* fix(terminal): spell a mention with a space the way Kimi Code does

Kimi Code's own `@` list puts in a path with a space as `@"my notes.md"`,
the way Claude Code spells it. The composer's menu put in `@my notes.md`,
which Kimi reads as a mention of `my` followed by a word.

* fix(terminal): offer Copilot's, Qwen Code's, CodeBuddy's and Kimi Code's commands

All four take typed slash commands, but the composer knew none of them: `/`
opened no menu and the placeholder offered only `@` files. List each one's
everyday commands as its installed version names them: Copilot CLI 1.0,
Qwen Code 0.24, CodeBuddy Code 2.161 and Kimi Code 2.1, which has `/new`
rather than `/clear` and `/permission` in the singular.

* fix(terminal): hand Copilot and CodeBuddy their attachments as mentions

Copilot and CodeBuddy attach a file only from an `@` mention, and a path
after the message's text is just words to them: an attached image reached
neither model, which had to go and read it with a tool, behind a prompt.
Send each attachment as an `@` mention instead, which both attach to the
turn, an image as an image. Neither reads a mention back past a space, so
a path with one still goes as quoted words.

* fix(core): import Pi's extension types from its current package

Pi moved from @mariozechner/pi-coding-agent to
@earendil-works/pi-coding-agent. Current Pi resolves both names for
extensions, and the bridge's import is type-only, so it is erased before
an older Pi that knows only the old name loads it. A bridge already
written with the old name reads as stale and launch's refresh rewrites it.

* fix(core): keep Pi and Oh My Pi panes working through retries and approvals

agent_end closes every attempt, so a run Pi retries after a provider
error read as done while it was still retrying. The bridge now takes
Pi's agent_settled as the end of a run when the build sends it, and
Oh My Pi's auto_retry_start puts the pane back to working.

Oh My Pi asks before running a tool through tool_approval_requested and
tool_approval_resolved, not Pi's UI-prompt pair, so its pane said
working while the approval dialog waited. Those now report waiting and
restore the turn.

* fix(core): take Prime Agent's hook reports from its background daemon

Prime Agent runs each session in a detached daemon, started by the first
session and outliving it, and the daemon runs tty7's bridge there with
the environment of the TUI that asked for the session. The report names
the right pane, but its process never runs under that pane's shell, so
the daemon turned every one away and a Prime Agent pane never left idle.

A report about Prime Agent is now taken by the pane it names when that
pane is running Prime Agent.

* fix(terminal): lay the composer over Pi's own input

The box docked under Pi's pane, so Pi's own ruled editor and its status
rows stayed on screen above it: two inputs. Pi now gets the covering box
Claude, Codex and Gemini have. Its editor is the lowest pair of
full-width rules — the upper one carries the spinner while a turn runs —
with the directory and usage rows under it, and the box covers from the
upper rule down. Pi's selectors take the editor's place between the same
rules but open on a blank row (or, for /settings, on a `>` search line)
and run on for several, so the box steps aside for them and comes back
once they close.

* fix(terminal): offer Pi's, Oh My Pi's, Prime Agent's and Grok Build's commands

All four take typed slash commands, but the composer knew none of them:
`/` opened no menu and the placeholder offered only `@` files. List each
one's everyday commands as its installed version names them — Pi 0.99,
Oh My Pi 18.4 (`/exit`, `/retry`, `/todo`), Prime Agent 0.9 (`/effort`
rather than Pi's `/thinking`) and Grok Build 1.0 (`/mcps`, `/recap`).

* fix(terminal): lay the composer over Oh My Pi's own input

The box docked under Oh My Pi's pane, so its own input stayed on screen
above the box. Oh My Pi now gets the covering box too. In its default
status-band shape, and in the rounded box, the input's first line opens
with `╰─ ` under the status line, and the box covers from that line
down; a dialog frame closes with `╰──…╯` and a tool approval or picker
takes the input's place, so the box steps aside for those. Its Pi and
Claude Code shapes are ruled like Pi's input and found the same way.

That input is two rows, where the box is about five, so laid over it the
box hid the last lines of the reply. For Oh My Pi the grid now gives up
the rows the box needs beyond the input, measured off the box as drawn
empty, and the agent draws its input that much higher.

* fix(terminal): lay the composer over Prime Agent's own input

The box docked under Prime Agent's pane, so its own shaded input block
stayed on screen above the box. Prime Agent now gets the covering box
too: its input is a blank row, the ` >` prompt line with any further
lines indented under it, and another blank row, right over the footer
that ends the screen. The model picker draws its own ` >` search line
between rules, away from the footer, so the box steps aside for it.

The block and footer are a row shorter than the box, which cut the hint
line above it in half; the grid makes room for that row as it does for
Oh My Pi.

* fix(terminal): lay the composer over Grok Build's own input

The box docked under Grok Build's pane, so its own framed input stayed on
screen above the box. Grok Build now gets the covering box too: its input
is the rounded frame whose first line opens with `❯`, with the key hints
under it. Its `/` and `/model` lists open over the frame between two
rules, and its dialogs are drawn across the frame's top edge; the box
steps aside for both, since they take the keys the box would send.

Grok Build keeps a command whose list was dismissed in its input, where
under the box nobody sees it and the next message was typed on after it:
`/modelReply …`. With text left there, the box now clears it with Ctrl+U
before sending.

* fix(terminal): spell mentions the way Pi and its forks read them

Pi, Oh My Pi and Prime Agent end a bare `@` mention at the first space,
and their own `@` lists put a path with one in double quotes,
`@"my notes.md"`; the composer put it in bare, so the mention named a
file that does not exist. Grok Build's list puts the path in as it is,
which the composer already did.

Oh My Pi reads a mentioned file — an image included — into the turn
itself, where a path in the message is just words for the model to go
and read, so its attachments now go as mentions.

* fix(terminal): send Oh My Pi, Grok Build and Prime Agent messages that end in a mention

Oh My Pi's and Grok Build's `@` lists open on a mention at the caret and
take the Enter that follows, so a message whose attachments or mention
closed it sat in their input, under the box, unsent. Like Gemini's and
Copilot's, their messages with an `@` now go with a space after them.

Prime Agent's list opens as a typed mention is typed and stays open past
the space after it: "read @a.txt " went out as "read @a.txt .git/". A
paste it reads whole, `!` and `/` included, so its messages are pasted.

* fix(terminal): stop a Grok Build turn with its own interrupt key

Esc in the box covering an agent's input is that agent's Esc, the key
that stops a turn. Grok Build's Esc leaves a running turn running — its
stop key is Ctrl+C — and the daemon, reading any Esc during a turn as
an interrupt, then called the pane done while Grok still worked. The
box now sends Grok Build Ctrl+C, and the daemon no longer counts an Esc
as stopping a Grok Build turn.

