Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
5769 commits
Select commit Hold shift + click to select a range
3b13282
Reuse the parsed notification when leasing a push delivery (#24645)
nwparker Oct 3, 2026
36d0086
Update README downloads badge
github-actions[bot] Oct 3, 2026
30e0cca
Let retired-cache GC observations settle across the existing six-turn…
nwparker Oct 3, 2026
f93808d
Collect test-selection evidence when full unit tests fail (#24955)
nwparker Oct 3, 2026
ebe7702
Check each project repository once while filtering mobile cards (#24540)
nwparker Oct 3, 2026
d2c9636
Skip renderer callbacks after their request has ended (#24631)
nwparker Oct 3, 2026
9e11375
Decode single-piece saved-session tails without copying them (#24632)
nwparker Oct 3, 2026
832caea
Avoid irrelevant scroll-action searches in Mac snapshots (#24731)
nwparker Oct 3, 2026
1c8d281
Stop copying every retained browser page before attachment (#24553)
nwparker Oct 3, 2026
0afc7b1
Reuse event byte sizes when relay watchers notify several clients (#2…
nwparker Oct 3, 2026
cca14bd
Stop building unused import candidates in the test planner (#24611)
nwparker Oct 3, 2026
c792386
docs(terminal): explain local macOS/Linux shell startup files
brynnclaw Oct 3, 2026
97fd7ed
fix(editor): recognize Ruby task and configuration files
ggbdpq Oct 3, 2026
b332742
Speed up large Markdown Find and render oversized tables (#24948)
nwparker Oct 3, 2026
fa2d50f
fix(source-control): generate clean OpenCode messages locally and ove…
nwparker Oct 3, 2026
81e69f3
fix(persistence): preserve projectGroupOrder on restart for flat fold…
lurunzi Oct 3, 2026
6565a3f
fix(runtime): reclaim temp files orphaned by interrupted mobile store…
LDH1103 Oct 3, 2026
8c4d63e
fix(terminal): show actionable copy for missing folder workspace paths
Waynting Oct 3, 2026
6486624
docs: reference local orca.yaml and .worktreeinclude
nwparker Oct 3, 2026
4f46f5b
fix(orchestration): allow model selection for OMP workers
nwparker Oct 3, 2026
c39f5f2
fix(cli): preserve primitive success results in JSON output
nwparker Oct 3, 2026
f255574
Show loaded file changes before deleting a workspace
nwparker Oct 3, 2026
0f1bbce
fix(keybindings): record and match Option+digit shortcuts on macOS
marcuslannister Oct 3, 2026
9f5c520
fix(editor): don't throw closing a stale active file
OrcaWin Oct 3, 2026
5f5c266
Fix Project Settings targeting for multiple local checkouts
fsmeier Oct 3, 2026
130b2ef
feat(documents): open CSV and TSV files from the OS
nwparker Oct 3, 2026
c1d403a
feat(cli): link GitHub and GitLab items on worktree create and set
SongMarco Oct 3, 2026
7b8498b
feat(sidebar): include folder workspaces in keyboard navigation
nwparker Oct 3, 2026
126f709
fix(build): turn off MSBuild file tracking for Windows native rebuilds
b1nhm1nh Oct 3, 2026
f113d35
Fix Ctrl+M in Linux and Windows terminals
yuzhichang Oct 3, 2026
98a6d20
fix(startup): read a nushell login PATH from $env.PATH
Kh05ifr4nD Oct 3, 2026
8919f3d
fix(cursor): run local hooks through sh for non-POSIX login shells
Kh05ifr4nD Oct 3, 2026
a5f28f2
Fix word wrap for both panes in side-by-side diffs
innocarpe Oct 3, 2026
df9acd8
fix(monaco): highlight Svelte block closers inside markup
innocarpe Oct 3, 2026
752dbc9
fix(repos): keep active clone dialog open on outside clicks
nwparker Oct 3, 2026
8ccc336
fix(editor): keep chat visible after closing Markdown tabs
nwparker Oct 3, 2026
44c584e
Honor typed starting numbers in chat ordered lists
nwparker Oct 3, 2026
4a5f00f
Normalize base source once while checking changed-code diagnostics (#…
nwparker Oct 3, 2026
a2896f5
Support real OpenCode sessions in native Chat (#24647)
nwparker Oct 3, 2026
ec47f0c
Drain removal fixture jobs before resetting and deleting their record…
nwparker Oct 3, 2026
668d6d4
Reuse measured Electron preparation for current Terminal Perf refs (#…
nwparker Oct 3, 2026
4049e63
feat(jcode): add Jcode as a supported TUI agent with managed hooks
czzczz Sep 23, 2026
2ca85d2
feat(jcode): evidence-backed status pipeline (turn_start, live pre_to…
nwparker Sep 23, 2026
6164d3f
fix(jcode): register vault fixture, dynamic model discovery, script r…
nwparker Sep 23, 2026
5b43e20
fix(jcode): keep finished-turn detail so completion notifications fire
nwparker Sep 23, 2026
5ab36cc
fix(jcode): show the prompt in agent rows instead of jcode's repainti…
nwparker Sep 23, 2026
33cab24
fix(jcode): pre-warm the per-pane daemon so a cold runtime dir cannot…
nwparker Sep 23, 2026
7fb201f
fix(jcode): stop the OSC color skip from crashing every pane connect
nwparker Sep 23, 2026
0a45ad5
refactor(jcode): fold three reverse-scan copies into one, reuse the s…
nwparker Sep 23, 2026
4f2007a
fix(jcode): narrow dynamic reads with predicates, pin the Windows hoo…
nwparker Sep 23, 2026
2c04f79
test(jcode): measure the gate against the synchronous path, not the c…
