OrchestratorPlan now accepts the TS-native rootFrame/fill-array/styleGuideName
shape emitted by decomposition.md. Removes StyleGuide struct; adds PlanFill +
first_solid_hex helper. variables.rs enters dormant state (no palette to seed).
Local verification pass: with a temporary design-md stub the S3a
crates compile against the available jian. op-editor-core (262 tests,
incl. 8 InsertSubtree) and op-orchestrator (31 tests) all pass; clippy
clean. This commit folds in the rustfmt diffs that surfaced.
Host-side impls of op-orchestrator's two trait seams:
- DesktopLlmClient: implements LlmClient over agent::QueryEngine —
each call() builds a fresh engine (isolated context per spec §3.2),
spawns it on the shared runtime, and bridges agent Events to
LlmChunk via a futures mpsc channel.
- DesktopDocSink: implements DocSink over op_editor_core::EditorState.
- run_design_request: the post-intent-gate entry that runs
Orchestrator::run().
NOT verified — op-host-desktop is casement-blocked (and op-editor-core
jian-blocked). Two integration points are left to the host author and
documented in the module header: (1) the intent gate in
chat_runtime.rs (classify_intent -> design vs chat), kept untouched to
avoid blind-editing the threading model; (2) DocSink undo-batch wiring
to op-editor-core's History batch API.
S3a Plan C Task 6 (partial).
run_cleanup_passes now does two of the three TS cleanup passes:
- remove_duplicate_status_bars: keeps the first status-bar child
under each root, deletes the rest.
- adjust_root_height_to_content: sets root frame height to the sum
of its direct children's pixel heights.
Signature gains root_ids: &[&str] so S3b's concurrent multi-root
path reuses it (spec §9). unwrapSingleComponentSectionRoot left as a
documented follow-up (heuristic-heavy).
Codex stop-time review found two bugs:
- A subtask aborted mid-stream returns node_count==0, which the run
loop classified as zero_node_failure (error path) — wrongly removing
the scaffold root and returning NoContent. Now checks abort.is_set()
after run_subtask: an abort during the call takes the abort path
(keeps the root, returns Aborted).
- The happy-path test asserted root_frame_id == "root", but
InsertSubtree remaps every id so the live root id is fresh. Assert
it is non-empty instead.
Codex reviewed the blind-written S3a code against the real
op-editor-core / jian-ops-schema APIs and fixed:
- run.rs: InsertSubtree remaps every node id, so the planned
root_frame.id is NOT the live id. Capture the actual root id from
active_children() after the scaffold insert and rewrite each
subtask's parent_frame_id to it.
- run.rs: a rejected scaffold InsertSubtree was treated as success;
now rolls back + ends the undo batch + returns Internal error.
- run.rs / prompt.rs: r#"..."# raw strings broke on the "# inside
embedded JSON ("fill": "#RRGGBB"); switched to r##"..."##.
- cleanup.rs: test asserted the literal "root" id; reads the
remapped id instead.
- prompt.rs: sub-agent NODE_FORMAT now states fields are camelCase
(cuts runtime parse failures from snake_case model output).
Still unverified — vendor/jian unpushed (see prior commits). Codex
confirmed scaffold.rs's PenNode JSON shape (type tag, camelCase,
SizingBehavior bare number, PenFill) is correct.
New crate restoring the design orchestrator (TS orchestrator.ts
phases 1-4, single-screen sequential) that the Rust migration
dropped. Pure crate — no winit/casement/agent dependency.
- types.rs: DocSink + LlmClient traits, CallRequest/LlmChunk/
Progress/RunSummary and friends
- intent.rs: classify_intent (design vs chat)
- plan.rs: OrchestratorPlan parse + heuristic fallback
- parse.rs: LLM output -> canonical PenNode trees
- plan_normalize.rs: single-screen plan normalization
- variables.rs: plan-derived $color-* seed/snapshot/rollback
- prompt.rs: planning + sub-agent prompt assembly via op-ai-skills
- scaffold.rs: single-screen canvas scaffold (InsertSubtree)
- subagent.rs: sequential sub-agent execution
- cleanup.rs: descendant_count + run_cleanup_passes (reusable for S3b)
- run.rs: Orchestrator::run() — 4-phase spine, spec §6 error/abort/
zero-content semantics
- test_support.rs: VecDocSink + ScriptedLlm test stubs
NOT verified locally: op-orchestrator depends on op-editor-core,
which does not currently build — vendor/jian is pinned to unpushed
commit 80121906 (see prior commit). Unit tests written throughout;
they run once the jian build is restored.
