Commit Graph
6 Commits
Author SHA1 Message Date
Metal AgentandClaude Opus 5 3cb5e1002c Name the closure's own context where the framework now demands one
Stage 4 of decision 0023, finished. The dependency swap itself compiled the
whole closure on the first attempt; what did not compile was `apps/lumbridge`,
and the entire API delta across a ten-month jump turned out to be three
signatures over 19 call sites.

`Window::focus` is now `focus(&mut self, handle: &FocusHandle, cx: &mut App)`
-- 16 sites. `flex_shrink()` takes the factor it used to assume, so it is
`flex_shrink(1.0)` -- 2 sites. `Application::new()` is gone with the rest of
the entry point, and is `gpui_platform::application()` -- 1 site. That is all
of it. Nothing else in the framework's surface moved under this product in ten
months.

The interesting failure was in the fix, not the framework. Adding `, cx` to
every `window.focus` site is right in a method that owns a `cx` parameter and
wrong inside `cx.listener(...)`, whose closure is handed its own context as a
fourth argument that this code discarded as `_`. One such site capturing the
outer `cx` produced 35 errors -- E0596, two E0521s, an E0500, thirty E0501s and
two E0524s -- none of which named the actual mistake, and all of which vanished
when the discarded parameter was given the name it should have had. Worth
recording: a borrow-checker avalanche after a dependency bump is far more
likely to be one wrong capture than a framework that changed its ownership
model.

No crate outside `apps/lumbridge` needed a single change, because none of them
imports a gpui type. That boundary was not designed for this and paid for
itself anyway.

`scripts/workspace-guard.sh` now asserts what it exists to assert. It compared
`gpui` against version 0.2.2 from the crates.io registry, which after the swap
was a guard that would have failed on the correct state of the tree. It now
checks that `gpui` and `gpui_platform` both carry
git+https://github.com/zed-industries/zed.git at rev ce48461e -- the same rev,
because the pair are one framework snapshot and a disagreement between them
would compile against two. Their versions (0.2.2 and 0.1.0) are deliberately
not asserted; neither has been bumped upstream in ten months and neither means
anything. Both failure modes were induced before being trusted: a wrong
expected rev fails on both packages, and a lockfile where only gpui_platform's
rev is altered fails on that package alone.

One thing to fix next, not here: `cargo deny check sources` now fails. Decision
0023 predicted the move would bring two Git sources; the resolved graph brings
four. wasm_thread (via gpui_web and scheduler) and xim-rs, which supplies
zed-xim, xim-ctext and xim-parser to gpui_linux, are both unallowed, and
zed-industries/scap is in the lockfile too. deny.toml is named in AGENTS.md as
a file a decision record governs, so it is left alone and reported rather than
edited underneath this commit.

The UI gate is green: workspace-guard, fmt, clippy with -D warnings over
--all-targets --all-features, and 79 tests passing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SPYebLiN2w4TqnHUYGdECq
2026-09-01 13:22:50 -07:00
Metal AgentandClaude Opus 5 beaffbd0a7 Put the layout store behind a boundary, and assert the words it puts on screen
Persistence here has two rules and neither was tested. Losing the layout must
never lose the session, so every failure falls back to the first-run workspace
and carries on; and the fallback must be visible, so each path returns a
status string the footer shows. Nine different strings, one of which is the
only notice a user gets that the arrangement they spent a morning on has been
dropped, and not one of them was asserted anywhere. The way to find out that
a corrupt snapshot reports "invalid layout ignored" was to corrupt one.

Ten tests now cover the branches a real machine reaches: nowhere to write, a
data directory that cannot be created, a database SQLite refuses to open, a
fresh database that is ready rather than restored, a round trip that restores
a panel created before the save, and both ways a snapshot can be unusable --
malformed JSON and well-formed JSON describing a workspace with no attached
panel, since parsing is not validation and only the second is easy to write by
accident.

workspace_database_path now reads through EnvSource rather than std::env, for
exactly the reason that trait was introduced in lumbridge-settings: the
workspace forbids unsafe, set_var is unsafe in Rust 2024, and a precedence
rule that cannot be exercised without mutating the process running the test is
a precedence rule that stays untested. The one behavioural consequence is that
a non-UTF-8 value in LUMBRIDGE_SPIKE_DB, XDG_DATA_HOME or HOME is now treated
as unset rather than used as a path; that is what every other setting in the
shell already does with such a value.

persist_panels stays a method, reduced to the one thing the shell owns: a
workspace with no store is not a save failure. It is memory-only, the footer
has said so since startup, and replacing that standing message with an error
every time a pane moved would say less, not more.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SPYebLiN2w4TqnHUYGdECq
2026-09-01 13:00:46 -07:00
Metal AgentandClaude Opus 5 e5d7a3efd5 Add layered settings, and fix a migration mechanism that silently lied
Two things, because the second could not be built on the first.

The schema stamp was part of the same execute_batch as the CREATE TABLE IF NOT
EXISTS statements, and it wrote unconditionally. Opening an older file therefore
added no columns but flipped the version forward anyway; opening a *newer* file
stamped it back down and then wrote rows the newer build could not read. Both
produced a database whose recorded version was a lie, and every future schema
change would have inherited it.

Now the version is read before anything is applied, migrations are ordered and
forward-only inside one transaction, a newer file is refused with SchemaTooNew
rather than downgraded, and a supported version raised without a step to reach
it fails at the first open instead of claiming success. Tested by stamping a
file at version 99 and asserting both the refusal and that the stamp is left
untouched.

lumbridge-settings resolves compiled default -> settings.toml -> environment.
The environment sits above the file deliberately: decision 0016 calls
LUMBRIDGE_CLAUDE_OAUTH=0 "one switch off", and a switch a config file can
silently re-enable is not a switch. A pinned value renders disabled and names
the variable, rather than accepting an edit that would do nothing.

