Desktop Material

Overview · Install · Features · Complete list · Screenshots · Roadmap & receipts · Development

總覽 · 安裝 · 功能 · 完整清單 · 截圖 · 路線圖同憑證 · 開發

Tabbed README — GitHub can't run scripts, so each tab above is a separate page.

分頁式 README — GitHub 唔行得 script,所以上面每個分頁都係獨立一版。

Features / 功能

The full Material Design 3 shell plus every Git and GitHub workflow Desktop Material ships. For milestone status and published CI/release evidence, see the Roadmap & receipts tab; for annotated captures, see the Screenshots tab.

完整嘅 Material Design 3 外殼,加埋 Desktop Material 出貨嘅每一個 Git 同 GitHub 工作流程。里程碑狀態同已發佈嘅 CI/發佈證據睇 路線圖同憑證 分頁;有註解嘅擷取睇 截圖 分頁。

The archived Linux TUI prototype adapted a subset of these workflows for character-cell terminals. Its source, generated parity contract, package notes, and five Xvfb captures remain as historical July 27 evidence only. It is not a current supported product/release target, and its gaps do not block the Windows application.

封存低嘅 Linux TUI 原型 將呢啲工作流程嘅一部分改編到字元格終端機。佢嘅原始碼、產生嘅 對等契約、套件筆記同五張 Xvfb 擷取,淨係作為 7 月 27 日嘅歷史證據。佢唔係目前支援嘅產品/發佈目標,佢嘅缺口亦都唔會阻塞 Windows 應用程式。

Looking for an exhaustive checklist instead of this prose tour? The Complete list tab records every feature in one bilingual (English / 廣東話) table and labels each one Added, Extended, or Inherited relative to upstream GitHub Desktop.

July 27 published source acceptance: the app-hosted browser, exact-90% Cheap LFS restore look-ahead, and private-repository lock passed the final focused 760/760 across 58 files gate, 14/14 verifier contracts, full TypeScript check, exact Windows production build, and isolated hidden-desktop interaction/privacy review. The source and captures are pushed through 2abccae8fd, and Pages/wiki publication is verified live. Packaged Windows E2E is verified. Installer/Release evidence was still pending at that dated checkpoint; the separate historical TUI correction is non-blocking under the Windows-only product boundary.

**7 月 27 日已發佈來源接受:**app 自寄瀏覽器、精確 90% Cheap LFS 還原預讀同私人儲存庫鎖,通過咗最終聚焦嘅 58 個檔案共 760/760 關卡、14/14 驗證者契約、完整 TypeScript 檢查、精確 Windows 生產建置,同隔離嘅隱藏桌面互動/私隱覆核。原始碼同擷取經 2abccae8fd 推送,Pages/wiki 發佈已驗證上線。已打包 Windows E2E 已驗證。喺嗰個有日期嘅檢查點,安裝程式/發佈證據仍然待辦;獨立嘅歷史 TUI 修正喺 Windows-only 產品界線下唔構成阻塞。

The whole feature set on one page / 成套功能一版睇晒

What the map saysPre-rendered Mermaid flowchart-v2. The text after the diagram describes it in full.

What holds it up

16. Quality and recovery

17. Docs and tooling

Work either side of Git

11. Build and Run, local AI

12. Automation and agent API

15. Editors and OS

The providers you talk to

4. Accounts and identity

8. Pull requests

9. Actions and releases

The Git you drive

5. Repositories

6. Commits and branches

7. Review and diff

10. Cheap LFS

The shell you look at

1. Material 3 shell

2. Language and audio

3. Tabs and windows

13. Search and regex

14. Notifications and dialogs

Desktop Material

What the map says. Desktop Material's 201 features sit in 17 numbered areas, clustered here five ways: the shell you look at (1 Material 3 shell, 2 language and audio, 3 tabs and windows, 13 search and the regex builder, 14 notifications and dialogs); the Git you drive (5 repositories, 6 commits and branches, 7 review and diff, 10 Cheap LFS); the providers you talk to (4 accounts and identity, 8 pull requests, 9 Actions and releases); work either side of Git (11 Build & Run and local AI, 12 automation and the agent API, 15 editors and OS integration); and the foundations (16 quality and recovery, 17 documentation and tooling). Those numbers are the section numbers in the Complete list, so the map is an index, not a summary.

