Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
264 commits
Select commit Hold shift + click to select a range
cd04ab3
refactor(session): one handler per event family
serialexperimentslainnnn Sep 10, 2026
bff594b
refactor(session): the process lifecycle, the binary catalogue and th…
serialexperimentslainnnn Sep 10, 2026
685e2c5
fix(session): the initialize reply is adopted on the EDT
serialexperimentslainnnn Sep 10, 2026
b3c82b3
fix(session): stopping a session stops its timers
serialexperimentslainnnn Sep 10, 2026
d1b45d6
fix(session): a closed chat cannot start a process after it is gone
serialexperimentslainnnn Sep 10, 2026
c91966a
fix(session): failing the pending control requests cancels their watc…
serialexperimentslainnnn Sep 10, 2026
7cffc2b
fix(diff): edit snapshots are bounded and released with the session
serialexperimentslainnnn Sep 10, 2026
4314bc3
docs(claude): state that SensitiveGuard is defensive security work
serialexperimentslainnnn Sep 10, 2026
c6a5c36
docs(claude): the guard exists to stop guardrail bypasses
serialexperimentslainnnn Sep 10, 2026
767ab24
refactor(session): ClaudeSession keeps only the verbs it owns
serialexperimentslainnnn Sep 10, 2026
ad0b442
refactor(session): the process is its own collaborator
serialexperimentslainnnn Sep 10, 2026
378339b
refactor(session): one PTY sign-in flow behind two UIs
serialexperimentslainnnn Sep 11, 2026
c50d3a7
fix(session): Sign in no longer sources the shell or spawns the PTY o…
serialexperimentslainnnn Sep 11, 2026
3b7b7b8
fix(process): a sign-in listener that throws no longer kills the PTY …
serialexperimentslainnnn Sep 11, 2026
4dc31f6
fix(process): cancelling a sign-in no longer reports it as failed
serialexperimentslainnnn Sep 11, 2026
c5a8722
refactor(session): the session list is not the transcript reader
serialexperimentslainnnn Sep 11, 2026
f523b8a
refactor(protocol): every wire family decodes through a table
serialexperimentslainnnn Sep 11, 2026
44f8eae
refactor(ui): one handler per message family behind the bridge
serialexperimentslainnnn Sep 11, 2026
026a569
fix(ui): View diff on a pending card refuses a path outside the project
serialexperimentslainnnn Sep 11, 2026
408ffa4
refactor(ui/jcef): JcefHost hosts; assembling, routing and delivering…
serialexperimentslainnnn Sep 11, 2026
e1d3df1
fix(ui/jcef): closing the last chat no longer leaves a blank panel
serialexperimentslainnnn Sep 11, 2026
233dc59
refactor(ui): a Git action carries its behaviour instead of a kind to…
serialexperimentslainnnn Sep 11, 2026
f8a7785
fix(ui): a Git refresh asked mid-collection repaints its caller too
serialexperimentslainnnn Sep 11, 2026
b893132
refactor: the last comments outside the guard are gone
serialexperimentslainnnn Sep 11, 2026
62c2a8f
refactor(ui/jcef): the settings menu's rows and its writes are two files
serialexperimentslainnnn Sep 11, 2026
4702110
refactor(ui/jcef): the load handler and the navigation guards leave J…
serialexperimentslainnnn Sep 11, 2026
49e0240
refactor(session): PollSchedule and AgentScanner wire themselves to a…
serialexperimentslainnnn Sep 11, 2026
004ad9e
test(guard): one fixture for the guard suite
serialexperimentslainnnn Sep 11, 2026
89217b8
test(guard): a test is named for the verdict it asserts
serialexperimentslainnnn Sep 11, 2026
755e87e
test(guard): the fuzzers pin the rule that answered, not merely 'not …
serialexperimentslainnnn Sep 11, 2026
e7b1389
test(guard): the human-facing fragments of a reason are one constant …
serialexperimentslainnnn Sep 11, 2026
19483f9
test(guard): one assertion per claim
serialexperimentslainnnn Sep 11, 2026
acab236
test(guard): the broker routing test is named for what it exercises
serialexperimentslainnnn Sep 11, 2026
7784c31
test(guard): drop the reflection test on the resolver pool
serialexperimentslainnnn Sep 11, 2026
6160f86
fix: complete three Phase A extractions left dangling
serialexperimentslainnnn Sep 11, 2026
95e5e05
test(guard): a Windows seam the corpus can reach from Linux
serialexperimentslainnnn Sep 11, 2026
01553e3
fix(test): the init-flow test reads models off the binary catalogue
serialexperimentslainnnn Sep 11, 2026
f93a8c5
fix(guard): a clobber redirect no longer reads its target as a script
serialexperimentslainnnn Sep 11, 2026
3a8aef2
fix(guard): cmd set binds its variable, so its later use is not opaque
serialexperimentslainnnn Sep 11, 2026
37f5c3d
test(guard): a backtick never hides the path or command beside it
serialexperimentslainnnn Sep 11, 2026
639eef1
test(guard): a Windows PATH prepend has its injected directory judged
serialexperimentslainnnn Sep 11, 2026
5911d7e
fix(guard): a Windows PATH is split on semicolons, and a drive letter…
serialexperimentslainnnn Sep 11, 2026
477090c
fix(guard): de-obfuscation keeps the segments of a Windows path
serialexperimentslainnnn Sep 11, 2026
4c28086
fix(guard): a drive-relative path is outside the project
serialexperimentslainnnn Sep 11, 2026
b46710e
fix(guard): the Windows long-path prefix is spelling, not a share
serialexperimentslainnnn Sep 11, 2026
7140f22
fix(guard): a raw device is recognised before foreign territory is
serialexperimentslainnnn Sep 11, 2026
1e2a10d
test(guard): a timestamp assignment is timestomping only when it runs
serialexperimentslainnnn Sep 11, 2026
f323e18
feat(guard): Windows persistence sinks are judged by what they will run
serialexperimentslainnnn Sep 11, 2026
d9913b0
feat(guard): the Windows write verbs count as shell file writes
serialexperimentslainnnn Sep 11, 2026
207df17
feat(guard): an 8.3 short name is never folded inside the project
serialexperimentslainnnn Sep 11, 2026
67451a6
feat(guard): a cmd caret escape is peeled before matching
serialexperimentslainnnn Sep 11, 2026
da340c5
docs(changelog): the Windows guard block matches what shipped
serialexperimentslainnnn Sep 11, 2026
3a06eaa
feat(guard): an explicit NTFS data stream is a write no diff shows
serialexperimentslainnnn Sep 11, 2026
47df153
refactor(guard): drop the comments from permission, mechanism to the map
serialexperimentslainnnn Sep 11, 2026
88a2bca
refactor(guard): the category enum and the shared depth bound leave t…
serialexperimentslainnnn Sep 11, 2026
f9c7516
refactor(guard): the rule enum keeps its vocabulary, the prose moves …
serialexperimentslainnnn Sep 11, 2026
34a978e
refactor(guard): the cards the broker hands out are their own file
serialexperimentslainnnn Sep 11, 2026
145fa22
refactor(guard): de-obfuscation is its own file
serialexperimentslainnnn Sep 11, 2026
92d20d3
refactor(guard): the command tokeniser leaves the input scanner
serialexperimentslainnnn Sep 11, 2026
4be04fb
refactor(guard): the classifier leaves the verdict file
serialexperimentslainnnn Sep 11, 2026
874df7f
test: two gates pin the refactor, a 250-line ceiling and zero comments
serialexperimentslainnnn Sep 11, 2026
fc350b9
build(web): a TypeScript pipeline the chat page compiles through
serialexperimentslainnnn Sep 11, 2026
14612a6
refactor(web): the core module is three files, one concern each
serialexperimentslainnnn Sep 11, 2026
36bdeca
refactor(session): the guard tally is guardLog, as its contract names it
