Applying an update downloads and swaps a binary and takes minutes; the
doctor showed a spinner inside a disabled button for the whole time.
SystemActions gained a streaming CLI runner that hands each line to the
caller as it arrives, with CHAIN_PLAIN=1 set for the child so the CLI
emits one line per transition instead of its redraw-in-place block.
The update card now shows an indeterminate bar labelled with the
running step and an elapsed counter on its own timer, so the counter
keeps moving between lines that can be minutes apart. No invented
percentage: the CLI reports steps, not a measurable total.
The streaming path still defers to debugRunFaiOverride, so tests stay
hermetic and never spawn a process; three guards pin that.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Three connection-truth fixes on the flow surface:
* The editor now lists the CONNECTED hub's flows: inside a sealed
area Studio passes the instance's own flows dir
(~/.chain/sealed/<slug>/data/flows) — previously the editor kept
showing the shared hub's files whatever the connection, so a
sealed area's list was simply wrong (and runSavedFlow hit the
other hub's namespace).
* A connection switch replaces the editor state entirely (keyed by
the sealed slug): an open buffer from one context never survives
into the other — same privacy class as the switch race.
* Sample truth comes from the hub: listFlows' FlowSummary.sample
(regenerated Dart SDK stubs) feeds the editor's sampleFlowNames;
unknown (old hub / fetch failed) means no chips. Inside a sealed
area the empty list offers the deliberate 'import example flows'
action via chain flows import-samples against the instance's own
dirs; the shared hub gets no such offer (it seeds samples itself,
and a deliberate deletion is respected).
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Field test of the setup wizard surfaced three trust breaks in one run:
an unexplained macOS Documents permission prompt, a perceived crash,
and an error message whose copy button could not be reached.
Root causes and fixes:
- chain init failures were shown as a SnackBar, which lands BEHIND the
wizard's modal barrier: dimmed, clipped, copy unreachable — and the
click aimed at it hit the barrier, dismissing the whole wizard with
all answers (the perceived crash). Errors now open a modal dialog
ABOVE the wizard via showChainErrorDialog with a copyable detail
block, and the wizard is no longer barrier-dismissible.
- When the resolved chain binary is older than Studio and rejects
--plan-json, the wizard now explains the version skew in plain
language (binary path + update path) instead of leaking a raw clap
usage error. A missing binary gets its own localized story.
- Step 3 announces which chain binary the preview will execute; when
that binary physically lives (symlinks resolved) in a TCC-protected
folder, the wizard pre-explains the macOS folder prompt.
Supporting changes: FriendlyError passes through friendlyError()
unchanged so call sites can ship precise localized stories through the
shared presentation; SystemActions gains resolvedChainBinary() plus
run/resolve test seams; ChainErrorBox hugs its content instead of
filling an unbounded dialog; the wizard's answers file is written
synchronously (the async dart:io variants never complete under the
widget-test fake-async zone).
Verified: flutter analyze clean, 53 tests green (6 new wizard error-
path tests incl. clipboard round-trip), plus a live GUI walk on macOS
in dark + light with a stale binary (skew dialog, copy verified via
clipboard) and with the real binary (TCC pre-explanation with the
resolved path, full plan preview).
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The workspace switcher now lists the operator's sealed areas (read from
~/.chain/sealed/ manifests, the same source the CLI uses) below the
shared projects, each with a lock icon and a running/stopped status.
Selecting one is a real connection switch: Studio reconnects its hub
client to the area's own port with a full state reload — one window,
one truth. A stopped area is started first (chain project start) with a
visible notice; a failure surfaces as a copyable error and rolls back to
the shared hub.
While in a sealed area an identity bar under the AppBar is painted in
the area's accent colour and names it, with a one-click Leave back to
the shared hub. The area colour is marking, not theming — Studio's blue
stays the app accent. Selecting a shared project from inside an area
switches the connection back first. The sealed connection is never
persisted across restarts.
New: SealedAreaService (manifest + PID discovery), Workspace sealed
switch logic, ChainSealedIdentityBar, SystemActions.chainProjectStart.
l10n DE+EN. flutter analyze clean; 33 tests green (switcher lists sealed
with lock+status, pill shows active area, identity bar renders in the
area colour). Runtime plumbing (discovery, start, endpoint, reach)
verified headlessly against real sealed instances under a redirected
HOME; the identity-bar screenshot is deferred (display click-automation
failed after sleep on the shared desktop — an environment issue, not a
code gap; the visible components are widget-tested).
