Skip to content

Fix Korean 2-Set terminal arrows - #4095

Merged
austinywang merged 11 commits into
mainfrom
issue-4093-korean-2set-arrow-keys
May 13, 2026
Merged

austinywang merged 11 commits into
mainfrom
issue-4093-korean-2set-arrow-keys

Conversation

@austinywang

@austinywang austinywang commented May 13, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • add a Korean 2-Set post-composition marked-selection regression for Left/Right arrows
  • pass the physical key and input source into the IME suppression decision
  • let plain Korean 2-Set Left/Right arrows reach Ghostty while preserving suppression for IME-owned marked-text changes
  • route Korean marked-selection arrow key equivalents into the terminal keyDown path so AppKit window handling cannot swallow them first

Fixes #4093

Verification

  • Reproduced locally in cmux NIGHTLY 0.64.4-nightly.2579225123401 with macOS input source com.apple.inputmethod.Korean.2SetKorean: after typing Korean text, Left/Right did not move the terminal cursor.
  • Added regression test: CJKIMEMarkedSelectionTests.testKeyDownForKoreanPostCompositionHorizontalArrowsForwardsToTerminal.
  • Did not run local tests per repository policy; CI is the test runner.
  • Ran git diff --check.
  • Built and launched tagged dev app with CMUX_SKIP_ZIG_BUILD=1 ./scripts/reload.sh --tag issue-4093-korean-2set-arrow-keys --launch.
  • Manual dogfood in tagged dev app with Korean 2-Set selected: physical 2-set input stayed Korean, Left moved the insertion point before the final character, and Right moved it back after the final character.

Build

App path:
/Users/austinwang/Library/Developer/Xcode/DerivedData/cmux-issue-4093-korean-2set-arrow-keys/Build/Products/Debug/cmux DEV issue-4093-korean-2set-arrow-keys.app

Notes

  • Cloud Mac video artifact was not captured because the debugging flow was redirected to local cmux NIGHTLY repro and tagged dev-app verification before the fix.
  • The working tree had a pre-existing dirty ghostty submodule (aef980e27..fe972c095) before this change; it was not staged or committed.

Note

Medium Risk
Modifies macOS IME key routing and marked-text suppression logic, which can subtly affect keyboard shortcuts and text input behavior across input methods. Adds input-source–specific branching and new preedit buffering paths, increasing the chance of regressions in edge-case key handling.

Overview
Fixes a regression where Korean 2-Set post-composition Left/Right arrows were being swallowed by AppKit by ensuring they flow through the terminal keyDown path and are explicitly allowed to forward even when the IME updates marked-selection.

Makes IME suppression decisions event + input-source aware (passing NSEvent and keyboard source ID), adds allow-list logic for Korean 2-Set arrow forwarding, and keeps IME-owned composition command keys from also moving the terminal cursor. Additionally buffers Zhuyin/Bopomofo component insertText updates as editable preedit (instead of committing to the terminal) and expands CJKIMEMarkedSelectionTests to cover the new Korean/Zhuyin behaviors.

Reviewed by Cursor Bugbot for commit 50b0c0e. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Fixes a regression where Left/Right arrows didn’t move the cursor after Korean 2‑Set input and restores correct Zhuyin (Bopomofo) IME routing. During composition, non‑Cmd key equivalents bypass the window so keyDown handles IME input; idle Zhuyin navigation keys reach the terminal; and Zhuyin preedit is buffered until commit (Fixes #4093).

  • Bug Fixes
    • Korean 2‑Set: forward only plain Left/Right after post‑composition selection changes; don’t reroute their key equivalents; clear stale key‑up suppression when forwarding.
    • Composition routing: while marked text is visible, do not handle non‑Cmd key equivalents at the window; keep IME composition commands (arrows, paging, space, return, tab, delete, home/end, escape) inside text input for IME sources; when no marked text, do not suppress Zhuyin Down/PageUp/PageDown/Space so they reach the terminal.
    • Zhuyin preedit: buffer raw Bopomofo components and tone marks as marked text and commit only the chosen candidate; refined replacement/selection handling and input‑source/event‑aware suppression.
    • Added tests for Korean arrow forwarding, idle Zhuyin navigation pass‑through, Zhuyin command routing with and without marked text, and Zhuyin preedit buffering/commit.

Written for commit 50b0c0e. Summary will update on new commits.

Summary by CodeRabbit

  • Bug Fixes

    • Prevent non-Command keys from being claimed during active IME composition and fix stale key-up handling.
  • New Features

    • Input-source–aware IME gating with special handling for Korean 2-Set arrow navigation.
    • Zhuyin (Bopomofo) preedit buffering and improved insertion/replacement behavior for composed text.
  • Tests

    • Expanded CJK IME tests covering Korean arrow forwarding, Zhuyin buffering, and post-composition behaviors.

Review Change Stack

@vercel

vercel Bot commented May 13, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Ready Ready Preview, Comment May 13, 2026 1:09pm
cmux-staging Building Building Preview, Comment May 13, 2026 1:09pm

@coderabbitai

coderabbitai Bot commented May 13, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

Makes IME suppression event- and input-source-aware, adds Korean “2Set” arrow detection and routing, captures keyboard layout in keyDown, alters AppDelegate key-equivalent handling for IME composition, and extends CJK IME tests.

Changes

Korean 2-Set IME arrow key routing

Layer / File(s) Summary
IME suppression logic and Korean/Bopomofo helpers
Sources/GhosttyNSView+IMEComposition.swift
shouldSuppressGhosttyKeyForwardingAfterIMEHandling now accepts event and inputSourceId; adds Korean “2Set” input-source allow-list, input-source predicates, modifier/key allow-lists, arrow/keyCode recognition, Bopomofo scalar validation, and updates DEBUG test helper signature.
keyDown integration and keyboard ID capture
Sources/GhosttyTerminalView.swift
keyDown captures KeyboardLayout.id before interpretation, passes inputSourceId into suppression checks, records imeConsumedKeyUps on suppression and clears stale entries on forwarding, and adds Bopomofo preedit buffering helpers used by insertText(_:replacementRange:).
AppDelegate window-level behavior
Sources/AppDelegate.swift
Swizzled NSWindow.cmux_performKeyEquivalent(with:) early branch now returns false for Ghostty first responder with marked text and non-Command events instead of delegating through.
CJK IME marked-selection tests
cmuxTests/CJKIMEMarkedSelectionTests.swift
Adds Carbon.HIToolbox import, KoreanArrowProbe, and tests validating Korean arrow forwarding, Zhuyin/Bopomofo buffering and suppression, and commit behavior.

Sequence Diagram

sequenceDiagram
  participant User
  participant Window as AppDelegate.cmux_performKeyEquivalent
  participant View as GhosttyNSView.keyDown
  participant Supp as GhosttyNSView.shouldSuppressGhosttyKeyForwardingAfterIMEHandling
  participant Terminal as Ghostty terminal
  User->>Window: press arrow/key
  Window->>View: window-level check (marked text, modifiers)
  alt window-level return false
    Window-->>User: return false (block performKeyEquivalent)
  else
    Window->>View: forward to keyDown
  end
  View->>View: capture KeyboardLayout.id (keyboardIdBefore)
  View->>View: interpretKeyEvents / handleTextInputKeyEvent
  View->>Supp: call(before, after, accumulatedText, event, inputSourceId)
  alt suppression true
    Supp-->>View: return true (suppress)
    View->>View: record imeConsumedKeyUps and return
  else
    Supp-->>View: return false (allow)
    View->>View: clear stale imeConsumedKeyUps
    View->>Terminal: forward key to terminal
  end
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related issues

Possibly related PRs

"🐰 I hopped through IME fields so wide,
arrows find the terminal, nowhere to hide,
source and event I sniff with care,
preedit stitched and commits laid bare,
keys and caret now dance side by side."

🚥 Pre-merge checks | ✅ 14 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 10.71% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (14 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately summarizes the main fix: enabling Korean 2-Set terminal arrow keys to work correctly after IME composition. It is specific and directly related to the core issue being resolved.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed No Swift 6 actor isolation violations. Changes are isolated to UI/MainActor methods. No problematic value models, service protocols, shared mutable Sendable types, or cross-isolation access.
Cmux Swift Blocking Runtime ✅ Passed No blocking/timing synchronization primitives introduced in IME fix. Changes use decision logic, state tracking, and helper methods only.
Cmux No Hacky Sleeps ✅ Passed Check inapplicable. Rule excludes Swift code and applies to TypeScript/JavaScript/shell/build scripts only. PR contains only Swift and test infrastructure changes.
Cmux Swift Concurrency ✅ Passed No legacy async patterns introduced. Changes add synchronous IME helper methods with no new DispatchQueue, Combine, completion-handlers, or fire-and-forget Tasks.
Cmux Swift @Concurrent ✅ Passed All changes are synchronous pure helpers for IME composition logic. No async functions, invalid @concurrent, or heavy operations violate the rules.
Cmux Swift File And Package Boundaries ✅ Passed Repository initialization with 1,742 new files. Check allows repo initializations. GhosttyNSView+IMEComposition.swift under 400 lines with focused IME responsibility (AppKit glue).
Cmux Swift Logging ✅ Passed No logging violations found in production Swift code changes. IME files contain no print/NSLog. Test and CLI output are allowed per rules.
Cmux Swiftui State Layout ✅ Passed No new SwiftUI state introduced. Changes are AppKit IME key handling. No @Published/@observable added. Pre-existing state only touched incidentally per allowed exceptions.
Cmux Architecture Rethink ✅ Passed Adds pure functional IME suppression logic without timing delays, mutable state, or lifecycle splits. Clear ownership and single source of truth for decisions. No architectural violations.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PR modifies IME key handling logic only. No user-visible NSWindow or NSPanel creation or changes. Test-only window fixture is allowed per review rules.
Description check ✅ Passed The PR description is comprehensive and addresses all required template sections with substantive content.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch issue-4093-korean-2set-arrow-keys

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@greptile-apps

greptile-apps Bot commented May 13, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

Fixes a regression where Korean 2-Set Left/Right arrows were swallowed after Hangul composition, and improves Zhuyin (Bopomofo) preedit buffering so raw phonetic components are held in marked-text until a candidate is committed.

  • AppDelegate: performKeyEquivalent now returns false (instead of recursing into cmux_performKeyEquivalent) for non-Command keys during IME composition, letting AppKit dispatch naturally through keyDown.
  • IME suppression logic: shouldSuppressGhosttyKeyForwardingAfterIMEHandling gains event and inputSourceId parameters; Korean 2-Set plain Left/Right are allow-listed to forward to the terminal even when the marked-text selection changes; a new shouldKeepIMECompositionCommandInsideTextInput guard suppresses navigation keys that belong to IME candidate menus (e.g., Zhuyin Down/Space).
  • Bopomofo preedit buffering: insertText now intercepts Bopomofo-scalar strings during key accumulation and routes them into insertBopomofoPreeditText, keeping them as editable preedit until the IME commits a chosen character; a imeConsumedKeyUps.remove call clears stale key-up suppression when a key is forwarded.

Confidence Score: 5/5

Safe to merge. The IME key-routing changes are localized to the Korean 2-Set and Zhuyin paths, existing suppression logic for all other input sources is preserved, and new regression tests cover the core scenarios.

The Korean 2-Set forwarding allow-list is a narrow, well-guarded change: only plain Left/Right on exactly com.apple.inputmethod.Korean.2SetKorean bypass suppression. The Bopomofo preedit buffering is similarly constrained to Bopomofo-range Unicode scalars. The AppDelegate change (returning false instead of recursing into cmux_performKeyEquivalent) cleanly removes an unnecessary detour. The new imeConsumedKeyUps.remove correctly cleans stale suppression on forwarded keys. No existing suppression paths are widened beyond their intended scope.

No files require special attention. The most complex logic lives in GhosttyNSView+IMEComposition.swift and is directly exercised by the new test suite.

Important Files Changed

Filename Overview
Sources/GhosttyNSView+IMEComposition.swift New IME suppression helpers: Korean 2-Set allow-list, Bopomofo source detection, and shouldKeepIMECompositionCommandInsideTextInput. Logic is correct; isInputMethodSource and isBopomofoInputSource correctly use en_US_POSIX locale with .caseInsensitive for ASCII bundle IDs.
Sources/GhosttyTerminalView.swift Adds Bopomofo preedit buffering in insertText, insertBopomofoPreeditText, and effectiveBopomofoPreeditReplacementRange; changes keyboardIdBefore to always capture (not just when no marked text); adds imeConsumedKeyUps.remove on forwarded keys. All logic correct; insertionLocation uses NSString.length safely since all Bopomofo/modifier-letter scalars are BMP.
Sources/AppDelegate.swift Single-line change: returns false instead of cmux_performKeyEquivalent(with:) during IME composition for non-Command keys, letting AppKit dispatch through keyDown rather than re-entering key-equivalent machinery. Intent and effect are correct.
cmuxTests/CJKIMEMarkedSelectionTests.swift New test cases cover Korean 2-Set Left/Right forwarding, idle Zhuyin key pass-through, Zhuyin Down suppression during composition, Bopomofo component buffering, mid-preedit insertion, and committed-candidate accumulator flow. Coverage is well-targeted to the changed paths.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[NSWindow.performKeyEquivalent] -->|hasMarkedText AND no Command| B[return false → AppKit dispatches via keyDown]
    A -->|no marked text OR has Command| C[normal key equivalent routing]
    B --> D[GhosttyNSView.keyDown]
    D --> E[capture keyboardIdBefore]
    E --> F[interpretKeyEvents]
    F -->|Bopomofo scalar + keyTextAccumulator active| G[insertBopomofoPreeditText: buffer in preedit]
    F -->|other text| H[insertText → unmarkText + accumulate]
    F --> I[shouldSuppressGhosttyKeyForwardingAfterIMEHandling]
    I -->|accumulated text present| J[return false — don't suppress]
    I -->|no marked text before or after| J
    I -->|marked text changed| K[return true — suppress]
    I -->|selection changed: Korean 2-Set Left/Right plain| J
    I -->|selection changed: other| K
    I -->|no change + inputmethod source + IME nav key| K
    I -->|no change + Korean 2-Set Left/Right plain| J
    I -->|no change + other| J
    J --> L[imeConsumedKeyUps.remove keyCode]
    L --> M[forward key event to Ghostty terminal]
    K --> N[imeConsumedKeyUps.insert keyCode: return early]
Loading

Reviews (6): Last reviewed commit: "Address IME suppression review feedback" | Re-trigger Greptile

Comment thread Sources/GhosttyNSView+IMEComposition.swift
Comment thread Sources/GhosttyNSView+IMEComposition.swift
Comment thread cmuxTests/CJKIMEMarkedSelectionTests.swift
coderabbitai[bot]
coderabbitai Bot previously requested changes May 13, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@cmuxTests/CJKIMEMarkedSelectionTests.swift`:
- Around line 218-298: The test currently calls surfaceView.keyDown(with:)
directly which bypasses AppKit's performKeyEquivalent/window/AppDelegate
routing; change the test to dispatch the generated NSEvent through the normal
AppKit event path (e.g. call window.sendEvent(event) or
NSApplication.shared.sendEvent(event)) after setting
window.makeFirstResponder(surfaceView) so performKeyEquivalent and the
window/AppDelegate reroute are exercised; keep the cjkIMEInterpretKeyEventsHook,
GhosttyNSView.debugGhosttySurfaceKeyEventObserver and the keyEvent(...) helper,
but replace the surfaceView.keyDown(with: event) call with sending the event via
window.sendEvent(event) (or NSApp.sendEvent) so the KoreanArrowProbe cases go
through performKeyEquivalent.

