Commit Graph
1118 Commits
Author SHA1 Message Date
l0ng-ai fa3d777c29 feat(release): ship a native Windows ARM64 build (#1043)
Release and nightly now build the desktop app for aarch64-pc-windows-msvc
alongside x64, publishing tty7-<version>-windows-arm64-setup.exe and
tty7-<version>-windows-arm64.zip.

- Cross-compiled on the x64 Windows runner, like server-windows' ARM64
  leg, and marked experimental until it has shipped once: a failure drops
  the ARM64 packages instead of holding up the release.
- Vendors Microsoft's arm64 ConPTY pair from the same package version as
  the x64 one, so ARM64 panes keep the OSC 11 fix (#345).
- Each Windows package bundles the WSL server for its own architecture.
- The installer's architecture comes in as a define: x64compatible for the
  x64 build (still installable on ARM64 under emulation), arm64 for the
  native one. One AppId, so either upgrades the other.
- The in-app updater on an ARM64 build asks for the arm64 packages; an x64
  build under emulation keeps taking x64 ones.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 22:04:46 +08:00
l0ng-ai d40233b572 feat(tabs): keep recently closed tabs in the machine tree, and a confirm-before-closing setting (#1037)
* feat(tree): keep each workspace's recently closed tabs in the machine tree

A workspace now keeps the tabs closed from it in its machine tree
(`Workspace::closed`), so reopening one no longer depends on the window
that closed it still being open.

- `TabCloseRemembered` closes a tab into that list: the tab leaves the
  workspace as a close takes it (other windows hear `TabClosed`), its panes
  are stopped with their last screens kept on disk, and their records stay
  in the pane list. Panes the client held that the tree never recorded are
  ended outright.
- `TabReopen` takes the named or newest entry off the list and answers it
  with its pane records, for the client to rebuild on fresh shells that
  open on the old screens. The records it leaves behind are claimed by the
  successors' seeds instead of being refused as duplicates.
- Entries last 24 hours and a workspace keeps the newest 20. The daemon's
  scrollback keeper expires them on its existing timer, and an entry that
  goes takes its records and stored screens with it.
- Both requests are gated on a new `closed-tabs` hello feature, offered only
  by a peer that serves a tree and panes, so an older daemon or remote
  server is never sent them.

The field is `#[serde(default)]` and skipped while empty, so older trees
load unchanged and an older build reads this one's.

Refs #1021

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* feat(tabs): reopen closed tabs from the machine, and a setting for when closing asks

Closing a tab now closes it into its workspace's recently-closed list on the
machine that holds the workspace, instead of into a list that ended with the
window. ⌘⇧T asks that machine for the newest entry, so a closed tab comes
back after quitting and relaunching the app, from any window of the
workspace, and in remote workspaces whose server keeps the list.

- The explicit close (⌘W, the tab's close button, bulk closes) registers the
  tab with the window's next sync, which turns that tab's `TabClose` into a
  `TabCloseRemembered`. The machine stops the panes and keeps their screens;
  the window no longer kills them itself. A tab dragged to another window or
  never rebuilt still goes out as a plain close.
- If the close cannot reach the machine (no `closed-tabs` feature, a window
  that has not pulled its layout, a sync that fails or is thrown away), the
  window falls back to what it did before: the tab goes on its own list and
  its panes are killed from here.
- Reopening waits briefly for this window's queued edits to land, so an
  immediate ⌘⇧T undoes the close it means, then rebuilds the tab through the
  existing restore: each pane a fresh shell in its old cwd, opening on its
  last screen, with its shell, SSH target and agent resume facts. The tab
  keeps its id. The window's own list is used when the machine has nothing.
- The home screen offers the next tab ⌘⇧T would reopen, read from the
  machine mirror, which now tracks this window's remembered closes.

A new setting, `confirm_close` (General > Tabs, "Confirm before closing"),
decides when closing a tab or pane asks first: `never`, `when-busy` (the
default and the old behaviour) or `always`. The SSH "Warn before closing"
opt-in is honoured under every mode. Under `always`, Close Other Tabs and
Close Tabs to the Right ask once for the whole batch.

Refs #1021

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(tree): a remembered close marks its panes' records as no longer live

The records stay in the pane list for the reopen, but the panes are stopped
right after the close. Left at live: true, `tty7 wait` on a pane of a
closed tab read it as a running agentless shell and waited forever instead
of reporting it exited.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 16:40:28 +08:00
l0ng-ai f0f2b83b6e feat(workspace): the machine's own window takes part in workspace takeover (#1042)
One workspace is driven by one window at a time, whether that window runs on
the machine itself or on a remote client. The local GUI used to connect to its
daemon without ever claiming a workspace, so a remote client and a local
window could drive the same panes at once and fight over their size.

- The local link now claims (WorkspaceAttach) every local workspace a window
  shows. Opening one on purpose (switcher, tty7 open, a new window onto it,
  switching in place) takes it over; restore, relaunch and reconnect only
  claim a workspace nobody else holds, and otherwise open taken over.
- Preempted events for this computer put the window in the same taken-over
  state remote workspaces use: panes detached (processes untouched), the
  status strip naming the holder, the input pill, Take Back, and the
  switcher's 'taken over' badge.
- A hydration of a local workspace another client holds does not attach its
  panes, so a restored window never resizes them under the holder.
- A reconnect re-claims what the window held and leaves what it was pushed
  off alone. Nothing but Take Back or an explicit open reclaims.
- The local hello carries the machine's hostname instead of the literal
  'this computer', which is what a displaced remote client displays.
2026-09-30 16:36:10 +08:00
l0ng-ai ab029f5ea1 fix(ssh): start a redialled SSH pane in the remote directory it was in (#1035)
* fix(ssh): start a redialled SSH pane in the remote directory it was in

A native SSH pane dialled again (restore after a daemon restart, Reconnect,
a split, ⌘T on an SSH tab, waking a sleeping tab) always landed in the login
directory. The client already sent the pane's remote cwd as
`SpawnNativeSsh.cwd`, but the daemon dropped it on the floor.

The daemon now threads it through `Pane::spawn_native_ssh` and
`SshManager::run_session` into the shell-integration bootstrap, whose first
line becomes `builtin cd -- '<dir>' 2>/dev/null` (fish-quoted for fish). It
is never typed at the prompt, never lands in history, and a directory that
is gone leaves the shell in the login directory without a word. Sessions
without integration take the plain shell request as before, so jump-host
menus never see it. The per-host probe cache still holds only the shell.
Only absolute paths are honoured. No wire or protocol change.

Callers now say what they mean: a saved host or quick connect passes no
start dir instead of the local cwd of whatever tab was in front; ⌘T and a
split on an SSH pane pass that pane's remote cwd; a sleeping SSH tab keeps
its remote cwd in the session layout. The daemon's replay now sends the
remote context before the cwd, so a window that reattaches to an SSH pane
does not wipe the remote directory it was just told.

Refs #1028

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(ssh): a local shell standing in for a restored SSH leaf starts locally

pane_to_session now keeps a native SSH leaf's far directory, so the
session_to_pane fallback that brings such a leaf back as a local shell
(the redial failed, or its daemon pane is gone on reattach) would hand
that remote path to a local spawn. Pass no cwd there for an SSH leaf.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 15:02:22 +08:00
l0ng-ai 0277ca67dc Centre the title-bar search box; bring back auto-hiding title-bar buttons as an Appearance option (#1036)
* feat(settings): an Appearance option to show the title-bar buttons only under the pointer

26.9.2 painted the new-tab and sidebar tiles only while the pointer was
over the bar they sit in; 26.9.3 took that out so the buttons would stay
discoverable. Both are fair, so it comes back as a choice: Appearance >
"Show title bar buttons on hover" (`auto_hide_titlebar_buttons`), off by
default, which keeps today's always-visible bar for everyone who has not
asked otherwise. A config written before the key existed reads as off.

With it on, the rail's two tiles follow the rail, and the collapsed
rail's pair and the trailing panel toggle follow the tab strip. The
window mark stays put, the tiles keep their layout slot so a reveal
never shifts anything, and the title-bar search box is always drawn.
The trailing toggle stays painted while the detail panel is open, as
before, since the panel's own tab row beside it always is.

The reveal is the hover sheet from 26.9.2 — a transparent last child
over each region, because `group_hover` loses the region the moment the
pointer reaches an occluding tile. Resting tiles go to zero opacity
rather than `invisible()`: gpui skips a hidden element's paint pass,
which is where its click and accessibility actions are registered, so a
screen reader could find a hidden tile by label and then not press it.
Shortcuts are actions and never depended on the tiles.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(titlebar): centre the search box on the window, not the bar after the traffic lights

On macOS `TitleBar` leaves an 80pt lead for the traffic lights before
the tab strip — whether or not the rail stands in front of them — and
the Search Everywhere box was centred on the strip. So it sat 40pt right
of the terminal column's middle: with the rail collapsed, 40pt right of
the window's (#1033). Fullscreen added the bar's own inset on top.

The band the box centres in now reaches back over that lead, so its left
edge is the terminal column's on every platform (12pt elsewhere). Its
right edge is unchanged: the strip's end on macOS, the terminal column's
end beside a docked panel or document off it.

