Conversation
149878f to
7958201
Compare
Sync update (
|
7958201 to
df4a0e1
Compare
Sync update (
|
Sync update (
|
6f6e819 to
4e73ab6
Compare
Sync update (
|
…tablyai#24726) * fix(files): retry failed shallow directory watch replacement * fix(plugins): restore development watchers after folder replacement * fix(plugins): reconcile root bindings without broad macOS watches * fix(plugins): avoid source-watch restarts on Windows child edits * fix(plugins): preserve full filesystem identity precision * fix(plugins): recognize root replacement on inode-less volumes * fix(plugins): preserve availability without reliable directory identity
…ts (stablyai#24888) * fix(watchers): preserve full directory identity precision * fix(watchers): recover replaced inode-less directories * fix(watchers): decline unavailable creation-time identities
…tial database is unreadable (stablyai#24605) * fix(opencode-go): stop before OPENCODE_API_KEY when the credential database is unreadable An unreadable OpenCode credential database read as 'no key', so the Go key resolver fell through to OPENCODE_API_KEY, which OpenCode shares with its Zen provider and can show usage for the wrong key. The database read now reports unreadable separately; with an env key set the resolver stops, and the usage fetch uses a configured cookie or shows a readable error. * fix(opencode-go): treat a denied credential-database listing as unreadable, not missing
…eadable (stablyai#24604) An unreadable state DB was read as 'not busy', so the trust grant ran a short app-server RPC that can refresh an abandoned backfill lease. A tri-state pending check lets the trust grant take its fallback, while other callers keep their existing boolean behaviour.
… SQLite reader worker (stablyai#24603) * refactor(sqlite): rename the OpenCode SQLite worker entry to foreign-sqlite-reader (STA-9122) The worker thread that reads OpenCode's database off the main thread is about to read other apps' databases too, so its entry is renamed to what it is: src/main/foreign-sqlite-readers/foreign-sqlite-reader-entry.ts, built as out/main/foreign-sqlite-reader-entry.js. Why now: stablyai#24572 fixed the Cursor focus freeze with a second, dedicated worker. Rather than grow one worker per foreign app, the next commit moves Cursor onto this entry and deletes that worker. This commit is the rename only; stablyai#24572's cursor-desktop-profile-worker-entry lines stay until then. It moves out of ai-vault/ into a new foreign-sqlite-readers/ module because it will no longer be session-scanner code; the module will own the readers, their dispatch, protocol and main-process client. The entry still routes only OpenCode kinds in this commit. The OpenCode dispatch, protocol and process entry stay in ai-vault/ and stay OpenCode-only, because the SSH/WSL relay reader bundles them (build-relay.mjs). Every reference is updated: electron.vite.config.ts input key, knip entry, the plain-node entry guard and its test, the asarUnpack list (the scanner service still spawns this entry under ELECTRON_RUN_AS_NODE), and the electron-builder test that reads the filename. The filename and the beside-or-one-up (Rollup chunks) lookup now live in foreign-sqlite-reader-entry-path.ts, which the OpenCode spawn reuses, plus an Electron-main resolver that uses the packaged app.asar path. * fix(cursor): move the desktop-login read from its dedicated worker onto the foreign SQLite reader (STA-9122) stablyai#24572 fixed the Cursor focus freeze (stablyai#24360) with a dedicated worker (rate-limits/cursor-desktop-profile-worker*.ts). Orca already runs OpenCode's database reads on a worker, and more foreign-app SQLite reads are coming, so keeping one worker per app means one entry, build input, asarUnpack line, knip entry and guard line each. This keeps one pattern instead: Cursor's state.vscdb read runs on the shared foreign SQLite reader entry, and the dedicated worker, its entry and its config lines are deleted. What moves: - The read itself is a pure cursorProfile reader in foreign-sqlite-readers/readers/ (was rate-limits/cursor-desktop-state-db.ts), run only on the worker. A separate dispatch owns the new kinds and refuses an unknown kind. The entry routes OpenCode kinds to the untouched OpenCode dispatch, so the relay's OpenCode reader stays byte-identical. - ForeignSqliteReaderClient gives each reader its own WorkerThreadRequestQueue lane (own lazily started, idle-torn-down thread; one shared factory) with in-flight dedupe per database path. Any failure resolves to the reader's existing failure value and never falls back to the main thread. Kept from stablyai#24572, so every reader gets them: - Await worker retirement before respawning. Worker.terminate() cannot interrupt a native SQLite call (e.g. a WAL-index rebuild), so the old thread lives on until that call returns; respawning at once stacked a new thread on the same work for every timed-out read (stablyai#24572 measured three live workers). This belongs in the shared host, which fire-and-forgot terminate(): LazyWorkerThreadHost now takes awaitRetirement and refuses to spawn until the terminated worker settles, and the queue fails calls closed meanwhile. Opt-in, because pure-JS clients (session scanner abort, port scan) respawn right after an abort. A rejected terminate() also ends retirement, so it cannot latch the reader off (raised in stablyai#24572's review). - 10 s Cursor timeout, 2 consecutive deaths, a queue cap of 8. - stablyai#24572's worker tests, rewritten against the shared client: responsive caller plus coalesced probes, unavailable worker without path leaks, stalled-worker recovery, no respawn before retirement, dispose settles. Tests: reader, dispatch, client (timeout, 10 s default, crash, malformed, unavailable without a main-thread read, dedupe, queue cap, own thread per reader), queue retirement (stalled and rejected terminate), import boundary, and an event-loop test reading a ~50 MB WAL with no -shm on a real worker. * test(sqlite): walk the reader import boundary with the shared source-tree scan (STA-9122) * fix(sqlite): key reader dedupe on a caller-supplied key, not the path alone (STA-9122)
…ablyai#24261) With many tabs open, a change to any one tab (a retitle, an agent finishing, a tab switch, a git status write, or a browser tab update on SSH and web clients) re-rendered every tab in the strip, so the strip stuttered. Each tab is now a memoized row that re-renders only when its own values change, with stable handlers, a stable drag id list and stable drag sensor options. Editor tabs get their own git status, and mirrored browser tabs keep their page-id list while the ids don't change. Part of stablyai#24241: opening, closing or reordering a tab still re-renders every tab once.