In `@Sources/GhosttyNSView`+IMEComposition.swift:
- Around line 119-122: The current isInputMethodSource(_:) uses
localizedCaseInsensitiveContains("inputmethod") which permissively matches any
bundle id containing that substring; to make it stricter, update
isInputMethodSource(_ inputSourceId: String?) to check for the dot-anchored
token (e.g., use a case-insensitive contains(".inputmethod.") or a
regex/hasSuffix/contains pattern that matches ".inputmethod."), so it only
returns true for standard Apple-style IM bundle IDs; keep the nil guard and
behavior otherwise the same.

In `@Sources/GhosttyTerminalView.swift`:
- Around line 13284-13293: In insertBopomofoPreeditText, compute the caret
offset using the original NSRange UTF-16 coordinates before mutating markedText:
after confirming replacementRange.location != NSNotFound and that
Range(replacementRange, in: markedText.string) exists, derive the new caret
location as replacementRange.location + chars.count (or compute distance from
start using the old range.lowerBound) first, then assign markedText =
NSMutableAttributedString(string: next) and finally call markedSelectedRange =
normalizedMarkedSelectionRange(NSRange(location: location, length: 0),
markedLength: markedText.length); this avoids using an index from the old string
against the new string and prevents the trap/crash.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: acd45826-e52a-44b5-9a82-4a7b8e879cae

📥 Commits

Reviewing files that changed from the base of the PR and between f206799 and 9795cb4.

📒 Files selected for processing (4)
  • Sources/AppDelegate.swift
  • Sources/GhosttyNSView+IMEComposition.swift
  • Sources/GhosttyTerminalView.swift
  • cmuxTests/CJKIMEMarkedSelectionTests.swift

Comment thread Sources/GhosttyNSView+IMEComposition.swift
Comment thread Sources/GhosttyTerminalView.swift
Comment thread Sources/GhosttyNSView+IMEComposition.swift
Comment thread Sources/GhosttyNSView+IMEComposition.swift
coderabbitai[bot]
coderabbitai Bot previously requested changes May 13, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@cmuxTests/CJKIMEMarkedSelectionTests.swift`:
- Around line 218-299: The test currently only asserts that arrow key events are
forwarded to Ghostty but doesn't verify the IME-updated marked selection; after
each window.sendEvent(event) in
testKeyDownForKoreanPostCompositionHorizontalArrowsForwardsToTerminal (inside
the probes loop within withExtendedLifetime) add an assertion that
surfaceView.selectedRange() (or equivalent accessor) equals probe.selectionAfter
so the test validates both the IME selection update and the forwarding behavior
handled by cjkIMEInterpretKeyEventsHook.

In `@Sources/GhosttyNSView`+IMEComposition.swift:
- Around line 5-7: The korean2SetInputSourceIDs Set currently only contains
"com.apple.inputmethod.Korean.2SetKorean" which is too narrow; update the Set
(korean2SetInputSourceIDs) to either include other Apple Korean input-source IDs
known to use the same IME flow (e.g., 3SetKorean, 390Sebeolsik,
GongjinCheongRomaja, HNCRomaja) or, if you intend to scope only to 2-Set for
now, add a concise comment next to private static let korean2SetInputSourceIDs
documenting that other Korean layouts are intentionally deferred and add a
TODO/issue reference for a follow-up to cover the family; ensure the symbol name
korean2SetInputSourceIDs is updated accordingly if you broaden semantics (e.g.,
rename to koreanInputSourceIDs) to reflect the wider coverage.

In `@Sources/GhosttyTerminalView.swift`:
- Around line 13227-13230: The buffered Bopomofo preedit path ignores NSNotFound
semantics and always appends instead of inserting at the current marked
insertion point; update the logic in insertText(_:replacementRange:) /
insertBopomofoPreeditText(chars, replacementRange:) so that when
replacementRange == NSNotFound and a marked range exists you use
markedSelectedRange as the actual replacement/insertion range (convert
markedSelectedRange to an NSRange as needed), otherwise preserve
replacementRange; ensure the code performs a replace-in-range operation rather
than appending to the end so in-place edits within keyTextAccumulator behave
correctly (refer to keyTextAccumulator, shouldBufferBopomofoInsertedPreedit(_:),
insertBopomofoPreeditText(_:replacementRange:), insertText(_:replacementRange:),
markedSelectedRange, and NSNotFound).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: a45bad3a-f9de-4da6-84d2-dd166e45d9eb

📥 Commits

Reviewing files that changed from the base of the PR and between 9795cb4 and 2090f4d.

📒 Files selected for processing (3)
  • Sources/GhosttyNSView+IMEComposition.swift
  • Sources/GhosttyTerminalView.swift
  • cmuxTests/CJKIMEMarkedSelectionTests.swift

Comment thread cmuxTests/CJKIMEMarkedSelectionTests.swift
Comment thread Sources/GhosttyNSView+IMEComposition.swift
Comment thread Sources/GhosttyTerminalView.swift
Comment thread Sources/GhosttyNSView+IMEComposition.swift Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 81a237a. Configure here.

Comment thread Sources/GhosttyTerminalView.swift Outdated
@austinywang

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 13, 2026

Copy link
Copy Markdown
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@austinywang

Copy link
Copy Markdown
Contributor Author

@coderabbitai resume

@austinywang
austinywang dismissed coderabbitai[bot]’s stale review May 13, 2026 12:47

Stale CodeRabbit review: all inline threads from this review are resolved and superseded by later commits/checks.

@austinywang
austinywang dismissed coderabbitai[bot]’s stale review May 13, 2026 12:47

Stale CodeRabbit review: all inline threads from this review are resolved and superseded by later commits/checks.

coderabbitai[bot]
coderabbitai Bot previously requested changes May 13, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
cmuxTests/CJKIMEMarkedSelectionTests.swift (2)

19-19: 🧹 Nitpick | 🔵 Trivial | ⚡ Quick win

Remove the empty deinit.

Per repo convention, deinit {} should only be included when there is a specific lifecycle reason (e.g., releasing resources, removing observers). This test class has no teardown logic. Based on learnings, the empty deinit should be removed unless it serves a purpose.

♻️ Proposed fix
-    deinit {}
-
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@cmuxTests/CJKIMEMarkedSelectionTests.swift` at line 19, Remove the empty
deinitializer from the CJKIMEMarkedSelectionTests class: delete the `deinit {}`
declaration (no other changes required) so the class follows repo convention of
only defining deinit when it performs teardown work like removing observers or
releasing resources.

1-474: 🧹 Nitpick | 🔵 Trivial | 💤 Low value

File length approaching the coherence threshold.

This test file is 474 lines, which is acceptable given its clear single responsibility (CJK IME marked-selection testing). However, it's approaching the 800-line threshold for coherent files. Future additions may warrant splitting into separate test files (e.g., Korean-specific and Zhuyin-specific test classes).

As per coding guidelines, "A new production Swift file must not exceed 400 lines without a clear single responsibility, or 800 lines even when the responsibility is mostly coherent."

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@cmuxTests/CJKIMEMarkedSelectionTests.swift` around lines 1 - 474, The file
CJKIMEMarkedSelectionTests.swift is nearing the 800-line guideline threshold;
split it into smaller, focused test files to keep each file under the policy
limits: extract Korean-specific tests (e.g.,
testKeyDownForKoreanPostCompositionHorizontalArrowsForwardsToTerminal and
KoreanArrowProbe) into a new CJKIMEKoreanTests.swift and Zhuyin-specific tests
(e.g., testSuppressesTerminalForwardingWhenZhuyinStartsMarkedText,
testBuffersZhuyinComponentInsertTextAsPreedit, etc.) into
CJKIMEZhuyinTests.swift, relocate shared helpers and types
(makeHostedTerminalWindow, keyEvent(_:keyCode:windowNumber:),
HostedTerminalWindow, and any debug setup/teardown logic) into a common test
helper file or base test class (e.g., GhosttyTestHelpers or CJKIMETestBase) that
both new test files import, and ensure each new file keeps its
`@MainActor/XCTestCase` annotations and restores any debug overrides in defer
blocks as in the original tests.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@Sources/GhosttyTerminalView.swift`:
- Around line 7755-7760: The call to
shouldSuppressGhosttyKeyForwardingAfterIMEHandling is passing translationEvent
(which has Ghostty-modified modifiers) but the suppression predicate needs the
raw physical AppKit key event; replace the translationEvent argument with the
original/unmodified physical NSEvent (the raw AppKit event variable used earlier
in this scope) so shouldSuppressGhosttyKeyForwardingAfterIMEHandling(before:
markedStateBefore, after: (markedText.string, markedSelectedRange),
accumulatedText: accumulatedText, event: <physical NSEvent>, inputSourceId:
keyboardIdBefore) receives the unmodified event for correct IME suppression
decisions.

---

Outside diff comments:
In `@cmuxTests/CJKIMEMarkedSelectionTests.swift`:
- Line 19: Remove the empty deinitializer from the CJKIMEMarkedSelectionTests
class: delete the `deinit {}` declaration (no other changes required) so the
class follows repo convention of only defining deinit when it performs teardown
work like removing observers or releasing resources.
- Around line 1-474: The file CJKIMEMarkedSelectionTests.swift is nearing the
800-line guideline threshold; split it into smaller, focused test files to keep
each file under the policy limits: extract Korean-specific tests (e.g.,
testKeyDownForKoreanPostCompositionHorizontalArrowsForwardsToTerminal and
KoreanArrowProbe) into a new CJKIMEKoreanTests.swift and Zhuyin-specific tests
(e.g., testSuppressesTerminalForwardingWhenZhuyinStartsMarkedText,
testBuffersZhuyinComponentInsertTextAsPreedit, etc.) into
CJKIMEZhuyinTests.swift, relocate shared helpers and types
(makeHostedTerminalWindow, keyEvent(_:keyCode:windowNumber:),
HostedTerminalWindow, and any debug setup/teardown logic) into a common test
helper file or base test class (e.g., GhosttyTestHelpers or CJKIMETestBase) that
both new test files import, and ensure each new file keeps its
`@MainActor/XCTestCase` annotations and restores any debug overrides in defer
blocks as in the original tests.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 14f0e44b-e84b-429a-a143-ba000a548ecb

📥 Commits

Reviewing files that changed from the base of the PR and between f2a1955 and afbfbe0.

📒 Files selected for processing (4)
  • Sources/AppDelegate.swift
  • Sources/GhosttyNSView+IMEComposition.swift
  • Sources/GhosttyTerminalView.swift
  • cmuxTests/CJKIMEMarkedSelectionTests.swift

Comment thread Sources/GhosttyTerminalView.swift
@coderabbitai

coderabbitai Bot commented May 13, 2026

Copy link
Copy Markdown
✅ Actions performed

Reviews resumed.

@austinywang
austinywang dismissed coderabbitai[bot]’s stale review May 13, 2026 13:10

Stale CodeRabbit review: all inline threads from this review are resolved and superseded by later CodeRabbit approval on the current head commit.

@austinywang
austinywang merged commit cbdddb9 into main May 13, 2026
36 of 37 checks passed
lawrencecchen added a commit that referenced this pull request May 14, 2026
* feat: improve markdown viewer

* fix: address markdown review feedback

* fix: clean up markdown review issues

* fix: address markdown review feedback

* fix: address latest markdown review

* Fix #3807: bring notification CLI to panel parity (#3811)

* Prove notification CLI parity is missing

Add behavior-level coverage for the missing notification socket and CLI actions before implementing them. The tests drive V2 notification action methods, CLI subcommands, extended list fields, and the UI open-notification flow so CI can show the pre-fix gap.

Constraint: Regression tests must be committed before the implementation for issue #3807

Constraint: Local Swift tests are not run in this repo; verification is through CI

Confidence: high

Scope-risk: narrow

Tested: git diff --check

Not-tested: Swift/XCUITest execution; intentionally deferred to CI

* Make notification actions scriptable from the CLI

The notifications panel already owned the behavior for dismissing, marking read, opening, and jumping to unread rows. This wires the socket and CLI to those existing store/AppDelegate paths, extends list output with panel metadata, and documents the new command surface without introducing a second notification action model.

Constraint: Existing Notifications page behavior must remain the source of truth

Constraint: Direct xcodebuild and local Swift/XCUITest runs are forbidden in this workspace

Rejected: Duplicate CLI-side focus or read-state logic | would diverge from AppDelegate.openNotification and TerminalNotificationStore semantics

Confidence: medium

Scope-risk: moderate

Tested: git diff --check

Tested: jq empty Resources/Localizable.xcstrings

Tested: python3 -m json.tool Resources/Localizable.xcstrings

Not-tested: Swift unit/UI execution; deferred to CI per repo policy

* Make notification CI compile under strict concurrency

The notification parity implementation introduced a shared formatter on a main-actor type and a test helper that crossed actor boundaries through escaping closures. This keeps the socket behavior unchanged while making date formatting local to the main-actor call path and keeping the XCTest socket request helper from capturing actor-isolated state in the background request closure.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace

Rejected: Run xcodebuild locally to confirm | user explicitly warned direct xcodebuild can deadlock the machine

Confidence: medium

Scope-risk: narrow

Tested: git diff --check

Tested: jq empty Resources/Localizable.xcstrings

Not-tested: Swift compilation and XCTest execution; deferred to CI

* Make notification parity actions atomic and exact

Review feedback exposed two behavior risks in the notification parity path: bulk dismissal was implemented as client-side list-and-loop work, and jump-to-unread could report one unread notification while opening a later valid one. The server now owns already-read dismissal as a single V2 action, the jump helper returns the notification it actually opened, and event/list parsing details match those server semantics.

