2aab0c4aabd8e45bbdaffd4eed484d818e6dc425
14
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
2aab0c4aab |
Stop compiling the GPL crate GPUI drags in behind the framework
Lumbridge is Apache-2.0, and decision 0023 quietly made it link
GPL-3.0-or-later. `crates/gpui/Cargo.toml` at the pinned revision carries
`ztracing.workspace = true` -- unconditional, not optional, not behind a
feature -- and `ztracing` is GPL-3.0-or-later, as are the `zlog` and
`ztracing_macro` it pulls. `sum_tree` asks for it too. The path is the ordinary
Linux build, not an `--all-features` artefact and not a dev-dependency:
lumbridge -> gpui_platform -> gpui_linux -> gpui -> ztracing -> zlog
-> ztracing_macro
`cargo deny check licenses` failed on it, exit 4.
This is the second thing decision 0023 got wrong by reading the manifests of the
crates it added instead of resolving the graph; the first was believing there
were two Zed Git sources when there are five. Both were found by a gate that had
never been run.
There was no feature to turn off, so the choice was to relax the licence policy,
drop the framework, or stop compiling the crate. `ztracing` is now redirected by
a `[patch]` table at `crates/lumbridge-ztracing-shim`, a first-party
zero-dependency no-op under Apache-2.0. `zlog` and `ztracing_macro` were
reachable only through it and leave the lockfile with it.
The shim is small because the usage is: nine `#[instrument(skip_all)]` sites
across `gpui/src/svg_renderer.rs`, `sum_tree/src/sum_tree.rs` and
`sum_tree/src/cursor.rs`, and nothing else. Upstream's own crate compiles to
almost exactly this whenever the `ztracing` cfg is off, which is every build
that is not a Tracy profiling build, so no shipping behaviour is lost. It is a
proc-macro crate deliberately: such a crate can export nothing but proc macros,
so an upstream revision that starts using `ztracing::Span` or
`ztracing::info_span!` fails to compile and names the shim, rather than
resolving to something plausible.
`scripts/workspace-guard.sh` gained a third gate asserting, against Cargo.lock
rather than the manifest, that no `ztracing`, `zlog` or `ztracing_macro`
resolves to a Zed source and that the patch table is still present. `cargo deny`
already checks this, and the duplication is the point: `scripts/ci.sh`
downgrades a missing cargo-deny to a warning unless `LUMBRIDGE_CI_STRICT=1`, and
that is how the licence closure went ungated once already. A `[patch]` is an
unusually quiet thing to lose -- delete the table and everything still compiles,
still passes, and is GPL again.
Removing the three GPL rejections exposed a fourth that had been sitting beside
them and was never reported separately: `libbz2-rs-sys` under `bzip2-1.0.6`,
reached through async-compression <- http_client <- gpui. It is BSD-style and
permissive with no copyleft, and is allowed in `deny.toml` with that reasoning
written down. `cargo deny check licenses sources` is exit 0 for the first time.
The Git-source allowances in `deny.toml` are all still needed; the patched
crate's own source was `zed.git`, which `gpui` still requires.
Decision 0025 records the whole of it.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SPYebLiN2w4TqnHUYGdECq
|
||
|
|
3cb5e1002c |
Name the closure's own context where the framework now demands one
Stage 4 of decision 0023, finished. The dependency swap itself compiled the whole closure on the first attempt; what did not compile was `apps/lumbridge`, and the entire API delta across a ten-month jump turned out to be three signatures over 19 call sites. `Window::focus` is now `focus(&mut self, handle: &FocusHandle, cx: &mut App)` -- 16 sites. `flex_shrink()` takes the factor it used to assume, so it is `flex_shrink(1.0)` -- 2 sites. `Application::new()` is gone with the rest of the entry point, and is `gpui_platform::application()` -- 1 site. That is all of it. Nothing else in the framework's surface moved under this product in ten months. The interesting failure was in the fix, not the framework. Adding `, cx` to every `window.focus` site is right in a method that owns a `cx` parameter and wrong inside `cx.listener(...)`, whose closure is handed its own context as a fourth argument that this code discarded as `_`. One such site capturing the outer `cx` produced 35 errors -- E0596, two E0521s, an E0500, thirty E0501s and two E0524s -- none of which named the actual mistake, and all of which vanished when the discarded parameter was given the name it should have had. Worth recording: a borrow-checker avalanche after a dependency bump is far more likely to be one wrong capture than a framework that changed its ownership model. No crate outside `apps/lumbridge` needed a single change, because none of them imports a gpui type. That boundary was not designed for this and paid for itself anyway. `scripts/workspace-guard.sh` now asserts what it exists to assert. It compared `gpui` against version 0.2.2 from the crates.io registry, which after the swap was a guard that would have failed on the correct state of the tree. It now checks that `gpui` and `gpui_platform` both carry git+https://github.com/zed-industries/zed.git at rev ce48461e -- the same rev, because the pair are one framework snapshot and a disagreement between them would compile against two. Their versions (0.2.2 and 0.1.0) are deliberately not asserted; neither has been bumped upstream in ten months and neither means anything. Both failure modes were induced before being trusted: a wrong expected rev fails on both packages, and a lockfile where only gpui_platform's rev is altered fails on that package alone. One thing to fix next, not here: `cargo deny check sources` now fails. Decision 0023 predicted the move would bring two Git sources; the resolved graph brings four. wasm_thread (via gpui_web and scheduler) and xim-rs, which supplies zed-xim, xim-ctext and xim-parser to gpui_linux, are both unallowed, and zed-industries/scap is in the lockfile too. deny.toml is named in AGENTS.md as a file a decision record governs, so it is left alone and reported rather than edited underneath this commit. The UI gate is green: workspace-guard, fmt, clippy with -D warnings over --all-targets --all-features, and 79 tests passing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SPYebLiN2w4TqnHUYGdECq |