nwparker Sep 24, 2026
888e3c4
test(jcode): drop the wall-clock gate assertion
nwparker Sep 24, 2026
a7b9358
fix(jcode): address CodeRabbit review on #22539
nwparker Sep 24, 2026
fe76440
fix(jcode): read the journal once per turn, key prompts by byte offset
nwparker Sep 24, 2026
4c2cb3c
fix(jcode): quote the managed hook path, drop tools from patch prompts
nwparker Sep 24, 2026
07d8aff
test(jcode): pin the tool-profile flag in the generation plan too
nwparker Sep 24, 2026
154b2fd
fix(text-generation): refuse an oversized argv prompt on Linux too
nwparker Sep 24, 2026
84d246b
fix(jcode): register in main's remote-installer guard, drop our dupli…
nwparker Oct 3, 2026
af4c3e2
fix(jcode): decompose the four files jcode pushed over max-lines
nwparker Oct 3, 2026
8dc16a7
feat(native-chat): open structured chats on the paired Orca server th…
brennanb2025 Oct 3, 2026
2fc517c
feat(cli): add --unread/--read to orca worktree set
razshlomo Oct 3, 2026
bde1c09
feat(cli): configure external worktree visibility per repo
nwparker Oct 3, 2026
a40e501
perf(git): reuse queries and stop canceled catalog scans (#24923)
nwparker Oct 3, 2026
1001118
test(e2e): require exact Linux package tokens (#24995)
nwparker Oct 3, 2026
0e36159
Allow cold node-pty setup on Windows ARM CI (#24997)
nwparker Oct 3, 2026
aca2d51
fix(jcode): harden Windows hooks and negotiate remote history (#24998)
nwparker Oct 3, 2026
6245192
fix(git): preserve SSH review context and worktree ownership (#24945)
nwparker Oct 3, 2026
5e65871
fix(opencode): keep shared-session TUI activity with its owning pane …
nwparker Oct 3, 2026
b601b98
fix(ci): wait for the fragment navigation policy report (#25017)
nwparker Oct 3, 2026
c2dba12
Add host-owned OpenCode and Devin managed account profiles (#24636)
nwparker Oct 3, 2026
786a040
Read OpenCode Go usage from the selected account (#24770)
nwparker Oct 3, 2026
1d010ce
fix(source-control): default Codex to GPT-5.6 Terra low (#24495)
BeamNawapat Oct 3, 2026
ee84608
fix(jira): search plain text when task search input isn't JQL (#22900)
AmoabaKelvin Oct 3, 2026
88e9517
Wait for OpenCode worker input before the first dispatch (#24601)
nwparker Oct 3, 2026
bbafca4
fix(source-control): generate PR details before Create PR on a ready …
AmoabaKelvin Oct 3, 2026
995715b
test(windows): record native PTY stress lifecycle milestones (#25042)
nwparker Oct 3, 2026
c5d298a
fix(cli): orca file open opens PDFs and other binaries like the File …
AmethystLiang Oct 3, 2026
fd030c4
Update README downloads badge
github-actions[bot] Oct 3, 2026
0c4e26e
refactor(orchestration): one function for six agent-to-agent sends (#…
brennanb2025 Oct 3, 2026
2bd656c
feat(native-chat): a Claude subagent waiting on a permission prompt r…
brennanb2025 Oct 3, 2026
752871b
Turn desktop notifications on or off per machine (#24518)
brennanb2025 Oct 3, 2026
9eb73a6
Replace agentArgsOverride with unified removeAgentArgs approach (#25091)
AmethystLiang Oct 3, 2026
4fdf6df
Reuse the ancestor path while building mobile agent rows (#24539)
nwparker Oct 3, 2026
8b1dc63
Release waiting terminal output when a mobile subscription fails to s…
nwparker Oct 3, 2026
558c10f
Avoid cloning terminal agent owners twice in relay listings (#24713)
nwparker Oct 3, 2026
caf8078
Reuse prepared statements for internal worker checks (#24573)
nwparker Oct 3, 2026
f1e6aea
Prepare the Activity search query once per filtered list (#24701)
nwparker Oct 3, 2026
b5814d0
Avoid rescanning shared chunks in the plain Node build guard (#24717)
nwparker Oct 3, 2026
b5db0ad
Select the latest stable release tag in one pass (#24786)
nwparker Oct 3, 2026
a436aab
Avoid Resource Manager renders when terminal removal leaves its inven…
nwparker Oct 3, 2026
cf43dd1
Cancel pending cursor updates when a terminal closes (#24566)
nwparker Oct 3, 2026
eee19ac
Cancel terminal preview fit frames when the preview closes (#24712)
nwparker Oct 3, 2026
1de8396
Skip new mobile toast work after feedback owner cleanup (#24759)
nwparker Oct 3, 2026
86b2dd6
Release terminal side effects after they have been delivered (#24548)
nwparker Oct 3, 2026
24580c7
Release relay handshake timers when a host connection leaves (#24554)
nwparker Oct 3, 2026
4498e09
Avoid restarting error timers on closed mobile relay links (#24567)
nwparker Oct 3, 2026
831710c
Avoid restarting error timers after mobile relay pairing closes (#24568)
nwparker Oct 3, 2026
0619462
Delete unreturned clipboard cache files after a failed write (#24599)
nwparker Oct 3, 2026
e1b046a
Skip new legacy file inventories after mobile search cleanup (#24792)
nwparker Oct 3, 2026
759c48c
Discard completed AI Vault cancellation IDs in the relay worker (#24820)
nwparker Oct 3, 2026
73904fc
Release completed updater setup timers and callbacks (#24920)
nwparker Oct 3, 2026
60b1664