Constraint: Notification action logic must reuse the existing store and AppDelegate paths

Rejected: Split TerminalController into new controllers in this PR | broad refactor is unrelated to issue #3807 and would obscure the parity fix

Confidence: medium

Scope-risk: moderate

Tested: git diff --check

Tested: jq empty Resources/Localizable.xcstrings

Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace instructions

* Expose app test symbols to CLI notification coverage

The integration regression exercises real app-backed notification state through the CLI harness, so the test target must import the built app module the same way the socket action tests do.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace
Rejected: Verify with xcodebuild locally | user explicitly forbids direct xcodebuild
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI

* Make notification list and dismiss payloads stable

Review caught two small contract hazards in the new notification RPC surface: the dismiss result used mixed JSON types, and a pipe in the appended tab title could shift the legacy list parser. The server now reports dismissals as counts consistently and escapes only the new trailing list field, with the CLI decoding it after structural parsing.

Constraint: The V1 list response remains pipe-delimited for backward compatibility, so only newly appended trailing fields can be encoded without changing old parser behavior
Rejected: Replace list_notifications with JSON-only output | existing V1 parsers depend on the line format
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace policy

* Return async notification socket responses from tests

CircleCI caught a compile-only issue in the async V2 test helper: the continuation result was awaited but not returned from the method that promises a response dictionary. Returning the continuation value restores the helper contract without changing the exercised socket behavior.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace
Rejected: Verify with local xcodebuild | user explicitly forbids direct xcodebuild
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI

* Avoid blocking notification CLI integration sockets

The integration regression has to create AppKit-backed notification state on the main actor, but running the CLI subprocess synchronously there can block the socket handler's main-actor store mutations. The test now awaits subprocess work on a background queue and verifies read state through the same CLI list path.

Constraint: Socket notification handlers intentionally hop to the main actor for store and AppDelegate work
Rejected: Run the CLI synchronously from the main actor | it can deadlock the in-process socket server during tests
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace policy

* Harden notification CLI response contracts

The notification parity path now distinguishes new list-notification trailer fields from old pipe-heavy bodies, rejects surface-only mark-read selectors, and returns post-open read state by marking through the shared store path after a successful focus action.

Constraint: list_notifications remains a legacy pipe-delimited protocol, so the new trailer needs its own discriminator while older body parsing keeps joining payload[6...]
Rejected: Add a third list_notifications sentinel field | the issue asked for exactly the two appended fields
Rejected: Rely on AppDelegate delayed mark-read for socket JSON | CLI callers need the open response and subsequent list output to reflect the explicit action
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace policy

* Make CLI integration helper capture explicit self

CircleCI's Swift compile step requires explicit self when the background subprocess closure calls the test helper method. This keeps the deadlock fix intact while satisfying Swift capture rules.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace
Rejected: Verify with local xcodebuild | user explicitly forbids direct xcodebuild
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI

* Make CLI presentation flags order-independent

Users naturally put presentation flags next to the command they are inspecting. Normalize --json and --id-format after command selection so docs examples such as cmux list-notifications --json produce JSON while still preserving literal flag-looking values for command options.

Constraint: Do not run reload.sh before CI is green; never run bare xcodebuild.

Rejected: Documentation-only correction | leaves copy-pasted command behavior surprising.

Rejected: Notification-only --json handling | repeats the same parser split for future JSON-capable commands.

Confidence: medium

Scope-risk: moderate

Directive: Keep presentation flag parsing centralized; update commandOptionsWithValues when adding value-taking command options.

Tested: git diff --check

Not-tested: Local XCTest/build per repo policy; CI will verify.

* Fix notification surface selector error message

* Make notification open mark read synchronously

* Fix CLI presentation flag parsing

* Test notification mark-read missing id

* Reject missing notification mark-read ids

* fix: polish markdown viewer dogfood

* Fix shared WebView task manager attribution

Fixes shared WebContent resource attribution in task manager rows and adds regression coverage.

* Prevent display-link crash from terminal portal layout reentry (#3885)

* Pin portal sync deferral during SwiftUI host callbacks

The silent-exit crash path points at SwiftUI/AppKit layout recursion reaching a CATransaction display-link flush. This test locks the intended invariant: geometry callbacks originating from the SwiftUI NSViewRepresentable host must defer portal reconciliation instead of forcing immediate AppKit layout, even while an interactive resize is active.

Constraint: Local tests are intentionally not run in this repository; CI owns regression proof.\nRejected: Assert on source text or unified-log contents | timing-dependent and not executable through the policy seam.\nConfidence: medium\nScope-risk: narrow\nDirective: Keep immediate portal flushing owned by external AppKit resize observers, not SwiftUI host callbacks.\nTested: Not run locally per repository policy and user instruction.\nNot-tested: Full multi-session crash reproduction is timing-dependent and not deterministic.

* Prevent portal layout reentry from terminal host callbacks

The terminal NSViewRepresentable host was allowed to bind into the window portal and synchronously flush AppKit layout from update/layout callbacks. That made SwiftUI's own host layout and the external terminal portal both believe they could drive geometry in the same render turn, matching the NSHostingView reentrant-layout warnings reported before the CATransaction display-link abort.\n\nThe portal now treats SwiftUI host callbacks as state capture only: they register the binding and schedule the portal owner to reconcile geometry after the current render turn. Immediate geometry flushing remains available to the portal's external AppKit resize observers, which are outside SwiftUI body/layout evaluation. The launch path also records clean exits and posts a one-time TerminalNotificationStore breadcrumb when a newer ghostty Breakpad envelope is found after an unclean exit.

Constraint: Local tests and app builds are not run before CI for this branch; verification is delegated to CI, then the required tagged reload.\nRejected: Wrap the CATransaction/display-link exception in @try/@catch | it would hide AppKit's abort symptom without removing the reentrant layout owner split.\nRejected: Keep immediate sync during interactive SwiftUI host callbacks | still allows layoutSubtreeIfNeeded inside the representable layout/update path.\nConfidence: medium\nScope-risk: moderate\nDirective: SwiftUI/AppKit host callbacks must not force terminal portal layout synchronously; add external observer paths for any future immediate resize flushing.\nTested: git diff --check; jq empty Resources/Localizable.xcstrings\nNot-tested: Local XCTest/build/repro per repository and user instructions; 75-minute multi-session crash reproduction is not deterministic.

* Record clean-exit breadcrumb after teardown

The crash breadcrumb should compare Breakpad envelopes against the last successfully completed termination path. Recording the timestamp after teardown avoids marking an exit clean before session persistence, process cleanup, and notification cleanup have finished.

Constraint: This is a follow-up correctness tweak before CI settled.\nRejected: Keep the timestamp at the start of applicationWillTerminate | a crash during termination cleanup could suppress the next-launch breadcrumb.\nConfidence: high\nScope-risk: narrow\nDirective: Only update the clean-exit timestamp after teardown work that must complete for a clean quit.\nTested: git diff --check; jq empty Resources/Localizable.xcstrings\nNot-tested: Local tests/builds per repository and user instructions.

* Defer first portal install from SwiftUI callbacks

A deferred SwiftUI host bind could still create the WindowTerminalPortal for the first time, and the initializer previously installed the host with an immediate layout flush. Threading the same deferral flag through portal creation keeps the invariant complete: representable update/layout callbacks never synchronously flush terminal portal layout, even on first bind.

Constraint: Must preserve immediate install behavior for non-SwiftUI external portal callers
Rejected: Assume portals already exist before host callbacks | first terminal bind in a new window can create one
Confidence: high
Scope-risk: narrow
Directive: Any future portal creation path from SwiftUI callbacks must carry deferred synchronization through initialization
Tested: git diff --check; jq empty Resources/Localizable.xcstrings
Not-tested: Local tests/builds per repository and user instructions

* Move crash breadcrumb work out of launch hot path

The crash breadcrumb scanner is pure Foundation logic, so it now lives in its own source file and performs the crash-directory scan from a detached utility task. App launch only schedules the check once, then posts the existing localized notification after the background scan returns to the main actor. The terminal host geometry policy is also simplified to make the always-deferred invariant explicit at the call site.

Constraint: Local build/tests are intentionally skipped until CI completes per issue instructions
Rejected: Keep synchronous directory enumeration in AppDelegate.configure | startup should not block on crash artifact I/O
Rejected: Preserve the dead immediate portal sync branch | host callbacks are never allowed to force layout synchronously
Confidence: high
Scope-risk: narrow
Directive: Do not reintroduce synchronous crash-directory scans or immediate portal layout flushes from SwiftUI host callbacks
Tested: git diff --check; jq empty Resources/Localizable.xcstrings; plutil -lint GhosttyTabs.xcodeproj/project.pbxproj
Not-tested: Local build/tests per repository and user instructions

* Tighten portal geometry regression seam

* Fix crash breadcrumb actor isolation

* Mark crash breadcrumb async helper nonisolated

* Make crash breadcrumb scan concurrent

* fix: remove inert crash breadcrumb cooldown key

* fix: use renamed crash breadcrumb annotation

* fix: own crash breadcrumb scan task

* Hide sidebar descriptions in title-only mode (#4040)

* Hide sidebar descriptions in title-only mode

* Add sidebar description visibility toggle

* Let sidebar titles use trailing slack

* Float sidebar shortcut hints over rows

* Remove unused sidebar width helper

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add Pi agent icon

PR: https://github.com/manaflow-ai/cmux/pull/4057

* Keep Claude Running after clear (#3631)

* Prove Claude clear hook loses running status

The regression exercises the Claude hook handler directly with a SessionStart payload whose source is clear, then sends a late Stop for the previous session. The current handler does not promote the clear boundary to Running or reject stale Stop mutations, so this test is expected to fail before the lifecycle fix.

Constraint: Tests must exercise the hook handler directly rather than driving the full app.

Confidence: high

Scope-risk: narrow

Directive: Keep this regression on the direct CLI hook path; do not replace it with source-text assertions.

Tested: Not run locally per repository policy.

Not-tested: CI red/green proof pending on GitHub Actions.

* Prove Claude clear should own running status

Add hook-level regression coverage for Claude Code /clear. The tests drive the bundled CLI against a mock cmux socket so CI proves SessionStart(source=clear) must set the visible Running status and a prior session Stop must not clobber that fresh lifecycle.

Constraint: Local tests are intentionally not run; CI owns test execution for this task.
Confidence: high
Scope-risk: narrow
Tested: Not run locally per instruction
Not-tested: Full app UI repro under CI

* Ignore stale Claude hook events after clear

Claude /clear starts a fresh hook lifecycle but the sidebar status key is shared at the workspace level. Persist the active Claude session per workspace, promote clear SessionStart to a visible Running state, and ignore teardown or notification mutations from sessions that are no longer current.

Constraint: Claude Code emits /clear as SessionStart(source=clear).
Rejected: Only set Running on clear SessionStart | late Stop from the previous lifecycle could still clobber the new status.
Confidence: high
Scope-risk: narrow
Directive: Future Claude hook status mutations must respect the active workspace session before touching claude_code.
Tested: Not run locally per instruction
Not-tested: Full app UI after CI

* Prove Claude clear hook loses running status

The regression exercises the Claude hook handler directly with a SessionStart payload whose source is clear, then sends a late Stop for the previous session. The current handler does not promote the clear boundary to Running or reject stale Stop mutations, so this test is expected to fail before the lifecycle fix.

Constraint: Tests must exercise the hook handler directly rather than driving the full app.

Confidence: high

Scope-risk: narrow

Directive: Keep this regression on the direct CLI hook path; do not replace it with source-text assertions.

Tested: Not run locally per repository policy.

Not-tested: CI red/green proof pending on GitHub Actions.

* Keep Claude clear sessions authoritative

Claude /clear arrives as a SessionStart source=clear event, but the hook store only remembered routing data. This change makes the store also own the active session for each workspace, promotes clear starts to Running, and ignores visible Stop/Notification/SessionEnd mutations when their session no longer matches the active workspace session.

Constraint: Claude Code documents SessionStart source=clear for /clear lifecycle boundaries.

Rejected: Only set Running on source=clear | old Stop and SessionEnd events could still clobber the new session afterward.

Confidence: high

Scope-risk: narrow

Directive: Visible Claude hook mutations must pass active-session ownership checks before changing sidebar status or notifications.

Tested: Not run locally per repository policy.

Not-tested: CI red/green proof pending on GitHub Actions.

* Allow Claude sessions to advance turns

A visible hook mutation can only be rejected as stale after the active session boundary is known. Keeping a completed turn id active after Stop made the next prompt in the same Claude session look stale before it could promote its own turn.

The Stop path now refreshes the active session with no turn id once the completed turn has been accepted, preserving stale-session protection across /clear while allowing normal multi-turn prompts to re-enter Running. The regression now exercises that two-turn path before the clear boundary.

Constraint: Do not run local tests; CI owns verification for this branch.
Rejected: Ignore turn id in all current-session checks | would weaken stale turn filtering for late Stop and Notification events.
Confidence: high
Scope-risk: narrow
Directive: Do not persist a completed turn id past Stop without proving the next prompt-submit can promote a new turn.
Tested: git diff --check
Not-tested: Local unit/regression tests per project policy

* Remove duplicate Claude clear helper

The branch integration accidentally kept two isClaudeClearSessionStart definitions in CLI/cmux.swift. The duplicate version referenced a non-existent parsedInput.source property, so Swift would reject the file before CI could exercise the hook lifecycle tests.

Keep the existing implementation that reads source from the parsed hook object and delete only the duplicate helper.

Constraint: Fix review-reported compile blocker without changing lifecycle behavior.
Rejected: Add source to ClaudeHookParsedInput | unnecessary for this compile fix and broader than the failing duplicate.
Confidence: high
Scope-risk: narrow
Directive: Keep exactly one Claude clear source helper unless the parsed input model is intentionally extended.
Tested: git diff --check; rg confirms a single isClaudeClearSessionStart definition and no parsedInput.source reference.
Not-tested: Local tests per project policy

* Restore Claude hook compileability after lifecycle merge

The active-session merge left behind the old source-property helper alongside the newer compact-payload helper. Removing the duplicate keeps source=clear detection on the JSON payload and avoids both the redeclaration and missing-property errors.

