diff --git a/.github/workflows/release-cut.yml b/.github/workflows/release-cut.yml
index 01cc16c6bda..71f9e8ca03f 100644
--- a/.github/workflows/release-cut.yml
+++ b/.github/workflows/release-cut.yml
@@ -1122,10 +1122,33 @@ jobs:
retention-days: 7
if-no-files-found: ignore
+ # Why: artifact jobs submit Windows binaries to SignPath. Keep every
+ # quota-consuming build behind all blocking release gates so a late test
+ # failure cannot create signing requests that can never be published.
+ release-preflight:
+ needs:
+ - cut
+ - terminal-rendering-golden
+ - skill-sharing-release-gate
+ - skill-sharing-linux-floor-release-gate
+ if: >-
+ always() &&
+ needs.cut.outputs.should_release == 'true' &&
+ needs.terminal-rendering-golden.result == 'success' &&
+ needs.skill-sharing-release-gate.result == 'success' &&
+ needs.skill-sharing-linux-floor-release-gate.result == 'success'
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+ steps:
+ - name: Confirm blocking release gates passed
+ run: echo "All blocking release gates passed; artifact builds may start."
+
build:
needs:
- cut
- create-release
+ - release-preflight
if: needs.cut.outputs.should_release == 'true'
strategy:
fail-fast: false
@@ -2026,6 +2049,7 @@ jobs:
needs:
- cut
- create-release
+ - release-preflight
if: needs.cut.outputs.should_release == 'true'
# Why: SignPath requires every job in this signing workflow to be
# GitHub-hosted. The actual mac build runs in release-mac-build.yml so
diff --git a/AGENTS.md b/AGENTS.md
index 1fbce202438..9817cc41cc8 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -76,6 +76,12 @@ When adding or changing a Git command:
- Keep the real-binary compatibility contract in PR CI current. When adopting a newer Git feature, add its version boundary so the preferred command and fallback both run against representative Git releases.
- Preserve commands that begin with global Git options such as `-c` before the subcommand, including auto-maintenance suppression used by worktree-create fetches.
+## Git Scan Safety
+
+- Never enumerate every ref and then run `git ls-tree -r` or `git show` once per ref. That ref × tree fan-out can retain gigabytes of output before a downstream `sort -u` or search can make progress.
+- Prefer `rg` over the checked-out files for source searches. For history or refs, use a named ref, an explicit namespace/path, `--max-count`, and a bounded output; do not use an unqualified `--all` scan as a first diagnostic.
+- Keep repository-wide commands targeted to the current repository and worktree. If an unbounded scan is genuinely required, measure the ref count first, explain the cost, and get confirmation before running it.
+
## Git Provider Compatibility
Source-control and review changes must consider GitLab and other supported git providers, not only GitHub. Keep provider-specific behavior behind explicit checks, and avoid GitHub-only naming for generic review concepts.
diff --git a/README.md b/README.md
index 82dfdbaa5c9..dfb676bcef5 100644
--- a/README.md
+++ b/README.md
@@ -36,7 +36,7 @@
Monitor and steer your agents from your phone — get notified when an agent finishes and send follow-ups from anywhere.
-[iOS App Store](https://apps.apple.com/us/app/orca-ide/id6766130217) · [TestFlight](https://testflight.apple.com/join/YjeGMQBA) · [Android APK 0.0.46](https://github.com/stablyai/orca/releases/download/mobile-android-v0.0.46/app-release.apk) · [Docs →](https://www.onorca.dev/docs/mobile)
+[iOS App Store](https://apps.apple.com/us/app/orca-ide/id6766130217) · [TestFlight](https://testflight.apple.com/join/YjeGMQBA) · [Android APK 0.0.47](https://github.com/stablyai/orca/releases/download/mobile-android-v0.0.47/app-release.apk) · [Docs →](https://www.onorca.dev/docs/mobile)
@@ -230,7 +230,7 @@ yay -S stably-orca-bin
Pair with your desktop app to monitor and steer your agents from your phone.
- **iOS:** [Download on the App Store](https://apps.apple.com/us/app/orca-ide/id6766130217) or [join TestFlight](https://testflight.apple.com/join/YjeGMQBA)
-- **Android:** [Download APK 0.0.46](https://github.com/stablyai/orca/releases/download/mobile-android-v0.0.46/app-release.apk) · [Install guide](https://www.onorca.dev/docs/android-apk)
+- **Android:** [Download APK 0.0.47](https://github.com/stablyai/orca/releases/download/mobile-android-v0.0.47/app-release.apk) · [Install guide](https://www.onorca.dev/docs/android-apk)
---
@@ -262,7 +262,6 @@ Want to contribute or run locally? See our [CONTRIBUTING.md](.github/CONTRIBUTIN
## Signed Builds
-
Windows code signing sponored/provided by [SignPath.io](https://signpath.io), certificate by [SignPath Foundation](https://signpath.org).
## License
diff --git a/config/reliability-gates.jsonc b/config/reliability-gates.jsonc
index ce075110603..9959618da51 100644
--- a/config/reliability-gates.jsonc
+++ b/config/reliability-gates.jsonc
@@ -1,6 +1,6 @@
{
"schemaVersion": 1,
- "updatedAt": "2026-08-23",
+ "updatedAt": "2026-08-31",
"policy": {
"maturityLevels": ["experimental", "soak", "blocking", "accepted-gap", "deprecated"],
"blockingPromotion": {
@@ -5722,6 +5722,284 @@
],
"demotionRule": "Keep experimental or demote if ownership cardinality flakes, duplicate replay reaches a second renderer, active metadata or authority moves to the wrong leaf, deep normalization regresses, or a supported provider bypasses normalization."
