368 Commits
Author SHA1 Message Date
l0ng-ai c84f761783 fix(mobile): read frames cancel-safely so a slow link can't desync a stream (#1093)
read_frame awaits the header and the payload separately and keeps nothing
between them, so dropping it mid-frame discards the bytes it has read and
leaves the stream inside a payload. The next read takes terminal output for
a length: "Frame of 2086478377 bytes exceeds the limit" is `)"]|` off a
pane running jq, seen on a phone over 4G.

Three callers drop it routinely:
- the phone app batches output with timeout(16ms, PaneReader::next), which
  fires whenever a large frame is still arriving on a slow link;
- the gateway's control and pane loops race it in select! against outgoing
  events and output, so a paste while a pane prints can lose input bytes.

Add FrameReader to tty7-mobile-proto: it keeps a partial frame in a Decoder
and only awaits a single read(), which takes nothing when dropped. Use it in
PaneReader, ControlReceiver and both gateway loops. read_frame stays for the
one-shot reads whose stream is abandoned on a timeout, and says so.
2026-10-04 16:17:40 +08:00
Adam HitchcockandClaude Opus 5.5 4ed2685d1e test(daemon): the reap-guard test spawns /bin/sleep; singleton tests dup with CLOEXEC (#1090)
* test(spawn): the reap-guard test spawns /bin/sleep

With GNU coreutils first on PATH, `sleep` resolves to `gsleep`, whose
executable name the guard then (correctly) refuses, so
`reap_guard_rejects_a_live_process_of_another_executable` failed on
such machines. It now spawns `/bin/sleep`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test(singleton): dup the seat descriptor with CLOEXEC

Two singleton tests `dup` the seat's descriptor to simulate a lingering
reference. A plain `dup` isn't close-on-exec, so a child another test
spawns in that window (the reap test's `sleep 30`) inherits it and holds
the flock for its whole life, failing the clear under the full parallel
run. `F_DUPFD_CLOEXEC` keeps the reference in-process.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-04 16:12:31 +08:00
Adam HitchcockandClaude Opus 5.5 b65a3e4efc test(git): pin status.showUntrackedFiles in the tests' scratch repositories (#1091)
Five tty7-core tests and two tty7-server conformance checks failed on a
machine with a global `status.showUntrackedFiles=no`: git hid the files
they had just written. PINS (and so pin_repo_config) now carries
`status.showUntrackedFiles=normal`, the worktree tests' temp_repo pins
its repository, and the host conformance suite's git_repo sets the key
itself, since other crates run it.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-04 16:12:16 +08:00
d3f7dadd5d feat(agents): Muse Code and jcode support, native hooks for Empryo, Muse Code and jcode (#1071)
* feat(agents): recognise Muse Code and jcode

Muse Code's `muse` launcher execs a versioned `muse-bin-<version>`
binary, so detection also maps that name to Muse. Muse resumes with
`muse resume <id>` (root options on either side of the subcommand);
jcode with `jcode --resume <id>`.

* feat(agents): install native Empryo and jcode hooks

* feat(agents): add jcode lifecycle hooks

* fix(agents): preserve jcode hooks and correct Empryo removal contract

* feat(agents): install Muse native plugin hooks

* docs(agents): list Empryo, Muse Code and jcode as hook-backed

* fix(i18n): translate Empryo, Muse Code and jcode search keywords

* fix(agents): read jcode hook payload from env, route its reports like Codex, bound muse CLI calls

jcode runs hooks with stdin closed and puts session_id/cwd in
JCODE_HOOK_PAYLOAD, so reports carried no session and resume never
learned an id. Its shared server also runs every session's hooks with
the first client's TTY7_PANE, so reports go through the same
session/directory routing as Codex. muse plugins calls now time out
after 30s and surface stderr. Adds ru strings for the new keys and
reattaches Kimi's doc comment to KIMI_HOOK_EVENTS.

* docs: count Muse Code and jcode in the README agent totals

---------

Co-authored-by: kalpakprod <307643502+kalpakprod@users.noreply.github.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-03 20:47:25 +08:00
02620cfa48 feat(ui): add ru-RU locale with CLDR few/many plurals (#1072)
* feat(ui): add ru-RU locale with CLDR few/many plurals

Russian joins English, Simplified Chinese and Japanese.

- `gui_language` accepts `ru-RU`; the picker shows the endonym «Русский»
  in every locale, as for 简体中文 and 日本語.
- `PluralCategory` gains `few` and `many`, chosen by the CLDR rule for
  the active locale (1 файл, 2 файла, 5 файлов, 11 файлов, 21 файл).
  en, zh and ja never select them, so their output is unchanged.
- `ru.rs` translates every key and every plural form; the exhaustiveness
  test now covers ru as well.
- Style follows Russian VS Code / Windows: infinitive verbs on buttons
  and menu items, imperative in hints, Git terms as in VS Code ru.

Claude-Session: https://claude.ai/code/session_01NnVhn11H75iA699hvPsiH3

* docs(config): list ru-RU among gui_language values

---------

Co-authored-by: kalpakprod <307643502+kalpakprod@users.noreply.github.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-03 20:36:31 +08:00
l0ng-ai 24c479c636 feat(mobile): close a pane; scroll full-screen programs; fix pinyin in the pane (#1065)
* fix(mobile): a swipe scrolls a full-screen program

A swipe over the terminal scrolled xterm's scrollback, and the alternate
screen keeps none, so over Claude Code's full-screen view, less or vim
it did nothing. On the alternate screen a swipe now turns the mouse
wheel instead, a notch a row, as on the desktop: a wheel report at the
finger for a program that asked for the mouse (SGR or the legacy
encoding, whichever it chose), arrow keys for one that did not.

* fix(mobile): pinyin keeps going when typing straight into the pane

Typing on the terminal itself goes through a hidden field, which was
emptied after every committed piece of text. iOS keeps its own copy of
the field's text, and a field cleared under it left the input method
stuck after the first character a pinyin composition committed. The
field now keeps its text while it has the keys and the pane is sent
what changed since the last send: characters taken off as DEL, then
what is new. It is emptied on blur.

While the field has the keys the pane's cursor is drawn solid, so a tap
on the terminal shows that it is ready to type into.

* feat(mobile): close a pane from the phone

The app could watch and drive a pane but never close one. Hold a pane's
row in the list, or pick Close pane from the terminal's menu: a sheet
says what will be stopped and on which machine, and only its danger
button closes it. From the terminal the app goes back to the list, which
drops the pane when the next tree arrives.

On the wire this is a new one-shot Open::ClosePane { pane_id, machine },
answered Ok or Denied. The gateway does what `tty7 pane close` does:
finds the workspace holding the pane, sends PaneClose, and hangs up the
panes it reports removed, on the gateway's machine or through the
desktop's existing link to a remote one. A gateway that predates the
variant drops the stream, which the app reports as "too old to close
panes from the phone".
2026-10-03 20:36:25 +08:00
Adam HitchcockandClaude Opus 5.5 5be29e5cf2 test(scrollback): the sweep test sweeps a directory of its own (#1077)
saving_twice_replaces_rather_than_appends flaked in CI: every on-disk
scrollback test shares one pinned config dir, and the sweep test's
sweep() deleted every snapshot but its own, including one another test
had just saved and was about to load. sweep() now delegates to
sweep_in(dir, keep), as history.rs's does, and the test sweeps a temp dir
of its own. Looping the module's tests 300 times: 11 failures before, 0
after.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-03 20:31:23 +08:00
Adam HitchcockandClaude Opus 5.5 dd4bd806c6 fix(github): a multibyte char after < no longer panics the markdown sanitizer (#1076)
`starts_with_tag` sliced `rest[..name.len()]` by bytes, so an issue or
PR body with `<` followed by a multibyte char (e.g. `<日本`) panicked the
GitHub panel's render and quit the app. It now uses `str::get`, so a
non-boundary is just "not a tag". A regression test fails on the old
code and passes now.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-03 20:29:57 +08:00
l0ng-ai 3990a05795 Mobile: an iOS pass from a user's seat (#1075)
* fix(mobile): draw a prompt's icons

Prompts built with Powerline and Nerd Font glyphs (branch, folder, git
status) showed as empty boxes: a phone has no such font to fall back on.
Ship the symbols-only Nerd Font, one cell wide, behind Hack.

* fix(gateway): send a phone the screen the desktop shows

A phone opening a pane was sent its raw output, ring segment by segment,
and read it with xterm.js. Across the pane's resizes that emulator wraps
and reflows unlike the desktop's, so shells' SIGWINCH redraws landed on
the wrong rows: prompts twice, old output under new prompts. Leaving a
full-screen program left stale lines behind the same way.

The gateway now reads the pane with the desktop's emulator and, on
opening, after a resize, and when the main screen comes back, sends the
phone that screen drawn afresh: scrollback, colours, cursor and modes.
Output in between still goes straight through.

* fix(mobile): the message box rides the keyboard on iOS

On iOS 26 the WebView, run edge to edge, does not say how much the
keyboard covers, so the message box and the dock stayed under it. The
app now hears the keyboard's frame natively and lays out above its top
edge, on iOS as on Android.

- WebKit's previous/next/Done bar over the keyboard is gone; a tap on
  nothing in particular, or on the pane, puts the keyboard away.
- Return sends however the keyboard delivers it.
- A shell's message box no longer capitalises or corrects: ls stays ls.
  An agent's keeps both, as a chat would.

* fix(gateway): a tab opened from the phone joins its repository's group

The desktop files a tab under its repository as its sidebar draws it, so
a tab opened from the phone while that window was out of sight stayed in
Ungrouped. The gateway now reads, for a tab the desktop has not filed,
which repository its directory is in, the way the desktop would.

* feat(mobile): close a tab from the phone

Swipe a tab's row left for Close, or use Close tab in a pane's menu. The
tab goes where the desktop puts a closed tab, onto the workspace's
recently-closed list, so tty7 on the computer can reopen it. A tab whose
agent is at work asks first.

A new CloseTab stream carries it; a machine that keeps no closed tabs
closes it for good and its panes are ended, as tty7 tab close does.

* feat(mobile): a machine's list reads at a glance, and the app opens where it was left

- The app reopens the machine it was last on; leaving for the list of
  machines is what makes it start there.
- A tab named after its directory goes by the directory's own name, its
  parent underneath, rather than a path cut off at the end that matters.
  An agent's row says where it works too.
- New tab asks which folder, from those the workspace has tabs in, the
  tab in front first; Workspace is asked only when there is a choice.
- The back button names where it goes in full until the title folds in.
- Search fields have a clear button; a few machines need no search.
- Rows swipe left to close their tab, and a pane's menu has Close tab.

* fix(mobile): agents' marks draw, and Return sends a sentence

- Claude Code's ⏺ and ⎿, ⏵⏵, ⚙, ⏰, ✔, braille spinners and the like
  showed as empty boxes: the phone's fonts do not reach a canvas for
  them. Noto's symbols and outline emoji ship, cut down to those blocks
  (about 80 KB), behind Hack and the prompt icons.
- The phone's keyboard reports Shift with Return whenever it has armed
  a capital — at the start, after a full stop — so a message ending in a
  sentence got a new line instead of being sent. Shift-Return starts a
  line only on a keyboard with a real Shift; Return delivered as typed
  text sends as well.

* fix(mobile): an agent's choices become buttons wherever they are on screen

The answers were looked for in the bottom 24 rows of the terminal, which
can be taller than the pane: Claude Code's question sat higher up and no
buttons came. The whole screen is read now.

* fix(mobile): a pane on its side keeps room for the pane

In landscape the bar, the key row, the page dots and the message box
left three lines of terminal. The bar slims and the keys and the message
box share a row, for eight. A message box's hint stays on one line, and
a row's hidden Close names its tab to VoiceOver.

* fix(mobile): Settings names the ⋯ menu with its own mark, and asks before clearing history

The phone's text font has no ⋯, so the note showed an empty box; the
menu button's icon stands in. Clearing the message history, which cannot
be undone, now asks first.

* fix(mobile): Changes shows the changed files, not just the untracked ones

The files' blocks shrank to nothing under a long list of untracked ones:
flex items that clip their overflow give up their height. They keep it
now, and the sheet scrolls. The untracked list sits flush and compact,
the top line totals the change, and lock files start folded.

* feat(mobile): pull a sheet down to put it away

Sheets showed a grabber but only closed from their × or the dimmed screen
around them. Pulled down — from the top, or from anywhere while their
content is scrolled to the start — they go; let go short of the way,
they settle back.

* fix(mobile): a machine that went away says so within seconds

The connection kept QUIC's default 30-second idle timeout, so a laptop
gone to sleep stayed "Direct · 1 ms" on the phone for half a minute, and
typing into it went nowhere without a word. The phone now gives up on a
silent machine after 12 seconds, a few keep-alives missed, says it
cannot reach it, and reconnects on its own once it is back.

* feat(mobile): keys and answers are felt

The key row, an agent's answer buttons and Send give the light tap the
phone's own keyboard does, and a row swiped far enough to open ticks as
it passes the point. Through the Tauri haptics plugin; nothing is felt
where there is no engine for it.

* feat(mobile): pair by pointing the phone's camera at the desktop's code

The pairing QR code reads tty7pair:…, and the app now answers to that
scheme: the phone's own Camera offers to open it in tty7, which pairs
straight away, as its Scan button does. No hunting for the button first.

* fix(settings): the pairing code can be read by the phone's camera

The phone app now opens from its tty7pair: link, so Show code says to
point the phone's camera at it first.

* fix(mobile): Android opens tty7pair: links too

The deep-link plugin's intent filter, written into the manifest by the
Android build.

* fix(mobile): pairing links without the deep-link plugin, cold launches included

The deep-link plugin's build script rewrites the iOS entitlements while
Xcode builds, which Xcode refuses ("modified during the build"), and a
link that launched the app was lost on the way in any case: UIKit hands
it to the first scene as it connects, and the event loop only passes on
links that come later.

- The tty7pair scheme is declared in Info.ios.plist and the Android
  manifest, and links are heard as Tauri's own Opened event.
- The scene delegate's connect is wrapped, before UIKit starts, to keep
  a launching link; the page asks for it once it listens, so neither
  order of arrival loses it.

* feat(mobile): another agent waiting or done says so over the pane you are in

Inside one pane, nothing told you another agent on the machine had
stopped for an answer or finished its turn; you had to back out and
look. The pane now watches the machine's tree too, and such a change
drops a card over the top of the pane, felt as it comes — the agent,
what it says or which tab — that opens that pane when tapped. What was
already so when the pane opened is not news.

* fix(mobile): with the lock on, the app switcher shows no panes

The phone keeps a picture of an app as it leaves, for its app switcher.
With the lock on, that picture showed whatever pane was open. The app is
now covered as it goes, and uncovered — or locked — as it comes back.

* fix(mobile): turning the lock off takes Face ID too

Anyone holding the phone, unlocked, could switch the app lock off from
Settings. Off now asks for Face ID or the passcode, as on does.

* fix(mobile): a pane that is not running says so, with a way on

After the machine's server restarted, panes no window had opened since
were gone, and the phone tried to watch them forever: "Daemon refused
Observe: no such pane 9. Reconnecting…". The gateway now marks panes
its server is not running; the list shows them as Not running, without
their last agent status, and opening one says what is going on and
offers a new tab in the same folder.

* feat(mobile): a workspace not on screen shows when an agent in it needs you

The switcher's chip for another workspace carries the status dot a
folded group does, so an agent waiting there is not hidden behind the
one you are looking at.

* fix(mobile): a new tab's agent starts, instead of waiting at the prompt

Opening a tab for Claude Code or Codex typed the command as soon as the
pane was live, while the shell was still printing its greeting; the
Enter was eaten and the command sat at the prompt unrun. It is typed once
the shell's output has gone quiet now, or after six seconds whatever.

Rows also say where a tab is the same way whatever it is named.

* fix(mobile): the first screen says how to pair in one step

With no machine paired yet, it now says where the code is on the
computer and that the phone's camera reads it.

* fix(mobile): a tap that closes a pane's menu does only that

Closing the ⋯ menu by tapping the pane also brought the keyboard up for
typing into it. The tap that puts a menu away is the menu's now.

* fix(mobile): second pass from a phone user's seat

- Chinese, Japanese and Korean text rendered as boxes in the terminal:
  the glyph atlas does not fall back past the web fonts, so the system's
  CJK fonts are named in the stack.
- A tab opened from the phone was drawn at the desktop's width first and
  then squeezed: the gateway now holds it at the phone's size from before
  the desktop hears of it, until the phone's own view takes over.
- A tab opened with no folder started wherever the server did; it starts
  at home, and the new-tab sheet offers Home.
- Going back to a machine showed a skeleton every time; its last tree is
  drawn at once and refreshed when the watch reports.
- Errors said the transport's chain, repeated: each part is said once, and
  an unreachable machine is explained in words.
- Wide panes say once that they can run at the phone's size; a pane taken
  over is taken over again on return.
- Back in a pane's history, a button jumps to the latest output.
- Find hides the key bar and message box and keeps the match clear of the
  bar; Copy keeps the pane's lines and offers Copy all.
- The message box pans a wide pane back to the cursor; Changes outside a
  repository says so plainly; machine rows count waiting agents; the back
  pill folds to a chevron with the title; filled reds use the system red.

* feat(mobile): attachments wait as chips beside the message box

A sent file used to drop its full temporary path into the box, five lines
of /var/folders/... underlined by the spell checker. It now waits as a
chip with its picture and name, can be taken back before sending, and its
path goes after the message when it is sent.

* fix(mobile): pairing says what went wrong, and leaves the code alone

The code field offered word suggestions over the keyboard; it is a code.
A wrong, expired or unreachable code is explained with what to do next
rather than the gateway's lower-case reason.

* feat(mobile): hold a tab's row for what can be done with it

A long press used to open the pane like a tap. It now brings up the
row's actions: open, open at the phone's size, Changes, a new tab in the
same folder, copy the folder's path, and close.

* fix(mobile): a pane on its way shows that it is coming

Opening a pane over a slow link left an empty screen until its replay
arrived. After a quarter second without it, three dots say it is coming.

* fix(mobile): agent menus, stopped panes and new tabs, as used

- An agent's arrow-key menu with no numbers (Claude Code's 'trust this
  folder?') now gets answer buttons too; picking one moves to it and
  presses Enter.
- A pane that is not running greys out its keys and message box instead
  of taking typing that goes nowhere.
- Suggestions match where a word starts, so 'ls' no longer offers every
  message that mentions tools.
- A new tab's starting size counted neither the status bar nor the home
  indicator, so its last rows sat under the key bar.
- A tab opened on the phone keeps the phone's size on later visits, so it
  follows the keyboard instead of hiding behind it.

* fix(mobile): another agent waiting is not missed, and dismissing is only that

- The card for another agent that needs you stays until it is answered or
  put away (it went after 15 seconds); a finished one still goes on its
  own. While any other agent waits, the back button carries a dot.
- The card's dismiss, a banner's action and Jump to latest took themselves
  away under the finger, and the same tap then reached the pane and
  brought up its keyboard; a clear cover takes that tap now.
- A row's Current tag no longer gets cut to 'C...' by a long name.

* fix(mobile): Changes lists a new folder once, by name

The untracked list walked into every new directory — a generated folder
filled the sheet with thirty truncated paths. New directories come as one
entry, as git status shows them, and each entry reads as a name with the
end of its folder beside it.

* fix(mobile): bar buttons answer a 44pt square

Back, More, Close and the pane's round buttons are drawn at 38pt and took
taps only there, under the 44pt a finger is owed. Each now answers a 44pt
square around the same drawing.
2026-10-03 20:28:29 +08:00
l0ng-ai 99b9327fab feat(mobile): the desktop sidebar's groups, and the tab it has in front (#1073)
* feat(mobile): the desktop sidebar's groups, and the tab it has in front

A machine's tabs on the phone were one flat list per workspace. They now come in the desktop's groups, in its order: pinned groups, then one per repository or SSH host, then Ungrouped, each folding as on the desktop. The tab the desktop has in front reads Current.

The gateway places each tab as the sidebar does, from what the machine tree already keeps: a tab's pinned group, or else the repo the desktop last filed it under. The naming rules moved from the sidebar into tty7-core so both name groups alike. An older gateway sends no groups and the phone shows one list, as before.