…cies (stablyai#24895) * Reuse the headless detector compiler without full dependency setup * Keep optional compiler-cache saves from failing cache warming
…hip the reader worker in orcad (stablyai#24638) * fix(opencode): read the binder's session store on the foreign SQLite reader worker (STA-9122) Before: the OpenCode session binder listed new sessions from opencode.db with node:sqlite on the main thread every 60 s (and on SessionStart kicks), so a large or contended store could stall the app the same way Cursor's did. After: the read is a pure openCodeBinderSessions reader in foreign-sqlite-readers/readers/, run only on the worker. The binder's correlation, pane snapshot and process sweep stay where they were. - The binder round awaits listSessions and re-checks its generation right after, so a stop() during the read discards the round before it touches the unbound map or the watermark. - The client's in-flight dedupe key now includes the cursor, so a stale round from before a restart cannot hand its rows to the restarted round. - Idle teardown is per reader. The binder lane keeps its thread for 120 s, longer than its 60 s poll, so the thread is not respawned every round. - A timeout, crash, malformed reply or unstartable worker resolves to [] (no sessions), the value the old read already returned on failure. - An absent store still reads as [] without a log line, and a permission or corrupt-file failure still logs (kept from stablyai#24577, now in the reader: it stats the path and throws anything but ENOENT/ENOTDIR to the client's log). - The binder lane inherits stablyai#24572's limits from the shared lane: no respawn until a timed-out worker has exited, 2 consecutive deaths, a queue cap of 8. Its timeout stays 60 s, matching its poll. - dispatch switches on the destructured kind, so a new kind without a case still fails to compile. orcad: the hook server runs there too, so orcad now ships foreign-sqlite-reader-entry.js beside orcad.js (ORCAD_ARTIFACTS, built as an orcad child). build-orcad runs a smoke check that starts the built worker under the build's Node and under the pinned runtime, and does a real binder read on a fixture DB, a Cursor read of a missing file and an OpenCode history list. The OpenCode history scanner uses the same entry and was bundled into orcad without it, so on orcad it always failed closed; it can now run. Tests: reader (cursor, same-ms ids, OpenCode 2 rows, missing then created, corrupt, inaccessible directory), retirement gate for the binder lane, dispatch routing, client lane (rows, failure -> [], dedupe per cursor, own thread, idle teardown default and override), binder loop with an async listSessions (failure -> [], stop during the read), orcad path resolution through orcad's host adapters, artifact list, and the smoke check against good, missing and non-reading entries. * test(opencode): cover the binder read deadline with fake timers and name the failure test accurately (STA-9122)
…tablyai#24607) * refactor(ai-vault): delete the unused session-scanner worker thread Production always scans through the forked session-scanner service process; the worker thread was reachable only under NODE_ENV=test or the undocumented ORCA_AI_VAULT_SERVICE_PROCESS=0 switch, and nothing fell back to it on service failure. Remove the thread (spawn, client, protocol, entry, tests), its build entry, knip and plain-node-guard listings, and the backend switch, so session-scanner-background always routes to the service. - Move the scan options type to the service protocol as AiVaultServiceScanOptions. - Tests now mock session-scanner-service-spawn, the seam production calls. - Repoint the hot-path listing reliability gate from the worker-client test to the service-client test, which covers the same bounded-queue, cancellation, and fault-restart properties for the real executor. STA-9122 * test(ai-vault): cover the service's Claude-vs-OMP subagent lister choice Runs the real service entry and subagent reader, replacing only the two per-agent listers, so a swapped lister choice fails. STA-9122
* Add Qoder session history and search with real CLI coverage * Allow the real Qoder marker file to end with a newline * Keep Qoder tool output out of history previews and search * Keep Qoder search pages readable by older clients * Verify persisted Qoder history after a real generated and resumed task * Negotiate Qoder filters before searching an older execution host * Combine search client imports for the CI plugin gate * Keep the relay search oracle aligned with legacy agent filtering * test(qoder): align search capability contracts and pin old-host fencing