Reaching back puts the collapsed rail's tiles inside the band, so the
box now keeps an equal clearance at both ends — two springs with a
minimum width either side of it. In a narrow column it shrinks instead
of sliding under New Tab or the panel toggle, and stays centred while
it does. The geometry is a pure `search_band`, tested for the macOS
rail-collapsed, rail-open and fullscreen cases and off macOS.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(titlebar): clear a hover flag whose sheet is not on screen; document the key

A title-bar hover flag is written only by its sheet, and only when the
sheet sees the pointer cross its edge. Hide the rail from its own tile, or
turn the switch off mid-hover, and the sheet leaves the tree with its flag
still set: the next time it is built the tiles came back painted with
nobody pointing at them, until the pointer happened to pass through and
out again. Clear the flag of any sheet not built this frame.

Also list auto_hide_titlebar_buttons in the configuration reference.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 14:59:53 +08:00
l0ng-ai c0c6f90284 fix(chrome): the workspace tile points like the switcher rows it opens 2026-09-30 14:14:35 +08:00
l0ng-ai e1ee74a379 fix(tabs): ⌘T on an SSH tab stays on its host; Switcher says Offline in words (#1031)
* feat(switcher): say Offline in words and dim the avatar; drop the link dot for a reachable workspace

The normal case carries nothing extra. An offline machine's row reads
"Offline" under the tab count, where Open and This window go, and its
avatar is dimmed. A dot stays only for states that want attention:
connecting, reconnecting, failed, or taken over by another client.

* fix(tabs): ⌘T on an SSH tab dials the same host and files the tab under it

A new tab from an SSH pane used to open a local shell in the default
directory, which landed in Ungrouped instead of under the host the user
was on. A native SSH pane now dials again with its spec, as ⌘D already
did; a shell that ssh'd onward from a local prompt gets a local tab that
types the same ssh command at its first prompt. Either way the tab is
seeded into the host's auto group before its pane reports in.
2026-09-30 12:29:56 +08:00
l0ng-ai 8db94666f0 fix(remote): fast, stable remote workspaces with more than ten panes (#1034)
* fix(ssh): a connection at the server's session limit is full, not dead

sshd allows ten sessions per connection by default and every remote pane is
one of them. The eleventh was refused with ConnectFailed, and the connection
was marked dead for it: taken out of the cache while all ten panes on it were
still using it. Every pane after that dialled its own fresh link, paying a full
handshake and server probe, and so did every short-lived route afterwards,
because nothing held the replacement and it went away as soon as that route
closed.

The cache now keeps a pool per destination. A refusal marks that connection
saturated for a while instead of dead; the pool hands out the first live one
with room and dials another beside them only when all are full. A route or a
native SSH pane that lands on a connection that turns out to be full goes back
to the pool for another.

* perf(remote): prove a server that is already running in one round trip

Every new connection to a machine tty7 had been to before spent six
sequential round trips proving what it already had: uname, a home lookup and
a stat over SFTP, a control probe and a process scan. The SFTP session it
opened also stayed open for the life of the connection, one of the handful of
sessions the server allows it.

One `sh -c` script now answers the common case: this dialect's server is
installed, answers the bridge probe, and is the one running (or a build of the
same dialect). Anything else falls through to the full install path unchanged.

* fix(remote): don't replace a pane that could not be reached with a fresh shell

Reattaching a restored pane treated every failure other than silence as "the
pane is gone on its machine" and spawned a fresh shell in its place. That
includes the link never opening at all — the server refusing another session,
a transport error — when the pane is still running over there. The tab lost
its session, and the old shell was left orphaned on the remote daemon; one
workspace had accumulated 53 shells for 17 panes.

Only the daemon's explicit "no such pane" now means gone. For a remote pane,
any other failure leaves it pending, and a pane that stands in for a running
one retries on its own a few times (2s, 4s, 8s, 16s, 16s) before leaving it to
Try Again. Local panes keep their previous behavior.

* perf(remote): ask a machine which panes are live over its control link

The pane liveness probe opened a pane route every ten seconds, which is an SSH
session channel on the remote side — one of the few the server allows per
connection. Once panes had taken them all, each probe dialled a whole new
connection. Ask over the control link that is already up instead: the
machine tree's pane records carry the daemon's own liveness.

* fix(scm): stop two windows from trading one repository watch every frame

Who holds a repository open is a global, reconciled by every window every
frame, but it was keyed by watcher kind alone. Two windows whose file trees or
panels sat in different repositories took the hold from each other each
frame, and every hand-over dropped the watch and opened it again. On a remote
workspace that is four round trips per cycle — about 28 control requests a
second for as long as both windows were open.

Holds are now keyed by window as well, and a closed window gives back what it
held.

* perf(ssh): open channels on one connection concurrently

The russh handle sat behind a tokio mutex held across every request on it,
and each request waits a full network round trip for its reply. So every
pane on a connection opened its channel after the one before it: on a link
with a few hundred milliseconds of latency, a workspace of twenty tabs came
back one tab at a time over about ten seconds.

Every call on the handle takes `&self` and waits on a reply channel of its
own, so the lock bought nothing. Drop it.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 12:29:48 +08:00
b26c26ca66 fix(palette): an open palette keeps workspace keys, and ⌘P answers from the Settings window (#1026)
* fix(palette): an open palette keeps workspace keys, and ⌘P answers from the Settings window

While the palette was open, any app binding it did not handle — ⌘1–9,
⌘D, ⌘W — fell through to the workspace behind it. The Settings window
has no palette listener, so the palette chord did nothing there. A
keystroke interceptor, which gpui runs before matching any binding,
now handles both.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(palette): shifted editing letters are not the query field's

The modal rule let every secondary+A/C/V/X/Z chord through as the query
field's own, shift included, so on macOS Cmd+Shift+A (New Agent Tab)
still opened a tab behind the open palette. Only redo keeps its shift.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-09-30 09:38:43 +08:00
2b94fddedc fix(ui): refocus the app when focus is lost so global shortcuts answer (#1023)
* fix(ui): refocus the app when focus is lost so global shortcuts answer

With focus on nothing, or on a handle whose element is no longer drawn (a
closed file panel, a dismissed menu), gpui dispatches keys on the window root
alone, one level above Tty7App's listeners. TogglePalette, ToggleSwitcher,
OpenSettings and every other tty7-root action went dead. on_focus_lost now
hands focus back via focus_active.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(ui): refocus settings only in the window that draws it

Settings opens in a window of its own, but focus_active handed focus to
the page's handle whenever settings was up, including in the workspace
window. There that handle is not drawn, so the refocus on focus loss
parked focus on nothing and the workspace shortcuts stayed dead while the
settings window was open. Focus the page only when this window draws it,
and fall through to the workspace's own panes otherwise.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-09-30 09:36:50 +08:00
802f9e0792 fix(agents): a Claude resume that finds no conversation starts fresh under its id (#1024)
* fix(agents): a Claude resume that finds no conversation starts fresh under its id

A tab opened and never used, or run with transcript saving off, has no
saved conversation, and `claude --resume` then stops at an error.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(agents): only chain the fresh Claude start where the pane's shell has ||

Windows PowerShell 5.1 and nu reject a line containing `||` outright, so
the fallback took the resume down with it there. The restore line now
chains the fresh start only for shells known to have the operator, judged
by the pane's own shell: its spawn spec, else the configured or login
shell for a local pane. A workspace pane with no explicit shell stays
unknown and gets the plain resume, since its default lives on its host.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-09-30 09:35:32 +08:00
l0ng-ai 0896404634 fix(switcher): require a name for a new workspace, and give the form buttons
The New Workspace form prefilled a random codename and offered no button,
only an "Enter to create" hint. The name box now starts empty and must be
filled; the footer carries Cancel and Create, with Create disabled (and
Enter inert) while the name is blank.
2026-09-30 09:12:39 +08:00
l0ng-ai ef203821b0 feat(a11y): name the icon buttons and search toggles
Bumps gpui-component to the tty7 branch commit that gives Button and
Input a role and a name and exposes popup menu items, and names the icon
buttons whose tooltips are elements rather than text (New Tab, the
sidebar and detail-panel toggles, Switch Workspace) and the file search
toggles (Match case, Match whole word, Use regular expression).
2026-09-30 08:43:52 +08:00
l0ng-ai bb0089f43d feat(a11y): label the remaining lists and let VoiceOver open files from the tree
Editor tabs are tabs named by file (and unsaved state) with a named close
button; Info rows read as 'label, value'; keyboard shortcut rows as
'action, keys'; SSH hosts as 'name, address' with their expanded state.
File-tree rows open on the press, which assistive tech cannot send, so
they take its press action directly: a screen reader could select a file
but never open it.
2026-09-30 03:09:48 +08:00
l0ng-ai cdd3f3c2cd feat(a11y): read Settings rows as named groups with their switches' state
Each row is a group named by its title and description, so the control in
it is heard with its setting's name; switches report on or off, the reset
link is a button, and the Modified only switch has a name of its own.
2026-09-30 02:56:02 +08:00
l0ng-ai 6d07ca41b0 feat(a11y): announce the app's own dialogs as dialogs, named by their title
The SSH sheet, the worktree form and the in-app alert are dialogs to a
screen reader, titled with the question they ask.
2026-09-30 02:48:54 +08:00
l0ng-ai 4ae1c86290 feat(a11y): expose the Changes panel's groups and files to screen readers
Group headers are buttons named with their count and expanded state; files
are tree items named by path and group; directories by name with their
expanded state.
2026-09-30 02:41:01 +08:00
l0ng-ai 420aa33cac feat(a11y): expose Search Everywhere's results to screen readers
Each row is a list option named by its title and subtitle, with the
highlighted one selected.
2026-09-30 02:23:14 +08:00
l0ng-ai 8efbbc4a38 feat(a11y): expose Settings navigation and file-tree rows; title the Settings window
Settings sections are tabs with their names and selected state, file-tree
rows are tree items named by file with selection and expansion, and the
Settings window carries a title for VoiceOver and the Window menu.
2026-09-30 02:19:08 +08:00
l0ng-ai 8f044924ab feat(a11y): expose the sidebar's tabs and the detail panel's tabs to screen readers
Each is a tab with its full title and selected state, and pressable by
assistive tech. Before, VoiceOver saw the window, its buttons and the
terminal, and nothing between them.
2026-09-30 02:12:13 +08:00
l0ng-ai e96cad4858 fix(agents): type a fork or launch command at the new shell's first prompt
Sent the moment the pane was up, the line was echoed by the tty above
everything the shell printed while starting, then read after it. It now
waits for the first prompt, for at most three seconds.
2026-09-30 02:01:04 +08:00
l0ng-ai bbc13279e7 fix(settings): drop 'Paired with …' once that phone is unpaired
Unpairing the phone just paired left 'Paired with probe.' above an empty
'No phones paired yet.'
2026-09-30 01:55:38 +08:00
l0ng-ai e66fa4d881 fix(ssh): never restore an SSH tab as a local shell; show a reattached one as connected
After the server restarted, a native SSH tab's old pane id was attached
to, the attach failed, and the fallback spawned a local shell in its
place: the tab that had been another machine was now this one, still
titled and grouped like the remote. An SSH leaf is now only reattached
when the server lists its pane; otherwise the host is dialled again.