Constraint: Do not run local tests; CI owns verification for this branch
Rejected: Reintroduce ClaudeHookParsedInput.source | duplicates state already retained in the compact hook payload
Confidence: high
Scope-risk: narrow
Tested: git diff --check; rg verified a single isClaudeClearSessionStart definition and no parsedInput.source references
Not-tested: Local compile/test execution per task policy

* Normalize Claude active-session cleanup keys

The active-session map is keyed by normalized workspace id, so cleanup after consuming a session must use the same normalized key. Otherwise a record containing incidental whitespace could leave a stale active-session entry behind.

Constraint: Address reviewer-reported lifecycle cleanup edge case without changing visible hook behavior.
Rejected: Store raw workspace ids as active map keys | inconsistent with existing upsert normalization and lookup guards.
Confidence: high
Scope-risk: narrow
Directive: Any activeSessionsByWorkspace lookup should use the normalized workspace key, matching insertion.
Tested: git diff --check
Not-tested: Local tests per project policy

* Harden CI Zig downloads against transient upstream failures

CircleCI and the activation workflow both depend on ziglang.org tarballs during remote macOS setup. A transient 500 from that host failed the debug build before any project code compiled, so the install path now retries downloads and avoids unnecessary Homebrew update/cleanup churn on CircleCI.

Constraint: CI must be made green remotely without running local tests or local xcodebuild.

Rejected: Push an empty commit to rerun CI | would leave the same upstream download flake unchanged.

Confidence: high

Scope-risk: narrow

Directive: Keep Zig installer retries in remote CI setup paths; failures here happen before project build logic runs.

Tested: git diff --check

Not-tested: Local tests and local builds not run per repository/user policy.

* Cover stale Claude session-end lifecycle

Greptile identified that stale SessionEnd exercises a different clear-state path than stale Stop. The existing active-session guard already blocks the mutation, so the regression now drives that hook directly and asserts the active /clear session keeps its status, PID, and notifications intact.

Constraint: Do not run local tests; CI is the verification source for this branch.

Rejected: Add another Swift integration test | the existing Python hook harness already executes the CLI handler through the socket path used by CI.

Confidence: high

Scope-risk: narrow

Tested: Not run locally per repo policy.

Not-tested: Local test execution.

* Stop activation CI from stalling on Zig downloads

The activation workflow was cancelled before build because repeated ziglang.org transfers crawled for the full job timeout. Prefer Homebrew's pinned zig@0.15 bottle on macOS runners, then keep the direct tarball path as a bounded fallback with connection, total-time, and minimum-speed limits.

Constraint: The failed check never reached project build or tests; the only failing surface was CI tool bootstrap.

Rejected: Increase the job timeout | it would hide the bootstrap failure and delay feedback.

Confidence: medium

Scope-risk: narrow

Directive: Keep activation workflow tool bootstrap bounded so performance CI reaches the benchmark or fails quickly.

Tested: git diff --check

Not-tested: Local workflow execution, per repository and user instruction.

* Gate Claude session-end cleanup on the consumed workspace

Greptile noted that session-end computed the current-session guard from the fallback workspace while clearing the consumed session's workspace. Move the guard next to the mutation target so stale cleanup and visible cleanup always evaluate the same workspace identity.

Constraint: This is follow-up review hardening on the existing active-session model.

Rejected: Collapse activeSessionsByWorkspace into sessions in this PR | per-workspace current-session lookup is the intended lifecycle boundary for stale event gating.

Confidence: high

Scope-risk: narrow

Directive: SessionEnd visible cleanup must be gated against the workspace being cleared, not an earlier fallback lookup.

Tested: git diff --check

Not-tested: Local test execution, per repository and user instruction.

* Gate Claude session-end cleanup on consumed workspace

A late SessionEnd can be resolved through fallback surface lookup, so the workspace used to find a record is not always the workspace whose visible state would be cleared. Move the staleness check after consume() and evaluate it against the consumed session's workspace, where the clear_status and notification cleanup actually run.

Constraint: Hook events are delivered by short-lived CLI processes and must tolerate stale or partial Claude payloads

Rejected: Keep the pre-consume fallback workspace guard | it can validate one workspace while clearing another

Confidence: high

Scope-risk: narrow

Tested: Added Swift integration regression for stale SessionEnd fallback cleanup

Not-tested: Local tests not run per repository policy

* Make stale Claude session-end test consume the seeded session

Greptile caught that the Swift regression used an unknown session id, so the hook returned before reaching the intended consumed-session visibility guard. Use the seeded stale session id in the SessionEnd payload so the test exercises consume(), then verifies that stale visible cleanup is blocked.

Constraint: Address high-priority review feedback without running local tests.

Rejected: Leave Python-only coverage | the Swift regression would continue passing for the wrong reason.

Confidence: high

Scope-risk: narrow

Directive: Stale session-end regressions should consume a known stale session before asserting visible cleanup is skipped.

Tested: git diff --check

Not-tested: Local tests per repository and user instruction

* Cover fallback Claude session-end consumption

The stale SessionEnd regression should prove the handler consumed the stale session through fallback lookup before deciding whether visible state may be cleared. Use an unknown late session id and assert the seeded stale session is removed from the store, so the test cannot pass without exercising the consumed-workspace guard.

Constraint: Review feedback flagged the prior Swift regression as able to pass without covering the intended guard

Rejected: Use the stored stale session id directly | that only covers the ordinary mapped-session stale path

Confidence: high

Scope-risk: narrow

Tested: Not run locally per repository policy; CI will run the Swift regression

Not-tested: Local XCTest execution

* Keep Claude clear ownership panel-scoped

The clear SessionStart path now owns the active Claude boundary only for explicit clear events, so late startup/resume SessionStart events from the previous session cannot reclaim the workspace before their stale Stop or SessionEnd arrives. The same clear path now passes the resolved surface id into status updates so split panels receive the Running state in the intended pane.

Constraint: Local test execution is disallowed by repository policy; CI remains the behavioral gate.

Rejected: Let every SessionStart mark active | late non-clear events can overwrite the clear boundary.

Rejected: Drop fail-open isCurrent behavior | transient store errors should not hide legitimate current status updates.

Confidence: medium

Scope-risk: moderate

Directive: Do not let non-clear Claude SessionStart events replace an explicit /clear active boundary without adding event ordering metadata.

Tested: python3 -m py_compile tests/test_claude_hook_clear_running_status.py; git diff --check; conflict marker scan.

Not-tested: Local Swift/unit/UI test execution per repo policy.

* Protect Claude clear state from stale session cleanup

Late hook events can arrive after an explicit /clear boundary. The SessionStart handler now skips PID registration when the event is stale against the active session, and SessionEnd consumption preserves the active session when the incoming turn id is older than the stored active turn.

Constraint: Local test execution is disallowed by repository policy; CI remains the behavioral gate.

Rejected: Clear active ownership before checking currentness | same-session stale SessionEnd would fail open and apply cleanup.

Rejected: Keep prefix-only command assertions | option ordering changes would make the regression test brittle.

Confidence: medium

Scope-risk: moderate

Directive: Do not consume a Claude session or replace its PID from a hook event that is stale relative to active session/turn state.

Tested: python3 -m py_compile tests/test_claude_hook_clear_running_status.py; git diff --check; conflict marker scan.

Not-tested: Local Swift/unit/UI test execution per repo policy.

* Allow new Claude sessions to replace stopped owners

A stopped Claude turn must keep the same session eligible for the next turn, but it must not strand the workspace if that process exits before session-end. Mark stopped ownership as replaceable and let only session activation paths use that escape hatch; clear-session ownership remains non-replaceable so stale pre-clear events stay blocked. Session-end fallback cleanup now checks the consumed session id so missing input session ids do not fail open.\n\nConstraint: /clear SessionStart must continue to suppress stale pre-clear startup, stop, and session-end events\nRejected: Clear active ownership on Stop | breaks same-session multi-turn prompt-submit currentness\nConfidence: medium\nScope-risk: narrow\nTested: git diff --check; conflict-marker scan\nNot-tested: local XCTest per repo policy; CI will run cmux unit regressions

* test: cover codex hooks TOML features section

* fix: harden hook config and auth token cache

* test: cover sign-out browser auth loading cleanup

* fix: cancel browser auth on sign-out

* test: cover codex config read failures

* fix: fail closed on codex config read errors

* test: cover auth sign-out callback race

* fix: discard auth callback after sign-out

* fix: keep claude subcommands out of hook injection

* fix: dismiss stale sparkle update replies

* fix: redact auth logs while preserving observability

* fix: reset update checks and guard sign-out races

* fix: preserve update metadata from driver state

* fix: await auth token assertions before comparing

* fix: address wrapper and auth review feedback

* fix: address session and config review feedback

* ci: retrigger pending checks

* fix: clear stale ime and auth token state

* fix: clean legacy codex hooks config

* test: cover legacy codex hooks markers

* fix: clean empty codex features table

* fix: preserve browser key reentry dispatch

* Fix new-workspace caller window routing (#4042)

* test: cover new workspace caller routing

* fix: route new workspace to caller context

* Add iMessage workspace insertion regression test

* Reset Kitty keyboard mode at shell prompt boundaries (#3870)

* Prove stale Kitty keyboard state leaks CSI-u key bytes

The regression exercises a hosted Ghostty terminal, leaves Kitty keyboard protocol enabled as a crashed TUI would, mirrors the clear-history socket handler clear_screen path, and captures raw PTY stdin bytes for a plain c key. Current behavior should encode CSI-u instead of a single ASCII byte, making the test fail until the protocol state is reset at the shell prompt boundary.

Constraint: Regression must cover PTY input bytes, not source text shape
Confidence: high
Scope-risk: narrow
Directive: Keep this test on the real ghostty_surface_key path; sendText alone bypasses the keyboard encoder
Tested: Manual current-main repro captured c9;1:3uc9;1:3uc9;1:3u after Kitty enable plus clear-history
Not-tested: Local unit execution deferred to CI per requested red/green workflow

* Reset stale Kitty keyboard mode at prompt boundaries

A crashed TUI can leave Ghostty's Kitty keyboard protocol stack pushed after clear-history, causing normal shell input to be encoded as CSI-u. Resetting the stack from the shell prompt hook makes the prompt boundary the ownership point for returning interactive shells to plain byte input.

Constraint: Fix must run through shell integration because Ghostty keeps protocol state inside the terminal surface

Rejected: Reset only in clear-history socket path | stale state also leaks after any crashed TUI returns to prompt

Confidence: high

Scope-risk: narrow

Directive: Keep prompt-boundary reset paired across bash and zsh integrations

Tested: Not run locally per repository testing policy; regression added in prior commit

Not-tested: CI not yet completed

* Clarify Kitty reset fixture failures

The stale keyboard regression now fails at the fixture boundary if the zsh integration does not emit the expected reset bytes, instead of falling through to a misleading PTY byte mismatch.

Constraint: Repository policy forbids local test execution for this PR loop

Confidence: high

Scope-risk: narrow

Tested: Not run locally per repository policy; CI will run the affected XCTest

Not-tested: Local XCTest execution

* chore: retrigger Vercel checks

* Add Kitty reset shell hook coverage

* Reset all terminal keyboard protocols at prompt

* Fix terminal keyboard reset test expectations

* Clarify disabling agent session auto-resume for #3640 (#3991)

* docs: explain disabling agent auto resume

* docs: name auto resume config path

* Fix stale restored agent resume state

* Harden restored agent hook liveness

* refactor: share restored agent normalization

* Honor iMessage workspace ordering and previews

* Add workspace cwd inheritance setting (#3921)

* feat: add workspace cwd inheritance setting

* fix: align workspace cwd setting key naming

* fix: apply workspace cwd setting to detached creation

* fix: expose workspace cwd inheritance setting

* fix: route pane break through detached workspace creation

* fix: keep pane break response pane ids non-null

* fix: distinguish pane break resolution errors

* Approve installed Codex hooks (#4035)

* Approve installed Codex hooks

* Address Codex hook trust review feedback

* Avoid tomllib in Codex hook tests

* Align Codex hook trust test mirror

* Harden Codex hook trust ownership

* Preserve legacy Codex hook cleanup

* Fix workspace unit test after merge

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Revert "Approve installed Codex hooks (#4035)" (#4074)

This reverts commit e4546b7675a4ffa5a41a5429218b60f4e7644e21.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Fix workspace unit test transfer resume state (#4076)

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Clarify in cmux --help that reload-config covers Ghostty config too (#4060)

* Clarify cmux help that reload-config covers Ghostty config too

`cmux reload-config` reloads BOTH ~/.config/cmux/cmux.json and Ghostty
config (~/.config/ghostty/config) and refreshes terminals in place, but
the help/docs only mentioned cmux.json. Agents (and humans) reading the
help would think they had to restart cmux after editing Ghostty config.

- cmux --help "Agent Help" now tells agents where Ghostty config lives
  and that reload-config picks it up live.
- cmux docs settings, cmux settings path, cmux config --help now list
  ~/.config/ghostty/config as a related (not cmux-owned) location and
  describe reload-config's actual scope.
- cmux schema sidebarAppearance.tintOpacity description now notes it's
  sidebar-only, and points to Ghostty background-opacity / blur for
  terminal transparency.
- skills/cmux/SKILL.md mirrors the wording.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Align ghostty_config JSON shape across CLI surfaces

Cursor Bugbot and Greptile both flagged that `cmux settings path --json`
emitted `ghostty_config` as a string while `cmux docs settings --json`
emitted it as an object {path, note}. An agent reading both outputs with
the same key expectation would have to special-case the type.

Standardize on the object shape with `path` and `note` in both, matching
docsPayload. This is the agent-discoverability path the PR is trying to
make reliable, so making the shape consistent is on-purpose.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Use canonical Ghostty config key background-blur (not background-blur-radius)

CodeRabbit flagged that `background-blur-radius` is outdated. Verified
against the Ghostty submodule at ghostty/src/config/Config.zig: line 70
declares `background-blur-radius` as a compatibilityRenamed alias for
`background-blur`. The current canonical key is `background-blur` and it
accepts the same integer value (e.g. `background-blur = 20`).