張圖講咩。 Desktop Material 嘅 201 項功能分佈喺 17 個編號範疇,喺呢度夾成五組:你望住嘅外殼(1 Material 3 外殼、2 語言同聲音、3 分頁同視窗、13 搜尋同 regex builder、14 通知同對話框);你操作嘅 Git(5 儲存庫、6 commit 同分支、7 覆核同差異、10 Cheap LFS);你溝通嘅供應方(4 帳戶同身分、8 pull request、9 Actions 同發佈);Git 兩邊嘅工作(11 Build & Run 同本機 AI、12 自動化同 agent API、15 編輯器同作業系統整合);同埋地基(16 品質同復原、17 文件同工具)。嗰啲數字就係 完整清單 入面嘅章節編號,所以呢張圖係索引,唔係摘要。

張圖講咩。 Desktop Material 嘅 201 項功能分喺 17 個範疇,呢度夾埋做五嚿:你望住嘅外殼(1 Material 3 外殼、2 語言同聲音、3 分頁同視窗、13 搜尋同 regex、14 通知同對話框);你揸住嘅 Git(5 倉庫、6 Commit 同分支、7 審閱同 diff、10 Cheap LFS);你要傾偈嘅供應商(4 帳戶同身分、8 Pull request、9 Actions 同 Release);Git 前後嗰啲工夫(11 Build & Run 同本機 AI、12 自動化同 agent API、15 編輯器同作業系統);同埋托住成座嘢嘅地基(16 品質同復原、17 文件同工具)。啲號碼就係 Complete list 嘅章節號,所以呢張係索引,唔係摘要。

Advanced Git and collaboration workflows (M21)

進階 Git 同協作工作流程(M21)

Local Ollama model lifecycle (M23)

本機 Ollama 模型生命週期(M23)

The accepted off-screen manager capture is a privacy-safe synthetic scene at 1452×1001. Its full health, inventory, search, running-state, pull cancellation and rollback, completed pull, copy, rename, load, unload, confirmed-delete, and provider-sync exercise is recorded in HANDOFF.md.

接受咗嘅離屏管理員擷取係一個 1452×1001、保護私隱嘅合成場景。佢完整嘅健康、清單、搜尋、執行狀態、pull 取消同回復、完成 pull、複製、改名、載入、卸載、確認刪除同供應方同步操作,記錄喺 HANDOFF.md

Material Design 3 Expressive shell

Material Design 3 Expressive 外殼

Appearance customization

How appearance is layeredPre-rendered Mermaid flowchart-v2. The text after the diagram describes it in full.

appends an audit commit,
never rewrites

One owner, one timeline

a cleared value inherits

Profile owner

Repository owner

Feature owner

Tab-title owner

Shift+right-click the real element
or use Context Menu / Shift+F10

Repository settings,
Appearance hub

Anchored editor for
that one owner

Normalized, schema-checked value

Its own local Git repo,
one setting.json

History: diff, undo,
redo, restore

How appearance is layered. There is no central appearance studio. You reach an editor two ways — Shift+right-clicking the element that actually owns the look (or focusing it and using the Context Menu key / Shift+F10), or the Repository settings Appearance hub — and both commit through the same owner path, so an edit made either way is indistinguishable, History included. The normalized value lands on exactly one owner: a profile owner, a repository owner, a feature owner, or a single tab's title owner. A repository owner whose value is cleared inherits the matching profile value. Each owner keeps one setting.json in its own local Git repository, and its History panel can diff, undo, redo, or restore — each of which appends an audit commit rather than rewriting the chain.

外觀係點分層。 呢度冇一個中央外觀工作室。你有兩條路開到編輯器 — 撳住 Shift 再右擊真正擁有嗰個樣嘅元素(或者聚焦佢再撳 Context Menu 掣/Shift+F10),或者經儲存庫設定嘅 Appearance hub — 兩條路都經同一條擁有者路徑提交,所以無論用邊條路改,結果都分唔出,連 History 都一樣。正規化之後嘅值淨係落喺一個擁有者:profile 擁有者、儲存庫擁有者、功能擁有者,或者單一分頁嘅標題擁有者。一個被清空咗值嘅儲存庫擁有者會繼承對應嘅 profile 值。每個擁有者喺自己嘅本機 Git 儲存庫入面保存一個 setting.json,而佢嘅 History 面板可以 diff、還原、重做或者恢復 — 每一項都係加一個稽核 commit,唔會改寫個鏈。

