Commit Graph

2417 Commits

Author SHA1 Message Date
hermes-seaeye[bot] 3e6a081d60
fmt(js): `npm run fix` on merge (#82055)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-08 22:51:53 +00:00
brooklyn! 3898e646e5
Merge pull request #82044 from NousResearch/bb/agent-plugins
Surface agent plugins in the desktop app's Settings → Plugins
2026-08-08 17:41:38 -05:00
Brooklyn Nicholson 44790bc9c8 feat(desktop): plugin descriptions + open the agent plugins folder
HermesPlugin/PluginRecord gain a description one-liner (kanban gets
one) shown in the inventory instead of the raw file path, and the
agent plugins section can open the backend's plugins dir — path from
config.get profile so it's profile-aware, local backends only since
openDir mkdir-creates.
2026-08-08 17:34:20 -05:00
Brooklyn Nicholson c86da8397b feat(desktop): agent plugins in Settings → Plugins
Backend plugins — native Hermes plugins and portable Agent Plugins v1
packages — were invisible in the desktop app. Settings → Plugins now
lists them under the desktop (renderer) plugins with source/portable
pills, enable/disable switches keyed by canonical registry key, and a
live-filter search box, backed by a nanostore over plugins.manage.
Categories other surfaces own (dashboard_auth/*, model-providers/*,
platforms/*) are curated out renderer-side.
2026-08-08 17:24:59 -05:00
brooklyn! 3391836888
Merge pull request #82036 from NousResearch/bb/session-arc-source
perf(desktop): keep session status inside the row's own fiber
2026-08-08 16:58:34 -05:00
brooklyn! 4907e3d900
Merge pull request #81977 from helix4u/fix/desktop-main-window-ready-fallback
fix(desktop): reveal windows after a missed ready-to-show event
2026-08-08 16:58:00 -05:00
Brooklyn Nicholson 41ae3db426 fix(desktop): reveal every window after a missed ready event, not just the main one
Session, instance, HUD, quick-entry and pet-overlay windows all open with
show: false and are revealed only by ready-to-show, so the Electron 40 bug
strands them exactly the way it stranded the primary window — and none of
them have the second-launch workaround that made the main-window case
recoverable.

Generalize the controller to any window and wire all six through one
wireWindowReveal helper. Callers pass their own reveal action (showInactive
for the pet overlay, show + focus for the HUD and quick entry) and their own
post-visible work, so whichever path wins runs them exactly once.

Quick entry now reveals the window the call created rather than whatever
`quickEntryWindow` points at when the event lands.
2026-08-08 16:51:44 -05:00
Brooklyn Nicholson 041cbff5e3 fix(desktop): keep the Playwright reveal path off the production fallback
Desktop E2E is hard-disabled in ci.yml (#76627) because the mock-backend
window never reaches a usable state, so nothing can validate dropping the
TEST_WORKER_INDEX force-show right now — and the suite's lead symptom is
already a window-readiness failure. Restore it, routed through the reveal
controller so the bookkeeping in onRevealed still runs exactly once, and
leave the removal to whoever re-enables the suite.
2026-08-08 16:51:44 -05:00
Brooklyn Nicholson 615a435b7a perf(desktop): stop a settling turn from repainting the whole sidebar
ChatSidebar read $workingSessionIds with useStore purely to notice that a turn
had finished and re-probe worktree lanes. Nothing in its markup used the value,
so every status edge re-rendered the entire sidebar — each section, each row —
to run an effect that touches no DOM.

Listen to the store instead. The rows own their status subscription, so a
session changing color repaints that row's fiber and nothing above it, which a
test now holds in place by counting row renders.
2026-08-08 16:51:25 -05:00
Brooklyn Nicholson b07ee44f1b refactor(desktop): let the sidebar row read its own status
The dot resolved its state through $sessionDotStateById while the arc on the
same row was decided from an isWorking prop, drilled from the sidebar through
two list components and asserted in five test setups. Two paths to the same
question is how the row's arc and its dot end up disagreeing, and it is why the
arc has broken independently of the dot before.

The row now reads the resolved state directly, and the arc rule moves next to
the states it talks about as `showsRunningArc`. `hasLiveTurn` keeps the row's
other treatment — brighter title, age yielding to the actions menu — on the
wider meaning it always had, where a turn waiting on an answer still counts as
this session's turn.