S3a Plan B + Plan C (orchestrator modules).
Existing EditorCommand variants are leaf-only (BatchInsertItem carries
only kind/name/x/y/w/h/fill_hex). The design orchestrator (S3a) must
apply rich nested designs — frames with children, layout, text — so
add InsertSubtree { nodes: Vec<PenNode>, parent_id }.
cmd_insert_subtree validates the parent is a container (or NONE = page
root), remaps every incoming node id to a fresh editor id via
remap_subtree_ids (so an externally-authored subtree can't collide
with live ids), and appends under the parent. The apply arm wraps it
in a history snapshot so the insert is one undo step.
NOT verified locally: op-editor-core does not currently build —
vendor/jian is pinned to unpushed commit 80121906 whose DesignMd*
types op-editor-core depends on are absent from every available jian.
The 8 InsertSubtree tests in command_subtree_tests.rs run once the
jian build is restored.
S3a Plan A.
Export section: the scale / format dropdowns open inline select
popups (1x/2x/3x, PNG/JPEG/WEBP/SVG/PDF) instead of the Export
modal, which is now reached only via File > Export Image. Adds a
full-width Export button; popup rows highlight on hover. Pickers
open upward so they are not clipped at the panel's bottom edge.
PropertyPanel scrolls when its content overflows the viewport,
with the Design / Code tab strip pinned; scroll is clamped on
every paint + hit-test, not just on wheel events.
LayerPanel: the Pages and Layers sections get bounded heights and
independent scroll regions; layer drag/drop is gated to the
visible Layers viewport.
Splits property_panel into property_panel_action / _export and
the host press paths into property_dispatch / scroll modules to
keep every edited file under the 800-line cap.
editor_state_to_layout_scene took active_page_index from the payload, which pen_document_to_payload hardcodes to 0 — so picking a page in the LayerPanel updated the panel but never switched the canvas. Read the live EditorState.ui.active_page_index instead, clamped to the page count.
Add op-figma as a dependency and implement FileAction::ImportFigma — an rfd .fig picker parses the binary file via parse_fig_binary and re-seeds EditorState.
run_action now returns a 3-state ActionOutcome instead of a bool: an import returns PathChangedUnsaved so it is treated as unsaved work (close still prompts) while the Git session is rebound to the now-pathless document. mark_document_saved is split so the rebind can run without refreshing the dirty baseline.
Wraps the release binary in a minimal `OpenPencil.app`
(Info.plist + icon) so a dev run gets the proper Dock name +
icon — an unbundled binary shows the raw executable name and a
generic icon, and the runtime objc2 fallback in `macos_app.rs`
can't fully override that. Run the binary from inside the bundle
(`OpenPencil.app/Contents/MacOS/openpencil-desktop`) and macOS
picks up the bundle identity.
Run bare, the non-bundled binary shows in the Dock as the raw
`openpencil-desktop` executable name with a blank icon — no
`Info.plist` to read `CFBundleName` / the icon from.
New `macos_app::apply()` sets both at startup via objc2:
`NSProcessInfo::setProcessName` for the Dock / menu-bar name and
`NSApplication::setApplicationIconImage` (from an embedded
`assets/icon.png`) for the Dock tile. `[package.metadata.bundle]`
also gains `icon`, so a packaged `.app` carries it natively.
objc2-app-kit / -foundation are pinned to the 0.2 line winit /
casement already lock.
cargo-deny failed on `clipboard-win` / `error-code` — pulled in by
`arboard`'s Win32 clipboard path — which are BSL-1.0. The Boost
Software License is permissive + OSI-approved; add it to the
licenses allow-list.
Hide the native title bar and let the TopBar own the window
chrome — the Electron `titleBarStyle: 'hidden'` recipe:
- macOS keeps a real `NSWindow` (rounded corners, shadow,
edge-resize, key-window responsiveness) with the title bar made
transparent + emptied; the native traffic-light buttons stay,
pushed down via casement's `with_traffic_light_inset` to centre
in the 40 px TopBar. Windows / Linux drop decorations and the
TopBar paints its own close / minimise / maximise dots.
- The TopBar reserves a left inset for the controls; it collapses
in macOS fullscreen (native lights hide), tracked by a
per-frame `window.fullscreen()` poll. `window_control_at`
returns `None` on macOS so a fullscreen click on a left-edge
app icon can't trigger a window control.