Check daemon idle state without building discarded terminal inventori…
nwparker Oct 3, 2026
8cd9751
fix(updater): keep macOS Orca open when background instances block up…
OrcaWin Oct 3, 2026
92965f3
Cancel review animations and timers when the Markdown preview closes …
nwparker Oct 3, 2026
44b955b
docs: update Android APK links to 0.0.52 (#25107)
AmethystLiang Oct 4, 2026
5df67ef
Preserve saved account credentials after enrollment errors (#25059)
nwparker Oct 4, 2026
3575895
Fix admission of later Claude question rows and real CLI verification…
nwparker Oct 4, 2026
2b1acd0
fix: remove managed profiles through canonical UUID paths (#25126)
nwparker Oct 4, 2026
af13da5
Recognize Build terminals and preserve Windows confirmation key routing
nwparker Oct 4, 2026
4ea021f
fix(opencode): finish status installation with invalid TUI settings (…
nwparker Oct 4, 2026
94f5669
fix(packaging): ship serve-sim only in macOS builds (#25128)
Jinwoo-H Oct 4, 2026
e5ba597
Recover working local forge CLIs behind broken PATH launchers
aashish254 Oct 4, 2026
3284b4c
Retain browser feedback notes across navigation and reload
E-BlackTV Oct 4, 2026
136b990
fix(search): negotiate supported agents across mixed host versions (#…
nwparker Oct 4, 2026
f199a20
Preserve OpenCode reasoning and recorded patches in native history (#…
nwparker Oct 4, 2026
1dc6157
ci: run the cross-version tests when the chat send builders or the RP…
brennanb2025 Oct 4, 2026
3cc5e1d
Avoid duplicate ripgrep scans for full file inventories (#23490)
nwparker Oct 4, 2026
5a2aa87
Select OpenCode plugin exports from the execution host version (#24662)
nwparker Oct 4, 2026
d5bb69d
Cut CI time in store, Git contention and readiness tests (#25147)
nwparker Oct 4, 2026
9207aef
Add an optional shortcut to toggle child workspaces (#24165)
mmarabel Oct 4, 2026
f8081c5
Filter Markdown filenames before sending the listing to the app (#25148)
nwparker Oct 4, 2026
8267b57
Fix Markdown Find editing without moving the caret or viewport (#25144)
nwparker Oct 4, 2026
ce07786
Keep opened issue details and edits in the selected repository (#24729)
nwparker Oct 4, 2026
b1b78b4
Update README downloads badge
github-actions[bot] Oct 4, 2026
ffd23fe
Avoid repeated runtime imports and recovery fixture seeding (#25155)
nwparker Oct 4, 2026
2576783
fix(agents): keep ~/.copilot/config.json owner-only when Orca trusts …
brennanb2025 Oct 4, 2026
2b3b692
Reduce terminal test overhead while preserving full parity checks (#2…
nwparker Oct 4, 2026
58bd15f
Fix ripgrep result completeness, filename handling, and search errors…
nwparker Oct 4, 2026
e8310d5
fix(opencode): submit admitted native startup briefs without overwrit…
nwparker Oct 4, 2026
f62bd7d
feat(csv-viewer): detect semicolon-separated CSVs (#19894)
kbsali Oct 4, 2026
b407d06
Reuse buffer cells during terminal cursor context scans (#25161)
nwparker Oct 4, 2026
c4e8735
Share PR preflight setup to reduce runner demand (#25150)
nwparker Oct 4, 2026
d9173ff
Keep Orca CLI first after shell startup (#25130)
nwparker Oct 4, 2026
8c61730
fix(opencode): keep overlay manifest cleanup inside owned directories…
nwparker Oct 4, 2026
87bc51d
Reduce test deadline waits and exact byte comparison costs (#25187)
nwparker Oct 4, 2026
70cf912
Clean up retired OpenCode configuration copies safely (#25222)
nwparker Oct 4, 2026
5389925
Preserve Windows SSH upload failures unless pwsh is missing (#25185)
nwparker Oct 4, 2026
d77c570
Verify shared preflight selection and record full unit timings (#25239)
nwparker Oct 4, 2026
ea6a6d6
Pass wrapped OpenCode run prompts as positional messages (#25001)
nwparker Oct 4, 2026
8d87d2c
feat(codex): tell Windows users once that Codex in Orca now shares ~/…
OrcaWin Oct 4, 2026
0f9bc5a
fix(codex): keep Orca-only MCP servers when refreshing the retained s…
OrcaWin Oct 4, 2026
95753a1
fix(jcode): report missing and outdated managed hooks (#25135)
NicholasTing Oct 4, 2026
a5b8b7e
Delete docs/reference/jcode-hook-events.md (#25288)
nwparker Oct 4, 2026
41cc775
Keep active notebook cells current after external reloads (#25172)
nwparker Oct 4, 2026
b32462f
Replace patched JSON parser with stream-json (#25202)
nwparker Oct 4, 2026
cbe6438
Reuse source-line calculations for Markdown review selections (#25173)
nwparker Oct 4, 2026
ddefd52
Keep selected text navigation from rewriting document links (#25175)
nwparker Oct 4, 2026
b99d28e
A resent chat message gets its recorded answer, never an early refusa…
brennanb2025 Oct 4, 2026
ab41610
Fix reordering workspaces with collapsed children (#25302)
nwparker Oct 4, 2026
97fa6ae
fix(native-chat): show a message Orca accepted and then failed to del…
brennanb2025 Oct 4, 2026
f0b5b85
Bound OpenCode history reads and repeated worker failures (#25292)
nwparker Oct 4, 2026
e42768f
Update in-app Android APK links to mobile 0.0.52 (#25168)
brennanb2025 Oct 4, 2026