Update the two docs that introduced the alias name:
- skills/cmux/SKILL.md
- web/data/cmux.schema.json (sidebarAppearance.tintOpacity description)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Add nucleo FFI command palette benchmark

* Open right sidebar tools as panes (#4065)

* Open right sidebar tools as panes

* Remove unreachable sidebar pane commands

* Fix sidebar pane unit test build

* Address sidebar pane review feedback

* Fix vault pane focus tracking

* Address right sidebar pane review followups

* Use modern sidebar pane flash observer

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Save crash diagnostics under cmux state (#4077)

* Save crash diagnostics under cmux state

* fix: key GhosttyKit artifacts by crash path

* fix: pin cmux crash GhosttyKit archive

* fix: mark crash breadcrumb scan concurrent

* fix: keep crash scan compatible with Xcode 16

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Menubar global search P1 (#3908)

* Ship local global search as a remappable menubar flow

Phase 1 needs browser and markdown value without terminal scrollback, so the index owns durable FTS5 upserts while AppDelegate keeps one navigation path from palette rows to focused panels. The global shortcut is wired through the existing shortcut settings instead of a standalone Carbon shim so Settings and cmux.json remain authoritative.

Constraint: Phase 1 excludes Ghostty terminal scrollback capture

Constraint: User required no local test execution and no reload before CI is green

Rejected: Hardcoded GlobalSearchHotkey shim | violates KeyboardShortcutSettings policy

Confidence: medium

Scope-risk: broad

Directive: Keep future terminal capture feeding SearchIndex documents through GlobalSearchCoordinator rather than adding another palette/navigation path

Tested: git diff --check; python3 -m json.tool Resources/Localizable.xcstrings; python3 -m json.tool web/data/cmux.schema.json; plutil -lint GhosttyTabs.xcodeproj/project.pbxproj

Not-tested: Local unit/UI tests and tagged app launch per task constraints

* Remove duplicate search refresh work

Cursor review pointed out that the menubar toggle and palette onAppear both refreshed the live index. Keeping the refresh in the palette lifecycle avoids resetting browser debounce tasks while still indexing each time the palette opens, and removing the unused workspace delete API keeps the storage surface honest.

Constraint: Review feedback came from PR #3908 after the first CI pass started

Rejected: Keep both refresh calls | causes avoidable debounce cancellation and slower browser result availability

Confidence: high

Scope-risk: narrow

Directive: Add workspace-level deletion only when a real workspace teardown caller is wired

Tested: git diff --check; python3 -m json.tool Resources/Localizable.xcstrings; python3 -m json.tool web/data/cmux.schema.json; plutil -lint GhosttyTabs.xcodeproj/project.pbxproj

Not-tested: Local tests/build per task constraints

* Fix global search stale index entries

* Address global search review feedback

* Fix search query token mapping compile error

* Fix global search CI failures

* Fix stale unavailable markdown search entries

* Cancel stale markdown search captures

* Cancel global search refresh on dismiss

* Fix global search review followups

* Address global search post-CI feedback

* Preserve markdown panel title search on read failure

* Address global search lifecycle feedback

* Address global search review lifecycle feedback

* Refine global search capture ownership

* fix: address global search review blockers

* feat: show open panels in global search

* fix: cover right sidebar tool panel in search

* Fix cmuxTests: rename restorableAgentAutoResumePending to restorableAgentResumeState (#4068)

* fix: handle repeated assistant imessage completions

* Open supported files in cmux on cmd-click (#4041)

* Open supported files in cmux on cmd-click

* Add cmd-click file preview verification script

* Reuse right pane for cmd-click file previews

* Keep cmd-click UI test terminal after preview focus

* Accept numeric cmd-click test payload values

* Capture cmd-click UI test window snapshots

* Add file-type-aware external open actions

* Address supported file routing review feedback

* Fix external open menu sendability warnings

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Suppress native proxy icon on cmux main windows (#3973)

* Add proxy icon regression test

* Suppress native proxy icon on cmux windows

* chore: retrigger preview deployments

* Refine native proxy icon suppression

* fix: keep titlebar folder icon aligned

* fix: restore titlebar folder icon leading offset

* test: cover folder icon frame replacement

* fix: resync folder icon on frame replacement

* test: cover folder icon ancestor movement

* fix: track folder icon ancestor movement

* fix: address folder icon review feedback

* test: stabilize folder icon ancestor sync

* fix: handle sidebar tool panels in global search

---------

Co-authored-by: austinpower1258 <austinwang115@gmail.com>

* Close browser panels when pages request window close (#4070)

* Add browser self-close restore regression test

* Close browser panels from WebKit close callbacks

* fix: index right sidebar tool panels as titles

* fix: keep web close callback synchronous

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add notification policy hooks

Merged https://github.com/manaflow-ai/cmux/pull/4054

* Fix sidebar unread badge after re-marking notifications (#4084)

* Add sidebar unread notification regression test

* Keep sidebar notification badge live during menu freeze

* Cover sidebar presentation fallback cases

* Limit Cloud VMs by active provider state (#4046)

* test: cover active vm limit with paused freestyle vms

* fix: enforce cloud vm limits by active state

* fix: parallelize cloud vm status refresh

* chore: update web security dependencies

* fix: handle right sidebar tools in global search

* fix: guard cloud vm status refresh races

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Fix Settings search synonyms (#4082)

* Add settings search synonym regressions

* Fix settings search synonyms

* Add shortcut bindings anchor regression

* Cover clickable PR settings search alias

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add tagged debug CLI helper (#4092)

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add unread defer shortcut (#4086)

* Add unread defer shortcut

* fix: address unread defer feedback

* fix: keep manual unread jump explicit

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Document notification hooks default off

Document that notification hooks are off by default and style the config key in localized docs.

* Approve installed Codex hooks after dogfood (#4075)

* Reapply Codex hook approval changes for dogfood

* Notify on Codex plan input requests

* Handle Codex plan question transcript items

* Address Codex hook review feedback

* Recover malformed Codex hook trust blocks

* Avoid duplicate consecutive cmux hook reinserts

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Document session restore behavior

Adds session restore docs, blog, README updates, and review cleanup.

* Use nucleo for command palette search

* Skip unrestorable Claude startup sessions

PR: https://github.com/manaflow-ai/cmux/pull/4079

* Revert "Suppress native proxy icon on cmux main windows" (#4099)

* Revert "Suppress native proxy icon on cmux main windows (#3973)"

This reverts commit 5048440ff44b4edbe328b65403724ff79476b2e6.

* Fix titlebar proxy icon without detached panel sync

* Apply proxy icon override to fallback config

* Restore key regain redraw invariant

* Tune nucleo palette initialism ranking

* Fix terminal portal resize lag (#4102)

* Fix Korean 2-Set terminal arrows (#4095)

* Add Korean 2-Set arrow IME regression

* Restore Korean 2-Set arrow forwarding

* Restore Zhuyin IME command routing

* Address IME review feedback

* Fix Korean IME regression test compile

* Address IME review follow-ups

* Address Bopomofo preedit review feedback

* Avoid idle Zhuyin key suppression

* Remove dead text input wrapper

* Address IME suppression review feedback

* Fix palette stitched highlight precedence

* Add Codex Teams subagent panes

* Open markdown files in preview panels from cmux open (#4085)

* fix: open markdown files in preview panels

* fix: preserve markdown viewer transparency

* fix: mute markdown open-with header button

* fix: align markdown header controls

* fix: align file header controls

* fix: address markdown review feedback

* test: cover opaque text editor alpha

* fix: align header open fallback

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add task manager sorting and program aggregates (#4066)

* Add task manager sorting and program aggregates

* Add sorting to cmux top output

* Add flat TSV cmux top output

* Add coding agent task manager totals

* Make task manager program totals payload-backed

* Recognize agent launcher process names in task manager

* Fix task manager test build helpers

* Recognize Claude versioned launcher processes

* Show loading state before task manager sample

* Recognize versioned agent process names

* Use agent totals for task manager hierarchy icons

* fix: address task manager review feedback

* fix: address follow-up task manager review

* fix: address final task manager review

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Keep manual unread sticky until terminal interaction (#4104)

* test: cover sticky manual unread state

* fix: keep manual unread sticky until terminal input

* fix: show workspace manual unread pane ring

* fix: sync manual unread badge on focus changes

* fix: stabilize manual unread representative fallback

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: austinpower1258 <austinwang115@gmail.com>

* Bump version to 0.64.5 (#4107)

* Fix Pi Vault icon and JSONL titles (#4120)

* test: cover Pi JSONL content block titles

* fix: parse Pi JSONL text blocks for Vault titles

* fix: align Pi JSONL title role handling

* fix: require typed text blocks for Pi titles

* Improve Cloud VM error guidance (#4094)

* Improve Cloud VM error guidance

* Address final Cloud VM review feedback

* Narrow Cloud VM sanitizer env var block

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Keep selected workspace visible after sidebar reorders

* Add sidebar scroll regression for workspace move to top

* Reveal selected workspace after sidebar reorders

* Handle right sidebar tool panels in global search

* Test workspace move to top visibility only

* Refine sidebar reorder scroll trigger

* Add move-to-top notification regression

* Skip no-op move-to-top notifications

* Assert no-op move-to-top keeps order

* Require matching manager for reorder scroll

* Scroll selected workspace on index shifts

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Use transparent backgrounds for file preview panels (#4088)

* Handle right sidebar tools in global search browse hits

* Use transparent backgrounds for file preview panels

* Cover panel theme background preservation

* Fix PDF file preview open menu

* Make file open menu button compact

* Fix PDF open menu chrome button

* Fix PDF open-with chrome click target

* Address file preview chrome review feedback

* Fix PDF background cache invalidation

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Inherit stdin in backgrounded ssh inside startup wrapper (#4135)

* Add regression test for SSH startup wrapper dropping stdin

After PR #3786 backgrounded the ssh invocation inside the startup
wrapper for signal/reconnect handling, `cmux ssh <host>` sessions
stopped forwarding keystrokes from the surface PTY to the remote
shell. Output flowed back (the remote prompt rendered in cmux UI),
but anything typed never reached zsh on the other side, which sat
blocked in `do_poll` on the remote pts.

Root cause: POSIX sh redirects stdin of an async command (`&`) to
/dev/null when job control is off — the default for the `/bin/sh -c …`
that runs the startup wrapper. Without an explicit `<&0` on the
`&`'d ssh line, the local PTY stdin is silently dropped.

This commit adds the failing regression test. The fix follows in
the next commit so CI can prove the test catches the bug.

* Inherit stdin in backgrounded ssh inside startup wrapper

PR #3786 wrapped the ssh invocation in `while :; do … & wait` to enable
SIGHUP/INT/TERM trap handling and reconnect-on-exit-255. Backgrounding
ssh, however, drops its stdin: POSIX sh redirects fd 0 of any async
command to /dev/null when job control is off, which is the default for
the `/bin/sh -c …` host that runs this wrapper.

As a result, output from the remote still flowed back to the surface
PTY (ssh's stdout/stderr stayed wired) but the user's keystrokes never
reached the remote — they hit ttysNNN on the Mac side, kernel echoed
them locally, but ssh's stdin was /dev/null so nothing was forwarded.
zsh on the far side sat in `do_poll` forever.

Explicit `<&0` on both the `command` line and the `( … )` shell-snippet
form overrides the POSIX default and re-attaches the wrapper's own
stdin to the backgrounded ssh process.

Verified with the regression test added in the previous commit, plus
manual repro on Darwin:

    /bin/sh -c 'cat &  wait'           # cat's fd 0 → /dev/null (bug)
    /bin/sh -c 'cat <&0 &  wait'       # cat's fd 0 → parent stdin (fix)

* Add docs search

Adds localized Pagefind docs search with heading anchors and section-aware results.

* Fix Swift interpolation escape in SSH stdin regression test (#4154)

`testSSHStartupForwardsStdinToBackgroundedSSH` used `\"<empty>\"` inside a
`\(...)` string interpolation. Swift parses `\"` as the end of the outer
literal, breaking compilation of cmuxTests on main:

    Cannot find ')' to match opening '(' in string interpolation
    Unterminated string literal

That kept `ci/circleci: macos-unit-tests` red on main after #4135 even
though `macos-debug-build` and `macos-release-build` still passed (the
test target was the only thing affected). The runtime fix (`<&0` on the
backgrounded ssh) is unchanged and was verified end-to-end on a cloud Mac.

Inside an interpolation, the string is already a Swift expression and
literal quotes are unescaped; drop the four backslashes.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Add command palette settings toggles

Adds command palette toggles for boolean Settings rows, including iMessage Mode.

* Ensure Rust toolchain is installed for nucleo FFI builds

* Document nucleo FFI thread and ABI assumptions

* Reuse nucleo index in preview search test helper

* Install Rust for activation perf builds

---------

Co-authored-by: Tobi Lutke <tobi@shopify.com>
Co-authored-by: Austin Wang <austinwang115@gmail.com>
Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Kevin Peng <48529172+kays0x@users.noreply.github.com>
lawrencecchen added a commit that referenced this pull request May 15, 2026
* Optimize command palette search

* Reduce command palette typing frame work

* Fix command palette result rendering

* Ignore stale command palette row snapshots

* Use command ids for palette row identity

* Match Zed-style palette result limiting

* Reduce palette preview search frame misses

* Use nucleo for command palette search (#4078)

* feat: improve markdown viewer

* fix: address markdown review feedback

* fix: clean up markdown review issues

* fix: address markdown review feedback

* fix: address latest markdown review

* Fix #3807: bring notification CLI to panel parity (#3811)

* Prove notification CLI parity is missing

Add behavior-level coverage for the missing notification socket and CLI actions before implementing them. The tests drive V2 notification action methods, CLI subcommands, extended list fields, and the UI open-notification flow so CI can show the pre-fix gap.

Constraint: Regression tests must be committed before the implementation for issue #3807

Constraint: Local Swift tests are not run in this repo; verification is through CI

Confidence: high

Scope-risk: narrow

Tested: git diff --check

Not-tested: Swift/XCUITest execution; intentionally deferred to CI

* Make notification actions scriptable from the CLI

The notifications panel already owned the behavior for dismissing, marking read, opening, and jumping to unread rows. This wires the socket and CLI to those existing store/AppDelegate paths, extends list output with panel metadata, and documents the new command surface without introducing a second notification action model.

Constraint: Existing Notifications page behavior must remain the source of truth

Constraint: Direct xcodebuild and local Swift/XCUITest runs are forbidden in this workspace

Rejected: Duplicate CLI-side focus or read-state logic | would diverge from AppDelegate.openNotification and TerminalNotificationStore semantics

Confidence: medium

Scope-risk: moderate

Tested: git diff --check

Tested: jq empty Resources/Localizable.xcstrings

Tested: python3 -m json.tool Resources/Localizable.xcstrings

Not-tested: Swift unit/UI execution; deferred to CI per repo policy

* Make notification CI compile under strict concurrency

The notification parity implementation introduced a shared formatter on a main-actor type and a test helper that crossed actor boundaries through escaping closures. This keeps the socket behavior unchanged while making date formatting local to the main-actor call path and keeping the XCTest socket request helper from capturing actor-isolated state in the background request closure.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace

Rejected: Run xcodebuild locally to confirm | user explicitly warned direct xcodebuild can deadlock the machine

Confidence: medium

Scope-risk: narrow

Tested: git diff --check

Tested: jq empty Resources/Localizable.xcstrings

Not-tested: Swift compilation and XCTest execution; deferred to CI

* Make notification parity actions atomic and exact

Review feedback exposed two behavior risks in the notification parity path: bulk dismissal was implemented as client-side list-and-loop work, and jump-to-unread could report one unread notification while opening a later valid one. The server now owns already-read dismissal as a single V2 action, the jump helper returns the notification it actually opened, and event/list parsing details match those server semantics.

