Give a shell the whole phone, and one bar to leave it by

A connected phone was drawing five rows of chrome around the thing the user
opened it for. The vault header at 56, the terminal's own tab strip at 52, a
connection line at 36, the shells strip at 46 and the four-entry bottom bar at
64: at 360dp that is about a third of the display, and every row of it was
about somewhere the user was not. What replaces them is one 52-pixel bar drawn
by the surface itself — back on the left, the session pills, and a `+` across
from them — and then the terminal.

Three of those rows belong to `PhoneShell` and each is now bound on
`IsShowingPages`. That is the same question asked once rather than three
conditions that could drift: the surface is either a page or a terminal, and
these are the chrome a page has. The header needed a wrapper because Avalonia's
bindings have no "and" and it already had a condition of its own; the strip
needed one for the same reason. The bottom bar had none and is bound directly.

The back arrow goes to the page the terminal was opened over rather than to
Hosts by name, because the system back gesture already picks that and an arrow
landing somewhere else would be the second of two answers to one question. The
bar's `+` raises a sheet offering the three connections this application can
make — a shell, a host's files over SFTP, a bucket — since SFTP and S3 used to
be two taps through the bottom bar's MORE and the bar is not on screen here. A
control that replaced it and led to one of the three would have quietly removed
the other two.

Two things moved rather than being dropped. The text-size buttons are pinned at
the right-hand end of the accessory key row, outside its scroller: the
connection line existed to keep them from scrolling out of reach, and being
outside the scroller answers that argument rather than abandoning it. The
dialled address moved onto the connecting card, which is the moment it is worth
reading — what is being connected to, before anything has answered — and after
that the shell's own prompt says it more accurately than a header derived from
the keychain ever did.

The sheet collapses the renderer rather than covering it. Whether Android's
`WebView` composites above Avalonia content the way Win32's child window does is
still unverified — `docs/android-port.md` has said so since the port — so this
follows the desktop's palette and gives up the rectangle outright, which is
correct under either answer. It collapses `IsTerminalShowing` and not
`IsTerminalSurface`, because the bar the sheet was raised from is part of that
surface and dropping it would take the bar, the tabs and the whole arrangement
with it, leaving the sheet floating over the page underneath.

`OnSurfaceChanged` is the one place the flag is lowered, and that is the load-
bearing half. Every way out of a terminal ends there — a destination, the files
screen, the palette connecting to a host, closing the last tab, a lock — and
each of them would otherwise leave a sheet set over a page. Not merely untidy:
the flag holds the renderer blank, so the next return to the terminal would
draw the menu again over a rectangle kept blank by it. Opening is refused off
the terminal surface for the same reason from the other direction.

The back gesture gains a guard above the switch, in the shape of the editor
guard that arrived with the phone's `+`. It is nearer than any of them: with no
header and no bottom bar, while the menu is up that gesture is the only way off
it other than the scrim and CANCEL.

The bottom bar's Terminal entry lost its `IsCurrent` binding. The bar is
collapsed on that surface, so the binding could only ever be read as false, and
a rule about a state the control cannot be in is a claim that it can.

Three tests in `ShellFlowTests`, which is where shared state-machine behaviour
for this head goes: the collapse and its recovery, the refusal to open over a
page, and the sheet lowering both by a menu entry and by a route it was never
wired to. Everything visual needs a device, so it is phase 11 of
`docs/manual-checks.md` — and 11.2 is the check that would finally settle the
compositing question this head has carried as unverified since the port.
This commit is contained in:
2026-08-03 14:33:16 +02:00
parent ce86a4ff72
commit 80ae586fc4
9 changed files with 591 additions and 172 deletions
@@ -687,6 +687,82 @@ public sealed class ShellFlowTests : IAsyncLifetime
shell.Screen.ShouldBe(ShellScreen.Vault);
}
/// <remarks>
/// The phone's connect menu is drawn over the terminal's own rectangle, so it obeys the rule the palette
/// does: whatever covers the renderer collapses it instead. The surface stays, because the bar the menu
/// was raised from is part of it — see <c>MainWindowViewModel.IsTerminalShowing</c>.
/// </remarks>
[Fact]
public async Task TheConnectSheet_HidesTheRendererAndLeavesTheSurfaceUnderIt()
{
var vault = await ReadyToConnectAsync();
await using var renderer = await FakeRenderer.AttachAsync(workspace, Token);
await vault.ConnectCommand.ExecuteAsync(null);
shell.OpenConnectSheetCommand.Execute(null);
shell.IsConnectSheetOpen.ShouldBeTrue();
shell.IsTerminalShowing.ShouldBeFalse("the sheet draws over the renderer's rectangle");
shell.IsTerminalSurface.ShouldBeTrue("the bar the sheet was raised from is on that surface");
shell.CloseConnectSheetCommand.Execute(null);
shell.IsTerminalShowing.ShouldBeTrue();
}
/// <remarks>
/// The flag holds the renderer blank, so one set while a page was showing would be a sheet nobody can
/// see keeping a terminal hidden that nothing would put back.
/// </remarks>
[Fact]
public async Task TheConnectSheet_RefusesToOpenOverAPage()
{
var vault = await ReadyToConnectAsync();
await using var renderer = await FakeRenderer.AttachAsync(workspace, Token);
await vault.ConnectCommand.ExecuteAsync(null);
shell.ShowScreenCommand.Execute(ShellScreen.Vault);
shell.OpenConnectSheetCommand.Execute(null);
shell.IsConnectSheetOpen.ShouldBeFalse();
}
/// <remarks>
/// Every entry on the menu navigates, and none of them closes the sheet itself: leaving the terminal
/// surface is what lowers it. That is the guarantee worth a test — it is what makes routes nobody wrote
/// the sheet for, like closing the last tab or locking, safe.
/// </remarks>
[Fact]
public async Task LeavingTheTerminal_LowersTheConnectSheetHoweverItIsLeft()
{
var vault = await ReadyToConnectAsync();
await using var renderer = await FakeRenderer.AttachAsync(workspace, Token);
await vault.ConnectCommand.ExecuteAsync(null);
// The menu's own second entry: one screen, over one view model, with the kind of remote chosen by
// the thing that navigates.
shell.OpenConnectSheetCommand.Execute(null);
shell.ShowFilesCommand.Execute(RemoteKind.Bucket);
shell.IsConnectSheetOpen.ShouldBeFalse();
shell.IsBucketsShowing.ShouldBeTrue();
// And a route the sheet was never wired to: back to the terminal, open it, then end the only shell
// there is.
shell.ShowTerminalCommand.Execute(null);
shell.OpenConnectSheetCommand.Execute(null);
shell.IsConnectSheetOpen.ShouldBeTrue();
await shell.CloseTabCommand.ExecuteAsync(shell.Tabs[0]);
shell.IsConnectSheetOpen.ShouldBeFalse("closing the last tab returns the surface to a page");
shell.IsShowingPages.ShouldBeTrue();
}
/// <remarks>
/// A visible WebView with no pane in it reads as the application having broken, so this is the one
/// transition that moves the surface back on its own.