* fix(core): don't start a turn from a notification's waiting status

Before an agent's first hook, a desktop notification marks its pane
waiting. Crush raises one after every turn ("Agent's turn completed"), and
its only hook, PreToolUse, is reported as a finished tool, which moves a
waiting pane back to working: from the first tool of a session on, the
pane read as working for good, as Crush has no Stop to end it.

A status set by a notification now gives way to idle when the first hook
report arrives, so the report only records the session and its activity.

* fix(terminal): take only a hook's word that the agent is asking

The box stands aside and sends nothing while the pane's agent is waiting,
since whatever it sent would answer the question on screen. For an agent
without hooks — Amp, or Crush before its first tool — the pane is marked
waiting by any desktop notification, "Agent is ready" at the end of a turn
among them, and it stays marked. From the first finished turn on the box
stood aside for good, and messages went into the agent's own input
instead.

Waiting now holds the box back only when hooks reported it. Those agents'
own dialogs take their input's place on screen, and the box steps aside
for them off the screen as for any other.

* fix(terminal): offer Goose's commands in the composer's menu

Goose takes typed slash commands — /model, /mode, /compact, /clear and
the rest of what its /help lists — but the box's `/` menu was empty for
it. It now lists them, as Goose 1.52 names them.

* fix(terminal): stop a Crush turn with the two Escs it asks for

Crush takes a first Esc during a turn as a question — "esc press again to
cancel", in its key help — and stops only on a second one. Over its input
the box's Esc sent one, the question sat in the help under the box where
nobody read it, and the turn ran on. For Crush the box now sends both,
as separate writes: in one read the two are a single key to it.

* fix(terminal): lay the composer over Crush's, Goose's and Amp's own input

The box docked under these agents' panes, so their own inputs stayed on
screen above it: two inputs. They now get the covering box too.

- Crush's editor opens on its `> ` prompt (`!` in yolo mode, `:::` while
  the chat has the keys) with each further line on `:::`, over a blank row
  and its key help. Its dialogs — the command palette, the model and
  session lists, a permission request — are framed over the screen with the
  editor left standing under them, and take the keys, so with a frame on
  screen the box steps aside.
- Goose prints its `> ` prompt under its context gauge, as the last thing
  on the screen, wherever its output ended. A turn's spinner and output,
  and a tool approval, are printed under the line sent, and the box steps
  aside for them until the next gauge and prompt. Its input is two rows
  where the box is about five, so the grid gives up the rest, as it does
  for Oh My Pi.
- Amp frames its input at the bottom of the screen, its mode in the top
  edge and the directory in the bottom one. Its palette and file list open
  framed and indented over the screen, and a notice in the input's place
  (out of credits) is a frame with nothing in its bottom edge; the box
  steps aside for both.

Text typed into one of these inputs before the box was opened over it
stays there, unseen, and the next message would run on after it. With
text left there the box now empties it first, a line at a time with
Ctrl+U and Backspace, as it empties Grok Build's with Ctrl+U.

* test(core): keep the closed-terminal write test from racing other tests' children

`a_terminal_with_its_other_end_gone_fails_the_write_at_once` failed about
one run in three alongside the other hook tests (never on its own): its
pty came from `openpty`, whose descriptors are inherited, and the Qoder,
CodeBuddy and Crush config tests spawn children on threads of their own.
A child that took a copy of the pane's end kept it open after the test
closed it, and the write went through.

Open both ends close-on-exec from the start, and since a child forked a
moment earlier still holds a copy until it gets to exec, retry a write
that went through after a short pause; every attempt must still return
within the timeout, which is what the test is for. 50 runs of the hook
tests in parallel now pass, where 13 of 40 failed before.

* fix(terminal): lay the composer over Copilot's, Qwen Code's, CodeBuddy's, Kimi Code's and OpenCode's own input

The box docked under these agents' panes, so their own inputs stayed on
screen above it: two inputs. They now get the covering box too.

- Copilot, Qwen Code and CodeBuddy rule their input off top and bottom,
  the prompt (`❯`; `>`, `*` or `!`; `>`) on the line right under the upper
  rule and the status rows under the lower one. Their approvals and
  pickers come framed or between rules of their own with the question on
  the first line, and their `/` and `@` lists open under the lower rule or,
  Copilot's, right over the upper one; the box steps aside for them. Qwen
  Code is drawn as Gemini's ruled input once was, but Gemini's looser test
  takes the `> model` row of Qwen Code's own `/` list for the prompt, so
  it gets the stricter one.
- With true colour Copilot shades its input instead — a `╻▄▄▄` and a
  `╹▀▀▀` edge around lines on a `┃` bar — and draws its lists shaded over
  it, the selected row opening with `❯ /`; a sent message has the time at
  its end.
- Kimi Code frames its input over its model line and context gauge. Its
  lists open under the frame, its approvals take the frame's place, and
  its welcome banner is a frame far up the screen.
- OpenCode draws its input on a bar closed by a `╹▀▀▀` edge over its key
  hints, in the middle of its home screen and at the bottom of a session.
  Its lists open on the same bar, each row closed by a `┃` at its right,
  and a permission request takes the input's place with no edge.

Text typed into one of these inputs before the box was laid over it is
emptied first, a line at a time with Ctrl+U and Backspace, placeholders
and offered suggestions not counted. CodeBuddy takes keys that arrive
together for a paste and does none of them, so it is sent them one at a
time.

* fix(terminal): take Qwen Code and CodeBuddy out of shell mode before a plain message

A `!` message is a shell command to Qwen Code and CodeBuddy, and both stay
in their shell mode after it has run, their prompt a `!`, until Esc takes
them out. The next message from the box ran as a command too
(`bash: ?: command not found`), and a second `!` message toggled the mode
off and went to the model.

With the box over the input, the prompt says which mode it is in: a plain
message now leaves shell mode with Esc first, and a `!` message sent in
it drops the `!` that would toggle it off. CodeBuddy's `!` prompt counts
as its input, so the box no longer steps aside for it.

* fix(terminal): paint the layer under the covering composer in the agent's own background

The layer laid over an agent's input was painted in the theme's
background. Grok Build, OpenCode and other agents that paint the screen
in a colour of their own were left with a strip of the theme's colour
around the box — a light band under Grok Build's dark screen.

The layer now takes the colour the agent paints the row over its input
in (the one most of its cells have), over the grid's columns only; the
pane's padding around them keeps the theme's. An agent that leaves the
terminal's own background, as Claude Code, Codex, Kimi Code and Copilot
do, keeps the layer as it was.