The list chain drops the prop, its types and the id set built to feed it.
`$workingSessionIds` stays where the sidebar genuinely needs it, for noticing
that a turn settled.
2026-08-08 16:42:00 -05:00
brooklyn! 71326399d3
Merge pull request #81991 from NousResearch/bb/session-status-dot
fix(desktop): make the session status dot mean one thing
2026-08-08 16:33:39 -05:00
brooklyn! 51597c5e07
Merge pull request #82007 from NousResearch/bb/hud-surface-note
The agent knows when it's floating in HUD mode, and looks at the app underneath
2026-08-08 16:28:35 -05:00
Brooklyn Nicholson f04ad5a829 style(desktop): drop the pulsing glow behind the status dot
Nothing renders it now that the dot holds still, and the row markup no longer
has to opt out of overflow clipping to leave room for the halo.
2026-08-08 16:26:48 -05:00
Brooklyn Nicholson 302ee80b6f refactor(desktop): give the status dot one source of truth and a quieter look
Priority between the overlapping signals — a session can be working and unread
and running a background job at once — was resolved at the call site from five
separate membership lookups, which is how surfaces drift apart. `$sessionDotStateById`
does it once and hands each surface a single answer.

The dot's visual language collapses to three colors on one fill/hollow axis
with nothing moving. Motion on a six-pixel circle can only say "something is
happening", which the row's arc already says better, and it cost a repaint per
frame on every row at once; filled now means producing and hollow means open
but quiet. Working and stalled had differed by 30% opacity and were in practice
the same dot. A settled session paints its project color or nothing, rather
than a grey mark of the same weight as a real status next to every resting row.

The switcher had grown its own dot with its own three states, so it disagreed
with the sidebar on the same session. It renders the shared one now.
2026-08-08 16:26:48 -05:00
Brooklyn Nicholson b70c5cadb3 fix(desktop): stop the session status going idle while the turn is running
The status sets are published under a session's current stored id, but the
sidebar row, a persisted tile and the route can each be holding a different
tip of the same lineage after a compression, and every consumer tested
membership with a plain equality check. When the tips disagreed the session
fell out of the working set mid-turn and the dot dropped to idle with the
model still going. Publish each state under every id the conversation answers
to instead, via a shared `lineageAliases` helper.

A conversation that has not been persisted yet has no stored id at all, and
the projection dropped those rows outright, so the first turn of a new chat
showed no dot and no row arc until the backend handed an id back. Fall back to
the runtime id, which until persistence is the same value the surfaces key on.

Background polls could also clear a live busy state before the backend had
caught up with a just-submitted turn, flicking the dot idle for a beat; the
stream path already guards against that, so the poll path now does too.

The stalled watchdog fired at eight minutes, well past the point of being
useful as a hint. Five is past the app's own long-but-healthy silences, like
a typecheck or a full test run, without outlasting the user's patience.
2026-08-08 16:26:48 -05:00
Brooklyn Nicholson 0665cd4b5b style(hud): tighten the surface-note comments and test helper
Comment wording only, plus the desktop test's boolean parameter becomes
an 'app' | 'hud' union so the call site says which window it means.
2026-08-08 16:21:15 -05:00
brooklyn! 8e9ecc1f3e
Merge pull request #82014 from NousResearch/bb/hud-band-hit-area
HUD: only take the mouse where the HUD actually is
2026-08-08 16:20:12 -05:00
Teknium 7537de9e74 fix(deps): patch 31 known CVEs across Python and npm lockfiles
OSV weekly scan reported 50 known vulnerabilities in pinned deps.
This bumps everything with a released, semver-compatible fix:

Python (uv.lock):
- aiohttp 3.14.1 -> 3.14.3 (GHSA-cq5v-8q36-5273, GHSA-mfx4-hv73-q22v,
  GHSA-mq44-7p77-q5h7)
- h2 4.3.0 -> 4.4.1 (CVE-2026-71554 request smuggling; exclude-newer
  exception documented in pyproject, remove after 2026-08-17)

npm (root workspace):
- brace-expansion 5.0.8 -> 5.0.9, undici 6.27->6.28 / 7.28->7.29,
  js-yaml 4.3.1, nanoid 3.3.17/3.3.18, ip-address 10.4.0,
  mermaid 11.16.1 + dompurify 3.4.13 (root overrides so the
  streamdown transitive copy is pinned too)
- electron 40.10.2 -> 40.10.6 (GHSA-r4w5-6pfg-jxp5; the 41.x major
  for GHSA-9f4c-93c8-jc8g is deferred to its own PR)

npm (website): mermaid, dompurify, js-yaml, nanoid, fast-uri 3.1.5,
postcss 8.5.23, undici 7.29.0
npm (photon sidecar): @opentelemetry/core 2.8.0 via override, undici
npm (whatsapp-bridge): body-parser 1.20.6

min-release-age excludes added to .npmrc/website/.npmrc for the
sub-2wk CVE-fix releases, each with a removal date.

Remaining findings are blocked upstream: cryptography <49 cap
(alibabacloud-tea-openapi), image-size (no fixed release), tar 6.x
transitive majors, electron 41.

Local rescan: 50 -> 19 known vulns, 0 introduced.
2026-08-08 14:06:48 -07:00
Brooklyn Nicholson 717b49c084 fix(desktop): read "is the cursor over the HUD" off the tree, not off a list
The hit test excluded <body> and <html> and missed `#root`, which is
full-window and hit-testable, so every point in the window came back as
something and the window never went mouse-transparent at all. Ask it
structurally instead: anything that CONTAINS the shell is scaffolding around
the HUD rather than part of it, which covers the mount, the body and the
document in one predicate and cannot be out of date again.

Focus gets the same treatment. #81552 pinned the window solid whenever
anything in it held focus, to stop the HUD going click-through under its own
dialogs — but the composer holds focus as the HUD's resting state, so an
engaged HUD claimed its whole rectangle. What that fix needed was focus
BESIDE the shell: a portalled dialog, popover or menu owns the next click,
including the one outside it that dismisses it, and the hit test cannot see
that one coming. Focus inside the shell is the composer, and the hit test
already covers everything the composer can reach.

The decision is a pure function now, so it can be tested against a real DOM
instead of inferred from the effect.
2026-08-08 15:46:40 -05:00
Brooklyn Nicholson 48d672e493 fix(desktop): the HUD only takes the mouse where the HUD actually is
Follow-up to #81920, which bounded the frost to the sheet and left the surface
underneath it unbounded. Nothing paints in the empty space above a short
transcript now, and clicks still die there.

Two reasons, both in this stylesheet. The shell's scaffolding — the shell
itself, the chat surface, the wrapper between them — is full-window,
invisible and hit-testable, so the click-through hit test found something at
every point in the window. And the band's box is the whole window by design
(it is the scroll container), so engaging the HUD turned that entire rectangle
into a click target, which on a fresh thread is a window-sized hole over
whatever you were working in.

So: default the shell to `pointer-events: none` and let surfaces opt in, and
clip the band's box to the sheet, which hit-testing honours. Opting in rather
than listing the scaffolding to exclude, because the scaffolding is not a list
anyone maintains — one more wrapper and the dead rectangle is back, whereas a
control that forgets to opt in is visibly dead.
2026-08-08 15:46:26 -05:00
Brooklyn Nicholson e24bac49fa feat(desktop): tell the agent when it is floating in HUD mode
In HUD mode Hermes is a strip over the app the user is actually working
in, so "what's under you?" or "look up the weather" is almost always
about that app — but the agent had no way to know it was floating, and
answered from its own browser and panes instead.

The desktop tags a HUD submit with `surface: 'hud'` and the gateway turns
that into a per-turn note pointing at read_window_below, and at carrying
the work out in the app underneath. It rides the model-bound message
beside the reaction and speech-interrupted notes rather than the system
prompt: one session can be driven from the app window on one turn and the
HUD on the next, and the system prompt has to stay byte-stable.

