Smoke binary now picks a Provider via `OPENPENCIL_LLM_PROVIDER`:
- `anthropic` (default) — `AnthropicProvider` + `OPENPENCIL_ANTHROPIC_API_KEY`
(or legacy `ANTHROPIC_API_KEY`).
- `openai-compat` (or `openai`) — `OpenAiCompatProvider` +
`OPENPENCIL_LLM_API_KEY` + `OPENPENCIL_LLM_BASE_URL`. Standard dialect;
works against DeepSeek, 火山方舟, 百炼, Moonshot, OpenRouter, OpenAI,
any OpenAI-compat vendor.
`agent` feature flags bumped from `["anthropic"]` to
`["anthropic", "openai"]` to pull in the `async-openai`-backed provider.
Default model selection branches on provider:
- anthropic → `claude-sonnet-4-6`
- everything else → `gpt-4o-mini` (override via
`OPENPENCIL_ORCHESTRATOR_MODEL`)
Verified end-to-end against 方舟 CP / glm-5.1 — pipeline topology works
through to a partial-success `Ok` summary. Full run details + the
non-Claude quality finding (`stroke.fill` accepting bare string vs
expected sequence) archived in openpencil-docs
`superpowers/notes/2026-05-24-orchestrator-headless-smoke-result.md`.
Task #27. Routes user messages through `op_orchestrator::classify_intent`
in `chat_session::launch_if_pending` — `Intent::Design` with a configured
`agent::Provider` launches into the orchestrator pipeline; everything
else (chat intent, or design intent with no Provider) falls through to
the existing `ChatProvider` CLI path.
The orchestrator is `async + &mut EditorState`; the chat path is built
around worker threads + blocking iterators (`ChatProvider::send`). Codex
architectural review picked Option E (UI-owned actor + RemoteDocSink +
ack channel):
- Worker thread owns a `RemoteDocSink` that forwards each `apply(cmd)`
over an mpsc channel to the UI thread, which `apply()`s on the real
`EditorState` and replies with an ack carrying a fresh state snapshot.
- `RemoteDocSink::state()` reads from a locally cached mirror updated
by each ack — covers `EditorCommand::InsertSubtree`'s ID-remapping +
history bookkeeping which must run on the UI thread.
- Two mpsc channels per turn: progress deltas (Planning / SubtaskStarted
/ etc.) into the chat transcript, and `DesignCmdReq` for apply +
undo-batch boundaries.
- `BeginUndoBatch` / `EndUndoBatch` are forwarded as own `DesignCmdOp`
variants so the UI can route them through real history batching once
`op-editor-core` exposes that API (currently no-op, matching
`DesktopDocSink`).
Provider source MVP: `OPENPENCIL_ANTHROPIC_API_KEY` (preferred) or
`ANTHROPIC_API_KEY` from env constructs an `AnthropicProvider`. Model
override via `OPENPENCIL_ORCHESTRATOR_MODEL` (defaults to
claude-sonnet-4-6). When neither key is set, design intent falls back
to the chat-CLI path so the user still gets an answer.
Wiring:
- `main.rs` `current_design: Option<DesignSession>` field next to
`current_chat`; mutually exclusive routing in `launch_if_pending`.
- `app_handler.rs` `RedrawRequested` pumps both `pump_commands`
(apply + ack) and `pump_progress` (deltas + summary); WaitUntil tick
schedules a 33 ms wake when either session is in flight.
- `keyboard_input.rs` Enter / send sites pass both Option<&mut> args.
Provider features: `agent` crate gains the `anthropic` cargo feature in
`op-host-desktop/Cargo.toml` so `AnthropicProvider` is reachable
(previously `default-features = false` left it gated out — chat path
only needed the trait + engine wiring).
3 new `RemoteDocSink` tests cover ack round-trip + closed-channel safety
+ undo-batch signal distinguishability. Workspace 1882 passed / 0
failed. cargo fmt + clippy --workspace -D warnings clean.
The `chat_orchestrator.rs::run_design_request` legacy entry stays for
now (used by future single-shot programmatic callers); the live path is
`DesignSession::start`. Validation providers stay `Skipped*` until
jian-skia `captureRegion` + vision LLM crate land (task #28).
Implements the D′ architecture host-side half:
- New `src/pre_validator.rs` with `LintPreValidator` struct and full
`impl PreValidator` that calls `op_design_lint::detect_and_plan()`
and translates each `PlannedFix → Vec<EditorCommand>` via
`planned_fix_to_commands`.
- `ClearEffects` handled by reading current effect count from
`sink.state()` and emitting N × `RemoveNodeEffect` highest→lowest.
- `SetStroke` decomposes into `SetNodeStrokeHex` + `SetNodeStrokeWidth`
to work around the absence of a full-PenStroke EditorCommand.
- Parity tests in `#[cfg(test)]` (binary crate, can't use tests/) prove
`LintPreValidator + EditorState` produces an equivalent document to
`detect_and_fix` for 5 fixtures (invisible container, text explicit
height, stacked horizontal padding, unexpected rotation, text effect).
JSON comparison normalises away the `children: None→Some([])` side
effect in the EditorState walker.
- `chat_orchestrator.rs` swaps `SkippedPreValidator` → `LintPreValidator`.
- `op-design-lint` added to `op-host-desktop/Cargo.toml` dependencies.
Continues the gradient + property-panel polish from the previous
commit and rounds out two new flows the TS app already has:
Gradient stops + effects:
- ColorTarget gains GradientStop(i) + EffectColor(i); HSV picker
preserves alpha across hue/SV drags so a transparent stop stays
transparent. Hex pill stays 6-char; alpha is reattached at commit
and the swatch sits on a 2x2 alpha checker so #00000000 reads as
transparent rather than empty.