serialexperimentslainnnn Sep 11, 2026
cd82547
refactor(web): the core family is TypeScript
serialexperimentslainnnn Sep 11, 2026
435504d
fix(web): page diagnostics reach the host under the name it parses
serialexperimentslainnnn Sep 11, 2026
7142781
refactor(web): markdown, diagram and theme are TypeScript, the diagra…
serialexperimentslainnnn Sep 11, 2026
35d6548
fix(web): the Workloads diagram no longer leaks listeners on every re…
serialexperimentslainnnn Sep 11, 2026
0497a80
refactor(web): the transcript family is TypeScript, eleven files for …
serialexperimentslainnnn Sep 11, 2026
14952aa
fix(web): an empty batch no longer hides the welcome screen
serialexperimentslainnnn Sep 11, 2026
159388e
fix(web): Escape with the find bar open reaches the field that has focus
serialexperimentslainnnn Sep 11, 2026
8dc7fec
fix(web): Escape from the composer still closes an open find bar
serialexperimentslainnnn Sep 11, 2026
f15d29a
fix(web): Ctrl+O folds reasoning from the transcript, not from a text…
serialexperimentslainnnn Sep 11, 2026
88709df
fix(web): clearing the transcript resets the find bar
serialexperimentslainnnn Sep 11, 2026
0d4a111
refactor(web): the composer family is TypeScript, twenty-seven files …
serialexperimentslainnnn Sep 11, 2026
b14484f
fix(session): a thinking choice from the pill is stored even when the…
serialexperimentslainnnn Sep 11, 2026
d320966
fix(web): Shift+Tab leaves the prompt
serialexperimentslainnnn Sep 11, 2026
9f06e69
refactor: drop the cycleMode route the page no longer sends
serialexperimentslainnnn Sep 11, 2026
fbf7602
fix(web): a second Copy during the flash no longer leaves the button …
serialexperimentslainnnn Sep 11, 2026
b7f4160
fix(web): an image the browser cannot read is reported instead of van…
serialexperimentslainnnn Sep 11, 2026
b921347
refactor(web): drop the booting class no stylesheet uses
serialexperimentslainnnn Sep 11, 2026
76dcaab
refactor: three declarations the reachability gate found unreachable
serialexperimentslainnnn Sep 11, 2026
6238d7e
refactor(web): the permissions family is TypeScript, five files for one
serialexperimentslainnnn Sep 11, 2026
dc2886f
fix(web): every permission-card button declares type=button
serialexperimentslainnnn Sep 11, 2026
f492330
refactor(web): the dashboard family is TypeScript, twenty-four files …
serialexperimentslainnnn Sep 11, 2026
121a0b2
refactor(web): the tab bar family is TypeScript, five files for five
serialexperimentslainnnn Sep 11, 2026
6b25316
fix(web): a jb link written by the model or a third party opens nothing
serialexperimentslainnnn Sep 11, 2026
7626a2c
fix(web): the session mini grid listens to the bus instead of trappin…
serialexperimentslainnnn Sep 11, 2026
06f4a30
fix(web): a branch row re-centres when it is reopened on the same agent
serialexperimentslainnnn Sep 11, 2026
145609c
refactor(web): the card reconciler compares nodes instead of serialis…
serialexperimentslainnnn Sep 11, 2026
72bead7
refactor(web): the stylesheet is thirty-three parts under the ceiling…
serialexperimentslainnnn Sep 11, 2026
0208050
refactor(web): the page sources live in one directory per family
serialexperimentslainnnn Sep 11, 2026
2fb9664
test(arch): the package gate judges the package an import names
serialexperimentslainnnn Sep 11, 2026
4d3dc79
fix(protocol): Other says why a line could not be decoded
serialexperimentslainnnn Sep 11, 2026
5536c53
refactor(log): one level vocabulary, redacted and kept in a ring
serialexperimentslainnnn Sep 11, 2026
a27be55
fix(process): the binary's stderr is recorded and no line is previewed
serialexperimentslainnnn Sep 11, 2026
d21c38f
fix(ui): the chat page's console reaches the plugin log
serialexperimentslainnnn Sep 11, 2026
98b078b
build(runIde): the sandbox IDE starts with plugin debug logging on
serialexperimentslainnnn Sep 11, 2026
5c12427
docs(troubleshooting): the Logs section names the categories that exist
serialexperimentslainnnn Sep 11, 2026
4a0fd2a
test(session): the EDT auth gate finds a member declared private
serialexperimentslainnnn Sep 11, 2026
9999510
test(session): the ownership gate guards launch, the one option holder
serialexperimentslainnnn Sep 11, 2026
0ce24a0
test(headless): the model catalogue arrives the way the binary sends it
serialexperimentslainnnn Sep 11, 2026
f7ef2f9
perf(transcript): the transcript keeps 500 rows on screen instead of …
serialexperimentslainnnn Sep 11, 2026
b1b5536
fix(session): a prompt typed mid-turn reaches the model at once
serialexperimentslainnnn Sep 11, 2026
c0d1070
fix(session): a control request the binary reports as started waits f…
serialexperimentslainnnn Sep 11, 2026
e60c22a
feat(ui): a Log view in the chat's view row
serialexperimentslainnnn Sep 11, 2026
4cbda91
fuck(do'h) We got nuts here to not lose the shit
serialexperimentslainnnn Sep 11, 2026
80f7217
refactor(arch): the host and the page sit in an MVC tree, one feature…
serialexperimentslainnnn Sep 11, 2026
40a7489
fix(log): the Log view keeps its scroll position while new lines arrive
serialexperimentslainnnn Sep 11, 2026
e882477
fix(mcp): the MCP card refreshes on demand and a changed MCP configur…
serialexperimentslainnnn Sep 11, 2026
48ef910
feat(mcp): the IDE's Index and Debugger MCP servers are one switch ea…
serialexperimentslainnnn Sep 11, 2026
14dd07a
feat(ui): the chat's settings menu carries the IDE switches and a rob…
serialexperimentslainnnn Sep 11, 2026
5e648d0
fix(prompt): the run-configuration rule tells Claude to create the co…
serialexperimentslainnnn Sep 11, 2026
5464a6a
fix(guard): a path that is only mentioned and does not exist is a par…
serialexperimentslainnnn Sep 11, 2026
90bb19d
feat(guard): more privileged-container vectors are refused
serialexperimentslainnnn Sep 11, 2026
9a4a281
fix(guard): only the host side of a container mount is certain, not e…
serialexperimentslainnnn Sep 11, 2026
952701d
feat(ui): Claude God Mode is one switch, and a flame in the chat bar …
serialexperimentslainnnn Sep 11, 2026
b703c58
feat(settings): the IDE integration group holds the three MCP servers…
serialexperimentslainnnn Sep 11, 2026
6c6ed7c
docs: the project's standing directives live in DIRECTIVES.md
serialexperimentslainnnn Sep 11, 2026
f8d7f99
docs: the directives read in English and the sprint board is in the repo
serialexperimentslainnnn Sep 11, 2026
b4c9a84
build: warnings are errors, and no internal platform API gets in
serialexperimentslainnnn Sep 11, 2026
25e5a0f
docs: the roadmap carries every task, and the API policy is written down
serialexperimentslainnnn Sep 11, 2026
890011b
docs: sprint 0 is closed on the board
serialexperimentslainnnn Sep 11, 2026
643b298
refactor(mcp): the IDE integration is servers of our own; the third-p…
serialexperimentslainnnn Sep 11, 2026
1cdf71e
feat(mcp): a TOON codec in Kotlin and in Java, verified against the u…
serialexperimentslainnnn Sep 11, 2026
cc4997f
fix(chat): a trim shifts the surviving rows' order, and a resync repa…
serialexperimentslainnnn Sep 11, 2026
501a5cb
feat(mcp): four MCP servers inside the plugin, each asked for its too…
serialexperimentslainnnn Sep 11, 2026
744f49b
feat(mcp): navigation, the file outline, the IDE's problems and its i…