Every tool the note names is checked against the agent's own schema
first, so a session without computer_use or read_window_below is never
pointed at a tool it cannot call.
2026-08-08 15:37:41 -05:00
hermes-seaeye[bot] 3da72f1fd1
fmt(js): `npm run fix` on merge (#82000)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-08 20:29:52 +00:00
hermes-seaeye[bot] a726a4aee6
fmt(js): `npm run fix` on merge (#81997)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-08 20:20:18 +00:00
Brooklyn Nicholson c96b978d54 fix(desktop): drop a stale comment describing the removed inheritance step 2026-08-08 15:00:44 -05:00
Brooklyn Nicholson bd39673b8f refactor(desktop): one path-comparison helper instead of two
The Windows-aware path matching added for project ownership was a second
copy of what the file tree's IPC layer already had — same Windows test, same
containment check, one of them carrying a trailing-slash branch its own
normalisation made unreachable. Both now share lib/path-compare.
2026-08-08 14:50:43 -05:00
Gille 48c05e0c6b fix(desktop): reveal main window after missed ready event
Co-authored-by: Thomas Repka <148156831+Gateton@users.noreply.github.com>
Co-authored-by: rshi0212 <61662344+rshi0212@users.noreply.github.com>
2026-08-08 13:41:04 -06:00
Brooklyn Nicholson 9050913e68 fix(desktop): remember the workspace you picked, not the one you looked at
On a remote backend a new chat starts in the remembered workspace, and
setCurrentCwd persisted that key on every call — including the six paths
that merely follow a conversation (resume settling, warm switch, stored-row
preview, agent relocation, boot seed, resolved new-chat default). So opening
a chat inside a project quietly made that project the destination for the
next "New session", which is the half of the report the resolver fix does
not reach: a Windows desktop driving a WSL gateway is a remote connection.

setCurrentCwdTransient already meant "move the path, claim nothing" — the
following paths now use it, and setCurrentCwd is reserved for a workspace
the user actually named.
2026-08-08 14:40:26 -05:00
Dan Bennett 7ff9d7db91 fix(desktop): match a project to its cwd across Windows path spellings
Project ownership compared paths literally, so a nested cwd failed to match
its project whenever the separator or drive-letter case differed — which on
Windows is routine. Normalise both sides for comparison only, folding case
for drive and UNC paths.
2026-08-08 14:40:25 -05:00
David Metcalfe 6dda0c91d9 fix(desktop): stop new chats inheriting the focused session's folder
resolveNewSessionCwd() inherited the focused chat's workspace, so every
"New session" landed in whatever project you were last looking at — and
after a restart the focused session's stored cwd is often a home-dir
fallback, which shadowed the configured default project dir entirely.

The boot seed had a second failure mode: ensureDefaultWorkspaceCwd() only
seeds while no session is active, and it ran after gateway.connect() — the
same event that un-gates route-resume. On a slow start the resume won and
the seed silently skipped. Seed before connect instead, where no session
can be active yet, and keep both seeds non-fatal.
2026-08-08 14:40:24 -05:00
ypQQ1984 4c9e1e8223 fix(test): make desktop ui tests locale-agnostic
Three desktop UI tests froze en-US-formatted strings while the
implementation formatters deliberately use the runtime locale
(new Intl.DateTimeFormat(undefined, ...) / Intl.NumberFormat(undefined,
...)) — runtime-locale output is the intended behavior for a localized
UI. On any non-en-US dev machine the tests fail even though the code is
correct:

    # zh-CN host:
    time.test.ts -> expected '三月' to be 'March'
    billing      -> Unable to find text 'Threshold: minimum is $10.'
                    (zh-CN renders USD as 'US$10')
    billing      -> Unable to find text '$25 added. Balance is refreshing.'

Assert the behavior contract instead of the frozen snapshot, per the
repo's testing guidance (behavior contracts over snapshots):

- time.test.ts: same-year month buckets render via fmtMonth, prior-year
  via fmtMonthYear — assert sessionBucketLabel(bucket) equals the shared
  formatter's output for bucket.at, with bucket-kind narrowing.
- billing/index.test.tsx: interpolate formatMoney(10) / formatMoney(25)
  into the expected strings.

No production code changes.

