Commit Graph

142 Commits

Author SHA1 Message Date
Andrex Ibiza, MBA 6d48fbed1b fix(tui): settle tmux clipboard load on child exit
Mark the write-only tmux load-buffer call as resolve-on-exit so a daemonized tmux server cannot retain inherited stdio and force a false timeout after the direct child has succeeded.

Completes the call-site acceptance item from #93134 as a companion to #93148.

Co-authored-by: JoaoMarcos44 <87440198+JoaoMarcos44@users.noreply.github.com>
2026-08-23 18:25:27 -07:00
liuhao1024 27fb1179f8 fix(tui): settle execFileNoThrow on timeout even when a daemon holds stdio
The timeout handler only called settle(124) when resolveOnExit was true.
In the default path the promise waits for 'close', which requires every
inherited stdio handle to close — a daemonized grandchild that kept the
pipes open meant 'close' never fired, and after the timeout SIGTERM
(which only reaches the direct child) nothing settled the promise. The
await hung forever: the clipboard path (setClipboard -> tmuxLoadBuffer
-> osc.ts spawn without resolveOnExit) leaked a pending promise whenever
a spawned tool forked a stdio-inheriting daemon (#93134).

Settle(124) unconditionally in the timeout handler. The settled-guard
makes it a no-op when the child's own 'exit'/'close' won the race, so
normal timeout behavior is unchanged; in the daemon case it becomes the
only exit and returns the same 124 the close path would have.

Also un-skips the documented-hang regression test, with a 30s daemon
sleeper so it genuinely outlives the timeout (and vitest's own 5s test
timeout — before the fix the test fails by timing out, not asserting),
plus an elapsed bound.
2026-08-23 18:25:27 -07:00
hermes-seaeye[bot] 27562ad5f8 fmt(js): npm run fix on merge (#90637)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-20 07:37:56 +00:00
kshitijk4poor 45f11263bd fix(tui): skip the kitty protocol push for Ghostty in the Ink TUI too
Widen the cli.py Ghostty exception to the sibling sites the review found: the Ink TUI pushes CSI >1u at raw-mode entry (App.tsx), on alt-screen exit, and on the extended-keys re-assert path (ink.tsx) for every EXTENDED_KEYS_TERMINALS entry including ghostty - same Alt-stripping bug. New skipKittyKeyboardProtocol() helper in terminal.ts gates the ENABLE push at all 3 sites; the DISABLE (pop) stays unconditional since popping an empty stack is a spec no-op. Also fix the cli.py comment citing the modifyOtherKeys encoding where the kitty CSI-u form (ESC[127;3u) is what the broken path expected, dedupe the quadruplicated Ghostty comment, and update the stale 'mirroring the Ink TUI' docstring. 7 new vitest cases.
2026-08-20 11:39:03 +05:30
hermes-seaeye[bot] eab087c06f fmt(js): npm run fix on merge (#90140)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-19 16:56:58 +00:00
Brooklyn Nicholson 6a3d50c6e0 fix(tui): allow the ESC byte in the SGR param matcher
eslint no-control-regex rejects the CSI regex even though ESC is the
sequence we have to parse.
2026-08-19 11:03:01 -05:00
Brooklyn Nicholson 2725d3225b fix(tui): stop the composer placeholder from sticking Terminal.app into dim
The placeholder hint and its synthetic cursor chip hand-rolled truecolor
escapes ([38;2;r;g;b / [48;2;r;g;b]) and wrote them raw past Ink's depth
layer. Legacy Terminal.app has no truecolor parser — it walks compound
params one by one, so the literal 2 in 38;2;… lands as SGR 2: dim ON,
with no 22m ever emitted. Every frame that painted the placeholder left
the terminal's dim attribute stuck, and subsequent cells rendered dimmed
until an unrelated bold span's 22m happened to clear it — text randomly
flipping dim and back, worst right after the composer empties.

Measured on a live resumed session (PTY capture, params interpreted the
legacy way): 1026 glyphs painted with stuck dim on main, 0 with the fix.

Route both helpers through Ink's own colorize, the same repair colorizeEcho
got for the fast-echo path (gray-accent bug) — the escape now downgrades
with the terminal's real color depth, and a 256-color terminal gets 38;5;N
it can actually parse.