Constraint: Notification action logic must reuse the existing store and AppDelegate paths

Rejected: Split TerminalController into new controllers in this PR | broad refactor is unrelated to issue #3807 and would obscure the parity fix

Confidence: medium

Scope-risk: moderate

Tested: git diff --check

Tested: jq empty Resources/Localizable.xcstrings

Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace instructions

* Expose app test symbols to CLI notification coverage

The integration regression exercises real app-backed notification state through the CLI harness, so the test target must import the built app module the same way the socket action tests do.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace
Rejected: Verify with xcodebuild locally | user explicitly forbids direct xcodebuild
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI

* Make notification list and dismiss payloads stable

Review caught two small contract hazards in the new notification RPC surface: the dismiss result used mixed JSON types, and a pipe in the appended tab title could shift the legacy list parser. The server now reports dismissals as counts consistently and escapes only the new trailing list field, with the CLI decoding it after structural parsing.

Constraint: The V1 list response remains pipe-delimited for backward compatibility, so only newly appended trailing fields can be encoded without changing old parser behavior
Rejected: Replace list_notifications with JSON-only output | existing V1 parsers depend on the line format
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace policy

* Return async notification socket responses from tests

CircleCI caught a compile-only issue in the async V2 test helper: the continuation result was awaited but not returned from the method that promises a response dictionary. Returning the continuation value restores the helper contract without changing the exercised socket behavior.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace
Rejected: Verify with local xcodebuild | user explicitly forbids direct xcodebuild
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI

* Avoid blocking notification CLI integration sockets

The integration regression has to create AppKit-backed notification state on the main actor, but running the CLI subprocess synchronously there can block the socket handler's main-actor store mutations. The test now awaits subprocess work on a background queue and verifies read state through the same CLI list path.

Constraint: Socket notification handlers intentionally hop to the main actor for store and AppDelegate work
Rejected: Run the CLI synchronously from the main actor | it can deadlock the in-process socket server during tests
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace policy

* Harden notification CLI response contracts

The notification parity path now distinguishes new list-notification trailer fields from old pipe-heavy bodies, rejects surface-only mark-read selectors, and returns post-open read state by marking through the shared store path after a successful focus action.

Constraint: list_notifications remains a legacy pipe-delimited protocol, so the new trailer needs its own discriminator while older body parsing keeps joining payload[6...]
Rejected: Add a third list_notifications sentinel field | the issue asked for exactly the two appended fields
Rejected: Rely on AppDelegate delayed mark-read for socket JSON | CLI callers need the open response and subsequent list output to reflect the explicit action
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace policy

* Make CLI integration helper capture explicit self

CircleCI's Swift compile step requires explicit self when the background subprocess closure calls the test helper method. This keeps the deadlock fix intact while satisfying Swift capture rules.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace
Rejected: Verify with local xcodebuild | user explicitly forbids direct xcodebuild
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI

* Make CLI presentation flags order-independent

Users naturally put presentation flags next to the command they are inspecting. Normalize --json and --id-format after command selection so docs examples such as cmux list-notifications --json produce JSON while still preserving literal flag-looking values for command options.

Constraint: Do not run reload.sh before CI is green; never run bare xcodebuild.

Rejected: Documentation-only correction | leaves copy-pasted command behavior surprising.

Rejected: Notification-only --json handling | repeats the same parser split for future JSON-capable commands.

Confidence: medium

Scope-risk: moderate

Directive: Keep presentation flag parsing centralized; update commandOptionsWithValues when adding value-taking command options.

Tested: git diff --check

Not-tested: Local XCTest/build per repo policy; CI will verify.

* Fix notification surface selector error message

* Make notification open mark read synchronously

* Fix CLI presentation flag parsing

* Test notification mark-read missing id

* Reject missing notification mark-read ids

* fix: polish markdown viewer dogfood

* Fix shared WebView task manager attribution

Fixes shared WebContent resource attribution in task manager rows and adds regression coverage.

* Prevent display-link crash from terminal portal layout reentry (#3885)

* Pin portal sync deferral during SwiftUI host callbacks

The silent-exit crash path points at SwiftUI/AppKit layout recursion reaching a CATransaction display-link flush. This test locks the intended invariant: geometry callbacks originating from the SwiftUI NSViewRepresentable host must defer portal reconciliation instead of forcing immediate AppKit layout, even while an interactive resize is active.

Constraint: Local tests are intentionally not run in this repository; CI owns regression proof.\nRejected: Assert on source text or unified-log contents | timing-dependent and not executable through the policy seam.\nConfidence: medium\nScope-risk: narrow\nDirective: Keep immediate portal flushing owned by external AppKit resize observers, not SwiftUI host callbacks.\nTested: Not run locally per repository policy and user instruction.\nNot-tested: Full multi-session crash reproduction is timing-dependent and not deterministic.

* Prevent portal layout reentry from terminal host callbacks

The terminal NSViewRepresentable host was allowed to bind into the window portal and synchronously flush AppKit layout from update/layout callbacks. That made SwiftUI's own host layout and the external terminal portal both believe they could drive geometry in the same render turn, matching the NSHostingView reentrant-layout warnings reported before the CATransaction display-link abort.\n\nThe portal now treats SwiftUI host callbacks as state capture only: they register the binding and schedule the portal owner to reconcile geometry after the current render turn. Immediate geometry flushing remains available to the portal's external AppKit resize observers, which are outside SwiftUI body/layout evaluation. The launch path also records clean exits and posts a one-time TerminalNotificationStore breadcrumb when a newer ghostty Breakpad envelope is found after an unclean exit.

Constraint: Local tests and app builds are not run before CI for this branch; verification is delegated to CI, then the required tagged reload.\nRejected: Wrap the CATransaction/display-link exception in @try/@catch | it would hide AppKit's abort symptom without removing the reentrant layout owner split.\nRejected: Keep immediate sync during interactive SwiftUI host callbacks | still allows layoutSubtreeIfNeeded inside the representable layout/update path.\nConfidence: medium\nScope-risk: moderate\nDirective: SwiftUI/AppKit host callbacks must not force terminal portal layout synchronously; add external observer paths for any future immediate resize flushing.\nTested: git diff --check; jq empty Resources/Localizable.xcstrings\nNot-tested: Local XCTest/build/repro per repository and user instructions; 75-minute multi-session crash reproduction is not deterministic.

* Record clean-exit breadcrumb after teardown

The crash breadcrumb should compare Breakpad envelopes against the last successfully completed termination path. Recording the timestamp after teardown avoids marking an exit clean before session persistence, process cleanup, and notification cleanup have finished.

Constraint: This is a follow-up correctness tweak before CI settled.\nRejected: Keep the timestamp at the start of applicationWillTerminate | a crash during termination cleanup could suppress the next-launch breadcrumb.\nConfidence: high\nScope-risk: narrow\nDirective: Only update the clean-exit timestamp after teardown work that must complete for a clean quit.\nTested: git diff --check; jq empty Resources/Localizable.xcstrings\nNot-tested: Local tests/builds per repository and user instructions.

* Defer first portal install from SwiftUI callbacks

A deferred SwiftUI host bind could still create the WindowTerminalPortal for the first time, and the initializer previously installed the host with an immediate layout flush. Threading the same deferral flag through portal creation keeps the invariant complete: representable update/layout callbacks never synchronously flush terminal portal layout, even on first bind.

Constraint: Must preserve immediate install behavior for non-SwiftUI external portal callers
Rejected: Assume portals already exist before host callbacks | first terminal bind in a new window can create one
Confidence: high
Scope-risk: narrow
Directive: Any future portal creation path from SwiftUI callbacks must carry deferred synchronization through initialization
Tested: git diff --check; jq empty Resources/Localizable.xcstrings
Not-tested: Local tests/builds per repository and user instructions

* Move crash breadcrumb work out of launch hot path

The crash breadcrumb scanner is pure Foundation logic, so it now lives in its own source file and performs the crash-directory scan from a detached utility task. App launch only schedules the check once, then posts the existing localized notification after the background scan returns to the main actor. The terminal host geometry policy is also simplified to make the always-deferred invariant explicit at the call site.

Constraint: Local build/tests are intentionally skipped until CI completes per issue instructions
Rejected: Keep synchronous directory enumeration in AppDelegate.configure | startup should not block on crash artifact I/O
Rejected: Preserve the dead immediate portal sync branch | host callbacks are never allowed to force layout synchronously
Confidence: high
Scope-risk: narrow
Directive: Do not reintroduce synchronous crash-directory scans or immediate portal layout flushes from SwiftUI host callbacks
Tested: git diff --check; jq empty Resources/Localizable.xcstrings; plutil -lint GhosttyTabs.xcodeproj/project.pbxproj
Not-tested: Local build/tests per repository and user instructions

* Tighten portal geometry regression seam

* Fix crash breadcrumb actor isolation

* Mark crash breadcrumb async helper nonisolated

* Make crash breadcrumb scan concurrent

* fix: remove inert crash breadcrumb cooldown key

* fix: use renamed crash breadcrumb annotation

* fix: own crash breadcrumb scan task

* Hide sidebar descriptions in title-only mode (#4040)

* Hide sidebar descriptions in title-only mode

* Add sidebar description visibility toggle

* Let sidebar titles use trailing slack

* Float sidebar shortcut hints over rows

* Remove unused sidebar width helper

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add Pi agent icon

PR: https://github.com/manaflow-ai/cmux/pull/4057

* Keep Claude Running after clear (#3631)

* Prove Claude clear hook loses running status

The regression exercises the Claude hook handler directly with a SessionStart payload whose source is clear, then sends a late Stop for the previous session. The current handler does not promote the clear boundary to Running or reject stale Stop mutations, so this test is expected to fail before the lifecycle fix.

Constraint: Tests must exercise the hook handler directly rather than driving the full app.

Confidence: high

Scope-risk: narrow

Directive: Keep this regression on the direct CLI hook path; do not replace it with source-text assertions.

Tested: Not run locally per repository policy.

Not-tested: CI red/green proof pending on GitHub Actions.

* Prove Claude clear should own running status

Add hook-level regression coverage for Claude Code /clear. The tests drive the bundled CLI against a mock cmux socket so CI proves SessionStart(source=clear) must set the visible Running status and a prior session Stop must not clobber that fresh lifecycle.

Constraint: Local tests are intentionally not run; CI owns test execution for this task.
Confidence: high
Scope-risk: narrow
Tested: Not run locally per instruction
Not-tested: Full app UI repro under CI

* Ignore stale Claude hook events after clear

Claude /clear starts a fresh hook lifecycle but the sidebar status key is shared at the workspace level. Persist the active Claude session per workspace, promote clear SessionStart to a visible Running state, and ignore teardown or notification mutations from sessions that are no longer current.

Constraint: Claude Code emits /clear as SessionStart(source=clear).
Rejected: Only set Running on clear SessionStart | late Stop from the previous lifecycle could still clobber the new status.
Confidence: high
Scope-risk: narrow
Directive: Future Claude hook status mutations must respect the active workspace session before touching claude_code.
Tested: Not run locally per instruction
Not-tested: Full app UI after CI

* Prove Claude clear hook loses running status

The regression exercises the Claude hook handler directly with a SessionStart payload whose source is clear, then sends a late Stop for the previous session. The current handler does not promote the clear boundary to Running or reject stale Stop mutations, so this test is expected to fail before the lifecycle fix.

Constraint: Tests must exercise the hook handler directly rather than driving the full app.

Confidence: high

Scope-risk: narrow

Directive: Keep this regression on the direct CLI hook path; do not replace it with source-text assertions.

Tested: Not run locally per repository policy.

Not-tested: CI red/green proof pending on GitHub Actions.

* Keep Claude clear sessions authoritative

Claude /clear arrives as a SessionStart source=clear event, but the hook store only remembered routing data. This change makes the store also own the active session for each workspace, promotes clear starts to Running, and ignores visible Stop/Notification/SessionEnd mutations when their session no longer matches the active workspace session.

Constraint: Claude Code documents SessionStart source=clear for /clear lifecycle boundaries.

Rejected: Only set Running on source=clear | old Stop and SessionEnd events could still clobber the new session afterward.

Confidence: high

Scope-risk: narrow

Directive: Visible Claude hook mutations must pass active-session ownership checks before changing sidebar status or notifications.

Tested: Not run locally per repository policy.

Not-tested: CI red/green proof pending on GitHub Actions.

* Allow Claude sessions to advance turns

A visible hook mutation can only be rejected as stale after the active session boundary is known. Keeping a completed turn id active after Stop made the next prompt in the same Claude session look stale before it could promote its own turn.

The Stop path now refreshes the active session with no turn id once the completed turn has been accepted, preserving stale-session protection across /clear while allowing normal multi-turn prompts to re-enter Running. The regression now exercises that two-turn path before the clear boundary.

Constraint: Do not run local tests; CI owns verification for this branch.
Rejected: Ignore turn id in all current-session checks | would weaken stale turn filtering for late Stop and Notification events.
Confidence: high
Scope-risk: narrow
Directive: Do not persist a completed turn id past Stop without proving the next prompt-submit can promote a new turn.
Tested: git diff --check
Not-tested: Local unit/regression tests per project policy

* Remove duplicate Claude clear helper

The branch integration accidentally kept two isClaudeClearSessionStart definitions in CLI/cmux.swift. The duplicate version referenced a non-existent parsedInput.source property, so Swift would reject the file before CI could exercise the hook lifecycle tests.

Keep the existing implementation that reads source from the parsed hook object and delete only the duplicate helper.