- A press on the TopBar's blank area drags the window.
TopBar chip also gains one brand icon per connected agent + an
`N agent[s] · M MCP` status (new `topbar.agentPlural` across all
15 locales).
Bumps the vendor/casement submodule to 5ad98f1c.
A click on the colour swatch inside the Fill / Stroke hex input
now opens the picker. Previously only the head-row swatch did, and
the Stroke section had no picker hit-test at all. The head-row
swatch was dropped as a trigger in a follow-up — the hex-row
swatch is the intuitive target. `hit_test_action` runs before the
hex-input focus hit-test, so a swatch click opens the picker
instead of focusing the hex field.
The infinite-canvas grid painted one `fill_round_rect` per dot —
~1200+ separate skia draw ops every frame, the dominant cost of an
empty-canvas pan / drag. New `RenderBackend::fill_dots` collects
the dot centres and the native backend draws them in a single
`Canvas::draw_points` (round-capped points); other backends keep a
`fill_oval` loop via the default impl.
Also: `NativeBackend::fill_rect` went through `Paint::solid`, which
hardcodes `opacity: 1.0` and dropped the colour's alpha — a
translucent fill (the 12% marquee-selection band) painted fully
opaque. It now carries alpha through `Paint.opacity` like
`stroke_rect` does.
Three chat-panel fixes that share `ai_chat_panel.rs` / `input.rs` /
`scroll.rs`, so they land together:
- Model picker scoped to connected agents: discovery still probes
every installed CLI into `chat.discovered_models`, but the picker
lists only providers the user connected (`rebuild_available_models`,
re-run on connect-toggle + discovery). Connect state persists in
settings.json. The dropdown is height-capped, scrolls (wheel /
trackpad) with a thumb, and tints the hovered row.
- Chat input wraps: long input flows across up to 3 visible rows,
clipped + bottom-anchored, instead of overflowing the panel edge.
- perf: a canvas pan / zoom no longer marks the layout scene dirty
— it only moves the viewport transform, so re-running the taffy
layout solve + skia text measurement every drag frame was pure
waste. The repaint still re-applies the viewport.
Cmd+C / Cmd+V / Cmd+X did document node-clipboard ops regardless
of focus, so there was no way to paste a prompt into the AI chat
input. They now branch on chat focus: with the chat input focused
they read/write the OS text clipboard (`arboard`), otherwise the
node clipboard as before.
- `clipboard.rs` — thin best-effort arboard wrapper.
- `WidgetHostNative::chat_input_paste` / `chat_input_cut` — append
/ cut on the focused chat buffer.
The TopBar agent chip hardcoded `agent_count: 0`, so it always
painted the empty 'Agents & MCP' set-up affordance even after the
user connected a provider in Settings → Agents. It now reflects
the real count of connected providers (`agent_settings.connected`).
The chip's '{N} agent' label keyed `topbar.agentSingular`, which
was missing from every locale table — the chip rendered the raw
key. Added the key to all 15 locales.
A fresh launch seeded the demo `sample()` document — a Frame with
a 'Hello OpenPencil' title and a 'Click me' button group. New
`EditorState::starter()` returns just one empty Frame (selected),
and both hosts open with it; `sample()` stays as the widget-test
fixture. input_tests retarget their `n11` selections to the
starter frame's `n10`.
Newer Claude Code CLIs emit stream message types the bundled SDK
was not compiled against — `rate_limit_event` being the one that
surfaced — and serde aborted the whole chat stream on the first
one ("unknown variant rate_limit_event").
The `Message` enum gains a `#[serde(other)] Unknown` catch-all so
any unmodelled `type` deserializes cleanly instead of failing the
parse; `hooks.rs` and `chat_claude.rs` match it as a silent no-op
(an unknown event carries no hook payload and no chat turn).
The pre-commit `bun run format` step was reformatting upstream
casement files (Cargo.toml indent, .swcrc / changelog .md / CI yml
flow), leaving the submodule working tree dirty after every commit
that touched openpencil. Listing vendor/casement alongside the
other submodules in .prettierignore stops the formatter from
walking it — same as vendor/agent and vendor/jian.
`muda` is gated to macOS / Windows so the Linux backend stub
returns `None` from `poll()` and never constructs a `MenuAction`
variant. clippy's `-D dead_code` then fires on every variant on
Linux. Adding a target-gated `#[cfg_attr(…, allow(dead_code))]`
silences it there while keeping the lint live on macOS / Windows
where the variants actually need to stay reachable.
