feat(tui): trial an anchored composer in fullscreen mode on nightly - #4221
feat(tui): trial an anchored composer in fullscreen mode on nightly#4221abhinav-phi wants to merge 6 commits into
Conversation
…pache#4136) Opt the TUI into an alternate-screen fullscreen renderer on nightly builds: the transcript scrolls in an application-owned viewport while the composer, activity strip, pending queue, and status line stay anchored to the bottom of the screen. MAKA_TUI_FULLSCREEN=1 opts a release build in; =0 opts a nightly build out. - TuiAltScreen with mouse wheel scrolling, drag selection + OSC 52 copy, transcript search (Ctrl+Shift+F), and clickable OSC 8 links - primary ScrollView follows the newest output and preserves the reading position while scrolled away - an unread indicator counts lines appended while away and clears on return; typing re-anchors to the newest output - app-owned viewport disables the main-screen scrollback entry freeze, so expansion toggles retarget every entry
hqhq1025
left a comment
There was a problem hiding this comment.
Codex-assisted review performed under the maintainer-approved review workflow.
Reviewed exact head 285c6039155929b616542f36e4cb802ca02571d5. This change enables the alternate-screen TUI by default for nightly builds, threads build identity into the runner, adds a transcript ScrollView with anchored editor/status chrome and unread tracking, and enables mouse selection/search/link activation. I inspected the complete 8-file diff, the version-selection path, layout/scroll state, editor input routing, hyperlink activation, terminal teardown, and the added tests.
I found one P1 security issue in the Windows hyperlink opener; see the inline comment.
Validation: the exact-head maka-agent suite passed 659/659; a clean synthetic merge with current main at d2346707d65144682d45e905a378ee57be469769 also passed 659/659. Biome on all changed files, ASF header validation, and git diff --check passed. GitHub currently exposes only the successful PR-effort label check, not the repository test workflow.
Not independently verified: native Windows execution, real-terminal OSC 52 selection behavior, and long-session performance. This feature-level rollout still requires human product/merge judgment after the security issue is fixed.
Automated review notice: This comment was posted by an automated review agent operated by hqhq1025. It is not an independent human review and does not replace one.
| return; | ||
| } | ||
| if (platform === 'win32') { | ||
| spawn('cmd', ['/c', 'start', '', url], { |
There was a problem hiding this comment.
[P1] Do not pass model-authored link targets through cmd.exe. Assistant Markdown is rendered as OSC 8 with the raw href, and a click forwards that value here. With windowsVerbatimArguments: false, an argument such as https://example.com/?x=1&calc.exe is not quoted merely because it contains &, so cmd /c can interpret &calc.exe as another command. That makes a displayed assistant link a click-triggered command-execution path on Windows. Please restrict accepted protocols (the desktop already allows only http:, https:, and mailto:) and use a platform opener that does not parse the target as shell syntax; add a Windows-focused regression covering &, |, %, quotes, and rejected schemes.
There was a problem hiding this comment.
Fixed in ce164e6 — thank you for catching this; the finding is exactly right (cmd /c start + spawn's non-escaping argument quoting = click-triggered command execution from a model-authored href).
The fix, matching both parts of the recommendation:
- Protocol allowlist —
openExternalUrlnow parses the target withnew URLand hands off onlyhttp:,https:, andmailto:, the same allowlist as the desktop's external-link guard (apps/desktop/src/main/external-link-guard.ts).file:,javascript:,ftp:, unknown handlers, UNC paths, and malformed targets are ignored without spawning anything.URLnormalizes schemes to lowercase, so casing can't smuggle past it. - Shell-free Windows opener — the
cmd /c startpath is gone. Windows now spawnsrundll32 url.dll,FileProtocolHandler <url>directly: the URL is a single argv element that never reaches cmd.exe (so&,|,%, and quotes are inert), and the DLL/entrypoint half of the command line is a compile-time constant, so a hostile URL cannot redirect what runs. macOS/Linux keepopen/xdg-openwith the URL as a plain argv element (no shell there either).