* fix(mobile): group headers lead, and folded ones stack close

A group's header read the same as the workspace label above it, and a folded one kept the gap meant for rows under it, so folded groups sat far apart. Headers are now the darker, larger line at a tap target's height; only an open group keeps room after its rows.
2026-10-03 20:27:02 +08:00
l0ng-ai e38f450d1e feat(terminal): a message composer that covers agent CLIs' own input (#1066)
* feat(terminal): dock a message composer under agent panes

A multi-line text box docked at the bottom of a pane whose foreground is a
coding agent, for writing a prompt with the platform's own editing keys, mouse
selection and an in-place IME, then handing it over whole. Toggle with
Cmd+I (Ctrl+Shift+I off macOS) or "Toggle Message Composer" in the palette.

- Docks below the grid instead of floating over it, so the agent reflows into
  the remaining rows and nothing it draws is hidden.
- Enter sends, Shift+Enter inserts a newline, Esc hands focus back to the
  terminal without closing (so the next Esc still interrupts the agent).
- A message is written as text, then Enter as a separate write after a short
  settle. Multi-line text goes as one bracketed paste; Codex is always pasted
  (its burst detector swallows the Enter otherwise); a leading `!` reaches
  Claude Code as its own key so it switches to shell mode.
- Nothing is sent while the agent is waiting on a permission prompt or
  question; the box turns amber and keeps the message.
- Writes queue per pane and stop if the agent exits mid-send, so an Enter can
  never land in the shell.
- Pasted screenshots, copied files and dropped files reuse the terminal's
  existing path-pasting routes and land in the box when it has focus.
- Drafts and the open state survive the view being rebuilt.

Refs #842

* feat(terminal): give the composer a chat-box layout with attachments and / @ menus

- A rounded, tinted frame whose hairline darkens on focus and on a file drag,
  a toolbar row with an attach button and a round send button that fills in
  once there is something to send. The key hints move into the send button's
  tooltip; the placeholder names the agent and what / and @ do.
- Files become chips instead of words in the text: the attach button, a drop
  on the box, a pasted screenshot or copied file, and remote uploads all go
  through one paste_paths route that attaches while the box has focus.
  Backspace at the start of an empty caret removes the last chip. On send the
  paths follow the text as the shell words a drop would have typed.
- `/` at the start of the message opens the agent's built-in commands (Claude
  Code, Codex, Gemini) plus Claude's custom commands from .claude/commands;
  `@` at the start of any word opens files from the pane's project, reusing
  the quick-open walk so it works on remote hosts too, spelled relative to the
  pane's directory. Up/Down move, Enter/Tab pick, Esc dismisses.
- Shift+Tab is passed through to the agent to cycle its permission mode.
- Enter with nothing to send no longer sends a bare Enter.

No model picker, mode label or context meter: tty7 has no source for them
that would stay true, and /model is one keystroke away in the menu.

* feat(terminal): lay the composer over the agent's own input, with its toolbar

The composer now stands in for the agent's input instead of sitting under
it, so the pane has one input rather than two.

- For Claude Code, Codex and Gemini the box is laid over the input area it
  finds on the grid (Claude's ruled prompt block and the status rows under it,
  Codex's `›` line, Gemini's framed prompt), painted in the grid's background.
  When the agent puts something else there — a permission prompt, a picker —
  the area stops reading as an input; after a 250ms grace the box steps aside
  and the keyboard goes to the TUI, and both come back with the input. Other
  agents keep the docked layout.
- Over the input, Esc is the agent's (it interrupts), Ctrl+C clears the box or
  reaches the agent when the box is empty, and text typed at the grid lands in
  the box.
- The toolbar: permission mode (read off the status row the box covers, falling
  back to the hooks' permission_mode; click or Shift+Tab to cycle), model
  (click opens Claude's picker), Think (Claude's thinking toggle), and a context
  ring. Labels come only from what the agent reported.
- Claude hooks now carry an AgentReadout — permission_mode from the hook
  payload, the model and context size of the last main-thread reply from the
  transcript, the context window (1M for a [1m] model or past 200k), and
  alwaysThinkingEnabled — worked out in the hook so remote panes get it too.
- Visual pass against the design: 13.5px text with the design's padding
  (the input's own padding subtracted), a 40px toolbar of 28px buttons, a dark
  round send button, image chips with their own glyph.

* feat(terminal): replace the composer's Think toggle with an effort picker

The toolbar's thinking toggle is gone; reasoning effort is what the
agent actually exposes as a per-session dial. The button shows the level
Claude Code is set to (CLAUDE_CODE_EFFORT_LEVEL, else effortLevel from its
settings, reported by the hook) and opens a menu of low / medium / high /
xhigh / max. Picking one sends the agent's own /effort command, and the
label follows the pick until the next hook event confirms it.

* feat(terminal): open the composer's model and effort lists over their buttons, and seat the box where the agent's input starts

* style(terminal): align the composer with the design: bottom inset, hairline ring, effort label

* style(ui): draw the sidebar dividers as one-device-pixel hairlines

* fix(terminal): keep the composer's contents still when its ring thickens

* fix(terminal): let a click outside the composer keep the keyboard

* fix(terminal): a click beside the covering composer leaves it, as one on the grid does

* fix(terminal): paint the composer's lists over its ring, and give Effort its chevron

* fix(terminal): show the effort level alone, close toolbar lists on an outside click, read per-model effort

* fix(core): take the effort level Claude reports in the hook payload

* feat(core): send a Claude turn's context size once its transcript catches up

* Revert "feat(core): send a Claude turn's context size once its transcript catches up"

This reverts commit 3544bc6b172901977749c6d6041650ae3795be37.

* refactor(terminal): drop the composer's context gauge until there is an exact source for it

* fix(terminal): a paste at the grid goes into the composer covering the input

With the box laid over the agent's input, typing at the grid already went
into the box, but a paste (Cmd+V, a dropped or copied file) still went to
the pty — into the agent's own input, out of sight under the box, where the
next Enter would send it unseen. A paste now lands in the box the way
typing does, files as attachments, and takes the keyboard with it.

* fix(terminal): cover the agent's input from its top rule at any pane height

The covering layer measured its height up from the pane's bottom edge in
whole rows plus the padding, but the grid's rows start at the top: whatever
part of a row the pane's height leaves over sits between the last row and
the padding. At most heights that left the top of the covered area — Claude
Code's upper rule — showing above the box. The grid now records that
leftover and the layer counts it in.

* fix(core): report Claude's model and effort only when they are this turn's

The hook filled in the model from the transcript's last reply on every
event. That reply is the previous turn's: after a `/model`, or a resume
under another `--model` (a resumed session's SessionStart names none), the
toolbar showed the old model — and at `Stop` too, since Claude Code runs
the hook before the turn's reply is always on disk. The model now comes
from SessionStart, or at Stop from the reply that turn wrote: found after
the prompt the payload names, matching the words it carries, waited for
briefly. Nothing exact means nothing reported.

Effort likewise: the settings fallback only runs for a model the event
names (it may be set per model), and a turn that ends without a level ran
on a model that takes none, which the toolbar now shows as no level rather
than the settings' general one. A level picked from the toolbar gives way
to the agent's report once that changes, as a picked model does.

* fix(terminal): offer Fable in the composer's model list

Claude Code's `/model` list has Fable between Opus and Sonnet, and
`/model fable` takes it by that alias, but the toolbar's list left it out:
it could not be picked there, and a session running it had no row checked.

* fix(terminal): a toolbar pick holds only until the agent's next finished turn

A model or effort picked from the toolbar was shown until the agent
reported a different value. When the pick did not take — Claude asks
before switching a cached conversation's model, and "No, go back" keeps
the old one — the report never changed and the toolbar showed the refused
model for good; after the agent quit and a new session started on the
model the pick was made from, the stale pick came back.

A pick now stands until the next finished turn, which reports what the
agent actually ran on, and is dropped when the agent session changes.

* fix(core): keep agent hook sequences short

A hook reports to the pane by writing an OSC 777 sequence to the tty the
agent draws on. macOS does not keep a tty write whole: under output
pressure the kernel parks the writer mid-sequence and lets the other
writer in, so the agent's redraw lands inside our sequence, the OSC
breaks, and the rest of the JSON is printed on screen. The longer the
sequence, the likelier that is.

The prompt a turn starts with was the bulk of it on `prompt-submit` (up
to 200 characters, three bytes each for CJK), and nothing reads it any
more since the conversation outline went away. Stop sending it, and cap
the agent's message at a status line's worth.

* fix(core): hand agent hook reports to the daemon over its socket

An agent hook reported by writing an OSC 777 sequence to the tty the
agent draws on. A tty write is not atomic: on macOS the kernel parks a
writer whenever the output queue is over its high-water mark, which is
exactly when the agent is busy redrawing, and lets the other writer in.
The agent's output then lands inside our sequence, the OSC breaks, and
the rest of the JSON is printed on screen. A pty test with a busy
writer next to a small one splits even 100-byte writes, at arbitrary
offsets, so no size keeps the sequence whole.

The hook now sends the same JSON to the daemon that owns its pane
(`$TTY7_PANE`, over the pane socket `$TTY7_CONFIG_DIR` leads to), which
applies it exactly as if its reader had found it in the output. The
pane id comes from the environment, which a detached tmux server or
the like carries out of the pane, so the daemon applies a report only
from a process that runs under the pane's shell. Anything else — no
daemon, one that predates the message, a refusal — falls back to the
tty as before, which is still how a hook with no daemon beside it
reports.

* fix(terminal): offer /effort in the composer's command menu for Claude

The toolbar's effort picker types `/effort`, but the `/` menu did not
list it. Bring the list in line with current Claude Code while at it:
`/usage` replaces `/cost`, which is now only its alias, `/rewind` joins,
and `/agents`, which Claude Code has removed, goes.

* fix(terminal): step aside for Codex's own lists instead of covering them

Codex marks the selected row of its lists -- the approval prompt,
/model, /permissions, the hook review and the update offer at launch --
with the same `›` that starts its input line. The composer took that row
for the input and laid the box over the list, hiding the options the
user had to pick from. A `›` row that is a numbered option with sibling
options around it is now read as a list, and the box steps aside.

* fix(terminal): offer Codex's /permissions, not the retired /approvals

Current Codex no longer knows /approvals; the command that chooses what
it may do without asking is /permissions. Also offer /resume.

* fix(core): install Codex hooks into CODEX_HOME when it is set

Codex reads hooks.json from its home, which CODEX_HOME moves. tty7
always wrote and checked ~/.codex/hooks.json, so for such a user the
hooks it installed never ran, and the state it reported described a file
Codex does not read. Local-only, like the other config-dir overrides.

* fix(core): find the pane a Codex hook reports on from the report itself

Codex runs its hooks in its app-server, one background process every
Codex session on the machine talks to. The first session starts it, and
it outlives that session, detached. Its hooks therefore carry the first
session's $TTY7_PANE and run under that pane's shell only while that
session lasts. Once it ended, the daemon refused every Codex report as
coming from outside the pane -- and the tty fallback has no terminal in
a detached process -- so a Codex pane never showed working, waiting or
done. While the first session was still running, a second pane's
reports were taken as the first pane's.

A Codex report is now matched to its pane by what it says: the pane
that already reported its session, else the one pane running Codex in
its directory (the one yet to report a session, and the named pane on a
tie). Other agents' reports are unchanged.

* fix(core): install Gemini hooks under GEMINI_CLI_HOME when it is set

Gemini CLI roots its user-level .gemini directory at GEMINI_CLI_HOME in
place of the home directory. tty7 always wrote and checked
~/.gemini/settings.json, so for such a user the hooks it installed never
ran, and the state it reported described a file Gemini does not read.
Local-only, like the other config-dir overrides.

* fix(terminal): find Gemini's input in the shaded block it draws now

Gemini CLI no longer frames its input in a rounded box: it shades the
prompt line between a row of lower half blocks and a row of upper half
blocks, and with shading off it draws a rule over the prompt instead. The
composer looked only for the old frame, so over a current Gemini it
stayed stepped aside for good and never covered the input.

A message already sent is shaded the same way in the transcript, so the
block counts only with nothing but the footer under it; a permission
prompt or a list in the input's place leaves the last message above more
than that, and the box steps aside for it. The old frame is still found
for older versions, and the shell, YOLO and history-search marks count as
a prompt as well as `>`.

* fix(terminal): give Gemini time to read a paste before pressing Enter

Gemini CLI takes an Enter that comes within 40ms of a bracketed paste as
a line break. It starts that window once it has read the whole paste, so
the 50ms the composer left between the paste and the Enter was not
enough for a long message: a 41-line message sat in Gemini's input as
"[Pasted Text: 41 lines]" plus an empty line, hidden under the box, and
was never sent. Gemini now waits as long after a paste as Copilot does;
a 400-line, 32KB message goes through whole and is submitted once.

* fix(terminal): hand Gemini its attachments and mentions so it reads them

Three things kept files from reaching a Gemini turn from the composer:

- Attachments went after the text as shell words. Gemini turns a drop
  into @ mentions itself, but only a paste that is nothing but paths;
  after the message's text a path is just words, and the model never saw
  the file. Gemini now gets its attachments as the mentions it would have
  made.
- A mention picked from the @ menu was spelled raw. Gemini ends a mention
  at the first unescaped space, so "my notes.txt" became "@my". Mentions
  for Gemini are escaped the way its own escapePath does it.
- With the caret at the end of an @ word Gemini lists matching files, and
  Enter takes the list's pick instead of sending, so a message closed by
  a mention - every message with an attachment - sat in the input under
  the box, unsent. A message with a mention now ends in a space, which
  closes the list; slash commands are left alone.

* fix(terminal): offer Gemini's current commands in the composer's menu

Gemini CLI now names its session browser /resume, with /chat kept as an
alias, and /clear starts a new session rather than only clearing the
screen. Offer /resume under its own name, say what /clear does now, and
add /model and /init, which the menu left out.

* fix(terminal): paste messages to Gemini instead of typing them

Gemini CLI judges each key of a typed burst against its input as it was
before the burst, so to it the input is still empty at every key. A "?"
anywhere in a typed line is taken for the key that opens its shortcuts
on an empty input and dropped ("what? yes" arrived as "what yes"), and a
"!" for the one that switches it into shell mode, which also clears what
came before it: "hi! there" became a shell command " there", one Enter
away from running.

Gemini now gets every message as a bracketed paste, like Codex, with a
leading "!" still sent as a key of its own - as for Claude Code - so a
message that starts with one keeps opening shell mode.

* fix(terminal): spell a mention with a space the way Claude and Codex read it

A file picked from the composer's @ menu went in raw for Claude Code and
Codex, so "my notes.md" came out as "@my notes.md":

- Claude Code ends a bare mention at the first whitespace, so it looked
  for "my" and the file never reached the turn. A path with a space now
  goes in double quotes, @"my notes.md", the form Claude's own list puts
  in and its parser reads back as one file.
- Codex hands mentions to the model as plain text, and its own list puts
  in the path alone: without the @, in double quotes when it has a space
  in it. The composer now does the same.

Checked for real: Claude 2.1.286 with no tools answers from @"my notes.md"
and not from @my notes.md or @my\ notes.md; Codex 0.158's list inserts
"my notes.md". Attachments are unchanged; both agents read one with a
space in its path.

* fix(core): name tty7's Gemini hooks so Gemini shows "tty7" while they run

While a hook runs Gemini CLI shows "Executing Hook: <name>" above its
input, and a hook without a name is shown by its whole command - the
quoted path of the tty7 binary and its arguments. tty7's Gemini entries
now carry "name": "tty7".

An install from before reads as outdated - its hooks' names are checked
along with their commands - so the launch-time refresh and the settings
page's Update rewrite it in place, one entry per event as before. Other
agents' entries get no name and are judged as before.

* fix(core): show no effort level for a Claude model that takes none

A new Claude session names its model but not its effort level, so the
hook fell back to the settings' level - and a session started on Haiku
showed "High" until its first turn ended. The hook now checks Claude
Code's own model catalog (its cache, read only) first: a model it lists
without effort options is reported with an empty level. A model it does
not list, or no catalog at all, falls back to the settings as before.

* fix(terminal): paste messages to OpenCode and Amp instead of typing them

OpenCode reads a burst of typed keys against the input as it was before
the burst, the way Gemini does: the `!` in "PONG! ok" switched it into
shell mode and the rest of the line ran as a shell command. Amp takes a
typed leading `?` for its shortcuts key and drops it, and a typed
leading `/` opens its command palette while the rest of the burst lands
in the input underneath, so Enter ran whatever the palette listed first.

Both now get every message as one bracketed paste, which each reads
intact and sends on the Enter that follows. A leading `!` still reaches
OpenCode as a key of its own, the only way it switches into shell mode;
Amp reads its `$` shell prefix off a paste.

* fix(terminal): stand the docked composer as far in from the bottom as from the sides

Docked under the grid, the box sits inside the pane's padding, and only
the side inset took it off: the box stood 20px up from the pane's bottom
and 16px in from its sides, where it covers an agent's input 16px from
all three.

* fix(terminal): offer OpenCode's commands in the composer's menu

OpenCode takes slash commands typed at its input, pasted ones included,
but the composer's `/` menu listed none for it and its placeholder left
out the commands hint. List the ones its own menu opens with, in its
words. Amp keeps an empty list: its `/` opens a command palette that a
message cannot drive.

* fix(terminal): hand OpenCode and Amp their attachments as pastes of their own

Both attach an image only from a paste that is nothing but its path; a
path after the message's text stays words, so an image attached in the
composer never reached the model. They now get the text, then each path
as a paste by itself after a typed space, and Enter once the last one has
had time to land. OpenCode shows the file as a part of the message and
Amp lists it under Images, as a drop onto their own input would.

* fix(terminal): don't answer pixel-size queries from a replayed pane

A reattach replays the pane's ring through the grid with query replies
muted, but the mute list missed `TextAreaSizeRequest`: alacritty hands
`CSI 14t` to the listener as its own event (the view owns the pixel
size) rather than as a `PtyWrite`. Every `CSI 14t` a TUI had sent was
answered again on each app restart, and the `CSI 4;h;w t` replies landed
on whatever reads the pane now — at a shell prompt, after the TUI that
asked had quit, zsh printed them as `;840;873t;840;873t...`.

Mute it with the other replies; live queries are still answered.

* fix(core): don't let a hook wait on a terminal whose pane has gone

An agent's session-end hook that falls back to the tty after its pane
closed opened the terminal device blocking. With the pty's other end gone
that open waits for a carrier that never comes, and on macOS it waits
holding the lock every lookup under /dev needs: the hook never exits, the
agent cannot finish exiting, and every new shell, ps and tty on the machine
hangs behind them until the hook is killed.

Open the device without waiting, then switch it back to blocking writes so
a busy terminal still gets the whole sequence; a terminal with no other end
fails the write at once.

* fix(terminal): paste messages to Copilot instead of typing them

Typed into Copilot's empty input, a leading `?` is the key that opens its
help: "?why" went out as "why". Paste every message, as for Codex and
Gemini. Copilot still reads a pasted leading `!` as its shell mode, and
already got the longer wait before Enter that a paste needs.

* fix(terminal): speak to Qwen Code the way Gemini is spoken to

Qwen Code is a fork of Gemini CLI and kept its input, but the composer
treated it as an agent with none of Gemini's traps:

- a typed leading `?` opened its shortcuts and was lost;
- a message closing on an `@` mention sat in the input, its Enter taken
  by the file list;
- a mention or attachment with a space in its path went out as words it
  cannot read back.

Give it Gemini's handling: pasted, with the shell-mode `!` as a key of its
own, a space after a closing mention, the longer wait before Enter, and
attachments and `@` picks spelled with Gemini's escaping, plus the comma
Qwen escapes too.

* fix(terminal): leave Copilot's file list behind before pressing Enter

With the caret at the end of an `@` word Copilot lists matching files, and
Enter takes the list's pick instead of sending, so a message that closed on
a mention (one picked from the composer's own `@` menu ends that way) sat in
Copilot's input unsent. End such a message with a space, as for Gemini.

* fix(terminal): hand CodeBuddy a leading `!` as a key of its own

CodeBuddy switches into bash mode only on a `!` typed into its empty input
by itself, as Claude Code does. Arriving in one burst with the rest of the
line it is just a character, so "!git status" went to the model as a
request to run the command, behind a permission prompt.

* fix(terminal): paste messages to Kimi Code so they are sent

Kimi Code takes keys arriving faster than anyone types for an unbracketed
paste, and the Enter right behind a typed line for one of its newlines: a
one-line message from the composer sat in Kimi's input with an empty line
under it, never sent. Paste every message instead. Kimi knows a bracketed
paste for one, sends on the Enter after it at once, and still reads a
pasted leading `!`, `?` or `/` as typed.

* fix(terminal): spell a mention with a space the way Kimi Code does

Kimi Code's own `@` list puts in a path with a space as `@"my notes.md"`,
the way Claude Code spells it. The composer's menu put in `@my notes.md`,
which Kimi reads as a mention of `my` followed by a word.