},
+ {
+ "id": "terminal-session.split-activation-ordering",
+ "title": "Terminal splits activate before inherited-CWD lookup settles",
+ "maturity": "experimental",
+ "protection": "partial",
+ "owner": "terminal-renderer-lifecycle",
+ "layer": "renderer-unit-and-local-transport",
+ "surfaces": [
+ "terminal pane split",
+ "inherited working directory",
+ "pre-connect terminal input",
+ "split close cleanup",
+ "pre-bind pane detach"
+ ],
+ "platforms": ["macos", "linux", "windows"],
+ "providers": ["local", "local-daemon", "ssh", "wsl", "remote-runtime"],
+ "coveredPlatforms": ["macos"],
+ "coveredProviders": ["local", "remote-runtime"],
+ "coverageNotes": "Deterministic renderer contracts hold CWD resolution behind an explicit promise, require the new pane to be created synchronously, and prove that close cancels the pending connection. A module-level stable-pane-key handoff preserves the exact CWD promise and bounded pre-connect input across whole-tab remounts, including a tab rehome between worktree buckets; stale owners are fenced, concrete PTY bind and definitive spawn failure clear the record, and explicit pane close discards it. Detach contracts reject cwd-pending and cwd-resolved deferred splits before PTY bind without mutation, carry resolved cwd for other unbound panes, and preserve persisted or live PTY handoff. Local IPC transport contracts exercise the real bounded pre-connect buffer and one live input FIFO across seeded and newly typed ordinary, acknowledged, and immediate writes, concurrent flushes, in-flight teardown, late spawn success or failure, attach failure, failed spawn, same-id reuse, stale-spawn retirement ownership, destroy, and mutable recovery metadata. The handoff registry is capped at 64 records for 15 seconds and shares the existing 1,024-entry/conservative UTF-16 input ceilings. A mocked direct-SSH authority-rotation contract proves a rejected stale spawn releases its deferred-CWD fence. The schema-v2 headful Electron benchmark records exact revision identity and attributes CWD request/settlement, PTY spawn request/result, bind, fixture unlock request/IPC write, fixture readiness, input, and first echo across 3 warmups and 20 measured cold-CWD cycles, requiring a distinct child PTY and observed child pty:exit before the next cycle. Remote-runtime coverage proves delegation remains host-owned; its host-delegated split path does not consume the local pre-connect input options, so remote-runtime input-remount replay and physical local-daemon, SSH, WSL, Linux, Windows, and folder-workspace latency journeys remain gaps.",
+ "motivatingLinks": ["https://github.com/stablyai/orca/commit/572ed1a8882"],
+ "invariant": "A terminal split creates and activates its renderer pane before an inherited-CWD lookup settles, starts its PTY only after the resolved directory is available, and cannot be externally detached while that deferred spawn remains unbound. A whole-tab remount or worktree rehome preserves the same stable pane's CWD promise and admitted local pre-connect bytes in order until a successor binds or the intent is definitively abandoned; stale owners cannot append or clear the successor's record. Other unbound panes preserve resolved cwd as startupCwd when detached. Bounded pre-connect input and later live local input share byte order, and teardown settles acknowledged writes without creating or rebinding a stale PTY. A disconnected or detached pending connect cannot bind its late fresh spawn, report its late failure through current callbacks, or ID-retire a newer same-ID owner; rejecting a stale direct-SSH spawn also releases the matching deferred-CWD fence. Natural exit cannot deliver queued work into a reused PTY id. Bound and remote-runtime splits remain owned by their execution host.",
+ "oracle": "Hold CWD resolution behind a controllable promise, invoke the production split path, and require manager.splitPane plus split telemetry before resolving it. Before PTY bind, require both cwd-pending and cwd-resolved deferred detach attempts to return null without layout, pane, tab, ownership, or focus mutation; separately require resolved cwd on an allowed unbound detach and unchanged persisted/live PTY adoption. Exercise the stable-pane handoff registry through repeated remounts and a worktree rehome, requiring the identical CWD promise, ordered ordinary/acknowledged/immediate seed replay, stale-owner fencing, 64-record/15-second bounds, and discard on bind, failure, or explicit close. Rotate a mocked direct-SSH authority while its delayed spawn is in flight, reject and disconnect the stale PTY claim, then require exactly one deferred-CWD cleanup when the delayed connect settles. At the local IPC PTY boundary, require zero connect calls while pending, the resolved CWD in spawn and local recovery metadata, one shared FIFO across seeded/new pre-connect and live ordinary/acknowledged/immediate input, prompt predecessor acknowledged-promise settlement on teardown, retirement of an unowned late fresh spawn, preservation of a newer same-ID owner, and zero stale delivery after failure, close, destroy, detach, natural exit, or same-id reuse. Capture callback exceptions must not change admission results. In visible Electron, press the real split shortcut for 3 warmup cycles, then after a cold inherited-CWD interval for each of 20 measured cycles, require an exact clean revision identity, complete focus/CWD/spawn/bind/fixture/input/echo attribution, distinct child PTYs, pane count, and child exits for every cycle; a timed-out, missing-event, or cleanup-aborted run must publish no headline latency and fail.",
+ "commands": [
+ "pnpm exec vitest run --config config/vitest.config.ts src/renderer/src/components/terminal-pane/terminal-pane-split-with-inherited-cwd.test.ts src/renderer/src/lib/pane-manager/pane-split-close.test.ts src/renderer/src/components/terminal-pane/resolve-split-cwd.test.ts src/renderer/src/components/terminal-pane/pty-connection-split-cwd-resolution.test.ts src/renderer/src/components/terminal-pane/terminal-pane-tab-detach.test.ts src/renderer/src/components/terminal-pane/pty-preconnect-input-buffer.test.ts src/renderer/src/components/terminal-pane/pty-transport-input-write.test.ts src/renderer/src/components/terminal-pane/deferred-split-pane-handoff.test.ts tests/e2e/terminal-split-activation-latency-artifact.unit.test.ts tests/e2e/terminal-split-activation-latency-main-probe.ts tests/e2e/terminal-split-activation-latency-phases.ts tests/e2e/terminal-split-activation-latency-report.unit.test.ts --reporter=dot",
+ // Historical evidence record retained so its seven-file command remains auditable.
+ "pnpm exec vitest run --config config/vitest.config.ts src/renderer/src/components/terminal-pane/terminal-pane-split-with-inherited-cwd.test.ts src/renderer/src/lib/pane-manager/pane-split-close.test.ts src/renderer/src/components/terminal-pane/resolve-split-cwd.test.ts src/renderer/src/components/terminal-pane/pty-connection-split-cwd-resolution.test.ts src/renderer/src/components/terminal-pane/terminal-pane-tab-detach.test.ts src/renderer/src/components/terminal-pane/pty-preconnect-input-buffer.test.ts src/renderer/src/components/terminal-pane/pty-transport-input-write.test.ts --reporter=dot",
+ // Historical evidence record retained so its nine-file command remains auditable.
+ "pnpm exec vitest run --config config/vitest.config.ts src/renderer/src/components/terminal-pane/terminal-pane-split-with-inherited-cwd.test.ts src/renderer/src/lib/pane-manager/pane-split-close.test.ts src/renderer/src/components/terminal-pane/resolve-split-cwd.test.ts src/renderer/src/components/terminal-pane/pty-connection-split-cwd-resolution.test.ts src/renderer/src/components/terminal-pane/terminal-pane-tab-detach.test.ts src/renderer/src/components/terminal-pane/pty-preconnect-input-buffer.test.ts src/renderer/src/components/terminal-pane/pty-transport-input-write.test.ts src/renderer/src/components/terminal-pane/deferred-split-pane-handoff.test.ts tests/e2e/terminal-split-activation-latency-artifact.unit.test.ts --reporter=dot",
+ // Historical schema-v1 evidence records only; their labels do not verify the checkout or harness.