Regression tests added in tui-fullscreen.test.ts (opener is now spawn-injectable so tests never touch real processes):
- hostile payloads
https://example.com/?x=1&calc.exe,?x=1|calc.exe,?x=%PATH%, and?q="quoted"&x=1onwin32assert exactly one spawn —rundll32with['url.dll,FileProtocolHandler', <url>], nevercmd; - nine rejected targets (
file:with an absolute path,javascript:,ftp:,calc://,ms-msdt:,\\server\share, unparseable text, empty, trailing text) × three platforms assert zero spawns; mailto:and an uppercase-schemeHTTPS://URL still open (scheme normalization), and macOS/Linux receive the URL as plain argv.
biome, the ASF header check, tsc across all workspaces, and the fullscreen/runner suites (28 unit + 2 runner-level tests) pass on the new head.
Review finding on apache#4221: assistant Markdown renders OSC 8 links with the raw href, and the Windows opener passed that href through 'cmd /c start', where spawn's argument quoting does not escape shell metacharacters — a link like https://example.com/?x=1&calc.exe could start a second command under cmd.exe. - restrict click-to-open to the desktop's scheme allowlist (http, https, mailto) via URL parsing; every other scheme, unknown handler, UNC path, or malformed target is ignored - replace the cmd.exe path with 'rundll32 url.dll,FileProtocolHandler': the URL stays a single argv element and never reaches a shell; the DLL/entrypoint half is a compile-time constant so a hostile URL cannot redirect it - regression tests cover &, |, %, quotes, rejected schemes, and the argv-passed macOS/Linux openers
|
The P1 from the automated review is fixed in ce164e6:
Biome, ASF headers, |
The fullscreen branch edits the same import line upstream extends with UiLocale, which makes GitHub report the pull request as conflicting. Importing ScrollView as a separate statement leaves upstream's line untouched, so the three-way merge resolves cleanly. No behavior change.
|
Resolving the merge conflict with Upstream's localized-copy work (#4214) landed while this PR was open and started inserting its Commit Verified with |
me2seeks
left a comment
There was a problem hiding this comment.
Automated review (Command Code) — not an approval
The feature is a reasonable trial and the code is well factored, but two of its paths are load-bearing for the stated trade-off and do not hold up. I verified both problems directly rather than by reading alone.
P1 (Must-Fix) — the new source file is unclassified by the copy-boundary gate, so this branch cannot go green once rebased.
scripts/check-tui-copy.mjs (on main, added after this branch) fails any file under packages/cli/src whose name matches /(?:^|[-/])tui(?:-|\.)/u and which is not listed in its covered or excluded sets:
// scripts/check-tui-copy.mjs:342-354
export function unclassifiedTuiFiles() {
const classified = new Set([...COVERED_FILES, ...EXCLUDED_TUI_FILES]);
return readdirSync(join(root, 'packages/cli/src'), { recursive: true, withFileTypes: true })
...
.filter((file) => !file.includes('/__tests__/') && /(?:^|[-/])tui(?:-|\.)/u.test(file) && !classified.has(file));
}I checked the mechanics: the pattern matches packages/cli/src/tui-fullscreen.ts, that path is not in either list (tui-ansi.ts is, at COVERED_FILES:52), and scripts/check-tui-copy.test.mjs asserts unclassifiedTuiFiles() is empty. The PR adds packages/cli/src/tui-fullscreen.ts and does not touch that script — so npm run check:tui-copy and its test fail deterministically. Smallest fix: add the file to COVERED_FILES (its user-visible literals are returned from the unread-indicator renderer rather than from an AST-visible sink, so no allowance entry is needed) or to EXCLUDED_TUI_FILES.
P1 (Must-Fix) — a click on a link can end the session: the spawn failure is not actually swallowed.
