* feat(panel): add Search and GitHub tabs to the right panel
The right panel grows from three tabs to five. Five word labels do not
fit the panel's 280px resting width, so the tab row now draws a glyph
per tab and names it in a tooltip.
Both new panes are placeholders here; the content search and the
GitHub issues/PR browser land on top of this.
* feat(panel): find in files in the right panel's Search tab
The Search tab replaces its placeholder with a content search over the
active tab's project -- the same roots the Files tab shows -- on the host
that project lives on. Hits arrive as you type (debounced, with a
generation counter so a stale answer never lands), grouped by file with a
count, each line excerpted with its matches highlighted. Clicking a hit
opens the built-in editor at that line and column; Enter searches again.
Match-case, whole-word and regex toggles sit at the end of the field, and
the tab focuses its field whenever it is brought forward.
Host::search_content is new on the Host trait, implemented once in
host::content_search (ignore walk + regex) and run by LocalHost directly
and by tty7-server over a new SearchContent control request. The walk
honours .gitignore with or without a repository, skips dot-entries, binary
files and files over 1 MB, and reports a capped search as truncated. The
request is gated on a new `content-search` hello feature, so a server that
predates it is never sent it; the panel says the server needs updating
instead of showing no results. Conformance cases cover local and the
stdio server alike.
* feat(panel): browse GitHub issues and pull requests in the right panel
The GitHub tab follows the focused pane's repository: its root is resolved
the way the Source Control tab does, its remotes are read through the Host
(the tree may be on another machine), and the github.com remote is bound,
upstream over origin in a fork, with a menu to pick another.
The list switches between issues and pull requests, open and closed, 50 rows
a page with Load more; rows carry a state glyph distinct by shape, labels
(click one to filter by it) and relative times. A row opens the detail in
place: title, state, author, labels, description and comments as Markdown,
and for a pull request its branches, size and changed files. A file opens in
the diff overlay through a new supplied-patch DiffSource, so GitHub's patch
renders exactly like a local one without a git probe.
Read-only, and sign-in reuses the GitHub CLI: GH_TOKEN, GITHUB_TOKEN, then
`gh auth token`, found on PATH or at the Homebrew locations a Finder launch
cannot see. Signed out, public repositories still work; 401, 403, 404 and
rate limits are told apart and explained. Requests go out from this machine
over the installer's ureq stack and proxy settings, on threads of their own,
cached per repository with background revalidation. Remote images in issue
text become links instead of loading, and non-web link targets are disarmed.
The Info tab gains a GitHub row that opens the branch on the remote it
tracks, or the repository for a branch never pushed.
* docs: list ShowRightPanelGitHub with the other panel actions
* feat(panel): one-line GitHub rows, a pill for the current tab
- GitHub list rows are one line: state glyph, #number, title. Labels and
the age of the last update appear on hover, from state rather than a
group_hover display switch, which gpui cannot paint.
- The current right panel tab sits on the sidebar's selected fill; ink
alone could not tell five same-weight glyphs apart.
- The GitHub glyph is a 1.8px outline like the other tab icons, not the
filled mark.
- The detail byline names both times (opened / updated) so it no longer
reads as disagreeing with the list's update age.
* feat(github): show screenshots pasted into issues
Images GitHub hosts itself (github.com/user-attachments, a repo's
/assets, *.githubusercontent.com) now render in issue and PR text, each
in a paragraph of its own so the text view draws it at its size rather
than at line height. Images from any other host stay links, so opening
an issue still tells no third party that you read it.
gpui held a null HTTP client, so no remote image could load; the app now
installs the update check's reqwest client (same user agent and proxy)
at launch.
* fix(github): load private-repo screenshots, give inline code a neutral fill
- Pasted attachments (github.com/user-attachments/assets/<uuid>) want a
browser session on a private repository, which an API token is not.
The detail and comment requests now ask for the full media type, and
each attachment is swapped for the signed private-user-images URL the
rendered body_html carries for the same uuid.
- Inline code in rendered Markdown (the GitHub tab and the editor's
preview) sits on a faint neutral fill instead of the theme accent,
which is also the selection colour. Needs gpui-component 6af19d91 for
TextViewStyle::inline_code_background.
* style(panel): tidy the GitHub and Search tabs' top rows
- GitHub drops its heading row on macOS. It existed only to hold the
refresh tile, and no other tab has one; refresh now sits with the
repository's other actions, in the repo row and a detail's header.
- Search's Aa / ab / .* toggles are muted while off instead of body ink.
- Search's idle note puts the folder on its own line, spelled ~/…, so
the narrow column no longer breaks the path at a slash.
* feat(panel): order the right panel's tabs Info, Files, Search, Changes, GitHub
Info stays first as the default and the pane's overview; after it come
two pairs, the project's files (Files, Search) and its version control
from local to remote (Changes, GitHub), where Changes and GitHub were
split by the file tabs before. The palette, the Keybindings list and the
docs follow the same order.
* style(panel): drop the change count from the Changes tab
Beside one glyph of five, the number read as a badge on that tab alone,
and the Changes tab already leads with the same count under its own
heading. right_panel_tabs no longer needs the row's width, which it only
measured to decide whether the count fit.
* style(icons): fit the GitHub glyph to the other tab icons' size
The Lucide mark filled its whole 24px box, edge to edge, where tty7's
own icons keep about 3.5px clear, so at 15px it drew a size larger than
the four tabs beside it. Scale it to 0.9 about the centre, and raise the
stroke to 2.0 so it still renders at the others' 1.8.
* style(icons): a simpler GitHub glyph
Drop the Lucide mark's tail and redraw the head and legs on tty7's own
grid: the same ~15px live area and 1.8 stroke as the other tab icons, no
scale transform. The legs keep it reading as the Octocat; a head alone
read as any cat.
* test(github): find gh on PATH in the blank-variable token test
The test placed gh only at /opt/homebrew/bin/gh, which gh_candidates never
offers on Windows, so the Windows CI job panicked at unwrap. Put gh on a PATH
directory spelled with the platform's exe name instead.
* fix(github): close image and link bypasses in the issue Markdown sanitiser
Checked against markdown-rs (the parser TextView uses), several inputs got
past the line-based rewrite:
- is_github_hosted cut the host only at `/`, so
`https://evil.io?.githubusercontent.com/x.png` (and `#`, `\`, `/`)
counted as GitHub-hosted and was fetched from evil.io. The host now ends
at the first of `/?#\` and may hold only DNS characters.
- `<img src>` values were written into `` unescaped, so a `)` in
the value closed the image and opened a second one from any host. Written
destinations are now percent-encoded.