The box's own fill was a faint tint of the text colour, which showed
whatever was under it: on Grok Build's dark layer the box went dark and
its text could not be read. It is now that tint laid over the theme's
background, the same colour as before on the theme's own background.

* fix(terminal): lay the composer over Qoder's own input and speak to it the way Gemini is spoken to

Qoder (both the global and the CN build) docked the box under its pane,
its own input left standing above it: two inputs.

- Its input sits between the last two full-width rules, opening with
  ` > ` (` * ` in YOLO mode, ` ! ` in shell mode), with only its model line
  under the lower rule. Over the upper rule its mode line has a rule of its
  own, with the `? for shortcuts` hint above it; the box covers those too.
  Its `/` and `@` lists open under the lower rule with the selected row
  opening with `❯`, and its trust and sign-in prompts, `/model` and `/help`
  open under a single rule with no prompt; the box steps aside for them.
- It is a Gemini CLI fork and kept that input: keys in a burst are read
  against the input before the burst (`echo hi` typed came out
  `echo hiecho hi`), a typed leading `?` opens its shortcuts, the Enter
  right behind a paste is a newline, its `@` list takes an Enter that comes
  right after a mention, and its list spells a path with a space
  `@my\ notes.md`. It now gets Gemini's handling of all of these.
- Like Qwen Code it stays in shell mode after a `!` command; a plain
  message leaves it with Esc first. Text left in its input is cleared with
  Ctrl+U and Backspace. Its `/` menu offers its current commands.

* fix(terminal): pick OpenCode's mentions from its own @ list so the files are attached

OpenCode attaches a file to a message only when it was picked from its
own `@` list (or handed over by an editor); the text of a mention is just
words to it. `@my notes.md` from the box, and `@plain.md` as well, reached
the model as text, which went looking for the file with its tools — and
the one with a space it had to find by globbing.

A message for OpenCode in a local pane is now cut at its `@` mentions of
paths that exist under the pane's directory (the longest run of up to four
words that names one), and each is sent the way a pick is made: a typed
`@`, the path pasted as the query with its spaces left out (a space would
close the list), and Enter once the list has had time to search. OpenCode
then shows `File  my notes.md` under the message. A space typed after it
closes a list that found nothing, so the Enter that sends is not taken by
it. An `@` that names nothing, commands and shell lines go as before.

* fix(terminal): cover Gemini's mode line and shortcuts hint along with its input

Gemini CLI 0.62 draws a mode line ("Shift+Tab to accept edits", "shell
mode enabled") over its input, with a rule of its own over it and the
`? for shortcuts` hint above that. The box covered the input from its
shaded block (or the rule right over its prompt) down, so the hint, the
rule and the mode line were left standing over the box.

The box now covers from the rule over that mode line, and from the hint
when it is there — the way it already does for Qoder, which draws the
same block; the two share the lookup. An input without a mode line over
it is covered from its own top as before.

* style(core): settle the clippy warnings the interrupt-key reader brought in

`is_interrupt_key` is only asked by the tests since the Grok Build change
went through `interrupts`, and two `let … else { return None }` read the
kitty-protocol key; the first is test-only now and the other two use `?`.

* fix(terminal): a screenshot pasted into the composer becomes an attachment

* fix(terminal): keep the composer's reserved rows, pastes and screen scans in line with the box

Scrolling back no longer resizes the pane, outside pastes land in the box
when it covers the input, the screen is scanned only while the box is open,
the command scan stops 8 directories deep, effort labels capitalise by
character, and two doc comments sit on their own items again.

* fix(core): route Codex reports past /new and codex -C, trust agent_settled only once seen

A session /new started goes to the Codex pane that had one; a report from
a directory no pane runs Codex in is matched among every Codex pane instead
of falling back to the app-server's. The Pi bridge no longer reads a
returned function from on() as proof agent_settled will come, and the Stop
hook re-reads the transcript only once it has grown.

* refactor: carry a session's source on AgentEvent and tidy the review fixes

The Codex router reads source off the parsed event instead of parsing the
hook body again. The command scan reads each real directory once rather than
capping depth, labels capitalise through one helper (alias_label no longer
slices bytes), the live input rows are set where Covering is decided, and
the transcript is opened once per poll.

* fix(terminal): read Claude's custom commands through Host

The scan reached std::fs directly, which the host-boundary check rejects;
it now walks the pane's host, joining and canonicalizing through it, and its
test covers a link back up the commands tree.
2026-10-01 23:46:26 +08:00
c361bd71e8 feat(panel): CPU% and memory per process, and a total, in Info → Processes (#1064)
* feat(panel): CPU% and memory per process, and a total, in Info → Processes

The daemon adds rss, cpu_ns and a start stamp to each ProcEntry (serde
default, so an old daemon or GUI skips them). The GUI turns two CPU-time
samples into a ps-style % and sums both into a Total line. `tty7 procs`
gains an RSS column.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(panel): no CPU% across a poll gap, and test CPU time is in ns

A new poll chain starts after the panel was shut or the pane changed;
comparing against the sample from before the gap showed a long-run average
as the current figure. Reset the tracker so the first round shows a dash.

Replace the self-usage test's cpu_ns > 0 (fails on Linux before the first
10 ms tick, passes unconverted mach ticks) with a check that the process's
CPU time covers this thread's own burned CPU time.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-01 15:18:27 +08:00
e1f93704fe fix(sidebar): Move to Group is a submenu listing every sidebar group (#1063)
* fix(sidebar): Move to Group is a submenu listing every sidebar group

The tab menu's Move to Group listed only pinned groups, laid out flat on
the grounds that there are never many. A sidebar that auto-groups by repo
holds dozens of groups, none of which could be picked. It is now a submenu
with every group the sidebar draws, in sidebar order, the tab's current one
checked, then Ungrouped (back to auto grouping) and New Group. Picking an
auto group pins it, as its header's pin does, and keeps the tab there.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(sidebar): Move to Group review fixes

- Ungrouped row replaced by Remove from Group, enabled only for a tab kept
  in a group; move_targets is pure (no locale lookup) over GroupKey.
- move_tab_to: an auto group is pinned with the tab in one edit
  (pin_auto_group_with), gpui-tested.
- A separator splits pinned from auto groups; targets are taken before the
  submenu borrows cx.
- No CHANGELOG hunk; the description carries it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(sidebar): Move to Group comment and pin_auto_group_with tidy

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(sidebar): Move to Group's labels line up with the tab menu

