Found during #155's sweep and recorded there as one line of prose with an
uncommitted proptest seed. This turns it into something that cannot be
lost and that states what is actually known.
Reproduced on main @ e745068 with PROPTEST_CASES=2000 against
rope_matches_crdt_projection_after_arbitrary_edits, then reduced by hand
to five lines: replacing a byte range with IDENTICAL bytes is a textual
no-op but a real CRDT operation, so undoing it advances the CRDT version
while leaving the materialized text unchanged. `undo_crdt_mode` derives
an empty replacement edit and still attaches the op `crdt.undo()`
produced, which trips the proptest's "a no-op edit must have crdt_op =
None" invariant.
The test is `#[ignore]`d rather than asserted-as-correct or left as a
seed, because the resolution is a judgement call I should not make
silently:
- the raw proptest seed is NOT committed, since it would fail the suite
on every run for a case whose correct outcome is undecided;
- the deterministic reduction reproduces without any seed, so nothing is
lost by leaving the seed out.
What the doc comment records, so the next reader need not redo it:
content stays correct (rope and CRDT projection agree either side); both
`crdt_op` consumers read the field unconditionally and do not
short-circuit on an empty range, so replicas still converge; and
`EditorCore::undo` never seeks `edit.range.start`, so no cursor jumps.
The open question is whether the invariant is simply mis-scoped — it was
written for the forward `apply_edit` short-circuit, which returns before
producing an op, and CRDT-mode undo/redo never reach that path. One
artifact is arbitrary either way: `derive_replacement_edit` reports the
empty range at the buffer END rather than at the edit site.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Store a detected major mode on each buffer and expose it through Lua.
Resolve mode-scoped bindings in dispatch, describe-key, and help links,
including exact encoded mode context after entering the help buffer.
Initialize modes once at buffer load, preserve explicit overrides and
clears across switches, and publish the mode through a per-window
statusline provider. Add daemon acceptance for the complete mode lifecycle.
Add compatibility-preserving full-screen ANSI operations, the bounded terminal
screen and input encoders, and a transactional TerminalManager owning one
read-only identity buffer, PTY process, and screen per session.
Drain terminal-owned process events before process.after-tick, retain exact
final output and PID/outcome annotations, reap killed buffers and shutdown
children safely, and enforce buffer-owned read-only checks across ordinary,
host, undo/redo, and CRDT mutation paths.
Cover split parser and grapheme boundaries, screen/reflow/history invariants,
device responses, lifecycle cleanup, and a real adversarial alternate-screen
PTY. Record the fully gated Stage 1 delivery and downstream TUI/GPU contracts.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Typing over a selection composed two edits in Lua —
delete_region() + insert_char() — so it recorded two undo steps:
one undo left the half-replaced text, two restored the original.
Undo granularity is per apply_edit in both modes (v0.1 pushes one
UndoEntry per edit; CRDT commits per edit via export and groups by
commit, with record_checkpoint unused), so the fix is to make
type-over one edit.
New core EditorCore::insert_char_over_region emits a single
EditOp::Replace when a region is active (cursor past the inserted
bytes, selection cleared) and delegates to insert_char otherwise.
The three type-over commands (buffer.newline / tab / self-insert)
call it via a new Lua binding instead of the delete+insert pair.
delete_region and insert_char are unchanged for their other
callers; region-aware backspace/delete already emit one op.
Verified one undo unit in BOTH modes (dual_mode
replace_is_a_single_undo_step covers v01 + crdt — a CRDT Replace is
delete-then-insert internally but one commit) plus an end-to-end
acceptance test through the key-dispatch path.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The last round-tripping editing keys. Same latency profile Enter had:
mid-burst they deferred behind unconfirmed inserts and everything
typed after them flushed in a delayed lump.
Daemon: single-delete CRDT hot path in apply_remote_crdt_op. The
deletion's start byte converts through the post-import doc (the
prefix is untouched); the end byte comes from walking the still
pre-import rope over the deleted codepoint count (reads at most
4 bytes per codepoint, not the file). Compound updates keep the
materialize+diff fallback.
pmacs-gpu:
- optimistic_crdt_delete mirrors the insert path; the shared gates
(optimistic_edit_eligible) and tail (finish_optimistic_edit) are
factored out. optimistic_delete_range predicts exactly one
codepoint — matching buffer.delete-backward/-forward's no-region
behavior — and declines on buffer edges, modifier variants
(C-BS word delete), or a mid-codepoint cursor. Region deletes
keep round-tripping into delete_region via the selection gate.
