diff --git a/config/reliability-gates.jsonc b/config/reliability-gates.jsonc index dafc1f8d251..521a789048a 100644 --- a/config/reliability-gates.jsonc +++ b/config/reliability-gates.jsonc @@ -168,6 +168,88 @@ ], "demotionRule": "Keep experimental until CI soak; investigate failures without relaxing fidelity, liveness or resource-count assertions." }, + { + "id": "terminal-performance.osc-status-scan-budget", + "title": "OSC 9999 status bursts reuse forward terminator searches", + "maturity": "experimental", + "protection": "partial", + "owner": "terminal-runtime", + "layer": "shared-unit-and-runtime-unit", + "surfaces": ["terminal output ingestion", "terminal agent-status side effects"], + "platforms": ["macos", "linux", "windows"], + "providers": ["local", "daemon", "ssh", "remote-runtime"], + "coveredPlatforms": ["macos"], + "coveredProviders": ["local", "daemon", "ssh", "remote-runtime"], + "coverageNotes": "Shared parser tests cover provider-independent bytes; main and renderer contract tests cover status and terminal-output delivery. Live Linux, Windows, WSL, SSH and remote-runtime processes are not launched. Execution, liveness, paths, wire formats and mobile UI are unchanged.", + "motivatingLinks": [ + "https://github.com/stablyai/orca/blob/main/src/shared/agent-status-osc.ts" + ], + "invariant": "Terminal status parsing preserves ordinary UTF-16 output, every valid payload in order, the last valid payload's clean-output offset, earliest BEL/ST termination, and incomplete-frame caps while searching each complete burst only forward.", + "oracle": "Two 5,000-frame bursts using exclusively BEL or ST produce every expected payload and ordinary output byte with at most twice the input length in native search ranges. Mixed terminators, every split through prefixes/JSON/ST, independent parser interleaving, malformed payloads, exact pending-cap boundaries and oversized complete frames retain their previous behavior. A one-character echo performs no terminator search. Parsed output chunks are not retained in legacy regular-expression state.", + "commands": [ + "ORCA_BACKGROUND_LAUNCH=1 pnpm test src/shared/agent-status-osc.test.ts src/shared/agent-status-osc-scan-budget.test.ts src/shared/agent-status-types.test.ts src/main/runtime/orca-runtime-hook-agent-status-projection.test.ts src/renderer/src/components/terminal-pane/terminal-title-tracker-parity.test.ts src/renderer/src/components/terminal-pane/pty-connection-main-side-effect-authority.test.ts src/renderer/src/components/terminal-pane/pty-connection-hook-completion-side-effects.test.ts src/renderer/src/components/terminal-pane/pty-transport-eager-buffer-replay.test.ts" + ], + "testFiles": [ + "src/shared/agent-status-osc.test.ts", + "src/shared/agent-status-osc-scan-budget.test.ts", + "src/main/runtime/orca-runtime-hook-agent-status-projection.test.ts", + "src/renderer/src/components/terminal-pane/terminal-title-tracker-parity.test.ts" + ], + "assertionRefs": [ + { + "file": "src/shared/agent-status-osc-scan-budget.test.ts", + "assertions": [ + "reads each burst only forward with terminator %j", + "keeps a one-character input echo on the ordinary-output path", + "does not retain the output chunk in legacy regular-expression state" + ] + }, + { + "file": "src/shared/agent-status-osc.test.ts", + "assertions": [ + "uses the earliest mixed terminator and counts only parsed payload offsets", + "keeps a distant ST usable after many intervening BEL frames", + "preserves every split of prefixes, JSON, and both terminators across independent streams", + "applies the pending cap only to incomplete frames" + ] + } + ], + "evidenceRuns": [ + { + "date": "2026-09-07", + "runner": "local", + "platform": "macos", + "command": "ORCA_BACKGROUND_LAUNCH=1 pnpm test src/shared/agent-status-osc.test.ts src/shared/agent-status-osc-scan-budget.test.ts src/shared/agent-status-types.test.ts src/main/runtime/orca-runtime-hook-agent-status-projection.test.ts src/renderer/src/components/terminal-pane/terminal-title-tracker-parity.test.ts src/renderer/src/components/terminal-pane/pty-connection-main-side-effect-authority.test.ts src/renderer/src/components/terminal-pane/pty-connection-hook-completion-side-effects.test.ts src/renderer/src/components/terminal-pane/pty-transport-eager-buffer-replay.test.ts", + "result": "passed", + "durationSeconds": 23.96, + "summary": "153 tests passed across eight files. Independent baseline differential review also matched 3,704 streams and 45,141 chunk results." + } + ], + "runtimeBudget": { + "p95Seconds": 30, + "scope": "Shared parser and main/renderer terminal contract tests; no launched app." + }, + "flakeHistory": { + "status": "not-started", + "evidence": "Initial deterministic local validation; CI soak has not started." + }, + "redGreenEvidence": { + "status": "complete", + "evidence": "The unchanged parser failed both search budgets: 618,560,785 searched characters for the 246,390-character BEL burst and 631,068,285 for the 251,390-character ST burst. Reusing forward match positions reduces those totals to 492,770 and 502,770 characters respectively, within twice the input length, with identical complete results." + }, + "performanceBudget": { + "required": true, + "evidence": "Warmed Node 24 macOS CPU medians: a 250 KB / 5,000-status burst fell from 100.240 ms to 1.903 ms; a 1 MB / 20,000-status burst fell from 1,588.492 ms to 7.369 ms. Wall-clock medians were 134.878 to 2.484 ms and 2,536.927 to 12.902 ms under concurrent machine load. These are adverse bursts, not typical callback sizes. The ordinary-output path is unchanged; one-character echo CPU was 2.173 versus 2.342 ms per 100,000 calls, and single-status BEL CPU was 10.835 versus 10.897 ms per 30,000 calls. Both native terminator searches advance monotonically within the current chunk; no regex state retains the input. No scheduling, polling, provider calls, pending limits, output filtering or payload parsing changed." + }, + "knownGaps": [ + "Live Electron input latency and Linux/Windows/WSL/SSH execution have not been measured for this parser-only change.", + "Fragmented unterminated payload accumulation and downstream processing of large status arrays remain outside this complete-burst search budget." + ], + "promotionCriteria": [ + "Complete CI soak while preserving byte fidelity and deterministic search budgets." + ], + "demotionRule": "Keep experimental until CI soak; investigate output, offset, carry or search-budget failures without relaxing the oracle." + }, { "id": "terminal-performance.padded-fullscreen-redraw", "title": "Fullscreen redraw padding does not stall terminal delivery", @@ -13743,6 +13825,7 @@ "invariant": "Starting a worker in the coordinator's current workspace must materialize one inactive terminal tab before worker-start returns, preserve coordinator focus, and remain exactly once after workspace re-entry. After an app update or restart, an exact live legacy worker must fence automatic provider resume, adopt its original PTY into its original background pane, retain readable output, and clear the resume record without spawning, writing, signalling, interrupting, replacing, or focusing the worker. A current-contract worker whose renderer graph identity is temporarily absent must retain its Dispatch capability and settle exactly once from exact hook-attested handle, pane, and process evidence; otherwise only an exact attested coordinator may take over. A worker_done caller may report success only after the owning runtime returns an explicit lifecycle verdict or authoritative reads prove that the exact Task, Dispatch, and worker report receipt settled the expected outcome. Federated terminal settlement must remain replay-eligible until the worker durably acknowledges it, and identical same-outcome retries must converge idempotently. Independently updated clients and worker servers must preserve the negotiated protocol: current peers use Run-home lifecycle settlement, while protocol v1/v2 peers retain their legacy completion path without receiving newer-only fields. A federated worker may accept only the authority defined by its negotiated protocol. An exact existing target workspace must receive a discoverable tab without stealing coordinator focus; if renderer reveal fails, worker-start must expose that the live worker remains background-only. Run and Dispatch checks must resolve through the caller's stable pane identity when a terminal handle is reminted, while a live handle outranks mismatched pane metadata. A nested worker's creator edge requires the current creator pane, process incarnation, and owning Run generation; reminting and rebinding that pane to another Run must remove the stale edge. Explicit legacy terminal inspection remains handle-scoped, and remote or headless worker presentation remains background-only.", "oracle": "Drive Run create, Task create, and worker-start through production Electron runtimes with a deterministic Codex fixture. Require append-only ledgers with one still-live PID and no interruption, a visible inactive worker tab while the coordinator stays active, Run delivery through stable pane identity, and stable PTY/incarnation, tab, leaf, worktree, Task, and Dispatch across workspace re-entry. In a restart journey, retain the original daemon PTY and PID, remove renderer ownership, retain sleeping-session evidence, mark the Dispatch legacy, relaunch, and require exact inactive tab adoption, readable ACK output, cleared resume state, one spawn, and no resume argv or Conversation interrupted text after another workspace round trip. The service oracle removes renderer lookup identity from current-contract callers while retaining real restored-PTY and hook commitments, replays authenticated completion and takeover across fresh runtimes, and requires one Task, Dispatch, terminal authority, message, mutation, ordinary-mail delivery, remote process fencing, and unchanged fixture marker bytes while foreign pane evidence remains rejected. Unit tests separately remint a creator pane and process from Run A into Run B, require the nested Run A worker to fall back to its current coordinator, require indexed query plans, and bound 300 Task reads with 50,000 retained Runs. They also assert authority-specific legacy affordances, exact identity and owner matching, retained-output fallback, pane-stable routing, federated non-activation, and SSH fallback parity.", "commands": [ + "ORCA_BACKGROUND_LAUNCH=1 npx vitest run --config config/vitest.config.ts src/main/runtime/rpc/methods/orchestration/messaging/check-worker-federated-attachment.test.ts", "pnpm exec vitest run --config config/vitest.config.ts src/main/runtime/rpc/orchestration-runtime-update-settlement.test.ts --reporter=dot", "pnpm exec vitest run --config config/vitest.config.ts src/cli/handlers/orchestration.test.ts src/cli/handlers/orchestration-check-identity.test.ts src/cli/handlers/orchestration-worker-cli.test.ts src/main/runtime/rpc/methods/orchestration/worker/composed-workers.test.ts src/main/runtime/rpc/methods/orchestration/messaging/check.test.ts src/main/runtime/rpc/methods/orchestration/messaging/send.test.ts src/main/ssh/ssh-remote-orca-cli.test.ts", "pnpm exec vitest run --config config/vitest.config.ts src/cli/handlers/orchestration-lifecycle-rejection.test.ts src/cli/handlers/orchestration-lifecycle-json-rejection.test.ts src/cli/handlers/orchestration-migration.test.ts", @@ -13757,6 +13840,7 @@ "pnpm run build:cli && SKIP_BUILD=1 pnpm exec playwright test tests/e2e/orchestration-worker-settlement-release-cli.spec.ts --config tests/playwright.config.ts --project electron-headless --workers=1" ], "testFiles": [ + "src/main/runtime/rpc/methods/orchestration/messaging/check-worker-federated-attachment.test.ts", "src/main/runtime/rpc/orchestration-runtime-update-settlement.test.ts", "src/main/runtime/orchestration/formatter.test.ts", "src/main/runtime/orchestration/orchestration-legacy-worker-terminal-recovery.test.ts", @@ -13780,6 +13864,13 @@ "tests/e2e/orchestration-worker-settlement-release-cli.spec.ts" ], "assertionRefs": [ + { + "file": "src/main/runtime/rpc/methods/orchestration/messaging/check-worker-federated-attachment.test.ts", + "assertions": [ + "replays the coordinator instruction and takes its ack after the app restarts", + "files loopback mail once under the local Dispatch Run without replacing its owner" + ] + }, { "file": "src/main/runtime/rpc/orchestration-runtime-update-settlement.test.ts", "assertions": [ @@ -14278,7 +14369,7 @@ "providers": ["local", "daemon", "ssh", "wsl", "remote-runtime"], "coveredPlatforms": ["macos"], "coveredProviders": ["local", "ssh"], - "coverageNotes": "Deterministic service tests cover release-versus-reuse ordering, transactional retain and takeover cancellation, exact host/pane/process identity, dead external/user-owned/transferred/stopped/abandoned reconciliation, host-partition persistence and legacy retirement replay with an absent web-terminal layout map, conservative unknown provider and legacy metadata handling, immutable transcript and bounded terminal archives, mutation restart, reset cleanup, replay idempotency, and 50-resource accounting. A macOS Electron journey invokes the freshly compiled worker-release CLI after the worker process disappears, then independently checks released SQLite state and coordinator liveness. Injected inventories cover local and SSH provider routing; live SSH, WSL, Windows, paired-runtime, and provider-close lost-ack journeys remain explicit gaps.", + "coverageNotes": "New phones explicitly report terminal takeover on real user sends, throttled per owning client and handle. Host byte lanes perform zero orchestration SQL work; local and injected SSH report tests fence release. Phones predating this build do not fence release. Deterministic service tests cover release-versus-reuse ordering, transactional retain and takeover cancellation, exact host/pane/process identity, dead external/user-owned/transferred/stopped/abandoned reconciliation, host-partition persistence and legacy retirement replay with an absent web-terminal layout map, conservative unknown provider and legacy metadata handling, immutable transcript and bounded terminal archives, mutation restart, reset cleanup, replay idempotency, and 50-resource accounting. A macOS Electron journey invokes the freshly compiled worker-release CLI after the worker process disappears, then independently checks released SQLite state and coordinator liveness. Injected inventories cover local and SSH provider routing; live SSH, WSL, Windows, paired-runtime, and provider-close lost-ack journeys remain explicit gaps.", "motivatingLinks": [ "https://github.com/stablyai/orca/pull/12355", "https://github.com/stablyai/orca/issues/13860", @@ -14289,6 +14380,8 @@ "invariant": "A settled Dispatch may close only its one coordinator-created terminal lease. Explicit reuse, real user input, retain, identity or host change, ambiguity, and another resource for the same exact host/pane/process must fence closure. Once the authoritative owning provider positively excludes the resource's exact immutable process incarnation, even an external, user-owned, or transferred dead resource must converge to released without any process close. Unknown host scope, missing incarnation metadata, or unavailable inventory must remain retained. Exact terminal-close persistence must settle when a host partition omits renderer-owned layout state. Output preservation and the requested-to-releasing transition are atomic, archives remain readable without the provider file, retries resume idempotently, and orchestration reset removes archive and authority state.", "oracle": "Record release intent for a settled owner, attempt exact reuse before close, and require worker-start to fail with terminal_release_in_progress while the terminal stays open; then release the original owner exactly once. Race retain and real user input against a controlled archive promise and require no committed archive or close. Rebase a closed web-terminal host partition without terminalLayoutsByTabId and require the persistence write to complete while preserving host-authoritative membership; replay a valid legacy retirement under the same omission and require exact membership removal plus revision advancement. For retained external, user-owned, transferred, stopped, and abandoned resources, run one fresh inventory against the exact local/WSL or SSH provider: an exact live incarnation and every unknown inventory shape stay retained, while positive absence atomically sets ownership_state and release_state to released with processAction none and zero closeTerminal calls. Change host or process identity and inject duplicate resource evidence to require retention. Freeze a structured transcript, delete its source file, and require archived worker-read to return the same bounded redacted messages. Restart a pending mutation, reset orchestration state, and create 50 resources while asserting replay convergence, zero orphan rows, two-query worker listing, and no unrelated close.", "commands": [ + "ORCA_BACKGROUND_LAUNCH=1 pnpm exec vitest run --config config/vitest.config.ts src/main/runtime/rpc/methods/orchestration/worker/worker-release-mobile-report.test.ts src/main/runtime/orca-runtime-terminal-handle-incarnation.test.ts src/renderer/src/lib/worker-terminal-takeover-report.test.ts", + "ORCA_BACKGROUND_LAUNCH=1 mobile/node_modules/.bin/vitest run --config mobile/vitest.config.ts mobile/src/session/mobile-worker-takeover-send-sites.test.ts mobile/src/terminal/worker-terminal-takeover-report.test.ts", "pnpm exec vitest run --config config/vitest.config.ts src/main/runtime/pty-inventory-liveness-verdict.test.ts src/main/runtime/orca-runtime-process-incarnation-liveness.test.ts src/main/runtime/mobile-session-terminal-persistence-retirement.test.ts src/main/runtime/rpc/methods/orchestration/worker/worker-release.test.ts src/main/runtime/rpc/methods/orchestration/worker/worker-release-recovery.test.ts src/main/runtime/rpc/orchestration-mutation-ledger.test.ts src/main/runtime/orchestration/worker-transcript-read.test.ts src/renderer/src/lib/worker-terminal-takeover-report.test.ts --reporter=dot", "pnpm exec vitest run --config config/vitest.config.ts src/main/runtime/orca-runtime-process-incarnation-liveness.test.ts src/main/runtime/mobile-session-terminal-persistence-retirement.test.ts src/main/runtime/rpc/methods/orchestration/worker/worker-release.test.ts src/main/runtime/rpc/methods/orchestration/worker/worker-release-recovery.test.ts src/main/runtime/rpc/orchestration-mutation-ledger.test.ts src/main/runtime/orchestration/worker-transcript-read.test.ts src/renderer/src/lib/worker-terminal-takeover-report.test.ts --reporter=dot", "pnpm exec vitest run --config config/vitest.config.ts src/main/runtime/orca-runtime-process-incarnation-liveness.test.ts src/main/runtime/rpc/methods/orchestration/worker/worker-release.test.ts src/main/runtime/rpc/methods/orchestration/worker/worker-release-recovery.test.ts src/main/runtime/rpc/orchestration-mutation-ledger.test.ts src/main/runtime/orchestration/worker-transcript-read.test.ts src/renderer/src/lib/worker-terminal-takeover-report.test.ts --reporter=dot", @@ -14297,6 +14390,9 @@ "pnpm run build:cli && SKIP_BUILD=1 pnpm exec playwright test tests/e2e/orchestration-worker-settlement-release-cli.spec.ts --config tests/playwright.config.ts --project electron-headless --workers=1" ], "testFiles": [ + "src/main/runtime/rpc/methods/orchestration/worker/worker-release-mobile-report.test.ts", + "mobile/src/session/mobile-worker-takeover-send-sites.test.ts", + "mobile/src/terminal/worker-terminal-takeover-report.test.ts", "src/main/runtime/pty-inventory-liveness-verdict.test.ts", "src/main/runtime/orca-runtime-process-incarnation-liveness.test.ts", "src/main/runtime/mobile-session-terminal-persistence-retirement.test.ts", @@ -14309,6 +14405,20 @@ "tests/e2e/orchestration-worker-settlement-release-cli.spec.ts" ], "assertionRefs": [ + { + "file": "src/main/runtime/rpc/methods/orchestration/worker/worker-release-mobile-report.test.ts", + "assertions": [ + "a handle-addressed phone report fences %s worker release", + "mobile %s bytes do no orchestration database work" + ] + }, + { + "file": "mobile/src/session/mobile-worker-takeover-send-sites.test.ts", + "assertions": [ + "%s reports on its send target once per handle per 30 seconds", + "%s never reports takeover" + ] + }, { "file": "src/main/runtime/pty-inventory-liveness-verdict.test.ts", "assertions": [ diff --git a/config/scripts/orchestration-skill-guidance.test.mjs b/config/scripts/orchestration-skill-guidance.test.mjs index ce501954322..c15e3e93ea8 100644 --- a/config/scripts/orchestration-skill-guidance.test.mjs +++ b/config/scripts/orchestration-skill-guidance.test.mjs @@ -168,9 +168,10 @@ describe('orchestration kernel', () => { expect(kernel).toContain( '`projection.attention` categories, `projection.attention.requiresAction`, and literal `projection.nextAction` argv' ) - expect(kernel).toContain( - 'An `inspect` `nextAction` on a `live` row with `attention.requiresAction` false is informational, not a command to re-run: keep waiting with `check --wait`' - ) + // Unverifiable workers can still owe release; the guide must explain the action itself. + expect(kernel).toContain('A `none` `nextAction` has no argv to run') + expect(kernel).toContain('read `liveness.reason` and keep waiting with `check --wait`') + expect(kernel).toContain('Absence never earns an argv; settlement and pending work still do') expect(kernel).toContain('choose `worker-stop` or `worker-abandon`') }) diff --git a/config/ts-nocheck-baseline.txt b/config/ts-nocheck-baseline.txt index b770b06f827..e897af7387c 100644 --- a/config/ts-nocheck-baseline.txt +++ b/config/ts-nocheck-baseline.txt @@ -34,7 +34,7 @@ src/main/runtime/orca-runtime-create-terminal-side-effect-command-code-detector. src/main/runtime/orca-runtime-create-terminal.ts src/main/runtime/orca-runtime-deliver-pending-messages.ts src/main/runtime/orca-runtime-emit-daemon-pty-transient-fact.ts -src/main/runtime/orca-runtime-fence-automation-owner.ts +src/main/runtime/orca-runtime-automation-operations.ts src/main/runtime/orca-runtime-file-commands.ts src/main/runtime/orca-runtime-fit-override-listeners.ts src/main/runtime/orca-runtime-focus-terminal.ts diff --git a/docs/assets/readme-downloads.svg b/docs/assets/readme-downloads.svg index ebee3673b77..724be685ea7 100644 --- a/docs/assets/readme-downloads.svg +++ b/docs/assets/readme-downloads.svg @@ -1,5 +1,5 @@ - - downloads: 42m + + downloads: 44m @@ -15,7 +15,7 @@ downloads downloads - 42m - 42m + 44m + 44m diff --git a/mobile/src/session/mobile-native-chat-permission-send.test.ts b/mobile/src/session/mobile-native-chat-permission-send.test.ts index f74289d97ab..1525f090029 100644 --- a/mobile/src/session/mobile-native-chat-permission-send.test.ts +++ b/mobile/src/session/mobile-native-chat-permission-send.test.ts @@ -1,3 +1,8 @@ +// Takeover RPCs have their own send-site integration tests; these fixtures script PTY acknowledgements. +vi.mock('../terminal/worker-terminal-takeover-report', () => ({ + reportWorkerTerminalUserInput: vi.fn() +})) + import { createElement } from 'react' import { act, create, type ReactTestRenderer } from 'react-test-renderer' import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest' diff --git a/mobile/src/session/mobile-native-chat-send.test.ts b/mobile/src/session/mobile-native-chat-send.test.ts index a3b3c1e720e..c13841f7f77 100644 --- a/mobile/src/session/mobile-native-chat-send.test.ts +++ b/mobile/src/session/mobile-native-chat-send.test.ts @@ -309,10 +309,13 @@ describe('typeMobileNativeChatCommandWithOutcome', () => { await expect(result).resolves.toBe('accepted') expect( - vi.mocked(client.sendRequest).mock.calls.map((call) => { - const params = call[1] as { text: string; enter: boolean } - return { text: params.text, enter: params.enter } - }) + vi + .mocked(client.sendRequest) + .mock.calls.filter(([method]) => method === 'terminal.send') + .map((call) => { + const params = call[1] as { text: string; enter: boolean } + return { text: params.text, enter: params.enter } + }) ).toEqual( ['\x15', '/', 'm', 'o', 'd', 'e', 'l', '\r'].map((text) => ({ text, @@ -338,7 +341,12 @@ describe('typeMobileNativeChatCommandWithOutcome', () => { await vi.runAllTimersAsync() await result - const params = vi.mocked(client.sendRequest).mock.calls.map((call) => call[1]) as Array<{ + // Why the filter: an accepted send also fires the unawaited takeover report, which is not a + // terminal.send and carries no draft. + const params = vi + .mocked(client.sendRequest) + .mock.calls.filter((call) => call[0] === 'terminal.send') + .map((call) => call[1]) as Array<{ text: string resolvedLaunchDraft?: { text: string; createdAt: number } }> diff --git a/mobile/src/session/mobile-native-chat-send.ts b/mobile/src/session/mobile-native-chat-send.ts index 16f4aac2d3e..22c44f3eb84 100644 --- a/mobile/src/session/mobile-native-chat-send.ts +++ b/mobile/src/session/mobile-native-chat-send.ts @@ -1,3 +1,4 @@ +import { reportWorkerTerminalUserInput } from '../terminal/worker-terminal-takeover-report' import type { RpcClient } from '../transport/rpc-client' import { isRpcDeliveryUnknown } from '../transport/rpc-delivery-ambiguity' import { isLogicalClientCutoverError } from '../transport/stable-logical-rpc-client' @@ -64,7 +65,11 @@ export async function sendMobileNativeChatMessageWithOutcome( // pins the composer for twice as long. { timeoutMs, budgetSpansConnect: true } ) - return isTerminalSendRpcAccepted(response) ? 'accepted' : 'rejected' + if (!isTerminalSendRpcAccepted(response)) { + return 'rejected' + } + reportWorkerTerminalUserInput(args.client, args.terminal) + return 'accepted' } catch (error) { // Why: a logical relay↔direct cutover rejects the in-flight send without // knowing whether its frame reached the wire (the desktop may have delivered diff --git a/mobile/src/session/mobile-session-route-parity.test.ts b/mobile/src/session/mobile-session-route-parity.test.ts index bc951bfa206..3a6b04661de 100644 --- a/mobile/src/session/mobile-session-route-parity.test.ts +++ b/mobile/src/session/mobile-session-route-parity.test.ts @@ -66,11 +66,11 @@ const HEAD_MAIN_HOOK_SHA256 = '10071240ef9edafc2b9c8bed73be83dceaf7828e3b29f17da const HEAD_HOOK_BINDING_SHA256 = '1dadb8c3dc0573ea20659ce7251629669e618dd0effaeac3a4536b29c2e865a1' const HEAD_CALLBACK_IDENTITY_SHA256 = '2a9e4825df007f6ef53b81aa5004991d6318eee7507b44d625c07e630be432eb' -const HEAD_CALLBACK_BODY_SHA256 = '22103ba85a86e3a3fcb80a7509c7a455d79863010cde3af02db6565b55e3ebe9' +const HEAD_CALLBACK_BODY_SHA256 = 'af7f3c62954250d4be7ee432ecd10dc2689792aad8230fed2d1d68bbc892d776' const HEAD_EFFECT_SHA256 = 'd9ebfaabc1e79773cdada7ab370b20459ed972f1f8edce1652199f4d0391cd13' const HEAD_CONTENT_HOOK_SHA256 = '9c3b612fef3f370d66873aefdbe1d701f20cb64ded31fef5cc45fde6f8189581' const HEAD_NESTED_FUNCTION_SHA256 = - '536c72b233c813bb0cea164b090bdce5406ceb965bbc5b83c1f89b89b46f3821' + 'fde6679349ab2b8c30c7e627841ff99bd1dd24441ee95323d0aa70230422ae24' const HEAD_NATIVE_REGISTRATION_SHA256 = 'cab85e4e4a3f43289ba93ddea9ccce57aea83e0bf14fd1620a965aad0c1cb49e' const HEAD_NATIVE_REMOVAL_SHA256 = diff --git a/mobile/src/session/mobile-worker-takeover-send-sites.test.ts b/mobile/src/session/mobile-worker-takeover-send-sites.test.ts new file mode 100644 index 00000000000..2700d8d24fe --- /dev/null +++ b/mobile/src/session/mobile-worker-takeover-send-sites.test.ts @@ -0,0 +1,267 @@ +import { createElement } from 'react' +import { act, create, type ReactTestRenderer } from 'react-test-renderer' +import { beforeEach, afterEach, expect, it, vi } from 'vitest' +import type { RpcClient } from '../transport/rpc-client' +import { resetWorkerTerminalTakeoverReportsForTest } from '../terminal/worker-terminal-takeover-report' +import { useMobileSessionTerminalSendActions } from './use-mobile-session-terminal-send-actions' +import { useMobileSessionTerminalInput } from './use-mobile-session-terminal-input' +import { useMobileTerminalPaste } from './use-mobile-terminal-paste' +import { useTerminalLiveInputCommit } from '../terminal/use-terminal-live-input-commit' +import { routeDictationTranscript } from '../terminal/terminal-live-dictation-routing' +import { + sendMobileNativeChatMessageWithOutcome, + clearMobileNativeChatInput +} from './mobile-native-chat-send' +import { sendMobileTerminalQueryReply } from '../terminal/mobile-terminal-query-reply' +import { createTerminalAndSendPrompt } from './pr-ai-triage-launch' +import { useMobileDiffReviewSendActions } from './use-mobile-diff-review-send-actions' +import { pasteMobileNativeChatImagePaths } from './mobile-native-chat-image-send' + +vi.mock('react-native', () => ({ Keyboard: { dismiss: vi.fn() } })) +vi.mock('../platform/haptics', () => ({ triggerError: vi.fn(), triggerSuccess: vi.fn() })) +vi.mock('expo-clipboard', () => ({ getStringAsync: async () => 'pasted text' })) +vi.mock('expo-file-system', () => ({ File: class {}, Paths: { cache: '/tmp' } })) +vi.mock('expo-image-manipulator', () => ({ ImageManipulator: {}, SaveFormat: {} })) + +const REPORT = 'orchestration.workerTerminalUserInput' +const ref = (current: T) => ({ current }) +const renderers: ReactTestRenderer[] = [] +function clientFixture() { + return { + sendRequest: vi.fn(async (method: string) => ({ + id: 'rpc', + ok: true as const, + result: + method === 'session.tabs.createTerminal' + ? { tab: { type: 'terminal', id: 'tab', terminal: 'term-1', title: 'test' } } + : method === REPORT + ? { changed: 1 } + : { send: { accepted: true } } + })) + } +} + +function mountSendSites(client: ReturnType, handle = 'term-1') { + const activeHandleRef = ref(handle) + const activeSessionTabTypeRef = ref('terminal') + const sendLiveTerminalInputRef = ref(async (_handle: string, _text: string) => false) + const scope = { + client, + clientRef: ref(client), + activeHandle: handle, + activeHandleRef, + activeSessionTabTypeRef, + connState: 'connected', + connStateRef: ref('connected'), + activeSessionTab: { type: 'terminal', terminal: handle }, + sendingRef: ref(false), + canSend: true, + deviceTokenRef: ref('phone'), + liveInputRef: ref(null), + commandInputRef: ref(null), + liveInputFocusTimerRef: ref(null), + sendLiveTerminalInputRef, + getSendCompletionGeneration: () => 0, + showToast: vi.fn(), + ptyModesRef: ref(new Map([[handle, { altScreen: true }]])), + terminalGestureInputBucketsRef: ref(new Map()), + terminalGestureInputQueuesRef: ref(new Map()), + terminalGestureInputInFlightRef: ref(new Set()), + bufferedTerminalDraftState: { + input: 'command', + beginBufferedTerminalDraftSend: vi.fn(), + restoreRejectedDraft: vi.fn(), + settleBufferedTerminalDraftSend: () => true + } + } + let actions!: ReturnType + let live!: ReturnType + let gestures!: ReturnType + let paste!: ReturnType + let diff!: ReturnType + function Harness() { + live = useTerminalLiveInputCommit({ + activeHandle: handle, + activeHandleRef, + activeSessionTabType: 'terminal', + activeSessionTabTypeRef, + connected: true, + liveInputRef: ref(null), + liveInputTerminalHandles: new Set([handle]), + liveInputTerminalHandlesRef: ref(new Set([handle])), + sendLiveTerminalInputRef, + setLiveInputCapture: vi.fn() + }) + actions = useMobileSessionTerminalSendActions({ + ...scope, + handleLiveInputAccessoryBytes: live.handleLiveInputAccessoryBytes + } as never) + gestures = useMobileSessionTerminalInput(scope as never) + paste = useMobileTerminalPaste({ + ...scope, + flushPendingLiveInputBeforeExternalSend: live.flushPendingLiveInputBeforeExternalSend, + getActiveWorktreeConnectionId: async () => null, + onError: vi.fn(), + onSuccess: vi.fn(), + refreshCanPaste: vi.fn() + } as never) + diff = useMobileDiffReviewSendActions({ + client: client as unknown as RpcClient, + connState: 'connected', + worktreeId: 'workspace', + screenState: { kind: 'loading' }, + setActionError: vi.fn(), + setSendSheet: vi.fn(), + saveCommentsAndReviewState: vi.fn() + } as never) + return null + } + act(() => { + renderers.push(create(createElement(Harness))) + }) + let text = '' + return { + 'live field': async () => { + text += 'x' + live.handleLiveInputChange({ nativeEvent: { text, isComposing: false } }) + await live.flushPendingLiveInputBeforeExternalSend(handle) + }, + 'live submit': () => live.handleLiveInputSubmit(), + 'live accessory': async () => { + live.handleLiveInputChange({ nativeEvent: { text: 'composing', isComposing: true } }) + await live.handleLiveInputAccessoryBytes({ bytes: '\x1b[A' }) + }, + 'raw accessory': () => actions.handleAccessoryKey({ bytes: '\x1b[A' } as never), + 'buffered submit': () => actions.handleSend(), + 'gesture arrows': async () => { + await gestures.handleTerminalInput(handle, '\x1b[A') + await gestures.flushTerminalGestureInput(handle) + }, + paste: () => paste(), + dictation: async () => { + const route = routeDictationTranscript('dictated text', true) + expect(route.kind).toBe('live-insert') + await actions.sendLiveTerminalInput(handle, route.text) + }, + 'native chat': () => + sendMobileNativeChatMessageWithOutcome({ + client: client as unknown as RpcClient, + terminal: handle, + text: 'hello' + }), + 'query reply': () => + sendMobileTerminalQueryReply({ + bytes: '\x1b[0n', + client, + clientId: 'phone', + connected: true, + handle, + hostSupportsQueryReplyInput: true, + subscribedTerminals: new Set([handle]) + }), + 'image heal': () => + clearMobileNativeChatInput({ + client: client as unknown as RpcClient, + terminal: handle, + clearInput: '\x15' + }), + 'image attachment': () => + pasteMobileNativeChatImagePaths({ + client, + terminal: handle, + deviceToken: 'phone', + imagePaths: ['/tmp/picture.png'], + followedByText: true + }), + 'PR triage': () => createTerminalAndSendPrompt(client, 'workspace', 'fix checks'), + 'diff review': () => diff.sendPromptToTerminal(handle, []), + programmatic: () => client.sendRequest('terminal.send') + } +} + +beforeEach(() => { + vi.useFakeTimers() + vi.setSystemTime(1_000) + resetWorkerTerminalTakeoverReportsForTest() +}) +afterEach(() => { + act(() => { + for (const renderer of renderers.splice(0)) { + renderer.unmount() + } + }) + vi.useRealTimers() +}) + +const realSites = [ + 'live field', + 'live submit', + 'live accessory', + 'raw accessory', + 'buffered submit', + 'gesture arrows', + 'paste', + 'dictation', + 'native chat' +] as const +it.each(realSites)('%s reports on its send target once per handle per 30 seconds', async (site) => { + const client = clientFixture() + const sites = mountSendSites(client) + const invoke = async () => { + await act(async () => { + await sites[site]() + }) + } + const reports = () => client.sendRequest.mock.calls.filter(([method]) => method === REPORT) + await invoke() + await invoke() + expect( + client.sendRequest.mock.calls.filter(([method]) => method === 'terminal.send').length + ).toBeGreaterThanOrEqual(2) + expect(reports()).toHaveLength(1) + expect(reports()[0]).toEqual([REPORT, { terminal: 'term-1' }, expect.any(Object)]) + await vi.advanceTimersByTimeAsync(29_999) + await invoke() + expect(reports()).toHaveLength(1) + await vi.advanceTimersByTimeAsync(1) + await invoke() + expect(reports()).toHaveLength(2) + const other = mountSendSites(client, 'term-2') + await act(async () => { + await other[site]() + }) + expect(reports()).toHaveLength(3) + expect(reports()[2][1]).toEqual({ terminal: 'term-2' }) +}) + +it.each([ + 'query reply', + 'image heal', + 'image attachment', + 'PR triage', + 'diff review', + 'programmatic' +] as const)('%s never reports takeover', async (site) => { + const client = clientFixture() + const sites = mountSendSites(client) + await act(async () => { + await sites[site]() + await sites[site]() + }) + expect(client.sendRequest.mock.calls.some(([method]) => method === 'terminal.send')).toBe(true) + expect(client.sendRequest.mock.calls.filter(([method]) => method === REPORT)).toHaveLength(0) +}) + +it.each(realSites)('%s does not report a rejected send', async (site) => { + const client = clientFixture() + client.sendRequest.mockResolvedValue({ + id: 'rpc', + ok: true, + result: { send: { accepted: false } } + }) + const sites = mountSendSites(client) + await act(async () => { + await sites[site]() + }) + expect(client.sendRequest.mock.calls.filter(([method]) => method === REPORT)).toHaveLength(0) +}) diff --git a/mobile/src/session/use-mobile-native-chat-answer-send.test.ts b/mobile/src/session/use-mobile-native-chat-answer-send.test.ts index 82db799deed..cfb35417e9f 100644 --- a/mobile/src/session/use-mobile-native-chat-answer-send.test.ts +++ b/mobile/src/session/use-mobile-native-chat-answer-send.test.ts @@ -1,3 +1,8 @@ +// Takeover RPCs have their own send-site integration tests; these fixtures script PTY acknowledgements. +vi.mock('../terminal/worker-terminal-takeover-report', () => ({ + reportWorkerTerminalUserInput: vi.fn() +})) + import { createElement } from 'react' import { act, create, type ReactTestRenderer } from 'react-test-renderer' import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest' diff --git a/mobile/src/session/use-mobile-native-chat-stop.test.ts b/mobile/src/session/use-mobile-native-chat-stop.test.ts index bdc405cb57d..a1ee9ab4dd9 100644 --- a/mobile/src/session/use-mobile-native-chat-stop.test.ts +++ b/mobile/src/session/use-mobile-native-chat-stop.test.ts @@ -6,6 +6,12 @@ import { markRpcDeliveryUnknown } from '../transport/rpc-delivery-ambiguity' import { MOBILE_NATIVE_CHAT_SEND_TIMEOUT_MS } from './mobile-native-chat-send' import { useMobileNativeChatStop } from './use-mobile-native-chat-stop' +// Why mocked: the reporter is tested on its own; here Stop's escapes must be counted alone. +const reportWorkerTerminalUserInput = vi.fn() +vi.mock('../terminal/worker-terminal-takeover-report', () => ({ + reportWorkerTerminalUserInput: (...args: unknown[]) => reportWorkerTerminalUserInput(...args) +})) + describe('useMobileNativeChatStop', () => { let renderer: ReactTestRenderer | null = null let stop: (() => void) | null = null @@ -19,6 +25,7 @@ describe('useMobileNativeChatStop', () => { result: { send: { accepted: true } } }) onSendError.mockReset() + reportWorkerTerminalUserInput.mockReset() }) afterEach(() => { @@ -184,4 +191,26 @@ describe('useMobileNativeChatStop', () => { expect(onSendError).not.toHaveBeenCalled() }) + + it('reports the takeover once an Escape is accepted', async () => { + await render(true, 'stream-1') + + act(() => stop?.()) + await act(async () => vi.runAllTimersAsync()) + + expect(reportWorkerTerminalUserInput).toHaveBeenCalledWith( + expect.objectContaining({ sendRequest }), + 'terminal-1' + ) + }) + + it('does not report a Stop the host rejected', async () => { + sendRequest.mockResolvedValue({ ok: true, result: { send: { accepted: false } } }) + await render(true, 'stream-1') + + act(() => stop?.()) + await act(async () => vi.runAllTimersAsync()) + + expect(reportWorkerTerminalUserInput).not.toHaveBeenCalled() + }) }) diff --git a/mobile/src/session/use-mobile-native-chat-stop.ts b/mobile/src/session/use-mobile-native-chat-stop.ts index 871d221abb2..69d2d8e73e8 100644 --- a/mobile/src/session/use-mobile-native-chat-stop.ts +++ b/mobile/src/session/use-mobile-native-chat-stop.ts @@ -3,6 +3,7 @@ import type { RpcClient } from '../transport/rpc-client' import { isRpcDeliveryUnknown } from '../transport/rpc-delivery-ambiguity' import { isLogicalClientCutoverError } from '../transport/stable-logical-rpc-client' import { isTerminalSendRpcAccepted } from '../terminal/terminal-send-rpc-response' +import { reportWorkerTerminalUserInput } from '../terminal/worker-terminal-takeover-report' import { openMobileNativeChatSendBudget } from './mobile-native-chat-send' export function useMobileNativeChatStop(args: { @@ -111,6 +112,8 @@ export function useMobileNativeChatStop(args: { .then((response) => { if (isTerminalSendRpcAccepted(response)) { sawAccepted = true + // A deliberate Stop is human input; it takes the worker over like any other key. + reportWorkerTerminalUserInput(client, handle) } else { sawRejected = true } diff --git a/mobile/src/session/use-mobile-session-terminal-input.ts b/mobile/src/session/use-mobile-session-terminal-input.ts index 02906099e79..3f6e417e23a 100644 --- a/mobile/src/session/use-mobile-session-terminal-input.ts +++ b/mobile/src/session/use-mobile-session-terminal-input.ts @@ -1,4 +1,6 @@ +import { reportWorkerTerminalUserInput } from '../terminal/worker-terminal-takeover-report' import { useCallback } from 'react' +import { isTerminalSendRpcAccepted } from '../terminal/terminal-send-rpc-response' import { clearTerminalLiveInputFocusTimer, scheduleTerminalLiveInputFocus @@ -110,7 +112,7 @@ export function useMobileSessionTerminalInput(scope: MobileSessionFileActionsMod terminalGestureInputInFlightRef.current.add(handle) try { // Why: gesture arrows parked across a reconnect would move a TUI long after the swipe. - await rpc.sendRequest( + const response = await rpc.sendRequest( 'terminal.send', buildTerminalSendParams({ terminal: handle, @@ -120,6 +122,9 @@ export function useMobileSessionTerminalInput(scope: MobileSessionFileActionsMod }), TERMINAL_INPUT_SEND_OPTIONS ) + if (isTerminalSendRpcAccepted(response)) { + reportWorkerTerminalUserInput(rpc, handle) + } } catch { // Transient failure } finally { diff --git a/mobile/src/session/use-mobile-session-terminal-send-actions.ts b/mobile/src/session/use-mobile-session-terminal-send-actions.ts index 6909f71ca63..aa365d5ba39 100644 --- a/mobile/src/session/use-mobile-session-terminal-send-actions.ts +++ b/mobile/src/session/use-mobile-session-terminal-send-actions.ts @@ -1,3 +1,4 @@ +import { reportWorkerTerminalUserInput } from '../terminal/worker-terminal-takeover-report' import { useCallback } from 'react' import { Keyboard } from 'react-native' import { triggerError } from '../platform/haptics' @@ -98,6 +99,9 @@ export function useMobileSessionTerminalSendActions(scope: MobileSessionTerminal TERMINAL_INPUT_SEND_OPTIONS ) const accepted = isTerminalSendRpcAccepted(response) + if (accepted) { + reportWorkerTerminalUserInput(client, activeHandle) + } if (!accepted) { restoreRejectedDraft() } @@ -166,7 +170,16 @@ export function useMobileSessionTerminalSendActions(scope: MobileSessionTerminal }), TERMINAL_INPUT_SEND_OPTIONS ) - .then(isTerminalSendRpcAccepted, () => false) + .then( + (response) => { + const accepted = isTerminalSendRpcAccepted(response) + if (accepted) { + reportWorkerTerminalUserInput(rpc, handle) + } + return accepted + }, + () => false + ) }, [showToast] ) diff --git a/mobile/src/session/use-mobile-terminal-paste.ts b/mobile/src/session/use-mobile-terminal-paste.ts index 57ea720c4c8..3680fa2e505 100644 --- a/mobile/src/session/use-mobile-terminal-paste.ts +++ b/mobile/src/session/use-mobile-terminal-paste.ts @@ -1,4 +1,6 @@ +import { reportWorkerTerminalUserInput } from '../terminal/worker-terminal-takeover-report' import { useCallback, type RefObject } from 'react' +import { isTerminalSendRpcAccepted } from '../terminal/terminal-send-rpc-response' import * as Clipboard from 'expo-clipboard' import { File as FsFile, Paths } from 'expo-file-system' import { ImageManipulator, SaveFormat } from 'expo-image-manipulator' @@ -155,7 +157,7 @@ export function useMobileTerminalPaste({ ) { return } - await currentClient.sendRequest('terminal.send', { + const response = await currentClient.sendRequest('terminal.send', { terminal: targetHandle, text: payload, enter: false, @@ -163,6 +165,9 @@ export function useMobileTerminalPaste({ ? { client: { id: deviceTokenRef.current, type: 'mobile' as const } } : {}) }) + if (isTerminalSendRpcAccepted(response)) { + reportWorkerTerminalUserInput(currentClient, targetHandle) + } onSuccess() refreshCanPaste() } catch (e) { diff --git a/mobile/src/terminal/terminal-live-accessory-raw-send.ts b/mobile/src/terminal/terminal-live-accessory-raw-send.ts index 3824d750792..6fa00ce7bac 100644 --- a/mobile/src/terminal/terminal-live-accessory-raw-send.ts +++ b/mobile/src/terminal/terminal-live-accessory-raw-send.ts @@ -1,3 +1,4 @@ +import { reportWorkerTerminalUserInput } from './worker-terminal-takeover-report' import { getTerminalLiveAccessoryRawSendTarget } from './terminal-live-accessory-raw-send-target' import { isTerminalSendRpcAccepted } from './terminal-send-rpc-response' import { buildTerminalSendParams, TERMINAL_INPUT_SEND_OPTIONS } from './terminal-send-request' @@ -37,5 +38,14 @@ export async function sendTerminalLiveAccessoryRawBytes( }), TERMINAL_INPUT_SEND_OPTIONS ) - .then(isTerminalSendRpcAccepted, () => false) + .then( + (response) => { + const accepted = isTerminalSendRpcAccepted(response) + if (accepted) { + reportWorkerTerminalUserInput(args.client!, rawSendTarget) + } + return accepted + }, + () => false + ) } diff --git a/mobile/src/terminal/terminal-webview-payload-hash.test.ts b/mobile/src/terminal/terminal-webview-payload-hash.test.ts index f8bfa4bd134..66cd2735ea2 100644 --- a/mobile/src/terminal/terminal-webview-payload-hash.test.ts +++ b/mobile/src/terminal/terminal-webview-payload-hash.test.ts @@ -6,8 +6,8 @@ import { XTERM_HTML } from './terminal-webview-html' // uncovered region ships silently. A diff here means the emitted WebView source changed — // update these values only when that change is deliberate, and only after checking the // document still runs. Refactors that merely move slice boundaries must leave them alone. -const EXPECTED_SHA256 = '42cc000faddc3b58b8fd4855f848c7878f0cd6166c613f66d733645e8e1b9608' -const EXPECTED_LENGTH = 729776 +const EXPECTED_SHA256 = '5c69dce3236662c381abbfb5d2d6b7163e0f4dd6841d72753733f9470326fee3' +const EXPECTED_LENGTH = 730428 describe('terminal WebView payload', () => { it('composes the expected document', () => { diff --git a/mobile/src/terminal/terminal-webview-theme-injected.test.ts b/mobile/src/terminal/terminal-webview-theme-injected.test.ts index 92e4127b2fc..d0947ef3e92 100644 --- a/mobile/src/terminal/terminal-webview-theme-injected.test.ts +++ b/mobile/src/terminal/terminal-webview-theme-injected.test.ts @@ -76,4 +76,43 @@ describe('mobile terminal-webview contrast floor gate', () => { context.applyTerminalTheme({ theme: { background: '#1e242a' } }) expect(term.options.minimumContrastRatio).toBe(DARK_FLOOR) }) + + // #10754: the desktop user can lower or disable the floor. Mobile mirrors the desktop gate, so the + // published value has to win here or the same session renders differently on the phone. + describe('published desktop override', () => { + function applyOn(term: { options: { minimumContrastRatio: number } }, input: unknown): void { + const context = loadThemeInjected({ + term, + document: { + documentElement: { style: { background: '' } }, + body: { style: { background: '' } } + } + }) as Record & { applyTerminalTheme: (input: unknown) => void } + context.applyTerminalTheme(input) + } + + it('uses the published floor instead of the luminance gate', () => { + const term = { options: { minimumContrastRatio: 0 } } + applyOn(term, { theme: { background: '#1e242a' }, minimumContrastRatio: 1 }) + expect(term.options.minimumContrastRatio).toBe(1) + }) + + it("clamps a published floor to xterm's 1-21 window", () => { + const term = { options: { minimumContrastRatio: 0 } } + applyOn(term, { theme: { background: '#1e242a' }, minimumContrastRatio: 99 }) + expect(term.options.minimumContrastRatio).toBe(21) + applyOn(term, { theme: { background: '#1e242a' }, minimumContrastRatio: 0 }) + expect(term.options.minimumContrastRatio).toBe(1) + }) + + it('falls back to the luminance gate for an older host that omits the field', () => { + const term = { options: { minimumContrastRatio: 0 } } + for (const published of [undefined, null, 'off', Number.NaN]) { + applyOn(term, { theme: { background: '#1e242a' }, minimumContrastRatio: published }) + expect(term.options.minimumContrastRatio).toBe(DARK_FLOOR) + applyOn(term, { theme: { background: '#ffffff' }, minimumContrastRatio: published }) + expect(term.options.minimumContrastRatio).toBe(LIGHT_FLOOR) + } + }) + }) }) diff --git a/mobile/src/terminal/terminal-webview-theme-injected.ts b/mobile/src/terminal/terminal-webview-theme-injected.ts index c2d9beb4786..98489b219c7 100644 --- a/mobile/src/terminal/terminal-webview-theme-injected.ts +++ b/mobile/src/terminal/terminal-webview-theme-injected.ts @@ -5,7 +5,8 @@ import { colors } from '../theme/mobile-theme' // #7934/#10104): a dark composed background gets a mild floor of 3 to rescue near-background body text // (e.g. Antigravity's #262b30 on #1e242a) without over-brightening vibrant ANSI colors; a light // background keeps the WCAG-AA 4.5 floor. Gate on the composed background luminance, not app mode, -// because either theme slot can hold either kind of theme. +// because either theme slot can hold either kind of theme. An explicit desktop override published on +// the theme payload (#10754) wins over the luminance gate; older hosts simply omit it. export const TERMINAL_WEBVIEW_THEME_JS = ` var DARK_BG_MIN_CONTRAST = 3; var LIGHT_BG_MIN_CONTRAST = 4.5; @@ -63,6 +64,12 @@ export const TERMINAL_WEBVIEW_THEME_JS = ` return (Math.max(la, lb) + 0.05) / (Math.min(la, lb) + 0.05); } + // Clamp an explicit desktop override to xterm's 1-21 range; null means "no usable override". + function normalizeTerminalContrastOverride(value) { + if (typeof value !== 'number' || !isFinite(value)) return null; + return Math.min(21, Math.max(1, value)); + } + // Pick the xterm minimumContrastRatio floor from the composed terminal background. // Unparseable input defaults to the dark floor so agent output never stays invisible. function resolveTerminalContrastFloor(background) { @@ -100,7 +107,13 @@ export const TERMINAL_WEBVIEW_THEME_JS = ` var background = terminalTheme.background || '${colors.terminalBg}'; document.documentElement.style.background = background; document.body.style.background = background; - terminalMinimumContrastRatio = resolveTerminalContrastFloor(background); + // Why prefer the published value: the desktop user may have lowered or disabled the floor (#10754); + // an older host omits the field and the luminance gate stays authoritative. + var publishedFloor = normalizeTerminalContrastOverride( + input && typeof input === 'object' ? input.minimumContrastRatio : undefined + ); + terminalMinimumContrastRatio = + publishedFloor === null ? resolveTerminalContrastFloor(background) : publishedFloor; if (term) { term.options.theme = terminalTheme; term.options.minimumContrastRatio = terminalMinimumContrastRatio; diff --git a/mobile/src/terminal/worker-terminal-takeover-report.test.ts b/mobile/src/terminal/worker-terminal-takeover-report.test.ts new file mode 100644 index 00000000000..5ef62be1f0b --- /dev/null +++ b/mobile/src/terminal/worker-terminal-takeover-report.test.ts @@ -0,0 +1,82 @@ +import { beforeEach, afterEach, expect, it, vi } from 'vitest' +import { + reportWorkerTerminalUserInput, + resetWorkerTerminalTakeoverReportsForTest +} from './worker-terminal-takeover-report' + +const success = { id: 'report', ok: true as const, result: { changed: 1 } } +beforeEach(() => { + vi.useFakeTimers() + vi.setSystemTime(1_000) + resetWorkerTerminalTakeoverReportsForTest() +}) +afterEach(() => vi.useRealTimers()) + +it('gates per handle and owning client for 30 seconds', () => { + const relay = { sendRequest: vi.fn().mockResolvedValue(success) } + const direct = { sendRequest: vi.fn().mockResolvedValue(success) } + for (let i = 0; i < 100; i++) { + reportWorkerTerminalUserInput(relay, 'term-1') + } + expect(relay.sendRequest).toHaveBeenCalledTimes(1) + reportWorkerTerminalUserInput(relay, 'term-2') + reportWorkerTerminalUserInput(direct, 'term-1') + expect(relay.sendRequest).toHaveBeenCalledTimes(2) + expect(direct.sendRequest).toHaveBeenCalledTimes(1) + vi.advanceTimersByTime(29_999) + reportWorkerTerminalUserInput(relay, 'term-1') + expect(relay.sendRequest).toHaveBeenCalledTimes(2) + vi.advanceTimersByTime(1) + reportWorkerTerminalUserInput(relay, 'term-1') + expect(relay.sendRequest).toHaveBeenCalledTimes(3) + expect(relay.sendRequest).toHaveBeenLastCalledWith( + 'orchestration.workerTerminalUserInput', + { terminal: 'term-1' }, + { timeoutMs: 5_000, budgetSpansConnect: true, failWhenDisconnected: true } + ) +}) + +it('does not await a report and coalesces input while it is pending', () => { + const client = { sendRequest: vi.fn(() => new Promise(() => {})) } + expect(reportWorkerTerminalUserInput(client, 'term-1')).toBeUndefined() + reportWorkerTerminalUserInput(client, 'term-1') + expect(client.sendRequest).toHaveBeenCalledTimes(1) +}) + +it.each(['throw', 'rpc refusal'])( + 'retries a %s once on the same target, then permits a later attempt', + async (failure) => { + const client = { + sendRequest: + failure === 'throw' + ? vi.fn().mockRejectedValue(new Error('offline')) + : vi.fn().mockResolvedValue({ id: 'report', ok: false, error: { message: 'refused' } }) + } + reportWorkerTerminalUserInput(client, 'term-1') + await vi.advanceTimersByTimeAsync(249) + expect(client.sendRequest).toHaveBeenCalledTimes(1) + await vi.advanceTimersByTimeAsync(1) + expect(client.sendRequest).toHaveBeenCalledTimes(2) + await vi.advanceTimersByTimeAsync(1_000) + expect(client.sendRequest).toHaveBeenCalledTimes(2) + client.sendRequest.mockResolvedValue(success) + reportWorkerTerminalUserInput(client, 'term-1') + expect(client.sendRequest).toHaveBeenCalledTimes(3) + } +) + +it('a report that changed nothing still arms the gate, so plain terminals pay once per window', async () => { + // Why: the host answers `changed: 0` for every ordinary terminal; reopening on that turned + // every accepted key into an RPC and a host write transaction (round 6 measurement: 100 for 100). + const client = { + sendRequest: vi.fn().mockResolvedValue({ id: 'report', ok: true, result: { changed: 0 } }) + } + for (let i = 0; i < 100; i++) { + reportWorkerTerminalUserInput(client, 'term-plain') + await vi.advanceTimersByTimeAsync(100) + } + expect(client.sendRequest).toHaveBeenCalledTimes(1) + await vi.advanceTimersByTimeAsync(30_000) + reportWorkerTerminalUserInput(client, 'term-plain') + expect(client.sendRequest).toHaveBeenCalledTimes(2) +}) diff --git a/mobile/src/terminal/worker-terminal-takeover-report.ts b/mobile/src/terminal/worker-terminal-takeover-report.ts new file mode 100644 index 00000000000..a3ed7f6424d --- /dev/null +++ b/mobile/src/terminal/worker-terminal-takeover-report.ts @@ -0,0 +1,59 @@ +import type { RpcClient } from '../transport/rpc-client' + +type ReportClient = Pick +const REPORT_INTERVAL_MS = 30_000 +const REPORT_RETRY_DELAY_MS = 250 +let reportsByClient = new WeakMap>() + +// The same logical client owns relay/direct cutover; never reroute a report via active UI state. +export function reportWorkerTerminalUserInput(client: ReportClient, terminal: string): void { + let reports = reportsByClient.get(client) + if (!reports) { + reports = new Map() + reportsByClient.set(client, reports) + } + const now = Date.now() + const last = reports.get(terminal) + if (last !== undefined && now - last < REPORT_INTERVAL_MS) { + return + } + if (reports.size >= 256) { + for (const [handle, reportedAt] of reports) { + if (now - reportedAt >= REPORT_INTERVAL_MS) { + reports.delete(handle) + } + } + } + // Why the gate ignores the answer: like desktop, one report per terminal per window is the + // whole cost of typing into any terminal, worker or not. A result-aware gate that reopened on + // "changed nothing" turned every key on an ordinary terminal into an RPC plus a host write. + reports.set(terminal, now) + void sendTakeoverReport(client, terminal).catch(() => { + if (reports.get(terminal) === now) { + reports.delete(terminal) + } + }) +} + +async function sendTakeoverReport(client: ReportClient, terminal: string): Promise { + const report = async (): Promise => { + const response = await client.sendRequest( + 'orchestration.workerTerminalUserInput', + { terminal }, + { timeoutMs: 5_000, budgetSpansConnect: true, failWhenDisconnected: true } + ) + if (!response.ok) { + throw new Error('Worker takeover report rejected') + } + } + try { + return await report() + } catch { + await new Promise((resolve) => setTimeout(resolve, REPORT_RETRY_DELAY_MS)) + return await report() + } +} + +export function resetWorkerTerminalTakeoverReportsForTest(): void { + reportsByClient = new WeakMap() +} diff --git a/package.json b/package.json index 321f2ada9ed..0536f4fd606 100644 --- a/package.json +++ b/package.json @@ -243,6 +243,7 @@ "electron-vite": "^5.0.0", "emoji-picker-react": "^4.19.1", "emojibase-data": "17.0.0", + "esbuild": "^0.25.12", "happy-dom": "^20.11.8", "html-to-image": "^1.11.13", "husky": "^9.1.7", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 9ee9fff6785..7add63b397b 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -366,6 +366,9 @@ importers: emojibase-data: specifier: 17.0.0 version: 17.0.0(emojibase@17.0.0) + esbuild: + specifier: ^0.25.12 + version: 0.25.12 happy-dom: specifier: ^20.11.8 version: 20.11.8 diff --git a/skill-guides/orchestration.md b/skill-guides/orchestration.md index 4e49a0d84af..d744785ab10 100644 --- a/skill-guides/orchestration.md +++ b/skill-guides/orchestration.md @@ -137,8 +137,8 @@ After three consecutive empty waits, stop waiting blindly and enumerate with `ORCA orchestration worker-list --include-remote --json` (defaults to the bound Run; `--run ` overrides; the receipt's `scope` names which), acting on each row's `projection.attention` categories, `projection.attention.requiresAction`, and literal `projection.nextAction` argv. -An `inspect` `nextAction` on a `live` row with `attention.requiresAction` false -is informational, not a command to re-run: keep waiting with `check --wait`. +A `none` `nextAction` has no argv to run: read `liveness.reason` and keep waiting +with `check --wait`. Absence never earns an argv; settlement and pending work still do. Leave the wait only on positive proof the agent stopped: `exited` liveness, the worker's own observation of process exit, or a transcript whose final agent turn sent no `worker_done`. Then load `references/recovery-and-cleanup.md` and choose diff --git a/src/cli/bundled-skill-guides.ts b/src/cli/bundled-skill-guides.ts index fc30604a264..47b5559f01b 100644 --- a/src/cli/bundled-skill-guides.ts +++ b/src/cli/bundled-skill-guides.ts @@ -66,10 +66,10 @@ const ORCA_PER_WORKSPACE_ENV_SSH_HOST_REFERENCE_MARKDOWN = "# SSH connection mod const ORCA_PER_WORKSPACE_ENV_WINDOWS_SCRIPTS_REFERENCE_MARKDOWN = "# Windows local-side scripts\n\nLoad this when the user's desktop is Windows and you are scaffolding the local-side scripts. A bare\n`.sh` will not execute there. Either require WSL or Git Bash and point `orca.yaml` at a launcher such\nas `bash ./scripts/orca-vm/.sh` through a `.cmd` file, or scaffold PowerShell equivalents.\n\nThe remote-side commands you run inside the Linux environment stay bash regardless of the desktop OS.\n\n```powershell\n#requires -Version 5\n$ErrorActionPreference = 'Stop'\n# resolve env→state→fallback; run the provider CLI / ssh the same way;\n# capture provider output; build the result object for the chosen mode and write ONE line of JSON to stdout.\n# Orca-server mode: @{ schemaVersion=1; pairingCode=$pairingCode; projectRoot=$projectRoot; userData=@{...} }\n# SSH mode: @{ schemaVersion=1; connection=@{ type=\"ssh\"; projectRoot=$projectRoot;\n# target=@{ label=$label; host=$host; port=$port; username=$user } } }\n($result | ConvertTo-Json -Compress -Depth 6)\n# progress/errors → Write-Error / the error stream, never stdout.\n```\n\nThe doctor's executable-bit check is a POSIX concept and is skipped on Windows, so a script that is\nunusable on the user's machine for a different reason still has to be caught by the `--provision`\nself-test.\n" // oxfmt-ignore -const ORCHESTRATION_MARKDOWN = "---\nname: orchestration\ndescription: >-\n Coordinate supervised Orca workers: threaded messages, blocking ask/reply,\n task dispatch, worker_done/escalation waits, task DAGs, decision gates,\n coordinator loops, and decomposing work across agents. Use `orca-cli` for full\n ownership handoffs — \"hand off\", \"handoff\", \"handover\", \"give this to another\n agent\", \"another worktree\" — unless asked to supervise, monitor, or coordinate\n a DAG, and for terminal control, lightweight terminal prompts, shell commands,\n Orca worktree management, and reading or waiting on terminals. Use Computer\n Use for external browser windows, webviews, Orca app UI, or desktop UI outside\n Orca's embedded browser only when the task requires OS/window-level control\n such as focus, menus, dialogs, coordinates, or screenshots. Use `orca-cli` for\n Orca's embedded pages and a page-automation tool such as Playwright or CDP for\n external pages.\n---\n\n# Orca orchestration\n\nOrchestration is Orca's structured coordination layer. It records who owns work,\nwhich attempt is authoritative, and when supervised work has settled.\n\n## Outcome\n\n**Result:** every in-scope Task has one explicit outcome and every settled worker\nterminal has a next owner or cleanup decision. **Next consumer:** the user who\nrequested supervision. **Done:** all expected Dispatches have settled, every\ndelivered message was processed before acknowledgment, each settled worker was\nreused, explicitly retained, or released, and the turn ends only when the report\nto that user names, per Task, its outcome, the evidence behind it, and any\nunresolved blocker.\n\n**Safe failure:** preserve work and authority and report the state as unknown or\n`unverifiable`. Only positive proof of exit authorizes stop, abandon, or retry,\nand only an accepted settlement authorizes release. Every other observation,\nabsence included, is a checkpoint.\n\n## Classify the role\n\n| Current context | Role | Route |\n| ---------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------- | ------------------------------------------------------------------------------ |\n| The user explicitly asks to supervise, monitor, wait for results, track completion, coordinate a DAG, use a decision gate, or manage ask/reply | Coordinator | Use the supervised loop below |\n| The current prompt contains a live injected preamble with Task and Dispatch IDs | Dispatched worker | Follow the preamble and the worker obligations below |\n| The user asks to hand off ownership or start another agent/worktree without supervision | Handoff owner | Use `orca-cli`; create no Run, Task, or Dispatch and do not monitor completion |\n| A message carries a legacy authority label | Compatibility operator | Load the legacy contract reference before any lifecycle mutation |\n| No live preamble and no explicit supervision | Ordinary terminal agent | Do not emit lifecycle messages; use `orca-cli` for terminal/worktree work |\n\nModel or effort selection does not make a handoff supervised. Never substitute a\nnon-Orca subagent tool when Orca orchestration provenance was requested.\n\n## Authority and safety floor\n\n- A Run is a durable namespace and coordinator inbox; it does not schedule or\n place workers. A Task is work. A Dispatch is one authoritative Task attempt.\n- Lifecycle authority comes from the active Dispatch, not a terminal title,\n copied ID, old database row, provider transcript, or visible pane.\n- Workers use the exact executable, handle, capability, Task ID, and Dispatch ID\n in the live preamble. Never reconstruct, translate, or broaden those arguments.\n- After remote start, address the worker by Dispatch ID. The execution host owns\n process, filesystem, transcript, stop, and cleanup facts. Preserve the verdicts\n `live` / `unverifiable` / `exited`; contact loss is not process death.\n- Liveness is layered: `worker-list`'s `projection.liveness` is the fleet verdict\n for the agent; `worker-show`'s `observation.status` is PTY liveness only. A live\n terminal can still hold a dead or stuck agent.\n- Folder workspaces are valid; never require Git or assume a worktree.\n- Clients and remote servers update independently. Treat unknown optional fields\n as absent. A new stream operation requires advertised capability because old\n decoders may silently drop unknown opcodes. Never fall back to local execution\n when remote authority or capability is unproven.\n- Use the executable you used to run `skills get` for the entire run. In the\n examples below, replace `ORCA` with it; do not create a shell variable or run\n `ORCA` literally. If it fails, report that exact error instead of switching.\n- A successful `orchestration send` proves durable enqueue; its wake or nudge is\n best-effort attention only and does not prove the recipient read or accepted it.\n\n## Worker obligations\n\nThe injected preamble is authoritative. A dispatched worker must:\n\n1. Do only the current Task and use the preamble's `ask` command for a blocking\n coordinator question. Never open a local question TUI the coordinator cannot\n answer. Resume the same message ID after an ask timeout.\n2. Send heartbeats only at the cadence in the preamble. A heartbeat proves\n liveness, not completion.\n3. Read coordinator follow-ups at each natural checkpoint — before starting a\n new file, after a test run — and once more immediately before `worker_done`:\n `ORCA orchestration check --terminal --json`.\n4. Send `worker_done` exactly once, from the dispatched terminal, with a\n three-sentence executive summary, both lifecycle IDs, and explicit\n `--outcome succeeded` or `--outcome failed`. Never encode failure only in prose.\n5. Append `--files-modified` and `--report-path` only with real values when\n applicable. After `worker_done`, end the dispatched turn and idle; do not poll\n or start new work.\n\nA direct user instruction after completion starts new user-owned work and takes\nprecedence over the idle rule. Do not reuse the settled lifecycle IDs.\n\n## Canonical supervised loop\n\nConfirm the runtime, bind one Run, and start the full independent wave before\nwaiting. `worker-start --spec` creates the Task and its attempt in one call:\n\n```text\nORCA status --json\nORCA orchestration run-create --objective \"\" --json\nORCA orchestration worker-start --spec \"\" --worktree current --agent codex --json\nORCA orchestration worker-start --spec \"\" --worktree current --agent claude --json\nORCA orchestration check --wait --types \"worker_done,escalation,question\" --timeout-ms 900000 --json\n```\n\nIf `worker-start` exits non-zero, do not relaunch. Read the receipt's\n`failedStage` and `residualResources`, then load\n`references/recovery-and-cleanup.md`.\n\nUse `task-create` plus `worker-start --task ` for planned fan-out with\ndependencies or a retry of a known Task. Use dependencies only for real ordering\nand prefer parallel waves over chains deeper than three or four steps; nested\nworkers obey the depth limit, and a new Run does not reset the caller's depth.\n\nA consuming `check` names its caller with `--terminal `, never `--from`;\nomit it inside the coordinator's own Orca terminal. It returns the bound Run's\noldest FIFO Delivery and replays that batch until acknowledged. Process every\nmessage: reply to questions, validate each `worker_done` against the expected\nactive Dispatch, and decide each settled terminal's next owner before the ack:\n\n```text\nORCA orchestration reply --id --body \"\" --json\nORCA orchestration worker-release --dispatch --json\nORCA orchestration check --ack --wait --types \"worker_done,escalation,question\" --timeout-ms 900000 --json\n```\n\nKeep waiting until every expected Dispatch settles. A timeout or empty result is\na checkpoint, not a failure. Do not stop, retry, release, or launch a duplicate\neditor without the positive proof `## Outcome` requires.\n\nAfter three consecutive empty waits, stop waiting blindly and enumerate with\n`ORCA orchestration worker-list --include-remote --json` (defaults to the bound\nRun; `--run ` overrides; the receipt's `scope` names which), acting on\neach row's `projection.attention` categories, `projection.attention.requiresAction`, and literal `projection.nextAction` argv.\nAn `inspect` `nextAction` on a `live` row with `attention.requiresAction` false\nis informational, not a command to re-run: keep waiting with `check --wait`.\nLeave the wait only on positive proof the agent stopped: `exited` liveness, the\nworker's own observation of process exit, or a transcript whose final agent turn\nsent no `worker_done`. Then load `references/recovery-and-cleanup.md` and choose\n`worker-stop` or `worker-abandon` explicitly. `unverifiable` is absence,\nincluding when `worker-show` reports `agentWait` null. Absence never authorizes\nstop, abandon, retry, or release; keep waiting or inspect.\n\n`worker-start` is the normal path, composing placement, terminal readiness,\nprompt injection, and supervised resource ownership. `dispatch --inject` leaves\nan operator-created process unsupervised and is only for an expressiveness gap.\n\n## Task-spec contract\n\nEvery Task spec must be self-contained and name:\n\n- **Target:** the files, component, or environment in scope.\n- **Change:** the concrete result to produce.\n- **Constraints:** invariants, compatibility rules, and do-not-touch boundaries.\n- **Ownership:** what this worker may edit and any coordination boundary.\n- **Observable acceptance:** the test, output, or evidence that proves completion.\n\n## Completion accounting\n\nAfter an accepted success or failure report, immediately do exactly one:\n\n1. Reuse the same proven agent terminal for an immediate follow-up Dispatch.\n2. Record user-requested retention with `worker-retain`.\n3. Run `worker-release`.\n\nRelease is post-settlement cleanup, not cancellation. Only an accepted\nsettlement authorizes it; no other observation does. If release is uncertain,\nfollow its exact recovery receipt and never substitute `terminal close`.\n\nA valid `worker_done` settles the Task and Dispatch automatically; do not follow\nit with `task-update --status completed`. Enumerate the terminals still owing a\ndecision with `worker-list --run --terminal-state reclaimable --json`,\nand do not end the coordinator turn until it returns none.\n\n## Conditional references\n\nThis compact guide is sufficient for the normal local loop. At an action gate\nbelow, run `ORCA skills get orchestration --reference references/.md` and\nread only that document; `--references` lists the names. If the CLI rejects\n`--reference`, run `ORCA skills get orchestration --full` once instead: it\nreturns this exact kernel and every reference, so read only the named one. If an\nolder CLI rejects `--full`, keep this kernel's safety floor, use that command's\n`--help`, and never guess newer flags.\n\n| Action gate | Bundled reference |\n| ------------------------------------------------------------------------------------------------------------- | ----------------------------------------- |\n| Expanded DAG waves, launch model/effort, same-terminal reuse, or review ownership | `references/coordinator-loop.md` |\n| You are a dispatched worker and the live preamble does not answer your question, or `check` returned an error | `references/worker-contract.md` |\n| New worktree, exact workspace, SSH, WSL, or connected-server placement | `references/placement-and-remote.md` |\n| Inbox replay, follow-up messages, group addresses, or decision gates | `references/messaging-and-gates.md` |\n| Failed/stopped/unknown attempts, retry, stop, abandon, retain, or uncertain release | `references/recovery-and-cleanup.md` |\n| Custom argv or terminal topology that `worker-start` cannot express | `references/low-level-topology.md` |\n| Any legacy label, adopted Run, compatibility receipt, or takeover | `references/legacy-contract-migration.md` |\n\nRetired scheduler commands are not aliases for Run creation. Recovery commands\nmust provide their exact next action; follow it with the same selected executable.\n" +const ORCHESTRATION_MARKDOWN = "---\nname: orchestration\ndescription: >-\n Coordinate supervised Orca workers: threaded messages, blocking ask/reply,\n task dispatch, worker_done/escalation waits, task DAGs, decision gates,\n coordinator loops, and decomposing work across agents. Use `orca-cli` for full\n ownership handoffs — \"hand off\", \"handoff\", \"handover\", \"give this to another\n agent\", \"another worktree\" — unless asked to supervise, monitor, or coordinate\n a DAG, and for terminal control, lightweight terminal prompts, shell commands,\n Orca worktree management, and reading or waiting on terminals. Use Computer\n Use for external browser windows, webviews, Orca app UI, or desktop UI outside\n Orca's embedded browser only when the task requires OS/window-level control\n such as focus, menus, dialogs, coordinates, or screenshots. Use `orca-cli` for\n Orca's embedded pages and a page-automation tool such as Playwright or CDP for\n external pages.\n---\n\n# Orca orchestration\n\nOrchestration is Orca's structured coordination layer. It records who owns work,\nwhich attempt is authoritative, and when supervised work has settled.\n\n## Outcome\n\n**Result:** every in-scope Task has one explicit outcome and every settled worker\nterminal has a next owner or cleanup decision. **Next consumer:** the user who\nrequested supervision. **Done:** all expected Dispatches have settled, every\ndelivered message was processed before acknowledgment, each settled worker was\nreused, explicitly retained, or released, and the turn ends only when the report\nto that user names, per Task, its outcome, the evidence behind it, and any\nunresolved blocker.\n\n**Safe failure:** preserve work and authority and report the state as unknown or\n`unverifiable`. Only positive proof of exit authorizes stop, abandon, or retry,\nand only an accepted settlement authorizes release. Every other observation,\nabsence included, is a checkpoint.\n\n## Classify the role\n\n| Current context | Role | Route |\n| ---------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------- | ------------------------------------------------------------------------------ |\n| The user explicitly asks to supervise, monitor, wait for results, track completion, coordinate a DAG, use a decision gate, or manage ask/reply | Coordinator | Use the supervised loop below |\n| The current prompt contains a live injected preamble with Task and Dispatch IDs | Dispatched worker | Follow the preamble and the worker obligations below |\n| The user asks to hand off ownership or start another agent/worktree without supervision | Handoff owner | Use `orca-cli`; create no Run, Task, or Dispatch and do not monitor completion |\n| A message carries a legacy authority label | Compatibility operator | Load the legacy contract reference before any lifecycle mutation |\n| No live preamble and no explicit supervision | Ordinary terminal agent | Do not emit lifecycle messages; use `orca-cli` for terminal/worktree work |\n\nModel or effort selection does not make a handoff supervised. Never substitute a\nnon-Orca subagent tool when Orca orchestration provenance was requested.\n\n## Authority and safety floor\n\n- A Run is a durable namespace and coordinator inbox; it does not schedule or\n place workers. A Task is work. A Dispatch is one authoritative Task attempt.\n- Lifecycle authority comes from the active Dispatch, not a terminal title,\n copied ID, old database row, provider transcript, or visible pane.\n- Workers use the exact executable, handle, capability, Task ID, and Dispatch ID\n in the live preamble. Never reconstruct, translate, or broaden those arguments.\n- After remote start, address the worker by Dispatch ID. The execution host owns\n process, filesystem, transcript, stop, and cleanup facts. Preserve the verdicts\n `live` / `unverifiable` / `exited`; contact loss is not process death.\n- Liveness is layered: `worker-list`'s `projection.liveness` is the fleet verdict\n for the agent; `worker-show`'s `observation.status` is PTY liveness only. A live\n terminal can still hold a dead or stuck agent.\n- Folder workspaces are valid; never require Git or assume a worktree.\n- Clients and remote servers update independently. Treat unknown optional fields\n as absent. A new stream operation requires advertised capability because old\n decoders may silently drop unknown opcodes. Never fall back to local execution\n when remote authority or capability is unproven.\n- Use the executable you used to run `skills get` for the entire run. In the\n examples below, replace `ORCA` with it; do not create a shell variable or run\n `ORCA` literally. If it fails, report that exact error instead of switching.\n- A successful `orchestration send` proves durable enqueue; its wake or nudge is\n best-effort attention only and does not prove the recipient read or accepted it.\n\n## Worker obligations\n\nThe injected preamble is authoritative. A dispatched worker must:\n\n1. Do only the current Task and use the preamble's `ask` command for a blocking\n coordinator question. Never open a local question TUI the coordinator cannot\n answer. Resume the same message ID after an ask timeout.\n2. Send heartbeats only at the cadence in the preamble. A heartbeat proves\n liveness, not completion.\n3. Read coordinator follow-ups at each natural checkpoint — before starting a\n new file, after a test run — and once more immediately before `worker_done`:\n `ORCA orchestration check --terminal --json`.\n4. Send `worker_done` exactly once, from the dispatched terminal, with a\n three-sentence executive summary, both lifecycle IDs, and explicit\n `--outcome succeeded` or `--outcome failed`. Never encode failure only in prose.\n5. Append `--files-modified` and `--report-path` only with real values when\n applicable. After `worker_done`, end the dispatched turn and idle; do not poll\n or start new work.\n\nA direct user instruction after completion starts new user-owned work and takes\nprecedence over the idle rule. Do not reuse the settled lifecycle IDs.\n\n## Canonical supervised loop\n\nConfirm the runtime, bind one Run, and start the full independent wave before\nwaiting. `worker-start --spec` creates the Task and its attempt in one call:\n\n```text\nORCA status --json\nORCA orchestration run-create --objective \"\" --json\nORCA orchestration worker-start --spec \"\" --worktree current --agent codex --json\nORCA orchestration worker-start --spec \"\" --worktree current --agent claude --json\nORCA orchestration check --wait --types \"worker_done,escalation,question\" --timeout-ms 900000 --json\n```\n\nIf `worker-start` exits non-zero, do not relaunch. Read the receipt's\n`failedStage` and `residualResources`, then load\n`references/recovery-and-cleanup.md`.\n\nUse `task-create` plus `worker-start --task ` for planned fan-out with\ndependencies or a retry of a known Task. Use dependencies only for real ordering\nand prefer parallel waves over chains deeper than three or four steps; nested\nworkers obey the depth limit, and a new Run does not reset the caller's depth.\n\nA consuming `check` names its caller with `--terminal `, never `--from`;\nomit it inside the coordinator's own Orca terminal. It returns the bound Run's\noldest FIFO Delivery and replays that batch until acknowledged. Process every\nmessage: reply to questions, validate each `worker_done` against the expected\nactive Dispatch, and decide each settled terminal's next owner before the ack:\n\n```text\nORCA orchestration reply --id --body \"\" --json\nORCA orchestration worker-release --dispatch --json\nORCA orchestration check --ack --wait --types \"worker_done,escalation,question\" --timeout-ms 900000 --json\n```\n\nKeep waiting until every expected Dispatch settles. A timeout or empty result is\na checkpoint, not a failure. Do not stop, retry, release, or launch a duplicate\neditor without the positive proof `## Outcome` requires.\n\nAfter three consecutive empty waits, stop waiting blindly and enumerate with\n`ORCA orchestration worker-list --include-remote --json` (defaults to the bound\nRun; `--run ` overrides; the receipt's `scope` names which), acting on\neach row's `projection.attention` categories, `projection.attention.requiresAction`, and literal `projection.nextAction` argv.\nA `none` `nextAction` has no argv to run: read `liveness.reason` and keep waiting\nwith `check --wait`. Absence never earns an argv; settlement and pending work still do.\nLeave the wait only on positive proof the agent stopped: `exited` liveness, the\nworker's own observation of process exit, or a transcript whose final agent turn\nsent no `worker_done`. Then load `references/recovery-and-cleanup.md` and choose\n`worker-stop` or `worker-abandon` explicitly. `unverifiable` is absence,\nincluding when `worker-show` reports `agentWait` null. Absence never authorizes\nstop, abandon, retry, or release; keep waiting or inspect.\n\n`worker-start` is the normal path, composing placement, terminal readiness,\nprompt injection, and supervised resource ownership. `dispatch --inject` leaves\nan operator-created process unsupervised and is only for an expressiveness gap.\n\n## Task-spec contract\n\nEvery Task spec must be self-contained and name:\n\n- **Target:** the files, component, or environment in scope.\n- **Change:** the concrete result to produce.\n- **Constraints:** invariants, compatibility rules, and do-not-touch boundaries.\n- **Ownership:** what this worker may edit and any coordination boundary.\n- **Observable acceptance:** the test, output, or evidence that proves completion.\n\n## Completion accounting\n\nAfter an accepted success or failure report, immediately do exactly one:\n\n1. Reuse the same proven agent terminal for an immediate follow-up Dispatch.\n2. Record user-requested retention with `worker-retain`.\n3. Run `worker-release`.\n\nRelease is post-settlement cleanup, not cancellation. Only an accepted\nsettlement authorizes it; no other observation does. If release is uncertain,\nfollow its exact recovery receipt and never substitute `terminal close`.\n\nA valid `worker_done` settles the Task and Dispatch automatically; do not follow\nit with `task-update --status completed`. Enumerate the terminals still owing a\ndecision with `worker-list --run --terminal-state reclaimable --json`,\nand do not end the coordinator turn until it returns none.\n\n## Conditional references\n\nThis compact guide is sufficient for the normal local loop. At an action gate\nbelow, run `ORCA skills get orchestration --reference references/.md` and\nread only that document; `--references` lists the names. If the CLI rejects\n`--reference`, run `ORCA skills get orchestration --full` once instead: it\nreturns this exact kernel and every reference, so read only the named one. If an\nolder CLI rejects `--full`, keep this kernel's safety floor, use that command's\n`--help`, and never guess newer flags.\n\n| Action gate | Bundled reference |\n| ------------------------------------------------------------------------------------------------------------- | ----------------------------------------- |\n| Expanded DAG waves, launch model/effort, same-terminal reuse, or review ownership | `references/coordinator-loop.md` |\n| You are a dispatched worker and the live preamble does not answer your question, or `check` returned an error | `references/worker-contract.md` |\n| New worktree, exact workspace, SSH, WSL, or connected-server placement | `references/placement-and-remote.md` |\n| Inbox replay, follow-up messages, group addresses, or decision gates | `references/messaging-and-gates.md` |\n| Failed/stopped/unknown attempts, retry, stop, abandon, retain, or uncertain release | `references/recovery-and-cleanup.md` |\n| Custom argv or terminal topology that `worker-start` cannot express | `references/low-level-topology.md` |\n| Any legacy label, adopted Run, compatibility receipt, or takeover | `references/legacy-contract-migration.md` |\n\nRetired scheduler commands are not aliases for Run creation. Recovery commands\nmust provide their exact next action; follow it with the same selected executable.\n" // oxfmt-ignore -const ORCHESTRATION_FULL_MARKDOWN = "---\nname: orchestration\ndescription: >-\n Coordinate supervised Orca workers: threaded messages, blocking ask/reply,\n task dispatch, worker_done/escalation waits, task DAGs, decision gates,\n coordinator loops, and decomposing work across agents. Use `orca-cli` for full\n ownership handoffs — \"hand off\", \"handoff\", \"handover\", \"give this to another\n agent\", \"another worktree\" — unless asked to supervise, monitor, or coordinate\n a DAG, and for terminal control, lightweight terminal prompts, shell commands,\n Orca worktree management, and reading or waiting on terminals. Use Computer\n Use for external browser windows, webviews, Orca app UI, or desktop UI outside\n Orca's embedded browser only when the task requires OS/window-level control\n such as focus, menus, dialogs, coordinates, or screenshots. Use `orca-cli` for\n Orca's embedded pages and a page-automation tool such as Playwright or CDP for\n external pages.\n---\n\n# Orca orchestration\n\nOrchestration is Orca's structured coordination layer. It records who owns work,\nwhich attempt is authoritative, and when supervised work has settled.\n\n## Outcome\n\n**Result:** every in-scope Task has one explicit outcome and every settled worker\nterminal has a next owner or cleanup decision. **Next consumer:** the user who\nrequested supervision. **Done:** all expected Dispatches have settled, every\ndelivered message was processed before acknowledgment, each settled worker was\nreused, explicitly retained, or released, and the turn ends only when the report\nto that user names, per Task, its outcome, the evidence behind it, and any\nunresolved blocker.\n\n**Safe failure:** preserve work and authority and report the state as unknown or\n`unverifiable`. Only positive proof of exit authorizes stop, abandon, or retry,\nand only an accepted settlement authorizes release. Every other observation,\nabsence included, is a checkpoint.\n\n## Classify the role\n\n| Current context | Role | Route |\n| ---------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------- | ------------------------------------------------------------------------------ |\n| The user explicitly asks to supervise, monitor, wait for results, track completion, coordinate a DAG, use a decision gate, or manage ask/reply | Coordinator | Use the supervised loop below |\n| The current prompt contains a live injected preamble with Task and Dispatch IDs | Dispatched worker | Follow the preamble and the worker obligations below |\n| The user asks to hand off ownership or start another agent/worktree without supervision | Handoff owner | Use `orca-cli`; create no Run, Task, or Dispatch and do not monitor completion |\n| A message carries a legacy authority label | Compatibility operator | Load the legacy contract reference before any lifecycle mutation |\n| No live preamble and no explicit supervision | Ordinary terminal agent | Do not emit lifecycle messages; use `orca-cli` for terminal/worktree work |\n\nModel or effort selection does not make a handoff supervised. Never substitute a\nnon-Orca subagent tool when Orca orchestration provenance was requested.\n\n## Authority and safety floor\n\n- A Run is a durable namespace and coordinator inbox; it does not schedule or\n place workers. A Task is work. A Dispatch is one authoritative Task attempt.\n- Lifecycle authority comes from the active Dispatch, not a terminal title,\n copied ID, old database row, provider transcript, or visible pane.\n- Workers use the exact executable, handle, capability, Task ID, and Dispatch ID\n in the live preamble. Never reconstruct, translate, or broaden those arguments.\n- After remote start, address the worker by Dispatch ID. The execution host owns\n process, filesystem, transcript, stop, and cleanup facts. Preserve the verdicts\n `live` / `unverifiable` / `exited`; contact loss is not process death.\n- Liveness is layered: `worker-list`'s `projection.liveness` is the fleet verdict\n for the agent; `worker-show`'s `observation.status` is PTY liveness only. A live\n terminal can still hold a dead or stuck agent.\n- Folder workspaces are valid; never require Git or assume a worktree.\n- Clients and remote servers update independently. Treat unknown optional fields\n as absent. A new stream operation requires advertised capability because old\n decoders may silently drop unknown opcodes. Never fall back to local execution\n when remote authority or capability is unproven.\n- Use the executable you used to run `skills get` for the entire run. In the\n examples below, replace `ORCA` with it; do not create a shell variable or run\n `ORCA` literally. If it fails, report that exact error instead of switching.\n- A successful `orchestration send` proves durable enqueue; its wake or nudge is\n best-effort attention only and does not prove the recipient read or accepted it.\n\n## Worker obligations\n\nThe injected preamble is authoritative. A dispatched worker must:\n\n1. Do only the current Task and use the preamble's `ask` command for a blocking\n coordinator question. Never open a local question TUI the coordinator cannot\n answer. Resume the same message ID after an ask timeout.\n2. Send heartbeats only at the cadence in the preamble. A heartbeat proves\n liveness, not completion.\n3. Read coordinator follow-ups at each natural checkpoint — before starting a\n new file, after a test run — and once more immediately before `worker_done`:\n `ORCA orchestration check --terminal --json`.\n4. Send `worker_done` exactly once, from the dispatched terminal, with a\n three-sentence executive summary, both lifecycle IDs, and explicit\n `--outcome succeeded` or `--outcome failed`. Never encode failure only in prose.\n5. Append `--files-modified` and `--report-path` only with real values when\n applicable. After `worker_done`, end the dispatched turn and idle; do not poll\n or start new work.\n\nA direct user instruction after completion starts new user-owned work and takes\nprecedence over the idle rule. Do not reuse the settled lifecycle IDs.\n\n## Canonical supervised loop\n\nConfirm the runtime, bind one Run, and start the full independent wave before\nwaiting. `worker-start --spec` creates the Task and its attempt in one call:\n\n```text\nORCA status --json\nORCA orchestration run-create --objective \"\" --json\nORCA orchestration worker-start --spec \"\" --worktree current --agent codex --json\nORCA orchestration worker-start --spec \"\" --worktree current --agent claude --json\nORCA orchestration check --wait --types \"worker_done,escalation,question\" --timeout-ms 900000 --json\n```\n\nIf `worker-start` exits non-zero, do not relaunch. Read the receipt's\n`failedStage` and `residualResources`, then load\n`references/recovery-and-cleanup.md`.