- `<image>` (which the HTML parser reads as `<img>`) passed as an ordinary
tag and loaded its src.
- A kept link target was copied without scanning; when the parser ended
the link elsewhere (open title, unbalanced paren) a `` inside it
came alive. Markup characters in it are now encoded.
- `file:///...` and similar character references passed is_safe_target
and decoded to a `file:` link. References are decoded before judging.
The rewrite still cannot see every construct the way the parser does
(code spans inside tag attributes, fences the parser rejects, multi-line
link definitions), so the detail view now also checks the parsed tree: a
block containing a non-GitHub image, an unsafe link or definition, or raw
`<img>` is drawn as its plain source instead.
* fix(github): hide gh's console, bound Retry-After, and reject URL authorities with ?#\
- run gh through proc::output_within with hide_console, so a Windows GUI
launch does not flash a console window and stdout is drained while gh runs.
- saturating_add a hostile Retry-After instead of overflowing i64.
- parse_github_url no longer accepts `https://evil.io#@github.com/o/r`.
* fix(search): no panic on an unbounded time budget, and read files through the size cap
ContentLimits arrive off the wire on a server; Instant + u64::MAX ms
panicked. A file that grew between the size check and the read was read
whole; it is now read through a take() at the cap.
* fix(panel): keep Load more on an empty filtered page, and drop another host's hits
- /issues pages filtered to one kind can come back empty while later pages
hold matches; the GitHub list said "No issues" and hid Load more. It now
reads on through up to five such pages and keeps Load more offered.
- While a new search runs, the previous hits stay on screen; if they came
from another host, a click opened their path on the active host. They are
now kept only when the host is the same.
Fix half-width punctuation, unify terminology (passphrase, Finder,
server), quotes and dash styles, and rewrite the most literal
translations. Point every language and the CLI at Settings →
Integrations, the page's actual name, instead of Settings → Agents.
* feat(search): list more agents' past sessions, and fork, copy or hide one
The Sessions tab listed Claude Code and Codex only, and a row could only
be resumed.
- Past sessions of Gemini CLI, Qwen Code, Pi, Oh My Pi, Kimi Code,
Copilot CLI, Droid, Qoder CLI and CodeBuddy are read from where each
keeps them (honouring QWEN_HOME, COPILOT_HOME, KIMI_CODE_HOME, …), with
the name the agent or user gave the session, else the first prompt.
Context blocks agents prepend (<system-reminder> and kin) no longer
hide a prompt.
- Cmd/Ctrl-E on a session row opens its actions: Resume, Fork Session
(agents that can fork, with the configured launch flags), Copy Session
ID, and Remove from List. Removing keeps the search open, drops the row
at once and remembers it in `hidden_agent_sessions`; the agent's own
history is not touched.
OpenCode and Cursor keep sessions in SQLite and are not read yet.
Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM
* feat(search): list remote workspaces' sessions, and OpenCode and Cursor
The Sessions tab only ever read this computer, and left out the two
agents that keep their history in SQLite.
- agent_history moves into tty7-core, and the scan goes through the
Host: a local workspace reads this machine in-process, a remote one
asks its server (new ControlRequest::AgentSessions; CONTROL_VERSION
11 -> 12, so each remote host takes one Update Server). Resumed or
forked sessions open on that machine, in the directory they ran in.
The last answer is kept per host so the tab does not open empty.
- OpenCode: top-level, unarchived sessions from opencode*.db (or
$OPENCODE_DB); a placeholder title gives way to the first prompt.
- Cursor CLI: chats under ~/.cursor/chats (or $CURSOR_CONFIG_DIR), named
from meta.json or store.db. Cursor files a chat only under the md5 of
its directory, so it is placed by matching open tabs' and other
sessions' directories; chats nothing matches are left out, since they
could not be resumed anywhere.
- SQLite is bundled (rusqlite), opened read-only, falling back to an
immutable read when the writer's WAL cannot be shared.
Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM
* test(search): wait for the real scan before seeding sessions
The search's own scan runs on a real thread. On CI it landed after the
test seeded its rows and replaced them, so the edit gesture found no
row. The test now waits for the scan first. Assertion messages no
longer print session ids (CodeQL rust/cleartext-logging).
Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM
* fix(search): harden the past-session scan and note it in the changelog
- Honour CLAUDE_CONFIG_DIR for Claude Code's projects, as the hooks
installer already does.
- Read a Codex rollout's head as bytes: the 2 MiB cap can split a
multi-byte character, and read_line then dropped the whole session.
- Escape `%` and `#` (not only `?`) in the immutable SQLite URI fallback,
so a database under such a directory still opens.
- Refuse a session id starting with `-`: ids now come from file and
directory names on disk, and one would be read as a flag by the
resume or fork command.
- Update the unreleased Sessions changelog entry for the new agents,
remote workspaces, the Cmd-E actions and the v12 dialect bump.
* fix(search): spell the immutable SQLite fallback as file:///C:/ on Windows
SQLite reads file:C:/x as a relative path, so the fallback open (and its
test) failed on Windows. An empty authority and a leading slash name the
file on every platform.
* test(search): keep ? out of the fixture directory name on Windows
Windows file names cannot hold a '?', so the fixture's create_dir_all
failed there before the fallback was ever opened.
Single choices were drawn two ways — segmented buttons for most, a
dropdown for a few — and the segmented rows ran to their labels' width,
so the right-hand column never lined up. settings_choice now renders a
dropdown; an off-preset value shows as a checked "Custom (N)" row.
The SSH strip's forward form keeps the segmented control: it lives
outside the settings window and has no popover state to use.
mouse_zoom_modifier now defaults to none. The platform modifier is cmd on
macOS, held for so much else that the font jumped size mid-scroll (#668).
Picking a modifier in Settings brings the wheel zoom back; cmd+/cmd- are
unchanged.
Before anything was typed, All showed only each tab's highlights: this
window's other tabs, actions already used, and sessions from this directory.
A fresh window had next to nothing to show. Each tab now leads with its
recent rows, is topped up from the rest of the tab to five, and ends with a
row into the tab for whatever did not fit.
With the tabs in the sidebar, the title bar's centred path repeated what the
rail already says. It is now a field-shaped button that opens Search
Everywhere, with its chord. The trailing ... menu, which only held Search
Everywhere and Settings, is gone: both stay on their shortcuts, the macOS
menu bar and the search itself.
- The changed-files filter keeps its view toggle inside the panel's content
inset, beside the field, so it lines up with the commit row above.
- A group heading's hover buttons are backed with the rail's own fill and
centred on the v4 heading line, instead of a white patch over the counts.