+ "ORCA_TERMINAL_SPLIT_LATENCY_BENCH=1 ORCA_TERMINAL_SPLIT_LATENCY_LABEL=baseline-df14d1a2983d8339e788d0e521f1c4affd9c6d5f-headful-run1 ORCA_TERMINAL_SPLIT_LATENCY_OUTPUT=/private/tmp/orca-terminal-split-activation-baseline-df14d1a2983d8339e788d0e521f1c4affd9c6d5f-headful-run1.json pnpm exec playwright test tests/e2e/terminal-split-activation-latency.spec.ts --config tests/playwright.config.ts --project electron-headful --workers=1",
+ "ORCA_TERMINAL_SPLIT_LATENCY_BENCH=1 ORCA_TERMINAL_SPLIT_LATENCY_LABEL=candidate-d453ffcdb704764daced1b2917fddee7224389f0-headful-run2 ORCA_TERMINAL_SPLIT_LATENCY_OUTPUT=/private/tmp/orca-terminal-split-activation-candidate-d453ffcdb704764daced1b2917fddee7224389f0-headful-run2.json pnpm exec playwright test tests/e2e/terminal-split-activation-latency.spec.ts --config tests/playwright.config.ts --project electron-headful --workers=1",
+ // Exact-HEAD schema-v1 evidence records use the committed harness but predate revision metadata.
+ "ORCA_TERMINAL_SPLIT_LATENCY_BENCH=1 ORCA_TERMINAL_SPLIT_LATENCY_LABEL=candidate-962faacec8c-headful-current ORCA_TERMINAL_SPLIT_LATENCY_OUTPUT=/private/tmp/orca-terminal-split-activation-962faacec8c-headful.json pnpm exec playwright test tests/e2e/terminal-split-activation-latency.spec.ts --config tests/playwright.config.ts --project electron-headful --workers=1",
+ "ORCA_TERMINAL_SPLIT_LATENCY_BENCH=1 ORCA_TERMINAL_SPLIT_LATENCY_LABEL=candidate-962faacec8c-headful-run2 ORCA_TERMINAL_SPLIT_LATENCY_OUTPUT=/private/tmp/orca-terminal-split-activation-962faacec8c-headful-run2.json pnpm exec playwright test tests/e2e/terminal-split-activation-latency.spec.ts --config tests/playwright.config.ts --project electron-headful --workers=1",
+ // Schema-v2 evidence embeds the exact checkout identity and clean/dirty state.
+ "ORCA_TERMINAL_SPLIT_LATENCY_BENCH=1 ORCA_TERMINAL_SPLIT_LATENCY_LABEL=candidate-073e6c7b0eb-headful-clean ORCA_TERMINAL_SPLIT_LATENCY_OUTPUT=/private/tmp/orca-terminal-split-activation-073e6c7b0eb-headful-clean.json pnpm exec playwright test tests/e2e/terminal-split-activation-latency.spec.ts --config tests/playwright.config.ts --project electron-headful --workers=1"
+ ],
+ "testFiles": [
+ "src/renderer/src/components/terminal-pane/terminal-pane-split-with-inherited-cwd.test.ts",
+ "src/renderer/src/lib/pane-manager/pane-split-close.test.ts",
+ "src/renderer/src/components/terminal-pane/resolve-split-cwd.test.ts",
+ "src/renderer/src/components/terminal-pane/pty-connection-split-cwd-resolution.test.ts",
+ "src/renderer/src/components/terminal-pane/terminal-pane-tab-detach.test.ts",
+ "src/renderer/src/components/terminal-pane/pty-preconnect-input-buffer.test.ts",
+ "src/renderer/src/components/terminal-pane/pty-transport-input-write.test.ts",
+ "src/renderer/src/components/terminal-pane/deferred-split-pane-handoff.test.ts",
+ "tests/e2e/terminal-split-activation-latency-artifact.unit.test.ts",
+ "tests/e2e/terminal-split-activation-latency-main-probe.ts",
+ "tests/e2e/terminal-split-activation-latency-phases.ts",
+ "tests/e2e/terminal-split-activation-latency-report.unit.test.ts",
+ "tests/e2e/terminal-split-activation-latency.spec.ts"
+ ],
+ "assertionRefs": [
+ {
+ "file": "src/renderer/src/components/terminal-pane/terminal-pane-split-with-inherited-cwd.test.ts",
+ "assertions": [
+ "creates and records the split before pending CWD resolution",
+ "passes the resolved CWD promise without reviving a stale manager",
+ "rapid nested splits reuse one pending CWD lookup",
+ "keeps remote-runtime split ownership on its execution host"
+ ]
+ },
+ {
+ "file": "src/renderer/src/lib/pane-manager/pane-split-close.test.ts",
+ "assertions": ["focuses the new pane before publishing an unresolved CWD spawn hint"]
+ },
+ {
+ "file": "src/renderer/src/components/terminal-pane/resolve-split-cwd.test.ts",
+ "assertions": [
+ "preserves a deferred split fence when OSC 7 updates cwd",
+ "clears a settled deferred entry only for matching promise identity",
+ "keeps a newer deferred lookup when an older cleanup callback arrives"
+ ]
+ },
+ {
+ "file": "src/renderer/src/components/terminal-pane/pty-connection-split-cwd-resolution.test.ts",
+ "assertions": [
+ "starts no PTY connection before inherited CWD resolves",
+ "applies the resolved directory to transport options",
+ "disposing the split before resolution cancels the pending spawn",
+ "invokes deferred-CWD cleanup exactly once after an authority-rotated direct-SSH spawn is disconnected and its delayed connect settles"
+ ]
+ },
+ {
+ "file": "src/renderer/src/components/terminal-pane/terminal-pane-tab-detach.test.ts",
+ "assertions": [
+ "rejects a deferred split while inherited CWD is pending without mutation",
+ "continues rejecting after CWD resolves until PTY bind",
+ "carries resolved CWD as startupCwd for an allowed unbound detach",
+ "preserves persisted and live remote PTY detach handoff"
+ ]
+ },
+ {
+ "file": "src/renderer/src/components/terminal-pane/pty-preconnect-input-buffer.test.ts",
+ "assertions": [
+ "concurrent flush calls share one worker and preserve mixed input order",
+ "clear settles an in-flight acknowledged write before its late resolve or reject",
+ "in-flight acknowledged input remains charged to entry and code-unit caps"
+ ]
+ },
+ {
+ "file": "src/renderer/src/components/terminal-pane/pty-transport-input-write.test.ts",
+ "assertions": [
+ "ordinary, acknowledged, and immediate pre-connect input flushes in byte order",
+ "pending acknowledged input settles on connect, destroy, and spawn failure",
+ "disconnect, destroy, and natural exit cancel an in-flight acknowledged write without blocking connect",
+ "live acknowledged input blocks later ordinary and immediate writes at its invocation position",
+ "the preconnect-to-live transition preserves the same input FIFO",