…4830) * fix(cursor): show the primary usage pool without hiding exhaustion Use Cursor's reported plan percentage when its base allowance disagrees. Select Cursor Models for compact display while preserving maximum-pool warning, overflow, sorting and collapse behavior. Adopts the plan mapping and primary headline intent from PR23531. Co-authored-by: DakaAlvarez <149860458+Dacadev97@users.noreply.github.com> * fix(cursor): describe compact usage summaries Correct the existing six translations and fallback to describe one summary per provider after the compact Cursor primary-pool adoption. Preserve quota mapping, selectors, alerts, sorting and detailed presentation. Validated source patch: d2a233e5f90a2cf8ccfb02dfafe99e0e03add48d with normal installed commit hooks, localization catalogs and changed-code quality. Standalone copy uses a private index and preserves the reviewed candidate ancestry. Co-authored-by: DakaAlvarez <149860458+Dacadev97@users.noreply.github.com> --------- Co-authored-by: DakaAlvarez <149860458+Dacadev97@users.noreply.github.com>
* fix(claude): settle a queued send the CLI withdrew from its own cancelled frame Claude reports each uuid-stamped command's lifecycle (queued, started, completed, cancelled). A send it withdraws from its queue gets `cancelled` before the interrupt or cancel_async_message answer, so a lost or failed answer no longer leaves that send pending: it settles as withdrawn, with the same reason and words as the receipt path. A command the CLI already started also ends `cancelled` when its turn is interrupted or fails, so `cancelled` after `started` is not a withdrawal; an echoed send has left the waiter lists and is never reached. Tests replay real 2.1.280 captures, scrubbed. * fix(claude): release a doubted send when the CLI reports its session idle A Claude send whose write ended in doubt is recorded `unknown`, and a live `unknown` reads as work still owed, so the chat showed Working until the child exited. Claude sends `session_state_changed idle` only once its whole queue has drained, so it can no longer be holding that send. The runtime now routes that report to the host's existing release, the same one Codex's thread-stopped report uses; it retires `unknown` only, never `pending`. * fix(claude): keep a command's started mark when a redelivery re-emits queued; fixtures name msg_lifecycle_v1 * fix(claude): settle every terminal lifecycle state of a send the CLI never echoed A send the CLI started, then cancelled before any echo, stayed pending: it may already be in the conversation, so it is released as doubt (unknown, recovered), never withdrawn and never re-sent. A late echo still accepts it. The 2.1.280 schema has two more terminal states. `discarded` (the CLI ended its session with the send still queued) settles as not delivered; `refused` (declined before it queued) settles as not accepted by the provider. After `started`, either one is doubt, as `cancelled` is. The late-settlement path gains an `unknown` outcome, which the host records as released doubt. * fix(claude): release a send the CLI took but left unanswered when it goes idle `session_state_changed idle` comes only once the CLI's queue has drained, so a send it took that is still unanswered there got no echo and never will: a turn that throws can leave `started` with no terminal state. Idle releases it as doubt. What proves the CLI took a send is its lifecycle frame. On a CLI that reports no lifecycle, it is the send's place on stdin: one whose write finished before an interrupt went out was read before the interrupt was, so the first idle after that interrupt releases it too. A send armed ahead of the interrupt but written after it is left alone, since the CLI may still run it. * fix(native-chat): keep the idle sweep off a Claude child that holds a send A Claude retrying a rate-limited request has taken the send but echoes nothing, so no turn row exists yet and the sweep rested the child after the idle window, turning the send into doubt. The adapter now reports whether the CLI holds a send (lifecycle `queued` or `started`, not yet echoed or ended), derived from the live waiters, and owed work counts it. Nothing is stored: every held send leaves the live set on its echo, its terminal lifecycle state, the CLI's idle, or the child's exit, so the hold ends with the send. * fix(claude): count only a started send at idle and as a held send 2.1.280's end-of-turn cleanup can report idle before it re-reads its queue, so a send read in that window goes queued, idle, started. Releasing every taken send at idle doubted that live send and dropped Working. Only a `started` send is released at idle or keeps the child from the idle sweep; a `queued` one ends by starting and echoing, by a terminal lifecycle frame, or with the child. The stdin-order path for CLIs without lifecycle frames is removed: a doubted send retired there disables content matching on CLIs that mint their own echo ids, and no Orca failure called for it. Those CLIs keep the earlier behaviour. Comments that said only a failed write or child exit ends a waiter, or that idle comes only once the queue has drained, now say what ends one. * docs(claude): say only what the CLI's lifecycle frames and idle actually prove * fix(claude): hold the idle sweep while Claude has a send queued, not only started The sweep rested a child whose CLI had queued a follow-up behind a turn, dropping the send it had already taken. The hold now spans the CLI reporting it took the send until its echo, a terminal lifecycle state, or the child's exit. The idle release still covers only started sends: 2.1.280 can report idle before it re-reads its queue. * refactor(native-chat): give