\n\nUse `task-create` plus `worker-start --task ` for planned fan-out with\ndependencies or a retry of a known Task. Use dependencies only for real ordering\nand prefer parallel waves over chains deeper than three or four steps; nested\nworkers obey the depth limit, and a new Run does not reset the caller's depth.\n\nA consuming `check` names its caller with `--terminal `, never `--from`;\nomit it inside the coordinator's own Orca terminal. It returns the bound Run's\noldest FIFO Delivery and replays that batch until acknowledged. Process every\nmessage: reply to questions, validate each `worker_done` against the expected\nactive Dispatch, and decide each settled terminal's next owner before the ack:\n\n```text\nORCA orchestration reply --id --body \"\" --json\nORCA orchestration worker-release --dispatch --json\nORCA orchestration check --ack --wait --types \"worker_done,escalation,question\" --timeout-ms 900000 --json\n```\n\nKeep waiting until every expected Dispatch settles. A timeout or empty result is\na checkpoint, not a failure. Do not stop, retry, release, or launch a duplicate\neditor without the positive proof `## Outcome` requires.\n\nAfter three consecutive empty waits, stop waiting blindly and enumerate with\n`ORCA orchestration worker-list --include-remote --json` (defaults to the bound\nRun; `--run ` overrides; the receipt's `scope` names which), acting on\neach row's `projection.attention` categories, `projection.attention.requiresAction`, and literal `projection.nextAction` argv.\nAn `inspect` `nextAction` on a `live` row with `attention.requiresAction` false\nis informational, not a command to re-run: keep waiting with `check --wait`.\nLeave the wait only on positive proof the agent stopped: `exited` liveness, the\nworker's own observation of process exit, or a transcript whose final agent turn\nsent no `worker_done`. Then load `references/recovery-and-cleanup.md` and choose\n`worker-stop` or `worker-abandon` explicitly. `unverifiable` is absence,\nincluding when `worker-show` reports `agentWait` null. Absence never authorizes\nstop, abandon, retry, or release; keep waiting or inspect.\n\n`worker-start` is the normal path, composing placement, terminal readiness,\nprompt injection, and supervised resource ownership. `dispatch --inject` leaves\nan operator-created process unsupervised and is only for an expressiveness gap.\n\n## Task-spec contract\n\nEvery Task spec must be self-contained and name:\n\n- **Target:** the files, component, or environment in scope.\n- **Change:** the concrete result to produce.\n- **Constraints:** invariants, compatibility rules, and do-not-touch boundaries.\n- **Ownership:** what this worker may edit and any coordination boundary.\n- **Observable acceptance:** the test, output, or evidence that proves completion.\n\n## Completion accounting\n\nAfter an accepted success or failure report, immediately do exactly one:\n\n1. Reuse the same proven agent terminal for an immediate follow-up Dispatch.\n2. Record user-requested retention with `worker-retain`.\n3. Run `worker-release`.\n\nRelease is post-settlement cleanup, not cancellation. Only an accepted\nsettlement authorizes it; no other observation does. If release is uncertain,\nfollow its exact recovery receipt and never substitute `terminal close`.\n\nA valid `worker_done` settles the Task and Dispatch automatically; do not follow\nit with `task-update --status completed`. Enumerate the terminals still owing a\ndecision with `worker-list --run --terminal-state reclaimable --json`,\nand do not end the coordinator turn until it returns none.\n\n## Conditional references\n\nThis compact guide is sufficient for the normal local loop. At an action gate\nbelow, run `ORCA skills get orchestration --reference references/.md` and\nread only that document; `--references` lists the names. If the CLI rejects\n`--reference`, run `ORCA skills get orchestration --full` once instead: it\nreturns this exact kernel and every reference, so read only the named one. If an\nolder CLI rejects `--full`, keep this kernel's safety floor, use that command's\n`--help`, and never guess newer flags.\n\n| Action gate | Bundled reference |\n| ------------------------------------------------------------------------------------------------------------- | ----------------------------------------- |\n| Expanded DAG waves, launch model/effort, same-terminal reuse, or review ownership | `references/coordinator-loop.md` |\n| You are a dispatched worker and the live preamble does not answer your question, or `check` returned an error | `references/worker-contract.md` |\n| New worktree, exact workspace, SSH, WSL, or connected-server placement | `references/placement-and-remote.md` |\n| Inbox replay, follow-up messages, group addresses, or decision gates | `references/messaging-and-gates.md` |\n| Failed/stopped/unknown attempts, retry, stop, abandon, retain, or uncertain release | `references/recovery-and-cleanup.md` |\n| Custom argv or terminal topology that `worker-start` cannot express | `references/low-level-topology.md` |\n| Any legacy label, adopted Run, compatibility receipt, or takeover | `references/legacy-contract-migration.md` |\n\nRetired scheduler commands are not aliases for Run creation. Recovery commands\nmust provide their exact next action; follow it with the same selected executable.\n\n---\n\n# Bundled references\n\nThese references belong to the version-matched guide above. Read only the documents named by its action gates.\n\n\n\n# Coordinator loop\n\nLoad this reference for expanded DAG waves, per-invocation launch preferences,\nsame-terminal reuse, or review ownership. The compact guide remains the source\nof truth for the loop order and completion boundary.\n\n## Ready waves\n\nCreate independent Tasks before the first wait. Encode only real dependencies,\nthen use the ready view as external memory:\n\n```text\nORCA orchestration task-create --spec \"\" --deps --json\nORCA orchestration task-list --ready --brief --json\n```\n\n`--brief` collapses whitespace and caps echoed specs at 160 characters;\n`spec_truncated` identifies shortened rows. Omit it when full specs are needed or\nwhen an older CLI rejects the flag. A nested worker must respect\n`nested_worker_depth_exceeded`; creating another Run does not reset depth.\n\n## Launch preferences\n\nFor a fresh Claude, Codex, or Cursor terminal, `--model` accepts an opaque\nprovider model ID. Pass it only when the user named a model; otherwise omit it\nso the worker inherits the user's configured agent default. Add `--effort` only\nwhen that model supports it:\n\n```text\nORCA orchestration worker-start --task --worktree current --agent claude --model opus --effort high --json\n```\n\n`--effort` requires `--model`; neither option combines with `--terminal`. A\nconnected worker server must advertise launch-preference support before Orca\nforwards either field. Compare `launch.requested` with `launch.effective`; never\nclaim a model or effort from requested arguments alone.\n\n## Reuse after settlement\n\nChoose the terminal's next owner before acknowledging the Delivery. When the\nsame exact agent has immediate follow-up work, recover the proven handle and\ntransfer cleanup ownership to the new Dispatch:\n\n```text\nORCA orchestration worker-show --dispatch --json\nORCA orchestration worker-start --task --terminal --json\n```\n\nOtherwise explicitly retain or release the settled worker. Do not leave it live\nonly to inspect output; archived output remains available through `worker-read`.\n\n## Review ownership\n\nA review-only `worker_done` authorizes synthesis of findings, not coordinator\nfile edits. Dispatch or hand off fixes unless the user explicitly assigned them\nto the coordinator. If the user's plan names a next owner, post-review fixes and\nPR preparation remain with that owner; the coordinator routes and synthesizes.\n\n\n\n# Legacy contract migration\n\nLoad this reference only for an authority label, adopted Run, compatibility or\nrecovery receipt, or explicit legacy takeover. A newly created attempt always\nuses the current grammar.\n\n## Authority labels\n\n- `[LEGACY COMPATIBILITY]` is live and attested. Run only the exact supported\n command printed with the message, using the same selected executable and\n arguments supplied by the original prompt.\n- `[LEGACY RECOVERY REPLAY — MAY HAVE BEEN SEEN]` is one bounded,\n at-least-once cutover replay. Process it idempotently and acknowledge only\n through the exact displayed guidance.\n- `[LEGACY READ-ONLY]` is inspection-only. It has no reply, acknowledgment, or\n lifecycle mutation.\n- An unlabeled current message uses the current guide and grammar.\n\nAn explicitly selected current Run, attested current binding, current Dispatch,\nor federated attachment takes precedence over legacy fallback. A retained\nadoption record alone does not grant mutation authority. If liveness, principal\nownership, capability, or the exact legacy contract is unproven, degrade to\nread-only inspection and never fall back to local execution.\n\nAdoption preserves the live agent process, PTY/session, terminal handle,\ntab/pane, worktree or folder workspace, Task, and Dispatch. It never restarts or\nreplaces the worker and never revives the retired scheduler. Loss of lifecycle\nauthority does not invalidate the existing process, assignment, or filesystem\nwork. Exact recovery may restore the same PTY once in its original inactive\nbackground tab; it must not spawn, write, signal, stop, switch, focus, split, or\ninject a terminal.\n\n## Compatibility recovery\n\nWhen a compatibility response returns structured next-step arguments, execute\nthose exact arguments with the same selected CLI executable. Do not translate\nfrom memory, broaden the recipient, or retry as a current mutation unless the\nreceipt explicitly authorizes it.\n\nA pending ask, reply, final Dispatch settlement, and consuming check have\ndurable recovery identities. Heartbeat and escalation remain at-least-once\nacross a manual contract-boundary retry. If an ask may already have been\nanswered, run the exact non-consuming recovery check printed by Orca before\ncreating any new question. Never guess among identical question threads.\n\nOn packaged Windows, a legacy ask uses a two-step commit/resume protocol. The\ninitial command commits the question, prints its exact\n`ask --resume ` command, and exits with launcher status `75`. Run\nthat exact resume after the launcher or update boundary. For an attested WSL\nlaunch, preserve the printed `orca-ide` executable and distro route. Older WSL\nworkers without launch proof remain lifecycle read-only even while their\nterminal and filesystem work continue.\n\n## Read-only inspection and takeover\n\nRead-only inspection does not consume mail:\n\n```text\nORCA orchestration run-list --json\nORCA orchestration run-show --id run_legacy_local --json\nORCA orchestration run-show --id --json\nORCA orchestration task-list --run --json\nORCA orchestration inbox --full --json\nORCA orchestration check --terminal --peek --format --json\nORCA terminal read --terminal --json\nORCA terminal wait --terminal --for tui-idle --timeout-ms 60000 --json\n```\n\n`run_legacy_local` is an empty audit tombstone after adoption. Find the ordinary\nRun whose objective is `Recovered orchestration work from a contract update`.\n\nOnly when the original coordinator is unavailable or cannot prove retained\nauthority may a new live coordinator take over from its own terminal:\n\n```text\nORCA orchestration run-use --id --takeover-legacy --json\nORCA orchestration check --run --json\n```\n\nTakeover binds the authenticated invoking terminal; `--from` cannot nominate\nanother coordinator. It fences only the old coordinator and moves pending mail\ninto current Run delivery. It preserves live workers, Tasks, Dispatches, processes, and files.\nNever take over while the original coordinator is actively coordinating.\n\nDo not launch a replacement editor merely because Orca updated or authority is\nunclear. Keep the original worker as the only editor until a stable handoff\npoint, then use a fresh current Dispatch in a conflict-free placement.\n\n\n\n# Low-level topology\n\nLoad this reference only when `worker-start` cannot express required custom argv\nor terminal topology. It is not the normal supervised loop and is never a full\nhandoff recipe.\n\n```text\nORCA terminal create --worktree active --title --command \"\" --json\nORCA terminal wait --terminal --for tui-idle --timeout-ms 60000 --json\nORCA orchestration dispatch --task --to --inject --json\n```\n\nWait for readiness only when startup could lose injected input. Prefer\nagent-first `worker-start` whenever its argv and topology are sufficient.\n\n`dispatch --inject` creates authoritative Task/Dispatch context but deliberately\nkeeps an operator-created process unsupervised: it creates no supervised worker\nresource row. `worker-show`, `worker-read`, and `worker-list` report the lane as\n`unsupervised`; `worker-stop` and `worker-abandon` do not close that process, and\nsettled retain/release take no process action.\n\nUse `worker-start --terminal ` when lifecycle ownership of an existing\nagent terminal is required. Never imply that low-level dispatch retroactively\nowns a process, never use it to route around the nested-depth limit, and never\nuse it for an ownership handoff.\n\n\n\n# Messaging and gates\n\nLoad this reference for inbox replay, attempt-specific guidance, group\naddresses, blocking questions, or coordinator-managed DAG decisions.\n\nA successful `send` proves durable enqueue. Wake and nudge are best-effort\nattention only: neither proves the recipient read the message, began a turn, or\naccepted steering.\n\n## Coordinator delivery loop\n\n`check` names its caller with `--terminal ` and is the only verb that\nrejects `--from`. Omit `--terminal` inside an Orca terminal, where Orca resolves\nthe caller; pass it explicitly from anywhere else, including a dispatched\nworker reading coordinator follow-ups.\n\nA consuming coordinator `check` returns the bound Run's oldest FIFO Delivery,\nup to 50 messages, and replays that exact batch until acknowledged. Process\nevery row and required terminal ownership decision before `--ack`. Type filters\ndecide when a waiter wakes; they do not authorize skipping older actionable\nmail. A Delivery therefore always carries the whole FIFO batch whatever its\ntypes, and a `check` without `--wait` hands that batch over unfiltered.\n`--peek` and `--all` are read-only inspection, not progress through the\ncoordinator inbox.\n\nAn empty wait or timeout is a checkpoint. Continue rolling waits until every\nexpected Dispatch settles. Heartbeat or visible activity means alive, not done.\n\n## Addresses\n\nUse a stable Dispatch address for attempt-specific coordinator guidance:\n\n```text\nORCA orchestration send --to dispatch: --subject \"Follow-up\" --body \"\" --json\n```\n\nDo not substitute a remote terminal handle. Omit `--from` for ordinary\ncoordinator calls; a dispatched worker instead copies the exact `--from` and\ncapability arguments in its preamble. `check` is the exception: it identifies\nits caller with `--terminal`, never `--from`.\n\nGroup addresses include `@all`, `@idle`, `@claude`, `@codex`, `@opencode`,\n`@gemini`, `@droid`, `@grok`, `@cursor`, and `@worktree:`. Use them only for\nintentional fan-out status or questions. `worker_done`, heartbeat, and other\nDispatch lifecycle messages never target groups.\n\n## Questions and gates\n\nA worker uses `ask`; its timeout leaves one durable question pending, which the\nworker resumes by message ID. The coordinator answers that message with `reply`.\n\nUse a gate only for a coordinator-owned Task-DAG decision:\n\n```text\nORCA orchestration gate-create --task --question \"\" --options --json\nORCA orchestration gate-resolve --id --resolution \"\" --json\nORCA orchestration gate-list --task --json\n```\n\nPass `json_array` using the quoting rules of the active shell; do not copy POSIX\nsingle-quote syntax into PowerShell or `cmd.exe`.\n\nDo not create a gate merely to answer a worker's `ask`.\n\n\n\n# Placement and remote execution\n\nLoad this reference before creating a new worktree or placing work through SSH,\nWSL, or another connected Orca server.\n\n## Placement choices\n\nA fresh worker means a fresh agent terminal, not a new Git worktree. Use the\ncurrent or an exact existing workspace by default. Create a worktree only when\nthe user requested one or a concrete checkout or filesystem conflict makes\nsharing unsafe.\n\n```text\n# Current workspace; setup is not rerun.\nORCA orchestration worker-start --task --worktree current --agent codex --json\n\n# Stacked child worktree.\nORCA orchestration worker-start --task --worktree new-child --name --agent codex --setup run --json\n\n# Independent top-level worktree.\nORCA orchestration worker-start --task --worktree new-top-level --name --agent codex --setup run --json\n```\n\nCurrent and exact existing workspaces create a fresh terminal unless\n`--terminal` is explicit. Folder workspaces are first-class; do not invoke Git\nor require worktree lineage when the selected workspace is a folder.\n\nRegister a folder workspace through project setup. `repo add --path `\nrequires a valid Git repository and rejects a plain directory:\n\n```text\nORCA project setup-existing-folder --project --host --path --kind folder --json\n```\n\nThen place work on the returned workspace with an exact selector. A worktree\nselector needs the full `::` value Orca returned, passed as\n`id:`; a bare repo id is not a worktree id. `new-child` and\n`new-top-level` are worktree creation and do not apply to a folder.\n\nNew worktrees use agent-first creation and run setup by default. Preserve the\nrepository's startup policy: `start-immediately` can report setup as `running`,\nwhile `wait-for-setup` gates prompt delivery on success. Orca lineage, Git base,\nfilesystem isolation, coordination parentage, UI grouping, and execution host\nare separate decisions.\n\n## Connected servers\n\nThe Run and Tasks remain authoritative on the current server. `--on` selects\nonly the worker's execution server and appears only on `worker-start`:\n\n```text\nORCA orchestration worker-start --task --on --worktree new-top-level --repo --name --agent codex --setup run --json\n```\n\nRemote `current` and `new-child` are invalid because they are ambiguous across\nservers. Use an exact discovered remote workspace, or `new-top-level` with an\nexact remote repository selector. After start, route every follow-up, read,\nstop, and cleanup by Dispatch ID; never repeat `--on` or substitute a remote\nterminal handle.\n\n```text\nORCA orchestration worker-show --dispatch --json\nORCA orchestration worker-read --dispatch --limit 50 --json\nORCA orchestration send --to dispatch: --subject \"Follow-up\" --body \"\" --json\nORCA orchestration worker-list --run --include-remote --json\n```\n\n`worker-list` reads local fleet state only; enumerate remote workers with\n`--include-remote` or every one of them reads `unverifiable`. Scope every list\nwith `--run `: unscoped, it reports every Dispatch this runtime has\nrecorded, and the workers you are waiting on are lost in that history.\n\n## Execution-host and mixed-version floor\n\nThe execution host owns process, filesystem, transcript, stop, and cleanup\nfacts. Render only `live`, `unverifiable`, or `exited`. Connection loss, relay\nabsence, missing client inventory, or timeout yields `unverifiable`, never\nsynthetic exit and never a client-local substitute action.\n\nClients and servers update independently. Optional response fields may be\nabsent. Forward model/effort, transcript reads, cleanup, or another new remote\noperation only when the peer advertises the relevant capability; unknown stream\nopcodes can be silently dropped. A narrow unsupported response may degrade to a\ndocumented older path, but must not broaden the target or cross the execution\nboundary. Changing host-published content reaches old clients even without a\nwire-shape change, so preserve established semantics or negotiate the behavior.\n\nFor WSL, use the exact executable and arguments returned by Orca so the distro\nand packaged launcher remain bound. Do not translate a printed `orca-ide`\nrecovery command into a PATH-resolved local command.\n\n\n\n# Recovery and cleanup\n\nLoad this reference only after a failed/stopped/unknown attempt, explicit retry\ndecision, stop/abandon request, retention request, or uncertain release.\n\n| Proven state | Safe action |\n| ----------------------- | ------------------------------------------------------------------ |\n| `ready` or active | Keep waiting; optionally read bounded output |\n| `failed` or `stopped` | Start a replacement with `--retry-of`; repeat placement explicitly |\n| `outcome_unknown` | Inspect, then choose `worker-stop` or explicit `worker-abandon` |\n| Accepted `worker_done` | Reuse, retain, or release |\n| Remote contact lost | Preserve `unverifiable`; do not stop or retry from absence alone |\n| `unverifiable` liveness | Keep waiting or inspect; never stop, abandon, retry, or release |\n| Proven `exited` agent | Enumerate with `worker-list`; follow its `nextAction` |\n\n## Inspect before acting\n\n```text\nORCA orchestration worker-list --run --json\nORCA orchestration worker-list --run --include-remote --json\nORCA orchestration worker-show --dispatch --json\nORCA orchestration worker-read --dispatch --limit 50 --json\n```\n\n`worker-list` is the enumerating command and the authority on agent liveness:\neach row carries `projection.liveness`, `projection.attention.categories`,\n`projection.attention.requiresAction`, and a literal `projection.nextAction`\nargv to run. Always scope it with `--run `; an unscoped list reports\nevery Dispatch this runtime has ever recorded and buries the live ones.\n`worker-show`'s `observation.status` is PTY liveness only, so a `live` terminal\nwhose agent died at a trust prompt still reads `live` there.\n\nWhen the two disagree, the fleet verdict decides — unless the fleet row is\n`unverifiable` for a reason that names a gap on this client rather than a fact\nabout the worker. `missing_status`, `host_unavailable`, and\n`capability_unsupported` are such gaps: the first means this runtime holds no\nstatus row, the second that it could not ask the execution host at all, and the\nthird that a stale peer answered but lacks the fleet-snapshot capability.\nAgainst any of them, a `worker-show` verdict sourced from the execution host is\nthe better evidence and outranks the row. Only `host_unavailable` is contact\nloss; the other two mean the host was never asked or answered without the\ncapability.\n\nThis never promotes absence. `unverifiable` from either command still authorizes\nnothing — only a positive `live` or `exited` verdict does.\n\nA worker started with `--on ` reads `unverifiable` until you\nenumerate with `--include-remote`, which asks its execution host for the\nverdict. Past 100 rows the response pages, so follow `page.nextCursor` with\n`--cursor ` until `page.hasMore` is false.\n\n## Stall needs positive evidence\n\nLeave the wait only on positive proof the agent stopped: `exited` liveness, the\nworker's own observation of process exit, or a transcript whose final agent turn\nsent no `worker_done`. Only then choose `worker-stop` or `worker-abandon`.\n\n`unverifiable` is always absence — `missing_status`, `stale_status`,\n`restored_unconfirmed`, or a remote worker with no connection — and a null\n`agentWait` or an unchanged `worker-read` tail is that same absence seen again.\nAbsence never authorizes stop, abandon, retry, or release: keep waiting, or\ninspect until you hold one of the positive signals above. A `nextAction` that\nnames an inspecting command is asking for evidence, not for cleanup.\n\n`worker-read --source auto` uses a proven provider transcript when available and\notherwise returns bounded terminal output with a typed `fallbackReason`.\nContinue with its top-level cursor, which is pinned to that source. If Orca\nreports `source_changed`, restart without the old cursor. A bounded initial\ntranscript tail can return an EOF cursor that follows only newly appended records;\nread `contentComplete`, `clipping`, and `warnings` before assuming omitted older\nrecords are pageable. Never guess a provider session ID, transcript path, or\nremote terminal handle.\n\n## Was the mutation applied?\n\nWhen a mutation's response was lost and named no Dispatch, do not replay blind.\nEvery orchestration mutation accepts `--retry-request `, which reuses one\noperation identity so Orca can replay, join, or recover it instead of starting a\nduplicate. Ask what happened first:\n\n```text\nORCA orchestration request-show --request --json\n```\n\n`completed` means the mutation already took effect; read its recorded receipt\ninstead of rerunning. `pending` means the original mutation is still running or\nOrca restarted before recording its outcome; replay the original command with\n`--retry-request `. `absent` means this runtime holds no receipt\nunder your caller identity — that is not proof nothing happened, so inspect the\naffected Task, Dispatch, and terminal before deciding whether to retry.\n\nWhen a worker's terminal accepted input but the submit is unconfirmed, use\n`terminal send --wait-submit `: it observes the accepted prompt for that\nlong and, on timeout, returns the input-accepted receipt without resending.\n\n## Refused starts\n\n`dispatch` and `worker-start` refuse the following preflight cases with a stable\n`error.code`; read it before choosing a recovery, and treat `error.data.nextSteps`\nas the exact recovery text. Older hosts may omit `data`, so treat every field as\noptional.\n\n| Code | Meaning | Recovery |\n| -------------------- | --------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |\n| `task_not_found` | No Task with that id, or not in the bound Run (`data.taskId`, `data.runId`) | Check `task-list --json`; create the Task with `task-create` if it does not exist |\n| `task_not_startable` | Task cannot start now: not `ready`, or invalid `--retry-of` (`data.status`, `data.unmetDependencies`, `data.retryOf`) | Wait for running dependencies with `check --wait`; retry or unblock failed ones; inspect `dispatch-show` if already dispatched |\n| `inject_rejected` | `--inject` refused because no recognized agent runs in the target (`data.terminal`, `data.reason`) | Start a recognized agent there or pick another terminal; or dispatch without `--inject` and use `terminal send` |\n| `runtime_error` | Any other failure, including a target terminal that already owns an active Dispatch | Read the message, inspect state, and do not retry unchanged |\n\n## Retry, stop, and abandon\n\nRetry only a positively proven failed or stopped attempt. Name the failed Task\nwith `--task`, since `--spec` creates a new one. Placement is never silently\ninherited:\n\n```text\nORCA orchestration worker-start --task --retry-of --worktree --agent --json\n```\n\nAfter three consecutive failures for one Task, its dispatch context\ncircuit-breaks and the Task is failed. Do not route around that boundary with a\nnew Run or an unrelated Dispatch.\n\nFor `outcome_unknown`, inspect first, then make an explicit choice:\n\n```text\nORCA orchestration worker-stop --dispatch --json\nORCA orchestration worker-abandon --dispatch --json\n```\n\n`worker-stop` closes only the exact proven supervised agent terminal. It never\ndeletes the worktree, setup terminal, configured tabs, or unrelated processes.\n`worker-abandon` fences orchestration while accepting that resources may remain\nlive; it performs no remote, process, or filesystem action.\n\n## Retain and release\n\n```text\nORCA orchestration worker-retain --dispatch --json\nORCA orchestration worker-release --dispatch --json\n```\n\nRetain only when the user explicitly wants the settled terminal kept live.\nRelease works after succeeded and failed reports, archives readable output, and\ncloses only the exact terminal owned by that settled Dispatch. Replays may call\nrelease again safely. Reused, pre-existing, setup, coordinator, active,\nuser-taken-over, and unproven terminals are retained.\n\nA `worker-start` that failed before its agent was ready still owns the terminal\nit created. Its receipt names `worker-release`, and `worker-list` reports that\nrow as `reclaimable`; release it there rather than closing the terminal by hand.\n\nNever release because of timeout, TUI idle, heartbeat, status, question,\nescalation, or stale/rejected completion. If the receipt says `release_pending`\nor `release_unknown`, follow its exact recovery action. Never substitute\n`terminal close`.\n\n`orchestration reset` is destructive recovery. Do not run it during active\ncoordination unless the user explicitly abandons that state.\n\n\n\n# Worker contract\n\nThe injected preamble is authoritative. Copy its command rather than\nreconstructing flags. In particular, preserve the exact executable, worker\nhandle, Dispatch capability, Task ID, and Dispatch ID.\n\n## Heartbeat\n\nSend heartbeats only at the cadence required by the live preamble. Skip them\nwhile blocked inside `ask` or `check --wait`; those calls are liveness signals.\n\n```text\nORCA orchestration send --from --dispatch-capability --type heartbeat --subject \"alive\" --task-id --dispatch-id --phase \"\"\n```\n\nUse typed lifecycle flags, not a hand-written JSON payload. A heartbeat proves\nliveness, never completion.\n\n## Ask and resume\n\nUse Orca `ask` whenever the coordinator must answer. Never open a local question\nTUI the coordinator cannot answer.\n\n```text\nORCA orchestration ask --from --dispatch-capability --question \"\" --options \",\" --timeout-ms 600000\n\nORCA orchestration ask --from --dispatch-capability --resume --timeout-ms 600000\n```\n\nA timeout or disconnect leaves the original question pending. Resume its\nmessage ID; do not create a duplicate question.\n\n## Reading coordinator follow-ups\n\nThe coordinator steers a running worker with `send --to dispatch:`. That\nenqueue is durable but does not interrupt you, so nothing arrives unless you\nlook:\n\n```text\nORCA orchestration check --terminal --json\n```\n\nRun it at each natural checkpoint — before starting a new file, after a test\nrun — and once more immediately before `worker_done`, so a redirect or a\ncancellation lands before the Task settles. `check` names its caller with\n`--terminal`, never `--from`. Stop checking after `worker_done`.\n\nIf `check` returns `consumer_fenced`, this process no longer owns its Dispatch:\nthe Attempt was re-attached to another worker or settled without you. Stop, do\nnot send `worker_done`, and do not retry the check. An empty `check` never means\nyou were replaced; `consumer_fenced` is the only way you learn that.\n\n## Escalation\n\nEscalate only before completion and only when the coordinator must intervene:\n\n```text\nORCA orchestration send --from --dispatch-capability --type escalation --subject \"Blocked: \" --body \"
\" --task-id --dispatch-id \n```\n\n## Completion\n\nSend exactly one terminal report. `--body` is three sentences: what changed,\nwhat was found, and what remains. Use `--outcome failed` when the requested work\nis not complete; never hide failure in prose or silently exit.\n\nAppend `--files-modified` or `--report-path` only when applicable, using actual\npaths. Do not send documentation placeholders as metadata.\n\n```text\nORCA orchestration send --from --dispatch-capability --type worker_done --subject \"\" --body \"\" --task-id --dispatch-id --outcome succeeded\n```\n\nAfter `worker_done`, end the dispatched turn and idle. Do not poll, close your\nown terminal, or begin unrelated work. A later direct user instruction is new\nuser-owned work and must not reuse settled lifecycle IDs; a supervised follow-up\narrives with a fresh preamble and Task block.\n" +const ORCHESTRATION_FULL_MARKDOWN = "---\nname: orchestration\ndescription: >-\n Coordinate supervised Orca workers: threaded messages, blocking ask/reply,\n task dispatch, worker_done/escalation waits, task DAGs, decision gates,\n coordinator loops, and decomposing work across agents. Use `orca-cli` for full\n ownership handoffs — \"hand off\", \"handoff\", \"handover\", \"give this to another\n agent\", \"another worktree\" — unless asked to supervise, monitor, or coordinate\n a DAG, and for terminal control, lightweight terminal prompts, shell commands,\n Orca worktree management, and reading or waiting on terminals. Use Computer\n Use for external browser windows, webviews, Orca app UI, or desktop UI outside\n Orca's embedded browser only when the task requires OS/window-level control\n such as focus, menus, dialogs, coordinates, or screenshots. Use `orca-cli` for\n Orca's embedded pages and a page-automation tool such as Playwright or CDP for\n external pages.\n---\n\n# Orca orchestration\n\nOrchestration is Orca's structured coordination layer. It records who owns work,\nwhich attempt is authoritative, and when supervised work has settled.\n\n## Outcome\n\n**Result:** every in-scope Task has one explicit outcome and every settled worker\nterminal has a next owner or cleanup decision. **Next consumer:** the user who\nrequested supervision. **Done:** all expected Dispatches have settled, every\ndelivered message was processed before acknowledgment, each settled worker was\nreused, explicitly retained, or released, and the turn ends only when the report\nto that user names, per Task, its outcome, the evidence behind it, and any\nunresolved blocker.\n\n**Safe failure:** preserve work and authority and report the state as unknown or\n`unverifiable`. Only positive proof of exit authorizes stop, abandon, or retry,\nand only an accepted settlement authorizes release. Every other observation,\nabsence included, is a checkpoint.\n\n## Classify the role\n\n| Current context | Role | Route |\n| ---------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------- | ------------------------------------------------------------------------------ |\n| The user explicitly asks to supervise, monitor, wait for results, track completion, coordinate a DAG, use a decision gate, or manage ask/reply | Coordinator | Use the supervised loop below |\n| The current prompt contains a live injected preamble with Task and Dispatch IDs | Dispatched worker | Follow the preamble and the worker obligations below |\n| The user asks to hand off ownership or start another agent/worktree without supervision | Handoff owner | Use `orca-cli`; create no Run, Task, or Dispatch and do not monitor completion |\n| A message carries a legacy authority label | Compatibility operator | Load the legacy contract reference before any lifecycle mutation |\n| No live preamble and no explicit supervision | Ordinary terminal agent | Do not emit lifecycle messages; use `orca-cli` for terminal/worktree work |\n\nModel or effort selection does not make a handoff supervised. Never substitute a\nnon-Orca subagent tool when Orca orchestration provenance was requested.\n\n## Authority and safety floor\n\n- A Run is a durable namespace and coordinator inbox; it does not schedule or\n place workers. A Task is work. A Dispatch is one authoritative Task attempt.\n- Lifecycle authority comes from the active Dispatch, not a terminal title,\n copied ID, old database row, provider transcript, or visible pane.\n- Workers use the exact executable, handle, capability, Task ID, and Dispatch ID\n in the live preamble. Never reconstruct, translate, or broaden those arguments.\n- After remote start, address the worker by Dispatch ID. The execution host owns\n process, filesystem, transcript, stop, and cleanup facts. Preserve the verdicts\n `live` / `unverifiable` / `exited`; contact loss is not process death.\n- Liveness is layered: `worker-list`'s `projection.liveness` is the fleet verdict\n for the agent; `worker-show`'s `observation.status` is PTY liveness only. A live\n terminal can still hold a dead or stuck agent.\n- Folder workspaces are valid; never require Git or assume a worktree.\n- Clients and remote servers update independently. Treat unknown optional fields\n as absent. A new stream operation requires advertised capability because old\n decoders may silently drop unknown opcodes. Never fall back to local execution\n when remote authority or capability is unproven.\n- Use the executable you used to run `skills get` for the entire run. In the\n examples below, replace `ORCA` with it; do not create a shell variable or run\n `ORCA` literally. If it fails, report that exact error instead of switching.\n- A successful `orchestration send` proves durable enqueue; its wake or nudge is\n best-effort attention only and does not prove the recipient read or accepted it.\n\n## Worker obligations\n\nThe injected preamble is authoritative. A dispatched worker must:\n\n1. Do only the current Task and use the preamble's `ask` command for a blocking\n coordinator question. Never open a local question TUI the coordinator cannot\n answer. Resume the same message ID after an ask timeout.\n2. Send heartbeats only at the cadence in the preamble. A heartbeat proves\n liveness, not completion.\n3. Read coordinator follow-ups at each natural checkpoint — before starting a\n new file, after a test run — and once more immediately before `worker_done`:\n `ORCA orchestration check --terminal --json`.\n4. Send `worker_done` exactly once, from the dispatched terminal, with a\n three-sentence executive summary, both lifecycle IDs, and explicit\n `--outcome succeeded` or `--outcome failed`. Never encode failure only in prose.\n5. Append `--files-modified` and `--report-path` only with real values when\n applicable. After `worker_done`, end the dispatched turn and idle; do not poll\n or start new work.\n\nA direct user instruction after completion starts new user-owned work and takes\nprecedence over the idle rule. Do not reuse the settled lifecycle IDs.\n\n## Canonical supervised loop\n\nConfirm the runtime, bind one Run, and start the full independent wave before\nwaiting. `worker-start --spec` creates the Task and its attempt in one call:\n\n```text\nORCA status --json\nORCA orchestration run-create --objective \"\" --json\nORCA orchestration worker-start --spec \"\" --worktree current --agent codex --json\nORCA orchestration worker-start --spec \"\" --worktree current --agent claude --json\nORCA orchestration check --wait --types \"worker_done,escalation,question\" --timeout-ms 900000 --json\n```\n\nIf `worker-start` exits non-zero, do not relaunch. Read the receipt's\n`failedStage` and `residualResources`, then load\n`references/recovery-and-cleanup.md`.\n\nUse `task-create` plus `worker-start --task ` for planned fan-out with\ndependencies or a retry of a known Task. Use dependencies only for real ordering\nand prefer parallel waves over chains deeper than three or four steps; nested\nworkers obey the depth limit, and a new Run does not reset the caller's depth.\n\nA consuming `check` names its caller with `--terminal `, never `--from`;\nomit it inside the coordinator's own Orca terminal. It returns the bound Run's\noldest FIFO Delivery and replays that batch until acknowledged. Process every\nmessage: reply to questions, validate each `worker_done` against the expected\nactive Dispatch, and decide each settled terminal's next owner before the ack:\n\n```text\nORCA orchestration reply --id --body \"\" --json\nORCA orchestration worker-release --dispatch --json\nORCA orchestration check --ack --wait --types \"worker_done,escalation,question\" --timeout-ms 900000 --json\n```\n\nKeep waiting until every expected Dispatch settles. A timeout or empty result is\na checkpoint, not a failure. Do not stop, retry, release, or launch a duplicate\neditor without the positive proof `## Outcome` requires.\n\nAfter three consecutive empty waits, stop waiting blindly and enumerate with\n`ORCA orchestration worker-list --include-remote --json` (defaults to the bound\nRun; `--run ` overrides; the receipt's `scope` names which), acting on\neach row's `projection.attention` categories, `projection.attention.requiresAction`, and literal `projection.nextAction` argv.\nA `none` `nextAction` has no argv to run: read `liveness.reason` and keep waiting\nwith `check --wait`. Absence never earns an argv; settlement and pending work still do.\nLeave the wait only on positive proof the agent stopped: `exited` liveness, the\nworker's own observation of process exit, or a transcript whose final agent turn\nsent no `worker_done`. Then load `references/recovery-and-cleanup.md` and choose\n`worker-stop` or `worker-abandon` explicitly. `unverifiable` is absence,\nincluding when `worker-show` reports `agentWait` null. Absence never authorizes\nstop, abandon, retry, or release; keep waiting or inspect.\n\n`worker-start` is the normal path, composing placement, terminal readiness,\nprompt injection, and supervised resource ownership. `dispatch --inject` leaves\nan operator-created process unsupervised and is only for an expressiveness gap.\n\n## Task-spec contract\n\nEvery Task spec must be self-contained and name:\n\n- **Target:** the files, component, or environment in scope.\n- **Change:** the concrete result to produce.\n- **Constraints:** invariants, compatibility rules, and do-not-touch boundaries.\n- **Ownership:** what this worker may edit and any coordination boundary.\n- **Observable acceptance:** the test, output, or evidence that proves completion.\n\n## Completion accounting\n\nAfter an accepted success or failure report, immediately do exactly one:\n\n1. Reuse the same proven agent terminal for an immediate follow-up Dispatch.\n2. Record user-requested retention with `worker-retain`.\n3. Run `worker-release`.\n\nRelease is post-settlement cleanup, not cancellation. Only an accepted\nsettlement authorizes it; no other observation does. If release is uncertain,\nfollow its exact recovery receipt and never substitute `terminal close`.\n\nA valid `worker_done` settles the Task and Dispatch automatically; do not follow\nit with `task-update --status completed`. Enumerate the terminals still owing a\ndecision with `worker-list --run --terminal-state reclaimable --json`,\nand do not end the coordinator turn until it returns none.\n\n## Conditional references\n\nThis compact guide is sufficient for the normal local loop. At an action gate\nbelow, run `ORCA skills get orchestration --reference references/.md` and\nread only that document; `--references` lists the names. If the CLI rejects\n`--reference`, run `ORCA skills get orchestration --full` once instead: it\nreturns this exact kernel and every reference, so read only the named one. If an\nolder CLI rejects `--full`, keep this kernel's safety floor, use that command's\n`--help`, and never guess newer flags.\n\n| Action gate | Bundled reference |\n| ------------------------------------------------------------------------------------------------------------- | ----------------------------------------- |\n| Expanded DAG waves, launch model/effort, same-terminal reuse, or review ownership | `references/coordinator-loop.md` |\n| You are a dispatched worker and the live preamble does not answer your question, or `check` returned an error | `references/worker-contract.md` |\n| New worktree, exact workspace, SSH, WSL, or connected-server placement | `references/placement-and-remote.md` |\n| Inbox replay, follow-up messages, group addresses, or decision gates | `references/messaging-and-gates.md` |\n| Failed/stopped/unknown attempts, retry, stop, abandon, retain, or uncertain release | `references/recovery-and-cleanup.md` |\n| Custom argv or terminal topology that `worker-start` cannot express | `references/low-level-topology.md` |\n| Any legacy label, adopted Run, compatibility receipt, or takeover | `references/legacy-contract-migration.md` |\n\nRetired scheduler commands are not aliases for Run creation. Recovery commands\nmust provide their exact next action; follow it with the same selected executable.\n\n---\n\n# Bundled references\n\nThese references belong to the version-matched guide above. Read only the documents named by its action gates.\n\n\n\n# Coordinator loop\n\nLoad this reference for expanded DAG waves, per-invocation launch preferences,\nsame-terminal reuse, or review ownership. The compact guide remains the source\nof truth for the loop order and completion boundary.\n\n## Ready waves\n\nCreate independent Tasks before the first wait. Encode only real dependencies,\nthen use the ready view as external memory:\n\n```text\nORCA orchestration task-create --spec \"\" --deps --json\nORCA orchestration task-list --ready --brief --json\n```\n\n`--brief` collapses whitespace and caps echoed specs at 160 characters;\n`spec_truncated` identifies shortened rows. Omit it when full specs are needed or\nwhen an older CLI rejects the flag. A nested worker must respect\n`nested_worker_depth_exceeded`; creating another Run does not reset depth.\n\n## Launch preferences\n\nFor a fresh Claude, Codex, or Cursor terminal, `--model` accepts an opaque\nprovider model ID. Pass it only when the user named a model; otherwise omit it\nso the worker inherits the user's configured agent default. Add `--effort` only\nwhen that model supports it:\n\n```text\nORCA orchestration worker-start --task --worktree current --agent claude --model opus --effort high --json\n```\n\n`--effort` requires `--model`; neither option combines with `--terminal`. A\nconnected worker server must advertise launch-preference support before Orca\nforwards either field. Compare `launch.requested` with `launch.effective`; never\nclaim a model or effort from requested arguments alone.\n\n## Reuse after settlement\n\nChoose the terminal's next owner before acknowledging the Delivery. When the\nsame exact agent has immediate follow-up work, recover the proven handle and\ntransfer cleanup ownership to the new Dispatch:\n\n```text\nORCA orchestration worker-show --dispatch --json\nORCA orchestration worker-start --task --terminal --json\n```\n\nOtherwise explicitly retain or release the settled worker. Do not leave it live\nonly to inspect output; archived output remains available through `worker-read`.\n\n## Review ownership\n\nA review-only `worker_done` authorizes synthesis of findings, not coordinator\nfile edits. Dispatch or hand off fixes unless the user explicitly assigned them\nto the coordinator. If the user's plan names a next owner, post-review fixes and\nPR preparation remain with that owner; the coordinator routes and synthesizes.\n\n\n\n# Legacy contract migration\n\nLoad this reference only for an authority label, adopted Run, compatibility or\nrecovery receipt, or explicit legacy takeover. A newly created attempt always\nuses the current grammar.\n\n## Authority labels\n\n- `[LEGACY COMPATIBILITY]` is live and attested. Run only the exact supported\n command printed with the message, using the same selected executable and\n arguments supplied by the original prompt.\n- `[LEGACY RECOVERY REPLAY — MAY HAVE BEEN SEEN]` is one bounded,\n at-least-once cutover replay. Process it idempotently and acknowledge only\n through the exact displayed guidance.\n- `[LEGACY READ-ONLY]` is inspection-only. It has no reply, acknowledgment, or\n lifecycle mutation.\n- An unlabeled current message uses the current guide and grammar.\n\nAn explicitly selected current Run, attested current binding, current Dispatch,\nor federated attachment takes precedence over legacy fallback. A retained\nadoption record alone does not grant mutation authority. If liveness, principal\nownership, capability, or the exact legacy contract is unproven, degrade to\nread-only inspection and never fall back to local execution.\n\nAdoption preserves the live agent process, PTY/session, terminal handle,\ntab/pane, worktree or folder workspace, Task, and Dispatch. It never restarts or\nreplaces the worker and never revives the retired scheduler. Loss of lifecycle\nauthority does not invalidate the existing process, assignment, or filesystem\nwork. Exact recovery may restore the same PTY once in its original inactive\nbackground tab; it must not spawn, write, signal, stop, switch, focus, split, or\ninject a terminal.\n\n## Compatibility recovery\n\nWhen a compatibility response returns structured next-step arguments, execute\nthose exact arguments with the same selected CLI executable. Do not translate\nfrom memory, broaden the recipient, or retry as a current mutation unless the\nreceipt explicitly authorizes it.\n\nA pending ask, reply, final Dispatch settlement, and consuming check have\ndurable recovery identities. Heartbeat and escalation remain at-least-once\nacross a manual contract-boundary retry. If an ask may already have been\nanswered, run the exact non-consuming recovery check printed by Orca before\ncreating any new question. Never guess among identical question threads.\n\nOn packaged Windows, a legacy ask uses a two-step commit/resume protocol. The\ninitial command commits the question, prints its exact\n`ask --resume ` command, and exits with launcher status `75`. Run\nthat exact resume after the launcher or update boundary. For an attested WSL\nlaunch, preserve the printed `orca-ide` executable and distro route. Older WSL\nworkers without launch proof remain lifecycle read-only even while their\nterminal and filesystem work continue.\n\n## Read-only inspection and takeover\n\nRead-only inspection does not consume mail:\n\n```text\nORCA orchestration run-list --json\nORCA orchestration run-show --id run_legacy_local --json\nORCA orchestration run-show --id --json\nORCA orchestration task-list --run --json\nORCA orchestration inbox --full --json\nORCA orchestration check --terminal --peek --format --json\nORCA terminal read --terminal --json\nORCA terminal wait --terminal --for tui-idle --timeout-ms 60000 --json\n```\n\n`run_legacy_local` is an empty audit tombstone after adoption. Find the ordinary\nRun whose objective is `Recovered orchestration work from a contract update`.\n\nOnly when the original coordinator is unavailable or cannot prove retained\nauthority may a new live coordinator take over from its own terminal:\n\n```text\nORCA orchestration run-use --id --takeover-legacy --json\nORCA orchestration check --run --json\n```\n\nTakeover binds the authenticated invoking terminal; `--from` cannot nominate\nanother coordinator. It fences only the old coordinator and moves pending mail\ninto current Run delivery. It preserves live workers, Tasks, Dispatches, processes, and files.\nNever take over while the original coordinator is actively coordinating.\n\nDo not launch a replacement editor merely because Orca updated or authority is\nunclear. Keep the original worker as the only editor until a stable handoff\npoint, then use a fresh current Dispatch in a conflict-free placement.\n\n\n\n# Low-level topology\n\nLoad this reference only when `worker-start` cannot express required custom argv\nor terminal topology. It is not the normal supervised loop and is never a full\nhandoff recipe.\n\n```text\nORCA terminal create --worktree active --title --command \"\" --json\nORCA terminal wait --terminal --for tui-idle --timeout-ms 60000 --json\nORCA orchestration dispatch --task --to --inject --json\n```\n\nWait for readiness only when startup could lose injected input. Prefer\nagent-first `worker-start` whenever its argv and topology are sufficient.\n\n`dispatch --inject` creates authoritative Task/Dispatch context but deliberately\nkeeps an operator-created process unsupervised: it creates no supervised worker\nresource row. `worker-show`, `worker-read`, and `worker-list` report the lane as\n`unsupervised`; `worker-stop` and `worker-abandon` do not close that process, and\nsettled retain/release take no process action.\n\nUse `worker-start --terminal ` when lifecycle ownership of an existing\nagent terminal is required. Never imply that low-level dispatch retroactively\nowns a process, never use it to route around the nested-depth limit, and never\nuse it for an ownership handoff.\n\n\n\n# Messaging and gates\n\nLoad this reference for inbox replay, attempt-specific guidance, group\naddresses, blocking questions, or coordinator-managed DAG decisions.\n\nA successful `send` proves durable enqueue. Wake and nudge are best-effort\nattention only: neither proves the recipient read the message, began a turn, or\naccepted steering.\n\n## Coordinator delivery loop\n\n`check` names its caller with `--terminal ` and is the only verb that\nrejects `--from`. Omit `--terminal` inside an Orca terminal, where Orca resolves\nthe caller; pass it explicitly from anywhere else, including a dispatched\nworker reading coordinator follow-ups.\n\nA consuming coordinator `check` returns the bound Run's oldest FIFO Delivery,\nup to 50 messages, and replays that exact batch until acknowledged. Process\nevery row and required terminal ownership decision before `--ack`. Type filters\ndecide when a waiter wakes; they do not authorize skipping older actionable\nmail. A Delivery therefore always carries the whole FIFO batch whatever its\ntypes, and a `check` without `--wait` hands that batch over unfiltered.\n`--peek` and `--all` are read-only inspection, not progress through the\ncoordinator inbox.\n\nAn empty wait or timeout is a checkpoint. Continue rolling waits until every\nexpected Dispatch settles. Heartbeat or visible activity means alive, not done.\n\n## Addresses\n\nUse a stable Dispatch address for attempt-specific coordinator guidance:\n\n```text\nORCA orchestration send --to dispatch: --subject \"Follow-up\" --body \"\" --json\n```\n\nDo not substitute a remote terminal handle. Omit `--from` for ordinary\ncoordinator calls; a dispatched worker instead copies the exact `--from` and\ncapability arguments in its preamble. `check` is the exception: it identifies\nits caller with `--terminal`, never `--from`.\n\nGroup addresses include `@all`, `@idle`, `@claude`, `@codex`, `@opencode`,\n`@gemini`, `@droid`, `@grok`, `@cursor`, and `@worktree:`. Use them only for\nintentional fan-out status or questions. `worker_done`, heartbeat, and other\nDispatch lifecycle messages never target groups.\n\n## Questions and gates\n\nA worker uses `ask`; its timeout leaves one durable question pending, which the\nworker resumes by message ID. The coordinator answers that message with `reply`.\n\nUse a gate only for a coordinator-owned Task-DAG decision:\n\n```text\nORCA orchestration gate-create --task --question \"\" --options --json\nORCA orchestration gate-resolve --id --resolution \"\" --json\nORCA orchestration gate-list --task --json\n```\n\nPass `json_array` using the quoting rules of the active shell; do not copy POSIX\nsingle-quote syntax into PowerShell or `cmd.exe`.\n\nDo not create a gate merely to answer a worker's `ask`.\n\n\n\n# Placement and remote execution\n\nLoad this reference before creating a new worktree or placing work through SSH,\nWSL, or another connected Orca server.\n\n## Placement choices\n\nA fresh worker means a fresh agent terminal, not a new Git worktree. Use the\ncurrent or an exact existing workspace by default. Create a worktree only when\nthe user requested one or a concrete checkout or filesystem conflict makes\nsharing unsafe.\n\n```text\n# Current workspace; setup is not rerun.\nORCA orchestration worker-start --task --worktree current --agent codex --json\n\n# Stacked child worktree.\nORCA orchestration worker-start --task --worktree new-child --name --agent codex --setup run --json\n\n# Independent top-level worktree.\nORCA orchestration worker-start --task --worktree new-top-level --name --agent codex --setup run --json\n```\n\nCurrent and exact existing workspaces create a fresh terminal unless\n`--terminal` is explicit. Folder workspaces are first-class; do not invoke Git\nor require worktree lineage when the selected workspace is a folder.\n\nRegister a folder workspace through project setup. `repo add --path `\nrequires a valid Git repository and rejects a plain directory:\n\n```text\nORCA project setup-existing-folder --project --host --path --kind folder --json\n```\n\nThen place work on the returned workspace with an exact selector. A worktree\nselector needs the full `::` value Orca returned, passed as\n`id:`; a bare repo id is not a worktree id. `new-child` and\n`new-top-level` are worktree creation and do not apply to a folder.\n\nNew worktrees use agent-first creation and run setup by default. Preserve the\nrepository's startup policy: `start-immediately` can report setup as `running`,\nwhile `wait-for-setup` gates prompt delivery on success. Orca lineage, Git base,\nfilesystem isolation, coordination parentage, UI grouping, and execution host\nare separate decisions.\n\n## Connected servers\n\nThe Run and Tasks remain authoritative on the current server. `--on` selects\nonly the worker's execution server and appears only on `worker-start`:\n\n```text\nORCA orchestration worker-start --task --on --worktree new-top-level --repo --name --agent codex --setup run --json\n```\n\nRemote `current` and `new-child` are invalid because they are ambiguous across\nservers. Use an exact discovered remote workspace, or `new-top-level` with an\nexact remote repository selector. After start, route every follow-up, read,\nstop, and cleanup by Dispatch ID; never repeat `--on` or substitute a remote\nterminal handle.\n\n```text\nORCA orchestration worker-show --dispatch --json\nORCA orchestration worker-read --dispatch --limit 50 --json\nORCA orchestration send --to dispatch: --subject \"Follow-up\" --body \"\" --json\nORCA orchestration worker-list --run --include-remote --json\n```\n\n`worker-list` reads local fleet state only; enumerate remote workers with\n`--include-remote` or every one of them reads `unverifiable`. Scope every list\nwith `--run `: unscoped, it reports every Dispatch this runtime has\nrecorded, and the workers you are waiting on are lost in that history.\n\n## Execution-host and mixed-version floor\n\nThe execution host owns process, filesystem, transcript, stop, and cleanup\nfacts. Render only `live`, `unverifiable`, or `exited`. Connection loss, relay\nabsence, missing client inventory, or timeout yields `unverifiable`, never\nsynthetic exit and never a client-local substitute action.\n\nClients and servers update independently. Optional response fields may be\nabsent. Forward model/effort, transcript reads, cleanup, or another new remote\noperation only when the peer advertises the relevant capability; unknown stream\nopcodes can be silently dropped. A narrow unsupported response may degrade to a\ndocumented older path, but must not broaden the target or cross the execution\nboundary. Changing host-published content reaches old clients even without a\nwire-shape change, so preserve established semantics or negotiate the behavior.\n\nFor WSL, use the exact executable and arguments returned by Orca so the distro\nand packaged launcher remain bound. Do not translate a printed `orca-ide`\nrecovery command into a PATH-resolved local command.\n\n\n\n# Recovery and cleanup\n\nLoad this reference only after a failed/stopped/unknown attempt, explicit retry\ndecision, stop/abandon request, retention request, or uncertain release.\n\n| Proven state | Safe action |\n| ----------------------- | ------------------------------------------------------------------ |\n| `ready` or active | Keep waiting; optionally read bounded output |\n| `failed` or `stopped` | Start a replacement with `--retry-of`; repeat placement explicitly |\n| `outcome_unknown` | Inspect, then choose `worker-stop` or explicit `worker-abandon` |\n| Accepted `worker_done` | Reuse, retain, or release |\n| Remote contact lost | Preserve `unverifiable`; do not stop or retry from absence alone |\n| `unverifiable` liveness | Keep waiting or inspect; never stop, abandon, retry, or release |\n| Proven `exited` agent | Enumerate with `worker-list`; follow its `nextAction` |\n\n## Inspect before acting\n\n```text\nORCA orchestration worker-list --run --json\nORCA orchestration worker-list --run --include-remote --json\nORCA orchestration worker-show --dispatch --json\nORCA orchestration worker-read --dispatch --limit 50 --json\n```\n\n`worker-list` is the enumerating command and the authority on agent liveness:\neach row carries `projection.liveness`, `projection.attention.categories`,\n`projection.attention.requiresAction`, and a literal `projection.nextAction`\nargv to run. Always scope it with `--run `; an unscoped list reports\nevery Dispatch this runtime has ever recorded and buries the live ones.\n`worker-show`'s `observation.status` is PTY liveness only, so a `live` terminal\nwhose agent died at a trust prompt still reads `live` there.\n\nWhen the two disagree, the fleet verdict decides — unless the fleet row is\n`unverifiable` for a reason that names a gap on this client rather than a fact\nabout the worker. `missing_status`, `host_unavailable`, and\n`capability_unsupported` are such gaps: the first means this runtime holds no\nstatus row, the second that it could not ask the execution host at all, and the\nthird that a stale peer answered but lacks the fleet-snapshot capability.\nAgainst any of them, a `worker-show` verdict sourced from the execution host is\nthe better evidence and outranks the row. Only `host_unavailable` is contact\nloss; the other two mean the host was never asked or answered without the\ncapability.\n\nThis never promotes absence. `unverifiable` from either command still authorizes\nnothing — only a positive `live` or `exited` verdict does.\n\nA worker started with `--on ` reads `unverifiable` until you\nenumerate with `--include-remote`, which asks its execution host for the\nverdict. Past 100 rows the response pages, so follow `page.nextCursor` with\n`--cursor ` until `page.hasMore` is false.\n\n## Stall needs positive evidence\n\nLeave the wait only on positive proof the agent stopped: `exited` liveness, the\nworker's own observation of process exit, or a transcript whose final agent turn\nsent no `worker_done`. Only then choose `worker-stop` or `worker-abandon`.\n\n`unverifiable` is always absence — `missing_status`, `stale_status`,\n`restored_unconfirmed`, or a remote worker with no connection — and a null\n`agentWait` or an unchanged `worker-read` tail is that same absence seen again.\nAbsence never authorizes stop, abandon, retry, or release: keep waiting, or\ninspect until you hold one of the positive signals above. A `nextAction` that\nnames an inspecting command is asking for evidence, not for cleanup.\n\n`worker-read --source auto` uses a proven provider transcript when available and\notherwise returns bounded terminal output with a typed `fallbackReason`.\nContinue with its top-level cursor, which is pinned to that source. If Orca\nreports `source_changed`, restart without the old cursor. A bounded initial\ntranscript tail can return an EOF cursor that follows only newly appended records;\nread `contentComplete`, `clipping`, and `warnings` before assuming omitted older\nrecords are pageable. Never guess a provider session ID, transcript path, or\nremote terminal handle.\n\n## Was the mutation applied?\n\nWhen a mutation's response was lost and named no Dispatch, do not replay blind.\nEvery orchestration mutation accepts `--retry-request `, which reuses one\noperation identity so Orca can replay, join, or recover it instead of starting a\nduplicate. Ask what happened first:\n\n```text\nORCA orchestration request-show --request --json\n```\n\n`completed` means the mutation already took effect; read its recorded receipt\ninstead of rerunning. `pending` means the original mutation is still running or\nOrca restarted before recording its outcome; replay the original command with\n`--retry-request `. `absent` means this runtime holds no receipt\nunder your caller identity — that is not proof nothing happened, so inspect the\naffected Task, Dispatch, and terminal before deciding whether to retry.\n\nWhen a worker's terminal accepted input but the submit is unconfirmed, use\n`terminal send --wait-submit `: it observes the accepted prompt for that\nlong and, on timeout, returns the input-accepted receipt without resending.\n\n## Refused starts\n\n`dispatch` and `worker-start` refuse the following preflight cases with a stable\n`error.code`; read it before choosing a recovery, and treat `error.data.nextSteps`\nas the exact recovery text. Older hosts may omit `data`, so treat every field as\noptional.\n\n| Code | Meaning | Recovery |\n| -------------------- | --------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |\n| `task_not_found` | No Task with that id, or not in the bound Run (`data.taskId`, `data.runId`) | Check `task-list --json`; create the Task with `task-create` if it does not exist |\n| `task_not_startable` | Task cannot start now: not `ready`, or invalid `--retry-of` (`data.status`, `data.unmetDependencies`, `data.retryOf`) | Wait for running dependencies with `check --wait`; retry or unblock failed ones; inspect `dispatch-show` if already dispatched |\n| `inject_rejected` | `--inject` refused because no recognized agent runs in the target (`data.terminal`, `data.reason`) | Start a recognized agent there or pick another terminal; or dispatch without `--inject` and use `terminal send` |\n| `runtime_error` | Any other failure, including a target terminal that already owns an active Dispatch | Read the message, inspect state, and do not retry unchanged |\n\n## Retry, stop, and abandon\n\nRetry only a positively proven failed or stopped attempt. Name the failed Task\nwith `--task`, since `--spec` creates a new one. Placement is never silently\ninherited:\n\n```text\nORCA orchestration worker-start --task --retry-of --worktree --agent --json\n```\n\nAfter three consecutive failures for one Task, its dispatch context\ncircuit-breaks and the Task is failed. Do not route around that boundary with a\nnew Run or an unrelated Dispatch.\n\nFor `outcome_unknown`, inspect first, then make an explicit choice:\n\n```text\nORCA orchestration worker-stop --dispatch --json\nORCA orchestration worker-abandon --dispatch --json\n```\n\n`worker-stop` closes only the exact proven supervised agent terminal. It never\ndeletes the worktree, setup terminal, configured tabs, or unrelated processes.\n`worker-abandon` fences orchestration while accepting that resources may remain\nlive; it performs no remote, process, or filesystem action.\n\n## Retain and release\n\n```text\nORCA orchestration worker-retain --dispatch --json\nORCA orchestration worker-release --dispatch --json\n```\n\nRetain only when the user explicitly wants the settled terminal kept live.\nRelease works after succeeded and failed reports, archives readable output, and\ncloses only the exact terminal owned by that settled Dispatch. Replays may call\nrelease again safely. Reused, pre-existing, setup, coordinator, active,\nuser-taken-over, and unproven terminals are retained.\n\nA `worker-start` that failed before its agent was ready still owns the terminal\nit created. Its receipt names `worker-release`, and `worker-list` reports that\nrow as `reclaimable`; release it there rather than closing the terminal by hand.\n\nNever release because of timeout, TUI idle, heartbeat, status, question,\nescalation, or stale/rejected completion. If the receipt says `release_pending`\nor `release_unknown`, follow its exact recovery action. Never substitute\n`terminal close`.\n\n`orchestration reset` is destructive recovery. Do not run it during active\ncoordination unless the user explicitly abandons that state.\n\n\n\n# Worker contract\n\nThe injected preamble is authoritative. Copy its command rather than\nreconstructing flags. In particular, preserve the exact executable, worker\nhandle, Dispatch capability, Task ID, and Dispatch ID.\n\n## Heartbeat\n\nSend heartbeats only at the cadence required by the live preamble. Skip them\nwhile blocked inside `ask` or `check --wait`; those calls are liveness signals.\n\n```text\nORCA orchestration send --from --dispatch-capability --type heartbeat --subject \"alive\" --task-id --dispatch-id --phase \"\"\n```\n\nUse typed lifecycle flags, not a hand-written JSON payload. A heartbeat proves\nliveness, never completion.\n\n## Ask and resume\n\nUse Orca `ask` whenever the coordinator must answer. Never open a local question\nTUI the coordinator cannot answer.\n\n```text\nORCA orchestration ask --from --dispatch-capability --question \"\" --options \",\" --timeout-ms 600000\n\nORCA orchestration ask --from --dispatch-capability --resume --timeout-ms 600000\n```\n\nA timeout or disconnect leaves the original question pending. Resume its\nmessage ID; do not create a duplicate question.\n\n## Reading coordinator follow-ups\n\nThe coordinator steers a running worker with `send --to dispatch:`. That\nenqueue is durable but does not interrupt you, so nothing arrives unless you\nlook:\n\n```text\nORCA orchestration check --terminal --json\n```\n\nRun it at each natural checkpoint — before starting a new file, after a test\nrun — and once more immediately before `worker_done`, so a redirect or a\ncancellation lands before the Task settles. `check` names its caller with\n`--terminal`, never `--from`. Stop checking after `worker_done`.\n\nIf `check` returns `consumer_fenced`, this process no longer owns its Dispatch:\nthe Attempt was re-attached to another worker or settled without you. Stop, do\nnot send `worker_done`, and do not retry the check. An empty `check` never means\nyou were replaced; `consumer_fenced` is the only way you learn that.\n\n## Escalation\n\nEscalate only before completion and only when the coordinator must intervene:\n\n```text\nORCA orchestration send --from --dispatch-capability --type escalation --subject \"Blocked: \" --body \"
\" --task-id --dispatch-id \n```\n\n## Completion\n\nSend exactly one terminal report. `--body` is three sentences: what changed,\nwhat was found, and what remains. Use `--outcome failed` when the requested work\nis not complete; never hide failure in prose or silently exit.\n\nAppend `--files-modified` or `--report-path` only when applicable, using actual\npaths. Do not send documentation placeholders as metadata.\n\n```text\nORCA orchestration send --from --dispatch-capability --type worker_done --subject \"\" --body \"\" --task-id --dispatch-id --outcome succeeded\n```\n\nAfter `worker_done`, end the dispatched turn and idle. Do not poll, close your\nown terminal, or begin unrelated work. A later direct user instruction is new\nuser-owned work and must not reuse settled lifecycle IDs; a supervised follow-up\narrives with a fresh preamble and Task block.\n" // oxfmt-ignore const ORCHESTRATION_COORDINATOR_LOOP_REFERENCE_MARKDOWN = "# Coordinator loop\n\nLoad this reference for expanded DAG waves, per-invocation launch preferences,\nsame-terminal reuse, or review ownership. The compact guide remains the source\nof truth for the loop order and completion boundary.\n\n## Ready waves\n\nCreate independent Tasks before the first wait. Encode only real dependencies,\nthen use the ready view as external memory:\n\n```text\nORCA orchestration task-create --spec \"\" --deps --json\nORCA orchestration task-list --ready --brief --json\n```\n\n`--brief` collapses whitespace and caps echoed specs at 160 characters;\n`spec_truncated` identifies shortened rows. Omit it when full specs are needed or\nwhen an older CLI rejects the flag. A nested worker must respect\n`nested_worker_depth_exceeded`; creating another Run does not reset depth.\n\n## Launch preferences\n\nFor a fresh Claude, Codex, or Cursor terminal, `--model` accepts an opaque\nprovider model ID. Pass it only when the user named a model; otherwise omit it\nso the worker inherits the user's configured agent default. Add `--effort` only\nwhen that model supports it:\n\n```text\nORCA orchestration worker-start --task --worktree current --agent claude --model opus --effort high --json\n```\n\n`--effort` requires `--model`; neither option combines with `--terminal`. A\nconnected worker server must advertise launch-preference support before Orca\nforwards either field. Compare `launch.requested` with `launch.effective`; never\nclaim a model or effort from requested arguments alone.\n\n## Reuse after settlement\n\nChoose the terminal's next owner before acknowledging the Delivery. When the\nsame exact agent has immediate follow-up work, recover the proven handle and\ntransfer cleanup ownership to the new Dispatch:\n\n```text\nORCA orchestration worker-show --dispatch --json\nORCA orchestration worker-start --task --terminal --json\n```\n\nOtherwise explicitly retain or release the settled worker. Do not leave it live\nonly to inspect output; archived output remains available through `worker-read`.\n\n## Review ownership\n\nA review-only `worker_done` authorizes synthesis of findings, not coordinator\nfile edits. Dispatch or hand off fixes unless the user explicitly assigned them\nto the coordinator. If the user's plan names a next owner, post-review fixes and\nPR preparation remain with that owner; the coordinator routes and synthesizes.\n" diff --git a/src/main/agent-hooks/hook-stdin-contract.ts b/src/main/agent-hooks/hook-stdin-contract.ts index acba7927650..de77b2f3e9f 100644 --- a/src/main/agent-hooks/hook-stdin-contract.ts +++ b/src/main/agent-hooks/hook-stdin-contract.ts @@ -74,21 +74,38 @@ export const WINDOWS_HOOK_STDIN_DRAIN_LABEL = 'orca_agent_hook_drain_stdin' export const WINDOWS_HOOK_STDIN_READER = '"%SystemRoot%\\System32\\more.com"' export const WINDOWS_HOOK_STDIN_DRAIN_COMMAND = `${WINDOWS_HOOK_STDIN_READER} >nul 2>nul` +// The Orca context a hook needs before it may own stdin; see the rule below. +const WINDOWS_HOOK_ENVIRONMENT_VARS = [ + 'ORCA_AGENT_HOOK_PORT', + 'ORCA_AGENT_HOOK_TOKEN', + 'ORCA_PANE_KEY' +] as const + // Why (#11549): missing Orca context means the hook ran outside an Orca pane, where the caller // may abandon stdin rather than close it — a read-to-EOF then blocks forever and strands a // visible window per hook event. The Windows rule: a hook must check the Orca env before it // owns stdin, and exit without reading when the env is missing — the payload is discarded on -// that path anyway. This applies to .cmd, the copilot .ps1, and the Git Bash kimi .sh alike. +// that path anyway. This applies to .cmd, the copilot .ps1, and the Git Bash kimi .sh alike, +// and to the launchers that own stdin themselves when the managed script is missing. // POSIX hooks keep capture-first: their callers close stdin, and exiting mid-write there // surfaces as EPIPE the agent can see (#8110). export function buildWindowsHookEnvironmentGuardLines(): string[] { - return [ - 'if "%ORCA_AGENT_HOOK_PORT%"=="" exit /b 0', - 'if "%ORCA_AGENT_HOOK_TOKEN%"=="" exit /b 0', - 'if "%ORCA_PANE_KEY%"=="" exit /b 0' - ] + return WINDOWS_HOOK_ENVIRONMENT_VARS.map((name) => `if "%${name}%"=="" exit /b 0`) } +/** The same guard in sh, for the Git Bash hooks and launchers that run on Windows. + * Default-formed because a static hook precheck (Grok) rejects a bare reference it + * cannot resolve. POSIX hosts keep capture-first — this is the Windows rule only. */ +export const WINDOWS_GIT_BASH_HOOK_ENVIRONMENT_GUARD = `if ${WINDOWS_HOOK_ENVIRONMENT_VARS.map( + (name) => `[ -z "\${${name}-}" ]` +).join(' || ')}; then exit 0; fi` + +/** The same guard for a PowerShell hook or launcher. Anything that reaches + * `[Console]::In.ReadToEnd()` must run this first, or it inherits #11549. */ +export const WINDOWS_POWERSHELL_HOOK_ENVIRONMENT_GUARD = `if (${WINDOWS_HOOK_ENVIRONMENT_VARS.map( + (name) => `-not $env:${name}` +).join(' -or ')}) { exit 0 }` + export function buildWindowsHookStdinDrainEpilogue(): string[] { return [`:${WINDOWS_HOOK_STDIN_DRAIN_LABEL}`, WINDOWS_HOOK_STDIN_DRAIN_COMMAND, 'exit /b 0'] } diff --git a/src/main/agent-hooks/installer-utils.test.ts b/src/main/agent-hooks/installer-utils.test.ts index 215979206e9..cbe29ee1ca1 100644 --- a/src/main/agent-hooks/installer-utils.test.ts +++ b/src/main/agent-hooks/installer-utils.test.ts @@ -31,7 +31,10 @@ import { type HooksConfig } from './installer-utils' import { buildPosixAgentHookPostCommand } from './hook-post-command' -import { POSIX_HOOK_STDIN_DRAIN_COMMAND } from './hook-stdin-contract' +import { + POSIX_HOOK_STDIN_DRAIN_COMMAND, + WINDOWS_POWERSHELL_HOOK_ENVIRONMENT_GUARD +} from './hook-stdin-contract' import { wrapRuntimeHomeHookCommand } from './runtime-home-hook-command' let tmpDir: string @@ -618,7 +621,10 @@ function expectedDecodedWindowsHookCommand(scriptPath: string): string { // Why: the execution-policy bypass rides in the payload, not on the command // line, so the launcher cannot spell the AV-blocked flag triple (#16003). // Why: PowerShell progress CLIXML corrupts consumers that merge stderr into JSON stdout. - return `$ProgressPreference='SilentlyContinue'; try { Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass -Force -ErrorAction SilentlyContinue } catch {}; if (Test-Path -LiteralPath ${quoted} -PathType Leaf) { & ${quoted}; exit $LASTEXITCODE }; [Console]::In.ReadToEnd() | Out-Null; exit 0` + // Why the guard is spelled by import: the launcher owns stdin on the missing-script path, + // so it obeys the shared Windows rule (#11549), and re-typing it here would let the two + // drift back apart. + return `$ProgressPreference='SilentlyContinue'; try { Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass -Force -ErrorAction SilentlyContinue } catch {}; if (Test-Path -LiteralPath ${quoted} -PathType Leaf) { & ${quoted}; exit $LASTEXITCODE }; ${WINDOWS_POWERSHELL_HOOK_ENVIRONMENT_GUARD}; [Console]::In.ReadToEnd() | Out-Null; exit 0` } describe('wrapWindowsHookCommand', () => { @@ -640,15 +646,23 @@ describe('wrapWindowsHookCommand', () => { ) }) - it('emits fallback stdout when the managed script is missing', () => { - const command = wrapWindowsHookCommand( - 'C:\\hooks\\cursor-hook.cmd', - {}, - { fallbackStdout: '{"permission":"allow"}' } - ) - expect(decodeWindowsHookCommand(command)).toContain( - 'Write-Output \'{"permission":"allow"}\'; exit 0' + // Why the ordering matters: a gate event reads silence as deny (#2426), and outside an + // Orca pane the guard exits before the read — so an answer placed after the drain never + // reaches the agent at all when the caller abandons the pipe (#11549). + it('answers before it guards, and guards before it owns stdin', () => { + const decoded = decodeWindowsHookCommand( + wrapWindowsHookCommand( + 'C:\\hooks\\cursor-hook.cmd', + {}, + { fallbackStdout: '{"permission":"allow"}' } + ) ) + const answer = decoded.indexOf('Write-Output \'{"permission":"allow"}\'') + const guard = decoded.indexOf(WINDOWS_POWERSHELL_HOOK_ENVIRONMENT_GUARD) + const ownsStdin = decoded.indexOf('[Console]::In.ReadToEnd()') + expect(answer).toBeGreaterThan(-1) + expect(guard).toBeGreaterThan(answer) + expect(ownsStdin).toBeGreaterThan(guard) }) // Why: a user profile path like `C:\Users\Jane Doe` is the regression from diff --git a/src/main/agent-hooks/installer-utils.ts b/src/main/agent-hooks/installer-utils.ts index 8667c418492..a53721d42fe 100644 --- a/src/main/agent-hooks/installer-utils.ts +++ b/src/main/agent-hooks/installer-utils.ts @@ -16,6 +16,7 @@ import { grantDirAcl, isPermissionError } from '../win32-utils' import { resolveHooksJsonWritePath } from './hook-config-write-path' import { writeRollingFileBackup } from '../rolling-file-backup' import { wrapWindowsPowerShellEncodedCommand } from './windows-powershell-hook-launcher' +import { WINDOWS_POWERSHELL_HOOK_ENVIRONMENT_GUARD } from './hook-stdin-contract' export type HookCommandConfig = { type: 'command' @@ -131,7 +132,10 @@ export function wrapWindowsHookCommand( options.fallbackStdout === undefined ? '' : `Write-Output ${quotePowerShellString(options.fallbackStdout)}; ` - const command = `${envPrefix}if (Test-Path -LiteralPath ${quoted} -PathType Leaf) { & ${quoted}; exit $LASTEXITCODE }; [Console]::In.ReadToEnd() | Out-Null; ${fallback}exit 0` + // Why the order: answer first (a gate event reads silence as deny), then the shared + // env guard, and only then own stdin — outside an Orca pane the caller may abandon the + // pipe, and ReadToEnd would strand the launcher there forever (#11549). + const command = `${envPrefix}if (Test-Path -LiteralPath ${quoted} -PathType Leaf) { & ${quoted}; exit $LASTEXITCODE }; ${fallback}${WINDOWS_POWERSHELL_HOOK_ENVIRONMENT_GUARD}; [Console]::In.ReadToEnd() | Out-Null; exit 0` return wrapWindowsPowerShellEncodedCommand(command) } diff --git a/src/main/agent-hooks/managed-hook-stdin-lifecycle.test.ts b/src/main/agent-hooks/managed-hook-stdin-lifecycle.test.ts index af70f6f54f0..dea4545ad11 100644 --- a/src/main/agent-hooks/managed-hook-stdin-lifecycle.test.ts +++ b/src/main/agent-hooks/managed-hook-stdin-lifecycle.test.ts @@ -63,12 +63,26 @@ import { KimiHookService } from '../kimi/hook-service' import { openClaudeHookService } from '../openclaude/hook-service' import { wrapPosixHookCommand, wrapWindowsHookCommand } from './installer-utils' -import { POSIX_HOOK_STDIN_READER } from './hook-stdin-contract' +import { + POSIX_HOOK_STDIN_READER, + WINDOWS_POWERSHELL_HOOK_ENVIRONMENT_GUARD +} from './hook-stdin-contract' import { wrapRuntimeHomeHookCommand } from './runtime-home-hook-command' import { createAgentHookMemorySftp } from './agent-hook-memory-sftp.test-fixture' import { findGitBash } from './windows-git-bash-path.test-fixture' +/** The launchers ship their command base64'd; assert the shape they actually run. */ +function decodeEncodedPowerShellCommand(command: string): string { + const encoded = command.match(/-EncodedCommand\s+(\S+)/) + expect(encoded, 'launcher carries an encoded command').not.toBeNull() + return Buffer.from(encoded![1], 'base64').toString('utf16le') +} + const REMOTE_HOME = '/home/dev' +// Why all three: Windows reports a write to a pipe whose reader is gone as any of these, +// depending on whether the read handle, the pipe, or the process went first. Enumerating +// them keeps the guard-exit legs from failing on which race the host happened to run. +const WRITER_BROKEN_BY_EARLY_EXIT = ['EPIPE', 'ECONNRESET', 'EOF'] const LARGE_PAYLOAD = Buffer.alloc(1_000_000, 'x') // Why: a developer box may set HKCU\...\Command Processor\AutoRun, which cmd.exe runs before any @@ -156,7 +170,10 @@ type HookRun = { function runHookProcess( executable: string, args: string[], - env: NodeJS.ProcessEnv + env: NodeJS.ProcessEnv, + // Why: `abandon` leaves the pipe open and unwritten — the shape a caller outside an Orca + // pane produces, and the only one that can catch a read-to-EOF that never returns (#11549). + stdin: 'close' | 'abandon' = 'close' ): Promise { return new Promise((resolve, reject) => { const child = spawn(executable, args, { env, stdio: ['pipe', 'pipe', 'pipe'] }) @@ -164,8 +181,9 @@ function runHookProcess( let stderr = '' let stdout = '' const timeout = setTimeout(() => { + child.stdin.destroy() child.kill('SIGKILL') - reject(new Error('hook did not finish after stdin closed')) + reject(new Error(`hook did not finish with stdin ${stdin}d`)) }, 10_000) child.on('error', (error) => { clearTimeout(timeout) @@ -182,7 +200,9 @@ function runHookProcess( clearTimeout(timeout) resolve({ exitCode, stdinErrors, stderr, stdout }) }) - child.stdin.end(LARGE_PAYLOAD) + if (stdin === 'close') { + child.stdin.end(LARGE_PAYLOAD) + } }) } @@ -303,6 +323,31 @@ describe('Windows managed hook stdin structure', () => { expect(copilot.indexOf('if (-not $env:ORCA_AGENT_HOOK_PORT')).toBeLessThan( copilot.indexOf('[Console]::In.ReadToEnd()') ) + // Why: the two encoded-PowerShell launchers own stdin themselves when the managed + // script is missing, so the same guard has to precede their ReadToEnd — and the + // fallback answer has to precede the guard, or a gate event outside a pane is + // answered with silence, which reads as deny (#2426/#15462). + for (const [name, command] of [ + [ + 'wrapWindowsHookCommand', + wrapWindowsHookCommand('C:\\missing\\orca-hook.cmd', {}, { fallbackStdout: '{}' }) + ], + [ + 'wrapRuntimeHomeHookCommand', + wrapRuntimeHomeHookCommand('missing-orca-hook', { neutralJsonWhenMissing: true }) + ] + ] as const) { + const decoded = decodeEncodedPowerShellCommand(command) + expect(decoded, `${name} decoded`).toContain(WINDOWS_POWERSHELL_HOOK_ENVIRONMENT_GUARD) + expect(decoded.indexOf("Write-Output '{}'"), `${name} answers first`).toBeLessThan( + decoded.indexOf(WINDOWS_POWERSHELL_HOOK_ENVIRONMENT_GUARD) + ) + expect( + decoded.indexOf(WINDOWS_POWERSHELL_HOOK_ENVIRONMENT_GUARD), + `${name} guards before owning stdin` + ).toBeLessThan(decoded.indexOf('[Console]::In.ReadToEnd()')) + } + const kimi = readFileSync(join(hooksDir, 'kimi-hook.sh'), 'utf8') expect(kimi.indexOf('if [ -z "$ORCA_AGENT_HOOK_PORT" ]')).toBeGreaterThan(-1) expect(kimi.indexOf('if [ -z "$ORCA_AGENT_HOOK_PORT" ]')).toBeLessThan( @@ -365,12 +410,11 @@ describe('Windows managed hook stdin structure', () => { const result = await runHookProcess(executable, args, hookEnvironment()) expect(result.exitCode, `${fileName} exit code`).toBe(0) // Why (#11549 class): every Windows-local hook exits before owning stdin when the - // Orca env is missing, so the writer may break — EPIPE, or ECONNRESET when Windows - // tears the pipe down first. hookEnvironment() strips every ORCA_* var, so this - // relaxation only ever covers the missing-env path — a happy-path case added to - // this loop must not reuse it. + // Orca env is missing, so the writer may break. hookEnvironment() strips every + // ORCA_* var, so this relaxation only ever covers the missing-env path — a + // happy-path case added to this loop must not reuse it. for (const error of result.stdinErrors) { - expect(['EPIPE', 'ECONNRESET'], `${fileName} stdin error`).toContain(error.code) + expect(WRITER_BROKEN_BY_EARLY_EXIT, `${fileName} stdin error`).toContain(error.code) } } @@ -395,9 +439,42 @@ describe('Windows managed hook stdin structure', () => { } ] for (const launcher of launcherCases) { - const result = await runHookProcess(launcher.executable, launcher.args, hookEnvironment()) - expect(result.exitCode, `${launcher.name} exit code`).toBe(0) - expect(result.stdinErrors, `${launcher.name} stdin errors`).toHaveLength(0) + // Why (#11549 class): a launcher that reaches an interpreter owns stdin for a + // missing script exactly like a managed script does, so it obeys the same rule — + // drain inside a pane, exit before reading outside one. Its writer may therefore + // break on the missing-env leg, and must not on the in-pane leg. + const outside = await runHookProcess( + launcher.executable, + launcher.args, + hookEnvironment() + ) + expect(outside.exitCode, `${launcher.name} exit code`).toBe(0) + for (const error of outside.stdinErrors) { + expect(WRITER_BROKEN_BY_EARLY_EXIT, `${launcher.name} stdin error`).toContain( + error.code + ) + } + const insideAPane = await runHookProcess( + launcher.executable, + launcher.args, + hookEnvironment({ + ORCA_AGENT_HOOK_PORT: '59999', + ORCA_AGENT_HOOK_TOKEN: 'token', + ORCA_PANE_KEY: 'tab:leaf' + }) + ) + expect(insideAPane.exitCode, `${launcher.name} in-pane exit code`).toBe(0) + expect(insideAPane.stdinErrors, `${launcher.name} in-pane stdin errors`).toHaveLength(0) + // Why this leg and not a shape assertion: an unguarded ReadToEnd exits fine when + // the writer closes the pipe. Only a caller that abandons it strands the launcher, + // which is what left a console per hook event on the reporting hosts. + const abandoned = await runHookProcess( + launcher.executable, + launcher.args, + hookEnvironment(), + 'abandon' + ) + expect(abandoned.exitCode, `${launcher.name} abandoned-stdin exit code`).toBe(0) } } finally { homedirMock.mockImplementation(() => process.env.HOME ?? tmpdir()) diff --git a/src/main/agent-hooks/runtime-home-hook-command.ts b/src/main/agent-hooks/runtime-home-hook-command.ts index 3a6f0d20725..e56fc603b43 100644 --- a/src/main/agent-hooks/runtime-home-hook-command.ts +++ b/src/main/agent-hooks/runtime-home-hook-command.ts @@ -1,4 +1,8 @@ -import { POSIX_HOOK_STDIN_DRAIN_COMMAND } from './hook-stdin-contract' +import { + POSIX_HOOK_STDIN_DRAIN_COMMAND, + WINDOWS_GIT_BASH_HOOK_ENVIRONMENT_GUARD, + WINDOWS_POWERSHELL_HOOK_ENVIRONMENT_GUARD +} from './hook-stdin-contract' import { encodeWindowsPowerShellHookCommand, WINDOWS_POWERSHELL_HOOK_SWITCHES @@ -19,16 +23,30 @@ export function wrapRuntimeHomeHookCommand( const windowsScript = `"\${HOME-}/.orca/agent-hooks/${scriptBaseName}.cmd"` const posixScript = `"\${HOME-}/.orca/agent-hooks/${scriptBaseName}.sh"` const drain = POSIX_HOOK_STDIN_DRAIN_COMMAND - const missingScriptFallback = options.neutralJsonWhenMissing ? `${drain}; printf '{}\\n'` : drain + const neutralJson = options.neutralJsonWhenMissing ? `printf '{}\\n'` : '' + // Why two forms: the missing-script fallback owns stdin, so it follows the rule of the host + // it lands on. POSIX callers close the pipe, so capture-first is safe there and a mid-write + // exit stays visible as EPIPE (#8110). A Windows caller may abandon the pipe, so there the + // answer comes first and the drain only runs with an Orca env behind it (#11549). + const posixMissingScriptFallback = neutralJson ? `${drain}; ${neutralJson}` : drain + const windowsMissingScriptFallback = [ + ...