- Shorten the prompt cursor and SSH tab title descriptions to one line.
* feat(ui): restyle the right panel after the v4 design
- Tab row: 12.5/16rem word tabs 22px in and 18px apart, the current one in
body ink at medium weight; no hover pill, no underline bar, no hairline
under the row.
- Info: Session, Processes and Ports are spaced 16px apart with no rules;
28px medium muted headings, 28px Session rows on a 76px label floor with
values in body ink, 26px process rows with a tree elbow for children, and
an explicit empty line for Ports.
- Files: the search sits in a 28px filled well; tree rows are 26px with a
disclosure chevron column, ignored entries dim their icon instead of
going italic, and a folder's change dot is 5px.
- docs/design-system.md updated to match.
* feat(switcher): restyle the workspace switcher after the v4 design
- Card: 112px from the top, 12px corners, 48px search row with an esc
keycap, 420px body split 340px / preview, 40px footer.
- Workspace rows are 52px: a 26px initial disc carrying the link state as
a ringed dot (live green, faint when offline, amber while connecting,
red on failure), a medium name with its stable number, a machine ·
path · time line, and the tab count over the state word.
- Preview rows are 44px with the sidebar's 18px brand disc, an all-muted
branch · diff line, a Current label and a 5px dot that blinks with the
sidebar while an agent is working.
- Footer: ghost New workspace button and keycap hints for navigate, open
and new window; the unused click-for-new-window string is dropped.
* feat(scm): restyle the Changes tab after the v4 design
- Pinned block keeps 8/10/14 rhythm; branch name medium, 26px sync tile.
- Commit message box rests at 56px with a 7px radius.
- Split commit control: inverted neutral fill when committable, faint
fill otherwise; 6px radius and an inset 0.5px seam.
- Change groups sit 16px apart under 22px sentence-case medium headers;
file names take width first and directories right-align, eliding
from the start.
- History: 32px header, 26px rows inset with rounded hover, 1px lines
and 7px beads (HEAD filled, others hollow), neutral inks on a
single-lane page, age column always shown, faint HEAD pill.
* feat(ui): restyle the rail and palette after the v4 design
- Default Light/Dark take warm neutrals (#fcfcfb/#1c1c1e, #18181a/#ececed);
Git added/modified seeds follow v4 green and amber.
- The left rail gets its own tinted fill again (Neutrals.rail, 3% toward
the ink) with its own surface ladder; the right panel keeps the content
fill. Captions and hairlines are floored on the rail too.
- Title bar is 48px; the bar over the terminal centres the active tab's
title in caption ink when tabs live in the rail.
- Rail header: 26px new-tab and collapse tiles, then the workspace chip
and search field (28px, 7px radius).
- Groups sit 16px apart under a 22px caption heading with
'branch · +a −d' in tabular numerals.
- Rows are 30px (42px with a branch line), 16px avatars, medium weight
when current, branch cut from the front, and a trailing 5px status dot
(blinks while working, hollow while waiting, unread count as a pill).
- docs/design-system.md updated.
* docs(design-system): note the commit button's inverted neutral fill
* fix(panel): align the right panel's insets with the v4 design
- Rows pad 8px inside lists inset 12px, so text sits on a 20px column in
every tab and hover fills start 12px in with a 6px radius. Headings,
empty states and the Ports line move to the same column.
- Tab labels 18px apart; the panel row's chrome tiles are 26px, 4px
apart, 12px from the edge. Default panel width 280.
- Info: label column floor keeps values at x=88; Ports add tile 22px.
- Changes: 8px top gap on macOS, pinned block on 14px edges with the
branch at 22, 12px sync glyph, 8px group chevron, 10px status cell,
1px between rows.
- History: compact gutter for single-lane pages, filtered rows on the
text column, 10px row gap, 24px age floor, header on 20px insets,
4/12 padding when expanded (heights re-counted in commits).
- Files: search well at 12px with an 11px glyph, 10px before the tree,
16px indent step, 16px bottom padding.
* feat(diff): restyle the diff overlay and commit detail after the v4 design
Carry the v4 language into the diff overlay and the commit detail view:
0.5px hairlines at 8% ink, 26px row pills with a 6px radius, the rem type
ladder from right_panel.rs, neutral chips instead of accent washes, the
shared git_badge for status letters, and tabular figures on counts.
Layout, spacing, type and colour only; no behaviour or i18n changes.
* feat(ui): restyle the dialogs, notices and home page after the v4 design
- New ui::dialog module holds the shared modal chrome, taken from the
workspace switcher: a 12px card, a 48px title row with an esc keycap,
18px insets, a 40px hairline footer, 28px borderless field wells on the
faint fill, 11.5px medium muted labels, and 18px keycaps.
- Buttons: the primary is the inverted neutral fill, the Commit button's
paint, instead of the accent. Secondary buttons are transparent with the
surface's hover rung. Override on a changed host key stays the one red
button. A disabled button sinks to the faint fill and drops its click
handler.
- SSH sheet: host and fingerprint lines sit in a mono detail well, and
keyboard-interactive prompts become field labels. Banners match the
sheet's width and card shape.
- Worktree prompt: moves to the same card, with the path preview hung off
the Name field.
- Notice pill: severity moves from a tinted edge to a 6px leading dot.
- Home: shortcut rows are 28px with a hover fill and keycap chords, and the
remote strip's action uses the secondary button.
* fix(panel): start Info and Changes flush under the tab row
Their first line is text centred in a 28px row, so the extra 8px step put
it visibly lower than the Files tab's search well. Only Files keeps it.
* fix(scm): put the commit detail on the right panel's 20px text column
* feat(palette): restyle the command palette after the v4 design
- Card: the switcher's 12px corner, 112px drop from the top (shorter
windows still scale it up), 600px max width.
- Search row keeps the list's own field; an esc keycap sits in its
trailing corner while the field is empty.
- Rows are 32px with an 8px corner, 8px list inset and 10px padding. The
keyboard row takes the popover's neutral selected step and a medium
title instead of the accent wash, via a palette row element in place
of ListItem.
- Section headings: 28px, 11.5/16rem medium caption ink, on the rows'
text column. Shortcuts are per-key 18px faint keycaps from ui::dialog.
- New 40px footer with the switcher's keycap hints (navigate, open).
- Empty state: headline in body ink, hint in caption ink.
* feat(ui): carry the v4 chrome into panes, the file viewer and SFTP
- theme: additive helpers for a device-pixel hairline, tabular figures
and an inverted neutral button variant.
- Pane splits rest as a device-pixel hairline in the divider tone; hover
and drag keep the accent at 1px like the other resize edges.