- Effects section reflowed into card-style blocks (image #9 spec):
title + minus, X/Y and Blur/Spread 2-col grids, color row with
swatch + rgba(...) text; clicking the swatch opens an HSV picker
bound to that effect index via SetEffectColor.
- Press dispatch on both hosts anchors picker overlays at the
clicked y so they pop adjacent to the swatch instead of the top.
Image + SVG import (toolbar + Fill section "图片" row):
- New FileAction::ImportImageOrSvg / PickFillImage; persistence_image
pops rfd, decodes raster as data: URL, inserts an Image node or
rewrites the selected node's primary fill.
- ImageNode actually renders on the canvas: NodePayload + SceneNode
carry image_src, canvas_viewport_paint.rs decodes the data URL
once and hands raw bytes to RenderBackend::draw_image with a
src-hash cache id. Grey placeholder paints only when decode fails
so transparent PNGs don't get a grey matte underneath.
- SVG import ported to TS-parity (packages/pen-engine svg-parser):
recursive <g> tree walk with inherited fill/stroke/style="...",
viewBox-aware scaling with maxDim cap, multi-subpath split, raw
d preserved on PathNode. Imports land wrapped in a Group named
after the source file.
Locale-aware first run:
- settings_io detects the OS locale (LC_ALL/LANG/LC_MESSAGES with
zh-Hans/zh-Hant heuristics) and seeds editor_ui.locale before
settings.json is read; persisted user choice still wins.
- macOS bundle declares CFBundleLocalizations + AllowMixedLocalizations
so NSOpenPanel / NSSavePanel render in the same language as the
rest of the chrome.
Web host kept exhaustive across the new variants (PickFillImage,
OpenEffectColorPicker, ColorTarget::EffectColor, GradientStop). Two
new files: persistence_image.rs (file-pick handlers, ≤120 lines) and
svg_path_data.rs (path-d tokenizer + bbox + normaliser, split from
svg_import.rs to stay under the 800-line cap). 277 op-editor-core
tests pass.
Port the pen-ai-skills diagnostics layer to a new pure Rust crate
`op-design-lint`: 14 design-lint detectors, the detect_all aggregator,
apply_fixes / detect_and_fix, and golden parity tests against the TS
oracle. Wire it into op-mcp as the read-only debug_validation_report
tool, gated by OPENPENCIL_DEBUG_TOOLS=1.
Detectors: empty_paths, unexpected_rotation, excessive_frame_effects,
invisible_containers, text_explicit_heights, text_effect,
text_corner_radius, text_stroke, text_bg_contrast, edge_section_padding,
stacked_horizontal_padding, sibling_inconsistencies (+ check_consistency),
detect_all.
Also includes: node_util shared helpers + pen-core color/visibility
ports, node_mut field accessors, set_property issue->node mutation
dispatch, golden fixture corpus + TS dump script, structural-parity
test, a CI golden-drift guard, and the gitignore fix so the fixture
docs/ dir is tracked.
This branch's per-commit history was squashed: the original 28 commits
carried fabricated timestamps and could not be honestly reconstructed,
so the work is recorded as a single commit at its real completion time.
Theme-toggle button now paints a Sun glyph in dark mode (click → light) and a Moon glyph in light mode (click → dark); the Sun icon was hardcoded before. Adds Icon::Moon (lucide crescent) and threads theme_mode into TopBar.
Bumps the casement submodule with a fix for the native macOS traffic-light reposition: idempotent absolute placement against resize, baseline invalidation on fullscreen exit, and a poison guard so a transitional re-capture can't drop the lights below their default position.
Task B2 of S3b-2: implements `run_concurrent` — the concurrent executor
that drives screen-group workers via a tokio Semaphore (RAII permits,
FIFO-fair, cap = effective_concurrency), collects per-worker buffered
EditorCommands, replays them into the real DocSink in subtask-plan-index
order, and fan-ins Progress events via mpsc channel.
Also splits concurrent.rs test block into concurrent_tests.rs (STEP 0)
to keep both files under the 800-line ceiling, wired via
`#[path = "concurrent_tests.rs"] mod tests` (same pattern as plan_repair).
Updated run_screen_group_worker signature: now takes Arc<Semaphore> +
mpsc::UnboundedSender<Progress> instead of &mut dyn FnMut(Progress).
Added CountingLlm to test_support for semaphore-cap verification.
Added tokio (sync + rt + macros) to op-orchestrator Cargo.toml.
208 tests pass; clippy -D warnings clean; fmt clean.
concurrent.rs: 432 lines; concurrent_tests.rs: 727 lines.
Existing EditorCommand variants are leaf-only (BatchInsertItem carries
only kind/name/x/y/w/h/fill_hex). The design orchestrator (S3a) must
apply rich nested designs — frames with children, layout, text — so
add InsertSubtree { nodes: Vec<PenNode>, parent_id }.
cmd_insert_subtree validates the parent is a container (or NONE = page
root), remaps every incoming node id to a fresh editor id via
remap_subtree_ids (so an externally-authored subtree can't collide
with live ids), and appends under the parent. The apply arm wraps it
in a history snapshot so the insert is one undo step.
NOT verified locally: op-editor-core does not currently build —
vendor/jian is pinned to unpushed commit 80121906 whose DesignMd*
types op-editor-core depends on are absent from every available jian.