* fix(terminal): offer Copilot's, Qwen Code's, CodeBuddy's and Kimi Code's commands

All four take typed slash commands, but the composer knew none of them: `/`
opened no menu and the placeholder offered only `@` files. List each one's
everyday commands as its installed version names them: Copilot CLI 1.0,
Qwen Code 0.24, CodeBuddy Code 2.161 and Kimi Code 2.1, which has `/new`
rather than `/clear` and `/permission` in the singular.

* fix(terminal): hand Copilot and CodeBuddy their attachments as mentions

Copilot and CodeBuddy attach a file only from an `@` mention, and a path
after the message's text is just words to them: an attached image reached
neither model, which had to go and read it with a tool, behind a prompt.
Send each attachment as an `@` mention instead, which both attach to the
turn, an image as an image. Neither reads a mention back past a space, so
a path with one still goes as quoted words.

* fix(core): import Pi's extension types from its current package

Pi moved from @mariozechner/pi-coding-agent to
@earendil-works/pi-coding-agent. Current Pi resolves both names for
extensions, and the bridge's import is type-only, so it is erased before
an older Pi that knows only the old name loads it. A bridge already
written with the old name reads as stale and launch's refresh rewrites it.

* fix(core): keep Pi and Oh My Pi panes working through retries and approvals

agent_end closes every attempt, so a run Pi retries after a provider
error read as done while it was still retrying. The bridge now takes
Pi's agent_settled as the end of a run when the build sends it, and
Oh My Pi's auto_retry_start puts the pane back to working.

Oh My Pi asks before running a tool through tool_approval_requested and
tool_approval_resolved, not Pi's UI-prompt pair, so its pane said
working while the approval dialog waited. Those now report waiting and
restore the turn.

* fix(core): take Prime Agent's hook reports from its background daemon

Prime Agent runs each session in a detached daemon, started by the first
session and outliving it, and the daemon runs tty7's bridge there with
the environment of the TUI that asked for the session. The report names
the right pane, but its process never runs under that pane's shell, so
the daemon turned every one away and a Prime Agent pane never left idle.

A report about Prime Agent is now taken by the pane it names when that
pane is running Prime Agent.

* fix(terminal): lay the composer over Pi's own input

The box docked under Pi's pane, so Pi's own ruled editor and its status
rows stayed on screen above it: two inputs. Pi now gets the covering box
Claude, Codex and Gemini have. Its editor is the lowest pair of
full-width rules — the upper one carries the spinner while a turn runs —
with the directory and usage rows under it, and the box covers from the
upper rule down. Pi's selectors take the editor's place between the same
rules but open on a blank row (or, for /settings, on a `>` search line)
and run on for several, so the box steps aside for them and comes back
once they close.

* fix(terminal): offer Pi's, Oh My Pi's, Prime Agent's and Grok Build's commands

All four take typed slash commands, but the composer knew none of them:
`/` opened no menu and the placeholder offered only `@` files. List each
one's everyday commands as its installed version names them — Pi 0.99,
Oh My Pi 18.4 (`/exit`, `/retry`, `/todo`), Prime Agent 0.9 (`/effort`
rather than Pi's `/thinking`) and Grok Build 1.0 (`/mcps`, `/recap`).

* fix(terminal): lay the composer over Oh My Pi's own input

The box docked under Oh My Pi's pane, so its own input stayed on screen
above the box. Oh My Pi now gets the covering box too. In its default
status-band shape, and in the rounded box, the input's first line opens
with `╰─ ` under the status line, and the box covers from that line
down; a dialog frame closes with `╰──…╯` and a tool approval or picker
takes the input's place, so the box steps aside for those. Its Pi and
Claude Code shapes are ruled like Pi's input and found the same way.

That input is two rows, where the box is about five, so laid over it the
box hid the last lines of the reply. For Oh My Pi the grid now gives up
the rows the box needs beyond the input, measured off the box as drawn
empty, and the agent draws its input that much higher.

* fix(terminal): lay the composer over Prime Agent's own input

The box docked under Prime Agent's pane, so its own shaded input block
stayed on screen above the box. Prime Agent now gets the covering box
too: its input is a blank row, the ` >` prompt line with any further
lines indented under it, and another blank row, right over the footer
that ends the screen. The model picker draws its own ` >` search line
between rules, away from the footer, so the box steps aside for it.

The block and footer are a row shorter than the box, which cut the hint
line above it in half; the grid makes room for that row as it does for
Oh My Pi.

* fix(terminal): lay the composer over Grok Build's own input

The box docked under Grok Build's pane, so its own framed input stayed on
screen above the box. Grok Build now gets the covering box too: its input
is the rounded frame whose first line opens with `❯`, with the key hints
under it. Its `/` and `/model` lists open over the frame between two
rules, and its dialogs are drawn across the frame's top edge; the box
steps aside for both, since they take the keys the box would send.

Grok Build keeps a command whose list was dismissed in its input, where
under the box nobody sees it and the next message was typed on after it:
`/modelReply …`. With text left there, the box now clears it with Ctrl+U
before sending.

* fix(terminal): spell mentions the way Pi and its forks read them

Pi, Oh My Pi and Prime Agent end a bare `@` mention at the first space,
and their own `@` lists put a path with one in double quotes,
`@"my notes.md"`; the composer put it in bare, so the mention named a
file that does not exist. Grok Build's list puts the path in as it is,
which the composer already did.

Oh My Pi reads a mentioned file — an image included — into the turn
itself, where a path in the message is just words for the model to go
and read, so its attachments now go as mentions.

* fix(terminal): send Oh My Pi, Grok Build and Prime Agent messages that end in a mention

Oh My Pi's and Grok Build's `@` lists open on a mention at the caret and
take the Enter that follows, so a message whose attachments or mention
closed it sat in their input, under the box, unsent. Like Gemini's and
Copilot's, their messages with an `@` now go with a space after them.

Prime Agent's list opens as a typed mention is typed and stays open past
the space after it: "read @a.txt " went out as "read @a.txt .git/". A
paste it reads whole, `!` and `/` included, so its messages are pasted.

* fix(terminal): stop a Grok Build turn with its own interrupt key

Esc in the box covering an agent's input is that agent's Esc, the key
that stops a turn. Grok Build's Esc leaves a running turn running — its
stop key is Ctrl+C — and the daemon, reading any Esc during a turn as
an interrupt, then called the pane done while Grok still worked. The
box now sends Grok Build Ctrl+C, and the daemon no longer counts an Esc
as stopping a Grok Build turn.

* fix(core): don't start a turn from a notification's waiting status

Before an agent's first hook, a desktop notification marks its pane
waiting. Crush raises one after every turn ("Agent's turn completed"), and
its only hook, PreToolUse, is reported as a finished tool, which moves a
waiting pane back to working: from the first tool of a session on, the
pane read as working for good, as Crush has no Stop to end it.

A status set by a notification now gives way to idle when the first hook
report arrives, so the report only records the session and its activity.

* fix(terminal): take only a hook's word that the agent is asking

The box stands aside and sends nothing while the pane's agent is waiting,
since whatever it sent would answer the question on screen. For an agent
without hooks — Amp, or Crush before its first tool — the pane is marked
waiting by any desktop notification, "Agent is ready" at the end of a turn
among them, and it stays marked. From the first finished turn on the box
stood aside for good, and messages went into the agent's own input
instead.

Waiting now holds the box back only when hooks reported it. Those agents'
own dialogs take their input's place on screen, and the box steps aside
for them off the screen as for any other.

* fix(terminal): offer Goose's commands in the composer's menu

Goose takes typed slash commands — /model, /mode, /compact, /clear and
the rest of what its /help lists — but the box's `/` menu was empty for
it. It now lists them, as Goose 1.52 names them.

* fix(terminal): stop a Crush turn with the two Escs it asks for

Crush takes a first Esc during a turn as a question — "esc press again to
cancel", in its key help — and stops only on a second one. Over its input
the box's Esc sent one, the question sat in the help under the box where
nobody read it, and the turn ran on. For Crush the box now sends both,
as separate writes: in one read the two are a single key to it.

* fix(terminal): lay the composer over Crush's, Goose's and Amp's own input

The box docked under these agents' panes, so their own inputs stayed on
screen above it: two inputs. They now get the covering box too.

- Crush's editor opens on its `> ` prompt (`!` in yolo mode, `:::` while
  the chat has the keys) with each further line on `:::`, over a blank row
  and its key help. Its dialogs — the command palette, the model and
  session lists, a permission request — are framed over the screen with the
  editor left standing under them, and take the keys, so with a frame on
  screen the box steps aside.
- Goose prints its `> ` prompt under its context gauge, as the last thing
  on the screen, wherever its output ended. A turn's spinner and output,
  and a tool approval, are printed under the line sent, and the box steps
  aside for them until the next gauge and prompt. Its input is two rows
  where the box is about five, so the grid gives up the rest, as it does
  for Oh My Pi.
- Amp frames its input at the bottom of the screen, its mode in the top
  edge and the directory in the bottom one. Its palette and file list open
  framed and indented over the screen, and a notice in the input's place
  (out of credits) is a frame with nothing in its bottom edge; the box
  steps aside for both.

Text typed into one of these inputs before the box was opened over it
stays there, unseen, and the next message would run on after it. With
text left there the box now empties it first, a line at a time with
Ctrl+U and Backspace, as it empties Grok Build's with Ctrl+U.

* test(core): keep the closed-terminal write test from racing other tests' children

`a_terminal_with_its_other_end_gone_fails_the_write_at_once` failed about
one run in three alongside the other hook tests (never on its own): its
pty came from `openpty`, whose descriptors are inherited, and the Qoder,
CodeBuddy and Crush config tests spawn children on threads of their own.
A child that took a copy of the pane's end kept it open after the test
closed it, and the write went through.

Open both ends close-on-exec from the start, and since a child forked a
moment earlier still holds a copy until it gets to exec, retry a write
that went through after a short pause; every attempt must still return
within the timeout, which is what the test is for. 50 runs of the hook
tests in parallel now pass, where 13 of 40 failed before.

* fix(terminal): lay the composer over Copilot's, Qwen Code's, CodeBuddy's, Kimi Code's and OpenCode's own input

The box docked under these agents' panes, so their own inputs stayed on
screen above it: two inputs. They now get the covering box too.

- Copilot, Qwen Code and CodeBuddy rule their input off top and bottom,
  the prompt (`❯`; `>`, `*` or `!`; `>`) on the line right under the upper
  rule and the status rows under the lower one. Their approvals and
  pickers come framed or between rules of their own with the question on
  the first line, and their `/` and `@` lists open under the lower rule or,
  Copilot's, right over the upper one; the box steps aside for them. Qwen
  Code is drawn as Gemini's ruled input once was, but Gemini's looser test
  takes the `> model` row of Qwen Code's own `/` list for the prompt, so
  it gets the stricter one.
- With true colour Copilot shades its input instead — a `╻▄▄▄` and a
  `╹▀▀▀` edge around lines on a `┃` bar — and draws its lists shaded over
  it, the selected row opening with `❯ /`; a sent message has the time at
  its end.
- Kimi Code frames its input over its model line and context gauge. Its
  lists open under the frame, its approvals take the frame's place, and
  its welcome banner is a frame far up the screen.
- OpenCode draws its input on a bar closed by a `╹▀▀▀` edge over its key
  hints, in the middle of its home screen and at the bottom of a session.
  Its lists open on the same bar, each row closed by a `┃` at its right,
  and a permission request takes the input's place with no edge.

Text typed into one of these inputs before the box was laid over it is
emptied first, a line at a time with Ctrl+U and Backspace, placeholders
and offered suggestions not counted. CodeBuddy takes keys that arrive
together for a paste and does none of them, so it is sent them one at a
time.

* fix(terminal): take Qwen Code and CodeBuddy out of shell mode before a plain message

A `!` message is a shell command to Qwen Code and CodeBuddy, and both stay
in their shell mode after it has run, their prompt a `!`, until Esc takes
them out. The next message from the box ran as a command too
(`bash: ?: command not found`), and a second `!` message toggled the mode
off and went to the model.

With the box over the input, the prompt says which mode it is in: a plain
message now leaves shell mode with Esc first, and a `!` message sent in
it drops the `!` that would toggle it off. CodeBuddy's `!` prompt counts
as its input, so the box no longer steps aside for it.

* fix(terminal): paint the layer under the covering composer in the agent's own background

The layer laid over an agent's input was painted in the theme's
background. Grok Build, OpenCode and other agents that paint the screen
in a colour of their own were left with a strip of the theme's colour
around the box — a light band under Grok Build's dark screen.

The layer now takes the colour the agent paints the row over its input
in (the one most of its cells have), over the grid's columns only; the
pane's padding around them keeps the theme's. An agent that leaves the
terminal's own background, as Claude Code, Codex, Kimi Code and Copilot
do, keeps the layer as it was.

The box's own fill was a faint tint of the text colour, which showed
whatever was under it: on Grok Build's dark layer the box went dark and
its text could not be read. It is now that tint laid over the theme's
background, the same colour as before on the theme's own background.

* fix(terminal): lay the composer over Qoder's own input and speak to it the way Gemini is spoken to

Qoder (both the global and the CN build) docked the box under its pane,
its own input left standing above it: two inputs.

- Its input sits between the last two full-width rules, opening with
  ` > ` (` * ` in YOLO mode, ` ! ` in shell mode), with only its model line
  under the lower rule. Over the upper rule its mode line has a rule of its
  own, with the `? for shortcuts` hint above it; the box covers those too.
  Its `/` and `@` lists open under the lower rule with the selected row
  opening with `❯`, and its trust and sign-in prompts, `/model` and `/help`
  open under a single rule with no prompt; the box steps aside for them.
- It is a Gemini CLI fork and kept that input: keys in a burst are read
  against the input before the burst (`echo hi` typed came out
  `echo hiecho hi`), a typed leading `?` opens its shortcuts, the Enter
  right behind a paste is a newline, its `@` list takes an Enter that comes
  right after a mention, and its list spells a path with a space
  `@my\ notes.md`. It now gets Gemini's handling of all of these.
- Like Qwen Code it stays in shell mode after a `!` command; a plain
  message leaves it with Esc first. Text left in its input is cleared with
  Ctrl+U and Backspace. Its `/` menu offers its current commands.

* fix(terminal): pick OpenCode's mentions from its own @ list so the files are attached

OpenCode attaches a file to a message only when it was picked from its
own `@` list (or handed over by an editor); the text of a mention is just
words to it. `@my notes.md` from the box, and `@plain.md` as well, reached
the model as text, which went looking for the file with its tools — and
the one with a space it had to find by globbing.

A message for OpenCode in a local pane is now cut at its `@` mentions of
paths that exist under the pane's directory (the longest run of up to four
words that names one), and each is sent the way a pick is made: a typed
`@`, the path pasted as the query with its spaces left out (a space would
close the list), and Enter once the list has had time to search. OpenCode
then shows `File  my notes.md` under the message. A space typed after it
closes a list that found nothing, so the Enter that sends is not taken by
it. An `@` that names nothing, commands and shell lines go as before.

* fix(terminal): cover Gemini's mode line and shortcuts hint along with its input

Gemini CLI 0.62 draws a mode line ("Shift+Tab to accept edits", "shell
mode enabled") over its input, with a rule of its own over it and the
`? for shortcuts` hint above that. The box covered the input from its
shaded block (or the rule right over its prompt) down, so the hint, the
rule and the mode line were left standing over the box.

The box now covers from the rule over that mode line, and from the hint
when it is there — the way it already does for Qoder, which draws the
same block; the two share the lookup. An input without a mode line over
it is covered from its own top as before.

* style(core): settle the clippy warnings the interrupt-key reader brought in

`is_interrupt_key` is only asked by the tests since the Grok Build change
went through `interrupts`, and two `let … else { return None }` read the
kitty-protocol key; the first is test-only now and the other two use `?`.

* fix(terminal): a screenshot pasted into the composer becomes an attachment

* fix(terminal): keep the composer's reserved rows, pastes and screen scans in line with the box

Scrolling back no longer resizes the pane, outside pastes land in the box
when it covers the input, the screen is scanned only while the box is open,
the command scan stops 8 directories deep, effort labels capitalise by
character, and two doc comments sit on their own items again.

* fix(core): route Codex reports past /new and codex -C, trust agent_settled only once seen

A session /new started goes to the Codex pane that had one; a report from
a directory no pane runs Codex in is matched among every Codex pane instead
of falling back to the app-server's. The Pi bridge no longer reads a
returned function from on() as proof agent_settled will come, and the Stop
hook re-reads the transcript only once it has grown.

* refactor: carry a session's source on AgentEvent and tidy the review fixes

The Codex router reads source off the parsed event instead of parsing the
hook body again. The command scan reads each real directory once rather than
capping depth, labels capitalise through one helper (alias_label no longer
slices bytes), the live input rows are set where Covering is decided, and
the transcript is opened once per poll.

* fix(terminal): read Claude's custom commands through Host

The scan reached std::fs directly, which the host-boundary check rejects;
it now walks the pane's host, joining and canonicalizing through it, and its
test covers a link back up the commands tree.
2026-10-01 23:46:26 +08:00
c361bd71e8 feat(panel): CPU% and memory per process, and a total, in Info → Processes (#1064)
* feat(panel): CPU% and memory per process, and a total, in Info → Processes

The daemon adds rss, cpu_ns and a start stamp to each ProcEntry (serde
default, so an old daemon or GUI skips them). The GUI turns two CPU-time
samples into a ps-style % and sums both into a Total line. `tty7 procs`
gains an RSS column.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(panel): no CPU% across a poll gap, and test CPU time is in ns

A new poll chain starts after the panel was shut or the pane changed;
comparing against the sample from before the gap showed a long-run average
as the current figure. Reset the tracker so the first round shows a dash.

Replace the self-usage test's cpu_ns > 0 (fails on Linux before the first
10 ms tick, passes unconverted mach ticks) with a check that the process's
CPU time covers this thread's own burned CPU time.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-01 15:18:27 +08:00
384a329df7 feat(terminal): program notifications follow the policy; read kitty OSC 99 (#1062)
* feat(terminal): program notifications follow the policy; read kitty OSC 99

OSC 9/777 notifications used to post from the reader thread regardless of
focus or the Never setting, and clicking one revealed nothing. They now queue
for the view, which applies notify_on_command_finish (Unfocused holds one back
only while its pane is focused in the key window), posts it clickable for the
pane, and titles it with the agent's name when it brings none. A pane whose
agent reports through tty7's hooks skips the copies the hooks already cover.

