On Linux the Keybindings page wrapped action names one to three CJK
glyphs per line and spilled them over the rows below, even though the
keycaps beside them left plenty of room. The label was a shrinkable
block sized to its own measured text, so any layout pass that measured
it narrower than it finally ended up left its painted lines wrapped at
that narrower width.
An action name is a single line: make it nowrap, and beside the keycaps
let it take the space they leave (flex_1) instead of sizing to its text,
so neither its box nor its lines depend on that measurement. Stacked
rows keep the whole row for the name as before.
The Agents half of the report (a long Codex install-failure note
squeezing the agent name to a glyph per line) is #897, already fixed on
main by #898 and not yet in a stable release.
A native SSH pane is owned by this machine's daemon, so its paths are
kept away from every Host call and it never gets a git_status_cwd. The
sidebar only grouped from git_status_cwd, which left every native SSH
tab in Scratch under repo-or-directory grouping, even though the remote
shell reports its cwd over OSC 7.
Fall back to that reported cwd for native SSH panes (absolute POSIX
paths only) and resolve it as a settled 'no repo': repo-or-directory
files the tab under the folder, repo grouping keeps it in Scratch.
Typed 'ssh' and WSL panes are unchanged.
Fixes#891
A pane running wsl.exe reports its cwd as a POSIX path from OSC 7, but its
host is this machine. The Files panel rooted the tree at that path verbatim
and handed it to the local read_dir, so on Windows /home/me was read as
C:\home\me and the panel showed "Could not be read"; drops into the tree
failed the same way since they target the rooted directory.
Root the tree at TerminalView::files_cwd instead: a cwd the pane's host
resolves is used as-is, a WSL pane's POSIX cwd goes through the distro's
\\wsl$ share (the same mapping Tab completion already uses), and a cwd no
host here can read (a shell ssh'd onward) roots nothing instead of an
unreadable directory.
#827 stopped a declined prompt from being asked again, but left the
prompts themselves with no notion of whether anyone was still waiting on
them. A routed auth prompt sat in the mailbox, in the parked queue behind
the sheet on screen, or on screen itself, until somebody answered it —
even after the connection attempt that raised it had timed out and moved
on. Answering it sent the secret into a dropped channel.
That is the report's sequence. A link drops while nobody is at the
keyboard; each reconnect attempt raises a password prompt and times out
unanswered, and before #827 the supervisor dialled again and again, so one
dead prompt per attempt piled up behind the first sheet. The user comes
back, types the password into a sheet nobody is listening to, the next one
comes up, one of them happens to be the live attempt and connects — and
the dead ones keep coming up however they are closed. #827 ends the
attempt loop on a timed-out password, but a key passphrase declined by
timeout still falls through to other methods and a transient failure, and
a single stale sheet is still left on screen either way.
A PendingAuth now carries a weak handle whose only strong count lives in
the responder for as long as it waits, so it can say when it has been
abandoned. The pump drops abandoned prompts instead of raising or parking
them, and takes down an on-screen routed sheet whose asker has gone,
moving on to whatever else is asking. The GUI also waits no longer than
the daemon's handshake does (the broker's 120s rather than 180s), so the
sheet comes down when the attempt behind it actually fails, not a minute
later.
Un-zoom routed focus through the tab's `last_focused`, which only
focus-in writes, so any gap between that record and the pane actually
zoomed put the cursor in a different pane when the split came back.
Since #843 the record is kept current on focus-in, which is why the
reported sequence no longer reproduces on main, but the zoomed pane is
the answer outright: hand it to the tab before focusing, so un-zoom no
longer depends on the record having caught up.
Zooming with focus off the panes (a palette just closed, the tab strip)
also zoomed the tab's first leaf rather than the pane the tab
remembers; it now falls back to `focus_target`, the same pane a switch
back to the tab would focus.