provider-proven late dispatch settlement its own module * test(claude): pin a steer a Stop interrupts after it started as doubt, not withdrawn * fix(native-chat): one ordered journal writer Every journal write, streamed or direct, lands in the chat's one write queue in the order it is issued, and has landed in the fold when its call returns (except while an owed import is paid, when it lands in queue order). The event sink stops being a queue ahead of it; journal-write coalescing, which moved a replaced write to the tail, is removed; closing a sink no longer loses writes already handed over. The ten flushStreamedEvents patches go. A streamed text item takes its place at its first delta, so a direct write inside the coalescing window never lands above text already streamed. A Stop interrupts whatever its bookkeeping writes do. * fix(native-chat): a failed Stop holds the lane until its queue pause lands A Stop whose note write or stop call failed skipped the wait for its withdrawal and pause, so the lane freed first; with writes queued behind owed work, the drain could hand the waiting card to the agent after Stop. * fix(native-chat): a journal write body is typed synchronous The queue's ordering rule needs every write body to finish before it returns; serialize still took a promise-returning body, so an await inside one would let a later write land first. The body type now refuses a promise. * fix(native-chat): a stream's first window snapshot always lands The first-delta write counted as the growth checkpoint, so the window's snapshot was skipped until 32 more characters arrived: a stream showed only its first token, and a Codex reasoning row could sit as an empty aside. The coalescer now marks the row-creating emit and the first snapshot after it, and both providers' growth throttles write those. * test(native-chat): streamed text rewritten in place above a Stop note Covers a stream whose later deltas wait in the window across a Stop, for Codex and Claude, and a Codex item completed inside the window. * chore(native-chat): drop comments that still describe coalesced journal writes * fix(native-chat): type the draft-table write body synchronous too * fix(native-chat): an empty delta owes no streamed-text emit The opening snapshot is forced past the growth rule, so an empty second Codex delta rewrote the row with identical text. The coalescer now marks a stream dirty only when a delta adds text. * fix(native-chat): a mutation's open pays an owed import first With the flushes gone, a Stop naming no turn, a goal set or a /clear could read the fold while provider rows still waited behind a restore's owed import: the Stop answered cancelled:false and interrupted nothing. The open every mutation shares now waits for the import, as a reader's does; a failed import is reported and never refuses the mutation. * chore(native-chat): whenImported says mutations await it too * test(native-chat): a Stop interrupts before its withdrawal or pause settles Pins the order for a write that is held and then fails, for a Stop naming its turn and one naming none. * test(native-chat): a Stop ends a starting child before its withdrawal or pause settles * test(native-chat): Stop order tests wait for the interrupt, not a 50 ms timer * test(native-chat): settlement-order test reads rows through the journal row parser Replaces a Reflect.get field walk, which the low-evidence audit rejects, with parseJournalRow and the named row types. * fix(native-chat): an empty delta still owes its emit, just not a forced one The previous fix stopped an empty delta from marking the stream dirty, which broke the pinned contract that an empty stream is snapshotted and flushed. The coalescer now marks a stream dirty on every delta and tracks separately whether its text changed since the last emit; only a changed snapshot is the opening one that skips the growth throttle. * revert(native-chat): drop the first-text row write from the delta coalescer The immediate first-delta emit (and the opening flag and counters it needed) had no Orca-observed failure behind it and added a journal commit per streamed item. The coalescer, the Claude checkpoints and the tests that pinned the first-text row go back to main's behaviour; the one ordered writer, the sink hand-off and the Stop rules stay.
…i#24357) When git lists the same folder twice (a leftover worktree registration that points at the main checkout), Orca's runtime listing turned each line into its own worktree with the same id, so `orca worktree current`, `active` and `branch:` failed with selector_ambiguous, and paired clients saw a duplicate row. The runtime scan now keeps git's first row per folder, the rule the desktop sidebar already uses. Separately, for a bare or separate-git-dir repo added through a linked worktree, the scan no longer relabels the main row with that worktree's folder (it relabels only when the folder's git dir is the common git dir), so the worktree keeps its own row and branch in the CLI and the sidebar. No extra git command runs. Part of stablyai#23631: the "Profile state writer command timed out" toast in that issue has a separate cause.
