Show per-file details for commits, and stop review from freezing the app - #385
Open
0x92 wants to merge 6 commits into
Open
Show per-file details for commits, and stop review from freezing the app#3850x92 wants to merge 6 commits into
0x92 wants to merge 6 commits into
Conversation
Reviewing a session meant reading one combined patch: which files a commit touched, and how much, was not visible anywhere. Two changes, both in the diff path: - Commit history rows expand to a per-file list with status and line counts, and clicking a file opens that file's diff directly - Reviewing a large working tree no longer blocks the UI The freeze was real work, not a hang: capturing the working-directory diff spawned one `cat` per untracked file and one `wc -l` per file, all synchronously on the main thread — 800+ spawns for a session with many untracked files, several seconds each pass. The path is now async and batched, with the file list gathered once instead of per consumer. The parsers for `--numstat -z`, `--name-status -z` and porcelain `-z` are pure functions with their own tests; the `-z` format packs `XY path` into a single token, which is easy to get wrong and impossible to notice by eye. Tests: commit file changes (23) and the unified diff parser (11).
Two defects, both in the path that inlines untracked files into a working-tree diff. The listing used `git ls-files --others --exclude-standard` split on newlines. Git delimits with newlines there, which a filename may contain, and quotes anything non-ASCII into a C-style escape — `täst.txt` arrived as the literal `"t\303\244st.txt"`, a name matching no file on disk, so the file vanished from the diff and from the stats without a word. The listing now uses `-z` and is split on NUL, and nothing is trimmed: a leading or trailing space is part of the name. Content and line counts were then read with `cat "<worktree>/<file>"` and `wc -l "<worktree>/<file>"`, built by interpolation. Git allows `$`, backticks and parentheses in a filename, and inside bash double quotes those are still syntax: a file named `back`whoami`.txt` in a repository was enough to run a command, with no interaction beyond opening the session. Both now go through `fs` — readFile for content, a streamed newline count for the totals — so a repository-controlled name never reaches a shell. untrackedFilePath() resolves the worktree-relative name git reports, going through the UNC mount for a WSL project the same way gitPlumbingCommands already does. The performance fix this PR made is kept and improved: capture spawns a fixed handful of commands whatever the file count, where before it was one `cat` and one batched `wc` per file. MAX_UNTRACKED_INLINE_FILES and MAX_UNTRACKED_INLINE_BYTES still bound what is inlined, and a per-file ceiling stands in for the 1 MB buffer `cat` used to have. chunkByCommandLength() goes with them — nothing builds a command line out of paths any more.
parsakhaz
requested changes
Aug 23, 2026
parsakhaz
left a comment
Member
There was a problem hiding this comment.
Verdict: Request changes, three correctness/security defects block the stated per-file review flow.
Counts: Must Fix: 3 (security: 1) · Should Fix: 1 · pass 1/3
Must Fix
- MF-1 (security): validate the commit ref before it reaches
CommandRunneratmain/src/ipc/git.ts:570andmain/src/services/gitDiffManager.ts:565-575,622. The new renderer-callable endpoint accepts any string and interpolates it into shell commands. A ref such asHEAD; <command>is shell syntax, so a compromised renderer or direct IPC caller can execute a command in the worktree. Restrict this endpoint toindex/UNCOMMITTEDor a full hexadecimal object ID before any command runs, and test rejection. - MF-2: make file-path extraction handle Git quoted paths at
frontend/src/utils/parseUnifiedDiff.ts:43-50. Git emits a non-ASCII filename asdiff --git "a/t\\303\\244st.txt" "b/t\\303\\244st.txt", while--name-status -zreturns the rawtäst.txt. The parser returns no file for that header, so clicking the correctly listed file cannot reveal its diff. Add quoted-path decoding and a test using a non-ASCII path. - MF-3: update and extend the extracted pending-view tests for the new payload at
frontend/src/components/panels/diff/pendingViewCommit.ts:14-18. Current evidence:pnpm --filter frontend testfails both existingpendingViewCommit.test.tscases becausetakePendingViewCommitnow returns an object rather than a string. Add the file-path preservation assertion and restore the suite.
Should Fix
- SF-1: the PR currently fails the repository blocking lint command on PR-introduced anti-slop findings in
CommitFileList.tsx,parseUnifiedDiff.ts,gitDiffManager.ts, and the new tests. Clear these before the branch is ready.
Checks
pnpm typecheck: passed.- Focused git diff tests: 30 passed; daemon registry suite was blocked by the local native SQLite ABI mismatch.
- Frontend suite: 270 passed, 2 failed as described in MF-3.
pnpm lint: failed on PR-introduced blocking findings.
parsakhaz
force-pushed
the
feature/commit-file-details
branch
from
August 23, 2026 19:53
a272064 to
77c978c
Compare
parsakhaz
approved these changes
Aug 23, 2026
parsakhaz
left a comment
Member
There was a problem hiding this comment.
Re-review on 77c978c: all three Must-Fix findings are resolved with focused regression coverage. Ref validation blocks shell-like input before CommandRunner, Git-quoted paths decode to their raw filenames, and pending file-reveal payload tests pass.
Member
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Description
Reviewing a session meant reading one combined patch: which files a commit
touched, and how much, was not visible anywhere. Two changes, both in the diff
path.
Per-file detail. Commit history rows expand to a per-file list with status and
line counts, and clicking a file opens that file's diff directly.
The review freeze. Reviewing a large working tree blocked the UI for seconds
at a time. It was real work, not a hang: capturing the working-directory diff
spawned one
catper untracked file and onewc -lper file, all synchronouslyon the main thread — 800+ process spawns for a session with many untracked files.
That path is now async and batched, with the file list gathered once instead of
once per consumer.
The parsers for
--numstat -z,--name-status -zand porcelain-zare purefunctions with their own tests; the
-zformat packsXY pathinto a singletoken, which is easy to get wrong and impossible to notice by eye.
Type of Change
Checklist
pnpm typecheckandpnpm lintlocallypnpm electron-devCritical Areas Modified
sessions:get-commit-files)Screenshots (if applicable)
Additional Notes
Tests: commit file changes (23) and the unified diff parser (11).
frontend/src/utils/parseUnifiedDiff.tsalso appears in the commit-graph PR —same file, same content, needed by both.
These four feature PRs are independent but all add an entry to the same
navigation plumbing (
navigationStore'sActiveView, the two sidebarcomponents,
preload.ts,api.ts,electron.d.ts). Whichever lands first,the others need a small rebase there — no logic overlaps.
Not done: the packaged-build check from CONTRIBUTING. I develop on Windows,
so
pnpm build:macwas not run.Automated QA
Status: passed on head
77c978c3using an isolated Pane directory, unique Vite port, and Chromium.+8/-3counts.pnpm typecheckandpnpm lintpassed.Remaining human check: exercise the same flow in packaged Electron with a real repository and a very large untracked tree.