The last two passes at the avatar — a flat theme disc, then a bare mark
painted in the brand colour — each gave something up the solid disc had:
the flat disc lost the hue that tells one agent from another down a
column of rows, and the bare mark read lighter and less settled than the
disc beside the status dot. Neither was better than where it started.
Back to a solid fill of the agent's brand with the mark in its own ink,
and the hairline `needs_edge` adds for Codex and Grok's pure black on a
dark window. The shell avatar goes back to its muted disc. `mark_ink`
goes with the style it served; the toolbar changes from the same PR stay.
The sidebar avatar dropped its brand-coloured disc for a flat theme one,
which left a column of identical grey marks: hue had been the fast way to
tell one agent from another down twenty rows, and the disc was the only
thing carrying it. Painting the mark itself restores the reading at a
third of the coloured area, so it no longer competes with the status dot
beside it — colour says who, the dot says what it wants. `mark_ink`
keeps the hue and only lifts a value that cannot be seen on the surface
under it, which is Codex and Grok's pure black on a dark theme.
The toolbar above it had the opposite problem: `+` and the panel toggle
were drawn at `sidebar_foreground`, the rung a tab title uses, so the two
controls were the darkest marks in the sidebar. They drop to
`muted_foreground`, level with the workspace chip, and the hover fill the
variant already carried answers the pointer.
The glyphs themselves: the panel icons fill their compartment so they
read as a sidebar rather than a split box, and the plus carries a sixth
more stroke than the closed shapes beside it — an open form at the family
weight reads both larger and fainter, which is what made it the odd one
out. Its cap now lands on a half pixel rather than a whole one; the
whole-pixel rungs are 10px and 12px in a 16px box, and neither is the
size.
Claude-Session: https://claude.ai/code/session_01FG2s9mbZu6LbjjmU54X7kt
The right-click menu and the File menu sit next to Split / New Tab items,
so the surrounding context already says what closes; plain "Close" (⌘W)
matches the macOS convention. The palette and Keybindings page keep the
full name, where there is no surrounding menu to disambiguate.
Alt+1..9 are vim's tab keys, and tty7 takes all nine for Go to Tab.
Two things stood between the reporter and getting them back.
**Nothing in the app could leave an action unbound.** Backspace on a
Keybindings row that has recorded nothing *reset* the row — dropped the
override so the action gets its shipped chord back. On a row nobody had
overridden, which is every row the first time it is looked at, that is a
no-op: pressing it over Alt+1 left Alt+1 sitting exactly where it was,
which reads as the default restoring itself. `config.json` has spelled
"no chord" as `[]` since #868, but no gesture wrote it.
Backspace now writes that empty list. The row falls to `—` and grows the
**Reset** button every overridden row has, which is the way back to the
default. The capture hint names the key, and the docs say what it is for.
**A keybinding line serde could not read failed the whole `Config`.**
`keybindings` is a hand-edited map and was strict, so `"ActivateTab1":
null` — or a number, or an object — quarantined `config.json` and started
the app on built-in defaults. Every rebinding in the file then read as
its shipped default, and the next settings write persisted those
defaults over what the user had written. It now reads one entry at a
time, like every other hand-edited nested key here: the lines that name
a shortcut bind, a line that does not is logged and skipped.
Tests, each failing on the unfixed code:
- `ui::app::keybinding_gpui_tests::backspace_on_a_row_unbinds_the_action_rather_than_restoring_its_default`
- `core::config::tests::a_keybinding_line_that_cannot_be_read_does_not_take_the_config_with_it`
and `ui::keymap::gpui_tests::alt_digits_can_be_moved_off_the_tab_actions_for_good`
pins the merge and a save/reload round trip: a list replaces the shipped
Alt+1, `[]` leaves nothing, and neither comes back after a restart.
Fixes#901
Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM
Faint text was painted as its ink at 66% alpha over the cell. On a light
background that fixed fade collapses the WCAG ratio: Catppuccin Latte's
foreground fell from 7.06:1 to 3.18:1, Rose Pine Dawn's to 3.08:1, and
every bright-black the palette rescue had lifted to 4.5:1 fell back to
~2.5:1 on all four light builtins (#858).