Kitty's OSC 99 is read too, chunked by i= with d=/p=/e=, in the client and in
the daemon sniffer, so a hookless agent's kitty notification marks it Waiting.
Claude Code's ghostty, kitty and iterm2 Notifications channels all land here;
its default, auto, sends nothing under TERM_PROGRAM=tty7.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(terminal): agent hook notices follow the per-pane rule

An agent's Waiting and Done notices from tty7's hooks were only posted while
the window was in the background, so an agent in another tab of the front
window never reached you. They now share shows_notification with program
notifications: Never posts nothing, When unfocused holds a notice back only
while its pane is focused in the key window, Always always posts. A hooked
pane still skips its program's own copies, so nothing doubles.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Revert "feat(terminal): agent hook notices follow the per-pane rule"

This reverts commit 7df400043c. The hook
notice change is a behaviour change of its own and moves to the stacked
branch upstream/hook-notices-per-pane.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* refactor(terminal): NotifyMode::allows, a Note type, and a cap on queued notes

One rule for every notification path: a mode allows a notice unless it is
Unfocused and the reader is watching. Kitty's pending chunks and a
finished note get names instead of tuples, and a pane whose view is not
polling keeps only its newest eight notes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(changelog): drop the Unreleased entry; the release notes carry it

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): a burst of program notes shows its newest three, and an exiting shell's are shown

`take_osc_notes` hands over the newest three queued notes and drops the
rest, so a program that writes a burst doesn't spray the desktop. The view
shows them ahead of `poll_foreground`'s exit check, so what a program said
just before its shell exited still gets through.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* refactor(terminal): one cap on queued program notes, three

The queue kept 8 and `take_osc_notes` then handed over the newest 3: two
caps for one rule. The queue now keeps 3 and `take_osc_notes` drains it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(terminal): at most five program notes per pane every ten seconds

The queue cap applies between polls, so a pane that keeps writing
notifications still posted a few every 300ms. Each pane now has a
NoteBudget: at most five notes per ten seconds reach the desktop, and the
rest are dropped and said once, as "More notifications from this pane
weren't shown", when the window turns over. The budget is asked on every
poll, held-back ones included, so that note comes even after the flood
stops and never for a count gone stale.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): kitty control payloads and id-less chunks don't build a note; OSC 9;10-12 aren't notes

A p=close, p=alive or p=? with the id of an unfinished OSC 99 note
finished and posted it. They are commands about notifications, so they
now leave pending notes alone. Chunks without an i= are each their own
notification per the spec, and no longer join an earlier id-less d=0
chunk. ConEmu's OSC 9;10, 9;11 and 9;12 (a prompt mark some shells emit
every prompt) were posted as notifications; they are subcommands like
9;1-9;9.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-01 15:17:44 +08:00
1d76051959 feat(terminal): tell a pane's program when the theme turns light or dark (DEC 2031) (#1061)
* fix(terminal): tell a pane's program when the theme turns light or dark (DEC 2031)

Claude Code's `theme: auto` reads OSC 11 at startup and re-reads it only
when the terminal sends `CSI ? 997 ; 1|2 n`, which it asks for with
`CSI ? 2031 h`. tty7 ignored 2031, so a running Claude kept its light diff
colours after a flip to dark. Track 2031 per pane (and across reattach),
push a 997 when the theme's background changes, and answer `CSI ? 996 n`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(terminal): report the colour scheme on reattach; review cleanups for DEC 2031

A pane reattached with 2031 on now hears the current scheme once the
replay is folded, so a theme flip while it was detached still reaches
the program. report() uses the presets' is_dark, watch reads
view.terminal directly, TRACKED lists 2031 inline, and the gpui test
moves into view.rs's gpui_tests harness with a reattach case.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(changelog): drop the Unreleased entry; the release notes carry it

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): one scheme report per reattach, not one per replayed frame

A replay is a modes Snapshot plus one Snapshot per ring segment, and each
sent its own 997. The Snapshot arm now only folds and flags; the report
goes out once, on the first frame after the replay. The tests use the
harness's next_input_until_timeout instead of a reader thread, and the
reattach test replays two Snapshots.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): send the reattach scheme report when the replay has been read

It went out on the first frame after the replay, so an idle pane, with no
live frame coming, never heard it. It is now sent once the reader's buffer
drains. TRACKED keeps its one line and names `COLOR_SCHEME_UPDATES` rather
than repeating 2031. The reattach test replays Snapshot, Size, Snapshot,
Snapshot with nothing after.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): a shell prompt ends DEC 2031, so a dead program's mode never reports into the shell

A program that switched 2031 on and died without `?2031l` left the mode on
in the pane's tracked modes, its ring, and the client's fold. A reattach
replay then still ended with 2031 on, so the reader sent its post-replay
report, and every theme flip sent another, into the shell's command line.

`TerminalModes` now drops 2031 on an OSC 133 `A`, `B` or `D` mark: the
shell owns the terminal again, so whatever asked for reports is gone.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(terminal): send the reattach scheme report after the replay, not at a read boundary

The reattach report went out whenever the reader drained what it had read.
An 8 MiB ring arrives over many reads, so a read that ended after the ring
segment holding a dead program's `?2031h` and before the one holding the
shell prompt that ended it typed `CSI ? 997 ; n` into the shell. The report
now waits for the first frame past the ring (the replayed Prompt, Cwd and
the rest, or live Output once it is folded).

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-10-01 15:17:22 +08:00
l0ng-ai d7dad45fa8 fix(gateway): reach the relay through a proxy when that is the only way out (#1058)
* fix(mobile): bump iroh to 1.3.0 so a stuck relay cannot stall direct dials

iroh 1.2.0 sends a connection's first datagrams to every known path one
after another inside the remote-state actor, awaiting each. When the relay
is unreachable its send queue fills and the actor blocks, so handshake
packets for a direct path that does work (a mesh VPN address, a public
IPv6) queue behind it and the dial times out. 1.3.0 sends to all paths
concurrently with a bounded wait (n0-computer/iroh#4512).

The desktop workspace was already on 1.3.0; the app has its own lockfile
and was left behind.

* fix(gateway): reach the relay through a proxy when that is the only way out

iroh dials its relay with its own resolver and its own TCP, ignoring the
system proxy. On a machine whose network only works through a local proxy
(Clash and the like, system-proxy or TUN mode alike) that dial never
succeeds, and nothing says so: phones on the same network still connect,
while a phone on cellular times out, because without a relay nothing
coordinates hole punching and the home router drops unsolicited inbound
packets.

The gateway now lists the ways out it knows of, most likely first:
tty7's own http_proxy setting, the system proxy, the environment's, then
direct. It starts on the first without waiting, and when the relay stays
unreachable for 10s it tries the others on a throwaway endpoint, switching
to the first that reaches a relay (same key, same port, so pairing codes
keep working). While none does, it looks again every minute.

A pairing code now names the relay only once it is actually connected;
before, it named whichever relay iroh picked by latency, reachable or not.

The platform proxy readers in daemon::install::proxy now also hand back
the proxy as a URL, for a client that is not ureq.

Claude-Session: https://claude.ai/code/session_018wE9ZRyxgWW2f55VSy9FvZ
2026-10-01 00:16:06 +08:00
l0ng-ai d40233b572 feat(tabs): keep recently closed tabs in the machine tree, and a confirm-before-closing setting (#1037)
* feat(tree): keep each workspace's recently closed tabs in the machine tree

A workspace now keeps the tabs closed from it in its machine tree
(`Workspace::closed`), so reopening one no longer depends on the window
that closed it still being open.

- `TabCloseRemembered` closes a tab into that list: the tab leaves the
  workspace as a close takes it (other windows hear `TabClosed`), its panes
  are stopped with their last screens kept on disk, and their records stay
  in the pane list. Panes the client held that the tree never recorded are
  ended outright.
- `TabReopen` takes the named or newest entry off the list and answers it
  with its pane records, for the client to rebuild on fresh shells that
  open on the old screens. The records it leaves behind are claimed by the
  successors' seeds instead of being refused as duplicates.
- Entries last 24 hours and a workspace keeps the newest 20. The daemon's
  scrollback keeper expires them on its existing timer, and an entry that
  goes takes its records and stored screens with it.
- Both requests are gated on a new `closed-tabs` hello feature, offered only
  by a peer that serves a tree and panes, so an older daemon or remote
  server is never sent them.

The field is `#[serde(default)]` and skipped while empty, so older trees
load unchanged and an older build reads this one's.

Refs #1021

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* feat(tabs): reopen closed tabs from the machine, and a setting for when closing asks

Closing a tab now closes it into its workspace's recently-closed list on the
machine that holds the workspace, instead of into a list that ended with the
window. ⌘⇧T asks that machine for the newest entry, so a closed tab comes
back after quitting and relaunching the app, from any window of the
workspace, and in remote workspaces whose server keeps the list.

- The explicit close (⌘W, the tab's close button, bulk closes) registers the
  tab with the window's next sync, which turns that tab's `TabClose` into a
  `TabCloseRemembered`. The machine stops the panes and keeps their screens;
  the window no longer kills them itself. A tab dragged to another window or
  never rebuilt still goes out as a plain close.
- If the close cannot reach the machine (no `closed-tabs` feature, a window
  that has not pulled its layout, a sync that fails or is thrown away), the
  window falls back to what it did before: the tab goes on its own list and
  its panes are killed from here.
- Reopening waits briefly for this window's queued edits to land, so an
  immediate ⌘⇧T undoes the close it means, then rebuilds the tab through the
  existing restore: each pane a fresh shell in its old cwd, opening on its
  last screen, with its shell, SSH target and agent resume facts. The tab
  keeps its id. The window's own list is used when the machine has nothing.
- The home screen offers the next tab ⌘⇧T would reopen, read from the
  machine mirror, which now tracks this window's remembered closes.

A new setting, `confirm_close` (General > Tabs, "Confirm before closing"),
decides when closing a tab or pane asks first: `never`, `when-busy` (the
default and the old behaviour) or `always`. The SSH "Warn before closing"
opt-in is honoured under every mode. Under `always`, Close Other Tabs and
Close Tabs to the Right ask once for the whole batch.

Refs #1021

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(tree): a remembered close marks its panes' records as no longer live

The records stay in the pane list for the reopen, but the panes are stopped
right after the close. Left at live: true, `tty7 wait` on a pane of a
closed tab read it as a running agentless shell and waited forever instead
of reporting it exited.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 16:40:28 +08:00
l0ng-ai f0f2b83b6e feat(workspace): the machine's own window takes part in workspace takeover (#1042)
One workspace is driven by one window at a time, whether that window runs on
the machine itself or on a remote client. The local GUI used to connect to its
daemon without ever claiming a workspace, so a remote client and a local
window could drive the same panes at once and fight over their size.

- The local link now claims (WorkspaceAttach) every local workspace a window
  shows. Opening one on purpose (switcher, tty7 open, a new window onto it,
  switching in place) takes it over; restore, relaunch and reconnect only
  claim a workspace nobody else holds, and otherwise open taken over.
- Preempted events for this computer put the window in the same taken-over
  state remote workspaces use: panes detached (processes untouched), the
  status strip naming the holder, the input pill, Take Back, and the
  switcher's 'taken over' badge.
- A hydration of a local workspace another client holds does not attach its
  panes, so a restored window never resizes them under the holder.
- A reconnect re-claims what the window held and leaves what it was pushed
  off alone. Nothing but Take Back or an explicit open reclaims.
- The local hello carries the machine's hostname instead of the literal
  'this computer', which is what a displaced remote client displays.
2026-09-30 16:36:10 +08:00
l0ng-ai 53f661e1a1 feat(remote): let a remote workspace target a Windows host over SSH (#1041)
A remote workspace refused any machine that was not Linux or macOS. This
teaches the installer and the link to reach a Windows OpenSSH host:

- Detection: `uname -sm` is still asked first, unchanged. When it fails
  (cmd.exe / PowerShell) or answers from Git for Windows, MSYS2 or Cygwin,
  a PowerShell probe reads PROCESSOR_ARCHITECTURE. The detected platform
  must match the SFTP home's shape, so a WSL DefaultShell over Windows
  SFTP is refused instead of installing a Linux server at /C:/...
- Assets: tty7-server-windows-{x86_64,aarch64}.exe, verified against
  checksums.txt like every other server; built by new server-windows
  jobs in release.yml and nightly.yml (ARM64 leg non-blocking), and the
  CI vcruntime guard now covers tty7-server.exe.
- Install: %USERPROFILE%\AppData\Local\tty7\bin\tty7-server-cXpY.exe via
  SFTP (/C:/... spelling). No mode bits are required or set. A running
  image is renamed aside to free its name and swept on the next install.
- Commands: every Windows command is a PowerShell script sent as
  -EncodedCommand, which survives cmd.exe, PowerShell and bash as the
  DefaultShell. The daemon is launched through Win32_Process.Create so
  it outlives the SSH session's job object, with this session's
  environment handed over; restarts use a new `tty7-server --stop`.
- Link: a Windows server is always reached by session exec with a plain
  `"C:\...\tty7-server-cXpY.exe" --stdio` (no env probe, no
  stream-local forward).
- Server: `--stdio` (control and --pane) now bridges on Windows to the
  daemon's loopback TCP endpoints instead of refusing.

Tested against a fake Windows host in install/windows_tests.rs; not yet
run against a real Windows machine.
2026-09-30 16:36:04 +08:00
l0ng-ai 8efea021e3 feat(ssh): shell integration for Windows hosts whose default shell is PowerShell (#1040)
The remote shell probe only understood POSIX answers, so a native SSH pane
on a Windows OpenSSH host always fell back to a plain shell with no prompt
marks, cwd reporting or title.

The probe is now a polyglot every default shell can read: POSIX shells
answer as before; PowerShell answers with its edition and $PSHOME, which
name the exact executable; cmd.exe echoes the line back verbatim and is
recognised, then deliberately left alone. For PowerShell the bootstrap
starts a second, interactive PowerShell of the same executable with the
existing integration via -NoLogo -NoExit -EncodedCommand (comments
stripped, about 6.5K chars total, well inside the Win32 command-line
limit), and a redialled pane's start directory (/C:/..., C:/..., UNC) is
restored with Set-Location -LiteralPath inside the encoded script.
2026-09-30 16:35:59 +08:00
l0ng-ai ab029f5ea1 fix(ssh): start a redialled SSH pane in the remote directory it was in (#1035)
* fix(ssh): start a redialled SSH pane in the remote directory it was in

A native SSH pane dialled again (restore after a daemon restart, Reconnect,
a split, ⌘T on an SSH tab, waking a sleeping tab) always landed in the login
directory. The client already sent the pane's remote cwd as
`SpawnNativeSsh.cwd`, but the daemon dropped it on the floor.

The daemon now threads it through `Pane::spawn_native_ssh` and
`SshManager::run_session` into the shell-integration bootstrap, whose first
line becomes `builtin cd -- '<dir>' 2>/dev/null` (fish-quoted for fish). It
is never typed at the prompt, never lands in history, and a directory that
is gone leaves the shell in the login directory without a word. Sessions
without integration take the plain shell request as before, so jump-host
menus never see it. The per-host probe cache still holds only the shell.
Only absolute paths are honoured. No wire or protocol change.

Callers now say what they mean: a saved host or quick connect passes no
start dir instead of the local cwd of whatever tab was in front; ⌘T and a
split on an SSH pane pass that pane's remote cwd; a sleeping SSH tab keeps
its remote cwd in the session layout. The daemon's replay now sends the
remote context before the cwd, so a window that reattaches to an SSH pane
does not wipe the remote directory it was just told.

Refs #1028

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(ssh): a local shell standing in for a restored SSH leaf starts locally

pane_to_session now keeps a native SSH leaf's far directory, so the
session_to_pane fallback that brings such a leaf back as a local shell
(the redial failed, or its daemon pane is gone on reattach) would hand
that remote path to a local spawn. Pass no cwd there for an SSH leaf.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 15:02:22 +08:00
l0ng-ai 0277ca67dc Centre the title-bar search box; bring back auto-hiding title-bar buttons as an Appearance option (#1036)
* feat(settings): an Appearance option to show the title-bar buttons only under the pointer

26.9.2 painted the new-tab and sidebar tiles only while the pointer was
over the bar they sit in; 26.9.3 took that out so the buttons would stay
discoverable. Both are fair, so it comes back as a choice: Appearance >
"Show title bar buttons on hover" (`auto_hide_titlebar_buttons`), off by
default, which keeps today's always-visible bar for everyone who has not
asked otherwise. A config written before the key existed reads as off.

With it on, the rail's two tiles follow the rail, and the collapsed
rail's pair and the trailing panel toggle follow the tab strip. The
window mark stays put, the tiles keep their layout slot so a reveal
never shifts anything, and the title-bar search box is always drawn.
The trailing toggle stays painted while the detail panel is open, as
before, since the panel's own tab row beside it always is.

The reveal is the hover sheet from 26.9.2 — a transparent last child
over each region, because `group_hover` loses the region the moment the
pointer reaches an occluding tile. Resting tiles go to zero opacity
rather than `invisible()`: gpui skips a hidden element's paint pass,
which is where its click and accessibility actions are registered, so a
screen reader could find a hidden tile by label and then not press it.
Shortcuts are actions and never depended on the tiles.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(titlebar): centre the search box on the window, not the bar after the traffic lights

On macOS `TitleBar` leaves an 80pt lead for the traffic lights before
the tab strip — whether or not the rail stands in front of them — and
the Search Everywhere box was centred on the strip. So it sat 40pt right
of the terminal column's middle: with the rail collapsed, 40pt right of
the window's (#1033). Fullscreen added the bar's own inset on top.

The band the box centres in now reaches back over that lead, so its left
edge is the terminal column's on every platform (12pt elsewhere). Its
right edge is unchanged: the strip's end on macOS, the terminal column's
end beside a docked panel or document off it.

Reaching back puts the collapsed rail's tiles inside the band, so the
box now keeps an equal clearance at both ends — two springs with a
minimum width either side of it. In a narrow column it shrinks instead
of sliding under New Tab or the panel toggle, and stays centred while
it does. The geometry is a pure `search_band`, tested for the macOS
rail-collapsed, rail-open and fullscreen cases and off macOS.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq

* fix(titlebar): clear a hover flag whose sheet is not on screen; document the key

A title-bar hover flag is written only by its sheet, and only when the
sheet sees the pointer cross its edge. Hide the rail from its own tile, or
turn the switch off mid-hover, and the sheet leaves the tree with its flag
still set: the next time it is built the tiles came back painted with
nobody pointing at them, until the pointer happened to pass through and
out again. Clear the flag of any sheet not built this frame.

Also list auto_hide_titlebar_buttons in the configuration reference.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 14:59:53 +08:00
l0ng-aiandClaude 4c8c317b91 feat(mobile): files, changes, a custom key bar, and a steadier connection (#1029)
The phone can now hand a pane a photo or file, read what an agent changed,
answer its prompts with a tap, and keep its link across leaving a pane.

Gateway and protocol:
- `Open::Upload` puts a file (up to 20 MB) in the directory the desktop
  keeps pasted images in, under a name a shell takes unquoted, and answers
  with its path. Panes on this machine only for now.
- `Open::Diff` answers with the working tree's changes against HEAD and its
  untracked files, for the directory a pane is in.
- Both are one-shot streams; an older gateway drops them unanswered, which
  the client reports as "update tty7".

App:
- Attach button in the message box: the uploaded path goes into the draft.
- Changes sheet from a pane's menu: a block per file, lines coloured.
- Settings → Key bar: remove, reorder and add keys, from a catalog or
  written out (`/compact\r`, `^C`), across pages; reset to the default.
- An agent's numbered choices show as buttons while it waits.
- Pinch to zoom, tap a link to open it, find in the scrollback, a Copy
  button for text a program copies (OSC 52), and an optional Face ID lock.
- Swipe from the left edge to go back; the iOS WebView has no page stack.
- One workspace at a time on a machine, picked from a row of chips.
- Agent avatars in their own colours.
- Each screen's watch is its own: a second watch no longer ends the first,
  which showed as "Can't reach" and a reconnect after leaving a pane.
- Dialing no longer holds the session lock, so Forget works while a
  machine is still connecting; its confirmation is an in-app sheet, since
  `window.confirm` shows nothing in the iOS WebView.
- iOS 15 minimum, as App Store Connect will require from April 2027.
- `scripts/testflight.sh` archives, signs for the App Store at export (the
  team has no devices for a development profile) and uploads.

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-30 12:30:04 +08:00
l0ng-ai 8db94666f0 fix(remote): fast, stable remote workspaces with more than ten panes (#1034)
* fix(ssh): a connection at the server's session limit is full, not dead

sshd allows ten sessions per connection by default and every remote pane is
one of them. The eleventh was refused with ConnectFailed, and the connection
was marked dead for it: taken out of the cache while all ten panes on it were
still using it. Every pane after that dialled its own fresh link, paying a full
handshake and server probe, and so did every short-lived route afterwards,
because nothing held the replacement and it went away as soon as that route
closed.

The cache now keeps a pool per destination. A refusal marks that connection
saturated for a while instead of dead; the pool hands out the first live one
with room and dials another beside them only when all are full. A route or a
native SSH pane that lands on a connection that turns out to be full goes back
to the pool for another.

* perf(remote): prove a server that is already running in one round trip

Every new connection to a machine tty7 had been to before spent six
sequential round trips proving what it already had: uname, a home lookup and
a stat over SFTP, a control probe and a process scan. The SFTP session it
opened also stayed open for the life of the connection, one of the handful of
sessions the server allows it.

One `sh -c` script now answers the common case: this dialect's server is
installed, answers the bridge probe, and is the one running (or a build of the
same dialect). Anything else falls through to the full install path unchanged.

* fix(remote): don't replace a pane that could not be reached with a fresh shell

Reattaching a restored pane treated every failure other than silence as "the
pane is gone on its machine" and spawned a fresh shell in its place. That
includes the link never opening at all — the server refusing another session,
a transport error — when the pane is still running over there. The tab lost
its session, and the old shell was left orphaned on the remote daemon; one
workspace had accumulated 53 shells for 17 panes.

Only the daemon's explicit "no such pane" now means gone. For a remote pane,
any other failure leaves it pending, and a pane that stands in for a running
one retries on its own a few times (2s, 4s, 8s, 16s, 16s) before leaving it to
Try Again. Local panes keep their previous behavior.

* perf(remote): ask a machine which panes are live over its control link

The pane liveness probe opened a pane route every ten seconds, which is an SSH
session channel on the remote side — one of the few the server allows per
connection. Once panes had taken them all, each probe dialled a whole new
connection. Ask over the control link that is already up instead: the
machine tree's pane records carry the daemon's own liveness.