The 8 InsertSubtree tests in command_subtree_tests.rs run once the
jian build is restored.
S3a Plan A.
Add op-figma as a dependency and implement FileAction::ImportFigma — an rfd .fig picker parses the binary file via parse_fig_binary and re-seeds EditorState.
run_action now returns a 3-state ActionOutcome instead of a bool: an import returns PathChangedUnsaved so it is treated as unsaved work (close still prompts) while the Git session is rebound to the now-pathless document. mark_document_saved is split so the rebind can run without refreshing the dirty baseline.
Run bare, the non-bundled binary shows in the Dock as the raw
`openpencil-desktop` executable name with a blank icon — no
`Info.plist` to read `CFBundleName` / the icon from.
New `macos_app::apply()` sets both at startup via objc2:
`NSProcessInfo::setProcessName` for the Dock / menu-bar name and
`NSApplication::setApplicationIconImage` (from an embedded
`assets/icon.png`) for the Dock tile. `[package.metadata.bundle]`
also gains `icon`, so a packaged `.app` carries it natively.
objc2-app-kit / -foundation are pinned to the 0.2 line winit /
casement already lock.
Cmd+C / Cmd+V / Cmd+X did document node-clipboard ops regardless
of focus, so there was no way to paste a prompt into the AI chat
input. They now branch on chat focus: with the chat input focused
they read/write the OS text clipboard (`arboard`), otherwise the
node clipboard as before.
- `clipboard.rs` — thin best-effort arboard wrapper.
- `WidgetHostNative::chat_input_paste` / `chat_input_cut` — append
/ cut on the focused chat buffer.
Drives the user's installed `git` via std::process::Command — the
same approach as the TS app's git-sys backend — so no libgit2/git2 C
dependency enters the workspace.
Covers repo discovery / init, working-tree status, staging, commit,
branch list / create / switch, history + diff, remotes, SSH keys and
credential storage. Adds a worktree-isolated merge orchestrator: a
branch merge runs in a throwaway detached worktree so a conflicting
.op merge never writes conflict markers into the live document — a
clean merge is fast-forwarded back, a conflicting one is reported as
a file-granular ConflictBag with the live tree left pristine.
Add five native-platform features to the winit desktop host
(op-host-desktop), closing the gap with the Electron app:
- Native menu bar (muda) — File / Edit / View / Help plus the macOS
app menu; selections route to the same host actions the keyboard
shortcuts use. Gated to macOS / Windows — muda needs GTK, which
this winit build does not link, so Linux keeps the in-canvas File
menu.
- Auto-update — a background probe of the GitHub releases API
reports status into the settings System tab; a found update
offers to open the download page, and a "Check for Updates" menu
item re-runs the probe.
- File association — argv parsing opens a .op / .pen document on
launch; [package.metadata.bundle] declares the OS-level handler.
- Window-state persistence — position / size / maximized restore
across restarts, with an off-screen guard for monitor changes.
- Drag-and-drop — dropping a .op / .pen file opens it.
Codex review round 1 findings (1 MAJOR + 3 MINOR) all addressed:
monitor-aware restore, failed-startup geometry guard, single-flight
update probe, case-insensitive extension match.
Also sink the agent-settings modal's hand-maintained EN/ZH string
table into the canonical 15-locale op-i18n tables, so the settings
chrome (including the new auto-update strings) is fully translated;
agent_settings_i18n.rs is now a thin op-i18n adapter.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
ChatRequest gains an attachments field; ChatState carries a per-turn
thinking mode, effort level and staged attachments (capped at 4 files /
5 MiB, attachment-only sends allowed). The chat panel grows a controls
row (thinking / effort / attach) and a dedicated attachment-chip row,
with hit-test and paint sharing one input-block origin.
All five providers consume the knobs — Claude maps thinking onto the
SDK token budget, Copilot onto reasoning_effort, the CLI / built-in
transports prepend an in-band directive, the HTTP transport adds body
fields; attachments spill to a private per-turn temp dir (cleaned on
drop) or inline base64. Also wires op-ai-skills into the built-in
provider and op-acp in as the AcpProvider chat backend.
Stage G — the binary `.fig` parser is now end-to-end functional;
`parse_fig` no longer returns NotYetImplemented for binary input.
- image_resolver.rs: resolve_image_blobs walks the converted document
and replaces `__blob:N` / `__hash:HEX` image-fill placeholders with
base64 `data:` URLs (MIME sniffed from magic bytes).
- lib.rs: new `parse_fig_binary(bytes, name, layout_mode) -> FigImport`
runs the whole pipeline — container split → Kiwi decode → tree
build → node conversion → image resolution. `parse_fig`'s Binary
arm delegates to it; `FigParseError::NotYetImplemented` retired in
favour of `Binary(String)`. Entry points re-exported.
- binary_e2e_tests.rs: assembles a real fig-kiwi container from
scratch (hand-built Kiwi schema + data chunks, deflate-compressed)
and asserts the full pipeline yields a PenDocument with the
rectangle at the right position/size + canonical-JSON round-trip.
op-figma 83 tests green (+6); clean build, no warnings.
Closes the §2.1 P0 gap — Figma binary `.fig` parsing.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
First stage of the Figma binary `.fig` parser port (op-figma was
clipboard-JSON only; binary returned NotYetImplemented).
- zip_reader.rs: hand-rolled minimal ZIP reader — EOCD scan, central
directory walk, store (method 0) + raw-deflate (method 8) entries.
Avoids the full `zip` crate dependency tree. 512 MiB per-entry cap.