On a light cell the fade is now walked back toward the ink until it clears
the 4.5:1 text floor, capped at the ink's own ratio. Dark cells, and the
legible-palette switch turned off, keep the plain fade byte-for-byte.
Fixes#858
Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM
effective_bindings kept one chord per action and set_binding overwrote that
slot, so "NextTab": "cmd-shift-]" silently took Ctrl+Tab away.
A string in keybindings now adds a chord beside the action's default (or
preset) chord; "" still unbinds, as configs and the docs already rely on; a
list is the exact chord set, [] unbinds. Configured chords are installed after
every shipped one, so a chord the user names wins a tie with another action's
default. The Settings page lists every chord of an action, and recording a
shortcut writes the list shape (it sets the binding) and takes only the stolen
chord from the action that had it.
Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM
Switching workspaces or reopening a window from the tray throws a pane's
TerminalView away and builds a new one over the same daemon pane. The new
view starts with no last status, so an agent that was already Done arrives
as None -> Done, which poll_agent_status cannot tell from a turn finishing
live, and every unfocused rebuilt pane got its unread badge back.
The daemon now counts finished turns per agent session (turns, bumped on
entering Done), and views leave an app-lifetime mark per (host, pane) of the
session, turn count and badge the reader was last shown. A rebuilt view's
first sight of Done takes the badge back from a matching mark instead of
raising a new one; a turn that finished while the view was gone has no mark
or a lower count, and still badges.
Fixes#870
Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM
Regression tests for issue #868: a chord added in config.json must join the
action's default chord rather than replace it, an empty string or list must
still unbind, a list replaces the chord set, the tmux preset composes, a user
chord wins a tie with another action's default, and Settings recordings write
the exact-set shape.
Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM
Hiding the whole title bar took the tab strip with it: with tabs on top
every chip, the New Tab tile and the panel/menu tiles vanished in
fullscreen, the docked document header (drawn only over the spanning bar)
disappeared, and the strip's drop band kept claiming a row that was now
terminal.
What is actually dead in fullscreen is minimize/maximize/close. The row now
stays; in fullscreen off macOS the strip goes into a plain row of the same
geometry instead of `TitleBar`, which always draws those buttons, and the
room reserved for them (strip width, chrome band over the panel, document
header padding) comes back. The notice text says the window buttons are
hidden rather than the title bar, and the keymap test whose premise was the
bar disappearing is replaced by one pinning the controls width.
The passphrase box checks which key file is on this machine with
std::fs::metadata, which the host-boundary guard rejected; allowlist it
beside the existing std::fs::read entry for the same client-side key.
An empty key field now resolves to the ~/.ssh defaults build_spec_inner
offers, so a default encrypted key can be given a passphrase from the
form. The key is also re-resolved when host or user change, since they
fill %h/%r in the path. Drop the unused SettingsForget string.
Closing the last window with the tray icon on retires tty7 to the tray:
process alive, Dock icon up, nothing on screen. That state had no way back
through the icon. macOS relaunching an already-running app arrives as
`applicationShouldHandleReopen:hasVisibleWindows:`, gpui's delegate forwards
it to a callback registered with `Application::on_reopen`, and tty7
registered none — so the click was a no-op, and the only ways back in were
`⌘N`, the tray's "Show tty7", or quitting and relaunching.
`windows::reopen` takes that callback, in the two shapes the state has: a
window still registered is activated rather than doubled, and no window at
all goes through the pathless-launch restore (`restore_target` + `open_at` +
`announce_detached_at_launch`) — the same path the tray's windowless branch
takes, so the workspace that retired is the one that returns and not a blank
one beside it. `reopen_with` is the seam the tests drive, so a reopen that
opens a second window beside the one on screen cannot pass.