||
|
|
beaffbd0a7 |
Put the layout store behind a boundary, and assert the words it puts on screen
Persistence here has two rules and neither was tested. Losing the layout must never lose the session, so every failure falls back to the first-run workspace and carries on; and the fallback must be visible, so each path returns a status string the footer shows. Nine different strings, one of which is the only notice a user gets that the arrangement they spent a morning on has been dropped, and not one of them was asserted anywhere. The way to find out that a corrupt snapshot reports "invalid layout ignored" was to corrupt one. Ten tests now cover the branches a real machine reaches: nowhere to write, a data directory that cannot be created, a database SQLite refuses to open, a fresh database that is ready rather than restored, a round trip that restores a panel created before the save, and both ways a snapshot can be unusable -- malformed JSON and well-formed JSON describing a workspace with no attached panel, since parsing is not validation and only the second is easy to write by accident. workspace_database_path now reads through EnvSource rather than std::env, for exactly the reason that trait was introduced in lumbridge-settings: the workspace forbids unsafe, set_var is unsafe in Rust 2024, and a precedence rule that cannot be exercised without mutating the process running the test is a precedence rule that stays untested. The one behavioural consequence is that a non-UTF-8 value in LUMBRIDGE_SPIKE_DB, XDG_DATA_HOME or HOME is now treated as unset rather than used as a path; that is what every other setting in the shell already does with such a value. persist_panels stays a method, reduced to the one thing the shell owns: a workspace with no store is not a save failure. It is memory-only, the footer has said so since startup, and replacing that standing message with an error every time a pane moved would say less, not more. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SPYebLiN2w4TqnHUYGdECq |
||
|
|
7bee985279 |
Finish the devices crate, and stop it being invisible
crates/lumbridge-devices was in neither workspace.members nor workspace.exclude, which is not a build error: Cargo simply never looked at it. Its 19 tests had never run, it never inherited unsafe_code = "forbid" or pedantic Clippy, and `cargo check` inside it refused outright with "current package believes it's in a workspace when it's not". Under that cover its lib.rs had been declaring `mod manage;` and re-exporting five items from a manage.rs that did not exist, so the crate did not compile at all. manage.rs is written here to the contract lib.rs already specified. available_actions reads neither DeviceReachability nor Device::presence: an offline device keeps its workspace action and an online one does not gain one, because the registry is the axis and reachability is Tailscale's separate claim. DeviceAction has three variants and no more -- install, reboot and upgrade are absent from the type rather than rejected at runtime, since a variant that exists is eventually rendered as a greyed-out button reading "coming soon" instead of "impossible". A test walks every operation in the module over every fixture device and asserts none of them ever produces LumbridgePresence::Confirmed, which stays unproducible until a lumbridge-remote runtime can answer for itself. RemoteTransport had been declared twice, here and in lumbridge-core, with byte-identical storage strings, because this crate had no dependency on that one. Two enumerations of one choice persisted through the same strings is a drift waiting to happen, so core keeps the single definition -- gaining the default and the picker phrase -- and this crate depends on core and re-exports it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SPYebLiN2w4TqnHUYGdECq |
||
|
|
e5d7a3efd5 |
Add layered settings, and fix a migration mechanism that silently lied
Two things, because the second could not be built on the first. The schema stamp was part of the same execute_batch as the CREATE TABLE IF NOT EXISTS statements, and it wrote unconditionally. Opening an older file therefore added no columns but flipped the version forward anyway; opening a *newer* file stamped it back down and then wrote rows the newer build could not read. Both produced a database whose recorded version was a lie, and every future schema change would have inherited it. Now the version is read before anything is applied, migrations are ordered and forward-only inside one transaction, a newer file is refused with SchemaTooNew rather than downgraded, and a supported version raised without a step to reach it fails at the first open instead of claiming success. Tested by stamping a file at version 99 and asserting both the refusal and that the stamp is left untouched. lumbridge-settings resolves compiled default -> settings.toml -> environment. The environment