Rename, an in-app viewer for text and images, host-to-container drag and
drop, New folder, keyboard operation — plus the pre-existing bugs the new
surface would otherwise have been built on top of.
New Tauri commands (file_commands.rs, registered in lib.rs):
* rename_container_path — `mv -n -- <from> <parent>/<name>` through
exec_oneshot_as, so the *exit code* is checked. exec_oneshot discards the
status and interleaves stderr into stdout, which would have made a
permission failure look like a success. `mv -n` on its own is not enough
either: GNU coreutils makes its refusal to clobber silent and exits 0, so
an explicit `test -e` on the destination is what turns a name clash into
an error the user sees. `mv`'s own words are surfaced, since renames
outside /workspace legitimately fail on permissions. The new name is
validated in Rust (no `/`, no NUL, not "." / ".." / empty, ≤255 bytes) —
it is user text going into argv, and a name with a separator would be a
move rather than a rename.
* read_container_file — exact bytes via Docker's archive endpoint, returned
as base64. Deliberately not exec_oneshot, which runs every chunk through
String::from_utf8_lossy and merges stderr, so it would corrupt any
non-UTF-8 file and could splice diagnostics into content. Base64 rather
than Vec<u8> because Tauri serialises a byte vec as a JSON number array.
Capped and truncation-reporting; the caller picks the cap (images get 5
MiB against text's 1 MiB, being the kind that blows a text-sized budget)
and Rust clamps it to 8 MiB regardless.
* create_container_directory — `mkdir` without -p, so a clash is an error
rather than a silent success. Named for its siblings rather than the bare
`create_directory` in the brief.
The tar-extraction half of download_container_file is now the shared
fetch_container_file() both commands use, and it abandons the transfer once
a capped read has what it needs.
Frontend:
* Single click selects, double click opens. Directory navigation moved onto
double click too — a single click used to navigate, which made it
impossible to select a directory in order to rename it. Rows are now
focusable and the table is a real `grid`: Enter opens, F2 renames, arrows
walk the rows. No outline suppression; the global :focus-visible ring is
what shows focus.
* FileViewerModal (built on ui/Modal, the only correct dialog) renders text
in a <pre> and images from a revocable blob: URL. tauri.conf.json's
img-src had neither `data:` nor `blob:`, so an in-app image was blocked by
CSP; `blob:` is added — revocable, and no megabytes of base64 in the DOM.
The asset protocol stays disabled. Anything else gets a "Save to host"
state instead of a broken preview, decided by extension and then by
sniffing the bytes for NUL.
* Host drag-and-drop uses Tauri's native onDragDropEvent, mirroring
TerminalView: HTML5 ondrop carries no paths and is blocked in the webview
on Windows by dragDropEnabled, which the terminal needs. The listener is
window-wide, so it routes by hit-testing the payload position (physical
pixels, hence the devicePixelRatio divide) against the pane's rect — a
hidden pane has a zero-size rect and never matches, which is what keeps
this and the terminal's listener apart. enter/over/leave drive a drop
highlight.
* Per-row Download is now "Save to host…"; directories no longer offer it.
Pre-existing bugs fixed:
* Uploaded files landed root:root with a 1970 mtime. tar::Header::new_gnu()
zeroes uid/gid/mtime and Docker honours the header verbatim, so uploads
were not writable by `claude`. All four single-file tar builds now go
through build_single_file_tar() with the container user's ids, read from
the container because entrypoint.sh remaps them to the host user on Unix
and deliberately does not on Windows.
* Symlinked directories could not be opened: `find -printf '%y'` reports `l`.
The listing now prints `%Y` as well, so is_directory dereferences and a
new is_symlink carries what `%y` used to say. The row labels the link.
* upload_file_to_container had no size cap and did a synchronous fs::read on
an async worker. Now 256 MiB (matching the terminal drop path) with the
read and tar build in spawn_blocking, and the host mtime preserved.
* A directory passed to upload reached fs::read and produced an opaque "Is a
directory". Rejected with an explanation instead — recursive upload is a
larger feature than this panel needs.
* download_container_file wrote the *first tar entry*, so downloading a
directory silently produced a garbage file. Non-regular entries are now an
explicit error.
Tests: 46 new (33 frontend across FilesTab, useFileManager and filePreview;
12 Rust covering the find-output parser and the rename validator, neither of
which had any). 405 frontend / 297 Rust, both green.
No drag-out dependency was added — tauri-plugin-drag is not introduced and
OS drag-out is not attempted; that stays deferred, with "Save to host…" as
the way files leave the container.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GBq2rGum6GX7xXgsas1fDc