0971479
Add shared workspace settings note and prevent filter modal expansion…
AmethystLiang Oct 4, 2026
b1e12d7
fix(native-chat): a new structured chat's model list comes from the m…
brennanb2025 Oct 4, 2026
ca77409
fix(agents): recognize Pi bundled npm entrypoint
boris-papevis Oct 4, 2026
6c07570
fix(cursor): keep usage cookies on the selected account (#25243)
nwparker Oct 4, 2026
f371532
Bound search preview retention and stop canceled remote scans (#25303)
nwparker Oct 4, 2026
8ff6ec9
Install OpenCode hooks in the terminal's config directory (#25296)
nwparker Oct 4, 2026
8e8efb1
Reduce avoidable work in PR checks and SSH test setup (#25309)
nwparker Oct 4, 2026
a753aff
Isolate code editor text and Undo history by execution host (#25174)
nwparker Oct 4, 2026
4a41e24
Fix: settle sortEpoch in store to prevent React update depth exceeded…
AmethystLiang Oct 4, 2026
fb77c14
fix: update Caffeinate tooltip copy about MacBook lid behavior (#23091)
AmethystLiang Oct 4, 2026
baa56fd
Simplify the phone-control and phone-size terminal dialogs (#25307)
Jinwoo-H Oct 4, 2026
3655bd9
fix(terminal): stop old output bleeding into Claude's screen when rev…
Jinwoo-H Oct 4, 2026
0c761a7
Admit short required auxiliary checks after PR preflight (#25317)
nwparker Oct 4, 2026
52b3766
Clarify keep-awake tooltip behavior by platform (#25323)
AmethystLiang Oct 4, 2026
3b01ba6
fix(native-chat): show "Sending…" on a message until the host confirm…
brennanb2025 Oct 4, 2026
1978469
fix(mobile): keep the working rings turning on the OTA page (#25299)
Jinwoo-H Oct 4, 2026
75344e5
docs: align contributor guidance with the PR template (#25034)
pqminh27 Oct 4, 2026
cecb621
fix(ui): restore IME Enter protection in workspace details (#24099)
setodeve Oct 4, 2026
d3afb5c
Preserve large paste destinations and native Undo boundaries (#25177)
nwparker Oct 4, 2026
e246090
Preserve image clipboard targets and content across editor changes (#…
nwparker Oct 4, 2026
8e5080c
Validate OpenCode worker model preferences on the execution host (#24…
nwparker Oct 4, 2026
955dce5
Keep workspace deletion dialogs steady while changes load (#25321)
nwparker Oct 4, 2026
51fe6f3
fix(editor): restored tabs for files outside your projects no longer …
brennanb2025 Oct 4, 2026
6f8eee3
fix(test): pass getInsertionRange in the image-insert access test (#2…
Jinwoo-H Oct 5, 2026
ccfc8fe
Update README downloads badge
github-actions[bot] Oct 5, 2026
0a8c572
fix(native-chat): start a new chat after an earlier start failed (#24…
brennanb2025 Oct 5, 2026
d9846e6
fix(test): give async image-insert store mocks the openFiles list (#2…
Jinwoo-H Oct 5, 2026
46c3c3b
Keep OpenCode worker model selection separate from the default (#24768)
nwparker Oct 5, 2026
822fc5b
Add repository OpenCode permission defaults (#25326)
nwparker Oct 5, 2026
b9b0f29
fix(relay): skip the dead-cell sweep's host scan when no cell qualifi…
Jinwoo-H Oct 5, 2026
e9daf9b
fix(relay): prune released control-connection reservations in bounded…
Jinwoo-H Oct 5, 2026
aac1c8f
chore(relay): move US cells c32 and c33 to the general same-cap list …
Jinwoo-H Oct 5, 2026
ebeea31
Support modern Qoder commands and verify authenticated resume
nwparker Oct 5, 2026
e884681
fix(relay): retain confirm results for a week and audit events for 90…
Jinwoo-H Oct 5, 2026
1bec53c
Reduce repeated CI setup and overlap mobile typechecks (#25359)
nwparker Oct 5, 2026
52bd9af
refactor(relay): stop creating three tables nothing writes (#25354)
Jinwoo-H Oct 5, 2026
3f6225d
fix(orchestration): accept max and ultra effort for Codex models Orca…
Jinwoo-H Oct 5, 2026
e347aa4
fix(mobile): honour the desktop pinned-worktree placement setting (#2…
Jinwoo-H Oct 5, 2026
b94cfa7
feat(relay): declare Asia spare cell c34 as migration-only (#25336)
Jinwoo-H Oct 5, 2026
7863871
Keep OpenCode foreground evidence when its background service starts …
nwparker Oct 5, 2026
16d937d
Keep large CSV previews responsive and add column resizing and links …
nwparker Oct 5, 2026
f873aaa
Fix duplicate session option flags and preserve argument values (#25382)
AmethystLiang Oct 5, 2026
d279adc
fix(activity): keep code blocks in row previews from rendering as scr…
Jinwoo-H Oct 5, 2026
e02adc5
Add translations for terminal shell settings (#25418)
AmethystLiang Oct 5, 2026
a154562
fix(native-chat): show a reply cut off by an Orca crash or quit like …
brennanb2025 Oct 5, 2026
2b0ce17
Show provider credit balances alongside usage limits (#25408)
nwparker Oct 5, 2026
c53b6f2
Edit CSV tables directly and remember column widths (#25442)
nwparker Oct 5, 2026
e46fa0d
test(linear): cover numeric-leading issue identifiers (#10241)
kenfdev Oct 5, 2026
67fc708
Group CSV editor modules and tests in their own folder (#25476)
nwparker Oct 5, 2026
1b957b7
fix: close worktree dialog before slow script checks (#25472)
nwparker Oct 5, 2026
