tuios 0.8.1 is a security release. It makes tuios ssh and tuios-web safer to expose, and it limits what a pane and its output can do outside the pane. It also brings hints mode, multi copy mode and the fixes merged since v0.8.0.
Before you upgrade, read Breaking changes and migration. Some commands and configs that worked in v0.8.0 are refused now.
The full list is at tuios.dev/releases.
Install
brew install tuios # Homebrew (macOS, Linux)
yay -S tuios-bin # AUR (tuios-web-bin for the web server)
nix run github:Gaurav-Gosain/tuios # Nix
curl -fsSL https://raw.githubusercontent.com/Gaurav-Gosain/tuios/main/install.sh | bash
go install github.com/Gaurav-Gosain/tuios/cmd/tuios@v0.8.1
docker run -it --rm ghcr.io/gaurav-gosain/tuios:v0.8.1A binary installed by the script or from an archive updates with tuios update.
Security fixes
Remote access
tuios sshkeys.tuios sshdoes not accept a key that has options, such ascommand=,from=orrestrict. tuios cannot apply these options, so it refuses the key. The log names the line of each refused key.tuios sshkeys file.tuios sshreads only~/.config/tuios/authorized_keys. It does not read~/.ssh/authorized_keysunless you name that file with--authorized-keys.tuios-webpasswords.tuios-webcan ask for a password. Use--random-password,--password-fileor theTUIOS_WEB_PASSWORDenvironment variable.--usersets the user name. The default user name istuios.- Host header. On
localhost,tuios-webaccepts a session only when the Host header names this machine. Use--allow-hostto add the name of a reverse proxy. - Empty
--host. An empty--hostlistens on every interface.tuios sshandtuios-webnow apply the rules for a network address to it. - pprof.
--pprof :6060listens on 127.0.0.1 only. To listen on every interface, give0.0.0.0:6060. - Worktree patches.
tuios worktree pullkeeps a patch that did not apply in a new file with a random name. Only you can read the file. The message shows its path.
Pane grants
- More callers check the grants. Pane grants now cover the link sockets, the tmux shim's pane holder, prompts,
send-keys,run-commandand typing through the client protocol. - Prompts. A pane without the
respondgrant cannot type into another pane that waits on a prompt. This applies to a pane withadmintoo. send-keyswithPREFIX.send-keyswithPREFIXfrom a pane is refused. The message names the commands to use instead.- Inbox answers. The Inbox refuses answers that
send-keystyped. This covers the digit keys, the second press of a risky allow, question answers and the release of held mail. - Link sockets. A process inside a pane, or a process that the daemon started, cannot connect to a link socket.
- Wider grants wait. A
config.tomlchange that widens[agents.permissions],[hosts]or a link policy waits fortuios config apply. Run it from a terminal outside tuios. A daemon restart also applies it.- A change that narrows these tables applies at once.
- The Inbox shows an item when a change waits.
tuios pane-grantsand the log say so too. - A daemon start that finds wider grants than the last run says so in the log, in
tuios pane-grantsand in the Inbox. - A host that you add with "Add a host" on the settings page applies at once.
ssh_options. A host'sssh_optionsaccepts only safe options, each with one plain value, written as-o Keyword=value.- tuios drops a host with a refused option. The Inbox and
tuios hostsname the reason. ProxyCommand,LocalCommand, the known hosts files,ControlPathand-Fare refused.- Port forwards (
-L,-R,-D) are refused. -JandProxyJumptake host names only.ForwardAgenttakes onlyyesorno.- A host
addrorcommandcannot start with a dash.
- tuios drops a host with a refused option. The Inbox and
Pane output
- Clipboard writes. The new option
appearance.selection.osc52_writecontrols what OSC 52 from a pane does. The values areoff,ask,focusedandon. The default isfocused.- With
focused, the focused pane sets the host clipboard. A write from another pane shows a message in the dock. Click the message to copy the text. - Each pane keeps one clipboard ask. A click copies only the text that the dock shows.
- With
- Control characters. Pastes, notifications, OSC 66 text and link addresses lose their control characters. Tabs and line breaks in a paste stay.
- Clipboard replies. tuios drops a clipboard reply that answers no read request of tuios.
- Kitty graphics files. A kitty graphics file must belong to you, and its path must be absolute. tuios does not read from
/proc,/sysor/dev, other than/dev/shm. At=tfile name must holdtty-graphics-protocol. - "cd here" and layout load. These type a
cdonly into a pane whose shell is at its prompt. In daemon mode, the daemon does this check.- tuios types no
cdfor a folder whose name holds a quote, a backslash or a control character. The dock says when it did not type. - Layout load starts each new window in its folder. It does not type a
cdinto a new window.
- tuios types no
New features
- Hints mode. The leader and
Flabel the copyable text on the focused pane, such as URLs, paths, hashes and IP addresses. Type a label to copy its text.- Shift and a label also types the text into the pane. Ctrl and a label opens a URL or a local path.
- The
[hints]table sets the patterns, the label alphabet, the open command and the dim.
- Multi copy mode. The copy mode key enters multi copy mode when the focused pane is in a multifocus set of two or more panes.
- Each pane gets its own cursor and selection. A search moves each pane to its own match.
ycopies the selection of each pane.Tabcycles the format.Ywrites the text to a new file.appearance.selection.multi_formatsets the format:plain,markdownorjson.
- Multifocus.
- A paste goes to every pane in the multifocus set.
- The new actions
toggle_multifocus_activeandtoggle_multifocus_allput panes in the set or take them out. They have no default key. - With
appearance.dim_unfocusedon, panes in the set are not dimmed. Setappearance.dim_multifocusto dim them again.
