All releases

latest release6 min read

v0.9.2

A security release. It updates Go and x/net for HTTP/2 advisories, adds keyboard_layout and option_glyphs for macOS Option and non-US layouts, lets links use an open ssh master, and keeps your screen when you quit.

GGGaurav Gosain

tuios 0.9.2 is a fix release with a security update. If you run tuios-web, update now. This build uses Go 1.26.9 and x/net v0.60.0, which fix a set of HTTP/2 and net/http advisories. It also fixes the macOS Option key on composing terminals and non-US layouts, keeps your terminal's screen and scrollback when you quit, draws images correctly in VS Code and Netcatty, and fixes herdr plugins on Windows.

The full list is at tuios.dev/releases.

Install

brew install tuios                     # Homebrew (macOS, Linux)
yay -S tuios-bin                       # AUR (tuios-web-bin for the web server)
nix run github:Gaurav-Gosain/tuios     # Nix
curl -fsSL https://raw.githubusercontent.com/Gaurav-Gosain/tuios/main/install.sh | bash
go install github.com/Gaurav-Gosain/tuios/cmd/tuios@v0.9.2
docker run -it --rm ghcr.io/gaurav-gosain/tuios:v0.9.2

A binary installed by the script or from an archive updates with tuios update.

Security

  • Go 1.26.9 and x/net v0.60.0. tuios and tuios-web now build with Go 1.26.9 and golang.org/x/net v0.60.0. These fix the net/http, HTTP/2, crypto/tls and os advisories GO-2026-6603 to GO-2026-6617. One of them, GO-2026-6617, lets a client crash an HTTP/2 server through a race in the HPACK encoder. tuios-web is an HTTP server, so update it first (#593).
  • Build from source. go.mod now has toolchain go1.26.9. If you build tuios yourself, use Go 1.26.9 or later.

New

  • macOS Option keys and keyboard layouts. Two new keys in [keybindings] control how tuios reads Option (#578, fixes #566 and points 1 and 3 of #575).
    • option_glyphs = "type" sends a character that Option composes to the pane. Use it if you type characters with Option, such as the right Option key in WezTerm. Before, right Option and 8 typed •, and tuios read it as opt+8 and switched to workspace 8. The default, "bind", works as before.
    • keyboard_layout = "other" turns off the US aliases for shifted digits, such as alt+& for alt+shift+7. Set it on AZERTY, QWERTZ and other layouts. Before, Option and the 1 key on French AZERTY ran move_and_follow_7. The default is "us".
    • A key that the terminal reports through the Kitty keyboard protocol uses the layout in that report.
    • A binding you set, such as opt+&, now always wins over a US alias.
    • tuios keybinds explain lists the bindings that a key runs through a US alias, and says how to turn the aliases off.
    • Docs: Shifted digits and AZERTY and One Option key for typing.
  • Links can use an open ssh master. The daemon's links never ask for a password, a passphrase or a code. A link and tuios hosts test now use an ssh master that is already open in $XDG_RUNTIME_DIR/tuios/cm, so you can link a machine that needs a password or a second factor. With no master open, ssh connects as before. The link does not use the folder when other users can open it, when your ssh config gives the host its own ControlPath, or when the host forwards the agent (#577). Docs: CONFIGURATION.md.
  • Ten session colours. Sessions now take their automatic colour from ten hues, up from six. On a theme that shows ten different hues, ten sessions get ten colours. Two sessions with the same colour are not put in rows next to each other on the rail. On a theme that paints two hues the same, such as one_dark, the pool keeps only the hues you can tell apart. A colour you set with set-session-accent does not change (#453). Thanks to @davidreuss.