sits above the file deliberately: decision 0016 calls LUMBRIDGE_CLAUDE_OAUTH=0 "one switch off", and a switch a config file can silently re-enable is not a switch. A pinned value renders disabled and names the variable, rather than accepting an edit that would do nothing. Every field carries a WriteAuthority. Routing all writes through Configure is the obvious design and would hand a layout-only agent the program every future pane launches — the guarantee decision 0006 exists to make. Anything naming a program, path or destination is Human-only, asserted by a test that reads the path rather than trusting the author. Four paths are permanently not settings, with the reason recorded beside each and a test asserting their absence: the usage endpoint URL, the credentials path, the client identity, and the shell program. A configuration file that can redirect where an access token is sent is a credential exfiltration path with a friendly name. Environment access is a trait rather than std::env, because the workspace forbids unsafe, set_var is unsafe in Rust 2024, and the layering rule has to be testable without mutating the process running the test. Verified live with LUMBRIDGE_CLAUDE_OAUTH=0: the account-endpoint row reads off, greyed, "pinned by LUMBRIDGE_CLAUDE_OAUTH". The Advanced page names every file, endpoint and child process Lumbridge touches and states that nothing is sent anywhere else — as a fact, not as a toggle nobody can flip. File loading, comment-preserving writes and editable controls are not in this pass; 0022 records why that order is the honest one. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
1556b87f37 |
Derive the interface palette instead of hardcoding eleven colours
main.rs held eleven `const … : u32` colours, and spikes/floem-shell held a byte-identical copy of the same eleven. Every one was a judgement call made once, and no user could change any of them without recompiling. lumbridge-theme takes a syntax theme's five anchors — background, foreground, comment, and the git added/deleted/modified colours where the theme has them — and derives the whole role set. The frame is the editor background pushed one logarithmic contrast step away from the content, so the work surface is the brightest thing on screen; a theme already at black lifts its surface instead of sinking its frame, which is why a pitch-black theme still shows a seam. Adapted from Buzz's adaptive-theme.ts (block/buzz, Apache-2.0) as a specification, not as copied code. The golden vectors were taken by running the original under Node — a research pass had supplied Python-derived vectors and claimed they reproduced it byte-exactly, and they did not: Python rounds half-to-even, JavaScript rounds half-up, they disagree on exactly one channel value of 22.5, and that decides whether the luminance bisection converges a step early. github-dark's chrome is #171a1d, not #191c20. Provenance colours are separate roles from state colours, with a test holding them pairwise distinct in every theme, because decision 0012 colours a usage reading by where its number came from and never by how alarming it is. This changed no pixels, and that was verified rather than asserted: the only difference between before-and-after screenshots is the digits of a process ID. The check earned its keep — the mechanical rename had rewritten three user-facing strings, turning the sidebar's "ATTENTION · 0" into "theme.attention · 0" and "+ ADD PANEL" into "+ ADD theme.surface". A literal-by-literal diff now confirms zero strings changed. The default theme pins its roles to the previous constants to make that true; the anchors underneath are real, and a test bounds how far the pure derivation sits from them. The terminal ANSI palette keeps its own table, so 29 colour literals remain in main.rs, all terminal. The catalog, its attribution, and the picker are separate work. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
316fa32745 |
Graduate the shell out of spikes/ into apps/lumbridge
The product was spikes/gpui-shell: a cargo workspace of its own, named in the root manifest's exclude list. It inherited neither unsafe_code = "forbid" nor clippy pedantic, and ./scripts/ci.sh never compiled it. Every test written into it silently never ran, and apps/lumbridge was an eleven-line stub printing a version string. Four separate research passes over the sidebar, settings, devices, and theme work independently discovered they were about to write substantial new code into that directory. Graduating first means writing it once. - apps/lumbridge is the product; spikes/ui-shell-model becomes crates/lumbridge-ui-fixture and joins the workspace. - scripts/ci.sh takes --headless and --ui. The headless pass excludes the two UI crates by name, so a contributor changing lumbridge-core does not wait on a window toolkit, and a runner that cannot carry GPUI still gates everything else. A new crate is headless by default rather than silently joining the slow job. - scripts/native-libs.sh replaces the ad-hoc symlink in the launcher, and says which apt package actually fixes the problem instead of working around it silently. The stale libxcb/libxkbcommon symlinks in the old spike target directory are gone; only libxkbcommon-x11.so was ever needed. - deny.toml and cargo deny check licenses. spikes/README.md called GPUI's licence closure a hard gate and the scorecard scored it pending; graduation makes it the product's closure, so it is enforced rather than described. Two rejections were reviewed and allowed with the reasoning recorded in the file: webpki-roots under CDLA-Permissive-2.0 (Mozilla's CA store, data not code, reached through ureq) and libfuzzer-sys under NCSA (reached only under all-features via gpui's image decoder; no shipped build links it). Clippy pedantic across both crates is clean at -D warnings. render was 353 lines; render_sidebar, render_tabs, and render_root come out of it, which the sidebar rework needed anyway. The remaining over-length functions are single declarative element trees and carry per-function allows with reasons, not a blanket suppression. Decision 0017 records the two calls this forces: published gpui 0.2.2 behind an accessibility adapter rather than an unpinned Zed revision and an MSRV bump, and Floem frozen rather than maintained in parity or deleted. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
