mirror of
https://github.com/l0ng-ai/tty7.git
synced 2026-10-07 00:02:06 +00:00
b65a3e4efc5c999d2f96d07ca4dbee2dd870a9fb
17
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
e60bf9f12c |
fix(mobile): resolve relays behind DNS that sets an EDNS Z flag (#1092)
simple-dns 0.12.0 reads the EDNS OPT record's TTL at the wrong offsets: it
takes the extended RCODE from the low byte, where RFC 6891 puts the DO/Z
flags. A resolver that sets a Z bit -- a Clash-style fake-IP DNS on the
router does -- turns every NOERROR answer into RCODE 16, so iroh resolves
nothing. The gateway never reaches a relay, pairing codes carry none, and
a phone off the LAN cannot connect ("It didn't answer").
Vendor simple-dns 0.12.0 with the offsets fixed and patch it in for both
the desktop and the mobile workspace. tests/edns_z_flag.rs drives iroh's
resolver against a nameserver that sets the flag, from the root package so
CI's default `cargo test` runs it and fails if the patch stops applying.
|
||
|
|
54978409c2 | chore(mobile): 0.1.4 (#1088) | ||
|
|
c5fe474125 |
fix(mobile): typing into a pane shows its cursor and what is being composed (#1084)
Tapping the terminal to type into it showed no cursor: xterm reports its cursor as shown and in place, but leaves it undrawn on the phone. And an input method's composing text — pinyin before a candidate is picked, dictation before it is done — lived only in the hidden field typing goes through, so nothing showed until it was committed, often only on Return. While the pane has the keys, the app draws the cursor itself, a blinking block at the pane's cursor cell, with the composing text underlined in front of it. A program that hides the terminal's cursor to draw its own (an agent's input box) gets only the composing text, where it lands. |
||
|
|
162a8e971a | chore(mobile): 0.1.3 (#1083) | ||
|
|
24c479c636 |
feat(mobile): close a pane; scroll full-screen programs; fix pinyin in the pane (#1065)
* fix(mobile): a swipe scrolls a full-screen program
A swipe over the terminal scrolled xterm's scrollback, and the alternate
screen keeps none, so over Claude Code's full-screen view, less or vim
it did nothing. On the alternate screen a swipe now turns the mouse
wheel instead, a notch a row, as on the desktop: a wheel report at the
finger for a program that asked for the mouse (SGR or the legacy
encoding, whichever it chose), arrow keys for one that did not.
* fix(mobile): pinyin keeps going when typing straight into the pane
Typing on the terminal itself goes through a hidden field, which was
emptied after every committed piece of text. iOS keeps its own copy of
the field's text, and a field cleared under it left the input method
stuck after the first character a pinyin composition committed. The
field now keeps its text while it has the keys and the pane is sent
what changed since the last send: characters taken off as DEL, then
what is new. It is emptied on blur.
While the field has the keys the pane's cursor is drawn solid, so a tap
on the terminal shows that it is ready to type into.
* feat(mobile): close a pane from the phone
The app could watch and drive a pane but never close one. Hold a pane's
row in the list, or pick Close pane from the terminal's menu: a sheet
says what will be stopped and on which machine, and only its danger
button closes it. From the terminal the app goes back to the list, which
drops the pane when the next tree arrives.
On the wire this is a new one-shot Open::ClosePane { pane_id, machine },
answered Ok or Denied. The gateway does what `tty7 pane close` does:
finds the workspace holding the pane, sends PaneClose, and hangs up the
panes it reports removed, on the gateway's machine or through the
desktop's existing link to a remote one. A gateway that predates the
variant drops the stream, which the app reports as "too old to close
panes from the phone".
|
||
|
|
3990a05795 |
Mobile: an iOS pass from a user's seat (#1075)
* fix(mobile): draw a prompt's icons
Prompts built with Powerline and Nerd Font glyphs (branch, folder, git
status) showed as empty boxes: a phone has no such font to fall back on.
Ship the symbols-only Nerd Font, one cell wide, behind Hack.
* fix(gateway): send a phone the screen the desktop shows
A phone opening a pane was sent its raw output, ring segment by segment,
and read it with xterm.js. Across the pane's resizes that emulator wraps
and reflows unlike the desktop's, so shells' SIGWINCH redraws landed on
the wrong rows: prompts twice, old output under new prompts. Leaving a
full-screen program left stale lines behind the same way.
The gateway now reads the pane with the desktop's emulator and, on
opening, after a resize, and when the main screen comes back, sends the
phone that screen drawn afresh: scrollback, colours, cursor and modes.
Output in between still goes straight through.
* fix(mobile): the message box rides the keyboard on iOS
On iOS 26 the WebView, run edge to edge, does not say how much the
keyboard covers, so the message box and the dock stayed under it. The
app now hears the keyboard's frame natively and lays out above its top
edge, on iOS as on Android.
- WebKit's previous/next/Done bar over the keyboard is gone; a tap on
nothing in particular, or on the pane, puts the keyboard away.
- Return sends however the keyboard delivers it.
- A shell's message box no longer capitalises or corrects: ls stays ls.
An agent's keeps both, as a chat would.
* fix(gateway): a tab opened from the phone joins its repository's group
The desktop files a tab under its repository as its sidebar draws it, so
a tab opened from the phone while that window was out of sight stayed in
Ungrouped. The gateway now reads, for a tab the desktop has not filed,
which repository its directory is in, the way the desktop would.
* feat(mobile): close a tab from the phone
Swipe a tab's row left for Close, or use Close tab in a pane's menu. The
tab goes where the desktop puts a closed tab, onto the workspace's
recently-closed list, so tty7 on the computer can reopen it. A tab whose
agent is at work asks first.