(neutralJson ? [neutralJson] : []), + WINDOWS_GIT_BASH_HOOK_ENVIRONMENT_GUARD, + drain + ].join('; ') + // Why platform-selected even when HOME is unset: which stdin rule applies follows the + // caller, not the reason the script could not be found. + const missingScriptFallback = `case "\${OSTYPE-}" in msys*|cygwin*|win32*) ${windowsMissingScriptFallback} ;; *) ${posixMissingScriptFallback} ;; esac` const powershell = '"${SYSTEMROOT-}/System32/WindowsPowerShell/v1.0/powershell.exe"' const powershellFallback = options.neutralJsonWhenMissing ? "; Write-Output '{}'" : '' - const powershellCommand = `$homePath = $env:HOME -replace '^/([A-Za-z])/', '$1:/'; $scriptPath = Join-Path $homePath '.orca\\agent-hooks\\${scriptBaseName}.cmd'; if (Test-Path -LiteralPath $scriptPath -PathType Leaf) { & $scriptPath; exit $LASTEXITCODE }; [Console]::In.ReadToEnd() | Out-Null${powershellFallback}; exit 0` + // Why the order: answer first, then the shared env guard, then own stdin — see wrapWindowsHookCommand. + const powershellCommand = `$homePath = $env:HOME -replace '^/([A-Za-z])/', '$1:/'; $scriptPath = Join-Path $homePath '.orca\\agent-hooks\\${scriptBaseName}.cmd'; if (Test-Path -LiteralPath $scriptPath -PathType Leaf) { & $scriptPath; exit $LASTEXITCODE }${powershellFallback}; ${WINDOWS_POWERSHELL_HOOK_ENVIRONMENT_GUARD}; [Console]::In.ReadToEnd() | Out-Null; exit 0` const encodedCommand = encodeWindowsPowerShellHookCommand(powershellCommand) // Why: the Git Bash and native Windows launchers must spell the same switches — window suppression (#14815) and an AV verdict on the shape (#16003) both hit either path. const powershellInvocation = `${powershell} ${WINDOWS_POWERSHELL_HOOK_SWITCHES} -EncodedCommand ${encodedCommand}` - const encodedWindowsBranch = `if [ -f ${powershell} ]; then ${powershellInvocation}; else ${missingScriptFallback}; fi` - const windowsBranch = `if [ -f ${windowsScript} ]; then case "\${HOME-}" in ${WINDOWS_GIT_BASH_RUNTIME_HOME_UNSAFE}) ${encodedWindowsBranch} ;; *) ${windowsScript} ;; esac; else ${missingScriptFallback}; fi` - const posixBranch = `if [ -f ${posixScript} ] && [ -r ${posixScript} ] && [ -x ${posixScript} ]; then /bin/sh ${posixScript}; else ${missingScriptFallback}; fi` + const encodedWindowsBranch = `if [ -f ${powershell} ]; then ${powershellInvocation}; else ${windowsMissingScriptFallback}; fi` + const windowsBranch = `if [ -f ${windowsScript} ]; then case "\${HOME-}" in ${WINDOWS_GIT_BASH_RUNTIME_HOME_UNSAFE}) ${encodedWindowsBranch} ;; *) ${windowsScript} ;; esac; else ${windowsMissingScriptFallback}; fi` + const posixBranch = `if [ -f ${posixScript} ] && [ -r ${posixScript} ] && [ -x ${posixScript} ]; then /bin/sh ${posixScript}; else ${posixMissingScriptFallback}; fi` // Why: OSTYPE is shell-owned, so platform selection adds no process to every hook invocation. return `if [ -z "\${HOME-}" ]; then ${missingScriptFallback}; else case "\${OSTYPE-}" in msys*|cygwin*|win32*) ${windowsBranch} ;; *) ${posixBranch} ;; esac; fi` } diff --git a/src/main/ai-vault/session-scanner-jsonl-reader.test.ts b/src/main/ai-vault/session-scanner-jsonl-reader.test.ts new file mode 100644 index 00000000000..386510ffd89 --- /dev/null +++ b/src/main/ai-vault/session-scanner-jsonl-reader.test.ts @@ -0,0 +1,104 @@ +import { expect, it, vi } from 'vitest' +import { consumeCompleteJsonlLines } from './session-scanner-jsonl-reader' + +const source = vi.hoisted(() => ({ chunks: [] as Buffer[] })) +vi.mock('../native-chat/wsl-transcript-fs-access', () => ({ + openTranscriptReadStream: async function* () { + yield* source.chunks + } +})) + +it('copies only the carried line when the next chunk contains many complete lines', async () => { + source.chunks = Array.from({ length: 100 }, () => Buffer.from(`${'a\n'.repeat(1000)}x`)) + const original = Buffer.concat + let copied = 0 + const concat = vi.spyOn(Buffer, 'concat').mockImplementation((chunks, total) => { + copied += total ?? chunks.reduce((sum, chunk) => sum + chunk.length, 0) + return original(chunks, total) + }) + let lines = 0 + let result: Awaited> + try { + result = await consumeCompleteJsonlLines({ + path: '/log', + start: 0, + onLine: () => { + lines += 1 + } + }) + } finally { + concat.mockRestore() + } + expect(lines).toBe(100000) + expect(result!).toEqual({ consumedThrough: 200099, trailingPartialLine: 'x', bytesRead: 200100 }) + expect(copied).toBeLessThan(1000) +}) + +it('preserves UTF-8/CRLF carry, byte callbacks and stop offsets', async () => { + source.chunks = [Buffer.from('ab\r'), Buffer.from('\ncd\npartial')] + const lines: string[] = [] + expect( + await consumeCompleteJsonlLines({ + path: '/log', + start: 5, + onLine: () => {}, + onLineBytes: (line) => lines.push(line.toString()) + }) + ).toEqual({ consumedThrough: 12, trailingPartialLine: 'partial', bytesRead: 14 }) + expect(lines).toEqual(['ab', 'cd']) + let stopped = false + expect( + await consumeCompleteJsonlLines({ + path: '/log', + start: 5, + onLine: () => { + stopped = true + }, + shouldStop: () => stopped + }) + ).toEqual({ consumedThrough: 9, trailingPartialLine: null, bytesRead: 14 }) + const unicode = Buffer.from('🦀\n') + source.chunks = [unicode.subarray(0, 2), unicode.subarray(2)] + const onLine = vi.fn() + await consumeCompleteJsonlLines({ path: '/log', start: 0, onLine }) + expect(onLine).toHaveBeenCalledWith('🦀') +}) + +// Why: a chunk boundary is not aligned to anything — it can land mid-record, +// mid-UTF-8-sequence, between CR and LF, or on an empty line. A dropped or +// merged line here silently corrupts an agent transcript, and a wrong +// `consumedThrough` makes the next incremental scan resume mid-line. +it('yields identical lines and resume offsets for every single-byte chunk split', async () => { + const bigRecord = `{"d":${'"'.padEnd(2000, 'z')}"}` + const expectedLines = [ + '{"a":1}', // plain LF record + '{"b":"🦀 é 𝄞"}', // CRLF record whose content is 2/3/4-byte UTF-8 + '', // empty line + '', // empty CRLF line + '{"c":"x\ry"}', // lone CR inside a record + bigRecord // single record larger than any carried prefix + ] + const trailing = '{"partial":' // final line with no trailing newline + const buffer = Buffer.from( + `{"a":1}\n{"b":"🦀 é 𝄞"}\r\n\n\r\n{"c":"x\ry"}\n${bigRecord}\n${trailing}`, + 'utf-8' + ) + const expectedConsumed = buffer.length - Buffer.byteLength(trailing) + + for (let cut = 0; cut <= buffer.length; cut++) { + source.chunks = [buffer.subarray(0, cut), buffer.subarray(cut)].filter((c) => c.length > 0) + const lines: string[] = [] + const result = await consumeCompleteJsonlLines({ + path: '/log', + start: 41, + onLine: (line) => lines.push(line) + }) + expect({ cut, lines, ...result }).toEqual({ + cut, + lines: expectedLines, + consumedThrough: 41 + expectedConsumed, + trailingPartialLine: trailing, + bytesRead: buffer.length + }) + } +}) diff --git a/src/main/ai-vault/session-scanner-jsonl-reader.ts b/src/main/ai-vault/session-scanner-jsonl-reader.ts index 613c50ef0ba..6734339dc2f 100644 --- a/src/main/ai-vault/session-scanner-jsonl-reader.ts +++ b/src/main/ai-vault/session-scanner-jsonl-reader.ts @@ -36,23 +36,24 @@ export async function consumeCompleteJsonlLines(args: { remainderLength += chunk.length continue } - const data = - remainderLength > 0 - ? Buffer.concat([...remainderParts, chunk], remainderLength + chunk.length) - : chunk - remainderParts = [] - remainderLength = 0 + const data = chunk + const carriedLength = remainderLength let lineStart = 0 let newlineIndex = data.indexOf(NEWLINE_BYTE, lineStart) while (newlineIndex !== -1) { - let lineEnd = newlineIndex - if (lineEnd > lineStart && data[lineEnd - 1] === CARRIAGE_RETURN_BYTE) { - lineEnd-- + let line = data.subarray(lineStart, newlineIndex) + // Only the first line of a chunk can carry a prefix; resetting inside the + // branch keeps the common per-line path allocation-free. + if (remainderLength > 0) { + line = Buffer.concat([...remainderParts, line], remainderLength + line.length) + remainderParts = [] + remainderLength = 0 } + const lineEnd = line.at(-1) === CARRIAGE_RETURN_BYTE ? line.length - 1 : line.length if (args.onLineBytes) { - args.onLineBytes(data.subarray(lineStart, lineEnd)) + args.onLineBytes(line.subarray(0, lineEnd)) } else { - args.onLine(data.toString('utf-8', lineStart, lineEnd)) + args.onLine(line.toString('utf-8', 0, lineEnd)) } lineStart = newlineIndex + 1 if (args.shouldStop?.()) { @@ -61,7 +62,7 @@ export async function consumeCompleteJsonlLines(args: { } newlineIndex = data.indexOf(NEWLINE_BYTE, lineStart) } - consumedThrough += lineStart + consumedThrough += carriedLength + lineStart if (stopped) { remainderParts = [] remainderLength = 0 diff --git a/src/main/antigravity/hook-script.ts b/src/main/antigravity/hook-script.ts index 67f1f639ef9..fb27ad63494 100644 --- a/src/main/antigravity/hook-script.ts +++ b/src/main/antigravity/hook-script.ts @@ -88,7 +88,10 @@ export function getManagedScript(target: 'local' | 'posix' = 'local'): string { export function getWindowsWrapperScript(eventName: string): string { return [ '@echo off', - 'setlocal', + // Why (#9358/#9941): `!` is legal in the hooks path, and inherited delayed expansion + // eats it out of the percent-expanded `%~dp0` — the wrapper then misses the core and + // silently falls back on every event. Same reason the core disables it. + 'setlocal DisableDelayedExpansion', `set "ORCA_ANTIGRAVITY_EVENT=${eventName}"`, 'set "ORCA_ANTIGRAVITY_CORE=%~dp0antigravity-hook.cmd"', 'if exist "%ORCA_ANTIGRAVITY_CORE%" (', @@ -102,8 +105,8 @@ export function getWindowsWrapperScript(eventName: string): string { ') else (', ' echo {}', ')', - // Why: when the shared core script is missing, this wrapper becomes the - // stdin owner and must finish the agent's payload write before returning. + // Missing-core fallbacks obey the same outside-Orca stdin guard as the core. + ...buildWindowsHookEnvironmentGuardLines(), WINDOWS_HOOK_STDIN_DRAIN_COMMAND, 'exit /b 0', '' diff --git a/src/main/antigravity/windows-hook-payload-delivery.test.ts b/src/main/antigravity/windows-hook-payload-delivery.test.ts index 8261cc3ce91..6c9ca08bd27 100644 --- a/src/main/antigravity/windows-hook-payload-delivery.test.ts +++ b/src/main/antigravity/windows-hook-payload-delivery.test.ts @@ -28,7 +28,8 @@ vi.mock('os', async (importOriginal) => { import { AntigravityHookService } from './hook-service' import { ANTIGRAVITY_EVENTS, ANTIGRAVITY_PRE_TOOL_USE_DECISION } from './hook-events' -import { getManagedScript } from './hook-script' +import { getManagedScript, getWindowsWrapperScript } from './hook-script' +import { WINDOWS_HOOK_STDIN_DRAIN_COMMAND } from '../agent-hooks/hook-stdin-contract' // Why (#9358/#9941): `!` is legal in a Windows path and in a pane key. Under inherited // delayed expansion cmd eats it out of a percent-expanded curl argument, so bake one into @@ -91,17 +92,23 @@ async function startHookListener(): Promise<{ type HookRun = { exitCode: number | null; stdout: string; stderr: string; timedOut: boolean } +// Why spell `/v`: `cmd /d /c ` is the chain in the bug report's process trace, +// and it inherits HKCU\...\Command Processor\DelayedExpansion. Naming the state makes the +// hostile half reachable on any host — under `/v:on` cmd eats `!` out of every percent +// expansion (#9358/#9941), and a harness pinned to `/v:off` could never fail on it. +type DelayedExpansion = 'on' | 'off' +const DELAYED_EXPANSION_STATES = ['off', 'on'] as const satisfies readonly DelayedExpansion[] + function runWrapper( wrapperPath: string, env: NodeJS.ProcessEnv, // Why: `null` abandons stdin instead of closing it — the shape a caller outside an Orca // pane produces, and the only way to prove the env guard exits before reading (#11549). - stdinPayload: string | null = PAYLOAD + stdinPayload: string | null = PAYLOAD, + delayedExpansion: DelayedExpansion = 'off' ): Promise { return new Promise((resolve, reject) => { - // Why: mirror how Antigravity spawns the hook — `cmd /c `, the exact - // chain in the bug report's process trace. - const child = spawn('cmd.exe', ['/d', '/c', wrapperPath], { + const child = spawn('cmd.exe', [`/v:${delayedExpansion}`, '/d', '/c', wrapperPath], { stdio: ['pipe', 'pipe', 'pipe'], windowsHide: true, env @@ -111,6 +118,7 @@ function runWrapper( let timedOut = false const timer = setTimeout(() => { timedOut = true + child.stdin.destroy() child.kill('SIGKILL') }, 15_000) child.on('error', (error) => { @@ -154,6 +162,24 @@ function expectedStdout(eventName: string): string { // Why: runs on every platform — the live delivery suite below is Windows-only, so this // keeps a POSIX-only CI leg from letting the interpreter back into the hot path. describe('Antigravity Windows hook post command', () => { + it.each(ANTIGRAVITY_EVENTS)('guards missing-core stdin for $eventName', ({ eventName }) => { + const script = getWindowsWrapperScript(eventName) + const drain = script.indexOf(WINDOWS_HOOK_STDIN_DRAIN_COMMAND) + const answer = script.lastIndexOf('echo {}') + expect(drain).toBeGreaterThan(answer) + for (const key of ['ORCA_AGENT_HOOK_PORT', 'ORCA_AGENT_HOOK_TOKEN', 'ORCA_PANE_KEY']) { + const guard = script.indexOf(`if "%${key}%"=="" exit /b 0`) + expect(guard, key).toBeGreaterThan(answer) + expect(guard, key).toBeLessThan(drain) + } + }) + + // Why (#9358/#9941): `%~dp0` carries the hooks path, so an inherited delayed expansion eats + // a `!` out of it and the wrapper silently misses the core on every event. + it.each(ANTIGRAVITY_EVENTS)('disables delayed expansion for $eventName', ({ eventName }) => { + expect(getWindowsWrapperScript(eventName)).toContain('setlocal DisableDelayedExpansion') + }) + it('posts through curl.exe rather than a PowerShell interpreter', () => { vi.spyOn(process, 'platform', 'get').mockReturnValue('win32') const script = getManagedScript('local') @@ -185,7 +211,10 @@ describe.skipIf(process.platform !== 'win32')('Antigravity Windows hook payload }) it('delivers every event wrapper payload to the listener without spawning PowerShell', async () => { - home = mkdtempSync(join(tmpdir(), 'orca-antigravity-hook-')) + // Why the `!` in the directory: it lands in the wrapper's `%~dp0`, which is what an + // inherited delayed expansion eats (#9358/#9941). Without it the `/v:on` leg below + // proves nothing about the core lookup. + home = mkdtempSync(join(tmpdir(), 'orca-antigravity-hook!bang-')) homedirMock.mockReturnValue(home) expect(new AntigravityHookService().install().state).toBe('installed') @@ -204,34 +233,42 @@ describe.skipIf(process.platform !== 'win32')('Antigravity Windows hook payload ORCA_WORKTREE_ID: WORKTREE_ID }) - for (const event of ANTIGRAVITY_EVENTS) { - const label = event.eventName - const before = listener.posts.length - const result = await runWrapper(join(hooksDir, event.windowsWrapperFileName), env) + for (const delayedExpansion of DELAYED_EXPANSION_STATES) { + for (const event of ANTIGRAVITY_EVENTS) { + const label = `${event.eventName} (/v:${delayedExpansion})` + const before = listener.posts.length + const result = await runWrapper( + join(hooksDir, event.windowsWrapperFileName), + env, + PAYLOAD, + delayedExpansion + ) - expect(result.timedOut, `${label} timed out`).toBe(false) - expect(result.exitCode, `${label} exit code`).toBe(0) - expect(result.stderr, `${label} stderr`).toBe('') - // Why: Antigravity reads silence on PreToolUse as deny (#2426), so the gate answer - // must survive the transport change. - expect(result.stdout.trim(), `${label} stdout`).toBe(expectedStdout(label)) + expect(result.timedOut, `${label} timed out`).toBe(false) + expect(result.exitCode, `${label} exit code`).toBe(0) + expect(result.stderr, `${label} stderr`).toBe('') + // Why: Antigravity reads silence on PreToolUse as deny (#2426), so the gate answer + // must survive the transport change. + expect(result.stdout.trim(), `${label} stdout`).toBe(expectedStdout(event.eventName)) - const posts = listener.posts.slice(before) - expect(posts, `${label} posted exactly one hook`).toHaveLength(1) - // Why: byte-exact, not "non-empty" — PowerShell recoded this body through the console - // code page, and a silently corrupted payload still looks posted. - expect(posts[0].payload, `${label} payload`).toBe(PAYLOAD) - expect(posts[0].hookEventName, `${label} hook_event_name`).toBe(label) - // Why: the `!` in both values is the delayed-expansion regression guard. - expect(posts[0].paneKey, `${label} paneKey`).toBe(PANE_KEY) - expect(posts[0].worktreeId, `${label} worktreeId`).toBe(WORKTREE_ID) - expect(posts[0].token, `${label} token`).toBe(HOOK_TOKEN) - expect(posts[0].contentType, `${label} content-type`).toContain( - 'application/x-www-form-urlencoded' - ) + const posts = listener.posts.slice(before) + expect(posts, `${label} posted exactly one hook`).toHaveLength(1) + // Why: byte-exact, not "non-empty" — PowerShell recoded this body through the console + // code page, and a silently corrupted payload still looks posted. + expect(posts[0].payload, `${label} payload`).toBe(PAYLOAD) + expect(posts[0].hookEventName, `${label} hook_event_name`).toBe(event.eventName) + // Why: the `!` in both values is the delayed-expansion regression guard — it is the + // `/v:on` leg that can actually fail on it. + expect(posts[0].paneKey, `${label} paneKey`).toBe(PANE_KEY) + expect(posts[0].worktreeId, `${label} worktreeId`).toBe(WORKTREE_ID) + expect(posts[0].token, `${label} token`).toBe(HOOK_TOKEN) + expect(posts[0].contentType, `${label} content-type`).toContain( + 'application/x-www-form-urlencoded' + ) + } } - // Why: five wrapper launches plus a real install can overrun the default under load. - }, 60_000) + // Why: ten wrapper launches plus a real install can overrun the default under load. + }, 90_000) // Why (#15117): Antigravity fires some events with no stdin at all. PowerShell substituted // `{}` before posting; curl forwards the empty body, so prove the post still happens — the @@ -264,6 +301,67 @@ describe.skipIf(process.platform !== 'win32')('Antigravity Windows hook payload expect(listener.posts[0].hookEventName).toBe('PreInvocation') }, 30_000) + // Why a helper: the missing-core cases all need a real install with the core removed, which + // is the shape an AV quarantine or a half-finished uninstall leaves behind. + async function installWithoutCore(): Promise { + home = mkdtempSync(join(tmpdir(), 'orca-antigravity-fallback-')) + homedirMock.mockReturnValue(home) + expect(new AntigravityHookService().install().state).toBe('installed') + const hooksDir = join(home, '.orca', 'agent-hooks') + rmSync(join(hooksDir, 'antigravity-hook.cmd')) + return hooksDir + } + + it.each(['ORCA_AGENT_HOOK_PORT', 'ORCA_AGENT_HOOK_TOKEN', 'ORCA_PANE_KEY'])( + 'answers every missing-core event with abandoned stdin and no %s', + async (missingKey) => { + const hooksDir = await installWithoutCore() + const listener = await startHookListener() + server = listener.server + const env = hookEnvironment({ + USERPROFILE: home, + HOME: home, + ORCA_AGENT_HOOK_PORT: String(listener.port), + ORCA_AGENT_HOOK_TOKEN: HOOK_TOKEN, + ORCA_PANE_KEY: PANE_KEY, + [missingKey]: '' + }) + for (const event of ANTIGRAVITY_EVENTS) { + const result = await runWrapper(join(hooksDir, event.windowsWrapperFileName), env, null) + expect(result.timedOut, event.eventName).toBe(false) + expect(result.exitCode, event.eventName).toBe(0) + expect(result.stdout.trim(), event.eventName).toBe(expectedStdout(event.eventName)) + expect(result.stderr, event.eventName).toBe('') + } + expect(listener.posts).toHaveLength(0) + }, + 90_000 + ) + + // Why: the guard must not cost the valid path its drain — with the Orca env present the + // fallback still owns stdin, so the agent's payload write completes instead of breaking. + it('still drains a closed payload for every missing-core event inside a pane', async () => { + const hooksDir = await installWithoutCore() + const listener = await startHookListener() + server = listener.server + const env = hookEnvironment({ + USERPROFILE: home, + HOME: home, + ORCA_AGENT_HOOK_PORT: String(listener.port), + ORCA_AGENT_HOOK_TOKEN: HOOK_TOKEN, + ORCA_PANE_KEY: PANE_KEY + }) + for (const event of ANTIGRAVITY_EVENTS) { + const result = await runWrapper(join(hooksDir, event.windowsWrapperFileName), env) + expect(result.timedOut, event.eventName).toBe(false) + expect(result.exitCode, event.eventName).toBe(0) + expect(result.stdout.trim(), event.eventName).toBe(expectedStdout(event.eventName)) + expect(result.stderr, event.eventName).toBe('') + } + // Why: the fallback answers the agent but has no core to post through. + expect(listener.posts).toHaveLength(0) + }, 60_000) + it('exits without reading stdin when the pane env is missing', async () => { home = mkdtempSync(join(tmpdir(), 'orca-antigravity-hook-')) homedirMock.mockReturnValue(home) diff --git a/src/main/browser/remote-browser-socks-buffering.test.ts b/src/main/browser/remote-browser-socks-buffering.test.ts new file mode 100644 index 00000000000..badae864399 --- /dev/null +++ b/src/main/browser/remote-browser-socks-buffering.test.ts @@ -0,0 +1,117 @@ +import { EventEmitter } from 'node:events' +import { createServer, type Socket } from 'node:net' +import { PassThrough } from 'node:stream' +import { afterEach, describe, expect, it, vi } from 'vitest' +import { RemoteBrowserSocksServer } from './remote-browser-socks-server' + +vi.mock('node:net', () => ({ + createServer: vi.fn(() => ({ listening: false })) +})) + +function setup(requestTail: Buffer = Buffer.alloc(0)) { + const upstream = new PassThrough() + const write = vi.spyOn(upstream, 'write') + const opened = Promise.withResolvers() + const open = vi.fn(() => opened.promise) + const server = new RemoteBrowserSocksServer({ open }) + const socket = Object.assign(new EventEmitter(), { + remoteAddress: '127.0.0.1', + destroyed: false, + write: vi.fn(() => true), + pause: vi.fn(), + end: vi.fn((_reply, callback) => callback()), + pipe: vi.fn(), + destroy: vi.fn(() => { + socket.destroyed = true + socket.emit('close') + }) + }) + const accept = vi.mocked(createServer).mock.calls.at(-1)![0] as (socket: Socket) => void + accept(socket as unknown as Socket) + socket.emit('data', Buffer.from([5, 1, 0])) + socket.emit('data', Buffer.concat([Buffer.from([5, 1, 0, 1, 127, 0, 0, 1, 1, 187]), requestTail])) + return { server, socket, upstream, write, opened, open } +} + +afterEach(() => vi.restoreAllMocks()) + +describe('pending browser SOCKS route buffering', () => { + it('copies fragmented pending bytes linearly and forwards every byte at the existing cap', async () => { + const { server, socket, upstream, write, opened } = setup() + const payload = Buffer.alloc(256 * 1024) + for (let index = 0; index < payload.length; index += 1) { + payload[index] = index % 251 + } + let copiedBytes = 0 + const originalCopy = Buffer.prototype.copy + const copy = vi.spyOn(Buffer.prototype, 'copy').mockImplementation(function (target, ...args) { + const copied = originalCopy.call(this, target, ...args) + copiedBytes += copied + return copied + }) + const concat = vi.spyOn(Buffer, 'concat') + try { + for (let index = 0; index < payload.length; index += 256) { + socket.emit('data', payload.subarray(index, index + 256)) + } + expect(concat.mock.calls.length).toBe(0) + expect(copiedBytes).toBeLessThan(payload.length * 3) + opened.resolve(upstream) + await vi.waitFor(() => expect(write).toHaveBeenCalledTimes(1)) + expect(write.mock.calls[0][0]).toEqual(payload) + } finally { + copy.mockRestore() + concat.mockRestore() + await server.close() + upstream.destroy() + } + }) + + it('keeps request-tail bytes ahead of later fragments in the pending payload', async () => { + const tail = Buffer.from('GET / HTTP/1.1\r\n') + const { server, socket, upstream, write, opened } = setup(tail) + const rest = Buffer.from('Host: example.com\r\n\r\n') + try { + for (const byte of rest) { + socket.emit('data', Buffer.from([byte])) + } + opened.resolve(upstream) + await vi.waitFor(() => expect(write).toHaveBeenCalledTimes(1)) + expect(write.mock.calls[0][0]).toEqual(Buffer.concat([tail, rest])) + } finally { + await server.close() + upstream.destroy() + } + }) + + it('rejects one byte beyond the cap and destroys a late upstream without forwarding', async () => { + const { server, socket, upstream, write, opened, open } = setup() + try { + await vi.waitFor(() => expect(open).toHaveBeenCalledTimes(1)) + socket.emit('data', Buffer.alloc(256 * 1024)) + expect(socket.destroyed).toBe(false) + socket.emit('data', Buffer.from([1])) + expect(socket.destroyed).toBe(true) + expect(socket.end.mock.calls[0][0][1]).toBe(1) + opened.resolve(upstream) + await vi.waitFor(() => expect(upstream.destroyed).toBe(true)) + expect(write).not.toHaveBeenCalled() + } finally { + await server.close() + } + }) + + it('discards pending input on client close while the route is opening', async () => { + const { server, socket, upstream, write, opened, open } = setup() + try { + await vi.waitFor(() => expect(open).toHaveBeenCalledTimes(1)) + socket.emit('data', Buffer.from('pending request')) + socket.destroy() + opened.resolve(upstream) + await vi.waitFor(() => expect(upstream.destroyed).toBe(true)) + expect(write).not.toHaveBeenCalled() + } finally { + await server.close() + } + }) +}) diff --git a/src/main/browser/remote-browser-socks-server.ts b/src/main/browser/remote-browser-socks-server.ts index 976ed48af8c..1b72963cf97 100644 --- a/src/main/browser/remote-browser-socks-server.ts +++ b/src/main/browser/remote-browser-socks-server.ts @@ -1,5 +1,7 @@ import { createServer, type Server, type Socket } from 'node:net' import type { Duplex } from 'node:stream' +import { GrowingByteBuffer } from '../../shared/growing-byte-buffer' +import { pipeUpstreamToClient } from './remote-browser-socks-upstream' const SOCKS_VERSION = 5 const SOCKS_NO_AUTH = 0 @@ -106,10 +108,13 @@ export class RemoteBrowserSocksServer { this.clients.add(socket) let phase: 'greeting' | 'request' | 'opening' | 'connected' | 'closed' = 'greeting' let buffered = Buffer.alloc(0) + const pendingUpstream = new GrowingByteBuffer() const timeout = setTimeout(() => socket.destroy(), HANDSHAKE_TIMEOUT_MS) const cleanup = (): void => { phase = 'closed' clearTimeout(timeout) + buffered = Buffer.alloc(0) + pendingUpstream.clear() this.clients.delete(socket) } const finishFailure = (reply: Uint8Array): void => { @@ -119,6 +124,7 @@ export class RemoteBrowserSocksServer { phase = 'closed' clearTimeout(timeout) buffered = Buffer.alloc(0) + pendingUpstream.clear() socket.pause() socket.end(reply, () => socket.destroy()) } @@ -127,13 +133,15 @@ export class RemoteBrowserSocksServer { if (phase === 'closed' || phase === 'connected') { return } - buffered = Buffer.concat([buffered, chunk]) if (phase === 'opening') { - if (buffered.byteLength > MAX_PENDING_UPSTREAM_BYTES) { + if (pendingUpstream.byteLength + chunk.byteLength > MAX_PENDING_UPSTREAM_BYTES) { fail(1) + } else { + pendingUpstream.append(chunk) } return } + buffered = Buffer.concat([buffered, chunk]) if (phase === 'greeting' && buffered.byteLength > MAX_HANDSHAKE_BYTES) { fail(1) return @@ -181,6 +189,8 @@ export class RemoteBrowserSocksServer { return } phase = 'opening' + pendingUpstream.append(buffered) + buffered = Buffer.alloc(0) void Promise.resolve() .then(() => this.open(normalizeListenerWildcard(parsed.target))) .then( @@ -193,9 +203,8 @@ export class RemoteBrowserSocksServer { clearTimeout(timeout) socket.off('data', onData) socket.write(SUCCESS_RESPONSE) - if (buffered.byteLength > 0) { - upstream.write(buffered) - buffered = Buffer.alloc(0) + if (pendingUpstream.byteLength > 0) { + upstream.write(pendingUpstream.takeBuffer()) } socket.pipe(upstream) pipeUpstreamToClient(upstream, socket) @@ -212,22 +221,6 @@ export class RemoteBrowserSocksServer { } } -function pipeUpstreamToClient(upstream: Duplex, socket: Socket): void { - upstream.on('data', (chunk: Buffer) => { - const bytes = Buffer.isBuffer(chunk) ? chunk : Buffer.from(chunk) - const accepted = socket.write(bytes, (error) => { - if (!error && 'settleRead' in upstream && typeof upstream.settleRead === 'function') { - upstream.settleRead(bytes.byteLength) - } - }) - if (!accepted) { - upstream.pause() - } - }) - socket.on('drain', () => upstream.resume()) - upstream.once('end', () => socket.end()) -} - function parseSocksRequest(buffer: Uint8Array): SocksRequest | null | undefined { if (buffer.byteLength < 4) { return undefined diff --git a/src/main/browser/remote-browser-socks-upstream.ts b/src/main/browser/remote-browser-socks-upstream.ts new file mode 100644 index 00000000000..167563ccad1 --- /dev/null +++ b/src/main/browser/remote-browser-socks-upstream.ts @@ -0,0 +1,18 @@ +import type { Socket } from 'node:net' +import type { Duplex } from 'node:stream' + +export function pipeUpstreamToClient(upstream: Duplex, socket: Socket): void { + upstream.on('data', (chunk: Buffer) => { + const bytes = Buffer.isBuffer(chunk) ? chunk : Buffer.from(chunk) + const accepted = socket.write(bytes, (error) => { + if (!error && 'settleRead' in upstream && typeof upstream.settleRead === 'function') { + upstream.settleRead(bytes.byteLength) + } + }) + if (!accepted) { + upstream.pause() + } + }) + socket.on('drain', () => upstream.resume()) + upstream.once('end', () => socket.end()) +} diff --git a/src/main/codex/config-toml-hook-trust-edit.ts b/src/main/codex/config-toml-hook-trust-edit.ts index 9d6e5dbc2d5..a8487012f05 100644 --- a/src/main/codex/config-toml-hook-trust-edit.ts +++ b/src/main/codex/config-toml-hook-trust-edit.ts @@ -56,7 +56,10 @@ function upsertTrustBlocks( hash: string, explicitEnabled?: boolean ): string { - const ranges = getUniqueTrustBlockRanges(content, keys) + const ranges = findHookTrustBlockRanges( + content, + new Set(keys.map(normalizeCodexHookTrustLookupKey)) + ) if (ranges.length === 0) { return appendTrustBlocks(content, keys, hash, explicitEnabled ?? true) } @@ -74,21 +77,6 @@ function upsertTrustBlocks( return deduped + content.slice(cursor) } -function getUniqueTrustBlockRanges( - content: string, - keys: readonly string[] -): HookTrustBlockRange[] { - const normalizedKeys = new Set(keys.map(normalizeCodexHookTrustLookupKey)) - return findHookTrustBlockRanges(content, normalizedKeys) - .filter( - (range, index, ranges) => - ranges.findIndex( - (candidate) => candidate.start === range.start && candidate.end === range.end - ) === index - ) - .sort((left, right) => left.start - right.start) -} - function isBlockDisabled(content: string, range: HookTrustBlockRange): boolean { const block = content.slice(range.headerLineEnd, range.end) const enabledMatch = /^[ \t]*enabled[ \t]*=[ \t]*(true|false)[ \t\r]*(?:#.*)?$/m.exec(block) diff --git a/src/main/codex/config-toml-hook-trust-scaling.test.ts b/src/main/codex/config-toml-hook-trust-scaling.test.ts new file mode 100644 index 00000000000..bb744fa4b16 --- /dev/null +++ b/src/main/codex/config-toml-hook-trust-scaling.test.ts @@ -0,0 +1,72 @@ +import type * as HookTrustBlocks from './config-toml-hook-trust-blocks' +import { expect, it, vi } from 'vitest' +import { upsertHookTrustContent } from './config-toml-hook-trust-edit' + +const counts = vi.hoisted(() => ({ starts: 0 })) +vi.mock('./config-toml-hook-trust-blocks', async (importOriginal) => { + const actual = await importOriginal() + return { + ...actual, + findHookTrustBlockRanges: (...args: Parameters) => + actual.findHookTrustBlockRanges(...args).map((range) => ({ + ...range, + get start() { + counts.starts += 1 + return range.start + } + })) + } +}) + +it('consumes monotonically scanned trust ranges without pairwise deduplication', () => { + const header = '[hooks.state."/foo/hooks.json:pre_tool_use:0:0"]' + const content = `${header}\nenabled = true\ntrusted_hash = "old"\n`.repeat(1000) + counts.starts = 0 + const result = upsertHookTrustContent(content, [ + { + sourcePath: '/foo/hooks.json', + eventLabel: 'pre_tool_use', + groupIndex: 0, + handlerIndex: 0, + command: '/bin/echo hi', + trustedHash: 'updated' + } + ]) + expect(counts.starts).toBeLessThan(5000) + expect(result.split(header)).toHaveLength(2) + expect(result).toContain('trusted_hash = "updated"') +}) + +// Dropping the old dedup+sort is only sound because the scanner advances its +// cursor past each block it emits. Pin that precondition: if a future scanner +// change lets ranges repeat or overlap, the upsert below would delete or widen +// a neighbouring trust block instead of rewriting just the matched one. +it('emits trust ranges with strictly ascending, non-overlapping spans', async () => { + const { findHookTrustBlockRanges } = await vi.importActual( + './config-toml-hook-trust-blocks' + ) + const key = '/foo/hooks.json:pre_tool_use:0:0' + const header = `[hooks.state."${key}"]` + const contents = [ + '', + header, + `${header}\n${header}\n`, + `${header}\nenabled = true\n`.repeat(50), + `${header}\r\nenabled = true\r\n`.repeat(3), + `[x]\nv = """\n${header}\n"""\n${header}\nenabled = true\n`, + `[x]\na = [\n${header}\n]\n${header}\nenabled = true\n`, + `${header}\nenabled = true\n[[arr]]\nz = 1\n${header}\n` + ] + for (const content of contents) { + const ranges = findHookTrustBlockRanges(content, new Set([key])) + for (const [index, range] of ranges.entries()) { + expect(range.end).toBeGreaterThanOrEqual(range.start) + expect(range.end).toBeLessThanOrEqual(content.length) + if (index > 0) { + expect(ranges[index - 1].start).toBeLessThan(range.start) + expect(ranges[index - 1].end).toBeLessThanOrEqual(range.start) + } + } + expect(new Set(ranges.map((range) => `${range.start}:${range.end}`)).size).toBe(ranges.length) + } +}) diff --git a/src/main/copilot/copilot-managed-script.ts b/src/main/copilot/copilot-managed-script.ts index 492caafc045..018b026c992 100644 --- a/src/main/copilot/copilot-managed-script.ts +++ b/src/main/copilot/copilot-managed-script.ts @@ -1,7 +1,8 @@ import { getSharedManagedScriptPath } from '../agent-hooks/installer-utils' import { buildPosixHookPayloadCapture, - buildPosixHookSpoolLines + buildPosixHookSpoolLines, + WINDOWS_POWERSHELL_HOOK_ENVIRONMENT_GUARD } from '../agent-hooks/hook-stdin-contract' export function getManagedScriptFileName(): string { @@ -30,7 +31,7 @@ export function getManagedScript(target: 'local' | 'posix' = 'local'): string { // Why (#11549 class): missing Orca context means a user-wide hook fired outside an // Orca pane. ReadToEnd blocks forever if that caller abandons the pipe, so the guard // must run before the hook owns stdin; the payload would be discarded anyway. - 'if (-not $env:ORCA_AGENT_HOOK_PORT -or -not $env:ORCA_AGENT_HOOK_TOKEN -or -not $env:ORCA_PANE_KEY) { exit 0 }', + WINDOWS_POWERSHELL_HOOK_ENVIRONMENT_GUARD, '$inputData = [Console]::In.ReadToEnd()', 'if ([string]::IsNullOrWhiteSpace($inputData)) { exit 0 }', 'try {', diff --git a/src/main/gitlab/mr-file-diffs.ts b/src/main/gitlab/mr-file-diffs.ts index 0e16567a294..8f6d10ce410 100644 --- a/src/main/gitlab/mr-file-diffs.ts +++ b/src/main/gitlab/mr-file-diffs.ts @@ -25,19 +25,23 @@ export function countDiffLines(diff: string): { additions: number; deletions: nu // diff line `---`, colliding with the `--- a/file` header — so it must // be counted once inside a hunk, not skipped. let inHunk = false - for (const line of diff.split('\n')) { - if (line.startsWith('@@')) { + let cursor = 0 + while (cursor < diff.length) { + if (diff.startsWith('@@', cursor)) { inHunk = true - continue + } else if (inHunk) { + const prefix = diff.charCodeAt(cursor) + if (prefix === 43) { + additions += 1 + } else if (prefix === 45) { + deletions += 1 + } } - if (!inHunk) { - continue - } - if (line.startsWith('+')) { - additions += 1 - } else if (line.startsWith('-')) { - deletions += 1 + const newline = diff.indexOf('\n', cursor) + if (newline === -1) { + break } + cursor = newline + 1 } return { additions, deletions } } diff --git a/src/main/gitlab/work-item-details.test.ts b/src/main/gitlab/work-item-details.test.ts index f1e2297e14b..9de6bb43d03 100644 --- a/src/main/gitlab/work-item-details.test.ts +++ b/src/main/gitlab/work-item-details.test.ts @@ -458,4 +458,42 @@ describe('countDiffLines', () => { // Why: the `@@` hunk check runs first, so it must not swallow `+`/`-` content. expect(countDiffLines('@@ -1 +1 @@\n-@@ old\n+@@ new')).toEqual({ additions: 1, deletions: 1 }) }) + + // Why: the scan now reads a prefix code unit at a byte cursor rather than a split + // segment, so line-ending and non-ASCII shapes are the new regression surface. + it('counts a CRLF hunk the same as an LF hunk', () => { + expect(countDiffLines('@@ -1 +1,2 @@\r\n-old\r\n+a\r\n+b\r\n')).toEqual({ + additions: 2, + deletions: 1 + }) + }) + + it('treats a lone CR as content, not a line break', () => { + expect(countDiffLines('@@ -1 +1 @@\n-old\r+new')).toEqual({ additions: 0, deletions: 1 }) + }) + + it('counts lines whose content is multi-byte or a surrogate pair', () => { + expect(countDiffLines('@@ -1 +1 @@\n-é ünïcode\n+🚀 rocket')).toEqual({ + additions: 1, + deletions: 1 + }) + }) + + it('ignores non-ASCII context lines and blank lines inside a hunk', () => { + expect(countDiffLines('@@ -1 +1 @@\n é leading accent\n 🚀 leading emoji\n\n')).toEqual({ + additions: 0, + deletions: 0 + }) + }) + + it('counts large diff prefixes without allocating a string array for every line', () => { + const diff = `--- a/file\n+++ b/file\n@@ -1 +1 @@\n${'-old\n+new\n context\n'.repeat(10000)}` + const split = vi.spyOn(String.prototype, 'split') + try { + expect(countDiffLines(diff)).toEqual({ additions: 10000, deletions: 10000 }) + expect(split.mock.calls.length).toBe(0) + } finally { + split.mockRestore() + } + }) }) diff --git a/src/main/ipc/pty-activation-inventory-scope.test.ts b/src/main/ipc/pty-activation-inventory-scope.test.ts new file mode 100644 index 00000000000..a6cb5dabad5 --- /dev/null +++ b/src/main/ipc/pty-activation-inventory-scope.test.ts @@ -0,0 +1,139 @@ +import { describe, expect, it, vi } from 'vitest' +import { setupPtyIpcSuite } from './pty-ipc-test-harness' +import { registerSshPtyProvider, getLocalPtyProvider } from './pty' +import { installPtyInspectIpcHandlers } from './pty/ipc/inspect' +import { ptyOwnership } from './pty/provider/ownership-state' + +vi.mock('electron', () => import('./pty-ipc-mock-registry').then((m) => m.electronModuleMock())) +vi.mock('fs', () => import('./pty-ipc-mock-registry').then((m) => m.fsModuleMock())) +vi.mock('node-pty', () => import('./pty-ipc-mock-registry').then((m) => m.nodePtyModuleMock())) +vi.mock('node:child_process', async (importOriginal) => + (await import('./pty-ipc-mock-registry')).childProcessModuleMock(await importOriginal()) +) +vi.mock('../opencode/hook-service', () => + import('./pty-ipc-mock-registry').then((m) => m.openCodeHookServiceModuleMock()) +) +vi.mock('../mimo/hook-service', () => + import('./pty-ipc-mock-registry').then((m) => m.mimoHookServiceModuleMock()) +) +vi.mock('../agent-hooks/server', () => + import('./pty-ipc-mock-registry').then((m) => m.agentHookServerModuleMock()) +) +vi.mock('../pi/titlebar-extension-service', () => + import('./pty-ipc-mock-registry').then((m) => m.piTitlebarExtensionModuleMock()) +) +vi.mock('../pwsh', () => import('./pty-ipc-mock-registry').then((m) => m.pwshModuleMock())) +vi.mock('../wsl', async (importOriginal) => + (await import('./pty-ipc-mock-registry')).wslModuleMock(await importOriginal()) +) +vi.mock('../telemetry/client', () => + import('./pty-ipc-mock-registry').then((m) => m.telemetryClientModuleMock()) +) +vi.mock('../telemetry/classify-error', () => + import('./pty-ipc-mock-registry').then((m) => m.classifyErrorModuleMock()) +) +vi.mock('../cli/linux-terminal-orca-cli-shim', () => + import('./pty-ipc-mock-registry').then((m) => m.linuxCliShimModuleMock()) +) +vi.mock('../memory/pty-registry', () => + import('./pty-ipc-mock-registry').then((m) => m.ptyRegistryModuleMock()) +) +vi.mock('../agent-hooks/migration-unsupported-pty-state', () => + import('./pty-ipc-mock-registry').then((m) => m.migrationUnsupportedPtyModuleMock()) +) +vi.mock('../codex/codex-pane-account-registry', () => + import('./pty-ipc-mock-registry').then((m) => m.codexPaneAccountRegistryModuleMock()) +) +vi.mock('../codex/codex-state-db-backfill-recovery', () => + import('./pty-ipc-mock-registry').then((m) => m.codexBackfillRecoveryModuleMock()) +) + +describe('scoped activation PTY inventory', () => { + const { handlers, installDaemonTestProvider } = setupPtyIpcSuite() + + function install() { + const localList = vi.fn(async () => [{ id: 'local', cwd: '/', title: 'shell' }]) + installDaemonTestProvider({ listProcesses: localList }) + const remoteLists = Array.from({ length: 50 }, (_, index) => { + const list = vi.fn(async () => [ + { + id: `ssh:host-${index}@@pty-1`, + cwd: '/remote', + title: 'agent', + worktreeId: 'repo::/remote' + } + ]) + registerSshPtyProvider(`host-${index}`, { + ...getLocalPtyProvider(), + listProcesses: list, + providesAgentSessionOwnerListings: () => true + }) + return list + }) + const startup = vi.fn(async () => {}) + installPtyInspectIpcHandlers({ getLocalPtyProviderStartupPromise: startup }) + const list = (scope?: unknown) => handlers.get('pty:listSessions')!(null, scope) + return { localList, remoteLists, startup, list } + } + + it('queries only the chosen SSH provider and preserves workspace and ownership evidence', async () => { + const { list, localList, remoteLists, startup } = install() + expect(await list({ connectionId: 'host-17' })).toEqual([ + { + id: 'ssh:host-17@@pty-1', + cwd: '/remote', + title: 'agent', + worktreeId: 'repo::/remote', + agentOwnership: 'absent' + } + ]) + expect(remoteLists[17]).toHaveBeenCalledOnce() + expect(remoteLists.reduce((count, mock) => count + mock.mock.calls.length, 0)).toBe(1) + expect(localList).not.toHaveBeenCalled() + expect(startup).not.toHaveBeenCalled() + expect(ptyOwnership.get('ssh:host-17@@pty-1')).toBe('host-17') + }) + + it('waits for local startup and never visits remote providers for a local scope', async () => { + const { list, localList, remoteLists, startup } = install() + let release!: () => void + startup.mockImplementation( + () => + new Promise((resolve) => { + release = resolve + }) + ) + const pending = list({ connectionId: null }) + expect(localList).not.toHaveBeenCalled() + release() + await pending + expect(localList).toHaveBeenCalledOnce() + expect(remoteLists.every((mock) => mock.mock.calls.length === 0)).toBe(true) + }) + + it('propagates selected-host failure and never substitutes the local inventory', async () => { + const { list, localList, remoteLists } = install() + remoteLists[3].mockRejectedValue(new Error('relay unavailable')) + await expect(list({ connectionId: 'host-3' })).rejects.toThrow('relay unavailable') + await expect(list({ connectionId: 'missing' })).rejects.toThrow('No PTY provider') + expect(localList).not.toHaveBeenCalled() + }) + + it.each([null, {}, { connectionId: '' }, { connectionId: 42 }])( + 'rejects malformed scope %j before inventory admission', + async (scope) => { + const { list, localList, remoteLists } = install() + await expect(list(scope)).rejects.toThrow('invalid_pty_session_list_scope') + expect(localList).not.toHaveBeenCalled() + expect(remoteLists.every((mock) => mock.mock.calls.length === 0)).toBe(true) + } + ) + + it('preserves unscoped diagnostic inventory and its remote-error fallback', async () => { + const { list, localList, remoteLists } = install() + remoteLists[3].mockRejectedValue(new Error('relay unavailable')) + expect(await list()).toHaveLength(50) + expect(localList).toHaveBeenCalledOnce() + expect(remoteLists.every((mock) => mock.mock.calls.length === 1)).toBe(true) + }) +}) diff --git a/src/main/ipc/pty/ipc/inspect.ts b/src/main/ipc/pty/ipc/inspect.ts index 5a6d03d8855..37226017b8f 100644 --- a/src/main/ipc/pty/ipc/inspect.ts +++ b/src/main/ipc/pty/ipc/inspect.ts @@ -6,10 +6,11 @@ import { PtyProcessListAdmission, visitPtyProcessListingsInBatches } from '../../../providers/pty-process-list-admission' -import type { PtyListedSession } from '../../../../shared/pty-listed-session' +import type { PtyListedSession, PtySessionListScope } from '../../../../shared/pty-listed-session' import { ptyOwnership } from '../provider/ownership-state' import { getProviderForPty, + getProvider, hasPtyProviderForInspection, registeredPtyProviders, sshProviders, @@ -40,37 +41,58 @@ export function installPtyInspectIpcHandlers(deps: { ) } - ipcMain.handle('pty:listSessions', async (): Promise => { - const deduped = new Map() - const admission = new PtyProcessListAdmission() - await visitPtyProcessListingsInBatches( - registeredPtyProviders(), - ({ provider, connectionId }) => - connectionId === null ? provider.listProcesses() : provider.listProcesses().catch(() => []), - ({ provider, connectionId }, sessions) => { - for (const rawSession of sessions) { - const session = admission.admit(rawSession) - // Why: kill actions only send back the PTY id, so rebuild ownership while listing to keep reconnect-discovered remote sessions routed to their provider. - ptyOwnership.set(session.id, connectionId) - deduped.set(session.id, { - id: session.id, - cwd: session.cwd, - title: session.title, - // Why: the renderer's binding map is empty during restore, so ownership is the only - // liveness evidence it has. Absence is authoritative only from a provider that - // serializes claims — otherwise it is 'unknown', never 'absent' (#8459). - agentOwnership: - (session.agentSessionOwners?.length ?? 0) > 0 - ? 'present' - : provider.providesAgentSessionOwnerListings?.(session.id) === true - ? 'absent' - : 'unknown' - }) + ipcMain.handle( + 'pty:listSessions', + async (_event, scope?: PtySessionListScope): Promise => { + if (scope !== undefined) { + if ( + !scope || + (scope.connectionId !== null && + (typeof scope.connectionId !== 'string' || !scope.connectionId.trim())) + ) { + throw new Error('invalid_pty_session_list_scope') + } + // Select the daemon only after startup has handed off ownership. + if (scope.connectionId === null) { + await getLocalPtyProviderStartupPromise() } } - ) - return Array.from(deduped.values()) - }) + const deduped = new Map() + const admission = new PtyProcessListAdmission() + await visitPtyProcessListingsInBatches( + scope === undefined + ? registeredPtyProviders() + : [{ provider: getProvider(scope.connectionId), connectionId: scope.connectionId }], + ({ provider, connectionId }) => + connectionId === null || scope !== undefined + ? provider.listProcesses() + : provider.listProcesses().catch(() => []), + ({ provider, connectionId }, sessions) => { + for (const rawSession of sessions) { + const session = admission.admit(rawSession) + // Why: kill actions only send back the PTY id, so rebuild ownership while listing to keep reconnect-discovered remote sessions routed to their provider. + ptyOwnership.set(session.id, connectionId) + deduped.set(session.id, { + id: session.id, + cwd: session.cwd, + title: session.title, + ...(session.worktreeId !== undefined ? { worktreeId: session.worktreeId } : {}), + // Why: the renderer's binding map is empty during restore, so ownership is the only + // liveness evidence it has. Absence is authoritative only from a provider that + // serializes claims — otherwise it is 'unknown', never 'absent' (#8459). + agentOwnership: + (session.agentSessionOwners?.length ?? 0) > 0 + ? 'present' + : provider.providesAgentSessionOwnerListings?.(session.id) === true + ? 'absent' + : 'unknown' + }) + } + } + ) + return Array.from(deduped.values()) + } + ) ipcMain.handle( 'pty:getAuthoritativeBufferSnapshotCapabilities', diff --git a/src/main/ipc/pty/pane/stable-pane-relay-absence-respawn.test.ts b/src/main/ipc/pty/pane/stable-pane-relay-absence-respawn.test.ts index 9a77dd7fbb9..e68bcf6ec99 100644 --- a/src/main/ipc/pty/pane/stable-pane-relay-absence-respawn.test.ts +++ b/src/main/ipc/pty/pane/stable-pane-relay-absence-respawn.test.ts @@ -81,6 +81,49 @@ function sessionStore(leaves: string[]): { store: Store; read: () => WorkspaceSe } describe('stable pane adoption after the relay reports the PTY absent', () => { + it.each([false, true])( + 'reattaches a live pane without launching a provider process (settled worker: %s)', + async (settledWorker) => { + const { store, read } = sessionStore([LEAF]) + const paneKey = `${OWNER.tabId}:${LEAF}` + const record = { + paneKey, + tabId: OWNER.tabId, + worktreeId: WORKTREE, + agent: 'claude' as const, + providerSession: { key: 'session_id' as const, id: 'provider-session' }, + prompt: '', + state: 'done' as const, + capturedAt: 1, + updatedAt: 1, + ...(settledWorker ? { automaticResumeBlockedBy: 'legacy-orchestration-worker' } : {}) + } + store.setWorkspaceSession({ + ...read(), + sleepingAgentSessionsByPaneKey: { [paneKey]: record } + }) + const spawn = vi.fn().mockResolvedValue({ id: OWNER.ptyId, isReattach: true }) + const onFreshSpawn = vi.fn() + const result = await spawnForStablePane({ + runtime: undefined, + store, + worktreeId: WORKTREE, + provider: { spawn } as unknown as IPtyProvider, + spawnOptions: { cols: 80, rows: 24, command: 'claude --resume provider-session' }, + owner: OWNER, + connectionId: 'conn-1', + resolveOwner: () => OWNER, + onFreshSpawn + }) + expect(result.owner).toBe(OWNER) + expect(spawn).toHaveBeenCalledExactlyOnceWith( + expect.objectContaining({ sessionId: OWNER.ptyId, attachOnly: true, command: undefined }) + ) + expect(onFreshSpawn).not.toHaveBeenCalled() + expect(read().tabsByWorktree[WORKTREE]).toHaveLength(1) + } + ) + it('spawns fresh once the relay has positively answered for that id', async () => { const { run, spawn } = spawnAfterAttachRejection( new SshPtyAbsentFromRelayError(`${SSH_SESSION_EXPIRED_ERROR}: pty-1`) diff --git a/src/main/jira/jira-issue-search.ts b/src/main/jira/jira-issue-search.ts index 743342f7727..0d39c841ed4 100644 --- a/src/main/jira/jira-issue-search.ts +++ b/src/main/jira/jira-issue-search.ts @@ -1,3 +1,4 @@ +import { sortByUpdatedAtDescending } from '../../shared/updated-at-order' import type { JiraIssue, JiraIssueFilter, JiraSiteSelection } from '../../shared/jira-types' import { acquire, release } from './request-queue' import { apiBasePath, jiraRequest, type JiraClientForSite } from './authenticated-request' @@ -18,9 +19,7 @@ function clampLimit(limit: number | undefined, fallback = 30): number { } function sortAndLimitIssues(issues: JiraIssue[], limit: number): JiraIssue[] { - return issues - .sort((a, b) => new Date(b.updatedAt).getTime() - new Date(a.updatedAt).getTime()) - .slice(0, limit) + return sortByUpdatedAtDescending(issues).slice(0, limit) } function filterToJql(filter: JiraIssueFilter): string { diff --git a/src/main/linear/linear-issue-query-support.ts b/src/main/linear/linear-issue-query-support.ts index 216fb5f9b80..3154284ae2a 100644 --- a/src/main/linear/linear-issue-query-support.ts +++ b/src/main/linear/linear-issue-query-support.ts @@ -1,3 +1,4 @@ +import { sortByUpdatedAtDescending } from '../../shared/updated-at-order' import type { LinearIssue } from '../../shared/linear/issue-types' import type { LinearWorkspaceSelection } from '../../shared/linear/workspace-types' import { LINEAR_ISSUE_API_PAGE_SIZE_MAX } from '../../shared/linear/issue-read-limits' @@ -30,18 +31,14 @@ export async function mapIssueForWorkspace( } export function sortAndLimitIssues(issues: LinearIssue[], limit: number): LinearIssue[] { - return issues - .sort((a, b) => new Date(b.updatedAt).getTime() - new Date(a.updatedAt).getTime()) - .slice(0, limit) + return sortByUpdatedAtDescending(issues).slice(0, limit) } export function sortLimitAndDescribeIssues( issues: LinearIssue[], limit: number ): { items: LinearIssue[]; clipped: boolean } { - const sorted = issues.sort( - (a, b) => new Date(b.updatedAt).getTime() - new Date(a.updatedAt).getTime() - ) + const sorted = sortByUpdatedAtDescending(issues) return { items: sorted.slice(0, limit), clipped: sorted.length > limit diff --git a/src/main/native-chat/agent-session-wire/agent-session-history-page-bounds.ts b/src/main/native-chat/agent-session-wire/agent-session-history-page-bounds.ts index 582336ed10d..f305b9cc149 100644 --- a/src/main/native-chat/agent-session-wire/agent-session-history-page-bounds.ts +++ b/src/main/native-chat/agent-session-wire/agent-session-history-page-bounds.ts @@ -66,8 +66,7 @@ export function boundHistoryItemsByBytes( submissionBytes: ReadonlyMap, maxBytes: number ): { items: AgentJournalRenderItem[]; dropped: number } { - const groups = groupItemsBySequence(items) - const ordered = keep === 'newest' ? groups.toReversed() : groups + const ordered = groupItemsBySequence(items, keep) const kept: AgentJournalRenderItem[][] = [] let total = 0 for (const group of ordered) { @@ -88,29 +87,42 @@ export function boundHistoryItemsByBytes( } } -function groupItemsBySequence( - items: readonly AgentJournalRenderItem[] -): AgentJournalRenderItem[][] { - const groups: AgentJournalRenderItem[][] = [] - for (const item of items) { - const current = groups.at(-1) - if (current?.[0]?.sequence === item.sequence) { - current.push(item) +/** Adjacent same-sequence runs, walked from the end (`newest`) or the start (`oldest`) + * so a caller that stops at its window never groups the history it will not return. + * Groups and their items keep the order the eager forward grouping produced. */ +function* groupItemsBySequence( + items: readonly AgentJournalRenderItem[], + keep: 'newest' | 'oldest' +): Generator { + let cursor = keep === 'newest' ? items.length : 0 + while (keep === 'newest' ? cursor > 0 : cursor < items.length) { + if (keep === 'newest') { + let start = cursor - 1 + const sequence = items[start].sequence + while (start > 0 && items[start - 1].sequence === sequence) { + start -= 1 + } + yield items.slice(start, cursor) + cursor = start } else { - groups.push([item]) + let end = cursor + 1 + const sequence = items[cursor].sequence + while (end < items.length && items[end].sequence === sequence) { + end += 1 + } + yield items.slice(cursor, end) + cursor = end } } - return groups } export function newestWholeSequenceGroups( items: readonly AgentJournalRenderItem[], limit: number ): AgentJournalRenderItem[] { - const groups = groupItemsBySequence(items) const selected: AgentJournalRenderItem[][] = [] let count = 0 - for (const group of groups.toReversed()) { + for (const group of groupItemsBySequence(items, 'newest')) { if (selected.length > 0 && count + group.length > limit) { break } diff --git a/src/main/native-chat/agent-session-wire/agent-session-history-page-grouping-parity.test.ts b/src/main/native-chat/agent-session-wire/agent-session-history-page-grouping-parity.test.ts new file mode 100644 index 00000000000..e1e8f68f7bd --- /dev/null +++ b/src/main/native-chat/agent-session-wire/agent-session-history-page-grouping-parity.test.ts @@ -0,0 +1,171 @@ +import { expect, it } from 'vitest' +import type { AgentJournalRenderItem } from '../../../shared/agent-session-journal-types' +import { + boundHistoryItemsByBytes, + historyEntryBytes, + newestWholeSequenceGroups, + oversizedHistoryItem +} from './agent-session-history-page-bounds' + +/** The pre-generator eager grouping, verbatim, as the differential oracle. */ +function referenceGroups(items: readonly AgentJournalRenderItem[]): AgentJournalRenderItem[][] { + const groups: AgentJournalRenderItem[][] = [] + for (const item of items) { + const current = groups.at(-1) + if (current?.[0]?.sequence === item.sequence) { + current.push(item) + } else { + groups.push([item]) + } + } + return groups +} + +function referenceNewestWholeSequenceGroups( + items: readonly AgentJournalRenderItem[], + limit: number +): AgentJournalRenderItem[] { + const selected: AgentJournalRenderItem[][] = [] + let count = 0 + for (const group of referenceGroups(items).toReversed()) { + if (selected.length > 0 && count + group.length > limit) { + break + } + selected.push(group) + count += group.length + } + return selected.toReversed().flat() +} + +function referenceBoundHistoryItemsByBytes( + items: AgentJournalRenderItem[], + keep: 'newest' | 'oldest', + submissionBytes: ReadonlyMap, + maxBytes: number +): { items: AgentJournalRenderItem[]; dropped: number } { + const groups = referenceGroups(items) + const ordered = keep === 'newest' ? groups.toReversed() : groups + const kept: AgentJournalRenderItem[][] = [] + let total = 0 + for (const group of ordered) { + const bytes = group.reduce((sum, item) => sum + historyEntryBytes(item, submissionBytes), 0) + if (kept.length === 0 && bytes > maxBytes) { + kept.push(group.map((item) => oversizedHistoryItem(item, bytes))) + break + } + if (total + bytes > maxBytes) { + break + } + kept.push(group) + total += bytes + } + return { + items: (keep === 'newest' ? kept.toReversed() : kept).flat(), + dropped: items.length - kept.reduce((count, group) => count + group.length, 0) + } +} + +function item(index: number, sequence: number): AgentJournalRenderItem { + return { + itemId: `i${index}`, + revision: 1, + sequence, + observedAt: index, + body: { kind: 'status', text: `s${index}` } + } +} + +/** Every sequence-run shape of `length` items, as run-length compositions. */ +function* runShapes(length: number): Generator { + if (length === 0) { + yield [] + return + } + for (let first = 1; first <= length; first += 1) { + for (const rest of runShapes(length - first)) { + yield [first, ...rest] + } + } +} + +/** Build items from run lengths; `repeatSequence` reuses an earlier sequence value + * in a later run so non-adjacent duplicates are exercised too. */ +function buildItems(runs: number[], repeatSequence: boolean): AgentJournalRenderItem[] { + const items: AgentJournalRenderItem[] = [] + let index = 0 + runs.forEach((runLength, runIndex) => { + const sequence = repeatSequence && runIndex > 0 && runIndex % 2 === 0 ? 0 : runIndex + for (let i = 0; i < runLength; i += 1) { + items.push(item(index++, sequence)) + } + }) + return items +} + +it('matches eager grouping at every newest-window limit for every run shape', () => { + let cases = 0 + for (let length = 0; length <= 7; length += 1) { + for (const runs of runShapes(length)) { + for (const repeatSequence of [false, true]) { + const items = buildItems(runs, repeatSequence) + // Every boundary, including 0, each exact group edge, and past the end. + for (let limit = 0; limit <= length + 1; limit += 1) { + expect( + newestWholeSequenceGroups(items, limit), + `runs ${runs.join(',')} repeat ${repeatSequence} limit ${limit}` + ).toEqual(referenceNewestWholeSequenceGroups(items, limit)) + cases += 1 + } + } + } + } + expect(cases).toBeGreaterThan(1000) +}) + +it('matches eager byte bounding at every budget boundary in both directions', () => { + const submissionBytes = new Map() + let truncatedCases = 0 + let partialCases = 0 + for (let length = 1; length <= 6; length += 1) { + for (const runs of runShapes(length)) { + for (const repeatSequence of [false, true]) { + const items = buildItems(runs, repeatSequence) + const perItem = historyEntryBytes(items[0]!, submissionBytes) + // Sweep exact group-boundary budgets plus one byte either side of each. + const budgets = new Set([0, 1]) + for (let n = 0; n <= length + 1; n += 1) { + budgets.add(n * perItem - 1) + budgets.add(n * perItem) + budgets.add(n * perItem + 1) + } + for (const keep of ['newest', 'oldest'] as const) { + for (const maxBytes of budgets) { + const actual = boundHistoryItemsByBytes([...items], keep, submissionBytes, maxBytes) + const expected = referenceBoundHistoryItemsByBytes( + [...items], + keep, + submissionBytes, + maxBytes + ) + expect( + actual, + `runs ${runs.join(',')} repeat ${repeatSequence} keep ${keep} bytes ${maxBytes}` + ).toEqual(expected) + if ( + actual.items.some( + (entry) => entry.body.kind === 'status' && /truncated/.test(entry.body.text) + ) + ) { + truncatedCases += 1 + } else if (actual.dropped > 0) { + partialCases += 1 + } + } + } + } + } + } + // The oversized-first-group and partial-window paths must both be exercised. + expect(truncatedCases).toBeGreaterThan(50) + expect(partialCases).toBeGreaterThan(50) +}) diff --git a/src/main/native-chat/agent-session-wire/agent-session-history-page-scaling.test.ts b/src/main/native-chat/agent-session-wire/agent-session-history-page-scaling.test.ts new file mode 100644 index 00000000000..794966b017f --- /dev/null +++ b/src/main/native-chat/agent-session-wire/agent-session-history-page-scaling.test.ts @@ -0,0 +1,48 @@ +import { expect, it } from 'vitest' +import type { AgentJournalRenderItem } from '../../../shared/agent-session-journal-types' +import { + boundHistoryItemsByBytes, + newestWholeSequenceGroups +} from './agent-session-history-page-bounds' + +function item(index: number): AgentJournalRenderItem { + return { + itemId: String(index), + revision: 1, + sequence: index, + observedAt: index, + body: { kind: 'status', text: 'ok' } + } +} + +it('visits only the retained sequence window and its boundary', () => { + let reads = 0 + const items = Array.from({ length: 10000 }, (_, index) => ({ + ...item(index), + get sequence() { + reads += 1 + return index + } + })) + expect(newestWholeSequenceGroups(items, 100).map((entry) => entry.itemId)).toEqual( + Array.from({ length: 100 }, (_, index) => String(9900 + index)) + ) + expect(reads).toBeLessThan(300) + reads = 0 + expect(boundHistoryItemsByBytes(items, 'newest', new Map(), 1000).items.length).toBeGreaterThan(0) + expect(reads).toBeLessThan(100) +}) + +it('retains entire boundary groups and preserves oversized first-group truncation', () => { + const items = [item(1), { ...item(2), sequence: 1 }, item(3), { ...item(4), sequence: 3 }] + expect(newestWholeSequenceGroups(items, 1)).toEqual(items.slice(2)) + expect(newestWholeSequenceGroups(items, 3)).toEqual(items.slice(2)) + expect(boundHistoryItemsByBytes(items, 'oldest', new Map(), 1)).toMatchObject({ + dropped: 2, + items: [{ itemId: '1' }, { itemId: '2' }] + }) + expect(boundHistoryItemsByBytes(items, 'newest', new Map(), 1)).toMatchObject({ + dropped: 2, + items: [{ itemId: '3' }, { itemId: '4' }] + }) +}) diff --git a/src/main/observability/local-file-sink-memory.test.ts b/src/main/observability/local-file-sink-memory.test.ts new file mode 100644 index 00000000000..2c6644694b9 --- /dev/null +++ b/src/main/observability/local-file-sink-memory.test.ts @@ -0,0 +1,128 @@ +import { mkdtempSync, readFileSync, rmSync, statSync } from 'node:fs' +import { tmpdir } from 'node:os' +import { join } from 'node:path' +import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest' +import { createLocalFileSink, DROPPED_RECORD_TYPE, type LocalFileSink } from './local-file-sink' + +function parseLine(raw: string): Record { + return JSON.parse(raw) as Record +} + +let directory: string +let sink: LocalFileSink | undefined +beforeEach(() => { + directory = mkdtempSync(join(tmpdir(), 'orca-trace-memory-')) + vi.useFakeTimers() +}) +afterEach(() => { + sink?.close() + sink = undefined + vi.useRealTimers() + rmSync(directory, { recursive: true, force: true }) +}) + +function retainedHeap(): number { + if (!globalThis.gc) { + throw new Error('Memory regression requires --expose-gc') + } + globalThis.gc() + globalThis.gc() + return process.memoryUsage().heapUsed +} + +describe('trace sink rejected record retention', () => { + it('keeps small-record byte scans deferred until the batch flush', () => { + const filePath = join(directory, 'trace.ndjson') + sink = createLocalFileSink({ filePath }) + const byteLength = vi.spyOn(Buffer, 'byteLength') + let beforeFlush: number + let afterFlush: number + try { + for (let index = 0; index < 20; index++) { + sink.push({ index, text: '💡漢字' }) + } + beforeFlush = byteLength.mock.calls.length + sink.flush() + afterFlush = byteLength.mock.calls.length + } finally { + byteLength.mockRestore() + } + expect(beforeFlush).toBe(0) + expect(afterFlush).toBe(20) + }) + + it('releases oversized serialized records before the pending batch flushes', () => { + const filePath = join(directory, 'trace.ndjson') + sink = createLocalFileSink({ filePath, maxBytes: 64 * 1024, batchWindowMs: 200 }) + const before = retainedHeap() + for (let index = 0; index < 24; index++) { + sink.push({ index, payload: 'x'.repeat(1024 * 1024) }) + } + const retained = retainedHeap() - before + expect(statSync(filePath).size).toBe(0) + expect(vi.getTimerCount()).toBe(1) + expect(retained).toBeLessThan(5 * 1024 * 1024) + sink.push({ valid: true }) + vi.advanceTimersByTime(200) + const written = readFileSync(filePath, 'utf8').split('\n').filter(Boolean).map(parseLine) + // Each rejected record leaves a marker, so the gap is readable instead of silent. + expect(written.filter((entry) => entry.type === DROPPED_RECORD_TYPE)).toHaveLength(24) + expect(written.at(-1)).toEqual({ valid: true }) + }) + + it('names the dropped record in the marker instead of leaving a silent gap', () => { + const filePath = join(directory, 'trace.ndjson') + sink = createLocalFileSink({ filePath, maxBytes: 64 * 1024, flushBufferThreshold: 1 }) + sink.push({ + type: 'effect-span', + name: 'worktree.create', + traceId: 'a'.repeat(32), + payload: 'x'.repeat(1024 * 1024) + }) + const [marker] = readFileSync(filePath, 'utf8').split('\n').filter(Boolean).map(parseLine) + expect(marker).toMatchObject({ + type: DROPPED_RECORD_TYPE, + reason: 'oversize', + name: 'worktree.create', + traceId: 'a'.repeat(32) + }) + expect(marker.droppedChars).toBeGreaterThan(1024 * 1024) + // Timestamped so the bundle collector's lookback filter ages markers out like any other span. + expect(BigInt(marker.endTimeUnixNano as string)).toBeGreaterThan(0n) + }) + + it('omits the marker when even the marker would exceed the byte cap', () => { + const filePath = join(directory, 'trace.ndjson') + sink = createLocalFileSink({ filePath, maxBytes: 40, flushBufferThreshold: 1 }) + sink.push({ payload: 'x'.repeat(1_000) }) + sink.push({ ok: 1 }) + expect(readFileSync(filePath, 'utf8')).toBe('{"ok":1}\n') + }) + + it('keeps the same count-triggered flush for valid records beside rejected ones', () => { + const filePath = join(directory, 'trace.ndjson') + sink = createLocalFileSink({ filePath, maxBytes: 32, flushBufferThreshold: 3 }) + sink.push({ valid: 1 }) + sink.push({ payload: '💡'.repeat(20) }) + expect(statSync(filePath).size).toBe(0) + sink.push({ payload: 'x'.repeat(100) }) + expect(readFileSync(filePath, 'utf8')).toBe('{"valid":1}\n') + sink.push({ valid: 2 }) + vi.advanceTimersByTime(200) + expect(readFileSync(filePath, 'utf8')).toBe('{"valid":1}\n{"valid":2}\n') + }) + + it('accepts the exact UTF-8 byte cap and preserves rotation and close flushes', () => { + const filePath = join(directory, 'trace.ndjson') + const record = { text: '💡' } + const line = `${JSON.stringify(record)}\n` + sink = createLocalFileSink({ filePath, maxBytes: Buffer.byteLength(line), maxFiles: 2 }) + sink.push(record) + sink.push({ text: '💡x' }) + sink.push(record) + sink.close() + expect(readFileSync(filePath, 'utf8')).toBe(line) + expect(readFileSync(`${filePath}.1`, 'utf8')).toBe(line) + expect(vi.getTimerCount()).toBe(0) + }) +}) diff --git a/src/main/observability/local-file-sink.ts b/src/main/observability/local-file-sink.ts index b2a74bbbb40..7e6eef9ddac 100644 --- a/src/main/observability/local-file-sink.ts +++ b/src/main/observability/local-file-sink.ts @@ -25,6 +25,9 @@ export const DEFAULT_MAX_FILES = 10 export const DEFAULT_BATCH_WINDOW_MS = 200 const PRIVATE_DIRECTORY_MODE = 0o700 const PRIVATE_FILE_MODE = 0o600 +/** NDJSON `type` for the placeholder left behind when a record is too large to store. */ +export const DROPPED_RECORD_TYPE = 'trace-record-dropped' +const MAX_MARKER_NAME_CHARS = 120 export type LocalFileSinkOptions = { readonly filePath: string @@ -77,7 +80,7 @@ export function createLocalFileSink(opts: LocalFileSinkOptions): LocalFileSink { let fd: number = openAppend(filePath) let currentBytes: number = safeFstatSize(fd) - let buffer: string[] = [] + let buffer: (string | null)[] = [] let timer: NodeJS.Timeout | null = null let closed = false @@ -171,11 +174,10 @@ export function createLocalFileSink(opts: LocalFileSinkOptions): LocalFileSink { } for (const line of lines) { - const lineBytes = Buffer.byteLength(line, 'utf8') - if (lineBytes > maxBytes) { - // Oversized single span would blow the maxFiles × maxBytes envelope; drop just this record. + if (line === null) { continue } + const lineBytes = Buffer.byteLength(line, 'utf8') if (pendingChunkBytes > 0 && currentBytes + pendingChunkBytes + lineBytes > maxBytes) { flushPendingChunk() } @@ -189,6 +191,27 @@ export function createLocalFileSink(opts: LocalFileSinkOptions): LocalFileSink { flushPendingChunk() } + /** + * Stand-in for a record too large to store. `droppedChars` is UTF-16 units, not bytes: measuring + * bytes is the scan this path exists to skip. Returns null when even the marker exceeds maxBytes. + */ + function oversizeMarker(record: unknown, droppedChars: number): string | null { + const span = + typeof record === 'object' && record !== null ? (record as Record) : {} + const name = typeof span.name === 'string' ? span.name.slice(0, MAX_MARKER_NAME_CHARS) : null + const traceId = typeof span.traceId === 'string' ? span.traceId.slice(0, 32) : null + const marker = `${JSON.stringify({ + type: DROPPED_RECORD_TYPE, + reason: 'oversize', + droppedChars, + // Lets the bundle collector's lookback filter age these out like any other span. + endTimeUnixNano: `${Date.now()}000000`, + ...(name === null ? {} : { name }), + ...(traceId === null ? {} : { traceId }) + })}\n` + return Buffer.byteLength(marker, 'utf8') > maxBytes ? null : marker + } + function ensureTimer(): void { if (timer || closed) { return @@ -216,7 +239,13 @@ export function createLocalFileSink(opts: LocalFileSinkOptions): LocalFileSink { // Redactor handles cycles upstream; a throw here means pre-redact data slipped in — drop rather than crash (best-effort). return } - buffer.push(line) + // UTF-8 uses at most three bytes per UTF-16 unit; small records need no admission scan. + const oversized = + line.length > maxBytes || + (line.length * 3 > maxBytes && Buffer.byteLength(line, 'utf8') > maxBytes) + // Rejected records still occupy a buffer slot (preserving flush timing) but carry a marker + // instead of their payload, so the gap they leave is readable rather than silent. + buffer.push(oversized ? oversizeMarker(record, line.length) : line) if (buffer.length >= flushThreshold) { flushBuffer() } else { diff --git a/src/main/persistence/applying-settings/settings-update-terminal-contrast.test.ts b/src/main/persistence/applying-settings/settings-update-terminal-contrast.test.ts new file mode 100644 index 00000000000..7de32d7b36d --- /dev/null +++ b/src/main/persistence/applying-settings/settings-update-terminal-contrast.test.ts @@ -0,0 +1,74 @@ +import { describe, expect, it, vi } from 'vitest' +import type { PersistedState } from '../../../shared/persisted-state-types' +import { updateSettings, type SettingsMutationOperations } from './settings-update' + +function makeOperations(): SettingsMutationOperations { + return { + // Only the fields updateSettings reads; the rest of GlobalSettings is irrelevant to the clamp. + state: { settings: { terminalFontSize: 14 }, repos: [] } as unknown as PersistedState, + bumpLocalWorktreeScanGeneration: vi.fn(), + removeRetainedBlob: vi.fn(), + scheduleSave: vi.fn(), + notifySettingsChanged: vi.fn() + } +} + +// #10754: desktop IPC, the web RPC and the CLI all reach the store through this boundary, and xterm +// throws on a non-finite minimumContrastRatio, so the clamp cannot live in the settings UI alone. +describe('updateSettings terminalMinimumContrastRatio', () => { + it('persists an in-range floor unchanged', () => { + const operations = makeOperations() + + expect( + updateSettings(operations, { terminalMinimumContrastRatio: 1 }).terminalMinimumContrastRatio + ).toBe(1) + expect( + updateSettings(operations, { terminalMinimumContrastRatio: 4.5 }).terminalMinimumContrastRatio + ).toBe(4.5) + }) + + it('clamps a hand-edited value into xterm range', () => { + const operations = makeOperations() + + expect( + updateSettings(operations, { terminalMinimumContrastRatio: 0 }).terminalMinimumContrastRatio + ).toBe(1) + expect( + updateSettings(operations, { terminalMinimumContrastRatio: 500 }).terminalMinimumContrastRatio + ).toBe(21) + }) + + it('drops an unusable value back to automatic rather than storing it', () => { + const operations = makeOperations() + + expect( + updateSettings(operations, { + terminalMinimumContrastRatio: Number.NaN + }).terminalMinimumContrastRatio + ).toBeUndefined() + expect( + updateSettings(operations, { + terminalMinimumContrastRatio: 'off' as unknown as number + }).terminalMinimumContrastRatio + ).toBeUndefined() + }) + + it('clears the override so the automatic floor comes back', () => { + const operations = makeOperations() + + updateSettings(operations, { terminalMinimumContrastRatio: 1 }) + expect( + updateSettings(operations, { terminalMinimumContrastRatio: undefined }) + .terminalMinimumContrastRatio + ).toBeUndefined() + }) + + it('leaves a stored floor alone when an unrelated setting is written', () => { + const operations = makeOperations() + + updateSettings(operations, { terminalMinimumContrastRatio: 1 }) + expect(updateSettings(operations, { terminalFontSize: 15 }).terminalMinimumContrastRatio).toBe( + 1 + ) + }) +}) diff --git a/src/main/persistence/applying-settings/settings-update.ts b/src/main/persistence/applying-settings/settings-update.ts index 20614061bdd..e8a080763da 100644 --- a/src/main/persistence/applying-settings/settings-update.ts +++ b/src/main/persistence/applying-settings/settings-update.ts @@ -9,6 +9,7 @@ import { normalizeTerminalQuickCommands } from '../../../shared/terminal-quick-c import { normalizeTerminalCustomThemes } from '../../../shared/terminal-custom-themes' import { normalizeTerminalCursorStyleDefault } from '../../../shared/terminal-cursor-style-settings' import { normalizeDesktopTerminalScrollbackRows } from '../../../shared/terminal-scrollback-policy' +import { normalizeTerminalMinimumContrastRatio } from '../../../shared/terminal-minimum-contrast-settings' import { normalizeTaskProviderSettings } from '../../../shared/task-providers' import { normalizeOpenInApplications } from '../../../shared/open-in-applications' import { normalizeTerminalShortcutPolicy } from '../../../shared/keybindings' @@ -123,6 +124,13 @@ export function updateSettings( updates.terminalScrollbackRows ) } + // Why here: every writer (desktop IPC, web RPC, CLI) crosses this boundary, so xterm can never be + // handed an out-of-range floor, and undefined stays undefined to mean "automatic" (#10754). + if ('terminalMinimumContrastRatio' in updates) { + sanitizedUpdates.terminalMinimumContrastRatio = normalizeTerminalMinimumContrastRatio( + updates.terminalMinimumContrastRatio + ) + } if ( 'terminalTuiScrollSensitivity' in updates || 'terminalTuiScrollSensitivityDefaultedToOne' in updates diff --git a/src/main/persistence/leasing-ssh-ptys/ssh-pty-binding-cleanup.test.ts b/src/main/persistence/leasing-ssh-ptys/ssh-pty-binding-cleanup.test.ts new file mode 100644 index 00000000000..03badd28f94 --- /dev/null +++ b/src/main/persistence/leasing-ssh-ptys/ssh-pty-binding-cleanup.test.ts @@ -0,0 +1,136 @@ +import { describe, expect, it, vi } from 'vitest' +import { getDefaultPersistedState, getDefaultWorkspaceSession } from '../../../shared/constants' +import type { SshRemotePtyLease } from '../../../shared/ssh-types' +import { toComparableRelaySshPtyId } from '../../../shared/ssh-pty-id' +import { clearSshRemotePtyBindingsForLeases } from './ssh-pty-binding-cleanup' + +function fixture(count: number) { + const state = getDefaultPersistedState('/home/test') + state.workspaceSession = getDefaultWorkspaceSession() + state.workspaceSession.tabsByWorktree.wt = Array.from({ length: count }, (_, i) => ({ + id: `tab-${i}`, + worktreeId: 'wt', + ptyId: `pty-${i}`, + title: '', + customTitle: null, + color: null, + sortOrder: i, + createdAt: 1 + })) + const leases: SshRemotePtyLease[] = Array.from({ length: count }, (_, i) => ({ + targetId: 'ssh-one', + ptyId: `pty-${i}`, + tabId: `tab-${i}`, + worktreeId: 'wt', + state: 'detached', + createdAt: 1, + updatedAt: 1 + })) + return { + state, + leases, + toComparablePtyId: vi.fn((_target: string, ptyId: string) => ptyId), + scheduleSave: vi.fn() + } +} + +describe('SSH binding cleanup indexing', () => { + it('normalizes each binding once across a large lease inventory', () => { + const operations = fixture(1000) + expect(clearSshRemotePtyBindingsForLeases(operations, 'ssh-one', operations.leases)).toBe(true) + expect(operations.toComparablePtyId).toHaveBeenCalledTimes(1000) + expect( + operations.state.workspaceSession!.tabsByWorktree.wt.every((tab) => tab.ptyId === null) + ).toBe(true) + expect(operations.scheduleSave).toHaveBeenCalledTimes(1) + }) + + it('retains foreign hosts and conflicting tab/workspace leases', () => { + const operations = fixture(4) + operations.leases[0].targetId = 'ssh-two' + operations.leases[1].tabId = 'other-tab' + operations.leases[2].worktreeId = 'other-workspace' + delete operations.leases[3].tabId + clearSshRemotePtyBindingsForLeases(operations, 'ssh-one', operations.leases) + expect(operations.state.workspaceSession!.tabsByWorktree.wt.map((tab) => tab.ptyId)).toEqual([ + 'pty-0', + 'pty-1', + 'pty-2', + null + ]) + }) + + it('matches layout leaves against every lease for a PTY while preserving leaf conflicts', () => { + const operations = fixture(1) + const session = operations.state.workspaceSession! + session.tabsByWorktree.wt[0].ptyId = null + session.terminalLayoutsByTabId['tab-0'] = { + root: null, + activeLeafId: null, + expandedLeafId: null, + ptyIdsByLeafId: { + matched: 'pty-0', + protected: 'pty-0', + wildcard: 'pty-1' + } + } + const lease = operations.leases[0] + operations.leases = [ + { ...lease, leafId: 'wrong' }, + { ...lease, leafId: 'matched' }, + { ...lease, ptyId: 'pty-1' } + ] + expect(clearSshRemotePtyBindingsForLeases(operations, 'ssh-one', operations.leases)).toBe(true) + expect(session.terminalLayoutsByTabId['tab-0'].ptyIdsByLeafId).toEqual({ + protected: 'pty-0' + }) + expect(operations.toComparablePtyId).toHaveBeenCalledTimes(3) + }) + + it('normalizes app-form binding ids onto the relay-form lease key', () => { + // Leases store the relay-local id; sessions may hold the app-wide "ssh:@@" form. + // The index key is the normalized form, so both spellings still name the same PTY. + const operations = fixture(1) + operations.toComparablePtyId = vi.fn(toComparableRelaySshPtyId) + operations.state.workspaceSession!.tabsByWorktree.wt[0].ptyId = 'ssh:ssh-one@@pty-0' + + expect(clearSshRemotePtyBindingsForLeases(operations, 'ssh-one', operations.leases)).toBe(true) + expect(operations.state.workspaceSession!.tabsByWorktree.wt[0].ptyId).toBeNull() + }) + + it('keeps a binding whose app-form id names a different SSH target', () => { + // Relay-local ids collide across targets ("pty-0" exists on every host). Clearing ssh-one must + // never scrub a pane still bound to a live ssh-two shell. + const operations = fixture(1) + operations.toComparablePtyId = vi.fn(toComparableRelaySshPtyId) + operations.state.workspaceSession!.tabsByWorktree.wt[0].ptyId = 'ssh:ssh-two@@pty-0' + + expect(clearSshRemotePtyBindingsForLeases(operations, 'ssh-one', operations.leases)).toBe(false) + expect(operations.state.workspaceSession!.tabsByWorktree.wt[0].ptyId).toBe('ssh:ssh-two@@pty-0') + expect(operations.scheduleSave).not.toHaveBeenCalled() + }) + + it('keeps every binding when no lease names its PTY', () => { + // A bucket miss must fail closed: leak a stale id rather than unbind a live pane. + const operations = fixture(2) + for (const lease of operations.leases) { + lease.ptyId = `unrelated-${lease.ptyId}` + } + + expect(clearSshRemotePtyBindingsForLeases(operations, 'ssh-one', operations.leases)).toBe(false) + expect(operations.state.workspaceSession!.tabsByWorktree.wt.map((tab) => tab.ptyId)).toEqual([ + 'pty-0', + 'pty-1' + ]) + expect(operations.scheduleSave).not.toHaveBeenCalled() + }) + + it('does not index leases when the session holds no bindings to check', () => { + const operations = fixture(500) + operations.state.workspaceSession!.tabsByWorktree = {} + operations.state.workspaceSession!.terminalLayoutsByTabId = {} + + expect(clearSshRemotePtyBindingsForLeases(operations, 'ssh-one', operations.leases)).toBe(false) + expect(operations.toComparablePtyId).not.toHaveBeenCalled() + }) +}) diff --git a/src/main/persistence/leasing-ssh-ptys/ssh-pty-binding-cleanup.ts b/src/main/persistence/leasing-ssh-ptys/ssh-pty-binding-cleanup.ts index 65b879795dc..c467e0fc3ab 100644 --- a/src/main/persistence/leasing-ssh-ptys/ssh-pty-binding-cleanup.ts +++ b/src/main/persistence/leasing-ssh-ptys/ssh-pty-binding-cleanup.ts @@ -9,8 +9,8 @@ export type SshPtyBindingCleanupOperations = { scheduleSave: () => void } +/** `binding.ptyId` must already be in lease-comparable (relay) form; callers normalize it. */ function sshRemotePtyLeaseMayReferenceBinding( - operations: SshPtyBindingCleanupOperations, lease: SshRemotePtyLease, binding: { ptyId: string @@ -20,8 +20,7 @@ function sshRemotePtyLeaseMayReferenceBinding( leafId?: string } ): boolean { - const bindingPtyId = operations.toComparablePtyId(binding.targetId, binding.ptyId) - if (lease.targetId !== binding.targetId || lease.ptyId !== bindingPtyId) { + if (lease.targetId !== binding.targetId || lease.ptyId !== binding.ptyId) { return false } // Why: target removal is destructive; scrub matching bindings before deleting the lease, else removing the tombstone can revive stale PTY ids. @@ -50,6 +49,33 @@ export function clearSshRemotePtyBindingsForLeases( if (!leases?.length) { return false } + // Keyed by the stored (relay) pty id, which is the only form a lease holds; every lookup below + // normalizes the binding id to that form first, so a bucket miss means "no lease names this pty" + // and the binding is KEPT. Failing closed here leaves a stale id to be retired on reattach, + // where clearing on a bad match would strand a live remote shell behind a respawned pane. + let leasesByPtyId: Map | undefined + const referencesBinding = ( + binding: Parameters[1] + ): boolean => { + if (!leasesByPtyId) { + leasesByPtyId = new Map() + for (const lease of leases) { + if (lease.targetId !== targetId) { + continue + } + const entries = leasesByPtyId.get(lease.ptyId) + if (entries) { + entries.push(lease) + } else { + leasesByPtyId.set(lease.ptyId, [lease]) + } + } + } + const ptyId = operations.toComparablePtyId(binding.targetId, binding.ptyId) + return (leasesByPtyId.get(ptyId) ?? []).some((lease) => + sshRemotePtyLeaseMayReferenceBinding(lease, { ...binding, ptyId }) + ) + } let changed = false const sessions = new Set( [ @@ -62,14 +88,7 @@ export function clearSshRemotePtyBindingsForLeases( for (const tab of tabs) { if ( tab.ptyId && - leases.some((lease) => - sshRemotePtyLeaseMayReferenceBinding(operations, lease, { - ptyId: tab.ptyId!, - worktreeId, - targetId, - tabId: tab.id - }) - ) + referencesBinding({ ptyId: tab.ptyId, worktreeId, targetId, tabId: tab.id }) ) { tab.ptyId = null changed = true @@ -92,16 +111,7 @@ export function clearSshRemotePtyBindingsForLeases( const worktreeId = worktreeIdByTabId.get(tabId) const nextBindings = Object.fromEntries( Object.entries(bindings).filter( - ([leafId, ptyId]) => - !leases.some((lease) => - sshRemotePtyLeaseMayReferenceBinding(operations, lease, { - ptyId, - targetId, - worktreeId, - tabId, - leafId - }) - ) + ([leafId, ptyId]) => !referencesBinding({ ptyId, targetId, worktreeId, tabId, leafId }) ) ) if (Object.keys(nextBindings).length !== Object.keys(bindings).length) { diff --git a/src/main/persistence/loading-store/workspace-session-terminal-binding-replay.test.ts b/src/main/persistence/loading-store/workspace-session-terminal-binding-replay.test.ts index 97f10729ca0..d41b973f3ab 100644 --- a/src/main/persistence/loading-store/workspace-session-terminal-binding-replay.test.ts +++ b/src/main/persistence/loading-store/workspace-session-terminal-binding-replay.test.ts @@ -168,4 +168,45 @@ describe('workspace session terminal binding replay', () => { [LEAF_TWO]: 'pty-b' }) }) + + it('fails closed when one tab id is duplicated inside a single worktree list', () => { + // Map indexing is last-wins where a linear find was first-wins; the ambiguity + // fence must skip these ids so the two strategies can never disagree. + const prior = session(null) + prior.tabsByWorktree = { + [WORKTREE_A]: [ + terminalTab(WORKTREE_A, 'duplicate-tab', 'pty-first'), + terminalTab(WORKTREE_A, 'duplicate-tab', 'pty-last') + ] + } + const incoming = session(null) + incoming.tabsByWorktree = { + [WORKTREE_A]: [terminalTab(WORKTREE_A, 'duplicate-tab', null)] + } + + preserveMissingWorkspaceSessionTerminalBindings(incoming, prior, bindingRecovery as never) + + expect(incoming.tabsByWorktree[WORKTREE_A]![0]!.ptyId).toBeNull() + }) + + it('indexes prior tabs once when replaying a large workspace snapshot', () => { + let reads = 0 + const prior = session(null) + prior.tabsByWorktree.worktree = Array.from({ length: 1000 }, (_, i) => ({ + ...terminalTab('worktree', `tab-${i}`, `pty-${i}`), + get id() { + reads++ + return `tab-${i}` + } + })) + const incoming = session(null) + incoming.tabsByWorktree.worktree = Array.from({ length: 1000 }, (_, i) => + terminalTab('worktree', `tab-${i}`, null) + ) + preserveMissingWorkspaceSessionTerminalBindings(incoming, prior, bindingRecovery as never) + expect(reads).toBeLessThan(10_000) + expect(incoming.tabsByWorktree.worktree.map((tab) => tab.ptyId)).toEqual( + Array.from({ length: 1000 }, (_, i) => `pty-${i}`) + ) + }) }) diff --git a/src/main/persistence/loading-store/workspace-session-terminal-binding-replay.ts b/src/main/persistence/loading-store/workspace-session-terminal-binding-replay.ts index c064877b1d8..8e805b67b50 100644 --- a/src/main/persistence/loading-store/workspace-session-terminal-binding-replay.ts +++ b/src/main/persistence/loading-store/workspace-session-terminal-binding-replay.ts @@ -93,6 +93,7 @@ export function preserveMissingWorkspaceSessionTerminalBindings( if (!priorList) { continue } + let priorById: Map | undefined for (const tab of tabs) { if (ambiguousTabIds.has(tab.id)) { continue @@ -100,7 +101,8 @@ export function preserveMissingWorkspaceSessionTerminalBindings( if (tab.ptyId) { continue } - const priorTab = priorList.find((candidate) => candidate.id === tab.id) + priorById ??= new Map(priorList.map((candidate) => [candidate.id, candidate])) + const priorTab = priorById.get(tab.id) const incomingLayout = nextLayouts[tab.id] const priorLayout = priorLayouts[tab.id] const priorPtyLeafId = priorLayout diff --git a/src/main/persistence/restoring-sessions/pane-alias-normalization-scaling.test.ts b/src/main/persistence/restoring-sessions/pane-alias-normalization-scaling.test.ts new file mode 100644 index 00000000000..2077af8d17a --- /dev/null +++ b/src/main/persistence/restoring-sessions/pane-alias-normalization-scaling.test.ts @@ -0,0 +1,114 @@ +import { expect, it, vi } from 'vitest' +import type { MigrationUnsupportedPtyEntry } from '../../../shared/agent-status-types' +import { legacyMigrationUnsupportedRowsToAliasEntries } from './pane-alias-normalization' + +vi.mock('../../agent-hooks/server', () => ({ agentHookServer: {} })) + +it('retains only the ambiguity verdict when many legacy rows name the same tab', () => { + const row: MigrationUnsupportedPtyEntry = { + ptyId: 'pty', + tabId: 'tab', + paneKey: 'tab:11111111-1111-4111-8111-111111111111', + reason: 'legacy-numeric-pane-key', + source: 'local', + updatedAt: 1 + } + const rows = Array.from({ length: 2000 }, () => row) + const iterator = Array.prototype[Symbol.iterator] + let copied = 0 + Array.prototype[Symbol.iterator] = function (this: unknown[]) { + if (this[0] === row) { + copied += this.length + } + return iterator.call(this) + } + let aliases: ReturnType + try { + aliases = legacyMigrationUnsupportedRowsToAliasEntries(rows) + } finally { + Array.prototype[Symbol.iterator] = iterator + } + expect(copied).toBeLessThan(10_000) + expect(aliases).toEqual([]) + const unique = legacyMigrationUnsupportedRowsToAliasEntries([row]) + expect(unique.map((entry) => entry.legacyPaneKey)).toEqual(['tab:0', 'tab:1']) + expect(unique.every((entry) => entry.stablePaneKey === row.paneKey)).toBe(true) +}) + +function legacyRow(overrides: Partial): MigrationUnsupportedPtyEntry { + return { + ptyId: 'pty', + tabId: 'tab', + paneKey: 'tab:11111111-1111-4111-8111-111111111111', + reason: 'legacy-numeric-pane-key', + source: 'local', + updatedAt: 1, + ...overrides + } +} + +// Ambiguity must fail closed: only an exactly-one row per tab may mint an alias. +it.each([ + ['0 rows', 0], + ['2 rows', 2], + ['3 rows', 3], + ['4 rows', 4] +])('mints no alias for a tab named by %s', (_label, count) => { + const rows = Array.from({ length: count }, (_, i) => + legacyRow({ + ptyId: `pty-${i}`, + paneKey: `tab:1111111${i}-1111-4111-8111-111111111111` + }) + ) + expect(legacyMigrationUnsupportedRowsToAliasEntries(rows)).toEqual([]) +}) + +it('mints both numeric aliases for a tab named by exactly 1 row', () => { + const row = legacyRow({ ptyId: 'pty-solo' }) + expect(legacyMigrationUnsupportedRowsToAliasEntries([row])).toEqual([ + { + ptyId: 'pty-solo', + legacyPaneKey: 'tab:0', + stablePaneKey: row.paneKey, + updatedAt: 1 + }, + { + ptyId: 'pty-solo', + legacyPaneKey: 'tab:1', + stablePaneKey: row.paneKey, + updatedAt: 1 + } + ]) +}) + +it('keeps unambiguous tabs in first-seen order while dropping ambiguous neighbours', () => { + const solo = legacyRow({ + tabId: 'solo', + ptyId: 'pty-solo', + paneKey: 'solo:11111111-1111-4111-8111-111111111111' + }) + const dupA = legacyRow({ + tabId: 'dup', + ptyId: 'pty-a', + paneKey: 'dup:22222222-2222-4222-8222-222222222222' + }) + const dupB = legacyRow({ + tabId: 'dup', + ptyId: 'pty-b', + paneKey: 'dup:33333333-3333-4333-8333-333333333333' + }) + const late = legacyRow({ + tabId: 'late', + ptyId: 'pty-late', + paneKey: 'late:44444444-4444-4444-8444-444444444444' + }) + // A third row for 'dup' must not resurrect it: ambiguity is sticky, not a parity toggle. + const aliases = legacyMigrationUnsupportedRowsToAliasEntries([solo, dupA, dupB, late, dupA]) + expect(aliases.map((entry) => entry.legacyPaneKey)).toEqual([ + 'solo:0', + 'solo:1', + 'late:0', + 'late:1' + ]) + expect(aliases.every((entry) => entry.ptyId !== 'pty-a' && entry.ptyId !== 'pty-b')).toBe(true) +}) diff --git a/src/main/persistence/restoring-sessions/pane-alias-normalization.ts b/src/main/persistence/restoring-sessions/pane-alias-normalization.ts index 057780ce143..c7e88c48021 100644 --- a/src/main/persistence/restoring-sessions/pane-alias-normalization.ts +++ b/src/main/persistence/restoring-sessions/pane-alias-normalization.ts @@ -14,21 +14,17 @@ export function legacyMigrationUnsupportedRowsToAliasEntries( const normalizedEntries = normalizeMigrationUnsupportedPtyEntries(entries).filter( (entry) => entry.tabId && entry.paneKey && parsePaneKey(entry.paneKey) ) - const entriesByTabId = new Map() + const entriesByTabId = new Map() for (const entry of normalizedEntries) { const tabId = entry.tabId if (!tabId) { continue } - entriesByTabId.set(tabId, [...(entriesByTabId.get(tabId) ?? []), entry]) + entriesByTabId.set(tabId, entriesByTabId.has(tabId) ? null : entry) } const aliasEntries: LegacyPaneKeyAliasEntry[] = [] - for (const [tabId, tabEntries] of entriesByTabId) { - if (tabEntries.length !== 1) { - continue - } - const [entry] = tabEntries - if (!entry.paneKey) { + for (const [tabId, entry] of entriesByTabId) { + if (!entry?.paneKey) { continue } // Why: pre-stable rows lack the old numeric key; only synthesize single-pane aliases when the row is unambiguous. diff --git a/src/main/pi/agent-status-extension-source.test.ts b/src/main/pi/agent-status-extension-source.test.ts index fed179837db..fa9823d76dd 100644 --- a/src/main/pi/agent-status-extension-source.test.ts +++ b/src/main/pi/agent-status-extension-source.test.ts @@ -481,12 +481,14 @@ describe('getPiAgentStatusExtensionSource', () => { await handlerCall }) - it('leaves runtime shutdown to PTY teardown instead of reporting turn completion', () => { + it('leaves runtime shutdown to PTY teardown instead of reporting turn completion', async () => { const harness = createHarness({ kind: 'pi' }) - // Why: Pi emits session_shutdown for reload/new/resume/fork while its PTY - // stays alive. agent_end is the only extension event that proves done. - expect(harness.handlers.session_shutdown).toBeUndefined() + // Why: Pi emits session_shutdown for reload/new/resume/fork while its PTY stays + // alive. agent_end is the only extension event that proves done, so the handler + // exists solely to release a dialog Pi tore down without a close. + await harness.callHook('session_shutdown') + expect(harness.fetchMock).not.toHaveBeenCalled() }) it('bounds stalled delivery to one active request and the latest pending status', async () => { diff --git a/src/main/pi/agent-status-extension-source.ts b/src/main/pi/agent-status-extension-source.ts index 8b046e0db79..38775ca1973 100644 --- a/src/main/pi/agent-status-extension-source.ts +++ b/src/main/pi/agent-status-extension-source.ts @@ -101,7 +101,7 @@ export function getPiAgentStatusExtensionSource(kind: PiAgentKind = 'pi'): strin '// Orca receiver from building an unbounded queue of obsolete snapshots.', 'const HOOK_POST_TIMEOUT_MS = 1000', 'let activePost = false', - ...