* fix(scm): stop two windows from trading one repository watch every frame

Who holds a repository open is a global, reconciled by every window every
frame, but it was keyed by watcher kind alone. Two windows whose file trees or
panels sat in different repositories took the hold from each other each
frame, and every hand-over dropped the watch and opened it again. On a remote
workspace that is four round trips per cycle — about 28 control requests a
second for as long as both windows were open.

Holds are now keyed by window as well, and a closed window gives back what it
held.

* perf(ssh): open channels on one connection concurrently

The russh handle sat behind a tokio mutex held across every request on it,
and each request waits a full network round trip for its reply. So every
pane on a connection opened its channel after the one before it: on a link
with a few hundred milliseconds of latency, a workspace of twenty tabs came
back one tab at a time over about ten seconds.

Every call on the handle takes `&self` and waits on a reply channel of its
own, so the lock bought nothing. Drop it.

Claude-Session: https://claude.ai/code/session_011mDkkQhwx4RJJBHee3yVpq
2026-09-30 12:29:48 +08:00
802f9e0792 fix(agents): a Claude resume that finds no conversation starts fresh under its id (#1024)
* fix(agents): a Claude resume that finds no conversation starts fresh under its id

A tab opened and never used, or run with transcript saving off, has no
saved conversation, and `claude --resume` then stops at an error.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(agents): only chain the fresh Claude start where the pane's shell has ||

Windows PowerShell 5.1 and nu reject a line containing `||` outright, so
the fallback took the resume down with it there. The restore line now
chains the fresh start only for shells known to have the operator, judged
by the pane's own shell: its spawn spec, else the configured or login
shell for a local pane. A workspace pane with no explicit shell stays
unknown and gets the plain resume, since its default lives on its host.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-09-30 09:35:32 +08:00
f7e4101992 feat(daemon): panes set FORCE_HYPERLINK=1 (#1025)
* feat(daemon): panes set FORCE_HYPERLINK=1

tty7 renders OSC 8 links, but supports-hyperlinks only trusts a fixed
TERM_PROGRAM list and strips them for tty7, so Claude Code's statusline
PR links came out as plain text.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(daemon): note that FORCE_HYPERLINK also reaches redirected output

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com>
2026-09-30 09:22:06 +08:00
l0ng-ai e66fa4d881 fix(ssh): never restore an SSH tab as a local shell; show a reattached one as connected
After the server restarted, a native SSH tab's old pane id was attached
to, the attach failed, and the fallback spawned a local shell in its
place: the tab that had been another machine was now this one, still
titled and grouped like the remote. An SSH leaf is now only reattached
when the server lists its pane; otherwise the host is dialled again.

A window reattaching to a live SSH pane also never learned its phase,
since status frames only went to whoever was attached when they were
sent. The pane keeps the last one and replays it, so the tab keeps its
connected dot and warn-before-closing still applies.
2026-09-30 01:39:32 +08:00
l0ng-ai f99fff93fd fix(ssh): log in as this machine's user when a host leaves User blank
The form says a blank User is resolved at connect, and the host card shows
$USER, but the empty string went to the server as the user name. sshd
refused it as an invalid user and tty7 reported every key as rejected.
2026-09-30 01:22:02 +08:00
l0ng-ai bf60899450 fix(cli): capture the newest segment in the modes the ones before it left on
A resize while vim was open started the newest segment inside the
alternate screen. Replayed from the ground state its redraws landed on the
main screen, so capture still showed vim's ~ column after vim had exited.
2026-09-30 01:13:35 +08:00
l0ng-ai 186d715ca7 fix(cli): don't take the prompt still being drawn for a refused exec line
The daemon reports a pane at its prompt from the D precmd writes first,
before the user's own hooks have drawn the prompt. A line exec sent in
that window was followed by that prompt's A and only then read and run,
and exec reported 'came back to its prompt without running the line'
with exit 1. Back-to-back exec calls failed that way under any prompt
theme slow enough, as did exec_returns_the_commands_output_and_exit_code.
A prompt with no command started before it now has to stay that way for
a moment before the line counts as refused.
2026-09-30 01:06:26 +08:00
l0ng-ai a35800b96d fix(config): read a shell entry with no program as the login shell
`shell` was the one structured field still read strictly, so a hand-edited
{"args": [...]} without a program failed the whole file. It was
quarantined and every other setting fell back to its default, and changes
made in Settings afterwards were never saved.
2026-09-30 00:33:22 +08:00
l0ng-ai 1aa6e1e35b fix(daemon): set up integration for the shell a pane actually runs
Launched from a terminal, the daemon spawns the shell it was started from
rather than the login shell. The name handed to shell integration still
came from get_shell(), which is always the login shell, so tty7 started
from bash with zsh as the login shell ran bash with zsh's ZDOTDIR and no
rcfile: no prompt marks, no prompt editor, no completion.
2026-09-30 00:11:02 +08:00
l0ng-ai 5ba588f6d2 fix(mobile): let Settings renew a pairing code, and say when one is spent (#1019)
While a code was on screen the Show code button was disabled, so the only
way to a fresh code was Cancel then Show code. Worse, any attempt at a
code closes the offer, so after a mistyped paste or a dropped connection
the page kept showing a dead code for up to ten minutes with no hint.

- The button reads "New code" while a code is up, and replaces it.
- A code that can no longer pair stays on screen faded, saying why
  (expired, tried, or replaced by a newer offer), with New code beside it.
- The validity note counts down instead of saying "10 minutes".
- Cancel, and switching phone access off, now withdraw the offer on disk;
  before, a dismissed code could still pair until it expired. Only our own
  offer is withdrawn, never one opened elsewhere since.

The gateway's pair_code now returns the offer's secret alongside the code,
and State gains pairing_is_open / has_open_pairing / close_pairing.

Claude-Session: https://claude.ai/code/session_01BDVpJ78s7RQVcj57vjTcfA
2026-09-29 22:50:59 +08:00
l0ng-aiandClaude 24cf458e3b feat(mobile): a phone app to watch and drive tty7 panes (#983)
* feat(mobile): a gateway that lets a paired phone reach this machine over iroh

The first half of the mobile app: everything on the desktop side, plus the
client library the app will link.

- tty7-mobile-proto: the phone<->gateway wire protocol. One stream per purpose
  (pair, control, pane), framed like the daemon's frames, with raw terminal
  bytes kept out of JSON. No tty7-core, so it cross-compiles for iOS/Android.
- tty7-gateway: dials nothing, accepts phones over iroh (hole punching, relay
  fallback, end-to-end encrypted), checks the peer's key against the paired
  device list, and bridges to the daemon. Panes are observed, not attached,
  and keystrokes go in through SendInput, so a phone never resizes a pane or
  takes it away from the desktop window. `pair` prints a one-time QR code.
- tty7-mobile-client: the phone side (pair, tree, pane streams, direct/relay
  and RTT for the link), plus a `probe` example that stands in for a phone.

Verified against a real, isolated daemon: pair, tree, and typing into a pane
over a direct path, ~0.8 ms median echo on loopback.

* feat(mobile): the Tauri app — pair, browse the machine, drive a pane

The phone half, as a Tauri 2 app in mobile/ (its own cargo workspace, so the
desktop build and CI never compile a WebView stack).

- Rust side: the phone's iroh endpoint and key, paired machines, and every
  live stream, behind eight commands. Terminal output crosses to the WebView
  as raw ArrayBuffers on a Tauri channel, batched per frame, in order with the
  pane's JSON events.
- Frontend: vanilla TS + xterm.js. Paired machines and pairing; one machine's
  workspaces, tabs and panes with agents that need you pinned on top and the
  link's direct/relay path and RTT in the header; a terminal that fits the
  desktop pane's width, with an esc/tab/ctrl/arrows key bar. Coming back from
  the background re-watches and re-opens, relying on the daemon's replay.

Verified as a macOS build against a live gateway and an isolated daemon:
paired from the app, tree rendered on a direct path, keystrokes and key-bar
arrows reached the pane. iOS/Android builds need Xcode / the Android NDK,
neither of which is on this machine; mobile/README.md has the steps.

* fix(gateway): one serve per machine, and say how to start a missing server

- `serve` takes an exclusive lock on <config dir>/mobile/serve.lock. A second
  gateway on the same key is a second endpoint answering to one address, so a
  phone reached whichever the network picked. It is now refused, naming the
  pid that holds the lock.
- With no tty7 server running, phones and the terminal both hear "tty7 isn't
  running on <host> — open tty7 there, or run `tty7 server start`" instead of
  "lost the tty7 server: No such file or directory". `serve` checks once at
  startup, and still starts, since tty7 may be opened after it.

* feat(mobile): redesign the app as a native-feeling, minimal UI

The first cut read as a web page of bordered boxes. This rebuilds it the way a
phone app moves and reads, in the desktop tty7's own look:

- Screens push and pop with View Transitions; large titles fold into the bar.
- Grouped inset lists on a tinted canvas, following the system Light/Dark with
  the desktop presets, accent and ANSI palettes. Hack for code and terminal.
- Panes are listed by tab, one card per workspace, with the desktop's agent
  avatars and status badges (Waiting hollow, Working blinking) and its words.
- Pairing is its own screen, with steps, a Paste button and inline errors.
- A machine that stays silent for 10 s says so and offers to pair again; an
  offline notice says what to check.
- The terminal header shows live/offline in words. A pane too wide to read is
  shown at a readable size and pans to follow the cursor, with a toggle to fit
  the whole width. The key bar has drawn icons, puts left/right first, and
  has a keyboard toggle.

PRODUCT.md and DESIGN.md record the product facts and the design system.

* feat(mobile): open a new tab from the phone

Each workspace on a machine's screen gets a "New tab" action. It starts a
shell at the end of that workspace, in the directory its last tab is in, and
opens it straight away.

- Protocol: a one-shot `Open::NewTab { workspace_id, cwd, size }` stream,
  answered with `Ok` and a `TabCreated { tab_id, pane_id }`, or `Denied`.
  It is additive, so the protocol version stays. A gateway from before this
  drops the stream unanswered, and the app says to update it.
- Gateway: takes the same two steps as `tty7 tab new`, spawning a shell owned
  by the workspace and then TabCreate. The shell starts at the grid the phone
  asked for, because no desktop window is showing it yet. Sizes are clamped.
- App: a `tab_new` command, with the size worked out from the screen at the
  readable font size.
- probe: `newtab <workspace-id> [cwd]`.

* feat(mobile): reach the machines the desktop is linked to over SSH

A machine's screen now lists, under its own workspaces, every machine its
tty7 holds an SSH link to, with that machine's workspaces. Panes there open,
take input and get new tabs like local ones. "Needs you" gathers panes from
all of them.

- The gateway routes through the local server over links it already holds,
  the same way `tty7 -m <machine>` does. It never dials a down link, because
  that would guess at credentials the phone does not have. A down link
  shows as "Link down", with a note to reconnect it on the desktop.
- Protocol, additive: `Tree.remotes`, and an optional `machine` (the link
  key) on `Open::Pane` and `Open::NewTab`. A local pane is asked for exactly
  as before, so older gateways still understand it.
- Rebuilding a route target from a link key moves from the CLI into
  tty7-core as `RouteInfo::target` / `RouteInfo::host`, so the CLI and the
  gateway share one rule. The CLI now calls it.

* perf(gateway): read linked machines in parallel, never waiting on a slow one

Linked machines were read one after another on every tree poll. One slow
SSH link, whose requests can take 10 s, stalled the whole tree for every
phone, local workspaces included. It also held a lock that queued pane
opens, input and new tabs on every other link.

- Each linked machine is read on its own thread (`poller::Poller`). A poll
  waits at most 250 ms. A machine that has not answered is reported as it
  last was, and its read lands for the next poll. Only one read is in flight
  per machine, however many phones are watching. A machine that drops off and
  comes back cannot receive a stale read, because each slot has a generation.
- Routed control connections are locked per machine, not all together.
- A link that is up but has not answered its first read is sent as
  `RemoteView.pending` (additive). The app shows "Reading…" with skeleton
  rows instead of claiming the machine has no workspaces.

* fix(mobile): keep reaching the computer after the gateway restarts

Every `serve` bound a random port, so a restart left each phone holding
addresses that no longer answered. Where the n0 relays are unreachable, which
is common behind the Great Firewall, the phone had no other way to find the
gateway until it was paired again.

- `serve` listens on the same UDP port every time. It picks one on first run,
  keeps it in `<config dir>/mobile/port`, and moves only if the port is taken.
  IPv6 binding may fail, as in iroh's own defaults.
- Both ends add mDNS lookup (`iroh-mdns-address-lookup`, service `_tty7._udp`).
  On the same network a phone finds the gateway by key when its addresses are
  stale, such as after a new DHCP lease or a new IPv6 prefix. The gateway
  advertises and the phone only listens. If multicast is refused, each side
  starts without it and says so, rather than failing.
- iOS: `Info.ios.plist` declares the local-network use and the Bonjour
  service, without which iOS blocks multicast.
- An ignored test (`--test mdns`) connects by key alone over mDNS, for a
  machine that allows multicast.

* feat(mobile): run the gateway in the desktop daemon, paired from Settings

Phone access no longer needs `tty7-gateway serve` in a terminal.
Settings → Mobile switches it on, and the local daemon runs the gateway from
then on, with every window closed as well. That is where the panes a phone
reaches live anyway.

- Settings → Mobile, in all three locales:
  - an "Allow phone access" switch;
  - a status line (running, starting, off, or why it failed);
  - "Show code", which draws the QR code and the tty7pair: code with a
    Copy button, and closes on its own once a phone uses it;
  - the paired phones, each with Unpair.
  The section is in search, including by its config key `mobile_access`.
- The daemon (`tty7-app --daemon`) runs a supervisor (`core::mobile`). It
  watches `mobile_access` in config.json, re-reading only when the file
  changes, and starts or stops the gateway. A failed start is retried every
  30 s and logged once.
- tty7-gateway grows a `service` module: `start()` returns a stoppable
  handle, and `pair_code()` makes a code. The CLI's `serve` and `pair` are
  thin wrappers over them now. The gateway logs through `log`, so the
  daemon's output lands in its log file, and it reports itself in
  `mobile/status.json`. `State::serving()` checks the lock, which a crash
  cannot leave stale. A gateway that cannot take the lock leaves the
  status alone, because it belongs to the one holding the lock.
- iroh is linked into the GUI binary only. tty7-server stays the lean static
  binary pushed to remote machines.

* feat(mobile): serve phones whichever daemon is running

A daemon started by `tty7 server start` is the lean tty7-server, which
carries no gateway. With phone access on, the Settings status stayed on
"Starting…" and no phone could connect.

The GUI now checks, 5 s after it starts and whenever phone access is
switched on. If nothing is serving, it starts `tty7-app --mobile-gateway`,
detached the same way as the daemon (`spawn::detach_helper`). The helper
serves until the switch goes off, and exits at once if another process
already holds the gateway lock. When the daemon's own gateway is up, no
helper is started. The helper logs under its own role, "mobile".

* refactor(mobile): the daemon owns the gateway, as a child, whoever started it

There were two ways of running the gateway: a thread inside `tty7-app
--daemon`, and a detached helper the GUI started when the daemon could not.
That is now one way.

Every daemon, whether `tty7-app --daemon` or `tty7-server`, runs
`tty7_core::daemon::mobile::supervise` from `run_with`. While
`mobile_access` is on it keeps the gateway running as a child process, and
stops it when the switch goes off.

- Which program: `tty7-app` runs itself as `--mobile-gateway`. `tty7-server`
  runs a `tty7-gateway serve --exit-with-stdin` from beside it or on PATH,
  and links nothing new. Without one, it writes the reason into
  `mobile/status.json` for Settings to show, instead of "Starting…" forever.
- Lifetime: the child's stdin is a pipe from the daemon, and the gateway
  exits when it closes. A stopped, crashed or handed-off daemon (the pipe
  is close-on-exec) takes its gateway with it, and the next daemon starts
  one from its own binary. No gateway from an older build survives an
  update.
- Isolation: iroh no longer runs inside the process that holds every pane.
- `Status` moves to tty7-core, the one definition that the daemon, the
  gateway and the GUI all share.
- Gone: the GUI's helper check (`core::mobile` in the app) and the in-daemon
  gateway thread.

* fix(mobile): stop and reap the gateway before a daemon handoff

Found by running a real `tty7 server restart`. The old gateway did exit,
because the new image's supervisor started its own gateway and the old one
lost the lock. But it was left as a zombie: the image after the exec never
reaps a child it did not start, so each handoff leaked a process entry.

`hand_over` now calls `daemon::mobile::stop_for_handoff` before the exec,
which closes the gateway's stdin and waits for it. A flag keeps the
supervisor from starting another in the moments before the exec, and
`handoff_failed` clears the flag if the exec never happens, so the daemon
goes on serving.

Checked with two handoffs in a row (tty7-app → tty7-server → tty7-server):
- each old gateway was reaped, with no zombies system-wide;
- exactly one fresh gateway was running after each handoff;
- the pane's shell and its environment survived;
- the probe phone kept working.

* feat(mobile): the switch shows whether phones can reach you, not a status row

Settings → Mobile had an "Allow phone access" switch that showed intent and a
separate Status row that showed reality. That is one thing shown twice, and
the switch could sit on while nothing was running.

- The switch is the state. Switching on holds it at "Starting…", disabled,
  until a gateway is actually serving. If the daemon reports a failure, or
  nothing comes up within 15 s, the switch goes back off, `mobile_access`
  is reverted, and a notification says why.
- If the page opens on a failure the daemon is still retrying, the switch
  shows off with the reason in its description, and switching it on
  retries.
- The Status row is removed, with its four strings. There are two new
  strings for the failure, in en, zh and ja.

Also fixes the Settings window never showing notifications. It is a `Root`
like the workspace window but did not draw the notification layer, so any
toast pushed from Settings was queued and never shown. That included the
existing "Set as Default Terminal" result.

Checked in a dev instance. On a tty7-server daemon with no tty7-gateway:
Starting… first, then off, with "Phone access could not start: … no
tty7-gateway beside it or on PATH". On a tty7-app daemon: on, with Show
code enabled and no toast.

* feat(mobile): drop the "Needs you" section

The machine screen gathered every pane whose agent was waiting or done into
a "Needs you" section above the workspaces. Done lasts until the next prompt,
so the section grew with every finished agent and mostly held panes that
needed nothing.

Panes now appear once, in their own workspace. Each keeps its status badge
and words ("Needs input", "Working", "Done") and the agent's message.
PRODUCT.md and the design sidecar are updated to match.

* fix(mobile): say when typing doesn't reach the pane

The gateway's input thread gave up silently on a failed send_input, and
the app's input task did the same on a failed write, so the phone kept
showing a live pane while keystrokes went nowhere. Both now report the
failure as a pane error. Keys after it are dropped rather than ending
the stream, which the phone would read as the pane closing.

* feat(mobile): a compose box, paste and Shift+Tab on the terminal

Replying to an agent meant typing into xterm a character at a time,
without autocorrect, dictation or a usable IME. The compose box is a
real text field: Send types the text and then Enter, as its own write,
and several lines go in as one bracketed paste when the program asked
for it. Drafts survive leaving the pane and a send that failed. An
agent's pane opens on the box with the keyboard down.

The key bar gains Shift+Tab (Claude Code's mode switch) and a paste key.
A failed keystroke now takes the pane offline with a Reconnect banner
instead of being swallowed.

* feat(mobile): reconnect on its own, and select text to copy

A dropped pane or machine stream is retried with backoff (1s, 2s, 4s …
15s) and at once when the network comes back, rather than waiting for a
tap on Reconnect. The pane keeps its last screen up until the new
replay starts, and output or errors from a replaced stream are ignored.

Touch selection does not work in xterm, so a copy key lays the whole
buffer out as plain text over the pane, wrapped to the phone and joined
where the terminal wrapped, for the phone's own selection and Copy.

* feat(daemon): size leases, and Take Back on the desktop

An observer can now run a pane at its own size (ClientMsg::Lease, feature
size-lease). The pty and every observer go to that size. The controller
keeps its grid, its resizes are remembered rather than applied, and the
pane goes back to the last of them when the lease ends: the observer lets
go, its connection closes, or the controller takes it back.

A controller hears about leases only after asking (Watch), since an older
client cannot decode DaemonMsg::Lease. The desktop asks on every attach,
spawn and relink where the daemon advertises the feature, locally or
through the host hello for remote workspaces, and shows the pane as in
use on the phone with a Take Back button.