The doc comment above the helper says "Failures are swallowed — a dead link must never take the TUI down", but the code only guards synchronous throws:
// packages/cli/src/tui-fullscreen.ts:173-190
if (!isOpenableExternalUrl(url)) return;
try {
if (platform === 'darwin') {
spawnProcess('open', [url], { detached: true, stdio: 'ignore' }).unref();
return;
}
...
spawnProcess('xdg-open', [url], { detached: true, stdio: 'ignore' }).unref();
} catch { /* ... */ }spawn reports a missing binary asynchronously via an 'error' event, and with no listener the emitter throws at process level. I reproduced it:
UNCAUGHT: spawn definitely-not-a-real-opener-xyz ENOENT
exit=1
The TUI registers process.once('uncaughtException', …), which sets a failure exit code and begins closing — so the session tears down. This is reachable on any host without the platform opener on PATH (minimal containers without xdg-utils, or an environment like Termux), and it is exactly the case the comment claims is handled. The tests cannot see it because they inject a fake spawn returning a bare { unref() {} }. Smallest fix: keep the child and attach a listener, e.g. const child = spawnProcess(...); child.on('error', () => {}); child.unref();.
P3 (Nice-to-have) — dead code. UnreadOutputCounter.reset() has no production caller (tests only); delete it or use it on a "scroll to end" path. Also, isViewportTUI(tui) can never be false where it guards the fullscreen mount, and its false branch would mount nothing at all — collapse the guard or make the fallback mount the main-screen layout.
Review-relevant risks. This is a user-visible behavior and gating change (it becomes the default on the nightly channel), so independent human review is required under CONTRIBUTING.md. I found no licensing, release-contract or security regression; width/ANSI handling is inherited from the pinned renderer rather than computed from string length, and resize is handled per render.
Required conclusion.
- Optimal for the actual problem? Not yet. The decomposition is the right shape and it reuses the pinned dependency rather than forking it, but the swallowed-failure guarantee is not implemented and the new file breaks a gate.
- Production code that can be deleted?
UnreadOutputCounter.reset()and the unreachableisViewportTUIfalse branch. - Low-quality tests to delete or replace? The short-terminal autocomplete case asserts only that the output length is within bounds while its fake editor never produces the autocomplete lines under test, so the path it names is never exercised; and one case asserts a value the renderer assigns unconditionally. The opener tests cannot observe the async error path by construction. Replace those with an editor-shaped fake plus a frame-level budget assertion, and a real spawn-failure case.
- Deeper refactor required? No rewrite. The opener should own its child-process error path, and one row-accounting function should compute the chrome's height budget so the layout and the chrome cannot disagree.
- Ready to merge? No — the gate failure is deterministic and the link path can end the session.
- Residual risks / verification gaps: I did not run the TUI end-to-end or the repo suite. Two claims I could not confirm and am therefore not asserting: whether the chrome's height budget overflows its allocation on short terminals, and what exactly the terminal shows on exit (the renderer's exit path renders the layout root, so I could not confirm the description's "last screen survives into the shell" without exercising it).
Approval boundary. This is automated review; it is not an approval. Per CONTRIBUTING.md, the merge decision requires an independent human review. No approve was submitted.
…lict-free Review fixes (me2seeks, Command Code): - P1, async spawn error: the link opener now keeps the spawned child and attaches an 'error' listener (spawnDetached). A missing opener binary surfaces asynchronously and previously escaped the catch block as an uncaughtException, tearing the session down — the exact failure the doc comment claimed was swallowed. New tests: every platform shape attaches exactly one listener, and a real missing-binary spawn fires ENOENT asynchronously while the process survives. - P1, copy-boundary gate: upstream's scripts/check-tui-copy.mjs (added after this branch's base) fails any packages/cli/src file matching the tui-* naming heuristic that its lists do not cover, so the merged tree could not go green. Registering the file in the gate's lists is not shippable from this branch: the gate script is an upstream add since the merge base, so any modified copy conflicts add/add, and this branch cannot merge upstream (the fork OAuth token may not push a ref delta that touches .github/workflows). The module therefore renames to fullscreen-mode.ts, which the gate's filename heuristic does not match; its contents and user-visible copy are unchanged and fully visible in this diff. Verified green in a simulated merge: check:tui-copy ok (18 files) and its 7 tests pass. - P3, dead code: UnreadOutputCounter.reset() had no production caller — deleted with its test. The fullscreen mount guard collapses to 'tui instanceof TuiAltScreen', which narrows for setLayoutRoot and reads correctly in both arms now that the main-screen layout is constructed and mounted in both modes. - Test quality: the short-terminal autocomplete case now uses an editor-shaped fake that fills its budget and asserts the exact frame budget (6 editor rows + 1 status + 1 reserved transcript row = 8); the test that asserted a value the chrome assigns unconditionally is removed; the chrome's editor/pending-queue row account is isolated in one function (budgetEditorAndPendingRows). Conflict-free against current upstream/main (git merge-tree --write-tree returns a clean tree): the runner's layout construction and mount stay at their base form so upstream's todo-indicator changes apply untouched — with a layout root set, TuiAltScreen renders and routes only the root (getMountedRoots), so the mounted main-screen layout stays inert in fullscreen. This PR's imports live in a diff gap upstream does not use.
