One list call now materializes at most maxEntries child rows (config,
default 1000 - GitHub's web-UI directory-listing bound). Candidates sort
before probing so a cut level keeps the name-sorted head and symlink
probing stops with the bound, and DirectoryListing carries a required
truncated flag on the seam and the wire so clients can state
incompleteness instead of silently missing tail entries.
- Escape in the path editor now supersedes a navigation the editor already
launched (request-sequence bump + loading reset), so a late success cannot
jump to the cancelled path; the single-pane fallback keeps covering a
superseded selection preview (ds-review-bot).
- The browse flow's pair registration rides ui-slots' new
deferGroupRegistration (one occupant, both holes, as a unit — construction
or late rival conflicts roll back wholesale and fail loud), mirroring
-native and deleting the would-be clone.
The construction-rollback + late-conflict-rollback + loud-rethrow block was
about to be a verbatim clone across the two flow packages; ui-slots now owns
it as deferGroupRegistration (one occupant, several holes, as a unit), with
direct specs for all three arms, and the native flow consumes it.
Holes declared after two flow providers activated left the loser throwing
out of the slot flush with partial occupancy. deferRegistration gains an
onFailure channel (late failures unsubscribe, then hand over instead of
throwing through the flush); the native flow's pair rolls back wholesale
and re-raises on the global channel the boot's fail-loud handler owns.
Duplicate rows of the SAME package stay silently idempotent (the component
identity guard skips an occupied hole).
BrowseDirectoryFlow and its injected face move to the package-internal
src/client/flow.ts, mirroring -native: ./client exports only the Loader
surface and the same-package spec imports the internal module directly.
- Directory-flow occupancy moves onto the inject face's reserved hooks
compartment: apply publishes a stable observable per surface and the
renderer binds useDirectoryFlow — no hand-rolled component subscriptions
(the client contract's channel for registrant-private reactive facts).
- The native flow's alive guard re-arms in effect setup: StrictMode's
development replay ran the cleanup once and every later outcome was
discarded.
- NativeDirectoryFlow moves to a package-internal module; ./client exports
only the Loader surface, tests import the internal module directly.
- The composition swap comment no longer advertises -browse as a complete
swap before its dialog lands (stacked follow-up).
An HMR replacement left the old instance's pick promise able to adopt a
second path through the shared owner callbacks; settlements now check a
component-lifetime ref (an injected-face identity change alone keeps the
pending settlement — the host-side dialog is unchanged, and the wire has no
per-request abort). Both settlement arms covered (ds-review-bot).
A navigation settling between the Edit-Path click and the first keystroke
executed navigate's draft reset and closed the editor underneath the user;
the click now bumps the request sequence like draft edits do
(ds-review-bot).
- The browse client half mirrors -native's rollback: a pair construction
that throws halfway (declared-but-occupied second hole) disposes the
earlier deferral before rethrowing, so no orphaned slot subscription
outlives the failed fiber (ds-review-bot).
- The TestWorkspaces browse methods gain the coverage CI's per-file gate
requires (defaults + stub overrides, recorded like their siblings).
A declared-but-occupied second hole registers synchronously, so the pair
construction can throw after the first deferral installed its subscription;
that orphan then fires against the failed fiber's inactive context. The
effect now disposes already-created deferrals before rethrowing
(ds-review-bot on the browse twin; same shape here).
- HMR/unmount bumps both request generations, so a listing or creation
settling after disposal neither updates dead state nor issues the
post-create relist.
- A selection whose preview listing fails clears back to the single pane:
the breadcrumb names the level, so the level must be the committing
target (reverses the earlier keep-marked behavior with its test).
A draft edit can invalidate the selection's preview request; Escape then
left selected set with no child and nothing loading — a half-empty
two-pane view. Cancel now clears the selection when no preview exists
(ds-review-bot round 7).
Editing the draft bumps the request sequence, so a slow lookup that settles
afterwards can neither clear the newer text nor repopulate the view with
the older path (ds-review-bot round 6).
The path editor and the folder-name input carried identical inline IME
handlers — the cross-file clone jscpd flagged against WorkspacePicker; one
component-level guard object serves both.