+ "disconnect and detach retire a late fresh spawn and suppress late failures before they reach current callbacks",
+ "natural exit fences queued ordinary and acknowledged chunks across same-id reuse",
+ "buffered exit and attach failure clear retained input",
+ "ordinary and acknowledged write failures drop later input without leaving promises pending",
+ "entry and code-unit ceilings bound pre-connect input retention",
+ "local recovery metadata observes the resolved split CWD",
+ "a stale fresh-spawn completion cannot retire a newer same-ID owner"
+ ]
+ },
+ {
+ "file": "src/renderer/src/components/terminal-pane/deferred-split-pane-handoff.test.ts",
+ "assertions": [
+ "hands the same cwd promise and buffered input to a remounted leaf in order",
+ "keeps input across repeated remounts and fences stale owners",
+ "releases an unmounted owner without dropping its pending handoff",
+ "retains input within the shared preconnect entry and code-unit caps",
+ "evicts the oldest handoff when the record cap is reached",
+ "expires an abandoned handoff after the bounded remount window"
+ ]
+ },
+ {
+ "file": "tests/e2e/terminal-split-activation-latency-artifact.unit.test.ts",
+ "assertions": [
+ "writes a passing benchmark report to the requested artifact path",
+ "fails when the benchmark artifact path cannot be written"
+ ]
+ },
+ {
+ "file": "tests/e2e/terminal-split-activation-latency-main-probe.ts",
+ "assertions": [
+ "attributes CWD and PTY spawn request/settlement events to the source and child PTYs",
+ "captures the fixture unlock carriage return on both ordinary and acknowledged IPC channels",
+ "restores the intercepted IPC handlers and listener when the probe is disposed"
+ ]
+ },
+ {
+ "file": "tests/e2e/terminal-split-activation-latency-phases.ts",
+ "assertions": [
+ "merges main-process events by operation and PTY identity without cross-cycle attribution",
+ "requires every activation, fixture, input, echo, pane, PTY, and cleanup observation for success",
+ "reports each attributed phase distribution with non-negative cross-clock durations"
+ ]
+ },
+ {
+ "file": "tests/e2e/terminal-split-activation-latency-report.unit.test.ts",
+ "assertions": [
+ "attributes main-process phases to the matching source and child PTYs",
+ "embeds schema-v2 revision identity and summarizes the attributed phases",
+ "invalidates a sample when the actual fixture-unlock IPC write is missing"
+ ]
+ },
+ {
+ "file": "tests/e2e/terminal-split-activation-latency.spec.ts",
+ "assertions": [
+ "requires a visible BrowserWindow and visible document before sampling",
+ "records schema-v2 revision identity plus attributed CWD, spawn, bind, fixture-ready, input, and echo phases",
+ "records 3 warmups, then 20 measured real-shortcut cycles after cold inherited-CWD intervals",
+ "requires every split to focus, bind a PTY distinct from its source, and echo immediate input",
+ "observes each closed child PTY exit before starting the next cycle",
+ "publishes headline latency only for a fully successful 3-warmup/20-measured run"
+ ]
+ }
+ ],
+ "evidenceRuns": [
+ {
+ "date": "2026-08-30",
+ "runner": "local",
+ "platform": "macos",
+ "result": "passed",
+ "command": "pnpm exec vitest run --config config/vitest.config.ts src/renderer/src/components/terminal-pane/terminal-pane-split-with-inherited-cwd.test.ts src/renderer/src/lib/pane-manager/pane-split-close.test.ts src/renderer/src/components/terminal-pane/resolve-split-cwd.test.ts src/renderer/src/components/terminal-pane/pty-connection-split-cwd-resolution.test.ts src/renderer/src/components/terminal-pane/terminal-pane-tab-detach.test.ts src/renderer/src/components/terminal-pane/pty-preconnect-input-buffer.test.ts src/renderer/src/components/terminal-pane/pty-transport-input-write.test.ts --reporter=dot",
+ "durationSeconds": 56.59,
+ "summary": "Seven focused files and 78 tests passed. Vitest reported 49.92 seconds and the measured wall time was 56.59 seconds; coverage includes split creation and focus ordering, nested CWD lineage, promise-identity and SSH authority-rotation cleanup fencing, full pre-bind detach fencing, resolved-CWD detach handoff, close-cancellation, single-FIFO ordering, late-spawn retirement and error suppression, preservation of a newer same-ID owner, generation fencing, in-flight settlement across explicit teardown and natural exit, attach cleanup, bounded retention, and existing input-write contracts."
+ },
+ {
+ "date": "2026-08-31",
+ "runner": "local",
+ "platform": "macos",
+ "result": "passed",
+ "command": "pnpm exec vitest run --config config/vitest.config.ts src/renderer/src/components/terminal-pane/terminal-pane-split-with-inherited-cwd.test.ts src/renderer/src/lib/pane-manager/pane-split-close.test.ts src/renderer/src/components/terminal-pane/resolve-split-cwd.test.ts src/renderer/src/components/terminal-pane/pty-connection-split-cwd-resolution.test.ts src/renderer/src/components/terminal-pane/terminal-pane-tab-detach.test.ts src/renderer/src/components/terminal-pane/pty-preconnect-input-buffer.test.ts src/renderer/src/components/terminal-pane/pty-transport-input-write.test.ts src/renderer/src/components/terminal-pane/deferred-split-pane-handoff.test.ts tests/e2e/terminal-split-activation-latency-artifact.unit.test.ts --reporter=dot",
+ "durationSeconds": 44.43,
+ "summary": "Nine focused files and 96 tests passed. Vitest reported 37.78 seconds and measured wall time was 44.43 seconds; the run adds stable-pane CWD/input handoff, repeated-remount stale-owner fencing, bounded 64-record/15-second retention, seeded-input caps, ordered ordinary/acknowledged/immediate replay, predecessor acknowledged-promise settlement, capture-callback failure containment, and benchmark-artifact write-failure coverage to the existing split, detach, CWD, and local transport contracts."
