1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
use shuvarie_db::SessionSummary;
use shuvarie_llm::FileChange;
use shuvarie_llm::{Attachment, Model, ShellStreams, TokenUsage};
use crate::question::QuestionPrompt;
#[derive(Debug, Clone)]
pub enum Event {
Pong,
ModelsLoaded {
provider_name: String,
models: Vec<Model>,
},
ModelsError {
provider_name: String,
error: String,
},
/// A registry's online fetch (on demand or `remote-first` at startup)
/// succeeded.
RegistryLoaded {
/// The registry id (`selune` for the built-in one).
registry: String,
providers: Vec<selune::Provider>,
},
/// A registry's online fetch (on demand or `remote-first` at startup)
/// failed.
RegistryError {
/// The registry id (`selune` for the built-in one).
registry: String,
error: String,
},
ConfigSaved,
ConfigError {
error: String,
},
SessionStarted,
SessionCreated {
id: uuid::Uuid,
title: String,
scene: Option<String>,
},
TokenReceived {
content: String,
},
ReasoningReceived {
content: String,
},
ContextLoaded {
paths: Vec<String>,
},
ToolStarted {
name: String,
args: serde_json::Value,
worker: Option<String>,
/// The spawn id of the worker run the call happened inside (`None`
/// for main-agent calls): parallel spawns of one worker each carry
/// their own id, so the UI can keep their activity apart.
spawn: Option<u64>,
call_id: String,
},
ToolFinished {
name: String,
ok: bool,
output: String,
worker: Option<String>,
/// The spawn id of the worker run the call happened inside (`None`
/// for main-agent calls.
spawn: Option<u64>,
file_change: Option<FileChange>,
streams: Option<ShellStreams>,
duration_ms: u64,
call_id: String,
},
ToolOutput {
tool: String,
worker: Option<String>,
/// The `run_shell` call this streamed chunk belongs to, resolved by
/// the core from the chunk's command against the still-running calls;
/// `None` when ambiguous or already settled, in which case the UI
/// falls back to the name+worker match.
call_id: Option<String>,
stdout: String,
stderr: String,
},
/// A bash-mode (`!`) command started running; display-only, never
/// persisted or sent to the model. `id` routes the follow-up events.
BashStarted {
id: u64,
command: String,
},
/// Live output tails for a running bash-mode command.
BashOutput {
id: u64,
stdout: String,
stderr: String,
},
/// A bash-mode command finished. `exit` is `None` when the process died
/// to a signal (or failed to spawn, in which case `stdout` carries the
/// spawn error).
BashFinished {
id: u64,
ok: bool,
exit: Option<i32>,
stdout: String,
stderr: String,
duration_ms: u64,
},
WorkerStarted {
name: String,
args: serde_json::Value,
call_id: String,
},
WorkerFinished {
name: String,
ok: bool,
output: String,
duration_ms: u64,
call_id: String,
},
StreamDone {
text: String,
usage: TokenUsage,
},
/// The agent is busy, so a submitted prompt was queued (steered) instead
/// of starting a new turn; it will be sent as the next user turn once the
/// agent finishes its current action (tool call, thinking, or text
/// segment), or when the turn completes.
PromptSteered {
content: String,
},
/// A new user turn started streaming: either an accepted `SendMessage`
/// (`steered: false`) or a dispatched steered prompt (`steered: true`, in
/// which case the first queued entry must leave the chat display).
/// `attachments` are the turn's attachment metadata (the media lives in
/// the blob store; the TUI requests it with `LoadAttachmentMedia`).
TurnStarted {
content: String,
attachments: Vec<Attachment>,
steered: bool,
},
/// Reply to [`Command::LoadAttachmentMedia`]: the requested blobs. An
/// absent blob (`bytes: None`) means the store cannot serve it (pruned
/// or failed to load) — the TUI keeps its unloaded chip.
AttachmentMedia {
items: Vec<LoadedAttachment>,
},
/// Reply to [`Command::ProbeDirectives`]: the attach strip's per-path
/// preview, order-aligned with the requested paths. The composer drops
/// stale replies (an older `token`) when the pending set changed again.
DirectivesProbed {
token: u64,
items: Vec<crate::attachments::DirectiveProbe>,
},
/// Reply to [`Command::RequestPathCompletions`]: the matching directory
/// entries for the composer's `@` mention popup. Stale replies (an older
/// `token`) are dropped the same way.