A window reattaching to a live SSH pane also never learned its phase,
since status frames only went to whoever was attached when they were
sent. The pane keeps the last one and replays it, so the tab keeps its
connected dot and warn-before-closing still applies.
2026-09-30 01:39:32 +08:00
l0ng-ai f99fff93fd fix(ssh): log in as this machine's user when a host leaves User blank
The form says a blank User is resolved at connect, and the host card shows
$USER, but the empty string went to the server as the user name. sshd
refused it as an invalid user and tty7 reported every key as rejected.
2026-09-30 01:22:02 +08:00
l0ng-ai 4880171974 fix(ui): show macOS's /private/tmp paths as /tmp
git and canonicalize hand back /private/tmp/… for anything under /tmp, and
the workspace switcher and the worktree form drew that spelling, which no
shell or pane title uses. Only what is drawn changes.
2026-09-30 01:11:18 +08:00
l0ng-ai 31f5d38f3d fix(sidebar): back a tab's hover close button for the row's full height
On a two-line row the diff count sits below the close button's band, and
the bottom of '+2' showed under the ×.
2026-09-30 00:53:59 +08:00
l0ng-ai c3fdbe5c77 fix(settings): focus a new host's first field; name tty7-defined hosts plainly
Add host opened a blank form with nothing focused, so typing went
nowhere. A host saved in tty7 read 'Defined in: In tty7'; the label is
now 'tty7 settings', as a group heading and after 'Defined in' alike.
2026-09-30 00:50:10 +08:00
l0ng-ai 6f29cac8bf fix(switcher): put the workspace the query names above ones matched by tabs
The list was ordered by current-then-recent whatever the query, so typing
'qa' and Enter reopened this window's workspace (its tabs are under
/tmp/t7qa) instead of the workspace named qa.
2026-09-30 00:28:15 +08:00
l0ng-ai 7e9225e6b0 fix(search): match a command's description by the words typed
Any subsequence of a long description counted as a hit, so 'theme' listed
Git: Discard All Changes second, through the letters of 'Throws away every
uncommitted change'.
2026-09-30 00:24:24 +08:00
l0ng-ai 6ac8d3fd64 fix(switcher): select the suggested workspace name so typing replaces it
The New Workspace form opened with the generated name and the caret in
front of it, so typing a name produced 'qadusky-raven'.
2026-09-30 00:20:43 +08:00
l0ng-ai e1ab8e26fc fix(panel): name the shell a default-shell pane is actually running
The Info tab named the login shell for any pane on the default shell, but
a server started from a terminal spawns the shell it was started from.
The root of the pane's process tree is that shell.
2026-09-30 00:16:08 +08:00
l0ng-ai e0308bd54f fix(terminal): keep output without a trailing newline through a resize
zsh's PROMPT_SP pads dangling output until it wraps onto the prompt's row.
The grid took that wrap for the prompt's own first row, so the next resize
at the prompt cleared the output and widening joined it onto the prompt.
At the prompt marks, a padded wrap after dangling output is turned back
into a hard break.

Also: editor breadcrumbs, breadcrumb reveal and Problems labels match
files against the project root's real path, so a project under a symlink
(macOS /tmp) no longer shows the absolute path; the terminal font size
setting says points, which is what its stepper shows.
2026-09-29 23:34:32 +08:00
l0ng-ai 5ba588f6d2 fix(mobile): let Settings renew a pairing code, and say when one is spent (#1019)
While a code was on screen the Show code button was disabled, so the only
way to a fresh code was Cancel then Show code. Worse, any attempt at a
code closes the offer, so after a mistyped paste or a dropped connection
the page kept showing a dead code for up to ten minutes with no hint.

- The button reads "New code" while a code is up, and replaces it.
- A code that can no longer pair stays on screen faded, saying why
  (expired, tried, or replaced by a newer offer), with New code beside it.
- The validity note counts down instead of saying "10 minutes".
- Cancel, and switching phone access off, now withdraw the offer on disk;
  before, a dismissed code could still pair until it expired. Only our own
  offer is withdrawn, never one opened elsewhere since.

The gateway's pair_code now returns the offer's secret alongside the code,
and State gains pairing_is_open / has_open_pairing / close_pairing.

Claude-Session: https://claude.ai/code/session_01BDVpJ78s7RQVcj57vjTcfA
2026-09-29 22:50:59 +08:00
l0ng-ai 9f44feed29 fix(scm): don't hand a new history page the previous page's rows (#1020)
The graph's row cache keyed on the page's address. Once the old page
was freed, the next one could land in the same allocation, match the
key, and be served the old, longer index list - so rendering indexed
past the end of the new page's commits and panicked (seen as
'index out of bounds: the len is 1 but the index is 1').

Key the cache on a Weak to the page instead: while the cache holds it,
the allocation can't be reused, so ptr_eq only matches the same page.
2026-09-29 22:50:57 +08:00
l0ng-ai d1b96e1346 feat(panel): show the author on a hovered GitHub row (#1018)
The author was already fetched for every issue and pull request but only
the detail view showed it. A hovered row now shows it between the labels
and the age.

In a narrow panel the author is what gives: it is capped, then truncated
down to nothing, while the labels and the age keep their width and the
title keeps a stub, so the meta no longer pushes past the row's edge.
2026-09-29 19:32:07 +08:00
l0ng-ai 8e9f55173b fix(agents): fork agent sessions in remote workspaces (#1016)
Forking from a pane in a remote workspace always failed with "the pane is
still connecting": a remote workspace's new pane is dialled asynchronously,
and the fork path demanded a ready terminal to type into. It now hands the
fork line to `run_when_ready`, the same land-then-run path quick launch uses.

The new pane also opens in the source's directory on its own host
(`spawnable_cwd`) rather than only a local one. Agents key their history by
directory, so a fork started in the remote home would find nothing to branch.

Panes that have ssh'd or entered WSL themselves stay excluded (tty7 holds no
link to that machine), and the notification now says exactly that instead of
"local panes only".
2026-09-29 19:31:59 +08:00
l0ng-ai 230a023ebf fix(terminal): stop the git retry check from redrawing every poll tick (#1015)
The retry added in #1011 went through update_global on every 300ms poll
while a pane's repo was unanswered, even when the probe was still in
flight or throttled and nothing was claimed. Each mutable touch of the
GitStatusCache global wakes its observers, so the window redrew about
three times a second for as long as a probe was pending or failing.
That is what a_commit_detail_reads_its_own_files_and_draws_them caught
on Linux CI (2 idle frames where 0 are expected).

Ask whether a retry is due read-only (GitStatusCache::probe_due) and
only touch the global when one is.
2026-09-29 19:31:55 +08:00
l0ng-ai 8c75722466 fix(sidebar): elide branch names from the end only (#1014)
The sidebar branch (group header and row git line) was front-elided,
but its width budget was a few pixels short: the line paints with
tabular figures while it was measured with proportional ones, and the
separator was measured as " · " though it is drawn as a bare "·"
between two gaps. The front-elided branch then overflowed and CSS
truncation cut its tail too, leaving "…nd-error-classificati…".

- Measure the git line and header with the same tabular font they paint
  with, and measure the separator as drawn.
- Elide the branch from the end, the plain cut a reader expects; the
  CSS backstop now cuts in the same direction.
2026-09-29 19:31:51 +08:00
l0ng-ai 3f9ae33a28 style(ui): lighter, tint-keeping selection and hover on the side panels
The tab rail's current row read as a dark slab. Both side panels (the tab
rail and the docked right panel) now step on their own lighter rungs,
1.07:1 for hover and 1.12:1 for selected, and step toward the panel's own
shade instead of the foreground, so a warm panel keeps its tint rather
than turning into a grey patch. On the default light theme that lands on
#ededec / #e8e8e7.