Fixes

  • Your screen after you quit. tuios no longer clears your terminal's screen and scrollback when you quit or detach. The lines from before tuios started are back on screen, and you can scroll up to them. tuios now sends a soft reset (DECSTR) and turns off each mode it turned on, in place of a full reset (RIS) (#592, discussion #588).
  • Images in VS Code and Netcatty. A terminal built on xterm.js leaves a picture behind when tuios moves or clears it. In Netcatty each scroll left a trail, and clear left a grey box. tuios now finds these terminals and draws pane images as block glyphs there. It reads the XTVERSION answer, also when it comes late or over tuios ssh, and TERM_PROGRAM=vscode. TUIOS_KITTY_GRAPHICS=1 and TUIOS_SIXEL_GRAPHICS=1 turn the graphics protocols on again. An image sent with the kitty protocol, such as chafa -f kitty, does not show on these terminals yet (#583, fixes #567).
  • Reattach. A reattach now keeps state that no cell shows. Before, a client looked right until a program used that state (#580).
    • The cursor that DECSC saved, on both screens. After a reattach, a shell's cursor went to the top left when vim quit.
    • Cells a program protected with DECSCA. A selective erase after a reattach erased them.
    • The character that REP (CSI b) repeats.
    • An open OSC 8 link on the ghostty build. Text printed in the link after a reattach was not a link.
    • A client bigger than the snapshot is sized to the snapshot. A line that wrapped at the last column then wraps at the same place.
  • Terminal emulation. The pure Go emulator now supports DECSCA protected cells. It restores the cursor and the character sets when a program leaves the alternate screen with 1049, as xterm and libghostty do. Before, the character sets of a full-screen program stayed in force after it quit (#580).
  • Windows. These fixes are for herdr plugins and the daemon on Windows (#581, fixes #579).
    • herdr plugins can open panes. The daemon now makes herdr.exe as a hardlink, or as a copy when the binary is on another drive.
    • A plugin program named without .exe, such as bin/<name>, is found through PATHEXT.
    • A plugin's processes stop when the plugin stops or the daemon ends. A program that a plugin command opens, such as an editor, keeps running.
    • tuios kill-server asks the daemon to stop, so the daemon saves its state and removes its sockets. Before, it ended the daemon at once and then timed out. It also reaches a daemon that you started over OpenSSH.
    • CI now runs these tests on Windows. A plugin that opens a pane and kill-server against a live daemon are not yet tested on a Windows desktop. Please report what you see in #579.
  • tuios-web. tuios-web moves to sip v0.9.0 and then v0.9.1 (#584, #594).
    • The fonts are WOFF2 and static text is gzipped. A cold load is about 4.4 MB, down from 11.7 MB.
    • The vtgl renderer draws underlines under spaces.
    • The vtgl renderer puts the grid in the right place. Before, it drew the grid about 200 px too low on tuios.dev/learn.

Learn tuios

The guided tour at tuios.dev/learn fits its output to the pane.

  • fastfetch picks the largest layout that fits the pane. neofetch still works as another name for it (#595).
  • ls prints names in columns and never breaks a name across two lines. help, git, colors, fortune, cowsay, top and the sample tables also fit the pane (#599).
  • ?renderer=vtgl loads the vtgl renderer (#582).

Upgrading

The daemon

The daemon protocol did not change, so a v0.9.1 daemon works with a v0.9.2 client. The new snapshot fields are optional in both directions. The reattach fixes, the ssh master links and the Windows plugin and kill-server fixes are in the daemon. To get them, restart the daemon:

tuios kill-server

This closes every pane in every session, so save your work first.

Config

Two new keys, both in [keybindings]. Their defaults keep the old behaviour.

[keybindings]
keyboard_layout = "us"   # us, other
option_glyphs = "bind"   # bind, type

Session colours

Each session's automatic colour can change once, because the pool now has ten hues.

tuios-web

sip no longer serves the /static/fonts/*.ttf URLs. The fonts are at /static/fonts/*.woff2. If a page or proxy of yours loads the TTF files, change it to the WOFF2 files.

Contributors

Thank you to everyone who sent a pull request for this release:

  • @davidreuss: ten session colours, with no two the same next to each other on the rail (#453)

And thanks to everyone who reported bugs: @dominionthedev for the composed Option characters (#566), @florian-guily for the AZERTY keys (#575), @LovesAsuna for the image trails (#567), @EricSanzLuna for herdr plugins on Windows (#579), and @mhmdar for the cleared screen on exit (#588).


Full Changelog: https://github.com/Gaurav-Gosain/tuios/compare/v0.9.1...v0.9.2