PathCompletions {
token: u64,
candidates: Vec<crate::attachments::PathCandidate>,
},
/// A send-side attachment accommodation the user should know about
/// (history images trimmed to the request budget or degraded to notes on
/// a text-only target): shown in the status row until the next
/// busy-state event replaces it.
AttachmentNotice {
text: String,
},
/// Reply to [`Command::RecallSteered`]: the recalled prompt content, or
/// `None` when nothing was queued.
SteeredRecalled {
stacked: bool,
content: Option<String>,
},
/// The steered queue was wiped by a session-level transition (new,
/// loaded, or deleted session).
SteeredCleared,
StreamError {
error: String,
},
StreamCancelled,
/// The context budget overflowed and an LLM compaction summarizer call
/// is now running (also brackets fork-with-summary and a manual
/// `/compact`). No stream events arrive until the matching
/// [`Event::CompactionFinished`], so the TUI must keep its busy indicator
/// armed for the whole window.
CompactionStarted,
/// The compaction summarizer call finished (success or failure); the
/// core task replays the interrupted turn (auto compaction), reloads the
/// forked session (fork with summary), or reports
/// [`Event::SessionCompacted`] (manual `/compact`) afterwards.
CompactionFinished,
/// A manual compaction (`/compact`) finished and the session was
/// reloaded: the summary message sits in the active path with the kept
/// tail hanging under it, and the leaf points at the tail's tip so the
/// compacted history stays fully on the active path. `session` is the
/// reloaded in-memory state for the chat display and sidebar. Unlike
/// [`Event::Forked`], no turn resumes afterwards.
SessionCompacted {
session: crate::Session,
},
/// The turn failed with a retryable error; the core task will re-send
/// the turn after `delay_ms`. `reason` is a short status-row label (the
/// connection-failure kind, or the generic `Turn error`). `attempt` is
/// the upcoming retry number (1-based) out of `max_attempts` (from
/// `[retry].max-retries`).
RetryScheduled {
reason: String,
message: String,
attempt: usize,
max_attempts: usize,
delay_ms: u64,
},
/// Per-request usage for one completed LLM request (main stream or
/// worker), added to the session's running totals. `context_tokens` is
/// the request's context footprint (see
/// `shuvarie_llm::context_footprint`) — present only for main-stream
/// requests, since workers run separate conversations — so the UI can
/// anchor its context-occupancy display on the latest one.
UsageUpdate {
usage: TokenUsage,
cost: f64,
context_tokens: Option<u64>,
},
/// Authoritative cumulative usage for the active session, sent after a
/// turn commits. Replaces (rather than adds to) any client-side running
/// totals so live per-request updates resync to the persisted numbers.
UsageSnapshot {
usage: TokenUsage,
cost: f64,
},
SessionsLoaded {
sessions: Vec<SessionSummary>,
},
SessionLoaded {
id: uuid::Uuid,
title: String,
session: crate::Session,
},
SessionDeleted {
id: uuid::Uuid,
},
/// A session's title changed: a `/title` edit, or a background
/// small-model generation replacing the provisional first-prompt
/// heuristic. The TUI updates its title bar and terminal tab title when
/// the changed session is the active one.
SessionTitleChanged {
id: uuid::Uuid,
title: String,
},
SessionError {
error: String,
},
/// A session could not be entered (or its lock was lost mid-session):
/// another live client holds the session-wide lock. The session list
/// refreshes so the picker can show it as in use.
SessionLocked {
id: uuid::Uuid,
},
/// The session forked: the active path now ends at a different node (an
/// `/undo` fork before the last user prompt, a `/tree` fork before a
/// turn node, or a `/tree` tool row walking to its reply). Carries the
/// reloaded session plus the forked-away node's content to recall into
/// the input (`prompt: Some`) or `None` for marker forks, walk-to-reply
/// forks, and automatic resumes (replay / interrupted retry).
Forked {
session: crate::Session,
prompt: Option<String>,
},
/// Reply to [`Command::OpenTree`]: the freshly loaded session tree for
/// the popup. Never touches the chat pane's state.
SessionTree {
session: crate::Session,
},
/// The active session was written to a JSON file (`/export`); `path` is
/// the file it was written to.