- File viewer header: medium file name, 5px unsaved dot, 26px/6px close
tile with its glyph on the content inset, divider hairline under it.
Status bar: divider hairline, caption size, tabular line/column.
- SFTP browser: file-tree rows (26px, 6px corner, 16px caption glyphs),
breadcrumb and notes on the 20px text column, a borderless edit well,
inverted OK button, and ink-on-track transfer progress.
- Forward rows line up with the process and port rows (text at 20px,
6px corner); Add and Reconnect use the inverted neutral fill.
* docs(design-system): note the v4 palette, pane, viewer and SFTP chrome
* feat(settings): restyle the settings page after the v4 design
- Nav: the rail's tinted fill and surface ladder behind a divider hairline;
a 28px filled search well; 28px rows in 7px pills, the current one on the
selected rung at medium weight instead of the accent; match counts in
muted ink; the modified-only filter toggles like a nav row.
- Pages: the title sits in the 48px title-bar band at 16/16rem; group
headings are 11.5/16rem medium muted on a 28px line; sections are split
by a 0.5px divider with 16px either side.
- Rows: labels in body ink at regular weight, descriptions at 12/16rem
muted, 28px floor with 8px padding; a search hit wears the faint neutral
fill rather than the accent tint.
- Controls: text fields and dropdowns are 28px filled pills with no
outline; buttons, segmented tracks and steppers are 26px with a 6px
radius on the same fill. The one primary action per view (save theme
draft, connect, install update) is the inverted neutral fill of the
commit button. Switches and sliders keep the accent.
- SSH: host list header with 26px tiles and a filled search, 22px group
headings, 42px two-line host rows; the form's labels are a muted,
right-aligned column level with 28px fields; disclosure headers use a
chevron on a 28px band.
- Theme cards are filled and unoutlined, taking the selected rung while
open; the theme panel keeps the content fill with a divider edge and its
title in the title-bar band. Keycaps are filled with no outline and
shortcut rows are divided by 0.5px hairlines.
- right_panel::SECTION_GAP is now shared; docs/design-system.md updated.
* feat(ui): spell tab titles out in full in the rail and title bar
The rail's rows and the centred title have room to spare, so they take
the whole label from a new full_tab_label rather than tab_label's
three-segment cut; only the width they have decides what gets elided.
* fix(settings): even out the page rhythm and line up the columns
- Nav header: drop the min_h(ROW_H)/min_h(0) pair on the heading, which
measured ~46pt taller than it painted and opened a hole under the search.
- Page titles sit under the title-bar band, level with the nav heading,
instead of jammed against the window's top edge.
- Headings get a 22pt group-header row and hug their rows; rules keep more
air, so a heading reads as its rows' rather than floating between.
- SSH: the host list gives width before the nav, so the nav no longer
narrows on that page; its header, search well and detail title run level
with the nav's; the empty note starts on the host-title column.
- Window & Tabs no longer opens on a stray rule.
- Integrations: status leads the buttons on one line, in the meta ink.
- Terminal: the shell footnote stays close to its rows.
* fix(ui): stop eliding branches that fit, and seat the SCM branch on the text column
- elide_tail_clusters returned "…" plus the whole string when nothing
needed cutting, so the rail's group header printed …feat/v4-redesign
with room to spare. Return the text as-is when it fits.
- The group header only reserves the chevron's width when it draws one.
- The Changes tab's branch name no longer stacks a small button's padding
on the row gap; it starts on the file names' column.
* fix(ui): keep a tab's name in place when an inline rename starts
gpui-component's Input keeps 12px of inner padding even with
appearance(false), so the name jumped sideways as the rail row, the
group header and the top-strip chip swapped their label for the field.
Claude-Session: https://claude.ai/code/session_01Q9vsQSxAZjkwT7nRAiFF1J
* revert(settings): restore the page rhythm from before 08497d57
The title in the title-bar band, full-row headings, SECTION_GAP rules and
the shell footnote's spacing read better than the tightened version. The
bug fixes from that commit stay: the nav gap under the search, the stray
rule on Window & Tabs, the SSH column alignment and nav width, and the
one-line Integrations rows.
Claude-Session: https://claude.ai/code/session_01Q9vsQSxAZjkwT7nRAiFF1J
* revert(settings): restore the pre-v4 settings layout, on the rail's fill
The v4 restyle (541a887a) and the follow-ups crowded the page. Bring
settings.rs back to main's layout and give its sidebar the main window's
tab-rail fill, so the two sidebars read as one surface.
Claude-Session: https://claude.ai/code/session_01Q9vsQSxAZjkwT7nRAiFF1J
* feat(settings): rebuild the settings window after the v4 design
Rewrites the settings page to the Settings design: a sidebar with search,
per-page modified counts and a "Modified only" switch; quiet grouped rows
with an inline Reset; and the design's own controls (switch, segmented,
stepper, slider, text field, dropdown and popover menus) in a new
`settings/kit.rs`.
- Appearance: Light / Dark / System cards and a theme menu per slot with a
live preview, search, keyboard navigation and swatches. Font menus are
searchable and draw each family in itself.
- Keyboard shortcuts: back link, search, "Restore N changed", Default/tmux.
A recorded chord another action already has now asks Replace / Cancel
instead of taking it over silently.
- SSH: one column of recent hosts, "Show all" by source, search; details and
a six-field editor open in place. Auth, jump/proxy, forwarding and
advanced sections are no longer shown; saved values are kept.
- Integrations: machine menu, agent search, install summary, agent icons,
and a per-row menu (Reinstall, Reveal hook file, Uninstall).
- General gains startup and restore; updates and the server move to About.
- Search results group live rows by page; a Modified view lists changes.
The page code moves out of settings.rs into src/ui/settings/.
* fix(ui): lay truncating names out at their full width
Moves the gpui fork to 5d366e6, which stops a size measured under
truncation from answering the later whole-text measure. Before it, a
truncating name beside other content in a flex_1 column read as just its
ellipsis with the whole column free. Adds a switcher test that fails
without the fork change.
* fix(scm): seat the History chevron on the change groups' column
The History header now draws its chevron in the change groups' own box
and size, so its title starts where Staged Changes and Untracked do.
Folded, the header drops to 24px with even padding instead of the
expanded section's taller band.
* chore: ignore local design mockups and Impeccable state
* fix(macos): show enter and tab shortcuts correctly in menus
Moves the gpui fork to 5c390b9, which maps enter and tab to their native
key equivalents. A menu item bound to secondary-enter, like
ToggleFullscreen, read as ⌘E.