One left-checked row makes gpui_component reserve a check column on every
row of that menu, so the whole submenu sat an icon's width right of the tab
menu it hangs off. Putting the check on the right keeps the labels at the
parent's inset.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(sidebar): pinning a repo whose folder is kept joins the kept group

A tab dragged out of a folder group while still in the repo is drawn
under the repo's auto group, beside the folder group keeping the same
directory. Move to Group lists both; picking the auto one (or its
header's pin) pushed a second folder group on the same path, two
identical headers splitting the folder's tabs by list order. Join the
kept group instead, as pin_folder already does.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-01 15:18:06 +08:00
384a329df7 feat(terminal): program notifications follow the policy; read kitty OSC 99 (#1062)
* feat(terminal): program notifications follow the policy; read kitty OSC 99

OSC 9/777 notifications used to post from the reader thread regardless of
focus or the Never setting, and clicking one revealed nothing. They now queue
for the view, which applies notify_on_command_finish (Unfocused holds one back
only while its pane is focused in the key window), posts it clickable for the
pane, and titles it with the agent's name when it brings none. A pane whose
agent reports through tty7's hooks skips the copies the hooks already cover.

Kitty's OSC 99 is read too, chunked by i= with d=/p=/e=, in the client and in
the daemon sniffer, so a hookless agent's kitty notification marks it Waiting.
Claude Code's ghostty, kitty and iterm2 Notifications channels all land here;
its default, auto, sends nothing under TERM_PROGRAM=tty7.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(terminal): agent hook notices follow the per-pane rule

An agent's Waiting and Done notices from tty7's hooks were only posted while
the window was in the background, so an agent in another tab of the front
window never reached you. They now share shows_notification with program
notifications: Never posts nothing, When unfocused holds a notice back only
while its pane is focused in the key window, Always always posts. A hooked
pane still skips its program's own copies, so nothing doubles.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Revert "feat(terminal): agent hook notices follow the per-pane rule"

This reverts commit 7df400043c. The hook
notice change is a behaviour change of its own and moves to the stacked
branch upstream/hook-notices-per-pane.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* refactor(terminal): NotifyMode::allows, a Note type, and a cap on queued notes

One rule for every notification path: a mode allows a notice unless it is
Unfocused and the reader is watching. Kitty's pending chunks and a
finished note get names instead of tuples, and a pane whose view is not
polling keeps only its newest eight notes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(changelog): drop the Unreleased entry; the release notes carry it

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): a burst of program notes shows its newest three, and an exiting shell's are shown

`take_osc_notes` hands over the newest three queued notes and drops the
rest, so a program that writes a burst doesn't spray the desktop. The view
shows them ahead of `poll_foreground`'s exit check, so what a program said
just before its shell exited still gets through.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* refactor(terminal): one cap on queued program notes, three

The queue kept 8 and `take_osc_notes` then handed over the newest 3: two
caps for one rule. The queue now keeps 3 and `take_osc_notes` drains it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(terminal): at most five program notes per pane every ten seconds

The queue cap applies between polls, so a pane that keeps writing
notifications still posted a few every 300ms. Each pane now has a
NoteBudget: at most five notes per ten seconds reach the desktop, and the
rest are dropped and said once, as "More notifications from this pane
weren't shown", when the window turns over. The budget is asked on every
poll, held-back ones included, so that note comes even after the flood
stops and never for a count gone stale.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): kitty control payloads and id-less chunks don't build a note; OSC 9;10-12 aren't notes

A p=close, p=alive or p=? with the id of an unfinished OSC 99 note
finished and posted it. They are commands about notifications, so they
now leave pending notes alone. Chunks without an i= are each their own
notification per the spec, and no longer join an earlier id-less d=0
chunk. ConEmu's OSC 9;10, 9;11 and 9;12 (a prompt mark some shells emit
every prompt) were posted as notifications; they are subcommands like
9;1-9;9.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-01 15:17:44 +08:00
1d76051959 feat(terminal): tell a pane's program when the theme turns light or dark (DEC 2031) (#1061)
* fix(terminal): tell a pane's program when the theme turns light or dark (DEC 2031)

Claude Code's `theme: auto` reads OSC 11 at startup and re-reads it only
when the terminal sends `CSI ? 997 ; 1|2 n`, which it asks for with
`CSI ? 2031 h`. tty7 ignored 2031, so a running Claude kept its light diff
colours after a flip to dark. Track 2031 per pane (and across reattach),
push a 997 when the theme's background changes, and answer `CSI ? 996 n`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(terminal): report the colour scheme on reattach; review cleanups for DEC 2031

A pane reattached with 2031 on now hears the current scheme once the
replay is folded, so a theme flip while it was detached still reaches
the program. report() uses the presets' is_dark, watch reads
view.terminal directly, TRACKED lists 2031 inline, and the gpui test
moves into view.rs's gpui_tests harness with a reattach case.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(changelog): drop the Unreleased entry; the release notes carry it

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): one scheme report per reattach, not one per replayed frame

A replay is a modes Snapshot plus one Snapshot per ring segment, and each
sent its own 997. The Snapshot arm now only folds and flags; the report
goes out once, on the first frame after the replay. The tests use the
harness's next_input_until_timeout instead of a reader thread, and the
reattach test replays two Snapshots.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): send the reattach scheme report when the replay has been read

It went out on the first frame after the replay, so an idle pane, with no
live frame coming, never heard it. It is now sent once the reader's buffer
drains. TRACKED keeps its one line and names `COLOR_SCHEME_UPDATES` rather
than repeating 2031. The reattach test replays Snapshot, Size, Snapshot,
Snapshot with nothing after.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): a shell prompt ends DEC 2031, so a dead program's mode never reports into the shell

A program that switched 2031 on and died without `?2031l` left the mode on
in the pane's tracked modes, its ring, and the client's fold. A reattach
replay then still ended with 2031 on, so the reader sent its post-replay
report, and every theme flip sent another, into the shell's command line.

`TerminalModes` now drops 2031 on an OSC 133 `A`, `B` or `D` mark: the
shell owns the terminal again, so whatever asked for reports is gone.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): send the reattach scheme report after the replay, not at a read boundary

The reattach report went out whenever the reader drained what it had read.
An 8 MiB ring arrives over many reads, so a read that ended after the ring
segment holding a dead program's `?2031h` and before the one holding the
shell prompt that ended it typed `CSI ? 997 ; n` into the shell. The report
now waits for the first frame past the ring (the replayed Prompt, Cwd and
the rest, or live Output once it is folded).