* feat(mobile): take a pane over at the phone's size

The terminal's phone button asks the gateway to run the pane at the
phone's grid (PaneRequest::TakeOver), which it turns into a size lease on
the observer connection, named after the paired device. The grid follows
the keyboard and rotation; leaving the pane, or the connection dropping,
gives it back. When the desktop takes it back the app says so and offers
to take it over again, never doing it on its own. A daemon too old for
leases is reported, and the pane keeps working.

* fix(mobile): link SystemConfiguration and install a rustls provider on iOS

The first iOS build failed to link: netdev and system-configuration, pulled
in by iroh, need SystemConfiguration.framework, which the generated Xcode
project does not list. bundle.iOS.frameworks adds it on `tauri ios init`.

Once linked, the app panicked at launch: iroh builds its reqwest client with
`rustls-no-provider`, so a process-wide crypto provider must be installed
before any client is built. Install ring's, which is already in the tree.

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(mobile): keep the terminal's scrollbar on screen while panning

Panning a pane wider than the phone scrolled xterm's own box sideways with
the text. The box was only the view's width, so its vertical scrollbar
panned off with the columns and its scrollback stopped taking touches past
the first screen. The box now spans every column, and the bar is shifted
to the visible right edge as the view pans.

The bar is also drawn like the indicator WebKit shows for the pan, thin,
rounded and translucent, instead of VS Code's 14px square slider, so the
two axes match.

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(mobile): pair by scanning the QR code, and Enter and quick-answer keys

Pairing took a pasted `tty7pair:` code, which on a real phone means getting
text off the desktop somehow. A Scan button next to Paste now reads the QR
code tty7 shows, through tauri-plugin-barcode-scanner, and pairs straight
away. The camera runs behind the WebView with our own viewfinder and Cancel,
since the plugin's full-screen view has no way out. The plugin is registered
on phones only, so the desktop dev build is unchanged.

The key bar gains Enter, so an agent's highlighted choice can be confirmed
without raising the keyboard, and 1 2 3 y n for numbered choices and y/n
prompts.

Co-Authored-By: Claude <noreply@anthropic.com>

* chore(mobile): sign for the App Store and declare exempt encryption

Sets the development team so `tauri ios init` writes it into the Xcode
project, and marks the app's encryption (standard TLS/QUIC only) as exempt
so TestFlight uploads skip the export-compliance question.

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(mobile): count the iOS safe areas once

The WKWebView's scroll view inset its content by the safe areas, and the
page, laid out with viewport-fit=cover, padded by env(safe-area-inset-*)
as well. The viewport came out 778pt tall on an 874pt screen: everything
sat a status bar's height too low, with a blank band under it. The scroll
view's automatic inset adjustment is now off, so the page runs edge to
edge and its CSS alone keeps clear of the status bar and home indicator.

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(mobile): the Terminal Mobile redesign

The app takes the desktop's neutral greys, light and dark, with ink rather
than a system blue for what is pressed or chosen.

- Machines: pairing's "+" moves to a floating bar at the bottom beside a
  search field. Each machine shows its link, round trip and tab count as
  last seen.
- A machine: tabs grouped by workspace with a count; round agent glyphs;
  a dot on the right for running or waiting on you. The per-group New tab
  buttons give way to one "+" in the same floating bar, beside tab search.
- New tab: a sheet to pick Claude Code, Codex or a shell, and the
  workspace. An agent's command is typed into the new tab once it is live.
- A pane: the bar keeps only back, the title with its state, and a menu
  for selecting text, the fit and the phone's size. Under it, one row of
  equal keys, a page at a time, and a message box that is always there;
  its round button sends, or when empty hands the keyboard to the
  terminal.

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(mobile): the tty7 mark as the iOS app icon

The phone showed Tauri's default icon: `tauri ios init` filled the Xcode
project with it. The committed icons/ios set was drawn on the macOS grid,
a rounded tile inset on transparency, which iOS would shrink inside its own
mask with a pale border. icons/app-icon-ios.svg is the same Duo mark full
bleed, rendered without alpha as the App Store requires.

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS

* fix(mobile): typing, scrolling and pairing on a real phone

- Typing into a pane: an input method's text never reached it, since iOS
  never commits a candidate into xterm's hidden textarea. Tapping the
  terminal now focuses a plain field of our own, whose committed text goes
  to the pane as it is committed. Backspace on the empty field, Enter, Tab
  and the arrows go as the terminal's keys.
- xterm sends nothing itself any more (disableStdin). That also stops the
  phone answering a program's colour and device queries: the desktop
  answers those, and the phone's late second answer landed in the shell as
  typed text.
- Scrolling the scrollback: xterm 6 has no working touch scrolling. A
  mostly vertical swipe now scrolls the buffer a row at a time and coasts;
  a sideways one is left to the native pan.
- Pairing: the steps name the desktop's Settings -> Mobile, Allow phone
  access and Show code, not a command-line gateway, and so do the notices
  when a machine cannot be reached.

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS

* fix(mobile): room for the keyboard, and smoother vertical scrolling

- The keyboard: the WebView runs edge to edge and is not resized for it,
  so it covered the dock and the pane's last lines. The app now takes the
  size of the visual viewport, drops the home indicator's gap while the
  keyboard is up, and keeps the cursor's line in sight.
- Scrolling: the terminal draws with xterm's WebGL renderer, which a
  scroll does not make lay every row out again. A swipe is applied once a
  frame, and moves the view by pixels: xterm scrolls whole rows, and the
  rest of a row is a GPU shift of the drawn screen, put on together with
  the rows it goes with.

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS

* feat(mobile): settings, message history, and a tighter home screen

- Settings, from beside the Machines title: appearance (automatic, light,
  dark; the status bar and keyboard follow through the window's interface
  style), terminal text size, how a pane wider than the phone first shows,
  clearing the message history, and the version.
- The message box keeps what it sends on the phone. As a message is
  written, past ones that match take the key row's place; with the box
  empty, a History button opens them all, searchable. A line that asks for
  a password is sent but not kept.
- ^R on the third key page, for the shell's own history search.
- A top-level screen's bar floats over the list, clear until the title
  scrolls under it, so the large title sits just under the status bar.

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS

* fix(mobile): a fitted pane fills the view, and its scrollbar drags

- A pane shorter than the view (a wide one, fitted) no longer leaves the
  bottom of the screen blank: the terminal here runs as many rows as fill
  the view, the extra ones holding the pane's earlier lines, and what is
  left over goes above so the prompt stays next to the keys. The pane on
  the desktop keeps its size.
- A drag that starts on the scrollbar is left to xterm. The swipe handler
  took it too, the other way round, and the two cancelled out.

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS

* fix(mobile): errors say what to do in the app, not on the command line

The messages a phone shows, and the two Settings → Mobile can, named the
gateway process, the CLI's `tty7 server start`, the transport and a lock
file's path. They now speak of tty7 on the computer and of pairing: open
it there, update it, pair again, quit the other copy.

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS

* style: rustfmt the gateway and mobile client

Claude-Session: https://claude.ai/code/session_01HVosmYyVSH3BrsLYx3tcSS

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-29 19:09:32 +08:00
l0ng-ai eec9350ff8 test(git): compare repo roots in one spelling so Windows passes (#1013)
canonicalize answers \\?\C:\... on Windows while git prints C:/...; the
production path already folds the first into the local spelling in
probe_repo, only the test compared them raw.
2026-09-29 17:34:48 +08:00
l0ng-ai 12ec0c92a9 fix(sidebar): stop ungrouping tabs when a git probe fails (#1011)
A tab's auto group comes from probing its cwd for a repository. Any
failure of that probe - git failing to spawn, the macOS /usr/bin/git shim
dying while Xcode is mid-switch, a remote link dropping - came back as
"not a repository", overwrote the tab's remembered group, and was never
re-checked while the pane sat idle. Tabs in perfectly good repositories
dropped into Ungrouped and stayed there.

- Read root, home and branch in-process on this machine with
  gix-discover instead of three git processes. Only the line counts
  still come from `git diff --numstat`, so they keep matching the diff
  views; a detached HEAD is still named by git for the same reason.
- Remote hosts keep asking their own git (a new control request would
  force a dialect bump), but the probe now tells "not a repository"
  (exit 128, or the directory is gone) apart from a failure.
- A failed probe leaves the cache as it was, so a tab keeps its
  remembered group, and an unanswered cwd is retried every 10s.
2026-09-29 16:55:03 +08:00
l0ng-ai 8cf31c718d feat(worktree): setup, .worktreeinclude, agent launch, recoverable removal, and a worktree CLI (#1009)
* feat(worktree): setup script, .worktreeinclude, fresh base, recoverable removal

- Start new worktrees from the remote default branch, fetched first, with
  --no-track; fall back to the current branch without a remote.
- Carry gitignored files listed in .worktreeinclude over from the main
  checkout, copy-on-write (clonefile on macOS, copy_file_range elsewhere);
  remote hosts copy through the Host trait under a size budget.
- Run .tty7/setup in the first pane before the agent, with TTY7_ROOT_PATH,
  TTY7_WORKTREE_PATH, TTY7_WORKTREE_NAME and a per-worktree TTY7_PORT block.
  The script only runs once its exact content is approved for the repo.
- The New Worktree dialog picks what the first pane starts (Shell or a
  recent agent) and takes a task for agents that open on a first message.
- Removal snapshots the checkout, uncommitted work included, under
  refs/tty7/trash/<name> first; the ref also retires the name. A branch
  git refuses to delete is reported instead of silently kept.
- Hide .tty7/worktrees via info/exclude rather than a catch-all
  .tty7/.gitignore, so .tty7/setup can be committed.

* feat(cli): tty7 worktree new/ls/rm

- worktree new: the GUI dialog's worktree from the command line — create,
  carry .worktreeinclude, open a tab named after the branch, and type
  .tty7/setup && <agent> [task] into it. Prints the path first.
- worktree ls: every checkout of the repo, tty7's marked, with the live
  panes working in each.
- worktree rm: refuses while panes are inside unless --close-panes, and a
  dirty checkout unless --force; reports the snapshot ref and a kept branch.
- Move shell_quote and the first-line builders into tty7-core so the GUI
  and the CLI type the same line.
- Docs: CLI reference and the Worktrees page cover .worktreeinclude,
  .tty7/setup, TTY7_PORT and recoverable removal.

* fix(worktree): run setup and the agent inside the worktree; Start is a dropdown

- The first line now opens with cd into the worktree: a shell's startup
  files can move the pane, and setup then ran in (and wrote into) the main
  checkout.
- The Start choice is a dropdown listing Shell and every agent this machine
  offers, instead of a segmented switch capped at three.
2026-09-29 16:54:59 +08:00
l0ng-ai 9c1961de39 fix(agent-hooks): make the OpenCode plugin load on OpenCode 2.x (#999) (#1007)
OpenCode 2.x only loads a default export shaped { id, setup | effect } and
rejects the file otherwise ("Plugin must export a default definition with
an id and an effect or setup function"). The generated tty7.js only had a
named export, so every 2.x user got a load error.

- Export default { id, server, setup }: 1.x (>= 1.3.4) reads `server`,
  2.x reads `setup`; the named Tty7Presence export stays for older 1.x.
- 2.x: subscribe via ctx.event.subscribe(), read event.data, map
  permission.asked, and treat session.created with a parentID as a child
  session. Stay inert inside the shared --service process, whose sessions
  belong to no single pane.
- Spawn the emitter directly with node:child_process instead of
  `sh -c`, which does not exist on Windows.
2026-09-28 23:15:31 +08:00
l0ng-ai 7f66f69674 fix(ssh): pin russh to our fork with the zlib truncation fixes (#997) (#1006)
A host with `Compression yes` (every one imported from an ssh config that
sets it) negotiated zlib@openssh.com, and the pinned ayamir/russh rev cut
every packet that inflated past 2x its compressed size. The zlib stream
desynced right after auth: the session showed as connected and never
printed a byte.

- Move the [patch.crates-io] pin to l0ng-ai/russh (branch tty7): ayamir's
  gssapi-with-mic commit plus Eugeny/russh 58886f4d and 24e2c374.
- Add an end-to-end test that runs a zlib session against an in-process
  russh server and checks every byte of a compressible + incompressible
  payload arrives (0 of 270336 bytes on the old pin).
- Re-importing an ssh config now updates `algorithms` on hosts that already
  exist, so dropping `Compression yes` and re-importing takes effect.
2026-09-28 23:07:49 +08:00
l0ng-ai 7016fdb7ed feat(editor): IDE-level code editor — multi-cursor, LSP, git gutter, symbols, split (#1002)
* fix(keymap): let the code editor's multi-cursor chords beat the pane keys

gpui-component now binds secondary-d, secondary-shift-l and
secondary-alt-up/down in the Input context for multiple cursors. A
context-free binding ranks as deep as the focused context and ties go to
the one added last, so tty7's SplitRight and FocusPaneUp/Down took those
keys inside the editor. Re-add the editor bindings after tty7's table; other
text fields have no handler for them and fall through to the pane keys.

* feat(editor): show the selection count in the status bar

With several cursors the Ln/Col readout (the primary caret's) is followed
by "(N selections)".

* feat(editor): git change markers in the gutter

Diff each buffer against its file's index version (what VS Code's quick
diff and the SCM panel's Changes compare with) and hand the hunks to the
editor as gutter markers: added, modified, and a wedge where lines were
deleted. The base is read with `git show :./name` through the buffer's own
host, so remote workspaces work too; SFTP buffers and untracked files get
no markers. It is re-read when the repository's SCM epoch moves, on save
and when the path changes; the diff itself is a line-level Myers diff run
off the UI thread shortly after each edit.

Next/previous change and Revert Change (one undo step, also in the
right-click menu) are commands; clicking a marker opens a peek of the
staged lines with a Revert button. The editor watch now also follows the
repository the gutter found, so a stage or checkout refreshes the markers.
The `editor_git_gutter` config (default on) is flipped by the
ToggleEditorGitGutter command.

* feat(editor): go to symbol, breadcrumbs, and back/forward navigation

Go to Symbol (Cmd-Shift-O in the editor) lists the file's outline on a new
Symbols tab of Search Everywhere: indented by nesting while browsing, ranked
flat with the containing symbols as a subtitle while searching. Arrowing
through the rows previews each symbol; Escape puts the caret and the scroll
back, Return keeps it.

The outline comes from the tree the highlighter already parsed, with a small
query per language (Rust, Go, Python, JavaScript, TypeScript/TSX, C, C++,
Java, Markdown, Ruby, shell). Tty7App::editor_set_document_symbols lets a
language server's documentSymbol answer replace it per buffer.

A breadcrumb row over the text shows the file's path from its project root
and the symbols around the caret; the symbols open Go to Symbol.

Back and forward (Ctrl-- / Ctrl-Shift-- on macOS, Alt-Left/Right elsewhere)
walk a per-tab history. Jumps are noticed by sampling the caret whenever the
editor draws: a change of file, or a move of ten lines or more without an
edit, records where the caret was. Quick open, go to line, file links and
anything that goes through open_file_in_editor_at are therefore captured
without hooks of their own; a place in a closed file reopens it.

* feat(editor): bind next/previous change to Alt+F5 in the code editor

Bind EditorNextChange / EditorPrevChange to alt-f5 / shift-alt-f5 in the
Input context only, after tty7's own table, so a terminal never loses the
function key. Mark the hunks stale right after a revert, before the
input's Change event lands, and cover the whole loop (markers, stepping,
revert as one undo) with a window test.

* feat(editor): line commands in the editor's right-click menu

Toggle Comment, Move Line Up/Down, Duplicate Line, Delete Line and Go to
Matching Bracket, dispatched to gpui-component's new editing actions so
each row shows its chord. Strings in en, zh and ja.

* feat(editor): language servers for the code editor

A new ui::lsp module runs language servers for local files the editor
opens: rust-analyzer, typescript-language-server, pyright (or pylsp),
gopls and clangd, from a registry table. Each server is keyed by
(server, project root), found from markers such as a Cargo workspace,
package.json, go.work/go.mod or pyproject.toml, and shared by every buffer
under that root. A server missing from PATH (which tty7 already fills from
the login shell) means no LSP for that language and a one-line hint in the
status bar.

The JSON-RPC client frames Content-Length messages over the server's stdio
on dedicated threads, holds everything back until initialize is answered,
cancels requests nobody waits for any more, and answers the server's own
requests (configuration, capability registration, applyEdit). Documents
use full-text sync, debounced, and flushed before every request. A server
whose last file closed shuts down after a grace period, every server exits
with the app, and one that crashes is restarted a few times before it is
left down.

Features: diagnostics as underlines with hover messages and an error and
warning count in the status bar; completion (snippets flattened to plain
text); hover; go to definition by secondary-click or F12, across files
through open_file_in_editor_at; code actions on the editor's own menu
(cmd-.), resolved and executed as the server needs; Format Document
(shift-alt-f); and Rename Symbol (F2) in the editor's bar, applied to open
buffers and to files on disk. The key bindings sit in the Input context so
F2 and F12 stay with terminal programs.

Positions are converted at the boundary: servers count UTF-16 units,
gpui-component counts chars, and the rope counts bytes.

The new editor_lsp setting (default on) turns it all off.

* fix(editor): clear the change markers when the file loses its base

A file that becomes untracked or leaves its repository kept the markers
of its last diff; clear them when the base goes away. Guard the base read
against a panic, which would otherwise leave the fetch flagged forever,
and test the read against a real repository: the base is the staged
version, and untracked files have none.

* test(keymap): the editor's navigation chords win inside the editor, not in a terminal

* fix(keymap): let the code editor's line commands beat the app's chords

The editor binds toggle comment, move/copy/delete line, insert line, select
line and go-to-bracket on its CodeEditor key context. A context-free app
binding ranks as deep as the focused context and wins the tie by being
added later, so ⌘/ (shortcut sheet), ⌘↵ (fullscreen), ⌘⇧↵ (maximize) and,
off macOS, ⌥↑/⌥↓ (pane focus) took those keys inside the editor. Re-add
them in fixed_bindings on CodeEditor, which only a multi-line code editor
declares, so plain text fields and the terminal keep the app's keys.

* fix(keymap): route cmd-K cmd-D to the code editor's skip-occurrence

The chord starts with ClearScrollback's key on macOS, and gpui drops a
pending chord that ranks below a complete match, so the fork's binding
never got its second key. Re-add it after tty7's table, in the CodeEditor
context only, so other text fields don't wait on cmd-K.

* feat(editor): history follows edits, and paging is not a jump

Places in the back/forward history now move with lines inserted or deleted
above them, read from the editor's line-edit log on every change. The caret
move a Page Up/Down, paste, undo or redo makes is heard through the
keystroke that caused it and is not recorded as a jump.

* feat(editor): Problems list, keyboard change peek, Editor settings

- Problems: every error, warning and note the language servers published
  for the open files, grouped by file, at the foot of the code panel.
  The status bar's counts and ToggleEditorProblems (Cmd/Ctrl+Shift+M)
  open it; a row opens its file at the line and column. Read through a
  new LspStore::diagnostics_snapshot, mapped to editor columns.
- EditorPeekChange (Alt+F3 in the editor) peeks the change under the
  caret, or goes to the next one. The peek now takes the keyboard from
  a click too: Enter reverts, Escape closes and hands focus back.
- Settings > General gains an Editor group: git change markers,
  language servers, soft wrap and rendered Markdown, searchable and
  resettable like every other row.

* feat(lsp): outline, references, workspace symbols, signature help

- documentSymbol feeds the editor's outline (breadcrumbs, Go to Symbol)
  through editor_set_document_symbols, refreshed 500 ms after typing
  pauses. Flat answers are nested by range; an empty answer from a server
  still indexing leaves the tree's outline in place.
- Find All References (shift-F12) and a definition with several answers
  open a Locations tab in the search. Arrowing through it previews a place
  in the file in front, and Return goes there, into any file.
- Go to Symbol in Workspace (secondary-T inside the editor) asks the
  server's workspace/symbol as the query is typed, into the same list.
- Completion items are resolved for their documentation and auto-import
  edits, which are applied on accept (with the gpui-component fork).
- Signature help opens on the server's trigger characters (or on '(' and
  ','), stays current while typing in the call, and closes when the server
  says the cursor has left it or on Escape.
- Diagnostics are replaced wholesale on publish; between publishes the
  fork now carries them through edits instead of dropping them.
- workspace/configuration answers from per-server settings, with an empty
  object for a section tty7 sets nothing for. rust-analyzer gets
  checkOnSave with cargo check, also as initializationOptions, and every
  server gets didChangeConfiguration after initialized.