Use `messages.iter().enumerate().skip(start)` instead of the
explicit index loop `for i in start..messages.len()`; clippy's
`-D warnings` gate on Rust 1.94 trips on the former. Also bump
the casement submodule to da0bf09 so its .gitattributes forces
LF for source files (fixes Windows CI `cargo fmt --check` on
the vendored fork).
The casement crate was depended on through a sibling-repo path
(`../../../winit`) that only existed on the maintainer's machine,
so CI couldn't load the workspace manifest and every Rust Check
job died with "failed to read winit/Cargo.toml".
Vendoring it as a real submodule under `vendor/casement` (matching
the `vendor/jian` pattern, picked up by CI's `submodules:
recursive` checkout) closes that gap. The renamed GitHub repo
`ZSeven-W/casement` (was `ZSeven-W/winit`) tracks the `op-file-open`
branch — `feat(macos): drain_opened_file_urls` + the package rename
landed there as commit 5877fa83.
- `.gitmodules`: add vendor/casement.
- Root Cargo.toml: exclude vendor/casement from the workspace glob
(it's its own workspace).
- op-host-native + op-host-desktop: path = "../../vendor/casement".
Closes the architectural piece of the "MCP element toolset" P1 gap
(TS pen-mcp ships ~100 add_card_*/add_toast_* element tools).
- op-editor-core: new `EditorCommand::InstantiateKitComponent`
variant + applier branch that calls
`EditorState::instantiate_kit_component` with the requested
drop point (defaults to (0, 0)).
- op-mcp: `element_tools.rs` — `InsertKitComponent` per-component
tool returning `OkWithCommand(_, InstantiateKitComponent)`;
`insert_kit_component_tools(state)` walks every loaded kit;
`element_tool_schemas(state)` emits the matching tools/list
JSON. Tool names sanitize dashes: `insert_btn_primary`,
`insert_card_basic`, etc.
- op-host-desktop: `rebuild_registry` chains the dynamic tools
in; `tools_list_response` takes EditorState and appends the
dynamic schemas next to TOOL_SCHEMAS.
- op-editor-core: tidies the empty-pages `ensure_pages` guard to
`is_none_or`.
Result: 6 starter-kit components → 6 working MCP tools. The 100-tool
catalog parity is now a data fill-in (more components in op-editor-
core/uikit.rs auto-register as more MCP tools).
Closes the last TS-vs-Rust parity gap — the Rust shell lacked the
TS `component-browser-panel.tsx` (UIKit library browser +
click-to-instantiate).
- op-editor-core: `uikit.rs` with `UIKit` / `KitComponent` /
`ComponentCategory` types + a built-in starter kit (6 components
spanning button/input/card/nav/layout/feedback) as PenNode
templates; `EditorState::instantiate_kit_component` deep-clones
with fresh ids and translates the whole subtree to the drop point
(children carry document-absolute coords).
- op-editor-ui: `component_browser_panel.rs` floating draggable
panel — header (close), category pills (filtered to non-empty),
3-col card grid with name + scaled preview rect; kit-id + search
filters applied.
- op-host-native: paint at §11.5 (below the Design-MD panel),
`dispatch_component_browser_press`, drag lifecycle, shared
`over_topmost_panel` helper covers both top-most panels across
wheel / pan / right-press / cursor_hint / layer-hover / 4
overlay-hover blocks + align hover + stale-hover clear.
- op-host-desktop: View-menu toggle, `drain_component_browser_insert`
places at the viewport centre.
- op-editor-core: `active_children`/`active_children_mut` /
`ensure_pages` symmetric `pages: Some([])` fallback —
inserts land in `doc.children` and survive a subsequent
`add_page` (which migrates them into Page 1).
- op-i18n: new `componentBrowser.empty` × 15 locales.
Bumps vendor/jian for the rebased `DesignMdSpec` schema + the
`jian pack` designMd-filter for packaged apps.
`document_fingerprint` only sees the committed document, so an
in-progress text-input draft — a half-typed property field or
variable-row value — was invisible to the pull's edit detection and
to `document_is_dirty`. A reload then dropped the draft silently.
Add `WidgetHostNative::commit_pending_input_pub` (commits property +
variable-row focus) and call it before the reconciliation checks:
in `confirm_document_reload` (covering pull / branch switch / merge),
before the during-pull edit comparison in `poll_git_pull_job`, and
in `save_tracked_document`. A pending draft now counts as an edit
and is saved / discarded / kept by explicit choice.