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-01 15:17:22 +08:00
Adam HitchcockandClaude Opus 5.5 ac5f20dfa7 fix(themes): accept integer colour components in .itermcolors files (#1059)
* fix(themes): accept integer colour components in .itermcolors files

iTerm2 and plistlib write exact 0 and 1 as <integer>, which the loader
rejected, dropping the whole theme.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(changelog): drop the Unreleased entry; the release notes carry it

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 15:17:01 +08:00
b63a4ebbe0 fix(ui): selecting a sidebar tab scrolls only as far as the nearest edge (#1060)
* fix(ui): selecting a sidebar tab no longer scrolls the list

activate() called sidebar_scroll.scroll_to_item(tab_index), but the
sidebar list's children are group blocks and dividers, not tab rows, so
the index named some other group and a click on a lower row jumped the
list. The row now brings itself into view when it is drawn: a row with
any part on screen stays put, one out of view scrolls in to the nearest
edge.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(ui): key the sidebar reveal by tab id and drop it when the row is not drawn

An index went stale when tabs were reordered or closed before the next
frame, and a reveal aimed at a row in a folded group fired whenever the
group was opened, long after the tab was selected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(changelog): drop the Unreleased entry; the release notes carry it

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(ui): a first row revealed from above brings its group header

When the sidebar scrolled a row in from above, the row landed on the top
edge with its group's heading still cut off above it, so the tab came into
view without the name of the group it is in. The first row of a group that
draws a header now counts the header (and the gap under it) as part of
itself when coming in from above. Rows on screen and rows below are
unchanged.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-01 14:58:11 +08:00
l0ng-ai 4e4789a045 fix(links): peel a CJK label off a path glued behind it (#1053)
An agent reporting a file it wrote prints `原型:/tmp/a.html` or
`原型:/tmp/a.html` with no space. The label rule only accepted ASCII
labels behind an ASCII colon, so the whole token was read as a relative
path and the click reported it missing under the pane's directory.

Accept any alphabetic label, one character long when it is not ASCII,
behind either colon. A single ASCII letter stays a Windows drive.
2026-10-01 00:17:43 +08:00
l0ng-ai 7e918f3a89 fix(editor): ⌘W on an empty editor closes the editor, not the terminal (#1056)
Closing the last file left nothing in the editor panel to hold the focus,
so it fell back to the terminal pane and the next ⌘W closed the terminal
instead of the empty editor.

The empty panel now has its own focus handle: it takes the focus over in
the frame after its last file closes (only for the tab whose editor had
it), and a click on it focuses it. ⌘W from there, or from the file tree
an empty ⌘⇧E hands the focus to, hides the panel and returns the focus to
the terminal. With the focus in the terminal, ⌘W is still the terminal's.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-10-01 00:17:39 +08:00
l0ng-ai d7dad45fa8 fix(gateway): reach the relay through a proxy when that is the only way out (#1058)
* fix(mobile): bump iroh to 1.3.0 so a stuck relay cannot stall direct dials

iroh 1.2.0 sends a connection's first datagrams to every known path one
after another inside the remote-state actor, awaiting each. When the relay
is unreachable its send queue fills and the actor blocks, so handshake
packets for a direct path that does work (a mesh VPN address, a public
IPv6) queue behind it and the dial times out. 1.3.0 sends to all paths
concurrently with a bounded wait (n0-computer/iroh#4512).

The desktop workspace was already on 1.3.0; the app has its own lockfile
and was left behind.

* fix(gateway): reach the relay through a proxy when that is the only way out

iroh dials its relay with its own resolver and its own TCP, ignoring the
system proxy. On a machine whose network only works through a local proxy
(Clash and the like, system-proxy or TUN mode alike) that dial never
succeeds, and nothing says so: phones on the same network still connect,
while a phone on cellular times out, because without a relay nothing
coordinates hole punching and the home router drops unsolicited inbound
packets.

The gateway now lists the ways out it knows of, most likely first:
tty7's own http_proxy setting, the system proxy, the environment's, then
direct. It starts on the first without waiting, and when the relay stays
unreachable for 10s it tries the others on a throwaway endpoint, switching
to the first that reaches a relay (same key, same port, so pairing codes
keep working). While none does, it looks again every minute.

A pairing code now names the relay only once it is actually connected;
before, it named whichever relay iroh picked by latency, reachable or not.

The platform proxy readers in daemon::install::proxy now also hand back
the proxy as a URL, for a client that is not ureq.

Claude-Session: https://claude.ai/code/session_018wE9ZRyxgWW2f55VSy9FvZ
2026-10-01 00:16:06 +08:00
l0ng-ai 96870ebcd4 ci(nightly): the phone app in the download table (#1055)
A Phone column: the TestFlight link, and the APK of the newest published mobile-v release, which ships apart from the nightly.
2026-09-30 22:35:32 +08:00
l0ng-ai 88bd7ca200 ci(nightly): a download table in the release notes, as a stable release has (#1054)
Built from the files the night actually produced, so one that did not build is left out rather than linked dead. Links go through the rolling nightly tag.
2026-09-30 22:30:49 +08:00
l0ng-ai fa3d777c29 feat(release): ship a native Windows ARM64 build (#1043)
Release and nightly now build the desktop app for aarch64-pc-windows-msvc
alongside x64, publishing tty7-<version>-windows-arm64-setup.exe and
tty7-<version>-windows-arm64.zip.

- Cross-compiled on the x64 Windows runner, like server-windows' ARM64
  leg, and marked experimental until it has shipped once: a failure drops
  the ARM64 packages instead of holding up the release.
- Vendors Microsoft's arm64 ConPTY pair from the same package version as
  the x64 one, so ARM64 panes keep the OSC 11 fix (#345).
- Each Windows package bundles the WSL server for its own architecture.
- The installer's architecture comes in as a define: x64compatible for the
  x64 build (still installable on ARM64 under emulation), arm64 for the
  native one. One AppId, so either upgrades the other.
- The in-app updater on an ARM64 build asks for the arm64 packages; an x64
  build under emulation keeps taking x64 ones.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 22:04:46 +08:00
l0ng-ai ce56e1674a chore(mobile): 0.1.2 (#1052) mobile-v0.1.2 2026-09-30 20:55:56 +08:00
l0ng-ai f6c866c53c fix(mobile): the Android app icon is tty7's, not the placeholder (#1051)
android init left the Android project on the template's icon. It is now an adaptive icon: the mark on a transparent layer, sized inside the safe circle any launcher mask keeps, over the tile's colour, with square and round ones for older launchers. Drawn from the same mark as the iOS icon; icons/android keeps the same files.
2026-09-30 20:42:44 +08:00
l0ng-ai 1172959e1d fix(menu): lighten the context menu shadow
Bump gpui-component to pick up a tighter popup menu shadow: the old
64px blur at 28% ink spread a grey halo far past the menu itself.
2026-09-30 20:36:24 +08:00
l0ng-ai f85c0fee76 fix(mobile): number TestFlight builds in UTC (#1050)
A laptop in UTC+8 numbered its builds eight hours ahead of CI, so a CI upload of the same version within eight hours of a local one came out lower and would be refused.
2026-09-30 19:32:02 +08:00
l0ng-ai 0a47cada12 ci(mobile): release iOS and Android together from one tag (#1048)
A `mobile-v<x.y.z>` tag now ships both platforms at one version: the
Android APK to a draft release as before, and an iOS build to
TestFlight. iOS no longer depends on one machine signed in to Xcode.

