yazi-gui-app
main, initialization, window lifecycle, dependency injection.
Architecture & decisions
OwlCommander is a full graphical file manager, not a TUI skin. The boundaries below must be recorded in docs/decisions/ before they change, and dependencies only flow downward.
Layers
The GUI may never touch std::fs or the Windows Shell directly; the engine may never reference GPUI types; COM details never escape their adapter.
Cargo workspace
Every crate has a single responsibility; test doubles live in testkit.
main, initialization, window lifecycle, dependency injection.
GPUI Entities, views, theme and component assembly.
High-performance FileViewport: list, grid, rubber-band select, drag & drop.
PreviewController and text/image/media/archive presenters.
Commands, reducers, window/tab session.
Engine facade, DTOs, event protocol, cancellation.
UI-free engine extracted and wrapped from vendor/yazi.
Lua runtime, Yazi plugin adapter, GuiView IR.
SQLite: workspace, history, favorites, layout, cache index.
Platform traits — pure interfaces plus test fakes.
Windows implementation; COM never escapes.
Virtual filesystem, time, Shell, drag & drop and screenshot doubles.
Operation contract
Every OperationPlan is preflighted before it starts: capabilities, same-path conflicts, identical source/target, permissions, disk space and overwrites.
Every request carries a RequestId, LocationRevision and CancellationToken.
Capabilities, conflicts, same source/target, permissions, space, overwrites; failures are rejected, never degraded to silent overwrite.
Chooses IFileOperation under WindowsShellLocal or the Yazi VFS executor.
Progress lands in the task center; late results are discarded by revision.
Decision records
Before changing an architectural boundary or safety semantic, a decision must be recorded here.
Verification gates
.\scripts\bootstrap.ps1 -VerifyOnly cargo +1.98.0 test --locked --offline cargo +1.98.0 clippy --locked --offline -- -D warnings git diff --check
Formatting uses cargo +1.98.0 fmt. UI work stays non-blocking; STA COM/OLE stays pinned to the documented broker thread; COM interface pointers never cross threads.
Upstream lock
UPSTREAM_LOCK.json, Cargo.lock and .cargo/vendor form a single non-drifting baseline. No cargo update, no floating Git dependencies, no edits to vendored upstream source — unless an explicit upgrade/patch decision says so.