- container.rs: ports `fig-parser.ts::figToBinaryParts` — unwraps the
ZIP archive form (`canvas.fig` + `images/*`), verifies the
`fig-kiwi` magic, splits length-prefixed chunks, decompresses each
via the deflate→zstd→raw fallback chain (PNG payloads passed
through). Output: decompressed parts + embedded image map.
- deps: flate2 (miniz_oxide pure-Rust backend), ruzstd, base64 — all
license-clean + wasm32-buildable.
Modules are `allow(dead_code)` until `parse_fig` is wired in the
final stage. op-figma 23 tests green (+6).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Closes six verified gaps from the 2026-05-17 TS-vs-Rust gap analysis,
each build- and test-green:
- editor: SetNodeFlip + SetEllipseArc commands (+ set_node_flip /
set_ellipse_arc MCP tools) — schema already had the fields, only
the command path was missing.
- export: export_node_raster crops a raster to one node's bbox;
File -> Export is now selection-aware (single selection -> layer).
- editor: SVG import — hand-rolled parser (shapes + path M/L/H/V/
C/S/Q/T/Z) in svg_import.rs; cubic curves flatten to dense straight
anchors at import time so the renderer/pen-tool stay on their 1:1
straight-segment model. + EditorCommand::ImportSvg + import_svg tool.
- mcp: HTTP transport — mcp_serve::run_http serves MCP over a
TcpListener (--mcp-http <port> <path>); process_message is shared
with the stdio path.
- cli: new op-cli crate (binary `op`) — a dependency-free HTTP MCP
client driving every tool via `op <tool> key=value...`.
- ai: ChatRequest gains thinking/effort fields (ThinkingMode /
EffortLevel, defaults Adaptive/Low to match the TS runtime config).
MCP tool catalog 77 -> 80. Oversized files split to honour the
800-line cap (svg_import, export, mcp_serve, adapter).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Phase 7.3 strangler reorg — add op-app, the thin crate that names the
editor application's composition root.
Investigation found no shared host bootstrap left to extract: the
editor-UI composition (widgets, theme, layout scene) already lives in
op-editor-ui, and each host (op-host-native / op-host-web) owns only
platform-specific backend wiring. So per YAGNI op-app stays thin — it
re-exports op-editor-ui plus the per-platform host entry point behind
its target cfg, and documents the composition. If real cross-host
wiring later emerges, it lands here.
Builds green on both native and wasm32-unknown-unknown.
Phase 7.3 strangler reorg — the final consumer (op-pen-loader) is
repointed off the openpencil-shell-core shim onto op-editor-ui (the
real source crate for the layout scene / scene-var / render-backend
facade), then the shim crate is deleted.
- op-pen-loader: openpencil-shell-core dep -> op-editor-ui;
every openpencil_shell_core:: path -> op_editor_ui::
- git rm crates/openpencil-shell-core/ (lib + jian.rs module + the
two re-export anchor tests, all superseded by op-editor-ui's own
surface; the jian.rs module had no consumers outside the shim)
- stale shell-core / shell-native comment refs in op-editor-core +
op-host-desktop manifests updated
Phase 7.3 strangler reorg — rename the native widget host and the
desktop runner crates to the op- prefix. The desktop+native merge was
declined: keeping the library / binary split preserves the mobile-
checkable op-host-native lib (cargo check -p op-host-native on iOS /
Android, relied on by check-jian-boundaries.sh + the CI mobile job),
which a folded-in winit binary would break. A clean separate rename is
purely mechanical and the brief permits it.
- openpencil-shell-native -> op-host-native (lib op_host_native)
- openpencil-desktop -> op-host-desktop crate; the shipped executable
keeps the stable openpencil-desktop [[bin]] name so release
artifacts + external CLI integrations are unaffected
- every openpencil_shell_core:: path -> op_editor_ui::
- every openpencil_shell_native:: path -> op_host_native::
- doc-comment / manual-smoke note refs updated
Phase 7.3 strangler reorg — rename the web widget host crate to the
op- prefix. The crate's openpencil-shell-core dependency is repointed
to op-editor-ui (the real source crate for the widget facade / theme
/ layout scene / scene vars / render-backend / gesture types).
- crate name: openpencil-shell-web -> op-host-web
- lib name: openpencil_shell_web -> op_host_web
- every openpencil_shell_core:: path -> op_editor_ui::
- native skia.rs include_bytes! path follows the moved assets dir
- smoke harness + lib doc-comment refs updated
Mirror the native host migration for `openpencil-shell-web`. The web
`WidgetHost` now holds an `op_editor_core::EditorState` authoritatively
instead of a shell-core `Document`. The ~30 shared widgets stay
`&Document`-bound and read-only — they are fed a derived `paint_doc`
snapshot rebuilt lazily by `refresh_paint_doc()` whenever
`editor_state_dirty` is set.
- Every mutation routes through an `op-editor-core` mutator + flags the
dirty bit; the snapshot re-derives once before paint / before any
hit-testing input event.
- Hit-test-then-mutate handlers refresh, hit-test on `&paint_doc`,
extract owned results, then mutate `editor_state`; shell-core hit
enums translate via `op_pen_loader::rev::*`.
- `paint` takes `&mut self` to drain the cache at the top of the pass.
- `op-editor-core` / `op-pen-loader` are optional deps behind the
`skia` feature (matching `skia-safe`) so the skia-free wasm32 CI stub
baseline stays clean — `op-pen-loader` pulls `jian-skia` transitively.
- Fix two pre-existing `--features skia` build blockers in `lib.rs`
(missing `Performance` web-sys feature, `canvas` moved before reuse).