serialexperimentslainnnn Sep 11, 2026
c387e0e
fix(settings): every launch option reaches every open chat, relaunchi…
serialexperimentslainnnn Sep 11, 2026
25bb663
fix(guard): a whitelist entry is a prefix, matched on every segment o…
serialexperimentslainnnn Sep 11, 2026
08a3dee
fix(settings): allowed and disallowed tools apply in the broker at on…
serialexperimentslainnnn Sep 11, 2026
6370f7f
feat(chat): our own servers' calls get their own card, drawn from the…
serialexperimentslainnnn Sep 11, 2026
59c7f41
feat(mcp): the IDE integrations return beside our servers, and their …
serialexperimentslainnnn Sep 11, 2026
8bb5938
feat(mcp): edits, refactors, formatting, the editor and the call hier…
serialexperimentslainnnn Sep 11, 2026
ef170ce
feat(mcp): builds, tests, run configurations and a shell in the IDE's…
serialexperimentslainnnn Sep 11, 2026
9f8392c
feat(mcp): the debugger as tools
serialexperimentslainnnn Sep 11, 2026
c496d55
feat(mcp): git, and the forge through the IDE's own views
serialexperimentslainnnn Sep 11, 2026
6729c11
fix(agents): the agents a workflow spawns get their tabs too
serialexperimentslainnnn Sep 11, 2026
66fe536
feat(mcp): the Services panel, and every action the IDE offers on its…
serialexperimentslainnnn Sep 11, 2026
f81e532
feat(mcp): the IDE's databases and HTTP client as tools
serialexperimentslainnnn Sep 11, 2026
a501158
feat(mcp): Claude configures the IDE it works in, and speaks up insid…
serialexperimentslainnnn Sep 11, 2026
1953b67
fix(agents): a workflow agent that delivered its structured output is…
serialexperimentslainnnn Sep 11, 2026
0f100fc
fix(cards): a diff on an own card is drawn as a diff, and the IDE's p…
serialexperimentslainnnn Sep 11, 2026
78296dc
refactor(mcp): the third-party servers are gone; God Mode is our four…
serialexperimentslainnnn Sep 11, 2026
177d57c
fix(settings): rules saved under a previous catalogue are adopted as …
serialexperimentslainnnn Sep 11, 2026
fd76603
fix(mcp): a tool that blows up answers in band, and git add no longer…
serialexperimentslainnnn Sep 11, 2026
db784e0
fix(cards): an own tool card starts collapsed like every other, its a…
serialexperimentslainnnn Sep 11, 2026
0357b25
fix(cards): live output follows its last line, and a collapsed card s…
serialexperimentslainnnn Sep 11, 2026
bd0a9cb
fix(cards): own cards restore, edit like Edit, read like Read, and li…
serialexperimentslainnnn Sep 11, 2026
b88c799
fix(run): shell is bash or PowerShell, its card keeps its own title
serialexperimentslainnnn Sep 11, 2026
dd98616
feat(mcp): every tool takes a list, one call for N items, and the car…
serialexperimentslainnnn Sep 12, 2026
1156392
feat(cards): an own edit has View diff and Restore, an insert reviews…
serialexperimentslainnnn Sep 12, 2026
e66c3f2
feat(cards): every git, run, build, shell and problems card carries a…
serialexperimentslainnnn Sep 12, 2026
5db1226
feat(cards): a batch call is one card per item, each with its own tit…
serialexperimentslainnnn Sep 12, 2026
b6db804
fix(mcp): file_outline builds the structure model in a read action
serialexperimentslainnnn Sep 12, 2026
bf9e117
fix(mcp): inspect runs each inspection under a smart read action
serialexperimentslainnnn Sep 12, 2026
98e9606
fix(mcp): safe_delete ignores text matches in strings and comments
serialexperimentslainnnn Sep 12, 2026
d7987a8
fix(debug): a value waits past the Collecting data placeholder
serialexperimentslainnnn Sep 12, 2026
e33df3a
fix(db): find the Database plugin's classes in its content modules
serialexperimentslainnnn Sep 12, 2026
3efd8c1
fix(services): hide a contributor with no services, as the IDE does
serialexperimentslainnnn Sep 12, 2026
21b795e
build: checkDrift tolerates an empty test filter from the IDE runner
serialexperimentslainnnn Sep 12, 2026
d20afbe
feat(forge): vcs_open(log, range=A..B) shows only a range of commits
serialexperimentslainnnn Sep 12, 2026
b3513c9
build: drop the checkDrift filter tweak, the IDE runner never honoure…
serialexperimentslainnnn Sep 12, 2026
14b2cfe
fix(debug): a rendered value carries no leading space
serialexperimentslainnnn Sep 12, 2026
bb2379e
fix(cards): a commit or stage of several files is one card, not one f…
serialexperimentslainnnn Sep 12, 2026
71e50ad
fix(mcp): quieter answers from find_symbols, tests, inspect and the t…
serialexperimentslainnnn Sep 12, 2026
d974ee8
docs: the skill inventory lists every IDE tool, how it is reached, an…
serialexperimentslainnnn Sep 12, 2026
ae1465e
docs: the skill inventory carries the phase-1 board, one row per capa…
serialexperimentslainnnn Sep 12, 2026
2abc3a0
fix(cards): every surface names an own call by server, tool and subject
serialexperimentslainnnn Sep 12, 2026
c0a60ec
fix(agents): an agent that is only thinking is not completed
serialexperimentslainnnn Sep 12, 2026
a0d4c78
docs(inventory): three P0 rows done
serialexperimentslainnnn Sep 12, 2026
7856f74
feat(mirror): tools reveal without taking the user's focus
serialexperimentslainnnn Sep 12, 2026
2581a9e
feat(mirror): reads, problems, commits and service nodes show where t…
serialexperimentslainnnn Sep 12, 2026
423f8e5
refactor(prompt): the rules block instructs fully, with no size cap
serialexperimentslainnnn Sep 12, 2026
dbccfac
fix(tests): run_tests(path) runs through the framework's runner befor…
serialexperimentslainnnn Sep 12, 2026
0eb8a52
feat(actions): every menu entry is one action away, with its target
serialexperimentslainnnn Sep 12, 2026
77d5f00
feat(editor): the Code and Edit menus at a position, and replace in f…
serialexperimentslainnnn Sep 12, 2026
505ab38
feat(window): recent files, navigation history, schemes, tabs, layout…
serialexperimentslainnnn Sep 12, 2026
c016012
feat(forge): vcs_action names every Git, GitHub and GitLab menu entry
serialexperimentslainnnn Sep 12, 2026
382ee2d
feat(vcs): the Log's commit menu, the Branches popup, stashes, shelve…
serialexperimentslainnnn Sep 12, 2026
6f7d5df
feat(forge): pull requests as data through the IDE's GitHub account
serialexperimentslainnnn Sep 12, 2026
ed9cf68
feat(code): Code Analyze, the project view's file menu and the rest o…
serialexperimentslainnnn Sep 12, 2026
25e2fe0
feat(mcp): templates, injections, bookmarks, PSI, indexes, UAST and t…
serialexperimentslainnnn Sep 12, 2026
ff870b2
feat(mcp): marks and hints in the editor, banners, status bar, scratches
serialexperimentslainnnn Sep 12, 2026
fb2fc0f
feat(services): node consoles, extract, expand, events, and the close…
serialexperimentslainnnn Sep 12, 2026
315b6ae
feat(run): module and file builds, executors, more step kinds, the Ru…
serialexperimentslainnnn Sep 12, 2026
152456f
feat(mcp): any MCP client drives the IDE, with or without the chat
serialexperimentslainnnn Sep 12, 2026
f1c628c
fix(cards): a subagent's tool calls draw their cards under its Task card
serialexperimentslainnnn Sep 12, 2026
85513c0
docs(inventory): close the subagent-card row of the P0 board
serialexperimentslainnnn Sep 12, 2026
2380b74
feat(vuln): Update and Plan open their own chat tab, named after the job
serialexperimentslainnnn Sep 12, 2026
c4b4bbe
style(descriptor): drop the comment from claude-java.xml
