Stop the shell asserting things that are not true

The footer was rebuilt on a real ledger two commits ago. The rest of the shell
was never audited the same way, and a multi-agent pass over it found the same
class of defect everywhere else:

- A sidebar card reading "Buzz · lumbridgecode / connected · signed identity"
  in the success colour. lumbridge-buzz is not a dependency of this binary.
- A saved host "amd-server", and a WORKTREES section with five entries and a
  working selector, backed by a lumbridge-git crate that does not exist.
- A first-run workspace of six panes announcing "Codex · runtime / metal ·
  Tailscale SSH", "Claude Code · UI / MacBook Air · local" and a Pi pane on a
  saved host. Every one of them was a /bin/sh, and the machine names were this
  developer's.
- A declared "Pi · spark-1 · laguna-s-2.1" usage profile with no probe of any
  kind behind it. Declaring a profile promises the gap is real; that one could
  never be filled.
- FOOTER_CENTER = "Codex · ChatGPT subscription · 62% window remaining",
  rendered by the Floem shell. Decision 0013 names that exact form as the thing
  that must never be shown.
- The header's PTY count painted green unconditionally, so "0/5 LIVE PTYS" read
  as success. runtime_rows already had the right rule three hundred lines away.
- A browser panel describing itself as "An isolated system-web-engine surface"
  on the chooser screen where you pick it. There is no web engine in this build.

First run is now three real local shells, and a pane claims a harness when one
has actually been launched into it. The seed mapping stays for when that is
possible.

Also removes the only unsafe block in the shell: a test set LUMBRIDGE_*_PROBE
through the environment, which needs unsafe under edition 2024 and silently
disabled both probes for every other test in the binary. Replaced with
UsageFeedOptions passed to start_with.

Clippy pedantic on the spike goes 79 -> 15 against root CI's -D warnings, so
graduating it into the workspace is not gated on a warning cleanup. The four
remaining too_many_lines are the render split, which the sidebar work needs to
do anyway.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Metal Agent
2026-08-31 22:54:24 -07:00
co-authored by Claude Opus 5
parent 219c674aea
commit 834b73e831
5 changed files with 223 additions and 201 deletions
+8 -18
View File
@@ -198,25 +198,15 @@ pub const PANES: [PaneFixture; 6] = [
},
];
pub const WORKSPACES: [&str; 5] = [
"Lumbridge Code",
"Runtime / metal",
"UI spikes",
"ACP adapters",
"Usage telemetry",
];
/// Static footer strings retained only by the Floem comparison shell.
/// The one footer string the frozen Floem shell renders.
///
/// These are layout fixtures, not usage. They are not a usage source and must
/// not be rendered as one: the GPUI shell now derives its footer from
/// `lumbridge_core::UsageLedger`, where every value carries a provenance and a
/// missing fact renders as missing. Delete these once Floem consumes the ledger
/// or the candidate is retired. See decision 0012.
pub const FOOTER_LEFT: &str = "6 panes · 3 remote · 1 needs input";
/// See [`FOOTER_LEFT`]: a layout fixture, not a usage reading.
pub const FOOTER_CENTER: &str = "Codex · ChatGPT subscription · 62% window remaining";
/// See [`FOOTER_LEFT`]: a layout fixture, not a usage reading.
pub const FOOTER_RIGHT: &str = "burn 8.4%/hr · resets in 2h 14m";
/// It replaces three that read like data — a pane census, "Codex · ChatGPT
/// subscription · 62% window remaining", and "burn 8.4%/hr · resets in 2h 14m".
/// Decision 0013 names that exact form as the thing that must never be shown,
/// and a comparison shell rendering a fabricated quota beside a real one is
/// worse than a comparison shell with no footer numbers at all. The GPUI shell
/// derives its footer from `lumbridge_core::UsageLedger`. See decision 0012.
pub const FOOTER_FIXTURE_NOTICE: &str = "layout fixture · no usage source";
#[derive(Clone, Debug, Eq, PartialEq)]
pub struct PaneState {