* feat(editor): text commands in the palette and keymap

Transform to Upper/Lower/Title Case, Trim Trailing Whitespace, Join Lines
and Remove Surrounding Brackets, as tty7 actions (bindable on the
Keybindings page, unbound by default) and as palette rows offered while a
buffer is open. Both run gpui-component's editing action on the active
buffer. Join Lines gets VS Code's ctrl-j as a fixed CodeEditor binding on
macOS, where the terminal keeps it as a line feed. Strings in en, zh, ja.

* feat(editor): split the editor into two groups

Cmd-\ (Ctrl-\ off macOS, bound only inside the editor so the terminal keeps
SIGQUIT) opens the file in front in a second group on the right. Each group
has its own file in front and, for different files, its own caret and
scroll; Cmd-Alt-Left/Right (Ctrl-Alt off macOS) or a click moves the focus
between them, and a group whose last file closes goes away. The split is
saved with the tab's other editor state.

The focused group is always TabCode's own files/active and the other waits
beside it, so everything that acts on the file in front - saving, go to
line, language servers, change markers, multiple cursors, history - follows
the focus unchanged. A file shown in both groups is drawn once, in the
focused one; the other shows a placeholder that brings the focus over. A
second InputState kept in sync would have needed every hook attached twice.

Also: palette rows and View menu items for Go to Symbol, Back, Forward and
Split; Cmd-Shift-O closes Go to Symbol when it is open; the status bar no
longer repeats the path the breadcrumbs show (a rendered Markdown file keeps
its breadcrumb path); change markers are kept current in both groups.

* test(keymap): the editor group chords win inside the editor

* fix(lsp): close a window's documents when the window closes

Documents were only closed by sync_window, which runs when a window's
buffer set changes. Closing a window never ran it, so no didClose was
sent, the idle shutdown never started, and a language server lived on
until quit (forever, with the app retired to the tray).

* fix(editor): restore a split whose left group had no recorded files

The recorder writes files: [] with a split when the left group held only
untitled or remote buffers, but restore returned early on an empty left
list and dropped the right group too.

* fix(editor): forget a swept orphan buffer's navigation state

The orphan sweep dropped clean buffers without calling forget_buffer, so
each one's outline cache (a full copy of its text), LSP symbols and
edit-log cursor stayed in EditorNav for the life of the window.

* fix(lsp): owner-only sync, stale-edit checks, request timeouts, re-enable

- Only the buffer that owns a document may use its server. The same file
  open in another window used to send its own text as didChange on F12,
  rename, references or signature help, swapping the document under the
  owner. LspStore::context now takes the requester and refuses a
  non-owner quietly, before anything is sent.
- apply_workspace_edit checks every open buffer an edit touches against
  a baseline: the texts when a rename was asked for or the code-action
  menu was filled, or the text the server last heard for its own
  workspace/applyEdit (which then answers applied: false). A buffer typed
  in, opened or closed since means nothing is applied.
- A request made after the server's output closed fails at once instead
  of waiting forever. Requests time out after 10 s (initialize after 60 s,
  shutdown after 2 s) and cancel themselves on the server.
- Turning editor_lsp back on asks every window for its open files again,
  which starts their servers. Windows register how to be asked; closed
  ones are forgotten.

* test(nav): spell out LineEdit's new at_line_start field

gpui-component's LineEdit now records an insertion at column 0, which
moves the whole line down. The literal edits in this test are mid-line.

* fix(editor): a restore merges into the tab, and commands follow the group focus

Session restore used to assign the recorded groups over whatever the tab
held when its files finished loading, so a file opened or a split made in
the meantime was lost. TabCode::restore_groups keeps a split made meanwhile
as it is, and otherwise lays out the recorded groups and puts the files
opened meanwhile back into the focused group, the last of them in front. A
restore the reader has moved on from no longer takes the keyboard, and never
hides a panel they opened.

The group focus only followed the keyboard when the editor drew. Keys are
safe - gpui draws a window whose focus moved before dispatching the next
key - but a command from the menu bar or a context menu is dispatched
without a draw, and acted on the group that had the focus before. A
capture-phase listener for every editor command on the editor's element now
settles the group first, wherever the command's handler sits.

* fix(editor): leave cmd-T to New Tab; offer workspace symbols from the palette

Inside the code editor cmd-T was rebound to Go to Symbol in Workspace,
which made tty7's most-used chord mean two things depending on focus.
It is New Tab everywhere again. Workspace symbols stay reachable as an
Editor palette row and as a rebindable, unbound action.

* build: pin gpui-component to the fork's editor work (0e7541fb)

* fix(search): let the editor's pickers stand alone in Search Everywhere

Go to Symbol, a language server's places and Go to Symbol in Workspace
opened on hidden tabs, so the window-wide scope row (All, Terminals,
Sessions, Hosts, Commands) sat over them with nothing selected, and Tab
swapped the list for the terminals. They now show a heading in place of
the row (References / Definitions / Symbols / Workspace Symbols, with a
count), Tab stays put, and the footer drops the scope hint.

* fix(search): Go to File stands alone like the editor's pickers

Go to File (cmd-O) is reached only by its chord, yet it sat under the
scope row with nothing lit and offered Tab to leave for the terminals.
Every tab outside the row now stands alone the same way: its name in
place of the row, Tab stays put, no scope hint in the footer.

* feat(search): give the editor its own scope row — Files, Symbols, Workspace Symbols

Go to File, Go to Symbol and Go to Symbol in Workspace were three
separate pickers, each on its own chord. They now share a second scope
row, the editor's, next to the window's: cmd-O and cmd-shift-O open on
it and Tab walks it. Only tabs that can answer show: Symbols needs a
file in front, Workspace Symbols a language server that searches the
project. A row of one shows as a heading. Each tab is opened the way its
chord opens it, so it arrives set up; references and definitions still
stand alone.

* feat(search): fold Workspace Symbols into Symbols

Symbols and Workspace Symbols answered the same question at two scopes.
Symbols now does both: with nothing typed it is the file's outline; once
a query is typed, the front file's language server is asked across the
project and its answers are listed after the file's own, each under a
heading when both have rows (the front file's own hits are dropped from
the project's). The separate tab, action and palette row are gone.

* fix(search): call the language server's project results Project, not Workspace

LSP's workspace/symbol searches the server's project root, which has
nothing to do with a tty7 workspace (a group of tabs). The Symbols tab's
second section said Workspace, reading as if it searched those. It says
Project now, and the tty7-facing names follow (project_symbols,
set_project_symbols, lsp_project_symbol_query); only code that speaks
the protocol keeps its word.

* ci(host-boundary): allow the language servers' local reads

ui::lsp only ever holds local buffers (OpenFile::local refuses any other
host) and runs its servers on this machine, so the files it reads to
measure a column, apply a rename to disk or find a project root are on
this disk. Each call is allowlisted with that reason.

* test(editor): spell test paths so they hold on Windows

The language-server tests used /p/... paths, which are not absolute on
Windows and so have no file:// URI; they now build platform paths
(lsp::test_path) or spell the URI out. The gutter and split tests
canonicalized their temp dirs to get past macOS's /private symlink,
which on Windows yields the \\?\ form no editor path is ever in; they
share a helper that canonicalizes everywhere but Windows.

* test(editor): resolve temp dirs the way the editor does

On the Windows runner the temp dir is an 8.3 short name (RUNNER~1),
which the editor's load expands through Host::canonicalize. The split
tests now resolve their fixtures through that same call instead of
guessing per platform.
2026-09-28 20:47:07 +08:00
l0ng-ai 3ef692b353 feat(agents): infer interrupted and stale turns, report permission prompts first-hand (#1003)
- Interrupts: an Esc / Ctrl+C (legacy, kitty and modifyOtherKeys forms)
  on a pane whose agent is mid-turn arms a 1s settle; if no hook event
  arrives, the turn is assumed over and goes Done. Claude's Stop skips
  user interrupts, so panes used to stay on working until the next prompt.
- Stale turns: a daemon sweep moves a turn that has been Working with no
  hook event for 30 minutes to Idle.
- Both set `inferred` on the session; the next real event clears it, and
  a tool finishing after a guess puts the turn back on Working. Inferred
  states raise no finish notification and no unread badge.
- Claude and Codex now hook PermissionRequest, and PreToolUse for their
  ask-the-user tools (AskUserQuestion / request_user_input), so Waiting
  shows the moment the prompt opens. Codex also gains PostToolUse, so it
  leaves Waiting once the approved tool has run.
- The "finished" desktop notification waits 1.5s and is dropped if the
  next turn starts first (queued message, Stop hook sending it back).
2026-09-28 20:47:01 +08:00
l0ng-ai 2e0d4de136 feat(github): show a pull request's checks, reviews and merge state (#1000)
The PR detail now leads with what it is usually opened to find out:

- Checks: check runs and commit statuses on the head commit, failures
  first, with durations and links to their logs. A section with more
  than five folds the passed and skipped ones into one row.
- Reviews: one row per reviewer (approved, changes requested,
  commented, requested), folding the way GitHub's sidebar reads them.
- A merge-state line under the branches ("Waiting on 1 check",
  "1 check failing", "Merge conflicts", "Ready to merge", ...).

Checks and reviews that cannot be read are left out instead of failing
the whole detail. While a check is running, just the checks are re-read
every 20 seconds (signed in only); once every verdict is in, the detail
is read again for the new merge state.

The list pins the pull request of the pane's branch under the repo row,
looked up through the branch's upstream so a fork's branch is found
under the fork's owner.

Long sections fold: comments past four keep the first and the latest
two, long descriptions and comments are clamped behind "Show full text",
and reviewers and changed files show a few with a "show all" row.
2026-09-28 20:46:49 +08:00
ARNO 643e0f7d95 feat(agents): add Qoder CN CLI integration (#988)
* feat(agents): add Qoder CN CLI integration

* fix(agents): spell Qoder CN's config override QODERCN_CONFIG_DIR

The China build of Qoder resolves its configuration through QODERCN_CONFIG_DIR.
The first pass invented QODER_CN_CONFIG_DIR instead, so an install that set the
real one was treated as unrelocated: hooks went to ~/.qoder-cn and history was
scanned from a directory the CLI never writes to. The test that should have
caught it set the same invented name, so it only proved the name agreed with
itself.

Picks up the rest of the review as well — detect the `qoder-cn` dispatcher
beside the other two binaries, call it the mainland-China build rather than a
different vendor, and drop the QODER_CN_HOOK_EVENTS alias for the table it only
pointed at. The serialized enums keep their variants appended; only the
independent ALL arrays moved QoderCLICn next to QoderCLI.
2026-09-28 13:35:10 +08:00
l0ng-ai 39776012e2 feat(github): read a repository with whichever gh account can see it (#987)
The GitHub panel borrowed only gh's active account, so a private repository
owned by an organisation another signed-in account belongs to read as a 404.

When the active account gets a 404, 401 or 403, retry with gh's other
github.com accounts and remember, per owner, the one that got through. The
other accounts are listed lazily (gh auth status checks each online), and a
token from GH_TOKEN/GITHUB_TOKEN keeps its no-fallback meaning.
2026-09-28 10:59:25 +08:00
l0ng-ai bf5149bea0 fix(editor): stop losing edits, share buffers, add file strip, quick open and go to line (#984)
* fix(host): save local files atomically via a temp file and rename

LocalHost::write_file truncated the target in place, so a crash, a full
disk or a killed process mid-save destroyed the user's file. It now
writes a hidden sibling temp file, syncs it, keeps the old file's mode
and renames it over the target, removing the temp file on any error.

It still writes in place where a rename would change something visible:
a non-regular target (symlink, directory, FIFO), a read-only file, and on
Unix a hard-linked file or one owned by another user, or when the temp
file cannot be created (e.g. a read-only directory).

* feat(editor): add editor_text for encodings, line endings, indentation and EditorConfig

A pure module the code editor will use when loading and saving files:
decode detects BOMs, binary files, UTF-8, GB18030 and a lossless
Windows-1252 fallback and normalises CRLF; encode restores the exact
bytes and names the first unrepresentable character; detect_indent
infers tabs or a 2/4/8 space width with language defaults; and
editorconfig_for resolves .editorconfig sections with save-time rules.

* feat(editor): share buffers across tabs, guard unsaved work, add a file strip

- One buffer per file per window; tabs list which buffers they show. The
  same file open in two tabs is no longer two diverging copies.
- Closing a tab, its last pane, the window, or quitting asks about unsaved
  files (Save / Cancel / Discard) instead of dropping them. Bulk closes skip
  tabs with unsaved files; a tab that vanishes any other way hands its
  unsaved buffers to the tab in front.
- File tree rename/delete now retarget or flag the open buffer, so a save
  no longer recreates the old path.
- Saves check the file's mtime first and ask before overwriting a change
  made elsewhere; this is the only detection SFTP buffers get.
- Dirty is a comparison with the saved text, so undoing back clears it.
- Reloads replace only the changed span as an ordinary edit, keeping undo.
- Load/save go through editor_text: encoding, BOM and CRLF round-trip,
  indentation is detected, .editorconfig is honoured.
- Header shows a strip of open files; New File, Save As (native panel
  locally, a path bar remotely), Go to Line (Ctrl+G), and the status bar
  shows indentation, encoding and a clickable line ending.
- Open files are remembered per tab across restarts.

* feat(search): quick open a file by name from a Files tab

Search Everywhere gains a Files tab that finds any file in the active
tab's project by fuzzy name and opens it in the built-in editor, with
`name:line[:col]` jumping to that spot. The list comes from one walk of
the project through the host (Host::search with an empty query), so it
works the same on local, SSH and WSL workspaces and skips what the tree
hides: dotfiles, .git and gitignored paths. The walk is capped at 50k
entries / 20k directories, kept between openings and revalidated in the
background each time the search opens.

Files join the All tab once a query finds them. Go to File... is bound to
Cmd+O on macOS (Cmd+P is already Search Everywhere) and ships unbound
elsewhere, where every obvious chord is taken or owed to the shell.

* chore(editor): allowlist the editor session file, tidy lints

* fix(editor): keep restored file order, drop stale close waits, carry files through tab merges

- Background arrivals (restore, merge, rescue) append to the strip in order
  instead of inserting beside the active file, which reversed them.
- A cancelled Save As, a dismissed path bar, or a dropped buffer cancels any
  close that was waiting on that save.
- Merging a tab into another carries its open files along.
- A shell exiting closes its tab without a prompt it could not honour;
  unsaved buffers move to the tab in front.
- Tabs rebuilt under the same id (server restart) restore their files.

* fix(host): only fall back to an in-place write when the rename is refused

On Windows every failure of the atomic save fell back to fs::write,
including a failure while staging the temp file. A full disk would then
truncate the original in place, the very loss the temp file prevents.
Staging errors now return as-is; only a refused rename (a file held open
elsewhere) takes the in-place path.
2026-09-28 00:32:18 +08:00
l0ng-ai b063ba97a0 refactor(settings): fold Window & Tabs into General, drop two settings (#982)
The Window & Tabs page is gone. Its three remaining tab settings (new tab
position, tab bar position, auto grouping) are a Tabs group on General,
below Startup & restore, so the nav has seven sections.

Removed outright:
- SSH tab title (`ssh_tab_title`, #726, unreleased). The sidebar already
  groups SSH tabs under their host, and renaming a tab pins its name.
- Open diff preview from sidebar counts (`sidebar_diff_preview`, #247).
  The sidebar counts and the Info panel's changes row always open the
  diff overlay; the large-tree stall it worked around is bounded. An old
  config.json that still carries either key loads as before.

The now-unused window settings icon goes with the page.
2026-09-27 19:11:45 +08:00
l0ng-ai fd2c4f7d4e feat(panel): Search and GitHub tabs in the right panel (#978)
* feat(panel): add Search and GitHub tabs to the right panel

The right panel grows from three tabs to five. Five word labels do not
fit the panel's 280px resting width, so the tab row now draws a glyph
per tab and names it in a tooltip.

Both new panes are placeholders here; the content search and the
GitHub issues/PR browser land on top of this.

* feat(panel): find in files in the right panel's Search tab

The Search tab replaces its placeholder with a content search over the
active tab's project -- the same roots the Files tab shows -- on the host
that project lives on. Hits arrive as you type (debounced, with a
generation counter so a stale answer never lands), grouped by file with a
count, each line excerpted with its matches highlighted. Clicking a hit
opens the built-in editor at that line and column; Enter searches again.
Match-case, whole-word and regex toggles sit at the end of the field, and
the tab focuses its field whenever it is brought forward.

Host::search_content is new on the Host trait, implemented once in
host::content_search (ignore walk + regex) and run by LocalHost directly
and by tty7-server over a new SearchContent control request. The walk
honours .gitignore with or without a repository, skips dot-entries, binary
files and files over 1 MB, and reports a capped search as truncated. The
request is gated on a new `content-search` hello feature, so a server that
predates it is never sent it; the panel says the server needs updating
instead of showing no results. Conformance cases cover local and the
stdio server alike.

* feat(panel): browse GitHub issues and pull requests in the right panel

The GitHub tab follows the focused pane's repository: its root is resolved
the way the Source Control tab does, its remotes are read through the Host
(the tree may be on another machine), and the github.com remote is bound,
upstream over origin in a fork, with a menu to pick another.

The list switches between issues and pull requests, open and closed, 50 rows
a page with Load more; rows carry a state glyph distinct by shape, labels
(click one to filter by it) and relative times. A row opens the detail in
place: title, state, author, labels, description and comments as Markdown,
and for a pull request its branches, size and changed files. A file opens in
the diff overlay through a new supplied-patch DiffSource, so GitHub's patch
renders exactly like a local one without a git probe.

Read-only, and sign-in reuses the GitHub CLI: GH_TOKEN, GITHUB_TOKEN, then
`gh auth token`, found on PATH or at the Homebrew locations a Finder launch
cannot see. Signed out, public repositories still work; 401, 403, 404 and
rate limits are told apart and explained. Requests go out from this machine
over the installer's ureq stack and proxy settings, on threads of their own,
cached per repository with background revalidation. Remote images in issue
text become links instead of loading, and non-web link targets are disarmed.

The Info tab gains a GitHub row that opens the branch on the remote it
tracks, or the repository for a branch never pushed.

* docs: list ShowRightPanelGitHub with the other panel actions

* feat(panel): one-line GitHub rows, a pill for the current tab

- GitHub list rows are one line: state glyph, #number, title. Labels and
  the age of the last update appear on hover, from state rather than a
  group_hover display switch, which gpui cannot paint.
- The current right panel tab sits on the sidebar's selected fill; ink
  alone could not tell five same-weight glyphs apart.
- The GitHub glyph is a 1.8px outline like the other tab icons, not the
  filled mark.
- The detail byline names both times (opened / updated) so it no longer
  reads as disagreeing with the list's update age.

* feat(github): show screenshots pasted into issues

Images GitHub hosts itself (github.com/user-attachments, a repo's
/assets, *.githubusercontent.com) now render in issue and PR text, each
in a paragraph of its own so the text view draws it at its size rather
than at line height. Images from any other host stay links, so opening
an issue still tells no third party that you read it.

gpui held a null HTTP client, so no remote image could load; the app now
installs the update check's reqwest client (same user agent and proxy)
at launch.

* fix(github): load private-repo screenshots, give inline code a neutral fill

- Pasted attachments (github.com/user-attachments/assets/<uuid>) want a
  browser session on a private repository, which an API token is not.
  The detail and comment requests now ask for the full media type, and
  each attachment is swapped for the signed private-user-images URL the
  rendered body_html carries for the same uuid.
- Inline code in rendered Markdown (the GitHub tab and the editor's
  preview) sits on a faint neutral fill instead of the theme accent,
  which is also the selection colour. Needs gpui-component 6af19d91 for
  TextViewStyle::inline_code_background.

* style(panel): tidy the GitHub and Search tabs' top rows

- GitHub drops its heading row on macOS. It existed only to hold the
  refresh tile, and no other tab has one; refresh now sits with the
  repository's other actions, in the repo row and a detail's header.
- Search's Aa / ab / .* toggles are muted while off instead of body ink.
- Search's idle note puts the folder on its own line, spelled ~/…, so
  the narrow column no longer breaks the path at a slash.

* feat(panel): order the right panel's tabs Info, Files, Search, Changes, GitHub

Info stays first as the default and the pane's overview; after it come
two pairs, the project's files (Files, Search) and its version control
from local to remote (Changes, GitHub), where Changes and GitHub were
split by the file tabs before. The palette, the Keybindings list and the
docs follow the same order.

* style(panel): drop the change count from the Changes tab

Beside one glyph of five, the number read as a badge on that tab alone,
and the Changes tab already leads with the same count under its own
heading. right_panel_tabs no longer needs the row's width, which it only
measured to decide whether the count fit.