(kind === 'pi' ? ['let piUiPromptActive = false'] : []), + ...(kind === 'pi' ? ['let piUiPromptDepth = 0', 'let piTurnInFlight = false'] : []), 'let pendingPost: { hookEventName: string; extra: Record; metadata: Record; ompRuntime: boolean } | null = null', ...sessionMetadataSourceLines, '', @@ -167,7 +167,7 @@ export function getPiAgentStatusExtensionSource(kind: PiAgentKind = 'pi'): strin ' hookEventName,', // Why: every coalesced snapshot must retain an open modal, not just its start event. kind === 'pi' - ? ' extra: { ...extra, ...(!ompRuntime && piUiPromptActive ? { ui_prompt_active: true } : {}) },' + ? ' extra: { ...extra, ...(!ompRuntime && piUiPromptDepth > 0 ? { ui_prompt_active: true } : {}) },' : ' extra,', ' metadata: getPostSessionMetadata(ompRuntime),', ' ompRuntime,', diff --git a/src/main/pi/agent-status-handler-source.ts b/src/main/pi/agent-status-handler-source.ts index a769bfc74d2..9d02abbd78d 100644 --- a/src/main/pi/agent-status-handler-source.ts +++ b/src/main/pi/agent-status-handler-source.ts @@ -9,6 +9,7 @@ export function getPiAgentStatusHandlerSourceLines(kind: PiAgentKind): string[] ? [ " pi.on('session_start', (event, ctx) => {", ' updateSessionMetadata(ctx)', + ...(kind === 'pi' ? [' piUiPromptDepth = 0'] : []), ' // Why: /reload re-registers the active session, but it is not a', ' // turn boundary and must not clear the visible status or unread state.', " if (event.reason === 'reload') return", @@ -105,6 +106,9 @@ export function getPiAgentStatusHandlerSourceLines(kind: PiAgentKind): string[] ...captureSessionMetadata, ' clearPendingAgentEndCheck()', ' agentEndReported = false', + // Why: a turn cannot begin under a dialog holding input focus, so this is the one + // boundary that can recover a modal whose close never arrived. + ...(kind === 'pi' ? [' piUiPromptDepth = 0', ' piTurnInFlight = true'] : []), " post('agent_start')", ' })', '', @@ -168,6 +172,9 @@ export function getPiAgentStatusHandlerSourceLines(kind: PiAgentKind): string[] ' function postAgentEndOnce(): void {', ' if (agentEndReported) return', ' agentEndReported = true', + // Why: distinct from agentEndReported, which also dedupes the completion post and so + // starts false on a pane that has not run a turn yet — that pane is idle, not busy. + ...(kind === 'pi' ? [' piTurnInFlight = false'] : []), " post('agent_end')", ' }', '', diff --git a/src/main/pi/agent-status-runtime-detection-source.ts b/src/main/pi/agent-status-runtime-detection-source.ts index 5d9cdbf6de8..6ba5edb69b9 100644 --- a/src/main/pi/agent-status-runtime-detection-source.ts +++ b/src/main/pi/agent-status-runtime-detection-source.ts @@ -1,26 +1,15 @@ import type { PiAgentKind } from '../../shared/pi-agent-kind' -export function getPiAgentStatusRuntimeDetectionSourceLines(kind: PiAgentKind): string[] { - if (kind === 'prime-agent') { - return [ - `const CONFIGURED_HOOK_PATH = '/hook/${kind}'`, - '', - 'function isOmpRuntime(): boolean {', - ' return false', - '}', - '', - 'function resolveHookPath(_ompRuntime: boolean): string {', - ' return CONFIGURED_HOOK_PATH', - '}' - ] - } - +/** Why: a bare-shell OMP launch runs inside a pi-kind pane, so every extension that has to + * defer to OMP's own approval events needs this check — not just the status extension it + * was first written for. */ +export function getPiOmpRuntimeDetectionSourceLines(configuredHookPath: string): string[] { return [ 'function processName(value: unknown): string {', " return String(value || '').split(/[\\\\/]/).pop()?.toLowerCase() || ''", '}', '', - `const CONFIGURED_HOOK_PATH = '/hook/${kind}'`, + `const CONFIGURED_HOOK_PATH = '${configuredHookPath}'`, 'let cachedOmpRuntime: boolean | null = null', '', 'function isOmpRuntime(): boolean {', @@ -39,7 +28,27 @@ export function getPiAgentStatusRuntimeDetectionSourceLines(kind: PiAgentKind): " ['omp', 'omp.js', 'omp.sh', 'omp.cmd', 'omp.exe', 'omp.bat'].includes(name)", ' )', ' return cachedOmpRuntime', - '}', + '}' + ] +} + +export function getPiAgentStatusRuntimeDetectionSourceLines(kind: PiAgentKind): string[] { + if (kind === 'prime-agent') { + return [ + `const CONFIGURED_HOOK_PATH = '/hook/${kind}'`, + '', + 'function isOmpRuntime(): boolean {', + ' return false', + '}', + '', + 'function resolveHookPath(_ompRuntime: boolean): string {', + ' return CONFIGURED_HOOK_PATH', + '}' + ] + } + + return [ + ...getPiOmpRuntimeDetectionSourceLines(`/hook/${kind}`), '', 'function resolveHookPath(ompRuntime: boolean): string {', ' // Why: runtime detection keeps a bare-shell OMP launch from reporting as Pi.', diff --git a/src/main/pi/agent-status-ui-prompt-source.ts b/src/main/pi/agent-status-ui-prompt-source.ts index 2f1ed92c9ae..5790c5c30a7 100644 --- a/src/main/pi/agent-status-ui-prompt-source.ts +++ b/src/main/pi/agent-status-ui-prompt-source.ts @@ -1,6 +1,6 @@ import type { PiAgentKind } from '../../shared/pi-agent-kind' -/** Pi owns nested prompt depth and emits one pair around select/confirm/input/editor/custom. */ +/** Mirrors the titlebar extension's dialog tracking so both agree on when the wait ends. */ export function getPiAgentStatusUiPromptHandlerSourceLines(kind: PiAgentKind): string[] { if (kind !== 'pi') { return [] @@ -9,14 +9,35 @@ export function getPiAgentStatusUiPromptHandlerSourceLines(kind: PiAgentKind): s return [ " pi.on('ui_prompt_start', () => {", ' if (isOmpRuntime()) return', - ' piUiPromptActive = true', + ' piUiPromptDepth++', + ' if (piUiPromptDepth > 1) return', " post('ui_prompt_start')", ' })', '', " pi.on('ui_prompt_end', (_event, ctx) => {", - ' if (isOmpRuntime() || !piUiPromptActive) return', - ' piUiPromptActive = false', - " post('ui_prompt_end', { is_idle: ctx?.isIdle?.() === true })", + ' if (isOmpRuntime() || piUiPromptDepth === 0) return', + ' piUiPromptDepth--', + ' if (piUiPromptDepth > 0) return', + ' // Why: ctx.isIdle throws outright once a session-switching modal invalidates the', + ' // runner (it calls assertActive), so local turn state is the floor, not a fallback:', + ' // with no turn in flight, no later event is coming to correct a working verdict, so', + ' // only consult ctx when this process believes work is running.', + ' let isIdle = !piTurnInFlight', + ' try {', + " if (!isIdle && typeof ctx?.isIdle === 'function') isIdle = ctx.isIdle() === true", + ' } catch {', + ' // Why: a runner this very modal invalidated cannot answer; keep the local verdict.', + ' }', + " post('ui_prompt_end', { is_idle: isIdle })", + ' })', + '', + " pi.on('session_shutdown', () => {", + ' if (isOmpRuntime()) return', + ' // Why: pi tears an open dialog down through resetExtensionUI without resolving its', + ' // promise, so a replaced session never emits the matching ui_prompt_end and the wait', + ' // would stick forever. Reset without posting: shutdown is not a turn boundary, and', + ' // the session_start that follows republishes the corrected state.', + ' piUiPromptDepth = 0', ' })', '' ] diff --git a/src/main/pi/agent-status-ui-prompt.test.ts b/src/main/pi/agent-status-ui-prompt.test.ts index 4ab9341589e..d91ccc37b34 100644 --- a/src/main/pi/agent-status-ui-prompt.test.ts +++ b/src/main/pi/agent-status-ui-prompt.test.ts @@ -92,11 +92,21 @@ describe('Pi UI prompt status', () => { expect(harness.statuses.map((status) => status?.payload.state)).toEqual(['waiting', 'done']) }) - it('does not infer done when the context cannot establish idleness', async () => { + it('returns a pane that never ran a turn to done when idleness is unreadable', async () => { const harness = createHarness() await post(harness, 'ui_prompt_start') await post(harness, 'ui_prompt_end') - expect(harness.statuses.at(-1)?.payload.state).toBe('working') + // Why: no turn has started, so the pane is idle — reporting working would spin forever. + expect(harness.statuses.at(-1)?.payload.state).toBe('done') + }) + + it('trusts local turn state over a ctx that claims work on an idle pane', async () => { + const harness = createHarness() + await post(harness, 'ui_prompt_start') + await harness.callHook('ui_prompt_end', {}, { isIdle: () => false }) + await flushPosts() + // Why: no turn ever started, so nothing later would correct a working verdict. + expect(harness.statuses.at(-1)?.payload.state).toBe('done') }) it('lets the normal settlement hook finish work after a modal closes', async () => { @@ -118,20 +128,139 @@ describe('Pi UI prompt status', () => { const harness = createHarness() await post(harness, 'ui_prompt_start') harness.reload() - await post(harness, 'session_start', { reason: 'reload' }) await post(harness, 'tool_execution_end', { toolName: 'bash' }) + // Why: re-registering handlers is not a session boundary and must not lose the wait. expect(harness.statuses.at(-1)?.payload.state).toBe('waiting') }) - it('keeps a session-switching modal blocked until it actually closes', async () => { + it('releases a modal that a session replacement tore down without a close', async () => { const harness = createHarness() await post(harness, 'before_agent_start', { prompt: 'Old session prompt' }) await post(harness, 'ui_prompt_start') - await post(harness, 'session_start', { reason: 'switch' }) expect(harness.statuses.at(-1)?.payload.state).toBe('waiting') - expect(harness.statuses.at(-1)?.payload.prompt).toBe('') + // Why: pi hides the dialog through resetExtensionUI without resolving its promise, + // so no ui_prompt_end is ever emitted — these two boundaries are the only release. + await post(harness, 'session_shutdown') + await post(harness, 'session_start', { reason: 'switch' }) + await post(harness, 'tool_execution_end', { toolName: 'bash' }) + expect(harness.statuses.at(-1)?.payload.state).not.toBe('waiting') + }) + + it('releases a modal dropped by a reload that emits no shutdown', async () => { + const harness = createHarness() + await post(harness, 'ui_prompt_start') + await post(harness, 'session_start', { reason: 'reload' }) + await post(harness, 'tool_execution_end', { toolName: 'bash' }) + expect(harness.statuses.at(-1)?.payload.state).not.toBe('waiting') + }) + + it('still captures the assistant reply that lands while a modal is open', async () => { + const harness = createHarness() + await post(harness, 'agent_start') + await post(harness, 'message_end', { + message: { role: 'assistant', content: [{ type: 'text', text: 'Before modal' }] } + }) + await post(harness, 'ui_prompt_start') + await post(harness, 'message_end', { + message: { role: 'assistant', content: [{ type: 'text', text: 'Final reply' }] } + }) await harness.callHook('ui_prompt_end', {}, { isIdle: () => true }) await flushPosts() + expect(harness.statuses.at(-1)?.payload).toMatchObject({ + state: 'done', + lastAssistantMessage: 'Final reply' + }) + expect(harness.statuses.at(-1)?.payload.toolName).toBeUndefined() + expect(harness.statuses.at(-1)?.payload.interactivePrompt).toBeUndefined() + }) + + it('still reports the close when the modal invalidated its own runner', async () => { + const harness = createHarness() + await post(harness, 'ui_prompt_start') + await harness.callHook( + 'ui_prompt_end', + {}, + { + isIdle: () => { + throw new Error('extension runner is no longer active') + } + } + ) + await flushPosts() + // Why: a lost close would strand the pane on waiting; no turn is running, so done. + expect(harness.statuses.at(-1)?.payload.state).toBe('done') + }) + + it('keeps a mid-turn modal working when its runner throws on close', async () => { + const harness = createHarness() + await post(harness, 'agent_start') + await post(harness, 'ui_prompt_start') + await harness.callHook( + 'ui_prompt_end', + {}, + { + isIdle: () => { + throw new Error('extension runner is no longer active') + } + } + ) + await flushPosts() + // Why: the turn is still in flight, so done would ring the completion bell early. + expect(harness.statuses.at(-1)?.payload.state).toBe('working') + await post(harness, 'agent_settled') + expect(harness.statuses.at(-1)?.payload.state).toBe('done') + }) + + it('recovers on a new turn when a modal close was lost', async () => { + const harness = createHarness() + await post(harness, 'ui_prompt_start') + expect(harness.statuses.at(-1)?.payload.state).toBe('waiting') + // Why: a turn cannot begin under a dialog holding input focus, so this is recovery. + await post(harness, 'agent_start') + await post(harness, 'tool_execution_end', { toolName: 'bash' }) + expect(harness.statuses.at(-1)?.payload.state).toBe('working') + }) + + it('keeps the wait until the outermost of nested modals closes', async () => { + const harness = createHarness() + await post(harness, 'ui_prompt_start') + await post(harness, 'ui_prompt_start') + await harness.callHook('ui_prompt_end', {}, { isIdle: () => true }) + await flushPosts() + expect(harness.statuses.at(-1)?.payload.state).toBe('waiting') + await harness.callHook('ui_prompt_end', {}, { isIdle: () => true }) + await flushPosts() + expect(harness.statuses.at(-1)?.payload.state).toBe('done') + }) + + it('returns an idle pane to done when its modal lost the runner', async () => { + const harness = createHarness() + await post(harness, 'agent_start') + await post(harness, 'agent_settled') + expect(harness.statuses.at(-1)?.payload.state).toBe('done') + await post(harness, 'ui_prompt_start') + await harness.callHook( + 'ui_prompt_end', + {}, + { + isIdle: () => { + throw new Error('extension runner is no longer active') + } + } + ) + await flushPosts() + // Why: the turn already reported its end, so no later event is coming to correct a + // guess of working — fall back to what this process knows rather than strand it. + expect(harness.statuses.at(-1)?.payload.state).toBe('done') + }) + + it('keeps a mid-turn modal working when its close cannot read idleness', async () => { + const harness = createHarness() + await post(harness, 'agent_start') + await post(harness, 'ui_prompt_start') + await post(harness, 'ui_prompt_end') + expect(harness.statuses.at(-1)?.payload.state).toBe('working') + await post(harness, 'agent_settled') expect(harness.statuses.at(-1)?.payload.state).toBe('done') }) diff --git a/src/main/pi/titlebar-extension-service.ts b/src/main/pi/titlebar-extension-service.ts index 3a43ce4ac38..8a093096f4e 100644 --- a/src/main/pi/titlebar-extension-service.ts +++ b/src/main/pi/titlebar-extension-service.ts @@ -150,7 +150,7 @@ export class PiTitlebarExtensionService { if (kind !== 'prime-agent') { this.writeManagedExtension( join(extensionsDir, ORCA_PI_EXTENSION_FILE), - withOrcaManagedExtensionMarker(getPiTitlebarExtensionSource()) + withOrcaManagedExtensionMarker(getPiTitlebarExtensionSource(kind)) ) this.writeManagedExtension( join(extensionsDir, ORCA_PI_PREFILL_EXTENSION_FILE), diff --git a/src/main/pi/titlebar-extension-source.test.ts b/src/main/pi/titlebar-extension-source.test.ts index bee2e007c57..be21f8c6a16 100644 --- a/src/main/pi/titlebar-extension-source.test.ts +++ b/src/main/pi/titlebar-extension-source.test.ts @@ -3,6 +3,8 @@ import { runInNewContext } from 'node:vm' import ts from 'typescript-api' import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest' +import { detectAgentStatusFromTitle } from '../../shared/agent-detection' +import type { PiAgentKind } from '../../shared/pi-agent-kind' import { getPiTitlebarExtensionSource } from './titlebar-extension-source' const BRAILLE_RE = /[⠀-⣿]/ @@ -23,8 +25,19 @@ type Harness = { const CWD = '/repo/orca-app' const SESSION = 'omp-session' const IDLE_TITLE = `π - ${SESSION} - orca-app` +const PROMPT_TITLE = `π ! ${SESSION} - orca-app` -function createHarness(options: { paneKey?: string; isIdle?: () => boolean } = {}): Harness { +function createHarness( + options: { + paneKey?: string + isIdle?: () => boolean + kind?: PiAgentKind + processTitle?: string + cwdImpl?: () => string + sessionNameImpl?: () => string + env?: Record + } = {} +): Harness { const titles: string[] = [] const ctx: TitlebarContext = { ui: { @@ -48,8 +61,11 @@ function createHarness(options: { paneKey?: string; isIdle?: () => boolean } = { module, exports: module.exports, process: { - env: { ORCA_PANE_KEY: options.paneKey ?? 'pane-1' }, - cwd: () => CWD + env: { ORCA_PANE_KEY: options.paneKey ?? 'pane-1', ...options.env }, + pid: options.env?.ORCA_PI_TITLE_MARKER_OWNED === undefined ? 111 : 222, + title: options.processTitle ?? 'pi', + argv: ['node', 'pi'], + cwd: options.cwdImpl ?? (() => CWD) }, console: { warn: vi.fn(), error: vi.fn(), log: vi.fn() }, Promise, @@ -61,7 +77,7 @@ function createHarness(options: { paneKey?: string; isIdle?: () => boolean } = { } as Record context.globalThis = context - const output = ts.transpileModule(getPiTitlebarExtensionSource(), { + const output = ts.transpileModule(getPiTitlebarExtensionSource(options.kind ?? 'pi'), { compilerOptions: { module: ts.ModuleKind.CommonJS, target: ts.ScriptTarget.ES2020 } }).outputText runInNewContext(output, context) @@ -76,7 +92,7 @@ function createHarness(options: { paneKey?: string; isIdle?: () => boolean } = { on(name: string, handler: HookHandler) { handlers[name] = handler }, - getSessionName: () => SESSION + getSessionName: options.sessionNameImpl ?? (() => SESSION) }) return { @@ -247,4 +263,329 @@ describe('getPiTitlebarExtensionSource', () => { expect(vi.getTimerCount()).toBe(0) expect(harness.lastTitle()).toBe(IDLE_TITLE) }) + + it('marks a mid-turn dialog as needing input and holds it against the spinner', async () => { + const harness = createHarness() + + await harness.callHook('agent_start') + await harness.callHook('ui_prompt_start') + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + expect(detectAgentStatusFromTitle(PROMPT_TITLE)).toBe('permission') + + // Why: the spinner interval keeps running, but must not repaint over the marker. + await vi.advanceTimersByTimeAsync(800) + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + + await harness.callHook('ui_prompt_end') + expect(harness.lastTitle()).toMatch(BRAILLE_RE) + expect(vi.getTimerCount()).toBe(1) + }) + + it('returns an idle pane to its plain title when the dialog closes', async () => { + const harness = createHarness() + + await harness.callHook('ui_prompt_start') + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + + await harness.callHook('ui_prompt_end') + expect(harness.lastTitle()).toBe(IDLE_TITLE) + expect(vi.getTimerCount()).toBe(0) + }) + + it('only the outermost of nested dialogs moves the title', async () => { + const harness = createHarness() + + await harness.callHook('agent_start') + await harness.callHook('ui_prompt_start') + await harness.callHook('ui_prompt_start') + await harness.callHook('ui_prompt_end') + // Why: the outer dialog still holds input focus. + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + + await harness.callHook('ui_prompt_end') + expect(harness.lastTitle()).toMatch(BRAILLE_RE) + }) + + it('ignores an unmatched dialog close', async () => { + const harness = createHarness() + + await harness.callHook('agent_start') + const titleCount = harness.titles.length + await harness.callHook('ui_prompt_end') + expect(harness.titles.length).toBe(titleCount) + }) + + it.each(['agent_settled', 'session_shutdown'])( + 'keeps the marker when %s lands under an open dialog', + async (name) => { + const harness = createHarness() + + await harness.callHook('agent_start') + await harness.callHook('ui_prompt_start') + await harness.callHook(name) + // Why: settling does not answer the dialog, so the pane still needs the user. + const expected = name === 'session_shutdown' ? IDLE_TITLE : PROMPT_TITLE + expect(harness.lastTitle()).toBe(expected) + // Why: settling stops the spinner but must leave the marker re-assert running, or + // pi's own next title write would silently retire a dialog that is still open. + expect(vi.getTimerCount()).toBe(name === 'session_shutdown' ? 0 : 1) + } + ) + + it('keeps the marker across an idle compaction that finishes under a dialog', async () => { + const harness = createHarness() + + await harness.callHook('ui_prompt_start') + await harness.callHook('auto_compaction_start', { reason: 'idle' }) + await harness.callHook('auto_compaction_end') + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + }) + + it('recovers the spinner on a new turn when a dialog close was lost', async () => { + const harness = createHarness() + + await harness.callHook('ui_prompt_start') + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + + // Why: a turn cannot start under a dialog holding input focus, so this is recovery. + await harness.callHook('agent_start') + await vi.advanceTimersByTimeAsync(80) + expect(harness.lastTitle()).toMatch(BRAILLE_RE) + }) + + it('leaves the marker to OMP approval events instead of painting it', () => { + expect(createHarness({ kind: 'omp' }).handlers.ui_prompt_start).toBeUndefined() + }) + + it('still caps idle maintenance while a dialog holds the title', async () => { + const harness = createHarness() + + await harness.callHook('auto_compaction_start', { reason: 'idle' }) + await harness.callHook('ui_prompt_start') + // Why: an open dialog must not suspend the cap that stops a stranded spinner. + vi.advanceTimersByTime(301_000) + + // Why: the spinner is capped, but the marker re-assert survives it — the dialog is + // still open, so the pane must keep reporting that it needs input. + expect(vi.getTimerCount()).toBe(1) + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + }) + + it('survives a dialog event that carries no ui context', async () => { + const harness = createHarness() + + await harness.callHook('agent_start') + await expect(harness.handlers.ui_prompt_start?.({}, undefined)).resolves.toBeUndefined() + await expect(harness.handlers.ui_prompt_end?.({}, undefined)).resolves.toBeUndefined() + }) + + it('keeps spinning when the dialog event could not paint the marker', async () => { + const harness = createHarness() + + await harness.callHook('agent_start') + await harness.handlers.ui_prompt_start?.({}, undefined) + // Why: suppressing frames without a marker would freeze the title mid-spinner, which + // still reads as working — the opposite of what the marker is for. + await vi.advanceTimersByTimeAsync(160) + expect(harness.lastTitle()).toMatch(BRAILLE_RE) + }) + + it('marks a nested dialog when the outer one could not paint', async () => { + const harness = createHarness() + + await harness.callHook('agent_start') + await harness.handlers.ui_prompt_start?.({}, undefined) + await harness.callHook('ui_prompt_start') + // Why: the outer ctx cannot decide that the whole stack stays unmarked. + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + }) + + it('clears the marker through the opening ctx when the close carries none', async () => { + const harness = createHarness() + + await harness.callHook('ui_prompt_start') + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + await harness.handlers.ui_prompt_end?.({}, undefined) + // Why: otherwise the pane asks for attention until the next turn. + expect(harness.lastTitle()).toBe(IDLE_TITLE) + }) + + it('does not reject when the dialog ctx can no longer paint', async () => { + const harness = createHarness() + const throwing = { + ui: { + setTitle: () => { + throw new Error('extension runner is no longer active') + } + } + } + + await expect(harness.handlers.ui_prompt_start?.({}, throwing)).resolves.toBeUndefined() + // Why: the marker never went up, so the spinner must not stay suppressed. + await harness.callHook('agent_start') + await vi.advanceTimersByTimeAsync(80) + expect(harness.lastTitle()).toMatch(BRAILLE_RE) + }) + + it('does not reject when the captured ctx dies before the dialog closes', async () => { + const harness = createHarness() + let live = true + const dying = { + ui: { + setTitle: (title: string) => { + if (!live) { + throw new Error('extension runner is no longer active') + } + harness.titles.push(title) + } + } + } + + await harness.handlers.ui_prompt_start?.({}, dying) + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + live = false + // Why: the close carries no ui, so it falls back to the ctx the modal invalidated. + await expect(harness.handlers.ui_prompt_end?.({}, undefined)).resolves.toBeUndefined() + // Why: a later turn still recovers a clean title through a live ctx. + await harness.callHook('agent_start') + await vi.advanceTimersByTimeAsync(80) + expect(harness.lastTitle()).toMatch(BRAILLE_RE) + }) + + it('does not strand the marker when the closing ctx throws on ui access', async () => { + const harness = createHarness() + // Why: pi's ctx.ui is a getter that calls assertActive(); a session-replacing dialog + // invalidates the runner, so reading ctx.ui throws rather than yielding undefined. + const stale = { + get ui(): never { + throw new Error('This extension ctx is stale') + } + } + + await harness.callHook('ui_prompt_start') + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + + await expect(harness.handlers.ui_prompt_end?.({}, stale as never)).resolves.toBeUndefined() + // Why: the opening ctx still paints, so the pane stops asking for input. + expect(harness.lastTitle()).toBe(IDLE_TITLE) + + // Why: a stranded markerPainted would suppress every later working frame. + await harness.callHook('agent_start') + await vi.advanceTimersByTimeAsync(80) + expect(harness.lastTitle()).toMatch(BRAILLE_RE) + }) + + it('does not reject when the opening ctx throws on ui access', async () => { + const harness = createHarness() + const stale = { + get ui(): never { + throw new Error('This extension ctx is stale') + } + } + + await harness.callHook('agent_start') + await expect(harness.handlers.ui_prompt_start?.({}, stale as never)).resolves.toBeUndefined() + // Why: no marker went up, so the spinner must keep running. + await vi.advanceTimersByTimeAsync(80) + expect(harness.lastTitle()).toMatch(BRAILLE_RE) + }) + + it('re-asserts the marker when pi repaints the title under a dialog', async () => { + const harness = createHarness() + + await harness.callHook('agent_start') + await harness.callHook('ui_prompt_start') + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + + // Why: pi repaints on session_info_changed/rebindCurrentSession with no event we see, + // so a marker that is merely "not overwritten by us" would be silently lost. + harness.titles.push('π - other - orca-app') + await vi.advanceTimersByTimeAsync(80) + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + }) + + it('re-asserts the marker on an idle pane with no spinner running', async () => { + const harness = createHarness() + + await harness.callHook('ui_prompt_start') + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + + // Why: no turn is running, so renderFrame never fires — only the slow re-assert can + // undo a title pi writes from session_info_changed or its update-check restore. + harness.titles.push('\u03c0 - other - orca-app') + await vi.advanceTimersByTimeAsync(1000) + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + + await harness.callHook('ui_prompt_end') + expect(harness.lastTitle()).toBe(IDLE_TITLE) + expect(vi.getTimerCount()).toBe(0) + }) + + it('releases the marker when a session replacement drops the dialog', async () => { + const harness = createHarness() + + await harness.callHook('ui_prompt_start') + expect(harness.lastTitle()).toBe(PROMPT_TITLE) + + // Why: pi hides the dialog without resolving it, so no close is coming. + await harness.callHook('session_start', { reason: 'switch' }) + expect(vi.getTimerCount()).toBe(0) + await harness.callHook('agent_start') + await vi.advanceTimersByTimeAsync(80) + expect(harness.lastTitle()).toMatch(BRAILLE_RE) + }) + + it('survives a deleted cwd instead of crashing the pi process', async () => { + const harness = createHarness({ + cwdImpl: () => { + throw new Error('ENOENT: uv_cwd') + } + }) + + // Why: these run inside setInterval callbacks, where an escape is an uncaught + // exception and pi exits(1) through its own uncaughtException handler. + await expect(harness.callHook('agent_start')).resolves.toBeUndefined() + await expect(harness.callHook('ui_prompt_start')).resolves.toBeUndefined() + // Why: an unguarded throw in the interval would surface here as an unhandled error. + await vi.advanceTimersByTimeAsync(2000) + await expect(harness.callHook('ui_prompt_end')).resolves.toBeUndefined() + await expect(harness.callHook('agent_settled')).resolves.toBeUndefined() + }) + + it('survives a session name that throws on a stale runtime', async () => { + let live = true + const harness = createHarness({ + sessionNameImpl: () => { + if (!live) { + throw new Error('This extension API is stale') + } + return SESSION + } + }) + + await harness.callHook('agent_start') + await harness.callHook('ui_prompt_start') + live = false + await vi.advanceTimersByTimeAsync(2000) + await expect(harness.callHook('ui_prompt_end')).resolves.toBeUndefined() + }) + + it('leaves the needs-input marker to the process that owns the pane', async () => { + // Why: child agents inherit ORCA_PANE_KEY, and a second process asserting the marker + // would report needs-input for a pane it does not speak for. + const harness = createHarness({ env: { ORCA_PI_TITLE_MARKER_OWNED: '111' } }) + + await harness.callHook('agent_start') + await harness.callHook('ui_prompt_start') + await vi.advanceTimersByTimeAsync(1000) + expect(harness.titles).not.toContain(PROMPT_TITLE) + expect(harness.lastTitle()).toMatch(BRAILLE_RE) + }) + + it('leaves an OMP runtime to its own approval events', () => { + const harness = createHarness({ processTitle: 'omp' }) + + expect(harness.handlers.ui_prompt_start).toBeDefined() + expect(() => harness.handlers.ui_prompt_start?.({}, undefined)).not.toThrow() + }) }) diff --git a/src/main/pi/titlebar-extension-source.ts b/src/main/pi/titlebar-extension-source.ts index a41eafb896f..7fc15c191bc 100644 --- a/src/main/pi/titlebar-extension-source.ts +++ b/src/main/pi/titlebar-extension-source.ts @@ -1,7 +1,54 @@ +import type { PiAgentKind } from '../../shared/pi-agent-kind' +import { getPiOmpRuntimeDetectionSourceLines } from './agent-status-runtime-detection-source' + export const ORCA_PI_EXTENSION_FILE = 'orca-titlebar-spinner.ts' -export function getPiTitlebarExtensionSource(): string { +export function getPiTitlebarExtensionSource(kind: PiAgentKind = 'pi'): string { + // Why: OMP reports input waits through its own approval events, which the status + // extension already maps, and it writes this same marker natively. The runtime check + // matters as well as the kind: a bare-shell OMP launch runs inside a pi-kind pane. + const uiPromptHandlers = + kind === 'pi' + ? [ + " pi.on('ui_prompt_start', async (_event, ctx) => {", + ' if (isOmpRuntime() || !ownsMarker) return', + ' promptDepth++', + ' // Why: retry on every open rather than only the outermost, so an outer ctx', + ' // that could not paint cannot decide the whole stack stays unmarked.', + ' if (markerPainted) return', + ' const painter = resolvePainter(ctx)', + ' // Why: only hold the spinner off once the marker is actually up, or a ctx', + ' // that cannot paint would freeze the title on its last working frame.', + " if (!paintTitle(painter, () => getMarkedTitle(pi, '!'))) return", + ' markerPainted = true', + ' promptCtx = painter', + ' startMarkerReassert(painter)', + ' })', + '', + " pi.on('ui_prompt_end', async (_event, ctx) => {", + ' if (isOmpRuntime() || !ownsMarker || promptDepth === 0) return', + ' promptDepth--', + ' if (promptDepth > 0) return', + ' // Why: the opening ctx already painted once, so a close whose own ctx is stale', + ' // does not leave the needs-input marker up until the next turn.', + ' const painter = resolvePainter(ctx) ?? promptCtx', + ' markerPainted = false', + ' promptCtx = null', + ' stopMarkerReassert()', + ' // Why: a still-live turn resumes its spinner in place; otherwise the pane is idle', + ' // and must drop the needs-input marker rather than keep asking for attention.', + ' if (timer) {', + ' renderFrame(painter)', + ' return', + ' }', + ' paintTitle(painter, () => getBaseTitle(pi))', + ' })', + '' + ] + : [] + return [ + ...(kind === 'pi' ? [...getPiOmpRuntimeDetectionSourceLines(`/hook/${kind}`), ''] : []), 'const BRAILLE_FRAMES = [', " '\\u280b',", " '\\u2819',", @@ -16,36 +63,111 @@ export function getPiTitlebarExtensionSource(): string { ']', '', 'const FRAME_INTERVAL_MS = 80', + '// Why: pi repaints the title from its own writers (session_info_changed, the win32', + '// update-check restore) with no event we observe, so the marker has to be re-asserted', + '// even when no spinner frame is due. Coarse on purpose: it only rewrites one string.', + 'const MARKER_REASSERT_MS = 1000', 'const AGENT_END_IDLE_RECHECK_MS = 25', 'const AGENT_END_IDLE_RECHECK_MAX_MS = 250', '// Why: a failed idle compaction can end without auto_compaction_end, and no agent turn will', '// close a maintenance spinner — cap it so idle maintenance cannot strand a working title.', 'const IDLE_COMPACTION_MAX_FRAMES = Math.ceil(300000 / FRAME_INTERVAL_MS)', '', - 'function getBaseTitle(pi) {', + '// Why: `-` is the plain separator; `!` is the state marker Orca reads as needs-input', + '// (src/shared/pi-state-title-marker.ts), so mobile and the CLI see the wait too.', + 'function getMarkedTitle(pi, marker) {', ' const cwd = process.cwd().split(/[\\\\/]/).filter(Boolean).at(-1) || process.cwd()', ' const session = pi.getSessionName()', - ' return session ? `\\u03c0 - ${session} - ${cwd}` : `\\u03c0 - ${cwd}`', + ' return session', + ' ? `\\u03c0 ${marker} ${session} - ${cwd}`', + ' : `\\u03c0 ${marker} ${cwd}`', + '}', + '', + 'function getBaseTitle(pi) {', + " return getMarkedTitle(pi, '-')", + '}', + '', + '// Why: the ctx.ui pi passes is a getter that calls assertActive() and throws once a', + '// session-replacing dialog invalidates the runner; optional chaining cannot screen', + '// that out. Read it behind a try and never mutate state before a paint has succeeded.', + 'function resolvePainter(ctx) {', + ' try {', + " return typeof ctx?.ui?.setTitle === 'function' ? ctx : null", + ' } catch {', + ' return null', + ' }', + '}', + '', + '// Why: buildTitle runs inside the try because it is not safe either — getSessionName()', + '// calls assertActive() and process.cwd() throws ENOENT once the worktree is deleted.', + '// Most call sites are timer callbacks, where an escape is an uncaught exception and pi', + '// exits(1) through its own uncaughtException handler.', + 'function paintTitle(ctx, buildTitle) {', + ' if (!ctx) return false', + ' try {', + ' ctx.ui.setTitle(buildTitle())', + ' return true', + ' } catch {', + ' return false', + ' }', '}', '', 'export default function (pi) {', ' if (!process.env.ORCA_PANE_KEY) return', + ...(kind === 'pi' + ? [ + ' // Why: child agents inherit the pane env, and the spinner is harmlessly', + ' // per-process — but the needs-input marker is status the pane reports, so only', + ' // one process may assert it. Mirrors ORCA_PI_STATUS_OWNED in the status hook.', + ' const markerOwnerPid = process.env.ORCA_PI_TITLE_MARKER_OWNED', + ' const ownsMarker = !markerOwnerPid || markerOwnerPid === String(process.pid)', + ' if (ownsMarker) process.env.ORCA_PI_TITLE_MARKER_OWNED = String(process.pid)' + ] + : []), + ' let timer = null', ' let frameIndex = 0', ' // Why: only idle maintenance owns a spinner of its own. A threshold compaction runs', ' // inside an agent turn, whose spinner must outlive it, and any newer start clears the', ' // marker so a late idle completion cannot stop current work (#16470).', ' let idleCompactionOwnsSpinner = false', + ' // Why: pi already collapses nested prompts into one start/end pair, so this counter', + ' // guards a close that never arrives, not nesting. A new turn cannot start under a', + ' // dialog holding input focus, so agent_start doubles as recovery.', + ' let promptDepth = 0', + ' let markerPainted = false', + ' let promptCtx = null', + ' // Why: a separate handle from `timer`, which clearAnimation() nulls — the marker must', + ' // survive a turn settling, a shutdown of the spinner, and the idle-maintenance cap.', + ' let markerTimer = null', ' let pendingAgentEndCheck = null', ' let pendingAgentEndContext = null', ' let agentEndIdleRecheckMs = AGENT_END_IDLE_RECHECK_MS', '', + ' function resetPromptState() {', + ' stopMarkerReassert()', + ' promptDepth = 0', + ' markerPainted = false', + ' promptCtx = null', + ' }', + '', ' function clearPendingAgentEndCheck() {', ' if (pendingAgentEndCheck !== null) clearTimeout(pendingAgentEndCheck)', ' pendingAgentEndCheck = null', ' pendingAgentEndContext = null', ' }', '', + ' function stopMarkerReassert() {', + ' if (markerTimer) clearInterval(markerTimer)', + ' markerTimer = null', + ' }', + '', + ' function startMarkerReassert(ctx) {', + ' stopMarkerReassert()', + " markerTimer = setInterval(() => paintTitle(ctx, () => getMarkedTitle(pi, '!')), MARKER_REASSERT_MS)", + " if (typeof markerTimer.unref === 'function') markerTimer.unref()", + ' }', + '', ' function clearAnimation() {', ' if (timer) {', ' clearInterval(timer)', @@ -58,19 +180,35 @@ export function getPiTitlebarExtensionSource(): string { ' function stopAnimation(ctx) {', ' clearPendingAgentEndCheck()', ' clearAnimation()', - ' ctx.ui.setTitle(getBaseTitle(pi))', + ' // Why: settling under an open dialog still leaves the pane waiting on the user, so', + ' // the idle title must not retire the marker the dialog is holding.', + " paintTitle(ctx, () => (markerPainted ? getMarkedTitle(pi, '!') : getBaseTitle(pi)))", ' }', '', ' function renderFrame(ctx) {', + ' // Why: the maintenance cap runs before the dialog guard so a dialog left open', + ' // cannot suspend it; stopAnimation keeps the marker while a dialog is open.', ' if (idleCompactionOwnsSpinner && frameIndex >= IDLE_COMPACTION_MAX_FRAMES) {', ' stopAnimation(ctx)', ' return', ' }', - ' const frame = BRAILLE_FRAMES[frameIndex % BRAILLE_FRAMES.length]', - ' const cwd = process.cwd().split(/[\\\\/]/).filter(Boolean).at(-1) || process.cwd()', - ' const session = pi.getSessionName()', - ' const title = session ? `${frame} \\u03c0 - ${session} - ${cwd}` : `${frame} \\u03c0 - ${cwd}`', - ' ctx.ui.setTitle(title)', + ' // Why: an 80ms working frame would repaint over the needs-input marker within one', + ' // tick, so a mid-turn dialog would still look busy everywhere the title is the', + ' // only evidence. Re-assert rather than skip: pi repaints the title on its own', + ' // (session_info_changed, resetExtensionUI, rebindCurrentSession) and would', + ' // otherwise wipe the marker with nothing to restore it. The frame still counts,', + ' // so the cap above keeps accruing in wall-clock.', + ' if (markerPainted) {', + " paintTitle(ctx, () => getMarkedTitle(pi, '!'))", + ' frameIndex++', + ' return', + ' }', + ' paintTitle(ctx, () => {', + ' const frame = BRAILLE_FRAMES[frameIndex % BRAILLE_FRAMES.length]', + ' const cwd = process.cwd().split(/[\\\\/]/).filter(Boolean).at(-1) || process.cwd()', + ' const session = pi.getSessionName()', + ' return session ? `${frame} \\u03c0 - ${session} - ${cwd}` : `${frame} \\u03c0 - ${cwd}`', + ' })', ' frameIndex++', ' }', '', @@ -101,9 +239,17 @@ export function getPiTitlebarExtensionSource(): string { ' }', '', " pi.on('agent_start', async (_event, ctx) => {", + ' resetPromptState()', ' startAnimation(ctx)', ' })', '', + ' // Why: pi drops an open dialog through resetExtensionUI without resolving its promise,', + ' // so a replaced or reloaded session never sends the matching close. Both boundaries', + ' // prove no dialog from the old session is still on screen.', + " pi.on('session_start', async () => {", + ' resetPromptState()', + ' })', + '', ' // Why: modern Pi/OMP emit agent_end mid-run and only settle later, so settlement is the', ' // authoritative completion boundary. Legacy runtimes never emit it, so agent_end stays.', " pi.on('agent_settled', async (_event, ctx) => {", @@ -126,6 +272,7 @@ export function getPiTitlebarExtensionSource(): string { " if (typeof pendingAgentEndCheck.unref === 'function') pendingAgentEndCheck.unref()", ' })', '', + ...uiPromptHandlers, " pi.on('auto_compaction_start', async (event, ctx) => {", " if (event?.reason !== 'idle') return", ' // Why: the idle worker can fire against a turn that just started, and reason alone does', @@ -142,6 +289,7 @@ export function getPiTitlebarExtensionSource(): string { ' })', '', " pi.on('session_shutdown', async (_event, ctx) => {", + ' resetPromptState()', ' stopAnimation(ctx)', ' })', '}', diff --git a/src/main/project-groups/nested-repo-import.test.ts b/src/main/project-groups/nested-repo-import.test.ts index 2b591fa9a71..aa8a0502e1f 100644 --- a/src/main/project-groups/nested-repo-import.test.ts +++ b/src/main/project-groups/nested-repo-import.test.ts @@ -138,7 +138,9 @@ describe('createNestedProjectGroupResolver', () => { parentPath: '/workspace', groupName: 'workspace', mode: 'separate', - repoPaths: ['/workspace/services/api', '/workspace/services/worker'], + get repoPaths(): readonly string[] { + throw new Error('separate imports must not build unused folder scopes') + }, createGroup: () => { throw new Error('should not create a group') } @@ -148,6 +150,30 @@ describe('createNestedProjectGroupResolver', () => { expect(resolver.getCreatedGroups()).toEqual([]) }) + it('leaves every separate-import repo ungrouped even when repo paths are supplied', () => { + const { groups, createGroup } = createGroupRecorder() + const repoPaths = [ + '/workspace/services/api', + '/workspace/services/worker', + '/workspace/platform/packages/shared' + ] + const resolver = createNestedProjectGroupResolver({ + parentPath: '/workspace', + groupName: 'workspace', + mode: 'separate', + repoPaths, + createGroup + }) + + expect(repoPaths.map((repoPath) => resolver.getGroupForRepo(repoPath))).toEqual([ + undefined, + undefined, + undefined + ]) + expect(resolver.getRootGroup()).toBeUndefined() + expect(groups).toEqual([]) + }) + it('preserves filesystem root parent paths when creating the root group', () => { const groups: ProjectGroup[] = [] const resolver = createNestedProjectGroupResolver({ diff --git a/src/main/project-groups/nested-repo-import.ts b/src/main/project-groups/nested-repo-import.ts index 17aee4a2994..c08839edc30 100644 --- a/src/main/project-groups/nested-repo-import.ts +++ b/src/main/project-groups/nested-repo-import.ts @@ -150,10 +150,12 @@ export function createNestedProjectGroupResolver(args: { createGroup: (input: CreateGroupInput) => ProjectGroup }): NestedProjectGroupResolver { const createdGroups: ProjectGroup[] = [] - const folderScopes = buildSparseFolderScopes({ - parentPath: args.parentPath, - repoPaths: args.repoPaths ?? [] - }) + // Every folder-scope read sits behind ensureRootGroup, so outside group mode the scopes are + // unreachable. One flag drives both so the skip can never drift from the guard that justifies it. + const createsGroups = args.mode === 'group' + const folderScopes = createsGroups + ? buildSparseFolderScopes({ parentPath: args.parentPath, repoPaths: args.repoPaths ?? [] }) + : [] const folderScopesByRelativePath = new Map( folderScopes.map((scope) => [scope.relativePath, scope]) ) @@ -161,7 +163,7 @@ export function createNestedProjectGroupResolver(args: { let rootGroup: ProjectGroup | undefined const ensureRootGroup = (): ProjectGroup | undefined => { - if (args.mode !== 'group') { + if (!createsGroups) { return undefined } if (rootGroup) { diff --git a/src/main/runtime/orca-runtime-fence-automation-owner.ts b/src/main/runtime/orca-runtime-automation-operations.ts similarity index 97% rename from src/main/runtime/orca-runtime-fence-automation-owner.ts rename to src/main/runtime/orca-runtime-automation-operations.ts index a90730c7886..fe65979ed1e 100644 --- a/src/main/runtime/orca-runtime-fence-automation-owner.ts +++ b/src/main/runtime/orca-runtime-automation-operations.ts @@ -23,7 +23,7 @@ import type { LegacyWorkerTerminalRecoveryResult } from './runtime-legacy-worker import { makePaneKey } from '../../shared/stable-pane-id' import { runtimeWorktreeIdsEqual } from './runtime-worktree-path-identity' -export class OrcaRuntimeWithFenceAutomationOwner extends OrcaRuntimeWithPtyForegroundProcessReads { +export class OrcaRuntimeWithAutomationOperations extends OrcaRuntimeWithPtyForegroundProcessReads { protected fenceAutomationOwner( id: string, expectedOwner: AutomationOwnerPrecondition | undefined, @@ -167,10 +167,6 @@ export class OrcaRuntimeWithFenceAutomationOwner extends OrcaRuntimeWithPtyForeg this.scheduleRestoredMessageRepoints() } - prepareLegacyWorkerTerminalRecovery(): LegacyWorkerTerminalRecoveryPlan { - return this.legacyWorkerRecovery.prepare() - } - protected async flushWorkspaceSessionOrThrowAsync(): Promise { const store = this.store if (store?.flushPendingOrThrowAsync) { diff --git a/src/main/runtime/orca-runtime-has-exact-persisted-terminal-surface-identity.ts b/src/main/runtime/orca-runtime-has-exact-persisted-terminal-surface-identity.ts index 6956644c748..d0425cdc1f9 100644 --- a/src/main/runtime/orca-runtime-has-exact-persisted-terminal-surface-identity.ts +++ b/src/main/runtime/orca-runtime-has-exact-persisted-terminal-surface-identity.ts @@ -1,5 +1,5 @@ // @ts-nocheck -- mechanically split from OrcaRuntimeService; behavior is covered by AST equivalence and characterization tests. -import { OrcaRuntimeWithFenceAutomationOwner } from './orca-runtime-fence-automation-owner' +import { OrcaRuntimeWithAutomationOperations } from './orca-runtime-automation-operations' import { resolveTerminalSessionWorktreeId, runtimeWorktreeIdsEqual @@ -26,7 +26,7 @@ import type { ArtifactWriteRequest } from '../../shared/artifacts' -export class OrcaRuntimeWithHasExactPersistedTerminalSurfaceIdentity extends OrcaRuntimeWithFenceAutomationOwner { +export class OrcaRuntimeWithHasExactPersistedTerminalSurfaceIdentity extends OrcaRuntimeWithAutomationOperations { protected hasExactPersistedTerminalSurfaceIdentity(expected: { worktreeId: string tabId: string diff --git a/src/main/runtime/orca-runtime-preserved-branch-cleanup.ts b/src/main/runtime/orca-runtime-preserved-branch-cleanup.ts index d53994032a1..2e1357e3450 100644 --- a/src/main/runtime/orca-runtime-preserved-branch-cleanup.ts +++ b/src/main/runtime/orca-runtime-preserved-branch-cleanup.ts @@ -136,8 +136,7 @@ export class OrcaRuntimeWithPreservedBranchCleanup extends OrcaRuntimeWithTermin new RuntimeLegacyWorkerTerminalRecoveryPersistence( () => this.store, () => this.getOrchestrationDb(), - (worktreeId) => this.tryGetWorkspaceSessionHostIdForWorktree(worktreeId), - (paneKey, blocked) => this.notifier?.setLegacyWorkerTerminalResumeFence?.(paneKey, blocked) + (worktreeId) => this.tryGetWorkspaceSessionHostIdForWorktree(worktreeId) ) protected readonly legacyWorkerRecovery = new RuntimeLegacyWorkerTerminalRecoveryController({ diff --git a/src/main/runtime/orca-runtime-register-pty.ts b/src/main/runtime/orca-runtime-register-pty.ts index 410798a329d..dae2519ca9f 100644 --- a/src/main/runtime/orca-runtime-register-pty.ts +++ b/src/main/runtime/orca-runtime-register-pty.ts @@ -80,6 +80,15 @@ export class OrcaRuntimeWithRegisterPty extends OrcaRuntimeWithInvalidateAllHand ...(binding && paneKey ? { tabId: binding.tabId, paneKey } : {}), ...(binding?.incarnationId ? { incarnationId: binding.incarnationId } : {}) }) + const hostScope = this.getOrchestrationCompatibilityHostScope(pty) + if (paneKey && binding?.incarnationId && hostScope) { + this._orchestrationDb?.retainReplacedWorkerTerminalResources({ + paneKey, + worktreeId, + hostScope: JSON.stringify(hostScope), + processIncarnation: `${ptyId}:${binding.incarnationId}` + }) + } const agentLaunchAuthority = binding?.agentLaunchAuthority if ( agentLaunchAuthority && diff --git a/src/main/runtime/orca-runtime-serialize-headless-terminal-buffer.ts b/src/main/runtime/orca-runtime-serialize-headless-terminal-buffer.ts index 8f4ddc430c5..673c31167f4 100644 --- a/src/main/runtime/orca-runtime-serialize-headless-terminal-buffer.ts +++ b/src/main/runtime/orca-runtime-serialize-headless-terminal-buffer.ts @@ -109,6 +109,9 @@ export class OrcaRuntimeWithSerializeHeadlessTerminalBuffer extends OrcaRuntimeW // still awaiting their first PTY (ptyId null) may adopt it, which preserves // the mobile pre-spawn subscribe flow. resolveLiveLeafForHandle(handle: string): { ptyId: string | null } | null { + // Why the discarded call: it re-links a runtime-owned handle whose `handles` record a renderer + // reload cleared, so the lookup below sees it; without it a phone's held handle inspects nothing. + this.getLivePtyForHandle(handle) const record = this.handles.get(handle) if (!record) { return null diff --git a/src/main/runtime/orca-runtime-subscribe-to-terminal-resize.ts b/src/main/runtime/orca-runtime-subscribe-to-terminal-resize.ts index d610dbb235f..1cef2bbf23a 100644 --- a/src/main/runtime/orca-runtime-subscribe-to-terminal-resize.ts +++ b/src/main/runtime/orca-runtime-subscribe-to-terminal-resize.ts @@ -54,16 +54,6 @@ export class OrcaRuntimeWithSubscribeToTerminalResize extends OrcaRuntimeWithApp // dispatch contexts immediately, rather than waiting for the coordinator's // next poll cycle. This catches agent crashes and unexpected exits within // milliseconds. The task is set back to 'pending' so it can be re-dispatched. - /** A worker settled by its own process exit makes its pane fenceable now, not at the next app - * start; a fence sweep must never fail the exit path behind it. */ - private sweepSettledWorkerResumeFencesAfterExit(): void { - try { - this.prepareLegacyWorkerTerminalRecovery() - } catch (error) { - console.warn('[orchestration] settled worker resume fence sweep failed', error) - } - } - protected failActiveDispatchOnExit( handle: string, paneKey: string | null, @@ -90,7 +80,6 @@ export class OrcaRuntimeWithSubscribeToTerminalResize extends OrcaRuntimeWithApp const stopping = this._orchestrationDb.getWorkerDispatch?.(dispatch.id) if (stopping?.state === 'stopping' && stopping.runtime_epoch === this.getRuntimeId()) { this._orchestrationDb.settleWorkerStop(dispatch.id) - this.sweepSettledWorkerResumeFencesAfterExit() return } @@ -99,7 +88,6 @@ export class OrcaRuntimeWithSubscribeToTerminalResize extends OrcaRuntimeWithApp workerProcessExited: true, terminationReason: cause.kind }) - this.sweepSettledWorkerResumeFencesAfterExit() if (isDeliberateTerminalExit(cause)) { return } @@ -145,7 +133,7 @@ export class OrcaRuntimeWithSubscribeToTerminalResize extends OrcaRuntimeWithApp exitCause: cause, handle }), - ...(recipient.runId ? { runId: recipient.runId } : {}) + runId: dispatch.run_id }) this.notifyMessageArrived(escalation.to_handle, escalation.type) } catch (error) { diff --git a/src/main/runtime/orca-runtime-terminal-handle-incarnation.test.ts b/src/main/runtime/orca-runtime-terminal-handle-incarnation.test.ts index 19605aa4ffa..9765465fdf0 100644 --- a/src/main/runtime/orca-runtime-terminal-handle-incarnation.test.ts +++ b/src/main/runtime/orca-runtime-terminal-handle-incarnation.test.ts @@ -53,6 +53,28 @@ function register(runtime: OrcaRuntimeService, incarnationId: string): void { } describe('runtime terminal handle incarnation fencing', () => { + it('inspects the retained SSH PTY during renderer reload without an input write', async () => { + const { runtime } = makeRuntime() + const handle = runtime.preAllocateHandleForPty(PTY_ID) + register(runtime, 'incarnation-1') + syncGraph(runtime) + const inspectProcess = vi.fn().mockResolvedValue({ foregroundProcess: 'codex' }) + runtime.setPtyController({ + write: vi.fn(() => true), + kill: () => true, + getForegroundProcess: async () => null, + inspectProcess + }) + expect(runtime.markRendererReloading(1)).not.toBeNull() + expect((runtime as unknown as { handles: Map }).handles.has(handle)).toBe( + false + ) + await expect( + runtime.inspectTerminalProcess(handle, { expectedIncarnationId: 'incarnation-1' }) + ).resolves.toEqual({ foregroundProcess: 'codex' }) + expect(inspectProcess).toHaveBeenCalledWith(PTY_ID, { expectedIncarnationId: 'incarnation-1' }) + }) + it('preserves a direct handle while the PTY incarnation is unchanged', async () => { const { runtime } = makeRuntime() const handle = runtime.preAllocateHandleForPty(PTY_ID) diff --git a/src/main/runtime/orca-runtime-tests/lineage-and-scan-cache-part-05.spec.ts b/src/main/runtime/orca-runtime-tests/lineage-and-scan-cache-part-05.spec.ts index 1df978ac165..ad66e89ec7e 100644 --- a/src/main/runtime/orca-runtime-tests/lineage-and-scan-cache-part-05.spec.ts +++ b/src/main/runtime/orca-runtime-tests/lineage-and-scan-cache-part-05.spec.ts @@ -95,7 +95,10 @@ describe('OrcaRuntimeService', () => { return [name, createRootDispatch(db, task.id, handles[name], paneKey(name))] }) ) - const legacyTask = db.createTask({ spec: 'legacy worker' }) + const legacyTask = db.createTask({ + runId: 'run_legacy_local', + spec: 'legacy worker' + }) const legacyDispatch = createRootDispatch( db, legacyTask.id, diff --git a/src/main/runtime/orca-runtime-tests/mobile-creation-and-orchestration-part-02.spec.ts b/src/main/runtime/orca-runtime-tests/mobile-creation-and-orchestration-part-02.spec.ts index 57c1d2c3031..9291c30c1a2 100644 --- a/src/main/runtime/orca-runtime-tests/mobile-creation-and-orchestration-part-02.spec.ts +++ b/src/main/runtime/orca-runtime-tests/mobile-creation-and-orchestration-part-02.spec.ts @@ -216,7 +216,10 @@ describe('OrcaRuntimeService', () => { runtime as unknown as { leaves: Map< string, - { lastAgentStatus: string | null; lastAgentStatusObservedLive: boolean } + { + lastAgentStatus: string | null + lastAgentStatusObservedLive: boolean + } > } ).leaves.values() @@ -415,7 +418,12 @@ describe('OrcaRuntimeService', () => { const [terminal] = (await runtime.listTerminals()).terminals runtime.onPtyData('pty-1', '\x1b]0;Codex working\x07', 100) - db.insertMessage({ from: 'term_worker', to: terminal.handle, subject: 'pending' }) + db.insertMessage({ + runId: 'run_legacy_local', + from: 'term_worker', + to: terminal.handle, + subject: 'pending' + }) runtime.notifyMessageArrived(terminal.handle, 'status') db.close() diff --git a/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-02.spec.ts b/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-02.spec.ts index 3c61985e597..a2d45395b26 100644 --- a/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-02.spec.ts +++ b/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-02.spec.ts @@ -390,7 +390,7 @@ describe('OrcaRuntimeService', () => { expect(getSession().terminalTopologyRevisionByRepoId?.[TEST_REPO_ID]).toBe(1) }) - it('fences provider resume and reveals one exact live legacy worker without stealing focus', async () => { + it('reveals one exact live legacy worker without stealing focus', async () => { const workerLeafId = HEADLESS_LEAF_ID const coordinatorLeafId = HEADLESS_SECOND_LEAF_ID const workerPaneKey = `legacy-worker:${workerLeafId}` @@ -526,10 +526,7 @@ describe('OrcaRuntimeService', () => { resolveLegacyWorkerTerminalRecovery } as never) - runtime.prepareLegacyWorkerTerminalRecovery() - expect( - getSession().sleepingAgentSessionsByPaneKey?.[workerPaneKey]?.automaticResumeBlockedBy - ).toBe('legacy-orchestration-worker') + expect(getSession().sleepingAgentSessionsByPaneKey?.[workerPaneKey]).toBeDefined() const recovered = await runtime.reconcileLegacyWorkerTerminals({ materializeRenderer: true diff --git a/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-03.spec.ts b/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-03.spec.ts index 44edd9aa371..00a08310877 100644 --- a/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-03.spec.ts +++ b/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-03.spec.ts @@ -17,7 +17,7 @@ import { } from '../orca-runtime-test-scenario-builders.spec' describe('OrcaRuntimeService', () => { - it('retries renderer reveal before clearing an adopted legacy worker resume fence', async () => { + it('retries renderer reveal before clearing an adopted legacy worker sleeping record', async () => { const workerPaneKey = `legacy-worker:${HEADLESS_LEAF_ID}` const incarnationId = '44444444-4444-4444-8444-444444444444' const session: WorkspaceSessionState = { @@ -106,7 +106,7 @@ describe('OrcaRuntimeService', () => { expect(resolveLegacyWorkerTerminalRecovery).toHaveBeenCalledWith(workerPaneKey, 'adopted') }) - it('keeps a revealed worker fenced until its exact renderer graph is published', async () => { + it('defers a revealed worker until its exact renderer graph is published', async () => { vi.useFakeTimers() try { const harness = makePostRevealWorkerRecoveryHarness(() => true) @@ -288,7 +288,7 @@ describe('OrcaRuntimeService', () => { } }) - it('keeps recovery fenced when the renderer omits the exact reveal identity', async () => { + it('defers recovery when the renderer omits the exact reveal identity', async () => { const harness = makePostRevealWorkerRecoveryHarness(() => false) harness.revealTerminalSession.mockResolvedValue({ tabId: 'legacy-post-reveal' }) @@ -417,7 +417,7 @@ describe('OrcaRuntimeService', () => { ) }) - it('keeps the legacy worker resume fence in memory when persistence fails', async () => { + it('keeps the legacy worker sleeping record in memory when persistence fails', async () => { const workerPaneKey = `legacy-worker:${HEADLESS_LEAF_ID}` const incarnationId = '99999999-9999-4999-8999-999999999999' const session: WorkspaceSessionState = { @@ -526,9 +526,7 @@ describe('OrcaRuntimeService', () => { }) expect(flushPendingOrThrowAsync).toHaveBeenCalledTimes(2) expect(revealTerminalSession).toHaveBeenCalledOnce() - expect( - getSession().sleepingAgentSessionsByPaneKey?.[workerPaneKey]?.automaticResumeBlockedBy - ).toBe('legacy-orchestration-worker') + expect(getSession().sleepingAgentSessionsByPaneKey?.[workerPaneKey]).toBeDefined() expect(getSession().sleepingAgentSessionsByPaneKey?.[concurrentPaneKey]?.tabId).toBe( 'concurrent-tab' ) diff --git a/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-04.spec.ts b/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-04.spec.ts index d09b4c64ce8..ea70b730388 100644 --- a/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-04.spec.ts +++ b/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-04.spec.ts @@ -56,7 +56,10 @@ describe('OrcaRuntimeService', () => { ) const db = new OrchestrationDb(':memory:') try { - const task = db.createTask({ spec: 'continue after missing worker recovery' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'continue after missing worker recovery' + }) const started = db.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -163,7 +166,10 @@ describe('OrcaRuntimeService', () => { ) const db = new OrchestrationDb(':memory:') try { - const task = db.createTask({ spec: 'retry missing worker recovery' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'retry missing worker recovery' + }) const started = db.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -328,10 +334,7 @@ describe('OrcaRuntimeService', () => { resolveLegacyWorkerTerminalRecovery } as never) - runtime.prepareLegacyWorkerTerminalRecovery() - expect( - getSession().sleepingAgentSessionsByPaneKey?.[workerPaneKey]?.automaticResumeBlockedBy - ).toBe('legacy-orchestration-worker') + expect(getSession().sleepingAgentSessionsByPaneKey?.[workerPaneKey]).toBeDefined() await expect(runtime.reconcileLegacyWorkerTerminals()).resolves.toMatchObject({ adoptedDispatchIds: ['dispatch-exited-two'], @@ -445,9 +448,7 @@ describe('OrcaRuntimeService', () => { exitedDispatchIds: [], deferredDispatchIds: ['dispatch-inventory-unavailable'] }) - expect( - getSession().sleepingAgentSessionsByPaneKey?.[workerPaneKey]?.automaticResumeBlockedBy - ).toBe('legacy-orchestration-worker') + expect(getSession().sleepingAgentSessionsByPaneKey?.[workerPaneKey]).toBeDefined() expect(resolveLegacyWorkerTerminalRecovery).not.toHaveBeenCalled() expect(listProcesses).toHaveBeenCalledOnce() expect(getSession().tabsByWorktree[TEST_WORKTREE_ID]).toEqual([]) @@ -477,7 +478,6 @@ describe('OrcaRuntimeService', () => { try { const runtime = new OrcaRuntimeService(store) const reconcile = vi.spyOn(runtime, 'reconcileLegacyWorkerTerminals').mockResolvedValue({ - blockedPaneCount: 1, adoptedDispatchIds: [], exitedDispatchIds: [], deferredDispatchIds: [] diff --git a/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-05.spec.ts b/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-05.spec.ts index 5798916570e..389c70d4f42 100644 --- a/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-05.spec.ts +++ b/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-05.spec.ts @@ -18,13 +18,12 @@ import { TEST_WORKTREE_PATH, makeFolderProjectGroup, makeFolderWorkspace, - makeRuntimeStoreWithWorkspaceSession, - store + makeRuntimeStoreWithWorkspaceSession } from '../orca-runtime-test-fixtures.spec' import { publishLegacyWorkerReveal } from '../orca-runtime-test-scenario-builders.spec' describe('OrcaRuntimeService', () => { - it('keeps live workers fenced without exact controller identity evidence', async () => { + it('defers live workers without exact controller identity evidence', async () => { const incarnationId = '56565656-5656-4656-8656-565656565656' const cases = [ { @@ -152,8 +151,7 @@ describe('OrcaRuntimeService', () => { for (const { name, leafId } of cases.slice(0, 2)) { expect( getSession().sleepingAgentSessionsByPaneKey?.[`legacy-${name}:${leafId}`] - ?.automaticResumeBlockedBy - ).toBe('legacy-orchestration-worker') + ).toBeDefined() } for (const { name, leafId } of cases.slice(2)) { expect( @@ -374,12 +372,7 @@ describe('OrcaRuntimeService', () => { } as never) try { - expect(runtime.prepareLegacyWorkerTerminalRecovery()).toMatchObject({ - blockedPanes: [expect.objectContaining({ paneKey: workerPaneKey })] - }) - expect( - sshSession.sleepingAgentSessionsByPaneKey?.[workerPaneKey]?.automaticResumeBlockedBy - ).toBe('legacy-orchestration-worker') + expect(sshSession.sleepingAgentSessionsByPaneKey?.[workerPaneKey]).toBeDefined() expect(localSession.sleepingAgentSessionsByPaneKey?.[workerPaneKey]).toBeUndefined() await expect( runtime.reconcileLegacyWorkerTerminals({ @@ -422,74 +415,4 @@ describe('OrcaRuntimeService', () => { } }) }) - - it('fences an unresolved folder legacy worker in its exact retained session partition', () => { - const connectionId = 'ssh-unresolved-folder' - const worktreeId = 'folder:missing-folder' - const workerPaneKey = `legacy-unresolved-folder-worker:${HEADLESS_LEAF_ID}` - const remoteInitialSession: WorkspaceSessionState = { - ...getDefaultWorkspaceSession(), - tabsByWorktree: { [worktreeId]: [] }, - sleepingAgentSessionsByPaneKey: { - [workerPaneKey]: { - paneKey: workerPaneKey, - tabId: 'legacy-unresolved-folder-worker', - worktreeId, - agent: 'codex', - providerSession: { key: 'session_id', id: 'legacy-unresolved-folder-session' }, - prompt: 'continue', - state: 'working', - capturedAt: 1, - updatedAt: 1, - origin: 'live', - connectionId - } - } - } - const localSession = getDefaultWorkspaceSession() - let remoteSession = remoteInitialSession - const getWorkspaceSession = vi.fn((hostId?: string | null) => - hostId === `ssh:${connectionId}` ? remoteSession : localSession - ) - const setWorkspaceSession = vi.fn((next: WorkspaceSessionState, hostId?: string | null) => { - if (hostId !== `ssh:${connectionId}`) { - throw new Error(`unexpected workspace-session host ${hostId ?? 'default'}`) - } - remoteSession = next - }) - const runtime = new OrcaRuntimeService({ - ...store, - getFolderWorkspaces: () => [], - getWorkspaceSession, - getWorkspaceSessionHostIds: () => ['local', `ssh:${connectionId}`], - setWorkspaceSession, - flushOrThrow: vi.fn() - } as never) - runtime.setOrchestrationDb({ - listLegacyWorkerTerminalRecoveryRows: () => [ - { - dispatch_id: 'dispatch-unresolved-folder', - task_id: 'task-unresolved-folder', - dispatch_status: 'completed', - contract_version: 0, - assignee_handle: 'term_unresolved_folder', - assignee_pane_key: workerPaneKey, - process_incarnation: 'pty-unresolved-folder:68686868-6868-4868-8868-686868686868', - worker_state: 'ready', - worktree_id: worktreeId, - agent_terminal_handle: 'term_unresolved_folder' - } - ] - } as unknown as OrchestrationDb) - - expect(runtime.prepareLegacyWorkerTerminalRecovery()).toMatchObject({ - blockedPanes: [expect.objectContaining({ paneKey: workerPaneKey, worktreeId })] - }) - expect( - remoteSession.sleepingAgentSessionsByPaneKey?.[workerPaneKey]?.automaticResumeBlockedBy - ).toBe('legacy-orchestration-worker') - expect(localSession.sleepingAgentSessionsByPaneKey?.[workerPaneKey]).toBeUndefined() - expect(setWorkspaceSession).toHaveBeenCalledOnce() - expect(setWorkspaceSession).toHaveBeenCalledWith(expect.any(Object), `ssh:${connectionId}`) - }) }) diff --git a/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-06.spec.ts b/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-06.spec.ts index 4078a291ab5..1907b2bb450 100644 --- a/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-06.spec.ts +++ b/src/main/runtime/orca-runtime-tests/terminal-output-and-worker-recovery-part-06.spec.ts @@ -153,11 +153,8 @@ describe('OrcaRuntimeService', () => { deferredDispatchIds: ['dispatch-ssh'] }) expect(listProcesses).not.toHaveBeenCalled() - expect( - getSession().sleepingAgentSessionsByPaneKey?.[workerPaneKey]?.automaticResumeBlockedBy - ).toBe('legacy-orchestration-worker') + expect(getSession().sleepingAgentSessionsByPaneKey?.[workerPaneKey]).toBeDefined() expect(localSession.sleepingAgentSessionsByPaneKey?.[workerPaneKey]).toBeUndefined() - expect(getWorkspaceSession).toHaveBeenCalledWith(`ssh:${connectionId}`) await expect( runtime.reconcileLegacyWorkerTerminals({ @@ -175,6 +172,7 @@ describe('OrcaRuntimeService', () => { } expect(getSession().sleepingAgentSessionsByPaneKey?.[workerPaneKey]).toBeUndefined() + expect(getWorkspaceSession).toHaveBeenCalledWith(`ssh:${connectionId}`) expect(setWorkspaceSession).toHaveBeenCalledWith(expect.any(Object), `ssh:${connectionId}`) expect(listProcesses).toHaveBeenCalledTimes(3) expect(revealTerminalSession).toHaveBeenCalledWith(TEST_WORKTREE_ID, { @@ -297,9 +295,7 @@ describe('OrcaRuntimeService', () => { exitedDispatchIds: [], deferredDispatchIds: ['dispatch-wsl'] }) - expect( - getSession().sleepingAgentSessionsByPaneKey?.[workerPaneKey]?.automaticResumeBlockedBy - ).toBe('legacy-orchestration-worker') + expect(getSession().sleepingAgentSessionsByPaneKey?.[workerPaneKey]).toBeDefined() expect(revealTerminalSession).not.toHaveBeenCalled() observedDistro = 'Ubuntu' diff --git a/src/main/runtime/orchestration-messages-fake-parity.test.ts b/src/main/runtime/orchestration-messages-fake-parity.test.ts index 72ed8695b5b..5a785fc8602 100644 --- a/src/main/runtime/orchestration-messages-fake-parity.test.ts +++ b/src/main/runtime/orchestration-messages-fake-parity.test.ts @@ -7,9 +7,13 @@ type PointerTarget = { ptyId: string; processIncarnation: string } // The slice of the mailbox store the pointer batch selector depends on. type PointerStore = { - insertMessage(message: { from: string; to: string; subject: string; type?: MessageType }): { - id: string - } + insertMessage(message: { + runId: string + from: string + to: string + subject: string + type?: MessageType + }): { id: string } stageMailboxPointerEnter(ids: string[], target: PointerTarget): boolean markMailboxPointerWriteAttempted(ids: string[], target: PointerTarget): boolean getUndeliveredUnreadMessages( @@ -32,7 +36,12 @@ describe.each(STORES)('mailbox pointer reservations (%s)', (_name, createStore) it('refuses a claim another flight already holds', () => { const store = createStore() - const message = store.insertMessage({ from: 'a', to: 'run:run-1', subject: 'contended' }) + const message = store.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'run:run-1', + subject: 'contended' + }) expect(store.stageMailboxPointerEnter([message.id], rival)).toBe(true) expect(store.stageMailboxPointerEnter([message.id], mine)).toBe(false) @@ -41,8 +50,18 @@ describe.each(STORES)('mailbox pointer reservations (%s)', (_name, createStore) it('rolls the whole batch back when one row is already claimed', () => { const store = createStore() - const free = store.insertMessage({ from: 'a', to: 'run:run-1', subject: 'free' }) - const taken = store.insertMessage({ from: 'a', to: 'run:run-1', subject: 'taken' }) + const free = store.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'run:run-1', + subject: 'free' + }) + const taken = store.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'run:run-1', + subject: 'taken' + }) expect(store.stageMailboxPointerEnter([taken.id], rival)).toBe(true) expect(store.stageMailboxPointerEnter([free.id, taken.id], mine)).toBe(false) @@ -52,8 +71,19 @@ describe.each(STORES)('mailbox pointer reservations (%s)', (_name, createStore) it('applies the exclusion and limit the pointer batch selector relies on', () => { const store = createStore() - store.insertMessage({ from: 'a', to: 'run:run-1', subject: 'reserved', type: 'escalation' }) - const kept = store.insertMessage({ from: 'a', to: 'run:run-1', subject: 'kept' }) + store.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'run:run-1', + subject: 'reserved', + type: 'escalation' + }) + const kept = store.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'run:run-1', + subject: 'kept' + }) expect( store diff --git a/src/main/runtime/orchestration/coordinator-decision-gates.test.ts b/src/main/runtime/orchestration/coordinator-decision-gates.test.ts index 15e0cd2c7b0..3e9934b85ad 100644 --- a/src/main/runtime/orchestration/coordinator-decision-gates.test.ts +++ b/src/main/runtime/orchestration/coordinator-decision-gates.test.ts @@ -12,13 +12,14 @@ describe('coordinator decision-gate authority', () => { it('opens a gate only for the sender-owned active Dispatch', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'owned gate target' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'owned gate target' }) const dispatch = createRootDispatch(db, task.id, 'term_owner', 'tab_owner:leaf_owner') const logs: string[] = [] openDecisionGateFromMessage( db, db.insertMessage({ + runId: 'run_legacy_local', from: 'term_owner', to: 'term_coordinator', subject: 'Need approval', @@ -41,20 +42,27 @@ describe('coordinator decision-gate authority', () => { it('rejects a gate targeting another active Dispatch without mutating either Task', () => { db = new OrchestrationDb(':memory:') - const attackerTask = db.createTask({ spec: 'attacker assignment' }) + const attackerTask = db.createTask({ + runId: 'run_legacy_local', + spec: 'attacker assignment' + }) const attacker = createRootDispatch( db, attackerTask.id, 'term_attacker', 'tab_attacker:leaf_attacker' ) - const victimTask = db.createTask({ spec: 'victim assignment' }) + const victimTask = db.createTask({ + runId: 'run_legacy_local', + spec: 'victim assignment' + }) const victim = createRootDispatch(db, victimTask.id, 'term_victim', 'tab_victim:leaf_victim') const logs: string[] = [] openDecisionGateFromMessage( db, db.insertMessage({ + runId: 'run_legacy_local', from: 'term_attacker', to: 'term_coordinator', subject: 'Block the victim', @@ -79,12 +87,16 @@ describe('coordinator decision-gate authority', () => { it('accepts the canonical sender of an imported federated Dispatch', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'remote gate target' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'remote gate target' + }) const dispatch = createRootDispatch(db, task.id, 'remote-worker') openDecisionGateFromMessage( db, db.insertMessage({ + runId: 'run_legacy_local', from: `dispatch:${dispatch.id}`, to: 'term_coordinator', subject: 'Remote approval required', diff --git a/src/main/runtime/orchestration/coordinator-dispatch-unobserved-prompt.test.ts b/src/main/runtime/orchestration/coordinator-dispatch-unobserved-prompt.test.ts index 5f99e283de3..f0960803988 100644 --- a/src/main/runtime/orchestration/coordinator-dispatch-unobserved-prompt.test.ts +++ b/src/main/runtime/orchestration/coordinator-dispatch-unobserved-prompt.test.ts @@ -66,7 +66,7 @@ describe('coordinator dispatch with an unobserved prompt', () => { it('never re-pastes a preamble whose turn start was not observed', async () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'do the work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'do the work' }) const runtime = createRuntime(new Error('agent_prompt_stalled')) const logs: string[] = [] @@ -88,7 +88,7 @@ describe('coordinator dispatch with an unobserved prompt', () => { it('lets a late worker report settle a dispatch whose prompt was unobserved', async () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'do the work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'do the work' }) await dispatch(createRuntime(new Error('agent_prompt_stalled')), task.id, []) const dispatchId = db.getDispatchContext(task.id)!.id const minted = db.mintDispatchCapability({ @@ -119,7 +119,7 @@ describe('coordinator dispatch with an unobserved prompt', () => { it('still fails the dispatch when the prompt was never delivered', async () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'do the work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'do the work' }) const runtime = createRuntime(new Error('terminal_not_writable')) await expect(dispatch(runtime, task.id, [])).rejects.toThrow('terminal_not_writable') diff --git a/src/main/runtime/orchestration/coordinator-drift-probe-coalescing.test.ts b/src/main/runtime/orchestration/coordinator-drift-probe-coalescing.test.ts index f42713c0dc9..5367af466bf 100644 --- a/src/main/runtime/orchestration/coordinator-drift-probe-coalescing.test.ts +++ b/src/main/runtime/orchestration/coordinator-drift-probe-coalescing.test.ts @@ -44,8 +44,8 @@ describe('Coordinator drift probe coalescing', () => { : { base: 'origin/main', behind: 0, recentSubjects: [] } } } - const first = db.createTask({ spec: 'first task' }) - const second = db.createTask({ spec: 'second task' }) + const first = db.createTask({ runId: 'run_legacy_local', spec: 'first task' }) + const second = db.createTask({ runId: 'run_legacy_local', spec: 'second task' }) const coordinator = new Coordinator(db, runtime, { spec: 'go', coordinatorHandle: 'coord', @@ -65,6 +65,7 @@ describe('Coordinator drift probe coalescing', () => { throw new Error(`missing dispatch for ${task.id}`) } db.insertMessage({ + runId: 'run_legacy_local', from: dispatch.assignee_handle, to: 'coord', subject: 'Done', @@ -105,8 +106,14 @@ describe('Coordinator drift probe coalescing', () => { } } } - const refused = db.createTask({ spec: 'requires a current base' }) - const allowed = db.createTask({ spec: 'can use stale base\nallow-stale-base: true' }) + const refused = db.createTask({ + runId: 'run_legacy_local', + spec: 'requires a current base' + }) + const allowed = db.createTask({ + runId: 'run_legacy_local', + spec: 'can use stale base\nallow-stale-base: true' + }) const coordinator = new Coordinator(db, runtime, { spec: 'go', coordinatorHandle: 'coord', diff --git a/src/main/runtime/orchestration/coordinator-escalation-triage.test.ts b/src/main/runtime/orchestration/coordinator-escalation-triage.test.ts index c020e62dca0..e0bdf75fc98 100644 --- a/src/main/runtime/orchestration/coordinator-escalation-triage.test.ts +++ b/src/main/runtime/orchestration/coordinator-escalation-triage.test.ts @@ -12,20 +12,21 @@ describe('coordinator escalation authority', () => { it('rejects an escalation targeting another active Dispatch', () => { db = new OrchestrationDb(':memory:') - const attackerTask = db.createTask({ spec: 'attacker assignment' }) + const attackerTask = db.createTask({ runId: 'run_legacy_local', spec: 'attacker assignment' }) const attacker = createRootDispatch( db, attackerTask.id, 'term_attacker', 'tab_attacker:leaf_attacker' ) - const victimTask = db.createTask({ spec: 'victim assignment' }) + const victimTask = db.createTask({ runId: 'run_legacy_local', spec: 'victim assignment' }) const victim = createRootDispatch(db, victimTask.id, 'term_victim') const logs: string[] = [] applyEscalationToDispatch( db, db.insertMessage({ + runId: 'run_legacy_local', from: 'term_attacker', to: 'term_coordinator', subject: 'Fail the victim', @@ -43,12 +44,13 @@ describe('coordinator escalation authority', () => { it('accepts the canonical sender of an imported federated Dispatch', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'remote escalation target' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'remote escalation target' }) const dispatch = createRootDispatch(db, task.id, 'remote-worker') applyEscalationToDispatch( db, db.insertMessage({ + runId: 'run_legacy_local', from: `dispatch:${dispatch.id}`, to: 'term_coordinator', subject: 'Remote worker failed', diff --git a/src/main/runtime/orchestration/coordinator-stale-base-flag.test.ts b/src/main/runtime/orchestration/coordinator-stale-base-flag.test.ts new file mode 100644 index 00000000000..818d3f848dc --- /dev/null +++ b/src/main/runtime/orchestration/coordinator-stale-base-flag.test.ts @@ -0,0 +1,52 @@ +import { describe, expect, it } from 'vitest' +import { parseAllowStaleBaseFromSpec } from './coordinator-stale-base-flag' + +describe('parseAllowStaleBaseFromSpec', () => { + it('matches canonical form on its own line and strips it', () => { + const spec = `Do the work +allow-stale-base: true` + const { allowStale, strippedSpec } = parseAllowStaleBaseFromSpec(spec) + expect(allowStale).toBe(true) + expect(strippedSpec).toBe('Do the work\n') + expect(strippedSpec).not.toContain('allow-stale-base') + }) + + it('matches case-insensitively', () => { + const spec = `Do the work +Allow-Stale-Base: TRUE` + const { allowStale, strippedSpec } = parseAllowStaleBaseFromSpec(spec) + expect(allowStale).toBe(true) + expect(strippedSpec).not.toMatch(/[Aa]llow-[Ss]tale-[Bb]ase/) + }) + + it('does not match allow-stale-base: false', () => { + const spec = `Do the work +allow-stale-base: false` + const { allowStale, strippedSpec } = parseAllowStaleBaseFromSpec(spec) + expect(allowStale).toBe(false) + expect(strippedSpec).toBe(spec) + }) + + it('does not match allow-stale-base: truthy', () => { + const spec = `Do the work +allow-stale-base: truthy` + const { allowStale, strippedSpec } = parseAllowStaleBaseFromSpec(spec) + expect(allowStale).toBe(false) + expect(strippedSpec).toBe(spec) + }) + + it('does not match the flag embedded inside a sentence', () => { + const spec = 'we allow-stale-base: true sometimes' + const { allowStale, strippedSpec } = parseAllowStaleBaseFromSpec(spec) + expect(allowStale).toBe(false) + expect(strippedSpec).toBe(spec) + }) + + it('handles the flag as the last line with no trailing newline', () => { + const spec = 'line 1\nallow-stale-base: true' + const { allowStale, strippedSpec } = parseAllowStaleBaseFromSpec(spec) + expect(allowStale).toBe(true) + expect(strippedSpec).toBe('line 1\n') + expect(strippedSpec.endsWith('allow-stale-base: true')).toBe(false) + }) +}) diff --git a/src/main/runtime/orchestration/coordinator.test.ts b/src/main/runtime/orchestration/coordinator.test.ts index 38701a9d7dd..75ba01ffa27 100644 --- a/src/main/runtime/orchestration/coordinator.test.ts +++ b/src/main/runtime/orchestration/coordinator.test.ts @@ -3,12 +3,11 @@ import { OrchestrationDb } from './db' import { reconcileLifecycleMessage } from './lifecycle-reconciliation' import { Coordinator } from './coordinator' import type { CoordinatorRuntime } from './coordinator-runtime-contract' -import { - DISPATCH_STALE_THRESHOLD, - parseAllowStaleBaseFromSpec -} from './coordinator-stale-base-flag' +import { DISPATCH_STALE_THRESHOLD } from './coordinator-stale-base-flag' import { createRootDispatch } from './db/root-dispatch-test-fixture' +const runId = 'run_legacy_local' + type DriftResult = { base: string behind: number @@ -92,6 +91,7 @@ function insertWorkerDone( } const from = params.from ?? dispatch?.assignee_handle ?? 'term_unknown' db.insertMessage({ + runId, from, to: params.to ?? 'coord', subject: 'Done', @@ -131,7 +131,10 @@ describe('Coordinator', () => { runtime.cliCommand = 'orca-ide' runtime.terminals = [{ handle: 'term_a', worktreeId: 'wt1', connected: true, writable: true }] - const task = db.createTask({ spec: 'implement feature' }) + const task = db.createTask({ + runId, + spec: 'implement feature' + }) // Simulate worker_done arriving after dispatch const coordinator = new Coordinator(db, runtime, { @@ -166,7 +169,10 @@ describe('Coordinator', () => { getTerminalPaneKey: (handle: string) => (handle === 'term_a' ? 'tab_a:leaf_a' : null) }) - const task = db.createTask({ spec: 'implement feature' }) + const task = db.createTask({ + runId, + spec: 'implement feature' + }) const coordinator = new Coordinator(db, withPaneLookup, { spec: 'build it', coordinatorHandle: 'coord', @@ -198,7 +204,10 @@ describe('Coordinator', () => { } : null }) - const task = db.createTask({ spec: 'implement feature' }) + const task = db.createTask({ + runId, + spec: 'implement feature' + }) const coordinator = new Coordinator(db, withAuthority, { spec: 'build it', coordinatorHandle: 'coord', @@ -223,9 +232,13 @@ describe('Coordinator', () => { db = new OrchestrationDb(':memory:') const runtime = createMockRuntime() - const task = db.createTask({ spec: 'send-driven completion' }) + const task = db.createTask({ + runId, + spec: 'send-driven completion' + }) const dispatch = createRootDispatch(db, task.id, 'term_a') const msg = db.insertMessage({ + runId, from: 'term_a', to: 'coord', subject: 'Done', @@ -250,7 +263,10 @@ describe('Coordinator', () => { db = new OrchestrationDb(':memory:') const runtime = createMockRuntime() - const task = db.createTask({ spec: 'duplicate completion' }) + const task = db.createTask({ + runId, + spec: 'duplicate completion' + }) const dispatch = createRootDispatch(db, task.id, 'term_a') const payload = JSON.stringify({ taskId: task.id, @@ -258,6 +274,7 @@ describe('Coordinator', () => { outcome: 'succeeded' }) const first = db.insertMessage({ + runId, from: 'term_a', to: 'coord', subject: 'Done', @@ -265,6 +282,7 @@ describe('Coordinator', () => { payload }) db.insertMessage({ + runId, from: 'term_a', to: 'coord', subject: 'Done again', @@ -289,7 +307,7 @@ describe('Coordinator', () => { db = new OrchestrationDb(':memory:') const runtime = createMockRuntime() - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId, spec: 'work' }) const coordinator = new Coordinator(db, runtime, { spec: 'go', @@ -321,7 +339,10 @@ describe('Coordinator', () => { { handle: 'term_b', worktreeId: 'wt1', connected: true, writable: true } ] - const task = db.createTask({ spec: 'risky work' }) + const task = db.createTask({ + runId, + spec: 'risky work' + }) const coordinator = new Coordinator(db, runtime, { spec: 'go', @@ -339,6 +360,7 @@ describe('Coordinator', () => { const dispatch = db.getDispatchContext(task.id) expect(dispatch).toBeDefined() db.insertMessage({ + runId, from: dispatch?.assignee_handle ?? 'missing-worker', to: 'coord', subject: `Failed attempt ${i + 1}`, @@ -360,7 +382,10 @@ describe('Coordinator', () => { throw new Error('terminal_not_writable') } - const task = db.createTask({ spec: 'cannot dispatch' }) + const task = db.createTask({ + runId, + spec: 'cannot dispatch' + }) const coordinator = new Coordinator(db, runtime, { spec: 'go', coordinatorHandle: 'coord', @@ -379,7 +404,10 @@ describe('Coordinator', () => { const runtime = createMockRuntime() runtime.terminals = [{ handle: 'term_a', worktreeId: 'wt1', connected: true, writable: true }] - const task = db.createTask({ spec: 'needs approval' }) + const task = db.createTask({ + runId, + spec: 'needs approval' + }) const coordinator = new Coordinator(db, runtime, { spec: 'go', @@ -398,6 +426,7 @@ describe('Coordinator', () => { const dispatch = db.getDispatchContext(task.id) expect(dispatch).toBeDefined() db.insertMessage({ + runId, from: 'term_a', to: 'coord', subject: 'Need approval', @@ -441,8 +470,12 @@ describe('Coordinator', () => { const runtime = createMockRuntime() runtime.terminals = [{ handle: 'term_a', worktreeId: 'wt1', connected: true, writable: true }] - const t1 = db.createTask({ spec: 'first' }) - const t2 = db.createTask({ spec: 'second', deps: [t1.id] }) + const t1 = db.createTask({ runId, spec: 'first' }) + const t2 = db.createTask({ + runId, + spec: 'second', + deps: [t1.id] + }) expect(t2.status).toBe('pending') @@ -492,9 +525,9 @@ describe('Coordinator', () => { { handle: 'term_c', worktreeId: 'wt1', connected: true, writable: true } ] - const t1 = db.createTask({ spec: 'one' }) - const t2 = db.createTask({ spec: 'two' }) - const t3 = db.createTask({ spec: 'three' }) + const t1 = db.createTask({ runId, spec: 'one' }) + const t2 = db.createTask({ runId, spec: 'two' }) + const t3 = db.createTask({ runId, spec: 'three' }) const coordinator = new Coordinator(db, runtime, { spec: 'go', @@ -530,7 +563,7 @@ describe('Coordinator', () => { const runtime = createMockRuntime() // No terminals available so dispatchReadyTasks creates one and we can // drive the stale-scan deterministically via SQL backdating. - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId, spec: 'work' }) const ctx = createRootDispatch(db, task.id, 'term_stale') // Backdate dispatched_at and last_heartbeat_at beyond the 10-min threshold @@ -569,7 +602,7 @@ describe('Coordinator', () => { const runtime = createMockRuntime() runtime.terminals = [{ handle: 'term_a', worktreeId: 'wt1', connected: true, writable: true }] - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId, spec: 'work' }) const ctx = createRootDispatch(db, task.id, 'term_a') const coordinator = new Coordinator(db, runtime, { @@ -581,6 +614,7 @@ describe('Coordinator', () => { const runPromise = coordinator.run() db.insertMessage({ + runId, from: 'term_a', to: 'coord', subject: 'alive', @@ -606,12 +640,16 @@ describe('Coordinator', () => { const runtime = createMockRuntime() const logs: string[] = [] - const task = db.createTask({ spec: 'retry-sensitive work' }) + const task = db.createTask({ + runId, + spec: 'retry-sensitive work' + }) const staleCtx = createRootDispatch(db, task.id, 'term_old') db.failDispatch(staleCtx.id, 'retry elsewhere') const activeCtx = createRootDispatch(db, task.id, 'term_current') db.insertMessage({ + runId, from: 'term_old', to: 'coord', subject: 'Late done', @@ -663,11 +701,15 @@ describe('Coordinator', () => { const runtime = createMockRuntime() const logs: string[] = [] - const task = db.createTask({ spec: 'owned work' }) + const task = db.createTask({ + runId, + spec: 'owned work' + }) const leafId = '11111111-1111-4111-8111-111111111111' const ctx = createRootDispatch(db, task.id, 'term_owner', `tab_before:${leafId}`) db.insertMessage({ + runId, from: 'term_reminted', to: 'coord', subject: 'Done after restart', @@ -693,7 +735,7 @@ describe('Coordinator', () => { it('can be stopped', async () => { db = new OrchestrationDb(':memory:') const runtime = createMockRuntime() - db.createTask({ spec: 'never finishes' }) + db.createTask({ runId, spec: 'never finishes' }) const coordinator = new Coordinator(db, runtime, { spec: 'go', @@ -723,7 +765,10 @@ describe('Coordinator', () => { recentSubjects: ['fix A', 'fix B', 'fix C'] }) - const task = db.createTask({ spec: 'do the work' }) + const task = db.createTask({ + runId, + spec: 'do the work' + }) const coordinator = new Coordinator(db, runtime, { spec: 'go', @@ -759,7 +804,10 @@ describe('Coordinator', () => { recentSubjects: ['fix A'] }) - const task = db.createTask({ spec: 'do the work' }) + const task = db.createTask({ + runId, + spec: 'do the work' + }) const coordinator = new Coordinator(db, runtime, { spec: 'go', @@ -799,7 +847,7 @@ describe('Coordinator', () => { const spec = `Investigate issue #42 allow-stale-base: true` - const task = db.createTask({ spec }) + const task = db.createTask({ runId, spec }) const coordinator = new Coordinator(db, runtime, { spec: 'go', @@ -832,7 +880,10 @@ allow-stale-base: true` runtime.terminals = [{ handle: 'term_a', worktreeId: 'wt1', connected: true, writable: true }] runtime.setProbeDrift(null) - const task = db.createTask({ spec: 'do the work' }) + const task = db.createTask({ + runId, + spec: 'do the work' + }) const coordinator = new Coordinator(db, runtime, { spec: 'go', @@ -861,7 +912,10 @@ allow-stale-base: true` runtime.terminals = [{ handle: 'term_a', worktreeId: 'wt1', connected: true, writable: true }] const logs: string[] = [] - const task = db.createTask({ spec: 'do the work' }) + const task = db.createTask({ + runId, + spec: 'do the work' + }) const coordinator = new Coordinator(db, runtime, { spec: 'go', @@ -892,7 +946,10 @@ allow-stale-base: true` runtime.terminals = [{ handle: 'term_a', worktreeId: 'wt1', connected: true, writable: true }] runtime.throwProbeDrift = new Error('boom') - const task = db.createTask({ spec: 'do the work' }) + const task = db.createTask({ + runId, + spec: 'do the work' + }) const coordinator = new Coordinator(db, runtime, { spec: 'go', @@ -915,53 +972,3 @@ allow-stale-base: true` }) }) }) - -describe('parseAllowStaleBaseFromSpec', () => { - it('matches canonical form on its own line and strips it', () => { - const spec = `Do the work -allow-stale-base: true` - const { allowStale, strippedSpec } = parseAllowStaleBaseFromSpec(spec) - expect(allowStale).toBe(true) - expect(strippedSpec).toBe('Do the work\n') - expect(strippedSpec).not.toContain('allow-stale-base') - }) - - it('matches case-insensitively', () => { - const spec = `Do the work -Allow-Stale-Base: TRUE` - const { allowStale, strippedSpec } = parseAllowStaleBaseFromSpec(spec) - expect(allowStale).toBe(true) - expect(strippedSpec).not.toMatch(/[Aa]llow-[Ss]tale-[Bb]ase/) - }) - - it('does not match allow-stale-base: false', () => { - const spec = `Do the work -allow-stale-base: false` - const { allowStale, strippedSpec } = parseAllowStaleBaseFromSpec(spec) - expect(allowStale).toBe(false) - expect(strippedSpec).toBe(spec) - }) - - it('does not match allow-stale-base: truthy', () => { - const spec = `Do the work -allow-stale-base: truthy` - const { allowStale, strippedSpec } = parseAllowStaleBaseFromSpec(spec) - expect(allowStale).toBe(false) - expect(strippedSpec).toBe(spec) - }) - - it('does not match the flag embedded inside a sentence', () => { - const spec = 'we allow-stale-base: true sometimes' - const { allowStale, strippedSpec } = parseAllowStaleBaseFromSpec(spec) - expect(allowStale).toBe(false) - expect(strippedSpec).toBe(spec) - }) - - it('handles the flag as the last line with no trailing newline', () => { - const spec = 'line 1\nallow-stale-base: true' - const { allowStale, strippedSpec } = parseAllowStaleBaseFromSpec(spec) - expect(allowStale).toBe(true) - expect(strippedSpec).toBe('line 1\n') - expect(strippedSpec.endsWith('allow-stale-base: true')).toBe(false) - }) -}) diff --git a/src/main/runtime/orchestration/db-empty-dispatch-shortcircuit.benchmark.test.ts b/src/main/runtime/orchestration/db-empty-dispatch-shortcircuit.benchmark.test.ts index c729a8b1dd7..6407e67bc4b 100644 --- a/src/main/runtime/orchestration/db-empty-dispatch-shortcircuit.benchmark.test.ts +++ b/src/main/runtime/orchestration/db-empty-dispatch-shortcircuit.benchmark.test.ts @@ -64,7 +64,7 @@ describe('orchestration empty-dispatch short-circuit (benchmark)', () => { it('still runs the fan-out once a dispatch exists (correctness preserved)', () => { const db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) createRootDispatch(db, task.id, 'term_5') const handles = Array.from({ length: 10 }, (_, i) => `term_${i}`) @@ -76,7 +76,11 @@ describe('orchestration empty-dispatch short-circuit (benchmark)', () => { it('predicate lifecycle: false when empty, true after dispatch (even completed), false after reset', () => { const db = new OrchestrationDb(':memory:') expect(db.hasAnyDispatchContexts()).toBe(false) - const ctx = createRootDispatch(db, db.createTask({ spec: 'work' }).id, 'term_worker') + const ctx = createRootDispatch( + db, + db.createTask({ runId: 'run_legacy_local', spec: 'work' }).id, + 'term_worker' + ) expect(db.hasAnyDispatchContexts()).toBe(true) // Completed rows still count — recent-completed lookups must stay valid. db.completeDispatch(ctx.id) diff --git a/src/main/runtime/orchestration/db-heartbeat-straggler-guard.test.ts b/src/main/runtime/orchestration/db-heartbeat-straggler-guard.test.ts index 793c218e162..c7743757aa9 100644 --- a/src/main/runtime/orchestration/db-heartbeat-straggler-guard.test.ts +++ b/src/main/runtime/orchestration/db-heartbeat-straggler-guard.test.ts @@ -13,7 +13,7 @@ afterEach(() => { function seedHeartbeatedDispatch(): { d: OrchestrationDb; dispatchId: string } { const d = new OrchestrationDb(':memory:') db = d - const task = d.createTask({ spec: 'work' }) + const task = d.