A new CloseTab stream carries it; a machine that keeps no closed tabs
closes it for good and its panes are ended, as tty7 tab close does.
* feat(mobile): a machine's list reads at a glance, and the app opens where it was left
- The app reopens the machine it was last on; leaving for the list of
machines is what makes it start there.
- A tab named after its directory goes by the directory's own name, its
parent underneath, rather than a path cut off at the end that matters.
An agent's row says where it works too.
- New tab asks which folder, from those the workspace has tabs in, the
tab in front first; Workspace is asked only when there is a choice.
- The back button names where it goes in full until the title folds in.
- Search fields have a clear button; a few machines need no search.
- Rows swipe left to close their tab, and a pane's menu has Close tab.
* fix(mobile): agents' marks draw, and Return sends a sentence
- Claude Code's ⏺ and ⎿, ⏵⏵, ⚙, ⏰, ✔, braille spinners and the like
showed as empty boxes: the phone's fonts do not reach a canvas for
them. Noto's symbols and outline emoji ship, cut down to those blocks
(about 80 KB), behind Hack and the prompt icons.
- The phone's keyboard reports Shift with Return whenever it has armed
a capital — at the start, after a full stop — so a message ending in a
sentence got a new line instead of being sent. Shift-Return starts a
line only on a keyboard with a real Shift; Return delivered as typed
text sends as well.
* fix(mobile): an agent's choices become buttons wherever they are on screen
The answers were looked for in the bottom 24 rows of the terminal, which
can be taller than the pane: Claude Code's question sat higher up and no
buttons came. The whole screen is read now.
* fix(mobile): a pane on its side keeps room for the pane
In landscape the bar, the key row, the page dots and the message box
left three lines of terminal. The bar slims and the keys and the message
box share a row, for eight. A message box's hint stays on one line, and
a row's hidden Close names its tab to VoiceOver.
* fix(mobile): Settings names the ⋯ menu with its own mark, and asks before clearing history
The phone's text font has no ⋯, so the note showed an empty box; the
menu button's icon stands in. Clearing the message history, which cannot
be undone, now asks first.
* fix(mobile): Changes shows the changed files, not just the untracked ones
The files' blocks shrank to nothing under a long list of untracked ones:
flex items that clip their overflow give up their height. They keep it
now, and the sheet scrolls. The untracked list sits flush and compact,
the top line totals the change, and lock files start folded.
* feat(mobile): pull a sheet down to put it away
Sheets showed a grabber but only closed from their × or the dimmed screen
around them. Pulled down — from the top, or from anywhere while their
content is scrolled to the start — they go; let go short of the way,
they settle back.
* fix(mobile): a machine that went away says so within seconds
The connection kept QUIC's default 30-second idle timeout, so a laptop
gone to sleep stayed "Direct · 1 ms" on the phone for half a minute, and
typing into it went nowhere without a word. The phone now gives up on a
silent machine after 12 seconds, a few keep-alives missed, says it
cannot reach it, and reconnects on its own once it is back.
* feat(mobile): keys and answers are felt
The key row, an agent's answer buttons and Send give the light tap the
phone's own keyboard does, and a row swiped far enough to open ticks as
it passes the point. Through the Tauri haptics plugin; nothing is felt
where there is no engine for it.
* feat(mobile): pair by pointing the phone's camera at the desktop's code
The pairing QR code reads tty7pair:…, and the app now answers to that
scheme: the phone's own Camera offers to open it in tty7, which pairs
straight away, as its Scan button does. No hunting for the button first.
* fix(settings): the pairing code can be read by the phone's camera
The phone app now opens from its tty7pair: link, so Show code says to
point the phone's camera at it first.
* fix(mobile): Android opens tty7pair: links too
The deep-link plugin's intent filter, written into the manifest by the
Android build.
* fix(mobile): pairing links without the deep-link plugin, cold launches included
The deep-link plugin's build script rewrites the iOS entitlements while
Xcode builds, which Xcode refuses ("modified during the build"), and a
link that launched the app was lost on the way in any case: UIKit hands
it to the first scene as it connects, and the event loop only passes on
links that come later.
- The tty7pair scheme is declared in Info.ios.plist and the Android
manifest, and links are heard as Tauri's own Opened event.
- The scene delegate's connect is wrapped, before UIKit starts, to keep
a launching link; the page asks for it once it listens, so neither
order of arrival loses it.
* feat(mobile): another agent waiting or done says so over the pane you are in
Inside one pane, nothing told you another agent on the machine had
stopped for an answer or finished its turn; you had to back out and
look. The pane now watches the machine's tree too, and such a change
drops a card over the top of the pane, felt as it comes — the agent,
what it says or which tab — that opens that pane when tapped. What was
already so when the pane opened is not news.
* fix(mobile): with the lock on, the app switcher shows no panes
The phone keeps a picture of an app as it leaves, for its app switcher.
With the lock on, that picture showed whatever pane was open. The app is
now covered as it goes, and uncovered — or locked — as it comes back.
* fix(mobile): turning the lock off takes Face ID too
Anyone holding the phone, unlocked, could switch the app lock off from
Settings. Off now asks for Face ID or the passcode, as on does.
* fix(mobile): a pane that is not running says so, with a way on
After the machine's server restarted, panes no window had opened since
were gone, and the phone tried to watch them forever: "Daemon refused
Observe: no such pane 9. Reconnecting…". The gateway now marks panes
its server is not running; the list shows them as Not running, without
their last agent status, and opening one says what is going on and
offers a new tab in the same folder.
* feat(mobile): a workspace not on screen shows when an agent in it needs you
The switcher's chip for another workspace carries the status dot a
folded group does, so an agent waiting there is not hidden behind the
one you are looking at.