Also harden hermes-ink's transitionAnsiCodes for compound SGRs: real tool
output ships [1;31m-style sequences whose endCode is [0m, dodging the
endCode-based weight detection — parse the params instead (skipping 38/48
extended-color arguments) so a compound bold→dim transition passes through
SGR 22 too.
2026-08-19 11:03:01 -05:00
Austin Pickett 4180c3f326 Merge pull request #89623 from NousResearch/fix/tui-focus-regain-atomic-repaint
fix(tui): heal focus regain without a separate screen clear (supersedes #88596)
2026-08-19 02:56:43 -05:00
Brooklyn Nicholson 31f62d76af fix(hermes-ink): reset SGR 22 when a style transition drops bold or dim
Bold (SGR 1) and dim (SGR 2) are independent terminal attributes that
share a single reset code (SGR 22). ansi-tokenize's diffAnsiCodes models
'same endCode' as 'same slot' — emitting [2m over a bold cell yields
bold+dim instead of dim, and dropping a weight entirely emits nothing.
Every such transition leaves the real terminal diverged from the
StylePool's tracked state, and since later transitions are computed from
that phantom state the corruption compounds and sticks: random spans of
wrong weight/brightness that depend on which cells changed in which
order — the long-standing 'random dimness/opacity changes at whim' in
the TUI.

transitionAnsiCodes() wraps the diff: when a weight flag is removed,
reset the family with SGR 22 and re-apply the target's weights; pure
additions and non-weight styles keep the minimal library diff. Wired
into StylePool.transition (cached per-pair, hot diff path) and the
full-frame renderer.

Proven by an end-to-end probe (LogUpdate frames -> strict SGR
interpreter -> compare cell attrs vs the screen model): 18 divergent
cells on main, 0 with the fix.
2026-08-18 14:08:43 -05:00
Brooklyn Nicholson 43f395a4f8 feat(tui): export Ink's colorize so callers can match its color depth
Anything writing raw SGR past the renderer has to resolve a tone the same
way Ink does — chalk downgrades to the terminal's real depth, and Apple
Terminal takes a bespoke rich-8-bit path on top of that. Sharing the
renderer's own function is the only way a bypass can't drift from it.
2026-08-18 08:42:37 -05:00
h8hawk 298f662108 fix(tui): restore Alt+Enter for newlines (#87066)
* fix(tui): restore Alt+Enter for newlines

Restore Alt+Enter support for inserting a new line in the TUI after the behavior was lost during newer input-handling updates.

Legacy terminals encode Alt+Enter as ESC followed by carriage return. Preserve those bytes as a single tokenizer sequence and parse the result as Return with the Meta modifier so TextInput inserts a newline instead of submitting.

Keep plain CR and LF mapped to unmodified Return, and cover the legacy ESC+CR sequence with a regression test.

* fix(tui): scope legacy Alt+Enter tokenization
2026-08-16 23:01:32 +00:00
brooklyn! 21c1fe6686 fix(tui): modified Enter and bare LF insert a newline in the composer across IDE and macOS terminals (#87854)
* fix(tui): send atomic CSI u for modified Enter in IDE terminals

VS Code/Cursor/Windsurf terminals bound Shift/Ctrl/Cmd+Enter to the
legacy \\r\n sequence, which Ink's parse-keypress split into a
backslash keypress plus a plain Return — inserting a stray backslash and
submitting instead of adding a newline. Emit Kitty CSI u sequences that
encode the modifier atomically, and migrate keybindings users already
have on disk.

Co-authored-by: yatesjalex <yatesjalex@users.noreply.github.com>

* fix(tui): treat a bare LF as a newline in macOS composer terminals

Terminals that can't send a distinct Shift+Enter collapse a modified
Enter / Ctrl+J down to a bare LF. shouldPreserveCtrlJNewline() already
handles the env-detectable cases (SSH, Windows Terminal, Ghostty, WSL),
but plain macOS terminals (Terminal.app, iTerm2 defaults) do the same and
aren't env-detectable, leaving no keyboard-driven newline there. Fold the
return-key decision into shouldInsertNewlineOnReturn() and accept a bare
LF as a multiline fallback on macOS too, keeping CR as submit everywhere.

Co-authored-by: LeonSGP43 <LeonSGP43@users.noreply.github.com>

---------

Co-authored-by: yatesjalex <yatesjalex@users.noreply.github.com>
Co-authored-by: LeonSGP43 <LeonSGP43@users.noreply.github.com>
2026-08-16 17:33:23 +00:00
hermes-seaeye[bot] af585de28e fmt(js): npm run fix on merge (#86801)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-15 07:46:57 +00:00
Teknium 29ce482047 style: eslint --fix import ordering in salvaged IME tests 2026-08-15 00:33:49 -07:00
hanhvs 5dec501c6e fix(tui): stop Vietnamese Telex IME from dropping characters
Third-party Vietnamese IMEs (OpenKey/Unikey/EVKey in Telex mode) recompose
a syllable by emitting an erase burst followed by the finished characters.
Two layers of the TUI input pipeline mishandled this, dropping letters and
leaving a stray space mid-syllable (e.g. "hạnh" rendered as "hạ  ", and
"vương sỹ hạnh" as "vương sỹ hạ  ").

Root causes, both confirmed from real captured byte streams:

1. parse-keypress: an IME often fuses a control byte (\x7f/\b, or even the
   U+202F marker OpenKey injects) with the recomposed text in a single stdin
   read. parseKeypress only recognizes a control key when the whole string is
   exactly that byte, so a mixed chunk fell through every branch, returned
   name:"" with a non-printable sequence, and the composer's printable gate
   discarded the entire chunk — taking the surrounding letters with it. Split
   text tokens on every control byte so the printable runs survive.
   CR/LF are deliberately not split, preserving paste/return semantics.