- Copy mode.
- Copy mode starts on the terminal cursor. Set
appearance.selection.copy_entry = "center"to start on the middle row. /searches forward and?searches back.nrepeats the search in its direction, andNgoes the other way.- The new actions
copy_mode_search_forwardandcopy_mode_search_backwardenter copy mode and open the search. They have no default key.
- Copy mode starts on the terminal cursor. Set
- Focus with
jandk. In window mode,jandkmove focus down and up. A config that already bindsjorkthere keeps its binding. - Agent mail.
- The mailbox shows each message body inside an untrusted content fence. Each thread shows its id.
nin the mailbox writes a new message to an agent in the session.- The new
[notifications.mail]table controls mail alerts.
- Other machines.
- Results from another machine are marked as untrusted.
capture-panetakes--json. send-agent-message --attachto a host puts each file in the far session's stash.
- Results from another machine are marked as untrusted.
- Agents. tuios reports the state of oh-my-pi. The detection commands report the age of their evidence.
- Keyboard layouts. Bindings match the physical key under any keyboard layout, non-Latin layouts too.
Fixes
- Nested attach. tuios refuses to attach a session from inside its own pane, or from a pane of a session that shows it.
tuios attach --forceskips the check.- A terminal window that you start from a pane can attach.
- New panes do not get the variables of an outer tuios pane.
- Layout sync. Clients send each change to the BSP tree to the daemon, which applies and numbers it (#230). Two clients that change one layout at the same time now end on the same layout. A v0.8.0 client in the same session still works.
- Focus. The neighbour search steps to a pane that shares only one row with the focused pane. It does not step to a diagonal pane.
- Global sessions.
- The session switcher switches between sessions on other machines.
- A machine pick goes to the daemon that can act on it.
- One link carries more than fifteen remote panes.
- Nix. The Nix package builds again with the correct vendor hash. CI checks the hash on every dependency change.
- Keys.
- Keypad keys, Begin and F13 and above reach the pane.
- The leader pressed twice sends the configured leader to the pane.
- Modifier aliases work in the leader key and in every key entry.
- Web client. The web client gets the last output of a pane.
- Also fixed. The copy sweep runs at the frame rate. The session rail fits narrow rows. Focus survives a stale push from another client.
Breaking changes and migration
tuios ssh
tuios sshdoes not start when there is no keys file. This applies tolocalhosttoo. Before, a server onlocalhostwith no keys file let every connection in.- If your key is only in
~/.ssh/authorized_keys,tuios sshdoes not use it now. Do one of these:-
Add your public key to
~/.config/tuios/authorized_keys:mkdir -p ~/.config/tuios cat ~/.ssh/id_ed25519.pub >> ~/.config/tuios/authorized_keys
Use your public key file if it has a different name.
-
Start with
--authorized-keys ~/.ssh/authorized_keys. tuios does not apply the rules insshd_configto these keys. -
Start with
--no-auth. Then every user on this machine can connect, or everyone who reaches the port on a network address.
-
- A key with options in the keys file is not accepted. Add the key again with no options if it must open a tuios session.
tuios-web
- A bind to an address other than
localhostneeds a password.--auto-tlsor--certalone is not enough, because TLS does not check who connects. Add--random-passwordor--password-file, or add--no-authon a network you trust. --allow-hostneeds a password or--no-auth. It works only with a loopback--host. Give the host name with no port.- On
localhostwith no password,tuios-webstill starts. It prints one line to say that other users on this machine can connect. - The password file must belong to you, with mode 600 or 400.
Pane grants
-
Prompts. A pane that types into another pane's prompt needs the
respondgrant.admindoes not include it. To give it to one pane, usetuios set-pane-grantsor--grants. -
send-keyswithPREFIX. A script in a pane that sendsPREFIXfails now. Use the tuios command for the action instead, such asfocus-window,new-windoworsplit-window. -
send-keyswith no window. From a pane,send-keyswith no window types into the focused pane. tuios does not read these keys as key bindings. -
run-command. From a pane withoutrespond,run-commandcannot type or press keys. Usesend-keysorsend-textwith-w. -
Config changes that widen. A change that widens
[agents.permissions],[hosts]or a link policy waits. Run this from a terminal outside tuios:tuios config apply
tuios hosts addfrom a pane also waits for it.
ssh_options
- Look in the Inbox or run
tuios hostsafter the upgrade. A host with a refused option is dropped. - Move a refused option, such as
ProxyCommandorLocalForward, into~/.ssh/config. Then name that host inaddr. - Keep port forwards (
-L,-R,-D) in~/.ssh/config. - Write each option as
-o Keyword=value, with one value and no quotes.
Clipboard and folders
- OSC 52. A program in a background pane cannot set the host clipboard without a click. To get the v0.8.0 behaviour, set
appearance.selection.osc52_write = "on". - "cd here" and layout load. tuios types no
cdinto a pane that runs a program. Go back to the shell prompt and try again. - Mixed versions. A v0.8.1 client with a v0.8.0 daemon types no
cdinto a daemon pane. To start a v0.8.1 daemon, runtuios kill-serverafter the upgrade. This closes every pane in every session, so save your work first.
Contributors
Thank you to everyone who sent a pull request for this release:
- @masshirodev: keypad keys, Begin and F13 and above (#195)
- @nathan-poncet: chords read by the key they type (#209)
- @fonnesbeck: oh-my-pi agent state (#223)
Thanks to JakeChop for reporting the security issues.
Full Changelog: v0.8.0...v0.8.1