* fix(mobile): a new tab's agent starts, instead of waiting at the prompt
Opening a tab for Claude Code or Codex typed the command as soon as the
pane was live, while the shell was still printing its greeting; the
Enter was eaten and the command sat at the prompt unrun. It is typed once
the shell's output has gone quiet now, or after six seconds whatever.
Rows also say where a tab is the same way whatever it is named.
* fix(mobile): the first screen says how to pair in one step
With no machine paired yet, it now says where the code is on the
computer and that the phone's camera reads it.
* fix(mobile): a tap that closes a pane's menu does only that
Closing the ⋯ menu by tapping the pane also brought the keyboard up for
typing into it. The tap that puts a menu away is the menu's now.
* fix(mobile): second pass from a phone user's seat
- Chinese, Japanese and Korean text rendered as boxes in the terminal:
the glyph atlas does not fall back past the web fonts, so the system's
CJK fonts are named in the stack.
- A tab opened from the phone was drawn at the desktop's width first and
then squeezed: the gateway now holds it at the phone's size from before
the desktop hears of it, until the phone's own view takes over.
- A tab opened with no folder started wherever the server did; it starts
at home, and the new-tab sheet offers Home.
- Going back to a machine showed a skeleton every time; its last tree is
drawn at once and refreshed when the watch reports.
- Errors said the transport's chain, repeated: each part is said once, and
an unreachable machine is explained in words.
- Wide panes say once that they can run at the phone's size; a pane taken
over is taken over again on return.
- Back in a pane's history, a button jumps to the latest output.
- Find hides the key bar and message box and keeps the match clear of the
bar; Copy keeps the pane's lines and offers Copy all.
- The message box pans a wide pane back to the cursor; Changes outside a
repository says so plainly; machine rows count waiting agents; the back
pill folds to a chevron with the title; filled reds use the system red.
* feat(mobile): attachments wait as chips beside the message box
A sent file used to drop its full temporary path into the box, five lines
of /var/folders/... underlined by the spell checker. It now waits as a
chip with its picture and name, can be taken back before sending, and its
path goes after the message when it is sent.
* fix(mobile): pairing says what went wrong, and leaves the code alone
The code field offered word suggestions over the keyboard; it is a code.
A wrong, expired or unreachable code is explained with what to do next
rather than the gateway's lower-case reason.
* feat(mobile): hold a tab's row for what can be done with it
A long press used to open the pane like a tap. It now brings up the
row's actions: open, open at the phone's size, Changes, a new tab in the
same folder, copy the folder's path, and close.
* fix(mobile): a pane on its way shows that it is coming
Opening a pane over a slow link left an empty screen until its replay
arrived. After a quarter second without it, three dots say it is coming.
* fix(mobile): agent menus, stopped panes and new tabs, as used
- An agent's arrow-key menu with no numbers (Claude Code's 'trust this
folder?') now gets answer buttons too; picking one moves to it and
presses Enter.
- A pane that is not running greys out its keys and message box instead
of taking typing that goes nowhere.
- Suggestions match where a word starts, so 'ls' no longer offers every
message that mentions tools.
- A new tab's starting size counted neither the status bar nor the home
indicator, so its last rows sat under the key bar.
- A tab opened on the phone keeps the phone's size on later visits, so it
follows the keyboard instead of hiding behind it.
* fix(mobile): another agent waiting is not missed, and dismissing is only that
- The card for another agent that needs you stays until it is answered or
put away (it went after 15 seconds); a finished one still goes on its
own. While any other agent waits, the back button carries a dot.
- The card's dismiss, a banner's action and Jump to latest took themselves
away under the finger, and the same tap then reached the pane and
brought up its keyboard; a clear cover takes that tap now.
- A row's Current tag no longer gets cut to 'C...' by a long name.
* fix(mobile): Changes lists a new folder once, by name
The untracked list walked into every new directory — a generated folder
filled the sheet with thirty truncated paths. New directories come as one
entry, as git status shows them, and each entry reads as a name with the
end of its folder beside it.
* fix(mobile): bar buttons answer a 44pt square
Back, More, Close and the pane's round buttons are drawn at 38pt and took
taps only there, under the 44pt a finger is owed. Each now answers a 44pt
square around the same drawing.