2. textInput: multi-character (IME/paste) inserts were committed through the
   16ms deferred key-burst path, which raced an interleaved re-render and
   snapped the buffer back to a stale value, dropping the recomposed tail.
   Commit them synchronously. Additionally, the fast-echo "\b \b" backspace
   shortcut desynced the screen when it ran right after an Ink repaint (forced
   by the U+202F marker), stranding the marker glyph; suppress fast-echo for
   the recompose burst that follows an Ink repaint and resume it on the next
   real keystroke.

Tested with real OpenKey and EVKey captures of "vương sỹ hạnh" across read
timings, plus parser unit coverage and an EVKey no-regression guard.
2026-08-15 00:33:49 -07:00
daromaj fffa303db2 fix(ui-tui/ink): don't skip a zero-height box that hosts absolute children
Opening any floating panel in the TUI (`/resume`, `/sessions`, `/models`,
`/skills`, …) with an ambient dock widget loaded shows nothing: the overlay
takes input (Esc is the only way out) but never paints. Part of #69592.

`renderNodeToOutput` has a ghost guard for boxes Yoga squeezes to h=0 whose
sibling lands on the same row — without it, the shorter content leaves the
longer one's tail on screen. The guard returns before rendering children.

The composer's floating panels are `position: absolute; bottom: 100%`
children of a relative Box that also holds the input rows. Opening a panel
sets `$isBlocked`, which unmounts those rows, so the host collapses to h=0
with a sibling on its row — and the guard drops the whole subtree, overlay
included.

An absolute child paints outside its host's layout bounds, so it never
writes the shared row and cannot ghost it. Skip only when the subtree has
no absolute descendant. The walk runs solely inside the h=0 branch, which
is already rare, so it stays off the hot path.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-14 21:22:06 -07:00
Teknium eb20188d2e style: import order + padding lines in terminal.test.ts 2026-08-14 15:10:42 -07:00
Teknium 5d8569d043 fix(tui): gate BSU/ESU on capability for ALL write paths, not just alt-screen
Follow-up to the salvaged #66538 commit: the ZELLIJ env gate fixed
detection, but writeDiffToTerminal still wrapped main-screen frames in
BSU/ESU unconditionally (skipSyncMarkers was only set for alt-screen).
Under Zellij the multiplexer re-chunks the stream, so the markers buy no
atomicity and stale frames leak into main-screen scrollback as the
repeated chrome reported in #66490. The renderer now passes
!SYNC_OUTPUT_SUPPORTED for every write path; supported terminals keep
today's behavior on both screens. Adds emitted-frame regression tests
for both marker modes.
2026-08-14 15:10:42 -07:00
Brian Sweatt d509e6df2f fix(tui): don't trust DEC 2026 synchronized output under Zellij
isSynchronizedOutputSupported() only excluded tmux, so running inside
Zellij under an outer terminal that advertises DEC 2026 (e.g. WezTerm
via TERM_PROGRAM) returned true. Zellij, like tmux, sits between us and
the outer terminal and chunks the stream, breaking BSU/ESU atomicity and
pushing old TUI frames into scrollback as repeated output.

Guard on the ZELLIJ env var (set to the session index, e.g. "0") the
same way we already guard on TMUX. Also thread an optional env argument
through the function so the behavior is unit-testable, mirroring
needsAltScreenResizeScrollbackClear() in the same module.

Closes #66490
2026-08-14 15:10:42 -07:00
John Lussier 96e794aa4a fix(tui): redraw after terminal focus regain 2026-08-14 13:51:26 -07:00
Gabriel Lesperance 68391930d0 perf(tui): bound scroll rendering and preserve anchors 2026-08-03 09:53:51 +05:30
hermes-seaeye[bot] 17e5f7244a fmt(js): npm run fix on merge (#75582)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-07-31 18:54:27 +00:00
ethernet 515e88a80f fix(sec): pin exact npm package versions everywhere 2026-07-31 13:42:03 -04:00
hermes-seaeye[bot] b5ca900508 fmt(js): npm run fix on merge (#74694)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-07-30 08:08:51 +00:00
Brooklyn Nicholson f1a91ad416 fix(tui): split terminal tab title from window title
Terminal.app truncates background tab titles from the left, so a single
long OSC 0 string (marker · session · model · cwd) leaves only the tail
visible — usually the cwd or process name. Emit OSC 1 (icon/tab) with
just the short session title and OSC 2 (window) with the full composed
string, so background tabs show the session name instead of the cwd tail.
2026-07-30 02:31:47 -05:00
Brooklyn Nicholson 4c03d5bff2 fix(tui): keep the Apple Terminal dim fallback inside the active palette
Terminal.app ignores SGR 2, so dim is substituted with a literal color.
That color was hardcoded to #6B7280 — a cold slate that belongs to no
theme. Next to themed text on the same line it reads as a second,
foreign foreground: on a light profile, gray words beside near-black
ones.