No web-editor behaviour change — feature parity preserved.
Flip WidgetHostNative off shell-core's Document onto
op_editor_core::EditorState. The host now owns one authoritative
state; every paint pass + hit-test reads a lazily-derived,
read-only Document snapshot (`paint_doc`), rebuilt via
op-pen-loader's pen_document_to_document + apply_editor_state_ui
whenever an `editor_state_dirty` flag is set.
Why: removes the dual-state strangler scaffold so the canonical
PenDocument model is the only editable state — input handlers
mutate EditorState, widgets stay read-only over the derived
Document. .op save now serializes editor_state.doc; load seeds
EditorState::from_document. shell-core's Document becomes a
paint-only target.
- op-editor-core: add host_support (EditorState::sample,
create_node_for_tool, replace_paths_with_polyline) + re-export
VariableScalar/VariableKind.
- shell-native: rewrite all 8 widget_host submodules onto
editor_state; split press.rs -> press_helpers.rs and keyboard
click routing -> click.rs to stay under the 800-line cap;
boolean_ops becomes a pure compute_boolean_op committed back
through EditorState.
- desktop: persistence / settings_io / chat_session /
model_discovery / main / frame move onto editor_state accessors.
Three additive variable-handling fixes so the editor host can migrate
onto EditorState as a mechanical port:
- Gap 1: add `variable: Option<String>` to ColorPickerState, port
`open_color_picker_for_variable`, and route `color_picker_set_hsv` /
`close_color_picker` through `set_variable_color` when set.
- Gap 2: add `op_pen_loader::editor_state_var_table(&EditorState)`,
folding persisted variables/themes plus the transient active-theme
selection + ref caches into a shell-core VariableTable. Lives in
op-pen-loader (not op-editor-core) to keep op-editor-core wasm-clean
and free of any shell-core dependency.
- Gap 3: confirmed undo/redo of variable create/delete/rename round-
trips for free (EditorSnapshot clones the whole PenDocument); added
tests to lock it in.
Phase 6 strangler scaffolding: WidgetHostNative now holds an
op_editor_core::EditorState alongside the legacy shell-core Document
so the ~30 widgets can migrate onto the canonical model one group at
a time while the workspace stays build-green.
The bridge is intentionally minimal — Document remains the source of
truth (every un-migrated widget paints from it and every apply_*
mutates it), and editor_state is not yet wired into paint or input.
There is no Document -> PenDocument converter, and the desktop
pen_doc_adapter only goes the other way (baking flex layout into AABB
rects, which is irreversible), so a per-frame round-trip would be
unsound. Each later 6.x task adds its own per-group sync point as it
switches a widget group's paint/input onto editor_state.
Field, accessors and dependency are all marked TEMPORARY — deleted in
Phase 7 when Document dies and editor_state becomes the host's only
state.
Port the in-process MCP server off shell-core's legacy `Document` /
`McpCommand` onto `op_editor_core::EditorState` / `EditorCommand`. The
module physically stays inside `openpencil-shell-core` (an `op-mcp`
crate extraction is a later Phase-7 task).
- Read tools snapshot `EditorState` (canonical `PenDocument`); write
tools emit `op_editor_core::EditorCommand` applied via
`EditorState::apply`. Node ids are now canonical `.op` schema
strings, not the old `u64`.
- Component commands surface a clean `ToolFailed` "known gap" error —
`op-editor-core` has no component registry yet. Same for
`set_node_collapsed` (`NodeFlag::Collapsed` has no schema field).
- `mcp_serve.rs` loads the `.op` file straight into an `EditorState`
(plain `jian-ops-schema` deserialization) and saves the
`PenDocument` back on every successful write.
- Delete the orphaned legacy apply path (`document/mcp_apply*.rs` +
`Document`/`VariableTable::apply_mcp_command`); the widgets that use
`Document` are untouched.
- Split `tools.rs` → `tools.rs` + `read_tools.rs` and
`component_tools.rs` → `component_tools.rs` + `page_tools.rs` to
hold the 800-line cap.
Replace the in-workspace copilot-sdk fork with the official
`github-copilot-sdk` crate (crates.io 0.1). Rewrite chat_copilot.rs
against its API: Client::start + a streaming SessionConfig whose
SessionHandler forwards `assistant.message_delta` / `session.error`
events into the ChatProvider channel, one client+session per turn.
Delete the crates/copilot-sdk fork directory. Build + 72 desktop
tests pass on the Rust 1.94 toolchain.
Closes the fourth chat-backend category from the project_agent_runtime
memory. Implements user direction "opencode 和 codex 我们调用 http
server, 通过 ipc 启动本地的 server 模式" — spawn the CLI as a local
HTTP server then POST chat requests to its bound port.
`crates/openpencil-desktop/src/chat_http_server.rs`:
- `HttpServerProvider::for_cli(CliName::Codex | OpenCode)` builds a
bridge that spawns `<bin> serve` and connects to the local
endpoint. Other CliName variants return `None`.
- Lifecycle:
1. Spawn child with stdin=null, stdout+stderr piped.
2. Drain stderr to /dev/null on a sibling task so the server
can't deadlock on a full pipe.
3. Block on stdout lines until one announces the bound port.
Default 10-second timeout (cold first-run can be slow). The
child is killed on timeout so we never leak a half-started
server.
4. Continue draining stdout for the remainder of the server's
life so its operational logs don't back-pressure.
5. POST `{ "message": <prompt> }` to `127.0.0.1:<port><path>`
using reqwest. Non-2xx response → Error + Done { Aborted }.