The settings page's nav sits on the same rail fill, so it now paints with
the rail's rungs instead of its own alpha tokens.
2026-09-29 19:27:16 +08:00
l0ng-aiandClaude 24cf458e3b feat(mobile): a phone app to watch and drive tty7 panes (#983)
* feat(mobile): a gateway that lets a paired phone reach this machine over iroh

The first half of the mobile app: everything on the desktop side, plus the
client library the app will link.

- tty7-mobile-proto: the phone<->gateway wire protocol. One stream per purpose
  (pair, control, pane), framed like the daemon's frames, with raw terminal
  bytes kept out of JSON. No tty7-core, so it cross-compiles for iOS/Android.
- tty7-gateway: dials nothing, accepts phones over iroh (hole punching, relay
  fallback, end-to-end encrypted), checks the peer's key against the paired
  device list, and bridges to the daemon. Panes are observed, not attached,
  and keystrokes go in through SendInput, so a phone never resizes a pane or
  takes it away from the desktop window. `pair` prints a one-time QR code.
- tty7-mobile-client: the phone side (pair, tree, pane streams, direct/relay
  and RTT for the link), plus a `probe` example that stands in for a phone.

Verified against a real, isolated daemon: pair, tree, and typing into a pane
over a direct path, ~0.8 ms median echo on loopback.

* feat(mobile): the Tauri app — pair, browse the machine, drive a pane

The phone half, as a Tauri 2 app in mobile/ (its own cargo workspace, so the
desktop build and CI never compile a WebView stack).

- Rust side: the phone's iroh endpoint and key, paired machines, and every
  live stream, behind eight commands. Terminal output crosses to the WebView
  as raw ArrayBuffers on a Tauri channel, batched per frame, in order with the
  pane's JSON events.
- Frontend: vanilla TS + xterm.js. Paired machines and pairing; one machine's
  workspaces, tabs and panes with agents that need you pinned on top and the
  link's direct/relay path and RTT in the header; a terminal that fits the
  desktop pane's width, with an esc/tab/ctrl/arrows key bar. Coming back from
  the background re-watches and re-opens, relying on the daemon's replay.

Verified as a macOS build against a live gateway and an isolated daemon:
paired from the app, tree rendered on a direct path, keystrokes and key-bar
arrows reached the pane. iOS/Android builds need Xcode / the Android NDK,
neither of which is on this machine; mobile/README.md has the steps.

* fix(gateway): one serve per machine, and say how to start a missing server

- `serve` takes an exclusive lock on <config dir>/mobile/serve.lock. A second
  gateway on the same key is a second endpoint answering to one address, so a
  phone reached whichever the network picked. It is now refused, naming the
  pid that holds the lock.
- With no tty7 server running, phones and the terminal both hear "tty7 isn't
  running on <host> — open tty7 there, or run `tty7 server start`" instead of
  "lost the tty7 server: No such file or directory". `serve` checks once at
  startup, and still starts, since tty7 may be opened after it.

* feat(mobile): redesign the app as a native-feeling, minimal UI

The first cut read as a web page of bordered boxes. This rebuilds it the way a
phone app moves and reads, in the desktop tty7's own look:

- Screens push and pop with View Transitions; large titles fold into the bar.
- Grouped inset lists on a tinted canvas, following the system Light/Dark with
  the desktop presets, accent and ANSI palettes. Hack for code and terminal.
- Panes are listed by tab, one card per workspace, with the desktop's agent
  avatars and status badges (Waiting hollow, Working blinking) and its words.
- Pairing is its own screen, with steps, a Paste button and inline errors.
- A machine that stays silent for 10 s says so and offers to pair again; an
  offline notice says what to check.
- The terminal header shows live/offline in words. A pane too wide to read is
  shown at a readable size and pans to follow the cursor, with a toggle to fit
  the whole width. The key bar has drawn icons, puts left/right first, and
  has a keyboard toggle.

PRODUCT.md and DESIGN.md record the product facts and the design system.

* feat(mobile): open a new tab from the phone

Each workspace on a machine's screen gets a "New tab" action. It starts a
shell at the end of that workspace, in the directory its last tab is in, and
opens it straight away.

- Protocol: a one-shot `Open::NewTab { workspace_id, cwd, size }` stream,
  answered with `Ok` and a `TabCreated { tab_id, pane_id }`, or `Denied`.
  It is additive, so the protocol version stays. A gateway from before this
  drops the stream unanswered, and the app says to update it.
- Gateway: takes the same two steps as `tty7 tab new`, spawning a shell owned
  by the workspace and then TabCreate. The shell starts at the grid the phone
  asked for, because no desktop window is showing it yet. Sizes are clamped.
- App: a `tab_new` command, with the size worked out from the screen at the
  readable font size.
- probe: `newtab <workspace-id> [cwd]`.

* feat(mobile): reach the machines the desktop is linked to over SSH

A machine's screen now lists, under its own workspaces, every machine its
tty7 holds an SSH link to, with that machine's workspaces. Panes there open,
take input and get new tabs like local ones. "Needs you" gathers panes from
all of them.

- The gateway routes through the local server over links it already holds,
  the same way `tty7 -m <machine>` does. It never dials a down link, because
  that would guess at credentials the phone does not have. A down link
  shows as "Link down", with a note to reconnect it on the desktop.
- Protocol, additive: `Tree.remotes`, and an optional `machine` (the link
  key) on `Open::Pane` and `Open::NewTab`. A local pane is asked for exactly
  as before, so older gateways still understand it.
- Rebuilding a route target from a link key moves from the CLI into
  tty7-core as `RouteInfo::target` / `RouteInfo::host`, so the CLI and the
  gateway share one rule. The CLI now calls it.

* perf(gateway): read linked machines in parallel, never waiting on a slow one

Linked machines were read one after another on every tree poll. One slow
SSH link, whose requests can take 10 s, stalled the whole tree for every
phone, local workspaces included. It also held a lock that queued pane
opens, input and new tabs on every other link.

- Each linked machine is read on its own thread (`poller::Poller`). A poll
  waits at most 250 ms. A machine that has not answered is reported as it
  last was, and its read lands for the next poll. Only one read is in flight
  per machine, however many phones are watching. A machine that drops off and
  comes back cannot receive a stale read, because each slot has a generation.
- Routed control connections are locked per machine, not all together.
- A link that is up but has not answered its first read is sent as
  `RemoteView.pending` (additive). The app shows "Reading…" with skeleton
  rows instead of claiming the machine has no workspaces.

* fix(mobile): keep reaching the computer after the gateway restarts

Every `serve` bound a random port, so a restart left each phone holding
addresses that no longer answered. Where the n0 relays are unreachable, which
is common behind the Great Firewall, the phone had no other way to find the
gateway until it was paired again.

- `serve` listens on the same UDP port every time. It picks one on first run,
  keeps it in `<config dir>/mobile/port`, and moves only if the port is taken.
  IPv6 binding may fail, as in iroh's own defaults.
- Both ends add mDNS lookup (`iroh-mdns-address-lookup`, service `_tty7._udp`).
  On the same network a phone finds the gateway by key when its addresses are
  stale, such as after a new DHCP lease or a new IPv6 prefix. The gateway
  advertises and the phone only listens. If multicast is refused, each side
  starts without it and says so, rather than failing.
- iOS: `Info.ios.plist` declares the local-network use and the Bonjour
  service, without which iOS blocks multicast.
- An ignored test (`--test mdns`) connects by key alone over mDNS, for a
  machine that allows multicast.

* feat(mobile): run the gateway in the desktop daemon, paired from Settings

Phone access no longer needs `tty7-gateway serve` in a terminal.
Settings → Mobile switches it on, and the local daemon runs the gateway from
then on, with every window closed as well. That is where the panes a phone
reaches live anyway.

- Settings → Mobile, in all three locales:
  - an "Allow phone access" switch;
  - a status line (running, starting, off, or why it failed);
  - "Show code", which draws the QR code and the tty7pair: code with a
    Copy button, and closes on its own once a phone uses it;
  - the paired phones, each with Unpair.
  The section is in search, including by its config key `mobile_access`.
- The daemon (`tty7-app --daemon`) runs a supervisor (`core::mobile`). It
  watches `mobile_access` in config.json, re-reading only when the file
  changes, and starts or stops the gateway. A failed start is retried every
  30 s and logged once.
- tty7-gateway grows a `service` module: `start()` returns a stoppable
  handle, and `pair_code()` makes a code. The CLI's `serve` and `pair` are
  thin wrappers over them now. The gateway logs through `log`, so the
  daemon's output lands in its log file, and it reports itself in
  `mobile/status.json`. `State::serving()` checks the lock, which a crash
  cannot leave stale. A gateway that cannot take the lock leaves the
  status alone, because it belongs to the one holding the lock.
- iroh is linked into the GUI binary only. tty7-server stays the lean static
  binary pushed to remote machines.

* feat(mobile): serve phones whichever daemon is running

A daemon started by `tty7 server start` is the lean tty7-server, which
carries no gateway. With phone access on, the Settings status stayed on
"Starting…" and no phone could connect.

