Source control¶
The source-control panel is a Git client backed by Rust. The frontend requests structured snapshots and diffs; Rust validates repository roots, arguments and workspace authorization before running Git.
Status and diffs¶
Open the source-control panel with Ctrl+G. The panel shows changed files, staged state and the current branch. Files can be shown as a flat list or as a tree projection without changing the underlying Git operations.
Diff tabs use CodeMirror and resolve the language before mounting so deleted and changed chunks receive the correct highlighting. The history panel renders a commit graph with lanes for branches and merges.
Stage and commit¶
Stage or unstage whole files and supported hunks from the panel. Enter a commit message and use Ctrl+Enter or Cmd+Enter to commit. The commit command runs against the resolved repository root, not an arbitrary path supplied by the webview.
Fetch, pull and push¶
Fetch, fast-forward pull and push are explicit source-control actions. Push detects whether an upstream is configured and reports the remote result. Network-backed Git operations remain scoped to the selected repository and are not silently triggered by opening the panel.
History¶
Use Git history to search commits, inspect refs and open changed files from a selected commit. The commit detail view can show a file list and a file-level diff.
Dubious ownership¶
Git may reject a repository when its filesystem ownership is not trusted. This is common with mounted volumes, containers and WSL. Trust such a repository only when you understand who controls the path. Do not work around the error by disabling repository safety globally.
Security boundary¶
Git commands share the workspace authorization registry with PTY spawns and AI tools. Repository resolution, pathspec validation and mutation commands are implemented on the Rust side. The webview cannot directly execute Git or inspect an unauthorized path.