* feat(search): replace the command palette with tabbed Search Everywhere
The palette was one flat list that every new kind of row had to be squeezed
into: tabs and SSH hosts rode along as "Switch to Tab: …" and "SSH: …"
commands, and the only way to narrow to one kind was a magic seed word.
Search Everywhere splits it into sources behind one trait — All, Actions,
Terminals, Hosts — each with its own empty-query layout and ranking. The All
tab shows each source's top rows, ordered by best match, with a row that
opens the full tab. Tab / Shift-Tab walk the tabs and keep the query.
- Terminals lists every open tab of every workspace (reusing the switcher's
tab rows) and jumps to it wherever it lives, plus the shells and agents.
- Hosts replaces the separate "Add Connection" input: a typed address or
full `ssh …` line offers to connect.
- Fixes Return doing nothing after a search that found nothing, or when the
search opens pre-filtered: gpui-component re-picks the row from a stale
frame; the delegate now re-arms the first row.
- Fixes `ssh -p 2222 me@box` being offered as a quick-connect address with
user `ssh -p 2222 me`.
The keymap action stays `TogglePalette` so custom bindings keep working.
* feat(search): a Sessions tab to resume past agent sessions
Search Everywhere gains a Sessions tab listing the Claude Code and Codex
sessions on this computer, read from ~/.claude/projects and
~/.codex/sessions ($CODEX_HOME). Sessions that ran in the focused tab's
directory lead; the All tab offers the last three of them before anything
is typed. Return opens a new tab in the session's directory and runs the
agent's resume command with its configured launch flags.
- Only each transcript's head and tail are read, off the window thread,
and cached by path, size and mtime: ~170ms cold for 50 sessions,
under 1ms warm. The search opens on the cached list and fills in.
- Titles: /rename name, then the agent's own title (ai-title, Codex's
session_index.jsonl), then the first thing typed, skipping harness
injections. Codex rollouts it ran for itself (subagent/internal) and
sessions never asked anything are left out.
- A session whose directory is gone is refused with a notice rather than
resumed where the agent cannot find it.
A new prompt_cursor_style setting (follow, block, bar, underline) shapes
the caret while the shell waits at a prompt, whether tty7's inline editor
or the shell's own line editor draws it. `follow`, the default, keeps
cursor_style everywhere, so nothing changes until it is set. Any other
value leaves cursor_style to the programs the shell runs: bar here with
cursor_style block gives kitty and ghostty's bar at the prompt and a block
inside a TUI that never sets a shape, such as Claude Code. A vi-mode
prompt keeps the shell's own insert/normal shapes.
Settings shows both cursor shapes as dropdowns, kept in step with resets,
language switches and config edits made outside the window.
Closes#958
* feat(links): make Windows file paths clickable
Drive-letter paths with either separator and UNC shares resolve as file
links, including when CJK prose or a Markdown link is glued onto them.
Windows paths are spelled with backslashes and an upper-case drive so
Explorer can open and reveal them, the Windows join is textual so a Mac
asking a Windows host sends one spelling, and a POSIX pane looks a drive
path up under /mnt/<drive> for WSL. Drive-relative tokens (a:b, C:,
C:notes.txt) are never probed.
Closes#965
* feat(links): quoted paths with spaces and Open with Default App
A path enclosed in matching double quotes, single quotes or backticks is
read as one candidate even when it contains spaces, with a line:column
location inside the quotes or right after the closing one. The quoted
span must look like a path (a separator, no space at either end, at most
260 chars) and yields a single reading, so quoted prose costs one lookup.
Unquoted spaces still end a path.
The file-link context menu gains Open with Default App, which always
uses the OS association. It is shown only for local files and hidden when
link_file_open is already system. The OS opener and Reveal now spell
Windows paths with backslashes before handing them to Explorer.
The pin icon read as a smudge at header size. Kept groups now carry a small
◆ beside their name — every kept group, label groups too, since with the
divider gone it is the one thing that tells kept from derived. On a folder
group the mark is still the click that unpins it, and the hover button that
pins an auto group shows the same character.
The divider is no longer drawn at rest. It keeps its (smaller) place in the
layout and its recorded bounds, so pinning a header by dragging it up and
handing a tab back by dropping it below behave exactly as before, and it
still shows as a line while it is the drop target.
The inline suggestion now takes the newest history entry that extends
the line, preferring one run in the current directory and falling back
to the newest anywhere, and skips commands whose last run failed. It
used to be the top frecency match, where run count and the directory
bonus outweighed recency. Ctrl+R keeps ranking by frecency.
Re-submitting a command now drops its older copy, matching the global
dedup applied when history loads, so up-arrow steps onto each command
once.
paint_marked blanks the cursor's cell to the theme background before laying
an IME composition down. A composition with nothing visible in it (Windows
IMEs can leave one behind) therefore painted a background-coloured hole with
an underline over the character and the block cursor on every cell the
cursor visited. Skip painting a preedit that has no ink.
Fixes#966
* feat(agents): recognise Empryo and Prime Agent
Prime Agent (PrimeIntellect-ai/prime-agent) is a Pi fork: detected as
`prime-agent`, resumes with `--resume <id>`, forks with `--fork <id>`,
`--no-session` opts out, and reports status through the shared Pi
extension bridge at ~/.prime/agent/extensions/tty7/index.ts.
Empryo is detected as `empryo` and resumes with `empryo --session <id>`.
No hook installer yet: Empryo filters TTY7* variables out of hook
processes, so `tty7-app agent-hook` would stop at the missing marker.
* feat(agents): Antigravity status hooks
Antigravity CLI (`agy`) now installs a `tty7` hook set in
~/.gemini/config/hooks.json, next to the user's own sets:
PreInvocation -> prompt-submit, PostToolUse -> tool-complete,
Stop -> stop. Only the first PreInvocation of a turn (invocationNum 0)
counts as a new prompt, later ones keep the turn working; a Stop with
fullyIdle false is ignored. conversationId and workspacePaths feed the
session id and cwd. PreToolUse is left alone because it must answer
with a decision.
* fix(agents): index Prime Agent and Antigravity in settings, scope conversationId alias
- Add settings titles, search keywords (en/ja/zh) and Agents index entries
for the two new HookAgents; agent_rows_are_in_the_search_index requires
one per HookAgent::ALL.
- Read Antigravity's conversationId as the session id only for antigravity:
the alias table is last-write-wins, so a global alias could replace
another agent's session id.
- Drop the stray .empryo/ job records.
---------
Co-authored-by: kalpak <you@example.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
* feat(tabs): MoveTabLeft / MoveTabRight — keyboard tab reordering
The drag that reorders a tab now has a keyboard form: the active tab trades
places with its neighbour in visual order, wrapping past either end. Ships
unbound like the pane-swap pair; bindable from config.json and the Keybindings
page, and listed in the palette and the docs.