|
||
|
|
99b9327fab |
feat(mobile): the desktop sidebar's groups, and the tab it has in front (#1073)
* feat(mobile): the desktop sidebar's groups, and the tab it has in front A machine's tabs on the phone were one flat list per workspace. They now come in the desktop's groups, in its order: pinned groups, then one per repository or SSH host, then Ungrouped, each folding as on the desktop. The tab the desktop has in front reads Current. The gateway places each tab as the sidebar does, from what the machine tree already keeps: a tab's pinned group, or else the repo the desktop last filed it under. The naming rules moved from the sidebar into tty7-core so both name groups alike. An older gateway sends no groups and the phone shows one list, as before. * fix(mobile): group headers lead, and folded ones stack close A group's header read the same as the workspace label above it, and a folded one kept the gap meant for rows under it, so folded groups sat far apart. Headers are now the darker, larger line at a tap target's height; only an open group keeps room after its rows. |
||
|
|
d7dad45fa8 |
fix(gateway): reach the relay through a proxy when that is the only way out (#1058)
* fix(mobile): bump iroh to 1.3.0 so a stuck relay cannot stall direct dials iroh 1.2.0 sends a connection's first datagrams to every known path one after another inside the remote-state actor, awaiting each. When the relay is unreachable its send queue fills and the actor blocks, so handshake packets for a direct path that does work (a mesh VPN address, a public IPv6) queue behind it and the dial times out. 1.3.0 sends to all paths concurrently with a bounded wait (n0-computer/iroh#4512). The desktop workspace was already on 1.3.0; the app has its own lockfile and was left behind. * fix(gateway): reach the relay through a proxy when that is the only way out iroh dials its relay with its own resolver and its own TCP, ignoring the system proxy. On a machine whose network only works through a local proxy (Clash and the like, system-proxy or TUN mode alike) that dial never succeeds, and nothing says so: phones on the same network still connect, while a phone on cellular times out, because without a relay nothing coordinates hole punching and the home router drops unsolicited inbound packets. The gateway now lists the ways out it knows of, most likely first: tty7's own http_proxy setting, the system proxy, the environment's, then direct. It starts on the first without waiting, and when the relay stays unreachable for 10s it tries the others on a throwaway endpoint, switching to the first that reaches a relay (same key, same port, so pairing codes keep working). While none does, it looks again every minute. A pairing code now names the relay only once it is actually connected; before, it named whichever relay iroh picked by latency, reachable or not. The platform proxy readers in daemon::install::proxy now also hand back the proxy as a URL, for a client that is not ureq. Claude-Session: https://claude.ai/code/session_018wE9ZRyxgWW2f55VSy9FvZ |
||
|
|
ce56e1674a | chore(mobile): 0.1.2 (#1052) | ||
|
|
f6c866c53c |
fix(mobile): the Android app icon is tty7's, not the placeholder (#1051)
android init left the Android project on the template's icon. It is now an adaptive icon: the mark on a transparent layer, sized inside the safe circle any launcher mask keeps, over the tile's colour, with square and round ones for older launchers. Drawn from the same mark as the iOS icon; icons/android keeps the same files. |
||
|
|
f85c0fee76 |
fix(mobile): number TestFlight builds in UTC (#1050)
A laptop in UTC+8 numbered its builds eight hours ahead of CI, so a CI upload of the same version within eight hours of a local one came out lower and would be refused. |
||
|
|
0a47cada12 |
ci(mobile): release iOS and Android together from one tag (#1048)
A `mobile-v<x.y.z>` tag now ships both platforms at one version: the Android APK to a draft release as before, and an iOS build to TestFlight. iOS no longer depends on one machine signed in to Xcode. - The version is tauri.conf.json's; a tag that disagrees with it fails the run, so the repo always says what shipped. Set to 0.1.1, the Android build already out. - scripts/testflight.sh signs and uploads with an App Store Connect API key when ASC_KEY_ID and ASC_ISSUER_ID are set, with a certificate Apple keeps in the cloud. That needs an Admin key. - A manual run builds both and uploads nothing. |
||
|
|
0c2033ab07 |
feat(mobile): run on Android, and release a signed APK (#1044)
* feat(mobile): run on Android The app builds and runs on Android, and fits there. - Back button and gesture close what is open over the screen, then go back a screen, and from the first one send the app to the background. Left to the WebView they closed the app, since it has no history. - The system bars: the page asks their size of the app (`insets`, over JNI), since WebViews before 140 report the safe areas as 0 even edge to edge. The CSS reads them as `--inset-*`, which iOS still fills from `env()`. - The keyboard: edge to edge, the WebView is not resized for it and its visual viewport stays whole, so the keyboard covered the message box. MainActivity hands its height to the page, which lays out as on iOS. - The title folds into the bar from the scroll position on every screen. The observer it used reported a title in plain view as out of sight on Android, so the bar started folded. - src-tauri/gen/android is kept in the repo for that MainActivity. * ci(mobile): release a signed Android APK A `mobile-v<x.y.z>` tag builds the app for arm64 at that version, signs it with the release key and attaches it to a draft release. The mobile app is versioned apart from the desktop's `v*` tags. - The release is never marked latest: the desktop updater reads /releases/latest and would take it for a desktop release. - The APK's certificate is checked against the release key's, since one signed with another key could not be installed over earlier ones. - The NDK is pinned, and the version must be x.y.z: Tauri derives the versionCode from it, and Android installs over a build only when that is higher. - Gradle signs a release build when keystore.properties names a key; CI writes it from secrets. - The release library is stripped: 30 MB to 20, the APK 32 to 23. * ci: tell people how to install the phone app The nightly release notes and each mobile-v release now say how to get the app on a phone: the TestFlight link for iPhone, and the newest mobile-v release's APK for Android. Both read .github/mobile-install.md. |
||
|
|
0701278fe9 |
fix(mobile): the list fades out under the floating search bar (#1039)
Rows scrolled under the floating bar showed through sharp and cut in half in the gap beneath it. A scroll-edge fade from the bar down to the screen's edge softens them into the canvas, as the system's own bars do. Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS |
||
|
|
ed87bd39b6 |
fix(mobile): testflight.sh puts the tty7 icon back after ios init (#1038)
`tauri ios init` fills the asset catalog with Tauri's placeholder icon, so a regenerated gen/ shipped build 0.1.0.9 with the wrong icon. Copy src-tauri/icons/ios over it on every run. Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS |
||
|
|
4c8c317b91 |
feat(mobile): files, changes, a custom key bar, and a steadier connection (#1029)
The phone can now hand a pane a photo or file, read what an agent changed, answer its prompts with a tap, and keep its link across leaving a pane. Gateway and protocol: - `Open::Upload` puts a file (up to 20 MB) in the directory the desktop keeps pasted images in, under a name a shell takes unquoted, and answers with its path. Panes on this machine only for now. - `Open::Diff` answers with the working tree's changes against HEAD and its untracked files, for the directory a pane is in. - Both are one-shot streams; an older gateway drops them unanswered, which the client reports as "update tty7". App: - Attach button in the message box: the uploaded path goes into the draft. - Changes sheet from a pane's menu: a block per file, lines coloured. - Settings → Key bar: remove, reorder and add keys, from a catalog or written out (`/compact\r`, `^C`), across pages; reset to the default. - An agent's numbered choices show as buttons while it waits. - Pinch to zoom, tap a link to open it, find in the scrollback, a Copy button for text a program copies (OSC 52), and an optional Face ID lock. - Swipe from the left edge to go back; the iOS WebView has no page stack. - One workspace at a time on a machine, picked from a row of chips. - Agent avatars in their own colours. - Each screen's watch is its own: a second watch no longer ends the first, which showed as "Can't reach" and a reconnect after leaving a pane. - Dialing no longer holds the session lock, so Forget works while a machine is still connecting; its confirmation is an in-app sheet, since `window.confirm` shows nothing in the iOS WebView. - iOS 15 minimum, as App Store Connect will require from April 2027. - `scripts/testflight.sh` archives, signs for the App Store at export (the team has no devices for a development profile) and uploads. Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
24cf458e3b |
feat(mobile): a phone app to watch and drive tty7 panes (#983)
* feat(mobile): a gateway that lets a paired phone reach this machine over iroh
The first half of the mobile app: everything on the desktop side, plus the
client library the app will link.