外觀係點分層。 呢度冇一個中央外觀工作室。你有兩條路開到編輯器:撳住 Shift 再右擊真正擁有嗰個樣嘅元素(或者 focus 住撳 Context Menu 掣/Shift+F10),或者行 Repository settings 嘅 Appearance hub;普通右擊繼續開原本嘅功能選單。兩條外觀路徑都行同一個 owner 路徑落去,所以邊度改都一模一樣,連 History 都一樣。個正規化咗嘅數值淨係落喺一個 owner 度:profile owner、repository owner、feature owner,或者某一個分頁標題嘅 owner。Repository owner 清空咗個值,就會繼承返 profile 嗰個。每個 owner 喺自己嘅本機 Git repo 揸住一個 setting.json,History 面板可以睇 diff、undo、redo、還原 — 每一下都係加多個審計 commit,唔會改寫舊歷史。

Repository tabs

儲存庫分頁

How the strip is organizedPre-rendered Mermaid flowchart-v2. The text after the diagram describes it in full.

no group may cross
this boundary

Window

Active profile

Tab strip

Pinned side

Unpinned side

Named groups plus
loose tabs

Group chip: name, colour,
count, collapsed state

One-shot sorts move each
group as a single block

Every tab stays bound
to one repository

Collapsing hides the members,
the chip stays

Export keeps order, pins,
aliases; omits group ids

How the strip is organized. Tabs and their groups belong to a window and a profile, so switching either gives you that context's own strip. The strip has a protected pin boundary and no group is allowed to straddle it; each side holds its own named groups and loose tabs. A group is a label, never a behaviour change: its chip carries the name, colour, member count and collapsed state, collapsing hides the members while the chip stays reachable, the one-shot sorts move a whole group rather than shuffling a stranger into the middle of it, and deleting a group closes nothing. Each tab stays bound to its repository throughout. A portable session export deliberately carries order, pins, favourites, aliases, and per-tab appearance but not group definitions or membership, because a group belongs to the profile that receives the import.

成條分頁列點編排。 分頁同佢哋嘅群組屬於一個視窗同一個 profile,所以轉視窗或者轉 profile 都會見到嗰個脈絡自己嗰條列。條列有一條受保護嘅釘選界線,冇任何群組跨得過;兩邊各自有自己嘅具名群組同散裝分頁。群組係一個標籤,唔會改變行為:佢個標籤帶住名稱、顏色、成員數同摺疊狀態;摺疊會收埋成員但係個標籤仍然到得到;一次過嘅排序會整組一齊移,唔會將個陌生分頁塞入中間;刪除群組唔會關閉任何嘢。每個分頁自始至終綁住佢嘅儲存庫。可攜嘅工作階段匯出刻意帶住次序、釘選、最愛、別名同逐分頁外觀,但係唔帶群組定義同成員關係,因為群組屬於接收匯入嗰個 profile。

成條分頁列點編排。 分頁同佢哋嘅群組屬於某個視窗、某個 profile,所以轉窗或者轉 profile 就會見到嗰邊自己嗰條列。條列有一條受保護嘅釘住界線,冇任何群組跨得過;兩邊各自有自己嘅具名群組同散裝分頁。群組淨係一個標籤,唔會改行為:個 chip 寫住名、顏色、成員數同收埋咗未,收埋之後成員唔見但 chip 仲喺度撳得到,一次過排序係搬成嚿群組,唔會塞個唔相干嘅分頁入去中間,而刪群組更加唔會關到任何分頁。每個分頁自始至終都綁實佢嗰個倉庫。可攜嘅工作階段匯出會帶走次序、釘住、收藏、別名同逐分頁外觀,但故意唔帶群組定義同成員關係 — 因為群組係屬於接收匯入嗰個 profile 嘅。

Multi-account

App-hosted browser — locally accepted

App 內瀏覽器 — 本機驗收已經過關。 你可以喺 Settings → Advanced → Open web links 揀連結喺 app 入面定系統瀏覽器開。App 內嗰個有分頁、網址列、前後頁、重新整理、Go、書籤同外部逃生門;遠端網頁鎖喺 sandboxed WebContentsView,冇 Node、冇 preload、冇 app IPC 信任、冇權限、唔會 幫你下載或者繞過壞憑證。登入分頁用記憶體工作階段、加唔到書籤,閂咗會清資料, 亦永遠有得轉去系統瀏覽器。