`Application::on_reopen` is registered beside `on_open_urls` in `main`,
because it has to exist before `run` — `keymap::init` runs inside the loop —
and the callback defers to the loop with `cx.spawn` rather than opening
windows on AppKit's delegate stack, the shape `on_open_urls` already uses.
`activate_window` is `makeKeyAndOrderFront:` on macOS.
Reported from a macOS machine where a lid close and wake left the process
frontmost with no window: `launchservicesd SETFRONT` at 23:51:40 with the
process still reported `running-active-NotVisible`, and the layout only back
after a quit and relaunch. The window itself being lost across display
sleep → wake is not explained by this change and carries no guess-fix here:
nothing in tty7 or in the pinned gpui hangs off display sleep or wake.
cargo fmt --check; cargo check --locked -p tty7 --tests; cargo test --locked
-p tty7 --bin tty7-app -- 1888 passed, 0 failed.
Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
`with_terminal` builds the chain once, out of `font_family` and
`font_fallbacks`, and from then on it is only ever copied: `set_font_family`
took it off the font it was replacing, and `alt_font` takes it off the
regular face when it builds bold and italic. Nothing reread it.
So a `font_fallbacks` edit had no live path at all — only panes opened
afterwards saw it. Changing `font_family` and changing it back did not help
either, because that path cloned the chain too.
Carrying the chain across a family change is also wrong on its own terms.
`fallback_chain` decides the pins from the family it is handed: it skips
pinning a last-resort face that the family already is, and pins the bundled
Hack otherwise. The chain built for `Hack` therefore has no Hack in it, and
reusing it after a switch away from Hack leaves the anchor missing.
`set_font_family` now rebuilds from the config, `reload_from_config` watches
`font_fallbacks` and pushes a rebuild into every open pane, and the rebuild
writes all three faces rather than the regular one alone — bold and italic
carry no chain of their own, so skipping them would strand two thirds of the
text on the old one.
A host could be described in full in Settings and still not be
connectable from there: there was no password box anywhere on the form.
The only way to store a password was to connect, wait to be asked, and
tick "remember" — and the only way to correct a wrong one was to connect
again and fail first. The key file lived two disclosure triangles deep
under Advanced, as a textarea of paths with nothing to pick one.
The form now carries the credential half of a connection, in an
Authentication block between the address and the collapsed sections:
- A password box, masked with a reveal toggle, seeded from the system
keychain so a stored password can be read back, corrected or cleared
without dialling anything. Clearing it and saving is how a saved
password is let go of.
- Identity files, moved up out of Advanced, with a Browse button that
opens the system picker and writes the path back as `~/.ssh/...`
rather than the absolute path the dialog hands over.
- A key passphrase box beside it, stored against the contents of the key
it unlocks — the same account the connect-time prompt uses. It follows
whichever key the field names, and says so when there is no readable
key to store one against.
Which boxes appear follows the method, the way every other SSH client
does it. The split is `build_spec_inner`'s: a password for Auto and
Password, key passphrases for Auto and Key, and nothing for Agent,
GSSAPI or 2FA — a box outside that would collect a secret, store it in
the keychain, and never offer it to anybody.
Nothing secret reaches the config file. That is also why Save could not
see a typed password: the dirty check compares profiles, and no profile
holds one. It now folds the two secrets in, so Save lights up for a
password the way it does for a port.
Saving moves a password with the address it is filed under — the
keychain accounts by endpoint, not by profile — and leaves nothing
behind under the old one, unless another host still dials it. A
passphrase belongs to its key rather than to this profile, so pointing a
host at a different key never touches the first key's entry.
Test dials with what is on screen rather than only with what is stored,
so it stops reporting a failure the form could not explain.
The layout is the other half of the report. These rows were built out of
the settings rows the rest of the page uses, which push their control to
the far right edge: right for a list of independent switches, wrong for
a form, and it left a hand's width of nothing between the word "Host"
and the box a hostname goes in. Labels now sit right-aligned against
their fields, descriptions and errors moved under the field they are
about, and the three that only restated their label became hints inside
the box.