6. Stream the response bytes; parse each newline-delimited
line through `chat_subprocess::parse_line` (the generic
text / thinking / tool_use / done / error envelope).
7. On any structured `done`, terminate; on receiver-drop,
start_kill the child.
- `parse_listening_line` handles three message formats observed
in the wild: `Listening on http://host:PORT` (Codex),
`Server listening on port NNNN` (OpenCode docs), bare
`listening NNNN` (some local-server frameworks).
`extract_port` prefers `:NNNN` after the last colon (HTTP URL
form) and falls back to the last digit run, so IP octets in
`127.0.0.1:8765` don't get picked up as the port (caught by a
failing test on first iteration).
- `chat_path` is a per-CLI template (defaults to `/v1/chat`); the
settings modal can swap it when wiring up a new server whose
URL differs.
Limitations to flag for future iterations:
- The server is killed after each `send`. Real multi-turn would
want a long-lived server, which means lifting the spawn into a
Client-like singleton (analogous to chat_copilot's
ClientSession). Today's per-send spawn pays the cold-start
twice per turn but keeps the bridge stateless.
- The request body shape (`{ "message": ... }`) is a guess. Each
server's actual API needs to be plumbed when we have real
Codex / OpenCode server specs to compare against.
`crates/openpencil-desktop/Cargo.toml`:
- Adds `reqwest = { version = "0.12", default-features = false,
features = ["rustls-tls", "json", "stream"] }` as a direct dep.
reqwest was already in the graph via anthropic-agent-sdk so the
cost is zero new transitive deps; declaring it directly makes
the chat_http_server module's intent explicit.
`crates/openpencil-desktop/src/chat_subprocess.rs`:
- `parse_line` lifted to `pub(crate)` so chat_http_server can
share the same wire-protocol parser. Centralizing the envelope
shape keeps the four bridges consistent — when one CLI's
protocol evolves, every bridge gets it.
`crates/openpencil-desktop/src/main.rs`:
- `mod chat_http_server;` slotted into the alphabetical mod list.
Tests (7 added, all pass):
- parse_listening_line_codex_format: `Listening on
http://127.0.0.1:8765` → 8765 (asserts the IP-octet rejection
that caught the first iteration's bug)
- parse_listening_line_opencode_format
- parse_listening_line_bare_number
- parse_listening_line_returns_none_when_absent
- for_cli_only_http_server_kinds: Codex + OpenCode → Some, others
→ None
- provider_constructs_as_chat_provider_trait_object: type-check
- provider_labels_match_cli_names: "Codex" / "OpenCode"
All four chat backends now wired in code:
✓ BuiltIn (agent-rs) — chat_runtime.rs
✓ ClaudeCode (anthropic-agent-sdk) — chat_claude.rs
✓ Copilot (copilot-sdk) — chat_copilot.rs
✓ Subprocess (Gemini generic + custom)— chat_subprocess.rs
✓ HttpServer (Codex + OpenCode) — chat_http_server.rs
Acp (third-party ndJSON) remains TODO — that's the fifth backend
in the architecture memo, the open extension point for CLIs we
don't ship a dedicated adapter for.
Total openpencil-desktop tests: 55 (was 48 before this commit).
First of the per-CLI ChatProvider adapters that replace the
hand-rolled stream-JSON parser in chat_subprocess.rs. This one wires
`anthropic_agent_sdk::query` (the in-workspace fork of
bartolli/anthropic-agent-sdk) into the OP chat-panel plumbing.
`crates/openpencil-desktop/src/chat_claude.rs`:
- `ClaudeCodeProvider` impls `ChatProvider`. Constructs trivially
via `new()` (SDK defaults) or `with_options(ClaudeAgentOptions)`
when the settings modal has user overrides (system prompt, model
pick, allowed-tools list, MCP servers, sandbox config — all 30+
SDK option fields).
- `send()` spawns the shared tokio runtime task, calls
`anthropic_agent_sdk::query(prompt, options)`, drains its async
`Stream<Item = Result<Message>>`, and dispatches each Message
through `handle_message`:
- `Message::Assistant.content` Vec<ContentBlock> is unpacked
per block: `Text { text }` → `ChatDelta::TextDelta`,
`Thinking { thinking, .. }` → `Thinking`, `ToolUse { name,
input, .. }` → `ToolUse { name, args = input.to_string() }`,
`ToolResult` swallowed (already part of conversation history
the CLI tracks).
- `Message::Result { subtype, is_error, .. }` is the turn
terminator. `is_error` → `StopReason::Aborted`; otherwise
`map_result_subtype` maps "success" → EndTurn,
"error_max_turns" → MaxTokens, error variants → Aborted,
unknown → EndTurn.
- `System` / `User` / `StreamEvent` swallowed (init / context /
partial-stream payloads the chat widget doesn't surface yet).
- Receiver-drop short-circuit: every iteration checks
`tx.is_closed()` so chat-panel teardown stops the SDK stream
promptly without waiting for the CLI to flush more output.
- Always emits a terminal `Done` — `Result` message → mapped stop
reason; stream EOF without a Result → `EndTurn` fallback.
`crates/openpencil-desktop/Cargo.toml`:
- Adds `anthropic-agent-sdk = { path = "../anthropic-agent-sdk" }`
+ `copilot-sdk = { path = "../copilot-sdk" }`. Copilot dep
declared now even though `chat_copilot.rs` lands in a follow-up,
so Cargo.lock resolves the whole graph in one pass.