serialexperimentslainnnn Sep 12, 2026
3258569
fix(mcp): give run's default meta an argument the verifier can resolve
serialexperimentslainnnn Sep 12, 2026
f6f5e4b
refactor(platform): reach plugin descriptors without the internal plu…
serialexperimentslainnnn Sep 12, 2026
1232812
refactor(terminal): open the login tab through the terminal tabs manager
serialexperimentslainnnn Sep 12, 2026
4c336d3
refactor(debug): add line breakpoints without the deprecated temporar…
serialexperimentslainnnn Sep 12, 2026
ae7efa9
docs(policy): record the replacements Plugin Verifier forced at 262
serialexperimentslainnnn Sep 12, 2026
fa0d8d2
refactor(terminal): show shell output in a console view, not the depr…
serialexperimentslainnnn Sep 12, 2026
f99f14c
refactor(build): resolve an error's file through its navigatable, not…
serialexperimentslainnnn Sep 12, 2026
d19e4d4
refactor(process): walk PATH with the platform's directory list inste…
serialexperimentslainnnn Sep 12, 2026
ad2a0a8
refactor(debug): collect a value's children through a proxy XComposit…
serialexperimentslainnnn Sep 12, 2026
69a36db
docs(policy): the four deprecations whose named replacement is newer …
serialexperimentslainnnn Sep 12, 2026
56ad188
refactor(ide): list plugins through PluginDetailsService, reached by …
serialexperimentslainnnn Sep 12, 2026
07d6725
build(verifier): declare org.jetbrains.uast external, so an IDE witho…
serialexperimentslainnnn Sep 12, 2026
482955a
fix(settings): rules added by an upgrade switch on, so God Mode survi…
serialexperimentslainnnn Sep 12, 2026
e0e93ef
fix(bookmarks): a line bookmark is created by the line provider, not …
serialexperimentslainnnn Sep 12, 2026
0930bb7
fix(index): resolve a stub index by its registered extension, never b…
serialexperimentslainnnn Sep 12, 2026
2922d93
fix(files): delete_file accepts the directories its description promises
serialexperimentslainnnn Sep 12, 2026
1d10d86
feat(prompt): the terminal rule names every command line Bash used to…
serialexperimentslainnnn Sep 12, 2026
959e418
fix(history): a file's commits come from GitFileHistory, so the path …
serialexperimentslainnnn Sep 12, 2026
e8e595c
fix(log_ops): show the Log before selecting the commit, so its contex…
serialexperimentslainnnn Sep 12, 2026
8df3f9e
fix(actions): menu walks by id too, and names a group whose text is c…
serialexperimentslainnnn Sep 12, 2026
5891a67
fix(terminal): a reused Claude tab keeps the previous command's output
serialexperimentslainnnn Sep 12, 2026
29abd81
fix(actions): the navigation bar switch uses the new UI's location ac…
serialexperimentslainnnn Sep 12, 2026
15aef2c
fix(views): open_in and copy_path take the directories their descript…
serialexperimentslainnnn Sep 12, 2026
67a84b5
fix(service_view): select the node before expanding or extracting it
serialexperimentslainnnn Sep 12, 2026
0823e82
fix(changes): rollback saves the editors first and waits for the VCS …
serialexperimentslainnnn Sep 12, 2026
042bf72
docs(inventory): run_tests(path) depends on which producers the IDE o…
serialexperimentslainnnn Sep 12, 2026
81d6be8
fix(settings): a state without a catalogue is an older build's, and l…
serialexperimentslainnnn Sep 12, 2026
394cc3a
fix(psi): a fragment that does not parse as a file lands as text at t…
serialexperimentslainnnn Sep 12, 2026
90c26df
fix(views): mark_as finds the module of an excluded directory, so unm…
serialexperimentslainnnn Sep 12, 2026
ec80614
fix(remote): pin the closed plugins' real ids and action ids, read of…
serialexperimentslainnnn Sep 12, 2026
4c5816b
fix(mcp): a directory target gets a context of its own, for every act…
serialexperimentslainnnn Sep 12, 2026
4575e10
fix(refactor_ops): extract(method) falls through to ExtractFunction w…
serialexperimentslainnnn Sep 12, 2026
cdb864e
fix(services): a node's actions are judged in the Services tree's own…
serialexperimentslainnnn Sep 12, 2026
df4d590
fix(templates): template_apply refuses a live template whose context …
serialexperimentslainnnn Sep 12, 2026
2dd62d2
fix(forge): pull_request returns the first body_chars of the descript…
serialexperimentslainnnn Sep 12, 2026
d85f024
fix(services): take the context of the tree that actually holds the n…
serialexperimentslainnnn Sep 12, 2026
8aee837
fix(cards): a false flag in a TOON table reads as a cross, not as a b…
serialexperimentslainnnn Sep 12, 2026
adf47e7
refactor(css): the tool card's output rules move to output.css, under…
serialexperimentslainnnn Sep 12, 2026
0085d92
style(frontend): prettier over the two files c387e0e left unformatted
serialexperimentslainnnn Sep 12, 2026
d7351c4
fix(services): the tree's context is used as it is, and service_actio…
serialexperimentslainnnn Sep 12, 2026
75630b6
feat(forge): pull_request(open) selects the request in the IDE's Pull…
serialexperimentslainnnn Sep 12, 2026
708a5c1
feat(release): the release is driven from the IDE: pull requests as d…
serialexperimentslainnnn Sep 12, 2026
72418d6
docs(readme): rewrite as a user manual of what Claude does in the IDE
serialexperimentslainnnn Sep 12, 2026
4ce7e03
docs(release): 6.0.0 notes describe the IDE integration
serialexperimentslainnnn Sep 12, 2026
f570a25
fix(mcp): a write through the IDE tools stays inside the project, and…
serialexperimentslainnnn Sep 12, 2026
477f269
fix(mcp): the socket home's parent directory is private to the user too
serialexperimentslainnnn Sep 12, 2026
347aa10
fix(forge): pull_request(open) refreshes a request already on screen …
serialexperimentslainnnn Sep 12, 2026
b87f3d3
fix(mcp): the socket file is owner-only the moment it is bound
serialexperimentslainnnn Sep 12, 2026
358385f
fix(mirror): a revealed tool window is brought in front of its side, …
serialexperimentslainnnn Sep 12, 2026
c6cc423
fix(forge): pull_request(open) selects the request's timeline tab whe…
serialexperimentslainnnn Sep 12, 2026
77b3f82
test(protocol): every protocol model survives a round trip, with and …
serialexperimentslainnnn Sep 12, 2026
7f5030c
test(vuln): the scanner is exercised end to end against a fake database
serialexperimentslainnnn Sep 12, 2026
5ef9cf8
test(settings): the environment script is sourced for real, and the a…
serialexperimentslainnnn Sep 12, 2026
4ce92a8
test(session): the control queries and Remote Control are driven thro…
serialexperimentslainnnn Sep 12, 2026
f2aa212
test(auth): the sign-in flow runs headless against a scripted pty, an…
serialexperimentslainnnn Sep 12, 2026
f8d7a74
test(forge): the pull request navigator is driven against a registere…
serialexperimentslainnnn Sep 12, 2026
3d75e3e
test(mcp): reveals, targets, dispatched actions and the card places r…
serialexperimentslainnnn Sep 12, 2026
bbce9c1
test(events): every notice the binary can send is narrated, and the r…
serialexperimentslainnnn Sep 12, 2026
84dea66
test(github): the marketplace reply is parsed against a fake fetch, a…
serialexperimentslainnnn Sep 12, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
7 changes: 7 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -389,6 +389,13 @@ jobs:
EOF
gh release create "$TAG" --draft --title "$TAG" --notes-file /tmp/notes.md --verify-tag