- Cursor-floor semantics tightened for non-monotonic predictions:
only the exact predicted byte (or another buffer) confirms; plus a
500ms timeout escape hatch — an unconfirmed floor (op dropped by
validation, peer racing the window cursor) now releases instead of
wedging deferred keys forever, falling back to round-trip input
until the next CursorByte resynchronizes.
- Unconfirmed-edit journal rebasing generalized from pure inserts to
delete-shaped entries (old_end translates independently, clamped).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The GPU frontend's per-keystroke edits arrive as FrontendEvent::CrdtOp.
The old apply path materialized the whole document and diffed it per
op — O(file) per typed character on the daemon main thread.
- CrdtState: persistent text-projection subscription (capture gated by
an AtomicBool so per-keystroke imports don't register/drop
callbacks); import_updates_with_text_deltas returns Loro's deltas;
unicode_to_utf8_pos converts the insert point.
- Buffer::apply_remote_crdt_op: the common single-insert delta applies
straight to the rope; deletes/compound updates keep the conservative
materialize+diff fallback. UTF-8 position regression test included.
- SyntaxRegistry::has_pending_parse_job_for: the main-thread
"parse in flight" bit render producers need for settle-gating.
- TextView::pos_to_display: stack buffer for short line prefixes +
valid_up_to() boundary trim — removes a per-cursor-move allocation.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Workspace skeleton: root Cargo.toml becomes a workspace with members
[".", "pmacs-protocol"]; [workspace.dependencies] pins serde,
postcard, thiserror so both crates use byte-identical versions (the
wire format depends on it). pmacs main package keeps its existing
shape (no file moves); it just gains pmacs-protocol as a path
dependency.
Identity types moved: BufferId (from buffer.rs), FrontendId + ByteRange
(from protocol.rs), Position type alias (from rope.rs). All four are
self-contained — no custom-type dependencies — so the first stage of
the move can land atomically without dragging cell/message types along.
src/buffer.rs / src/protocol.rs / src/rope.rs each gain a 'pub use
pmacs_protocol::...' re-export for the moved names, so existing
internal imports (crate::buffer::BufferId, crate::rope::Position, etc.)
continue to resolve unchanged. New consumers (pmacs-gpu, debug tools)
will depend on pmacs-protocol directly.
One visibility change: BufferId::from_raw was pub(crate); promoted to
pub with a doc note that it's not stable API for external consumers.
The (crate) restriction was advisory only — external deserialization
already worked via the derived Deserialize, so making it pub doesn't
widen the actual surface, just makes it honest.
Lib gate: 1314 passed, no regressions.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Lays the groundwork for WorkspaceEdit/rename (L2+) by making
navigation cross-file-correct.
- Relocate file_path/file_meta from the EditorCore global onto
Buffer itself, so each buffer keeps its own filesystem identity
across cross-file navigation. Accessors + registry/editor/lua/
semantic_render call sites migrated; zero behavioural change for
single-file flows.
- uri->path: project_index::uri_to_path made pub; pmacs.lsp.path_for_uri.
- find-or-open: BufferRegistry::find_by_path + pmacs.buffer.find_or_open
dedups an already-open file instead of spawning a duplicate buffer
(SP-4 Gap A).
- Bounded jump ring on EditorCore (cap 64, oldest-evict, stale-buffer
skip): push_jump/jump_back + pmacs.editor.* bindings + lsp.jump-back
command bound to M-,.
- pmacs.lsp.go_to_definition cross-file branch: decode URI ->
push_jump -> find_or_open -> reposition, with a failure path that
unwinds the pushed origin. ensure_server now passes cfg.env through.