- tty7-mobile-proto: the phone<->gateway wire protocol. One stream per purpose
(pair, control, pane), framed like the daemon's frames, with raw terminal
bytes kept out of JSON. No tty7-core, so it cross-compiles for iOS/Android.
- tty7-gateway: dials nothing, accepts phones over iroh (hole punching, relay
fallback, end-to-end encrypted), checks the peer's key against the paired
device list, and bridges to the daemon. Panes are observed, not attached,
and keystrokes go in through SendInput, so a phone never resizes a pane or
takes it away from the desktop window. `pair` prints a one-time QR code.
- tty7-mobile-client: the phone side (pair, tree, pane streams, direct/relay
and RTT for the link), plus a `probe` example that stands in for a phone.
Verified against a real, isolated daemon: pair, tree, and typing into a pane
over a direct path, ~0.8 ms median echo on loopback.
* feat(mobile): the Tauri app — pair, browse the machine, drive a pane
The phone half, as a Tauri 2 app in mobile/ (its own cargo workspace, so the
desktop build and CI never compile a WebView stack).
- Rust side: the phone's iroh endpoint and key, paired machines, and every
live stream, behind eight commands. Terminal output crosses to the WebView
as raw ArrayBuffers on a Tauri channel, batched per frame, in order with the
pane's JSON events.
- Frontend: vanilla TS + xterm.js. Paired machines and pairing; one machine's
workspaces, tabs and panes with agents that need you pinned on top and the
link's direct/relay path and RTT in the header; a terminal that fits the
desktop pane's width, with an esc/tab/ctrl/arrows key bar. Coming back from
the background re-watches and re-opens, relying on the daemon's replay.
Verified as a macOS build against a live gateway and an isolated daemon:
paired from the app, tree rendered on a direct path, keystrokes and key-bar
arrows reached the pane. iOS/Android builds need Xcode / the Android NDK,
neither of which is on this machine; mobile/README.md has the steps.
* fix(gateway): one serve per machine, and say how to start a missing server
- `serve` takes an exclusive lock on <config dir>/mobile/serve.lock. A second
gateway on the same key is a second endpoint answering to one address, so a
phone reached whichever the network picked. It is now refused, naming the
pid that holds the lock.
- With no tty7 server running, phones and the terminal both hear "tty7 isn't
running on <host> — open tty7 there, or run `tty7 server start`" instead of
"lost the tty7 server: No such file or directory". `serve` checks once at
startup, and still starts, since tty7 may be opened after it.
* feat(mobile): redesign the app as a native-feeling, minimal UI
The first cut read as a web page of bordered boxes. This rebuilds it the way a
phone app moves and reads, in the desktop tty7's own look:
- Screens push and pop with View Transitions; large titles fold into the bar.
- Grouped inset lists on a tinted canvas, following the system Light/Dark with
the desktop presets, accent and ANSI palettes. Hack for code and terminal.
- Panes are listed by tab, one card per workspace, with the desktop's agent
avatars and status badges (Waiting hollow, Working blinking) and its words.
- Pairing is its own screen, with steps, a Paste button and inline errors.
- A machine that stays silent for 10 s says so and offers to pair again; an
offline notice says what to check.
- The terminal header shows live/offline in words. A pane too wide to read is
shown at a readable size and pans to follow the cursor, with a toggle to fit
the whole width. The key bar has drawn icons, puts left/right first, and
has a keyboard toggle.
PRODUCT.md and DESIGN.md record the product facts and the design system.
* feat(mobile): open a new tab from the phone
Each workspace on a machine's screen gets a "New tab" action. It starts a
shell at the end of that workspace, in the directory its last tab is in, and
opens it straight away.
- Protocol: a one-shot `Open::NewTab { workspace_id, cwd, size }` stream,
answered with `Ok` and a `TabCreated { tab_id, pane_id }`, or `Denied`.
It is additive, so the protocol version stays. A gateway from before this
drops the stream unanswered, and the app says to update it.
- Gateway: takes the same two steps as `tty7 tab new`, spawning a shell owned
by the workspace and then TabCreate. The shell starts at the grid the phone
asked for, because no desktop window is showing it yet. Sizes are clamped.
- App: a `tab_new` command, with the size worked out from the screen at the
readable font size.
- probe: `newtab <workspace-id> [cwd]`.
* feat(mobile): reach the machines the desktop is linked to over SSH
A machine's screen now lists, under its own workspaces, every machine its
tty7 holds an SSH link to, with that machine's workspaces. Panes there open,
take input and get new tabs like local ones. "Needs you" gathers panes from
all of them.