The GUI now checks, 5 s after it starts and whenever phone access is
switched on. If nothing is serving, it starts `tty7-app --mobile-gateway`,
detached the same way as the daemon (`spawn::detach_helper`). The helper
serves until the switch goes off, and exits at once if another process
already holds the gateway lock. When the daemon's own gateway is up, no
helper is started. The helper logs under its own role, "mobile".

* refactor(mobile): the daemon owns the gateway, as a child, whoever started it

There were two ways of running the gateway: a thread inside `tty7-app
--daemon`, and a detached helper the GUI started when the daemon could not.
That is now one way.

Every daemon, whether `tty7-app --daemon` or `tty7-server`, runs
`tty7_core::daemon::mobile::supervise` from `run_with`. While
`mobile_access` is on it keeps the gateway running as a child process, and
stops it when the switch goes off.

- Which program: `tty7-app` runs itself as `--mobile-gateway`. `tty7-server`
  runs a `tty7-gateway serve --exit-with-stdin` from beside it or on PATH,
  and links nothing new. Without one, it writes the reason into
  `mobile/status.json` for Settings to show, instead of "Starting…" forever.
- Lifetime: the child's stdin is a pipe from the daemon, and the gateway
  exits when it closes. A stopped, crashed or handed-off daemon (the pipe
  is close-on-exec) takes its gateway with it, and the next daemon starts
  one from its own binary. No gateway from an older build survives an
  update.
- Isolation: iroh no longer runs inside the process that holds every pane.
- `Status` moves to tty7-core, the one definition that the daemon, the
  gateway and the GUI all share.
- Gone: the GUI's helper check (`core::mobile` in the app) and the in-daemon
  gateway thread.

* fix(mobile): stop and reap the gateway before a daemon handoff

Found by running a real `tty7 server restart`. The old gateway did exit,
because the new image's supervisor started its own gateway and the old one
lost the lock. But it was left as a zombie: the image after the exec never
reaps a child it did not start, so each handoff leaked a process entry.

`hand_over` now calls `daemon::mobile::stop_for_handoff` before the exec,
which closes the gateway's stdin and waits for it. A flag keeps the
supervisor from starting another in the moments before the exec, and
`handoff_failed` clears the flag if the exec never happens, so the daemon
goes on serving.

Checked with two handoffs in a row (tty7-app → tty7-server → tty7-server):
- each old gateway was reaped, with no zombies system-wide;
- exactly one fresh gateway was running after each handoff;
- the pane's shell and its environment survived;
- the probe phone kept working.

* feat(mobile): the switch shows whether phones can reach you, not a status row

Settings → Mobile had an "Allow phone access" switch that showed intent and a
separate Status row that showed reality. That is one thing shown twice, and
the switch could sit on while nothing was running.

- The switch is the state. Switching on holds it at "Starting…", disabled,
  until a gateway is actually serving. If the daemon reports a failure, or
  nothing comes up within 15 s, the switch goes back off, `mobile_access`
  is reverted, and a notification says why.
- If the page opens on a failure the daemon is still retrying, the switch
  shows off with the reason in its description, and switching it on
  retries.
- The Status row is removed, with its four strings. There are two new
  strings for the failure, in en, zh and ja.

Also fixes the Settings window never showing notifications. It is a `Root`
like the workspace window but did not draw the notification layer, so any
toast pushed from Settings was queued and never shown. That included the
existing "Set as Default Terminal" result.

Checked in a dev instance. On a tty7-server daemon with no tty7-gateway:
Starting… first, then off, with "Phone access could not start: … no
tty7-gateway beside it or on PATH". On a tty7-app daemon: on, with Show
code enabled and no toast.

* feat(mobile): drop the "Needs you" section

The machine screen gathered every pane whose agent was waiting or done into
a "Needs you" section above the workspaces. Done lasts until the next prompt,
so the section grew with every finished agent and mostly held panes that
needed nothing.

Panes now appear once, in their own workspace. Each keeps its status badge
and words ("Needs input", "Working", "Done") and the agent's message.
PRODUCT.md and the design sidecar are updated to match.

* fix(mobile): say when typing doesn't reach the pane

The gateway's input thread gave up silently on a failed send_input, and
the app's input task did the same on a failed write, so the phone kept
showing a live pane while keystrokes went nowhere. Both now report the
failure as a pane error. Keys after it are dropped rather than ending
the stream, which the phone would read as the pane closing.

* feat(mobile): a compose box, paste and Shift+Tab on the terminal

Replying to an agent meant typing into xterm a character at a time,
without autocorrect, dictation or a usable IME. The compose box is a
real text field: Send types the text and then Enter, as its own write,
and several lines go in as one bracketed paste when the program asked
for it. Drafts survive leaving the pane and a send that failed. An
agent's pane opens on the box with the keyboard down.

The key bar gains Shift+Tab (Claude Code's mode switch) and a paste key.
A failed keystroke now takes the pane offline with a Reconnect banner
instead of being swallowed.

* feat(mobile): reconnect on its own, and select text to copy

A dropped pane or machine stream is retried with backoff (1s, 2s, 4s …
15s) and at once when the network comes back, rather than waiting for a
tap on Reconnect. The pane keeps its last screen up until the new
replay starts, and output or errors from a replaced stream are ignored.

Touch selection does not work in xterm, so a copy key lays the whole
buffer out as plain text over the pane, wrapped to the phone and joined
where the terminal wrapped, for the phone's own selection and Copy.

* feat(daemon): size leases, and Take Back on the desktop

An observer can now run a pane at its own size (ClientMsg::Lease, feature
size-lease). The pty and every observer go to that size. The controller
keeps its grid, its resizes are remembered rather than applied, and the
pane goes back to the last of them when the lease ends: the observer lets
go, its connection closes, or the controller takes it back.

A controller hears about leases only after asking (Watch), since an older
client cannot decode DaemonMsg::Lease. The desktop asks on every attach,
spawn and relink where the daemon advertises the feature, locally or
through the host hello for remote workspaces, and shows the pane as in
use on the phone with a Take Back button.

* feat(mobile): take a pane over at the phone's size

The terminal's phone button asks the gateway to run the pane at the
phone's grid (PaneRequest::TakeOver), which it turns into a size lease on
the observer connection, named after the paired device. The grid follows
the keyboard and rotation; leaving the pane, or the connection dropping,
gives it back. When the desktop takes it back the app says so and offers
to take it over again, never doing it on its own. A daemon too old for
leases is reported, and the pane keeps working.

* fix(mobile): link SystemConfiguration and install a rustls provider on iOS

The first iOS build failed to link: netdev and system-configuration, pulled
in by iroh, need SystemConfiguration.framework, which the generated Xcode
project does not list. bundle.iOS.frameworks adds it on `tauri ios init`.

Once linked, the app panicked at launch: iroh builds its reqwest client with
`rustls-no-provider`, so a process-wide crypto provider must be installed
before any client is built. Install ring's, which is already in the tree.

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(mobile): keep the terminal's scrollbar on screen while panning

Panning a pane wider than the phone scrolled xterm's own box sideways with
the text. The box was only the view's width, so its vertical scrollbar
panned off with the columns and its scrollback stopped taking touches past
the first screen. The box now spans every column, and the bar is shifted
to the visible right edge as the view pans.

The bar is also drawn like the indicator WebKit shows for the pan, thin,
rounded and translucent, instead of VS Code's 14px square slider, so the
two axes match.

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(mobile): pair by scanning the QR code, and Enter and quick-answer keys

Pairing took a pasted `tty7pair:` code, which on a real phone means getting
text off the desktop somehow. A Scan button next to Paste now reads the QR
code tty7 shows, through tauri-plugin-barcode-scanner, and pairs straight
away. The camera runs behind the WebView with our own viewfinder and Cancel,
since the plugin's full-screen view has no way out. The plugin is registered
on phones only, so the desktop dev build is unchanged.

The key bar gains Enter, so an agent's highlighted choice can be confirmed
without raising the keyboard, and 1 2 3 y n for numbered choices and y/n
prompts.

Co-Authored-By: Claude <noreply@anthropic.com>

* chore(mobile): sign for the App Store and declare exempt encryption

Sets the development team so `tauri ios init` writes it into the Xcode
project, and marks the app's encryption (standard TLS/QUIC only) as exempt
so TestFlight uploads skip the export-compliance question.

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(mobile): count the iOS safe areas once

The WKWebView's scroll view inset its content by the safe areas, and the
page, laid out with viewport-fit=cover, padded by env(safe-area-inset-*)
as well. The viewport came out 778pt tall on an 874pt screen: everything
sat a status bar's height too low, with a blank band under it. The scroll
view's automatic inset adjustment is now off, so the page runs edge to
edge and its CSS alone keeps clear of the status bar and home indicator.

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(mobile): the Terminal Mobile redesign

The app takes the desktop's neutral greys, light and dark, with ink rather
than a system blue for what is pressed or chosen.

- Machines: pairing's "+" moves to a floating bar at the bottom beside a
  search field. Each machine shows its link, round trip and tab count as
  last seen.
- A machine: tabs grouped by workspace with a count; round agent glyphs;
  a dot on the right for running or waiting on you. The per-group New tab
  buttons give way to one "+" in the same floating bar, beside tab search.
- New tab: a sheet to pick Claude Code, Codex or a shell, and the
  workspace. An agent's command is typed into the new tab once it is live.
- A pane: the bar keeps only back, the title with its state, and a menu
  for selecting text, the fit and the phone's size. Under it, one row of
  equal keys, a page at a time, and a message box that is always there;
  its round button sends, or when empty hands the keyboard to the
  terminal.