Tests: 5 jump-ring unit tests; m4_12_cross_file_go_to_definition_and_
jump_back end-to-end via a new `defenv` fake-LSP mode. All gates green
(lib 1262/0, m4 67/0, m8_1/m8_9/m8_10, m9_1, m11_5 --features crdt 2/0).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Root cause of the CI Lint regression: commit 6113c53 bumped
rust-version 1.85 -> 1.95. clippy::collapsible_if is MSRV-gated —
collapsing `if let { if let }` needs let-chains, stabilized in Rust
1.95. At MSRV 1.85 clippy suppressed these; at 1.95 it emits them.
The patterns were pre-existing; the MSRV bump surfaced 47 of them
and turned `Lint (luajit)` / `Lint (lua54)` red at HEAD (was green
through PR #7; red from PR #8 = the release-prep MSRV bump).
Resolution (operator-chosen: autofix into let-chains): applied
`cargo clippy --fix` across the luajit, lua54, and crdt lanes
(--all-targets). The fix only applied with the lint at warn level;
`-- -D warnings` turns it into an error and blocks --fix.
Verified on the pinned 1.95.0, all three lanes:
clippy --all-targets -D warnings clean (luajit / lua54 / crdt);
fmt 0 diffs; lib tests 1223/0.
Note: the prior #6 "quiescent audit, clippy clean" was inaccurate —
clippy was not actually re-run there (build/version/fmt only), so
this MSRV-gated regression went uncaught until the live attach-debug
investigation surfaced it. This commit restores genuine clippy
cleanliness at MSRV 1.95.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
CI was red on every recent main commit (pre-existing, not from the
V0.2/audit work): the workflow installs rolling `stable`, which on
the runners is ~1 year newer than the local toolchain that validated
the code. Under `RUSTFLAGS: -D warnings` + `clippy -- -D warnings`,
new rustc/clippy lints across pre-existing code became hard failures.
Confirmed identical on the 4 commits before v1.0-rc (e.g. the
`rope.rs:1076` unused_parens compile error is byte-identical there).
Resolution:
- `rust-toolchain.toml` pins channel 1.95.0 (the validated version).
The repo directory override makes every cargo invocation use it
regardless of what the CI action installs, eliminating the
local/CI toolchain-drift class permanently. Bump deliberately.
- Mechanical lint fixes (~17 sites, all the trivial/auto-fixable
class — no logic change): `cargo clippy --fix` + `cargo fix`
applied the machine-applicable set; hand-fixed the residuals:
daemon.rs (duplicated #[allow]), completion_framework.rs
(sort_by -> sort_by_key/Reverse), attach.rs (map().unwrap_or ->
map_or, crdt), buffer.rs (is_some+expect -> match, crdt),
m10_11_acceptance.rs (if -> match guard x2, crdt).
- `cargo fmt --all` (clippy --fix left overlay_paint.rs unformatted).
Verified clean under 1.95.0, all lanes: fmt 0 diffs; clippy
--all-targets -D warnings clean for luajit, lua54, AND crdt;
-D warnings build clean luajit+lua54; doc tests pass; lib 1223/0;
autofix-modified tests (m7_5, m8_1 incl. the Finding-2 fs_watch fix)
pass.
Scope: this clears CI red class #1 (toolchain-gap lints) only.
Independent and still triage-pending: #2 macOS F9 nix
PeerCredentials portability (Test (macos-*)), #3 M1/M4/M6 perf/fuzz
gates. Per plan, those are triaged after CI confirms #1 green.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Post-ship-gate completion of M10.10 (optimistic local edit
application, Path β). The milestone core landed in 45be65b
"M10.10 ship gate"; this commit completes the frontend keystroke
path and absorbs Day-5 corrections.
Completes:
- optimistic::frontend_event_for_keystroke — keystroke orchestrator
(classify_key predicate → mirror-ready check → CrdtOp or Key
fallback per Refinement 4 graceful degradation).
- BufferMirror cursor tracking (active_buffer, cursor_byte_pos via
CursorByte) + char-boundary-aware delete helpers (prev/next_char_len)
so multibyte backspace/delete don't trip loro's mid-codepoint
rejection.
- buffer.rs: crdt_state accessor (was test-only) now production —
daemon's BufferSnapshot export path uses it.
