Addresses the PR #103 review.
- BLOCKING semantic right-click: the dispatcher routes
PointerKind::Context directly to open_menu_at_byte, bypassing
dispatch_pointer's break — so GPU C-k, right-click, dismiss, C-k still
appended, and M-y survived the click. open_menu_at_byte now breaks the
chain like the grid right-click path.
- HIGH C-k under intercepts: kill_line captured text then called
buf:delete un-pcall'd. A REJECTING intercept threw before fail_kill,
leaving the old chain live (the next C-k appended to a kill that never
happened); a TRANSFORMING intercept could delete different bytes while
the ring and OS clipboard kept the original text. The delete is now
pcall'd and verified by length delta: rejection clears the chain with a
status; a transformed delete feeds nothing (the interceptor's result
stands — accepted post-hoc semantics), also clearing the chain. Same
discipline applied to cut's delete_region.
- HIGH rejected M-y: buf:replace ran outside pcall, so a rejecting
intercept threw through command dispatch and left sessions[fid] live —
a second M-y could reuse the supposedly-invalid session. The replace is
pcall'd; rejection drops the session with a status.
Tests (kill_ring_acceptance now 28): semantic_context_right_click_breaks
_the_chain (drives open_menu_at_byte directly — the GPU route);
rejecting_intercept_clears_the_kill_chain (reject-once intercept: the
kill after the rejection pushes fresh, not append);
transforming_intercept_does_not_feed_the_ring (delete shrunk to one
byte: ring untouched, interceptor's result stands);
rejecting_intercept_ends_the_yank_session (second M-y refuses on
no-session, no splice).
Gates: fmt + workspace clippy clean; lib 1500; crdt 1672; killring 28;
cua 5; m6_4 repl (intercept suite) 15; git diff --check clean.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>