Two bugs the new shape turned up: a percentage-width control inside a
flex-grown wrapper has no definite parent to resolve against, so the
host and key fields collapsed to one character and the method dropdown
clipped its own menu to "GSSAP"; and "Needs a host" appeared in red on a
form nobody had typed in, because the untouched check counted a port
field that opens on 22 and is never empty.
Claude-Session: https://claude.ai/code/session_01LAqfzqELnoDWU56LBXS1Nh
Hook events map Qoder's lifecycle to tty7's state machine: session start,
prompt submit, permission requests, MCP tool elicitation (an authorized MCP
tool can still pause for user input mid-call), tool completion, stop, and
session end. Compaction events are filtered out—Qoder emits a session-start
after compacting the active turn, which would reset the status line to Idle
without this filter, even though the turn is still running.
Settings path resolution respects QODER_CONFIG_DIR for local installs,
falling back to ~/.qoder/settings.json. Remote targets ignore the override
(a local env var must not redirect remote hooks).
Session commands support --resume and --fork-session. The resume command
strips conflicting flags (--resume, -r, --continue, -c, --session-id,
--worktree, --fork-session) from the original launch argv before appending
the new session id. The -w/--cwd flags survive (Qoder's -w means --cwd,
not --worktree). Both commands require session persistence: when
--no-session-persistence is present, there is no saved conversation to
reopen, so the commands return None.
Tests cover compaction preservation, MCP elicitation state transitions,
QODER_CONFIG_DIR's effect on the hook lifecycle (multi-case isolation),
resume/fork command generation, worktree flag handling, and persistence
requirements.
Localization complete for en/ja/zh. Icon embedded, search keywords wired.
Agents animate in the terminal title while they work, and they do not
agree on an alphabet: Claude Code cycles the quadrant circles and rests
on an asterisk, others step through the braille frames, some write
nothing at all. Rendered as they arrive, a column of tabs carries a mark
in front of some rows and not others, in three vocabularies — while the
row already says what the agent is doing, in one, with its status dot.
So the mark comes off, for everyone, with no setting. A switch would not
settle this: nobody opens settings to decide how a spinner is drawn, and
a default-off toggle buys two render paths to maintain forever in order
to answer a question that has one right answer per person and no way for
the app to know which.
**A known alphabet, not a shape.** The obvious rule — a leading character
that is non-ASCII and above some code point, followed by a space — matches
by shape, and `🔥 build`, or `📁 ~/repo` written by somebody's shell
integration, fits it exactly and quietly loses its first character with no
way to ask for it back and no clue as to what took it. Matching marks we
have actually seen costs the same and cannot do that: the braille block,
the four quadrant circles, and Claude Code's resting asterisk. When an
agent invents a mark that is not on the list, the failure is today's
behaviour — the mark stays — which is the safe direction to fail in, and
adding it is a line in the table.
Two things the rule insists on, both to keep it from reaching past what
it is for. A mark only counts with whitespace behind it, so `✳fixing` is
a word that starts with a character rather than a mark in front of one.
And a title that is *only* a mark keeps it: taking it would leave an empty
string, and an empty title is not a tab called nothing, it is a tab that
falls back to its number — less than the mark was saying.
It happens in `TabView::label`, which is where a title becomes a label, so
the strip, the sidebar, the switcher and the rename box's prefill all
agree without being told separately — and, because `label` reaches a
given name before it reaches the title, a tab somebody deliberately
called `✳ release` keeps what they called it. That ordering is the only
thing standing between a user's name and a rename behind their back, so
there is a test on it rather than a comment. Three existing tests carried
`✳` in their fixtures and now expect it gone. The one in `switcher.rs` was
asserting that a tab in another window is named the way a local one would
be, which is still exactly what it asserts; the one in `tty7-cli` is the
table getting this for free, since `tab_label` reads `label` and so
`tty7 ls` says what the tab strip says without either being told about the
other. The daemon's fixtures keep their marks on purpose: a title is stored
as the terminal wrote it, and only what turns one into a label takes
anything off.
