Move Windows dialogs and credential I/O off the foreground thread (#64250)
## Summary
Move Windows file-open, file-save, and native message dialogs off the
foreground executor so time spent waiting for a user does not appear as
a long foreground task poll. Move Windows Credential Manager reads,
writes, and deletes to the background executor as well.
The caller-facing receiver/task APIs remain unchanged. No hang-journal
suppression or new public GPUI task-spawn API is introduced.
## Implementation
- Run synchronous native dialogs on dedicated threads with COM STA
initialization and cleanup on the same thread.
- Keep the native owner relationship when a window exists; support
ownerless file/save dialogs by passing a null owner HWND.
- Serialize dialogs per owner using one mutex, also used to wait for
active native work before destroying the owner HWND. Closing the GPUI
window sets a shared cancellation flag and hides the native window;
queued requests see that flag and cannot launch. No pending counter,
lifetime lease, cancellation registry, or idle-notification channels are
needed.
- Use a worker-thread timer to request native cancellation when the
caller drops its receiver or the owner closes.
- Preserve message prompts without a Cancel option by vetoing user
cancellation unless an internal cancellation was requested.
- Distinguish actual file-dialog failures from user cancellation.
Sleep/wake and frame-visibility telemetry are intentionally deferred.
## Validation
- `corgi fmt -p gpui_windows -- --check` and scoped `git diff --check`
passed.
- Minimal scratch Windows-target harnesses type-checked the dialog
module and native API wiring against real Windows 0.62 bindings. These
are not full integration builds.
- Six extracted native-independent state/policy tests passed, covering
owner shutdown, queued-request cancellation state, per-request
cancellation isolation, per-owner serialization, ownerless cancellation,
and 12 message-prompt cancellation-policy combinations. These do not
execute native dialogs or the complete coordinator/worker handoff.
- Before the shutdown simplification, Cameron built and launched Zed
successfully on Windows using a shorter `CARGO_TARGET_DIR`, and reported
running the manual prompt checks. The captured output contains no
foreground/action hang or saved task-trace messages, but exact
prompt-by-prompt coverage and timing have not been established.
- The committed Windows test suite has not yet been run natively.
## Open review items
This PR remains a draft. The dialog helper has been simplified to
approximately 245 production lines, retaining native ownership and using
the existing per-owner mutex for shutdown instead of separate lifetime
bookkeeping. Independent static review found no concrete lifetime
regression. Native cancellation still uses the existing worker-thread
timer/window-enumeration mechanism; Windows runtime validation of the
revised shutdown path is outstanding.
Before merging, verify ownerless prompts, focus/Alt+Tab behavior,
overlapping requests for the same owner, cancellation while
queued/shown, owner closure, and nested overwrite confirmations on
Windows. Absence of hang logs alone does not establish those behaviors.
The required review-confirmation marker in README.md must be removed
manually by the human author after review.
Release Notes:
- N/A
- [GPUI] Move window dialogs and credential I/O off foreground thread
a0f8fa7bdbAnthony Eid committed on 9/15/2026, 6:59:14 PM· committed by GitHubparent01c555b