- Open and New folder disable while a path draft is uncommitted: targetPath
still names the previous selection/listing, and committing against it
while a different path shows in the header adopts the wrong directory.
- The Miller columns keep their own row so a status/error line renders below
them inside the card instead of competing as a third flex item the dialog
clips off-screen.
- Both text inputs (path editor, folder name) carry the IME composition
guard the workspace-name inputs already had: a composing Enter confirms
the candidate, never submits.
With no listed level (an unreadable or missing home directory), the
path-edit zone previously disabled forever, stranding the operator on the
alert with only Cancel; it now opens with an empty draft so an absolute
path remains the way forward. Covered by a recovery test.
Rows keep their NATIVE button role inside a listitem seat (role overrides
exposed selectable folders as passive list items to assistive technology),
the crumb trail becomes a navigation landmark, and the path-edit input joins
the parentInert derivation so the nested create dialog cannot be undercut
through it.
- Dismissal (Escape/mask) is ignored while adoption is busy: the owner's
in-flight createWorkspace must not land behind an apparent cancel.
- Every parent control goes inert while the nested create dialog is open
(Modal traps no focus, so Shift-Tab/AT could close, adopt, or retarget
underneath the child).
- Creation settlements are gated on an open-generation ref: a create that
resolves or rejects after the flow closed (and possibly reopened) can no
longer relist the stale target or surface its alert in the fresh dialog.
- The keyless snapshot waits for the Open button's enabled state before
clicking — on slow runners the selection's child listing was still in
flight and the click landed on a disabled button.
- Escape (and the mask) now reaches only the topmost dialog: while the
nested New-folder dialog is up the browser ignores its own Modal close,
and the nested dialog's in-flight fence keeps both open during creation.
- New folder disables while any listing loads, so a slow post-create
relist/select sequence cannot host a second create against a target the
pending listing is about to change.
- Deep ancestry scrolls inside a dedicated crumb trail whose tail is pinned
into view; the path-edit zone keeps its reserved width instead of being
clipped by the card, preserving cross-drive path entry.
- The workspace-management e2e records a directory-browser aria golden at a
staged tree (host HOME pointed at the scaffold cwd collapses ancestry into
the Home crumb, keeping the artifact machine-independent), and the keyless
snapshot's row targeting goes through visible label text — listitem
accessible-name computation differs across dom-accessibility-api
environments (the CI-only miss).
A fresh injected face while the same request is open re-fires the effect;
the armed guard must not relaunch the chooser (the uncovered branch CI's
per-file gate flagged).
- While a picking flow is open (native chooser pending, browse dialog up) or
its pick is being adopted, every other menu action disables: a late outcome
must not race a concurrent selection or creation (ds-review-bot warning).
- ctx.directoryPicker joins the architecture Capability Services map (both
languages); neighboring rows condensed to keep the doc inside its ceiling.
- directory-picker-browse documents that its client half lands in the next
stacked PR: a -browse composition today hides the picking affordance (the
documented empty-hole default) rather than misbehaving (ds-review-bot
critical; the dialog itself ships in #821).
Review finding (PR #791): the column carried bare values (no seq), so the
client could not seed its value store without risking a stale list block
outranking newer push frames — and nothing consumed the column at all,
leaving cold titles absent after a restart. SessionSummary.projections is
now the same SessionProjectionsBlock as the history tail (values +
asOfSeq; attached rows cut the live registry, cold rows serve the cache's
identity-checked cachedSnapshot whose asOfSeq is the lowest served-row
watermark). SessionManager.refreshList seeds each row's block into the
per-session projection store via per-key apply — partial-baseline
semantics: an absent key never clears, and higher-seq-wins keeps stale
list blocks beneath push frames and tail baselines — so cold titles
surface in the sidebar without opening a session.