`crates/openpencil-desktop/src/main.rs`:
- `mod chat_claude;` between `mod chat_runtime` and
`mod chat_subprocess` so the alphabetical mod-list rule holds.
Tests (3 added, all pass):
- `map_result_subtype_table` covers the success / error_max_turns /
error_during_execution / error / unknown table.
- `provider_label_is_human_readable` asserts the chat widget gets
"Claude Code" as the displayed label.
- `provider_constructs_as_chat_provider_trait_object` is the
compile-time type-check that `ClaudeCodeProvider` satisfies the
`Send + Sync` bounds so it can live behind `Arc<dyn ChatProvider>`
in the widget host.
End-to-end smoke testing requires an actual `claude` binary on PATH.
The 3 tests here verify the wiring + type contracts but not the live
CLI interaction; that lands when the settings modal exposes the
"connect" button + we have a real session to drive.
46 openpencil-desktop tests pass (was 43 before this commit).
Next: chat_copilot.rs over `copilot_sdk::Client + Session`, then
chat_http_server.rs for Codex / OpenCode `serve` mode per the user's
"opencode 和 codex 我们调用 http server, 通过 ipc 启动本地的 server 模式".
Per user direction "可以不放在 vendor 里面,我们移动到自己的工程,
后面就和他们分叉" — promote the two community SDKs from vendor/ to
crates/ so they become first-class OP workspace members we own and
evolve, instead of read-only vendored snapshots.
Moves:
vendor/anthropic-agent-sdk/ → crates/anthropic-agent-sdk/
vendor/copilot-sdk-rust/ → crates/copilot-sdk/
Workspace integration:
- Root `Cargo.toml` exclude list drops both vendor entries; the
existing `members = ["crates/*"]` glob auto-includes them.
- `crates/copilot-sdk/Cargo.toml`: stripped all `[[example]]`
blocks (22 of them) — the examples/ dir was already removed
during the import, and leaving the entries broke
`cargo test --workspace --no-run`.
- `crates/anthropic-agent-sdk/Cargo.toml`: already had its
`[[example]]` blocks pruned in the previous commit.
Lockfile pins (workspace `Cargo.lock`):
Pulling reqwest 0.12.28 (via anthropic-agent-sdk) into the
unified workspace dep graph re-resolved several `icu_*` crates to
the 2.2 line, which requires rustc 1.86. OP's toolchain is 1.85
(locked to stay compatible with the skia-safe-op fork). Pinned:
icu_collections 2.2.0 → 2.1.1
icu_locale_core 2.2.0 → 2.1.1
icu_normalizer 2.2.0 → 2.1.1
icu_normalizer_data 2.2.0 → 2.1.1
icu_properties 2.2.0 → 2.1.2
icu_properties_data 2.2.0 → 2.1.2
icu_provider 2.2.0 → 2.1.1
idna_adapter 1.2.2 → 1.2.1
All eight pins are the latest versions on each crate's 2.1.x /
1.2.x line that compile on rustc 1.85.
Verification:
- `cargo check -p anthropic-agent-sdk` ✓
- `cargo check -p copilot-sdk` ✓
- `cargo test --workspace --no-run` ✓
- `cargo test -p openpencil-shell-core --lib` → 250 pass
- `cargo test -p openpencil-desktop chat_` → 16 pass
Next: replace the hand-rolled subprocess parser in chat_subprocess.rs
with thin per-CLI adapters that route Claude Code through
`anthropic_agent_sdk::SubprocessTransport` and Copilot through
`copilot_sdk::Client + Session`. Gemini stays on the generic stdin
bridge until an upstream Rust SDK exists. Codex + OpenCode get an
HttpServerProvider that spawns `<bin> serve` then connects via a
local HTTP client.
The shell-core trait + `EchoProvider` from `3d754fdc` was the
abstraction. This wires up the first real backend so the AI chat
panel can drive a non-stubbed LLM turn from the native binary.
`crates/openpencil-desktop/src/chat_runtime.rs`:
- `BuiltInProvider` wraps `agent::QueryEngine` (the cross-product
Rust agent runtime at /Users/kayshen/Workspace/ZSeven-W/agent-rs).
- Process-wide tokio runtime singleton (multi-thread, `op-chat`
threads) initialized lazily on first send so cold chrome startup
doesn't pay for the spawn.
- Async → sync bridge: `ChatProvider::send` returns
`Iterator<Item = ChatDelta>`; the impl spawns a tokio task that
pumps agent-rs `Event`s into a `std::sync::mpsc::channel`, then
returns the receiver iterator. Closes on `Result` / `Error` /
receiver drop. Maps `TextDelta` / `Thinking` / `ToolUse` /
`Result` / `Error` straight to the corresponding `ChatDelta`
variants; `ToolResult` / `Usage` / `Notice` / `Unknown` swallow
silently (widget doesn't render them yet — they land in a Phase 2
transcript view).
- `map_stop_reason` table covers agent-rs's stop-reason strings
(`end_turn` / `stop_sequence` / `max_tokens` / `tool_use` /
`aborted` / `user_abort`); unknown values fall through to
`EndTurn` (safe default — turn over).
- `from_provider` is the constructor — takes any
`Arc<dyn Provider>` so tests + future settings-modal wiring (per-
provider credential modals) can drive in their own backend impls.
Cargo:
- `agent = { path = "../../../agent-rs/crates/agent",
default-features = false }` — no default features today because
the `anthropic` feature drags in reqwest's TLS stack (rustls /
icu_collections@2.2 / idna_adapter@1.2) which needs rustc 1.86
while this workspace pins 1.85. The BuiltIn trait + engine wiring
ship now; concrete Anthropic / OpenAI-compat / Ollama Provider
impls flip on once rust-toolchain bumps.