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(d, task.id, 'term_worker') d.recordHeartbeat(dispatch.id, '2026-05-03T00:00:00.000Z') return { d, dispatchId: dispatch.id } diff --git a/src/main/runtime/orchestration/db-message-timestamp.test.ts b/src/main/runtime/orchestration/db-message-timestamp.test.ts index d4d000c48d3..3900904e5b1 100644 --- a/src/main/runtime/orchestration/db-message-timestamp.test.ts +++ b/src/main/runtime/orchestration/db-message-timestamp.test.ts @@ -8,7 +8,12 @@ describe('orchestration message timestamps', () => { it('exposes SQLite timestamps with an explicit UTC designator', () => { db = new OrchestrationDb(':memory:') - const message = db.insertMessage({ from: 'a', to: 'b', subject: 'timestamped' }) + const message = db.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'b', + subject: 'timestamped' + }) expect(message.created_at).toMatch(/^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}(?:\.\d+)?Z$/) db.markAsDelivered([message.id]) diff --git a/src/main/runtime/orchestration/db-messages.test.ts b/src/main/runtime/orchestration/db-messages.test.ts new file mode 100644 index 00000000000..789797d12f0 --- /dev/null +++ b/src/main/runtime/orchestration/db-messages.test.ts @@ -0,0 +1,194 @@ +import { afterEach, describe, expect, it } from 'vitest' +import type Database from '../../sqlite/sync-database' +import { OrchestrationDb, type MessageType } from './db' + +const runId = 'run_legacy_local' + +describe('OrchestrationDb', () => { + let db: OrchestrationDb | undefined + + afterEach(() => { + db?.close() + }) + + function createDb(): OrchestrationDb { + db = new OrchestrationDb(':memory:') + return db + } + + describe('messages', () => { + it('inserts and retrieves a message', () => { + const d = createDb() + const msg = d.insertMessage({ + runId, + from: 'term_a', + to: 'term_b', + subject: 'hello', + body: 'world' + }) + expect(msg.id).toMatch(/^msg_/) + expect(msg.from_handle).toBe('term_a') + expect(msg.to_handle).toBe('term_b') + expect(msg.subject).toBe('hello') + expect(msg.body).toBe('world') + expect(msg.type).toBe('status') + expect(msg.priority).toBe('normal') + expect(msg.read).toBe(0) + expect(msg.sequence).toBeGreaterThan(0) + }) + + it('returns unread messages in sequence order', () => { + const d = createDb() + d.insertMessage({ runId, from: 'a', to: 'b', subject: 'first' }) + d.insertMessage({ runId, from: 'a', to: 'b', subject: 'second' }) + d.insertMessage({ runId, from: 'a', to: 'c', subject: 'other' }) + + const unread = d.getUnreadMessages('b') + expect(unread).toHaveLength(2) + expect(unread[0].subject).toBe('first') + expect(unread[1].subject).toBe('second') + }) + + it('filters unread by type', () => { + const d = createDb() + d.insertMessage({ + runId, + from: 'a', + to: 'b', + subject: 'status msg', + type: 'status' + }) + d.insertMessage({ + runId, + from: 'a', + to: 'b', + subject: 'done msg', + type: 'worker_done' + }) + + const filtered = d.getUnreadMessages('b', ['worker_done']) + expect(filtered).toHaveLength(1) + expect(filtered[0].type).toBe('worker_done') + }) + + it('excludes already-delivered rows from getUndeliveredUnreadMessages', () => { + const d = createDb() + const m1 = d.insertMessage({ runId, from: 'a', to: 'b', subject: 'one' }) + const m2 = d.insertMessage({ runId, from: 'a', to: 'b', subject: 'two' }) + + d.markAsDelivered([m1.id]) + + // Push delivery query: only undelivered, unread. + const pending = d.getUndeliveredUnreadMessages('b') + expect(pending).toHaveLength(1) + expect(pending[0].id).toBe(m2.id) + + // Explicit `check` still sees both (they are still unread). + const unread = d.getUnreadMessages('b') + expect(unread).toHaveLength(2) + }) + + it('creates the undelivered inbox index used by push delivery', () => { + const d = createDb() + const sqlite = (d as unknown as { db: Database.Database }).db + + const indexes = sqlite + .prepare( + `SELECT name FROM sqlite_master WHERE type = 'index' AND tbl_name = 'messages' AND name = 'idx_messages_undelivered_inbox'` + ) + .all() + + expect(indexes).toHaveLength(1) + }) + + it('filters getUndeliveredUnreadMessages by type', () => { + const d = createDb() + d.insertMessage({ + runId, + from: 'a', + to: 'b', + subject: 's', + type: 'status' + }) + const wd = d.insertMessage({ + runId, + from: 'a', + to: 'b', + subject: 'd', + type: 'worker_done' + }) + + const filtered = d.getUndeliveredUnreadMessages('b', ['worker_done']) + expect(filtered).toHaveLength(1) + expect(filtered[0].id).toBe(wd.id) + }) + + it('marks messages as read', () => { + const d = createDb() + const m1 = d.insertMessage({ runId, from: 'a', to: 'b', subject: 'one' }) + const m2 = d.insertMessage({ runId, from: 'a', to: 'b', subject: 'two' }) + + d.markAsRead([m1.id]) + + const unread = d.getUnreadMessages('b') + expect(unread).toHaveLength(1) + expect(unread[0].id).toBe(m2.id) + }) + + it('stores typed payload and thread_id', () => { + const d = createDb() + const payload = JSON.stringify({ taskId: 'task_abc', filesModified: ['src/a.ts'] }) + const msg = d.insertMessage({ + runId, + from: 'a', + to: 'b', + subject: 'done', + type: 'worker_done', + priority: 'high', + threadId: 'thread_1', + payload + }) + + expect(msg.type).toBe('worker_done') + expect(msg.priority).toBe('high') + expect(msg.thread_id).toBe('thread_1') + expect(msg.payload).toBe(payload) + }) + + it('rejects invalid message type', () => { + const d = createDb() + expect(() => + d.insertMessage({ + runId, + from: 'a', + to: 'b', + subject: 'bad', + type: 'invalid' as MessageType + }) + ).toThrow() + }) + + it('getInbox returns all messages across recipients', () => { + const d = createDb() + d.insertMessage({ runId, from: 'a', to: 'b', subject: 'one' }) + d.insertMessage({ runId, from: 'a', to: 'c', subject: 'two' }) + d.insertMessage({ runId, from: 'b', to: 'a', subject: 'three' }) + + const inbox = d.getInbox(10) + expect(inbox).toHaveLength(3) + }) + + it('getMessageById returns the correct message', () => { + const d = createDb() + const msg = d.insertMessage({ + runId, + from: 'a', + to: 'b', + subject: 'test' + }) + const found = d.getMessageById(msg.id) + expect(found?.subject).toBe('test') + expect(d.getMessageById('msg_nonexistent')).toBeUndefined() + }) + }) +}) diff --git a/src/main/runtime/orchestration/db-stopping-worker-task-guard.test.ts b/src/main/runtime/orchestration/db-stopping-worker-task-guard.test.ts new file mode 100644 index 00000000000..a747ae07a51 --- /dev/null +++ b/src/main/runtime/orchestration/db-stopping-worker-task-guard.test.ts @@ -0,0 +1,122 @@ +import { afterEach, beforeEach, describe, expect, it } from 'vitest' +import { OrchestrationDb } from './db' +import { createRootDispatch } from './db/root-dispatch-test-fixture' + +const PANE_W = 'tab_w:aaaaaaaa-aaaa-4aaa-8aaa-aaaaaaaaaaaa' + +describe('a Task whose supervised worker is stopping', () => { + let db: OrchestrationDb + beforeEach(() => { + db = new OrchestrationDb(':memory:') + }) + afterEach(() => db.close()) + + function localWorker() { + const task = db.createTask({ runId: 'run_legacy_local', spec: 'local work' }) + const { dispatch } = db.createStartingWorkerDispatch({ + taskId: task.id, + startOptions: {}, + creator: { kind: 'system' }, + maxDepth: 9 + }) + db.prepareStartingWorkerAuthority({ + dispatchId: dispatch.id, + handle: 'term_w', + paneKey: PANE_W, + processIncarnation: 'inc1', + worktreeId: 'wt', + effects: [], + setupState: 'not_configured' + }) + db.markWorkerDispatchReady(dispatch.id) + return { task, dispatch } + } + + describe('task-update', () => { + it('refuses to re-open the Task while the worker is stopping', () => { + const { task, dispatch } = localWorker() + db.beginWorkerStop(dispatch.id, 'epoch_home') + expect(db.getTask(task.id)?.status).toBe('blocked') + + expect(() => db.updateTaskStatus(task.id, 'dispatched')).toThrowError( + expect.objectContaining({ + code: 'task_not_startable', + data: { taskId: task.id, dispatchId: dispatch.id } + }) + ) + expect(db.getTask(task.id)?.status).toBe('blocked') + }) + + it('refuses to re-open the Task while the stop outcome is unknown', () => { + const { task, dispatch } = localWorker() + db.beginWorkerStop(dispatch.id, 'epoch_home') + db.markWorkerStopUnknown(dispatch.id, 'the execution host did not answer') + + expect(() => db.updateTaskStatus(task.id, 'dispatched')).toThrowError( + expect.objectContaining({ code: 'task_not_startable' }) + ) + expect(db.getTask(task.id)?.status).toBe('blocked') + }) + + it('control: still accepts dispatched for an active Dispatch with no supervised worker', () => { + const task = db.createTask({ runId: 'run_legacy_local', spec: 'unsupervised work' }) + createRootDispatch(db, task.id, 'term_worker') + + expect(db.updateTaskStatus(task.id, 'dispatched')?.status).toBe('dispatched') + }) + + it('control: still accepts dispatched while the supervised worker is ready', () => { + const { task } = localWorker() + + expect(db.updateTaskStatus(task.id, 'dispatched')?.status).toBe('dispatched') + }) + + it('control: a no-op re-assert of dispatched under a stopping worker stays legal', () => { + const { task, dispatch } = localWorker() + expect(db.getTask(task.id)?.status).toBe('dispatched') + db.beginWorkerStop(dispatch.id, 'epoch_home') + // beginWorkerStop moved the Task to blocked; put it back the only way that is not a re-open. + db.db.prepare("UPDATE tasks SET status = 'dispatched' WHERE id = ?").run(task.id) + + expect(db.updateTaskStatus(task.id, 'dispatched')?.status).toBe('dispatched') + }) + }) + + describe('operator escape', () => { + it('accepts a re-issued worker-stop and reaches an honest stop_unknown outcome', () => { + const { task, dispatch } = localWorker() + db.beginWorkerStop(dispatch.id, 'epoch_dead_runtime') + + // The runtime that owned the first stop died mid-flight; the re-issue is the way out. + const reissued = db.beginWorkerStop(dispatch.id, 'epoch_new_runtime') + expect(reissued).toMatchObject({ disposition: 'stopping' }) + expect(db.getWorkerDispatch(dispatch.id)?.runtime_epoch).toBe('epoch_new_runtime') + + db.markWorkerStopUnknown(dispatch.id, 'the execution host did not answer') + expect(db.abandonWorkerDispatch(dispatch.id)).toMatchObject({ disposition: 'abandoned' }) + expect(db.getTask(task.id)?.status).toBe('blocked') + }) + + it('refuses a re-issue from the runtime whose own stop is still in flight', () => { + const { dispatch } = localWorker() + db.beginWorkerStop(dispatch.id, 'epoch_this_runtime') + + // The terminal is closing and its exit event has not landed yet. Letting this second pass + // record stop_unknown would make the exit read as a crash instead of this stop succeeding. + expect(() => db.beginWorkerStop(dispatch.id, 'epoch_this_runtime')).toThrowError( + /cannot stop from stopping/ + ) + + // The row is still the one the exit path claims a clean stop from: stopping, same epoch. + expect(db.getWorkerDispatch(dispatch.id)).toMatchObject({ + state: 'stopping', + runtime_epoch: 'epoch_this_runtime' + }) + expect(db.settleWorkerStop(dispatch.id).state).toBe('stopped') + expect(db.getDispatchContextById(dispatch.id)).toMatchObject({ + status: 'failed', + last_failure: 'stopped' + }) + }) + }) +}) diff --git a/src/main/runtime/orchestration/db-task-create-readiness.test.ts b/src/main/runtime/orchestration/db-task-create-readiness.test.ts index 019b627da6c..4b661829d02 100644 --- a/src/main/runtime/orchestration/db-task-create-readiness.test.ts +++ b/src/main/runtime/orchestration/db-task-create-readiness.test.ts @@ -33,12 +33,16 @@ describe('task creation dependency readiness', () => { it('creates a late dependent as ready when every dependency is completed', () => { const db = createDb() - const first = db.createTask({ spec: 'first' }) - const second = db.createTask({ spec: 'second' }) + const first = db.createTask({ runId: 'run_legacy_local', spec: 'first' }) + const second = db.createTask({ runId: 'run_legacy_local', spec: 'second' }) db.updateTaskStatus(first.id, 'completed') db.updateTaskStatus(second.id, 'completed') - const child = db.createTask({ spec: 'child', deps: [first.id, second.id] }) + const child = db.createTask({ + runId: 'run_legacy_local', + spec: 'child', + deps: [first.id, second.id] + }) expect(child.status).toBe('ready') }) @@ -49,7 +53,7 @@ describe('task creation dependency readiness', () => { const path = join(directory, 'orchestration.db') const db = createDb(path) const concurrent = createDb(path) - const dependency = db.createTask({ spec: 'dependency' }) + const dependency = db.createTask({ runId: 'run_legacy_local', spec: 'dependency' }) const sqlite = (db as unknown as OrchestrationDbAccess).db const prepare = sqlite.prepare.bind(sqlite) let injected = false @@ -61,7 +65,7 @@ describe('task creation dependency readiness', () => { return prepare(sql) }) - const child = db.createTask({ spec: 'child', deps: [dependency.id] }) + const child = db.createTask({ runId: 'run_legacy_local', spec: 'child', deps: [dependency.id] }) expect(injected).toBe(true) expect(child.status).toBe('ready') @@ -69,10 +73,14 @@ describe('task creation dependency readiness', () => { it('promotes only after every dependency completes', () => { const db = createDb() - const first = db.createTask({ spec: 'first' }) - const second = db.createTask({ spec: 'second' }) + const first = db.createTask({ runId: 'run_legacy_local', spec: 'first' }) + const second = db.createTask({ runId: 'run_legacy_local', spec: 'second' }) db.updateTaskStatus(first.id, 'completed') - const child = db.createTask({ spec: 'child', deps: [first.id, second.id] }) + const child = db.createTask({ + runId: 'run_legacy_local', + spec: 'child', + deps: [first.id, second.id] + }) expect(child.status).toBe('pending') db.updateTaskStatus(second.id, 'completed') @@ -83,11 +91,15 @@ describe('task creation dependency readiness', () => { 'does not unlock a dependent whose dependency is %s', (status) => { const db = createDb() - const terminal = db.createTask({ spec: 'terminal dependency' }) - const completing = db.createTask({ spec: 'completing dependency' }) + const terminal = db.createTask({ runId: 'run_legacy_local', spec: 'terminal dependency' }) + const completing = db.createTask({ runId: 'run_legacy_local', spec: 'completing dependency' }) db.updateTaskStatus(terminal.id, status) - const child = db.createTask({ spec: 'child', deps: [terminal.id, completing.id] }) + const child = db.createTask({ + runId: 'run_legacy_local', + spec: 'child', + deps: [terminal.id, completing.id] + }) expect(child.status).toBe('pending') db.updateTaskStatus(completing.id, 'completed') @@ -98,9 +110,9 @@ describe('task creation dependency readiness', () => { it('rejects missing dependencies without inserting a task', () => { const db = createDb() - expect(() => db.createTask({ spec: 'child', deps: ['task_missing'] })).toThrow( - 'Dependency task task_missing must belong to run' - ) + expect(() => + db.createTask({ runId: 'run_legacy_local', spec: 'child', deps: ['task_missing'] }) + ).toThrow('Dependency task task_missing must belong to run') expect(db.listTasks()).toEqual([]) }) @@ -109,7 +121,7 @@ describe('task creation dependency readiness', () => { const sqlite = (db as unknown as OrchestrationDbAccess).db sqlite.exec('BEGIN IMMEDIATE') - const task = db.createTask({ spec: 'transactional child' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'transactional child' }) sqlite.exec('ROLLBACK') expect(db.getTask(task.id)).toBeUndefined() @@ -120,11 +132,19 @@ describe('task creation dependency readiness', () => { directories.push(directory) const path = join(directory, 'orchestration.db') const before = createDb(path) - const completed = before.createTask({ spec: 'completed' }) - const open = before.createTask({ spec: 'open' }) + const completed = before.createTask({ runId: 'run_legacy_local', spec: 'completed' }) + const open = before.createTask({ runId: 'run_legacy_local', spec: 'open' }) before.updateTaskStatus(completed.id, 'completed') - const ready = before.createTask({ spec: 'ready', deps: [completed.id] }) - const pending = before.createTask({ spec: 'pending', deps: [completed.id, open.id] }) + const ready = before.createTask({ + runId: 'run_legacy_local', + spec: 'ready', + deps: [completed.id] + }) + const pending = before.createTask({ + runId: 'run_legacy_local', + spec: 'pending', + deps: [completed.id, open.id] + }) before.close() databases.splice(databases.indexOf(before), 1) diff --git a/src/main/runtime/orchestration/db-task-dispatch-invariant.test.ts b/src/main/runtime/orchestration/db-task-dispatch-invariant.test.ts index 53340b6dce5..2b81b2f2897 100644 --- a/src/main/runtime/orchestration/db-task-dispatch-invariant.test.ts +++ b/src/main/runtime/orchestration/db-task-dispatch-invariant.test.ts @@ -30,9 +30,17 @@ describe('Task/Dispatch invariant transactions', () => { 'allows a dependency-blocked pending Task to become %s', (status) => { const { db } = createDatabase() - const dependency = db.createTask({ spec: 'unresolved dependency' }) - const task = db.createTask({ spec: 'manual resolution', deps: [dependency.id] }) - const dependent = db.createTask({ spec: 'downstream work', deps: [task.id] }) + const dependency = db.createTask({ runId: 'run_legacy_local', spec: 'unresolved dependency' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'manual resolution', + deps: [dependency.id] + }) + const dependent = db.createTask({ + runId: 'run_legacy_local', + spec: 'downstream work', + deps: [task.id] + }) expect(task.status).toBe('pending') const updated = db.updateTaskStatus(task.id, status, 'manual resolution') @@ -45,7 +53,7 @@ describe('Task/Dispatch invariant transactions', () => { it('surfaces invalid Task lifecycle edges instead of returning the unchanged row', () => { const { db } = createDatabase() - const task = db.createTask({ spec: 'invalid lifecycle edge' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'invalid lifecycle edge' }) db.updateTaskStatus(task.id, 'blocked') expect(() => @@ -67,8 +75,12 @@ describe('Task/Dispatch invariant transactions', () => { 'rolls back a %s Task when Dispatch settlement fails', (status) => { const { db } = createDatabase() - const task = db.createTask({ spec: 'atomic work' }) - const dependent = db.createTask({ spec: 'dependent work', deps: [task.id] }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'atomic work' }) + const dependent = db.createTask({ + runId: 'run_legacy_local', + spec: 'dependent work', + deps: [task.id] + }) const dispatch = createRootDispatch(db, task.id, 'term_worker') const capability = db.mintDispatchCapability({ dispatchId: dispatch.id, @@ -111,7 +123,10 @@ describe('Task/Dispatch invariant transactions', () => { it('does not commit a caller-owned transaction', () => { const { db } = createDatabase() - const task = db.createTask({ spec: 'outer transaction work' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'outer transaction work' + }) const dispatch = createRootDispatch(db, task.id, 'term_worker') const sqlite = sqliteFor(db) @@ -135,7 +150,10 @@ describe('Task/Dispatch invariant transactions', () => { it('keeps Dispatch creation inside a caller-owned transaction', () => { const { db } = createDatabase() - const task = db.createTask({ spec: 'outer transaction dispatch' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'outer transaction dispatch' + }) const sqlite = sqliteFor(db) sqlite.exec('BEGIN IMMEDIATE') @@ -152,7 +170,10 @@ describe('Task/Dispatch invariant transactions', () => { 'settles every active Dispatch left by a pre-fix split when the Task becomes %s', (status) => { const { db } = createDatabase() - const task = db.createTask({ spec: 'legacy split work' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'legacy split work' + }) const first = createRootDispatch(db, task.id, 'term_first') sqliteFor(db).prepare("UPDATE tasks SET status = 'ready' WHERE id = ?").run(task.id) const second = createRootDispatch(db, task.id, 'term_second') @@ -169,17 +190,31 @@ describe('Task/Dispatch invariant transactions', () => { expect(db.getActiveDispatchForTerminal('term_first')).toBeUndefined() expect(db.getActiveDispatchForTerminal('term_second')).toBeUndefined() expect(() => - createRootDispatch(db, db.createTask({ spec: 'first later work' }).id, 'term_first') + createRootDispatch( + db, + db.createTask({ runId: 'run_legacy_local', spec: 'first later work' }).id, + 'term_first' + ) ).not.toThrow() expect(() => - createRootDispatch(db, db.createTask({ spec: 'second later work' }).id, 'term_second') + createRootDispatch( + db, + db.createTask({ + runId: 'run_legacy_local', + spec: 'second later work' + }).id, + 'term_second' + ) ).not.toThrow() } ) it('does not requeue a legacy split Task while another Dispatch remains active', () => { const { db } = createDatabase() - const task = db.createTask({ spec: 'legacy split retry' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'legacy split retry' + }) const first = createRootDispatch(db, task.id, 'term_first') sqliteFor(db).prepare("UPDATE tasks SET status = 'ready' WHERE id = ?").run(task.id) const second = createRootDispatch(db, task.id, 'term_second') @@ -193,7 +228,10 @@ describe('Task/Dispatch invariant transactions', () => { it('does not block a legacy split Task while another Dispatch remains active', () => { const { db } = createDatabase() - const task = db.createTask({ spec: 'legacy split release' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'legacy split release' + }) const first = createRootDispatch(db, task.id, 'term_first') sqliteFor(db).prepare("UPDATE tasks SET status = 'ready' WHERE id = ?").run(task.id) const second = createRootDispatch(db, task.id, 'term_second') @@ -211,7 +249,10 @@ describe('Task/Dispatch invariant transactions', () => { 'rejects moving a Task to %s while a Dispatch remains active', (status) => { const { db } = createDatabase() - const task = db.createTask({ spec: 'guarded work' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'guarded work' + }) const dispatch = createRootDispatch(db, task.id, 'term_worker') expect(() => db.updateTaskStatus(task.id, status, 'must not persist')).toThrowError( @@ -227,7 +268,10 @@ describe('Task/Dispatch invariant transactions', () => { it('rejects moving a Task to dispatched without an active Dispatch', () => { const { db } = createDatabase() - const task = db.createTask({ spec: 'unassigned work' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'unassigned work' + }) expect(() => db.updateTaskStatus(task.id, 'dispatched')).toThrowError( expect.objectContaining({ @@ -241,7 +285,10 @@ describe('Task/Dispatch invariant transactions', () => { it('rejects a Dispatch when failure wins after readiness was observed', () => { const first = createDatabase() const concurrent = createDatabase(first.path) - const task = first.db.createTask({ spec: 'interleaved work' }) + const task = first.db.createTask({ + runId: 'run_legacy_local', + spec: 'interleaved work' + }) const sqlite = sqliteFor(first.db) const prepare = sqlite.prepare.bind(sqlite) let injected = false @@ -264,8 +311,14 @@ describe('Task/Dispatch invariant transactions', () => { it('atomically rejects a same-pane Dispatch that loses the occupancy race', () => { const first = createDatabase() const concurrent = createDatabase(first.path) - const firstTask = first.db.createTask({ spec: 'first terminal claimant' }) - const secondTask = first.db.createTask({ spec: 'second terminal claimant' }) + const firstTask = first.db.createTask({ + runId: 'run_legacy_local', + spec: 'first terminal claimant' + }) + const secondTask = first.db.createTask({ + runId: 'run_legacy_local', + spec: 'second terminal claimant' + }) const sqlite = sqliteFor(first.db) const prepare = sqlite.prepare.bind(sqlite) let winnerId: string | undefined @@ -303,14 +356,20 @@ describe('Task/Dispatch invariant transactions', () => { it('rejects worker authority when another Dispatch owns the pane', () => { const { db } = createDatabase() - const ownerTask = db.createTask({ spec: 'current pane owner' }) + const ownerTask = db.createTask({ + runId: 'run_legacy_local', + spec: 'current pane owner' + }) const owner = createRootDispatch( db, ownerTask.id, 'term_owner', 'tab_old:cccccccc-cccc-4ccc-8ccc-cccccccccccc' ) - const workerTask = db.createTask({ spec: 'competing supervised worker' }) + const workerTask = db.createTask({ + runId: 'run_legacy_local', + spec: 'competing supervised worker' + }) const started = db.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -346,7 +405,10 @@ describe('Task/Dispatch invariant transactions', () => { 'rejects a %s Task update while its supervised worker remains active', (status) => { const { db } = createDatabase() - const task = db.createTask({ spec: 'supervised lifecycle' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'supervised lifecycle' + }) const started = db.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -394,7 +456,10 @@ describe('Task/Dispatch invariant transactions', () => { it('keeps a federated late start authoritative after rejecting Task failure', () => { const { db } = createDatabase() - const task = db.createTask({ spec: 'federated lifecycle' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'federated lifecycle' + }) const started = db.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, diff --git a/src/main/runtime/orchestration/db-task-dispatch-lifecycle-guards.test.ts b/src/main/runtime/orchestration/db-task-dispatch-lifecycle-guards.test.ts index bb6d3472d4e..f4cdcdf63b8 100644 --- a/src/main/runtime/orchestration/db-task-dispatch-lifecycle-guards.test.ts +++ b/src/main/runtime/orchestration/db-task-dispatch-lifecycle-guards.test.ts @@ -29,7 +29,7 @@ afterEach(() => { describe('Task/Dispatch lifecycle guards', () => { it('rejects a worker report while another supervised Dispatch is active', () => { const database = createDatabase() - const task = database.createTask({ spec: 'legacy supervised split' }) + const task = database.createTask({ runId: 'run_legacy_local', spec: 'legacy supervised split' }) const first = startWorker(database, task.id, 'first') sqliteFor(database).prepare("UPDATE tasks SET status = 'ready' WHERE id = ?").run(task.id) const second = startWorker(database, task.id, 'second') @@ -55,7 +55,7 @@ describe('Task/Dispatch lifecycle guards', () => { 'settles context-only legacy siblings after a %s worker report', (outcome) => { const database = createDatabase() - const task = database.createTask({ spec: 'legacy mixed split' }) + const task = database.createTask({ runId: 'run_legacy_local', spec: 'legacy mixed split' }) const contextOnly = createRootDispatch(database, task.id, 'term_context') sqliteFor(database).prepare("UPDATE tasks SET status = 'ready' WHERE id = ?").run(task.id) const worker = startWorker(database, task.id, 'reporter') @@ -78,7 +78,10 @@ describe('Task/Dispatch lifecycle guards', () => { expect(() => createRootDispatch( database, - database.createTask({ spec: 'later context work' }).id, + database.createTask({ + runId: 'run_legacy_local', + spec: 'later context work' + }).id, 'term_context' ) ).not.toThrow() @@ -87,7 +90,10 @@ describe('Task/Dispatch lifecycle guards', () => { it('settles a newer context-only legacy sibling after a worker report', () => { const database = createDatabase() - const task = database.createTask({ spec: 'reversed legacy mixed split' }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: 'reversed legacy mixed split' + }) const worker = startWorker(database, task.id, 'reversed_reporter') sqliteFor(database).prepare("UPDATE tasks SET status = 'ready' WHERE id = ?").run(task.id) const contextOnly = createRootDispatch(database, task.id, 'term_reversed_context') @@ -112,7 +118,10 @@ describe('Task/Dispatch lifecycle guards', () => { 'treats abandon of an already %s worker as stale without a lifecycle conflict', (state) => { const database = createDatabase() - const task = database.createTask({ spec: `already ${state}` }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: `already ${state}` + }) const worker = startWorker(database, task.id, `already_${state}`) if (state === 'failed') { database.failDispatch(worker.dispatchId, 'process exited', { workerProcessExited: true }) @@ -130,7 +139,10 @@ describe('Task/Dispatch lifecycle guards', () => { it('rejects generic failure while a supervised worker remains active', () => { const database = createDatabase() - const task = database.createTask({ spec: 'supervised failure guard' }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: 'supervised failure guard' + }) const worker = startWorker(database, task.id, 'guarded') expect(() => database.failDispatch(worker.dispatchId, 'unsafe retry')).toThrowError( @@ -151,7 +163,10 @@ describe('Task/Dispatch lifecycle guards', () => { it('atomically settles worker state when a proven process exit fails its Dispatch', () => { const database = createDatabase() - const task = database.createTask({ spec: 'exited worker' }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: 'exited worker' + }) const worker = startWorker(database, task.id, 'exited') expect( @@ -168,7 +183,10 @@ describe('Task/Dispatch lifecycle guards', () => { it('settles a stop-unknown worker when a positive PTY exit arrives', () => { const database = createDatabase() - const task = database.createTask({ spec: 'stop-unknown exited worker' }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: 'stop-unknown exited worker' + }) const worker = startWorker(database, task.id, 'stop_unknown_exited') expect(database.beginWorkerStop(worker.dispatchId, 'runtime_test').disposition).toBe('stopping') @@ -198,7 +216,10 @@ describe('Task/Dispatch lifecycle guards', () => { it('keeps a Task dispatched when missing-terminal recovery leaves another worker active', () => { const database = createDatabase() - const task = database.createTask({ spec: 'legacy missing-terminal split' }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: 'legacy missing-terminal split' + }) const missing = startWorker(database, task.id, 'missing') sqliteFor(database).prepare("UPDATE tasks SET status = 'ready' WHERE id = ?").run(task.id) const live = startWorker(database, task.id, 'live') @@ -225,7 +246,10 @@ describe('Task/Dispatch lifecycle guards', () => { 'keeps a Task dispatched when a %s worker start fails beside a live worker', (kind) => { const database = createDatabase() - const task = database.createTask({ spec: `${kind} split start failure` }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: `${kind} split start failure` + }) const failed = database.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -342,7 +366,10 @@ describe('Task/Dispatch lifecycle guards', () => { it('rolls back federated start uncertainty when the Task transition cannot commit', () => { const database = createDatabase() - const task = database.createTask({ spec: 'atomic federated uncertainty' }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: 'atomic federated uncertainty' + }) const started = database.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -383,7 +410,10 @@ describe('Task/Dispatch lifecycle guards', () => { '%s releases the last context-only sibling after a newer worker start fails', (operation) => { const database = createDatabase() - const task = database.createTask({ spec: `${operation} historical sibling` }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: `${operation} historical sibling` + }) const contextOnly = createRootDispatch(database, task.id, `term_${operation}`) sqliteFor(database).prepare("UPDATE tasks SET status = 'ready' WHERE id = ?").run(task.id) const failed = database.createStartingWorkerDispatch({ @@ -411,7 +441,10 @@ describe('Task/Dispatch lifecycle guards', () => { expect(() => createRootDispatch( database, - database.createTask({ spec: `${operation} later work` }).id, + database.createTask({ + runId: 'run_legacy_local', + spec: `${operation} later work` + }).id, `term_${operation}` ) ).not.toThrow() @@ -422,7 +455,10 @@ describe('Task/Dispatch lifecycle guards', () => { '%s records guarded receipts for context-only Dispatch and Task release', (operation) => { const database = createDatabase() - const task = database.createTask({ spec: `${operation} receipt release` }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: `${operation} receipt release` + }) const contextOnly = createRootDispatch(database, task.id, `term_${operation}`) const released = @@ -445,7 +481,10 @@ describe('Task/Dispatch lifecycle guards', () => { it('rolls back both context-only projections when the Task transition fails', () => { const database = createDatabase() - const task = database.createTask({ spec: 'context-only atomic receipt' }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: 'context-only atomic receipt' + }) const contextOnly = createRootDispatch(database, task.id, 'term_context') sqliteFor(database).exec(` CREATE TRIGGER reject_context_release_task_block @@ -470,7 +509,10 @@ describe('Task/Dispatch lifecycle guards', () => { '%s preserves a live worker sibling and lets it report', (operation) => { const database = createDatabase() - const task = database.createTask({ spec: `${operation} legacy worker split` }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: `${operation} legacy worker split` + }) const live = startWorker(database, task.id, `${operation}_live`) sqliteFor(database).prepare("UPDATE tasks SET status = 'ready' WHERE id = ?").run(task.id) const released = startWorker(database, task.id, `${operation}_released`) @@ -502,7 +544,10 @@ describe('Task/Dispatch lifecycle guards', () => { it('blocks a Task when an interleaved stop settles its final active Dispatch', () => { const database = createDatabase() - const task = database.createTask({ spec: 'interleaved legacy worker release' }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: 'interleaved legacy worker release' + }) const stopping = startWorker(database, task.id, 'interleaved_stopping') sqliteFor(database).prepare("UPDATE tasks SET status = 'ready' WHERE id = ?").run(task.id) const abandoned = startWorker(database, task.id, 'interleaved_abandoned') @@ -521,7 +566,10 @@ describe('Task/Dispatch lifecycle guards', () => { it('restores a live sibling after stopping an uncertain worker start', () => { const database = createDatabase() - const task = database.createTask({ spec: 'uncertain legacy worker split' }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: 'uncertain legacy worker split' + }) const live = startWorker(database, task.id, 'uncertain_live') sqliteFor(database).prepare("UPDATE tasks SET status = 'ready' WHERE id = ?").run(task.id) const uncertain = database.createStartingWorkerDispatch({ @@ -552,7 +600,10 @@ describe('Task/Dispatch lifecycle guards', () => { 'restores a live sibling after an uncertain worker start fails through %s', (recovery) => { const database = createDatabase() - const task = database.createTask({ spec: `${recovery} uncertain sibling` }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: `${recovery} uncertain sibling` + }) const live = startWorker(database, task.id, `${recovery}_live`) sqliteFor(database).prepare("UPDATE tasks SET status = 'ready' WHERE id = ?").run(task.id) const uncertain = database.createStartingWorkerDispatch({ @@ -589,7 +640,10 @@ describe('Task/Dispatch lifecycle guards', () => { it('rejects gate creation while a supervised worker remains active', () => { const database = createDatabase() - const task = database.createTask({ spec: 'worker gate guard' }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: 'worker gate guard' + }) const worker = startWorker(database, task.id, 'gate') expect(() => database.createGate({ taskId: task.id, question: 'Proceed?' })).toThrowError( @@ -607,7 +661,10 @@ describe('Task/Dispatch lifecycle guards', () => { it('rolls back gate resolution when an active Dispatch blocks readiness', () => { const database = createDatabase() - const task = database.createTask({ spec: 'corrupt gated task' }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: 'corrupt gated task' + }) const gate = database.createGate({ taskId: task.id, question: 'Proceed?' }) sqliteFor(database).prepare("UPDATE tasks SET status = 'ready' WHERE id = ?").run(task.id) const dispatch = createRootDispatch(database, task.id, 'term_worker') diff --git a/src/main/runtime/orchestration/db-task-dispatch-races.test.ts b/src/main/runtime/orchestration/db-task-dispatch-races.test.ts index b4c27ac0c64..c671aa4566b 100644 --- a/src/main/runtime/orchestration/db-task-dispatch-races.test.ts +++ b/src/main/runtime/orchestration/db-task-dispatch-races.test.ts @@ -29,7 +29,10 @@ describe('Task/Dispatch concurrency', () => { it('reads a concurrent Task result before applying an explicit status correction', () => { const first = createDatabase() const concurrent = createDatabase(first.path) - const task = first.db.createTask({ spec: 'concurrent status winner' }) + const task = first.db.createTask({ + runId: 'run_legacy_local', + spec: 'concurrent status winner' + }) const sqlite = sqliteFor(first.db) const exec = sqlite.exec.bind(sqlite) let concurrentWon = false @@ -57,7 +60,7 @@ describe('Task/Dispatch concurrency', () => { it('holds the Task status writer reservation through its lifecycle reads', () => { const first = createDatabase() const concurrent = createDatabase(first.path) - const task = first.db.createTask({ spec: 'reserved status winner' }) + const task = first.db.createTask({ runId: 'run_legacy_local', spec: 'reserved status winner' }) const sqlite = sqliteFor(first.db) const exec = sqlite.exec.bind(sqlite) sqliteFor(concurrent.db).pragma('busy_timeout = 0') @@ -86,7 +89,7 @@ describe('Task/Dispatch concurrency', () => { it('rolls back Dispatch failure when Task requeue fails', () => { const { db } = createDatabase() - const task = db.createTask({ spec: 'atomic retry failure' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'atomic retry failure' }) const dispatch = createRootDispatch(db, task.id, 'term_worker') sqliteFor(db).exec(` CREATE TRIGGER reject_task_requeue @@ -113,7 +116,10 @@ describe('Task/Dispatch concurrency', () => { it('does not let stale failure overwrite a completed worker report', () => { const first = createDatabase() const concurrent = createDatabase(first.path) - const task = first.db.createTask({ spec: 'worker completion wins' }) + const task = first.db.createTask({ + runId: 'run_legacy_local', + spec: 'worker completion wins' + }) const started = first.db.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -177,7 +183,10 @@ describe('Task/Dispatch concurrency', () => { it('keeps nested dispatch failure atomic with its caller transaction', () => { const { db } = createDatabase() - const task = db.createTask({ spec: 'nested atomic failure' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'nested atomic failure' + }) const dispatch = createRootDispatch(db, task.id, 'term_worker') const sqlite = sqliteFor(db) @@ -198,8 +207,14 @@ describe('Task/Dispatch concurrency', () => { it('serializes reminted-pane worker authority claims', () => { const first = createDatabase() const concurrent = createDatabase(first.path) - const losingTask = first.db.createTask({ spec: 'losing worker' }) - const winningTask = first.db.createTask({ spec: 'winning worker' }) + const losingTask = first.db.createTask({ + runId: 'run_legacy_local', + spec: 'losing worker' + }) + const winningTask = first.db.createTask({ + runId: 'run_legacy_local', + spec: 'winning worker' + }) const loser = first.db.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, diff --git a/src/main/runtime/orchestration/db-undelivered-mailboxes.test.ts b/src/main/runtime/orchestration/db-undelivered-mailboxes.test.ts index 86bc9fdf46b..b20dd625310 100644 --- a/src/main/runtime/orchestration/db-undelivered-mailboxes.test.ts +++ b/src/main/runtime/orchestration/db-undelivered-mailboxes.test.ts @@ -8,10 +8,20 @@ describe('undelivered orchestration mailboxes', () => { it('lists only mailboxes with undelivered unread messages', () => { db = new OrchestrationDb(':memory:') - const delivered = db.insertMessage({ from: 'a', to: 'delivered', subject: 'done' }) - const read = db.insertMessage({ from: 'a', to: 'read', subject: 'seen' }) - db.insertMessage({ from: 'a', to: 'pending', subject: 'first' }) - db.insertMessage({ from: 'a', to: 'pending', subject: 'second' }) + const delivered = db.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'delivered', + subject: 'done' + }) + const read = db.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'read', + subject: 'seen' + }) + db.insertMessage({ runId: 'run_legacy_local', from: 'a', to: 'pending', subject: 'first' }) + db.insertMessage({ runId: 'run_legacy_local', from: 'a', to: 'pending', subject: 'second' }) db.markAsDelivered([delivered.id]) db.markAsRead([read.id]) @@ -20,7 +30,12 @@ describe('undelivered orchestration mailboxes', () => { it('persists and settles a pending pointer Enter independently of delivery', () => { db = new OrchestrationDb(':memory:') - const message = db.insertMessage({ from: 'a', to: 'run:run_1', subject: 'staged' }) + const message = db.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'run:run_1', + subject: 'staged' + }) expect( db.stageMailboxPointerEnter([message.id], { diff --git a/src/main/runtime/orchestration/db.test.ts b/src/main/runtime/orchestration/db.test.ts index 4825246586a..33af326f34d 100644 --- a/src/main/runtime/orchestration/db.test.ts +++ b/src/main/runtime/orchestration/db.test.ts @@ -4,9 +4,10 @@ import { join } from 'node:path' import { afterEach, describe, expect, it } from 'vitest' import Database from '../../sqlite/sync-database' import { LEGACY_RUN_ID, OrchestrationDb } from './db' -import type { MessageType } from './db' import { createRootDispatch } from './db/root-dispatch-test-fixture' +const runId = 'run_legacy_local' + // Overwrites the datetime('now')-seeded timestamps with explicit fixture values // so stale-detection assertions stay deterministic (no wall clock). function setDispatchTimes( @@ -33,154 +34,10 @@ describe('OrchestrationDb', () => { return db } - describe('messages', () => { - it('inserts and retrieves a message', () => { - const d = createDb() - const msg = d.insertMessage({ - from: 'term_a', - to: 'term_b', - subject: 'hello', - body: 'world' - }) - expect(msg.id).toMatch(/^msg_/) - expect(msg.from_handle).toBe('term_a') - expect(msg.to_handle).toBe('term_b') - expect(msg.subject).toBe('hello') - expect(msg.body).toBe('world') - expect(msg.type).toBe('status') - expect(msg.priority).toBe('normal') - expect(msg.read).toBe(0) - expect(msg.sequence).toBeGreaterThan(0) - }) - - it('returns unread messages in sequence order', () => { - const d = createDb() - d.insertMessage({ from: 'a', to: 'b', subject: 'first' }) - d.insertMessage({ from: 'a', to: 'b', subject: 'second' }) - d.insertMessage({ from: 'a', to: 'c', subject: 'other' }) - - const unread = d.getUnreadMessages('b') - expect(unread).toHaveLength(2) - expect(unread[0].subject).toBe('first') - expect(unread[1].subject).toBe('second') - }) - - it('filters unread by type', () => { - const d = createDb() - d.insertMessage({ from: 'a', to: 'b', subject: 'status msg', type: 'status' }) - d.insertMessage({ from: 'a', to: 'b', subject: 'done msg', type: 'worker_done' }) - - const filtered = d.getUnreadMessages('b', ['worker_done']) - expect(filtered).toHaveLength(1) - expect(filtered[0].type).toBe('worker_done') - }) - - it('excludes already-delivered rows from getUndeliveredUnreadMessages', () => { - const d = createDb() - const m1 = d.insertMessage({ from: 'a', to: 'b', subject: 'one' }) - const m2 = d.insertMessage({ from: 'a', to: 'b', subject: 'two' }) - - d.markAsDelivered([m1.id]) - - // Push delivery query: only undelivered, unread. - const pending = d.getUndeliveredUnreadMessages('b') - expect(pending).toHaveLength(1) - expect(pending[0].id).toBe(m2.id) - - // Explicit `check` still sees both (they are still unread). - const unread = d.getUnreadMessages('b') - expect(unread).toHaveLength(2) - }) - - it('creates the undelivered inbox index used by push delivery', () => { - const d = createDb() - const sqlite = (d as unknown as { db: Database.Database }).db - - const indexes = sqlite - .prepare( - `SELECT name FROM sqlite_master WHERE type = 'index' AND tbl_name = 'messages' AND name = 'idx_messages_undelivered_inbox'` - ) - .all() - - expect(indexes).toHaveLength(1) - }) - - it('filters getUndeliveredUnreadMessages by type', () => { - const d = createDb() - d.insertMessage({ from: 'a', to: 'b', subject: 's', type: 'status' }) - const wd = d.insertMessage({ from: 'a', to: 'b', subject: 'd', type: 'worker_done' }) - - const filtered = d.getUndeliveredUnreadMessages('b', ['worker_done']) - expect(filtered).toHaveLength(1) - expect(filtered[0].id).toBe(wd.id) - }) - - it('marks messages as read', () => { - const d = createDb() - const m1 = d.insertMessage({ from: 'a', to: 'b', subject: 'one' }) - const m2 = d.insertMessage({ from: 'a', to: 'b', subject: 'two' }) - - d.markAsRead([m1.id]) - - const unread = d.getUnreadMessages('b') - expect(unread).toHaveLength(1) - expect(unread[0].id).toBe(m2.id) - }) - - it('stores typed payload and thread_id', () => { - const d = createDb() - const payload = JSON.stringify({ taskId: 'task_abc', filesModified: ['src/a.ts'] }) - const msg = d.insertMessage({ - from: 'a', - to: 'b', - subject: 'done', - type: 'worker_done', - priority: 'high', - threadId: 'thread_1', - payload - }) - - expect(msg.type).toBe('worker_done') - expect(msg.priority).toBe('high') - expect(msg.thread_id).toBe('thread_1') - expect(msg.payload).toBe(payload) - }) - - it('rejects invalid message type', () => { - const d = createDb() - expect(() => - d.insertMessage({ - from: 'a', - to: 'b', - subject: 'bad', - type: 'invalid' as MessageType - }) - ).toThrow() - }) - - it('getInbox returns all messages across recipients', () => { - const d = createDb() - d.insertMessage({ from: 'a', to: 'b', subject: 'one' }) - d.insertMessage({ from: 'a', to: 'c', subject: 'two' }) - d.insertMessage({ from: 'b', to: 'a', subject: 'three' }) - - const inbox = d.getInbox(10) - expect(inbox).toHaveLength(3) - }) - - it('getMessageById returns the correct message', () => { - const d = createDb() - const msg = d.insertMessage({ from: 'a', to: 'b', subject: 'test' }) - const found = d.getMessageById(msg.id) - expect(found?.subject).toBe('test') - expect(d.getMessageById('msg_nonexistent')).toBeUndefined() - }) - }) - describe('tasks', () => { it('creates a task with no deps as ready', () => { const d = createDb() - const task = d.createTask({ spec: 'do something' }) + const task = d.createTask({ runId, spec: 'do something' }) expect(task.id).toMatch(/^task_/) expect(task.status).toBe('ready') expect(task.deps).toBe('[]') @@ -191,6 +48,7 @@ describe('OrchestrationDb', () => { it('persists explicit task display metadata', () => { const d = createDb() const task = d.createTask({ + runId, spec: 'full details', taskTitle: 'Checkout race', displayName: 'Fix checkout race' @@ -204,6 +62,7 @@ describe('OrchestrationDb', () => { it('persists the creating terminal handle for task-created worktrees', () => { const d = createDb() const task = d.createTask({ + runId, spec: 'spawn related workspace', createdByTerminalHandle: 'term_creator' }) @@ -214,16 +73,16 @@ describe('OrchestrationDb', () => { it('creates a task with deps as pending', () => { const d = createDb() - const parent = d.createTask({ spec: 'parent' }) - const child = d.createTask({ spec: 'child', deps: [parent.id] }) + const parent = d.createTask({ runId, spec: 'parent' }) + const child = d.createTask({ runId, spec: 'child', deps: [parent.id] }) expect(child.status).toBe('pending') expect(JSON.parse(child.deps)).toEqual([parent.id]) }) it('promotes pending tasks when deps complete', () => { const d = createDb() - const t1 = d.createTask({ spec: 'first' }) - const t2 = d.createTask({ spec: 'second', deps: [t1.id] }) + const t1 = d.createTask({ runId, spec: 'first' }) + const t2 = d.createTask({ runId, spec: 'second', deps: [t1.id] }) expect(d.getTask(t2.id)?.status).toBe('pending') @@ -234,9 +93,9 @@ describe('OrchestrationDb', () => { it('does not promote task until ALL deps complete', () => { const d = createDb() - const t1 = d.createTask({ spec: 'a' }) - const t2 = d.createTask({ spec: 'b' }) - const t3 = d.createTask({ spec: 'c', deps: [t1.id, t2.id] }) + const t1 = d.createTask({ runId, spec: 'a' }) + const t2 = d.createTask({ runId, spec: 'b' }) + const t3 = d.createTask({ runId, spec: 'c', deps: [t1.id, t2.id] }) d.updateTaskStatus(t1.id, 'completed') expect(d.getTask(t3.id)?.status).toBe('pending') @@ -247,7 +106,7 @@ describe('OrchestrationDb', () => { it('sets completed_at on completion', () => { const d = createDb() - const task = d.createTask({ spec: 'do it' }) + const task = d.createTask({ runId, spec: 'do it' }) const updated = d.updateTaskStatus(task.id, 'completed', '{"result": true}') expect(updated?.completed_at).toBeTruthy() expect(updated?.result).toBe('{"result": true}') @@ -255,7 +114,7 @@ describe('OrchestrationDb', () => { it('completing a task frees its active dispatch context', () => { const d = createDb() - const task = d.createTask({ spec: 'do it' }) + const task = d.createTask({ runId, spec: 'do it' }) createRootDispatch(d, task.id, 'term_a') d.updateTaskStatus(task.id, 'completed') @@ -266,8 +125,8 @@ describe('OrchestrationDb', () => { it('listTasks filters by status', () => { const d = createDb() - d.createTask({ spec: 'ready task' }) - const t2 = d.createTask({ spec: 'another' }) + d.createTask({ runId, spec: 'ready task' }) + const t2 = d.createTask({ runId, spec: 'another' }) d.updateTaskStatus(t2.id, 'completed') expect(d.listTasks({ status: 'ready' })).toHaveLength(1) @@ -277,15 +136,15 @@ describe('OrchestrationDb', () => { it('listTasks returns all when no filter', () => { const d = createDb() - d.createTask({ spec: 'one' }) - d.createTask({ spec: 'two' }) + d.createTask({ runId, spec: 'one' }) + d.createTask({ runId, spec: 'two' }) expect(d.listTasks()).toHaveLength(2) }) it('listTasksWithDispatch joins active dispatch metadata', () => { const d = createDb() - const ready = d.createTask({ spec: 'ready task' }) - const dispatched = d.createTask({ spec: 'active task' }) + const ready = d.createTask({ runId, spec: 'ready task' }) + const dispatched = d.createTask({ runId, spec: 'active task' }) const ctx = createRootDispatch(d, dispatched.id, 'term_worker') const rows = d.listTasksWithDispatch() @@ -300,7 +159,7 @@ describe('OrchestrationDb', () => { it('listTasksWithDispatch does not surface completed dispatches', () => { const d = createDb() - const task = d.createTask({ spec: 'work' }) + const task = d.createTask({ runId, spec: 'work' }) createRootDispatch(d, task.id, 'term_worker') d.updateTaskStatus(task.id, 'completed') @@ -314,8 +173,8 @@ describe('OrchestrationDb', () => { it('supports parent_id for task decomposition', () => { const d = createDb() - const parent = d.createTask({ spec: 'parent' }) - const child = d.createTask({ spec: 'child', parentId: parent.id }) + const parent = d.createTask({ runId, spec: 'parent' }) + const child = d.createTask({ runId, spec: 'child', parentId: parent.id }) expect(child.parent_id).toBe(parent.id) }) }) @@ -323,7 +182,7 @@ describe('OrchestrationDb', () => { describe('dispatch contexts', () => { it('creates a dispatch context and marks task as dispatched', () => { const d = createDb() - const task = d.createTask({ spec: 'work' }) + const task = d.createTask({ runId, spec: 'work' }) const ctx = createRootDispatch(d, task.id, 'term_worker') expect(ctx.id).toMatch(/^ctx_/) @@ -335,8 +194,8 @@ describe('OrchestrationDb', () => { it('rejects dispatch for non-ready tasks', () => { const d = createDb() - const parent = d.createTask({ spec: 'parent' }) - const child = d.createTask({ spec: 'child', deps: [parent.id] }) + const parent = d.createTask({ runId, spec: 'parent' }) + const child = d.createTask({ runId, spec: 'child', deps: [parent.id] }) expect(() => createRootDispatch(d, child.id, 'term_worker')).toThrow( /only ready tasks can be dispatched/ @@ -345,8 +204,8 @@ describe('OrchestrationDb', () => { it('rejects dispatch to an occupied terminal', () => { const d = createDb() - const t1 = d.createTask({ spec: 'first' }) - const t2 = d.createTask({ spec: 'second' }) + const t1 = d.createTask({ runId, spec: 'first' }) + const t2 = d.createTask({ runId, spec: 'second' }) createRootDispatch(d, t1.id, 'term_worker') expect(() => createRootDispatch(d, t2.id, 'term_worker')).toThrow( @@ -361,8 +220,8 @@ describe('OrchestrationDb', () => { it('rejects dispatch to a reminted handle on a pane with an active dispatch', () => { const d = createDb() - const t1 = d.createTask({ spec: 'first' }) - const t2 = d.createTask({ spec: 'second' }) + const t1 = d.createTask({ runId, spec: 'first' }) + const t2 = d.createTask({ runId, spec: 'second' }) createRootDispatch(d, t1.id, 'term_old', `tab_1:${LEAF_A}`) expect(() => createRootDispatch(d, t2.id, 'term_new', `tab_1:${LEAF_A}`)).toThrow( @@ -372,8 +231,8 @@ describe('OrchestrationDb', () => { it('rejects dispatch when pane keys share a leaf after break-out', () => { const d = createDb() - const t1 = d.createTask({ spec: 'first' }) - const t2 = d.createTask({ spec: 'second' }) + const t1 = d.createTask({ runId, spec: 'first' }) + const t2 = d.createTask({ runId, spec: 'second' }) createRootDispatch(d, t1.id, 'term_old', `tab_1:${LEAF_A}`) expect(() => createRootDispatch(d, t2.id, 'term_new', `tab_2:${LEAF_A}`)).toThrow( @@ -383,8 +242,8 @@ describe('OrchestrationDb', () => { it('allows concurrent dispatches to different panes', () => { const d = createDb() - const t1 = d.createTask({ spec: 'first' }) - const t2 = d.createTask({ spec: 'second' }) + const t1 = d.createTask({ runId, spec: 'first' }) + const t2 = d.createTask({ runId, spec: 'second' }) createRootDispatch(d, t1.id, 'term_a', `tab_1:${LEAF_A}`) expect(() => createRootDispatch(d, t2.id, 'term_b', `tab_1:${LEAF_B}`)).not.toThrow() @@ -392,8 +251,8 @@ describe('OrchestrationDb', () => { it('falls back to handle lock when pane keys are missing', () => { const d = createDb() - const t1 = d.createTask({ spec: 'first' }) - const t2 = d.createTask({ spec: 'second' }) + const t1 = d.createTask({ runId, spec: 'first' }) + const t2 = d.createTask({ runId, spec: 'second' }) createRootDispatch(d, t1.id, 'term_worker') // New dispatch has a pane key but the active row is legacy (no pane key): @@ -403,8 +262,8 @@ describe('OrchestrationDb', () => { it('allows dispatch to a terminal after previous dispatch completes', () => { const d = createDb() - const t1 = d.createTask({ spec: 'first' }) - const t2 = d.createTask({ spec: 'second' }) + const t1 = d.createTask({ runId, spec: 'first' }) + const t2 = d.createTask({ runId, spec: 'second' }) const ctx1 = createRootDispatch(d, t1.id, 'term_worker') d.completeDispatch(ctx1.id) @@ -414,7 +273,7 @@ describe('OrchestrationDb', () => { it('getDispatchContext returns latest for a task', () => { const d = createDb() - const task = d.createTask({ spec: 'work' }) + const task = d.createTask({ runId, spec: 'work' }) const ctx = createRootDispatch(d, task.id, 'term_a') const found = d.getDispatchContext(task.id) expect(found?.id).toBe(ctx.id) @@ -422,7 +281,7 @@ describe('OrchestrationDb', () => { it('getDispatchContext uses insertion order when timestamps tie', () => { const d = createDb() - const task = d.createTask({ spec: 'work' }) + const task = d.createTask({ runId, spec: 'work' }) const ctx1 = createRootDispatch(d, task.id, 'term_a') d.failDispatch(ctx1.id, 'retry') const ctx2 = createRootDispatch(d, task.id, 'term_a') @@ -432,7 +291,7 @@ describe('OrchestrationDb', () => { it('getActiveDispatchForTerminal returns active dispatch', () => { const d = createDb() - const task = d.createTask({ spec: 'work' }) + const task = d.createTask({ runId, spec: 'work' }) createRootDispatch(d, task.id, 'term_a') const active = d.getActiveDispatchForTerminal('term_a') @@ -442,10 +301,16 @@ describe('OrchestrationDb', () => { it('getLatestDispatchForTerminal returns the most recent completed dispatch', () => { const d = createDb() - const firstTask = d.createTask({ spec: 'first' }) + const firstTask = d.createTask({ + runId, + spec: 'first' + }) const first = createRootDispatch(d, firstTask.id, 'term_a') d.completeDispatch(first.id) - const secondTask = d.createTask({ spec: 'second' }) + const secondTask = d.createTask({ + runId, + spec: 'second' + }) const second = createRootDispatch(d, secondTask.id, 'term_a') d.completeDispatch(second.id) @@ -457,7 +322,7 @@ describe('OrchestrationDb', () => { it('circuit breaker trips after 3 failures', () => { const d = createDb() - const task = d.createTask({ spec: 'flaky' }) + const task = d.createTask({ runId, spec: 'flaky' }) const ctx = createRootDispatch(d, task.id, 'term_a') const after1 = d.failDispatch(ctx.id, 'timeout') @@ -480,7 +345,7 @@ describe('OrchestrationDb', () => { it('completeDispatch sets completed_at', () => { const d = createDb() - const task = d.createTask({ spec: 'work' }) + const task = d.createTask({ runId, spec: 'work' }) const ctx = createRootDispatch(d, task.id, 'term_a') d.completeDispatch(ctx.id) @@ -493,7 +358,10 @@ describe('OrchestrationDb', () => { describe('decision gates', () => { it('creates a gate and blocks the task', () => { const d = createDb() - const task = d.createTask({ spec: 'needs approval' }) + const task = d.createTask({ + runId, + spec: 'needs approval' + }) createRootDispatch(d, task.id, 'term_a') const gate = d.createGate({ taskId: task.id, @@ -513,7 +381,7 @@ describe('OrchestrationDb', () => { it('resolves a gate and unblocks the task', () => { const d = createDb() - const task = d.createTask({ spec: 'work' }) + const task = d.createTask({ runId, spec: 'work' }) const gate = d.createGate({ taskId: task.id, question: 'ok?' }) const resolved = d.resolveGate(gate.id, 'yes') @@ -526,7 +394,7 @@ describe('OrchestrationDb', () => { it('times out a gate', () => { const d = createDb() - const task = d.createTask({ spec: 'work' }) + const task = d.createTask({ runId, spec: 'work' }) const gate = d.createGate({ taskId: task.id, question: 'ok?' }) const timedOut = d.timeoutGate(gate.id) @@ -535,8 +403,8 @@ describe('OrchestrationDb', () => { it('lists gates with filters', () => { const d = createDb() - const t1 = d.createTask({ spec: 'a' }) - const t2 = d.createTask({ spec: 'b' }) + const t1 = d.createTask({ runId, spec: 'a' }) + const t2 = d.createTask({ runId, spec: 'b' }) d.createGate({ taskId: t1.id, question: 'q1' }) const g2 = d.createGate({ taskId: t2.id, question: 'q2' }) d.resolveGate(g2.id, 'done') @@ -599,8 +467,13 @@ describe('OrchestrationDb', () => { describe('lifecycle', () => { it('resetAll clears all tables', () => { const d = createDb() - d.insertMessage({ from: 'a', to: 'b', subject: 'test' }) - d.createTask({ spec: 'work' }) + d.insertMessage({ + runId, + from: 'a', + to: 'b', + subject: 'test' + }) + d.createTask({ runId, spec: 'work' }) d.resetAll() @@ -610,8 +483,13 @@ describe('OrchestrationDb', () => { it('resetMessages clears only messages', () => { const d = createDb() - d.insertMessage({ from: 'a', to: 'b', subject: 'test' }) - d.createTask({ spec: 'work' }) + d.insertMessage({ + runId, + from: 'a', + to: 'b', + subject: 'test' + }) + d.createTask({ runId, spec: 'work' }) d.resetMessages() @@ -621,8 +499,13 @@ describe('OrchestrationDb', () => { it('resetTasks clears tasks and dispatch contexts', () => { const d = createDb() - d.insertMessage({ from: 'a', to: 'b', subject: 'test' }) - const task = d.createTask({ spec: 'work' }) + d.insertMessage({ + runId, + from: 'a', + to: 'b', + subject: 'test' + }) + const task = d.createTask({ runId, spec: 'work' }) createRootDispatch(d, task.id, 'term_a') d.resetTasks() @@ -636,6 +519,7 @@ describe('OrchestrationDb', () => { it('insertMessage accepts type = heartbeat', () => { const d = createDb() const msg = d.insertMessage({ + runId, from: 'worker', to: 'coord', subject: 'alive', @@ -647,7 +531,7 @@ describe('OrchestrationDb', () => { it('recordHeartbeat updates last_heartbeat_at on dispatched rows', () => { const d = createDb() - const task = d.createTask({ spec: 'work' }) + const task = d.createTask({ runId, spec: 'work' }) const ctx = createRootDispatch(d, task.id, 'term_a') d.recordHeartbeat(ctx.id, '2026-05-04T00:00:00.000Z') @@ -662,10 +546,10 @@ describe('OrchestrationDb', () => { // (b) dispatched, heartbeated 12 min ago → STALE (expected result) // (c) dispatched, never heartbeated, dispatched 30s ago → not stale (grace) // (d) completed, heartbeated 30 min ago → not stale (status filter) - const taskA = d.createTask({ spec: 'a' }) - const taskB = d.createTask({ spec: 'b' }) - const taskC = d.createTask({ spec: 'c' }) - const taskD = d.createTask({ spec: 'd' }) + const taskA = d.createTask({ runId, spec: 'a' }) + const taskB = d.createTask({ runId, spec: 'b' }) + const taskC = d.createTask({ runId, spec: 'c' }) + const taskD = d.createTask({ runId, spec: 'd' }) const ctxA = createRootDispatch(d, taskA.id, 'term_a') const ctxB = createRootDispatch(d, taskB.id, 'term_b') const ctxC = createRootDispatch(d, taskC.id, 'term_c') @@ -710,15 +594,19 @@ describe('OrchestrationDb', () => { // Fresh worker: dispatched 12:00, heartbeat 12:05 (space-format), both // after the 11:55 threshold → NOT stale. - const fresh = createRootDispatch(d, d.createTask({ spec: 'fresh' }).id, 'term_fresh') + const fresh = createRootDispatch(d, d.createTask({ runId, spec: 'fresh' }).id, 'term_fresh') setDispatchTimes(d, fresh.id, '2026-07-12 12:00:00', '2026-07-12 12:05:00') // Legacy ISO-format fresh row (mixed-format table) stays fresh too. - const legacy = createRootDispatch(d, d.createTask({ spec: 'legacy' }).id, 'term_legacy') + const legacy = createRootDispatch( + d, + d.createTask({ runId, spec: 'legacy' }).id, + 'term_legacy' + ) setDispatchTimes(d, legacy.id, '2026-07-12T12:00:00.000Z', '2026-07-12T12:05:00.000Z') // Genuinely hung: dispatched + heartbeated at 10:00, ~2h before threshold. - const hung = createRootDispatch(d, d.createTask({ spec: 'hung' }).id, 'term_hung') + const hung = createRootDispatch(d, d.createTask({ runId, spec: 'hung' }).id, 'term_hung') setDispatchTimes(d, hung.id, '2026-07-12 10:00:00', '2026-07-12 10:00:00') const stale = d.getStaleDispatches('2026-07-12T11:55:00.000Z') @@ -730,7 +618,7 @@ describe('OrchestrationDb', () => { // Space-format dispatched_at one minute after the threshold, no heartbeat // yet → still inside the grace window, must not be flagged. - const ctx = createRootDispatch(d, d.createTask({ spec: 'x' }).id, 'term_x') + const ctx = createRootDispatch(d, d.createTask({ runId, spec: 'x' }).id, 'term_x') setDispatchTimes(d, ctx.id, '2026-07-12 12:00:00') const stale = d.getStaleDispatches('2026-07-12T11:59:00.000Z') @@ -742,7 +630,11 @@ describe('OrchestrationDb', () => { it('getStaleDispatches keeps a fresh row just after a UTC-midnight threshold (#8452)', () => { const d = createDb() - const ctx = createRootDispatch(d, d.createTask({ spec: 'midnight' }).id, 'term_midnight') + const ctx = createRootDispatch( + d, + d.createTask({ runId, spec: 'midnight' }).id, + 'term_midnight' + ) setDispatchTimes(d, ctx.id, '2026-05-04 00:04:00') const stale = d.getStaleDispatches('2026-05-04T00:00:00.000Z') @@ -755,7 +647,7 @@ describe('OrchestrationDb', () => { it('getStaleDispatches keeps a live worker with a fresh space-format heartbeat (#8452)', () => { const d = createDb() - const ctx = createRootDispatch(d, d.createTask({ spec: 'live' }).id, 'term_live') + const ctx = createRootDispatch(d, d.createTask({ runId, spec: 'live' }).id, 'term_live') setDispatchTimes(d, ctx.id, '2026-07-12 10:00:00', '2026-07-12 11:59:00') const stale = d.getStaleDispatches('2026-07-12T11:55:00.000Z') @@ -765,6 +657,7 @@ describe('OrchestrationDb', () => { it('getThreadMessagesFor returns only same-thread replies to a handle', () => { const d = createDb() const outbound = d.insertMessage({ + runId, from: 'worker', to: 'coord', subject: 'Question', @@ -773,6 +666,7 @@ describe('OrchestrationDb', () => { }) // Reply in the same thread addressed to the worker const reply = d.insertMessage({ + runId, from: 'coord', to: 'worker', subject: 'Re: Question', @@ -781,6 +675,7 @@ describe('OrchestrationDb', () => { }) // Distractor: different thread, same recipient d.insertMessage({ + runId, from: 'coord', to: 'worker', subject: 'other', @@ -789,6 +684,7 @@ describe('OrchestrationDb', () => { }) // Distractor: same thread but not addressed to worker d.insertMessage({ + runId, from: 'coord', to: 'someone_else', subject: 'cc', @@ -902,6 +798,7 @@ describe('OrchestrationDb', () => { // (a) INSERT type='heartbeat' now succeeds expect(() => d.insertMessage({ + runId, from: 'w', to: 'c', subject: 'alive', @@ -911,7 +808,7 @@ describe('OrchestrationDb', () => { ).not.toThrow() // (b) last_heartbeat_at column exists on dispatch_contexts - const task = d.createTask({ spec: 'work' }) + const task = d.createTask({ runId, spec: 'work' }) const ctx = createRootDispatch(d, task.id, 'term_a') d.recordHeartbeat(ctx.id, '2026-05-04T00:00:00.000Z') expect(d.getDispatchContext(task.id)?.last_heartbeat_at).toBe('2026-05-04T00:00:00.000Z') @@ -942,11 +839,12 @@ describe('OrchestrationDb', () => { const d = new OrchestrationDb(path) db = d - const task = d.createTask({ spec: 'work' }) + const task = d.createTask({ runId, spec: 'work' }) const ctx = createRootDispatch(d, task.id, 'term_a', 'tab_1:leaf_1') expect(d.getDispatchContextById(ctx.id)?.assignee_pane_key).toBe('tab_1:leaf_1') const msg = d.insertMessage({ + runId, from: 'w', to: 'c', subject: 'done', @@ -960,6 +858,7 @@ describe('OrchestrationDb', () => { const path = createV1Snapshot() const first = new OrchestrationDb(path) first.insertMessage({ + runId, from: 'w', to: 'c', subject: 'alive', @@ -972,6 +871,7 @@ describe('OrchestrationDb', () => { db = second expect(() => second.insertMessage({ + runId, from: 'w', to: 'c', subject: 'again', diff --git a/src/main/runtime/orchestration/db/attempt-outcome-projection.test.ts b/src/main/runtime/orchestration/db/attempt-outcome-projection.test.ts index eae300a7b20..a8dc098728a 100644 --- a/src/main/runtime/orchestration/db/attempt-outcome-projection.test.ts +++ b/src/main/runtime/orchestration/db/attempt-outcome-projection.test.ts @@ -48,7 +48,7 @@ describe('durable Attempt observation and outcome projection', () => { function createAttempt(): { taskId: string; dispatchId: string } { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'observe outcome' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'observe outcome' }) const dispatch = createRootDispatch(db, task.id, 'term_observed') return { taskId: task.id, dispatchId: dispatch.id } } @@ -162,7 +162,10 @@ describe('durable Attempt observation and outcome projection', () => { const path = join(dir, 'orchestration.sqlite') try { db = new OrchestrationDb(path) - const task = db.createTask({ spec: 'durable observation' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'durable observation' + }) const dispatch = createRootDispatch(db, task.id, 'term_durable') db.recordAttemptObservation( fact(dispatch.id, { @@ -189,7 +192,10 @@ describe('durable Attempt observation and outcome projection', () => { it('keeps worker_done settlement as the atomic success fast path', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'worker_done fast path' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'worker_done fast path' + }) const started = db.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, diff --git a/src/main/runtime/orchestration/db/contract-constants.ts b/src/main/runtime/orchestration/db/contract-constants.ts index 287ce565d5b..47e0cd6165a 100644 --- a/src/main/runtime/orchestration/db/contract-constants.ts +++ b/src/main/runtime/orchestration/db/contract-constants.ts @@ -7,4 +7,4 @@ export const LEGACY_CONTRACT_VERSION = 0 export const CURRENT_CONTRACT_VERSION = ORCHESTRATION_CONTRACT_VERSION // Schema versions: v2 'heartbeat'+last_heartbeat_at, v3 delivered_at, v4 task-creator terminal, v5 task_title/display_name, v6 pane identity, v7 lightweight Runs, v8 crash-safe Run deliveries, v9 durable question threads, v10 Dispatch capabilities, v11 durable mutation receipts, v12 composed worker state, v18 post-v6 version-skew repair, v19 adopted legacy Runs and compatibility receipts, v20 legacy question backfill, v21 legacy scheduler-loss provenance, v22 dispatch assignee lookup, v23 worker terminal resource ownership, v24 creator-incarnation authority, v25 active Dispatch handle lookup, v26 indexed mutation receipt capacity, v27 durable federation acknowledgments, v28 durable local mutation caller identity, v31 dispatch/resource identity links, v32 bounded worker-terminal recovery metadata, v33 durable mailbox pointer Enter state, v34 role-addressed mailbox deliveries, v35 mailbox delivery default and index-predicate repair, v36 dispatch mailbox consumer generation, v37 recorded dispatch creator identity, v39 structured session journal archives. -export const SCHEMA_VERSION = 39 +export const SCHEMA_VERSION = 40 diff --git a/src/main/runtime/orchestration/db/decision-gate-lifecycle.test.ts b/src/main/runtime/orchestration/db/decision-gate-lifecycle.test.ts index 219cf6fe212..9fdc9d9b5fb 100644 --- a/src/main/runtime/orchestration/db/decision-gate-lifecycle.test.ts +++ b/src/main/runtime/orchestration/db/decision-gate-lifecycle.test.ts @@ -9,7 +9,7 @@ describe('decision-gate lifecycle transitions', () => { it('blocks the dispatched Task when creating a gate', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'gate blocks task' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'gate blocks task' }) createRootDispatch(db, task.id, 'term_gate') expect(db.getTask(task.id)?.status).toBe('dispatched') @@ -20,7 +20,7 @@ describe('decision-gate lifecycle transitions', () => { it('rolls back the gate row when the Task transition cannot commit', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'atomic gate creation' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'atomic gate creation' }) const dispatch = createRootDispatch(db, task.id, 'term_gate') db.db.exec(` CREATE TRIGGER reject_gate_task_block diff --git a/src/main/runtime/orchestration/db/decision-gates/decision-gate-store.ts b/src/main/runtime/orchestration/db/decision-gates/decision-gate-store.ts index 532fa52b22a..296bcea42bc 100644 --- a/src/main/runtime/orchestration/db/decision-gates/decision-gate-store.ts +++ b/src/main/runtime/orchestration/db/decision-gates/decision-gate-store.ts @@ -1,6 +1,5 @@ import type { DecisionGateRow, DispatchContextRow, GateStatus } from '../../types' import { OrchestrationError } from '../../orchestration-error' -import { LEGACY_RUN_ID } from '../contract-constants' import { generateId } from '../generated-id' import type { OrchestrationDb } from '../orchestration-db' import { transitionLifecycleWithDb } from '../lifecycle-transition' @@ -18,6 +17,16 @@ export function createGate( ): DecisionGateRow { this.db.exec('SAVEPOINT create_gate') try { + const task = this.getTask(gate.taskId) + if (!task) { + throw new OrchestrationError( + 'lifecycle_not_found', + `Task ${gate.taskId} was not found while creating a decision gate.`, + { taskId: gate.taskId } + ) + } + const runId = task.run_id + this.requireRun(runId) const active = this.db .prepare( `SELECT * FROM dispatch_contexts @@ -65,22 +74,8 @@ export function createGate( .prepare( 'INSERT INTO decision_gates (id, run_id, task_id, question, options) VALUES (?, ?, ?, ?, ?)' ) - .run( - id, - this.getTask(gate.taskId)?.run_id ?? LEGACY_RUN_ID, - gate.taskId, - gate.question, - optionsJson - ) + .run(id, runId, gate.taskId, gate.question, optionsJson) this.completeActiveDispatchesForTask(gate.taskId) - const task = this.getTask(gate.taskId) - if (!task) { - throw new OrchestrationError( - 'lifecycle_not_found', - `Task ${gate.taskId} was not found while creating a decision gate.`, - { taskId: gate.taskId } - ) - } transitionLifecycleWithDb(this.db, { entity: 'task', id: gate.taskId, diff --git a/src/main/runtime/orchestration/db/dispatch-depth.test.ts b/src/main/runtime/orchestration/db/dispatch-depth.test.ts index 97df3f01c51..013cedffe91 100644 --- a/src/main/runtime/orchestration/db/dispatch-depth.test.ts +++ b/src/main/runtime/orchestration/db/dispatch-depth.test.ts @@ -16,7 +16,7 @@ describe('nested worker depth', () => { function coordinatorDispatchesWorker(maxDepth = UNCAPPED) { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'root task' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'root task' }) const worker = db.createDispatchContext({ taskId: task.id, assigneeHandle: 'term_worker', @@ -33,7 +33,7 @@ describe('nested worker depth', () => { it('refuses a worker dispatching a sub-worker at the default cap', () => { coordinatorDispatchesWorker() - const nested = db.createTask({ spec: 'nested task' }) + const nested = db.createTask({ runId: 'run_legacy_local', spec: 'nested task' }) expect(() => db.createDispatchContext({ taskId: nested.id, @@ -51,7 +51,7 @@ describe('nested worker depth', () => { it('tells the refused worker to complete the task itself', () => { coordinatorDispatchesWorker() - const nested = db.createTask({ spec: 'nested task' }) + const nested = db.createTask({ runId: 'run_legacy_local', spec: 'nested task' }) expect(() => db.createDispatchContext({ taskId: nested.id, @@ -64,7 +64,7 @@ describe('nested worker depth', () => { it('permits one more generation when the cap is raised, and records depth 2', () => { coordinatorDispatchesWorker() - const nested = db.createTask({ spec: 'nested task' }) + const nested = db.createTask({ runId: 'run_legacy_local', spec: 'nested task' }) const sub = db.createDispatchContext({ taskId: nested.id, assigneeHandle: 'term_sub', @@ -113,9 +113,9 @@ describe('nested worker depth', () => { db.db .prepare( `INSERT INTO remote_dispatch_attachments - (dispatch_id, task_id, home_peer_fingerprint, protocol_version, runtime_epoch, + (dispatch_id, task_id, home_run_id, home_peer_fingerprint, protocol_version, runtime_epoch, pane_key, process_incarnation, state, depth) - VALUES (?, ?, 'peer', 1, 'epoch', ?, ?, ?, ?)` + VALUES (?, ?, 'run_home', 'peer', 1, 'epoch', ?, ?, ?, ?)` ) .run(`ctx_${state}_${depth}_${paneKey}_${inc}`, 'task_remote', paneKey, inc, state, depth) } @@ -182,7 +182,10 @@ describe('nested worker depth', () => { it('takes the maximum when a process holds both a local and a remote role', () => { // Query order must not decide the answer: the deeper role governs. db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'local role' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'local role' + }) db.createDispatchContext({ taskId: task.id, assigneeHandle: 'term_both', @@ -220,13 +223,19 @@ describe('nested worker depth', () => { it('stamps depth 1 for a root coordinator', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'root work' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'root work' + }) expect(startWorker(task.id, SYSTEM, UNCAPPED).dispatch.depth).toBe(1) }) it('refuses a worker starting a sub-worker at the default cap', () => { coordinatorDispatchesWorker() - const nested = db.createTask({ spec: 'nested work' }) + const nested = db.createTask({ + runId: 'run_legacy_local', + spec: 'nested work' + }) expect(() => startWorker( nested.id, @@ -238,7 +247,10 @@ describe('nested worker depth', () => { it('refuses a worker retrying into a sub-worker at the default cap', () => { coordinatorDispatchesWorker() - const nested = db.createTask({ spec: 'nested retry work' }) + const nested = db.createTask({ + runId: 'run_legacy_local', + spec: 'nested retry work' + }) const first = startWorker(nested.id, SYSTEM, UNCAPPED) db.failWorkerStart(first.dispatch.id, 'accepted', 'first attempt failed') expect(() => @@ -257,7 +269,10 @@ describe('nested worker depth', () => { // Context-only dispatch stores null on purpose; requiring an incarnation // locally would silently drop real parents and fail open. db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'context only' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'context only' + }) const row = db.createDispatchContext({ taskId: task.id, assigneeHandle: 'term_ctx', diff --git a/src/main/runtime/orchestration/db/dispatch-mailbox-consumer-fencing.test.ts b/src/main/runtime/orchestration/db/dispatch-mailbox-consumer-fencing.test.ts index c7d287e8bdb..29a2e468ee8 100644 --- a/src/main/runtime/orchestration/db/dispatch-mailbox-consumer-fencing.test.ts +++ b/src/main/runtime/orchestration/db/dispatch-mailbox-consumer-fencing.test.ts @@ -22,7 +22,7 @@ describe('dispatch mailbox consumer fencing', () => { afterEach(() => db.close()) function dispatchWithMail(subjects: string[]): { id: string; runId: string } { - const task = db.createTask({ spec: 'fenced worker work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'fenced worker work' }) const dispatch = createRootDispatch(db, task.id, 'term_worker', PANE_A) for (const subject of subjects) { db.insertMessage({ @@ -116,7 +116,10 @@ describe('dispatch mailbox consumer fencing', () => { }) it('bumps and fences on the worker-start attach path', () => { - const task = db.createTask({ spec: 'worker-start attach' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'worker-start attach' + }) const started = db.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -149,6 +152,7 @@ describe('dispatch mailbox consumer fencing', () => { it('gives a federated attachment its own generation on the worker host', () => { const dispatchId = 'ctx_remote_fence' db.createRemoteDispatchAttachment({ + runId: 'run-home', dispatchId, taskId: 'task_remote', homePeerFingerprint: 'home-peer', @@ -187,7 +191,10 @@ describe('dispatch mailbox consumer fencing', () => { }) it('starts a retry Dispatch on a fresh mailbox address rather than sharing the old one', () => { - const task = db.createTask({ spec: 'work that fails once' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'work that fails once' + }) const first = db.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, diff --git a/src/main/runtime/orchestration/db/dispatch-row-writer.ts b/src/main/runtime/orchestration/db/dispatch-row-writer.ts index 807814a87b1..84862ee343d 100644 --- a/src/main/runtime/orchestration/db/dispatch-row-writer.ts +++ b/src/main/runtime/orchestration/db/dispatch-row-writer.ts @@ -49,8 +49,8 @@ const STARTING_DISPATCH_CONTEXT_SQL = `INSERT INTO dispatch_contexts ( ) VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, 'pending', datetime('now'))` const REMOTE_DISPATCH_ATTACHMENT_SQL = `INSERT INTO remote_dispatch_attachments ( - dispatch_id, task_id, home_peer_fingerprint, protocol_version, runtime_epoch, depth - ) VALUES (?, ?, ?, ?, ?, ?)` + dispatch_id, home_run_id, task_id, home_peer_fingerprint, protocol_version, runtime_epoch, depth + ) VALUES (?, ?, ?, ?, ?, ?, ?)` /** Last line of defence: a row that reached here unstamped would read as a root. */ function assertStampedDepth(depth: number): void { @@ -140,6 +140,7 @@ export function insertRemoteDispatchAttachmentRow( db: Database.Database, params: { dispatchId: string + runId: string taskId: string homePeerFingerprint: string protocolVersion: number @@ -151,6 +152,7 @@ export function insertRemoteDispatchAttachmentRow( assertStampedDepth(params.depth) db.prepare(REMOTE_DISPATCH_ATTACHMENT_SQL).run( params.dispatchId, + params.runId, params.taskId, params.homePeerFingerprint, params.protocolVersion, diff --git a/src/main/runtime/orchestration/db/federation/federated-dispatch-observation-fence.test.ts b/src/main/runtime/orchestration/db/federation/federated-dispatch-observation-fence.test.ts index e32bf27a00c..ecc3ca5e2c0 100644 --- a/src/main/runtime/orchestration/db/federation/federated-dispatch-observation-fence.test.ts +++ b/src/main/runtime/orchestration/db/federation/federated-dispatch-observation-fence.test.ts @@ -8,7 +8,10 @@ describe('federated Dispatch observation fence', () => { it('rejects out-of-order epochs and observations captured before release', () => { const database = (db = new OrchestrationDb(':memory:')) - const task = database.createTask({ spec: 'fenced federated observation' }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: 'fenced federated observation' + }) const started = database.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, diff --git a/src/main/runtime/orchestration/db/federation/remote-dispatch-attachment-create.ts b/src/main/runtime/orchestration/db/federation/remote-dispatch-attachment-create.ts index 56d26ccfe3b..d927cf96838 100644 --- a/src/main/runtime/orchestration/db/federation/remote-dispatch-attachment-create.ts +++ b/src/main/runtime/orchestration/db/federation/remote-dispatch-attachment-create.ts @@ -8,6 +8,7 @@ export function createRemoteDispatchAttachment( this: OrchestrationDb, params: { dispatchId: string + runId: string taskId: string homePeerFingerprint: string protocolVersion: number @@ -43,6 +44,16 @@ export function createRemoteDispatchAttachment( `Remote attachment request ${params.mutationReceipt.requestId} already exists.` ) } + if (!params.runId?.trim()) { + throw new OrchestrationError('invalid_argument', 'Missing Run ID') + } + this.db + .prepare( + `INSERT OR IGNORE INTO runs (id, objective, home_database, consumer_generation, legacy) + VALUES (?, ?, 'remote', 0, 0)` + ) + .run(params.runId, `Coordinated from ${params.homePeerFingerprint}`) + this.requireRun(params.runId) ensureMutationReceiptCapacity(this.db) this.db .prepare( @@ -59,6 +70,7 @@ export function createRemoteDispatchAttachment( ) insertRemoteDispatchAttachmentRow(this.db, { dispatchId: params.dispatchId, + runId: params.runId, taskId: params.taskId, homePeerFingerprint: params.homePeerFingerprint, protocolVersion: params.protocolVersion, diff --git a/src/main/runtime/orchestration/db/federation/remote-dispatch-attachment-release.test.ts b/src/main/runtime/orchestration/db/federation/remote-dispatch-attachment-release.test.ts index ab515ffb30c..0865d4b8972 100644 --- a/src/main/runtime/orchestration/db/federation/remote-dispatch-attachment-release.test.ts +++ b/src/main/runtime/orchestration/db/federation/remote-dispatch-attachment-release.test.ts @@ -16,6 +16,7 @@ describe('the remote attachment release guard', () => { function settledAttachment(dispatchId: string): void { db.createRemoteDispatchAttachment({ + runId: 'run-home', dispatchId, taskId: `task_${dispatchId}`, homePeerFingerprint: 'home-peer', diff --git a/src/main/runtime/orchestration/db/lifecycle-transition.test.ts b/src/main/runtime/orchestration/db/lifecycle-transition.test.ts index eed4332879f..936208e77ef 100644 --- a/src/main/runtime/orchestration/db/lifecycle-transition.test.ts +++ b/src/main/runtime/orchestration/db/lifecycle-transition.test.ts @@ -8,7 +8,7 @@ describe('guarded lifecycle transitions', () => { it('rejects a stale prior state without changing the projection', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'guarded transition' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'guarded transition' }) expect(() => db!.transitionLifecycle({ @@ -23,7 +23,7 @@ describe('guarded lifecycle transitions', () => { it('composes its projection into the caller-owned transaction', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'caller-owned rollback' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'caller-owned rollback' }) db.db.exec('SAVEPOINT lifecycle_test') expect( @@ -49,7 +49,7 @@ describe('guarded lifecycle transitions', () => { ['completed', 'blocked'] ] as const)('preserves public task updates from %s to %s', (from, to) => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'manual status correction' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'manual status correction' }) db.db.prepare('UPDATE tasks SET status = ? WHERE id = ?').run(from, task.id) expect(db.updateTaskStatus(task.id, to)?.status).toBe(to) diff --git a/src/main/runtime/orchestration/db/messages/message-insert.ts b/src/main/runtime/orchestration/db/messages/message-insert.ts index 2984545a09b..82573305479 100644 --- a/src/main/runtime/orchestration/db/messages/message-insert.ts +++ b/src/main/runtime/orchestration/db/messages/message-insert.ts @@ -1,5 +1,4 @@ import type { MessageType, MessagePriority, MessageDeliveryContract, MessageRow } from '../../types' -import { LEGACY_RUN_ID } from '../contract-constants' import { generateId } from '../generated-id' import { exposeMessageTimestamps } from '../utc-timestamp' import type { OrchestrationDb } from '../orchestration-db' @@ -26,7 +25,10 @@ export type MessageInsert = { } export function insertMessage(this: OrchestrationDb, msg: MessageInsert): MessageRow { - const runId = msg.runId ?? LEGACY_RUN_ID + const runId = msg.runId + if (!runId) { + throw new Error('Run is required') + } const deliveryContract = msg.deliveryContract ?? 'current_delivery' this.requireRun(runId) const id = msg.id ?? generateId('msg') diff --git a/src/main/runtime/orchestration/db/schema/create-graph-tables-sql.ts b/src/main/runtime/orchestration/db/schema/create-graph-tables-sql.ts index 5aed50eb7f9..0897cb852de 100644 --- a/src/main/runtime/orchestration/db/schema/create-graph-tables-sql.ts +++ b/src/main/runtime/orchestration/db/schema/create-graph-tables-sql.ts @@ -38,6 +38,7 @@ CREATE TABLE IF NOT EXISTS federated_dispatches ( ); CREATE TABLE IF NOT EXISTS remote_dispatch_attachments ( + home_run_id TEXT NOT NULL, dispatch_id TEXT PRIMARY KEY, task_id TEXT NOT NULL, home_peer_fingerprint TEXT NOT NULL, diff --git a/src/main/runtime/orchestration/db/schema/federated-home-run-migration.test.ts b/src/main/runtime/orchestration/db/schema/federated-home-run-migration.test.ts new file mode 100644 index 00000000000..b970435223a --- /dev/null +++ b/src/main/runtime/orchestration/db/schema/federated-home-run-migration.test.ts @@ -0,0 +1,26 @@ +import { afterEach, describe, expect, it } from 'vitest' +import { OrchestrationDb } from '../orchestration-db' +import { migrateV40 } from './migrate-v40' +import { importFederatedControlMessage } from '../../federation-control-message' + +describe('federated home Run migration', () => { + const db = new OrchestrationDb(':memory:') + afterEach(() => db.close()) + + it('adds the home Run column and refuses mail for a development placeholder', () => { + db.db.exec('ALTER TABLE remote_dispatch_attachments DROP COLUMN home_run_id') + db.db.exec(`INSERT INTO remote_dispatch_attachments + (dispatch_id, task_id, home_peer_fingerprint, runtime_epoch) + VALUES ('ctx_old', 'task_old', 'home', 'epoch')`) + migrateV40.call(db, 39) + expect(db.getRemoteDispatchAttachment('ctx_old')?.home_run_id).toBe('') + expect(() => + importFederatedControlMessage(db, { + dispatchId: 'ctx_old', + messageId: 'message_old', + payload: JSON.stringify({ from: 'home', subject: 'Instruction', body: '', type: 'message' }) + }) + ).toThrow('Run not found:') + expect(db.getMessageById('message_old')).toBeUndefined() + }) +}) diff --git a/src/main/runtime/orchestration/db/schema/migrate-v40.ts b/src/main/runtime/orchestration/db/schema/migrate-v40.ts new file mode 100644 index 00000000000..50ef46f82cc --- /dev/null +++ b/src/main/runtime/orchestration/db/schema/migrate-v40.ts @@ -0,0 +1,11 @@ +import type { OrchestrationDb } from '../orchestration-db' + +export function migrateV40(this: OrchestrationDb, current: number): void { + if (current >= 40 || this.hasColumn('remote_dispatch_attachments', 'home_run_id')) { + return + } + // Federation is unreleased; any development-only rows fail Run validation until reattached. + this.db.exec( + "ALTER TABLE remote_dispatch_attachments ADD COLUMN home_run_id TEXT NOT NULL DEFAULT ''" + ) +} diff --git a/src/main/runtime/orchestration/db/schema/migrate.ts b/src/main/runtime/orchestration/db/schema/migrate.ts index b8da910722d..582dedf4752 100644 --- a/src/main/runtime/orchestration/db/schema/migrate.ts +++ b/src/main/runtime/orchestration/db/schema/migrate.ts @@ -10,6 +10,7 @@ import { migrateV36 } from './migrate-v36' import { migrateV37 } from './migrate-v37' import { migrateV38 } from './migrate-v38' import { migrateV39 } from './migrate-v39' +import { migrateV40 } from './migrate-v40' // Why: CREATE TABLE IF NOT EXISTS won't alter existing DBs; migrate in a txn that bumps user_version only on success (atomic all-or-nothing). export function migrate(this: OrchestrationDb): void { @@ -30,6 +31,7 @@ export function migrate(this: OrchestrationDb): void { migrateV37.call(this, current) migrateV38.call(this, current) migrateV39.call(this, current) + migrateV40.call(this, current) this.createMailboxDeliveryIndexesIfPossible() this.db.pragma(`user_version = ${SCHEMA_VERSION}`) this.db.exec('COMMIT') diff --git a/src/main/runtime/orchestration/db/tasks/task-status-transition.ts b/src/main/runtime/orchestration/db/tasks/task-status-transition.ts index e1de8dc5b17..dcddc781b6d 100644 --- a/src/main/runtime/orchestration/db/tasks/task-status-transition.ts +++ b/src/main/runtime/orchestration/db/tasks/task-status-transition.ts @@ -35,18 +35,24 @@ export function updateTaskStatus( ORDER BY rowid DESC LIMIT 1` ) .get(id) as { id: string } | undefined - const activeWorker = terminalStatus - ? (this.db - .prepare( - `SELECT active.id + // Why: a supervised worker owns its Task for as long as it is alive. Every status this + // function lets past the active-Dispatch check must clear the same worker check, or the Task + // re-opens under a worker whose own lifecycle can no longer settle it (#16904 relay wedge). + // A no-op re-assert of `dispatched` re-opens nothing and stays legal. + const reopensUnderWorker = requiresActiveDispatch && task.status !