…ai#24789) * Bound AI Vault cache loading and cooperative atomic saves Preserve schema 3 caches across compatible releases while limiting bytes, JSON structure, and newest unique rows. Keep in-process entries authoritative and retain a valid prior snapshot when the newest row cannot fit. Credits @AmethystLiang for the original PR10708 cache bounds and cooperative persistence intent. * Use checked cache JSON properties in cooperative serialization Preserves lazy own-property access and all serializer bounds, yields and errors.
…yai#25144) * Fix Markdown Find editing without changing the caret or viewport * Preserve Markdown selections across search focus and stale updates
…yai#24729) Keeps a fork issue’s details, metadata and edits bound to the repository the user opened, including same-number issues in fork and upstream. Repairs selected-assignee leakage and delayed failed edits repainting another issue. Fixes stablyai#24378 Incorporates and cross-reviews contributor PR stablyai#24379, including its source-resolver correction and regression material. Covers the contributor PR’s Project-row identity and retained-dialog mutation findings. The final published head passes focused tests, hidden macOS rendering and current CI; the callback-timing bot thread has an evidence-based response. Co-authored-by: Katsuma Takehisa <k.takehisa@nissogr.com>
…a folder (stablyai#25087) * fix(agents): keep ~/.copilot/config.json owner-only when Orca trusts a folder Marking a folder trusted for Copilot rewrote ~/.copilot/config.json through a temp file created with the default umask mode (usually 0644), so an owner-only file that can hold copilotTokens became readable by other local users. Since the folder-trust change this write also runs on SSH hosts, where other users exist. The rewrite now always writes the file owner-only (0600). * test(agents): cover a fresh owner-only Copilot config.json under a permissive umask --------- Co-authored-by: m4air <m4air@Mac.localdomain>
…ablyai#25151) * Speed up terminal test oracles without reducing replay coverage * Call asynchronous parser through its checked test interface * Preserve evidence document final newline for concurrent merges
…stablyai#25156) * Preserve ripgrep search results, filename identity, and failure diagnostics * Fix adversarial Unicode and Explorer filename findings * Register search failure localization fallback * Preserve host filename identity through document and watcher consumers
…ing input (stablyai#24762) * fix: wait for OpenCode worker composer before first dispatch Reuse captured composer readiness on local and paired execution hosts and revoke launching-shell paste anchors. Co-authored-by: Brennan Benson <79079362+brennanb2025@users.noreply.github.com> * feat(opencode): probe execution-host CLI capabilities * fix(opencode): select plugin default for execution host loader * fix(opencode): limit prompt prefill capability to verified release * feat(opencode): probe launch capabilities on the execution host * fix(opencode): select plugin loader for the launched host binary * fix(opencode): match WSL probe cwd and declared guest environment * fix(opencode): preserve launch environment deletion boundaries * wip(opencode): authorize native startup prompt intent at execution owner * fix(opencode): atomically replace status plugin entrypoints * fix(opencode): retain plugin permissions across restrictive umasks * test(opencode): resolve permission fixture from primary cwd * feat(opencode): install startup prompt plugin independently of status hooks * fix(opencode): wait for admitted startup intent and preserve failed-launch briefs * fix(opencode): unsubscribe hook settings during async host shutdown * STRICT launch CI contract correction * CAPS launch CI contract correction * INTENT launch CI contract correction * test: initialize Claude prompt state in output retention fixture * Wait for OpenCode location hydration in intent startup * Bind OpenCode startup readiness to the current location in intent startup * Retry interrupted OpenCode startup prompt claims --------- Co-authored-by: Brennan Benson <79079362+brennanb2025@users.noreply.github.com> Co-authored-by: Ahmed Nagy <ahmednagy25t@gmail.com> Co-authored-by: Orca startup hydration review <agents@stably.ai> Co-authored-by: Orca <dev@stably.ai>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: Neil <neil@stably.ai>
* Share PR static analysis and compiler runner * Preserve evidence document final newline for concurrent merges * Keep readiness reuse contracts aligned with the physical preflight gate
* Restore the owning Orca CLI path after shell profiles * Use a literal marker for the Bash lookup regression * Preserve plain panes and initialize zsh after prompt hook replacement * Preserve user line-editor dispatchers during deferred startup * fix: retain CLI startup when global Zsh replaces prompt hooks * test: replay global Zsh hook replacement after host startup * test: isolate controlled Zsh widgets from distro keyboard setup * fix(shell): preserve user hooks during deferred zsh initialization * Keep completed Zsh startup hooks retired when the wrapper is sourced again --------- Co-authored-by: Codex <codex@openai.com> Co-authored-by: Orca maintenance <orca-maintenance@users.noreply.github.com> Co-authored-by: Orca campaign <orca-campaign@local.invalid>