The Pull confirm ran at spawn time, but a `git pull` resolves
asynchronously on a worker thread — the user can keep editing the
document while it runs. The post-pull reload then discarded those
during-pull edits with no prompt.
Capture a document fingerprint when the pull is spawned; in
`poll_git_pull_job`, compare it against the document at reload time.
An unchanged document reloads silently as before; a document edited
during the pull goes back through the unsaved-changes confirm so the
edits are saved / discarded / kept by explicit choice.
The Commit and Pull paths ignored the editor's in-memory document,
so they could act on stale disk state:
- Commit staged the last-saved file. With unsaved edits open, the
commit captured stale content, not what the user saw. It now saves
the document first (flushing pending inline edits) and skips the
commit if that write fails.
- Pull rewrites the tracked .op on disk but never reloaded the
editor or guarded unsaved edits. It now confirms via the
unsaved-changes prompt before starting, and `poll_git_pull_job`
reloads the document after a fast-forward / merge so the editor
reflects the pulled state (a conflict leaves unparsable markers,
so the panel shows merge-in-progress instead).
Mirrors the reload discipline already used by branch switch / merge.
GitSession binds an op_git::GitRepo to the currently-open document,
rebinding whenever the document path changes — the Git panel reads
it for branch / status / history and drives commits, the worktree
merge orchestrator and diffs through it.
Network- and scan-bound git work (pull, status, diff / show) runs on
worker threads (GitPullJob / GitStatusJob / GitDiffJob) drained on a
later frame, so a large repository or a slow remote never freezes the
UI; an open panel re-snapshots every 2 s to stay current with
external changes. A clean branch merge reloads the document from
disk; a conflicting one surfaces the quarantined ConflictBag in a
dialog. main.rs is split — git_host.rs + keyboard_input.rs — to keep
it under the 800-line cap.
The floating Git panel — opened from the View menu — shows branch,
working-tree status and recent commits, and offers commit / refresh /
pull plus one-click branch switching. Clicking the status line, a
commit row or a conflicted file opens an in-panel scrollable
unified-diff viewer (the panel widens to 620 px with ▲/▼/✕ controls
and per-line colouring). Each non-current branch row carries a "⤵"
button that requests an isolated worktree merge.
GitPanelState / GitDiffView / GitPanelAction are plain data on
op-editor-core so the widget layer stays wasm-clean — it never calls
git itself. Diff rendering is split into git_panel_diff.rs and the
native press dispatch into git_press.rs to honour the 800-line cap;
the panel is hit-tested before the right-rail blocks so its wide
diff mode cannot lose clicks to the property rail underneath.
`casement` is ZSeven-W's winit fork (sibling repo, referenced by
local path for now). It adds the macOS open-documents Apple-event
hook that upstream winit lacks, needed for Finder double-click open.
The `package = "casement"` key keeps the `winit` import name so all
`use winit::…` stays unchanged.
glutin-winit is dropped: it hard-depends on the upstream `winit`
package, which would pull a second, incompatible winit into the
tree. Its only use — GlWindow::build_surface_attributes — is replaced
by a direct glutin SurfaceAttributesBuilder call in provider.rs.
Drives the user's installed `git` via std::process::Command — the
same approach as the TS app's git-sys backend — so no libgit2/git2 C
dependency enters the workspace.
Covers repo discovery / init, working-tree status, staging, commit,
branch list / create / switch, history + diff, remotes, SSH keys and
credential storage. Adds a worktree-isolated merge orchestrator: a
branch merge runs in a throwaway detached worktree so a conflicting
.op merge never writes conflict markers into the live document — a
clean merge is fast-forwarded back, a conflicting one is reported as
a file-granular ConflictBag with the live tree left pristine.
A chat send fired while a turn was still streaming left the
interrupted turn's assistant bubble with streaming = true forever —
it never reached the terminal Done that clears the flag, so the
panel kept animating a caret on a stale message. begin_send now
clears every streaming flag before pushing the new bubble, keeping
the invariant that only the trailing assistant message streams.
Add five native-platform features to the winit desktop host
(op-host-desktop), closing the gap with the Electron app:
- Native menu bar (muda) — File / Edit / View / Help plus the macOS
app menu; selections route to the same host actions the keyboard
shortcuts use. Gated to macOS / Windows — muda needs GTK, which
this winit build does not link, so Linux keeps the in-canvas File
menu.