Verified: zh-CN host 40/40, LANG=C.UTF-8 40/40, tsc clean, eslint clean.
2026-08-08 12:33:19 -07:00
brooklyn! de1f370f9c
Merge pull request #81920 from NousResearch/bb/hud-frost-backing
HUD: only frost the part of the window the transcript is behind
2026-08-08 13:16:04 -05:00
hermes-seaeye[bot] edb27240e2
fmt(js): `npm run fix` on merge (#81914)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-08 18:10:42 +00:00
Brooklyn Nicholson f03fc46845 fix(desktop): don't frost the HUD window the sheet isn't covering
The frost is native vibrancy, which is the window's content view rather than
an element — it fills the whole rectangle and nothing in the page can clip it
to the sheet. That was only ever right while the sheet covered the window;
anywhere it falls short, the difference is frost over empty space. On a fresh
thread the sheet is zero and the difference is the entire window, which is the
grey slab that appears the moment you put the caret in the composer.

Gating the caller's `engaged` was not enough, and is why the first attempt at
this missed: the hook turns the frost on for a focused composer by itself,
independent of what the caller passes. The veto belongs inside, next to that
check.
2026-08-08 13:08:48 -05:00
Brooklyn Nicholson 843c3abcc7 fix(desktop): an empty HUD thread shouldn't paint a blank panel
A fresh thread has nothing to show, but the HUD showed a slab of frosted
glass above the bar anyway. Vibrancy is the window's whole content view, so
it frosts the full rectangle — fine while the band always filled the window,
wrong the moment there is no transcript to fill it. It stays off until there
is something to back.

The sheet had a 12px floor for the same reason: the breathing room above the
first row was added in CSS, so a zero-row transcript still measured 12. It is
folded into the measured height now and only applies when there are rows.
2026-08-08 12:31:52 -05:00
Brooklyn Nicholson 0c2cdccccc fix(build): win32 get-windows staging must skip the tarball's bundled darwin binding
The published tarball ships lib/binding/napi-9-darwin-unknown-arm64 on every
platform, so a real Windows host has both it and the downloaded win32 binding
— the classify-everything gate threw on the darwin dir and killed every
Windows pack. Stage only bindings naming the target platform (classify still
rejects impostors), stop copyGlobByExt from recursing into lib/binding, and
add a version tripwire so a get-windows bump fails the build until the
lib/windows.js rewrite is re-verified.

Also from review: the renderer answers window.read.respond with empty text
when the IPC invoke rejects (older shell / main-side throw) instead of
stalling the tool's 30s timeout; the tool schema discloses that sibling
Hermes windows are skipped; docs gain read_window_below in both references.
2026-08-08 12:17:50 -05:00
Brooklyn Nicholson beda5149d9 test: pin read_window_below into the toolset + post-hook contracts, appease eslint
The desktop_ui and post-hook ownership contract tests enumerate their tool
sets exactly — add read_window_below to both (plus the executor-path
parametrize case). Lint: sorted type import, explicit GetWindowsModule type
instead of an import() annotation, curly + blank-line style.
2026-08-08 12:17:50 -05:00
Brooklyn Nicholson f463a7e8ee build(desktop): stage get-windows like node-pty
get-windows@9.3.0 (MIT, zero runtime deps on macOS/Linux) is external to the
esbuild bundle and staged into dist/node_modules per target platform: the
universal Swift helper on macOS, the prebuilt N-API binding on Windows
(fail-closed magic-byte validation), nothing on Linux (xprop at runtime).
The staged lib/windows.js is rewritten to load the binding directly so
@mapbox/node-pre-gyp's tree stays out of the package.
2026-08-08 12:17:50 -05:00
Brooklyn Nicholson f22ae72921 feat(desktop): answer window.read.request with the window below
New electron/window-below.ts: pure z-order picker (walks past our own pid,
first other-process window whose bounds overlap ours) over get-windows'
front-to-back enumeration, with the Linux xprop stacking order reversed to
match (EWMH _NET_CLIENT_LIST_STACKING is bottom-to-top). Main answers the
hermes🪟readBelow IPC; on macOS other apps' titles pass through only
when Screen Recording is already granted — never prompted for.
2026-08-08 12:17:50 -05:00
hermes-seaeye[bot] 2389564d83
fmt(js): `npm run fix` on merge (#81849)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-08 16:55:45 +00:00
brooklyn! 31cedb4830
Merge pull request #81552 from NousResearch/bb/hud-mode
HUD mode: a chrome-free floating chat for the desktop app
2026-08-08 11:43:44 -05:00
webtecnica 464e7e4e5f fix(docker): read attached binary files in backend (#76577) 2026-08-08 05:44:18 -07:00
Brooklyn Nicholson c5332b2f86 fix(desktop): stop the HUD going click-through under its own dialogs
The window decided nothing was there whenever focus left the composer, which
is exactly what opening a dialog or clicking a link does — a portalled overlay
lives outside the shell, so `:focus-within` goes with it and the window turned
mouse-transparent underneath the thing you had just opened. The old hit test
only knew about the bar's rectangle, too.