- The version is tauri.conf.json's; a tag that disagrees with it fails
  the run, so the repo always says what shipped. Set to 0.1.1, the
  Android build already out.
- scripts/testflight.sh signs and uploads with an App Store Connect API
  key when ASC_KEY_ID and ASC_ISSUER_ID are set, with a certificate
  Apple keeps in the cloud. That needs an Admin key.
- A manual run builds both and uploads nothing.
2026-09-30 18:20:50 +08:00
l0ng-ai 0646dc8b82 ci(mobile): match the signing digest whatever apksigner calls the signer (#1047) mobile-v0.1.1 2026-09-30 17:45:00 +08:00
l0ng-ai 399ecdf777 docs(readme): lead with three pillars instead of a feature list (#1046)
Restructure both READMEs around what tty7 is for: shells that outlive the
window, agents that drive other agents, and remote machines that work the
same way because they run the same server. Performance becomes a short
supporting section with concrete numbers; the rest of the feature list
collapses into one paragraph that links to the docs.

Also:
- Correct the persistence claim: shells survive quitting the app, not a
  reboot; after a reboot the layout, the screen tail, and supported agent
  conversations come back.
- Add a past-sessions column to the agent matrix, matching the agents
  agent_history::scan reads.
- Drop the wrapper-script / agent_launch paragraph (already in the
  configuration reference) and the separate full-quality video link.
- docs/window/search-everywhere.mdx: the Sessions tab has listed every
  supported agent, on remote workspaces too, since #977; the page still
  described only Claude Code and Codex on this computer. Also document the
  Cmd/Ctrl-E row actions.
2026-09-30 17:40:14 +08:00
l0ng-ai c834e728ce ci(mobile): keep the NDK install from failing on SIGPIPE (#1045) 2026-09-30 17:25:06 +08:00
l0ng-ai 0c2033ab07 feat(mobile): run on Android, and release a signed APK (#1044)
* feat(mobile): run on Android

The app builds and runs on Android, and fits there.

- Back button and gesture close what is open over the screen, then go
  back a screen, and from the first one send the app to the background.
  Left to the WebView they closed the app, since it has no history.
- The system bars: the page asks their size of the app (`insets`, over
  JNI), since WebViews before 140 report the safe areas as 0 even edge
  to edge. The CSS reads them as `--inset-*`, which iOS still fills
  from `env()`.
- The keyboard: edge to edge, the WebView is not resized for it and its
  visual viewport stays whole, so the keyboard covered the message box.
  MainActivity hands its height to the page, which lays out as on iOS.
- The title folds into the bar from the scroll position on every screen.
  The observer it used reported a title in plain view as out of sight on
  Android, so the bar started folded.
- src-tauri/gen/android is kept in the repo for that MainActivity.

* ci(mobile): release a signed Android APK

A `mobile-v<x.y.z>` tag builds the app for arm64 at that version, signs
it with the release key and attaches it to a draft release. The mobile
app is versioned apart from the desktop's `v*` tags.

- The release is never marked latest: the desktop updater reads
  /releases/latest and would take it for a desktop release.
- The APK's certificate is checked against the release key's, since one
  signed with another key could not be installed over earlier ones.
- The NDK is pinned, and the version must be x.y.z: Tauri derives the
  versionCode from it, and Android installs over a build only when that
  is higher.
- Gradle signs a release build when keystore.properties names a key;
  CI writes it from secrets.
- The release library is stripped: 30 MB to 20, the APK 32 to 23.

* ci: tell people how to install the phone app

The nightly release notes and each mobile-v release now say how to get
the app on a phone: the TestFlight link for iPhone, and the newest
mobile-v release's APK for Android. Both read .github/mobile-install.md.
2026-09-30 17:17:06 +08:00
l0ng-ai d40233b572 feat(tabs): keep recently closed tabs in the machine tree, and a confirm-before-closing setting (#1037)
* feat(tree): keep each workspace's recently closed tabs in the machine tree

A workspace now keeps the tabs closed from it in its machine tree
(`Workspace::closed`), so reopening one no longer depends on the window
that closed it still being open.

- `TabCloseRemembered` closes a tab into that list: the tab leaves the
  workspace as a close takes it (other windows hear `TabClosed`), its panes
  are stopped with their last screens kept on disk, and their records stay
  in the pane list. Panes the client held that the tree never recorded are
  ended outright.
- `TabReopen` takes the named or newest entry off the list and answers it
  with its pane records, for the client to rebuild on fresh shells that
  open on the old screens. The records it leaves behind are claimed by the
  successors' seeds instead of being refused as duplicates.
- Entries last 24 hours and a workspace keeps the newest 20. The daemon's
  scrollback keeper expires them on its existing timer, and an entry that
  goes takes its records and stored screens with it.
- Both requests are gated on a new `closed-tabs` hello feature, offered only
  by a peer that serves a tree and panes, so an older daemon or remote
  server is never sent them.

The field is `#[serde(default)]` and skipped while empty, so older trees
load unchanged and an older build reads this one's.

Refs #1021

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* feat(tabs): reopen closed tabs from the machine, and a setting for when closing asks

Closing a tab now closes it into its workspace's recently-closed list on the
machine that holds the workspace, instead of into a list that ended with the
window. ⌘⇧T asks that machine for the newest entry, so a closed tab comes
back after quitting and relaunching the app, from any window of the
workspace, and in remote workspaces whose server keeps the list.

- The explicit close (⌘W, the tab's close button, bulk closes) registers the
  tab with the window's next sync, which turns that tab's `TabClose` into a
  `TabCloseRemembered`. The machine stops the panes and keeps their screens;
  the window no longer kills them itself. A tab dragged to another window or
  never rebuilt still goes out as a plain close.
- If the close cannot reach the machine (no `closed-tabs` feature, a window
  that has not pulled its layout, a sync that fails or is thrown away), the
  window falls back to what it did before: the tab goes on its own list and
  its panes are killed from here.
- Reopening waits briefly for this window's queued edits to land, so an
  immediate ⌘⇧T undoes the close it means, then rebuilds the tab through the
  existing restore: each pane a fresh shell in its old cwd, opening on its
  last screen, with its shell, SSH target and agent resume facts. The tab
  keeps its id. The window's own list is used when the machine has nothing.
- The home screen offers the next tab ⌘⇧T would reopen, read from the
  machine mirror, which now tracks this window's remembered closes.