Constraint: Fix review-reported compile blocker without changing lifecycle behavior.
Rejected: Add source to ClaudeHookParsedInput | unnecessary for this compile fix and broader than the failing duplicate.
Confidence: high
Scope-risk: narrow
Directive: Keep exactly one Claude clear source helper unless the parsed input model is intentionally extended.
Tested: git diff --check; rg confirms a single isClaudeClearSessionStart definition and no parsedInput.source reference.
Not-tested: Local tests per project policy

* Restore Claude hook compileability after lifecycle merge

The active-session merge left behind the old source-property helper alongside the newer compact-payload helper. Removing the duplicate keeps source=clear detection on the JSON payload and avoids both the redeclaration and missing-property errors.

Constraint: Do not run local tests; CI owns verification for this branch
Rejected: Reintroduce ClaudeHookParsedInput.source | duplicates state already retained in the compact hook payload
Confidence: high
Scope-risk: narrow
Tested: git diff --check; rg verified a single isClaudeClearSessionStart definition and no parsedInput.source references
Not-tested: Local compile/test execution per task policy

* Normalize Claude active-session cleanup keys

The active-session map is keyed by normalized workspace id, so cleanup after consuming a session must use the same normalized key. Otherwise a record containing incidental whitespace could leave a stale active-session entry behind.

Constraint: Address reviewer-reported lifecycle cleanup edge case without changing visible hook behavior.
Rejected: Store raw workspace ids as active map keys | inconsistent with existing upsert normalization and lookup guards.
Confidence: high
Scope-risk: narrow
Directive: Any activeSessionsByWorkspace lookup should use the normalized workspace key, matching insertion.
Tested: git diff --check
Not-tested: Local tests per project policy

* Harden CI Zig downloads against transient upstream failures

CircleCI and the activation workflow both depend on ziglang.org tarballs during remote macOS setup. A transient 500 from that host failed the debug build before any project code compiled, so the install path now retries downloads and avoids unnecessary Homebrew update/cleanup churn on CircleCI.

Constraint: CI must be made green remotely without running local tests or local xcodebuild.

Rejected: Push an empty commit to rerun CI | would leave the same upstream download flake unchanged.

Confidence: high

Scope-risk: narrow

Directive: Keep Zig installer retries in remote CI setup paths; failures here happen before project build logic runs.

Tested: git diff --check

Not-tested: Local tests and local builds not run per repository/user policy.

* Cover stale Claude session-end lifecycle

Greptile identified that stale SessionEnd exercises a different clear-state path than stale Stop. The existing active-session guard already blocks the mutation, so the regression now drives that hook directly and asserts the active /clear session keeps its status, PID, and notifications intact.

Constraint: Do not run local tests; CI is the verification source for this branch.

Rejected: Add another Swift integration test | the existing Python hook harness already executes the CLI handler through the socket path used by CI.

Confidence: high

Scope-risk: narrow

Tested: Not run locally per repo policy.

Not-tested: Local test execution.

* Stop activation CI from stalling on Zig downloads

The activation workflow was cancelled before build because repeated ziglang.org transfers crawled for the full job timeout. Prefer Homebrew's pinned zig@0.15 bottle on macOS runners, then keep the direct tarball path as a bounded fallback with connection, total-time, and minimum-speed limits.

Constraint: The failed check never reached project build or tests; the only failing surface was CI tool bootstrap.

Rejected: Increase the job timeout | it would hide the bootstrap failure and delay feedback.

Confidence: medium

Scope-risk: narrow

Directive: Keep activation workflow tool bootstrap bounded so performance CI reaches the benchmark or fails quickly.

Tested: git diff --check

Not-tested: Local workflow execution, per repository and user instruction.

* Gate Claude session-end cleanup on the consumed workspace

Greptile noted that session-end computed the current-session guard from the fallback workspace while clearing the consumed session's workspace. Move the guard next to the mutation target so stale cleanup and visible cleanup always evaluate the same workspace identity.

Constraint: This is follow-up review hardening on the existing active-session model.

Rejected: Collapse activeSessionsByWorkspace into sessions in this PR | per-workspace current-session lookup is the intended lifecycle boundary for stale event gating.

Confidence: high

Scope-risk: narrow

Directive: SessionEnd visible cleanup must be gated against the workspace being cleared, not an earlier fallback lookup.

Tested: git diff --check

Not-tested: Local test execution, per repository and user instruction.

* Gate Claude session-end cleanup on consumed workspace

A late SessionEnd can be resolved through fallback surface lookup, so the workspace used to find a record is not always the workspace whose visible state would be cleared. Move the staleness check after consume() and evaluate it against the consumed session's workspace, where the clear_status and notification cleanup actually run.

Constraint: Hook events are delivered by short-lived CLI processes and must tolerate stale or partial Claude payloads

Rejected: Keep the pre-consume fallback workspace guard | it can validate one workspace while clearing another

Confidence: high

Scope-risk: narrow

Tested: Added Swift integration regression for stale SessionEnd fallback cleanup

Not-tested: Local tests not run per repository policy

* Make stale Claude session-end test consume the seeded session

Greptile caught that the Swift regression used an unknown session id, so the hook returned before reaching the intended consumed-session visibility guard. Use the seeded stale session id in the SessionEnd payload so the test exercises consume(), then verifies that stale visible cleanup is blocked.

Constraint: Address high-priority review feedback without running local tests.

Rejected: Leave Python-only coverage | the Swift regression would continue passing for the wrong reason.

Confidence: high

Scope-risk: narrow

Directive: Stale session-end regressions should consume a known stale session before asserting visible cleanup is skipped.

Tested: git diff --check

Not-tested: Local tests per repository and user instruction

* Cover fallback Claude session-end consumption

The stale SessionEnd regression should prove the handler consumed the stale session through fallback lookup before deciding whether visible state may be cleared. Use an unknown late session id and assert the seeded stale session is removed from the store, so the test cannot pass without exercising the consumed-workspace guard.

Constraint: Review feedback flagged the prior Swift regression as able to pass without covering the intended guard

Rejected: Use the stored stale session id directly | that only covers the ordinary mapped-session stale path

Confidence: high

Scope-risk: narrow

Tested: Not run locally per repository policy; CI will run the Swift regression

Not-tested: Local XCTest execution

* Keep Claude clear ownership panel-scoped

The clear SessionStart path now owns the active Claude boundary only for explicit clear events, so late startup/resume SessionStart events from the previous session cannot reclaim the workspace before their stale Stop or SessionEnd arrives. The same clear path now passes the resolved surface id into status updates so split panels receive the Running state in the intended pane.

Constraint: Local test execution is disallowed by repository policy; CI remains the behavioral gate.

Rejected: Let every SessionStart mark active | late non-clear events can overwrite the clear boundary.

Rejected: Drop fail-open isCurrent behavior | transient store errors should not hide legitimate current status updates.

Confidence: medium

Scope-risk: moderate

Directive: Do not let non-clear Claude SessionStart events replace an explicit /clear active boundary without adding event ordering metadata.

Tested: python3 -m py_compile tests/test_claude_hook_clear_running_status.py; git diff --check; conflict marker scan.

Not-tested: Local Swift/unit/UI test execution per repo policy.

* Protect Claude clear state from stale session cleanup

Late hook events can arrive after an explicit /clear boundary. The SessionStart handler now skips PID registration when the event is stale against the active session, and SessionEnd consumption preserves the active session when the incoming turn id is older than the stored active turn.

Constraint: Local test execution is disallowed by repository policy; CI remains the behavioral gate.

Rejected: Clear active ownership before checking currentness | same-session stale SessionEnd would fail open and apply cleanup.

Rejected: Keep prefix-only command assertions | option ordering changes would make the regression test brittle.

Confidence: medium

Scope-risk: moderate

Directive: Do not consume a Claude session or replace its PID from a hook event that is stale relative to active session/turn state.

Tested: python3 -m py_compile tests/test_claude_hook_clear_running_status.py; git diff --check; conflict marker scan.

Not-tested: Local Swift/unit/UI test execution per repo policy.

* Allow new Claude sessions to replace stopped owners

A stopped Claude turn must keep the same session eligible for the next turn, but it must not strand the workspace if that process exits before session-end. Mark stopped ownership as replaceable and let only session activation paths use that escape hatch; clear-session ownership remains non-replaceable so stale pre-clear events stay blocked. Session-end fallback cleanup now checks the consumed session id so missing input session ids do not fail open.\n\nConstraint: /clear SessionStart must continue to suppress stale pre-clear startup, stop, and session-end events\nRejected: Clear active ownership on Stop | breaks same-session multi-turn prompt-submit currentness\nConfidence: medium\nScope-risk: narrow\nTested: git diff --check; conflict-marker scan\nNot-tested: local XCTest per repo policy; CI will run cmux unit regressions

* test: cover codex hooks TOML features section

* fix: harden hook config and auth token cache

* test: cover sign-out browser auth loading cleanup

* fix: cancel browser auth on sign-out

* test: cover codex config read failures

* fix: fail closed on codex config read errors

* test: cover auth sign-out callback race

* fix: discard auth callback after sign-out

* fix: keep claude subcommands out of hook injection

* fix: dismiss stale sparkle update replies

* fix: redact auth logs while preserving observability

* fix: reset update checks and guard sign-out races

* fix: preserve update metadata from driver state

* fix: await auth token assertions before comparing

* fix: address wrapper and auth review feedback

* fix: address session and config review feedback

* ci: retrigger pending checks

* fix: clear stale ime and auth token state

* fix: clean legacy codex hooks config

* test: cover legacy codex hooks markers

* fix: clean empty codex features table

* fix: preserve browser key reentry dispatch

* Fix new-workspace caller window routing (#4042)

* test: cover new workspace caller routing

* fix: route new workspace to caller context

* Add iMessage workspace insertion regression test

* Reset Kitty keyboard mode at shell prompt boundaries (#3870)

* Prove stale Kitty keyboard state leaks CSI-u key bytes

The regression exercises a hosted Ghostty terminal, leaves Kitty keyboard protocol enabled as a crashed TUI would, mirrors the clear-history socket handler clear_screen path, and captures raw PTY stdin bytes for a plain c key. Current behavior should encode CSI-u instead of a single ASCII byte, making the test fail until the protocol state is reset at the shell prompt boundary.

Constraint: Regression must cover PTY input bytes, not source text shape
Confidence: high
Scope-risk: narrow
Directive: Keep this test on the real ghostty_surface_key path; sendText alone bypasses the keyboard encoder
Tested: Manual current-main repro captured c9;1:3uc9;1:3uc9;1:3u after Kitty enable plus clear-history
Not-tested: Local unit execution deferred to CI per requested red/green workflow

* Reset stale Kitty keyboard mode at prompt boundaries

A crashed TUI can leave Ghostty's Kitty keyboard protocol stack pushed after clear-history, causing normal shell input to be encoded as CSI-u. Resetting the stack from the shell prompt hook makes the prompt boundary the ownership point for returning interactive shells to plain byte input.

Constraint: Fix must run through shell integration because Ghostty keeps protocol state inside the terminal surface

Rejected: Reset only in clear-history socket path | stale state also leaks after any crashed TUI returns to prompt

Confidence: high

Scope-risk: narrow

Directive: Keep prompt-boundary reset paired across bash and zsh integrations

Tested: Not run locally per repository testing policy; regression added in prior commit

Not-tested: CI not yet completed

* Clarify Kitty reset fixture failures

The stale keyboard regression now fails at the fixture boundary if the zsh integration does not emit the expected reset bytes, instead of falling through to a misleading PTY byte mismatch.

Constraint: Repository policy forbids local test execution for this PR loop

Confidence: high

Scope-risk: narrow

Tested: Not run locally per repository policy; CI will run the affected XCTest

Not-tested: Local XCTest execution

* chore: retrigger Vercel checks

* Add Kitty reset shell hook coverage

* Reset all terminal keyboard protocols at prompt

* Fix terminal keyboard reset test expectations

* Clarify disabling agent session auto-resume for #3640 (#3991)

* docs: explain disabling agent auto resume

* docs: name auto resume config path

* Fix stale restored agent resume state

* Harden restored agent hook liveness

* refactor: share restored agent normalization

* Honor iMessage workspace ordering and previews

* Add workspace cwd inheritance setting (#3921)

* feat: add workspace cwd inheritance setting

* fix: align workspace cwd setting key naming

* fix: apply workspace cwd setting to detached creation

* fix: expose workspace cwd inheritance setting

* fix: route pane break through detached workspace creation

* fix: keep pane break response pane ids non-null

* fix: distinguish pane break resolution errors

* Approve installed Codex hooks (#4035)

* Approve installed Codex hooks

* Address Codex hook trust review feedback

* Avoid tomllib in Codex hook tests

* Align Codex hook trust test mirror

* Harden Codex hook trust ownership

* Preserve legacy Codex hook cleanup

* Fix workspace unit test after merge

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Revert "Approve installed Codex hooks (#4035)" (#4074)

This reverts commit e4546b7675a4ffa5a41a5429218b60f4e7644e21.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Fix workspace unit test transfer resume state (#4076)

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Clarify in cmux --help that reload-config covers Ghostty config too (#4060)

* Clarify cmux help that reload-config covers Ghostty config too

`cmux reload-config` reloads BOTH ~/.config/cmux/cmux.json and Ghostty
config (~/.config/ghostty/config) and refreshes terminals in place, but
the help/docs only mentioned cmux.json. Agents (and humans) reading the
help would think they had to restart cmux after editing Ghostty config.

- cmux --help "Agent Help" now tells agents where Ghostty config lives
  and that reload-config picks it up live.
- cmux docs settings, cmux settings path, cmux config --help now list
  ~/.config/ghostty/config as a related (not cmux-owned) location and
  describe reload-config's actual scope.
- cmux schema sidebarAppearance.tintOpacity description now notes it's
  sidebar-only, and points to Ghostty background-opacity / blur for
  terminal transparency.
- skills/cmux/SKILL.md mirrors the wording.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Align ghostty_config JSON shape across CLI surfaces

Cursor Bugbot and Greptile both flagged that `cmux settings path --json`
emitted `ghostty_config` as a string while `cmux docs settings --json`
emitted it as an object {path, note}. An agent reading both outputs with
the same key expectation would have to special-case the type.

Standardize on the object shape with `path` and `note` in both, matching
docsPayload. This is the agent-discoverability path the PR is trying to
make reliable, so making the shape consistent is on-purpose.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Use canonical Ghostty config key background-blur (not background-blur-radius)

CodeRabbit flagged that `background-blur-radius` is outdated. Verified
against the Ghostty submodule at ghostty/src/config/Config.zig: line 70
declares `background-blur-radius` as a compatibilityRenamed alias for
`background-blur`. The current canonical key is `background-blur` and it
accepts the same integer value (e.g. `background-blur = 20`).