Make the tone theme-supplied via setDimFallbackColor, fed the active
muted tone from the same effect that already publishes selectionBg.
#6B7280 stays as the pre-theme boot default so the first frame is
unchanged, and terminals that honor SGR 2 are untouched.
2026-07-25 23:00:03 -05:00
Brooklyn Nicholson 4426d57a84 feat(ui-tui): OSC-10 foreground polarity tiebreaker for transparent terminals
Transparent profiles make OSC-11 useless (xterm reports the unset default,
pure black, regardless of the composited surface) so polarity detection
lagged editor theme flips. OSC-10 reports the theme's REAL foreground on
those hosts — its luminance reveals the pole. hermes-ink grows a foreground
slot (shared reportedColorSlot factory), App.tsx queries both in the
startup batch (background first so a trusted answer wins without churn),
and the app commits an inferred pole only when the background was
distrusted AND the foreground is decisive (bright=dark theme, dark=light;
mid-grays and #000/#fff defaults commit nothing). User pins still outrank.
2026-07-21 16:36:57 -05:00
Brooklyn Nicholson cd05498e2c feat(ui-tui): background-aware theme adaptation + paired palettes + /theme pin
OSC-11 asks the terminal for its actual background at startup (env
heuristics are blind on xterm.js hosts) and the theme re-derives against
the answer: desktop-contract adaptation (contrast floors + fill polarity),
a shared list-row selection primitive instead of per-picker panel fills,
paired light_colors/dark_colors skin blocks with a machine audit, and a
/theme auto|light|dark pin (display.tui_theme) for hosts whose probe lies.
E2E coverage for the OSC reply chain + /theme-info diagnostics.
2026-07-21 16:36:57 -05:00
Austin Pickett 2f6a4e099b fix(tui): recognize standard DSR cursor position reports (supersedes #48762) (#67731)
* fix(tui): recognize standard DSR cursor position reports in input parser

The CURSOR_POSITION_RE regex only matched DECXCPR reports (CSI ? row;col R)
but not standard DSR reports (CSI row;col R without the ? marker). Terminals
that respond to CSI ? 6 n with the plain DSR form had their cursor position
reports fall through to parseKeypress, where they were inserted as literal
text — garbling the composer input with escape sequences like ESC[22;1R.

Fix: make the regex match both forms. For the standard form (no ?), only
treat it as a cursor position report when row > 1, since modified F3 keys
(Shift+F3 = CSI 1;2 R, etc.) always use row 1 and are genuinely ambiguous
with row-1 cursor reports.

* fix(tui): reject invalid row-zero DSR cursor position reports

Follow-up to the standard-DSR recognition fix. The row guard rejected
only row === 1, which let CSI 0;col R (row 0, no ? marker) through and
misclassified it as a cursorPosition report. Terminal coordinates are
1-indexed, so row 0 is an invalid DSR report and must remain
unclassified.

Change the guard to row <= 1 to match the stated 'row > 1' semantics,
and add a boundary test asserting CSI 0;col R is not emitted as a
response.

Supersedes #48762; incorporates review feedback from that PR.

---------

Co-authored-by: Alex Yates <43525405+yatesjalex@users.noreply.github.com>
2026-07-19 19:35:20 -04:00
Teknium 46d16f4c28 fix(tui): recover mouse tracking without a resize via DECRQM watchdog (#66080)
When the terminal's own 'disable mouse reporting' toggle (or an external
app / tmux) clears the DEC mouse modes, a mouse-only user is deadlocked:
every existing recovery trigger (resize, >5s stdin gap + keypress,
raw-mode bounce) needs stdin — and mouse reporting being off is exactly
why no stdin arrives. Users had to resize the window to scroll again.

Fix: a mouse-mode watchdog in App that DECRQM-probes mode 1000 every 2s
while tracking is expected on. If the terminal reports the mode RESET,
reassertTerminalModes() re-arms tracking — the same recovery a resize
performs, without the resize. Probes are skipped whenever a mouse/wheel
event arrived within the interval (tracking provably alive → zero query
chatter during normal use), never fired while paused for an editor
handoff or when /mouse off was chosen, and the watchdog permanently
disables itself on terminals that don't answer DECRQM (DA1-sentinel
resolution via the existing timeout-free TerminalQuerier).