It asks the document instead. Everything the HUD deliberately doesn't catch is
already `pointer-events: none`, so whatever comes back under the cursor is
something real, and focus is read at the document rather than the shell.
2026-08-08 03:52:17 -05:00
Brooklyn Nicholson 4500b43914 feat(desktop): frost the HUD band and fade it in three states
The band is real macOS vibrancy now rather than backdrop-filter, which
reaches nothing in a transparent window — its backdrop root is the document,
and the desktop was never in it. Vibrancy composites below the web contents,
so it can see the desktop, and it can't be masked or clipped from the page.
That rules out the gradient the band used to carry and settles it as a flat
panel: uniform tint, uniform frost.

The fade does the work the gradient was doing. A landing turn brings the
transcript half way up to be glanced at, focus promotes it to properly
readable, and the hold takes it back down and then away — the panel sliding
behind the bar as the last of the text goes.

It only fades from an idle transcript. A running turn or a question waiting
on you holds it open, because a prompt that fades out is one you can neither
read nor answer, and the hold timer alone would expire through a long tool
call that prints nothing.
2026-08-08 03:52:17 -05:00
Brooklyn Nicholson 10c1530599 refactor(desktop): put the HUD toggle beside the layout editor
HUD mode is a layout choice, so it belongs with the other one. The
keyboard-shortcuts button goes away with it — it was a second door to a
settings tab that the command palette and the keybind itself already open.
2026-08-08 03:52:02 -05:00
Brooklyn Nicholson f444e0c5e7 feat(desktop): point an open HUD at the tab you toggle from
Asking for HUD mode from another tab used to just raise whatever the HUD
already had, so the conversation you were looking at never arrived. Main
now retargets the window and tells every renderer where it is pointed, so
the toggle keeps reading "switch" rather than "dismiss".
2026-08-08 03:51:59 -05:00
hermes-seaeye[bot] 2d5e93161b
fmt(js): `npm run fix` on merge (#81589)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-08 08:15:17 +00:00
kshitij ad59bd92c7 test(desktop): align renamed message-fetch mocks; brace query-param guards
The salvage's getLatestSessionMessages/getAllSessionMessages split left
two desktop test files mocking the old getSessionMessages name (vi.mock
partial-mock let the real function through, so calls hit the un-mocked
path). Also braces the new single-line if guards per the curly lint
rule.
2026-08-08 13:36:08 +05:30
kshitij 2607dc9a85 fix(desktop): forward pagination params through the remote session interceptor
The remote interceptor rebuilt session/messages requests from pathname
only, silently dropping limit/offset/order. Against a paginating remote
backend, getAllSessionMessages would refetch the same default page until
the safe-load guard threw, breaking export/artifacts/branch for remote
sessions over one page.
2026-08-08 13:36:08 +05:30
kinsolee c750d5354a fix(sessions): prevent oversized transcripts from exhausting memory 2026-08-08 13:36:08 +05:30
Brooklyn Nicholson a3d57f18c2 fix(desktop): open HUD mode on the tab you're looking at
Both entry points read $selectedStoredSessionId, which is the WORKSPACE pane's
session — so whichever tile was fronted, the main tab went into the HUD. Tabs
exist precisely so those aren't the same question.

`getActiveComposer()` already answers it for the focus bus, healing to the
visible surface when its cached claim is buried, and a tile's routing key is its
stored session id. One resolver now, shared by the titlebar button and ⌘⇧H.

Coming back re-resumes through the tile delegate when the target is an open
tile. The ordinary resume path enforces "a session is either main or a tile,
never both" and would have closed the tile to take it into main, quietly
rearranging tabs the user opened on purpose.
2026-08-08 02:28:58 -05:00