Update the two docs that introduced the alias name:
- skills/cmux/SKILL.md
- web/data/cmux.schema.json (sidebarAppearance.tintOpacity description)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Add nucleo FFI command palette benchmark

* Open right sidebar tools as panes (#4065)

* Open right sidebar tools as panes

* Remove unreachable sidebar pane commands

* Fix sidebar pane unit test build

* Address sidebar pane review feedback

* Fix vault pane focus tracking

* Address right sidebar pane review followups

* Use modern sidebar pane flash observer

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Save crash diagnostics under cmux state (#4077)

* Save crash diagnostics under cmux state

* fix: key GhosttyKit artifacts by crash path

* fix: pin cmux crash GhosttyKit archive

* fix: mark crash breadcrumb scan concurrent

* fix: keep crash scan compatible with Xcode 16

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Menubar global search P1 (#3908)

* Ship local global search as a remappable menubar flow

Phase 1 needs browser and markdown value without terminal scrollback, so the index owns durable FTS5 upserts while AppDelegate keeps one navigation path from palette rows to focused panels. The global shortcut is wired through the existing shortcut settings instead of a standalone Carbon shim so Settings and cmux.json remain authoritative.

Constraint: Phase 1 excludes Ghostty terminal scrollback capture

Constraint: User required no local test execution and no reload before CI is green

Rejected: Hardcoded GlobalSearchHotkey shim | violates KeyboardShortcutSettings policy

Confidence: medium

Scope-risk: broad

Directive: Keep future terminal capture feeding SearchIndex documents through GlobalSearchCoordinator rather than adding another palette/navigation path

Tested: git diff --check; python3 -m json.tool Resources/Localizable.xcstrings; python3 -m json.tool web/data/cmux.schema.json; plutil -lint GhosttyTabs.xcodeproj/project.pbxproj

Not-tested: Local unit/UI tests and tagged app launch per task constraints

* Remove duplicate search refresh work

Cursor review pointed out that the menubar toggle and palette onAppear both refreshed the live index. Keeping the refresh in the palette lifecycle avoids resetting browser debounce tasks while still indexing each time the palette opens, and removing the unused workspace delete API keeps the storage surface honest.

Constraint: Review feedback came from PR #3908 after the first CI pass started

Rejected: Keep both refresh calls | causes avoidable debounce cancellation and slower browser result availability

Confidence: high

Scope-risk: narrow

Directive: Add workspace-level deletion only when a real workspace teardown caller is wired

Tested: git diff --check; python3 -m json.tool Resources/Localizable.xcstrings; python3 -m json.tool web/data/cmux.schema.json; plutil -lint GhosttyTabs.xcodeproj/project.pbxproj

Not-tested: Local tests/build per task constraints

* Fix global search stale index entries

* Address global search review feedback

* Fix search query token mapping compile error

* Fix global search CI failures

* Fix stale unavailable markdown search entries

* Cancel stale markdown search captures

* Cancel global search refresh on dismiss

* Fix global search review followups

* Address global search post-CI feedback

* Preserve markdown panel title search on read failure

* Address global search lifecycle feedback

* Address global search review lifecycle feedback

* Refine global search capture ownership

* fix: address global search review blockers

* feat: show open panels in global search

* fix: cover right sidebar tool panel in search

* Fix cmuxTests: rename restorableAgentAutoResumePending to restorableAgentResumeState (#4068)

* fix: handle repeated assistant imessage completions

* Open supported files in cmux on cmd-click (#4041)

* Open supported files in cmux on cmd-click

* Add cmd-click file preview verification script

* Reuse right pane for cmd-click file previews

* Keep cmd-click UI test terminal after preview focus

* Accept numeric cmd-click test payload values

* Capture cmd-click UI test window snapshots

* Add file-type-aware external open actions

* Address supported file routing review feedback

* Fix external open menu sendability warnings

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Suppress native proxy icon on cmux main windows (#3973)

* Add proxy icon regression test

* Suppress native proxy icon on cmux windows

* chore: retrigger preview deployments

* Refine native proxy icon suppression

* fix: keep titlebar folder icon aligned

* fix: restore titlebar folder icon leading offset

* test: cover folder icon frame replacement

* fix: resync folder icon on frame replacement

* test: cover folder icon ancestor movement

* fix: track folder icon ancestor movement

* fix: address folder icon review feedback

* test: stabilize folder icon ancestor sync

* fix: handle sidebar tool panels in global search

---------

Co-authored-by: austinpower1258 <austinwang115@gmail.com>

* Close browser panels when pages request window close (#4070)

* Add browser self-close restore regression test

* Close browser panels from WebKit close callbacks

* fix: index right sidebar tool panels as titles

* fix: keep web close callback synchronous

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add notification policy hooks

Merged https://github.com/manaflow-ai/cmux/pull/4054

* Fix sidebar unread badge after re-marking notifications (#4084)

* Add sidebar unread notification regression test

* Keep sidebar notification badge live during menu freeze

* Cover sidebar presentation fallback cases

* Limit Cloud VMs by active provider state (#4046)

* test: cover active vm limit with paused freestyle vms

* fix: enforce cloud vm limits by active state

* fix: parallelize cloud vm status refresh

* chore: update web security dependencies

* fix: handle right sidebar tools in global search

* fix: guard cloud vm status refresh races

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Fix Settings search synonyms (#4082)

* Add settings search synonym regressions

* Fix settings search synonyms

* Add shortcut bindings anchor regression

* Cover clickable PR settings search alias

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add tagged debug CLI helper (#4092)

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add unread defer shortcut (#4086)

* Add unread defer shortcut

* fix: address unread defer feedback

* fix: keep manual unread jump explicit

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Document notification hooks default off

Document that notification hooks are off by default and style the config key in localized docs.

* Approve installed Codex hooks after dogfood (#4075)

* Reapply Codex hook approval changes for dogfood

* Notify on Codex plan input requests

* Handle Codex plan question transcript items

* Address Codex hook review feedback

* Recover malformed Codex hook trust blocks

* Avoid duplicate consecutive cmux hook reinserts

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Document session restore behavior

Adds session restore docs, blog, README updates, and review cleanup.

* Use nucleo for command palette search

* Skip unrestorable Claude startup sessions

PR: https://github.com/manaflow-ai/cmux/pull/4079

* Revert "Suppress native proxy icon on cmux main windows" (#4099)

* Revert "Suppress native proxy icon on cmux main windows (#3973)"

This reverts commit 5048440ff44b4edbe328b65403724ff79476b2e6.

* Fix titlebar proxy icon without detached panel sync

* Apply proxy icon override to fallback config

* Restore key regain redraw invariant

* Tune nucleo palette initialism ranking

* Fix terminal portal resize lag (#4102)

* Fix Korean 2-Set terminal arrows (#4095)

* Add Korean 2-Set arrow IME regression

* Restore Korean 2-Set arrow forwarding

* Restore Zhuyin IME command routing

* Address IME review feedback

* Fix Korean IME regression test compile

* Address IME review follow-ups

* Address Bopomofo preedit review feedback

* Avoid idle Zhuyin key suppression

* Remove dead text input wrapper

* Address IME suppression review feedback

* Fix palette stitched highlight precedence

* Add Codex Teams subagent panes

* Open markdown files in preview panels from cmux open (#4085)

* fix: open markdown files in preview panels

* fix: preserve markdown viewer transparency

* fix: mute markdown open-with header button

* fix: align markdown header controls

* fix: align file header controls

* fix: address markdown review feedback

* test: cover opaque text editor alpha

* fix: align header open fallback

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add task manager sorting and program aggregates (#4066)

* Add task manager sorting and program aggregates

* Add sorting to cmux top output

* Add flat TSV cmux top output

* Add coding agent task manager totals

* Make task manager program totals payload-backed

* Recognize agent launcher process names in task manager

* Fix task manager test build helpers

* Recognize Claude versioned launcher processes

* Show loading state before task manager sample

* Recognize versioned agent process names

* Use agent totals for task manager hierarchy icons

* fix: address task manager review feedback

* fix: address follow-up task manager review

* fix: address final task manager review

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Keep manual unread sticky until terminal interaction (#4104)

* test: cover sticky manual unread state

* fix: keep manual unread sticky until terminal input

* fix: show workspace manual unread pane ring

* fix: sync manual unread badge on focus changes

* fix: stabilize manual unread representative fallback

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: austinpower1258 <austinwang115@gmail.com>

* Bump version to 0.64.5 (#4107)

* Fix Pi Vault icon and JSONL titles (#4120)

* test: cover Pi JSONL content block titles

* fix: parse Pi JSONL text blocks for Vault titles

* fix: align Pi JSONL title role handling

* fix: require typed text blocks for Pi titles

* Improve Cloud VM error guidance (#4094)

* Improve Cloud VM error guidance

* Address final Cloud VM review feedback

* Narrow Cloud VM sanitizer env var block

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Keep selected workspace visible after sidebar reorders

* Add sidebar scroll regression for workspace move to top

* Reveal selected workspace after sidebar reorders

* Handle right sidebar tool panels in global search

* Test workspace move to top visibility only

* Refine sidebar reorder scroll trigger

* Add move-to-top notification regression

* Skip no-op move-to-top notifications

* Assert no-op move-to-top keeps order

* Require matching manager for reorder scroll

* Scroll selected workspace on index shifts

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Use transparent backgrounds for file preview panels (#4088)

* Handle right sidebar tools in global search browse hits

* Use transparent backgrounds for file preview panels

* Cover panel theme background preservation

* Fix PDF file preview open menu

* Make file open menu button compact

* Fix PDF open menu chrome button

* Fix PDF open-with chrome click target

* Address file preview chrome review feedback

* Fix PDF background cache invalidation

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Inherit stdin in backgrounded ssh inside startup wrapper (#4135)

* Add regression test for SSH startup wrapper dropping stdin

After PR #3786 backgrounded the ssh invocation inside the startup
wrapper for signal/reconnect handling, `cmux ssh <host>` sessions
stopped forwarding keystrokes from the surface PTY to the remote
shell. Output flowed back (the remote prompt rendered in cmux UI),
but anything typed never reached zsh on the other side, which sat
blocked in `do_poll` on the remote pts.

Root cause: POSIX sh redirects stdin of an async command (`&`) to
/dev/null when job control is off — the default for the `/bin/sh -c …`
that runs the startup wrapper. Without an explicit `<&0` on the
`&`'d ssh line, the local PTY stdin is silently dropped.

This commit adds the failing regression test. The fix follows in
the next commit so CI can prove the test catches the bug.

* Inherit stdin in backgrounded ssh inside startup wrapper

PR #3786 wrapped the ssh invocation in `while :; do … & wait` to enable
SIGHUP/INT/TERM trap handling and reconnect-on-exit-255. Backgrounding
ssh, however, drops its stdin: POSIX sh redirects fd 0 of any async
command to /dev/null when job control is off, which is the default for
the `/bin/sh -c …` host that runs this wrapper.

As a result, output from the remote still flowed back to the surface
PTY (ssh's stdout/stderr stayed wired) but the user's keystrokes never
reached the remote — they hit ttysNNN on the Mac side, kernel echoed
them locally, but ssh's stdin was /dev/null so nothing was forwarded.
zsh on the far side sat in `do_poll` forever.

Explicit `<&0` on both the `command` line and the `( … )` shell-snippet
form overrides the POSIX default and re-attaches the wrapper's own
stdin to the backgrounded ssh process.

Verified with the regression test added in the previous commit, plus
manual repro on Darwin:

    /bin/sh -c 'cat &  wait'           # cat's fd 0 → /dev/null (bug)
    /bin/sh -c 'cat <&0 &  wait'       # cat's fd 0 → parent stdin (fix)

* Add docs search

Adds localized Pagefind docs search with heading anchors and section-aware results.

* Fix Swift interpolation escape in SSH stdin regression test (#4154)

`testSSHStartupForwardsStdinToBackgroundedSSH` used `\"<empty>\"` inside a
`\(...)` string interpolation. Swift parses `\"` as the end of the outer
literal, breaking compilation of cmuxTests on main:

    Cannot find ')' to match opening '(' in string interpolation
    Unterminated string literal

That kept `ci/circleci: macos-unit-tests` red on main after #4135 even
though `macos-debug-build` and `macos-release-build` still passed (the
test target was the only thing affected). The runtime fix (`<&0` on the
backgrounded ssh) is unchanged and was verified end-to-end on a cloud Mac.

Inside an interpolation, the string is already a Swift expression and
literal quotes are unescaped; drop the four backslashes.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Add command palette settings toggles

Adds command palette toggles for boolean Settings rows, including iMessage Mode.

* Ensure Rust toolchain is installed for nucleo FFI builds

* Document nucleo FFI thread and ABI assumptions

* Reuse nucleo index in preview search test helper

* Install Rust for activation perf builds

---------

Co-authored-by: Tobi Lutke <tobi@shopify.com>
Co-authored-by: Austin Wang <austinwang115@gmail.com>
Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Kevin Peng <48529172+kays0x@users.noreply.github.com>

* Address command palette review feedback

* Address command palette review follow-ups

* Fix command palette preview responsiveness

* Build command palette search index off main actor

* Keep small cold palette searches synchronous

* fix: clear panel badges when marking notifications read

* fix: preserve nucleo normalized matches

* fix: preserve typo fallback with nucleo search

* fix: keep search fallback semantics

* fix: keep nucleo aliases authoritative

* fix: preserve typo fallback without ffi contention

* fix: avoid stale palette reset snapshot

* fix: narrow nucleo typo fallback

* fix: address command palette review bots

* fix: preserve palette activation during index refresh

* test: cover nucleo multi-token field matching

* fix: tokenize nucleo ffi queries

* fix: preserve palette activations during index refresh

* fix: sync palette pending state before async search

* fix: keep long keyword matches below title matches

* fix: keep nucleo fuzzy matches within fields

* fix: guard palette preview reuse by fingerprint

* test: skip optional nucleo bundle check without cargo

* fix: keep final palette results uncapped

* fix: respect optional nucleo fallback

* fix: initialize rustup toolchain in release workflow

* fix: run pending palette activation after sync refresh

* Fix command palette duplicate ID indexing

* Remove stale command palette label helpers

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Tobi Lutke <tobi@shopify.com>
Co-authored-by: Austin Wang <austinwang115@gmail.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Kevin Peng <48529172+kays0x@users.noreply.github.com>

This branch was successfully deployed

1 active deployment
Preview – cmux — 50b0c0e2 Deployed May 13, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Korean 2-set IME: arrow keys swallowed in terminal (regression from #3867)

1 participant