* fix(tabs): keep a keyboard tab move inside its sidebar group
On a left tab bar the move stepped along the flat visual order, so a
step out of a group reordered self.tabs without moving anything on
screen (still saved, still synced as TabMove, and visible later on a
top bar), and a wrap through another group landed the tab at its own
group's far end by accident. The move now reassigns only the slots of
the tab's own sidebar section, and wraps at that section's ends.
---------
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
* feat(sidebar): keep pinned groups on the workspace and derive the rest
Replace the sidebar's hand-made groups with the model from #955: the sidebar
groups tabs by repo automatically, and you pin what you want to keep.
- Pinned groups (`PinnedGroup`: id, optional name, optional folder, fold) are
stored on the workspace in the machine tree, in display order, and a tab
points at one by `GroupId`. Everything else is an auto group worked out
every frame and never stored: by repo home, or by `user@host` for an SSH
pane — native or a shell that ssh'd onward — so `/home/ubuntu` on two
machines no longer lands under one header.
- A tab whose cwd *enters* a pinned folder joins it (deepest folder wins; a
repo home equal to the folder counts, which keeps worktrees with their
repo). It is edge-triggered through `EntryWatch`, so a tab dragged out
while still inside the folder stays out until it leaves and comes back, and
a tab restored at launch is not pulled in by where it already sits.
- Groups sync as one `WorkspaceSetGroups` / `GroupsChanged`, pushed only from
an edit and adopted from every pull, so a fresh window can never push an
empty set over the workspace's. The machine hands tabs naming a dropped
group back to auto grouping in the same mutation. Control dialect → v11.
- Config: `sidebar_grouping` (three modes) and `sidebar_collapsed_groups` give
way to one `sidebar_auto_grouping` toggle; folds live with the workspace.
- `tty7 tab ls` reports the pinned group a tab is in (name or folder leaf;
JSON carries id, name and folder).
* feat(sidebar): draw pinned groups above a divider, with their own gestures
The sidebar now reads as two halves: the groups you keep, in the order you
put them, then a divider, then the groups it works out (Arc-style).
- Pinned headers drag-reorder among themselves (their own reorder surface, so
a pinned header cannot be dropped among the derived ones); the order lands
on the workspace's group list, not on the tabs.
- An auto header carried above the divider is pinned when let go. With
nothing pinned yet the divider appears during that drag as a "Drop here to
pin" zone, since a hairline at the top of the list is nothing to aim at.
- A tab kept in a pinned group and dropped anywhere below the divider goes
back to auto grouping; the divider lights to say so.
- An empty pinned group stays, with a "+ New Tab" row that opens a tab in its
folder (or where ⌘T would, for a label group) and files it there.
- Folder groups carry a pin mark that unpins on click and a tooltip with the
folder; auto headers show pin and "+" on hover.
- Header menus: pinned — Rename, Set Folder… (local workspaces), Use Current
Tab's Folder, Clear Folder, New Tab, Unpin (folder groups), Delete. Auto —
Pin Group, New Tab. Nothing renames an auto group; nothing pins implicitly.
* feat(sidebar): open folders as pinned groups from Finder, the file tree and the palette
Every way into a pinned group the design calls for:
- Drop a folder from Finder or Explorer onto the sidebar to pin it (a local
workspace only — a dropped path is this machine's, and a folder group keeps
a directory on the workspace's host). Files are let fall.
- "Pin as Group" on a folder in the file tree, on local and remote workspaces
alike, since the tree and the group are both on the workspace's host.
- Palette "New Group" makes an empty label group and opens its name for
typing; "Open Folder as Group…" picks a folder with the system picker, pins
it and opens a tab in it. The picker browses this computer, so that one is
not offered on a remote workspace.
- Tab right-click "Move to Group" lists the pinned groups plus "New Group…",
which files the tab in a fresh label group with its name open for typing.
Pinning a folder already pinned hands back the group that keeps it rather
than making a second one to split its tabs with.
* fix(sidebar): let groups that arrive from elsewhere pull no tab into a folder
A window draws its first frames before its copy of the workspace's groups
lands, so every tab's entry watch recorded "in no folder" — and the groups
landing then read as each tab walking into its folder. A restored tab, or one
dragged out of its folder group, was pulled back in on every launch.
Groups adopted from a pull or from another window's `GroupsChanged` now start
every tab's watch over from where it is; only this window's own pin gathers
the tabs inside the folder, and says so tab by tab. A tab also goes up with
the group it names even when the window does not know that group yet, so a
sync in that same gap cannot send every kept tab back to auto grouping.
* docs(sidebar): describe pinned and auto groups, and log the change
Rewrite the sidebar page's grouping section around "grouped by repo
automatically; pin what you want to keep": the divider, folder and label
groups, the edge-triggered join, every way to pin, and the header menus. The
configuration reference swaps `sidebar_grouping` for `sidebar_auto_grouping`,
the CLI reference describes the GROUP column as the pinned group, and the
changelog gains an Unreleased entry (#955).
* fix(sidebar): file a tab opened by the CLI in a pinned folder into it
A tab that reaches a window as TabCreated — from `tty7 tab new` or another
window — started its entry watch as a restored tab, so opening one inside a
pinned folder left it in the auto group below. It is as new as a tab opened
here, and now joins the folder like one; every window that hears of it
reaches the same answer.
* test(machine): build the group sets in their initializers
Clippy's field_reassign_with_default on the two WorkspaceGroups the
set-groups test assembles.
* fix(sidebar): draw restored tabs in their auto group, and title by repo again
Auto groups are not stored, so after a restart every tab sat in Ungrouped
until its own repo probe came back, then jumped; before pinned groups the
stored repo key put it in place on the first frame. Each tab now carries
`last_auto`, the auto group it last resolved to, as a hint: stored with the
tab, sent up alongside its group in `TabSetGroup` whenever the live answer
moves, and used to draw the tab until the probe answers. The probe always wins
and rewrites the hint, and the hint never outranks a pinned group or the
folder-entry rule. Another window's hint only fills a gap, so two windows can
never bounce a disagreement between them.
The workspace's fallback title regained the repo majority it lost: the most
common pinned folder first, then the repo most unpinned tabs were last filed
under (a worktree counting toward its repo home), then a pane's cwd.
* refactor: drop what the new sidebar left unused, and two clippy findings
- `TerminalView::native_ssh_cwd` and its helper existed for the sidebar's old
folder grouping of native SSH panes; an SSH tab now groups by host, and
nothing else read it.