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
A Welcome 'Setup assistant' button opens a wizard that collects
scenario / intent / target (+ approval & data-local toggles), then calls
`chain init --answers` to preview the assembled plan and `--apply --force`
to write the config — reusing the Rust deterministic engine, no logic
duplicated. New SystemActions.chainInit; copyable errors via
showFaiProcessError; EN+DE l10n. analyze clean; smoke test + existing
welcome/sidebar tests pass.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Studio's Start-hub looked for 'fai' on PATH; post-rename the entry
binary is 'chain', so a fresh install failed to start the daemon.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The Studio design system, widgets and helpers carried a Fai* / fai_
prefix (FaiSpace, FaiColors, FaiTheme, FaiLog, 17 fai_*.dart files, the
faiBinary* l10n keys). Studio is the Ch∆In product, so rename them to
Chain* / chain_ — carefully preserving English fail/failure/failed.
Also fix stale references: the 'fai' binary in l10n strings -> 'chain',
FAI_* env vars (FAI_BIN/DATA_DIR/MODULES_DIR/TODAY/BOOTSTRAP_TOKEN) ->
CHAIN_*, fai_platform -> fai_chain, fai_hub -> chain_hub. Vendor
security-hook tooling (FAI_BANNED_TERMS_FILE) + the .fai bundle ext left.
flutter analyze + test: clean (20 passed).
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Track the platform rename: the hub spawn path is now ~/.chain/bin/chain
(was ~/.fai/bin/fai.exe on Windows — both dir and binary were stale, so
Studio could not launch the hub after the config-dir rename), the
~/.fai/* help strings become ~/.chain/*, FAI_REGISTRY_TOKEN ->
CHAIN_REGISTRY_TOKEN, and the two in-app doc URLs point at the public
fai/chain repo (fai/platform was renamed to the private fai/chain-private).
The .fai module bundle extension is left unchanged (format phase).
flutter analyze: no issues.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Studio follows the platform rename: product branding F∆I -> Ch∆In in UI
strings, command examples fai -> chain, and — critically — the spawned
hub binary path ~/.fai/bin/fai -> ~/.fai/bin/chain so Studio launches
the renamed binary. The fai_* Dart identifiers (FaiLog, widget files,
the generated SDK) stay = vendor/internal namespace. flutter analyze:
no issues.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
- Connection-aware Welcome: when the hub is down, show a hero with a
primary "Start hub" CTA + install fallback instead of a dead,
all-unchecked onboarding checklist (the first-run cliff).
- Actionable binary-not-found (file picker + install link, not a
"set FAI_BIN" dead end) and a connect-failure banner after
repeated failed health polls.
- Localize six hardcoded English error/toast clusters (DE+EN ARB).
- Bundle Inter + JetBrains Mono as assets; drop the runtime
google_fonts fetch (air-gap / KRITIS safe, no font-swap flash).
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Settings dialog's Theme Plugin section is now a grid of
swatched tiles:
- Built-in (none) — falls back to FaiTheme.light/.dark
- One tile per installed studio.theme.* plugin, each
showing the plugin's primary/secondary/tertiary as
live colour dots. Tile loads its preview lazily so a
dozen installed themes don't block the picker.
- Custom — opens a colour-picker dialog with 12 curated
Material presets + a hex input + live preview. Selecting
applies ColorScheme.fromSeed for both brightnesses.
main.dart's _pluginThemes parses a 'custom:#RRGGBB' sigil
in the same notifier slot as plugin capability ids, so the
existing persistence + restoration paths cover the custom
case with no new state.
Bumps editor to 0.11.0 (type-checked port connections +
dynamic card width fix + card-height border allowance) and
Studio to 0.58.0.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
UI parity with the platform CLI: `fai reset` (v0.10.93) is now
reachable from Settings. The panel shows the reset blurb plus
two checkboxes mirroring the CLI flags (Keep modules / Keep
audit log + saved flows), then a destructive-styled "Reset hub
state" button. Click goes through a confirm dialog before
SystemActions.faiReset is invoked.
After the CLI returns, Studio bounces its gRPC channel against
the same endpoint (the daemon restarts on the same channel +
port, so no Settings change needed) and reloads every panel:
channel status, system AI, MCP clients, n8n endpoints, registry
token. Output (success or failure) is shown in a copyable error
box so any unexpected stderr lands somewhere the operator can
paste from.
Sits at the bottom of the dialog under "HUB MAINTENANCE",
separated from the everyday config so a destructive button
doesn't crowd the day-to-day controls.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Sweeping pass against six user reports collected this session.
1. "Capabilities ist nicht deutsch, Chain auch nicht."
The DE locale still leaked English vocabulary. Replaced
"Capabilities" → "Fähigkeiten" and "Chain" / "Hash-Chain"
→ "Kette" / "Hash-Kette" everywhere — store search hint,
recommended-source body, federated toast, doctor summary
chain row, modules panel summary, MCP / n8n hints, the
approvals history blurb. Wire-level identifiers
(`chain.reset`) stay as code.