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(mobile): the tty7 mark as the iOS app icon

The phone showed Tauri's default icon: `tauri ios init` filled the Xcode
project with it. The committed icons/ios set was drawn on the macOS grid,
a rounded tile inset on transparency, which iOS would shrink inside its own
mask with a pale border. icons/app-icon-ios.svg is the same Duo mark full
bleed, rendered without alpha as the App Store requires.

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS

* fix(mobile): typing, scrolling and pairing on a real phone

- Typing into a pane: an input method's text never reached it, since iOS
  never commits a candidate into xterm's hidden textarea. Tapping the
  terminal now focuses a plain field of our own, whose committed text goes
  to the pane as it is committed. Backspace on the empty field, Enter, Tab
  and the arrows go as the terminal's keys.
- xterm sends nothing itself any more (disableStdin). That also stops the
  phone answering a program's colour and device queries: the desktop
  answers those, and the phone's late second answer landed in the shell as
  typed text.
- Scrolling the scrollback: xterm 6 has no working touch scrolling. A
  mostly vertical swipe now scrolls the buffer a row at a time and coasts;
  a sideways one is left to the native pan.
- Pairing: the steps name the desktop's Settings -> Mobile, Allow phone
  access and Show code, not a command-line gateway, and so do the notices
  when a machine cannot be reached.

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS

* fix(mobile): room for the keyboard, and smoother vertical scrolling

- The keyboard: the WebView runs edge to edge and is not resized for it,
  so it covered the dock and the pane's last lines. The app now takes the
  size of the visual viewport, drops the home indicator's gap while the
  keyboard is up, and keeps the cursor's line in sight.
- Scrolling: the terminal draws with xterm's WebGL renderer, which a
  scroll does not make lay every row out again. A swipe is applied once a
  frame, and moves the view by pixels: xterm scrolls whole rows, and the
  rest of a row is a GPU shift of the drawn screen, put on together with
  the rows it goes with.

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS

* feat(mobile): settings, message history, and a tighter home screen

- Settings, from beside the Machines title: appearance (automatic, light,
  dark; the status bar and keyboard follow through the window's interface
  style), terminal text size, how a pane wider than the phone first shows,
  clearing the message history, and the version.
- The message box keeps what it sends on the phone. As a message is
  written, past ones that match take the key row's place; with the box
  empty, a History button opens them all, searchable. A line that asks for
  a password is sent but not kept.
- ^R on the third key page, for the shell's own history search.
- A top-level screen's bar floats over the list, clear until the title
  scrolls under it, so the large title sits just under the status bar.

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS

* fix(mobile): a fitted pane fills the view, and its scrollbar drags

- A pane shorter than the view (a wide one, fitted) no longer leaves the
  bottom of the screen blank: the terminal here runs as many rows as fill
  the view, the extra ones holding the pane's earlier lines, and what is
  left over goes above so the prompt stays next to the keys. The pane on
  the desktop keeps its size.
- A drag that starts on the scrollbar is left to xterm. The swipe handler
  took it too, the other way round, and the two cancelled out.

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS

* fix(mobile): errors say what to do in the app, not on the command line

The messages a phone shows, and the two Settings → Mobile can, named the
gateway process, the CLI's `tty7 server start`, the transport and a lock
file's path. They now speak of tty7 on the computer and of pairing: open
it there, update it, pair again, quit the other copy.

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS

* style: rustfmt the gateway and mobile client

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-29 19:09:32 +08:00
l0ng-ai 12ec0c92a9 fix(sidebar): stop ungrouping tabs when a git probe fails (#1011)
A tab's auto group comes from probing its cwd for a repository. Any
failure of that probe - git failing to spawn, the macOS /usr/bin/git shim
dying while Xcode is mid-switch, a remote link dropping - came back as
"not a repository", overwrote the tab's remembered group, and was never
re-checked while the pane sat idle. Tabs in perfectly good repositories
dropped into Ungrouped and stayed there.

- Read root, home and branch in-process on this machine with
  gix-discover instead of three git processes. Only the line counts
  still come from `git diff --numstat`, so they keep matching the diff
  views; a detached HEAD is still named by git for the same reason.
- Remote hosts keep asking their own git (a new control request would
  force a dialect bump), but the probe now tells "not a repository"
  (exit 128, or the directory is gone) apart from a failure.
- A failed probe leaves the cache as it was, so a tab keeps its
  remembered group, and an unanswered cwd is retried every 10s.
2026-09-29 16:55:03 +08:00
l0ng-ai 8cf31c718d feat(worktree): setup, .worktreeinclude, agent launch, recoverable removal, and a worktree CLI (#1009)
* feat(worktree): setup script, .worktreeinclude, fresh base, recoverable removal

- Start new worktrees from the remote default branch, fetched first, with
  --no-track; fall back to the current branch without a remote.
- Carry gitignored files listed in .worktreeinclude over from the main
  checkout, copy-on-write (clonefile on macOS, copy_file_range elsewhere);
  remote hosts copy through the Host trait under a size budget.
- Run .tty7/setup in the first pane before the agent, with TTY7_ROOT_PATH,
  TTY7_WORKTREE_PATH, TTY7_WORKTREE_NAME and a per-worktree TTY7_PORT block.
  The script only runs once its exact content is approved for the repo.
- The New Worktree dialog picks what the first pane starts (Shell or a
  recent agent) and takes a task for agents that open on a first message.
- Removal snapshots the checkout, uncommitted work included, under
  refs/tty7/trash/<name> first; the ref also retires the name. A branch
  git refuses to delete is reported instead of silently kept.
- Hide .tty7/worktrees via info/exclude rather than a catch-all
  .tty7/.gitignore, so .tty7/setup can be committed.

* feat(cli): tty7 worktree new/ls/rm

- worktree new: the GUI dialog's worktree from the command line — create,
  carry .worktreeinclude, open a tab named after the branch, and type
  .tty7/setup && <agent> [task] into it. Prints the path first.
- worktree ls: every checkout of the repo, tty7's marked, with the live
  panes working in each.
- worktree rm: refuses while panes are inside unless --close-panes, and a
  dirty checkout unless --force; reports the snapshot ref and a kept branch.
- Move shell_quote and the first-line builders into tty7-core so the GUI
  and the CLI type the same line.
- Docs: CLI reference and the Worktrees page cover .worktreeinclude,
  .tty7/setup, TTY7_PORT and recoverable removal.

* fix(worktree): run setup and the agent inside the worktree; Start is a dropdown

- The first line now opens with cd into the worktree: a shell's startup
  files can move the pane, and setup then ran in (and wrote into) the main
  checkout.
- The Start choice is a dropdown listing Shell and every agent this machine
  offers, instead of a segmented switch capped at three.
2026-09-29 16:54:59 +08:00
l0ng-ai c5cdf5382b feat(editor): redesigned find bar with a replace shortcut
Bumps gpui-component to e9dd0538:
- The find bar is one filled pill (search glyph, field, case, replace,
  "3 of 6" count, up/down, close) with no border or rule, and it no
  longer stacks its own padding on the editor's.
- The current match is amber, the other hits a neutral wash, so Enter
  visibly moves between them in any theme.
- ⌘⌥F / ⌘R (Ctrl+H elsewhere) opens find with the replace row.

The breadcrumb row drops to 22px and sets the symbol in the code font.
2026-09-29 10:00:08 +08:00
l0ng-ai 4b1336b089 fix(prompt): set the text prompt in the Interface font (#1008)
gpui paints a prompt as a root of its own, beside the window's Root, so it
inherits nothing Root sets: the card fell back to gpui's .SystemUIFont
instead of the Interface font the rest of the chrome uses. Also add a test
that the quit-and-stop question never falls through to the platform dialog
(gpui's unthemed single-line fallback on Linux, #920).
2026-09-28 23:15:36 +08:00
l0ng-ai 7f66f69674 fix(ssh): pin russh to our fork with the zlib truncation fixes (#997) (#1006)
A host with `Compression yes` (every one imported from an ssh config that
sets it) negotiated zlib@openssh.com, and the pinned ayamir/russh rev cut
every packet that inflated past 2x its compressed size. The zlib stream
desynced right after auth: the session showed as connected and never
printed a byte.

- Move the [patch.crates-io] pin to l0ng-ai/russh (branch tty7): ayamir's
  gssapi-with-mic commit plus Eugeny/russh 58886f4d and 24e2c374.
- Add an end-to-end test that runs a zlib session against an in-process
  russh server and checks every byte of a compressible + incompressible
  payload arrives (0 of 270336 bytes on the old pin).
- Re-importing an ssh config now updates `algorithms` on hosts that already
  exist, so dropping `Compression yes` and re-importing takes effect.
2026-09-28 23:07:49 +08:00
l0ng-ai 7d3cee4d71 feat(editor): v6 chrome — recency-capped file strip, open-files list, Dock/Fill switch
The header keeps only the most recently fronted files (3 docked, 7 filled,
fewer with side panels open) in their strip order; the rest sit behind a +N
button that lists every open file with a filter, keyboard navigation and
Close saved / Close others. A two-cell Dock/Fill switch replaces the header's
right-click menu, and a filled editor leads with a pill naming the terminal
it covers that docks it back.