+ },
+ {
+ "date": "2026-08-31",
+ "runner": "local",
+ "platform": "macos",
+ "result": "passed",
+ "command": "pnpm exec vitest run --config config/vitest.config.ts src/renderer/src/components/terminal-pane/terminal-pane-split-with-inherited-cwd.test.ts src/renderer/src/lib/pane-manager/pane-split-close.test.ts src/renderer/src/components/terminal-pane/resolve-split-cwd.test.ts src/renderer/src/components/terminal-pane/pty-connection-split-cwd-resolution.test.ts src/renderer/src/components/terminal-pane/terminal-pane-tab-detach.test.ts src/renderer/src/components/terminal-pane/pty-preconnect-input-buffer.test.ts src/renderer/src/components/terminal-pane/pty-transport-input-write.test.ts src/renderer/src/components/terminal-pane/deferred-split-pane-handoff.test.ts tests/e2e/terminal-split-activation-latency-artifact.unit.test.ts tests/e2e/terminal-split-activation-latency-main-probe.ts tests/e2e/terminal-split-activation-latency-phases.ts tests/e2e/terminal-split-activation-latency-report.unit.test.ts --reporter=dot",
+ "durationSeconds": 4.14,
+ "summary": "The updated twelve-path focused command passed 99 tests (10 runnable test files plus 2 benchmark support modules), including schema-v2 main-process phase attribution, report revision identity, fixture IPC-write validation, stable-pane handoff, ordered pre-connect/live input, cleanup, detach, failure, and same-ID ownership contracts."
+ },
+ {
+ "date": "2026-08-30",
+ "runner": "local",
+ "platform": "macos",
+ "result": "passed",
+ "command": "ORCA_TERMINAL_SPLIT_LATENCY_BENCH=1 ORCA_TERMINAL_SPLIT_LATENCY_LABEL=baseline-df14d1a2983d8339e788d0e521f1c4affd9c6d5f-headful-run1 ORCA_TERMINAL_SPLIT_LATENCY_OUTPUT=/private/tmp/orca-terminal-split-activation-baseline-df14d1a2983d8339e788d0e521f1c4affd9c6d5f-headful-run1.json pnpm exec playwright test tests/e2e/terminal-split-activation-latency.spec.ts --config tests/playwright.config.ts --project electron-headful --workers=1",
+ "durationSeconds": 72,
+ "summary": "At baseline df14d1a2983d8339e788d0e521f1c4affd9c6d5f, the visible BrowserWindow and document completed 3/3 warmups followed by 20/20 measured cold-CWD cycles with every event present, distinct child PTYs, and observed child exits. Shortcut-to-focus p50/p95/max was 65.7/88.7/102.6 ms, PTY bind was 122.8/154.0/159.7 ms, and first echo was 203.8/264.2/332.7 ms. Artifact SHA-256: 6d860cd0cd210f55f2349a197318248af488042117b20c08b6831160950c3277."
+ },
+ {
+ "date": "2026-08-30",
+ "runner": "local",
+ "platform": "macos",
+ "result": "passed",
+ "command": "ORCA_TERMINAL_SPLIT_LATENCY_BENCH=1 ORCA_TERMINAL_SPLIT_LATENCY_LABEL=candidate-d453ffcdb704764daced1b2917fddee7224389f0-headful-run2 ORCA_TERMINAL_SPLIT_LATENCY_OUTPUT=/private/tmp/orca-terminal-split-activation-candidate-d453ffcdb704764daced1b2917fddee7224389f0-headful-run2.json pnpm exec playwright test tests/e2e/terminal-split-activation-latency.spec.ts --config tests/playwright.config.ts --project electron-headful --workers=1",
+ "durationSeconds": 72,
+ "summary": "At candidate d453ffcdb704764daced1b2917fddee7224389f0, the visible BrowserWindow and document completed 3/3 warmups followed by 20/20 measured cold-CWD cycles with every event present, distinct child PTYs, and observed child exits. Shortcut-to-focus p50/p95/max was 12.8/14.4/16.5 ms, PTY bind was 177.0/316.1/333.3 ms, and first echo was 268.6/627.4/710.7 ms. Artifact SHA-256: 9aef7fa842c732eb74f0066a77b2a0336e8f956a06ca61387f9999d6e76213cc."
+ },
+ {
+ "date": "2026-08-31",
+ "runner": "local",
+ "platform": "macos",
+ "result": "passed",
+ "command": "ORCA_TERMINAL_SPLIT_LATENCY_BENCH=1 ORCA_TERMINAL_SPLIT_LATENCY_LABEL=candidate-962faacec8c-headful-current ORCA_TERMINAL_SPLIT_LATENCY_OUTPUT=/private/tmp/orca-terminal-split-activation-962faacec8c-headful.json pnpm exec playwright test tests/e2e/terminal-split-activation-latency.spec.ts --config tests/playwright.config.ts --project electron-headful --workers=1",
+ "durationSeconds": 72,
+ "summary": "At exact HEAD 962faacec8c, the visible BrowserWindow and document completed 3/3 warmups followed by 20/20 measured cold-CWD cycles with every event present, distinct child PTYs, and observed child exits. Shortcut-to-focus p50/p95/max was 12.6/13.7/13.7 ms, PTY bind was 140.5/399.1/464.1 ms, and first echo was 192.0/519.3/2343.1 ms. Artifact SHA-256: 875e9d37dc711472a81438e4bbdbc8cbc7aada8c961d14195c024d8da350b9e2."
+ },
+ {
+ "date": "2026-08-31",
+ "runner": "local",
+ "platform": "macos",
+ "result": "passed",
+ "command": "ORCA_TERMINAL_SPLIT_LATENCY_BENCH=1 ORCA_TERMINAL_SPLIT_LATENCY_LABEL=candidate-962faacec8c-headful-run2 ORCA_TERMINAL_SPLIT_LATENCY_OUTPUT=/private/tmp/orca-terminal-split-activation-962faacec8c-headful-run2.json pnpm exec playwright test tests/e2e/terminal-split-activation-latency.spec.ts --config tests/playwright.config.ts --project electron-headful --workers=1",
+ "durationSeconds": 72,
+ "summary": "At exact HEAD 962faacec8c, the visible BrowserWindow and document completed 3/3 warmups followed by 20/20 measured cold-CWD cycles with every event present, distinct child PTYs, and observed child exits. Shortcut-to-focus p50/p95/max was 12.8/14.0/14.3 ms, PTY bind was 236.5/654.0/687.3 ms, and first echo was 566.8/1191.5/1219.7 ms. Artifact SHA-256: 4f66b93e5c936ade05f880010f4ec027385d5c89893430169af91c7fdfbe1d06."