Every field carries a WriteAuthority. Routing all writes through Configure is
the obvious design and would hand a layout-only agent the program every future
pane launches — the guarantee decision 0006 exists to make. Anything naming a
program, path or destination is Human-only, asserted by a test that reads the
path rather than trusting the author.

Four paths are permanently not settings, with the reason recorded beside each
and a test asserting their absence: the usage endpoint URL, the credentials
path, the client identity, and the shell program. A configuration file that can
redirect where an access token is sent is a credential exfiltration path with a
friendly name.

Environment access is a trait rather than std::env, because the workspace forbids
unsafe, set_var is unsafe in Rust 2024, and the layering rule has to be testable
without mutating the process running the test.

Verified live with LUMBRIDGE_CLAUDE_OAUTH=0: the account-endpoint row reads off,
greyed, "pinned by LUMBRIDGE_CLAUDE_OAUTH". The Advanced page names every file,
endpoint and child process Lumbridge touches and states that nothing is sent
anywhere else — as a fact, not as a toggle nobody can flip.

File loading, comment-preserving writes and editable controls are not in this
pass; 0022 records why that order is the honest one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-01 00:06:06 -07:00
Metal AgentandClaude Opus 5 1556b87f37 Derive the interface palette instead of hardcoding eleven colours
main.rs held eleven `const … : u32` colours, and spikes/floem-shell held a
byte-identical copy of the same eleven. Every one was a judgement call made once,
and no user could change any of them without recompiling.

lumbridge-theme takes a syntax theme's five anchors — background, foreground,
comment, and the git added/deleted/modified colours where the theme has them —
and derives the whole role set. The frame is the editor background pushed one
logarithmic contrast step away from the content, so the work surface is the
brightest thing on screen; a theme already at black lifts its surface instead of
sinking its frame, which is why a pitch-black theme still shows a seam.

Adapted from Buzz's adaptive-theme.ts (block/buzz, Apache-2.0) as a
specification, not as copied code. The golden vectors were taken by running the
original under Node — a research pass had supplied Python-derived vectors and
claimed they reproduced it byte-exactly, and they did not: Python rounds
half-to-even, JavaScript rounds half-up, they disagree on exactly one channel
value of 22.5, and that decides whether the luminance bisection converges a step
early. github-dark's chrome is #171a1d, not #191c20.

Provenance colours are separate roles from state colours, with a test holding
them pairwise distinct in every theme, because decision 0012 colours a usage
reading by where its number came from and never by how alarming it is.

This changed no pixels, and that was verified rather than asserted: the only
difference between before-and-after screenshots is the digits of a process ID.
The check earned its keep — the mechanical rename had rewritten three user-facing
strings, turning the sidebar's "ATTENTION · 0" into "theme.attention · 0" and
"+ ADD PANEL" into "+ ADD theme.surface". A literal-by-literal diff now confirms
zero strings changed.

The default theme pins its roles to the previous constants to make that true;
the anchors underneath are real, and a test bounds how far the pure derivation
sits from them. The terminal ANSI palette keeps its own table, so 29 colour
literals remain in main.rs, all terminal. The catalog, its attribution, and the
picker are separate work.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-31 23:23:30 -07:00
Metal AgentandClaude Opus 5 316fa32745 Graduate the shell out of spikes/ into apps/lumbridge
The product was spikes/gpui-shell: a cargo workspace of its own, named in the
root manifest's exclude list. It inherited neither unsafe_code = "forbid" nor
clippy pedantic, and ./scripts/ci.sh never compiled it. Every test written into
it silently never ran, and apps/lumbridge was an eleven-line stub printing a
version string.

Four separate research passes over the sidebar, settings, devices, and theme
work independently discovered they were about to write substantial new code into
that directory. Graduating first means writing it once.

- apps/lumbridge is the product; spikes/ui-shell-model becomes
  crates/lumbridge-ui-fixture and joins the workspace.
- scripts/ci.sh takes --headless and --ui. The headless pass excludes the two UI
  crates by name, so a contributor changing lumbridge-core does not wait on a
  window toolkit, and a runner that cannot carry GPUI still gates everything
  else. A new crate is headless by default rather than silently joining the slow
  job.
- scripts/native-libs.sh replaces the ad-hoc symlink in the launcher, and says
  which apt package actually fixes the problem instead of working around it
  silently. The stale libxcb/libxkbcommon symlinks in the old spike target
  directory are gone; only libxkbcommon-x11.so was ever needed.
- deny.toml and cargo deny check licenses. spikes/README.md called GPUI's
  licence closure a hard gate and the scorecard scored it pending; graduation
  makes it the product's closure, so it is enforced rather than described. Two
  rejections were reviewed and allowed with the reasoning recorded in the file:
  webpki-roots under CDLA-Permissive-2.0 (Mozilla's CA store, data not code,
  reached through ureq) and libfuzzer-sys under NCSA (reached only under
  all-features via gpui's image decoder; no shipped build links it).

Clippy pedantic across both crates is clean at -D warnings. render was 353
lines; render_sidebar, render_tabs, and render_root come out of it, which the
sidebar rework needed anyway. The remaining over-length functions are single
declarative element trees and carry per-function allows with reasons, not a
blanket suppression.

Decision 0017 records the two calls this forces: published gpui 0.2.2 behind an
accessibility adapter rather than an unpinned Zed revision and an MSRV bump, and
Floem frozen rather than maintained in parity or deleted.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-31 23:05:12 -07:00
karti 8971ddcf58 Scaffold Lumbridge architecture and research plan 2026-08-31 14:37:49 -07:00