c2c7649
fix(mobile): stop Android from selecting words while the chat transcr…
chokolademilch7 Oct 5, 2026
b332839
Remove completed SSH picker E2E plan (#24824)
kazooooo-ma Oct 5, 2026
40f9e7a
fix(codex): resume account switches without blanking the terminal (#2…
nwparker Oct 5, 2026
8b5de39
Submit initial OpenCode 2.0.12 prompts through the native startup plu…
nwparker Oct 5, 2026
fa180a9
feat(jira): pick the assignee when creating an issue — Automatic, me,…
kazuki-hanai Oct 5, 2026
1569e06
Reduce repeated terminal scans and unused Qoder test imports (#25425)
nwparker Oct 5, 2026
e2da3a1
fix: prevent IME confirmation from submitting text fields (#25480)
nwparker Oct 5, 2026
d173514
Update README downloads badge
github-actions[bot] Oct 5, 2026
2a68ea9
refactor(terminal): one commit module for terminal topology closes, w…
Jinwoo-H Oct 5, 2026
8f846d4
fix(native-chat): a Stop binds only the turn it actually stopped (#24…
brennanb2025 Oct 5, 2026
ad5aa01
fix(native-chat): a chat's finished-turn alerts come from the host re…
brennanb2025 Oct 5, 2026
98171a8
fix(native-chat): never delete chat history on read; a chat Orca can'…
brennanb2025 Oct 5, 2026
a68ee67
fix(codex): stop prompting a Codex restart when only its home changed…
OrcaWin Oct 5, 2026
d19e064
Fix legacy worker recovery snapshot timing for rollback safety (#25413)
AmethystLiang Oct 5, 2026
f250db5
fix(jira): read a missing or malformed Jira status as disconnected (#…
brennanb2025 Oct 5, 2026
761d63a
feat(agent-launch): keep long prompts off the launch line and paste t…
brennanb2025 Oct 5, 2026
b354aab
fix(mobile-chat): a failed message's text is added to the draft, and …
brennanb2025 Oct 5, 2026
ca2cdc0
feat(native-chat): answer /context in chat view for OpenClaude and OM…
brennanb2025 Oct 5, 2026
57fedee
fix(native-chat): the agent's exit ends its record, and an unconfirme…
brennanb2025 Oct 5, 2026
d9cc1d0
feat(activity): filters, matching header, row right-click menu, and s…
Jinwoo-H Oct 5, 2026
c5a1c0e
Add confirmed deletion of nested worktrees (#25668)
nwparker Oct 5, 2026
17ecee6
fix(relay): read reconcile's counter units after the cell lock (#25638)
Jinwoo-H Oct 5, 2026
d518d4a
Retire automatic profile JSON snapshots with safe recovery and downgr…
OrcaWin Oct 5, 2026
56dbf1b
fix(i18n): polish Japanese onboarding checklist copy (#19035)
tb-soshiro Oct 5, 2026
a42e586
fix(native-chat): keep a Stop's note with the turn it waited for and …
brennanb2025 Oct 5, 2026
e9ed75a
fix(native-chat): mark a chat whose start failed on its tab and works…
brennanb2025 Oct 5, 2026
a3bd6a6
fix: restore main's lint and localization checks after the nested-wor…
brennanb2025 Oct 5, 2026
f1ed355
feat(relay): drain pace window as a reviewed same-cap input, with dra…
Jinwoo-H Oct 5, 2026
e817b0e
refactor(native-chat): keep the provider resume handle opaque to shar…
brennanb2025 Oct 5, 2026
508419f
test: check structured-chat code for Electron imports even before the…
brennanb2025 Oct 5, 2026
7208be6
test(native-chat): cover paired runtime launch compatibility (#25072)
brennanb2025 Oct 5, 2026
d791421
Extract provider process supervision and stream reading from Codex (#…
brennanb2025 Oct 5, 2026
e2a1ecd
feat(activity): multi-select agent rows with a bulk right-click menu …
Jinwoo-H Oct 5, 2026
10bea3a
feat(relay): report lane service times, 503 causes, per-site hold p99…
Jinwoo-H Oct 5, 2026
990b0ed
fix(orchestration): give an OpenCode worker its task only once OpenCo…
OrcaWin Oct 5, 2026
ca883c5
fix(ci): unblock main's static analysis after the nested-worktree del…
brennanb2025 Oct 5, 2026
ab91559
feat(relay): one-command director deploy driver (#25642)
Jinwoo-H Oct 5, 2026
086b06c
fix(test): build the stop-note test's Codex provider handle with code…
Jinwoo-H Oct 5, 2026
9def4b9
feat(native-chat): publish where each submission was sent and the tur…
brennanb2025 Oct 5, 2026
33ad909
refactor(mobile): remove client context and terminal geometry import …
nwparker Oct 5, 2026
764fea5
test(mobile): mount recorder through public client context
nwparker Oct 5, 2026
7ef65fb
test(mobile): use explicit type imports for recorder context
nwparker Oct 5, 2026
4937c8d
fix(renderer): preserve spaced Windows path pastes
innocarpe Oct 2, 2026
fdc1745
test(renderer): cover Windows basename punctuation boundary
innocarpe Oct 2, 2026
8c51903
test(editor): exercise Windows terminal paste through public editor p…
nwparker Oct 5, 2026
7d77ec2
test(editor): follow block-style lint in clipboard controls
nwparker Oct 5, 2026
648175e
fix(renderer): address Windows path review feedback
innocarpe Oct 5, 2026
0e52049
fix(renderer): match Unicode terminal path basenames
innocarpe Oct 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
94 changes: 86 additions & 8 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -1,12 +1,90 @@