- The file tree's context menu takes `cx` instead of `danger` and the new
groups flag, back to the argument count it had on main.
- A title test builds its workspace in the initializer.
* feat(agents): quick launch for detected CLI agents (#955)
Every agent whose launch program is on PATH becomes a palette command,
"Agent: <name>", ordered by frecency and bindable as LaunchAgent:<slug>.
"New Agent Tab" (Cmd+Shift+A on macOS; unbound elsewhere, where
Ctrl+Shift+A is select-all) launches the most recently used one, and the
New Tab menu gains a single "Launch Agent..." row that opens the palette
pre-filtered to them.
A launch always opens a new pane (a tab in the active tab's cwd, or a
split when picked from the palette with Alt held) and types the command
into that pane's shell once it exists - immediately for a local pane, on
landing for a remote one via PendingSpawn::run_on_land - never into a
pane that was already there. Detection, status and resume then work as
for a hand-typed agent.
The command is the agent's bare binary unless the new `agent_launch`
config map overrides it. A wrapper named there is detected as its agent
without an `agent_commands` entry: the daemon folds the programs
`agent_launch` runs into its alias map (interpreters, shells and real
agent names excepted), reloaded when config.json changes instead of
once per process, and a mapped script run under its interpreter
(`bash ~/bin/cc`, `node cc.js`) is now recognised too.
A running agent's pane menu gets "Set Current Launch Args as Default",
which writes its launch argv - minus session flags and positional
prompts, joined with the settings' quoting - into `agent_launch`.
Remote workspaces cannot be asked for their PATH through the Host
trait, so they offer the agents previously seen running in that
workspace (WindowView::seen_agents).
* fix(agents): count only agents that start under a view, not ones reattached to
A view rebuilt over a running pane - every agent tab after an app
restart, or a workspace switched back to - saw its agent appear from
nothing and reported it as detected, bumping that agent's frecency once
per launch of the app. The terminal now remembers whether its link was
an attach, and such a view only reports agents once its shell has been
seen back at the prompt with no agent in front.
Also pins down that the agents seen in a remote workspace, its quick
launch list, persist in views.json with the rest of the workspace.
* fix(daemon): probe the foreground as soon as a new program takes it
The foreground probes ran on output only, at most once per 500ms
interval. A quick launch types the agent's command the moment the shell
is up, so the agent drew its whole first screen inside the interval of
the prompt it was typed at and then waited for a key: the pane never
learned it was running an agent until something else printed. Seen in
a dev instance, where a launched Claude Code stayed undetected at its
trust prompt.
The reader now asks the pty for its foreground process group on every
read (one ioctl) and probes immediately when it changes.
The + menu listed every shell the machine reports (nine on a stock macOS box)
above the SSH hosts. The Local section now names the default shell, always
first, then only shells that have actually been opened, by frecency, three rows
at most, the same way the SSH section caps its hosts.
Shell usage is recorded in a new `shell_frecency` config map, keyed by the
inventory label, bumped from both the menu row and the palette. Every shell is
now a palette command titled "Shell: {label}" (same word in every locale), and
an "Other Shells…" row opens the palette pre-filtered to them. That row is
hidden when the menu already names the whole inventory. Running a shell command
from the palette respects the ⌥/Alt split modifier like the menu row.
A tab can be put to sleep from its context menu or the command palette:
its panes are stopped (screens kept on disk), the tab keeps its place in
the sidebar, and selecting it wakes it through the same restore a reboot
runs, resuming a supported agent's session. The sleep mark lives on the
machine tree, so it survives app and daemon restarts.
Closes#762
A forward could only be removed, so pointing one local port at another
remote target meant deleting the rule and retyping the other one (#439).
Forward rules gain an `enabled` flag (serde default on, so saved profiles
and older peers keep every rule live) and the daemon a SetForwardEnabled
op for panes and workspaces. Off releases the listener and keeps the
entry; on rebinds it from the rule it was made from, and is refused by
name when another switched-on forward of the same owner holds the port.
The Ports panel and the Settings rules editor each get a switch; a
switch flipped in the panel on a rule from a saved host is written back
to that host.
Closes#439
Saved SSH hosts and their usage counts move out of config.json into
servers.json beside it, so config.json can be synced between machines
without carrying a server list (#911). An older config.json is split on
first load: servers.json is written first (0600), then only the two keys
are removed from config.json, leaving every other key as it was. When
both files hold hosts, servers.json wins and the stale copy falls out of
config.json at its next save. A servers.json that does not parse is kept
aside and blocks saves, as config.json does; hand edits hot-reload.
Settings -> Window & Tabs -> SSH tab title (`ssh_tab_title`) pins an SSH
tab to the profile name (saved host name, ~/.ssh/config alias, or the
address typed for a quick connect) or the hostname, on the OSC title's
rung of the existing label ladder: a renamed tab still wins, OSC titles
are still tracked, local panes are untouched (#726).
`tty7 exec %N -- CMD` types a line at an existing pane's shell prompt,
follows the shell integration's OSC 133 marks to the command's end, prints
what it printed (rendered to text by default, `--raw` for the bytes) and
exits with its exit code. `--timeout` exits 124 and leaves the command
running. A pane with no prompt marks, or one not at a prompt, is refused
before anything is typed.
`tty7 send` can take its text from `--stdin` or `--from-file`, sent byte
for byte and never echoed in --json, so a secret stays out of `ps` and
shell history. `--paste` frames the text the way the GUI's paste does:
bracketed when the pane has mode 2004 on, unframed otherwise, reported in
--json. The framing moves into tty7-core (`core::paste`) so the GUI's
clipboard paste, the agent prompt and the CLI share one construction, and
the daemon now reports each pane's bracketed-paste mode in PaneContext.
Closes#839Closes#838
* fix(render): scale fallback-font icons up to fill their cell
A lone Private Use Area glyph supplied by a fallback face is drawn at the
primary's font size on the fallback's own metrics, so Nerd Font icons came
out about two thirds of the cell. Grow such a glyph, aspect ratio kept,
until it fills the width of its cells or the height of the row (at most
2x), and centre it there. Overflow is still shrunk as before, text from a
fallback face keeps its metrics, and the primary's own icons are untouched.
Closes#866
* fix(render): fit fallback icons to their cells, borrowing a same-colour blank
Checked in the running app with Symbols Nerd Font Mono behind Menlo: its
icons ink a full em (1.6 cells), so growth alone never fired. What made
them small was the one-cell budget an icon gets when the space after it
paints a background, which is every icon in a coloured prompt segment.
Fit a fallback icon to its cells and one em of height instead, letting it
take the blank after it when that blank paints no background or the
icon's own, and only when that makes it bigger. Leave the Powerline
separators to the existing rule.
