# v0.9.1

URL: https://tuios.dev/releases/v0-9-1

> A fix release. It fixes a daemon crash on agent transcripts, races in the daemon client state, a scrollback line that broke after a reattach, and a theme from a config file that missed the panes. tuios-web moves to sip v0.8.5.

tuios 0.9.1 is a fix release. It fixes a daemon crash on agent transcripts, races in the daemon's client state, a scrollback line that broke after a reattach, and a theme from a config file that missed the panes.
It also moves tuios-web to sip v0.8.5, which blocks DNS rebinding and caps the size of a browser window.

The full list is at [tuios.dev/releases](https://tuios.dev/releases).

## Install

```bash
brew install tuios                     # Homebrew (macOS, Linux)
yay -S tuios-bin                       # AUR (tuios-web-bin for the web server)
nix run github:Gaurav-Gosain/tuios     # Nix
curl -fsSL https://raw.githubusercontent.com/Gaurav-Gosain/tuios/main/install.sh | bash
go install github.com/Gaurav-Gosain/tuios/cmd/tuios@v0.9.1
docker run -it --rm ghcr.io/gaurav-gosain/tuios:v0.9.1
```

A binary installed by the script or from an archive updates with `tuios update`.

## Fixes

- **Daemon crash on transcripts.** Two reads of one agent transcript at the same time could crash the daemon and close every pane. The reads now run one at a time ([#574](https://github.com/Gaurav-Gosain/tuios/pull/574)). Thanks to @Guipegoraro.
- **Client state order.** With more than one client on a session, a client could get an older state after a newer one. It could then go back to an old workspace, or move the session back for every client ([#561](https://github.com/Gaurav-Gosain/tuios/pull/561), [#565](https://github.com/Gaurav-Gosain/tuios/pull/565)).
  - The repair that an attaching client gets now comes in order with the other states.
  - A push from one client reaches the other clients in order, also when two clients push at once.
  - The reply to a push no longer overtakes a state that is already queued for that client.
- **Reattach.** A line that wrapped at the last column could break in the scrollback after a reattach. Every character after the wrap was one column out. The pane snapshot now carries the pending wrap ([#571](https://github.com/Gaurav-Gosain/tuios/pull/571)).
- **Origin mode on the ghostty build.** A restored cursor under DECOM with left and right margins no longer moves too far right ([#571](https://github.com/Gaurav-Gosain/tuios/pull/571)).
- **Themes from a config file.** A theme saved in config.toml, an included file or a config.d file now recolours the panes. Before, only the borders changed until you used the theme picker ([#569](https://github.com/Gaurav-Gosain/tuios/pull/569)).
- **Screensaver speed.** The screensaver and the effect preview paint at 60 fps at most. At `max_fps` 240 the effects ran four times too fast and used four times the CPU ([#563](https://github.com/Gaurav-Gosain/tuios/pull/563)).
- **No false config problem in the browser.** A tuios-web client no longer shows "1 config problem" when the config does not set `notify`. A setting that a client cannot carry out is now a notice in the log viewer ([#572](https://github.com/Gaurav-Gosain/tuios/pull/572)).
- **Kitty keys in tuios-web.** Escape and Ctrl+C reach tuios with the kitty keyboard protocol. This comes with sip v0.8.4 ([#570](https://github.com/Gaurav-Gosain/tuios/pull/570)).
- **Libraries.** tuiffects v0.7.1 removes control bytes from effect input and writes smaller frames. tuitest v0.1.0 makes the e2e suite recover from emulator panics ([#570](https://github.com/Gaurav-Gosain/tuios/pull/570)).
- **CLI code.** The root and ssh commands are in their own files. The CLI works as before ([#568](https://github.com/Gaurav-Gosain/tuios/pull/568)). Thanks to @LeeSamuel14.
- **Browser tests in CI.** The Playwright tests for tuios-web run on pull requests and every night ([#572](https://github.com/Gaurav-Gosain/tuios/pull/572)).

## Security

- **DNS rebinding.** tuios-web uses sip v0.8.5, which checks the Host header on a loopback bind. `--allow-host` adds names to that check ([#573](https://github.com/Gaurav-Gosain/tuios/pull/573)).
- **Frames.** tuios-web sends `frame-ancestors 'self'` and `X-Frame-Options`. A page on another site cannot put tuios-web in a frame.
- **Window size.** One browser could ask tuios-web for about 22 GB of memory with a large window. tuios-web now clamps every window to 1200 columns, 500 rows and 250000 cells ([#563](https://github.com/Gaurav-Gosain/tuios/pull/563), [#573](https://github.com/Gaurav-Gosain/tuios/pull/573)).

## Upgrading

### The daemon

The daemon protocol did not change, so a v0.9.0 daemon works with a v0.9.1 client. The transcript crash, state order and reattach fixes are in the daemon. To get them, restart the daemon:

```bash
tuios kill-server
```

This closes every pane in every session, so save your work first.

### tuios-web

- **`--allow-host '*'` is refused.** Give `--allow-host` a host name, such as `term.example.com`. tuios-web does not start with `*`.
- **Windows are clamped.** A browser window gets 1200 columns, 500 rows and 250000 cells at most. A window that is 1200 columns wide gets 208 rows. tuios-web clamps a larger window and keeps the session.

## Contributors

Thank you to everyone who sent a pull request for this release:

- @Guipegoraro: the transcript read crash fix ([#574](https://github.com/Gaurav-Gosain/tuios/pull/574))
- @LeeSamuel14: the root and ssh command files ([#568](https://github.com/Gaurav-Gosain/tuios/pull/568))

***

**Full Changelog**: <https://github.com/Gaurav-Gosain/tuios/compare/v0.9.0...v0.9.1>