/config/scripts/create-draft-release.mjs text eol=lf
/config/scripts/orca-dev.mjs text eol=lf
/config/scripts/latest-stable-release.mjs text eol=lf
/config/scripts/publish-complete-draft-releases.mjs text eol=lf
/config/scripts/release-rc-history.mjs text eol=lf
/config/scripts/run-internal-dev-setup.mjs text eol=lf
/config/scripts/verify-cli-bin.mjs text eol=lf
/config/scripts/verify-release-required-assets.mjs text eol=lf
# A shebang plus CRLF makes vite's SSR transform emit a literal `#!` mid-module,
# so any suite importing the script dies at load with a SyntaxError. Pin the whole
# directory rather than the scripts that happen to have a test today.
/config/scripts/**/*.mjs text eol=lf
/skill-guides/*.md text eol=lf
/skill-stubs/*.md text eol=lf
/skill-stubs/_shared/*.md text eol=lf
/skills/*/SKILL.md text eol=lf
/src/cli/bundled-skill-guides.ts text eol=lf
# Bundled plugin trees are byte-hashed; CRLF checkout would break the pinned hash.
/resources/plugins/** text eol=lf
# Relay assets are copied verbatim into the bundle and hashed byte-for-byte into
# .version, which names the immutable remote install dir. A CRLF checkout makes a
# Windows-built client disagree with a mac/Linux-built one on the same release,
# so one host ends up with two relay trees (#17886 review).
/config/relay-assets/** text eol=lf
# Pin the bytes so a patch reads and diffs identically on every host. It is NOT
# what makes the hash right: pnpm hashes a patch LF-normalized, so a CRLF checkout
# cannot change it. Believing otherwise put a hand-computed raw digest in the
# lockfile twice and broke every install (#17886).
# These files are stored LF, which is not always the encoding they were written
# against -- @vscode/windows-process-tree ships CRLF sources -- so any code that
# runs `git apply` on one must force `-c core.autocrlf=input` rather than trust
# the host's setting. See config/scripts/windows-process-tree-gyp-rebuild.mjs.
/config/patches/*.patch -text
# Same reason, and pnpm parses these too: a CRLF checkout makes the mobile
# patches unparseable, so Windows packaging dies on ERR_PNPM_INVALID_PATCH.
/mobile/patches/*.patch -text
# The xterm bundle hunks also make a diff nobody can read; review the hand-written
# source patch under xterm-src/ instead. The sibling patches stay diffable.
/config/patches/@xterm__xterm@*.patch -diff
/config/patches/xterm-src/*.patch text eol=lf
# pnpm parses these unified diffs during Windows installs; keep checkout bytes stable.
/mobile/patches/*.patch -text
# Generated wrapper fixtures: collapse them in the PR diff so they stop drowning
# the reviewable change, and pin LF because they are compared byte-for-byte.
# Not -diff: the shell diff is the review surface when a wrapper does change.
/src/main/__fixtures__/shell-wrapper-snapshots/*.txt linguist-generated=true text eol=lf
# Captured agent PTY transcripts. -text, not `text eol=lf` like the wrapper snapshots above:
# these carry real CR and CRLF bytes as the terminal emitted them, and line-ending
# normalisation on a Windows checkout would rewrite the evidence the fixture exists to be.
/src/main/runtime/__fixtures__/*.txt -text
/src/main/daemon/__fixtures__/pty-transcripts/*.txt -text
# Generated runtime English subset: compared byte-for-byte by
# verify:localization-runtime-catalog, so a CRLF checkout would fail the gate.
/src/renderer/src/i18n/en-runtime-required.json linguist-generated=true text eol=lf
# Generated method->params catalog: compared byte-for-byte by
# verify:rpc-params-catalog, so a CRLF checkout would fail the gate.
/src/shared/rpc-contract/rpc-params-catalog.generated.ts linguist-generated=true text eol=lf
# Mobile RPC recording goldens: replay requires the file text to equal what rpc:record writes
# (LF), so a CRLF checkout would fail every golden.
/mobile/rpc-foundation/goldens/*.json text eol=lf
# Mobile web page source. Every text byte here is hashed into an asset digest and from
# there into buildId, so a CRLF Windows checkout would ship a different bundle id for
# identical source (91af2897 vs 9d78435e, measured on the bundle this replaced).
/mobile/src/** text eol=lf
/mobile/app/** text eol=lf
/mobile/web-entry/** text eol=lf
# The blanket pin above would mark a future binary as text; exempt the asset types an
# RN page actually carries.
/mobile/src/**/*.png -text
/mobile/src/**/*.jpg -text
/mobile/src/**/*.jpeg -text
/mobile/src/**/*.gif -text
/mobile/src/**/*.ico -text
/mobile/src/**/*.webp -text
/mobile/src/**/*.ttf -text
/mobile/src/**/*.otf -text
/mobile/src/**/*.woff -text
/mobile/src/**/*.woff2 -text
/mobile/app/**/*.png -text
/mobile/app/**/*.jpg -text
/mobile/app/**/*.jpeg -text
/mobile/app/**/*.gif -text
/mobile/app/**/*.ico -text
/mobile/app/**/*.webp -text
/mobile/app/**/*.ttf -text
/mobile/app/**/*.otf -text
/mobile/app/**/*.woff -text
/mobile/app/**/*.woff2 -text
/mobile/web-entry/**/*.png -text
/mobile/web-entry/**/*.jpg -text
/mobile/web-entry/**/*.jpeg -text
/mobile/web-entry/**/*.gif -text
/mobile/web-entry/**/*.ico -text
/mobile/web-entry/**/*.webp -text
/mobile/web-entry/**/*.ttf -text
/mobile/web-entry/**/*.otf -text
/mobile/web-entry/**/*.woff -text
/mobile/web-entry/**/*.woff2 -text
10 changes: 10 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
# Product source remains owned by its normal reviewers; localization inputs need focused review.
/src/renderer/src/i18n/locales/ @brennanb2025
/config/scripts/*localization*.mjs @brennanb2025
/config/scripts/*locale*.mjs @brennanb2025
/config/i18next.config.ts @brennanb2025

# The relay's deploy and operate surface: workspace, workflows, and the rollout lease action.
/cloud/ @Jinwoo-H
/.github/workflows/cloud-*.yml @Jinwoo-H
/.github/actions/cloud-sql-rollout-lease/ @Jinwoo-H
21 changes: 12 additions & 9 deletions .github/CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,11 @@ pnpm install
pnpm dev
```

Ordinary installs include native optional dependencies for the current OS and CPU only.