+ },
+ {
+ "date": "2026-08-31",
+ "runner": "local",
+ "platform": "macos",
+ "result": "passed",
+ "command": "ORCA_TERMINAL_SPLIT_LATENCY_BENCH=1 ORCA_TERMINAL_SPLIT_LATENCY_LABEL=candidate-073e6c7b0eb-headful-clean ORCA_TERMINAL_SPLIT_LATENCY_OUTPUT=/private/tmp/orca-terminal-split-activation-073e6c7b0eb-headful-clean.json pnpm exec playwright test tests/e2e/terminal-split-activation-latency.spec.ts --config tests/playwright.config.ts --project electron-headful --workers=1",
+ "durationSeconds": 87.6,
+ "summary": "At exact clean HEAD 073e6c7b0eb1c0ccbb115db1528b641901997c73, the schema-v2 artifact records dirty=false, a visible BrowserWindow/document, and 3/3 warmups plus 20/20 measured cycles with every missing-event counter at zero, distinct child PTYs, and observed child exits. Measured focus p50/p95/max was 12.0/13.6/14.7 ms; attributed CWD lookup was 40/97/103 ms, CWD-settle to spawn request 1/4/4 ms, spawn request to result 48/120/122 ms, and spawn result to bind 2.1/2.5/2.5 ms. Fixture unlock request to IPC write was 0.5/0.8/0.9 ms, IPC write to fixture-ready parse was 35.1/87.4/141.8 ms, and input to first echo was 1.3/3.5/3.9 ms. Total shortcut-to-bind was 113.5/161.3/162.7 ms and shortcut-to-first-echo was 158.5/240.7/291.2 ms. Artifact SHA-256: 1e7ff9e658b717056273d64ecdf662cc6b5776bb6dae1827ed213b7647e4a5fb."
+ }
+ ],
+ "evidenceProcedure": "Run the benchmark spec in a visible macOS Electron project from a clean primary worktree, complete 3 warmups followed by 20 measured cold-CWD cycles, require zero missing events and successful cleanup, save the schema-v2 JSON report, and record its SHA-256 plus embedded revision identity. The four older records are schema-v1 historical audit records whose labels do not verify the checkout or include phase attribution; the clean schema-v2 record is the current candidate evidence. A paired baseline/final rerun with one revision-verifying harness remains required before promotion or a readiness comparison claim.",
+ "runtimeBudget": {
+ "p95Seconds": 240,
+ "scope": "the full listed gate command set: one current twelve-path focused invocation (ten runnable test files plus two benchmark support modules), one historical nine-file unit invocation, one historical seven-file unit invocation, and five opt-in 3-warmup/20-measured visible Electron benchmark invocations (four schema-v1 historical records plus one clean schema-v2 record)"
+ },
+ "flakeHistory": {
+ "status": "not-started",
+ "evidence": "The focused promise-barrier, remount-handoff, benchmark-artifact, and schema-v2 attribution suite passes locally in 99 tests; the clean visible benchmark passes 3/3 warmups and 20/20 measured cycles with zero missing events. Its first attempt hit a transient warmup cleanup-dialog click timeout, then the exact command passed on retry without a launch, profile, or port workaround. Routed CI and soak history have not started. Historical benchmark labels do not verify the product checkout or embed revision identity."
+ },
+ "redGreenEvidence": {
+ "status": "partial",
+ "evidence": "Before the production seam landed, the split assertion failed with zero manager calls while CWD was pending, and the transport assertion rejected the first pre-connect input. Before the detach fence, a deferred split could be removed after CWD resolved but before PTY bind, dropping its pre-connect input. Before the single-flight hardening, the concurrent-flush oracle delivered ordinary input before the earlier acknowledged write and clear left the in-flight promise pending. Before stale-spawn ownership fencing, the combined deferred-connect and newer same-ID attach fixture called kill on the current PTY. An intentional one-line revert of deferred-CWD cleanup in the stale direct-SSH claim branch failed its focused callback assertion with zero calls instead of one; restoring it passed the prior focused tests. The remount-handoff, transport, artifact-write, and schema-v2 attribution regressions are green in the 99-test twelve-path run, but isolated intentional-revert evidence for each cleanup branch remains outstanding."
+ },
+ "performanceBudget": {
+ "required": true,
+ "evidence": "Pane creation and focus add no timer, polling, provider inventory, or subprocess work. CWD resolution remains one existing bounded request off the visible activation path, and detach admission adds only bounded map and record lookups. The remount handoff adds one module-level map lookup per pane lifecycle, a 64-record cap, and a 15-second expiry; it retains no unbounded payload. Pre-connect input, including an in-flight acknowledged write and remount seed replay, is capped at 1,024 entries and a conservative UTF-16 ceiling derived from the existing terminal-input byte limit, drains through one worker in order, and clears on teardown or failed connect. The historical schema-v1 same-mode pair recorded shortcut-to-focus p50/p95/max changing from 65.7/88.7/102.6 ms to 12.8/14.4/16.5 ms; those labels do not embed revision identity, so the comparison is directional evidence only. The clean schema-v2 candidate attributes focus at 12.0/13.6/14.7 ms while CWD lookup takes 40/97/103 ms and spawn request-to-result takes 48/120/122 ms, demonstrating that provider/process startup follows activation rather than blocking it. In that clean run, shortcut-to-bind is 113.5/161.3/162.7 ms, fixture IPC-write-to-ready is 35.1/87.4/141.8 ms, and input-to-echo is 1.3/3.5/3.9 ms; these readiness phases are diagnostic, one-host descriptive measurements, and no clean schema-v2 baseline exists to support a readiness improvement or regression claim. The n=20 empirical p95 values are descriptive, are not a distribution guarantee, and are not CI-enforced."
+ },
+ "promotionCriteria": [
+ "Record complete red/green evidence for close, remount/rehome handoff, mixed-input ordering, metadata, and failure cleanup.",
+ "Collect 100 consecutive focused CI passes or 14 days without an unexplained flake.",
+ "Run the committed real-shortcut Electron benchmark in routed CI or soak before enforcing a latency budget.",
+ "Collect physical local-daemon, SSH or WSL plus Linux, Windows, and folder-workspace evidence before claiming provider-complete coverage."
