All releases

3 min read

v0.9.1

A fix release. It fixes a daemon crash on agent transcripts, races in the daemon client state, a scrollback line that broke after a reattach, and a theme from a config file that missed the panes. tuios-web moves to sip v0.8.5.

GGGaurav Gosain

tuios 0.9.1 is a fix release. It fixes a daemon crash on agent transcripts, races in the daemon's client state, a scrollback line that broke after a reattach, and a theme from a config file that missed the panes. It also moves tuios-web to sip v0.8.5, which blocks DNS rebinding and caps the size of a browser window.

The full list is at tuios.dev/releases.

Install

brew install tuios                     # Homebrew (macOS, Linux)
yay -S tuios-bin                       # AUR (tuios-web-bin for the web server)
nix run github:Gaurav-Gosain/tuios     # Nix
curl -fsSL https://raw.githubusercontent.com/Gaurav-Gosain/tuios/main/install.sh | bash
go install github.com/Gaurav-Gosain/tuios/cmd/tuios@v0.9.1
docker run -it --rm ghcr.io/gaurav-gosain/tuios:v0.9.1

A binary installed by the script or from an archive updates with tuios update.

Fixes

  • Daemon crash on transcripts. Two reads of one agent transcript at the same time could crash the daemon and close every pane. The reads now run one at a time (#574). Thanks to @Guipegoraro.
  • Client state order. With more than one client on a session, a client could get an older state after a newer one. It could then go back to an old workspace, or move the session back for every client (#561, #565).
    • The repair that an attaching client gets now comes in order with the other states.
    • A push from one client reaches the other clients in order, also when two clients push at once.
    • The reply to a push no longer overtakes a state that is already queued for that client.
  • Reattach. A line that wrapped at the last column could break in the scrollback after a reattach. Every character after the wrap was one column out. The pane snapshot now carries the pending wrap (#571).
  • Origin mode on the ghostty build. A restored cursor under DECOM with left and right margins no longer moves too far right (#571).
  • Themes from a config file. A theme saved in config.toml, an included file or a config.d file now recolours the panes. Before, only the borders changed until you used the theme picker (#569).
  • Screensaver speed. The screensaver and the effect preview paint at 60 fps at most. At max_fps 240 the effects ran four times too fast and used four times the CPU (#563).
  • No false config problem in the browser. A tuios-web client no longer shows "1 config problem" when the config does not set notify. A setting that a client cannot carry out is now a notice in the log viewer (#572).
  • Kitty keys in tuios-web. Escape and Ctrl+C reach tuios with the kitty keyboard protocol. This comes with sip v0.8.4 (#570).
  • Libraries. tuiffects v0.7.1 removes control bytes from effect input and writes smaller frames. tuitest v0.1.0 makes the e2e suite recover from emulator panics (#570).
  • CLI code. The root and ssh commands are in their own files. The CLI works as before (#568). Thanks to @LeeSamuel14.
  • Browser tests in CI. The Playwright tests for tuios-web run on pull requests and every night (#572).

Security

  • DNS rebinding. tuios-web uses sip v0.8.5, which checks the Host header on a loopback bind. --allow-host adds names to that check (#573).
  • Frames. tuios-web sends frame-ancestors 'self' and X-Frame-Options. A page on another site cannot put tuios-web in a frame.
  • Window size. One browser could ask tuios-web for about 22 GB of memory with a large window. tuios-web now clamps every window to 1200 columns, 500 rows and 250000 cells (#563, #573).

Upgrading

The daemon

The daemon protocol did not change, so a v0.9.0 daemon works with a v0.9.1 client. The transcript crash, state order and reattach fixes are in the daemon. To get them, restart the daemon:

tuios kill-server

This closes every pane in every session, so save your work first.

tuios-web

  • --allow-host '*' is refused. Give --allow-host a host name, such as term.example.com. tuios-web does not start with *.
  • Windows are clamped. A browser window gets 1200 columns, 500 rows and 250000 cells at most. A window that is 1200 columns wide gets 208 rows. tuios-web clamps a larger window and keeps the session.

Contributors

Thank you to everyone who sent a pull request for this release:

  • @Guipegoraro: the transcript read crash fix (#574)
  • @LeeSamuel14: the root and ssh command files (#568)

Full Changelog: https://github.com/Gaurav-Gosain/tuios/compare/v0.9.0...v0.9.1