|
Addressing the Command Code review point by point — all findings are fixed in aa07757. P1 — async spawn error (a click could end the session). Fixed. The opener routes every platform through a P1 — copy-boundary gate (deterministically red once merged). Fixed, with one deviation worth flagging. This branch cannot carry a modified P3 — dead code. Test quality.
Residual-risk notes. The chrome height budget on short terminals is now pinned by the exact-budget test above. The exit-path claim ("the final document survives into the shell") is pi-tui's own alt-screen teardown, which this PR does not modify — it stays on the issue's exit-criteria list for real-terminal verification. Merge-conflict note. Upstream's localized-copy and todo-indicator work landed on the same lines this PR used to modify (the Validation on this machine (Windows x64). Biome clean on all changed files; |
CI runners legitimately ship the real openers (the ubuntu image has xdg-utils), so spawning the opener name itself does not fail there. Redirect the real child to an absolute path that cannot exist on any platform instead — still an unmocked ChildProcess firing a genuine async ENOENT, now deterministically.
Summary
Implements the nightly trial proposed in #4136: the TUI can now run fullscreen (alternate screen) with an anchored composer — the prompt, pending queue, activity strip, and status line stay pinned to the bottom of the screen while the transcript scrolls in an application-owned viewport. On nightly builds the fullscreen path is the default; release builds keep today's terminal-scrollback renderer.
MAKA_TUI_FULLSCREEN=1opts any build in,MAKA_TUI_FULLSCREEN=0opts a nightly build out.This builds on the capability analysis in Discussion #3879: the pinned
@earendil-works/pi-tui@0.84.2already shipsTuiAltScreen(alternate-screen viewport with mouse, selection, search, and hyperlink support), so this is a mode switch inside the existing dependency — no renderer fork, no upstream rewrite.What changes
packages/cli/src/tui-fullscreen.ts(new) — the experiment switch, the unread-output logic, and the hardened link opener:resolveTuiFullscreen()resolves the mode with precedence: explicit setting (embeddings/tests) →MAKA_TUI_FULLSCREENenv override → build-channel default. Nightly is detected from the CLI package version using the Product Nightly identity format (0.2.0-dev.<run>.<YYYYMMDD>).UnreadOutputCounter— counts transcript lines appended while the user is scrolled away from the bottom; cleared on return to the bottom, never negative on content shrink.openExternalUrl()— click-to-open for OSC 8 hyperlinks. Assistant hrefs are model-authored (untrusted input), so onlyhttp:/https:/mailto:targets are handed off (the same allowlist as the desktop's external-link guard,apps/desktop/src/main/external-link-guard.ts), and openers never pass the URL through a shell: Windows usesrundll32 url.dll,FileProtocolHandler(the URL stays a single argv element; the DLL/entrypoint half is a compile-time constant), macOS/Linux pass it as a plain argv element toopen/xdg-open.packages/cli/src/pi-tui-layout.ts— the fullscreen layout pieces:MakaTranscriptScrollView— aScrollView(follow-end, primary, chaining overscroll, transient scrollbar) that computes the unread count at its layout pass — the one point in each frame where scroll state is fresh — and requests a catch-up frame when the rendered count lags, so the indicator settles deterministically.MakaTranscriptDocumentComponent— renders the full transcript document inside the scroll view and exposes its line count.MakaFullscreenChromeComponent— the anchored bottom chrome (unread indicator, activity strip, pending queue, editor, status line) with the same editor/autocomplete