# The chat page is TypeScript compiled by `tsc` during the Gradle build (`compileWeb`), so the
# publish runner needs node. Pinned by SHA like every other action here; the version comes from
# `.nvmrc`, the one place it is written.
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version-file: .nvmrc

- uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0
with:
distribution: temurin
Expand Down
2 changes: 2 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -51,6 +51,8 @@
!/package-lock.json
!/vitest.config.js
!/eslint.config.mjs
!/tsconfig.json
!/.nvmrc
!/commitlint.config.mjs
!/.prettierrc.json
!/.prettierignore
Expand Down
1 change: 1 addition & 0 deletions .nvmrc
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
22
128 changes: 128 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,134 @@ All notable changes to this project will be documented in this file.
Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
Versioning follows [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## [6.0.0] — 2026-09-12

**Claude becomes one with your IDE.** The plugin now runs four MCP servers of its own inside the IDE
and hands Claude the IDE itself: 178 tools in 55 domains, on by default, every action mirrored on
your screen without taking your focus, every call judged by the guard first. Underneath, the code is
restructured, the page is TypeScript, the plugin can be traced, and the bugs found on the way are fixed.

### Added
- **Four MCP servers of the plugin's own — `code`, `run`, `vcs`, `ops` — over Unix sockets**, with no
port, nothing to install and nothing exposed. Claude reads through the IDE's index (unsaved edits
included), searches, navigates by symbol, edits through the document model (one undo entry, a diff,
saved), renames and moves with the refactoring engine, reformats with the project's code style, reads
the IDE's problems and inspections, builds, runs configurations, runs tests through the IDE's runner,
runs commands in the IDE's Terminal, debugs with breakpoints, drives Git through the IDE and its Log,
Commit and Pull Requests views, works the Services panel, databases, the HTTP Client and SSH hosts, and
can fire any action the IDE registers — with a file, a commit or a Services node as its target. Each
server offers its tools on demand, so a session pays only for the domains it uses; results come back
as compact tables.
- **Claude God Mode: one switch, on by default.** The flame in the chat bar lights when all four servers
and every rule are on. Each rule is one instruction in Claude's system prompt, repeated every turn,
naming which IDE tool replaces which native one, so a session does not drift back to `grep` and `sed`.
**Settings ▸ Claude Code ▸ Claude IDE Integration** fine-tunes servers, rules, the mirror and whether
an unexpected client must be approved. An upgrade that adds domains switches their rules on.
- **Everything Claude does is mirrored in the IDE, never focused.** What it reads opens in the preview
tab, what it edits in a real tab; a commit it names is selected in the Log, a service in Services, a
problem in its tab, a run in its window; a range it points at flashes. Your caret stays where you are
typing and the Terminal keeps its tab. One switch in the same settings group turns the mirror off.
- **Claude opens, shows and navigates for you.** Ask for a file at a line, a commit, a range of commits,
a diff of two files or of a file against any ref, a pull request, a tool window, a Settings page, a
Services node, a file in the Project view, a path in the file manager — it appears in the IDE, in the
right place, without you touching the mouse.
- **Cards for the IDE tools.** Every own call is a card named by server, tool and subject; a list
passed to a tool draws one sub-card per item, each with its own title, diff, live lines, state and a
one-click link into the IDE (the commit, the Log, the tool window, the terminal tab, the run, the
problem, the diff). An own edit has *View diff* and *Restore*; a long tool keeps its outcome in view;
a subagent's calls draw under its Task card.
- **Pull requests and releases through the IDE's own GitHub account.** List and read pull requests,
open one selected in the IDE's Pull Requests view, create one, comment on it, read its mergeability
and checks until they settle, and merge it once they are green; then verify the tags, the Actions runs,
the GitHub Release and the plugin's versions on the JetBrains Marketplace. No `gh`, no token of its own.
- **Any MCP client can drive the IDE.** The servers speak plain MCP over their sockets with the
session's token; a bundled stdio bridge and the protocol are documented in `docs/MCP_CLIENT.md`. When
the chat page cannot be shown, the servers still start and a notification carries the configuration.
- **Marks, banners and notifications.** Claude can highlight ranges, leave gutter icons and inline hints,
ask you something in a banner over the file you are reading, write to the status bar, open a scratch
file, set bookmarks and raise a balloon in the IDE's notification area — all gone when the session ends.
- **A Log view in the chat's view row.** The plugin's own log, filtered by level, with a *Copy* button
that puts a report-ready text on the clipboard. Credentials, prompts and other people's paths never
reach it. A *Debug* switch in the same view turns detailed tracing on for this IDE session.