- The gateway routes through the local server over links it already holds,
the same way `tty7 -m <machine>` does. It never dials a down link, because
that would guess at credentials the phone does not have. A down link
shows as "Link down", with a note to reconnect it on the desktop.
- Protocol, additive: `Tree.remotes`, and an optional `machine` (the link
key) on `Open::Pane` and `Open::NewTab`. A local pane is asked for exactly
as before, so older gateways still understand it.
- Rebuilding a route target from a link key moves from the CLI into
tty7-core as `RouteInfo::target` / `RouteInfo::host`, so the CLI and the
gateway share one rule. The CLI now calls it.
* perf(gateway): read linked machines in parallel, never waiting on a slow one
Linked machines were read one after another on every tree poll. One slow
SSH link, whose requests can take 10 s, stalled the whole tree for every
phone, local workspaces included. It also held a lock that queued pane
opens, input and new tabs on every other link.
- Each linked machine is read on its own thread (`poller::Poller`). A poll
waits at most 250 ms. A machine that has not answered is reported as it
last was, and its read lands for the next poll. Only one read is in flight
per machine, however many phones are watching. A machine that drops off and
comes back cannot receive a stale read, because each slot has a generation.
- Routed control connections are locked per machine, not all together.
- A link that is up but has not answered its first read is sent as
`RemoteView.pending` (additive). The app shows "Reading…" with skeleton
rows instead of claiming the machine has no workspaces.
* fix(mobile): keep reaching the computer after the gateway restarts
Every `serve` bound a random port, so a restart left each phone holding
addresses that no longer answered. Where the n0 relays are unreachable, which
is common behind the Great Firewall, the phone had no other way to find the
gateway until it was paired again.
- `serve` listens on the same UDP port every time. It picks one on first run,
keeps it in `<config dir>/mobile/port`, and moves only if the port is taken.
IPv6 binding may fail, as in iroh's own defaults.
- Both ends add mDNS lookup (`iroh-mdns-address-lookup`, service `_tty7._udp`).
On the same network a phone finds the gateway by key when its addresses are
stale, such as after a new DHCP lease or a new IPv6 prefix. The gateway
advertises and the phone only listens. If multicast is refused, each side
starts without it and says so, rather than failing.
- iOS: `Info.ios.plist` declares the local-network use and the Bonjour
service, without which iOS blocks multicast.
- An ignored test (`--test mdns`) connects by key alone over mDNS, for a
machine that allows multicast.
* feat(mobile): run the gateway in the desktop daemon, paired from Settings
Phone access no longer needs `tty7-gateway serve` in a terminal.
Settings → Mobile switches it on, and the local daemon runs the gateway from
then on, with every window closed as well. That is where the panes a phone
reaches live anyway.
- Settings → Mobile, in all three locales:
- an "Allow phone access" switch;
- a status line (running, starting, off, or why it failed);
- "Show code", which draws the QR code and the tty7pair: code with a
Copy button, and closes on its own once a phone uses it;
- the paired phones, each with Unpair.
The section is in search, including by its config key `mobile_access`.
- The daemon (`tty7-app --daemon`) runs a supervisor (`core::mobile`). It
watches `mobile_access` in config.json, re-reading only when the file
changes, and starts or stops the gateway. A failed start is retried every
30 s and logged once.
- tty7-gateway grows a `service` module: `start()` returns a stoppable
handle, and `pair_code()` makes a code. The CLI's `serve` and `pair` are
thin wrappers over them now. The gateway logs through `log`, so the
daemon's output lands in its log file, and it reports itself in
`mobile/status.json`. `State::serving()` checks the lock, which a crash
cannot leave stale. A gateway that cannot take the lock leaves the
status alone, because it belongs to the one holding the lock.
- iroh is linked into the GUI binary only. tty7-server stays the lean static
binary pushed to remote machines.
* feat(mobile): serve phones whichever daemon is running
A daemon started by `tty7 server start` is the lean tty7-server, which
carries no gateway. With phone access on, the Settings status stayed on
"Starting…" and no phone could connect.
The GUI now checks, 5 s after it starts and whenever phone access is
switched on. If nothing is serving, it starts `tty7-app --mobile-gateway`,
detached the same way as the daemon (`spawn::detach_helper`). The helper
serves until the switch goes off, and exits at once if another process
already holds the gateway lock. When the daemon's own gateway is up, no
helper is started. The helper logs under its own role, "mobile".
* refactor(mobile): the daemon owns the gateway, as a child, whoever started it
There were two ways of running the gateway: a thread inside `tty7-app
--daemon`, and a detached helper the GUI started when the daemon could not.
That is now one way.
Every daemon, whether `tty7-app --daemon` or `tty7-server`, runs
`tty7_core::daemon::mobile::supervise` from `run_with`. While
`mobile_access` is on it keeps the gateway running as a child process, and
stops it when the switch goes off.
- Which program: `tty7-app` runs itself as `--mobile-gateway`. `tty7-server`
runs a `tty7-gateway serve --exit-with-stdin` from beside it or on PATH,
and links nothing new. Without one, it writes the reason into
`mobile/status.json` for Settings to show, instead of "Starting…" forever.
- Lifetime: the child's stdin is a pipe from the daemon, and the gateway
exits when it closes. A stopped, crashed or handed-off daemon (the pipe
is close-on-exec) takes its gateway with it, and the next daemon starts
one from its own binary. No gateway from an older build survives an
update.
- Isolation: iroh no longer runs inside the process that holds every pane.
- `Status` moves to tty7-core, the one definition that the daemon, the
gateway and the GUI all share.
- Gone: the GUI's helper check (`core::mobile` in the app) and the in-daemon
gateway thread.