* docs(render): name icon_fit in the fit_scale test's comment
Linux has no native prompt, so every window.prompt fell through to gpui's
fallback renderer, which sets the message and the detail as unbreakable
single lines in a fixed-width box with overflow hidden. The quit-and-stop
warning was cut off mid-sentence. Install a prompt builder on platforms
without a native dialog that lays the same prompt out as a card whose text
wraps, in the app's own surfaces, with Return taking answer 0 and Escape
the cancel answer.
Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM
libproc's proc_listallpids takes its buffer size in bytes but answers
with the number of pids, and the macOS process table read that number
as bytes twice: once sizing the buffer (count / 4 + 64 slots) and once
reading back how much was filled (count / 4 again). On a Mac with ~700
processes only the first ~60 pids reached the table.
The kernel lists its newest processes first, so what survived was
whatever started most recently. A `go run` server launched a moment ago
was in; the pane's shell, started long before, usually was not, and a
walk from a root missing from the table returns nothing: no processes,
no ports, and a probe state of Ok. A freshly built parent/child chain,
which is what a quick check of the probe builds, is exactly the case
that happened to work.
The listing now goes through list_all_pids, which takes the call as a
closure so the size arithmetic is tested off a Mac against an emulation
of libproc's convention.
Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM
The README now opens on an animated WebP of the one-minute tour (GitHub
won't play an mp4 inline), linking the full-quality mp4. The docs home
page autoplays the mp4 in the hero slot. The old hero screenshot and the
separate tour poster block are gone.
Every placeholder frame in docs/ now shows a real capture of the current
build: 20 screenshots plus two short looping clips (prompt editor, pane
drag). The README and the docs home page link a one-minute tour covering
agent status across repos, one agent driving another through the CLI,
the prompt editor, diffs, pane dragging, and sessions surviving a quit.
A working agent's dot now alternates every 600ms between its colour and
a paler, still opaque, blend of it over the dot's ring, so a column of
tabs shows at a glance which agents are still going.
It rides the existing half-second home-cursor tick rather than an
animation: two repaints a second while some tab has a working agent,
and none once no agent is working (the dot settles back on its full
colour with one last frame).
On Windows and Linux the tabs sit under a full-width title bar, and a
second 40px band left them well down from the window's top. The row is
now the tab's hover pill plus 2px either side.
Settings used to cover the workspace it was opened from, hiding the
terminal a setting was being tried on. It now opens a separate window.
- The state and page stay on the workspace's Tty7App; a thin
SettingsWindow view borrows it to draw, observes it to repaint, and
sets its own rem size. The state is built against the new window, so
its inputs and subscriptions belong to it.
- Opening again raises the window instead of closing it. Esc, Cmd-W and
the close button go through close_settings_checked, so unsaved forms
and theme drafts still prompt; closing hands focus back to the
workspace window. The window goes when its owner is released.
- open_settings_then / close_settings_then run follow-ups in the right
window: loading an SSH form happens in the settings window, and
Connect opens its tab in the workspace window.
- Window opacity, blur and backdrop are pushed to every window, since
they are now changed from a window that is not the workspace.
- Tests keep the in-window overlay so they can drive settings through
their single test window.
Folded, the history section is the last line in the window and sat flush
against the bottom edge, inside the window's rounded corner. Pad it 2px
above and 4px below; the expanded section is unchanged, so its
commits-per-height pin still holds.
The v5 restyle turned the tab rows, the search field and the workspace
switcher into full pills, which read too round at this density. Put
back CARD_RADIUS on the rows, rounded_lg on the search field and
rounded_md on the switcher (and its rename field), keeping the 28px
row height. PILL_RADIUS has no users left and goes with them.
The workspace switcher painted its picked row a hard-coded #1768CF with
white text, in the workspace list, the tab list and the New Workspace
host dropdown. It bypassed the theme and was the loudest block on
screen. Use the popover's neutral selected step and keep each row's own
inks, so a taken-over warning still reads as one.
- Rails share the window fill and are separated by a hairline only;
the current tab is a neutral selected step plus a semibold title
instead of the blue navigation wash (the unused role is removed).
- Default Light theme takes ink #0F1419 and accent #1F6BF0; the caret
follows the accent.
- Sidebar: 28px pill rows with 18px avatars (two-line rows keep card
corners), pill search field and workspace switcher, group headings
in body ink with the chevron shown only when folded.
- Right panel: word tabs (Info / Changes / Files) with an underline
bar on a closing hairline. The Changes count is dropped before any
label is cut, and the panel floor grows with the measured labels so
the chrome tiles are never pushed off the edge.
- Headings are no longer uppercased; popovers use a 10px radius.
- docs/design-system.md updated to match.
On macOS the panel toggle and app menu tiles sat at the end of the terminal
column's strip whenever the detail panel was closed, including when a docked
diff or file column stood to its right, leaving them in the middle of the
window beside the document's header. Hide them while a document is docked and
stop reserving their width for the tab chips.
Three things went wrong with a Files panel rooted on a distro's \\wsl$
share:
- A drop brought a `name:Zone.Identifier` file along with every
downloaded file. fs::copy is CopyFileEx on Windows, which copies the
NTFS alternate data streams, and the share has no streams to keep one
in, so it lands as a file of its own. A copy onto a WSL share now
moves the contents only; one onto NTFS still goes through fs::copy
and keeps the mark.
- A file removed from the shell in the distro stayed in the tree. The
share accepts a ReadDirectoryChangesW and never reports a change, so
the watch looked healthy and was deaf. Directories on a WSL share are
now watched by a notify PollWatcher every 2s instead, made the first
time one is needed.
- Right-clicking a row did not select it, so nothing marked the row the
menu was about. A right click now selects the row without opening it.
Dropping a RemoteWatch sent WatchClose with a blocking call, and the last
handle is usually let go on the UI thread: from Tty7App::render via
scm_sync_watchers, and from scm_watch_opened when an open lands after its
subscription moved on. Every window froze for a round trip each time, up
to WatchClose's 5 s deadline on a quiet link. Sampling a live instance
caught ~1.1 s of such stalls in 10 s.
- ControlClient::post sends a request without registering for its reply;
the reader already drops replies nobody is waiting for.
- RemoteWatch::drop posts WatchClose instead of calling it.
- pane_workspace_for built the full SSH spec, keychain lookups included,
only to strip the secrets again. It now builds it from NoCredentials,
which takes the securityd trips off pane_liveness::sweep.
Claude-Session: https://claude.ai/code/session_01YX786Hyr4ivijWxv66zVkf