Versioned settings & history

有版本嘅設定同歷史

Non-modal dialog framework

非模態對話框框架

Notification centre

通知中心

Search everywhere, with a regex builder

周圍都搜尋得到,仲有 regex builder

Repository safety and cleanup

儲存庫安全同清理

Dynamic UI scaling

動態介面縮放

Per-repo .gitignore manager

逐儲存庫嘅 .gitignore 管理員

One-click Build & Run

一鍵 Build & Run

Automation and GitHub Actions

自動化同 GitHub Actions

Agent access and command line

Agent 存取同命令列

Why three front doors reach one back doorPre-rendered Mermaid flowchart-v2. The text after the diagram describes it in full.

explicit and usable

stale, or missing permission

legacy, never bound

Visible UI

One command path:
the same stores and safety checks

Scheduled automation

Agent API and CLI

Loopback, bearer token,
body and queue limits

Repository account binding

The stored account key selects
a credential-vault identity

Stops at sign-in or
account recovery

One exact-origin identity binds;
several need a labelled choice

Fetch, pull, push, post-push
refresh, remote-HEAD discovery

Results never carry a token

Why three front doors reach one back door. Whether a Git operation is started by clicking in the UI, by scheduled automation, or by the opt-in local agent server, it executes through the same stores and the same safety checks — the agent route simply passes a loopback, bearer-token, body-size and queue gate first. From there the repository's own account binding, not sign-in order, decides which identity is used: the stored account key selects a credential-vault identity, a binding that has gone stale or lost permission stops at account recovery instead of borrowing a neighbour, and a legacy never-bound repository is bound by a single exact-origin match while several matches ask you to choose. Account credentials are never returned in a result.

點解三度前門通向同一度後門。 一個 Git 操作,無論係喺介面撳出嚟、由排程自動化發起,定係由你主動開啟嘅本機 agent 伺服器叫出嚟,都係經同一批 store 同同一批安全檢查執行 — agent 嗰條路淨係多咗先過 loopback、bearer token、內文大小同佇列呢幾道閘。之後決定用邊個身分嘅,係儲存庫自己嘅帳戶綁定,唔係登入次序:儲存低嘅帳戶鍵揀出憑證保管庫入面嘅身分;一個已經過時或者失去權限嘅綁定會停喺帳戶復原,唔會借隔籬嗰個嚟用;而一個從來未綁過嘅舊儲存庫,喺得一個精確 origin 相符嗰陣會自動綁定,有幾個相符就要你自己揀。帳戶憑證永遠唔會喺結果入面回傳。

點解三度前門通向同一度後門。 一個 Git 操作,無論係你喺介面撳出嚟、排程自動化跑出嚟,定係由你自己開啟嘅本機 agent 伺服器叫出嚟,都係行同一批 store 同同一批安全檢查 — agent 嗰條路淨係要先過 loopback、bearer token、body 大細同佇列嘅關卡。之後決定用邊個身分嘅,係倉庫自己嘅帳戶綁定,唔係邊個先登入:儲住嗰條帳戶 key 會撳出憑證保險庫入面嘅身分;綁定過期咗或者冇權限就停喺帳戶復原,唔會靜靜雞借隔籬個帳戶;而從來未綁過嘅舊倉庫,如果同 origin 淨係有一個身分就自動綁,有幾個就要你自己揀。結果永遠唔會帶住權杖走。

Power-user history, stashes, and windows

進階用戶嘅歷史、stash 同視窗

Guided Git and provider administration

引導式 Git 同供應方管理

How a huge selection reaches the remotePre-rendered Mermaid flowchart-v2. The text after the diagram describes it in full.

no

yes

yes

no

Reviewed selection

Cheap LFS first pins the files
over its own threshold

Split into stable batches:
1.4 GB of changed blobs, or
10,000 files, whichever comes first

More than one batch?

Ordinary commit behaviour,
unchanged

Prove a non-force push
destination exists

Stage only this batch's paths

Record the intent ref

Commit only those paths

Promote the proven commit
to the pending ref

Push that exact SHA:
fast-forward rules, hooks still run

Is that commit
the remote tip?

