Repository navigation
Conversation
osc52_read was a config.toml-only switch. It is now also a Settings row, "Programs can read clipboard", in the Terminal section: off by default, with help text that names the use (nvim or tmux over SSH pasting from the local clipboard) and the risk (any program in the terminal can read what you copied). The switch is also live now. Before, each pane copied the value when it was spawned, so turning reads OFF left every open pane still sharing the clipboard, which is the wrong failure for a privacy switch. The app now holds one shared gate, hands every pane a clone, and updates it on every settings change; each read checks it at that moment. - ember-session: LocalPtyConfig::osc52_read is a shared Arc<AtomicBool>, and the listener reads the clipboard through an injectable source so tests can prove what is and isn't read. - ember-core: the Settings row and its toggle, plus the config doc. - ember-app: the gate lives in Shared, seeded from the loaded config and updated in adjust_setting alongside the other live side effects. Tests: the row is off by default and flips only osc52_read; the setting survives a config.toml save and load (and an older file without the key loads with reads off); and the gate is live in a running pane, off -> on -> off, with the clipboard never read while off. The existing listener tests now fail if anything reads the clipboard while reads are off. Sabotage-checked: ignoring the gate, or always reading, each fails. Builds on the OSC 52 engine-gate fix, without which no read reaches the listener. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014xVjnf8UuQPRQtv2QqgpPK
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds "Programs can read clipboard" to Settings → Terminal: a toggle for the existing
osc52_readconfig switch, and makes the switch live.What changes for a user
Why "live" matters here
Before, each pane copied
osc52_readwhen it was spawned. For most settings, "new panes only" is fine. For a privacy switch it's the wrong failure: turning reads off would leave every open pane still sharing the clipboard. Now the app holds one shared gate (Arc<AtomicBool>inShared), seeded from the loaded config, handed to every pane, and updated inadjust_settingalongside the other live side effects. Each read checks it at that moment.Tests
clipboard_read_toggle_is_off_by_default_and_mutates_only_osc52_readosc52_read, and flips backosc52_read_survives_a_save_and_loadconfig.toml; an older file without the key loads with reads offosc52_read_gate_is_live_in_a_running_paneSabotage-checked: making the listener ignore the gate fails the "on" read. Making it always read trips the "must not be read" panic and fails the "off" read.
Not covered by an automated test: the two lines of app wiring (seeding
Shared, updating inadjust_setting). Covering them needs a fullWindowState. They're small and visible in the diff; worth a look in review.Validation
cargo fmt --check,clippy -D warningsandcargo test --all --all-featuresare clean. CHANGELOG[Unreleased]has anAddedentry, above #21'sFixed.🤖 Generated with Claude Code
https://claude.ai/code/session_014xVjnf8UuQPRQtv2QqgpPK