Before a cross-architecture build (including `pnpm build:mac`, which produces both x64 and
arm64 artifacts by default), run `pnpm install:release` to add the other CPU's variants.
See [the install policy](../docs/reference/pnpm-install-policy.md).

## Branch Naming

Use a clear, descriptive branch name that reflects the change.
Expand Down Expand Up @@ -52,21 +57,20 @@ If your change affects UI or interaction behavior, verify it on the platforms it

Project-owned type declarations belong in `.ts` files. `.d.ts` is reserved for ambient shims (e.g., `env.d.ts`, `vite/client.d.ts`). TypeScript's `skipLibCheck: true` setting applies globally, including to our own `.d.ts` files, which means any unresolved type reference in a `.d.ts` silently becomes `any` at its call sites. Write your types in `.ts` files so the compiler actually checks them.

CI enforces this for `src/preload/` and `src/shared/` — see `docs/preload-typecheck-hole.md`.
CI enforces this for `src/preload/` and `src/shared/`.

## Pull Requests

Each pull request should:
Each pull request should follow [`.github/pull_request_template.md`](./pull_request_template.md). In particular:

- explain the user-visible change
- stay focused on a single topic when possible
- include screenshots or screen recordings for new UI or behavior changes
- if you are an outside contributor, link the issue your PR addresses
- open with an ELI5 of the change (plain language paragraph; the PR title is the one-liner)
- explain what changed and why, and stay focused on a single topic when possible
- for any UI or interaction change, attach **before and after** screenshots (or short videos); if there is no visual or interaction change, write `N/A` and briefly explain why
- include high-quality tests when behavior changes or bug fixes warrant them
- include a brief code review summary from your AI coding agent that explicitly checks cross-platform compatibility, SSH/remote/local compatibility, supported agent and integration compatibility, performance risk, UI quality when applicable, and basic security risk
- mention any platform-specific, remote/SSH-specific, agent-specific, integration-specific, or git-provider-specific behavior and testing notes
- **Include your X (Twitter) handle!** We love giving shoutouts to our contributors when we merge features on [@orca_build](https://x.com/orca_build).

If there is no visual change, say that explicitly in the PR description.
- **Include your X (Twitter) handle** in the PR template Author section — we shout out contributors when we merge features on [@orca_build](https://x.com/orca_build).

## Release Process

Expand Down Expand Up @@ -114,7 +118,6 @@ All stable kinds (`patch`, `minor`, `major`) are computed off the latest _stable

The scheduled 2x/day RC cron in [`release-rc.yml`](../../actions/workflows/release-rc.yml) is independent and continues to run automatically from `main`.


## Release Channels

The public Homebrew cask tracks stable desktop releases:
Expand Down
2 changes: 2 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,8 @@ body:
value: |
Use this form for Orca bugs. Include enough detail for someone else to reproduce the issue.

Please write your issue in English.

- type: dropdown
id: os
attributes:
Expand Down
2 changes: 2 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,8 @@ body:
value: |
Use this form for new features or workflow improvements.

Please write your issue in English.

- type: textarea
id: problem
attributes:
Expand Down
5 changes: 5 additions & 0 deletions .github/ISSUE_TEMPLATE/other.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,11 @@ name: Other
description: Report another Orca issue type
title: '[Other]: '
body:
- type: markdown
attributes:
value: |
Please write your issue in English.

- type: textarea
id: details
attributes:
Expand Down
152 changes: 152 additions & 0 deletions .github/actions/cloud-sql-rollout-lease/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,152 @@
# Cloud SQL rollout lease

A compare-and-swap lease on one Cloud Storage object, used to serialize Cloud SQL
**connection-budget** rollouts across two repositories.

`concurrency.group: production-cloud-sql-rollout` only serializes runs inside a single repository.
Once the relay workflows live in `stablyai/orca` and the app workflows stay in
`stablyai/orca-cloud`, there are two independent queues pointed at one shared Cloud SQL instance.
`relay-cloud-sql-connection-budget.mjs` computes `rolloutOverlap` as a `Math.max` over the relay
director, api, auth and relay-cell candidates, which is only sound when exactly one rollout is in
flight. This lease is what keeps that assumption true. Keep the per-repo concurrency groups **and**
the lease; they solve different halves of the problem.

## What it protects

No workflow runs a Cloud SQL schema migration. Every locked workflow either deploys a Cloud Run
revision or applies a GCE instance template against the shared instance, so the lease must cover
**all rollouts**, not just migrations.

## Usage

The lease step must run **after** `google-github-actions/setup-gcloud`, and after
`actions/checkout` — `uses: ./.github/actions/...` resolves against the checked-out workspace.
It belongs in the first job of the workflow that holds a GCP credential, which is not always the
gate job: `deploy-relay-production-same-cap`'s gate runs no `gcloud`, so its first acquire happens
in the first cell job.

```yaml
- uses: google-github-actions/auth@v2
with: { workload_identity_provider: ..., service_account: ... }
- uses: google-github-actions/setup-gcloud@v2
- uses: ./.github/actions/cloud-sql-rollout-lease
with:
bucket: onorca-cloud-terraform-state
object: terraform/state/cloud-sql-rollout/production.lock
```

Buckets and objects in use:

| Environment | Bucket | Object |
| ----------- | -------------------------------------- | --------------------------------------------------- |
| production | `onorca-cloud-terraform-state` | `terraform/state/cloud-sql-rollout/production.lock` |
| staging | `onorca-cloud-staging-terraform-state` | `terraform/state/cloud-sql-rollout/staging.lock` |

Workflows that serve both environments (`deploy-relay-asia-topology`,
`operate-relay-asia-admission`) select the pair with an `inputs.environment == 'production'`
ternary on both `bucket` and `object`. `deploy-staging` keeps its own `deploy-artifacts-staging`
concurrency group but takes the staging lease, because it rolls the staging API revision.