* fix(mobile): stop and reap the gateway before a daemon handoff
Found by running a real `tty7 server restart`. The old gateway did exit,
because the new image's supervisor started its own gateway and the old one
lost the lock. But it was left as a zombie: the image after the exec never
reaps a child it did not start, so each handoff leaked a process entry.
`hand_over` now calls `daemon::mobile::stop_for_handoff` before the exec,
which closes the gateway's stdin and waits for it. A flag keeps the
supervisor from starting another in the moments before the exec, and
`handoff_failed` clears the flag if the exec never happens, so the daemon
goes on serving.
Checked with two handoffs in a row (tty7-app → tty7-server → tty7-server):
- each old gateway was reaped, with no zombies system-wide;
- exactly one fresh gateway was running after each handoff;
- the pane's shell and its environment survived;
- the probe phone kept working.
* feat(mobile): the switch shows whether phones can reach you, not a status row
Settings → Mobile had an "Allow phone access" switch that showed intent and a
separate Status row that showed reality. That is one thing shown twice, and
the switch could sit on while nothing was running.
- The switch is the state. Switching on holds it at "Starting…", disabled,
until a gateway is actually serving. If the daemon reports a failure, or
nothing comes up within 15 s, the switch goes back off, `mobile_access`
is reverted, and a notification says why.
- If the page opens on a failure the daemon is still retrying, the switch
shows off with the reason in its description, and switching it on
retries.
- The Status row is removed, with its four strings. There are two new
strings for the failure, in en, zh and ja.
Also fixes the Settings window never showing notifications. It is a `Root`
like the workspace window but did not draw the notification layer, so any
toast pushed from Settings was queued and never shown. That included the
existing "Set as Default Terminal" result.
Checked in a dev instance. On a tty7-server daemon with no tty7-gateway:
Starting… first, then off, with "Phone access could not start: … no
tty7-gateway beside it or on PATH". On a tty7-app daemon: on, with Show
code enabled and no toast.
* feat(mobile): drop the "Needs you" section
The machine screen gathered every pane whose agent was waiting or done into
a "Needs you" section above the workspaces. Done lasts until the next prompt,
so the section grew with every finished agent and mostly held panes that
needed nothing.
Panes now appear once, in their own workspace. Each keeps its status badge
and words ("Needs input", "Working", "Done") and the agent's message.
PRODUCT.md and the design sidecar are updated to match.
* fix(mobile): say when typing doesn't reach the pane
The gateway's input thread gave up silently on a failed send_input, and
the app's input task did the same on a failed write, so the phone kept
showing a live pane while keystrokes went nowhere. Both now report the
failure as a pane error. Keys after it are dropped rather than ending
the stream, which the phone would read as the pane closing.
* feat(mobile): a compose box, paste and Shift+Tab on the terminal
Replying to an agent meant typing into xterm a character at a time,
without autocorrect, dictation or a usable IME. The compose box is a
real text field: Send types the text and then Enter, as its own write,
and several lines go in as one bracketed paste when the program asked
for it. Drafts survive leaving the pane and a send that failed. An
agent's pane opens on the box with the keyboard down.
The key bar gains Shift+Tab (Claude Code's mode switch) and a paste key.
A failed keystroke now takes the pane offline with a Reconnect banner
instead of being swallowed.
* feat(mobile): reconnect on its own, and select text to copy
A dropped pane or machine stream is retried with backoff (1s, 2s, 4s …
15s) and at once when the network comes back, rather than waiting for a
tap on Reconnect. The pane keeps its last screen up until the new
replay starts, and output or errors from a replaced stream are ignored.
Touch selection does not work in xterm, so a copy key lays the whole
buffer out as plain text over the pane, wrapped to the phone and joined
where the terminal wrapped, for the phone's own selection and Copy.
* feat(daemon): size leases, and Take Back on the desktop
An observer can now run a pane at its own size (ClientMsg::Lease, feature
size-lease). The pty and every observer go to that size. The controller
keeps its grid, its resizes are remembered rather than applied, and the
pane goes back to the last of them when the lease ends: the observer lets
go, its connection closes, or the controller takes it back.
A controller hears about leases only after asking (Watch), since an older
client cannot decode DaemonMsg::Lease. The desktop asks on every attach,
spawn and relink where the daemon advertises the feature, locally or
through the host hello for remote workspaces, and shows the pane as in
use on the phone with a Take Back button.
* feat(mobile): take a pane over at the phone's size
The terminal's phone button asks the gateway to run the pane at the
phone's grid (PaneRequest::TakeOver), which it turns into a size lease on
the observer connection, named after the paired device. The grid follows
the keyboard and rotation; leaving the pane, or the connection dropping,
gives it back. When the desktop takes it back the app says so and offers
to take it over again, never doing it on its own. A daemon too old for
leases is reported, and the pane keeps working.
* fix(mobile): link SystemConfiguration and install a rustls provider on iOS
The first iOS build failed to link: netdev and system-configuration, pulled
in by iroh, need SystemConfiguration.framework, which the generated Xcode
project does not list. bundle.iOS.frameworks adds it on `tauri ios init`.
Once linked, the app panicked at launch: iroh builds its reqwest client with
`rustls-no-provider`, so a process-wide crypto provider must be installed
before any client is built. Install ring's, which is already in the tree.
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(mobile): keep the terminal's scrollbar on screen while panning
Panning a pane wider than the phone scrolled xterm's own box sideways with
the text. The box was only the view's width, so its vertical scrollbar
panned off with the columns and its scrollback stopped taking touches past
the first screen. The box now spans every column, and the bar is shifted
to the visible right edge as the view pans.
The bar is also drawn like the indicator WebKit shows for the pan, thin,
rounded and translucent, instead of VS Code's 14px square slider, so the
two axes match.