- `tokio` (rt-multi-thread + macros + sync) + `futures` for the
async bridge; `async-trait` for the test double's `Provider`
impl. All three are target-gated to native (cfg desktop OS) per
the workspace WASM-boundary policy in `Cargo.toml`.
Tests (3 added — all pass):
- `builtin_provider_streams_text_deltas_through_iterator` — drives
a scripted `Provider` test double through the engine, asserts
`ChatDelta::TextDelta("Hello")` arrives first and the run ends
with `Done { stop_reason: EndTurn }`.
- `builtin_provider_surfaces_event_error` — `Event::Error` from the
provider lands as a `ChatDelta::Error` carrying both code +
message.
- `map_stop_reason_table` — exhaustive table of every variant +
unknown fallthrough.
Next: Subprocess / HttpServer / Acp bridges per the 4-backend taxonomy
in `project_agent_runtime` memory — each lives in its own module so
the 800-line cap stays honored.
Pivot the desktop's Open path to the canonical `jian-ops-schema`
parser and route layout through `jian-core::LayoutEngine` so files
saved by the TS editor, Jian apps, or any tool emitting the
canonical schema load through the shared parser + paragraph shaper.
Loader (pen_doc_adapter.rs + pen_doc_path_bounds.rs)
- All 12 PenNode variants → NodePayload, with each root's authored
(base.x, base.y) added to harvested rects so multi-design files
(e.g. pencil-demo.op's 14 mockups) spread across the canvas.
- Path anchors port `getPathBoundsFromAnchors` — endpoints + Bezier
handles + cubic-derivative extrema — so curved paths scale into
their (width, height) the way the canonical renderer paints.
- jian-skia's `SkiaMeasure` plugged in via
`LayoutEngine::with_backend(...)`, replacing the ~10% character-
count heuristic with real paragraph-shaper metrics. Wrap/layout
now agree with paint instead of cascading 10% errors.
- Numeric-string fontWeight (`"700"`, `"normal"`, ...) parsed in
both jian-core and the desktop adapter; expanded keyword table
covers black/heavy/extralight/extrabold/demibold/hairline/etc.
- Version-tolerant `load_canonical` retries with `version` rewritten
to `"1.0"` so legacy `version: "2.8"` files still load.
Text + icon rendering
- `Node.text_wrap` gated on `textGrowth: fixed-width` — single-line
by default so font-fallback overshoot doesn't break lines the TS
app shows on one line.
- CJK-aware `wrap_text` (canvas_viewport_overlay.rs) — per-char CJK
breaks, word breaks for Latin, blank-line preservation, explicit
`\n` splits. Takes a weight param.
- `RenderBackend::measure_text_weighted` added with NativeBackend +
WebBackend overrides so wrap measurement matches weighted paint.
- icons.rs + new icons_data.rs sibling cover ~75 lucide variants
for first-party `iconFontName` names from pen-core element-builders
(trending-up/down, compass, refresh-cw, layout-dashboard, users,
package, zap, sliders-horizontal, activity, loader, focus,
chart-line, settings-2, arrow-right, check-circle, alert-triangle,
alert-octagon, sticky-note, bar-chart-2, bold/italic/underline,
shopping-cart/bag, send, message-circle, rocket, menu, credit-card,
x-circle, mail, smartphone, chrome, apple, user, ...). Unknown
names stroke a dot fallback (FALLBACK_ICON_D) instead of a block.
All d-strings copied from lucide-react@0.545.0.
- `Icon::from_name(&str)` resolves kebab-case + common aliases.
- Synthetic bold via PaintStyle::StrokeAndFill for weights ≥600 on
both native and web (single-weight bundles can't serve a real
bold variant).
Chrome polish
- Hover state on file menu / locale picker / shape picker / layer
panel rows / AgentSettings nav + provider cards. Host's
apply_cursor_move updates each per its open state.
- File menu compacted (row 30, header 22, no `…` suffix on actions),
recent file names truncate with a CJK-aware helper.
- `rfd::MessageDialog` on every failed Open / OpenRecent / Save /
SaveAs / ExportImage with bilingual (EN/ZH) title + path + detail.
OpenRecent failures prune the stale entry.
- `figma_import.rs` modal honest-stub (Coming soon copy, brand glyph),
TopBar Folder+Chevron compound + Figma button.
- Settings sidebar nav + provider cards tinted on hover.
- Recent-files panel polished to single-line names with age column.
Tests
- pen_doc_adapter_tests.rs (sibling via #[path]) — 19 cases covering
multi-root canvas offsets, shape size fallbacks, path anchor
absolutize + Bezier extrema, fixed-width wrap, numeric-string
weights, login.op + pencil-demo.op fixture loads.
- canvas_viewport_overlay.rs wrap_tests — 7 cases: ASCII / CJK /
CJK+Latin / explicit-newline / blank-line / weighted advances.
- icons.rs first_party_icon_font_names_all_resolve guards 27+
authored names against placeholder regressions.
File-cap discipline
- pen_doc_adapter.rs split into mod + path-bounds sibling + tests
sibling.
- icons.rs split into mod + icons_data.rs sibling so the catalogue
can grow without busting the cap.
- canvas_viewport_overlay.rs absorbs wrap_text + UniformBackend /
WeightedBackend test stubs.
Sub-modules
- vendor/jian advanced for `resolve_weight` numeric-string parsing.