Terminals whose toggle merely gates event delivery report SET, so an
active user toggle is never fought; terminals whose toggle clears the
modes report RESET after re-enable and recover within ~2s.
2026-07-16 22:25:50 -07:00
github-actions[bot] 75f45a0692 fmt(js): npm run fix on merge (#65229)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-07-15 21:40:56 +00:00
ethernet 214cbf77f0 refactor(lint): hoist shared eslint + prettier config to root 2026-07-16 01:42:02 +05:30
ethernet 7b3f3047ab feat(ci): run JS tests in CI, add npm run check in ws root 2026-07-13 17:22:17 -04:00
xxxigm 18297899d7 fix(tui): drop ink-text-input re-export from @hermes/ink entry-exports (#31227)
The dashboard TUI bundle hung at startup with only 141 bytes of ANSI
reset sequences and a blank screen forever. Root cause: esbuild's
lightweight `__esm` helper at the top of `dist/entry.js` does not
await nested async init, so a circular async cycle in the module
graph never resolves. The cycle came from re-exporting
``TextInput`/`UncontrolledTextInput`` from `'ink-text-input'` here —
that npm package depends on the upstream `ink` package, whose graph
loops back through React + our in-tree `@hermes/ink` ink fork. The
result: `init_entry_exports` was emitted as `async … await
init_build4()` (where `build4` is `node_modules/ink-text-input/build`),
and the top-level `await Promise.all([init_entry_exports().then(...)])`
in `src/entry.tsx` deadlocked waiting on the dangling Promise.

Nobody in `ui-tui/` actually imports `TextInput` from `@hermes/ink` —
the composer uses the in-tree `src/components/textInput.tsx` widget
instead. Drop the re-export from the source so the bundle no longer
inlines the upstream ink graph at all. Callers that legitimately want
the upstream widget can still import it from the dedicated
`@hermes/ink/text-input` subpath, which sits outside `entry-exports`
and so does not get inlined into consumers' bundles.

After the fix:
* `dist/entry.js` shrinks from 2.9MB → 2.4MB (~11.5k fewer bundled
  lines) with zero `async __esm` wrappers remaining.
* `init_entry_exports` is now a synchronous `__esm` module.
* The bundle's top-level await chain resolves in ~30ms instead of
  hanging.
2026-07-01 02:10:32 -07:00
talmax1124 d2c7760ceb fix(tui): coalesce drag-resize reflow + harden resize-burst heal coverage
Two resize fixes for a steadier TUI under aggressive terminal resizing.

1. Drag-resize flicker (useMainApp): `cols` was synced to
   `stdout.columns` synchronously on every 'resize' event. Each distinct
   width remounts the visible transcript rows (they're keyed on cols so
   yoga re-measures off live geometry), so a drag — which fires a burst of
   resize events — turned into a per-tick remount storm that flickers and
   stutters. Throttle the sync with a leading+trailing edge: the first
   event reflows immediately (stays responsive), the rest collapse to at
   most one reflow per RESIZE_COALESCE_MS (~30fps), and the trailing edge
   always applies the final width so the settled layout is exact.

2. Resize-burst heal coverage (#18449): the existing ink-resize test only
   exercised a single same-dimension event. Add two regressions that drive
   a rapid resize *burst* (wobbling dims that settle back to the start, and
   an isolated same-dimension event with no tree change) and assert the
   renderer converges to a clean erased repaint — screen erased, then
   content repainted after — rather than a partial diff over drifted cells.

   This also relaxes the pre-existing single-event assertion, which
   hard-coded the exact bytes `ESC[2J ESC[H`; the heal legitimately
   interposes `ESC[3J` (erase scrollback) on some recovery paths, so all
   three tests now assert the semantic invariant instead of a byte run.
2026-06-30 16:47:39 -07:00
Teknium 5e7bca95d9 fix(tui): coalesce render frames while stdout backpressure is unresolved (#31486) (#54171)
When the previous frame's stdout.write has not drained (the outer terminal
parser is overwhelmed by a wide CR+LF burst — CJK + ANSI tool output on a
high-context session), the renderer kept writing a new frame every tick. That
piled writes onto an already-backed-up pipe and kept the macrotask queue hot,
starving the stdin 'readable' callback — the observed stdin freeze where the
agent loop keeps running but keystrokes/Ctrl-C are dead.

onRender now coalesces: while pendingWriteStart is non-null (prior write's
drain callback hasn't fired) it skips the frame and retries on the drain tick
instead of writing. A MAX_COALESCED_BACKPRESSURE_FRAMES ceiling forces a write
through after N skips so a terminal whose drain callback never fires (OSError
EIO on flush) self-heals once the pipe recovers rather than wedging forever.
TTY-only; piped stdout has no flow control. Coalesce counter resets on every
real write.

This is the stdout-backpressure strand left open after #54046 fixed the
swallowed-exception strand.
2026-06-28 04:00:22 -07:00
sweetcornna 002357a83f fix(tui): repump stdin after readable handler errors 2026-06-28 00:53:29 -07:00
Brooklyn Nicholson 62fe9fd101 style(desktop,tui): fix all lint/type/formatting issues
Bring apps/desktop and ui-tui to a clean state for typecheck, eslint,
and prettier:

- Run prettier across both trees (printWidth/wrap drift; prettier is not
  CI-enforced for these JS projects, so main had accumulated drift).
- Apply eslint --fix for padding-line-between-statements and perfectionist
  import/export sorting.
- Manual fixes for non-auto-fixable rules:
  - remove unused node:net import in electron/main.cjs (uses Electron net)
  - replace inline `typeof import(...)` annotations with top-level
    `import type * as EnvModule` in two ui-tui test files
  - scoped eslint-disable no-control-regex on intentional sentinel/ANSI
    regexes (mathUnicode.ts, text.ts)
  - resolve react-hooks/exhaustive-deps per-case: correct swapped/missing
    deps, collapse redundant session.* members, and justified disables on
    settings mount-only data-load effects to preserve run-once behavior

No behavior changes; test pass/fail counts are unchanged from the main
baseline.
2026-06-26 01:04:33 -05:00
FT_IOxCS 92a456f711 fix(cli,deps): clear esbuild audit loop
Upgrade the Vite/esbuild surfaces that kept web, ui-tui, and the bootstrap installer on vulnerable esbuild versions, regenerate the root lockfile, and preserve intentional package+lock dependency edits during update lockfile cleanup.
2026-06-15 06:18:27 -07:00
brooklyn! 1e5ff4a577 fix(hermes-ink): disable mouse tracking on raw-mode teardown to stop SGR leak (#42527)
The raw-mode teardown path (rawModeEnabledCount -> 0) disabled
modifyOtherKeys, kitty keyboard, focus reporting, and bracketed paste,
then dropped raw mode and detached the readable listener -- but left DEC
mouse tracking (1000/1002/1003/1006) asserted. With raw mode off and no
reader attached, the terminal falls back to cooked-mode echo, so every
mouse move emits a hover report (DEC 1003) that prints as literal text:
a flood of '35;col;row M' shards over the prompt in a long session.

handleSuspend() already guards against exactly this (it writes
DISABLE_MOUSE_TRACKING before SIGSTOP); the ordinary teardown path
missed the same guard. Add DISABLE_MOUSE_TRACKING to the teardown, and
re-assert tracking on raw-mode re-entry (via the Ink instance's
reassertTerminalModes, which is gated on altScreenActive and idempotent)
so a transient drop->re-add round-trips cleanly instead of silently
leaving the mouse dead.

Adds a regression test driving a real Ink mount: the last raw-mode
consumer detaching must emit DISABLE_MOUSE_TRACKING.

Reported via a community bug report.
2026-06-08 21:31:06 -05:00
Teknium 4ce9caed04 fix(tui): type execFileNoThrow stdio/ChildProcess and make memoryMonitor critical test heap-independent (#40612)
Salvaged from #40415; re-verified on main, tightened, tested.

Co-authored-by: psionic73 <psionic73@users.noreply.github.com>
2026-06-07 18:23:42 -07:00
Brooklyn Nicholson 725290db63 test(hermes-ink): fuzz the tokenizer flush valve against fragment leaks
Hammer createTokenizer with the worst stalls a terminal can produce —
split + flush at every interior byte, and a 200-report byte-by-byte feed
that flushes after every single byte — and assert the two invariants that
make the SGR-leak class structurally impossible: nothing ever leaks as a
text token, and every complete report reassembles whole. A mixed
mouse+keystroke variant proves real input survives the same storm.
2026-06-03 19:38:08 -05:00
Brooklyn Nicholson 6efc7eda57 refactor(hermes-ink): delete now-dead SGR mouse fragment recovery
With the tokenizer reassembling split CSI sequences across a flush (prior
commit), no SGR mouse fragment can reach a text token anymore — terminals
write a mouse report as one atomic sequence, and any read/flush split now
re-joins in the tokenizer buffer instead of leaking. That makes the whole
downstream recovery layer dead code:

- SGR_MOUSE_FRAGMENT_RE, MOUSE_BURST_NOISE_RE, MOUSE_BURST_RESIDUE_RE
- parseTextWithSgrMouseFragments / parseSgrMouseFragment /
  normalizeSgrMouseFragment
- the whole-text mouse-burst noise fast path in parseMultipleKeypresses

Remove all of it (~185 lines) and the tests that only exercised it. The
narrow legacy X10 wheel-tail resynth stays (distinct mechanism, kept with
its own test). This retires the #17701 → #18113 → #26781 → #28463 → #35512
regex hardening chain in favor of the one correct parser fix.
2026-06-03 19:29:42 -05:00
Brooklyn Nicholson de124800a2 test(hermes-ink): drop input-event SGR guard test
The guard it covered was removed in the previous commit (fragments no
longer reach input-event — they reassemble at the tokenizer). Reassembly
is now covered by termio/tokenize.test.ts and the flush-boundary cases in
parse-keypress.test.ts.
2026-06-03 19:24:51 -05:00
Brooklyn Nicholson f354323547 fix(hermes-ink): reassemble split mouse sequences at the tokenizer; drop the regex sink
Root-cause fix for the SGR mouse fragment leak (`46M35;40M...` typed into
the prompt). The leak was never really about the fragments — it was the
flush emitting them. When App's 50ms watchdog fires mid-CSI during a render
stall, the tokenizer was force-emitting the buffered partial as a token and
resetting to ground, so both the prefix and the ESC-less remainder surfaced
as unparseable input.