+ ],
+ "knownGaps": [
+ "The clean schema-v2 candidate run and the historical schema-v1 comparison records ran on one Apple-silicon macOS host with a synthetic POSIX echo shell and a git-backed workspace; their n=20 empirical p95 values are descriptive and not CI-enforced.",
+ "No physical local-daemon, SSH, WSL, Linux, Windows, or folder-workspace latency journey has run; the synthetic fixture is currently skipped on Windows because it requires a POSIX shell.",
+ "Remote-runtime split creation remains host-delegated and its transport does not consume the local pre-connect seed/capture options; CWD handoff is covered, but remote-runtime pre-connect input replay has no implementation or evidence.",
+ "The four stored schema-v1 artifacts predate the final harness attribution/reporting and do not embed revision identity; the clean schema-v2 candidate artifact is revision-verified, but both product revisions still need a paired schema-v2 rerun with one committed harness before promotion.",
+ "No forced-failure visible benchmark artifact has been recorded; the focused artifact-write and missing-event report contracts verify local failure handling, while failure-report serialization remains unverified by a full visible run.",
+ "No clean schema-v2 baseline phase artifact exists, so the attributed CWD, spawn, fixture-ready, bind, and echo timings diagnose where time is spent but do not establish a shell-readiness improvement or regression."
+ ],
+ "demotionRule": "Keep experimental or demote if pane activation waits on CWD, a deferred split can detach before PTY bind, a remount or rehome loses its stable CWD/input handoff, stale owners mutate a successor record, detached cwd is lost, input reorders or remains pending after cleanup, a closed pane can spawn, stale retirement kills a newer same-ID owner, remote-runtime delegation creates a competing local pane, or the focused suite flakes without an identified product or harness cause."
+ },
{
"id": "terminal-session.kill-all-surface-cleanup",
"title": "Kill all sessions removes only the confirmed terminal surfaces and current bindings",
@@ -8194,9 +8472,7 @@
"assertionRefs": [
{
"file": "tests/e2e/persisted-session-production-upgrade.spec.ts",
- "assertions": [
- "upgrades a legacy daemon session and keeps it stable after relaunch"
- ]
+ "assertions": ["upgrades a legacy daemon session and keeps it stable after relaunch"]
}
],
"evidenceRuns": [
@@ -13970,14 +14246,14 @@
"providers": ["local", "daemon", "ssh"],
"coveredPlatforms": ["macos"],
"coveredProviders": ["local", "ssh"],
- "coverageNotes": "Deterministic renderer and IPC-transport tests prove count and text ceilings, oldest-reply shedding, explicit query-reply source routing, ordinary-input preservation, one-reply-per-write delivery for OSC, DA1, and CPR replies, real xterm OSC reply generation, drain-failure containment, and clear/reuse generation fencing. Remote-runtime tests preserve separate query-reply writes across pending input, async validation, and viewport-claim buffering. Host-contract tests prove a later DA1/CPR reply cannot overtake a deferred OSC reply, including a coalesced legacy-client payload. Live macOS Electron tests cover local PTY OSC replies and interactive typing; a macOS-hosted Docker OpenSSH test proves an upstream-node-pty Linux relay keeps OSC/DA1 replies out of the next fish child's stdin. No live daemon, paired-runtime, WSL, physical Linux/Windows client, or binary mixed-version run is registered.",
+ "coverageNotes": "Deterministic renderer and IPC-transport tests prove count and text ceilings, oldest-reply shedding, explicit query-reply source routing, ordinary-input preservation, acknowledged-write FIFO barriers, single-worker drain reentrancy, one-reply-per-write delivery for OSC, DA1, and CPR replies, real xterm OSC reply generation, drain-failure containment, teardown settlement, and clear/reuse generation fencing. Remote-runtime tests preserve separate query-reply writes across pending input, async validation, and viewport-claim buffering. Host-contract tests prove a later DA1/CPR reply cannot overtake a deferred OSC reply, including a coalesced legacy-client payload. Live macOS Electron tests cover local PTY OSC replies and interactive typing; a macOS-hosted Docker OpenSSH test proves an upstream-node-pty Linux relay keeps OSC/DA1 replies out of the next fish child's stdin. No live daemon, paired-runtime, WSL, physical Linux/Windows client, or binary mixed-version run is registered.",
"motivatingLinks": [
"https://github.com/stablyai/orca/issues/13137",
"https://github.com/stablyai/orca/issues/7329",
"https://github.com/stablyai/orca/issues/13892"
],
- "invariant": "The desktop PTY input queue retains at most 64 explicitly sourced pending terminal query replies and 4096 UTF-16 code units. Every retained reply reaches the provider as one atomic write, and the host writes each reply the moment it accepts it, so replies reach the PTY in the order they were produced with no queue that could reorder them. A reply's own echo is contained on the output side by projecting its known echo shapes; the ESC-initial verbatim shape is matched only when complete, never held as a partial, so a query torn at its own ESC is still answered. Overflow removes only the oldest query replies, never ordinary input except the documented modified-F3/CPR byte collision, and drain failures cannot clear a newer queue generation.",
- "oracle": "Synchronously enqueue separate 10,000-entry OSC and DA1 reply floods before the scheduled drain and assert that only the initial immediate reply and newest 64 pending replies are written, each as one provider write, before a trailing keystroke. At the host boundary, defer an OSC reply and assert that separate or legacy-coalesced DA1/CPR replies flush after it in observed query order. At the remote-runtime boundary, preserve separate writes around pending ordinary input, async validation, and viewport-claim buffering. Repeat behind 10,000 ordinary inputs and exercise the text ceiling, real xterm generation, provider-write failure, rejected yield, and clear/reuse generation fencing.",
+ "invariant": "The desktop PTY input queue retains at most 64 explicitly sourced pending terminal query replies and 4096 UTF-16 code units. Every retained reply reaches the provider as one atomic write, and ordinary, acknowledged, and reply input share one invocation-ordered FIFO so no later write overtakes an acknowledged write. Reentrant write callbacks cannot start a second drain worker or strand input admitted after clear/reuse. A reply's own echo is contained on the output side by projecting its known echo shapes; the ESC-initial verbatim shape is matched only when complete, never held as a partial, so a query torn at its own ESC is still answered. Overflow removes only the oldest query replies, never ordinary input except the documented modified-F3/CPR byte collision, and failure or teardown cannot clear a newer queue generation or strand an acknowledged promise.",