A new setting, `confirm_close` (General > Tabs, "Confirm before closing"),
decides when closing a tab or pane asks first: `never`, `when-busy` (the
default and the old behaviour) or `always`. The SSH "Warn before closing"
opt-in is honoured under every mode. Under `always`, Close Other Tabs and
Close Tabs to the Right ask once for the whole batch.

Refs #1021

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(tree): a remembered close marks its panes' records as no longer live

The records stay in the pane list for the reopen, but the panes are stopped
right after the close. Left at live: true, `tty7 wait` on a pane of a
closed tab read it as a running agentless shell and waited forever instead
of reporting it exited.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 16:40:28 +08:00
l0ng-ai f0f2b83b6e feat(workspace): the machine's own window takes part in workspace takeover (#1042)
One workspace is driven by one window at a time, whether that window runs on
the machine itself or on a remote client. The local GUI used to connect to its
daemon without ever claiming a workspace, so a remote client and a local
window could drive the same panes at once and fight over their size.

- The local link now claims (WorkspaceAttach) every local workspace a window
  shows. Opening one on purpose (switcher, tty7 open, a new window onto it,
  switching in place) takes it over; restore, relaunch and reconnect only
  claim a workspace nobody else holds, and otherwise open taken over.
- Preempted events for this computer put the window in the same taken-over
  state remote workspaces use: panes detached (processes untouched), the
  status strip naming the holder, the input pill, Take Back, and the
  switcher's 'taken over' badge.
- A hydration of a local workspace another client holds does not attach its
  panes, so a restored window never resizes them under the holder.
- A reconnect re-claims what the window held and leaves what it was pushed
  off alone. Nothing but Take Back or an explicit open reclaims.
- The local hello carries the machine's hostname instead of the literal
  'this computer', which is what a displaced remote client displays.
2026-09-30 16:36:10 +08:00
l0ng-ai 53f661e1a1 feat(remote): let a remote workspace target a Windows host over SSH (#1041)
A remote workspace refused any machine that was not Linux or macOS. This
teaches the installer and the link to reach a Windows OpenSSH host:

- Detection: `uname -sm` is still asked first, unchanged. When it fails
  (cmd.exe / PowerShell) or answers from Git for Windows, MSYS2 or Cygwin,
  a PowerShell probe reads PROCESSOR_ARCHITECTURE. The detected platform
  must match the SFTP home's shape, so a WSL DefaultShell over Windows
  SFTP is refused instead of installing a Linux server at /C:/...
- Assets: tty7-server-windows-{x86_64,aarch64}.exe, verified against
  checksums.txt like every other server; built by new server-windows
  jobs in release.yml and nightly.yml (ARM64 leg non-blocking), and the
  CI vcruntime guard now covers tty7-server.exe.
- Install: %USERPROFILE%\AppData\Local\tty7\bin\tty7-server-cXpY.exe via
  SFTP (/C:/... spelling). No mode bits are required or set. A running
  image is renamed aside to free its name and swept on the next install.
- Commands: every Windows command is a PowerShell script sent as
  -EncodedCommand, which survives cmd.exe, PowerShell and bash as the
  DefaultShell. The daemon is launched through Win32_Process.Create so
  it outlives the SSH session's job object, with this session's
  environment handed over; restarts use a new `tty7-server --stop`.
- Link: a Windows server is always reached by session exec with a plain
  `"C:\...\tty7-server-cXpY.exe" --stdio` (no env probe, no
  stream-local forward).
- Server: `--stdio` (control and --pane) now bridges on Windows to the
  daemon's loopback TCP endpoints instead of refusing.

Tested against a fake Windows host in install/windows_tests.rs; not yet
run against a real Windows machine.
2026-09-30 16:36:04 +08:00
l0ng-ai 8efea021e3 feat(ssh): shell integration for Windows hosts whose default shell is PowerShell (#1040)
The remote shell probe only understood POSIX answers, so a native SSH pane
on a Windows OpenSSH host always fell back to a plain shell with no prompt
marks, cwd reporting or title.

The probe is now a polyglot every default shell can read: POSIX shells
answer as before; PowerShell answers with its edition and $PSHOME, which
name the exact executable; cmd.exe echoes the line back verbatim and is
recognised, then deliberately left alone. For PowerShell the bootstrap
starts a second, interactive PowerShell of the same executable with the
existing integration via -NoLogo -NoExit -EncodedCommand (comments
stripped, about 6.5K chars total, well inside the Win32 command-line
limit), and a redialled pane's start directory (/C:/..., C:/..., UNC) is
restored with Set-Location -LiteralPath inside the encoded script.
2026-09-30 16:35:59 +08:00
l0ng-ai 0701278fe9 fix(mobile): the list fades out under the floating search bar (#1039)
Rows scrolled under the floating bar showed through sharp and cut in
half in the gap beneath it. A scroll-edge fade from the bar down to the
screen's edge softens them into the canvas, as the system's own bars do.

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
2026-09-30 15:28:22 +08:00
l0ng-ai ed87bd39b6 fix(mobile): testflight.sh puts the tty7 icon back after ios init (#1038)
`tauri ios init` fills the asset catalog with Tauri's placeholder icon,
so a regenerated gen/ shipped build 0.1.0.9 with the wrong icon. Copy
src-tauri/icons/ios over it on every run.

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
2026-09-30 15:28:16 +08:00
l0ng-ai ab029f5ea1 fix(ssh): start a redialled SSH pane in the remote directory it was in (#1035)
* fix(ssh): start a redialled SSH pane in the remote directory it was in

A native SSH pane dialled again (restore after a daemon restart, Reconnect,
a split, ⌘T on an SSH tab, waking a sleeping tab) always landed in the login
directory. The client already sent the pane's remote cwd as
`SpawnNativeSsh.cwd`, but the daemon dropped it on the floor.

The daemon now threads it through `Pane::spawn_native_ssh` and
`SshManager::run_session` into the shell-integration bootstrap, whose first
line becomes `builtin cd -- '<dir>' 2>/dev/null` (fish-quoted for fish). It
is never typed at the prompt, never lands in history, and a directory that
is gone leaves the shell in the login directory without a word. Sessions
without integration take the plain shell request as before, so jump-host
menus never see it. The per-host probe cache still holds only the shell.
Only absolute paths are honoured. No wire or protocol change.