SessionExported {
path: std::path::PathBuf,
},
SearchResults {
hits: Vec<shuvarie_db::SearchHit>,
},
SearchError {
error: String,
},
QuestionAsked {
id: u64,
questions: Vec<QuestionPrompt>,
},
/// A tool call hit an `ask` permission rule and is paused until the user
/// answers; the TUI shows the `description` (the action plus the matched
/// rule) and replies with [`Command::PermissionDecide`]. `allow_session`
/// marks asks the user can grant for the rest of the session (paths and
/// commands; scene confirmations are one-shot), and `allow_dir` marks
/// path asks the user can additionally widen to everything in the asked
/// file's folder for the session.
PermissionRequested {
id: u64,
description: String,
allow_session: bool,
allow_dir: bool,
},
LspStatus {
servers: Vec<shuvarie_lsp::LspStatus>,
},
LspDiagnostics {
path: String,
diagnostics: Vec<shuvarie_lsp::DiagnosticInfo>,
},
LspError {
error: String,
},
/// The state of every configured MCP server: emitted at startup, after
/// each turn's MCP connect pass, and by [`Command::McpList`] /
/// [`Command::McpReconnect`]. The sidebar's MCP section renders it.
McpStatus {
servers: Vec<shuvarie_mcp::McpStatus>,
},
/// An MCP lifecycle action failed (unknown server name, or a connection
/// attempt that did not complete). The per-server failure detail is
/// carried by the following [`Event::McpStatus`].
McpError {
error: String,
},
SkillsLoaded {
skills: Vec<crate::Skill>,
warnings: Vec<crate::SkillWarning>,
},
/// The custom-command roster (`.shuvarie/commands` + the global config
/// dir's `commands`), sent at startup and refreshed by
/// [`Command::Reload`]. The TUI turns them into slash-menu entries and
/// expands their templates on invocation.
CustomCommandsLoaded {
commands: Vec<crate::custom_commands::CustomCommand>,
warnings: Vec<crate::custom_commands::CustomCommandWarning>,
},
/// A warning surfaced as a dismissible popup: the `shell.path` configured
/// in config.kdl was not found (so `run_shell` falls back to the platform
/// default shell), or a decision-model shell check is configured but
/// cannot run (no decision provider selected, an unknown decision name, a
/// rubric the protocol rejects).
ShellWarning {
message: String,
},
/// An OAuth-backed provider (ChatGPT, Copilot) started a device-code
/// sign-in: the user must visit `verification_uri` and enter `user_code`
/// in the browser; the provider completes sign-in automatically while it
/// polls. Surfaced as a dismissible popup like [`Event::ShellWarning`].
AuthPrompt {
provider: String,
verification_uri: String,
user_code: String,
},
/// An OAuth device-flow sign-in completed: the provider holds a usable
/// credential (a fresh browser authorization, or a cached/refreshed token
/// accepted during a [`Command::AuthProviderLogin`] check).
AuthSuccess {
provider: String,
},
/// An OAuth sign-in failed or the client could not authorize: the device
/// flow timed out or was declined, the provider does not use OAuth sign-in
/// (an API key is required), or the connection name is unknown.
AuthFailed {
provider: String,
error: String,
},
/// The configured scene set for the scene switcher, sent at startup:
/// the built-in Default first, then the configured scenes in name order
/// with their optional descriptions. Entries carry their switch identity
/// (`SceneListEntry::id`, `None` = built-in Default) rather than bare
/// names, so a configured scene named "Default" stays switchable.
/// `default` is the scene new sessions start under (`None` = built-in
/// Default). `warnings` carries one message per same-level scene
/// conflict (a name defined by more than one source of the global or
/// local config loads neither copy).
ScenesLoaded {
scenes: Vec<crate::scenes::SceneListEntry>,
default: Option<String>,
warnings: Vec<String>,
},
/// The active session's scene changed (`None` = built-in Default).
SceneChanged {
name: Option<String>,
},
/// A scene switch failed: the agent is busy, or the scene name no longer
/// resolves.
SceneError {
error: String,
},
/// The session's per-model usage changed: an assistant message carrying
/// attribution was persisted (a committed turn, or a partial one cut by a
/// cancel/error). `models` is the full deduped list, first-use ordered;
/// `session_id` lets a stale event from a just-left session be dropped.
ModelUsed {
session_id: uuid::Uuid,
models: Vec<crate::session::ModelUsage>,
},
}
/// One blob of a [`Event::AttachmentMedia`] reply.
#[derive(Debug, Clone)]
pub struct LoadedAttachment {
pub sha256: String,
/// The blob's bytes, or `None` when the store cannot serve it (pruned by
/// garbage collection, or the read failed).
pub bytes: Option<Vec<u8>>,
}