== 'dispatched' + const activeWorker = + terminalStatus || reopensUnderWorker + ? (this.db + .prepare( + `SELECT active.id FROM dispatch_contexts active JOIN worker_dispatches worker ON worker.dispatch_id = active.id WHERE active.task_id = ? AND active.status IN ('pending', 'dispatched') AND worker.state NOT IN ('failed', 'succeeded', 'stopped', 'abandoned') ORDER BY active.rowid DESC LIMIT 1` - ) - .get(id) as { id: string } | undefined) - : undefined + ) + .get(id) as { id: string } | undefined) + : undefined if (activeWorker) { throw new OrchestrationError( 'task_not_startable', diff --git a/src/main/runtime/orchestration/db/tasks/task-store.ts b/src/main/runtime/orchestration/db/tasks/task-store.ts index 4ad3e8e3ffa..af43dc2be12 100644 --- a/src/main/runtime/orchestration/db/tasks/task-store.ts +++ b/src/main/runtime/orchestration/db/tasks/task-store.ts @@ -1,7 +1,6 @@ import type Database from '../../../../sqlite/sync-database' import type { TaskStatus, TaskRow } from '../../types' import { buildOrchestrationTaskDisplayMetadata } from '../../../../../shared/orchestration-task-display' -import { LEGACY_RUN_ID } from '../contract-constants' import { generateId } from '../generated-id' import type { TaskRuntimeLineageRow } from '../run-list-page' import type { OrchestrationDb } from '../orchestration-db' @@ -25,7 +24,10 @@ export function createTask( runId?: string } ): TaskRow { - const runId = task.runId ?? LEGACY_RUN_ID + const runId = task.runId + if (!runId) { + throw new Error('Run is required') + } this.requireRun(runId) if (task.parentId) { const parent = this.getTask(task.parentId) diff --git a/src/main/runtime/orchestration/db/worker-dispatch/worker-dispatch-authority.ts b/src/main/runtime/orchestration/db/worker-dispatch/worker-dispatch-authority.ts index b89468c77a0..5e0f5f5b142 100644 --- a/src/main/runtime/orchestration/db/worker-dispatch/worker-dispatch-authority.ts +++ b/src/main/runtime/orchestration/db/worker-dispatch/worker-dispatch-authority.ts @@ -160,12 +160,66 @@ export function prepareStartingWorkerAuthority( } } +/** + * Custody for an agent terminal this worker-start just created, recorded at creation instead of + * after the agent boot wait. Until the row exists a keystroke into the booting pane finds no + * ownership to flip, so the takeover is silently dropped and a later `worker-release` closes the + * pane under the user. + * + * Ownership of a pane only; the Dispatch capability stays behind the boot wait, because authority + * must not be handed to a process that has not come up. + */ +export function recordCreatedWorkerTerminalCustody( + this: OrchestrationDb, + params: { + dispatchId: string + handle: string + paneKey: string + processIncarnation: string + worktreeId: string + hostScope?: string | null + } +): void { + this.db.exec('BEGIN IMMEDIATE') + try { + // Same guard as prepareStartingWorkerAuthority, read inside the transaction: a dispatch stopped + // while the terminal was being created must not acquire an owner. + const dispatch = this.getDispatchContextById(params.dispatchId) + const worker = this.getWorkerDispatch(params.dispatchId) + if (!dispatch || dispatch.status !== 'pending' || worker?.state !== 'starting') { + throw new OrchestrationError( + 'dispatch_inactive', + `Dispatch ${params.dispatchId} is not starting.` + ) + } + if (!this.getWorkerTerminalResourceByOwner(params.dispatchId)) { + this.createWorkerTerminalResourceStatement({ + dispatchId: params.dispatchId, + worktreeId: params.worktreeId, + terminalHandle: params.handle, + paneKey: params.paneKey, + processIncarnation: params.processIncarnation, + endpointId: worker.runtime_epoch, + endpointIncarnation: params.processIncarnation, + hostScope: params.hostScope, + ownership: 'owned' + }) + } + this.db.exec('COMMIT') + } catch (error) { + this.db.exec('ROLLBACK') + throw error + } +} + export type WorkerDispatchAuthorityMethods = { prepareStartingWorkerAuthority: typeof prepareStartingWorkerAuthority + recordCreatedWorkerTerminalCustody: typeof recordCreatedWorkerTerminalCustody } export function attachWorkerDispatchAuthority(ctor: { prototype: object }): void { Object.assign(ctor.prototype, { - prepareStartingWorkerAuthority + prepareStartingWorkerAuthority, + recordCreatedWorkerTerminalCustody }) } diff --git a/src/main/runtime/orchestration/db/worker-dispatch/worker-dispatch-outcome.ts b/src/main/runtime/orchestration/db/worker-dispatch/worker-dispatch-outcome.ts index 5ff97f83fd9..6544f519497 100644 --- a/src/main/runtime/orchestration/db/worker-dispatch/worker-dispatch-outcome.ts +++ b/src/main/runtime/orchestration/db/worker-dispatch/worker-dispatch-outcome.ts @@ -2,10 +2,7 @@ import type { WorkerDispatchRow } from '../../types' import { OrchestrationError } from '../../orchestration-error' import type { OrchestrationDb } from '../orchestration-db' import { transitionLifecycleWithDb } from '../lifecycle-transition' -import { - adoptFailedStartTerminal, - type FailedStartTerminalAdoption -} from '../worker-terminal/failed-start-terminal-adoption' +import { recordFailedStartDispatchIdentity } from '../worker-terminal/failed-start-dispatch-identity' export function markWorkerDispatchReady( this: OrchestrationDb, @@ -51,11 +48,7 @@ export function failWorkerStart( // Why (#16095): revocation exists to stop a worker acting on a dispatch that never landed. A // prompt whose turn start went unobserved provably landed, so its worker keeps the authority its // own report needs. - options: { - retainCapability?: boolean - /** A start that died before authority attached still owns the terminal it created. */ - adoptResidualTerminal?: FailedStartTerminalAdoption - } = {} + options: { retainCapability?: boolean } = {} ): WorkerDispatchRow { this.db.exec('BEGIN IMMEDIATE') try { @@ -104,11 +97,7 @@ export function failWorkerStart( }) } this.closeQuestionsForDispatch(dispatchId) - adoptFailedStartTerminal( - this, - this.getWorkerDispatch(dispatchId) as WorkerDispatchRow, - options.adoptResidualTerminal - ) + recordFailedStartDispatchIdentity(this, this.getWorkerDispatch(dispatchId) as WorkerDispatchRow) this.db.exec('COMMIT') return this.getWorkerDispatch(dispatchId) as WorkerDispatchRow } catch (error) { diff --git a/src/main/runtime/orchestration/db/worker-dispatch/worker-dispatch-stop.ts b/src/main/runtime/orchestration/db/worker-dispatch/worker-dispatch-stop.ts index 8dbda2030c5..fd4ee773bb4 100644 --- a/src/main/runtime/orchestration/db/worker-dispatch/worker-dispatch-stop.ts +++ b/src/main/runtime/orchestration/db/worker-dispatch/worker-dispatch-stop.ts @@ -59,7 +59,19 @@ export function beginWorkerStop( this.db.exec('COMMIT') return { disposition: 'already_settled', worker, dispatch } } - if (!['ready', 'start_unknown'].includes(worker.state)) { + // Why `stopping` under a DIFFERENT epoch is accepted: a stop whose runtime died mid-flight + // leaves the row here forever, and refusing the re-issue was the only operator escape + // (#16904). Re-running the stop earns the honest outcome — settled, or `stop_unknown`, from + // which the worker can be abandoned. It never asserts an exit the runtime did not observe. + // + // Why the epoch and not just the state: this runtime's own `stopping` row means its stop is + // still in flight, and a second pass would record `stop_unknown` over it. The exit event that + // follows claims a clean stop only from `stopping` under its own epoch + // (failActiveDispatchOnExit), so it would then read the operator's stop as a crash and + // escalate it. Same predicate as that reader, so both agree on whose stop this is. + const stopStrandedByAnotherRuntime = + worker.state === 'stopping' && worker.runtime_epoch !== runtimeEpoch + if (!['ready', 'start_unknown'].includes(worker.state) && !stopStrandedByAnotherRuntime) { throw new OrchestrationError( 'dispatch_inactive', `Dispatch ${dispatchId} cannot stop from ${worker.state}.` diff --git a/src/main/runtime/orchestration/db/worker-dispatch/worker-terminal-recovery.ts b/src/main/runtime/orchestration/db/worker-dispatch/worker-terminal-recovery.ts index 97179eb0185..410318bf9c6 100644 --- a/src/main/runtime/orchestration/db/worker-dispatch/worker-terminal-recovery.ts +++ b/src/main/runtime/orchestration/db/worker-dispatch/worker-terminal-recovery.ts @@ -9,7 +9,6 @@ import { DISPATCH_CIRCUIT_BREAK_FAILURES } from '../dispatch-context/dispatch-ci import type { OrchestrationDb } from '../orchestration-db' import { reconcileTaskAfterDispatchInterruption } from '../dispatch-context/task-dispatch-reconciliation' import { transitionLifecycleWithDb } from '../lifecycle-transition' -import { WORKER_SETTLED_STATES } from '../../worker-terminal-ownership' export function listLegacyWorkerTerminalRecoveryRows( this: OrchestrationDb @@ -23,18 +22,9 @@ export function listLegacyWorkerTerminalRecoveryRows( FROM dispatch_contexts dc INNER JOIN worker_dispatches wd ON wd.dispatch_id = dc.id WHERE wd.state IN ('starting', 'ready', 'start_unknown', 'stopping', 'stop_unknown') - -- A settled worker whose terminal orchestration still owns keeps a resumable agent - -- session; it needs the resume fence until release or retain retires the pane. - OR (wd.state IN (${WORKER_SETTLED_STATES.map(() => '?').join(', ')}) - AND EXISTS ( - SELECT 1 FROM worker_terminal_resources wtr - WHERE wtr.owner_dispatch_id = dc.id - AND wtr.ownership_state = 'owned' - AND wtr.release_state NOT IN ('released', 'retained') - )) ORDER BY dc.rowid` ) - .all(...WORKER_SETTLED_STATES) as LegacyWorkerTerminalRecoveryRow[] + .all() as LegacyWorkerTerminalRecoveryRow[] } export function reconcileMissingWorkerTerminal( diff --git a/src/main/runtime/orchestration/db/worker-terminal/failed-start-dispatch-identity.ts b/src/main/runtime/orchestration/db/worker-terminal/failed-start-dispatch-identity.ts new file mode 100644 index 00000000000..671b12c39a7 --- /dev/null +++ b/src/main/runtime/orchestration/db/worker-terminal/failed-start-dispatch-identity.ts @@ -0,0 +1,34 @@ +import type { WorkerDispatchRow } from '../../types' +import type { OrchestrationDb } from '../orchestration-db' + +/** + * A start that dies before `prepareStartingWorkerAuthority` never filled the Dispatch context in, + * and release re-proves identity through it — so the custody row written at terminal creation would + * name a pane no release path could match. Copy that identity across. + * + * `capability_hash` stays null, so this grants nothing: it records which pane the Dispatch owns. + * + * No transaction: composes inside `failWorkerStart`'s. + */ +export function recordFailedStartDispatchIdentity( + db: OrchestrationDb, + worker: WorkerDispatchRow +): void { + const resource = db.getWorkerTerminalResourceByOwner(worker.dispatch_id) + if (!resource || resource.terminal_handle !== worker.agent_terminal_handle) { + return + } + db.db + .prepare( + `UPDATE dispatch_contexts + SET assignee_handle = ?, assignee_pane_key = ?, process_incarnation = ?, host_scope = ? + WHERE id = ? AND status = 'failed' AND capability_hash IS NULL` + ) + .run( + resource.terminal_handle, + resource.pane_key, + resource.process_incarnation, + resource.host_scope, + worker.dispatch_id + ) +} diff --git a/src/main/runtime/orchestration/db/worker-terminal/failed-start-terminal-adoption.ts b/src/main/runtime/orchestration/db/worker-terminal/failed-start-terminal-adoption.ts deleted file mode 100644 index 607ae9f45a7..00000000000 --- a/src/main/runtime/orchestration/db/worker-terminal/failed-start-terminal-adoption.ts +++ /dev/null @@ -1,68 +0,0 @@ -import type { WorkerDispatchRow } from '../../types' -import type { OrchestrationDb } from '../orchestration-db' - -/** Identity of a terminal this worker-start created and never handed to an owner. */ -export type FailedStartTerminalAdoption = { - terminalHandle: string - worktreeId: string | null - paneKey: string - processIncarnation: string - hostScope?: string | null -} - -/** - * A start that dies before `prepareStartingWorkerAuthority` leaves the terminal it created with no - * owner, so no release path can ever close it and the fleet can only say `inspect`. Record the - * ownership the successful path would have recorded, so ordinary `worker-release` owns the cleanup. - * - * No transaction: composes inside `failWorkerStart`'s. - */ -export function adoptFailedStartTerminal( - db: OrchestrationDb, - worker: WorkerDispatchRow, - adoption: FailedStartTerminalAdoption | undefined -): void { - if (!adoption || worker.agent_terminal_handle !== adoption.terminalHandle) { - return - } - if (db.getWorkerTerminalResourceByOwner(worker.dispatch_id)) { - return - } - // A second owner for one process could close it twice, or close a terminal already handed on. - const conflict = db.db - .prepare( - `SELECT 1 FROM worker_terminal_resources - WHERE ownership_state <> 'released' - AND (terminal_handle = ? OR process_incarnation = ?) LIMIT 1` - ) - .get(adoption.terminalHandle, adoption.processIncarnation) - if (conflict) { - return - } - db.createWorkerTerminalResourceStatement({ - dispatchId: worker.dispatch_id, - worktreeId: adoption.worktreeId ?? worker.worktree_id, - terminalHandle: adoption.terminalHandle, - paneKey: adoption.paneKey, - processIncarnation: adoption.processIncarnation, - endpointId: worker.runtime_epoch ?? null, - endpointIncarnation: adoption.processIncarnation, - hostScope: adoption.hostScope ?? null, - ownership: 'owned' - }) - // Release re-proves identity through the Dispatch context, which a failed start never filled in. - // This records which pane the Dispatch owns; `capability_hash` stays null, so it grants nothing. - db.db - .prepare( - `UPDATE dispatch_contexts - SET assignee_handle = ?, assignee_pane_key = ?, process_incarnation = ?, host_scope = ? - WHERE id = ? AND status = 'failed' AND capability_hash IS NULL` - ) - .run( - adoption.terminalHandle, - adoption.paneKey, - adoption.processIncarnation, - adoption.hostScope ?? null, - worker.dispatch_id - ) -} diff --git a/src/main/runtime/orchestration/db/worker-terminal/worker-terminal-resource-store.ts b/src/main/runtime/orchestration/db/worker-terminal/worker-terminal-resource-store.ts index 1d7232107b1..e6942503dbf 100644 --- a/src/main/runtime/orchestration/db/worker-terminal/worker-terminal-resource-store.ts +++ b/src/main/runtime/orchestration/db/worker-terminal/worker-terminal-resource-store.ts @@ -2,6 +2,7 @@ import type { WorkerTerminalResourceRow, WorkerTerminalOwnershipState } from '../../worker-terminal-ownership' +import { WORKER_SETTLED_STATES } from '../../worker-terminal-ownership' import { OrchestrationError } from '../../orchestration-error' import { generateId } from '../generated-id' import type { OrchestrationDb } from '../orchestration-db' @@ -199,9 +200,40 @@ export function transferWorkerTerminalResourceStatement( return this.getWorkerTerminalResource(params.resourceId) as WorkerTerminalResourceRow } +// A new process in the same pane is ordinary user work, not the settled Dispatch's resource. +export function retainReplacedWorkerTerminalResources( + this: OrchestrationDb, + params: { paneKey: string; worktreeId: string; hostScope: string; processIncarnation: string } +): number { + return Number( + this.db + .prepare( + `UPDATE worker_terminal_resources + SET release_state = 'retained', retained_reason = 'identity_unproven', + updated_at = datetime('now') + WHERE pane_key = ? AND worktree_id = ? AND host_scope = ? + AND process_incarnation IS NOT NULL AND process_incarnation != ? + AND ownership_state = 'owned' AND release_state = 'not_requested' + AND EXISTS ( + SELECT 1 FROM worker_dispatches w + WHERE w.dispatch_id = worker_terminal_resources.owner_dispatch_id + AND w.state IN (${WORKER_SETTLED_STATES.map(() => '?').join(', ')}) + )` + ) + .run( + params.paneKey, + params.worktreeId, + params.hostScope, + params.processIncarnation, + ...WORKER_SETTLED_STATES + ).changes + ) +} + // Finds an owned, settled, exact-match resource for an explicitly reused terminal. export type WorkerTerminalResourceStoreMethods = { + retainReplacedWorkerTerminalResources: typeof retainReplacedWorkerTerminalResources backfillWorkerTerminalResources: typeof backfillWorkerTerminalResources createWorkerTerminalResourceStatement: typeof createWorkerTerminalResourceStatement getWorkerTerminalResource: typeof getWorkerTerminalResource @@ -214,6 +246,7 @@ export type WorkerTerminalResourceStoreMethods = { export function attachWorkerTerminalResourceStore(ctor: { prototype: object }): void { Object.assign(ctor.prototype, { + retainReplacedWorkerTerminalResources, backfillWorkerTerminalResources, createWorkerTerminalResourceStatement, getWorkerTerminalResource, diff --git a/src/main/runtime/orchestration/db/writer-run-required.test.ts b/src/main/runtime/orchestration/db/writer-run-required.test.ts new file mode 100644 index 00000000000..21fcbeb28d6 --- /dev/null +++ b/src/main/runtime/orchestration/db/writer-run-required.test.ts @@ -0,0 +1,40 @@ +import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest' +import { OrchestrationDb } from './orchestration-db' + +describe('writers require a Run', () => { + let db: OrchestrationDb + beforeEach(() => { + db = new OrchestrationDb(':memory:') + }) + afterEach(() => db.close()) + + it('rejects a message without a Run instead of using the legacy Run', () => { + expect(() => db.insertMessage({ from: 'sender', to: 'worker', subject: 'mail' })).toThrow( + 'Run is required' + ) + expect(db.db.prepare('SELECT id FROM messages').all()).toEqual([]) + }) + + it('rejects a Task without a Run instead of using the legacy Run', () => { + expect(() => db.createTask({ spec: 'work' })).toThrow('Run is required') + expect(db.listTasks()).toEqual([]) + }) + + it('rejects a decision gate whose Task has no Run', () => { + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) + vi.spyOn(db, 'getTask').mockReturnValue({ ...task, run_id: undefined } as never) + expect(() => db.createGate({ taskId: task.id, question: 'Proceed?' })).toThrow() + expect(db.listGates()).toEqual([]) + }) + + it('rejects a decision gate without a Task before writing', () => { + db.db.exec(` + CREATE TRIGGER reject_gate_insert BEFORE INSERT ON decision_gates + BEGIN SELECT RAISE(ABORT, 'gate insert reached'); END; + `) + expect(() => db.createGate({ taskId: 'missing', question: 'Proceed?' })).toThrow( + 'Task missing was not found while creating a decision gate.' + ) + expect(db.listGates()).toEqual([]) + }) +}) diff --git a/src/main/runtime/orchestration/dispatch-failure-idempotency.test.ts b/src/main/runtime/orchestration/dispatch-failure-idempotency.test.ts index c6f75723cf3..5704db1490e 100644 --- a/src/main/runtime/orchestration/dispatch-failure-idempotency.test.ts +++ b/src/main/runtime/orchestration/dispatch-failure-idempotency.test.ts @@ -6,7 +6,7 @@ import { createRootDispatch } from './db/root-dispatch-test-fixture' describe('dispatch failure idempotency', () => { it('counts an active dispatch failure only once', () => { const db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_worker') expect(db.failDispatch(dispatch.id, 'exit')?.failure_count).toBe(1) @@ -19,7 +19,7 @@ describe('dispatch failure idempotency', () => { it('does not overwrite a completed dispatch', () => { const db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_worker') db.completeDispatch(dispatch.id) @@ -33,7 +33,7 @@ describe('dispatch failure idempotency', () => { it('rolls back the dispatch when the task update fails', () => { const db = new OrchestrationDb(':memory:') const sqlite = (db as unknown as { db: Database.Database }).db - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_worker') sqlite.exec(` CREATE TRIGGER reject_task_failure_update diff --git a/src/main/runtime/orchestration/failed-start-terminal-adoption.test.ts b/src/main/runtime/orchestration/failed-start-terminal-adoption.test.ts deleted file mode 100644 index d38248f9cb8..00000000000 --- a/src/main/runtime/orchestration/failed-start-terminal-adoption.test.ts +++ /dev/null @@ -1,157 +0,0 @@ -import { afterEach, describe, expect, it } from 'vitest' -import { OrchestrationDb } from './db' - -const HANDLE = 'term_residual' -const PANE_KEY = 'tab_residual:leaf_residual' -const INCARNATION = 'runtime:pty-residual:1' - -describe('a start that fails before authority still owns the terminal it created', () => { - let db: OrchestrationDb | undefined - - afterEach(() => { - db?.close() - }) - - /** Replays the shipping order: readiness stage records the handle, then the wait fails. */ - function failStartAfterCreatingTerminal( - adoption?: Parameters[3] - ): { db: OrchestrationDb; dispatchId: string } { - const d = (db = new OrchestrationDb(':memory:')) - const task = d.createTask({ spec: 'residual terminal' }) - const started = d.createStartingWorkerDispatch({ - creator: { kind: 'system' }, - maxDepth: Number.MAX_SAFE_INTEGER, - taskId: task.id, - startOptions: {} - }) - const effects = [ - { kind: 'terminal', role: 'agent', action: 'created', id: HANDLE, surface: 'visible' } - ] - d.recordWorkerStage({ - dispatchId: started.dispatch.id, - stage: 'terminal_readying', - worktreeId: 'repo::worktree', - terminalHandle: HANDLE, - effects, - residualResources: effects - }) - d.failWorkerStart( - started.dispatch.id, - 'agent_readiness', - 'Agent startup blocked: codex-interactive-prompt', - adoption - ) - return { db: d, dispatchId: started.dispatch.id } - } - - const adoption = { - adoptResidualTerminal: { - terminalHandle: HANDLE, - worktreeId: 'repo::worktree', - paneKey: PANE_KEY, - processIncarnation: INCARNATION, - hostScope: null - } - } - - it('leaves nothing that can close the terminal when the start is not adopted', () => { - const { db: d, dispatchId } = failStartAfterCreatingTerminal() - - expect(d.getWorkerTerminalResourceByOwner(dispatchId)).toBeUndefined() - expect(d.requestWorkerTerminalRelease(dispatchId)).toMatchObject({ - disposition: 'retained', - reason: 'no_owned_resource' - }) - }) - - it('records the ownership the successful path would have recorded', () => { - const { db: d, dispatchId } = failStartAfterCreatingTerminal(adoption) - - expect(d.getWorkerTerminalResourceByOwner(dispatchId)).toMatchObject({ - owner_dispatch_id: dispatchId, - terminal_handle: HANDLE, - pane_key: PANE_KEY, - process_incarnation: INCARNATION, - ownership_state: 'owned', - release_state: 'not_requested' - }) - }) - - it('lets worker-release proceed on the failed dispatch', () => { - const { db: d, dispatchId } = failStartAfterCreatingTerminal(adoption) - - expect(d.requestWorkerTerminalRelease(dispatchId)).toMatchObject({ - disposition: 'requested', - resource: { release_state: 'requested' } - }) - }) - - it('re-proves identity through the dispatch context release reads', () => { - const { db: d, dispatchId } = failStartAfterCreatingTerminal(adoption) - - expect( - d.isDispatchProcessCurrent({ dispatchId, paneKey: PANE_KEY, processIncarnation: INCARNATION }) - ).toBe(true) - // Adoption records which pane the dispatch owns; it never restores authority over it. - expect(d.getDispatchContextById(dispatchId)).toMatchObject({ - status: 'failed', - capability_hash: null - }) - expect(d.getDispatchContextById(dispatchId)?.capability_revoked_at).not.toBeNull() - }) - - it('publishes the terminal as reclaimable so the fleet names release', () => { - const { db: d, dispatchId } = failStartAfterCreatingTerminal(adoption) - - expect(d.listWorkerTerminalResources({ dispatchIds: [dispatchId] })[0]).toMatchObject({ - agentTerminalHandle: HANDLE, - terminalState: 'reclaimable' - }) - }) - - it('never claims a terminal the durable row does not name', () => { - const { db: d, dispatchId } = failStartAfterCreatingTerminal({ - adoptResidualTerminal: { ...adoption.adoptResidualTerminal, terminalHandle: 'term_other' } - }) - - expect(d.getWorkerTerminalResourceByOwner(dispatchId)).toBeUndefined() - }) - - it('never claims a terminal another live resource already accounts for', () => { - const d = (db = new OrchestrationDb(':memory:')) - const first = d.createStartingWorkerDispatch({ - creator: { kind: 'system' }, - maxDepth: Number.MAX_SAFE_INTEGER, - taskId: d.createTask({ spec: 'owner' }).id, - startOptions: {} - }) - d.prepareStartingWorkerAuthority({ - dispatchId: first.dispatch.id, - handle: HANDLE, - paneKey: PANE_KEY, - processIncarnation: INCARNATION, - worktreeId: 'repo::worktree', - setupState: 'not_applicable', - effects: [], - terminalOwnership: 'created' - }) - const second = d.createStartingWorkerDispatch({ - creator: { kind: 'system' }, - maxDepth: Number.MAX_SAFE_INTEGER, - taskId: d.createTask({ spec: 'claimant' }).id, - startOptions: {} - }) - d.recordWorkerStage({ - dispatchId: second.dispatch.id, - stage: 'terminal_readying', - terminalHandle: HANDLE - }) - - d.failWorkerStart(second.dispatch.id, 'agent_readiness', 'blocked', adoption) - - expect(d.getWorkerTerminalResourceByOwner(second.dispatch.id)).toBeUndefined() - expect(d.getWorkerTerminalResourceByOwner(first.dispatch.id)).toMatchObject({ - ownership_state: 'owned' - }) - }) -}) diff --git a/src/main/runtime/orchestration/federation-acknowledgment-integrity.test.ts b/src/main/runtime/orchestration/federation-acknowledgment-integrity.test.ts index fd8e32d1a32..e5c452f91a1 100644 --- a/src/main/runtime/orchestration/federation-acknowledgment-integrity.test.ts +++ b/src/main/runtime/orchestration/federation-acknowledgment-integrity.test.ts @@ -14,6 +14,7 @@ describe('federation acknowledgment integrity', () => { db = new OrchestrationDb(':memory:') const dispatchId = `ctx_protocol_${protocolVersion}` db.createRemoteDispatchAttachment({ + runId: 'run-home', dispatchId, taskId: `task_protocol_${protocolVersion}`, homePeerFingerprint: 'home_peer', diff --git a/src/main/runtime/orchestration/federation-control-message.ts b/src/main/runtime/orchestration/federation-control-message.ts index bcab04f99b8..2d86ef3c67b 100644 --- a/src/main/runtime/orchestration/federation-control-message.ts +++ b/src/main/runtime/orchestration/federation-control-message.ts @@ -58,11 +58,20 @@ export function importFederatedControlMessage( payload: string } ): { imported: boolean; type: MessageType } { + const attachment = db.getRemoteDispatchAttachment(params.dispatchId) + if (!attachment) { + throw new OrchestrationError( + 'dispatch_not_found', + `Remote Dispatch ${params.dispatchId} was not found.` + ) + } + db.requireRun(attachment.home_run_id) const message = parseFederatedControlMessage(params.payload) const recipient = `dispatch:${params.dispatchId}` const existing = db.getMessageById(params.messageId) if (existing) { if ( + existing.run_id !== attachment.home_run_id || existing.to_handle !== recipient || existing.from_handle !== message.from || existing.subject !== message.subject || @@ -81,6 +90,7 @@ export function importFederatedControlMessage( } db.insertMessage({ id: params.messageId, + runId: attachment.home_run_id, from: message.from, to: recipient, subject: message.subject, diff --git a/src/main/runtime/orchestration/lifecycle-caller-edges.test.ts b/src/main/runtime/orchestration/lifecycle-caller-edges.test.ts index 3bc2eee4ae9..7f445388a25 100644 --- a/src/main/runtime/orchestration/lifecycle-caller-edges.test.ts +++ b/src/main/runtime/orchestration/lifecycle-caller-edges.test.ts @@ -109,7 +109,10 @@ describe('lifecycle graph against its callers', () => { it('settles a stopping worker whose PTY exits during the stop', () => { const database = createDatabase() - const task = database.createTask({ spec: 'stopping exited worker' }) + const task = database.createTask({ + runId: 'run_legacy_local', + spec: 'stopping exited worker' + }) const dispatchId = startWorker(database, task.id, 'stopping_exited') expect(database.beginWorkerStop(dispatchId, 'runtime_test').disposition).toBe('stopping') @@ -127,9 +130,18 @@ describe('lifecycle graph against its callers', () => { it('still lets a coordinator reopen or overturn a settled Task', () => { const database = createDatabase() - const reopened = database.createTask({ spec: 'reopen me' }) - const overturned = database.createTask({ spec: 'overturn me' }) - const retried = database.createTask({ spec: 'retry me' }) + const reopened = database.createTask({ + runId: 'run_legacy_local', + spec: 'reopen me' + }) + const overturned = database.createTask({ + runId: 'run_legacy_local', + spec: 'overturn me' + }) + const retried = database.createTask({ + runId: 'run_legacy_local', + spec: 'retry me' + }) database.updateTaskStatus(reopened.id, 'completed', 'first result') database.updateTaskStatus(overturned.id, 'completed', 'wrong result') database.updateTaskStatus(retried.id, 'failed', 'boom') diff --git a/src/main/runtime/orchestration/lifecycle-reconciliation.test.ts b/src/main/runtime/orchestration/lifecycle-reconciliation.test.ts index 3f0f0a7664f..dedea449629 100644 --- a/src/main/runtime/orchestration/lifecycle-reconciliation.test.ts +++ b/src/main/runtime/orchestration/lifecycle-reconciliation.test.ts @@ -10,10 +10,11 @@ describe('lifecycle reconciliation', () => { it('rejects handle churn when neither side has stable pane identity', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_before_restart') const logs: string[] = [] const message = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_after_restart', to: 'term_coordinator', subject: 'Done', @@ -37,9 +38,10 @@ describe('lifecycle reconciliation', () => { it('completes worker_done from the dispatched pane after a handle remint', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_before_restart', `tab_w:${LEAF_A}`) const message = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_after_restart', to: 'term_coordinator', subject: 'Done', @@ -54,7 +56,7 @@ describe('lifecycle reconciliation', () => { it('completes an exact-authority worker_done after an uncertain worker start', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const started = db.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -82,6 +84,7 @@ describe('lifecycle reconciliation', () => { ).toEqual({ valid: true }) const message = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_worker', to: 'term_coordinator', subject: 'Done after reconnect', @@ -106,9 +109,10 @@ describe('lifecycle reconciliation', () => { it('fails both the dispatch and task from an authenticated failed worker report', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_worker', `tab_w:${LEAF_A}`) const message = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_worker', to: 'term_coordinator', subject: 'Failed: tests cannot start', @@ -139,7 +143,7 @@ describe('lifecycle reconciliation', () => { it('keeps worker report settlement nested in its caller transaction', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_worker') db.db.exec('BEGIN IMMEDIATE') @@ -160,19 +164,16 @@ describe('lifecycle reconciliation', () => { it('replays an identical terminal outcome without mutating settled state', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_worker') const makeMessage = () => db.insertMessage({ + runId: 'run_legacy_local', from: 'term_worker', to: 'term_coordinator', subject: 'Done', type: 'worker_done', - payload: JSON.stringify({ - taskId: task.id, - dispatchId: dispatch.id, - outcome: 'succeeded' - }) + payload: JSON.stringify({ taskId: task.id, dispatchId: dispatch.id, outcome: 'succeeded' }) }) expect(reconcileLifecycleMessage(db, makeMessage()).action).toBe('completed') @@ -199,6 +200,7 @@ describe('lifecycle reconciliation', () => { ])('rejects malformed worker reports with $code', ({ payload, code }) => { db = new OrchestrationDb(':memory:') const message = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_worker', to: 'term_coordinator', subject: 'Done', @@ -215,11 +217,12 @@ describe('lifecycle reconciliation', () => { it('completes worker_done from the same leaf after a pane break-out changed the tab half', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) // Dispatch recorded the post-break-out pane key; the worker shell still // holds the spawn-time key with the old tab id. const dispatch = createRootDispatch(db, task.id, 'term_before_restart', `tab_new:${LEAF_A}`) const message = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_after_restart', to: 'term_coordinator', subject: 'Done', @@ -234,9 +237,10 @@ describe('lifecycle reconciliation', () => { it('rejects mismatched opaque pane keys instead of treating them as legacy', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_owner', `tab_w:${LEAF_A}`) const message = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_reminted', to: 'term_coordinator', subject: 'Done', @@ -251,9 +255,10 @@ describe('lifecycle reconciliation', () => { it('rejects worker_done from a foreign pane that claims the assignee handle', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_owner', `tab_w1:${LEAF_A}`) const message = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_owner', to: 'term_coordinator', subject: 'Done', @@ -294,9 +299,10 @@ describe('lifecycle reconciliation', () => { it('does not let a caller-supplied rejection marker turn completion into success', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_worker', `tab_w:${LEAF_A}`) const message = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_worker', to: 'term_coordinator', subject: 'Done', @@ -323,9 +329,10 @@ describe('lifecycle reconciliation', () => { it('rejects a coordinator completion for a pane-bound dispatch', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_worker', `tab_w:${LEAF_A}`) const message = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_coordinator', to: 'term_coordinator', subject: 'Done', @@ -342,9 +349,13 @@ describe('lifecycle reconciliation', () => { it('uses exact handle equality only for a legacy dispatch without a pane key', () => { db = new OrchestrationDb(':memory:') - const acceptedTask = db.createTask({ spec: 'legacy work' }) + const acceptedTask = db.createTask({ + runId: 'run_legacy_local', + spec: 'legacy work' + }) const acceptedDispatch = createRootDispatch(db, acceptedTask.id, 'term_legacy') const accepted = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_legacy', to: 'term_coordinator', subject: 'Done', @@ -357,9 +368,13 @@ describe('lifecycle reconciliation', () => { }) expect(reconcileLifecycleMessage(db, accepted).action).toBe('completed') - const rejectedTask = db.createTask({ spec: 'other legacy work' }) + const rejectedTask = db.createTask({ + runId: 'run_legacy_local', + spec: 'other legacy work' + }) const rejectedDispatch = createRootDispatch(db, rejectedTask.id, 'term_other_legacy') const rejected = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_foreign', to: 'term_coordinator', subject: 'Done', @@ -379,8 +394,12 @@ describe('lifecycle reconciliation', () => { it('does not release a dependent when a foreign completion wins the arrival race', () => { db = new OrchestrationDb(':memory:') - const parent = db.createTask({ spec: 'parent' }) - const child = db.createTask({ spec: 'child', deps: [parent.id] }) + const parent = db.createTask({ runId: 'run_legacy_local', spec: 'parent' }) + const child = db.createTask({ + runId: 'run_legacy_local', + spec: 'child', + deps: [parent.id] + }) const dispatch = createRootDispatch(db, parent.id, 'term_worker', `tab_w:${LEAF_A}`) const payload = JSON.stringify({ taskId: parent.id, @@ -389,6 +408,7 @@ describe('lifecycle reconciliation', () => { }) const foreign = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_coordinator', to: 'term_coordinator', subject: 'Done', @@ -403,6 +423,7 @@ describe('lifecycle reconciliation', () => { expect(db.getTask(child.id)?.status).toBe('pending') const owner = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_worker_reminted', to: 'term_coordinator', subject: 'Done', @@ -416,7 +437,7 @@ describe('lifecycle reconciliation', () => { it('does not let a foreign replay overwrite an authorized completion', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_worker', `tab_w:${LEAF_A}`) const payload = JSON.stringify({ taskId: task.id, @@ -424,6 +445,7 @@ describe('lifecycle reconciliation', () => { outcome: 'succeeded' }) const owner = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_worker', to: 'term_coordinator', subject: 'Done', @@ -435,6 +457,7 @@ describe('lifecycle reconciliation', () => { const result = db.getTask(task.id)?.result const replay = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_foreign', to: 'term_coordinator', subject: 'Forged replay', @@ -451,10 +474,11 @@ describe('lifecycle reconciliation', () => { it('surfaces worker_done sent from a different pane as rejected', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_owner', `tab_w1:${LEAF_A}`) const logs: string[] = [] const message = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_other_worker', to: 'term_coordinator', subject: 'Done', @@ -474,9 +498,10 @@ describe('lifecycle reconciliation', () => { it('surfaces a heartbeat sent from a different pane without recording liveness', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_owner', `tab_w1:${LEAF_A}`) const heartbeat = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_other_worker', to: 'term_coordinator', subject: 'alive', @@ -508,9 +533,10 @@ describe('lifecycle reconciliation', () => { it('surfaces a foreign heartbeat that claims the assignee handle', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_owner', `tab_w1:${LEAF_A}`) const heartbeat = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_owner', to: 'term_coordinator', subject: 'alive', @@ -528,9 +554,10 @@ describe('lifecycle reconciliation', () => { it('records a heartbeat whose pane key drifted only in the tab half', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_owner', `tab_new:${LEAF_A}`) const heartbeat = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_owner', to: 'term_coordinator', subject: 'alive', @@ -548,12 +575,16 @@ describe('lifecycle reconciliation', () => { it('suppresses same-dispatch heartbeats once worker_done is reconciled', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'work' }) const dispatch = createRootDispatch(db, task.id, 'term_worker') - const otherTask = db.createTask({ spec: 'other work' }) + const otherTask = db.createTask({ + runId: 'run_legacy_local', + spec: 'other work' + }) const otherDispatch = createRootDispatch(db, otherTask.id, 'term_other') const insertHeartbeat = (dispatchId: string, from: string) => db.insertMessage({ + runId: 'run_legacy_local', from, to: 'term_coordinator', subject: 'alive', @@ -565,6 +596,7 @@ describe('lifecycle reconciliation', () => { reconcileLifecycleMessage(db, staleHeartbeat) reconcileLifecycleMessage(db, otherHeartbeat) const done = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_worker', to: 'term_coordinator', subject: 'Done', diff --git a/src/main/runtime/orchestration/lightweight-run-worker-exit-escalation.test.ts b/src/main/runtime/orchestration/lightweight-run-worker-exit-escalation.test.ts index 2b8d9c90bc2..d37e379e1c5 100644 --- a/src/main/runtime/orchestration/lightweight-run-worker-exit-escalation.test.ts +++ b/src/main/runtime/orchestration/lightweight-run-worker-exit-escalation.test.ts @@ -412,7 +412,7 @@ describe('STA-4604 worker PTY exit escalation reaches the coordinator', () => { } }) - it('falls back to the legacy gate when the dispatch owning Run row is gone', async () => { + it('preserves the dispatch Run when legacy coordinator routing is used', async () => { const { runtime, workerHandle, coordinatorHandle } = makeRuntimeWithTwoPanes() const insertMessage = vi.fn((message: { to: string }) => ({ ...message, @@ -435,8 +435,7 @@ describe('STA-4604 worker PTY exit escalation reaches the coordinator', () => { expect(insertMessage).toHaveBeenCalledWith( expect.objectContaining({ to: coordinatorHandle, type: 'escalation' }) ) - // An orphaned dispatch has no Run mailbox to address, so it must not invent one. - expect(insertMessage.mock.calls[0]?.[0]).not.toHaveProperty('runId') + expect(insertMessage.mock.calls[0]?.[0]).toHaveProperty('runId', 'run-that-no-longer-exists') }) it('still reaches the Run mailbox when the Run has no bound coordinator', async () => { diff --git a/src/main/runtime/orchestration/mailbox-pointer-eligibility.test.ts b/src/main/runtime/orchestration/mailbox-pointer-eligibility.test.ts index 87b090e4e48..2276665fc1c 100644 --- a/src/main/runtime/orchestration/mailbox-pointer-eligibility.test.ts +++ b/src/main/runtime/orchestration/mailbox-pointer-eligibility.test.ts @@ -15,9 +15,9 @@ const MAILBOX = 'dispatch:d1' function seeded(): OrchestrationDb { const db = new OrchestrationDb(':memory:') db.insertMessages([ - { from: 'coordinator', to: MAILBOX, subject: 'a', type: 'status' }, - { from: 'coordinator', to: MAILBOX, subject: 'b', type: 'question' }, - { from: 'coordinator', to: MAILBOX, subject: 'c', type: 'status' } + { runId: 'run_legacy_local', from: 'coordinator', to: MAILBOX, subject: 'a', type: 'status' }, + { runId: 'run_legacy_local', from: 'coordinator', to: MAILBOX, subject: 'b', type: 'question' }, + { runId: 'run_legacy_local', from: 'coordinator', to: MAILBOX, subject: 'c', type: 'status' } ]) return db } diff --git a/src/main/runtime/orchestration/mailbox-pointer-stage.test.ts b/src/main/runtime/orchestration/mailbox-pointer-stage.test.ts index 9573f02fc0c..d76a480ecfd 100644 --- a/src/main/runtime/orchestration/mailbox-pointer-stage.test.ts +++ b/src/main/runtime/orchestration/mailbox-pointer-stage.test.ts @@ -59,7 +59,12 @@ function stageArgs(db: OrchestrationDb, state: OrchestrationMailboxPointerState) describe('mailbox pointer staging watermark', () => { it('leaves no watermark when the reservation claim is lost', () => { const db = new OrchestrationDb(':memory:') - const message = db.insertMessage({ from: 'a', to: 'run:run-1', subject: 's' }) + const message = db.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'run:run-1', + subject: 's' + }) // A concurrent flight already owns the reservation, so this claim cannot succeed. expect( db.stageMailboxPointerEnter([message.id], { ptyId: 'other-pty', processIncarnation: 'inc-x' }) @@ -79,7 +84,12 @@ describe('mailbox pointer staging watermark', () => { it('leaves no watermark when the reservation write throws', () => { const db = new OrchestrationDb(':memory:') - const message = db.insertMessage({ from: 'a', to: 'run:run-1', subject: 's' }) + const message = db.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'run:run-1', + subject: 's' + }) const throwing = new Proxy(db, { get(target, prop, receiver) { if (prop === 'markMailboxPointerWriteAttempted') { @@ -107,7 +117,12 @@ describe('mailbox pointer staging watermark', () => { it('keeps the watermark for the flight that owns the reservation', () => { const db = new OrchestrationDb(':memory:') - const message = db.insertMessage({ from: 'a', to: 'run:run-1', subject: 's' }) + const message = db.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'run:run-1', + subject: 's' + }) const state = new OrchestrationMailboxPointerState() const args = stageArgs(db, state) stageOrchestrationMailboxPointer({ @@ -122,7 +137,12 @@ describe('mailbox pointer staging watermark', () => { it('drains a delivery parked behind the watermark when the write is refused', () => { const db = new OrchestrationDb(':memory:') - const message = db.insertMessage({ from: 'a', to: 'run:run-1', subject: 's' }) + const message = db.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'run:run-1', + subject: 's' + }) const state = new OrchestrationMailboxPointerState() const args = stageArgs(db, state) const redrive = vi.fn() @@ -148,7 +168,7 @@ describe('mailbox pointer staging watermark', () => { it('still points new mail after a delivery lost its reservation claim', async () => { const db = new OrchestrationDb(':memory:') - db.insertMessage({ from: 'a', to: 'run:run-1', subject: 'first' }) + db.insertMessage({ runId: 'run_legacy_local', from: 'a', to: 'run:run-1', subject: 'first' }) let stealNextClaim = true const contended = new Proxy(db, { get(target, prop, receiver) { @@ -172,7 +192,7 @@ describe('mailbox pointer staging watermark', () => { expect(writePty).not.toHaveBeenCalled() // Newer mail must still reach the agent; a leaked watermark used to park it forever. - db.insertMessage({ from: 'a', to: 'run:run-1', subject: 'second' }) + db.insertMessage({ runId: 'run_legacy_local', from: 'a', to: 'run:run-1', subject: 'second' }) delivery.deliver(LEAF, { mailboxHandle: 'run:run-1', skipAbsenceProbe: true }) await new Promise((resolve) => setImmediate(resolve)) diff --git a/src/main/runtime/orchestration/mailbox-pointer-submit.test.ts b/src/main/runtime/orchestration/mailbox-pointer-submit.test.ts index 00126bc237b..02d556204df 100644 --- a/src/main/runtime/orchestration/mailbox-pointer-submit.test.ts +++ b/src/main/runtime/orchestration/mailbox-pointer-submit.test.ts @@ -14,7 +14,12 @@ import type { WriteSettlement } from '../../../shared/pty-write-settlement' describe('orchestration mailbox pointer submit', () => { it('does not settle a replacement reservation after an old Enter write resolves', async () => { const db = new OrchestrationDb(':memory:') - const message = db.insertMessage({ from: 'a', to: 'run:run-1', subject: 'staged' }) + const message = db.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'run:run-1', + subject: 'staged' + }) const ptyId = 'pty-reused' const oldReservation = { ptyId, processIncarnation: 'inc-old' } const replacementReservation = { ptyId, processIncarnation: 'inc-new' } @@ -86,8 +91,18 @@ describe('orchestration mailbox pointer submit', () => { it('does not overwrite a message already reserved by another pointer flight', () => { const db = new OrchestrationDb(':memory:') - const first = db.insertMessage({ from: 'a', to: 'run:run-1', subject: 'first' }) - const second = db.insertMessage({ from: 'a', to: 'run:run-1', subject: 'second' }) + const first = db.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'run:run-1', + subject: 'first' + }) + const second = db.insertMessage({ + runId: 'run_legacy_local', + from: 'a', + to: 'run:run-1', + subject: 'second' + }) const original = { ptyId: 'pty-a', processIncarnation: 'inc-a' } const replacement = { ptyId: 'pty-b', processIncarnation: 'inc-b' } diff --git a/src/main/runtime/orchestration/message-batch-atomicity.test.ts b/src/main/runtime/orchestration/message-batch-atomicity.test.ts index f2e43ed31e4..fda83fad9a9 100644 --- a/src/main/runtime/orchestration/message-batch-atomicity.test.ts +++ b/src/main/runtime/orchestration/message-batch-atomicity.test.ts @@ -108,8 +108,20 @@ describe('message batch atomicity', () => { expect(() => db?.insertMessages([ - { id: 'inner_first', from: 'sender', to: 'recipient', subject: 'first' }, - { id: 'inner_second', from: 'sender', to: 'recipient', subject: 'second' } + { + runId: 'run_legacy_local', + id: 'inner_first', + from: 'sender', + to: 'recipient', + subject: 'first' + }, + { + runId: 'run_legacy_local', + id: 'inner_second', + from: 'sender', + to: 'recipient', + subject: 'second' + } ]) ).toThrow('blocked') sqlite.exec('COMMIT') @@ -133,6 +145,7 @@ describe('message batch atomicity', () => { expect(() => db?.commitWorkerDoneMessageMutation(() => { db?.insertMessage({ + runId: 'run_legacy_local', id: 'inner', from: 'worker', to: 'coordinator', diff --git a/src/main/runtime/orchestration/nested-worker-depth-migration.test.ts b/src/main/runtime/orchestration/nested-worker-depth-migration.test.ts index fa955b7cf08..9d05c0dac07 100644 --- a/src/main/runtime/orchestration/nested-worker-depth-migration.test.ts +++ b/src/main/runtime/orchestration/nested-worker-depth-migration.test.ts @@ -34,6 +34,7 @@ describe('nested worker depth migration (v30)', () => { const oldDb = new Database(dbPath) oldDb.exec('ALTER TABLE dispatch_contexts DROP COLUMN depth') oldDb.exec('ALTER TABLE remote_dispatch_attachments DROP COLUMN depth') + oldDb.exec('ALTER TABLE remote_dispatch_attachments DROP COLUMN home_run_id') oldDb.pragma('user_version = 29') oldDb .prepare( @@ -78,7 +79,7 @@ describe('nested worker depth migration (v30)', () => { ) .run() - const task = db.createTask({ spec: 'post-upgrade nesting attempt' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'post-upgrade nesting attempt' }) expect(() => db!.createDispatchContext({ taskId: task.id, diff --git a/src/main/runtime/orchestration/orchestration-adopted-run-binding.test.ts b/src/main/runtime/orchestration/orchestration-adopted-run-binding.test.ts index 800a7511451..d667267e0a6 100644 --- a/src/main/runtime/orchestration/orchestration-adopted-run-binding.test.ts +++ b/src/main/runtime/orchestration/orchestration-adopted-run-binding.test.ts @@ -47,11 +47,13 @@ function createAdoptedFixture(options: { settleWork: boolean }): AdoptedFixture const before = new OrchestrationDb(dbPath) const task = before.createTask({ + runId: 'run_legacy_local', spec: 'legacy assignment', createdByTerminalHandle: LEGACY_COORDINATOR_HANDLE }) const dispatch = createRootDispatch(before, task.id, LEGACY_WORKER_HANDLE, LEGACY_WORKER_PANE) const recovery = before.insertMessage({ + runId: 'run_legacy_local', from: LEGACY_WORKER_HANDLE, to: LEGACY_COORDINATOR_HANDLE, subject: 'recovered worker outcome', diff --git a/src/main/runtime/orchestration/orchestration-all-start-versions-migration.test.ts b/src/main/runtime/orchestration/orchestration-all-start-versions-migration.test.ts index b4c9281d89b..b62677e465b 100644 --- a/src/main/runtime/orchestration/orchestration-all-start-versions-migration.test.ts +++ b/src/main/runtime/orchestration/orchestration-all-start-versions-migration.test.ts @@ -36,7 +36,12 @@ describe('orchestration migration from every prior version stamp', () => { expect(reopened.db.pragma('user_version', { simple: true }), `reopen v${version}`).toBe( SCHEMA_VERSION ) - expect(() => reopened.createTask({ spec: `migration v${version}` })).not.toThrow() + expect(() => + reopened.createTask({ + runId: 'run_legacy_local', + spec: `migration v${version}` + }) + ).not.toThrow() reopened.close() } }) diff --git a/src/main/runtime/orchestration/orchestration-db-retention-pagination.test.ts b/src/main/runtime/orchestration/orchestration-db-retention-pagination.test.ts index 38eeca64337..c980b8fe02a 100644 --- a/src/main/runtime/orchestration/orchestration-db-retention-pagination.test.ts +++ b/src/main/runtime/orchestration/orchestration-db-retention-pagination.test.ts @@ -103,6 +103,7 @@ describe('OrchestrationDb bounded mutation receipts', () => { insertMutationReceipts(db, MUTATION_RECEIPT_MAX_ROWS, 'completed') db.createRemoteDispatchAttachment({ + runId: 'run-home', dispatchId: 'ctx_remote_pruned', taskId: 'task_remote_pruned', homePeerFingerprint: 'caller', @@ -131,6 +132,7 @@ describe('OrchestrationDb bounded mutation receipts', () => { expect(() => db!.createRemoteDispatchAttachment({ + runId: 'run-home', dispatchId: 'ctx_remote_overflow', taskId: 'task_remote_overflow', homePeerFingerprint: 'caller', @@ -151,7 +153,7 @@ describe('OrchestrationDb bounded mutation receipts', () => { it('guards atomic worker acceptance without changing task state', () => { db = new OrchestrationDb(':memory:') - const task = db.createTask({ spec: 'capacity check' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'capacity check' }) insertMutationReceipts(db, MUTATION_RECEIPT_MAX_ROWS, 'pending') expect(() => @@ -226,7 +228,10 @@ describe('OrchestrationDb dispatch assignee index migration', () => { tempDir = mkdtempSync(join(tmpdir(), 'orca-dispatch-index-migration-')) const dbPath = join(tempDir, 'orchestration.db') db = new OrchestrationDb(dbPath) - const task = db.createTask({ spec: 'indexed lookup' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'indexed lookup' + }) const dispatch = createRootDispatch(db, task.id, 'term_worker') db.close() db = undefined @@ -245,7 +250,9 @@ describe('OrchestrationDb dispatch assignee index migration', () => { db = new OrchestrationDb(dbPath) const sqlite = sqliteFor(db) expect(sqlite.pragma('user_version', { simple: true })).toBe(SCHEMA_VERSION) - expect(db.getDispatchContextById(dispatch.id)).toMatchObject({ assignee_handle: 'term_worker' }) + expect(db.getDispatchContextById(dispatch.id)).toMatchObject({ + assignee_handle: 'term_worker' + }) expect(db.getTask(task.id)).toMatchObject({ created_by_pane_key: null, created_by_process_incarnation: null, diff --git a/src/main/runtime/orchestration/orchestration-federated-legacy-probe.test.ts b/src/main/runtime/orchestration/orchestration-federated-legacy-probe.test.ts new file mode 100644 index 00000000000..ad08a7383f0 --- /dev/null +++ b/src/main/runtime/orchestration/orchestration-federated-legacy-probe.test.ts @@ -0,0 +1,97 @@ +import { mkdtempSync, rmSync } from 'node:fs' +import { tmpdir } from 'node:os' +import { join } from 'node:path' +import { afterEach, describe, expect, it } from 'vitest' +import { LEGACY_RUN_ID, OrchestrationDb } from './db' +import { SCHEMA_VERSION } from './db/contract-constants' +import { resolveOrchestrationMigrationStartVersion } from './orchestration-schema-version-skew' + +describe('federated mailbox legacy-adoption probe', () => { + let db: OrchestrationDb | undefined + let directory: string | undefined + + afterEach(() => { + db?.close() + if (directory) { + rmSync(directory, { recursive: true, force: true }) + } + }) + + function seedMailbox(handle: string, kind: 'message' | 'delivery'): string { + directory = mkdtempSync(join(tmpdir(), 'orca-federated-legacy-probe-')) + const path = join(directory, 'orchestration.db') + db = new OrchestrationDb(path) + db.db.exec(` + INSERT INTO remote_dispatch_attachments ( + dispatch_id, task_id, home_peer_fingerprint, home_run_id, runtime_epoch, state + ) VALUES ('ctx_remote', 'task_remote', 'peer_home', 'run_home', 'epoch', 'ready'); + `) + if (kind === 'message') { + db.db + .prepare( + `INSERT INTO messages ( + id, run_id, delivery_contract, from_handle, to_handle, subject, type + ) VALUES ('msg_probe', ?, 'current_delivery', 'term_home', ?, 'continue', 'dispatch')` + ) + .run(LEGACY_RUN_ID, handle) + } else { + db.db + .prepare( + `INSERT INTO deliveries (id, run_id, mailbox_handle, consumer_generation, message_ids) + VALUES ('delivery_probe', ?, ?, 0, '[]')` + ) + .run(LEGACY_RUN_ID, handle) + } + return path + } + + it.each(['message', 'delivery'] as const)( + 'does not replay adoption for a misfiled federated %s', + (kind) => { + const path = seedMailbox('dispatch:ctx_remote', kind) + expect( + resolveOrchestrationMigrationStartVersion(db!.db, SCHEMA_VERSION, SCHEMA_VERSION) + ).toBe(SCHEMA_VERSION) + db!.close() + db = new OrchestrationDb(path) + expect(db.getLegacyAdoption()).toBeUndefined() + if (kind === 'message') { + expect(db.getMessageById('msg_probe')).toMatchObject({ + run_id: LEGACY_RUN_ID, + delivery_contract: 'current_delivery' + }) + } else { + expect( + db.db.prepare("SELECT status FROM deliveries WHERE id = 'delivery_probe'").get() + ).toEqual({ + status: 'outstanding' + }) + } + } + ) + + it.each(['message', 'delivery'] as const)( + 'still replays adoption for a genuine legacy %s', + (kind) => { + const path = seedMailbox('term_legacy_coordinator', kind) + expect( + resolveOrchestrationMigrationStartVersion(db!.db, SCHEMA_VERSION, SCHEMA_VERSION) + ).toBe(6) + db!.close() + db = new OrchestrationDb(path) + expect(db.getLegacyAdoption()).toBeDefined() + if (kind === 'message') { + expect(db.getMessageById('msg_probe')).toMatchObject({ + run_id: db.getLegacyAdoption()!.adopted_run_id, + delivery_contract: 'legacy_direct' + }) + } else { + expect( + db.db.prepare("SELECT status FROM deliveries WHERE id = 'delivery_probe'").get() + ).toEqual({ + status: 'fenced' + }) + } + } + ) +}) diff --git a/src/main/runtime/orchestration/orchestration-legacy-storage-test-fixture.ts b/src/main/runtime/orchestration/orchestration-legacy-storage-test-fixture.ts index 4cdc8f5ee91..886f2383db5 100644 --- a/src/main/runtime/orchestration/orchestration-legacy-storage-test-fixture.ts +++ b/src/main/runtime/orchestration/orchestration-legacy-storage-test-fixture.ts @@ -54,6 +54,7 @@ export function createLegacyStorageCutoverFixture(): { }) const legacyTask = first.createTask({ + runId: 'run_legacy_local', spec: 'legacy', createdByTerminalHandle: 'term_legacy_coord' }) @@ -76,16 +77,19 @@ export function createLegacyStorageCutoverFixture(): { ) const legacyMessages = [ first.insertMessage({ + runId: 'run_legacy_local', from: 'term_legacy_coord', to: 'term_legacy_worker', subject: 'read worker mail' }), first.insertMessage({ + runId: 'run_legacy_local', from: 'term_legacy_worker', to: 'term_legacy_coord', subject: 'read coordinator mail' }), first.insertMessage({ + runId: 'run_legacy_local', from: 'term_legacy_coord', to: 'term_legacy_worker', subject: 'second worker page' @@ -99,6 +103,7 @@ export function createLegacyStorageCutoverFixture(): { question: 'Retained question?' }) const rejection = first.insertMessage({ + runId: 'run_legacy_local', from: 'term_legacy_worker', to: 'term_legacy_coord', subject: 'Rejected heartbeat', @@ -106,6 +111,7 @@ export function createLegacyStorageCutoverFixture(): { payload: JSON.stringify({ _orcaLifecycleRejection: { code: 'migration', reason: 'cutover' } }) }) const lookalike = first.insertMessage({ + runId: 'run_legacy_local', from: 'term_legacy_worker', to: 'term_legacy_coord', subject: 'Ordinary legacy mail', @@ -115,36 +121,42 @@ export function createLegacyStorageCutoverFixture(): { }) const malformedRejections = [ first.insertMessage({ + runId: 'run_legacy_local', from: 'term_legacy_worker', to: 'term_legacy_coord', subject: 'Invalid JSON marker', payload: '{"_orcaLifecycleRejection":' }), first.insertMessage({ + runId: 'run_legacy_local', from: 'term_legacy_worker', to: 'term_legacy_coord', subject: 'Array marker', payload: JSON.stringify({ _orcaLifecycleRejection: [] }) }), first.insertMessage({ + runId: 'run_legacy_local', from: 'term_legacy_worker', to: 'term_legacy_coord', subject: 'String marker', payload: JSON.stringify({ _orcaLifecycleRejection: 'migration' }) }), first.insertMessage({ + runId: 'run_legacy_local', from: 'term_legacy_worker', to: 'term_legacy_coord', subject: 'Incomplete marker', payload: JSON.stringify({ _orcaLifecycleRejection: { code: 'migration' } }) }), first.insertMessage({ + runId: 'run_legacy_local', from: 'term_legacy_worker', to: 'term_legacy_coord', subject: 'Non-string marker fields', payload: JSON.stringify({ _orcaLifecycleRejection: { code: 19, reason: false } }) }), first.insertMessage({ + runId: 'run_legacy_local', from: 'term_legacy_worker', to: 'term_legacy_coord', subject: 'Array root', @@ -153,6 +165,7 @@ export function createLegacyStorageCutoverFixture(): { ]) }), first.insertMessage({ + runId: 'run_legacy_local', from: 'term_legacy_worker', to: 'term_legacy_coord', subject: 'String root', diff --git a/src/main/runtime/orchestration/orchestration-legacy-worker-terminal-recovery.test.ts b/src/main/runtime/orchestration/orchestration-legacy-worker-terminal-recovery.test.ts index abb0b7bdfcc..7d0f0931263 100644 --- a/src/main/runtime/orchestration/orchestration-legacy-worker-terminal-recovery.test.ts +++ b/src/main/runtime/orchestration/orchestration-legacy-worker-terminal-recovery.test.ts @@ -26,14 +26,6 @@ function recoveryRow( describe('legacy worker terminal recovery planning', () => { it('retains completed Dispatches when the worker process row is still live', () => { expect(planLegacyWorkerTerminalRecovery([recoveryRow()])).toEqual({ - blockedPanes: [ - { - worktreeId: 'repo::/workspace', - paneKey: `tab-worker:${LEAF_ID}`, - contractVersion: 0, - settled: false - } - ], candidates: [ expect.objectContaining({ dispatchId: 'dispatch-1', @@ -45,18 +37,10 @@ describe('legacy worker terminal recovery planning', () => { }) }) - it('blocks resume but refuses recovery when durable handles disagree', () => { + it('refuses recovery when durable handles disagree', () => { expect( planLegacyWorkerTerminalRecovery([recoveryRow({ agent_terminal_handle: 'term-replacement' })]) ).toEqual({ - blockedPanes: [ - { - worktreeId: 'repo::/workspace', - paneKey: `tab-worker:${LEAF_ID}`, - contractVersion: 0, - settled: false - } - ], candidates: [], ambiguousDispatchIds: [] }) @@ -70,8 +54,6 @@ describe('legacy worker terminal recovery planning', () => { expect(plan.candidates).toEqual([expect.objectContaining({ dispatchId: 'dispatch-live' })]) expect(plan.ambiguousDispatchIds).toEqual([]) - // A live dispatch still holds this pane, so it must not be reported as a settled fence. - expect(plan.blockedPanes).toEqual([expect.objectContaining({ settled: false })]) }) it('fails closed when two Dispatches claim one terminal identity', () => { @@ -82,7 +64,6 @@ describe('legacy worker terminal recovery planning', () => { expect(plan.candidates).toEqual([]) expect(plan.ambiguousDispatchIds).toEqual(['dispatch-1', 'dispatch-2']) - expect(plan.blockedPanes).toHaveLength(1) }) it('does not trust malformed pane or process identities', () => { @@ -94,7 +75,6 @@ describe('legacy worker terminal recovery planning', () => { ]) expect(plan).toEqual({ - blockedPanes: [], candidates: [], ambiguousDispatchIds: [] }) diff --git a/src/main/runtime/orchestration/orchestration-legacy-worker-terminal-recovery.ts b/src/main/runtime/orchestration/orchestration-legacy-worker-terminal-recovery.ts index 8b1426cb07e..7a159a89ea0 100644 --- a/src/main/runtime/orchestration/orchestration-legacy-worker-terminal-recovery.ts +++ b/src/main/runtime/orchestration/orchestration-legacy-worker-terminal-recovery.ts @@ -19,16 +19,7 @@ export type LegacyWorkerTerminalRecoveryCandidate = { incarnationId: PtyIncarnationId } -export type LegacyWorkerTerminalRecoveryBlockedPane = { - worktreeId: string - paneKey: string - contractVersion: number - /** The dispatch reported an outcome; its pane needs the fence but owns no process to recover. */ - settled: boolean -} - export type LegacyWorkerTerminalRecoveryPlan = { - blockedPanes: LegacyWorkerTerminalRecoveryBlockedPane[] candidates: LegacyWorkerTerminalRecoveryCandidate[] ambiguousDispatchIds: string[] } @@ -65,26 +56,13 @@ function countCandidateKeys( export function planLegacyWorkerTerminalRecovery( rows: readonly LegacyWorkerTerminalRecoveryRow[] ): LegacyWorkerTerminalRecoveryPlan { - const blockedPanes = new Map() const parsedCandidates: LegacyWorkerTerminalRecoveryCandidate[] = [] for (const row of rows) { const worktreeId = row.worktree_id?.trim() const paneKey = row.assignee_pane_key?.trim() const pane = paneKey ? parsePaneKey(paneKey) : null const settled = WORKER_SETTLED_STATES.includes(row.worker_state) - if (worktreeId && paneKey && pane) { - const blockedKey = `${worktreeId}\0${paneKey}` - const alreadySettled = blockedPanes.get(blockedKey)?.settled - blockedPanes.set(blockedKey, { - worktreeId, - paneKey, - contractVersion: row.contract_version, - // A pane reused across dispatches is settled only once every dispatch holding it is. - settled: (alreadySettled ?? true) && settled - }) - } - // A settled worker owns no live process to adopt or roll back, so its identity must never - // compete with a running worker's in the ambiguity count below. + // Settled dispatches need no adoption and must not make an active worker's identity ambiguous. if (settled) { continue } @@ -134,7 +112,6 @@ export function planLegacyWorkerTerminalRecovery( return !ambiguous }) return { - blockedPanes: [...blockedPanes.values()], candidates, ambiguousDispatchIds: [...ambiguousDispatchIds] } diff --git a/src/main/runtime/orchestration/orchestration-mutation-question-db.test.ts b/src/main/runtime/orchestration/orchestration-mutation-question-db.test.ts index 5a26448bd98..c4911b7d676 100644 --- a/src/main/runtime/orchestration/orchestration-mutation-question-db.test.ts +++ b/src/main/runtime/orchestration/orchestration-mutation-question-db.test.ts @@ -77,6 +77,7 @@ describe('OrchestrationDb mutation and question state', () => { it('accepts a question message in the fresh canonical schema', () => { const d = createDb() const message = d.insertMessage({ + runId: 'run_legacy_local', from: 'worker', to: 'run:run_1', subject: 'Need input', diff --git a/src/main/runtime/orchestration/orchestration-schema-version-skew.ts b/src/main/runtime/orchestration/orchestration-schema-version-skew.ts index a2767e1e5a7..85e0a78b3ae 100644 --- a/src/main/runtime/orchestration/orchestration-schema-version-skew.ts +++ b/src/main/runtime/orchestration/orchestration-schema-version-skew.ts @@ -42,7 +42,8 @@ const VERSIONED_POST_V6_COLUMNS = [ { version: 36, table: 'dispatch_contexts', column: 'consumer_generation' }, { version: 36, table: 'remote_dispatch_attachments', column: 'consumer_generation' }, { version: 37, table: 'dispatch_contexts', column: 'creator_handle' }, - { version: 37, table: 'dispatch_contexts', column: 'creator_pane_key' } + { version: 37, table: 'dispatch_contexts', column: 'creator_pane_key' }, + { version: 40, table: 'remote_dispatch_attachments', column: 'home_run_id' } ] as const // Why: v34 shipped without these two, so a v34 stamp proves nothing about them; v35 repairs both @@ -122,15 +123,22 @@ function messagesAllowQuestions(db: Database.Database): boolean { function hasConsistentLegacyAdoption(db: Database.Database): boolean { const sourceRunId = 'run_legacy_local' + // Misfiled federated mail is not evidence of a pre-Runs database. + const notFederatedMailbox = (handle: string): string => + `NOT EXISTS (SELECT 1 FROM remote_dispatch_attachments AS attachment + WHERE 'dispatch:' || attachment.dispatch_id = ${handle})` + const deliveryFilter = hasOrchestrationColumn(db, 'deliveries', 'mailbox_handle') + ? ` AND ${notFederatedMailbox('mailbox_handle')}` + : '' const sourceGraph = db .prepare( `SELECT 1 WHERE EXISTS(SELECT 1 FROM tasks WHERE run_id = ?) OR EXISTS(SELECT 1 FROM dispatch_contexts WHERE run_id = ?) OR EXISTS(SELECT 1 FROM decision_gates WHERE run_id = ?) - OR EXISTS(SELECT 1 FROM messages WHERE run_id = ?) + OR EXISTS(SELECT 1 FROM messages WHERE run_id = ? AND ${notFederatedMailbox('to_handle')}) OR EXISTS(SELECT 1 FROM question_threads WHERE run_id = ?) - OR EXISTS(SELECT 1 FROM deliveries WHERE run_id = ?)` + OR EXISTS(SELECT 1 FROM deliveries WHERE run_id = ?${deliveryFilter})` ) .get(sourceRunId, sourceRunId, sourceRunId, sourceRunId, sourceRunId, sourceRunId) const adoption = db diff --git a/src/main/runtime/orchestration/orchestration-settled-worker-resume-fence-db.test.ts b/src/main/runtime/orchestration/orchestration-settled-worker-resume-fence-db.test.ts deleted file mode 100644 index ee52bc026d0..00000000000 --- a/src/main/runtime/orchestration/orchestration-settled-worker-resume-fence-db.test.ts +++ /dev/null @@ -1,124 +0,0 @@ -import { afterEach, describe, expect, it } from 'vitest' -import { OrchestrationDb } from './db' -import { planLegacyWorkerTerminalRecovery } from './orchestration-legacy-worker-terminal-recovery' -import type { WorkerTerminalResourceRow } from './worker-terminal-ownership' - -const PANE_KEY = 'tab_worker:33333333-3333-4333-8333-333333333333' - -describe('settled worker terminal resume fence rows', () => { - let db: OrchestrationDb | undefined - - afterEach(() => db?.close()) - - function createReadyWorker(): { db: OrchestrationDb; taskId: string; dispatchId: string } { - const d = new OrchestrationDb(':memory:') - db = d - const task = d.createTask({ spec: 'settled worker' }) - const started = d.createStartingWorkerDispatch({ - creator: { kind: 'system' }, - maxDepth: Number.MAX_SAFE_INTEGER, - taskId: task.id, - startOptions: {} - }) - d.prepareStartingWorkerAuthority({ - dispatchId: started.dispatch.id, - handle: 'term_worker', - paneKey: PANE_KEY, - processIncarnation: 'runtime:pty:1', - worktreeId: 'repo::worktree', - setupState: 'not_applicable', - effects: [], - terminalOwnership: 'created' - }) - d.markWorkerDispatchReady(started.dispatch.id) - return { db: d, taskId: task.id, dispatchId: started.dispatch.id } - } - - /** Asserts the `requested` arm so the resource row is non-null for the caller. */ - function requestRelease(d: OrchestrationDb, dispatchId: string): WorkerTerminalResourceRow { - const requested = d.requestWorkerTerminalRelease(dispatchId) - if (requested.disposition !== 'requested') { - throw new Error(`expected a release request, got ${requested.disposition}`) - } - return requested.resource - } - - function settle(d: OrchestrationDb, taskId: string, dispatchId: string): void { - expect( - d.settleWorkerReport({ - taskId, - dispatchId, - outcome: 'succeeded', - result: 'worker succeeded' - }).action - ).toBe('settled') - } - - it('keeps a settled-but-unreleased worker terminal in the recovery rows', () => { - const { db: d, taskId, dispatchId } = createReadyWorker() - settle(d, taskId, dispatchId) - - expect(d.getWorkerDispatch(dispatchId)?.state).toBe('succeeded') - expect(d.listLegacyWorkerTerminalRecoveryRows()).toEqual([ - expect.objectContaining({ - dispatch_id: dispatchId, - worker_state: 'succeeded', - assignee_pane_key: PANE_KEY - }) - ]) - }) - - // A settled worker owns no live process, so it must only fence — never be offered for adoption. - it('plans a settled pane as a fence with no adoption candidate', () => { - const { db: d, taskId, dispatchId } = createReadyWorker() - settle(d, taskId, dispatchId) - - const plan = planLegacyWorkerTerminalRecovery(d.listLegacyWorkerTerminalRecoveryRows()) - - expect(plan.blockedPanes).toEqual([ - expect.objectContaining({ paneKey: PANE_KEY, settled: true }) - ]) - expect(plan.candidates).toEqual([]) - expect(plan.ambiguousDispatchIds).toEqual([]) - }) - - // `release_unknown` is the ticket's own repro: release could not be proven, the pane keeps a - // resumable provider session, and dropping it here would re-open the auto-resume. - it('keeps a settled worker terminal whose release could not be proven', () => { - const { db: d, taskId, dispatchId } = createReadyWorker() - settle(d, taskId, dispatchId) - const resource = requestRelease(d, dispatchId) - expect( - d.markWorkerTerminalReleaseUnknown(resource.id, 'terminal no longer resolves').release_state - ).toBe('unknown') - - expect(d.listLegacyWorkerTerminalRecoveryRows()).toEqual([ - expect.objectContaining({ dispatch_id: dispatchId, assignee_pane_key: PANE_KEY }) - ]) - }) - - it('drops a settled worker terminal once its resource is released', () => { - const { db: d, taskId, dispatchId } = createReadyWorker() - settle(d, taskId, dispatchId) - const resource = requestRelease(d, dispatchId) - expect(d.settleWorkerTerminalRelease(resource.id).release_state).toBe('released') - - expect(d.listLegacyWorkerTerminalRecoveryRows()).toEqual([]) - }) - - it('drops a settled worker terminal the user chose to retain', () => { - const { db: d, taskId, dispatchId } = createReadyWorker() - d.retainWorkerTerminalResource(dispatchId) - settle(d, taskId, dispatchId) - - expect(d.listLegacyWorkerTerminalRecoveryRows()).toEqual([]) - }) - - it('drops a settled worker terminal the user took over', () => { - const { db: d, taskId, dispatchId } = createReadyWorker() - settle(d, taskId, dispatchId) - expect(d.markWorkerTerminalUserOwned(PANE_KEY)).toBe(1) - - expect(d.listLegacyWorkerTerminalRecoveryRows()).toEqual([]) - }) -}) diff --git a/src/main/runtime/orchestration/orchestration-version-skew-migration.test.ts b/src/main/runtime/orchestration/orchestration-version-skew-migration.test.ts index 12ccf7303ca..f8fa7a5df48 100644 --- a/src/main/runtime/orchestration/orchestration-version-skew-migration.test.ts +++ b/src/main/runtime/orchestration/orchestration-version-skew-migration.test.ts @@ -389,7 +389,10 @@ describe('OrchestrationDb version-skew migration', () => { tempDir = mkdtempSync(join(tmpdir(), 'orca-db-version-skew-v30-reset-')) const dbPath = join(tempDir, 'orchestration.db') db = new OrchestrationDb(dbPath) - const task = db.createTask({ spec: 'reset by an older writer' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'reset by an older writer' + }) const started = db.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, diff --git a/src/main/runtime/orchestration/orchestration-worker-dispatch-db.test.ts b/src/main/runtime/orchestration/orchestration-worker-dispatch-db.test.ts index 16a118008de..d6e6038cd65 100644 --- a/src/main/runtime/orchestration/orchestration-worker-dispatch-db.test.ts +++ b/src/main/runtime/orchestration/orchestration-worker-dispatch-db.test.ts @@ -15,7 +15,7 @@ describe('OrchestrationDb worker Dispatch state', () => { it('creates and activates a composed worker Dispatch transactionally', () => { const d = createDb() - const task = d.createTask({ spec: 'worker' }) + const task = d.createTask({ runId: 'run_legacy_local', spec: 'worker' }) const started = d.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -82,7 +82,7 @@ describe('OrchestrationDb worker Dispatch state', () => { it('retains an active supervised worker terminal', () => { const d = createDb() - const task = d.createTask({ spec: 'retain active worker' }) + const task = d.createTask({ runId: 'run_legacy_local', spec: 'retain active worker' }) const started = d.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -114,7 +114,7 @@ describe('OrchestrationDb worker Dispatch state', () => { it('requeues an active Task before settling a worker whose terminal is missing', () => { const d = createDb() - const task = d.createTask({ spec: 'recover missing worker' }) + const task = d.createTask({ runId: 'run_legacy_local', spec: 'recover missing worker' }) const started = d.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -153,7 +153,7 @@ describe('OrchestrationDb worker Dispatch state', () => { it('commits worker-start mutation acceptance with the starting Dispatch', () => { const d = createDb() - const task = d.createTask({ spec: 'atomic acceptance' }) + const task = d.createTask({ runId: 'run_legacy_local', spec: 'atomic acceptance' }) const mutationReceipt = { callerFingerprint: 'caller_fingerprint', requestId: 'worker_start_request', @@ -207,7 +207,7 @@ describe('OrchestrationDb worker Dispatch state', () => { it('fails a composed start without losing residual resource receipts', () => { const d = createDb() - const task = d.createTask({ spec: 'worker' }) + const task = d.createTask({ runId: 'run_legacy_local', spec: 'worker' }) const started = d.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -232,7 +232,7 @@ describe('OrchestrationDb worker Dispatch state', () => { it('allows retry only from the Task current terminal Dispatch', () => { const d = createDb() - const task = d.createTask({ spec: 'retry current' }) + const task = d.createTask({ runId: 'run_legacy_local', spec: 'retry current' }) const first = d.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -272,7 +272,7 @@ describe('OrchestrationDb worker Dispatch state', () => { it('treats abandon of a superseded Dispatch as a no-op', () => { const d = createDb() - const task = d.createTask({ spec: 'stale abandon' }) + const task = d.createTask({ runId: 'run_legacy_local', spec: 'stale abandon' }) const first = d.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -317,7 +317,7 @@ describe('OrchestrationDb worker Dispatch state', () => { it('lets the stop fence win before a late worker completion', () => { const d = createDb() - const task = d.createTask({ spec: 'race' }) + const task = d.createTask({ runId: 'run_legacy_local', spec: 'race' }) const started = d.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -350,7 +350,7 @@ describe('OrchestrationDb worker Dispatch state', () => { it('allows explicit stop recovery from uncertain local and remote starts', () => { const d = createDb() - const task = d.createTask({ spec: 'uncertain local start' }) + const task = d.createTask({ runId: 'run_legacy_local', spec: 'uncertain local start' }) const started = d.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, @@ -365,6 +365,7 @@ describe('OrchestrationDb worker Dispatch state', () => { }) d.createRemoteDispatchAttachment({ + runId: 'run-home', dispatchId: 'ctx_remote_unknown', taskId: 'task_remote_unknown', homePeerFingerprint: 'home_peer', @@ -398,6 +399,7 @@ describe('OrchestrationDb worker Dispatch state', () => { const paneKey = 'tab_remote:11111111-1111-4111-8111-111111111111' const attach = (dispatchId: string): void => { d.createRemoteDispatchAttachment({ + runId: 'run-home', dispatchId, taskId: `task_${dispatchId}`, homePeerFingerprint: 'home_peer', @@ -452,6 +454,7 @@ describe('OrchestrationDb worker Dispatch state', () => { const leafId = '11111111-1111-4111-8111-111111111111' const attach = (dispatchId: string, paneKey: string): void => { d.createRemoteDispatchAttachment({ + runId: 'run-home', dispatchId, taskId: `task_${dispatchId}`, homePeerFingerprint: 'home_peer', @@ -499,7 +502,7 @@ describe('OrchestrationDb worker Dispatch state', () => { it('returns already-settled when completion wins before stop', () => { const d = createDb() - const task = d.createTask({ spec: 'race' }) + const task = d.createTask({ runId: 'run_legacy_local', spec: 'race' }) const started = d.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, diff --git a/src/main/runtime/orchestration/r1-identity-migration.test.ts b/src/main/runtime/orchestration/r1-identity-migration.test.ts index bb263d0b9ce..673a72fd844 100644 --- a/src/main/runtime/orchestration/r1-identity-migration.test.ts +++ b/src/main/runtime/orchestration/r1-identity-migration.test.ts @@ -27,7 +27,7 @@ describe('R1 identity migration', () => { tempDir = mkdtempSync(join(tmpdir(), 'orca-r1-identity-')) const dbPath = join(tempDir, 'orchestration.db') db = new OrchestrationDb(dbPath) - const task = db.createTask({ spec: 'legacy supervised worker' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'legacy supervised worker' }) const started = db.createStartingWorkerDispatch({ taskId: task.id, startOptions: { worktree: 'folder:/workspace' }, diff --git a/src/main/runtime/orchestration/types.ts b/src/main/runtime/orchestration/types.ts index 00005443006..85d5dcfc159 100644 --- a/src/main/runtime/orchestration/types.ts +++ b/src/main/runtime/orchestration/types.ts @@ -190,6 +190,7 @@ export type FederatedDispatchRow = { } export type RemoteDispatchAttachmentRow = { + home_run_id: string dispatch_id: string task_id: string home_peer_fingerprint: string diff --git a/src/main/runtime/orchestration/worker-start-unobserved-prompt-settlement.test.ts b/src/main/runtime/orchestration/worker-start-unobserved-prompt-settlement.test.ts index 382ec304bb6..1d123f51b38 100644 --- a/src/main/runtime/orchestration/worker-start-unobserved-prompt-settlement.test.ts +++ b/src/main/runtime/orchestration/worker-start-unobserved-prompt-settlement.test.ts @@ -6,7 +6,7 @@ const INCARNATION = 'runtime_test:term_worker:1' let db: OrchestrationDb function startWorker(spec: string): { taskId: string; dispatchId: string; capability: string } { - const task = db.createTask({ spec }) + const task = db.createTask({ runId: 'run_legacy_local', spec }) const started = db.