- Auto-update — a background probe of the GitHub releases API
reports status into the settings System tab; a found update
offers to open the download page, and a "Check for Updates" menu
item re-runs the probe.
- File association — argv parsing opens a .op / .pen document on
launch; [package.metadata.bundle] declares the OS-level handler.
- Window-state persistence — position / size / maximized restore
across restarts, with an off-screen guard for monitor changes.
- Drag-and-drop — dropping a .op / .pen file opens it.
Codex review round 1 findings (1 MAJOR + 3 MINOR) all addressed:
monitor-aware restore, failed-startup geometry guard, single-flight
update probe, case-insensitive extension match.
Also sink the agent-settings modal's hand-maintained EN/ZH string
table into the canonical 15-locale op-i18n tables, so the settings
chrome (including the new auto-update strings) is fully translated;
agent_settings_i18n.rs is now a thin op-i18n adapter.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
Restructure the floating AI chat transcript from flat text bubbles
into a structured view:
- ChatMessage carries thinking text, tool calls and images plus
per-block collapsed flags and a streaming flag. Image ids come
from a process-global counter so a fresh ChatState cannot collide
with the native decode cache.
- ChatPoll splits provider deltas into text / thinking / tool_calls;
apply_poll_to_message folds them into the in-flight assistant
message and clears streaming on the terminal Done. The no-provider
error path also ends the stream and drops staged attachments.
- New RenderBackend::draw_image (default no-op) backed by a bounded
FIFO decode cache + aspect-fit in the native skia backend; web
degrades to a framed placeholder.
- New ai_chat_transcript widget: deterministic layout shared by
paint and hit-test (no live text measurement), collapsible
thinking / tool-call blocks, a streaming caret + typing-dot
animation, and image thumbnails.
Reviewed with Codex (3 rounds to clean).
CI's Rust Check runs `cargo clippy --workspace --all-targets -- -D
warnings`; the fmt failure had masked it, so accumulated lints surfaced
once formatting was fixed. Resolve them:
- op-acp / op-ai-skills (this change set): while-let loop, redundant
struct update, and `should_implement_trait` allows on the Option /
infallible token parsers.
- Pre-existing in op-editor-core / op-figma, swept so the workspace
gate is clean: redundant `drop`, `too_many_arguments` allow,
collapsible `if let`, a type alias for a complex tuple, manual
`Iterator::find`, and an `approx_constant` test value.
Lint fixes only — no behaviour change.
Addresses the remaining round-4 codex findings (the `short_src`
byte-slice panic + the arc-handle reverse-iteration fixes already
landed via an earlier sweep).
- `cmd_set_ellipse_arc` clamps `sweep_angle` to ±360° — an API /
MCP sweep beyond a full turn just over-draws; it now persists a
sane single-revolution value.
- Path hit-test (`point_in_node`) follows the flattened, bezier-
aware outline instead of the bounding box: a curved or thin path
no longer selects empty bbox space, a zero-height stroked path
stays clickable, and a filled closed path is hittable across its
interior (new `point_in_polygon` even-odd test).
- The viewport-less `apply_release` now commits / clears
`path_anchor_drag` + `arc_handle_drag` (parity with
`apply_release_with_viewport`) so a drag can't leak across that
release path.
op-editor-core 242 / op-editor-ui 157 / op-host-native 21 tests green.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
CI's Rust Check runs a workspace-wide `cargo fmt --check`. Reformat the
new op-acp / op-ai-skills crates and the Part A chat changes to rustfmt
canon. Also sweeps two files an earlier commit left non-compliant
(canvas_viewport_paint.rs, op-pen-loader/adapter.rs) so the workspace
check is clean. Formatting only — no behaviour change.
ChatRequest gains an attachments field; ChatState carries a per-turn
thinking mode, effort level and staged attachments (capped at 4 files /
5 MiB, attachment-only sends allowed). The chat panel grows a controls
row (thinking / effort / attach) and a dedicated attachment-chip row,
with hit-test and paint sharing one input-block origin.
All five providers consume the knobs — Claude maps thinking onto the
SDK token budget, Copilot onto reasoning_effort, the CLI / built-in
transports prepend an in-band directive, the HTTP transport adds body
fields; attachments spill to a private per-turn temp dir (cleaned on
drop) or inline base64. Also wires op-ai-skills into the built-in
provider and op-acp in as the AcpProvider chat backend.