SessionSummary grows an optional projections column (whole value per key,
same passthrough posture as the history-tail block): attached rows cut the
live registry watermark cache; cold rows view the persisted projection
cache's stored rows via the new registry viewCheckpoint face (version-
matching keys only, zero I/O) — the RFC's motivating scenario, every
session's title across a listing without loading one event log. The column
is fail-soft and absence-coded: no registry, no cache row, or a throwing
read serve the row without the column, never breaking the listing.
directory-picker-browse becomes dual-face: its browser half fills
ui-workspace's two directory-flow holes with the Select Workspace Directory
dialog (figma Harness 813-23126 family — Miller two-column view, breadcrumb
with click-to-edit path zone, nested New-folder dialog), driving the node
half's host.listDirectory/host.createDirectory and owning its locale
namespace (directory-browser, zh default / en). The dialog moves here from
ui-workspace wholesale — the trigger surfaces keep only the flow-hole owner
conversation.
apps/cli flips its one directory-picker row -native -> -browse, swapping the
host backend and the client interaction together; picking now works for
remote deployments out of the box. The keyless workspace-flow snapshot boots
the browse bundle and drives menu -> dialog -> Documents -> project -> Open
against the fixture tree.
ui-workspace's two trigger surfaces each declare a single-kind directory-flow
hole (conversation.hero.workspace.directoryFlow / sidebar.workspaces.directoryFlow,
same owner contract) and keep only the trigger and the adoption: the Open-local-
folder entry renders while the surface's hole is occupied, and the occupant
reports one picked path per open through the hole's owner conversation
(open/busy/onPicked/onCancel/onError).
directory-picker-native becomes dual-face: its browser half fills both holes
with a renderless occupant driving host.pickDirectory, so the cordis.yml row
that mounts the backend also composes the client interaction — a mismatch is
impossible and a second flow package fails at client load.
With composition wiring both sides, the host.describe.directoryPicker
advertisement and the client's kind branching lose their last consumer:
the field, WorkspacesService.directoryPickerKind(), the DirectoryPickerKind
wire type, and the picker's per-open describe read are deleted. The connection
fixture now serves a deterministic pickDirectory path so the keyless snapshot
drives the full pick-then-adopt flow. ui-workspace's hand-rolled declaration
deferral is replaced by the deferRegistration helper it duplicated.
master's toolcall-open extracted runNativeCommand inside apiproxy for the
openPath opener while the picker seam had moved the native chooser (its other
consumer) into directory-picker-native; after the merge the two packages each
carried a verbatim copy. The runner now lives in packages/util/native-command
(zero-dependency library, per the util-group contract) and both native
integrations depend on it.
The browse interaction also presents a dialog (the in-app modal), so 'dialog'
failed to discriminate the two capability kinds; 'native' names where the
chooser runs. Package directory-picker-dialog -> directory-picker-native, kind
'dialog' -> 'native', with every seam/gateway/client/doc reference updated and
the seam Agent Note's naming rationale rewritten to match.
ds-review-bot round 5: '\\' and '\\server' satisfy win32.isAbsolute and
the previous two-separator test, yet resolve() collapses them to
drive-relative roots. The UNC arm now requires server and share components;
incomplete prefixes reject with the business codes, covered per-platform.
ds-review-bot round 4. On Windows, isAbsolute admits rooted drive-less
forms (\foo, /foo) that resolve() then rebases onto the process's current
drive; both browse primitives now gate on a fullyQualified check (drive
letter or UNC on win32, POSIX-absolute elsewhere) with a platform test
seam, per-platform unit cases, and the contract wording updated on the
seam, the backend README pair, and the error messages.
The picker-kind effect also kept a resolved 'dialog' across close, so a
backend swapped while the menu was closed could paint the stale entry for
one frame on reopen; the close arm now clears the state, pinned by a
reopen-under-pending-read race test.
ds-review-bot round 3. The seam package broke the service-package export
contract (named export only), so the config catalog filed it under Other
libraries and default imports failed; it now default-exports DirectoryPicker
like every abstract seam, and the regenerated catalog lists it as one.
The picker-kind effect also let a settlement from a superseded flow open
leak into the current one (close/reopen mid-describe, or a reconnect that
swaps the backend): the read now resets the affordance on every open and a
cleanup-toggled flag discards obsolete settlements, both directions pinned
by jsdom races.