summaryrefslogtreecommitdiff
path: root/src/CHANGELOG.md
diff options
context:
space:
mode:
Diffstat (limited to 'src/CHANGELOG.md')
-rw-r--r--src/CHANGELOG.md75
1 files changed, 74 insertions, 1 deletions
diff --git a/src/CHANGELOG.md b/src/CHANGELOG.md
index 39c2057d..db75ca6b 100644
--- a/src/CHANGELOG.md
+++ b/src/CHANGELOG.md
@@ -2,6 +2,79 @@
## 0.0.2
+- A panic is written down somewhere it survives. Every crash this program has
+ ever had went to stderr and nowhere else, and stderr is the one place it
+ cannot keep anything: in the TTY shell stderr IS the screen, so the trace
+ lands on the grid the terminal is being reset out of and the next `clear`
+ takes it; the SDL and AppKit shells have no terminal at all; a `--detach`
+ session's goes wherever its launcher left it, which is usually nowhere. So
+ the message and the frames behind it are now appended to `crashes` beside the
+ `init` file, under one line naming the build that produced them — version,
+ commit, UTC timestamp, os-arch and pid — which is exactly the set a bug
+ report needs and the set a reporter cannot be asked to reconstruct after the
+ fact. `src/crash.zig` runs inside the panic handler, so it takes no lock of
+ this program's, allocates nothing of its own, and every failure is swallowed:
+ a crash file that could not be written must not become the crash, and stderr
+ still gets its own copy either way. The file carries NO STACK TRACE, and that
+ is measured rather than chosen: `writeCurrentStackTrace` called from a panic
+ handler *before* `defaultPanic` wedges the process at 0% CPU, and
+ `captureCurrentStackTrace` — which looks like the safe half of it — takes
+ `SelfInfo`'s rwlock exclusively on its first call, so a panic inside the walk
+ leaves that lock held and `defaultPanic` waits on it for the life of the
+ process. A crash that becomes a hang is worse than the crash. What makes
+ `defaultPanic` itself survive that is its private `panic_stage`, reachable
+ from nowhere outside `std.debug`, so the frames stay on stderr where they
+ already work. ONE record per process, because the nested panic std's trace
+ printer raises comes back through the handler: the first version of this
+ wrote the real message and then "reached unreachable code" underneath it,
+ which is the panic handler's own second `vaxis.recover()` double-closing the
+ tty — `recover()` never cleared the global saying there was one. That call is
+ guarded now too, in both the panic and the segfault handler, which is a fix
+ older than this file. The AppKit shell got a panic handler of its
+ own in the process: the macOS build roots at `macos.zig`, so the one in
+ `main.zig` had never run there — in the shell with the least useful stderr of
+ the four.
+- A big screen can attach to a detached session. The wire's grid ceiling is
+ 512x128 and no frontend ever clamped to it — the hello carried the window
+ raw — so a 4K display at a small font, which is already past 128 rows, had
+ its geometry refused by the session's decoder as `BadValue`. That path
+ answers with `close(.protocol)` and no `refuse` behind it, so the frontend
+ reported the one thing a bare hangup can mean: "that session hung up on the
+ connect", at a session with all 32 slots free. `client.zig` now asks for the
+ largest grid the protocol carries, which is what its own GEOMETRY note
+ already promises a frontend gets — the session is drawn at its own size in
+ the corner of a bigger window, exactly as when another frontend is the
+ smaller one. A zero geometry is dropped rather than clamped, because the
+ session grid is the smallest common one and a frontend reporting 1 would
+ collapse everybody else: `TIOCGWINSZ` answers 0x0 during a teardown and the
+ tty shell forwarded it, so that was the same mute hangup by another route.
+ The clamp alone would have replaced one bug with a worse one: `max_cols *
+ max_rows` is 65536 and a run's length prefix is a `u16`, so the single grid
+ legal at both bounds is the one grid whose full frame — and an attach always
+ produces a full frame — cannot be described by one run. It panicked on the
+ `@intCast` in a safe build and was illegal behaviour in a fast one. The
+ encoder splits the run instead, which `frameBound` had already paid for, and
+ the protocol version is bumped to 2: the geometry a v2 frontend now asks for
+ is one a v1 daemon panics encoding, so a mixed pair — `zig build` replacing
+ the binary under a running session — meets a `Refusal.version` instead of
+ losing every pane shell the daemon owns.
+- `pardes nosuchfile` opens an editor. It used to return `BadArgs` out of
+ `main`, which std prints as `error: BadArgs` with a return trace under it:
+ indistinguishable from a crash, for a typo, and it left the human with no
+ editor at all. A launch that names nothing now boots one `+Errors` pane
+ filling the window — acme's own vocabulary for output that came from the
+ program rather than from a word somebody clicked — saying `file or directory
+ not found` and the argument AS TYPED, in the directory it was typed in — an
+ output pane's directory is where a `Grep` from it walks, where its `Newtty`
+ spawns and what its `Save` prefills, so a pane rooted at `""` would have
+ pointed all three at `/`. A typo INSIDE pardes is refused by that shell in one
+ line instead: the hand-off block that keeps a pardes from stacking a second
+ full-screen UI inside a pane of the first says in its own comment that a word
+ naming nothing must not get through, and an `+Errors` boot would have made a
+ typo the one input that did. A `chdir` that fails on a directory that really
+ is one is still `BadArgs`: that is a permission problem, not a typo, and the
+ two want different answers.
+
- The macOS trackpad's two verbs trade places: a two-finger click is Exec and
a deep press is Look. Exec is what a hand spends a session doing, so it takes
the gesture that costs nothing, and the verb that goes somewhere is worth one
@@ -40,7 +113,7 @@
environment, whose `PATH` is `/usr/bin:/bin:/usr/sbin:/sbin`, and every pty
shell, `|` filter and language server inherited it — so `yazi` in
`/opt/homebrew/bin` was missing in the app and present in the same build run
- from a shell, which reads as "the Dock build is broken". `shell_bin`
+ from a shell, which reads as "the Dock build is broken". `host_io.Shell`
composes `/etc/paths` then `/etc/paths.d/*` in the order `path_helper`
reads them and adopts the result before the first fork in all four native
hosts. It appends, so an inherited entry is never demoted and a configured