* style(icons): fit the GitHub glyph to the other tab icons' size

The Lucide mark filled its whole 24px box, edge to edge, where tty7's
own icons keep about 3.5px clear, so at 15px it drew a size larger than
the four tabs beside it. Scale it to 0.9 about the centre, and raise the
stroke to 2.0 so it still renders at the others' 1.8.

* style(icons): a simpler GitHub glyph

Drop the Lucide mark's tail and redraw the head and legs on tty7's own
grid: the same ~15px live area and 1.8 stroke as the other tab icons, no
scale transform. The legs keep it reading as the Octocat; a head alone
read as any cat.

* test(github): find gh on PATH in the blank-variable token test

The test placed gh only at /opt/homebrew/bin/gh, which gh_candidates never
offers on Windows, so the Windows CI job panicked at unwrap. Put gh on a PATH
directory spelled with the platform's exe name instead.

* fix(github): close image and link bypasses in the issue Markdown sanitiser

Checked against markdown-rs (the parser TextView uses), several inputs got
past the line-based rewrite:

- is_github_hosted cut the host only at `/`, so
  `https://evil.io?.githubusercontent.com/x.png` (and `#`, `\`, `&#47;`)
  counted as GitHub-hosted and was fetched from evil.io. The host now ends
  at the first of `/?#\` and may hold only DNS characters.
- `<img src>` values were written into `![..](..)` unescaped, so a `)` in
  the value closed the image and opened a second one from any host. Written
  destinations are now percent-encoded.
- `<image>` (which the HTML parser reads as `<img>`) passed as an ordinary
  tag and loaded its src.
- A kept link target was copied without scanning; when the parser ended
  the link elsewhere (open title, unbalanced paren) a `![..](..)` inside it
  came alive. Markup characters in it are now encoded.
- `file&#58;///...` and similar character references passed is_safe_target
  and decoded to a `file:` link. References are decoded before judging.

The rewrite still cannot see every construct the way the parser does
(code spans inside tag attributes, fences the parser rejects, multi-line
link definitions), so the detail view now also checks the parsed tree: a
block containing a non-GitHub image, an unsafe link or definition, or raw
`<img>` is drawn as its plain source instead.

* fix(github): hide gh's console, bound Retry-After, and reject URL authorities with ?#\

- run gh through proc::output_within with hide_console, so a Windows GUI
  launch does not flash a console window and stdout is drained while gh runs.
- saturating_add a hostile Retry-After instead of overflowing i64.
- parse_github_url no longer accepts `https://evil.io#@github.com/o/r`.

* fix(search): no panic on an unbounded time budget, and read files through the size cap

ContentLimits arrive off the wire on a server; Instant + u64::MAX ms
panicked. A file that grew between the size check and the read was read
whole; it is now read through a take() at the cap.

* fix(panel): keep Load more on an empty filtered page, and drop another host's hits

- /issues pages filtered to one kind can come back empty while later pages
  hold matches; the GitHub list said "No issues" and hid Load more. It now
  reads on through up to five such pages and keeps Load more offered.
- While a new search runs, the previous hits stay on screen; if they came
  from another host, a click opened their path on the active host. They are
  now kept only when the host is the same.
2026-09-27 19:04:42 +08:00
l0ng-ai d6c223751d fix(i18n): proofread the Chinese UI copy (#980) (#981)
Fix half-width punctuation, unify terminology (passphrase, Finder,
server), quotes and dash styles, and rewrite the most literal
translations. Point every language and the CLI at Settings →
Integrations, the page's actual name, instead of Settings → Agents.
2026-09-27 18:32:56 +08:00
l0ng-ai ed939bbc26 feat(search): browse every agent's past sessions, locally and on remote workspaces (#977)
* feat(search): list more agents' past sessions, and fork, copy or hide one

The Sessions tab listed Claude Code and Codex only, and a row could only
be resumed.

- Past sessions of Gemini CLI, Qwen Code, Pi, Oh My Pi, Kimi Code,
  Copilot CLI, Droid, Qoder CLI and CodeBuddy are read from where each
  keeps them (honouring QWEN_HOME, COPILOT_HOME, KIMI_CODE_HOME, …), with
  the name the agent or user gave the session, else the first prompt.
  Context blocks agents prepend (<system-reminder> and kin) no longer
  hide a prompt.
- Cmd/Ctrl-E on a session row opens its actions: Resume, Fork Session
  (agents that can fork, with the configured launch flags), Copy Session
  ID, and Remove from List. Removing keeps the search open, drops the row
  at once and remembers it in `hidden_agent_sessions`; the agent's own
  history is not touched.

OpenCode and Cursor keep sessions in SQLite and are not read yet.

Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM

* feat(search): list remote workspaces' sessions, and OpenCode and Cursor

The Sessions tab only ever read this computer, and left out the two
agents that keep their history in SQLite.

- agent_history moves into tty7-core, and the scan goes through the
  Host: a local workspace reads this machine in-process, a remote one
  asks its server (new ControlRequest::AgentSessions; CONTROL_VERSION
  11 -> 12, so each remote host takes one Update Server). Resumed or
  forked sessions open on that machine, in the directory they ran in.
  The last answer is kept per host so the tab does not open empty.
- OpenCode: top-level, unarchived sessions from opencode*.db (or
  $OPENCODE_DB); a placeholder title gives way to the first prompt.
- Cursor CLI: chats under ~/.cursor/chats (or $CURSOR_CONFIG_DIR), named
  from meta.json or store.db. Cursor files a chat only under the md5 of
  its directory, so it is placed by matching open tabs' and other
  sessions' directories; chats nothing matches are left out, since they
  could not be resumed anywhere.
- SQLite is bundled (rusqlite), opened read-only, falling back to an
  immutable read when the writer's WAL cannot be shared.

Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM

* test(search): wait for the real scan before seeding sessions

The search's own scan runs on a real thread. On CI it landed after the
test seeded its rows and replaced them, so the edit gesture found no
row. The test now waits for the scan first. Assertion messages no
longer print session ids (CodeQL rust/cleartext-logging).

Claude-Session: https://claude.ai/code/session_01JRqYZ9E153WpSHGS2AW3BM

* fix(search): harden the past-session scan and note it in the changelog

- Honour CLAUDE_CONFIG_DIR for Claude Code's projects, as the hooks
  installer already does.
- Read a Codex rollout's head as bytes: the 2 MiB cap can split a
  multi-byte character, and read_line then dropped the whole session.
- Escape `%` and `#` (not only `?`) in the immutable SQLite URI fallback,
  so a database under such a directory still opens.
- Refuse a session id starting with `-`: ids now come from file and
  directory names on disk, and one would be read as a flag by the
  resume or fork command.
- Update the unreleased Sessions changelog entry for the new agents,
  remote workspaces, the Cmd-E actions and the v12 dialect bump.

* fix(search): spell the immutable SQLite fallback as file:///C:/ on Windows

SQLite reads file:C:/x as a relative path, so the fallback open (and its
test) failed on Windows. An empty authority and a leading slash name the
file on every platform.

* test(search): keep ? out of the fixture directory name on Windows

Windows file names cannot hold a '?', so the fixture's create_dir_all
failed there before the fallback was ever opened.
2026-09-27 18:18:05 +08:00
l0ng-ai 84935813d5 feat(terminal): the mouse wheel no longer zooms the font by default
mouse_zoom_modifier now defaults to none. The platform modifier is cmd on
macOS, held for so much else that the font jumped size mid-scroll (#668).
Picking a modifier in Settings brings the wheel zoom back; cmd+/cmd- are
unchanged.
2026-09-27 10:42:02 +08:00
l0ng-ai 572bfc014b feat(ui): v4 redesign, including a rebuilt settings window (#973)
* feat(ui): restyle the right panel after the v4 design

- Tab row: 12.5/16rem word tabs 22px in and 18px apart, the current one in
  body ink at medium weight; no hover pill, no underline bar, no hairline
  under the row.
- Info: Session, Processes and Ports are spaced 16px apart with no rules;
  28px medium muted headings, 28px Session rows on a 76px label floor with
  values in body ink, 26px process rows with a tree elbow for children, and
  an explicit empty line for Ports.
- Files: the search sits in a 28px filled well; tree rows are 26px with a
  disclosure chevron column, ignored entries dim their icon instead of
  going italic, and a folder's change dot is 5px.
- docs/design-system.md updated to match.

* feat(switcher): restyle the workspace switcher after the v4 design

- Card: 112px from the top, 12px corners, 48px search row with an esc
  keycap, 420px body split 340px / preview, 40px footer.
- Workspace rows are 52px: a 26px initial disc carrying the link state as
  a ringed dot (live green, faint when offline, amber while connecting,
  red on failure), a medium name with its stable number, a machine ·
  path · time line, and the tab count over the state word.
- Preview rows are 44px with the sidebar's 18px brand disc, an all-muted
  branch · diff line, a Current label and a 5px dot that blinks with the
  sidebar while an agent is working.
- Footer: ghost New workspace button and keycap hints for navigate, open
  and new window; the unused click-for-new-window string is dropped.

* feat(scm): restyle the Changes tab after the v4 design

- Pinned block keeps 8/10/14 rhythm; branch name medium, 26px sync tile.
- Commit message box rests at 56px with a 7px radius.
- Split commit control: inverted neutral fill when committable, faint
  fill otherwise; 6px radius and an inset 0.5px seam.
- Change groups sit 16px apart under 22px sentence-case medium headers;
  file names take width first and directories right-align, eliding
  from the start.
- History: 32px header, 26px rows inset with rounded hover, 1px lines
  and 7px beads (HEAD filled, others hollow), neutral inks on a
  single-lane page, age column always shown, faint HEAD pill.

* feat(ui): restyle the rail and palette after the v4 design

- Default Light/Dark take warm neutrals (#fcfcfb/#1c1c1e, #18181a/#ececed);
  Git added/modified seeds follow v4 green and amber.
- The left rail gets its own tinted fill again (Neutrals.rail, 3% toward
  the ink) with its own surface ladder; the right panel keeps the content
  fill. Captions and hairlines are floored on the rail too.
- Title bar is 48px; the bar over the terminal centres the active tab's
  title in caption ink when tabs live in the rail.
- Rail header: 26px new-tab and collapse tiles, then the workspace chip
  and search field (28px, 7px radius).
- Groups sit 16px apart under a 22px caption heading with
  'branch · +a −d' in tabular numerals.
- Rows are 30px (42px with a branch line), 16px avatars, medium weight
  when current, branch cut from the front, and a trailing 5px status dot
  (blinks while working, hollow while waiting, unread count as a pill).
- docs/design-system.md updated.

* docs(design-system): note the commit button's inverted neutral fill

* fix(panel): align the right panel's insets with the v4 design

- Rows pad 8px inside lists inset 12px, so text sits on a 20px column in
  every tab and hover fills start 12px in with a 6px radius. Headings,
  empty states and the Ports line move to the same column.
- Tab labels 18px apart; the panel row's chrome tiles are 26px, 4px
  apart, 12px from the edge. Default panel width 280.
- Info: label column floor keeps values at x=88; Ports add tile 22px.
- Changes: 8px top gap on macOS, pinned block on 14px edges with the
  branch at 22, 12px sync glyph, 8px group chevron, 10px status cell,
  1px between rows.
- History: compact gutter for single-lane pages, filtered rows on the
  text column, 10px row gap, 24px age floor, header on 20px insets,
  4/12 padding when expanded (heights re-counted in commits).
- Files: search well at 12px with an 11px glyph, 10px before the tree,
  16px indent step, 16px bottom padding.

* feat(diff): restyle the diff overlay and commit detail after the v4 design

Carry the v4 language into the diff overlay and the commit detail view:
0.5px hairlines at 8% ink, 26px row pills with a 6px radius, the rem type
ladder from right_panel.rs, neutral chips instead of accent washes, the
shared git_badge for status letters, and tabular figures on counts.
Layout, spacing, type and colour only; no behaviour or i18n changes.

* feat(ui): restyle the dialogs, notices and home page after the v4 design

- New ui::dialog module holds the shared modal chrome, taken from the
  workspace switcher: a 12px card, a 48px title row with an esc keycap,
  18px insets, a 40px hairline footer, 28px borderless field wells on the
  faint fill, 11.5px medium muted labels, and 18px keycaps.
- Buttons: the primary is the inverted neutral fill, the Commit button's
  paint, instead of the accent. Secondary buttons are transparent with the
  surface's hover rung. Override on a changed host key stays the one red
  button. A disabled button sinks to the faint fill and drops its click
  handler.
- SSH sheet: host and fingerprint lines sit in a mono detail well, and
  keyboard-interactive prompts become field labels. Banners match the
  sheet's width and card shape.
- Worktree prompt: moves to the same card, with the path preview hung off
  the Name field.
- Notice pill: severity moves from a tinted edge to a 6px leading dot.
- Home: shortcut rows are 28px with a hover fill and keycap chords, and the
  remote strip's action uses the secondary button.

* fix(panel): start Info and Changes flush under the tab row

Their first line is text centred in a 28px row, so the extra 8px step put
it visibly lower than the Files tab's search well. Only Files keeps it.

* fix(scm): put the commit detail on the right panel's 20px text column

* feat(palette): restyle the command palette after the v4 design

- Card: the switcher's 12px corner, 112px drop from the top (shorter
  windows still scale it up), 600px max width.
- Search row keeps the list's own field; an esc keycap sits in its
  trailing corner while the field is empty.
- Rows are 32px with an 8px corner, 8px list inset and 10px padding. The
  keyboard row takes the popover's neutral selected step and a medium
  title instead of the accent wash, via a palette row element in place
  of ListItem.
- Section headings: 28px, 11.5/16rem medium caption ink, on the rows'
  text column. Shortcuts are per-key 18px faint keycaps from ui::dialog.
- New 40px footer with the switcher's keycap hints (navigate, open).
- Empty state: headline in body ink, hint in caption ink.

* feat(ui): carry the v4 chrome into panes, the file viewer and SFTP

- theme: additive helpers for a device-pixel hairline, tabular figures
  and an inverted neutral button variant.
- Pane splits rest as a device-pixel hairline in the divider tone; hover
  and drag keep the accent at 1px like the other resize edges.
- File viewer header: medium file name, 5px unsaved dot, 26px/6px close
  tile with its glyph on the content inset, divider hairline under it.
  Status bar: divider hairline, caption size, tabular line/column.
- SFTP browser: file-tree rows (26px, 6px corner, 16px caption glyphs),
  breadcrumb and notes on the 20px text column, a borderless edit well,
  inverted OK button, and ink-on-track transfer progress.
- Forward rows line up with the process and port rows (text at 20px,
  6px corner); Add and Reconnect use the inverted neutral fill.

* docs(design-system): note the v4 palette, pane, viewer and SFTP chrome

* feat(settings): restyle the settings page after the v4 design

- Nav: the rail's tinted fill and surface ladder behind a divider hairline;
  a 28px filled search well; 28px rows in 7px pills, the current one on the
  selected rung at medium weight instead of the accent; match counts in
  muted ink; the modified-only filter toggles like a nav row.
- Pages: the title sits in the 48px title-bar band at 16/16rem; group
  headings are 11.5/16rem medium muted on a 28px line; sections are split
  by a 0.5px divider with 16px either side.
- Rows: labels in body ink at regular weight, descriptions at 12/16rem
  muted, 28px floor with 8px padding; a search hit wears the faint neutral
  fill rather than the accent tint.
- Controls: text fields and dropdowns are 28px filled pills with no
  outline; buttons, segmented tracks and steppers are 26px with a 6px
  radius on the same fill. The one primary action per view (save theme
  draft, connect, install update) is the inverted neutral fill of the
  commit button. Switches and sliders keep the accent.
- SSH: host list header with 26px tiles and a filled search, 22px group
  headings, 42px two-line host rows; the form's labels are a muted,
  right-aligned column level with 28px fields; disclosure headers use a
  chevron on a 28px band.
- Theme cards are filled and unoutlined, taking the selected rung while
  open; the theme panel keeps the content fill with a divider edge and its
  title in the title-bar band. Keycaps are filled with no outline and
  shortcut rows are divided by 0.5px hairlines.
- right_panel::SECTION_GAP is now shared; docs/design-system.md updated.

* feat(ui): spell tab titles out in full in the rail and title bar

The rail's rows and the centred title have room to spare, so they take
the whole label from a new full_tab_label rather than tab_label's
three-segment cut; only the width they have decides what gets elided.

* fix(settings): even out the page rhythm and line up the columns

- Nav header: drop the min_h(ROW_H)/min_h(0) pair on the heading, which
  measured ~46pt taller than it painted and opened a hole under the search.
- Page titles sit under the title-bar band, level with the nav heading,
  instead of jammed against the window's top edge.
- Headings get a 22pt group-header row and hug their rows; rules keep more
  air, so a heading reads as its rows' rather than floating between.
- SSH: the host list gives width before the nav, so the nav no longer
  narrows on that page; its header, search well and detail title run level
  with the nav's; the empty note starts on the host-title column.
- Window & Tabs no longer opens on a stray rule.
- Integrations: status leads the buttons on one line, in the meta ink.
- Terminal: the shell footnote stays close to its rows.

* fix(ui): stop eliding branches that fit, and seat the SCM branch on the text column

- elide_tail_clusters returned "…" plus the whole string when nothing
  needed cutting, so the rail's group header printed …feat/v4-redesign
  with room to spare. Return the text as-is when it fits.
- The group header only reserves the chevron's width when it draws one.
- The Changes tab's branch name no longer stacks a small button's padding
  on the row gap; it starts on the file names' column.

* fix(ui): keep a tab's name in place when an inline rename starts

gpui-component's Input keeps 12px of inner padding even with
appearance(false), so the name jumped sideways as the rail row, the
group header and the top-strip chip swapped their label for the field.

Claude-Session: https://claude.ai/code/session_01Q9vsQSxAZjkwT7nRAiFF1J

* revert(settings): restore the page rhythm from before 08497d57

The title in the title-bar band, full-row headings, SECTION_GAP rules and
the shell footnote's spacing read better than the tightened version. The
bug fixes from that commit stay: the nav gap under the search, the stray
rule on Window & Tabs, the SSH column alignment and nav width, and the
one-line Integrations rows.

Claude-Session: https://claude.ai/code/session_01Q9vsQSxAZjkwT7nRAiFF1J

* revert(settings): restore the pre-v4 settings layout, on the rail's fill

The v4 restyle (541a887a) and the follow-ups crowded the page. Bring
settings.rs back to main's layout and give its sidebar the main window's
tab-rail fill, so the two sidebars read as one surface.

Claude-Session: https://claude.ai/code/session_01Q9vsQSxAZjkwT7nRAiFF1J

* feat(settings): rebuild the settings window after the v4 design

Rewrites the settings page to the Settings design: a sidebar with search,
per-page modified counts and a "Modified only" switch; quiet grouped rows
with an inline Reset; and the design's own controls (switch, segmented,
stepper, slider, text field, dropdown and popover menus) in a new
`settings/kit.rs`.

- Appearance: Light / Dark / System cards and a theme menu per slot with a
  live preview, search, keyboard navigation and swatches. Font menus are
  searchable and draw each family in itself.
- Keyboard shortcuts: back link, search, "Restore N changed", Default/tmux.
  A recorded chord another action already has now asks Replace / Cancel
  instead of taking it over silently.
- SSH: one column of recent hosts, "Show all" by source, search; details and
  a six-field editor open in place. Auth, jump/proxy, forwarding and
  advanced sections are no longer shown; saved values are kept.
- Integrations: machine menu, agent search, install summary, agent icons,
  and a per-row menu (Reinstall, Reveal hook file, Uninstall).
- General gains startup and restore; updates and the server move to About.
- Search results group live rows by page; a Modified view lists changes.

The page code moves out of settings.rs into src/ui/settings/.

* fix(ui): lay truncating names out at their full width

Moves the gpui fork to 5d366e6, which stops a size measured under
truncation from answering the later whole-text measure. Before it, a
truncating name beside other content in a flex_1 column read as just its
ellipsis with the whole column free. Adds a switcher test that fails
without the fork change.

* fix(scm): seat the History chevron on the change groups' column

The History header now draws its chevron in the change groups' own box
and size, so its title starts where Staged Changes and Untracked do.
Folded, the header drops to 24px with even padding instead of the
expanded section's taller band.

* chore: ignore local design mockups and Impeccable state

* fix(macos): show enter and tab shortcuts correctly in menus

Moves the gpui fork to 5c390b9, which maps enter and tab to their native
key equivalents. A menu item bound to secondary-enter, like
ToggleFullscreen, read as ⌘E.
2026-09-27 09:48:25 +08:00