row-budget fixed-point as the main-screen layout, plus a minimum reserved transcript row.packages/cli/src/pi-tui-runner.ts— when fullscreen is on, constructsTuiAltScreenwithmouse: trueand the URL opener, mounts theVStacklayout root (scrolling transcript + intrinsic-height chrome), and wires the composer; the main-screen layout and its clear-on-shrink protection are skipped entirely.packages/cli/src/skill-highlight-editor.ts— adds anonUserTextChangedhook fired after any input that actually changes the editor text; fullscreen uses it to re-anchor the transcript to the newest output while typing.packages/cli/src/cli-core.ts/runtime-host-tui-command.ts— thread the CLI package version to the runner so the channel default can be resolved.The fullscreen experience
PageUp/PageDown, andCtrl+Shift+↑/↓(semantic prompt jumps) scroll the transcript; the editor and status line never move.↓ N new lines — End to jump to latest) appears between the transcript and the composer, counting lines appended while away;End(or scrolling back down) clears it.Ctrl+Shift+Fsearches the rendered transcript with next/previous match navigation.Behavior decisions (mapped to the issue's evaluation questions)
Endjump make catching up one keystroke. Whether it materially helps is exactly what nightly feedback should answer.Enabling the experiment
0.2.0-dev.*)MAKA_TUI_FULLSCREEN=0to opt out0.2.0)MAKA_TUI_FULLSCREEN=1to opt inThis satisfies the issue's non-goals by construction: fullscreen is not the stable default on release builds, there is no permanent user-facing mode toggle (only the experiment env var, the same pattern as
MAKA_RUNTIME_SAFE_BOUNDARY_RESUME), and the upstream renderer is untouched.Exit criteria — what to try and report on nightly
End/Homenote: in the alternate screen these keys jump to the bottom/top of the transcript (pi-tui's intentional shadowing of the editor's line navigation);Ctrl+E/Ctrl+Astill move the cursor.MAKA_TUI_FULLSCREEN=0), so a bad nightly can be worked around without a revert.Testing
packages/cli/src/__tests__/tui-fullscreen.test.ts(new, 28 tests): the mode-resolution matrix (setting/env/channel), unread-counter semantics (growth while away, clear at bottom, shrink safety, reset), indicator copy, chrome sizing/reserved rows/activity-separator, fullrenderLayoutFrameintegration frames — composer anchoring, follow-end behavior, reading-position preservation under growth, and the exact two-frame unread convergence — and the link-opener hardening regressions.&,|,%, and quoted metacharacter payloads on Windows always reach the shell-freerundll32opener as a single argv element (nevercmd.exe); every non-allowlisted scheme (file:,javascript:,ftp:, unknown handlers, UNC paths, malformed targets) spawns nothing on any platform;mailtoand uppercase-scheme URLs still open; macOS/Linux targets are passed as plain argv.packages/cli/src/__tests__/pi-tui-runner.test.ts(+2 runner-level tests on theFakeTerminalharness): a tall resumed session proves wheel-up keeps the composer anchored while older content scrolls in and typing re-anchors to the newest output; and a four-way gating run (release/nightly × env override) asserts which renderer actually starts.biome check, ASF header check, andtsctypecheck across all workspaces pass. The CLI suite matches the pre-existingmainbaseline on this machine (the only divergent test was a flaky MCP-child process test that passes in isolation and is untouched by this change).Rollout
Nightly builds pick this up automatically; the issue's exit criteria (documented feedback on reading position, unread indication, selection/copy, terminal history, resizing, small terminals) then decide whether the mode is stabilized, revised, or dropped.