…stablyai#24763) * fix: wait for OpenCode worker composer before first dispatch Reuse captured composer readiness on local and paired execution hosts and revoke launching-shell paste anchors. Co-authored-by: Brennan Benson <79079362+brennanb2025@users.noreply.github.com> * feat(opencode): probe execution-host CLI capabilities * fix(opencode): select plugin default for execution host loader * fix(opencode): limit prompt prefill capability to verified release * feat(opencode): probe launch capabilities on the execution host * fix(opencode): select plugin loader for the launched host binary * fix(opencode): match WSL probe cwd and declared guest environment * fix(opencode): preserve launch environment deletion boundaries * wip(opencode): authorize native startup prompt intent at execution owner * fix(opencode): atomically replace status plugin entrypoints * fix(opencode): retain plugin permissions across restrictive umasks * test(opencode): resolve permission fixture from primary cwd * feat(opencode): install startup prompt plugin independently of status hooks * fix(opencode): wait for admitted startup intent and preserve failed-launch briefs * fix(opencode): confine overlay manifest cleanup to owned directories Co-authored-by: Adnan Khan <adnank11427@gmail.com> * fix: wait for OpenCode worker composer before first dispatch Reuse captured composer readiness on local and paired execution hosts and revoke launching-shell paste anchors. Co-authored-by: Brennan Benson <79079362+brennanb2025@users.noreply.github.com> * feat(opencode): probe execution-host CLI capabilities * fix(opencode): select plugin default for execution host loader * fix(opencode): limit prompt prefill capability to verified release * feat(opencode): probe launch capabilities on the execution host * fix(opencode): select plugin loader for the launched host binary * fix(opencode): match WSL probe cwd and declared guest environment * fix(opencode): preserve launch environment deletion boundaries * wip(opencode): authorize native startup prompt intent at execution owner * fix(opencode): atomically replace status plugin entrypoints * fix(opencode): retain plugin permissions across restrictive umasks * test(opencode): resolve permission fixture from primary cwd * feat(opencode): install startup prompt plugin independently of status hooks * fix(opencode): wait for admitted startup intent and preserve failed-launch briefs * fix(opencode): unsubscribe hook settings during async host shutdown * STRICT launch CI contract correction * CAPS launch CI contract correction * INTENT launch CI contract correction * test: initialize Claude prompt state in output retention fixture * Wait for OpenCode location hydration in intent startup * Bind OpenCode startup readiness to the current location in intent startup --------- Co-authored-by: Brennan Benson <79079362+brennanb2025@users.noreply.github.com> Co-authored-by: Ahmed Nagy <ahmednagy25t@gmail.com> Co-authored-by: Adnan Khan <adnank11427@gmail.com> Co-authored-by: Orca startup hydration review <agents@stably.ai>
4e73ab6 to
7f93f86
Compare
* fix: wait for OpenCode worker composer before first dispatch Reuse captured composer readiness on local and paired execution hosts and revoke launching-shell paste anchors. Co-authored-by: Brennan Benson <79079362+brennanb2025@users.noreply.github.com> * feat(opencode): probe execution-host CLI capabilities * fix(opencode): select plugin default for execution host loader * fix(opencode): limit prompt prefill capability to verified release * feat(opencode): probe launch capabilities on the execution host * fix(opencode): select plugin loader for the launched host binary * fix(opencode): match WSL probe cwd and declared guest environment * fix(opencode): preserve launch environment deletion boundaries * wip(opencode): authorize native startup prompt intent at execution owner * fix(opencode): atomically replace status plugin entrypoints * fix(opencode): retain plugin permissions across restrictive umasks * test(opencode): resolve permission fixture from primary cwd * feat(opencode): install startup prompt plugin independently of status hooks * fix(opencode): wait for admitted startup intent and preserve failed-launch briefs * fix(opencode): confine overlay manifest cleanup to owned directories Co-authored-by: Adnan Khan <adnank11427@gmail.com> * fix: wait for OpenCode worker composer before first dispatch Reuse captured composer readiness on local and paired execution hosts and revoke launching-shell paste anchors. Co-authored-by: Brennan Benson <79079362+brennanb2025@users.noreply.github.com> * feat(opencode): probe execution-host CLI capabilities * fix(opencode): select plugin default for execution host loader * fix(opencode): limit prompt prefill capability to verified release * feat(opencode): probe launch capabilities on the execution host * fix(opencode): select plugin loader for the launched host binary * fix(opencode): match WSL probe cwd and declared guest environment * fix(opencode): preserve launch environment deletion boundaries * wip(opencode): authorize native startup prompt intent at execution owner * fix(opencode): atomically replace status plugin entrypoints * fix(opencode): retain plugin permissions across restrictive umasks * test(opencode): resolve permission fixture from primary cwd * feat(opencode): install startup prompt plugin independently of status hooks * fix(opencode): wait for admitted startup intent and preserve failed-launch briefs * fix(opencode): unsubscribe hook settings