Plain English, no code. Two bugs, two fixes, then one decision for you.
When you open a terminal on a remote machine, there are three things, not one.
Your network blips. The pane stays on screen. The program keeps running over there. Only the connection between them breaks.
So reconnecting is one job: match the notes back up to the programs. Both bugs below are that matching going wrong.
A real user report: 2 terminals became 19, then 20. Most were panes they never opened.
The cause is boring and completely fixable: the notes were filed under the program's name, not the pane's. One pane could collect unlimited notes, and nothing threw the old ones away.
Piling up is no longer something we prevent — there is one slot, so it cannot happen. That's the difference between a rule you enforce and a shape where the bug has nowhere to live.
The note is filed under a permanent serial number stamped on the pane when it's created — not under "which tab it's in". Tabs change: you can drag a pane into another tab any time. A serial number never does. File things under what doesn't move.
This is the worse one, because it's how you end up with two AI agents writing into the same conversation.
The other machine did find your program. Comparing is how it noticed the tab was different. But it answered "not found" — so a message meaning "it's alive and I'm being fussy" looked exactly like "it's gone."
Moving a pane between tabs is a normal thing you're allowed to do, so it must never make a terminal unreachable. That comparison is removed.
It was also failing at its real job anyway. It existed to catch a different problem — the remote machine reusing an old ID for a brand-new program, like an apartment number being handed to a new tenant. It never caught that. So we check the tenant instead of the apartment number: catches the real case, stops rejecting panes that merely moved.
A replacement terminal starts only on actual proof the old program is gone.
The second proof is the clever one. The helper on the remote machine keeps its list of running programs only in memory. So if that same helper — same process, not a restarted one — says a program isn't in its list, it must have exited. There is nowhere else it could be.
And if the helper restarted, it remembers nothing, so we say we don't know. We never treat a fresh helper's empty list as news that your programs died.
| Situation | Today | After |
|---|---|---|
| Network drops and comes back | Terminals multiply; the remote machine fills with junk | Your terminals come back. Nothing invented. |
| You drag a pane to a new tab | A second agent resumes onto the same conversation | Just works. |
| Orca genuinely can't tell if a program survived | Silently starts a new one | Pane says "disconnected", with two buttons |
| Leftover programs on a remote machine | Invisible, pile up forever | Listed with folder and name — you choose what to close |
Today, uncertainty gets resolved silently and wrongly. After this, uncertainty becomes visible — a disconnected pane with two buttons.
Slightly more friction in a rare case, in exchange for never resuming your agent twice. I think it's clearly right, but it changes what people see, so it's your call.
Six steps. Each ships on its own and can be undone on its own.
| Step | What it does | |
|---|---|---|
| 1 | Stop the tab comparison killing live terminals | Fixes the double-agent bug. Small, self-contained, helps immediately. |
| 2 | Stop faking "the program exited" | Today a failed reconnect tells the pane the program exited — a claim we can't back up. Ships with the two-button UI. |
| 3 | Write the notes in one place | They go to two different places today, which makes the cleanup silently do nothing. This is the actual cause of 2 → 19. |
| 4 | One piece of code writes the notes | Two paths write them and a third forgets to — which is why an existing safety check never runs during reconnect. |
| 5 | Check whether an old recovery path ever runs | Two reviewers believe it's unreachable. Measure before building on it. |
| 6 | The proof rule | Only if step 5 shows it's needed. |
| Pane | One terminal box on your screen. |
| Program | The shell or agent actually running — often on another machine. |
| Note | Orca's record that a pane goes with a program. Saved to disk, so it survives a restart. |
| Helper | The small program Orca installs on a remote machine to run terminals there. |
| Orphan | A program still running that no pane claims. We list them; we never close them for you. |
It removes roughly 900–1,250 lines and adds roughly 450–700. Most of what goes away exists only to patch up disagreements between notes filed different ways. Once there's one note per pane, that code has nothing left to do.
counsel-design.html — how this was reviewed and what it cost.
report.html — evidence for the work already written.
Click any diagram to zoom · scroll to scale · drag to pan.