The object sits beside `terraform/state/relay-fence-broker/<env>.lock`. The IAM grant names both the
relay and app service accounts, so it is a **foundation-root** resource: `roles/storage.objectAdmin`
conditioned on the `terraform/state/cloud-sql-rollout/` prefix, **plus** an unconditioned
`roles/storage.legacyBucketReader`. Without the second role the generation-matched write fails in a
way that looks like a permissions flake.

## One lease per run, not per job

`deploy-relay-production-capacity` calls its reusable job six times and
`deploy-relay-production-same-cap` four times. Each call is a separate job on a separate runner, so
a naive per-job acquire/release would leave the object free between waves — for runs that have taken
up to 85 minutes.

The lease is therefore keyed to the **run**, not the job. `holder-key` defaults to
`${{ github.repository }}/${{ github.run_id }}`, and a job that finds its own holder key on a live
lease **re-enters** it: the record is refreshed, not rejected. Every job in the chain acquires; only
the last one releases.

```yaml
jobs:
gate:
steps:
- uses: ./.github/actions/cloud-sql-rollout-lease
with: { bucket: ..., object: ..., release: 'false' } # intermediate

wave-1: # ... release: 'false' on every wave job

release_lease:
needs: [gate, wave-1, wave-2, wave-3, wave-4]
if: always()
steps:
- uses: google-github-actions/auth@v2
- uses: google-github-actions/setup-gcloud@v2
- uses: ./.github/actions/cloud-sql-rollout-lease
with: { bucket: ..., object: ..., release: 'true' } # final
```

`release: 'false'` still acquires and still runs its `post` step; `post` only skips the delete. A
single-job workflow leaves `release` at its `true` default and needs no extra job. So does a
workflow whose several jobs can never hold the lease at once: `prove-relay-staging-capacity`'s two
lease-holding jobs are guarded by complementary `inputs.mode` conditions, and the contract test
checks that exclusivity rather than assuming it.

If the final job never runs (runner killed, run cancelled hard), the lease expires on its TTL.

## Timing

- **TTL 35 minutes**, matching `apps/relay-fence-broker/src/mutation-lease.ts`.
- **Renewal every 5 minutes.** `main` spawns a detached background Node process that rewrites
`expires_at` on the same generation-matched path; `post` kills it by pid read back from
`$GITHUB_STATE`. The renewer stops on its own the moment the object stops being ours, and has a
six-hour backstop in case `post` never runs. Its log is written to
`$RUNNER_TEMP/cloud-sql-rollout-lease-renewer.log` and echoed by `post`.
- Renewal is mandatory, not optional: capacity runs have taken 85 minutes, well past any sane TTL.

## Failure behaviour

| Situation | Behaviour |
| -------------------------------- | ----------------------------------------------------------------------------------------------------------------- |
| Object absent | Acquire with `ifGenerationMatch: 0`. |
| Live lease, our own holder key | Re-enter. Refresh `expires_at`, keep `acquired_at`. Never fails. |
| Live lease, another holder | **Fail the job immediately**, printing the holder's repository, workflow and run URL. Never queues, never steals. |
| Expired lease | Take over with the observed generation and emit `::warning::` naming the stale holder. |
| `412` on write | Someone raced us. Fail as a conflict. |
| Bucket unreachable, `403`, `5xx` | **Fail closed.** |
| Record present but unparseable | **Fail closed.** A record we cannot read is never treated as free; an operator must inspect and delete it. |
| Release finds a foreign holder | Warn and leave it alone. Our lease had already expired. |
| Release fails | Warn only. `post` never fails a job over a release; the TTL bounds the damage. |

## Why `monitor-relay-production` must not use this

`monitor-relay-production` is in the `production-cloud-sql-rollout` concurrency group but is
**read-only**: its identity holds only monitoring, logging, Cloud SQL and compute _viewer_ roles,
and it runs `gcloud sql instances describe`, never a mutation. It consumes no connection budget.
Putting it on the durable lease would let a monitoring run block a real rollout, and a rollout block
monitoring exactly when an operator most needs it. Keep its same-repo concurrency group; keep it off
the lease. The lock census contract test records it in the not-a-candidate map with this reason.

## Token acquisition

`gcloud auth print-access-token`, not a hand-rolled exchange of the `external_account` credentials
file. Every consuming workflow already runs `setup-gcloud`, gcloud already handles every ADC flavour
including the service-account impersonation leg, and this action must stay zero-dependency because
it is duplicated by hand into the public repo. The GCE metadata server that
`apps/relay-fence-broker/src/google-metadata.ts` uses does **not** exist on GitHub or Blacksmith
runners; only the compare-and-swap algorithm is shared with the fence broker.

## Duplication

This directory is copied verbatim into `stablyai/orca`. It has no `package.json`, no
`node_modules`, and imports nothing outside itself — `action-contract.test.mjs` enforces all three.
Cross-repo consumption via `uses: stablyai/orca/.github/actions/...@<sha>` was rejected: it would
put public-repo code inside private app deploys that hold a production credential, and neither
repository protects `main` today.

## Tests

```
node --test .github/actions/cloud-sql-rollout-lease/
```

`storage-lease.test.mjs` drives the real compare-and-swap path against an in-memory Cloud Storage
fake that enforces generations. No network.
Loading