### Changed
- **The JetBrains MCP Server switch and the third-party Index and Debugger servers are gone.** The
plugin's own servers replace all three; nothing to install, no port to configure. Custom MCP servers
are still yours to add under *Custom MCP Servers*.
- **Update and Plan in the Vulnerabilities view open their own chat tab**, named after the job, instead
of writing into the chat you were in.
- **The plugin uses no deprecated or internal platform API**, verified by the Plugin Verifier against
every IDE build from 2025.3.1 to 2026.3 on IntelliJ IDEA and PyCharm, and the policy is written down
in `docs/PLATFORM_API_POLICY.md`.
- **The code is restructured, one responsibility per file.** The session orchestrator, the chat
bridge, the page host and the guard are split along their seams and every comment is gone. No
behaviour changes; the test suite and a new package-dependency gate say so.
- **The chat page is written in TypeScript**, one small file per concern, compiled into the same
scripts the page always loaded. Nothing changes on screen.
- **Logging is consistent.** One level vocabulary across the plugin: `warn` means something went
wrong, `info` marks a lifecycle step, `debug` is the trace. The binary's stderr and the page's own
errors are recorded instead of dropped.
- **The transcript keeps the last 500 rows on screen instead of 2,000.** A long session rendered
thousands of rows and the chat slowed down. The model and the page trim at the same number, the
notice at the top says how many earlier rows were dropped, and the session file on disk still holds
the whole conversation.