This leaves the row with nothing moving in it, which is a real loss and is
answered separately: `AgentStatus::dot_rgb` returns three flat colours,
and a `Working` dot that breathes says the same thing in the vocabulary
the row already speaks.
On Windows and Linux a fullscreen window has no caption. The platform asks
what is under the pointer through `WM_NCHITTEST`, gpui answers from the
window control hitboxes the frame registered, and fullscreen clears
`WS_CAPTION` — there is nothing left to answer with. Measured on a
fullscreen tty7: `GetWindowLong` reports `WS_CAPTION` clear, and every
point along the top of the window comes back `HTCLIENT`, where the same
window a moment earlier answered `HTCAPTION`, `HTMINBUTTON` and `HTCLOSE`.
The bar was drawn anyway. `WindowControls` renders minimize, maximize and
close whenever the target is not macOS, without asking whether the window
is fullscreen, so all three sat there taking hover styling — gpui's own
dispatch reaches them fine — and doing nothing at all when clicked.
Dragging the bar did nothing either.
So on those two the bar goes. It is the app's own chrome there: a caption
to move the window by and the controls at its end, none of which a
fullscreen window has. Drawing chrome that cannot work is worse than
drawing none.
Not on macOS, and the reason is not that the bug is milder there — it is
that the premise does not hold at all. `WindowControls` draws none of the
three on macOS; the ones that go dead elsewhere are the system's traffic
lights, and the system hides them itself. What that bar does in fullscreen
is hold the band the system reserves: the traffic lights land on it when
the menu bar is revealed, and so does the translucent strip drawn under
the menu bar. Take the bar away and that strip lands on the terminal and
covers its first row instead — measured, and the difference is exactly
`TITLE_BAR_HEIGHT`. Fullscreen belongs to the system on macOS, and the bar
is part of how the system dresses the window rather than something broken.
Nothing on the bar becomes unreachable where it goes. Its controls are
actions first, dispatched from the window's root rather than from the bar,
and each has a chord or a seat in the palette, which has one;
`what_the_title_bar_offers_is_reachable_without_it` is that in a test.
Worth noting for anyone reading it: `ToggleTabSidebar` ships with no
chord, so in fullscreen the palette is how it is reached.
Entering says how to leave, because entering is the instant the bar
disappears — so only where it does, and only through the action: a window
that starts fullscreen because the setting says so is not a surprise
anybody needs explaining, and `startup_mode` is untouched by the toggle
either way. The chord comes from the keymap rather than from a string, so
it reads `F11` or whatever it was rebound to.
The notice carries an id, which is what keeps a held-down `F11` to one
notice rather than a column of identical ones: pushing under an id already
on screen replaces that one. Leaving through the action takes it back as
well. Leaving some other way lets it time out instead — a second or two of
a stale notice, which is not worth a per-frame watch on a state that lies:
`toggle_fullscreen` is spawned onto the executor on every backend, so
`is_fullscreen` still reports the old value when the action returns, and a
render-time test for "not fullscreen now" can take the notice back before
it has been seen.
Verified on Windows 11 26200, and on macOS 26.5.2 by a second pair of
hands: the macOS half of this is the reason the change is not applied
there. Linux is reasoned about rather than measured — it draws its own
chrome the way Windows does, and the same `WM_NCHITTEST`-shaped question
is answered through gpui's window control hitboxes.
The new `link_rtt` landed between `pane_procs`'s doc comment and
`pane_procs` itself, so the comment about walking pane process trees
documented the latency probe instead.
`format_rtt` also compared the unrounded milliseconds against 1000, so a
999.6 ms round trip printed as "1000 ms" — a millisecond reading past
the range the millisecond branch exists to cover. Round first, then pick
the unit.
Claude-Session: https://claude.ai/code/session_01E4EPKzHg1fm9HMmHkUYpER