Callers now say what they mean: a saved host or quick connect passes no
start dir instead of the local cwd of whatever tab was in front; ⌘T and a
split on an SSH pane pass that pane's remote cwd; a sleeping SSH tab keeps
its remote cwd in the session layout. The daemon's replay now sends the
remote context before the cwd, so a window that reattaches to an SSH pane
does not wipe the remote directory it was just told.

Refs #1028

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(ssh): a local shell standing in for a restored SSH leaf starts locally

pane_to_session now keeps a native SSH leaf's far directory, so the
session_to_pane fallback that brings such a leaf back as a local shell
(the redial failed, or its daemon pane is gone on reattach) would hand
that remote path to a local spawn. Pass no cwd there for an SSH leaf.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 15:02:22 +08:00
l0ng-ai 0277ca67dc Centre the title-bar search box; bring back auto-hiding title-bar buttons as an Appearance option (#1036)
* feat(settings): an Appearance option to show the title-bar buttons only under the pointer

26.9.2 painted the new-tab and sidebar tiles only while the pointer was
over the bar they sit in; 26.9.3 took that out so the buttons would stay
discoverable. Both are fair, so it comes back as a choice: Appearance >
"Show title bar buttons on hover" (`auto_hide_titlebar_buttons`), off by
default, which keeps today's always-visible bar for everyone who has not
asked otherwise. A config written before the key existed reads as off.

With it on, the rail's two tiles follow the rail, and the collapsed
rail's pair and the trailing panel toggle follow the tab strip. The
window mark stays put, the tiles keep their layout slot so a reveal
never shifts anything, and the title-bar search box is always drawn.
The trailing toggle stays painted while the detail panel is open, as
before, since the panel's own tab row beside it always is.

The reveal is the hover sheet from 26.9.2 — a transparent last child
over each region, because `group_hover` loses the region the moment the
pointer reaches an occluding tile. Resting tiles go to zero opacity
rather than `invisible()`: gpui skips a hidden element's paint pass,
which is where its click and accessibility actions are registered, so a
screen reader could find a hidden tile by label and then not press it.
Shortcuts are actions and never depended on the tiles.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(titlebar): centre the search box on the window, not the bar after the traffic lights

On macOS `TitleBar` leaves an 80pt lead for the traffic lights before
the tab strip — whether or not the rail stands in front of them — and
the Search Everywhere box was centred on the strip. So it sat 40pt right
of the terminal column's middle: with the rail collapsed, 40pt right of
the window's (#1033). Fullscreen added the bar's own inset on top.

The band the box centres in now reaches back over that lead, so its left
edge is the terminal column's on every platform (12pt elsewhere). Its
right edge is unchanged: the strip's end on macOS, the terminal column's
end beside a docked panel or document off it.

Reaching back puts the collapsed rail's tiles inside the band, so the
box now keeps an equal clearance at both ends — two springs with a
minimum width either side of it. In a narrow column it shrinks instead
of sliding under New Tab or the panel toggle, and stays centred while
it does. The geometry is a pure `search_band`, tested for the macOS
rail-collapsed, rail-open and fullscreen cases and off macOS.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(titlebar): clear a hover flag whose sheet is not on screen; document the key

A title-bar hover flag is written only by its sheet, and only when the
sheet sees the pointer cross its edge. Hide the rail from its own tile, or
turn the switch off mid-hover, and the sheet leaves the tree with its flag
still set: the next time it is built the tiles came back painted with
nobody pointing at them, until the pointer happened to pass through and
out again. Clear the flag of any sheet not built this frame.

Also list auto_hide_titlebar_buttons in the configuration reference.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 14:59:53 +08:00
l0ng-ai c0c6f90284 fix(chrome): the workspace tile points like the switcher rows it opens 2026-09-30 14:14:35 +08:00
l0ng-aiandClaude 4c8c317b91 feat(mobile): files, changes, a custom key bar, and a steadier connection (#1029)
The phone can now hand a pane a photo or file, read what an agent changed,
answer its prompts with a tap, and keep its link across leaving a pane.

Gateway and protocol:
- `Open::Upload` puts a file (up to 20 MB) in the directory the desktop
  keeps pasted images in, under a name a shell takes unquoted, and answers
  with its path. Panes on this machine only for now.
- `Open::Diff` answers with the working tree's changes against HEAD and its
  untracked files, for the directory a pane is in.
- Both are one-shot streams; an older gateway drops them unanswered, which
  the client reports as "update tty7".

App:
- Attach button in the message box: the uploaded path goes into the draft.
- Changes sheet from a pane's menu: a block per file, lines coloured.
- Settings → Key bar: remove, reorder and add keys, from a catalog or
  written out (`/compact\r`, `^C`), across pages; reset to the default.
- An agent's numbered choices show as buttons while it waits.
- Pinch to zoom, tap a link to open it, find in the scrollback, a Copy
  button for text a program copies (OSC 52), and an optional Face ID lock.
- Swipe from the left edge to go back; the iOS WebView has no page stack.
- One workspace at a time on a machine, picked from a row of chips.
- Agent avatars in their own colours.
- Each screen's watch is its own: a second watch no longer ends the first,
  which showed as "Can't reach" and a reconnect after leaving a pane.
- Dialing no longer holds the session lock, so Forget works while a
  machine is still connecting; its confirmation is an in-app sheet, since
  `window.confirm` shows nothing in the iOS WebView.
- iOS 15 minimum, as App Store Connect will require from April 2027.
- `scripts/testflight.sh` archives, signs for the App Store at export (the
  team has no devices for a development profile) and uploads.

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-30 12:30:04 +08:00
l0ng-ai e1ee74a379 fix(tabs): ⌘T on an SSH tab stays on its host; Switcher says Offline in words (#1031)
* feat(switcher): say Offline in words and dim the avatar; drop the link dot for a reachable workspace

The normal case carries nothing extra. An offline machine's row reads
"Offline" under the tab count, where Open and This window go, and its
avatar is dimmed. A dot stays only for states that want attention:
connecting, reconnecting, failed, or taken over by another client.

* fix(tabs): ⌘T on an SSH tab dials the same host and files the tab under it

A new tab from an SSH pane used to open a local shell in the default
directory, which landed in Ungrouped instead of under the host the user
was on. A native SSH pane now dials again with its spec, as ⌘D already
did; a shell that ssh'd onward from a local prompt gets a local tab that
types the same ssh command at its first prompt. Either way the tab is
seeded into the host's auto group before its pane reports in.
2026-09-30 12:29:56 +08:00