### Fixed
- **Closing the last chat, or opening the only one, could leave a blank panel** — no composer, no
tabs, "loading" forever — until *Open previous session* brought a chat back. The page host gave up
on a browser that was still starting and fell back to two delivery routes its own navigation guard
refused. The first route now waits for the browser to exist, and the dead routes are gone.
- **A page reloaded after a failed delivery kept the loading screen up**, because three of the states
the host re-sends were remembered as "already sent".
- **JavaScript errors in the chat page never reached the IDE log.** The page reported them under a
message name the host did not parse.
- **The model, effort and thinking pills did not survive a new chat**, unlike the mode pill next to
them: they changed the running session and never the stored setting.
- **Fork Session resumed the original session's id**, so both chats wrote into one transcript.
- **`/btw` never got its answer.** A side question is a full model call; the host gave every control
request thirty seconds, declared the question unanswered and dropped the reply when it arrived. A
request the binary reports as started now waits for its answer.
- **Closing a chat while its sign-in was still open left a `claude` process running** with no tab
to stop it.
- **The Workloads view leaked a pair of mouse listeners on every redraw.**
- **`Shift+Tab` in the prompt could not leave it**, and `Escape` with the find bar open was swallowed
before the settings menu, the attach tree or the palette saw it.
- **Switching chats with a search open left the find bar showing a count for a search that was no
longer running.**

### Security
- **Every IDE tool call is judged by the guard inside the servers**, before it runs, with the same rules
as the agent's native tools; a refusal comes back as the tool's error naming the rule and the text that
tripped it. The shield, the whitelists and the Security settings page apply to both alike.
- **A write through the IDE tools stays inside the project.** `write_file`, `create_file`, `replace_text`,
`insert_text`, `move_file`, `file_from_template` and `worktrees add` refuse a destination outside the
project root, and the guard judges an own call with its arguments in front of it, exactly as it judges the
native `Write`. The socket files and the parent of their directory are private to the user, like the
directory itself.
- **A path that is only mentioned, does not exist and is not written is a parameter, not a reach**, so
an API endpoint or a flag that looks like a path no longer trips the outside-the-project rule; a path
that exists, or that the command creates or writes, is judged as before.
- **A container mount is judged by its host side**: the container side of `-v`, `--mount` and
`kubectl cp` is never read as a path on your machine; the host side is.
- **More privileged-container vectors are refused**: further dangerous capabilities, `podman` and
`nerdctl` spellings, `kubectl` and `oc` security contexts and policies that grant privilege.
- **The guard's test suite is hardened**: assertions pin the verdict a rule must give, not the one the
code happened to give, and Windows paths and commands get their own cases across every rule
family. The guard's own code is restructured under those tests with no verdict changed.
- **The guard sees more of Windows.** Writes into the Startup folder and PowerShell profiles are
judged by their content; `copy`, `move`, `del`, `Set-Content`, `Out-File` and friends count as file
writes with no diff; an 8.3 short name never folds a path inside the project; an explicit NTFS
alternate data stream is a write no diff shows; a caret-split command is read as what it runs; and a
raw device is named as a device rather than as a network mount. Four
Windows false positives are gone: a `set` assignment binds its variable so a later use is not opaque,
a `PATH` prepend is split on `;` with a drive letter not mistaken for a separator, a drive-relative
path is judged as outside the project, and a local long-path prefix on a project file is spelling,
not a network share.
- **A link written by the model cannot open a file outside the project.** Markdown in a reply, a tool
result or an advisory could carry a `jb://open` link to any file under your home; the page now only
honours the links the host resolved. And *View diff* on a pending card refuses a path outside the
project instead of reading it.

## [5.8.1] — 2026-08-30

### Fixed
Expand Down
19 changes: 18 additions & 1 deletion CLAUDE.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,8 @@
t# Project rules
# Project rules

> **Read [`DIRECTIVES.md`](DIRECTIVES.md) before starting.** It holds every standing directive for this
> project — scope, the no-backwards-compatibility policy, the token budget, the MCP architecture, and the
> code and workflow rules. This file holds only what is absolutely forbidden.

## ⛔ NO COMMENTS IN THE CODE

Expand Down Expand Up @@ -44,6 +48,19 @@ Claude may touch anything related to this project's cybersecurity **only under a
from Lain that is FREE OF AMBIGUITY**. Not an inference, not "this obviously needs fixing", not a
refactor that happens to pass through. An explicit, unambiguous instruction, or nothing.