Make the flush state-aware (xterm.js discipline): a bare ESC still flushes
to the Escape key (the legitimate ESCDELAY case), but a buffer still inside
a multi-byte control sequence (csi/osc/dcs/apc/ss3/intermediate) is NOT
emitted — it's kept so the continuation reassembles on the next feed. A
one-tick truncation valve in createTokenizer.flush() drops a partial that
survives a second flush with no progress, so a genuinely truncated write
can't fuse into the next keypress.

With partials never entering the input stream, the downstream scrubber is
dead code: remove the SGR fragment guard from input-event.ts (both the
original `/^\[<\d+;\d+;\d+[Mm]/` and the consolidated form added earlier in
this PR). The parse-keypress burst-recovery regexes (MOUSE_BURST_*) are now
also redundant but left in place as a safety net for one release; they can
be removed in a follow-up once this soaks.

Tests: tokenize.test.ts proves a mid-CSI flush keeps/reassembles and that a
stale partial is dropped after a second flush and a bare ESC still emits;
parse-keypress.test.ts adds the end-to-end split-then-reassemble case
yielding a single clean mouse event with no leaked key.

Supersedes #29337.
2026-06-03 19:24:28 -05:00
Brooklyn Nicholson 01c010e233 fix(hermes-ink): collapse SGR mouse fragment guards into one flush-aware rule
When App's 50ms flush watchdog fires mid-CSI during a render stall, an
SGR mouse report (ESC[<btn;col;row M/m) is split across stdin chunks: the
tokenizer force-emits the buffered prefix and resets to ground, so both
the prefix and the ESC-less remainder reach InputEvent as nameless tokens.

The previous guard only matched a full `[<\d+;\d+;\d+[Mm]` fragment, so
the flushed prefixes (`ESC[<0;35;`) and the 1-/2-field and leading-`;`
tails (`46M`, `35;46M`, `;46M`) still leaked into the composer as
`46M35;40M...` during long sessions.

Replace the three would-be narrow regexes with one consolidated rule that
covers every split position. A `(?=...\d)` lookahead keeps typed `<`, `[`,
`;`, and `M` safe (no coordinate digit), and the embedded M/m terminator
in the param class leaves stuck-together fragments / prose intact. The
existing `!keypress.name` gate continues to protect real keystrokes, which
arrive one char per chunk with a name set.

Supersedes #29337 (covers the prefix-leak and leading-`;`/1-/2-field tail
cases that PR's two added guards missed).
2026-06-03 19:05:26 -05:00
Brooklyn Nicholson dfba3f3e51 fix(tui): clear selection on right-click copy + group transcript blocks
Two TUI polish fixes.

(1) Right-click copy now clears the highlight.
The right-click handler copied an active selection via onCopySelectionNoClear
(the copy-on-select variant that keeps the highlight during a drag) and never
cleared it, so after right-click-to-copy the selection stayed lit with no
confirmation and a follow-up right-click re-copied the stale range instead of
pasting. A successful right-click copy now clears the selection and notifies;
if the copy fails (no clipboard path) the highlight survives and we fall back
to the right-click paste handler, exactly as before.

(2) Group transcript blocks so boundaries read clearly.
Model replies, reasoning/tool trails, and system/error notes rendered with no
vertical separation, so distinct block types butted together and were hard to
scan. Group adjacent blocks by kind: one blank line opens only where the visual
group changes (model prose <-> reasoning/tool trails <-> notes), while a run of
same-kind blocks renders flush. The rule lives in domain/blockLayout.ts
(messageGroup + hasLeadGap) and is applied intrinsically in MessageLine via a
`prev` prop, which fixes the things ad-hoc per-block margins kept breaking:

  - Streaming stability: the gap is derived from the stable predecessor, never
    the live block's own changing text, so the actively-streaming reply computes
    the same gap while it streams as the settled segment does once it flushes.
    No reflow/jump.
  - Transparent empty trails: a trail hidden by /details, or one carrying only a
    token tally (the finalDetails segment message.complete appends), renders
    nothing and is transparent to grouping (prevRenderedMsg skips it), so there
    are no floating gaps, no doubled gap after a prompt, and no padded space
    above the final reply. In the default/collapsed modes content-bearing trails
    always render, so the grouping is a no-op there.

The virtual-height estimator counts the group-boundary line so scroll math
stays accurate before Yoga remeasures.

ui-tui/src/domain/blockLayout.ts (new), components/messageLine.tsx,
components/streamingAssistant.tsx, components/appLayout.tsx,
lib/virtualHeights.ts, app/useMainApp.ts.