during async host shutdown * STRICT launch CI contract correction * CAPS launch CI contract correction * INTENT launch CI contract correction * test: initialize Claude prompt state in output retention fixture * Wait for OpenCode location hydration in intent startup * Bind OpenCode startup readiness to the current location in intent startup * Collect retired source-scoped OpenCode configuration overlays conservatively Credit brennanb2025 for the original bounded, delayed overlay garbage-collection contribution in PR stablyai#7627. Preserve ambiguous legacy and shared-service state. * Correct inaccessible-source fixture without spying on native ESM exports * Keep delayed OpenCode cleanup within existing file limits * Reuse the overlay manifest module for existing owned-entry operations * Use the existing filesystem import in the ownership mock * test(opencode): keep overlay GC link tests portable --------- Co-authored-by: Brennan Benson <79079362+brennanb2025@users.noreply.github.com> Co-authored-by: Ahmed Nagy <ahmednagy25t@gmail.com> Co-authored-by: Adnan Khan <adnank11427@gmail.com> Co-authored-by: Orca startup hydration review <agents@stably.ai> Co-authored-by: OpenCode Campaign <opencode-campaign@users.noreply.github.com>
…#25185) * test(ssh): reproduce missing-pwsh text in staging paths * fix(ssh): classify missing PowerShell from command exit evidence * test: expose generic Windows upload error misclassification * test: await armed SSH upload before advancing fake clock * test: retain real immediate delivery around upload timeout control * fix: classify PowerShell absence from command exits only * test: expose missing-command text inside SSH stderr paths * fix: require missing pwsh diagnostic command identity * test: keep mixed write errors out of missing-command fallback * fix: require complete missing PowerShell diagnostic * test: capture complete native missing pwsh diagnostics * fix: recognize complete missing pwsh native diagnostics * test(ssh): cover source-derived NormalView localization and wrapping * fix(ssh): identify complete missing-pwsh records across NormalView layouts * test(ssh): cover raw-wrap separators and repeated error headers * fix(ssh): preserve wrapped separators and reject repeated error headers --------- Co-authored-by: Orca Campaign <campaign@localhost>
7f93f86 to
080b232
Compare
…yai#25239) * Strengthen shared preflight contracts and record unit timing results * Record rejected shard-weight holdouts
) * fix: wait for OpenCode worker composer before first dispatch Reuse captured composer readiness on local and paired execution hosts and revoke launching-shell paste anchors. Co-authored-by: Brennan Benson <79079362+brennanb2025@users.noreply.github.com> * feat(opencode): probe execution-host CLI capabilities * fix(opencode): select plugin default for execution host loader * fix(opencode): limit prompt prefill capability to verified release * feat(opencode): probe launch capabilities on the execution host * fix(opencode): select plugin loader for the launched host binary * fix(opencode): match WSL probe cwd and declared guest environment * fix(opencode): preserve launch environment deletion boundaries * wip(opencode): authorize native startup prompt intent at execution owner * fix(opencode): atomically replace status plugin entrypoints * fix(opencode): retain plugin permissions across restrictive umasks * test(opencode): resolve permission fixture from primary cwd * feat(opencode): install startup prompt plugin independently of status hooks * fix(opencode): wait for admitted startup intent and preserve failed-launch briefs * fix(opencode): confine overlay manifest cleanup to owned directories Co-authored-by: Adnan Khan <adnank11427@gmail.com> * fix: wait for OpenCode worker composer before first dispatch Reuse captured composer readiness on local and paired execution hosts and revoke launching-shell paste anchors. Co-authored-by: Brennan Benson <79079362+brennanb2025@users.noreply.github.com> * feat(opencode): probe execution-host CLI capabilities * fix(opencode): select plugin default for execution host loader * fix(opencode): limit prompt prefill capability to verified release * feat(opencode): probe launch capabilities on the execution host * fix(opencode): select plugin loader for the launched host binary * fix(opencode): match WSL probe cwd and declared guest environment * fix(opencode): preserve launch environment deletion boundaries * wip(opencode): authorize native startup prompt intent at execution owner * fix(opencode): atomically replace status plugin entrypoints * fix(opencode): retain plugin permissions across restrictive umasks * test(opencode): resolve permission fixture from primary cwd * feat(opencode): install startup prompt plugin independently of status hooks * fix(opencode): wait for admitted startup intent and preserve failed-launch briefs * fix(opencode): unsubscribe hook settings during async host shutdown * fix(opencode): confine overlay manifest cleanup to owned directories Co-authored-by: Adnan Khan <adnank11427@gmail.com> * test(readiness): census recorded OpenCode composer boots * fix(opencode): reject redirected overlay parents before cleanup * fix(orcad): retain runtime cleanup when subscribing to hook settings * refactor(launch): extract OpenCode config and attachment authority * fix(opencode): retain host version selection across relay restarts * fix(opencode): pass run prompts as