Clear both checkpoints, refresh,
then start the next batch

The checkpoint survives; the next
attempt reconciles it before new work

How a huge selection reaches the remote. Cheap LFS runs first, as a separate earlier step, so genuinely large files become pointers before ordinary Git bytes are ever measured. What remains is split on a stable file order under two ceilings at once — 1.4 GB of changed blobs (100 MB of the decimal 1.5 GB budget is reserved for pack overhead) and 10,000 files, plus a conservative 48 MiB raw-diff estimate — so a mountain of tiny files splits too. One batch behaves exactly like an ordinary commit. Two or more, and Desktop Material first proves a non-force destination, then repeats a strict loop per batch: record an intent ref, commit only that batch's paths, promote the proven commit to a pending ref, push that exact SHA, and only create the next commit once the push is proven to be the remote tip. If the push, the app, or the machine dies mid-loop, those two compare-and-swap checkpoints are what the next attempt reconciles before it starts anything new. Ordinary pushes and your persistent Git configuration are untouched.

一大堆嘢係點樣推得上遠端。 Cheap LFS 行先,係獨立而且更早嘅一步,所以真係大嗰啲檔案喺度量普通 Git 位元組之前就已經變咗 pointer。剩低嘅按穩定檔案次序切開,同時受兩條上限管住 — 1.4 GB 改動 blob(十進位 1.5 GB 預算入面留咗 100 MB 俾 pack 開銷)同 10,000 個檔案,加一個保守嘅 48 MiB 原始差異估算 — 所以一大堆細檔案一樣會切開。得一個批次嘅話,行為同普通 commit 完全一樣。兩個或者以上,Desktop Material 會先證明目的地唔需要 force,然後逐個批次重複一個嚴格循環:記錄一個 intent ref、淨係 commit 嗰個批次嘅路徑、將已證明嘅 commit 升做 pending ref、推送嗰個精確 SHA,並且要等推送被證明係遠端 tip 之後先建立下一個 commit。如果推送、app 或者部機喺循環中途死咗,下一次嘗試就係靠嗰兩個 compare-and-swap 檢查點做對帳,之後先開始任何新嘢。普通推送同你持久嘅 Git 設定完全唔會郁。

一大堆嘢係點樣推得上遠端。 Cheap LFS 行先,係獨立而且更早嘅一步,所以真係大嗰啲檔喺度量普通 Git 位元組之前就已經變咗指標。剩低嘅按穩定檔案次序切開,同時受兩條上限管住 — 1.4 GB 變更 blob(十進制 1.5 GB 預算入面留返 100 MB 俾打包開銷)同 10,000 個檔,再加一個保守嘅 48 MiB raw diff 估算 — 所以一大堆芝麻綠豆咁細嘅檔一樣切得開。得一批嘅話,行為同普通 commit 一模一樣。兩批或以上,Desktop Material 會先證明有一個唔使 force 嘅推送目的地,跟住逐批死板咁行呢個圈:寫低 intent ref、淨係 commit 呢批嘅路徑、將證實咗嘅 commit 升做 pending ref、推嗰個精確 SHA,直到證實佢真係遠端 tip 先至開下一個 commit。中途死機、閂咗 app 或者推到一半斷線,下次嘅嘗試就係靠嗰兩個 compare-and-swap 檢查點對返數,先至做新嘢。普通 push 同你嘅持久 Git 設定完全冇郁過。

Guided GitHub workflows

引導式 GitHub 工作流程

Responsiveness and resource lifecycle / 反應速度同資源生命週期

Fully Material, everywhere

周圍都係徹底 Material

Also shipped: multi-clone with organization chips, parallel/sequential modes and URL-only import/export; one-click commit and push with a generated message; self-update checks against Desktop Material releases; SVG diff hardening and display controls; safer undo/reset/tag deletion confirmations; and responsive, keyboard-accessible MD3 surfaces throughout the app.

**另外出咗:**多重 clone 配組織標籤、並行/順序模式同淨係網址嘅匯入/匯出;一鍵 commit 同 push 配自動產生訊息;對住 Desktop Material 發佈嘅自我更新檢查;SVG 差異加固同顯示控制;更安全嘅還原/重置/標籤刪除確認;以及成個 app 入面響應式、鍵盤可存取嘅 MD3 介面。