Breadcrumbs lose their rule and use chevrons, with only the file name in body
ink. The status bar is 28px, leads with a missing language server, and reads
cursor, indent, encoding, line ending, language; the actionable readouts
answer hover and the cursor opens Go to Line.
2026-09-28 22:08:27 +08:00
l0ng-ai 7e23dd6ff1 fix(ui): widen three-answer prompts so the update dialog's buttons fit
The alert card is a fixed 360px and its buttons never shrink, so the update
prompt's three answers (Update and relaunch / Install on Next Launch / Later)
ran past the edge and were clipped. Prompts with three or more answers now
use a 460px card, and the answer row wraps (still flush right) as a fallback
for locales with longer labels.
2026-09-28 21:58:44 +08:00
l0ng-ai afe24f0afc feat(terminal): upload pasted and dropped files to remote panes (#1004)
Copying a file in Finder and pasting it into an SSH pane, or dropping one
onto it, used to paste this machine's path — which the remote program
cannot open. Only clipboard images were uploaded first.

Every local path a pane is handed now goes through one route: uploaded
into its own directory under ~/.cache/tty7/clipboard on an SSH host (so it
keeps its real name), rewritten for WSL, and pasted as-is locally. Folders
upload recursively, a transfer is only abandoned once it stops moving, and
staged pastes older than a week are pruned.

Rows of a remote Files tree now drag as their own type instead of
ExternalPaths, so no drop target mistakes a far-side path for a local file.
2026-09-28 20:47:13 +08:00
l0ng-ai 7016fdb7ed feat(editor): IDE-level code editor — multi-cursor, LSP, git gutter, symbols, split (#1002)
* fix(keymap): let the code editor's multi-cursor chords beat the pane keys

gpui-component now binds secondary-d, secondary-shift-l and
secondary-alt-up/down in the Input context for multiple cursors. A
context-free binding ranks as deep as the focused context and ties go to
the one added last, so tty7's SplitRight and FocusPaneUp/Down took those
keys inside the editor. Re-add the editor bindings after tty7's table; other
text fields have no handler for them and fall through to the pane keys.

* feat(editor): show the selection count in the status bar

With several cursors the Ln/Col readout (the primary caret's) is followed
by "(N selections)".

* feat(editor): git change markers in the gutter

Diff each buffer against its file's index version (what VS Code's quick
diff and the SCM panel's Changes compare with) and hand the hunks to the
editor as gutter markers: added, modified, and a wedge where lines were
deleted. The base is read with `git show :./name` through the buffer's own
host, so remote workspaces work too; SFTP buffers and untracked files get
no markers. It is re-read when the repository's SCM epoch moves, on save
and when the path changes; the diff itself is a line-level Myers diff run
off the UI thread shortly after each edit.

Next/previous change and Revert Change (one undo step, also in the
right-click menu) are commands; clicking a marker opens a peek of the
staged lines with a Revert button. The editor watch now also follows the
repository the gutter found, so a stage or checkout refreshes the markers.
The `editor_git_gutter` config (default on) is flipped by the
ToggleEditorGitGutter command.

* feat(editor): go to symbol, breadcrumbs, and back/forward navigation

Go to Symbol (Cmd-Shift-O in the editor) lists the file's outline on a new
Symbols tab of Search Everywhere: indented by nesting while browsing, ranked
flat with the containing symbols as a subtitle while searching. Arrowing
through the rows previews each symbol; Escape puts the caret and the scroll
back, Return keeps it.

The outline comes from the tree the highlighter already parsed, with a small
query per language (Rust, Go, Python, JavaScript, TypeScript/TSX, C, C++,
Java, Markdown, Ruby, shell). Tty7App::editor_set_document_symbols lets a
language server's documentSymbol answer replace it per buffer.

A breadcrumb row over the text shows the file's path from its project root
and the symbols around the caret; the symbols open Go to Symbol.

Back and forward (Ctrl-- / Ctrl-Shift-- on macOS, Alt-Left/Right elsewhere)
walk a per-tab history. Jumps are noticed by sampling the caret whenever the
editor draws: a change of file, or a move of ten lines or more without an
edit, records where the caret was. Quick open, go to line, file links and
anything that goes through open_file_in_editor_at are therefore captured
without hooks of their own; a place in a closed file reopens it.

* feat(editor): bind next/previous change to Alt+F5 in the code editor

Bind EditorNextChange / EditorPrevChange to alt-f5 / shift-alt-f5 in the
Input context only, after tty7's own table, so a terminal never loses the
function key. Mark the hunks stale right after a revert, before the
input's Change event lands, and cover the whole loop (markers, stepping,
revert as one undo) with a window test.

* feat(editor): line commands in the editor's right-click menu

Toggle Comment, Move Line Up/Down, Duplicate Line, Delete Line and Go to
Matching Bracket, dispatched to gpui-component's new editing actions so
each row shows its chord. Strings in en, zh and ja.

* feat(editor): language servers for the code editor

A new ui::lsp module runs language servers for local files the editor
opens: rust-analyzer, typescript-language-server, pyright (or pylsp),
gopls and clangd, from a registry table. Each server is keyed by
(server, project root), found from markers such as a Cargo workspace,
package.json, go.work/go.mod or pyproject.toml, and shared by every buffer
under that root. A server missing from PATH (which tty7 already fills from
the login shell) means no LSP for that language and a one-line hint in the
status bar.

The JSON-RPC client frames Content-Length messages over the server's stdio
on dedicated threads, holds everything back until initialize is answered,
cancels requests nobody waits for any more, and answers the server's own
requests (configuration, capability registration, applyEdit). Documents
use full-text sync, debounced, and flushed before every request. A server
whose last file closed shuts down after a grace period, every server exits
with the app, and one that crashes is restarted a few times before it is
left down.

Features: diagnostics as underlines with hover messages and an error and
warning count in the status bar; completion (snippets flattened to plain
text); hover; go to definition by secondary-click or F12, across files
through open_file_in_editor_at; code actions on the editor's own menu
(cmd-.), resolved and executed as the server needs; Format Document
(shift-alt-f); and Rename Symbol (F2) in the editor's bar, applied to open
buffers and to files on disk. The key bindings sit in the Input context so
F2 and F12 stay with terminal programs.

Positions are converted at the boundary: servers count UTF-16 units,
gpui-component counts chars, and the rope counts bytes.

The new editor_lsp setting (default on) turns it all off.

* fix(editor): clear the change markers when the file loses its base

A file that becomes untracked or leaves its repository kept the markers
of its last diff; clear them when the base goes away. Guard the base read
against a panic, which would otherwise leave the fetch flagged forever,
and test the read against a real repository: the base is the staged
version, and untracked files have none.

* test(keymap): the editor's navigation chords win inside the editor, not in a terminal

* fix(keymap): let the code editor's line commands beat the app's chords

The editor binds toggle comment, move/copy/delete line, insert line, select
line and go-to-bracket on its CodeEditor key context. A context-free app
binding ranks as deep as the focused context and wins the tie by being
added later, so ⌘/ (shortcut sheet), ⌘↵ (fullscreen), ⌘⇧↵ (maximize) and,
off macOS, ⌥↑/⌥↓ (pane focus) took those keys inside the editor. Re-add
them in fixed_bindings on CodeEditor, which only a multi-line code editor
declares, so plain text fields and the terminal keep the app's keys.

* fix(keymap): route cmd-K cmd-D to the code editor's skip-occurrence

The chord starts with ClearScrollback's key on macOS, and gpui drops a
pending chord that ranks below a complete match, so the fork's binding
never got its second key. Re-add it after tty7's table, in the CodeEditor
context only, so other text fields don't wait on cmd-K.

* feat(editor): history follows edits, and paging is not a jump

Places in the back/forward history now move with lines inserted or deleted
above them, read from the editor's line-edit log on every change. The caret
move a Page Up/Down, paste, undo or redo makes is heard through the
keystroke that caused it and is not recorded as a jump.

* feat(editor): Problems list, keyboard change peek, Editor settings

- Problems: every error, warning and note the language servers published
  for the open files, grouped by file, at the foot of the code panel.
  The status bar's counts and ToggleEditorProblems (Cmd/Ctrl+Shift+M)
  open it; a row opens its file at the line and column. Read through a
  new LspStore::diagnostics_snapshot, mapped to editor columns.
- EditorPeekChange (Alt+F3 in the editor) peeks the change under the
  caret, or goes to the next one. The peek now takes the keyboard from
  a click too: Enter reverts, Escape closes and hands focus back.
- Settings > General gains an Editor group: git change markers,
  language servers, soft wrap and rendered Markdown, searchable and
  resettable like every other row.

