l0ng-ai ba5b29818d fix(control): stop a reply that cannot be encoded from reading as a hang
Six findings from review, all in the same seam — what happens when a
message cannot go on the wire, and who is allowed to conclude the link
is dead from that.

- `Sink`/`ControlClient::send` encode before writing, so 'this message
  cannot be serialized' and 'this link failed' are distinguishable. Only
  the second can have put bytes out, and only the second is grounds for
  marking the connection dead — the client used to go `Reconnecting`
  over an oversize `WriteFile` the server never saw.
- `Conn::finish` answers an unencodable reply with the error instead of
  dropping it. Dropping left the client waiting out the request's whole
  deadline for a reply that was never coming.
- `Search` drops the hits whose paths are not UTF-8 rather than letting
  one Latin-1 filename make the whole reply unencodable. `SearchHit` is
  the only `PathBuf` on this wire; serde refuses such a path outright.
- The control socket is bound under a tightened umask. `bind` creates
  the node at `0777 & ~umask` and the `chmod` was a window — under
  `umask 002` a group-connectable one, onto unauthenticated `ReadFile`.
- Binding no longer re-permissions a directory it did not create. With
  `$TTY7_CONTROL_SOCK` or the hashed fallback the parent can be `/tmp`,
  and 0700 there locks every other user out of it.
- A blob is filed under the `pending` lock, so a caller timing out in
  the gap cannot leave a whole file's contents in the side table for the
  life of the connection.
2026-07-28 21:41:42 +08:00
2026-07-28 14:52:21 +08:00

tty7

tty7

A terminal workbench: shells, sessions, SSH, coding agents.

Pure Rust · GPU rendering on Zed's gpui · VT core from Alacritty


CI Version License Discord

English · 简体中文

Why

  • Fast — ~2× the throughput of Alacritty, Ghostty, or Kitty (benchmarks)
  • Sessions persist — quit or reboot; your shells keep running, no tmux
  • Editor-grade input — completion, syntax highlighting, history search built in; zero config for zsh, bash, fish, PowerShell
  • Agent-aware — recognizes Claude Code & co. in a pane: status, notifications, session resume

Install

Native builds for each platform on Releases:

macOS …-macos-arm64.dmg · …-x86_64.dmg drag into Applications
Windows …-setup.exe · portable ….zip
Linux …-x86_64.AppImage chmod +x and run — x11/wayland libs bundled

What's inside

Input ghost suggestions from history · explained tab completion · syntax highlighting · multi-line editing · click places the caret · ⌃ R fuzzy history
Window tabs & splits · ⌘ P palette · ⌘ F scrollback search · nine themes · IME
Coding agents per-pane agent detection (~17 CLIs): status dot, notifications, branch + diff, resume after reboot, tray icon that signals "needs your input"
SSH native russh stack: profiles with keychain secrets, SFTP panel, port forwarding, jump hosts

Details for every row: docs/features.md. Keybindings: ⌘ , opens Settings — browse and remap everything, tmux preset included (full list).

Benchmarks

Same machine, same day, same 155×40 grid — Apple M1 Pro, macOS 26.3.1, five-run averages (2026-07-04):

tty7 Alacritty Ghostty Kitty
Plaintext IO — 11 MB cat (lower = better) 95 ms 239 ms 179 ms 185 ms
DOOM-fire frame rate (higher = better) 888 fps 485 fps 552 fps 617 fps
Cold-launch memory 116 MB¹ 105 MB 128 MB 130 MB

¹ GUI 105 MB + the persistent daemon 11 MB.

Methodology and one-command reproduction: scripts/bench/.


S
Description
A terminal workbench in pure Rust: shells, persistent sessions, SSH, coding agents. GPU-rendered on Zed's gpui, VT core from Alacritty.
Readme Apache-2.0
34 MiB
Languages
Rust 99.1%
Shell 0.5%
PowerShell 0.2%
Inno Setup 0.1%