positional messages Preserve run flags and use the existing shell quoting and run-command detector to append the initial message after --, reusing an existing separator. TUI launches retain their version-selected prompt transport and draft behavior. Original run-order work: @coelho-doti (stablyai#13065, tracked in stablyai#17551). * fix(opencode): keep wrapped run tasks positional Recognize supported environment prefixes and PowerShell call operators without mistaking prompt arguments for executables. Keep environment and run separators separate, preserve the task text and exclude run commands from native submission. Source-parent: 23fc08b Related-to: stablya/orca#17551 Credits: @coelho-doti (stablya/orca#13065) * Prepare complete private OpenCode launch validation source Integrate the complete reviewed readiness, capability, native prompt, overlay and positional-run source onto frozen main. Preserve canonical atomic ACL retry, status generator/disposal, restrictive-umask fixtures and unowned source. Keep supported wrapped run commands positional. Private-validation-source: a44345c Original-full-source: 23fc08b Original-core-base: 8186ded Frozen-main: 08ee7ba Owned-source-paths: 111 Publication-policy: private validation only; preserve the six separate PR boundaries and held model/provider drafts Co-authored-by: Brennan Benson <79079362+brennanb2025@users.noreply.github.com> Co-authored-by: Adnan Khan <adnank11427@gmail.com> Credits: juli-gonzalez readiness contribution; Ahmed Nagy atomic plugin writer; coelho-doti positional run contribution * Prepare private complete 111-path launch validation on current main Private validation only. Preserve main credential additions and original launch ownership. Held model and provider topics remain excluded. * Recognize env options before positional OpenCode run messages * STRICT launch CI contract correction * CAPS launch CI contract correction * INTENT launch CI contract correction * test(opencode): wait for malformed claim retries before expiring intent Observe real endpoint I/O completion under fake timers before forcing expiry. * test: initialize Claude prompt state in output retention fixture * Wait for OpenCode location hydration in intent startup * fix(opencode): bind startup readiness to the composer location * Bind OpenCode startup readiness to the current location in intent startup * Retry interrupted OpenCode startup prompt claims --------- Co-authored-by: Brennan Benson <79079362+brennanb2025@users.noreply.github.com> Co-authored-by: Ahmed Nagy <ahmednagy25t@gmail.com> Co-authored-by: Adnan Khan <adnank11427@gmail.com> Co-authored-by: Orca startup hydration review <agents@stably.ai> Co-authored-by: Orca <dev@stably.ai>
terminal send --interrupt wrote a bare ETX. A TUI that enabled the kitty keyboard protocol ignores that byte, so the CLI reported success while the turn kept running. When the PTY's headless model has kitty flags, write CSI 99;5u. Flags of 0 still send ETX. Fixes stablyai#17665
…odel A namespace change rebuilt the headless terminal from a provider snapshot and dropped the kitty keyboard flags, so a later interrupt sent ETX. The replacement now reapplies those flags, and the writer sends the interrupt bytes already chosen for that send.
Flag 4 does not change legacy Ctrl+C encoding, so an interrupt in that mode was sending CSI 99;5u instead of ETX.
…odel A mounted renderer snapshot omits kitty pushes. The provider replacement path already restores the flags carried beside the payload. Renderer hydration now does the same, so an interrupt still encodes Ctrl+C.
A blank serialized buffer can still carry the keyboard flags beside the payload. Hydration used to return before applying them, so a fresh emulator stayed at 0 and an interrupt sent ETX.
080b232 to
17d74ca
Compare
Upstream: stablyai#24370
ELI5
Ctrl+C in the in-app terminal now interrupts a Kitty-mode terminal application using the Kitty Ctrl+C sequence, including when the key event comes from a non-Latin input source.
What Changed
Why
The renderer intercepts Ctrl+C before xterm can encode it. On a non-Latin key path, the renderer could send the Kitty sequence without setting a pending Ctrl+C intent, while the exact-byte fallback recognized only ETX. The interrupt was delivered, but intent tracking and bracketed-paste recovery were skipped. The shared recognition keeps the byte and the renderer's follow-up behavior aligned.
Linked Issue
Fixes stablyai#17665
Visual Proof
N/A — the layout does not change, and a screenshot cannot show terminal input bytes or intent tracking. Regression tests assert both byte encodings and the non-Latin renderer path.
Testing
Ran on macOS:
All 86 tests passed. I did not manually test this on macOS, Linux, Windows, SSH, or mobile sessions. The full lint, typecheck, test, and build commands were not run locally.
AI Disclosure
OpenAI Codex (GPT-6) assisted with the implementation and review.
Review
Self-reviewed byte selection, the renderer's intent recognition, and bracketed-paste interruption. The integration test uses a non-Latin key event with code KeyC, sends Kitty Ctrl+C, and checks both inferred intent and paste-state reset.
Agent skill upstream boundary
Notes
The wire format remains ETX when Kitty disambiguation flags are not enabled. Automated tests cover the shared helper, renderer, runtime writer, headless emulator, and hydration paths; no live TUI or remote SSH session was tested.
Checklist