2. "Bei Fehlern unten muss man die auch ins clipboard
kopieren können." New `FaiErrorBox` widget: selectable
monospace block with a small copy-to-clipboard icon
button that flips to a checkmark for two seconds after
click. Applied to the Doctor update banner output and
the Settings channel toast — the two places long
stderr / stdout lands.
3. "Öffnen bei Log kann es nicht öffnen. Audit-DB auch
nicht. PID auch nicht."
Cause: `SystemActions.openInOs` shells out to `open` /
`xdg-open` on file paths the OS has no default handler
for (SQLite DB, PID file, log without an .ext that
binds). New `revealInOs` uses `open -R` on macOS,
`explorer /select,` on Windows, and the parent
directory via `xdg-open` on Linux. Doctor's path rows
carry an `isDirectory` flag that routes through the new
`openOrReveal` so files reveal in Finder / Explorer
instead of failing silently.
4. "Oben im Store könnte man diesen Redaktionshinweis auch
so bauen, dass man mit pfeil nach rechts links auch
weitere anzeigen kann."
The Today-Hero became a carousel. Curated fallback
list grew from one entry to four (public sources, the
sandbox-by-default permission story, the hash-chained
audit story, the air-gap-ready single-binary pitch).
Hero gets prev / next chevrons plus a dot indicator
when the current snapshot has more than one slide.
Operator-accepted stories stay single — the carousel
collapses when there's only one to show.
5. "Ich fände es schöner wenn rechts und links im Store
die Abstände konsistent sind, das Reload-Symbol rechts
ist zu weit rechts und Store links auch nicht bündig."
AppBar now has `titleSpacing: FaiSpace.xl` so the
title's left edge sits flush with the body's left
padding (24 dp), and the trailing `SizedBox` after the
reload icon shrunk so the icon's outer edge meets the
right edge of the rightmost grid card.
6. "Oben der Titel zeigt fai_studio an, das sollte F∆I
Studio sein." The OS window title was the
pubspec-derived "fai_studio". Macos/Linux/Windows
runners now hard-code "F∆I Studio" (with the U+2206
triangle escape so the C++ source stays ASCII). macOS
bundle name and display name lifted out of the
PRODUCT_NAME variable for the same reason.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
UI parity for operators who never touch a CLI, plus a Store
that reads more like an app store.
Settings dialog:
- Channel rows gain a popup menu: Connect / Make active /
Enable autostart / Disable autostart. "Connect" still
re-points Studio's wire; "Make active" actually writes
~/.fai/current-channel via `fai channel switch`.
- Inline output panel surfaces the spawned binary's stdout
on success or stderr on failure, so operators see what
happened without opening a terminal.
Store page rewrite:
- Big top search bar with a clear button. Live filter on
every keystroke.
- Horizontal category strip auto-populated from the index;
segmented status row (All / Published / Alpha / Planned),
Installed-only chip, result count.
- Grid of cards that reflows to fit the viewport — replaces
the previous single-column list. Each card shows
category-aware icon, version, status, tagline preview, and
a one-click Install (or Details for installed / planned).
- Per-module detail sheet renders the full bilingual
description with a DE/EN toggle, separate Required-
capabilities + Required-host-services sections, repo link,
Read-docs button. Install + Uninstall live at the bottom.
- StoreItem and HubService.searchStore now carry the German
tagline + description so the locale toggle has something
to switch to.
SystemActions extended with `faiChannelSwitch`,
`faiDaemonEnable`, `faiDaemonDisable` so Settings can spawn
the right CLI without each call site reimplementing the
`fai` resolution rules.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
UI parity for Windows operators who never touch a shell:
- Module sheet gains an Uninstall button at the bottom.
Two-step confirmation, then calls UninstallModule + closes
the sheet + refreshes the Modules page.
- Doctor page picks up two new sections:
* Daemon files — log / config / audit DB / modules /
flows / pid, each with a one-click "Open" button that
shells out to the OS handler (open / xdg-open /
explorer).
* Daemon control — Restart / Stop / Status buttons that
spawn `fai daemon …`. Captured stdout/stderr renders
inline so the operator sees what happened.
- Update banner gains an "Apply update" button that spawns
`fai update apply --channel <c>`. The previous version
showed the command as text — Windows users had no way to
execute it.
- Event log panel gains a "Verify now" button that re-runs
the chain check (via the existing doctor refresh).
New SystemActions helper resolves the `fai` binary via
$FAI_BIN → PATH → `~/.fai/bin/fai` (or the Windows
equivalent), so the buttons work whether the operator
restarted their shell after installing or not.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>