Co-Authored-By: Claude <noreply@anthropic.com>
* feat(mobile): pair by scanning the QR code, and Enter and quick-answer keys
Pairing took a pasted `tty7pair:` code, which on a real phone means getting
text off the desktop somehow. A Scan button next to Paste now reads the QR
code tty7 shows, through tauri-plugin-barcode-scanner, and pairs straight
away. The camera runs behind the WebView with our own viewfinder and Cancel,
since the plugin's full-screen view has no way out. The plugin is registered
on phones only, so the desktop dev build is unchanged.
The key bar gains Enter, so an agent's highlighted choice can be confirmed
without raising the keyboard, and 1 2 3 y n for numbered choices and y/n
prompts.
Co-Authored-By: Claude <noreply@anthropic.com>
* chore(mobile): sign for the App Store and declare exempt encryption
Sets the development team so `tauri ios init` writes it into the Xcode
project, and marks the app's encryption (standard TLS/QUIC only) as exempt
so TestFlight uploads skip the export-compliance question.
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(mobile): count the iOS safe areas once
The WKWebView's scroll view inset its content by the safe areas, and the
page, laid out with viewport-fit=cover, padded by env(safe-area-inset-*)
as well. The viewport came out 778pt tall on an 874pt screen: everything
sat a status bar's height too low, with a blank band under it. The scroll
view's automatic inset adjustment is now off, so the page runs edge to
edge and its CSS alone keeps clear of the status bar and home indicator.
Co-Authored-By: Claude <noreply@anthropic.com>
* feat(mobile): the Terminal Mobile redesign
The app takes the desktop's neutral greys, light and dark, with ink rather
than a system blue for what is pressed or chosen.
- Machines: pairing's "+" moves to a floating bar at the bottom beside a
search field. Each machine shows its link, round trip and tab count as
last seen.
- A machine: tabs grouped by workspace with a count; round agent glyphs;
a dot on the right for running or waiting on you. The per-group New tab
buttons give way to one "+" in the same floating bar, beside tab search.
- New tab: a sheet to pick Claude Code, Codex or a shell, and the
workspace. An agent's command is typed into the new tab once it is live.
- A pane: the bar keeps only back, the title with its state, and a menu
for selecting text, the fit and the phone's size. Under it, one row of
equal keys, a page at a time, and a message box that is always there;
its round button sends, or when empty hands the keyboard to the
terminal.
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(mobile): the tty7 mark as the iOS app icon
The phone showed Tauri's default icon: `tauri ios init` filled the Xcode
project with it. The committed icons/ios set was drawn on the macOS grid,
a rounded tile inset on transparency, which iOS would shrink inside its own
mask with a pale border. icons/app-icon-ios.svg is the same Duo mark full
bleed, rendered without alpha as the App Store requires.
Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
* fix(mobile): typing, scrolling and pairing on a real phone
- Typing into a pane: an input method's text never reached it, since iOS
never commits a candidate into xterm's hidden textarea. Tapping the
terminal now focuses a plain field of our own, whose committed text goes
to the pane as it is committed. Backspace on the empty field, Enter, Tab
and the arrows go as the terminal's keys.
- xterm sends nothing itself any more (disableStdin). That also stops the
phone answering a program's colour and device queries: the desktop
answers those, and the phone's late second answer landed in the shell as
typed text.
- Scrolling the scrollback: xterm 6 has no working touch scrolling. A
mostly vertical swipe now scrolls the buffer a row at a time and coasts;
a sideways one is left to the native pan.
- Pairing: the steps name the desktop's Settings -> Mobile, Allow phone
access and Show code, not a command-line gateway, and so do the notices
when a machine cannot be reached.
Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
* fix(mobile): room for the keyboard, and smoother vertical scrolling
- The keyboard: the WebView runs edge to edge and is not resized for it,
so it covered the dock and the pane's last lines. The app now takes the
size of the visual viewport, drops the home indicator's gap while the
keyboard is up, and keeps the cursor's line in sight.
- Scrolling: the terminal draws with xterm's WebGL renderer, which a
scroll does not make lay every row out again. A swipe is applied once a
frame, and moves the view by pixels: xterm scrolls whole rows, and the
rest of a row is a GPU shift of the drawn screen, put on together with
the rows it goes with.
Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
* feat(mobile): settings, message history, and a tighter home screen
- Settings, from beside the Machines title: appearance (automatic, light,
dark; the status bar and keyboard follow through the window's interface
style), terminal text size, how a pane wider than the phone first shows,
clearing the message history, and the version.
- The message box keeps what it sends on the phone. As a message is
written, past ones that match take the key row's place; with the box
empty, a History button opens them all, searchable. A line that asks for
a password is sent but not kept.
- ^R on the third key page, for the shell's own history search.
- A top-level screen's bar floats over the list, clear until the title
scrolls under it, so the large title sits just under the status bar.
Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
* fix(mobile): a fitted pane fills the view, and its scrollbar drags
- A pane shorter than the view (a wide one, fitted) no longer leaves the
bottom of the screen blank: the terminal here runs as many rows as fill
the view, the extra ones holding the pane's earlier lines, and what is
left over goes above so the prompt stays next to the keys. The pane on
the desktop keeps its size.
- A drag that starts on the scrollbar is left to xterm. The swipe handler
took it too, the other way round, and the two cancelled out.
Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
* fix(mobile): errors say what to do in the app, not on the command line
The messages a phone shows, and the two Settings → Mobile can, named the
gateway process, the CLI's `tty7 server start`, the transport and a lock
file's path. They now speak of tty7 on the computer and of pairing: open
it there, update it, pair again, quit the other copy.
Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
* style: rustfmt the gateway and mobile client
Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS
---------
Co-authored-by: Claude <noreply@anthropic.com>
|