219c674aea |
Read Claude Code's own quota endpoint, not just its status line
Decision 0015 rejected the account usage endpoint because AGENTS.md forbade reading a harness's credential. The rule was written to stop one program helping itself to another's secrets, and it was catching a legitimate use with it: the user asking about their own subscription, through software they installed to do that. AGENTS.md now states the narrow allowance instead of an absolute the project does not hold, and 0016 records it. The status line stays. It is free and it speaks every turn. What it cannot do is report the per-model weekly limits a Max plan meters separately, or answer at all before a session has taken a turn. The first live reading found the account-wide seven-day window at 38% left and a per-model weekly window at 77% left — a second ceiling the footer previously could not see. Constraints the credential is read under, all enforced in code: access token only, never the refresh token; zeroed on drop, along with the file buffer it was borrowed out of; unprintable by construction, since HarnessError carries no owned strings and AccessToken's Debug is hand-written; identified as lumbridge/<version>, because sending claude-code/2.1.0 would make our traffic indistinguishable from the harness's in Anthropic's logs; and off entirely under LUMBRIDGE_CLAUDE_OAUTH=0. The request runs on a detached thread with a slow refresh and a 429 backoff, so a ten-second round trip cannot stall the transcript follower or make quitting wait on the network, and one surface failing does not fault the other two. Footer polish on top: the harness name prints once per group instead of in front of each of its four windows, each quota carries a short scope pill (5h, 7d, Fable wk, tokens) where an invisible BORDER-weight label used to be, quotas sort ahead of spend, and a window under ten percent turns its headline amber — value colour on the number, provenance colour on the meter, never mixed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
ef52aa7ce2 |
Replace the footer's placeholder usage with a real observation ledger
The footer showed invented percentages. It now shows what two harnesses actually report, or says it does not know. lumbridge-core gains an append-only per-profile UsageLedger and a projection that labels every derived value estimated, withholds a burn rate from a single sample, withholds a window fraction with no reported ceiling, withholds an exhaustion estimate that lands after the reset, and reports an expired window as rolled over rather than freezing its last percentage. A missing fact renders as missing, never as zero. (0012) lumbridge-harness is the impure side: processes, clocks, and untrusted wire text in, observations out. Three adapters: - Codex's account/rateLimits/read over the app-server's JSON-RPC stdio. The client cannot express a request outside a two-variant enum and answers every server-to-client request with -32601, so a harness asking Lumbridge for a credential is refused by construction. (0013) - Claude Code's session transcripts, as a byte-offset tail follower that reports nothing until the backlog is read to EOF — a partially-read backlog is indistinguishable from a burst of spend, and the first run against 20 MB reported forty-six billion tokens an hour. The parser models four counters, so the conversations in those files are not representable. (0014) - Claude Code's five-hour and seven-day subscription windows, via a bridge installed as its statusLine command. 0014 had claimed no such surface existed; it does, and the record is corrected in place rather than quietly edited. Lumbridge does not read the OAuth credential to call the account usage endpoint, which is what comparable tools do — AGENTS.md forbids it, and 0015 says so rather than leaving the gap unexplained. Also in here: a capability-check ordering fix in the workspace reducer, where the applied-request replay table was consulted before the capability check and so answered questions the caller had no right to ask; the GPUI spike wired to the live probes with per-harness gauges and provenance chips; and a launcher that matches its own window by PID, because GPUI sets WM_NAME but not _NET_WM_NAME and a title match never succeeded. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
b838d000db |
feat: add interactive VT and workspace command plane
CI / rust (push) Successful in 3m48s
|
||
|
|
32d190c6c6 |
Add bounded runtime actor and live PTY pane
CI / rust (push) Successful in 3m26s
|
||
|
|
27beb69ff8 |
Build interactive native workspace vertical slice
CI / rust (push) Successful in 1m43s
|
||
|
|
aaa1cb1fa9 |
Spike native shells and define local-first integrations
CI / rust (push) Successful in 1m40s
|
||
|
|
8971ddcf58 | Scaffold Lumbridge architecture and research plan |