* feat(lsp): outline, references, workspace symbols, signature help

- documentSymbol feeds the editor's outline (breadcrumbs, Go to Symbol)
  through editor_set_document_symbols, refreshed 500 ms after typing
  pauses. Flat answers are nested by range; an empty answer from a server
  still indexing leaves the tree's outline in place.
- Find All References (shift-F12) and a definition with several answers
  open a Locations tab in the search. Arrowing through it previews a place
  in the file in front, and Return goes there, into any file.
- Go to Symbol in Workspace (secondary-T inside the editor) asks the
  server's workspace/symbol as the query is typed, into the same list.
- Completion items are resolved for their documentation and auto-import
  edits, which are applied on accept (with the gpui-component fork).
- Signature help opens on the server's trigger characters (or on '(' and
  ','), stays current while typing in the call, and closes when the server
  says the cursor has left it or on Escape.
- Diagnostics are replaced wholesale on publish; between publishes the
  fork now carries them through edits instead of dropping them.
- workspace/configuration answers from per-server settings, with an empty
  object for a section tty7 sets nothing for. rust-analyzer gets
  checkOnSave with cargo check, also as initializationOptions, and every
  server gets didChangeConfiguration after initialized.

* feat(editor): text commands in the palette and keymap

Transform to Upper/Lower/Title Case, Trim Trailing Whitespace, Join Lines
and Remove Surrounding Brackets, as tty7 actions (bindable on the
Keybindings page, unbound by default) and as palette rows offered while a
buffer is open. Both run gpui-component's editing action on the active
buffer. Join Lines gets VS Code's ctrl-j as a fixed CodeEditor binding on
macOS, where the terminal keeps it as a line feed. Strings in en, zh, ja.

* feat(editor): split the editor into two groups

Cmd-\ (Ctrl-\ off macOS, bound only inside the editor so the terminal keeps
SIGQUIT) opens the file in front in a second group on the right. Each group
has its own file in front and, for different files, its own caret and
scroll; Cmd-Alt-Left/Right (Ctrl-Alt off macOS) or a click moves the focus
between them, and a group whose last file closes goes away. The split is
saved with the tab's other editor state.

The focused group is always TabCode's own files/active and the other waits
beside it, so everything that acts on the file in front - saving, go to
line, language servers, change markers, multiple cursors, history - follows
the focus unchanged. A file shown in both groups is drawn once, in the
focused one; the other shows a placeholder that brings the focus over. A
second InputState kept in sync would have needed every hook attached twice.

Also: palette rows and View menu items for Go to Symbol, Back, Forward and
Split; Cmd-Shift-O closes Go to Symbol when it is open; the status bar no
longer repeats the path the breadcrumbs show (a rendered Markdown file keeps
its breadcrumb path); change markers are kept current in both groups.

* test(keymap): the editor group chords win inside the editor

* fix(lsp): close a window's documents when the window closes

Documents were only closed by sync_window, which runs when a window's
buffer set changes. Closing a window never ran it, so no didClose was
sent, the idle shutdown never started, and a language server lived on
until quit (forever, with the app retired to the tray).

* fix(editor): restore a split whose left group had no recorded files

The recorder writes files: [] with a split when the left group held only
untitled or remote buffers, but restore returned early on an empty left
list and dropped the right group too.

* fix(editor): forget a swept orphan buffer's navigation state

The orphan sweep dropped clean buffers without calling forget_buffer, so
each one's outline cache (a full copy of its text), LSP symbols and
edit-log cursor stayed in EditorNav for the life of the window.

* fix(lsp): owner-only sync, stale-edit checks, request timeouts, re-enable

- Only the buffer that owns a document may use its server. The same file
  open in another window used to send its own text as didChange on F12,
  rename, references or signature help, swapping the document under the
  owner. LspStore::context now takes the requester and refuses a
  non-owner quietly, before anything is sent.
- apply_workspace_edit checks every open buffer an edit touches against
  a baseline: the texts when a rename was asked for or the code-action
  menu was filled, or the text the server last heard for its own
  workspace/applyEdit (which then answers applied: false). A buffer typed
  in, opened or closed since means nothing is applied.
- A request made after the server's output closed fails at once instead
  of waiting forever. Requests time out after 10 s (initialize after 60 s,
  shutdown after 2 s) and cancel themselves on the server.
- Turning editor_lsp back on asks every window for its open files again,
  which starts their servers. Windows register how to be asked; closed
  ones are forgotten.

* test(nav): spell out LineEdit's new at_line_start field

gpui-component's LineEdit now records an insertion at column 0, which
moves the whole line down. The literal edits in this test are mid-line.

* fix(editor): a restore merges into the tab, and commands follow the group focus

Session restore used to assign the recorded groups over whatever the tab
held when its files finished loading, so a file opened or a split made in
the meantime was lost. TabCode::restore_groups keeps a split made meanwhile
as it is, and otherwise lays out the recorded groups and puts the files
opened meanwhile back into the focused group, the last of them in front. A
restore the reader has moved on from no longer takes the keyboard, and never
hides a panel they opened.

The group focus only followed the keyboard when the editor drew. Keys are
safe - gpui draws a window whose focus moved before dispatching the next
key - but a command from the menu bar or a context menu is dispatched
without a draw, and acted on the group that had the focus before. A
capture-phase listener for every editor command on the editor's element now
settles the group first, wherever the command's handler sits.

* fix(editor): leave cmd-T to New Tab; offer workspace symbols from the palette

Inside the code editor cmd-T was rebound to Go to Symbol in Workspace,
which made tty7's most-used chord mean two things depending on focus.
It is New Tab everywhere again. Workspace symbols stay reachable as an
Editor palette row and as a rebindable, unbound action.

* build: pin gpui-component to the fork's editor work (0e7541fb)

* fix(search): let the editor's pickers stand alone in Search Everywhere

Go to Symbol, a language server's places and Go to Symbol in Workspace
opened on hidden tabs, so the window-wide scope row (All, Terminals,
Sessions, Hosts, Commands) sat over them with nothing selected, and Tab
swapped the list for the terminals. They now show a heading in place of
the row (References / Definitions / Symbols / Workspace Symbols, with a
count), Tab stays put, and the footer drops the scope hint.

* fix(search): Go to File stands alone like the editor's pickers

Go to File (cmd-O) is reached only by its chord, yet it sat under the
scope row with nothing lit and offered Tab to leave for the terminals.
Every tab outside the row now stands alone the same way: its name in
place of the row, Tab stays put, no scope hint in the footer.

* feat(search): give the editor its own scope row — Files, Symbols, Workspace Symbols

Go to File, Go to Symbol and Go to Symbol in Workspace were three
separate pickers, each on its own chord. They now share a second scope
row, the editor's, next to the window's: cmd-O and cmd-shift-O open on
it and Tab walks it. Only tabs that can answer show: Symbols needs a
file in front, Workspace Symbols a language server that searches the
project. A row of one shows as a heading. Each tab is opened the way its
chord opens it, so it arrives set up; references and definitions still
stand alone.

* feat(search): fold Workspace Symbols into Symbols

Symbols and Workspace Symbols answered the same question at two scopes.
Symbols now does both: with nothing typed it is the file's outline; once
a query is typed, the front file's language server is asked across the
project and its answers are listed after the file's own, each under a
heading when both have rows (the front file's own hits are dropped from
the project's). The separate tab, action and palette row are gone.

* fix(search): call the language server's project results Project, not Workspace

LSP's workspace/symbol searches the server's project root, which has
nothing to do with a tty7 workspace (a group of tabs). The Symbols tab's
second section said Workspace, reading as if it searched those. It says
Project now, and the tty7-facing names follow (project_symbols,
set_project_symbols, lsp_project_symbol_query); only code that speaks
the protocol keeps its word.

* ci(host-boundary): allow the language servers' local reads

ui::lsp only ever holds local buffers (OpenFile::local refuses any other
host) and runs its servers on this machine, so the files it reads to
measure a column, apply a rename to disk or find a project root are on
this disk. Each call is allowlisted with that reason.

* test(editor): spell test paths so they hold on Windows

The language-server tests used /p/... paths, which are not absolute on
Windows and so have no file:// URI; they now build platform paths
(lsp::test_path) or spell the URI out. The gutter and split tests
canonicalized their temp dirs to get past macOS's /private symlink,
which on Windows yields the \\?\ form no editor path is ever in; they
share a helper that canonicalizes everywhere but Windows.

* test(editor): resolve temp dirs the way the editor does

On the Windows runner the temp dir is an 8.3 short name (RUNNER~1),
which the editor's load expands through Host::canonicalize. The split
tests now resolve their fixtures through that same call instead of
guessing per platform.
2026-09-28 20:47:07 +08:00
l0ng-ai 3ef692b353 feat(agents): infer interrupted and stale turns, report permission prompts first-hand (#1003)
- Interrupts: an Esc / Ctrl+C (legacy, kitty and modifyOtherKeys forms)
  on a pane whose agent is mid-turn arms a 1s settle; if no hook event
  arrives, the turn is assumed over and goes Done. Claude's Stop skips
  user interrupts, so panes used to stay on working until the next prompt.
- Stale turns: a daemon sweep moves a turn that has been Working with no
  hook event for 30 minutes to Idle.
- Both set `inferred` on the session; the next real event clears it, and
  a tool finishing after a guess puts the turn back on Working. Inferred
  states raise no finish notification and no unread badge.
- Claude and Codex now hook PermissionRequest, and PreToolUse for their
  ask-the-user tools (AskUserQuestion / request_user_input), so Waiting
  shows the moment the prompt opens. Codex also gains PostToolUse, so it
  leaves Waiting once the approved tool has run.
- The "finished" desktop notification waits 1.5s and is dropped if the
  next turn starts first (queued message, Stop hook sending it back).
2026-09-28 20:47:01 +08:00