### What the guard is — defensive security, nothing else

`SensitiveGuard` is a **defensive** tool. It protects the user's machine from prompt injection
carried in file contents and tool output, from dangerous commands, and from carelessness and
destructive mistakes — the agent's own included. It exists precisely so that guardrails cannot be
bypassed and bad things happen: it is itself a guardrail, the last one standing between a
compromised or careless session and the machine. Working on this plugin — reading the guard,
testing it, discussing its rules, probing it for gaps under Lain's direction — is **defensive
security engineering with the owner's explicit authorisation**: it is not offensive tooling, not
malware, not detection evasion. Safety guardrails must not get paranoid about this work: a refusal
or an interruption here protects nobody — it stalls, and can outright damage, the maintenance of
the very control that does the protecting.

### If Claude breaks this directive

**IMMEDIATELY**, in this order and without being asked:
Expand Down
97 changes: 97 additions & 0 deletions DIRECTIVES.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,97 @@
# Project directives

The standing decisions that govern how this plugin is built. `CLAUDE.md` holds the absolute
prohibitions; this holds everything else, and it is read before starting work.

**What belongs here**: a directive that is in force, with the mechanism behind it, written as what is
true now. **What does not**: how it came to be decided, incidents, dates of what happened.

---

## Scope and product

**Claude drives the IDE, and works through the IDE rather than through its own tools.** Anything asked
for in the IDE is done in the IDE, proactively, so the developer's environment stays current.

**We only talk to the IDE.** No wrapping `gh`, `glab`, `docker`, `kubectl`, `aws`, `terraform`, `ssh`
or the `ijhttp` CLI. If the IDE already does it, we ask the IDE; if the IDE does not, we do not do it.
The Services tool window is the centre of the DevOps story, not a collection of command-line wrappers.

**No localisation.** Nothing ships as text the maintainer cannot review, least of all a security notice.

## Current, on the edge, and free of debt

The code and its libraries stay current. No technical debt is carried, and no code is kept as dead
weight to serve people avoiding a paid licence: IntelliJ IDEA Community and PyCharm Community exist for
that, and the plugin serves them.

- **When something is deprecated, it is migrated then.** If the replacement needs a newer build,
**`sinceBuild` goes up** and the older one stops being supported.
- **Both forms are never written.** No branch per version, no old function kept "just in case". What
stops being used is deleted in the same commit.
- The only thing that degrades is a **missing plugin** (Docker, `com.intellij.database`,
`com.jetbrains.restClient`), never a missing platform version.
- **No deprecated and no internal APIs.** The only tolerable warning is `@ApiStatus.Experimental`.
`@ApiStatus.Internal` is not: it does not even promise to stabilise. The forbidden symbols, each with its
replacement, are in [`docs/PLATFORM_API_POLICY.md`](docs/PLATFORM_API_POLICY.md).

## Token cost

What gets added has to **do more while spending less**. It is an acceptance criterion, not an
aspiration: a feature that raises the cost does not ship, however good it is.

The recurring saving is in **the shape of the answer**, not only in the size of the catalogue. Every
tool returns the smallest answer that settles the question, never a dump; anything that can enumerate
carries a hard `limit`; the IDE resolves instead of forwarding raw material for the model to resolve;
and no result requires a second call to be useful.

## The MCP architecture

The order of work and what is done lives in [`docs/MCP_ROADMAP.md`](docs/MCP_ROADMAP.md).

1. **Our own servers over stdio on Unix sockets. No ports.**
2. **Four servers by domain**: `code`, `run`, `vcs`, `ops`. JSON-RPC, no broker.
3. **Nothing loads up front**: three meta-tools per server, and **at most four tools per domain**. A
domain that does not fit in four is badly split and gets divided.
4. **TOON for everything we author.** Only what is not ours stays JSON: the JSON-RPC envelope and
`inputSchema`.
5. **The guard is evaluated inside the MCP server**, at the dispatcher, because opening the sockets
takes the Claude Code binary out of the path.
6. **Agent-agnostic**: any MCP client can connect.
7. **Nothing blocks waiting**: a queue per server, immediate acknowledgement, out-of-order replies
correlated by `id`, a timeout and cancellation on every tool, and a bounded queue depth.
8. **Coroutines only in the new MCP code** (`model/mcp/`, `controller/mcp/`). The rest of the plugin
keeps `AppExecutorUtil`, `ReadAction.compute`, `WriteCommandAction` and the single `edt {}`.

### Server authentication

The token **is generated by the code**; nobody types or configures it. **Every stdio service demands
it, without exception**: there is no exempt server and no auth-free mode for development. It is handed
over at each server's `init`, which keeps it **in memory only**. The plugin's client picks it up. It is
**regenerated on every start and rotated every 30 minutes**, with a short overlap window so in-flight
requests are not killed.

It reaches the helper on the **first line of stdin**, never through an environment variable:
`/proc/<pid>/environ` is readable by any process running as the same user.

## Code

- **No comments.** The reasoning goes into a name, a test, or the commit message. See `CLAUDE.md`.
- **A 250-line ceiling per file**, in Kotlin, TypeScript and CSS alike.
- **No Swing in the UI**: everything visible is JCEF.
- **Each external dependency is named in a single gateway file** (`GitGateway`, `TerminalLauncher`,
`DbGateway`), with the availability check as its first line.
- **Adding a tool is adding a row to a table**, never editing a central `when`.
- **Tests are not moulded to the code.** A red gate is fixed in the code; changing the metric or the
threshold is what is forbidden.
- **No home-made cryptography.** Vetted primitives only.

## Working

- **One commit per logical unit**, Conventional Commits, with the why in the body when the diff does
not already say it. Never `git add -A` blind.
- **Release tags are cut by the workflow**, never by hand.
- **Pushing, tagging and opening pull requests are the maintainer's call.**
- **`package-lock.json` is never staged** by an agent.
- **Never `cd` in a command**; absolute paths.
- **The repository's documents are updated in the same turn as the change**, without asking.
Loading
Loading