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, diff --git a/src/main/runtime/rpc/methods/orchestration.ts b/src/main/runtime/rpc/methods/orchestration.ts index fbc8f263cd0..ed89ae4519d 100644 --- a/src/main/runtime/rpc/methods/orchestration.ts +++ b/src/main/runtime/rpc/methods/orchestration.ts @@ -1,5 +1,4 @@ import type { RpcMethod } from '../core' -import { sweepingSettledWorkerResumeFences } from './settled-worker-resume-fence-sweep' import { ORCHESTRATION_RUN_METHODS } from './orchestration/runs/runs' import { ORCHESTRATION_WORKER_METHODS } from './orchestration/worker/worker-methods' import { ORCHESTRATION_FEDERATION_METHODS } from './orchestration/federation/federation-methods' @@ -24,4 +23,4 @@ export const ORCHESTRATION_METHODS: RpcMethod[] = [ ...ORCHESTRATION_ASK_METHODS, ...ORCHESTRATION_GATE_METHODS, ...ORCHESTRATION_RESET_METHODS -].map(sweepingSettledWorkerResumeFences) +] diff --git a/src/main/runtime/rpc/methods/orchestration/federation/federated-message-targeting.test.ts b/src/main/runtime/rpc/methods/orchestration/federation/federated-message-targeting.test.ts index 8e80a8e3925..c28ef94a4a9 100644 --- a/src/main/runtime/rpc/methods/orchestration/federation/federated-message-targeting.test.ts +++ b/src/main/runtime/rpc/methods/orchestration/federation/federated-message-targeting.test.ts @@ -25,6 +25,7 @@ describe('orchestration federated message targeting', () => { vi.spyOn(runtime, 'getTerminalPaneKey').mockReturnValue(paneKey) vi.spyOn(runtime, 'getTerminalProcessIncarnation').mockReturnValue(processIncarnation) db.createRemoteDispatchAttachment({ + runId: 'run-home', dispatchId, taskId: 'task_remote_targeting', homePeerFingerprint: 'home_peer', diff --git a/src/main/runtime/rpc/methods/orchestration/federation/federated-release-safety.test.ts b/src/main/runtime/rpc/methods/orchestration/federation/federated-release-safety.test.ts index f3e160244d1..d5150dc052e 100644 --- a/src/main/runtime/rpc/methods/orchestration/federation/federated-release-safety.test.ts +++ b/src/main/runtime/rpc/methods/orchestration/federation/federated-release-safety.test.ts @@ -152,6 +152,7 @@ describe('federated worker release ownership', () => { function createAttachment(dispatchId: string, terminalOwnership?: 'created' | 'external'): void { db.createRemoteDispatchAttachment({ + runId: 'run-home', dispatchId, taskId: `task_${dispatchId}`, homePeerFingerprint: HOME_FINGERPRINT, diff --git a/src/main/runtime/rpc/methods/orchestration/federation/federated-worker-start.ts b/src/main/runtime/rpc/methods/orchestration/federation/federated-worker-start.ts index b577cc87737..a7c59b7064b 100644 --- a/src/main/runtime/rpc/methods/orchestration/federation/federated-worker-start.ts +++ b/src/main/runtime/rpc/methods/orchestration/federation/federated-worker-start.ts @@ -162,6 +162,7 @@ export async function startFederatedWorker(args: { server.environmentId, 'orchestration.federationAttachStart', { + runId, dispatchId: started.dispatch.id, taskId: taskForRemote.id, taskSpec: taskForRemote.spec, diff --git a/src/main/runtime/rpc/methods/orchestration/federation/federation-agent-launch.test.ts b/src/main/runtime/rpc/methods/orchestration/federation/federation-agent-launch.test.ts index 748e4c55295..ace3bfe407a 100644 --- a/src/main/runtime/rpc/methods/orchestration/federation/federation-agent-launch.test.ts +++ b/src/main/runtime/rpc/methods/orchestration/federation/federation-agent-launch.test.ts @@ -56,6 +56,7 @@ describe('federated worker agent launch', () => { const result = (await method.handler( method.params!.parse({ + runId: 'run-home', dispatchId: 'ctx_remote', taskId: 'task_remote', taskSpec: 'remote cursor worker', diff --git a/src/main/runtime/rpc/methods/orchestration/federation/federation-control-mail.test.ts b/src/main/runtime/rpc/methods/orchestration/federation/federation-control-mail.test.ts index 755f85fd512..c95ec9b5630 100644 --- a/src/main/runtime/rpc/methods/orchestration/federation/federation-control-mail.test.ts +++ b/src/main/runtime/rpc/methods/orchestration/federation/federation-control-mail.test.ts @@ -107,6 +107,7 @@ describe('orchestration federation control mail', () => { homeDb.markWorkerDispatchReady(dispatchId) workerDb.createRemoteDispatchAttachment({ + runId: 'run-home', dispatchId, taskId: task.id, homePeerFingerprint: homeFingerprint, diff --git a/src/main/runtime/rpc/methods/orchestration/federation/federation-folder-placement.test.ts b/src/main/runtime/rpc/methods/orchestration/federation/federation-folder-placement.test.ts index b8264bd61a7..68364dac1ed 100644 --- a/src/main/runtime/rpc/methods/orchestration/federation/federation-folder-placement.test.ts +++ b/src/main/runtime/rpc/methods/orchestration/federation/federation-folder-placement.test.ts @@ -27,6 +27,7 @@ describe('orchestration federated folder placement', () => { await expect( method.handler( method.params!.parse({ + runId: 'run-home', dispatchId: 'ctx_folder', taskId: 'task_folder', taskSpec: 'work in folder', diff --git a/src/main/runtime/rpc/methods/orchestration/federation/federation-lifecycle-settlement.test.ts b/src/main/runtime/rpc/methods/orchestration/federation/federation-lifecycle-settlement.test.ts index 3e949383731..e111865d904 100644 --- a/src/main/runtime/rpc/methods/orchestration/federation/federation-lifecycle-settlement.test.ts +++ b/src/main/runtime/rpc/methods/orchestration/federation/federation-lifecycle-settlement.test.ts @@ -445,6 +445,7 @@ describe('orchestration federation lifecycle settlement', () => { const dispatchId = `ctx_persisted_protocol_${protocolVersion}` const taskId = `task_persisted_protocol_${protocolVersion}` workerDb.createRemoteDispatchAttachment({ + runId: 'run-home', dispatchId, taskId, homePeerFingerprint: 'run-home-device-token', diff --git a/src/main/runtime/rpc/methods/orchestration/federation/federation-liveness-verdict.test.ts b/src/main/runtime/rpc/methods/orchestration/federation/federation-liveness-verdict.test.ts index 20ae3135ec2..7c75c52eb6c 100644 --- a/src/main/runtime/rpc/methods/orchestration/federation/federation-liveness-verdict.test.ts +++ b/src/main/runtime/rpc/methods/orchestration/federation/federation-liveness-verdict.test.ts @@ -58,6 +58,7 @@ describe('federation host liveness verdicts', () => { status: 'exited' } as never) db.createRemoteDispatchAttachment({ + runId: 'run-home', dispatchId: DISPATCH_ID, taskId: 'task_remote', homePeerFingerprint: HOME_FINGERPRINT, @@ -112,6 +113,7 @@ describe('federation host liveness verdicts', () => { throw new Error('Expected the real runtime PTY to be listed') } hostDb.createRemoteDispatchAttachment({ + runId: 'run-home', dispatchId: DISPATCH_ID, taskId: 'task_remote', homePeerFingerprint: HOME_FINGERPRINT, diff --git a/src/main/runtime/rpc/methods/orchestration/federation/federation-setup.test.ts b/src/main/runtime/rpc/methods/orchestration/federation/federation-setup.test.ts index c905ddffeb8..83865cf96e4 100644 --- a/src/main/runtime/rpc/methods/orchestration/federation/federation-setup.test.ts +++ b/src/main/runtime/rpc/methods/orchestration/federation/federation-setup.test.ts @@ -49,6 +49,7 @@ describe('orchestration federated setup evidence', () => { } ] db.createRemoteDispatchAttachment({ + runId: 'run-home', dispatchId, taskId: 'task_remote_setup', homePeerFingerprint: 'home_peer', diff --git a/src/main/runtime/rpc/methods/orchestration/federation/federation-start-prompt-budget.test.ts b/src/main/runtime/rpc/methods/orchestration/federation/federation-start-prompt-budget.test.ts index 83b446eb102..d3d5b6d71b1 100644 --- a/src/main/runtime/rpc/methods/orchestration/federation/federation-start-prompt-budget.test.ts +++ b/src/main/runtime/rpc/methods/orchestration/federation/federation-start-prompt-budget.test.ts @@ -29,6 +29,7 @@ describe('federation attach-start prompt budget', () => { await expect( method.handler( method.params!.parse({ + runId: 'run-home', dispatchId: 'ctx_oversized_remote', taskId: 'task_oversized_remote', taskSpec: 'x'.repeat(8 * 1024 * 1024), diff --git a/src/main/runtime/rpc/methods/orchestration/federation/federation-start-schema.ts b/src/main/runtime/rpc/methods/orchestration/federation/federation-start-schema.ts index d5d1874a788..1e7257df27d 100644 --- a/src/main/runtime/rpc/methods/orchestration/federation/federation-start-schema.ts +++ b/src/main/runtime/rpc/methods/orchestration/federation/federation-start-schema.ts @@ -3,6 +3,7 @@ import { OptionalFiniteNumber, OptionalString, requiredString } from '../../../s import { OptionalWorkerLaunchPreference } from '../worker/worker-start-schema' export const FederationAttachStartParams = z.object({ + runId: requiredString('Missing Run ID'), dispatchId: requiredString('Missing Dispatch ID'), taskId: requiredString('Missing Task ID'), taskSpec: requiredString('Missing Task spec'), diff --git a/src/main/runtime/rpc/methods/orchestration/federation/federation.ts b/src/main/runtime/rpc/methods/orchestration/federation/federation.ts index 57afd3103a2..785f6a67eec 100644 --- a/src/main/runtime/rpc/methods/orchestration/federation/federation.ts +++ b/src/main/runtime/rpc/methods/orchestration/federation/federation.ts @@ -65,6 +65,7 @@ export const ORCHESTRATION_FEDERATION_ATTACH_METHODS: RpcMethod[] = [ const db = runtime.getOrchestrationDb() db.createRemoteDispatchAttachment({ + runId: params.runId, dispatchId: params.dispatchId, taskId: params.taskId, homePeerFingerprint: orchestrationMutation.callerFingerprint, diff --git a/src/main/runtime/rpc/methods/orchestration/messaging/check-worker-federated-attachment.test.ts b/src/main/runtime/rpc/methods/orchestration/messaging/check-worker-federated-attachment.test.ts new file mode 100644 index 00000000000..58e0b3aa0ca --- /dev/null +++ b/src/main/runtime/rpc/methods/orchestration/messaging/check-worker-federated-attachment.test.ts @@ -0,0 +1,188 @@ +import { mkdtempSync, rmSync } from 'node:fs' +import { tmpdir } from 'node:os' +import { join } from 'node:path' +import { afterEach, describe, expect, it, vi } from 'vitest' +import { ORCHESTRATION_METHODS } from '../../orchestration' +import type { RpcContext } from '../../../core' +import { OrchestrationDb } from '../../../../orchestration/db' +import { OrcaRuntimeService } from '../../../../orca-runtime' +import { + encodeFederatedControlMessage, + importFederatedControlMessage +} from '../../../../orchestration/federation-control-message' + +const DISPATCH_ID = 'ctx_federated_worker_1' +const WORKER_HANDLE = 'term_federated_worker' +const WORKER_PANE = 'tab_w:eeeeeeee-eeee-4eee-8eee-eeeeeeeeeeee' +const INCARNATION = 'runtime_test:term_federated_worker:1' + +type CheckResult = { + runId: string + deliveryId: string | null + messages: { id: string; subject: string }[] + count: number + replayed: boolean + acknowledged: string | null +} + +describe('orchestration.check on a federated attachment across a restart', () => { + let directory: string | undefined + let db: OrchestrationDb | undefined + + afterEach(() => { + db?.close() + db = undefined + if (directory) { + rmSync(directory, { recursive: true, force: true }) + directory = undefined + } + }) + + function launch(path: string): RpcContext { + db = new OrchestrationDb(path) + const runtime = new OrcaRuntimeService() + runtime.setOrchestrationDb(db) + vi.spyOn(runtime, 'getTerminalPaneKey').mockImplementation((handle) => + handle === WORKER_HANDLE ? WORKER_PANE : null + ) + vi.spyOn(runtime, 'getLiveTerminalPaneKey').mockImplementation((handle) => + runtime.getTerminalPaneKey(handle) + ) + vi.spyOn(runtime, 'getTerminalProcessIncarnation').mockImplementation((handle) => + handle === WORKER_HANDLE ? INCARNATION : null + ) + return { runtime } + } + + function check(ctx: RpcContext, params: Record = {}): Promise { + const method = ORCHESTRATION_METHODS.find((entry) => entry.name === 'orchestration.check') + if (!method) { + throw new Error('orchestration.check is not registered') + } + const parsed = method.params + ? method.params.parse({ terminal: WORKER_HANDLE, ...params }) + : undefined + return method.handler(parsed, ctx) as Promise + } + + function attach(store: OrchestrationDb, dispatchId: string, runId: string): void { + store.createRemoteDispatchAttachment({ + dispatchId, + runId, + taskId: 'task_federated_1', + homePeerFingerprint: 'peer_fp', + protocolVersion: 1, + runtimeEpoch: 'epoch_1', + mutationReceipt: { + callerFingerprint: 'peer_fp', + requestId: 'attach_1', + method: 'orchestration.federationAttachStart', + payloadHash: 'attach_payload' + } + }) + expect(store.getRunRaw(runId)).toBeDefined() + store.prepareRemoteAttachmentAuthority({ + dispatchId, + paneKey: WORKER_PANE, + processIncarnation: INCARNATION, + worktreeId: 'folder_workspace', + terminalHandle: WORKER_HANDLE, + setupState: 'not_applicable', + effects: [] + }) + store.markRemoteAttachmentReady(dispatchId) + } + + it('replays the coordinator instruction and takes its ack after the app restarts', async () => { + directory = mkdtempSync(join(tmpdir(), 'orca-federated-check-')) + const path = join(directory, 'orchestration.db') + + const first = launch(path) + attach(db as OrchestrationDb, DISPATCH_ID, 'run_coordinator') + importFederatedControlMessage(db as OrchestrationDb, { + dispatchId: DISPATCH_ID, + messageId: 'msg_federated_1', + payload: encodeFederatedControlMessage({ + from: 'term_coord', + subject: 'continue the task', + body: 'the plan changed', + type: 'dispatch', + priority: 'normal', + threadId: null, + payload: null + }) + }) + + const delivered = await check(first) + expect(delivered.messages.map((message) => message.id)).toEqual(['msg_federated_1']) + expect(delivered.runId).toBe('run_coordinator') + expect(delivered.replayed).toBe(false) + const deliveryId = delivered.deliveryId as string + expect(deliveryId).not.toBeNull() + ;(db as OrchestrationDb).close() + + // The worker's process outlives the app; its instruction is still unacknowledged. + const second = launch(path) + const replayed = await check(second) + expect(replayed.deliveryId).toBe(deliveryId) + expect(replayed.replayed).toBe(true) + expect(replayed.messages.map((message) => message.id)).toEqual(['msg_federated_1']) + + const acknowledged = await check(second, { ack: deliveryId }) + expect(acknowledged.acknowledged).toBe(deliveryId) + expect(acknowledged.count).toBe(0) + }) + + it('files loopback mail once under the local Dispatch Run without replacing its owner', async () => { + const ctx = launch(':memory:') + const store = db as OrchestrationDb + const run = store.createRun({ + objective: 'loopback coordinator', + coordinatorHandle: 'term_coord', + coordinatorPaneKey: 'tab_coord:pane_coord' + }) + const task = store.createTask({ runId: run.id, spec: 'loopback task' }) + const { dispatch } = store.createStartingWorkerDispatch({ + creator: { kind: 'system' }, + maxDepth: Number.MAX_SAFE_INTEGER, + taskId: task.id, + startOptions: {} + }) + attach(store, dispatch.id, run.id) + expect(store.getRemoteDispatchAttachment(dispatch.id)?.home_run_id).toBe(dispatch.run_id) + expect(store.getRun(run.id)).toEqual(run) + const message = { + dispatchId: dispatch.id, + messageId: 'msg_loopback', + payload: encodeFederatedControlMessage({ + from: 'term_coord', + subject: 'continue', + body: 'loopback instruction', + type: 'dispatch', + priority: 'normal', + threadId: null, + payload: null + }) + } + expect(importFederatedControlMessage(store, message).imported).toBe(true) + expect(importFederatedControlMessage(store, message).imported).toBe(false) + expect(store.getMessageById(message.messageId)?.run_id).toBe(run.id) + const delivered = await check(ctx) + expect(delivered.runId).toBe(run.id) + expect(delivered.messages.map((entry) => entry.id)).toEqual([message.messageId]) + expect((await check(ctx, { ack: delivered.deliveryId })).count).toBe(0) + }) + + it('refuses an attachment with no home Run before writing a Delivery', async () => { + const ctx = launch(':memory:') + const store = db as OrchestrationDb + attach(store, DISPATCH_ID, 'run_coordinator') + const attachment = store.getRemoteDispatchAttachment(DISPATCH_ID)! + vi.spyOn(store, 'findActiveRemoteAttachmentForPane').mockReturnValue({ + ...attachment, + home_run_id: undefined + } as never) + await expect(check(ctx)).rejects.toThrow() + expect(store.db.prepare('SELECT id FROM deliveries').all()).toEqual([]) + }) +}) diff --git a/src/main/runtime/rpc/methods/orchestration/messaging/check-worker.ts b/src/main/runtime/rpc/methods/orchestration/messaging/check-worker.ts index 27df8fd2afa..355a12be5c1 100644 --- a/src/main/runtime/rpc/methods/orchestration/messaging/check-worker.ts +++ b/src/main/runtime/rpc/methods/orchestration/messaging/check-worker.ts @@ -3,7 +3,6 @@ import type { OrcaRuntimeService } from '../../../../orca-runtime' import { OrchestrationError } from '../../../../orchestration/orchestration-error' import { formatMessageBanner } from '../../../../orchestration/formatter' import { exposeMessages } from './mailbox-message-receipt' -import { ORCHESTRATION_LEGACY_RUN_ID } from '../../../../../../shared/orchestration-rpc-contract' import { routeAllMailboxPages } from '../schemas' import { asDispatchFence, callerHoldsDispatchPane, dispatchFenced } from './dispatch-mailbox-fence' import type { CheckParams } from '../schemas' @@ -46,13 +45,15 @@ export async function checkWorkerMailbox(args: { : remoteAttachment ? { dispatchId: remoteAttachment.dispatch_id, - runId: undefined, + runId: remoteAttachment.home_run_id, generation: remoteAttachment.consumer_generation } : undefined if (!workerMailbox) { return undefined } + const deliveryRunId = workerMailbox.runId + db.requireRun(deliveryRunId) const address = `dispatch:${workerMailbox.dispatchId}` // Why: a federated worker host has no dispatch_contexts row, so its generation lives on the // remote_dispatch_attachments row instead. @@ -164,7 +165,6 @@ export async function checkWorkerMailbox(args: { } } await revalidateWorkerMailbox() - const deliveryRunId = workerMailbox.runId ?? ORCHESTRATION_LEGACY_RUN_ID let acknowledged try { acknowledged = params.ack diff --git a/src/main/runtime/rpc/methods/orchestration/messaging/send-point-to-point.ts b/src/main/runtime/rpc/methods/orchestration/messaging/send-point-to-point.ts index c7386acd49f..807e709003a 100644 --- a/src/main/runtime/rpc/methods/orchestration/messaging/send-point-to-point.ts +++ b/src/main/runtime/rpc/methods/orchestration/messaging/send-point-to-point.ts @@ -7,7 +7,6 @@ import type { SendParams } from '../schemas' import { legacyWorkerDeliveryContract } from '../routing' import { exposeMessage } from './mailbox-message-receipt' import { recordReceiptForPostCommitNudge } from './mutation-replay-nudge' -import { sweepSettledWorkerResumeFences } from '../../settled-worker-resume-fence-sweep' import type { SendRecipientWarning } from './recipient-routing' import type { z } from 'zod' @@ -150,11 +149,6 @@ export function sendPointToPointMessage(args: { ? db.commitWorkerDoneMessageMutation(commitMessage) : commitMessage() committed.nudge() - if (messageType === 'worker_done') { - // Settlement is what makes the pane fenceable; without this the fence only appeared at the - // next app start and reopening the pane in the same session respawned the agent. - sweepSettledWorkerResumeFences(runtime) - } return committed.receipt } diff --git a/src/main/runtime/rpc/methods/orchestration/runs/migration-behavior.test.ts b/src/main/runtime/rpc/methods/orchestration/runs/migration-behavior.test.ts index d372c733246..929dd5c1ee3 100644 --- a/src/main/runtime/rpc/methods/orchestration/runs/migration-behavior.test.ts +++ b/src/main/runtime/rpc/methods/orchestration/runs/migration-behavior.test.ts @@ -31,7 +31,7 @@ describe('orchestration migration behavior', () => { it('lists an explicitly selected legacy Run without binding or mutation', async () => { const { db, runtime } = createRuntime() - const task = db.createTask({ spec: 'pre-upgrade work' }) + const task = db.createTask({ runId: 'run_legacy_local', spec: 'pre-upgrade work' }) const taskList = ORCHESTRATION_METHODS.find( (method) => method.name === 'orchestration.taskList' )! @@ -55,6 +55,7 @@ describe('orchestration migration behavior', () => { it('formats legacy terminal inspection as read-only without consuming mail', async () => { const { db, runtime } = createRuntime() const message = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_worker', to: 'term_coord', subject: 'still working', @@ -79,6 +80,7 @@ describe('orchestration migration behavior', () => { // A consuming check refuses a handle with no live pane before it reads any mail. vi.spyOn(runtime, 'getTerminalPaneKey').mockReturnValue('tab_legacy:leaf_legacy') const message = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_worker', to: 'term_coord', subject: 'still working' @@ -98,6 +100,7 @@ describe('orchestration migration behavior', () => { it('rejects replies to legacy mail without marking or inserting rows', async () => { const { db, runtime } = createRuntime() const message = db.insertMessage({ + runId: 'run_legacy_local', from: 'term_worker', to: 'term_coord', subject: 'legacy question' diff --git a/src/main/runtime/rpc/methods/orchestration/worker/created-worker-terminal-custody.ts b/src/main/runtime/rpc/methods/orchestration/worker/created-worker-terminal-custody.ts new file mode 100644 index 00000000000..c73884b1d96 --- /dev/null +++ b/src/main/runtime/rpc/methods/orchestration/worker/created-worker-terminal-custody.ts @@ -0,0 +1,32 @@ +import type { OrcaRuntimeService } from '../../../../orca-runtime' +import type { OrchestrationDb } from '../../../../orchestration/db' +import { requireWorkerAuthority } from './worker-topology' + +/** + * Custody for an agent terminal this start created, recorded when the terminal exists rather than + * after the agent boot wait: a keystroke into the booting pane has to find an `owned` row to flip, + * or the takeover is dropped and a later `worker-release` closes the pane under the user. + * + * Ownership of a pane only. The Dispatch capability still waits for the agent to come up. + * + * `created` is false for an explicit `--terminal` reuse, which is the caller's own pane, and for a + * structured session, which reaches its authority in this same turn and so has no gap to close. + */ +export function recordCreatedWorkerTerminalCustody( + runtime: OrcaRuntimeService, + stage: { db: OrchestrationDb; dispatchId: string; worktreeId: string; terminalHandle: string }, + created: boolean +): void { + if (!created) { + return + } + const authority = requireWorkerAuthority(runtime, stage.terminalHandle) + stage.db.recordCreatedWorkerTerminalCustody({ + dispatchId: stage.dispatchId, + handle: stage.terminalHandle, + paneKey: authority.paneKey, + processIncarnation: authority.processIncarnation, + worktreeId: stage.worktreeId, + hostScope: authority.hostScope ?? null + }) +} diff --git a/src/main/runtime/rpc/methods/orchestration/worker/failed-start-residual-terminal.test.ts b/src/main/runtime/rpc/methods/orchestration/worker/failed-start-residual-terminal.test.ts deleted file mode 100644 index bdf5daad565..00000000000 --- a/src/main/runtime/rpc/methods/orchestration/worker/failed-start-residual-terminal.test.ts +++ /dev/null @@ -1,191 +0,0 @@ -import { afterEach, describe, expect, it } from 'vitest' -import type { OrcaRuntimeService } from '../../../../orca-runtime' -import { OrchestrationDb } from '../../../../orchestration/db' -import { resolveResidualAgentTerminal } from './failed-start-residual-terminal' -import { failWorkerStartWithReceipt } from './worker-start-receipt' -import type { WorkerEffect } from './worker-topology' - -const HANDLE = 'term_residual' -const PANE_KEY = 'tab_residual:leaf_residual' -const INCARNATION = 'pty-residual:1' - -const createdAgentTerminal: WorkerEffect = { - kind: 'terminal', - role: 'agent', - action: 'created', - id: HANDLE, - surface: 'visible' -} - -function createRuntime(overrides: Partial> = {}): OrcaRuntimeService { - return { - getOrchestrationDispatchAuthority: () => ({ - paneKey: PANE_KEY, - processIncarnation: INCARNATION, - hostScope: { kind: 'local', hostId: 'local' } - }), - getTerminalPaneKey: () => PANE_KEY, - getTerminalProcessIncarnation: () => INCARNATION, - ...overrides - } as unknown as OrcaRuntimeService -} - -describe('residual agent terminal left by a failed start', () => { - it('resolves identity for a terminal this start created', () => { - expect( - resolveResidualAgentTerminal({ - runtime: createRuntime(), - effects: [createdAgentTerminal], - terminalHandle: HANDLE, - worktreeId: 'repo::worktree' - }) - ).toEqual({ - terminalHandle: HANDLE, - worktreeId: 'repo::worktree', - paneKey: PANE_KEY, - processIncarnation: INCARNATION, - hostScope: JSON.stringify({ kind: 'local', hostId: 'local' }) - }) - }) - - it('resolves the agent-first worktree terminal the same way', () => { - expect( - resolveResidualAgentTerminal({ - runtime: createRuntime(), - effects: [{ ...createdAgentTerminal, action: 'reused_agent_terminal' }], - terminalHandle: HANDLE, - worktreeId: null - }) - ).toMatchObject({ terminalHandle: HANDLE }) - }) - - it('never claims a caller-supplied terminal', () => { - expect( - resolveResidualAgentTerminal({ - runtime: createRuntime(), - effects: [{ ...createdAgentTerminal, action: 'reused' }], - terminalHandle: HANDLE, - worktreeId: null - }) - ).toBeUndefined() - }) - - it('never claims a setup terminal', () => { - expect( - resolveResidualAgentTerminal({ - runtime: createRuntime(), - effects: [{ ...createdAgentTerminal, role: 'setup' }], - terminalHandle: HANDLE, - worktreeId: null - }) - ).toBeUndefined() - }) - - it('refuses a pane whose process cannot be identified', () => { - expect( - resolveResidualAgentTerminal({ - runtime: createRuntime({ - getOrchestrationDispatchAuthority: () => null, - getTerminalProcessIncarnation: () => null - }), - effects: [createdAgentTerminal], - terminalHandle: HANDLE, - worktreeId: null - }) - ).toBeUndefined() - }) - - it('refuses when the start never resolved a terminal', () => { - expect( - resolveResidualAgentTerminal({ - runtime: createRuntime(), - effects: [], - terminalHandle: undefined, - worktreeId: null - }) - ).toBeUndefined() - }) - - it('stays silent when identity resolution throws', () => { - expect( - resolveResidualAgentTerminal({ - runtime: createRuntime({ - getOrchestrationDispatchAuthority: () => { - throw new Error('handle retired') - } - }), - effects: [createdAgentTerminal], - terminalHandle: HANDLE, - worktreeId: null - }) - ).toBeUndefined() - }) -}) - -describe('failed worker-start receipt for a residual terminal', () => { - let db: OrchestrationDb | undefined - - afterEach(() => { - db?.close() - }) - - function failStart(residual: boolean): { recovery?: string } { - const d = (db = new OrchestrationDb(':memory:')) - const task = d.createTask({ spec: 'residual receipt' }) - const started = d.createStartingWorkerDispatch({ - creator: { kind: 'system' }, - maxDepth: Number.MAX_SAFE_INTEGER, - taskId: task.id, - startOptions: {} - }) - d.recordWorkerStage({ - dispatchId: started.dispatch.id, - stage: 'terminal_readying', - terminalHandle: HANDLE, - effects: [createdAgentTerminal], - residualResources: [createdAgentTerminal] - }) - return failWorkerStartWithReceipt({ - db: d, - mode: { - mode: 'terminal', - preferred: 'terminal', - reason: 'user_default', - detail: 'terminal by default' - } as const, - runId: 'run_residual', - taskId: task.id, - dispatchId: started.dispatch.id, - failedStage: 'agent_readiness', - error: new Error('Agent startup blocked: codex-interactive-prompt'), - setup: { - requested: 'not_applicable', - effective: 'not_applicable', - source: 'existing_worktree', - hookFound: false, - startupPolicy: 'start-immediately', - state: 'not_applicable' - }, - launch: { requested: { agent: 'codex' }, effective: { agent: 'codex' } } as never, - ...(residual - ? { - residualAgentTerminal: { - terminalHandle: HANDLE, - worktreeId: 'repo::worktree', - paneKey: PANE_KEY, - processIncarnation: INCARNATION, - hostScope: null - } - } - : {}) - }) as { recovery?: string } - } - - it('names worker-release for the terminal it left behind', () => { - expect(failStart(true).recovery).toContain('worker-release') - }) - - it('promises no cleanup when there is no residual terminal', () => { - expect(failStart(false).recovery).toBeUndefined() - }) -}) diff --git a/src/main/runtime/rpc/methods/orchestration/worker/failed-start-residual-terminal.ts b/src/main/runtime/rpc/methods/orchestration/worker/failed-start-residual-terminal.ts deleted file mode 100644 index e42923e93a9..00000000000 --- a/src/main/runtime/rpc/methods/orchestration/worker/failed-start-residual-terminal.ts +++ /dev/null @@ -1,53 +0,0 @@ -import type { OrcaRuntimeService } from '../../../../orca-runtime' -import type { FailedStartTerminalAdoption } from '../../../../orchestration/db/worker-terminal/failed-start-terminal-adoption' -import type { WorkerEffect } from './worker-topology' - -/** True only for an agent terminal this worker-start brought into existence. An explicit - * `--terminal` reuse records `reused` and is never residual — it is the caller's terminal. */ -function orchestrationCreatedAgentTerminal( - effects: readonly WorkerEffect[], - handle: string -): boolean { - return effects.some( - (effect) => - effect.kind === 'terminal' && - effect.role === 'agent' && - effect.id === handle && - (effect.action?.startsWith('created') === true || effect.action === 'reused_agent_terminal') - ) -} - -/** - * Identity for the terminal a failed start leaves behind, so the failed Dispatch can own it and - * `worker-release` can close it. Returns nothing unless the pane and process are both provable: - * an unprovable identity must never authorize a later close. - */ -export function resolveResidualAgentTerminal(args: { - runtime: OrcaRuntimeService - effects: readonly WorkerEffect[] - terminalHandle: string | undefined - worktreeId: string | null -}): FailedStartTerminalAdoption | undefined { - const handle = args.terminalHandle - if (!handle || !orchestrationCreatedAgentTerminal(args.effects, handle)) { - return undefined - } - try { - const authority = args.runtime.getOrchestrationDispatchAuthority(handle) - const paneKey = authority?.paneKey ?? args.runtime.getTerminalPaneKey(handle) - const processIncarnation = - authority?.processIncarnation ?? args.runtime.getTerminalProcessIncarnation(handle) - if (!paneKey || !processIncarnation) { - return undefined - } - return { - terminalHandle: handle, - worktreeId: args.worktreeId, - paneKey, - processIncarnation, - hostScope: authority?.hostScope ? JSON.stringify(authority.hostScope) : null - } - } catch { - return undefined - } -} diff --git a/src/main/runtime/rpc/methods/orchestration/worker/failed-worker-start-teardown.ts b/src/main/runtime/rpc/methods/orchestration/worker/failed-worker-start-teardown.ts index 32827377b54..250b639fc60 100644 --- a/src/main/runtime/rpc/methods/orchestration/worker/failed-worker-start-teardown.ts +++ b/src/main/runtime/rpc/methods/orchestration/worker/failed-worker-start-teardown.ts @@ -3,40 +3,27 @@ import { discardStructuredWorkerSession, releaseStructuredWorkerSession } from '../../orchestration-structured-worker-session' -import { resolveResidualAgentTerminal } from './failed-start-residual-terminal' import type { createStructuredWorkerSessionForWorktree } from './worker-topology' -import type { FailedStartTerminalAdoption } from '../../../../orchestration/db/worker-terminal/failed-start-terminal-adoption' /** - * Undoes what a start created before it failed, and reports what `worker-release` still owns. + * Undoes what a start created before it failed. * * A start that never reached ready leaves no settlement to release the hold later, and its session * was already published as a chat tab — without the discard, a failed start strands a dead chat tab * that the durable restore index republishes on every app launch. Both halves are best-effort by * construction, so neither can replace the real error. + * + * A created PTY terminal is deliberately NOT torn down: its custody row was written at creation, so + * `worker-release` on the failed Dispatch owns that cleanup and the coordinator decides when. */ export async function tearDownFailedWorkerStart(args: { runtime: OrcaRuntimeService structuredSession: Awaited> | null dispatchId: string - effects: unknown[] - terminalHandle: string | undefined - worktreeId: string | null -}): Promise { +}): Promise { const { runtime, structuredSession } = args - // A structured session is torn down outright here, so it must never also be adopted as a residual - // terminal for `worker-release` to close a second time. - const residualAgentTerminal = structuredSession - ? undefined - : resolveResidualAgentTerminal({ - runtime, - effects: args.effects as never, - terminalHandle: args.terminalHandle, - worktreeId: args.worktreeId - }) releaseStructuredWorkerSession(args.dispatchId, runtime) if (structuredSession) { await discardStructuredWorkerSession(structuredSession.identity.sessionId, runtime) } - return residualAgentTerminal } diff --git a/src/main/runtime/rpc/methods/orchestration/worker/legacy-dispatch-projection.test.ts b/src/main/runtime/rpc/methods/orchestration/worker/legacy-dispatch-projection.test.ts index 4df73994beb..75ad57f3a12 100644 --- a/src/main/runtime/rpc/methods/orchestration/worker/legacy-dispatch-projection.test.ts +++ b/src/main/runtime/rpc/methods/orchestration/worker/legacy-dispatch-projection.test.ts @@ -117,6 +117,6 @@ describe('pre-v3 dispatch rows in worker-list', () => { }) expect(worker.projection.attention.categories).toContain('unverifiable') expect(worker.projection.attention.requiresAction).toBe(true) - expect(worker.projection.nextAction.kind).toBe('inspect') + expect(worker.projection.nextAction).toEqual({ kind: 'none', argv: [] }) }) }) diff --git a/src/main/runtime/rpc/methods/orchestration/worker/local-worker-start.ts b/src/main/runtime/rpc/methods/orchestration/worker/local-worker-start.ts index 48b14f9a84e..d67d09b766a 100644 --- a/src/main/runtime/rpc/methods/orchestration/worker/local-worker-start.ts +++ b/src/main/runtime/rpc/methods/orchestration/worker/local-worker-start.ts @@ -19,6 +19,7 @@ import { failWorkerStartWithReceipt } from './worker-start-receipt' import { parseTaskDeps } from './task-deps-argument' import { assertExplicitWorkerTerminalUsable } from './explicit-worker-terminal-validation' import { deliverWorkerDispatchPreamble } from './deliver-worker-dispatch-preamble' +import { recordCreatedWorkerTerminalCustody } from './created-worker-terminal-custody' import { tearDownFailedWorkerStart } from './failed-worker-start-teardown' import { createExistingWorktreeWorkerTerminal, @@ -203,6 +204,7 @@ export async function startLocalWorker(args: { setup: setupReceipt, effects } + recordCreatedWorkerTerminalCustody(runtime, setupStage, !params.terminal && !structuredSession) if (persistGatedSetupSpawnFailure(setupStage)) { failedStage = 'setup_start' throw new Error('Setup terminal failed to start before the gated agent launch.') @@ -285,13 +287,10 @@ export async function startLocalWorker(args: { ...(terminalRevealWarning ? { warning: terminalRevealWarning } : {}) } } catch (error) { - const residualAgentTerminal = await tearDownFailedWorkerStart({ + await tearDownFailedWorkerStart({ runtime, structuredSession, - dispatchId: started.dispatch.id, - effects, - terminalHandle, - worktreeId: resolvedWorktree?.id ?? null + dispatchId: started.dispatch.id }) return failWorkerStartWithReceipt({ db, @@ -302,8 +301,7 @@ export async function startLocalWorker(args: { error, setup: setupReceipt, launch: launch.receipt, - mode, - ...(residualAgentTerminal ? { residualAgentTerminal } : {}) + mode }) } } diff --git a/src/main/runtime/rpc/methods/orchestration/worker/manual-dispatch-observation.test.ts b/src/main/runtime/rpc/methods/orchestration/worker/manual-dispatch-observation.test.ts index 4cd8810ad6b..2890fa08938 100644 --- a/src/main/runtime/rpc/methods/orchestration/worker/manual-dispatch-observation.test.ts +++ b/src/main/runtime/rpc/methods/orchestration/worker/manual-dispatch-observation.test.ts @@ -242,7 +242,13 @@ describe('manual Dispatch observation', () => { const result = (await workerListMethod.handler( workerListMethod.params?.parse({ run: run.id }), { runtime } - )) as { workers: { dispatchId: string; workerState: string; terminalState: string | null }[] } + )) as { + workers: { + dispatchId: string + workerState: string + terminalState: string | null + }[] + } expect(result.workers).toEqual([ expect.objectContaining({ @@ -262,7 +268,10 @@ describe('manual Dispatch observation', () => { const runtime = new OrcaRuntimeService() runtime.setOrchestrationDb(db) const closeTerminal = vi.spyOn(runtime, 'closeTerminal') - const task = db.createTask({ spec: 'operator-owned lane' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'operator-owned lane' + }) const dispatch = createRootDispatch( db, task.id, diff --git a/src/main/runtime/rpc/methods/orchestration/worker/worker-release-mobile-report.test.ts b/src/main/runtime/rpc/methods/orchestration/worker/worker-release-mobile-report.test.ts new file mode 100644 index 00000000000..68d40b4a04e --- /dev/null +++ b/src/main/runtime/rpc/methods/orchestration/worker/worker-release-mobile-report.test.ts @@ -0,0 +1,165 @@ +import { afterEach, beforeEach, expect, it, vi } from 'vitest' +import { createOrchestrationWorkerReleaseHarness } from './worker-release.test-support' +import { TERMINAL_SEND_METHODS } from '../../terminal/terminal-send-method' +import { sendTerminalStreamInput } from '../../terminal/terminal-input-delivery' +import { isStreamingMethod, type RpcMethod } from '../../../core' + +const h = createOrchestrationWorkerReleaseHarness() +beforeEach(() => h.setup()) +afterEach(() => h.cleanup()) + +it.each(['local', 'ssh'])( + 'a handle-addressed phone report fences %s worker release', + async (host) => { + if (host === 'ssh') { + vi.mocked(h.runtime.getOrchestrationDispatchAuthority).mockImplementation((handle) => + handle === 'term_worker' + ? ({ + terminalHandle: handle, + paneKey: h.workerPaneKey, + processIncarnation: 'runtime_test:term_worker:1', + hostScope: { kind: 'ssh', targetId: 'ssh-1' } + } as never) + : null + ) + } + const worker = await h.startSettledWorker() + expect(h.db.getWorkerTerminalResourceByOwner(worker.dispatchId)?.host_scope).toContain(host) + h.runtime.registerPreAllocatedHandleForPty('pty-worker', 'term_worker') + h.runtime.registerPty('pty-worker', 'repo::worktree', undefined, { + tabId: 'tab_worker', + leafId: 'bbbbbbbb-bbbb-4bbb-8bbb-bbbbbbbbbbbb' + }) + vi.mocked(h.runtime.getTerminalPaneKey).mockRestore() + await expect( + h.call('orchestration.workerTerminalUserInput', { terminal: 'term_worker' }) + ).resolves.toEqual({ changed: 1 }) + expect(h.db.getWorkerTerminalResourceByOwner(worker.dispatchId)?.ownership_state).toBe( + 'user_owned' + ) + await expect( + h.call('orchestration.workerTerminalUserInput', { terminal: 'term_worker' }) + ).resolves.toEqual({ changed: 0 }) + await expect( + h.call('orchestration.workerRelease', { dispatch: worker.dispatchId }) + ).resolves.toMatchObject({ state: 'retained', reason: 'user_takeover' }) + expect(h.runtime.closeTerminal).not.toHaveBeenCalled() + } +) + +it('an unknown handle does not fence another worker or access the database', async () => { + const worker = await h.startSettledWorker() + h.runtime.registerPreAllocatedHandleForPty('pty-worker', 'term_worker') + h.runtime.registerPty('pty-worker', 'repo::worktree', undefined, { + tabId: 'tab_worker', + leafId: 'bbbbbbbb-bbbb-4bbb-8bbb-bbbbbbbbbbbb' + }) + vi.mocked(h.runtime.getTerminalPaneKey).mockRestore() + const db = vi.spyOn(h.runtime, 'getOrchestrationDb') + await expect( + h.call('orchestration.workerTerminalUserInput', { terminal: 'term_missing' }) + ).resolves.toEqual({ changed: 0 }) + expect(db).not.toHaveBeenCalled() + expect(h.db.getWorkerTerminalResourceByOwner(worker.dispatchId)?.ownership_state).toBe('owned') + await expect( + h.call('orchestration.workerRelease', { dispatch: worker.dispatchId }) + ).resolves.toMatchObject({ state: 'released' }) +}) + +it.each(['unary', 'stream'])('mobile %s bytes do no orchestration database work', async (lane) => { + const worker = await h.startSettledWorker() + const runtime = h.runtime + runtime.registerPreAllocatedHandleForPty('pty-worker', 'term_worker') + runtime.registerPty('pty-worker', 'repo::worktree', undefined, { + tabId: 'tab_worker', + leafId: 'bbbbbbbb-bbbb-4bbb-8bbb-bbbbbbbbbbbb', + incarnationId: 'runtime_test:term_worker:1' + }) + const write = vi.fn(() => true) + runtime.setPtyController({ write, kill: () => true, getForegroundProcess: async () => null }) + const commit = vi.fn(async () => {}) + vi.spyOn(runtime, 'beginMobileInputFloor').mockReturnValue({ commit, rollback: vi.fn() }) + const dbAccess = vi.spyOn(runtime, 'getOrchestrationDb') + const takeover = vi.spyOn(h.db, 'markWorkerTerminalUserOwned') + const prepare = vi.spyOn(h.db.db, 'prepare') + const exec = vi.spyOn(h.db.db, 'exec') + const params = { + terminal: 'term_worker', + text: 'x', + client: { id: 'phone', type: 'mobile' as const } + } + if (lane === 'stream') { + await expect(sendTerminalStreamInput(runtime, { ...params, isMobile: true })).resolves.toBe( + 'delivered' + ) + } else { + const method = TERMINAL_SEND_METHODS.find( + (m): m is RpcMethod => m.name === 'terminal.send' && !isStreamingMethod(m) + )! + await expect( + method.handler(method.params!.parse(params) as never, { runtime } as never) + ).resolves.toMatchObject({ send: { accepted: true } }) + } + expect(write).toHaveBeenCalledWith('pty-worker', 'x') + expect(commit).toHaveBeenCalledTimes(1) + expect(dbAccess).not.toHaveBeenCalled() + expect(takeover).not.toHaveBeenCalled() + expect(prepare).not.toHaveBeenCalled() + expect(exec).not.toHaveBeenCalled() + expect(h.db.getWorkerTerminalResourceByOwner(worker.dispatchId)?.ownership_state).toBe('owned') +}) + +it('the report is reachable from a mobile-scoped device token', async () => { + // Why: mobile tokens are gated by an allowlist before dispatch. The phone reporter swallows a + // refusal, so a missing entry silently reverts every phone to the unfenced behaviour. + const { MOBILE_RPC_METHOD_ALLOWLIST } = + await import('../../../../runtime-rpc/runtime-rpc-mobile-method-allowlist') + expect(MOBILE_RPC_METHOD_ALLOWLIST.has('orchestration.workerTerminalUserInput')).toBe(true) +}) + +// Round-1 regression (#19337 review): a phone key landing inside the worker's boot wait used to +// find no `owned` row, report `changed: 0`, and still arm the client's 30 s gate — so the real +// takeover was suppressed and `worker-release` closed the pane. #19608 writes custody at terminal +// creation, so the boot-wait key itself takes the pane. +it('a phone report during the boot wait takes the pane and fences the later release', async () => { + const gate = h.deferred() + vi.spyOn(h.runtime, 'waitForTerminal').mockReturnValue(gate.promise as never) + const task = h.db.createTask({ spec: 'mid-boot phone takeover', runId: h.activeRunId }) + const start = h.call('orchestration.workerStart', { + task: task.id, + from: 'term_coord', + agent: 'codex' + }) + await vi.waitFor(() => expect(h.runtime.waitForTerminal).toHaveBeenCalled()) + const dispatchId = ( + h.db.db.prepare("SELECT dispatch_id FROM worker_dispatches WHERE state = 'starting'").get() as { + dispatch_id: string + } + ).dispatch_id + + h.runtime.registerPreAllocatedHandleForPty('pty-worker', 'term_worker') + h.runtime.registerPty('pty-worker', 'repo::worktree', undefined, { + tabId: 'tab_worker', + leafId: 'bbbbbbbb-bbbb-4bbb-8bbb-bbbbbbbbbbbb' + }) + vi.mocked(h.runtime.getTerminalPaneKey).mockRestore() + await expect( + h.call('orchestration.workerTerminalUserInput', { terminal: 'term_worker' }) + ).resolves.toEqual({ changed: 1 }) + + gate.resolve({ + handle: 'term_worker', + condition: 'tui-idle', + satisfied: true, + status: 'running', + exitCode: null + }) + await expect(start).resolves.toMatchObject({ state: 'ready' }) + expect(h.db.getWorkerTerminalResourceByOwner(dispatchId)?.ownership_state).toBe('user_owned') + + h.settle(task.id, dispatchId, 'succeeded') + await expect( + h.call('orchestration.workerRelease', { dispatch: dispatchId }) + ).resolves.toMatchObject({ state: 'retained', reason: 'user_takeover', processAction: 'none' }) + expect(h.runtime.closeTerminal).not.toHaveBeenCalled() +}) diff --git a/src/main/runtime/rpc/methods/orchestration/worker/worker-release.test.ts b/src/main/runtime/rpc/methods/orchestration/worker/worker-release.test.ts index 5207b83c8de..e6466ed48c4 100644 --- a/src/main/runtime/rpc/methods/orchestration/worker/worker-release.test.ts +++ b/src/main/runtime/rpc/methods/orchestration/worker/worker-release.test.ts @@ -322,18 +322,36 @@ describe('orchestration worker release', () => { expect(h.db.getWorkerTerminalResourceByOwner(dispatchId)?.ownership_state).toBe('user_owned') }) - it('retains when the exact process identity changed instead of closing', async () => { + it('keeps a resumed settled worker retained in worker-list without re-dispatch or release', async () => { h.setup() - const { dispatchId } = await h.startSettledWorker() + const { dispatchId, taskId } = await h.startSettledWorker() + const dispatch = h.db.getDispatchContextById(dispatchId) + const task = h.db.getTask(taskId) + vi.mocked(h.runtime.createTerminal).mockClear() + vi.mocked(h.runtime.sendTerminalAgentPrompt).mockClear() vi.mocked(h.runtime.getTerminalProcessIncarnation).mockImplementation((handle) => handle === 'term_worker' ? 'runtime_test:term_worker:2' : null ) - const receipt = (await h.call('orchestration.workerRelease', { dispatch: dispatchId })) as { - state: string - reason?: string + + await expect( + h.call('orchestration.workerRelease', { dispatch: dispatchId }) + ).resolves.toMatchObject({ + state: 'retained', + reason: 'identity_unproven', + processAction: 'none' + }) + const listed = (await h.call('orchestration.workerList', { run: h.activeRunId })) as { + workers: { dispatchId: string; terminalState: string; workerState: string }[] } - expect(receipt).toMatchObject({ state: 'retained', reason: 'identity_unproven' }) + expect(listed.workers).toEqual([ + expect.objectContaining({ dispatchId, terminalState: 'retained', workerState: 'succeeded' }) + ]) + expect(h.db.getTask(taskId)).toEqual(task) + expect(h.db.getDispatchContextById(dispatchId)).toEqual(dispatch) + expect(h.db.getWorkerTerminalResourceByOwner(dispatchId)?.release_state).toBe('retained') expect(h.runtime.closeTerminal).not.toHaveBeenCalled() + expect(h.runtime.createTerminal).not.toHaveBeenCalled() + expect(h.runtime.sendTerminalAgentPrompt).not.toHaveBeenCalled() }) it('retains when the terminal host scope changed instead of closing', async () => { diff --git a/src/main/runtime/rpc/methods/orchestration/worker/worker-release.ts b/src/main/runtime/rpc/methods/orchestration/worker/worker-release.ts index 2a24a3efd0e..e121f1b3f25 100644 --- a/src/main/runtime/rpc/methods/orchestration/worker/worker-release.ts +++ b/src/main/runtime/rpc/methods/orchestration/worker/worker-release.ts @@ -10,7 +10,6 @@ import { type WorkerReleaseReceipt } from './worker-release-completion' import { WorkerDispatchParams, WorkerRetainParams } from './worker-release-schemas' -import { sweepSettledWorkerResumeFences } from '../../settled-worker-resume-fence-sweep' export const ORCHESTRATION_WORKER_RELEASE_METHODS: RpcMethod[] = [ defineMethod({ @@ -137,22 +136,27 @@ export const ORCHESTRATION_WORKER_RELEASE_METHODS: RpcMethod[] = [ // identity credential that never leaves main, so the caller names the session and the owning // runtime resolves it — a renderer echoing the pane key back would make it learnable. params: z - .object({ paneKey: z.string().min(1).optional(), sessionId: z.string().min(1).optional() }) - .refine((value) => Boolean(value.paneKey ?? value.sessionId), 'Missing paneKey or sessionId'), + .object({ + paneKey: z.string().min(1).optional(), + sessionId: z.string().min(1).optional(), + terminal: z.string().min(1).optional() + }) + .refine( + (value) => Boolean(value.paneKey ?? value.sessionId ?? value.terminal), + 'Missing paneKey, sessionId or terminal' + ), // Real user keystrokes durably relinquish orchestration ownership on the owning runtime, so // restarts, SSH drops, remote viewing, and renderer remounts cannot erase the takeover. handler: (params, { runtime }) => { // A structured worker reports by session id; it has no pane of its own to name. const paneKey = - params.paneKey ?? runtime.getStructuredWorkerPaneKeyForSession(params.sessionId!) + params.paneKey ?? + (params.sessionId + ? runtime.getStructuredWorkerPaneKeyForSession(params.sessionId) + : runtime.getTerminalPaneKey(params.terminal!)) const changed = paneKey ? runtime.getOrchestrationDb().markWorkerTerminalUserOwned(paneKey) : 0 - if (changed > 0) { - // Only a real takeover retires the resource; ordinary panes report here too and must not - // pay for a plan read on every keystroke window. - sweepSettledWorkerResumeFences(runtime) - } return { changed } } }) diff --git a/src/main/runtime/rpc/methods/orchestration/worker/worker-start-receipt.ts b/src/main/runtime/rpc/methods/orchestration/worker/worker-start-receipt.ts index 9fd98dd9db3..f2dee00b44c 100644 --- a/src/main/runtime/rpc/methods/orchestration/worker/worker-start-receipt.ts +++ b/src/main/runtime/rpc/methods/orchestration/worker/worker-start-receipt.ts @@ -4,8 +4,8 @@ import { isUnknownWorkerStartOutcome, type WorkerSetupReceipt } from './worker-t import type { OrchestrationWorkerLaunchReceipt } from './worker-launch-preferences' import type { WorkerStartModeReceipt } from '../../orchestration-worker-start-mode' import { isAgentSessionPtyWriteRefusedError } from '../../../../../../shared/agent-session-pty-write-admission' -import type { FailedStartTerminalAdoption } from '../../../../orchestration/db/worker-terminal/failed-start-terminal-adoption' import { structuredChatPtyWriteRefusalCopy } from '../../../../../../shared/agent-session-pty-write-refusal-copy' +import { isStructuredWorkerHandle } from '../../../../structured-worker-identity' export function failWorkerStartWithReceipt(args: { db: OrchestrationDb @@ -17,8 +17,6 @@ export function failWorkerStartWithReceipt(args: { setup: WorkerSetupReceipt launch: OrchestrationWorkerLaunchReceipt mode: WorkerStartModeReceipt - /** The terminal this start created and never handed to an owner. */ - residualAgentTerminal?: FailedStartTerminalAdoption }): unknown { const agentSessionRefusal = isAgentSessionPtyWriteRefusedError(args.error) ? args.error.refusal @@ -33,14 +31,14 @@ export function failWorkerStartWithReceipt(args: { : args.db.failWorkerStart(args.dispatchId, args.failedStage, reason, { // Why (#16095): the preamble is written before submission is verified, so a stalled // verdict never means the worker lacks its task — keep the authority its report needs. - retainCapability: isAgentPromptStalledError(args.error), - ...(args.residualAgentTerminal ? { adoptResidualTerminal: args.residualAgentTerminal } : {}) + retainCapability: isAgentPromptStalledError(args.error) }) - // Only claim cleanup the ownership table actually accepted; the adoption declines a terminal - // another resource already accounts for. - const adopted = - Boolean(args.residualAgentTerminal) && - Boolean(args.db.getWorkerTerminalResourceByOwner(args.dispatchId)) + // Only name cleanup this start actually left behind: a terminal it created and still owns. A + // structured session is discarded by the teardown, a pane the user typed into is theirs, and an + // unknown outcome is not settled — none of the three has anything for `worker-release` to close. + const residual = unknown ? undefined : args.db.getWorkerTerminalResourceByOwner(args.dispatchId) + const releasable = + residual?.ownership_state === 'owned' && !isStructuredWorkerHandle(residual.terminal_handle) return { runId: args.runId, taskId: args.taskId, @@ -55,7 +53,7 @@ export function failWorkerStartWithReceipt(args: { effects: JSON.parse(worker.effects) as unknown[], residualResources: JSON.parse(worker.residual_resources) as unknown[], ...(agentSessionRefusal ? { agentSessionRefusal } : {}), - ...(adopted + ...(releasable ? { recovery: `This start created a terminal that never ran the Task. Close it with: orca orchestration worker-release --dispatch ${args.dispatchId}` } diff --git a/src/main/runtime/rpc/methods/orchestration/worker/worker-stop.ts b/src/main/runtime/rpc/methods/orchestration/worker/worker-stop.ts index 605d8c52d4a..643323cf62e 100644 --- a/src/main/runtime/rpc/methods/orchestration/worker/worker-stop.ts +++ b/src/main/runtime/rpc/methods/orchestration/worker/worker-stop.ts @@ -245,8 +245,9 @@ export const ORCHESTRATION_WORKER_STOP_METHODS: RpcMethod[] = [ const activeStopByRuntime = new WeakMap>>() -/** Two callers stopping one Dispatch: the second reached `beginWorkerStop` after the first moved - * the row to `stopping` and got `dispatch_inactive` instead of the first caller's receipt. */ +/** Two callers stopping one Dispatch: coalesced so only one of them closes the terminal. Both are + * in this runtime and so carry one epoch, which `beginWorkerStop` refuses a second time anyway; + * the epoch it does accept belongs to a row a dead runtime stranded, and no caller here holds one. */ function dedupeWorkerStop( runtime: OrcaRuntimeService, dispatchId: string, diff --git a/src/main/runtime/rpc/methods/orchestration/worker/worker-terminal-custody-at-creation.test.ts b/src/main/runtime/rpc/methods/orchestration/worker/worker-terminal-custody-at-creation.test.ts new file mode 100644 index 00000000000..201201e5877 --- /dev/null +++ b/src/main/runtime/rpc/methods/orchestration/worker/worker-terminal-custody-at-creation.test.ts @@ -0,0 +1,216 @@ +/** + * Custody for an agent terminal this start created is written when the terminal is created, not + * after the agent boot wait. + * + * A worker pane is visible on desktop and phone the moment it exists. While the row was written + * only after `tui-idle` (up to 60 s later), a keystroke into the booting pane found no `owned` row, + * `markWorkerTerminalUserOwned` returned 0, and the takeover was lost — so a later `worker-release` + * closed the pane the user had claimed. + */ + +import { afterEach, describe, expect, it, vi } from 'vitest' +import { OrchestrationDb } from '../../../../orchestration/db' +import { createOrchestrationWorkerReleaseHarness } from './worker-release.test-support' + +const READY_WAIT = { + handle: 'term_worker', + condition: 'tui-idle', + satisfied: true, + status: 'running', + exitCode: null +} + +describe('worker terminal custody is recorded at terminal creation', () => { + const h = createOrchestrationWorkerReleaseHarness() + + afterEach(() => h.cleanup()) + + /** Holds the agent boot wait open so the mid-start database state can be read. */ + function holdBootWait(): { finish: (satisfied?: boolean) => void } { + const gate = h.deferred() + vi.spyOn(h.runtime, 'waitForTerminal').mockReturnValue(gate.promise as never) + return { + finish: (satisfied = true) => + gate.resolve({ ...READY_WAIT, satisfied, status: satisfied ? 'running' : 'exited' }) + } + } + + function startingDispatchId(): string { + return ( + h.db.db + .prepare("SELECT dispatch_id FROM worker_dispatches WHERE state = 'starting'") + .get() as { dispatch_id: string } + ).dispatch_id + } + + async function startHeldAtBootWait(options: { terminal?: string } = {}): Promise<{ + dispatchId: string + taskId: string + start: Promise + finish: (satisfied?: boolean) => void + }> { + const task = h.db.createTask({ spec: 'custody at creation', runId: h.activeRunId }) + const { finish } = holdBootWait() + const start = h.call('orchestration.workerStart', { + task: task.id, + from: 'term_coord', + ...(options.terminal ? { terminal: options.terminal } : { agent: 'codex' }) + }) + await vi.waitFor(() => expect(h.runtime.waitForTerminal).toHaveBeenCalled()) + return { dispatchId: startingDispatchId(), taskId: task.id, start, finish } + } + + it('owns the created terminal before the boot wait resolves', async () => { + h.setup() + const held = await startHeldAtBootWait() + + expect(h.db.getWorkerTerminalResourceByOwner(held.dispatchId)).toMatchObject({ + ownership_state: 'owned', + release_state: 'not_requested', + terminal_handle: 'term_worker', + pane_key: h.workerPaneKey, + process_incarnation: 'runtime_test:term_worker:1', + host_scope: JSON.stringify({ kind: 'local', hostId: 'local' }) + }) + // worker-list reads the same row: a booting worker now says `active`, not `retained`. + expect(h.db.listWorkerTerminalResources({ dispatchIds: [held.dispatchId] })[0]).toMatchObject({ + agentTerminalHandle: 'term_worker', + terminalState: 'active' + }) + + held.finish() + await expect(held.start).resolves.toMatchObject({ state: 'ready' }) + }) + + it('claims nothing for an explicitly reused terminal until authority transfers it', async () => { + h.setup() + const held = await startHeldAtBootWait({ terminal: 'term_worker' }) + + expect(h.db.getWorkerTerminalResourceByOwner(held.dispatchId)).toBeUndefined() + + held.finish() + await expect(held.start).resolves.toMatchObject({ state: 'ready' }) + expect(h.db.getWorkerTerminalResourceByOwner(held.dispatchId)).toMatchObject({ + ownership_state: 'external', + retained_reason: 'external_terminal' + }) + }) + + it('lets a keystroke during the boot wait take the pane, and release then retains it', async () => { + h.setup() + const held = await startHeldAtBootWait() + + await expect( + h.call('orchestration.workerTerminalUserInput', { paneKey: h.workerPaneKey }) + ).resolves.toEqual({ changed: 1 }) + + held.finish() + await expect(held.start).resolves.toMatchObject({ state: 'ready' }) + expect(h.db.getWorkerTerminalResourceByOwner(held.dispatchId)).toMatchObject({ + ownership_state: 'user_owned', + retained_reason: 'user_takeover' + }) + + h.settle(held.taskId, held.dispatchId, 'succeeded') + await expect( + h.call('orchestration.workerRelease', { dispatch: held.dispatchId }) + ).resolves.toMatchObject({ state: 'retained', reason: 'user_takeover', processAction: 'none' }) + expect(h.runtime.closeTerminal).not.toHaveBeenCalled() + }) + + it('still refuses to release a starting worker that already owns its terminal', async () => { + h.setup() + const held = await startHeldAtBootWait() + + await expect( + h.call('orchestration.workerRelease', { dispatch: held.dispatchId }) + ).rejects.toThrow(/only a settled worker can release/) + + held.finish() + await held.start + }) + + it('leaves a start that died on the boot wait a terminal worker-release can close', async () => { + h.setup() + const held = await startHeldAtBootWait() + held.finish(false) + + await expect(held.start).resolves.toMatchObject({ + state: 'failed', + failedStage: 'agent_readiness', + recovery: expect.stringContaining('worker-release') + }) + expect(h.db.getWorkerTerminalResourceByOwner(held.dispatchId)).toMatchObject({ + ownership_state: 'owned', + terminal_handle: 'term_worker' + }) + + await expect( + h.call('orchestration.workerRelease', { dispatch: held.dispatchId }) + ).resolves.toMatchObject({ state: 'released', processAction: 'closed_agent_terminal' }) + expect(h.runtime.closeTerminal).toHaveBeenCalledWith('term_worker') + }) + + it('promises no cleanup while the start outcome is still unknown', async () => { + h.setup() + const task = h.db.createTask({ spec: 'unknown outcome', runId: h.activeRunId }) + const unknown = Object.assign(new Error('the execution host went away'), { + code: 'operation_unknown' + }) + vi.spyOn(h.runtime, 'waitForTerminal').mockRejectedValue(unknown) + + const receipt = (await h.call('orchestration.workerStart', { + task: task.id, + from: 'term_coord', + agent: 'codex' + })) as { state: string; dispatchId: string; nextCommands?: string[] } + + expect(receipt).toMatchObject({ state: 'outcome_unknown' }) + // worker-release refuses an unsettled worker, so the receipt must not name it. + expect(receipt).not.toHaveProperty('recovery') + expect(receipt.nextCommands?.join(' ')).toContain('worker-abandon') + expect(h.db.getWorkerTerminalResourceByOwner(receipt.dispatchId)).toMatchObject({ + ownership_state: 'owned' + }) + }) + + it('promises no cleanup for a reused terminal whose start died', async () => { + h.setup() + const held = await startHeldAtBootWait({ terminal: 'term_worker' }) + held.finish(false) + + const receipt = await held.start + expect(receipt).toMatchObject({ state: 'failed' }) + expect(receipt).not.toHaveProperty('recovery') + expect(h.db.getWorkerTerminalResourceByOwner(held.dispatchId)).toBeUndefined() + }) +}) + +describe('custody refuses a dispatch that stopped while its terminal was being created', () => { + let db: OrchestrationDb | undefined + + afterEach(() => db?.close()) + + it('records no owner once the dispatch is no longer starting', () => { + const d = (db = new OrchestrationDb(':memory:')) + const started = d.createStartingWorkerDispatch({ + creator: { kind: 'system' }, + maxDepth: Number.MAX_SAFE_INTEGER, + taskId: d.createTask({ runId: 'run_legacy_local', spec: 'stopped mid-create' }).id, + startOptions: {} + }) + // Startup reconciliation abandons a `starting` worker whose terminal it cannot find. + d.reconcileMissingWorkerTerminal(started.dispatch.id, 'runtime restarted') + + expect(() => + d.recordCreatedWorkerTerminalCustody({ + dispatchId: started.dispatch.id, + handle: 'term_worker', + paneKey: 'tab_w:leaf_w', + processIncarnation: 'pty_w:1', + worktreeId: 'repo::worktree' + }) + ).toThrow(/is not starting/) + expect(d.getWorkerTerminalResourceByOwner(started.dispatch.id)).toBeUndefined() + }) +}) diff --git a/src/main/runtime/rpc/methods/settled-worker-resume-fence-sweep.ts b/src/main/runtime/rpc/methods/settled-worker-resume-fence-sweep.ts deleted file mode 100644 index e3aac0e5803..00000000000 --- a/src/main/runtime/rpc/methods/settled-worker-resume-fence-sweep.ts +++ /dev/null @@ -1,45 +0,0 @@ -import type { OrcaRuntimeService } from '../../orca-runtime' -import type { RpcMethod } from '../core' - -/** - * One pass both stamps the automatic-resume fence on every settled worker pane and lifts it from - * every pane the recovery plan no longer claims. A fenced pane refuses a fresh spawn, so any path - * that drops a worker's row from that plan — release, user retain, user takeover — has to run the - * sweep in the same call, or the fence outlives its dispatch and the pane stays unspawnable until - * the next app start. Failures are swallowed: a fence sweep must never fail the RPC behind it. - */ -export function sweepSettledWorkerResumeFences(runtime: OrcaRuntimeService): void { - try { - runtime.prepareLegacyWorkerTerminalRecovery() - } catch (error) { - console.warn('[orchestration] settled worker resume fence sweep failed', error) - } -} - -/** Settling a worker is what makes its pane fenceable, and release/retain/takeover are what make it - * unfenceable again — so every one of those has to sweep in the same call. Without the settlement - * half the fence only appeared at the next app start, and reopening the pane in the same session - * respawned the agent. */ -const FENCE_SWEEPING_METHOD_NAMES = new Set([ - 'orchestration.workerRelease', - 'orchestration.workerRetain', - 'orchestration.workerStop', - 'orchestration.workerAbandon', - // Reusing a settled worker's pane for a new Dispatch drops the old row from the plan; without - // this the stale fence stays on the pane it just relaunched into. - 'orchestration.workerStart' -]) - -export function sweepingSettledWorkerResumeFences(method: RpcMethod): RpcMethod { - if (!FENCE_SWEEPING_METHOD_NAMES.has(method.name)) { - return method - } - return { - ...method, - handler: async (params, ctx) => { - const result = await method.handler(params, ctx) - sweepSettledWorkerResumeFences(ctx.runtime) - return result - } - } -} diff --git a/src/main/runtime/rpc/methods/structured-worker-stop-receipt.test.ts b/src/main/runtime/rpc/methods/structured-worker-stop-receipt.test.ts index 82cc53ff735..151285ffb1e 100644 --- a/src/main/runtime/rpc/methods/structured-worker-stop-receipt.test.ts +++ b/src/main/runtime/rpc/methods/structured-worker-stop-receipt.test.ts @@ -62,7 +62,10 @@ describe('worker-stop on a structured worker this runtime cannot reach', () => { worktreeId: WORKTREE, hostScope: { kind: 'local', hostId: 'local' } }) - const task = db.createTask({ spec: 'stop a structured worker' }) + const task = db.createTask({ + runId: 'run_legacy_local', + spec: 'stop a structured worker' + }) const started = db.createStartingWorkerDispatch({ creator: { kind: 'system' }, maxDepth: Number.MAX_SAFE_INTEGER, diff --git a/src/main/runtime/rpc/orchestration-11745-regression-verification.test.ts b/src/main/runtime/rpc/orchestration-11745-regression-verification.test.ts index 47d585ca244..7a644cc9def 100644 --- a/src/main/runtime/rpc/orchestration-11745-regression-verification.test.ts +++ b/src/main/runtime/rpc/orchestration-11745-regression-verification.test.ts @@ -642,7 +642,11 @@ function createAdoptedDb(options: { settleWork: boolean }): { const dbPath = join(dir, 'orchestration.db') const before = new OrchestrationDb(dbPath) - const task = before.createTask({ spec: 'legacy assignment', createdByTerminalHandle: 'term_old' }) + const task = before.createTask({ + runId: 'run_legacy_local', + spec: 'legacy assignment', + createdByTerminalHandle: 'term_old' + }) createRootDispatch( before, task.id, @@ -650,6 +654,7 @@ function createAdoptedDb(options: { settleWork: boolean }): { 'tab_old:33333333-3333-4333-8333-333333333333' ) const recovery = before.insertMessage({ + runId: 'run_legacy_local', from: 'term_old_worker', to: 'term_old', subject: 'recovered worker outcome', diff --git a/src/main/runtime/rpc/orchestration-legacy-compatibility-dispatcher-test-fixture.ts b/src/main/runtime/rpc/orchestration-legacy-compatibility-dispatcher-test-fixture.ts index cca68da8f63..faf934a6d66 100644 --- a/src/main/runtime/rpc/orchestration-legacy-compatibility-dispatcher-test-fixture.ts +++ b/src/main/runtime/rpc/orchestration-legacy-compatibility-dispatcher-test-fixture.ts @@ -53,6 +53,7 @@ export function createHarness(): LegacyCompatibilityDispatcherHarness { const dbPath = join(dir, 'orchestration.db') const before = new OrchestrationDb(dbPath) const task = before.createTask({ + runId: 'run_legacy_local', spec: 'legacy assignment', createdByTerminalHandle: COORDINATOR_HANDLE }) diff --git a/src/main/runtime/rpc/orchestration-legacy-coordinator-race.test.ts b/src/main/runtime/rpc/orchestration-legacy-coordinator-race.test.ts index 3040c37a9ef..71daf09b0e3 100644 --- a/src/main/runtime/rpc/orchestration-legacy-coordinator-race.test.ts +++ b/src/main/runtime/rpc/orchestration-legacy-coordinator-race.test.ts @@ -43,6 +43,7 @@ function createHarness(): Harness { const dbPath = join(dir, 'orchestration.db') const before = new OrchestrationDb(dbPath) const task = before.createTask({ + runId: 'run_legacy_local', spec: 'legacy assignment', createdByTerminalHandle: COORDINATOR_HANDLE }) diff --git a/src/main/runtime/rpc/orchestration-legacy-question-takeover.test.ts b/src/main/runtime/rpc/orchestration-legacy-question-takeover.test.ts index 77d7e2d5a02..82c59f39587 100644 --- a/src/main/runtime/rpc/orchestration-legacy-question-takeover.test.ts +++ b/src/main/runtime/rpc/orchestration-legacy-question-takeover.test.ts @@ -40,12 +40,14 @@ function createHarness(options?: { seedCutoverQuestion?: boolean; seedCutoverAns const dbPath = join(dir, 'orchestration.db') const before = new OrchestrationDb(dbPath) const task = before.createTask({ + runId: 'run_legacy_local', spec: 'legacy assignment', createdByTerminalHandle: COORDINATOR_HANDLE }) const dispatch = createRootDispatch(before, task.id, WORKER_HANDLE, WORKER_PANE) const cutoverQuestion = options?.seedCutoverQuestion ? before.insertMessage({ + runId: 'run_legacy_local', from: WORKER_HANDLE, to: COORDINATOR_HANDLE, subject: 'Question', @@ -60,6 +62,7 @@ function createHarness(options?: { seedCutoverQuestion?: boolean; seedCutoverAns const cutoverAnswer = cutoverQuestion && options?.seedCutoverAnswer ? before.insertMessage({ + runId: 'run_legacy_local', from: COORDINATOR_HANDLE, to: WORKER_HANDLE, subject: 'Re: Question', @@ -308,7 +311,10 @@ describe('legacy question takeover compatibility', () => { resumed as { result: { legacyCompatibility: { - answerAcknowledgement: { questionId: string; answerMessageId: string } + answerAcknowledgement: { + questionId: string + answerMessageId: string + } } } } diff --git a/src/main/runtime/rpc/orchestration-legacy-takeover-delivery.test.ts b/src/main/runtime/rpc/orchestration-legacy-takeover-delivery.test.ts index bcaf5fca11f..feb3017b538 100644 --- a/src/main/runtime/rpc/orchestration-legacy-takeover-delivery.test.ts +++ b/src/main/runtime/rpc/orchestration-legacy-takeover-delivery.test.ts @@ -51,6 +51,7 @@ function createHarness(): Harness { const dbPath = join(dir, 'orchestration.db') const before = new OrchestrationDb(dbPath) const task = before.createTask({ + runId: 'run_legacy_local', spec: 'legacy assignment', createdByTerminalHandle: COORDINATOR_HANDLE }) diff --git a/src/main/runtime/rpc/orchestration-legacy-takeover-dispatcher.test.ts b/src/main/runtime/rpc/orchestration-legacy-takeover-dispatcher.test.ts index 2a2d6b4937b..e5a05fe7d26 100644 --- a/src/main/runtime/rpc/orchestration-legacy-takeover-dispatcher.test.ts +++ b/src/main/runtime/rpc/orchestration-legacy-takeover-dispatcher.test.ts @@ -47,6 +47,7 @@ function createHarness(): Harness { const dbPath = join(dir, 'orchestration.db') const before = new OrchestrationDb(dbPath) const task = before.createTask({ + runId: 'run_legacy_local', spec: 'legacy assignment', createdByTerminalHandle: COORDINATOR_HANDLE }) diff --git a/src/main/runtime/rpc/orchestration-mutation-ledger.test.ts b/src/main/runtime/rpc/orchestration-mutation-ledger.test.ts index d44d3f153d7..b87f595f4b2 100644 --- a/src/main/runtime/rpc/orchestration-mutation-ledger.test.ts +++ b/src/main/runtime/rpc/orchestration-mutation-ledger.test.ts @@ -44,7 +44,7 @@ describe('durable orchestration mutation ledger', () => { const runtime = new OrcaRuntimeService() runtime.setOrchestrationDb(db) const effect = vi.fn((subject: string) => - db.insertMessage({ from: 'caller', to: 'recipient', subject }) + db.insertMessage({ runId: 'run_legacy_local', from: 'caller', to: 'recipient', subject }) ) const dispatcher = new RpcDispatcher({ runtime, @@ -299,7 +299,10 @@ describe('durable orchestration mutation ledger', () => { const db = new OrchestrationDb(':memory:') const runtime = new OrcaRuntimeService() runtime.setOrchestrationDb(db) - const params = { from: 'term_coord', task: db.createTask({ spec: 'restart' }).id } + const params = { + from: 'term_coord', + task: db.createTask({ runId: 'run_legacy_local', spec: 'restart' }).id + } const callerFingerprint = db.getOrCreateLocalMutationCallerFingerprint() const payloadHash = createHash('sha256') .update(JSON.stringify({ method: 'orchestration.workerStart', params })) diff --git a/src/main/runtime/rpc/orchestration-mutation-request-show.test.ts b/src/main/runtime/rpc/orchestration-mutation-request-show.test.ts index cb31ea22736..e64fb5b9640 100644 --- a/src/main/runtime/rpc/orchestration-mutation-request-show.test.ts +++ b/src/main/runtime/rpc/orchestration-mutation-request-show.test.ts @@ -22,7 +22,7 @@ function createHarness() { const runtime = new OrcaRuntimeService() runtime.setOrchestrationDb(db) const effect = vi.fn((subject: string) => - db.insertMessage({ from: 'caller', to: 'recipient', subject }) + db.insertMessage({ runId: 'run_legacy_local', from: 'caller', to: 'recipient', subject }) ) const dispatcher = new RpcDispatcher({ runtime, diff --git a/src/main/runtime/rpc/orchestration-runtime-update-settlement.test.ts b/src/main/runtime/rpc/orchestration-runtime-update-settlement.test.ts index b2d3d110627..4172097853d 100644 --- a/src/main/runtime/rpc/orchestration-runtime-update-settlement.test.ts +++ b/src/main/runtime/rpc/orchestration-runtime-update-settlement.test.ts @@ -62,6 +62,7 @@ function createUpdateHarness(): Harness { const oldRuntimeDb = new OrchestrationDb(dbPath) const task = oldRuntimeDb.createTask({ + runId: 'run_legacy_local', spec: 'finish work across an app update', createdByTerminalHandle: COORDINATOR_HANDLE }) diff --git a/src/main/runtime/runtime-legacy-worker-terminal-recovery-controller.ts b/src/main/runtime/runtime-legacy-worker-terminal-recovery-controller.ts index cbb28e20336..ce034d8e349 100644 --- a/src/main/runtime/runtime-legacy-worker-terminal-recovery-controller.ts +++ b/src/main/runtime/runtime-legacy-worker-terminal-recovery-controller.ts @@ -22,10 +22,6 @@ export class RuntimeLegacyWorkerTerminalRecoveryController { constructor(private readonly ports: LegacyWorkerRecoveryPorts) {} - prepare(): LegacyWorkerTerminalRecoveryPlan { - return this.ports.preparePlan() - } - reconcile( options: LegacyWorkerRecoveryOptions = {} ): Promise { diff --git a/src/main/runtime/runtime-legacy-worker-terminal-recovery-persistence.ts b/src/main/runtime/runtime-legacy-worker-terminal-recovery-persistence.ts index 613718de7e5..df794567737 100644 --- a/src/main/runtime/runtime-legacy-worker-terminal-recovery-persistence.ts +++ b/src/main/runtime/runtime-legacy-worker-terminal-recovery-persistence.ts @@ -1,4 +1,4 @@ -import { LOCAL_EXECUTION_HOST_ID, type ExecutionHostId } from '../../shared/execution-host' +import type { ExecutionHostId } from '../../shared/execution-host' import type { WorkspaceSessionState } from '../../shared/workspace-session-state-types' import { retireTerminalSurfaceFromPersistence } from './mobile-session-terminal-persistence-retirement' import type { OrchestrationDb } from './orchestration/db' @@ -18,144 +18,11 @@ export class RuntimeLegacyWorkerTerminalRecoveryPersistence { constructor( private readonly getStore: () => RuntimeStore | null, private readonly getDb: () => OrchestrationDb, - private readonly getHostId: (worktreeId: string) => ExecutionHostId | null, - /** The store write only reaches the next app start; a live renderer holds its own copy. */ - private readonly notifyFenceChanged?: (paneKey: string, blocked: boolean) => void + private readonly getHostId: (worktreeId: string) => ExecutionHostId | null ) {} - /** Panes announced as fenced before any sleeping record existed; the only place a lift for one - * can come from, because `liftRetiredFences` can only see panes that already have a record. */ - private readonly announcedBlockedPaneKeys = new Set() - prepare(): LegacyWorkerTerminalRecoveryPlan { - const plan = this.getPlan() - if (!plan) { - // An unreadable plan is not evidence that any pane stopped needing its fence: stamp - // nothing, lift nothing, retry on the next pass. - return { blockedPanes: [], candidates: [], ambiguousDispatchIds: [] } - } - const store = this.getStore() - if ( - !store?.getWorkspaceSession || - !store.setWorkspaceSession || - (!store.flushPendingOrThrowAsync && !store.flushOrThrow) - ) { - return plan - } - const sessions = new Map< - ExecutionHostId, - { current: WorkspaceSessionState; next: WorkspaceSessionState } - >() - const changedHostIds = new Set() - const fenceChanges: [string, boolean][] = [] - for (const blocked of plan.blockedPanes) { - // A worker can settle while its tab is still open, so there is no sleeping record to stamp - // yet. Tell the live renderer anyway: it mints the record on close and must fence it there. - if (!this.announcedBlockedPaneKeys.has(blocked.paneKey)) { - this.announcedBlockedPaneKeys.add(blocked.paneKey) - fenceChanges.push([blocked.paneKey, true]) - } - let hostIds: ExecutionHostId[] - try { - const hostId = this.getHostId(blocked.worktreeId) - if (!hostId) { - throw new Error('folder_workspace_not_found') - } - hostIds = [hostId] - } catch (error) { - console.warn('[orchestration] legacy worker resume fence owner is unavailable', { - worktreeId: blocked.worktreeId, - error - }) - hostIds = store.getWorkspaceSessionHostIds?.() ?? [LOCAL_EXECUTION_HOST_ID] - } - for (const hostId of hostIds) { - let state = sessions.get(hostId) - if (!state) { - const current = store.getWorkspaceSession(hostId) - if (!current) { - continue - } - state = { current, next: structuredClone(current) } - sessions.set(hostId, state) - } - const record = state.next.sleepingAgentSessionsByPaneKey?.[blocked.paneKey] - if ( - !record || - !runtimeWorktreeIdsEqual(record.worktreeId, blocked.worktreeId) || - record.automaticResumeBlockedBy === 'legacy-orchestration-worker' - ) { - continue - } - state.next.sleepingAgentSessionsByPaneKey = { - ...state.next.sleepingAgentSessionsByPaneKey, - [blocked.paneKey]: { ...record, automaticResumeBlockedBy: 'legacy-orchestration-worker' } - } - changedHostIds.add(hostId) - } - } - this.liftRetiredFences(store, plan, sessions, changedHostIds, fenceChanges) - const changed = [...sessions].filter(([hostId]) => changedHostIds.has(hostId)) - try { - for (const [hostId, state] of changed) { - store.setWorkspaceSession(state.next, hostId) - } - } catch (error) { - console.warn('[orchestration] failed to stage legacy worker resume fence', error) - return plan - } - for (const [paneKey, blocked] of fenceChanges) { - this.notifyFenceChanged?.(paneKey, blocked) - } - return plan - } - - /** A fence that outlives its dispatch leaves a pane that can never spawn again, so release, - * retain, user takeover and dispatch pruning — each of which drops the row from the plan — - * retire it here. An unreadable plan yields no blocked panes, so callers must not sweep. */ - private liftRetiredFences( - store: RuntimeStore, - plan: LegacyWorkerTerminalRecoveryPlan, - sessions: Map, - changedHostIds: Set, - fenceChanges: [string, boolean][] - ): void { - const blockedPaneKeys = new Set(plan.blockedPanes.map((blocked) => blocked.paneKey)) - for (const paneKey of this.announcedBlockedPaneKeys) { - if (!blockedPaneKeys.has(paneKey)) { - this.announcedBlockedPaneKeys.delete(paneKey) - fenceChanges.push([paneKey, false]) - } - } - for (const hostId of store.getWorkspaceSessionHostIds?.() ?? [LOCAL_EXECUTION_HOST_ID]) { - const staged = sessions.get(hostId) - const session = staged?.next ?? store.getWorkspaceSession?.(hostId) - const retired = Object.entries(session?.sleepingAgentSessionsByPaneKey ?? {}).filter( - ([paneKey, record]) => - record.automaticResumeBlockedBy === 'legacy-orchestration-worker' && - !blockedPaneKeys.has(paneKey) - ) - if (retired.length === 0) { - continue - } - let state = staged - if (!state) { - const current = store.getWorkspaceSession?.(hostId) - if (!current) { - continue - } - state = { current, next: structuredClone(current) } - sessions.set(hostId, state) - } - const next = { ...state.next.sleepingAgentSessionsByPaneKey } - for (const [paneKey, record] of retired) { - const { automaticResumeBlockedBy: _retired, ...unfenced } = record - next[paneKey] = unfenced - fenceChanges.push([paneKey, false]) - } - state.next.sleepingAgentSessionsByPaneKey = next - changedHostIds.add(hostId) - } + return this.getPlan() ?? { candidates: [], ambiguousDispatchIds: [] } } async persist( diff --git a/src/main/runtime/runtime-legacy-worker-terminal-recovery-runner.ts b/src/main/runtime/runtime-legacy-worker-terminal-recovery-runner.ts index bd15abc7d4d..6bbe3b2ed2f 100644 --- a/src/main/runtime/runtime-legacy-worker-terminal-recovery-runner.ts +++ b/src/main/runtime/runtime-legacy-worker-terminal-recovery-runner.ts @@ -104,7 +104,6 @@ export async function runLegacyWorkerTerminalRecovery( exitedDispatchIds.push(candidate.dispatchId) } const result = { - blockedPaneCount: plan.blockedPanes.length, adoptedDispatchIds, exitedDispatchIds, deferredDispatchIds: [...deferredDispatchIds] diff --git a/src/main/runtime/runtime-legacy-worker-terminal-recovery-types.ts b/src/main/runtime/runtime-legacy-worker-terminal-recovery-types.ts index c65afd73952..16ca330647c 100644 --- a/src/main/runtime/runtime-legacy-worker-terminal-recovery-types.ts +++ b/src/main/runtime/runtime-legacy-worker-terminal-recovery-types.ts @@ -5,7 +5,6 @@ import type { PtyControllerInventory } from './runtime-pty-controller-contract' import type { ResolvedWorktree } from './runtime-worktree-path-identity' export type LegacyWorkerTerminalRecoveryResult = { - blockedPaneCount: number adoptedDispatchIds: string[] exitedDispatchIds: string[] deferredDispatchIds: string[] diff --git a/src/main/runtime/runtime-legacy-worker-terminal-resume-fence.test.ts b/src/main/runtime/runtime-legacy-worker-terminal-resume-fence.test.ts deleted file mode 100644 index 6fe14f2abe7..00000000000 --- a/src/main/runtime/runtime-legacy-worker-terminal-resume-fence.test.ts +++ /dev/null @@ -1,286 +0,0 @@ -import { afterEach, describe, expect, it, vi } from 'vitest' -import { getDefaultWorkspaceSession } from '../../shared/constants' -import { LOCAL_EXECUTION_HOST_ID } from '../../shared/execution-host' -import type { WorkspaceSessionState } from '../../shared/workspace-session-state-types' -import { OrchestrationDb } from './orchestration/db' -import { OrcaRuntimeService } from './orca-runtime' -import { ORCHESTRATION_METHODS } from './rpc/methods/orchestration' -import { RuntimeLegacyWorkerTerminalRecoveryPersistence } from './runtime-legacy-worker-terminal-recovery-persistence' -import type { RuntimeStore } from './runtime-store-contract' - -const PANE_KEY = 'tab_worker:33333333-3333-4333-8333-333333333333' -const WORKTREE_ID = 'repo::worktree' - -function sessionWithSleepingWorker(): WorkspaceSessionState { - return { - ...getDefaultWorkspaceSession(), - sleepingAgentSessionsByPaneKey: { - [PANE_KEY]: { - paneKey: PANE_KEY, - tabId: 'tab_worker', - worktreeId: WORKTREE_ID, - agent: 'codex', - providerSession: { key: 'session_id', id: 'codex-session-1' }, - prompt: '', - state: 'done', - capturedAt: 1, - updatedAt: 1, - origin: 'live' - } - } - } as WorkspaceSessionState -} - -describe('settled worker automatic-resume fence persistence', () => { - let db: OrchestrationDb | undefined - - afterEach(() => db?.close()) - - function harness( - onFenceChanged?: (paneKey: string, blocked: boolean) => void, - /** False models a worker that settles while its tab is still open: no record to stamp yet. */ - withSleepingRecord = true - ): { - db: OrchestrationDb - taskId: string - dispatchId: string - persistence: RuntimeLegacyWorkerTerminalRecoveryPersistence - fence: () => string | undefined - } { - const orchestrationDb = new OrchestrationDb(':memory:') - db = orchestrationDb - let session = withSleepingRecord - ? sessionWithSleepingWorker() - : (getDefaultWorkspaceSession() as WorkspaceSessionState) - const store = { - getWorkspaceSession: () => session, - setWorkspaceSession: (next: WorkspaceSessionState) => { - session = next - }, - getWorkspaceSessionHostIds: () => [LOCAL_EXECUTION_HOST_ID], - flushOrThrow: vi.fn() - } as unknown as RuntimeStore - const task = orchestrationDb.createTask({ spec: 'fence me' }) - const started = orchestrationDb.createStartingWorkerDispatch({ - creator: { kind: 'system' }, - maxDepth: Number.MAX_SAFE_INTEGER, - taskId: task.id, - startOptions: {} - }) - orchestrationDb.prepareStartingWorkerAuthority({ - dispatchId: started.dispatch.id, - handle: 'term_worker', - paneKey: PANE_KEY, - processIncarnation: 'runtime:pty:1', - worktreeId: WORKTREE_ID, - setupState: 'not_applicable', - effects: [], - terminalOwnership: 'created' - }) - orchestrationDb.markWorkerDispatchReady(started.dispatch.id) - return { - db: orchestrationDb, - taskId: task.id, - dispatchId: started.dispatch.id, - persistence: new RuntimeLegacyWorkerTerminalRecoveryPersistence( - () => store, - () => orchestrationDb, - () => LOCAL_EXECUTION_HOST_ID, - onFenceChanged - ), - fence: () => session.sleepingAgentSessionsByPaneKey?.[PANE_KEY]?.automaticResumeBlockedBy - } - } - - function settle(d: OrchestrationDb, taskId: string, dispatchId: string): void { - expect( - d.settleWorkerReport({ taskId, dispatchId, outcome: 'succeeded', result: 'done' }).action - ).toBe('settled') - } - - it('pushes the fence to the live renderer instead of waiting for the next app start', () => { - const fenceChanges: [string, boolean][] = [] - const h = harness((paneKey, blocked) => fenceChanges.push([paneKey, blocked])) - settle(h.db, h.taskId, h.dispatchId) - - h.persistence.prepare() - - expect(fenceChanges).toEqual([[PANE_KEY, true]]) - }) - - it('announces the fence for a pane that has no sleeping record to stamp yet', () => { - const fenceChanges: [string, boolean][] = [] - const h = harness((paneKey, blocked) => fenceChanges.push([paneKey, blocked]), false) - settle(h.db, h.taskId, h.dispatchId) - - h.persistence.prepare() - expect(fenceChanges).toEqual([[PANE_KEY, true]]) - - const requested = h.db.requestWorkerTerminalRelease(h.dispatchId) - h.db.settleWorkerTerminalRelease((requested as { resource: { id: string } }).resource.id) - h.persistence.prepare() - - // A fence the plan no longer claims must be lifted even with no record to read it from. - expect(fenceChanges).toEqual([ - [PANE_KEY, true], - [PANE_KEY, false] - ]) - }) - - // The STA-4577 repro: worker_done, no release, restart, open the worktree — the pane still - // holds a resumable provider session and must not respawn `codex resume`. - it('fences a settled worker pane whose terminal was never released', () => { - const h = harness() - settle(h.db, h.taskId, h.dispatchId) - - h.persistence.prepare() - - expect(h.fence()).toBe('legacy-orchestration-worker') - }) - - it('lifts the fence once release retires the terminal resource', () => { - const h = harness() - settle(h.db, h.taskId, h.dispatchId) - h.persistence.prepare() - expect(h.fence()).toBe('legacy-orchestration-worker') - - const requested = h.db.requestWorkerTerminalRelease(h.dispatchId) - expect(requested.disposition).toBe('requested') - h.db.settleWorkerTerminalRelease((requested as { resource: { id: string } }).resource.id) - h.persistence.prepare() - - expect(h.fence()).toBeUndefined() - }) - - it('lifts the fence when the user takes the pane over', () => { - const h = harness() - settle(h.db, h.taskId, h.dispatchId) - h.persistence.prepare() - expect(h.fence()).toBe('legacy-orchestration-worker') - - expect(h.db.markWorkerTerminalUserOwned(PANE_KEY)).toBe(1) - h.persistence.prepare() - - expect(h.fence()).toBeUndefined() - }) - - // An unreadable plan is not evidence a pane stopped needing its fence. - it('keeps the fence when the recovery plan cannot be read', () => { - const h = harness() - settle(h.db, h.taskId, h.dispatchId) - h.persistence.prepare() - expect(h.fence()).toBe('legacy-orchestration-worker') - - vi.spyOn(h.db, 'listLegacyWorkerTerminalRecoveryRows').mockImplementation(() => { - throw new Error('orchestration_db_unavailable') - }) - const warn = vi.spyOn(console, 'warn').mockImplementation(() => {}) - try { - expect(h.persistence.prepare()).toEqual({ - blockedPanes: [], - candidates: [], - ambiguousDispatchIds: [] - }) - } finally { - warn.mockRestore() - } - - expect(h.fence()).toBe('legacy-orchestration-worker') - }) - - // A live worker's pane was already fenced while main reconciles it against PTY inventory; the - // settled arm must not disturb that, and the plan must still name it as unsettled. - it('keeps a live worker pane fenced and marked unsettled', () => { - const h = harness() - - const plan = h.persistence.prepare() - - expect(h.fence()).toBe('legacy-orchestration-worker') - expect(plan.blockedPanes).toEqual([ - expect.objectContaining({ paneKey: PANE_KEY, settled: false }) - ]) - expect(plan.candidates).toEqual([expect.objectContaining({ dispatchId: h.dispatchId })]) - }) -}) - -// STA-4577's other half: settlement with no release and no restart. The stamp only ran at startup -// and after release/retain/takeover, so reopening the pane in the same session respawned the agent. -describe('worker_done without a release', () => { - let db: OrchestrationDb | undefined - - afterEach(() => db?.close()) - - it('fences the pane in the same session', async () => { - const orchestrationDb = new OrchestrationDb(':memory:') - db = orchestrationDb - let session = sessionWithSleepingWorker() - const store = { - getWorkspaceSession: () => session, - setWorkspaceSession: (next: WorkspaceSessionState) => { - session = next - }, - getWorkspaceSessionHostIds: () => [LOCAL_EXECUTION_HOST_ID], - flushOrThrow: vi.fn() - } as unknown as RuntimeStore - const runtime = new OrcaRuntimeService(store) - runtime.setOrchestrationDb(orchestrationDb) - vi.spyOn(runtime, 'getTerminalPaneKey').mockImplementation((handle) => - handle === 'term_worker' ? PANE_KEY : 'tab_coord:aaaaaaaa-aaaa-4aaa-8aaa-aaaaaaaaaaaa' - ) - vi.spyOn(runtime, 'getTerminalProcessIncarnation').mockReturnValue('runtime:pty:1') - vi.spyOn(runtime, 'notifyMessageArrived').mockImplementation(() => {}) - - const run = orchestrationDb.createRun({ - objective: 'settle without release', - coordinatorHandle: 'term_coord', - coordinatorPaneKey: 'tab_coord:aaaaaaaa-aaaa-4aaa-8aaa-aaaaaaaaaaaa' - }) - const task = orchestrationDb.createTask({ spec: 'settle without release', runId: run.id }) - const started = orchestrationDb.createStartingWorkerDispatch({ - creator: { kind: 'system' }, - maxDepth: Number.MAX_SAFE_INTEGER, - taskId: task.id, - startOptions: {} - }) - orchestrationDb.prepareStartingWorkerAuthority({ - dispatchId: started.dispatch.id, - handle: 'term_worker', - paneKey: PANE_KEY, - processIncarnation: 'runtime:pty:1', - worktreeId: WORKTREE_ID, - setupState: 'not_applicable', - effects: [], - terminalOwnership: 'created' - }) - orchestrationDb.markWorkerDispatchReady(started.dispatch.id) - const capability = orchestrationDb.mintDispatchCapability({ - dispatchId: started.dispatch.id, - paneKey: PANE_KEY, - processIncarnation: 'runtime:pty:1' - }) - expect(session.sleepingAgentSessionsByPaneKey?.[PANE_KEY]?.automaticResumeBlockedBy).toBe( - undefined - ) - - const send = ORCHESTRATION_METHODS.find((method) => method.name === 'orchestration.send')! - await send.handler( - send.params!.parse({ - from: 'term_worker', - to: 'term_coord', - subject: 'Done', - type: 'worker_done', - payload: JSON.stringify({ - taskId: task.id, - dispatchId: started.dispatch.id, - outcome: 'succeeded' - }) - }), - { runtime, orchestrationCapability: capability } - ) - - expect(orchestrationDb.getWorkerDispatch(started.dispatch.id)?.state).toBe('succeeded') - expect(session.sleepingAgentSessionsByPaneKey?.[PANE_KEY]?.automaticResumeBlockedBy).toBe( - 'legacy-orchestration-worker' - ) - }) -}) diff --git a/src/main/runtime/runtime-notifier-contract.ts b/src/main/runtime/runtime-notifier-contract.ts index aa2982082b4..9cdc365e1ba 100644 --- a/src/main/runtime/runtime-notifier-contract.ts +++ b/src/main/runtime/runtime-notifier-contract.ts @@ -80,7 +80,6 @@ export type RuntimeNotifier = { ptyId?: string ): void /** The fence lives in the workspace session, which a live renderer only re-reads at startup. */ - setLegacyWorkerTerminalResumeFence?(paneKey: string, blocked: boolean): void splitTerminal( tabId: string, paneRuntimeId: number, diff --git a/src/main/runtime/runtime-rpc-request-authorization.test.ts b/src/main/runtime/runtime-rpc-request-authorization.test.ts index d7e7576bc27..5ff19f94563 100644 --- a/src/main/runtime/runtime-rpc-request-authorization.test.ts +++ b/src/main/runtime/runtime-rpc-request-authorization.test.ts @@ -92,9 +92,19 @@ describe('OrcaRuntimeRpcServer', () => { } try { - db.insertMessage({ from: 'worker', to: 'coordinator', subject: 'before reset' }) + db.insertMessage({ + runId: 'run_legacy_local', + from: 'worker', + to: 'coordinator', + subject: 'before reset' + }) const first = await resetMessages('reset-first', firstDevice.token) - db.insertMessage({ from: 'worker', to: 'coordinator', subject: 'after reset' }) + db.insertMessage({ + runId: 'run_legacy_local', + from: 'worker', + to: 'coordinator', + subject: 'after reset' + }) const replay = await resetMessages('reset-replay', firstDevice.token) expect(first).toMatchObject({ @@ -129,6 +139,7 @@ describe('OrcaRuntimeRpcServer', () => { const device = server['deviceRegistry']!.addDevice('existing-cli', 'runtime') const existingFingerprint = createHash('sha256').update(device.token).digest('hex') db.createRemoteDispatchAttachment({ + runId: 'run_home', dispatchId: 'ctx_existing_remote', taskId: 'task_existing_remote', homePeerFingerprint: existingFingerprint, diff --git a/src/main/runtime/runtime-rpc/runtime-rpc-mobile-method-allowlist.ts b/src/main/runtime/runtime-rpc/runtime-rpc-mobile-method-allowlist.ts index d6142e95569..534cf04b883 100644 --- a/src/main/runtime/runtime-rpc/runtime-rpc-mobile-method-allowlist.ts +++ b/src/main/runtime/runtime-rpc/runtime-rpc-mobile-method-allowlist.ts @@ -246,6 +246,8 @@ export const MOBILE_RPC_METHOD_ALLOWLIST = new Set([ 'status.get', 'agentTeams.prepareLaunch', 'agentTeams.tmuxCompat', + // Why: the phone reports a takeover out of band, the same signal the desktop renderer sends. + 'orchestration.workerTerminalUserInput', 'terminal.clearBuffer', 'terminal.close', 'terminal.closeAll', diff --git a/src/main/runtime/runtime-terminal-orphan-topology-validation.test.ts b/src/main/runtime/runtime-terminal-orphan-topology-validation.test.ts new file mode 100644 index 00000000000..cb8f22e864b --- /dev/null +++ b/src/main/runtime/runtime-terminal-orphan-topology-validation.test.ts @@ -0,0 +1,151 @@ +import { expect, it } from 'vitest' +import type { RuntimeTerminalOrphanAdoptionRequest } from '../../shared/runtime-types' +import { validateRuntimeTerminalOrphanTopology } from './runtime-terminal-orphan-topology-validation' + +function fixture(count: number): RuntimeTerminalOrphanAdoptionRequest { + const ids = Array.from({ length: count }, (_, index) => `tab-${index}`) + return { + worktree: 'folder-workspace', + expectedTopologyRevision: 1, + claims: ids.map((tabId) => ({ + tabId, + leafId: tabId, + terminal: tabId, + ptyId: tabId, + incarnationId: tabId + })) as RuntimeTerminalOrphanAdoptionRequest['claims'], + topology: { + tabs: ids.map((tabId) => ({ + tabId, + root: { type: 'leaf', leafId: tabId }, + activeLeafId: tabId, + expandedLeafId: null + })), + groups: [{ id: 'g', activeTabId: ids[0], tabOrder: ids, recentTabIds: ids.toReversed() }] + } + } +} + +it('validates large restored MRU lists with linear tab-order reads', () => { + const request = fixture(1000) + let reads = 0 + const group = request.topology!.groups[0] + group.tabOrder = new Proxy(group.tabOrder, { + get(target, key, receiver) { + if (typeof key === 'string' && /^\d+$/.test(key)) { + reads += 1 + } + return Reflect.get(target, key, receiver) + } + }) + expect( + validateRuntimeTerminalOrphanTopology( + request, + request.claims.map((claim) => ({ claim })) + ).topologyTabsById.size + ).toBe(1000) + expect(reads).toBeLessThanOrEqual(3000) +}) + +it.each(['duplicate', 'foreign-recent', 'foreign-active'])( + 'rejects %s group membership', + (kind) => { + const request = fixture(2) + const group = request.topology!.groups[0] + if (kind === 'duplicate') { + group.tabOrder.push(group.tabOrder[0]) + } + if (kind === 'foreign-recent') { + group.recentTabIds = ['foreign'] + } + if (kind === 'foreign-active') { + group.activeTabId = 'foreign' + } + expect(() => + validateRuntimeTerminalOrphanTopology( + request, + request.claims.map((claim) => ({ claim })) + ) + ).toThrow('terminal_orphan_topology_invalid') + } +) + +function validate(request: RuntimeTerminalOrphanAdoptionRequest) { + return validateRuntimeTerminalOrphanTopology( + request, + request.claims.map((claim) => ({ claim })) + ) +} + +type Groups = NonNullable['groups'] + +function withGroups(count: number, groups: Groups): RuntimeTerminalOrphanAdoptionRequest { + const request = fixture(count) + request.topology!.groups = groups + return request +} + +// Membership is per-group, but the no-tab-in-two-groups rule is global. Replacing that rule with +// the per-group set would let one pane be adopted into two groups and cross-wire the session. +it('rejects a tab claimed by two different groups', () => { + expect(() => + validate( + withGroups(2, [ + { id: 'g1', activeTabId: 'tab-0', tabOrder: ['tab-0', 'tab-1'], recentTabIds: [] }, + { id: 'g2', activeTabId: 'tab-1', tabOrder: ['tab-1'], recentTabIds: [] } + ]) + ) + ).toThrow('terminal_orphan_topology_invalid') +}) + +it('rejects a duplicated group id', () => { + expect(() => + validate( + withGroups(2, [ + { id: 'g', activeTabId: 'tab-0', tabOrder: ['tab-0'], recentTabIds: [] }, + { id: 'g', activeTabId: 'tab-1', tabOrder: ['tab-1'], recentTabIds: [] } + ]) + ) + ).toThrow('terminal_orphan_topology_invalid') +}) + +// Cardinality 0: an empty tab order can never hold the active tab, so adoption must fail closed +// rather than fall through to an arbitrary pane. +it('rejects an empty tab order', () => { + expect(() => + validate(withGroups(2, [{ id: 'g', activeTabId: 'tab-0', tabOrder: [], recentTabIds: [] }])) + ).toThrow('terminal_orphan_topology_invalid') +}) + +it('rejects a claimed tab that no group lists', () => { + expect(() => + validate( + withGroups(2, [{ id: 'g', activeTabId: 'tab-0', tabOrder: ['tab-0'], recentTabIds: [] }]) + ) + ).toThrow('terminal_orphan_topology_invalid') +}) + +it.each([ + ['1 tab per group', [['tab-0'], ['tab-1']]], + ['both tabs in one group', [['tab-0', 'tab-1']]] +])('accepts an exactly-covering split with %s', (_label, tabOrders) => { + const groups: Groups = tabOrders.map((tabOrder, i) => ({ + id: `g${i}`, + activeTabId: tabOrder[0], + tabOrder, + // Reverse MRU: every entry must still resolve inside its own group. + recentTabIds: tabOrder.toReversed() + })) + expect(validate(withGroups(2, groups)).topologyTabsById.size).toBe(2) +}) + +it.each([ + ['omitted', undefined], + ['empty', [] as string[]] +])('accepts %s recentTabIds', (_label, recentTabIds) => { + expect( + validate( + withGroups(2, [{ id: 'g', activeTabId: 'tab-0', tabOrder: ['tab-0', 'tab-1'], recentTabIds }]) + ).topologyTabsById.size + ).toBe(2) +}) diff --git a/src/main/runtime/runtime-terminal-orphan-topology-validation.ts b/src/main/runtime/runtime-terminal-orphan-topology-validation.ts index 72b1e43ef08..0864533f4c7 100644 --- a/src/main/runtime/runtime-terminal-orphan-topology-validation.ts +++ b/src/main/runtime/runtime-terminal-orphan-topology-validation.ts @@ -54,7 +54,8 @@ export function validateRuntimeTerminalOrphanTopology( const seenGroupIds = new Set() const groupedTabIds = new Set() for (const group of topologyGroups) { - if (seenGroupIds.has(group.id) || !group.tabOrder.includes(group.activeTabId)) { + const groupTabIds = new Set(group.tabOrder) + if (seenGroupIds.has(group.id) || !groupTabIds.has(group.activeTabId)) { throw new Error('terminal_orphan_topology_invalid') } seenGroupIds.add(group.id) @@ -64,7 +65,7 @@ export function validateRuntimeTerminalOrphanTopology( } groupedTabIds.add(tabId) } - if (group.recentTabIds?.some((tabId) => !group.tabOrder.includes(tabId))) { + if (group.recentTabIds?.some((tabId) => !groupTabIds.has(tabId))) { throw new Error('terminal_orphan_topology_invalid') } } diff --git a/src/main/runtime/settled-worker-process-replacement.test.ts b/src/main/runtime/settled-worker-process-replacement.test.ts new file mode 100644 index 00000000000..2e575cd4546 --- /dev/null +++ b/src/main/runtime/settled-worker-process-replacement.test.ts @@ -0,0 +1,111 @@ +import { afterEach, describe, expect, it } from 'vitest' +import { OrcaRuntimeService } from './orca-runtime' +import { OrchestrationDb } from './orchestration/db' + +const TAB = 'worker-tab' +const LEAF = '11111111-1111-4111-8111-111111111111' +const PANE = `${TAB}:${LEAF}` +const WORKSPACE = '/folder-workspace' +const LOCAL_HOST = JSON.stringify({ kind: 'local', hostId: 'local' }) +const SSH_HOST = JSON.stringify({ kind: 'ssh', targetId: 'remote-host' }) +let db: OrchestrationDb +let runtime: OrcaRuntimeService + +afterEach(() => { + db?.close() +}) + +function seedWorker(hostScope: string, settled = true) { + db = new OrchestrationDb(':memory:') + runtime = new OrcaRuntimeService(null) + runtime.setOrchestrationDb(db) + const started = db.createStartingWorkerDispatch({ + creator: { kind: 'system' }, + maxDepth: Number.MAX_SAFE_INTEGER, + taskSpec: 'Ordinary pane after worker completion', + taskRunId: 'run_legacy_local', + startOptions: {} + }) + db.prepareStartingWorkerAuthority({ + dispatchId: started.dispatch.id, + handle: 'term_original', + paneKey: PANE, + processIncarnation: 'pty-original:inc-original', + hostScope, + worktreeId: WORKSPACE, + setupState: 'not_applicable', + effects: [], + terminalOwnership: 'created' + }) + db.markWorkerDispatchReady(started.dispatch.id) + if (settled) { + db.settleWorkerReport({ + taskId: started.task.id, + dispatchId: started.dispatch.id, + outcome: 'succeeded', + result: '{}' + }) + } + return { + dispatchId: started.dispatch.id, + task: db.getTask(started.task.id), + dispatch: db.getDispatchContextById(started.dispatch.id) + } +} + +function register(ptyId: string, incarnationId?: string, connectionId: string | null = null) { + runtime.registerPty(ptyId, WORKSPACE, connectionId, { + tabId: TAB, + leafId: LEAF, + ...