Source control

The source-control panel is a Git client backed by Rust. The frontend requests structured snapshots and diffs; Rust validates repository roots, arguments and workspace authorization before running Git.

Status and diffs

Open the source-control panel with Ctrl+G. The panel shows changed files, staged state and the current branch. Files can be shown as a flat list or as a tree projection without changing the underlying Git operations.

Diff tabs use CodeMirror and resolve the language before mounting so deleted and changed chunks receive the correct highlighting. The history panel renders a commit graph with lanes for branches and merges.

Stage and commit

Stage or unstage whole files and supported hunks from the panel. Enter a commit message and use Ctrl+Enter or Cmd+Enter to commit. The commit command runs against the resolved repository root, not an arbitrary path supplied by the webview.

Fetch, pull and push

Fetch, fast-forward pull and push are explicit source-control actions. Push detects whether an upstream is configured and reports the remote result. Network-backed Git operations remain scoped to the selected repository and are not silently triggered by opening the panel.

History

Use Git history to search commits, inspect refs and open changed files from a selected commit. The commit detail view can show a file list and a file-level diff.

Dubious ownership

Git may reject a repository when its filesystem ownership is not trusted. This is common with mounted volumes, containers and WSL. Trust such a repository only when you understand who controls the path. Do not work around the error by disabling repository safety globally.

Security boundary

Git commands share the workspace authorization registry with PTY spawns and AI tools. Repository resolution, pathspec validation and mutation commands are implemented on the Rust side. The webview cannot directly execute Git or inspect an unauthorized path.