Day-5 corrections:
- packages/manifest.rs: fix pre-existing M8-era proptest generator
that produced ".."-containing entry paths the parser correctly
rejects (segment-structured regex; stale regression seed removed).
Out of M10.10 scope; absorbed so future milestone sweeps see clean
output instead of a known-failing test requiring prose.
- tests: extract inline PTY/daemon helpers to shared tests/common/
module (m5_5, m5_8 now import; no coverage change — m5_5 retains
19 m10_10 tests). tests/common/ added (required for compilation).
Audit history (M10.10-AUDIT.md is gitignored internal-only; this
message is the sole version-controlled record):
M10.10 PASSES within Path β scope (end-of-line optimistic visual
paint; mid-line/delete-forward round-trip; full CRDT-op exchange
across the text-input scope). The initial audit verdict was WRONG —
optimistic-apply was structurally unreachable in the production
binary (build_capabilities advertised crdt_replica: false). Six
post-audit review rounds surfaced 28 findings (F5–F32) beyond the
framing pass's original 4. Six M10-era discipline additions emerged,
each empirically grounded: end-to-end-exercise check (bidirectional
scope), composition-consistency check, verification-milestone premise
check, library-API verification check, forward-pointer-comment
hygiene, methodology-composition check.
Scorecard adopts Option C dual methodology: layer (a) framing-pass
accuracy is 7/8 milestones-not-findings AND 2/8 findings-as-failures
— the 5/8 spread is the density diagnostic (M10.10's defining
characteristic; neither number alone is honest). Layer (c): 7/8 and
6/8 (M10.8 inherited-gap cluster). Budget honesty: 5-day
pre-authorization covered anticipated implementation surprises (K1,
Risk #6 a); Finding 3 was a third surprise absorbed via compression,
not structural slack; the six post-audit rounds were entirely
unbudgeted and are the milestone's dominant cost. M10.10's density
is partly forecastable — it is the only M10 milestone with all three
of: architectural reversal, multi-milestone integration, and
verification depending on incomplete cross-milestone wiring.
Ship-gate clean on clean checkout (cargo clean + rebuild): luajit+crdt
1364/1364, luajit 1211/1211, lua54+crdt 1364/1364, lua54 1211/1211,
m5_5 daemon-e2e 36/36, perf 1MB=1.1ms vs 10ms gate, clippy 0 across
feature combos, fmt clean. One transient flake observed
(async_runtime::supersede_cancels_in_flight_job_within_50ms — timing
test starved under concurrent compile load, non-reproducible in
isolation, known infra pattern, not an M10.10 regression).
Next: M10.11 (two-laptop acceptance) inherits all six discipline
additions; v1.0 ships after M10.11.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Land the optimistic local-edit-application layer on top of the M10 CRDT
foundation: frontend-side rope replica with local edit application,
daemon-authoritative broadcast, and bidirectional cursor reconciliation.
Keystrokes feel instantaneous because the local replica answers next-render
queries before the daemon round-trip completes, while the daemon remains
the single source of truth for conflict resolution and broadcast to remote
replicas.
Architecture beats:
- BufferMirror (src/buffer_mirror.rs) holds a per-frontend rope replica
with explicit cursor-staleness tracking. Every event that may move the
active cursor or swap the active buffer marks the mirror stale; the
next CursorByte from the daemon clears it.
- CrdtOpOrigin {OptimisticReplica(FrontendId), DaemonKey} routes broadcast.
OptimisticReplica skips re-application on the originating frontend
(already applied locally); DaemonKey broadcasts to all replicas including
source -- covers Lua-driven and generated-buffer edits that bypass the
optimistic path.
- Generated buffers (*help*, *workers*, *pmacs-instance*, *errors*) funnel
apply_edit output through queue_daemon_origin_crdt_op so post-attach
CRDT upgrades don't drop their edits.
- forbid(unsafe_code) preserved throughout; loro 1.12 added as the CRDT
engine.
Audit posture: M10.10 shipped through six post-audit review rounds with
twenty-eight cumulative findings, most categorized as "incomplete
application of a prior round's mechanism." The audit doc records
grep-driven exhaustiveness as the standing countermeasure.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>