(incarnationId ? { incarnationId } : {}) + }) +} + +describe('settled worker process replacement accounting', () => { + it.each([null, 'remote-host'])( + 'retains the replaced resource on owning host %s', + (connectionId) => { + const worker = seedWorker(connectionId ? SSH_HOST : LOCAL_HOST) + register('pty-resumed', 'inc-resumed', connectionId) + register('pty-resumed', 'inc-resumed', connectionId) + expect(db.getWorkerTerminalResourceByOwner(worker.dispatchId)).toMatchObject({ + release_state: 'retained', + retained_reason: 'identity_unproven', + process_incarnation: 'pty-original:inc-original' + }) + expect(db.getTask(worker.task!.id)).toEqual(worker.task) + expect(db.getDispatchContextById(worker.dispatchId)).toEqual(worker.dispatch) + expect(db.listWorkerTerminalResources({})).toEqual([ + expect.objectContaining({ dispatchId: worker.dispatchId, terminalState: 'retained' }) + ]) + } + ) + + it('keeps the original live resource unchanged across reattach', () => { + const worker = seedWorker(LOCAL_HOST) + const original = db.getWorkerTerminalResourceByOwner(worker.dispatchId) + register('pty-original', 'inc-original') + expect(db.getWorkerTerminalResourceByOwner(worker.dispatchId)).toEqual(original) + }) + + it('does not use missing incarnation evidence as proof of replacement', () => { + const worker = seedWorker(LOCAL_HOST) + const original = db.getWorkerTerminalResourceByOwner(worker.dispatchId) + register('pty-unverifiable') + expect(db.getWorkerTerminalResourceByOwner(worker.dispatchId)).toEqual(original) + }) + + it('does not change another execution host with the same pane and folder', () => { + const worker = seedWorker(SSH_HOST) + const original = db.getWorkerTerminalResourceByOwner(worker.dispatchId) + register('pty-resumed', 'inc-resumed') + expect(db.getWorkerTerminalResourceByOwner(worker.dispatchId)).toEqual(original) + }) + + it('does not change an active Dispatch resource', () => { + const worker = seedWorker(LOCAL_HOST, false) + const original = db.getWorkerTerminalResourceByOwner(worker.dispatchId) + register('pty-resumed', 'inc-resumed') + expect(db.getWorkerTerminalResourceByOwner(worker.dispatchId)).toEqual(original) + }) +}) diff --git a/src/main/runtime/workspace-session-membership-scaling.test.ts b/src/main/runtime/workspace-session-membership-scaling.test.ts new file mode 100644 index 00000000000..802245461b7 --- /dev/null +++ b/src/main/runtime/workspace-session-membership-scaling.test.ts @@ -0,0 +1,123 @@ +import { expect, it, vi } from 'vitest' +import type { TabGroup } from '../../shared/tab-types' +import type { WorkspaceSessionState } from '../../shared/workspace-session-state-types' +import { rebaseWorkspaceSessionTerminalMembership } from './workspace-session-terminal-membership-authority' + +it('rebases a large group without rescanning tab order for every recent tab', () => { + const ids = Array.from({ length: 1000 }, (_, index) => `tab-${index}`) + const session: WorkspaceSessionState = { + activeRepoId: 'repo', + activeWorktreeId: 'repo::/workspace', + activeTabId: null, + tabsByWorktree: { + 'repo::/workspace': ids.map((id, index) => ({ + id, + worktreeId: 'repo::/workspace', + ptyId: null, + title: id, + customTitle: null, + color: null, + sortOrder: index, + createdAt: 0 + })) + }, + terminalLayoutsByTabId: {}, + terminalTopologyRevisionByRepoId: { repo: 1 }, + tabGroups: { + 'repo::/workspace': [ + { + id: 'group', + worktreeId: 'repo::/workspace', + activeTabId: 'missing', + tabOrder: [...ids, 'missing'], + recentTabIds: [...ids, 'missing'] + } + ] + } + } + const includes = vi.spyOn(Array.prototype, 'includes') + let result: WorkspaceSessionState + let probes: number + try { + result = rebaseWorkspaceSessionTerminalMembership(session, session) + probes = includes.mock.calls.length + } finally { + includes.mockRestore() + } + expect(probes).toBeLessThan(10) + expect(result.tabGroups?.['repo::/workspace'][0]).toMatchObject({ + tabOrder: ids, + recentTabIds: ids, + activeTabId: ids[0] + }) +}) + +// Why: the rebased session is the host-authoritative one, so a tab id the host no +// longer has must not survive into it. `activeTabId` already failed closed; the +// filtered `recentTabIds` used to be dropped when it emptied, letting the `...group` +// spread put the unfiltered array back. +it('drops tab ids the host no longer has from group membership, failing closed', () => { + const buildSession = ( + activeTabId: string | null, + recentTabIds: string[] | undefined + ): WorkspaceSessionState => + ({ + activeRepoId: 'repo', + activeWorktreeId: 'repo::/workspace', + activeTabId: null, + tabsByWorktree: { + 'repo::/workspace': ['kept-a', 'kept-b'].map((id, index) => ({ + id, + worktreeId: 'repo::/workspace', + ptyId: null, + title: id, + customTitle: null, + color: null, + sortOrder: index, + createdAt: 0 + })) + }, + terminalLayoutsByTabId: {}, + terminalTopologyRevisionByRepoId: { repo: 1 }, + tabGroups: { + 'repo::/workspace': [ + { + id: 'group', + worktreeId: 'repo::/workspace', + activeTabId, + tabOrder: ['kept-a', 'closed-on-host', 'kept-b'], + ...(recentTabIds ? { recentTabIds } : {}) + } + ] + } + }) as WorkspaceSessionState + + const rebase = ( + activeTabId: string | null, + recentTabIds: string[] | undefined + ): TabGroup | undefined => { + const session = buildSession(activeTabId, recentTabIds) + return rebaseWorkspaceSessionTerminalMembership(session, session).tabGroups?.[ + 'repo::/workspace' + ][0] + } + + // Every recent id is stale: the array must empty, not revert to the stale one. + expect(rebase('kept-b', ['closed-on-host'])).toMatchObject({ + tabOrder: ['kept-a', 'kept-b'], + activeTabId: 'kept-b', + recentTabIds: [] + }) + // Mixed: only the host-known ids survive, in order. + expect(rebase('kept-a', ['closed-on-host', 'kept-b', 'closed-on-host', 'kept-a'])).toMatchObject({ + recentTabIds: ['kept-b', 'kept-a'] + }) + // A stale active tab falls back to the first surviving tab, never to the stale id. + expect(rebase('closed-on-host', ['kept-a'])).toMatchObject({ + activeTabId: 'kept-a', + recentTabIds: ['kept-a'] + }) + expect(rebase(null, undefined)).toMatchObject({ activeTabId: 'kept-a' }) + // A group that never carried recentTabIds must not gain the key. + expect(rebase('kept-a', undefined)).not.toHaveProperty('recentTabIds') +}) diff --git a/src/main/runtime/workspace-session-terminal-membership-authority.ts b/src/main/runtime/workspace-session-terminal-membership-authority.ts index 2869e3c813c..76cbcdf4dad 100644 --- a/src/main/runtime/workspace-session-terminal-membership-authority.ts +++ b/src/main/runtime/workspace-session-terminal-membership-authority.ts @@ -93,17 +93,18 @@ function rebaseTabGroups( if (tabOrder.length === 0) { return [] } + const tabIds = new Set(tabOrder) const activeTabId = - group.activeTabId && tabOrder.includes(group.activeTabId) - ? group.activeTabId - : (tabOrder[0] ?? null) - const recentTabIds = group.recentTabIds?.filter((tabId) => tabOrder.includes(tabId)) + group.activeTabId && tabIds.has(group.activeTabId) ? group.activeTabId : (tabOrder[0] ?? null) + const recentTabIds = group.recentTabIds?.filter((tabId) => tabIds.has(tabId)) return [ { ...group, tabOrder, activeTabId, - ...(recentTabIds && recentTabIds.length > 0 ? { recentTabIds } : {}) + // Why assigned even when it filters to empty: omitting the key lets `...group` + // re-introduce the unfiltered array, persisting ids for tabs the host dropped. + ...(group.recentTabIds ? { recentTabIds: recentTabIds ?? [] } : {}) } ] }) diff --git a/src/main/skills/agent-skill-selection.test.ts b/src/main/skills/agent-skill-selection.test.ts index 7dfa576211b..1b743374230 100644 --- a/src/main/skills/agent-skill-selection.test.ts +++ b/src/main/skills/agent-skill-selection.test.ts @@ -2,7 +2,8 @@ import { describe, expect, it } from 'vitest' import type { DiscoveredSkill } from '../../shared/skills' import { AGENT_SKILL_SELECTOR_AMBIGUOUS_CODE, - AGENT_SKILL_SELECTOR_NOT_FOUND_CODE + AGENT_SKILL_SELECTOR_NOT_FOUND_CODE, + AgentSkillSharingError } from '../../shared/agent-skill-sharing-contract' import { selectDiscoveredSkills } from './agent-skill-selection' @@ -50,3 +51,62 @@ describe('agent skill selection', () => { ).toThrow(expect.objectContaining({ code: AGENT_SKILL_SELECTOR_AMBIGUOUS_CODE })) }) }) + +it('indexes a batch of selectors without rescanning discovery', () => { + let reads = 0 + const skills = Array.from({ length: 1000 }, (_, index) => ({ + ...skill(`id-${index}`, `name-${index}`), + get id() { + reads++ + return `id-${index}` + } + })) + const selected = selectDiscoveredSkills( + skills, + skills.map((_, index) => `id-${index}`) + ) + expect(selected).toHaveLength(1000) + expect(selected[999]).toBe(skills[999]) + expect(reads).toBeLessThan(10000) +}) + +it('indexes only the requested selectors, not every discovered skill', () => { + let nameReads = 0 + const skills = Array.from({ length: 1000 }, (_, index) => ({ + ...skill(`id-${index}`, `name-${index}`), + get name() { + nameReads++ + return `name-${index}` + } + })) + expect(selectDiscoveredSkills(skills, ['id-900'])).toEqual([skills[900]]) + // One membership probe per discovered skill, plus reads for the single match's + // own bucket and the trailing collision check. Indexing every name would need + // three reads apiece. + expect(nameReads).toBeLessThanOrEqual(1_100) +}) + +// `matchingIds` is what the CLI prints so the user can disambiguate, so the +// index must report every match in discovery order, exactly like the old filter. +it('reports every ambiguous match in discovery order', () => { + let thrown: unknown + try { + selectDiscoveredSkills( + [skill('one', 'same'), skill('unrelated', 'other'), skill('two', 'same')], + ['same'] + ) + } catch (error) { + thrown = error + } + expect(thrown).toBeInstanceOf(AgentSkillSharingError) + const error = thrown as AgentSkillSharingError + expect(error.code).toBe(AGENT_SKILL_SELECTOR_AMBIGUOUS_CODE) + expect(error.data).toEqual({ selector: 'same', matchingIds: ['one', 'two'] }) +}) + +it('retains first duplicate ID authority and exact ID precedence over names', () => { + const first = skill('id', 'first') + expect( + selectDiscoveredSkills([first, skill('id', 'second'), skill('other', 'id')], ['id']) + ).toEqual([first]) +}) diff --git a/src/main/skills/agent-skill-selection.ts b/src/main/skills/agent-skill-selection.ts index 23fb5581cab..e38dd3767d2 100644 --- a/src/main/skills/agent-skill-selection.ts +++ b/src/main/skills/agent-skill-selection.ts @@ -10,13 +10,35 @@ export function selectDiscoveredSkills( selectors: readonly string[] ): DiscoveredSkill[] { const selected = new Map() + // Indexed only for the selectors actually asked for: a share request carries at + // most 512 of them while discovery can return every skill on the machine, and + // indexing the whole set costs more than the scans it replaces for the + // one-or-two-selector requests agents actually send. + const requested = new Set(selectors) + const byId = new Map() + const discoveredByName = new Map() + for (const skill of skills) { + // First writer wins, matching the `find` this replaces. + if (requested.has(skill.id) && !byId.has(skill.id)) { + byId.set(skill.id, skill) + } + if (!requested.has(skill.name)) { + continue + } + const named = discoveredByName.get(skill.name) + if (named) { + named.push(skill) + } else { + discoveredByName.set(skill.name, [skill]) + } + } for (const selector of selectors) { - const exactId = skills.find((skill) => skill.id === selector) + const exactId = byId.get(selector) if (exactId) { selected.set(exactId.id, exactId) continue } - const named = skills.filter((skill) => skill.name === selector) + const named = discoveredByName.get(selector) ?? [] if (named.length === 0) { throw new AgentSkillSharingError( AGENT_SKILL_SELECTOR_NOT_FOUND_CODE, @@ -36,7 +58,12 @@ export function selectDiscoveredSkills( const values = [...selected.values()] const byName = new Map() for (const skill of values) { - byName.set(skill.name, [...(byName.get(skill.name) ?? []), skill]) + const named = byName.get(skill.name) + if (named) { + named.push(skill) + } else { + byName.set(skill.name, [skill]) + } } const collision = [...byName.entries()].find(([, named]) => named.length > 1) if (collision) { diff --git a/src/main/skills/discovery.ts b/src/main/skills/discovery.ts index a93968177a9..385ae99ca33 100644 --- a/src/main/skills/discovery.ts +++ b/src/main/skills/discovery.ts @@ -10,7 +10,8 @@ import type { } from '../../shared/skills' import { buildSkillDiscoverySources, - compareSkills, + sortDiscoveredSkills, + sortSkillDiscoverySources, sourceKindForSkill, sourceLabelForSkill, stablePathId, @@ -292,7 +293,7 @@ export async function discoverSkills(args: { mergeScannedSkill(seen, skill) } } - const skills = Array.from(seen.values()).sort(compareSkills) + const skills = sortDiscoveredSkills(Array.from(seen.values())) // Why: root *ids* — a repo/plugin id is already a hash, while its label carries // the repo or plugin name and its path carries the user's directory names. A // fully cached scan did no filesystem work, so it stays silent rather than @@ -309,9 +310,7 @@ export async function discoverSkills(args: { } return { skills, - sources: sources.sort((a, b) => - a.label.localeCompare(b.label, undefined, { sensitivity: 'base' }) - ), + sources: sortSkillDiscoverySources(sources), scannedAt: Date.now() } } diff --git a/src/main/skills/skill-cloud-grant-installation.test.ts b/src/main/skills/skill-cloud-grant-installation.test.ts index 11d15a30689..5355e6f4869 100644 --- a/src/main/skills/skill-cloud-grant-installation.test.ts +++ b/src/main/skills/skill-cloud-grant-installation.test.ts @@ -133,3 +133,89 @@ describe('installSkillCloudGrant', () => { ) }) }) + +// The failure report is keyed by user-visible skill IDs, so switching the +// membership test from `includes` to a Set must not change which entries appear, +// how often, or in what order. +it('reports selected manifest entries in manifest order, duplicates and all', async () => { + const skills = ['b', 'a', 'dupe', 'dupe', 'unselected'].map((id) => ({ + id, + name: `name-${id}`, + digest: 'a'.repeat(64), + files: [] + })) + const bundleGrant = { + ...grant, + version: { ...grant.version, manifest: { skills, bundleDigest: 'c'.repeat(64) } } + } as unknown as SkillCloudDownloadGrant + const runtime = { + installSharedSkillBundleRequest: vi + .fn() + .mockRejectedValue(new Error('skill-install-filesystem-failed')) + } as unknown as OrcaRuntimeService + const result = await installSkillBundleCloudGrant(runtime, bundleGrant, { + operationId: 'op', + // Repeated and unknown selections must be inert, exactly as with `includes`. + selectedSkillIds: ['dupe', 'a', 'a', 'b', 'never-in-manifest'], + destination: { scope: 'global' } + }) + expect(result.status).toBe('ok') + if (result.status === 'ok') { + expect(result.value.skills.map((skill) => skill.skillId)).toEqual(['b', 'a', 'dupe', 'dupe']) + } +}) + +it('reports no skills when nothing was selected', async () => { + const skills = [{ id: 'a', name: 'a', digest: 'a'.repeat(64), files: [] }] + const bundleGrant = { + ...grant, + version: { ...grant.version, manifest: { skills, bundleDigest: 'c'.repeat(64) } } + } as unknown as SkillCloudDownloadGrant + const runtime = { + installSharedSkillBundleRequest: vi.fn().mockRejectedValue(new Error('skill-install-cancelled')) + } as unknown as OrcaRuntimeService + const result = await installSkillBundleCloudGrant(runtime, bundleGrant, { + operationId: 'op', + selectedSkillIds: [], + destination: { scope: 'global' } + }) + expect(result.status).toBe('ok') + if (result.status === 'ok') { + expect(result.value.skills).toEqual([]) + } +}) + +it.each(['skill-install-cancelled', 'skill-install-filesystem-failed'])( + 'indexes selected IDs when reporting %s', + async (code) => { + let reads = 0 + const ids = Array.from({ length: 1000 }, (_, index) => `skill-${index}`) + const selectedSkillIds = new Proxy(ids, { + get(target, key, receiver) { + if (typeof key === 'string' && /^\d+$/.test(key)) { + reads += 1 + } + return Reflect.get(target, key, receiver) + } + }) + const skills = ids.map((id) => ({ id, name: id, digest: 'a'.repeat(64), files: [] })) + const bundleGrant = { + ...grant, + version: { ...grant.version, manifest: { skills, bundleDigest: 'c'.repeat(64) } } + } as unknown as SkillCloudDownloadGrant + const runtime = { + installSharedSkillBundleRequest: vi.fn().mockRejectedValue(new Error(code)) + } as unknown as OrcaRuntimeService + const result = await installSkillBundleCloudGrant(runtime, bundleGrant, { + operationId: 'op', + selectedSkillIds, + destination: { scope: 'global' } + }) + expect(result.status).toBe('ok') + if (result.status === 'ok') { + expect(result.value.skills.map((skill) => skill.skillId)).toEqual(ids) + expect(result.value.status).toBe(code.includes('cancelled') ? 'cancelled' : 'failed') + } + expect(reads).toBeLessThanOrEqual(2000) + } +) diff --git a/src/main/skills/skill-cloud-grant-installation.ts b/src/main/skills/skill-cloud-grant-installation.ts index add69270c5d..e60c8712820 100644 --- a/src/main/skills/skill-cloud-grant-installation.ts +++ b/src/main/skills/skill-cloud-grant-installation.ts @@ -49,6 +49,7 @@ function bundleFailureResult( if (!('skills' in manifest)) { throw new Error('skill-bundle-cloud-manifest-required') } + const selectedSkillIds = new Set(request.selectedSkillIds) return { operationId: request.operationId, packageId: request.package.packageId, @@ -56,7 +57,7 @@ function bundleFailureResult( bundleDigest: request.package.bundleDigest, status: failure.category === 'cancelled' ? 'cancelled' : 'failed', skills: manifest.skills - .filter((skill) => request.selectedSkillIds.includes(skill.id)) + .filter((skill) => selectedSkillIds.has(skill.id)) .map((skill) => ({ skillId: skill.id, name: skill.name, diff --git a/src/main/skills/skill-discovery-order.test.ts b/src/main/skills/skill-discovery-order.test.ts new file mode 100644 index 00000000000..18500bdf00e --- /dev/null +++ b/src/main/skills/skill-discovery-order.test.ts @@ -0,0 +1,153 @@ +import { afterEach, describe, expect, it, vi } from 'vitest' +import type { DiscoveredSkill, SkillDiscoverySource } from '../../shared/skills' +import { sortDiscoveredSkills, sortSkillDiscoverySources } from './skill-discovery-sources' + +// Scripts and case/accent/numeric shapes whose collation differs between locales +// and ICU builds, so a reused collator that drifted from `localeCompare` shows up. +const COLLATION_CORPUS = [ + '', + ' ', + 'a', + 'A', + 'éclair', + 'Eclair', + 'ÉCLAIR', + 'Ångström', + 'Angstrom', + 'İstanbul', + 'Istanbul', + 'ıstanbul', + 'straße', + 'strasse', + 'STRASSE', + 'ẞ', + '中文', + '日本語', + 'にほんご', + '한국어', + 'item2', + 'item10', + 'item01', + 'ITEM2', + '10', + '2', + 'ñ', + 'n', + 'œ', + 'oe', + 'æ', + 'привет', + 'ПРИВЕТ', + 'skill-a', + 'skill_a', + 'skill a', + 'co-op', + 'coop', + 'zebra', + 'zebra' +] + +function skill(index: number): DiscoveredSkill { + return { + id: String(index), + name: ['éclair', 'Eclair', 'item2', 'item10', 'Ångström', 'zebra', 'İstanbul'][index % 7], + description: null, + providers: ['codex'], + sourceKind: 'home', + sourceLabel: ['Home', 'hôme', 'Repo', 'repo'][index % 4], + rootPath: '/skills', + directoryPath: '/skills/example', + skillFilePath: `/skills/${index % 13}/SKILL.md`, + installed: true, + updatedAt: null + } +} + +// Preserve the original comparator as the ordering and operation-count oracle. +function compareOriginal(a: DiscoveredSkill, b: DiscoveredSkill): number { + return ( + a.name.localeCompare(b.name, undefined, { sensitivity: 'base' }) || + a.sourceLabel.localeCompare(b.sourceLabel, undefined, { sensitivity: 'base' }) || + a.skillFilePath.localeCompare(b.skillFilePath) + ) +} + +function discoverySource(index: number): SkillDiscoverySource { + return { + id: String(index), + label: COLLATION_CORPUS[index % COLLATION_CORPUS.length], + path: `/roots/${index}`, + sourceKind: 'home', + providers: ['codex'], + owner: null, + exists: true + } +} + +afterEach(() => vi.restoreAllMocks()) + +describe('discovered skill ordering', () => { + it('preserves name, source, path and stable ties with one collator per sort', () => { + const skills = Array.from({ length: 2_000 }, (_, index) => skill(index)) + const localeCompare = vi.spyOn(String.prototype, 'localeCompare') + const expected = [...skills].sort(compareOriginal) + const optionedCalls = (): number => + localeCompare.mock.calls.filter((args) => args[2] !== undefined).length + expect(optionedCalls()).toBeGreaterThan(10_000) + localeCompare.mockClear() + const NativeCollator = Intl.Collator + const construct = vi.spyOn(Intl, 'Collator').mockImplementation(function (locales, options) { + return new NativeCollator(locales, options) + }) + + expect(sortDiscoveredSkills(skills)).toBe(skills) + expect(skills.map(({ id }) => id)).toEqual(expected.map(({ id }) => id)) + expect(optionedCalls()).toBe(0) + expect(construct).toHaveBeenCalledExactlyOnceWith(undefined, { sensitivity: 'base' }) + sortDiscoveredSkills([...skills]) + expect(construct).toHaveBeenCalledTimes(2) + }) + + it('matches the per-call comparator across scripts, case, accents and numerals', () => { + const skills = COLLATION_CORPUS.flatMap((name, index) => + COLLATION_CORPUS.map((sourceLabel, inner) => ({ + ...skill(index), + id: `${index}-${inner}`, + name, + sourceLabel + })) + ) + expect(skills.length).toBe(COLLATION_CORPUS.length ** 2) + const expected = [...skills].sort(compareOriginal) + expect(sortDiscoveredSkills([...skills]).map(({ id }) => id)).toEqual( + expected.map(({ id }) => id) + ) + }) + + it('sorts discovery sources like the per-call label comparator', () => { + const sources = Array.from({ length: 400 }, (_, index) => discoverySource(index)) + const expected = [...sources].sort((a, b) => + // oxlint-disable-next-line sort-comparator-performance/no-repeated-collator -- Parity oracle. + a.label.localeCompare(b.label, undefined, { sensitivity: 'base' }) + ) + const NativeCollator = Intl.Collator + const construct = vi.spyOn(Intl, 'Collator').mockImplementation(function (locales, options) { + return new NativeCollator(locales, options) + }) + expect(sortSkillDiscoverySources(sources).map(({ id }) => id)).toEqual( + expected.map(({ id }) => id) + ) + expect(construct).toHaveBeenCalledExactlyOnceWith(undefined, { sensitivity: 'base' }) + }) + + it('does no comparison setup for empty or singleton discovery results', () => { + const construct = vi.spyOn(Intl, 'Collator') + for (const skills of [[], [skill(0)]]) { + expect(sortDiscoveredSkills(skills)).toBe(skills) + } + for (const sources of [[], [discoverySource(0)]]) { + expect(sortSkillDiscoverySources(sources)).toBe(sources) + } + expect(construct).not.toHaveBeenCalled() + }) +}) diff --git a/src/main/skills/skill-discovery-sources.ts b/src/main/skills/skill-discovery-sources.ts index 9d9781c3687..09bf8e208c8 100644 --- a/src/main/skills/skill-discovery-sources.ts +++ b/src/main/skills/skill-discovery-sources.ts @@ -47,14 +47,27 @@ export function sourceLabelForSkill(root: SkillScanRoot, sourceKind: SkillSource return sourceKind === 'bundled' ? `${root.label} bundled` : root.label } -export function compareSkills(a: DiscoveredSkill, b: DiscoveredSkill): number { - return ( - a.name.localeCompare(b.name, undefined, { sensitivity: 'base' }) || - a.sourceLabel.localeCompare(b.sourceLabel, undefined, { sensitivity: 'base' }) || - a.skillFilePath.localeCompare(b.skillFilePath) +export function sortDiscoveredSkills(skills: DiscoveredSkill[]): DiscoveredSkill[] { + if (skills.length < 2) { + return skills + } + const compare = new Intl.Collator(undefined, { sensitivity: 'base' }).compare + return skills.sort( + (a, b) => + compare(a.name, b.name) || + compare(a.sourceLabel, b.sourceLabel) || + a.skillFilePath.localeCompare(b.skillFilePath) ) } +export function sortSkillDiscoverySources(sources: SkillDiscoverySource[]): SkillDiscoverySource[] { + if (sources.length < 2) { + return sources + } + const compare = new Intl.Collator(undefined, { sensitivity: 'base' }).compare + return sources.sort((a, b) => compare(a.label, b.label)) +} + function source( id: string, label: string, diff --git a/src/main/skills/skill-discovery-wsl.test.ts b/src/main/skills/skill-discovery-wsl.test.ts index 2bcab34355d..93640698dd0 100644 --- a/src/main/skills/skill-discovery-wsl.test.ts +++ b/src/main/skills/skill-discovery-wsl.test.ts @@ -1,4 +1,4 @@ -import { describe, expect, it } from 'vitest' +import { describe, expect, it, vi } from 'vitest' import type { SkillScanRoot } from './skill-discovery-sources' import { buildWslSkillDiscoveryCommand, parseWslSkillDiscoveryOutput } from './skill-discovery-wsl' @@ -88,3 +88,29 @@ describe('WSL skill discovery', () => { ) }) }) + +it('reuses one source collator while preserving locale, lexical numbers, and stable ties', () => { + const labels = Array.from( + { length: 200 }, + (_, index) => + ['éclair', 'Eclair', 'item2', 'item10', 'Ångström', 'zebra', 'İstanbul'][index % 7] + ) + const roots = labels.map((label, index) => ({ ...homeRoot, id: String(index), label })) + const expected = [...roots].sort((a, b) => + // oxlint-disable-next-line sort-comparator-performance/no-repeated-collator -- Preserve the old comparator as the parity oracle. + a.label.localeCompare(b.label, undefined, { sensitivity: 'base' }) + ) + const NativeCollator = Intl.Collator + const construct = vi.spyOn(Intl, 'Collator').mockImplementation(function (locales, options) { + return new NativeCollator(locales, options) + }) + const localeCompare = vi.spyOn(String.prototype, 'localeCompare') + try { + const result = parseWslSkillDiscoveryOutput('', roots, 42) + expect(result.sources.map((source) => source.id)).toEqual(expected.map((root) => root.id)) + expect(construct).toHaveBeenCalledExactlyOnceWith(undefined, { sensitivity: 'base' }) + expect(localeCompare).not.toHaveBeenCalled() + } finally { + vi.restoreAllMocks() + } +}) diff --git a/src/main/skills/skill-discovery-wsl.ts b/src/main/skills/skill-discovery-wsl.ts index c9bbcbb96cb..eae829a893f 100644 --- a/src/main/skills/skill-discovery-wsl.ts +++ b/src/main/skills/skill-discovery-wsl.ts @@ -9,7 +9,8 @@ import { quoteBashString } from '../wsl-bash-command' import { runWslProcess } from '../wsl/wsl-runner' import { buildSkillDiscoverySources, - compareSkills, + sortDiscoveredSkills, + sortSkillDiscoverySources, sourceKindForSkill, sourceLabelForSkill, stablePathId, @@ -162,10 +163,8 @@ export function parseWslSkillDiscoveryOutput( } }) return { - skills: [...skillsByCanonicalPath.values()].sort(compareSkills), - sources: sources.sort((a, b) => - a.label.localeCompare(b.label, undefined, { sensitivity: 'base' }) - ), + skills: sortDiscoveredSkills([...skillsByCanonicalPath.values()]), + sources: sortSkillDiscoverySources(sources), scannedAt } } diff --git a/src/main/skills/skill-update-convergence.test.ts b/src/main/skills/skill-update-convergence.test.ts index 3e8d2633a06..7f30a799282 100644 --- a/src/main/skills/skill-update-convergence.test.ts +++ b/src/main/skills/skill-update-convergence.test.ts @@ -169,4 +169,34 @@ describe('convergableSkillNames', () => { ) expect([...result]).toEqual(['orca-cli']) }) + // A skill directory can legitimately be named `constructor`, and lock names come + // straight off disk, so the snapshot lookup must not walk Object.prototype. + it('keeps a skill named after an Object prototype key eligible instead of throwing', () => { + for (const name of ['constructor', 'toString', 'hasOwnProperty', '__proto__']) { + expect([ + ...convergableSkillNames([placement(name, 1)], new Map([[name, '091d9bcc']]), {}) + ]).toEqual([name]) + } + }) + + it('indexes placements once across many independent locked skills', () => { + let nameReads = 0 + const installations = Array.from({ length: 1000 }, (_, index) => ({ + ...placement(`skill-${index}`, index % 2 ? 2 : 1), + get name() { + nameReads++ + return `skill-${index}` + } + })) + const locks = new Map(installations.map((entry) => [entry.name, STUB.gitTreeSha!])) + const snapshots = Object.fromEntries([...locks.keys()].map((name) => [name, [PRE_STUB, STUB]])) + nameReads = 0 + expect([...convergableSkillNames(installations, locks, snapshots)]).toEqual( + [...locks.keys()].filter((_, index) => index % 2 === 1) + ) + expect(nameReads).toBeLessThanOrEqual(1000) + nameReads = 0 + expect([...convergableSkillNames(installations, new Map(), snapshots)]).toEqual([]) + expect(nameReads).toBe(0) + }) }) diff --git a/src/main/skills/skill-update-convergence.ts b/src/main/skills/skill-update-convergence.ts index c318e89d8b8..e87200662ff 100644 --- a/src/main/skills/skill-update-convergence.ts +++ b/src/main/skills/skill-update-convergence.ts @@ -28,22 +28,39 @@ export function convergableSkillNames( knownSnapshots: Readonly> ): ReadonlySet { const convergable = new Set(globalSkillLocks.keys()) + if (convergable.size === 0) { + return convergable + } + const observableByName = new Map() + for (const entry of installations) { + const name = entry.name + if ( + !globalSkillLocks.has(name) || + !SUPPORTED_GLOBAL_SKILL_TOPOLOGIES.has(entry.topology) || + !entry.observedPackageDigest + ) { + continue + } + const entries = observableByName.get(name) + if (entries) { + entries.push(entry) + } else { + observableByName.set(name, [entry]) + } + } for (const [name, lockHash] of globalSkillLocks) { // Why: judged only over the placements the command writes, like eligibility // itself. A plugin-cache or repo copy is never the command's to converge, so // it must neither gate the name nor rescue it — an unidentifiable cache copy // (or one parked at the lock's own revision) would otherwise defeat the gate // and re-arm the unwinnable update. - const observable = installations.filter( - (entry) => - entry.name === name && - SUPPORTED_GLOBAL_SKILL_TOPOLOGIES.has(entry.topology) && - entry.observedPackageDigest - ) + const observable = observableByName.get(name) ?? [] if (observable.length === 0) { continue } - const revisions = knownSnapshots[name] ?? [] + // `Object.hasOwn`: names come from an on-disk lock file, so a skill called + // `constructor` would otherwise read a function off the prototype and throw. + const revisions = (Object.hasOwn(knownSnapshots, name) && knownSnapshots[name]) || [] // Why: the revision each placement resolved to during observation, not a fresh // lookup by whole-folder digest. Identity tolerates files the manifest never // listed, so a folder holding an agent CLI's sidecar digests to nothing any diff --git a/src/main/startup/main-process-runtime-service.ts b/src/main/startup/main-process-runtime-service.ts index a684e951bc3..1b7f69213ad 100644 --- a/src/main/startup/main-process-runtime-service.ts +++ b/src/main/startup/main-process-runtime-service.ts @@ -129,7 +129,6 @@ export function initializeMainProcessRuntime(): OrcaRuntimeService { agentHookServer.subscribeEnrichedStatus((enriched) => recordObservedAgentStatusPaneIdentity(observedPaneIdentities, enriched.paneKey, runtime) ) - runtime.prepareLegacyWorkerTerminalRecovery() // Why before anything can attach: a client host that reattaches to a restarted runtime is only // handed its pages back if the runtime found them first. runtime.rehydrateClientHostedBrowserPages() diff --git a/src/main/usage/usage-breakdown-scaling.test.ts b/src/main/usage/usage-breakdown-scaling.test.ts new file mode 100644 index 00000000000..2412d5d097d --- /dev/null +++ b/src/main/usage/usage-breakdown-scaling.test.ts @@ -0,0 +1,130 @@ +import { expect, it } from 'vitest' +import { createUsageEventAggregation } from './usage-event-aggregation' +import type { UsageAttributedEventFields } from './usage-rollup-records' + +type Event = UsageAttributedEventFields & { cost: number } +const aggregation = createUsageEventAggregation({ + metric: { + empty: () => ({ cost: 0 }), + fromEvent: (event) => ({ cost: event.cost }), + fold: (target, source) => { + target.cost += source.cost + } + }, + cloneSessionForMerge: (session) => structuredClone(session) +}) + +function events(count: number): Event[] { + return Array.from({ length: count }, (_, index) => ({ + sessionId: 'session', + timestamp: '2026-09-07T00:00:00Z', + day: '2026-09-07', + model: `model-${index % 5}`, + projectKey: `path-${index}`, + projectLabel: `Path ${index}`, + repoId: null, + worktreeId: null, + inputTokens: 1, + cachedInputTokens: 0, + outputTokens: 2, + reasoningOutputTokens: 0, + totalTokens: 3, + cost: 0.5 + })) +} + +it('folds events without rescanning accumulated location breakdowns', () => { + let reads = 0 + const input = events(1000) + input.forEach((event, index) => + Object.defineProperty(event, 'projectKey', { + get() { + reads += 1 + return `path-${index}` + } + }) + ) + const result = aggregation.aggregate([...input, ...input]) + expect(reads).toBeLessThan(30000) + const session = result.sessions[0] + expect(session.totalTokens).toBe(6000) + expect(session.cost).toBe(1000) + expect(session.locationBreakdown).toHaveLength(1000) + expect(session.locationBreakdown.every((entry) => entry.eventCount === 2)).toBe(true) + expect(session.modelBreakdown).toHaveLength(5) + expect(result.dailyAggregates).toHaveLength(1000) +}) + +it('merges rollups using first-match indexes without mutating source breakdowns', () => { + const source = aggregation.aggregate(events(1000)).sessions[0] + const existing = structuredClone(source) + let reads = 0 + for (const entry of [...existing.locationBreakdown, ...existing.locationModelBreakdown]) { + const key = entry.locationKey + Object.defineProperty(entry, 'locationKey', { + get() { + reads += 1 + return key + } + }) + } + const target = new Map([['session', existing]]) + aggregation.mergeSessions(target, [source, source]) + expect(reads).toBeLessThan(10000) + expect(existing.totalTokens).toBe(9000) + expect(existing.cost).toBe(1500) + expect(source.totalTokens).toBe(3000) + expect(existing.locationBreakdown.every((entry) => entry.eventCount === 3)).toBe(true) +}) + +it('preserves first-wins duplicate rows and exact location/model tuple identity', () => { + const source = aggregation.aggregate(events(1)).sessions[0] + const existing = structuredClone(source) + existing.locationBreakdown.push({ ...existing.locationBreakdown[0], eventCount: 42 }) + aggregation.mergeSessions(new Map([['session', existing]]), [source]) + expect(existing.locationBreakdown.map((entry) => entry.eventCount)).toEqual([2, 42]) + const input = events(2) + input[0].projectKey = 'a::b' + input[0].model = 'c' + input[1].projectKey = 'a' + input[1].model = 'b::c' + expect(aggregation.aggregate(input).sessions[0].locationModelBreakdown).toHaveLength(2) +}) + +// Quotes and backslashes are the shapes a plain `::` separator would still collapse. +it('keeps location/model tuples distinct under quote and backslash keys', () => { + const input = events(4) + input[0].projectKey = 'a"' + input[0].model = 'b' + input[1].projectKey = 'a' + input[1].model = '"b' + input[2].projectKey = 'a\\' + input[2].model = 'b' + input[3].projectKey = 'a' + input[3].model = '\\b' + const session = aggregation.aggregate(input).sessions[0] + expect(session.locationModelBreakdown).toHaveLength(4) + expect(session.locationModelBreakdown.every((entry) => entry.eventCount === 1)).toBe(true) +}) + +// The merge index must learn the rows it appends, or a second source carrying the same +// location/model would append a duplicate row instead of folding into the first. +it('folds later sources into rows the merge itself appended', () => { + const [first] = events(1) + first.projectKey = 'new-location' + first.projectLabel = 'New location' + first.model = 'new-model' + const incoming = aggregation.aggregate([first]).sessions[0] + const existingOnly = events(1) + existingOnly[0].projectKey = 'other' + const existing = aggregation.aggregate(existingOnly).sessions[0] + aggregation.mergeSessions(new Map([['session', existing]]), [incoming, structuredClone(incoming)]) + const rows = existing.locationBreakdown.filter((entry) => entry.locationKey === 'new-location') + expect(rows.map((entry) => entry.eventCount)).toEqual([2]) + const models = existing.modelBreakdown.filter((entry) => entry.modelKey === 'new-model') + expect(models.map((entry) => entry.eventCount)).toEqual([2]) + const tuples = existing.locationModelBreakdown.filter( + (entry) => entry.locationKey === 'new-location' && entry.modelKey === 'new-model' + ) + expect(tuples.map((entry) => entry.eventCount)).toEqual([2]) +}) diff --git a/src/main/usage/usage-event-aggregation.ts b/src/main/usage/usage-event-aggregation.ts index ca3eee17544..d58a854fb37 100644 --- a/src/main/usage/usage-event-aggregation.ts +++ b/src/main/usage/usage-event-aggregation.ts @@ -2,6 +2,11 @@ * Folds attributed usage events into per-session and per-day rollups. Shared by every * event-based usage provider so a token-accounting fix lands in all of them at once. */ +import { + indexUsageSessionBreakdowns, + usageLocationModelKey, + type UsageSessionBreakdownIndex +} from './usage-session-breakdown-index' import { mergeUsageDailyAggregates, mergeUsageSessions } from './usage-rollup-merge' import { usageDailyAggregateKey, @@ -71,9 +76,10 @@ export function createUsageEventAggregation< function foldLocation( target: UsageLocationBreakdown[], event: TEvent, - eventMetric: TMetric + eventMetric: TMetric, + index: UsageSessionBreakdownIndex['locations'] ): void { - const existing = target.find((entry) => entry.locationKey === event.projectKey) ?? null + const existing = index.get(event.projectKey) if (existing) { existing.eventCount++ existing.inputTokens += event.inputTokens @@ -85,7 +91,7 @@ export function createUsageEventAggregation< return } - target.push({ + const entry: UsageLocationBreakdown = { locationKey: event.projectKey, projectLabel: event.projectLabel, repoId: event.repoId, @@ -97,16 +103,19 @@ export function createUsageEventAggregation< reasoningOutputTokens: event.reasoningOutputTokens, totalTokens: event.totalTokens, ...eventMetric - }) + } + target.push(entry) + index.set(event.projectKey, entry) } function foldModel( target: UsageModelBreakdown[], event: TEvent, - eventMetric: TMetric + eventMetric: TMetric, + index: UsageSessionBreakdownIndex['models'] ): void { const key = event.model ?? 'unknown' - const existing = target.find((entry) => entry.modelKey === key) ?? null + const existing = index.get(key) if (existing) { existing.eventCount++ existing.inputTokens += event.inputTokens @@ -118,7 +127,7 @@ export function createUsageEventAggregation< return } - target.push({ + const entry: UsageModelBreakdown = { modelKey: key, modelLabel: event.model ?? 'Unknown model', eventCount: 1, @@ -128,19 +137,19 @@ export function createUsageEventAggregation< reasoningOutputTokens: event.reasoningOutputTokens, totalTokens: event.totalTokens, ...eventMetric - }) + } + target.push(entry) + index.set(key, entry) } function foldLocationModel( target: UsageLocationModelBreakdown[], event: TEvent, - eventMetric: TMetric + eventMetric: TMetric, + index: UsageSessionBreakdownIndex['locationModels'] ): void { const modelKey = event.model ?? 'unknown' - const existing = - target.find( - (entry) => entry.locationKey === event.projectKey && entry.modelKey === modelKey - ) ?? null + const existing = index.get(usageLocationModelKey(event.projectKey, modelKey)) if (existing) { existing.eventCount++ existing.inputTokens += event.inputTokens @@ -152,7 +161,7 @@ export function createUsageEventAggregation< return } - target.push({ + const entry: UsageLocationModelBreakdown = { locationKey: event.projectKey, modelKey, modelLabel: event.model ?? 'Unknown model', @@ -165,7 +174,9 @@ export function createUsageEventAggregation< reasoningOutputTokens: event.reasoningOutputTokens, totalTokens: event.totalTokens, ...eventMetric - }) + } + target.push(entry) + index.set(usageLocationModelKey(event.projectKey, modelKey), entry) } function finalizeSessions( @@ -209,6 +220,7 @@ export function createUsageEventAggregation< } { const sessionsById = new Map>() const dailyByKey = new Map>() + const breakdownsBySession = new Map>() for (const event of events) { const eventMetric = metric.fromEvent(event) @@ -229,9 +241,19 @@ export function createUsageEventAggregation< session.totalReasoningOutputTokens += event.reasoningOutputTokens session.totalTokens += event.totalTokens metric.fold(session, eventMetric) - foldLocation(session.locationBreakdown, event, eventMetric) - foldModel(session.modelBreakdown, event, eventMetric) - foldLocationModel(session.locationModelBreakdown, event, eventMetric) + let breakdowns = breakdownsBySession.get(event.sessionId) + if (!breakdowns) { + breakdowns = indexUsageSessionBreakdowns(session) + breakdownsBySession.set(event.sessionId, breakdowns) + } + foldLocation(session.locationBreakdown, event, eventMetric, breakdowns.locations) + foldModel(session.modelBreakdown, event, eventMetric, breakdowns.models) + foldLocationModel( + session.locationModelBreakdown, + event, + eventMetric, + breakdowns.locationModels + ) const dailyKey = usageDailyAggregateKey(event) const daily = dailyByKey.get(dailyKey) ?? createEmptyDailyAggregate(event) diff --git a/src/main/usage/usage-rollup-merge.ts b/src/main/usage/usage-rollup-merge.ts index f63408f01a1..662a77c07a5 100644 --- a/src/main/usage/usage-rollup-merge.ts +++ b/src/main/usage/usage-rollup-merge.ts @@ -1,4 +1,9 @@ /** Combines rollups produced by separate sources (rollout files, sibling databases) of one provider. */ +import { + indexUsageSessionBreakdowns, + usageLocationModelKey, + type UsageSessionBreakdownIndex +} from './usage-session-breakdown-index' import { usageDailyAggregateKey, type UsageDailyAggregate, @@ -16,6 +21,7 @@ export function mergeUsageSessions( sessions: UsageSession[], { fold, cloneSessionForMerge }: UsageRollupMergeOptions ): void { + const breakdownsBySession = new Map>() for (const session of sessions) { const existing = target.get(session.sessionId) if (!existing) { @@ -39,10 +45,13 @@ export function mergeUsageSessions( existing.totalTokens += session.totalTokens fold(existing, session) + let breakdowns = breakdownsBySession.get(session.sessionId) + if (!breakdowns) { + breakdowns = indexUsageSessionBreakdowns(existing) + breakdownsBySession.set(session.sessionId, breakdowns) + } for (const location of session.locationBreakdown) { - const existingLocation = - existing.locationBreakdown.find((entry) => entry.locationKey === location.locationKey) ?? - null + const existingLocation = breakdowns.locations.get(location.locationKey) if (existingLocation) { existingLocation.eventCount += location.eventCount existingLocation.inputTokens += location.inputTokens @@ -52,13 +61,14 @@ export function mergeUsageSessions( existingLocation.totalTokens += location.totalTokens fold(existingLocation, location) } else { - existing.locationBreakdown.push({ ...location }) + const copy = { ...location } + existing.locationBreakdown.push(copy) + breakdowns.locations.set(location.locationKey, copy) } } for (const model of session.modelBreakdown) { - const existingModel = - existing.modelBreakdown.find((entry) => entry.modelKey === model.modelKey) ?? null + const existingModel = breakdowns.models.get(model.modelKey) if (existingModel) { existingModel.eventCount += model.eventCount existingModel.inputTokens += model.inputTokens @@ -68,17 +78,16 @@ export function mergeUsageSessions( existingModel.totalTokens += model.totalTokens fold(existingModel, model) } else { - existing.modelBreakdown.push({ ...model }) + const copy = { ...model } + existing.modelBreakdown.push(copy) + breakdowns.models.set(model.modelKey, copy) } } for (const locationModel of session.locationModelBreakdown) { - const existingLocationModel = - existing.locationModelBreakdown.find( - (entry) => - entry.locationKey === locationModel.locationKey && - entry.modelKey === locationModel.modelKey - ) ?? null + const existingLocationModel = breakdowns.locationModels.get( + usageLocationModelKey(locationModel.locationKey, locationModel.modelKey) + ) if (existingLocationModel) { existingLocationModel.eventCount += locationModel.eventCount existingLocationModel.inputTokens += locationModel.inputTokens @@ -88,7 +97,12 @@ export function mergeUsageSessions( existingLocationModel.totalTokens += locationModel.totalTokens fold(existingLocationModel, locationModel) } else { - existing.locationModelBreakdown.push({ ...locationModel }) + const copy = { ...locationModel } + existing.locationModelBreakdown.push(copy) + breakdowns.locationModels.set( + usageLocationModelKey(locationModel.locationKey, locationModel.modelKey), + copy + ) } } } diff --git a/src/main/usage/usage-session-breakdown-index.ts b/src/main/usage/usage-session-breakdown-index.ts new file mode 100644 index 00000000000..7cc88be20e5 --- /dev/null +++ b/src/main/usage/usage-session-breakdown-index.ts @@ -0,0 +1,37 @@ +import type { + UsageSession, + UsageLocationBreakdown, + UsageModelBreakdown, + UsageLocationModelBreakdown +} from './usage-rollup-records' + +export function usageLocationModelKey(locationKey: string, modelKey: string): string { + return JSON.stringify([locationKey, modelKey]) +} + +export function indexUsageSessionBreakdowns(session: UsageSession) { + const locations = new Map>() + const models = new Map>() + const locationModels = new Map>() + for (const entry of session.locationBreakdown) { + if (!locations.has(entry.locationKey)) { + locations.set(entry.locationKey, entry) + } + } + for (const entry of session.modelBreakdown) { + if (!models.has(entry.modelKey)) { + models.set(entry.modelKey, entry) + } + } + for (const entry of session.locationModelBreakdown) { + const key = usageLocationModelKey(entry.locationKey, entry.modelKey) + if (!locationModels.has(key)) { + locationModels.set(key, entry) + } + } + return { locations, models, locationModels } +} + +export type UsageSessionBreakdownIndex = ReturnType< + typeof indexUsageSessionBreakdowns +> diff --git a/src/main/warp-themes/directory-entry-order.ts b/src/main/warp-themes/directory-entry-order.ts new file mode 100644 index 00000000000..1b4cbf81bcb --- /dev/null +++ b/src/main/warp-themes/directory-entry-order.ts @@ -0,0 +1,11 @@ +// Warp theme discovery walks user home and app-data trees, so callers filter to +// the entries they want *before* sorting: same resulting order (the comparator is +// a total order over a stable sort), without collating the hundreds of unrelated +// names a home directory holds. +export function sortDirectoryEntriesByName(entries: T[]): T[] { + if (entries.length < 2) { + return entries + } + const compare = new Intl.Collator(undefined, { sensitivity: 'base' }).compare + return entries.sort((left, right) => compare(left.name, right.name)) +} diff --git a/src/main/warp-themes/discovery.test.ts b/src/main/warp-themes/discovery.test.ts index 977a5b30de7..0a6851019c4 100644 --- a/src/main/warp-themes/discovery.test.ts +++ b/src/main/warp-themes/discovery.test.ts @@ -43,6 +43,78 @@ describe('getWarpThemeDirectories', () => { readdirSyncMock.mockReturnValue([]) }) + it('sorts dynamic directories with one collator and preserves locale ties', () => { + platformMock.mockReturnValue('darwin') + const names = ['éclair', 'Eclair', 'item2', 'item10', 'Ångström', 'zebra', 'İstanbul'].map( + (name) => `.warp-${name}` + ) + readdirSyncMock.mockReturnValue(names.map(directoryEntry)) + const expected = [...names].sort((a, b) => + // oxlint-disable-next-line sort-comparator-performance/no-repeated-collator -- Preserve the old comparator as the parity oracle. + a.localeCompare(b, undefined, { sensitivity: 'base' }) + ) + const NativeCollator = Intl.Collator + const construct = vi.spyOn(Intl, 'Collator').mockImplementation(function (locales, options) { + return new NativeCollator(locales, options) + }) + const localeCompare = vi.spyOn(String.prototype, 'localeCompare') + try { + expect(getWarpThemeDirectories().slice(6)).toEqual( + expected.map((name) => `/Users/alice/${name}/themes`) + ) + expect(construct).toHaveBeenCalledExactlyOnceWith(undefined, { sensitivity: 'base' }) + expect(localeCompare).not.toHaveBeenCalled() + } finally { + construct.mockRestore() + localeCompare.mockRestore() + } + }) + + it('collates only the Warp entries in a crowded home directory', () => { + platformMock.mockReturnValue('darwin') + const noise = Array.from({ length: 500 }, (_, index) => directoryEntry(`project-${index}`)) + const warpNames = ['.warp-zebra', '.warp-Ångström', '.warp-éclair'] + readdirSyncMock.mockReturnValue([...noise, ...warpNames.map(directoryEntry)]) + const expected = [...warpNames].sort((a, b) => + // oxlint-disable-next-line sort-comparator-performance/no-repeated-collator -- Preserve the old comparator as the parity oracle. + a.localeCompare(b, undefined, { sensitivity: 'base' }) + ) + const NativeCollator = Intl.Collator + const compares: string[][] = [] + vi.spyOn(Intl, 'Collator').mockImplementation(function (locales, options) { + const collator = new NativeCollator(locales, options) + return { + ...collator, + compare: (left: string, right: string) => { + compares.push([left, right]) + return collator.compare(left, right) + } + } + }) + try { + expect(getWarpThemeDirectories().slice(6)).toEqual( + expected.map((name) => `/Users/alice/${name}/themes`) + ) + // Filtering first keeps the crowd out of ICU: only Warp names are collated. + expect(compares.flat().every((name) => name.startsWith('.warp'))).toBe(true) + expect(compares.length).toBeLessThan(10) + } finally { + vi.restoreAllMocks() + } + }) + + it('skips a directory scan that finds no dynamic Warp entries', () => { + platformMock.mockReturnValue('darwin') + readdirSyncMock.mockReturnValue([directoryEntry('Documents'), fileEntry('.warprc')]) + const construct = vi.spyOn(Intl, 'Collator') + try { + expect(getWarpThemeDirectories()).toHaveLength(6) + expect(construct).not.toHaveBeenCalled() + } finally { + vi.restoreAllMocks() + } + }) + it('returns macOS Warp channel theme directories in stable-first order', () => { platformMock.mockReturnValue('darwin') expect(getWarpThemeDirectories()).toEqual([ diff --git a/src/main/warp-themes/discovery.ts b/src/main/warp-themes/discovery.ts index fd29419c12c..68f8a70c654 100644 --- a/src/main/warp-themes/discovery.ts +++ b/src/main/warp-themes/discovery.ts @@ -2,6 +2,7 @@ import { readdirSync } from 'node:fs' import type { Dirent } from 'node:fs' import { homedir, platform } from 'node:os' import path from 'node:path' +import { sortDirectoryEntriesByName } from './directory-entry-order' const WARP_CHANNELS = [ { macName: '.warp', linuxName: 'warp-terminal', windowsName: 'Warp' }, @@ -16,10 +17,13 @@ const WARP_CHANNELS = [ } ] -function readDirectoryEntries(directoryPath: string): Dirent[] { +function readDirectoryEntries( + directoryPath: string, + include: (entry: Dirent) => boolean +): Dirent[] { try { - return readdirSync(directoryPath, { withFileTypes: true }).sort((left, right) => - left.name.localeCompare(right.name, undefined, { sensitivity: 'base' }) + return sortDirectoryEntriesByName( + readdirSync(directoryPath, { withFileTypes: true }).filter(include) ) } catch { return [] @@ -57,9 +61,10 @@ function getMacWarpThemeDirectories(home: string): string[] { return warpThemeDirectoriesFromDataHomes( [ ...WARP_CHANNELS.map((channel) => pathImpl.join(home, channel.macName)), - ...readDirectoryEntries(home) - .filter((entry) => entry.isDirectory() && entry.name.startsWith('.warp')) - .map((entry) => pathImpl.join(home, entry.name)) + ...readDirectoryEntries( + home, + (entry) => entry.isDirectory() && entry.name.startsWith('.warp') + ).map((entry) => pathImpl.join(home, entry.name)) ], pathImpl ) @@ -77,13 +82,11 @@ function getLinuxWarpThemeDirectories(home: string): string[] { return warpThemeDirectoriesFromDataHomes( [ ...WARP_CHANNELS.map((channel) => pathImpl.join(dataHome, channel.linuxName)), - ...readDirectoryEntries(dataHome) - .filter( - (entry) => - entry.isDirectory() && - (entry.name === 'warp-terminal' || entry.name.startsWith('warp-')) - ) - .map((entry) => pathImpl.join(dataHome, entry.name)) + ...readDirectoryEntries( + dataHome, + (entry) => + entry.isDirectory() && (entry.name === 'warp-terminal' || entry.name.startsWith('warp-')) + ).map((entry) => pathImpl.join(dataHome, entry.name)) ], pathImpl ) @@ -102,10 +105,7 @@ function getWindowsWarpThemeDirectories(home: string): string[] { path.win32 ) } - for (const entry of readDirectoryEntries(warpAppData)) { - if (!entry.isDirectory()) { - continue - } + for (const entry of readDirectoryEntries(warpAppData, (entry) => entry.isDirectory())) { addDedupeDirectory( directories, seenDirectories, diff --git a/src/main/warp-themes/manual-warp-theme-files.test.ts b/src/main/warp-themes/manual-warp-theme-files.test.ts new file mode 100644 index 00000000000..975e40414dc --- /dev/null +++ b/src/main/warp-themes/manual-warp-theme-files.test.ts @@ -0,0 +1,47 @@ +import path from 'node:path' +import { describe, expect, it, vi } from 'vitest' + +vi.mock('electron', () => ({ BrowserWindow: {}, dialog: {} })) + +import { createManualWarpThemeFileCandidates } from './manual-warp-theme-files' + +describe('manual theme ordering', () => { + it('reuses one collator for labels and path ties without changing the selected order', () => { + const names = ['éclair', 'Eclair', 'item2', 'item10', 'Ångström', 'zebra', 'İstanbul'] + const paths = Array.from({ length: 200 }, (_, index) => + path.join('themes', names[index % names.length]!, `${names[(index * 3) % names.length]}.yaml`) + ) + const expected = [...paths].sort( + (a, b) => + // oxlint-disable-next-line sort-comparator-performance/no-repeated-collator -- Preserve the old comparator as the parity oracle. + path.basename(a).localeCompare(path.basename(b), undefined, { sensitivity: 'base' }) || + // oxlint-disable-next-line sort-comparator-performance/no-repeated-collator -- Preserve the old comparator as the parity oracle. + a.localeCompare(b, undefined, { sensitivity: 'base' }) + ) + const NativeCollator = Intl.Collator + const construct = vi.spyOn(Intl, 'Collator').mockImplementation(function (locales, options) { + return new NativeCollator(locales, options) + }) + const localeCompare = vi.spyOn(String.prototype, 'localeCompare') + try { + expect(createManualWarpThemeFileCandidates(paths).map((file) => file.path)).toEqual(expected) + expect(construct).toHaveBeenCalledExactlyOnceWith(undefined, { sensitivity: 'base' }) + expect(localeCompare).not.toHaveBeenCalled() + } finally { + vi.restoreAllMocks() + } + }) + + it('returns a single dialog selection without collating', () => { + const construct = vi.spyOn(Intl, 'Collator') + try { + expect(createManualWarpThemeFileCandidates([]).map((file) => file.path)).toEqual([]) + expect(createManualWarpThemeFileCandidates(['a/one.yaml']).map((file) => file.path)).toEqual([ + 'a/one.yaml' + ]) + expect(construct).not.toHaveBeenCalled() + } finally { + vi.restoreAllMocks() + } + }) +}) diff --git a/src/main/warp-themes/manual-warp-theme-files.ts b/src/main/warp-themes/manual-warp-theme-files.ts index 496ad9e3919..b50ff8ee48b 100644 --- a/src/main/warp-themes/manual-warp-theme-files.ts +++ b/src/main/warp-themes/manual-warp-theme-files.ts @@ -2,29 +2,28 @@ import { createHash } from 'node:crypto' import path from 'node:path' import { BrowserWindow, dialog, type OpenDialogOptions, type WebContents } from 'electron' import type { WarpThemeImportSkippedFile } from '../../shared/terminal-custom-themes' -import { - compareThemeFileLabels, - isYamlFile, - MAX_THEME_FILES, - type ThemeFileCandidate -} from './theme-file-scanner' +import { isYamlFile, MAX_THEME_FILES, type ThemeFileCandidate } from './theme-file-scanner' export function createManualWarpThemeFileCandidates(filePaths: string[]): ThemeFileCandidate[] { - return filePaths - .map((filePath) => ({ - path: filePath, - label: path.basename(filePath), - contentHashDiscriminator: true - })) - .sort((left, right) => { - const labelComparison = compareThemeFileLabels(left, right) - if (labelComparison !== 0) { - return labelComparison - } - // Why: manual dialogs can return selections in click order. Sort only in - // main so duplicate basenames get deterministic IDs without persisting paths. - return left.path.localeCompare(right.path, undefined, { sensitivity: 'base' }) - }) + const candidates = filePaths.map((filePath) => ({ + path: filePath, + label: path.basename(filePath), + contentHashDiscriminator: true + })) + // Picking a single file is the common dialog outcome and needs no collation. + if (candidates.length < 2) { + return candidates + } + const compareLabels = new Intl.Collator(undefined, { sensitivity: 'base' }).compare + return candidates.sort((left, right) => { + const labelComparison = compareLabels(left.label, right.label) + if (labelComparison !== 0) { + return labelComparison + } + // Why: manual dialogs can return selections in click order. Sort only in + // main so duplicate basenames get deterministic IDs without persisting paths. + return compareLabels(left.path, right.path) + }) } export function manualWarpThemeContentDiscriminator(label: string, content: string): string { diff --git a/src/main/warp-themes/theme-file-scanner.test.ts b/src/main/warp-themes/theme-file-scanner.test.ts new file mode 100644 index 00000000000..bbfd5639e65 --- /dev/null +++ b/src/main/warp-themes/theme-file-scanner.test.ts @@ -0,0 +1,36 @@ +import { mkdir, mkdtemp, readdir, rm, writeFile } from 'node:fs/promises' +import { tmpdir } from 'node:os' +import path from 'node:path' +import { expect, it, vi } from 'vitest' +import { scanWarpThemeDirectory } from './theme-file-scanner' + +it('reuses one collator per directory while preserving capped scan order', async () => { + const directory = await mkdtemp(path.join(tmpdir(), 'orca-theme-order-')) + const names = ['éclair', 'item2', 'item10', 'Ångström', 'zebra', 'İstanbul'] + try { + await Promise.all(names.map((name) => writeFile(path.join(directory, `${name}.yaml`), ''))) + await mkdir(path.join(directory, 'nested')) + await writeFile(path.join(directory, 'nested', 'theme.yaml'), '') + const expected = (await readdir(directory)) + // oxlint-disable-next-line sort-comparator-performance/no-repeated-collator -- Preserve the old comparator as the parity oracle. + .sort((a, b) => a.localeCompare(b, undefined, { sensitivity: 'base' })) + .map((name) => (name === 'nested' ? path.join(name, 'theme.yaml') : name)) + const NativeCollator = Intl.Collator + const construct = vi.spyOn(Intl, 'Collator').mockImplementation(function (locales, options) { + return new NativeCollator(locales, options) + }) + const localeCompare = vi.spyOn(String.prototype, 'localeCompare') + try { + const result = await scanWarpThemeDirectory(directory, undefined, { themeFileLimit: 6 }) + expect(result.files.map((file) => file.label)).toEqual(expected.slice(0, 6)) + expect(result.themeFileLimitHit).toBe(true) + // One directory needs collation; the single-entry nested folder needs none. + expect(construct).toHaveBeenCalledExactlyOnceWith(undefined, { sensitivity: 'base' }) + expect(localeCompare).not.toHaveBeenCalled() + } finally { + vi.restoreAllMocks() + } + } finally { + await rm(directory, { recursive: true, force: true }) + } +}) diff --git a/src/main/warp-themes/theme-file-scanner.ts b/src/main/warp-themes/theme-file-scanner.ts index ba20abe0cc2..2602acb71da 100644 --- a/src/main/warp-themes/theme-file-scanner.ts +++ b/src/main/warp-themes/theme-file-scanner.ts @@ -2,6 +2,7 @@ import { opendir } from 'node:fs/promises' import type { Dirent } from 'node:fs' import path from 'node:path' import type { WarpThemeImportSkippedFile } from '../../shared/terminal-custom-themes' +import { sortDirectoryEntriesByName } from './directory-entry-order' export const MAX_THEME_FILES = 200 const MAX_THEME_DIRECTORY_DEPTH = 3 @@ -44,17 +45,6 @@ export function isYamlFile(filePath: string): boolean { return YAML_EXTENSIONS.has(path.extname(filePath).toLowerCase()) } -export function compareThemeFileLabels( - left: ThemeFileCandidate, - right: ThemeFileCandidate -): number { - return left.label.localeCompare(right.label, undefined, { sensitivity: 'base' }) -} - -function compareDirentNames(left: Dirent, right: Dirent): number { - return left.name.localeCompare(right.name, undefined, { sensitivity: 'base' }) -} - function isYamlFileEntry(entry: Dirent): boolean { return (entry.isFile() || entry.isSymbolicLink()) && isYamlFile(entry.name) } @@ -141,10 +131,10 @@ async function collectYamlFilesFromDirectory( return } - const sortedEntries = entries.sort(compareDirentNames) if (previewBudgetExpiredWhileReading) { return } + const sortedEntries = sortDirectoryEntriesByName(entries) if (entryLimitHit && !budget.entryLimitReported) { skippedFiles.push({ label: relativeDirectory || sourceLabel, diff --git a/src/main/window/runtime-window-lifecycle.ts b/src/main/window/runtime-window-lifecycle.ts index 2a6ab95a07f..78c5f2ec426 100644 --- a/src/main/window/runtime-window-lifecycle.ts +++ b/src/main/window/runtime-window-lifecycle.ts @@ -149,8 +149,6 @@ export function registerRuntimeWindowLifecycle( resolution, ...(ptyId ? { ptyId } : {}) }), - setLegacyWorkerTerminalResumeFence: (paneKey, blocked) => - send('agentStatus:legacyWorkerTerminalResumeFence', { paneKey, blocked }), splitTerminal: (tabId, paneRuntimeId, opts) => { send('ui:splitTerminal', { tabId, diff --git a/src/preload/api/agent-status-api.ts b/src/preload/api/agent-status-api.ts index 89677022506..7aa6c21115d 100644 --- a/src/preload/api/agent-status-api.ts +++ b/src/preload/api/agent-status-api.ts @@ -28,10 +28,6 @@ export type AgentStatusApi = { ptyId?: string }) => void ) => () => void - /** Listen for the automatic-resume fence a settled worker's pane gains or loses mid-session. */ - onLegacyWorkerTerminalResumeFence: ( - callback: (data: { paneKey: string; blocked: boolean }) => void - ) => () => void getMigrationUnsupportedSnapshot: () => Promise /** Drop a paneKey from the main-process hook cache and on-disk last-status file. Fire-and-forget. */ drop: (paneKey: string) => void diff --git a/src/preload/api/agent-status-bridge.ts b/src/preload/api/agent-status-bridge.ts index 3c3415cd207..3cc1654aaed 100644 --- a/src/preload/api/agent-status-bridge.ts +++ b/src/preload/api/agent-status-bridge.ts @@ -61,16 +61,6 @@ export const agentStatusApi = { ipcRenderer.on('agentStatus:legacyWorkerTerminalRecovery', listener) return () => ipcRenderer.removeListener('agentStatus:legacyWorkerTerminalRecovery', listener) }, - onLegacyWorkerTerminalResumeFence: ( - callback: (data: { paneKey: string; blocked: boolean }) => void - ): (() => void) => { - const listener = ( - _event: Electron.IpcRendererEvent, - data: { paneKey: string; blocked: boolean } - ) => callback(data) - ipcRenderer.on('agentStatus:legacyWorkerTerminalResumeFence', listener) - return () => ipcRenderer.removeListener('agentStatus:legacyWorkerTerminalResumeFence', listener) - }, getMigrationUnsupportedSnapshot: (): Promise => ipcRenderer.invoke('agentStatus:getMigrationUnsupportedSnapshot'), /** Drop the cached hook status for a paneKey on both sides (memory + on-disk) so a relaunch can't resurrect a dismissed row. */ diff --git a/src/preload/api/pty-api.ts b/src/preload/api/pty-api.ts index d2d547d98cb..f7ce3dfc1af 100644 --- a/src/preload/api/pty-api.ts +++ b/src/preload/api/pty-api.ts @@ -4,7 +4,7 @@ import type { } from '../../shared/agent-session-resume' import type { StartupCommandDelivery } from '../../shared/codex-startup-delivery' import type { ProjectExecutionRuntimeResolution } from '../../shared/project-execution-runtime' -import type { PtyListedSession } from '../../shared/pty-listed-session' +import type { PtyListedSession, PtySessionListScope } from '../../shared/pty-listed-session' import type { PtyMainDeliveryDiagnostics } from '../../shared/pty-delivery-diagnostics' import type { PtyModelRestoreNeededEvent } from '../../shared/pty-model-restore-marker' import type { @@ -123,7 +123,7 @@ export type PtyApi = { confirmForegroundProcess: (id: string) => Promise getCwd: (id: string) => Promise getSize: (id: string) => Promise<{ cols: number; rows: number } | null> - listSessions: () => Promise + listSessions: (scope?: PtySessionListScope) => Promise getAuthoritativeBufferSnapshotCapabilities?: ( ids: string[] ) => Promise<{ id: string; authoritative: boolean | null }[]> diff --git a/src/preload/api/pty-bridge-session-control.ts b/src/preload/api/pty-bridge-session-control.ts index 2854278c20b..d85967c6f23 100644 --- a/src/preload/api/pty-bridge-session-control.ts +++ b/src/preload/api/pty-bridge-session-control.ts @@ -7,7 +7,7 @@ import type { SleepingAgentLaunchConfig } from '../../shared/agent-session-resume' import type { TuiAgent } from '../../shared/tui-agent' -import type { PtyListedSession } from '../../shared/pty-listed-session' +import type { PtyListedSession, PtySessionListScope } from '../../shared/pty-listed-session' import type { PtyRendererDeliveryHealthReply, PtyRendererDeliveryStateReport @@ -150,7 +150,8 @@ export const ptySessionControlApi = { }, kill: (id: string, opts?: { keepHistory?: boolean }): Promise => ipcRenderer.invoke('pty:kill', { id, keepHistory: opts?.keepHistory ?? false }), - listSessions: (): Promise => ipcRenderer.invoke('pty:listSessions'), + listSessions: (scope?: PtySessionListScope): Promise => + ipcRenderer.invoke('pty:listSessions', scope), getAuthoritativeBufferSnapshotCapabilities: ( ids: string[] ): Promise<{ id: string; authoritative: boolean | null }[]> => diff --git a/src/renderer/src/assets/main.css b/src/renderer/src/assets/main.css index b4051a3b988..a65dfe59e9a 100644 --- a/src/renderer/src/assets/main.css +++ b/src/renderer/src/assets/main.css @@ -400,11 +400,6 @@ z-index: 40 !important; } -/* Above the z-40 updater/onboarding chrome, below the floating workspace panel's z-45. */ -.native-chat-pane-shell:has([data-native-chat-working='true']) { - z-index: 44; -} - [data-sonner-toaster] [data-sonner-toast][data-styled='true'] { align-items: flex-start; flex-wrap: wrap; diff --git a/src/renderer/src/components/activity/ActivityThreadOptionsMenu.test.tsx b/src/renderer/src/components/activity/ActivityThreadOptionsMenu.test.tsx index 3f753f3d69d..6ba2b7906a4 100644 --- a/src/renderer/src/components/activity/ActivityThreadOptionsMenu.test.tsx +++ b/src/renderer/src/components/activity/ActivityThreadOptionsMenu.test.tsx @@ -167,9 +167,18 @@ describe('ActivityThreadOptionsMenu', () => { expect(document.body.textContent).toContain('Agent') }) - it('explains compact mode on hover', async () => { + it('updates compact mode without closing the menu', async () => { + const onCompactModeChange = vi.fn() await act(async () => { - root.render() + root.render( + + + + ) }) const trigger = container.querySelector( @@ -179,19 +188,20 @@ describe('ActivityThreadOptionsMenu', () => { trigger?.dispatchEvent(new KeyboardEvent('keydown', { bubbles: true, key: 'Enter' })) }) - const compactMode = document.querySelector('[role="menuitemcheckbox"]') + const compactMode = Array.from( + document.querySelectorAll('[role="menuitemcheckbox"]') + ).find((item) => item.textContent === 'Compact mode') await act(async () => { - compactMode?.dispatchEvent(new Event('pointermove', { bubbles: true })) + compactMode?.dispatchEvent(new KeyboardEvent('keydown', { bubbles: true, key: 'Enter' })) }) - expect(document.body.textContent).toContain( - 'Shows shorter thread rows with one-line titles and two-line status messages.' - ) + expect(onCompactModeChange).toHaveBeenCalledWith(true) + expect(document.body.textContent).toContain('Compact mode') }) it('puts persisted search visibility and unread actions in the menu', async () => { const onShowSearchChange = vi.fn() - const onToggleUnread = vi.fn() + const onUnreadOnlyChange = vi.fn() await act(async () => { root.render( @@ -203,7 +213,7 @@ describe('ActivityThreadOptionsMenu', () => { showSearch onShowSearchChange={onShowSearchChange} unreadOnly={false} - onToggleUnread={onToggleUnread} + onUnreadOnlyChange={onUnreadOnlyChange} /> ) @@ -230,8 +240,8 @@ describe('ActivityThreadOptionsMenu', () => { expect(onShowSearchChange).toHaveBeenCalledWith(false) }) - it('explains show unread threads only on hover without a second unread state marker', async () => { - const onToggleUnread = vi.fn() + it('updates the unread filter without closing the menu', async () => { + const onUnreadOnlyChange = vi.fn() await act(async () => { root.render( @@ -241,7 +251,7 @@ describe('ActivityThreadOptionsMenu', () => { onCompactModeChange={vi.fn()} onMarkAllThreadsRead={vi.fn()} unreadOnly={false} - onToggleUnread={onToggleUnread} + onUnreadOnlyChange={onUnreadOnlyChange} /> ) @@ -254,15 +264,15 @@ describe('ActivityThreadOptionsMenu', () => { trigger?.dispatchEvent(new KeyboardEvent('keydown', { bubbles: true, key: 'Enter' })) }) - const unreadItem = document.querySelector('[role="menuitemcheckbox"]') + const unreadItem = Array.from( + document.querySelectorAll('[role="menuitemcheckbox"]') + ).find((item) => item.textContent === 'Show unread only') await act(async () => { - unreadItem?.dispatchEvent(new Event('pointermove', { bubbles: true })) + unreadItem?.dispatchEvent(new KeyboardEvent('keydown', { bubbles: true, key: 'Enter' })) }) - expect(document.body.textContent).toContain( - 'Filters the activity list to show only threads with unread updates.' - ) - expect(document.querySelector('[data-unread-dot]')).toBeNull() + expect(onUnreadOnlyChange).toHaveBeenCalledWith(true) + expect(document.body.textContent).toContain('Show unread only') }) it('renders show child agents checkbox when onShowChildAgentsChange is provided', async () => { @@ -281,6 +291,14 @@ describe('ActivityThreadOptionsMenu', () => { trigger?.dispatchEvent(new KeyboardEvent('keydown', { bubbles: true, key: 'Enter' })) }) + const childAgentsItem = Array.from( + document.querySelectorAll('[role="menuitemcheckbox"]') + ).find((item) => item.textContent === 'Show child agents') + await act(async () => { + childAgentsItem?.dispatchEvent(new KeyboardEvent('keydown', { bubbles: true, key: 'Enter' })) + }) + + expect(onShowChildAgentsChange).toHaveBeenCalledWith(true) expect(document.body.textContent).toContain('Show child agents') }) }) diff --git a/src/renderer/src/components/activity/activity-scope-filter-controls.tsx b/src/renderer/src/components/activity/activity-scope-filter-controls.tsx index a9e75e10483..e90ec1f3322 100644 --- a/src/renderer/src/components/activity/activity-scope-filter-controls.tsx +++ b/src/renderer/src/components/activity/activity-scope-filter-controls.tsx @@ -1,6 +1,6 @@ import React from 'react' import { useAppStore } from '@/store' -import { DropdownMenuItem, DropdownMenuSeparator } from '@/components/ui/dropdown-menu' +import { DropdownMenuItem } from '@/components/ui/dropdown-menu' import { translate } from '@/i18n/i18n' import SidebarRepositoryFilterSection from '@/components/sidebar/SidebarRepositoryFilterSection' import { SidebarHostScopeMenuSection } from '@/components/sidebar/SidebarHostScopeMenuSection' @@ -11,12 +11,30 @@ import { import { useSidebarHostScopeOptions } from '@/components/sidebar/use-sidebar-host-scope-options' /** - * Host/project scope controls for the Agents activity surfaces. State is the - * persisted agents-view scope (agentsVisibleHostIds / agentsFilterRepoIds), - * deliberately separate from the workspace-nav filters. + * Whether {@link ActivityScopeFilterMenuItems} renders anything. + * Why exported: the parent owns the Filters label and separator, so it has to + * know whether the section would be empty. */ -export function ActivityScopeFilterMenuSections(): React.JSX.Element | null { +export function useActivityScopeFilterMenuItemsVisible(): boolean { const repos = useAppStore((s) => s.repos) + const agentsVisibleHostIds = useAppStore((s) => s.agentsVisibleHostIds) + const agentsFilterRepoIds = useAppStore((s) => s.agentsFilterRepoIds) + const { hostOptions } = useSidebarHostScopeOptions() + return ( + agentsVisibleHostIds !== null || + agentsFilterRepoIds.length > 0 || + shouldShowHostScopeControls(hostOptions) || + repos.length > 1 + ) +} + +/** + * Host/project scope items for the Agents activity surfaces. State is the + * persisted agents-view scope (agentsVisibleHostIds / agentsFilterRepoIds), + * deliberately separate from the workspace-nav filters. The parent owns the + * Filters label and separator. + */ +export function ActivityScopeFilterMenuItems(): React.JSX.Element | null { const agentsVisibleHostIds = useAppStore((s) => s.agentsVisibleHostIds) const setAgentsVisibleHostIds = useAppStore((s) => s.setAgentsVisibleHostIds) const agentsFilterRepoIds = useAppStore((s) => s.agentsFilterRepoIds) @@ -24,25 +42,14 @@ export function ActivityScopeFilterMenuSections(): React.JSX.Element | null { const { hostOptions } = useSidebarHostScopeOptions() const showHostScopeControls = shouldShowHostScopeControls(hostOptions) const hasScopeFilter = agentsVisibleHostIds !== null || agentsFilterRepoIds.length > 0 + const visible = useActivityScopeFilterMenuItemsVisible() - if (!hasScopeFilter && !showHostScopeControls && repos.length <= 1) { + if (!visible) { return null } + return ( <> - {hasScopeFilter ? ( - { - setAgentsVisibleHostIds(null) - setAgentsFilterRepoIds([]) - }} - > - {translate( - 'auto.components.activity.ActivityScopeFilterControls.resetScope', - 'Show all hosts and projects' - )} - - ) : null} {showHostScopeControls ? ( - + {hasScopeFilter ? ( + { + setAgentsVisibleHostIds(null) + setAgentsFilterRepoIds([]) + }} + > + {translate( + 'auto.components.activity.ActivityScopeFilterControls.resetScope', + 'Show all hosts and projects' + )} + + ) : null} ) } diff --git a/src/renderer/src/components/activity/activity-thread-options-menu.tsx b/src/renderer/src/components/activity/activity-thread-options-menu.tsx index bd398986bd3..5a9bd3bc59c 100644 --- a/src/renderer/src/components/activity/activity-thread-options-menu.tsx +++ b/src/renderer/src/components/activity/activity-thread-options-menu.tsx @@ -1,21 +1,12 @@ import React from 'react' -import { - Check, - CheckCheck, - GitFork, - Layers, - ListChecks, - ListFilter, - Rows3, - Search, - Trash2 -} from 'lucide-react' +import { CheckCheck, ListFilter, Trash2 } from 'lucide-react' import { Button } from '@/components/ui/button' import { DropdownMenu, DropdownMenuCheckboxItem, DropdownMenuContent, DropdownMenuItem, + DropdownMenuLabel, DropdownMenuRadioGroup, DropdownMenuRadioItem, DropdownMenuSeparator, @@ -27,12 +18,19 @@ import { import { Tooltip, TooltipContent, TooltipTrigger } from '@/components/ui/tooltip' import { translate } from '@/i18n/i18n' import { - ActivityScopeFilterMenuSections, - useActivityScopeFilterActive + ActivityScopeFilterMenuItems, + useActivityScopeFilterActive, + useActivityScopeFilterMenuItemsVisible } from './activity-scope-filter-controls' import type { ActivityGroupBy } from './activity-thread-types' -const ALIGNED_CHECKBOX_ITEM_CLASS = 'pl-2 [&>span.absolute]:hidden' +const GROUP_BY_OPTIONS = [ + 'none', + 'status', + 'project', + 'worktree', + 'agent' +] as const satisfies readonly ActivityGroupBy[] function getActivityGroupByLabel(groupBy: ActivityGroupBy): string { switch (groupBy) { @@ -63,7 +61,7 @@ export function ActivityThreadOptionsMenu({ showSearch = false, onShowSearchChange, unreadOnly = false, - onToggleUnread + onUnreadOnlyChange }: { groupBy?: ActivityGroupBy onGroupByChange?: (groupBy: ActivityGroupBy) => void @@ -78,10 +76,14 @@ export function ActivityThreadOptionsMenu({ showSearch?: boolean onShowSearchChange?: (showSearch: boolean) => void unreadOnly?: boolean - onToggleUnread?: () => void + onUnreadOnlyChange?: (unreadOnly: boolean) => void }): React.JSX.Element { const skipCloseAutoFocusRef = React.useRef(false) const scopeFilterActive = useActivityScopeFilterActive() + const scopeFilterItemsVisible = useActivityScopeFilterMenuItemsVisible() + const hasFilters = Boolean( + onUnreadOnlyChange || onShowChildAgentsChange || scopeFilterItemsVisible + ) const optionsLabel = scopeFilterActive ? translate( 'auto.components.activity.ActivityPrototypePage.threadListOptionsFiltered', @@ -126,7 +128,7 @@ export function ActivityThreadOptionsMenu({ side="right" align="start" sideOffset={8} - className="w-56" + className="w-60" onCloseAutoFocus={(event) => { if (skipCloseAutoFocusRef.current) { event.preventDefault() @@ -134,70 +136,56 @@ export function ActivityThreadOptionsMenu({ } }} > - {onShowSearchChange || onToggleUnread ? ( + {hasFilters ? ( <> - {onShowSearchChange ? ( + + {translate( + 'auto.components.activity.ActivityPrototypePage.filtersSection', + 'Filters' + )} + + {onUnreadOnlyChange ? ( { - skipCloseAutoFocusRef.current = checked === true - onShowSearchChange(checked === true) - }} + checked={unreadOnly} + onCheckedChange={(checked) => onUnreadOnlyChange(checked === true)} + onSelect={(event) => event.preventDefault()} > - -
- {translate( - 'auto.components.activity.ActivityPrototypePage.showSearch', - 'Show search' - )} - - {showSearch ? : null} + {translate( + 'auto.components.activity.ActivityPrototypePage.showUnreadOnly', + 'Show unread only' + )} ) : null} - {onToggleUnread ? ( - - - onToggleUnread()} - onSelect={(event) => event.preventDefault()} - > - - - {translate( - 'auto.components.activity.ActivityPrototypePage.showUnreadOnly', - 'Show unread only' - )} - - {unreadOnly ? : null} - - - - {translate( - 'auto.components.activity.ActivityPrototypePage.unreadOnlyDescription', - 'Filters the activity list to show only threads with unread updates.' - )} - - + {onShowChildAgentsChange ? ( + onShowChildAgentsChange(checked === true)} + onSelect={(event) => event.preventDefault()} + > + {translate( + 'auto.components.activity.ActivityPrototypePage.showChildAgents', + 'Show child agents' + )} + ) : null} + ) : null} - + + {translate('auto.components.activity.ActivityPrototypePage.viewSection', 'View')} + {groupBy && onGroupByChange ? ( - - + {translate( 'auto.components.activity.ActivityPrototypePage.770d458144', 'Group by' )} - + {getActivityGroupByLabel(groupBy)} @@ -207,73 +195,36 @@ export function ActivityThreadOptionsMenu({ value={groupBy} onValueChange={(value) => onGroupByChange(value as ActivityGroupBy)} > - {[ - ['none', 'None', 'auto.components.activity.ActivityPrototypePage.none'], - ['status', 'Status', 'auto.components.activity.ActivityPrototypePage.4a3986b200'], - [ - 'project', - 'Project', - 'auto.components.activity.ActivityPrototypePage.8c3b621ddf' - ], - [ - 'worktree', - 'Worktree', - 'auto.components.activity.ActivityPrototypePage.b29191b3e0' - ], - ['agent', 'Agent', 'auto.components.activity.ActivityPrototypePage.f6396e1f85'] - ].map(([value, label, key]) => ( + {GROUP_BY_OPTIONS.map((value) => ( event.preventDefault()} > - {translate(key, label)} + {getActivityGroupByLabel(value)} ))} ) : null} - - - onCompactModeChange(checked === true)} - onSelect={(event) => event.preventDefault()} - > - - - {translate( - 'auto.components.activity.ActivityPrototypePage.f70e4bec47', - 'Compact mode' - )} - - {compactMode ? : null} - - - - {translate( - 'auto.components.activity.ActivityPrototypePage.compactModeDescription', - 'Shows shorter thread rows with one-line titles and two-line status messages.' - )} - - - {onShowChildAgentsChange ? ( + onCompactModeChange(checked === true)} + onSelect={(event) => event.preventDefault()} + > + {translate('auto.components.activity.ActivityPrototypePage.f70e4bec47', 'Compact mode')} + + {onShowSearchChange ? ( onShowChildAgentsChange(checked === true)} - onSelect={(event) => event.preventDefault()} + checked={showSearch} + onCheckedChange={(checked) => { + const show = checked === true + skipCloseAutoFocusRef.current = show + onShowSearchChange(show) + }} > - - - {translate( - 'auto.components.activity.ActivityPrototypePage.showChildAgents', - 'Show child agents' - )} - - {showChildAgents ? : null} + {translate('auto.components.activity.ActivityPrototypePage.showSearch', 'Show search')} ) : null} {onMarkAllThreadsRead || onClearCompleted ? ( diff --git a/src/renderer/src/components/browser-pane/assemble-chrome/BrowserPaneOverlayLayer.tsx b/src/renderer/src/components/browser-pane/assemble-chrome/BrowserPaneOverlayLayer.tsx index 3aee63c0af7..b15c8420ff0 100644 --- a/src/renderer/src/components/browser-pane/assemble-chrome/BrowserPaneOverlayLayer.tsx +++ b/src/renderer/src/components/browser-pane/assemble-chrome/BrowserPaneOverlayLayer.tsx @@ -15,6 +15,7 @@ import { useClientHostedBrowserRows } from '@/lib/pane-manager/client-hosted-browser-row-state' import { ClientHostedBrowserHostRowPane } from '../client-hosted-browser-host-row-pane' +import { useAnyBrowserPageMountAdmission } from '../host-guest/browser-page-mount-admission' // Why: Electron destroys its guest on DOM reparent, so BrowserPanes render at worktree level and moving a tab between groups only swaps the overlay's CSS position-anchor. @@ -60,7 +61,8 @@ const BrowserOverlaySlot = memo(function BrowserOverlaySlot({ ? browserTab.pageIds : [browserTab.activePageId ?? browserTab.id] const needsGuestPaint = useBrowserGuestPaintRetention(browserPageIds) - const isPaintable = isActive || needsGuestPaint + const isMountAdmitted = useAnyBrowserPageMountAdmission(browserPageIds) + const isPaintable = isActive || needsGuestPaint || isMountAdmitted // Why: CSS anchor positioning pins the overlay to its owning group's body — a tab move only swaps positionAnchor, no measurement/state. // Orphan branch (no anchorName) stays display:none until the tab is reassigned or destroyed. const style: React.CSSProperties = useMemo( diff --git a/src/renderer/src/components/browser-pane/assemble-chrome/browser-workspace-pane.tsx b/src/renderer/src/components/browser-pane/assemble-chrome/browser-workspace-pane.tsx index b50a6aa1692..e473f442a90 100644 --- a/src/renderer/src/components/browser-pane/assemble-chrome/browser-workspace-pane.tsx +++ b/src/renderer/src/components/browser-pane/assemble-chrome/browser-workspace-pane.tsx @@ -22,6 +22,10 @@ import { WorkspaceDocPagePane } from '../workspace-doc/workspace-doc-page-pane' import { DeferredBrowserContent } from './DeferredBrowserContent' import { isBrowserPagePanePaintable } from '../host-guest/browser-page-paintability' import { SshRoutedBrowserPageGate } from './ssh-routed-browser-page-gate' +import { + isBrowserPageMountAdmitted, + useAnyBrowserPageMountAdmission +} from '../host-guest/browser-page-mount-admission' export default function BrowserPane({ browserTab, @@ -71,6 +75,7 @@ export default function BrowserPane({ () => localBrowserPages.map((page) => page.id), [localBrowserPages] ) + const hasAdmittedPage = useAnyBrowserPageMountAdmission(localBrowserPageIds) const pageDriver = useBrowserDriverForPage(activeBrowserPageId) // Why: a runtime-backed page is streamed, never locally driven, so its driver must read idle. const activeBrowserDriver = runtimeEnvironmentActive ? IDLE_BROWSER_DRIVER : pageDriver @@ -166,7 +171,9 @@ export default function BrowserPane({ key={page.id} retainMounted={isWorktreeActive} mountEligible={isBrowserPagePanePaintable({ - isActive: isActive && page.id === activeBrowserPageId, + isActive: + (isActive && page.id === activeBrowserPageId) || + (hasAdmittedPage && isBrowserPageMountAdmitted(page.id)), isAutomationVisible: automationVisiblePageIds.has(page.id), isMobileDriven: mobileDrivenPageIds.has(page.id), hasRemoteViewer: remotelyViewedPageIds.has(page.id) diff --git a/src/renderer/src/components/browser-pane/host-guest/browser-page-mount-admission.ts b/src/renderer/src/components/browser-pane/host-guest/browser-page-mount-admission.ts new file mode 100644 index 00000000000..3c2b1c8a706 --- /dev/null +++ b/src/renderer/src/components/browser-pane/host-guest/browser-page-mount-admission.ts @@ -0,0 +1,63 @@ +import { useSyncExternalStore } from 'react' + +// Newly requested pages must start a guest even when opened in the background. Restored pages are +// deliberately absent so worktree restoration can remain lazy. +const admittedPageIds = new Set() +const listeners = new Set<() => void>() +let version = 0 + +export function isBrowserPageMountAdmitted(pageId: string): boolean { + return admittedPageIds.has(pageId) +} + +function emit(): void { + version += 1 + for (const listener of listeners) { + listener() + } +} + +export function admitBrowserPageMount(pageId: string): void { + if (admittedPageIds.has(pageId)) { + return + } + admittedPageIds.add(pageId) + emit() +} + +export function releaseBrowserPageMount(pageId: string): void { + if (!admittedPageIds.delete(pageId)) { + return + } + emit() +} + +export function useBrowserPageMountAdmission(pageId: string): boolean { + useSyncExternalStore( + (listener) => { + listeners.add(listener) + return () => listeners.delete(listener) + }, + () => { + void version + return isBrowserPageMountAdmitted(pageId) + }, + () => false + ) + return isBrowserPageMountAdmitted(pageId) +} + +export function useAnyBrowserPageMountAdmission(pageIds: readonly string[]): boolean { + useSyncExternalStore( + (listener) => { + listeners.add(listener) + return () => listeners.delete(listener) + }, + () => { + void version + return pageIds.some(isBrowserPageMountAdmitted) + }, + () => false + ) + return pageIds.some(isBrowserPageMountAdmitted) +} diff --git a/src/renderer/src/components/dashboard-popout/preview-terminal-options.test.ts b/src/renderer/src/components/dashboard-popout/preview-terminal-options.test.ts index 319ec241293..2ad4147d235 100644 --- a/src/renderer/src/components/dashboard-popout/preview-terminal-options.test.ts +++ b/src/renderer/src/components/dashboard-popout/preview-terminal-options.test.ts @@ -58,6 +58,43 @@ describe('buildPreviewTerminalOptions', () => { scrollback: 1000 } + // #10754: the dashboard preview renders the agent's live buffer, so it has to reproduce the same + // contrast floor the pane used or a Powerline statusline looks different in the popout. + it('mirrors the automatic contrast floor when no override is set', () => { + expect( + buildPreviewTerminalOptions({ + ...base, + terminalInput: null, + theme: { background: '#1e242a' } + }).minimumContrastRatio + ).toBe(3) + expect( + buildPreviewTerminalOptions({ + ...base, + terminalInput: null, + theme: { background: '#ffffff' }, + themeMode: 'light' + }).minimumContrastRatio + ).toBe(4.5) + }) + + it('honors the user contrast override, clamped to xterm range', () => { + expect( + buildPreviewTerminalOptions({ + ...base, + terminalInput: null, + settings: { ...SETTINGS, terminalMinimumContrastRatio: 1 } + }).minimumContrastRatio + ).toBe(1) + expect( + buildPreviewTerminalOptions({ + ...base, + terminalInput: null, + settings: { ...SETTINGS, terminalMinimumContrastRatio: 0 } + }).minimumContrastRatio + ).toBe(1) + }) + it('keeps the kitty advertisement and skips ConPTY options off Windows', () => { const options = buildPreviewTerminalOptions({ ...base, diff --git a/src/renderer/src/components/dashboard-popout/preview-terminal-options.ts b/src/renderer/src/components/dashboard-popout/preview-terminal-options.ts index 284f6510558..14fe851a657 100644 --- a/src/renderer/src/components/dashboard-popout/preview-terminal-options.ts +++ b/src/renderer/src/components/dashboard-popout/preview-terminal-options.ts @@ -80,7 +80,8 @@ export function buildPreviewTerminalOptions(args: { theme: args.theme ?? undefined, minimumContrastRatio: resolveTerminalMinimumContrastRatio( args.theme?.background, - args.themeMode + args.themeMode, + args.settings?.terminalMinimumContrastRatio ) } } diff --git a/src/renderer/src/components/hover-reveal-touch-action-visibility.test.ts b/src/renderer/src/components/hover-reveal-touch-action-visibility.test.ts index 30c7d53b17b..d47c278582a 100644 --- a/src/renderer/src/components/hover-reveal-touch-action-visibility.test.ts +++ b/src/renderer/src/components/hover-reveal-touch-action-visibility.test.ts @@ -17,6 +17,7 @@ const HOVER_REVEAL_FILES = [ resolve(__dirname, 'editor/DiffSectionHeader.tsx'), resolve(__dirname, 'github-project/ProjectPicker.tsx'), resolve(__dirname, 'github-project/ProjectRow.tsx'), + resolve(__dirname, 'native-chat/NativeChatMessageRow.tsx'), resolve(__dirname, 'right-sidebar/AiVaultSessionRow.tsx'), resolve(__dirname, 'right-sidebar/ChecksPanel.tsx'), resolve(__dirname, 'right-sidebar/local-port-row.tsx'), diff --git a/src/renderer/src/components/native-chat/NativeChatComposer.tsx b/src/renderer/src/components/native-chat/NativeChatComposer.tsx index 79ca7cbd851..4833f89fc94 100644 --- a/src/renderer/src/components/native-chat/NativeChatComposer.tsx +++ b/src/renderer/src/components/native-chat/NativeChatComposer.tsx @@ -1,3 +1,4 @@ +import type { NativeChatComposerInput } from './native-chat-composer-input' import { forwardRef, useCallback, useImperativeHandle, useState } from 'react' import { useAppStore } from '../../store' import { sendRuntimePtyInput } from '@/runtime/runtime-terminal-inspection' @@ -147,7 +148,7 @@ const NativeChatComposerPane = forwardRef { + const syncCaret = useCallback((el: NativeChatComposerInput) => { setCaret(el.selectionStart ?? el.value.length) }, []) @@ -353,7 +354,7 @@ const NativeChatComposerPane = forwardRef { + (value: string, element: NativeChatComposerInput) => { setDraft(value) setHistory((prev) => ({ entries: prev.entries, index: null })) syncCaret(element) diff --git a/src/renderer/src/components/native-chat/NativeChatComposerField.tsx b/src/renderer/src/components/native-chat/NativeChatComposerField.tsx index 25fff0267be..6b474a2f267 100644 --- a/src/renderer/src/components/native-chat/NativeChatComposerField.tsx +++ b/src/renderer/src/components/native-chat/NativeChatComposerField.tsx @@ -1,3 +1,5 @@ +import { NativeChatPromptEditor } from './NativeChatPromptEditor' +import type { NativeChatComposerInput } from './native-chat-composer-input' import type { ClipboardEventHandler, KeyboardEventHandler, RefObject } from 'react' import { useLayoutEffect, useRef } from 'react' import { ImageOff } from 'lucide-react' @@ -19,7 +21,7 @@ export type NativeChatComposerFieldProps = { /** Pane identity published to the drop pipeline so a native file drop lands * only in the composer it was dropped on. */ composerScopeKey: string - textareaRef: RefObject + textareaRef: RefObject draft: string disabled: boolean hasPty: boolean @@ -35,11 +37,11 @@ export type NativeChatComposerFieldProps = { isDictating: boolean isDictationHoldMode: boolean imeEnterGesture: ReturnType - onDraftChange: (value: string, element: HTMLTextAreaElement) => void - onTextareaSelect: (element: HTMLTextAreaElement) => void - onKeyDown: KeyboardEventHandler - onImeSettled: (element: HTMLTextAreaElement) => void - onPaste: ClipboardEventHandler + onDraftChange: (value: string, element: NativeChatComposerInput) => void + onTextareaSelect: (element: NativeChatComposerInput) => void + onKeyDown: KeyboardEventHandler + onImeSettled: (element: NativeChatComposerInput) => void + onPaste: ClipboardEventHandler pickerListboxId: string onChoosePickerItem: (item: NativeChatPickerItem) => void onRetrySkills: () => void @@ -151,7 +153,7 @@ export function NativeChatComposerField({ textarea.value = draft }, [draft, imeEnterGesture, textareaRef]) - const settleImeValue = (element: HTMLTextAreaElement): void => { + const settleImeValue = (element: NativeChatComposerInput): void => { if (droppedDraftClearRef.current) { droppedDraftClearRef.current = false element.value = imeComposedSegment(compositionBaseRef.current, element.value) @@ -204,38 +206,39 @@ export function NativeChatComposerField({ ))} ) : null} -