Tests: blockLayout.test.ts (grouping + hidden/empty-trail visibility),
virtualHeights leadGap, app-mouse.test.ts copy behavior. Full ui-tui suite
green apart from 3 pre-existing local/env failures (cursorDrift, ink-resize,
virtualHeights user-prompt-width) unchanged from main.
2026-06-02 22:03:38 -05:00
ethernet a51a7b9b92 fix(node/nix): consolidate workspace lockfile + update all consumers
Consolidate per-package package-lock.json files into a single root-level
workspace lockfile.  Update all consumers:

- Nix: shared src/npmDeps/npmDepsHash in lib.nix; devshell hook stamps
  package.json paths then runs npm ci from root; individual .nix files
  use mkNpmPassthru attrs instead of per-package fetchNpmDeps.
- Python CLI: new _workspace_root() helper so _tui_need_npm_install,
  _make_tui_argv, _build_web_ui resolve lockfile/node_modules from the
  workspace root.
- Desktop: replace --force-build/mtime heuristic with content-hash build
  stamp (_compute_desktop_content_hash via pathspec).  Remove --force-build
  flag.
- Dockerfile: single root npm install; no per-directory lockfile copies.
- CI: nix-lockfile-fix and osv-scanner reference root package-lock.json;
  apps/dashboard → apps/desktop.
- Tests: new test_tui_npm_install.py; desktop stamp tests in
  test_gui_command.py; updated assertions in test_cmd_update.py,
  test_web_ui_build.py, test_dockerfile_pid1_reaping.py.
- Docs: remove --force-build from desktop flag table.

Deleted: apps/desktop/package-lock.json, ui-tui/package-lock.json,
ui-tui/packages/hermes-ink/package-lock.json, web/package-lock.json.
2026-06-02 20:28:18 -04:00
brooklyn! cd067ab91e fix(tui): swallow degraded mouse-burst noise so a stalled loop can't lock the composer (#35512)
* fix(tui): swallow degraded mouse-burst noise so a stalled loop can't lock the composer

When the Node event loop blocks during a heavy render/tool-call burst, stdin
stops being drained. Mode-1003 any-motion mouse reports pile up in the kernel
buffer, get partially read, and arrive as text with the `\x1b[<` prefix AND
coordinate digits chewed off across many partial reads. The existing fragment
recovery (SGR_MOUSE_FRAGMENT_RE) only handles clean `button;col;row[Mm]`
triples, so the degraded shards leak into the composer as typed text — the user
can no longer type or exit until the stall clears.

Captured leak (Windows Terminal, during tool calls):

  M6M35;220;56M6M35;218;56M169;48M;157;47M;44M20;43M79;40M78;40M0M7M35;49;41M
  48;41M;47;40M9;15;32M[I;31M5;211;26M35;211;25M7M;220;1MM0M09;25M24M23M3;22M
  M18M99;26M32MM38M63;44M47MM1;51M M4M54M

Add two recovery layers in parseTextWithSgrMouseFragments / the text-token path:

- MOUSE_BURST_NOISE_RE: whole-text fast path. If a text token is drawn only
  from the mouse-leak alphabet (`[ ] < ; I M m`, digits, spaces) AND carries
  the structural signature of mouse coordinates (>=3 M/m terminators, a digit,
  and a `;`), swallow it wholesale.
- MOUSE_BURST_RESIDUE_RE: swallows pure-noise residue in the gaps between and
  after recovered fragments, so a partially-recovered burst doesn't trail a
  chewed-up tail into the prompt.

All three constraints together preserve real prose: `Mmm MMM mmm yummy` has no
digit/`;`, `see 1;2;3M for details` has disqualifying letters, and
`1234;56;78M9;10;11M` has only two terminators — none are swallowed.

This is defense-in-depth: it stops the leak/lockout regardless of what blocks
the loop. The underlying event-loop stall during streaming is a separate,
still-open issue that needs live-turn instrumentation to root-cause.

* fix(tui): check mouse-burst noise before fragment recovery; drop test cast

Copilot review on #35512:

- MOUSE_BURST_NOISE_RE was only evaluated when parseTextWithSgrMouseFragments
  returned null. A noise blob that contains any intact `<b;c;r M` fragment makes
  fragment recovery return non-null, so the whole-text swallow never fired and
  the code emitted a pile of recovered mouse events instead of dropping the blob
  wholesale (contradicting the comment, and doing extra work mid-stall). Move the
  noise check ahead of fragment recovery so pure-noise tokens are dropped early.
  Add a regression test for a noise blob carrying intact fragments.

- Drop the unnecessary `(e as { isPasted?: boolean })` cast in the test;
  discriminated-union narrowing on `e.kind === 'key'` exposes isPasted directly.

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-05-30 22:27:14 -05:00
Nick 0a83247e9f feat: add TUI session orchestrator
Add a first-class active-session orchestrator for the Ink TUI:

- list, activate, close, and launch live process-local TUI sessions
- hydrate committed and in-flight output when switching sessions
- dispatch a new prompt session from the +new row with session-scoped model picks
- expose a clickable live-session count in the status chrome
- preserve stable row order while initially focusing the current session
- support mouse hit-testing for floating orchestrator overlays
- add backend and frontend regression coverage for the lifecycle and UI helpers
2026-05-26 20:51:59 -07:00