+ "oracle": "Synchronously enqueue separate 10,000-entry OSC and DA1 reply floods before the scheduled drain and assert that only the initial immediate reply and newest 64 pending replies are written, each as one provider write, before a trailing keystroke. Stall an acknowledged write between earlier and later ordinary/reply input, then require teardown to settle it and same-id reuse to receive no stale tail. Reenter the queue synchronously from an acknowledged write with both enqueue and clear/reuse, requiring one drain and fresh input delivery only after the stale acknowledged write settles false. At the host boundary, defer an OSC reply and assert that separate or legacy-coalesced DA1/CPR replies flush after it in observed query order. At the remote-runtime boundary, preserve separate writes around pending ordinary input, async validation, and viewport-claim buffering. Repeat behind 10,000 ordinary inputs and exercise the text ceiling, real xterm generation, provider-write failure, rejected yield, and clear/reuse generation fencing.",
"commands": [
"pnpm exec vitest run --config config/vitest.config.ts src/renderer/src/components/terminal-pane/pty-input-write-queue.test.ts src/renderer/src/components/terminal-pane/pty-transport-input-write.test.ts src/shared/terminal-query-reply.test.ts src/shared/pty-startup-ingress-live-query-reply.test.ts src/shared/pty-startup-reply-echo-shapes.test.ts",
"pnpm exec vitest run --config config/vitest.config.ts src/renderer/src/components/terminal-pane/remote-runtime-pty-batching.test.ts src/renderer/src/components/terminal-pane/remote-runtime-pty-query-reply-immediate.test.ts src/renderer/src/components/terminal-pane/remote-runtime-pty-transport-input-coalescing.test.ts",
@@ -14009,14 +14285,20 @@
"real xterm OSC 10/11 query handlers remain subject to the same retention ceiling",
"retained OSC, DA1, and CPR replies stay one provider write each and both OSC and DA1 floods remain bounded",
"provider-write and yield failures settle without unhandled rejection, repeated same-generation admission, or stale-generation clearing",
- "clear releases saturated reply accounting and fences in-flight validation before later input"
+ "clear releases saturated reply accounting and fences in-flight validation before later input",
+ "acknowledged input is serialized between earlier and later ordinary/reply writes",
+ "clear settles active and pending acknowledged input before same-id queue reuse",
+ "reentrant enqueue cannot start a second drain worker past an unacknowledged write",
+ "reentrant clear captures the stale cancellation and continues draining fresh input"
]
},
{
"file": "src/renderer/src/components/terminal-pane/pty-transport-input-write.test.ts",
"assertions": [
"sendInputImmediate applies the reply ceiling while sendInput preserves a reply-shaped ordinary payload in exact IPC write order",
- "a thrown renderer write triggers one owning-transport recovery callback and rejects later input in that queue generation"
+ "a thrown renderer write triggers one owning-transport recovery callback and rejects later input in that queue generation",
+ "live and preconnect acknowledged writes remain FIFO barriers for later ordinary and immediate input",
+ "disconnect, detach, and natural exit settle acknowledged writes and fence same-id stale chunks"
]
},
{
@@ -14072,13 +14354,13 @@
],
"evidenceRuns": [
{
- "date": "2026-08-25",
+ "date": "2026-08-30",
"runner": "local",
"platform": "macos",
"command": "pnpm exec vitest run --config config/vitest.config.ts src/renderer/src/components/terminal-pane/pty-input-write-queue.test.ts src/renderer/src/components/terminal-pane/pty-transport-input-write.test.ts src/shared/terminal-query-reply.test.ts src/shared/pty-startup-ingress-live-query-reply.test.ts src/shared/pty-startup-reply-echo-shapes.test.ts",
"result": "passed",
- "durationSeconds": 1.05,
- "summary": "Five files and 92 tests passed, including the live-pty echo-shape transcript, including explicit IPC reply-source routing, the 10,000-reply count ceiling, text ceiling, 10,000-entry ordinary backlog preservation, real xterm OSC query flood, single-shot drain-failure recovery, one-reply-per-write echo containment, and clear/reuse generation fencing."
+ "durationSeconds": 15,
+ "summary": "Five files and 149 tests passed in 15.16 seconds, including explicit IPC reply-source routing, the 10,000-reply count and text ceilings, 10,000-entry ordinary backlog preservation, acknowledged-write FIFO barriers, synchronous reentrancy fencing, prompt teardown settlement, same-id generation fencing, real xterm OSC query floods, single-shot drain-failure recovery, and one-reply-per-write echo containment."
},
{
"date": "2026-08-09",
@@ -14127,7 +14409,7 @@
},
"redGreenEvidence": {
"status": "partial",
- "evidence": "Without the branch's admission cap, the 10,000-reply fixture writes all replies before the trailing keystroke. Before the source-routing repair, the queue had no API capable of distinguishing reply-shaped ordinary input; before failure containment, a thrown provider write rejected waitForDrain and Vitest recorded an unhandled rejection; the first containment pass retried a failed generation and invoked recovery twice; before generation fencing, a rejected stale yield cleared fresh input. No saved intentional-break artifact is attached yet."
+ "evidence": "Without the branch's admission cap, the 10,000-reply fixture writes all replies before the trailing keystroke. Before the source-routing repair, the queue had no API capable of distinguishing reply-shaped ordinary input; before failure containment, a thrown provider write rejected waitForDrain and Vitest recorded an unhandled rejection; the first containment pass retried a failed generation and invoked recovery twice; before generation fencing, a rejected stale yield cleared fresh input. Before reentrancy fencing, a synchronous accepted-write callback started a second drain that falsely accepted the pending write; clear/reuse also captured the replacement generation's cancellation and stranded fresh input. No saved intentional-break artifact is attached yet."
},
"performanceBudget": {
"required": true,
diff --git a/config/scripts/benchmark-artifact-comparison.test.mjs b/config/scripts/benchmark-artifact-comparison.test.mjs
index d7700deda04..f8777a13b57 100644
--- a/config/scripts/benchmark-artifact-comparison.test.mjs
+++ b/config/scripts/benchmark-artifact-comparison.test.mjs
@@ -95,6 +95,66 @@ describe('benchmark artifact comparison', () => {
})
})
+ it('compares terminal split headline metrics in milliseconds', () => {
+ const dir = makeTempDir()
+ const baselinePath = writeArtifact(dir, 'split-baseline.json', {
+ label: 'split baseline',
+ headlineMs: {
+ shortcutToFocusP50: 284.2,
+ shortcutToFocusP95: 676.3
+ }
+ })
+ const candidatePath = writeArtifact(dir, 'split-candidate.json', {
+ label: 'split candidate',
+ headlineMs: {
+ shortcutToFocusP50: 12.7,
+ shortcutToFocusP95: 13.7
+ }
+ })
+
+ const comparison = comparePaths(baselinePath, candidatePath)
+
+ expect(comparison.baseline.kind).toBe('terminal-split-activation')
+ expect(comparison.metrics).toEqual(
+ expect.arrayContaining([
+ expect.objectContaining({
+ key: 'shortcutToFocusP50',
+ unit: 'ms',
+ baseline: 284.2,
+ candidate: 12.7,
+ status: 'improved'
+ }),
+ expect.objectContaining({
+ key: 'shortcutToFocusP95',
+ unit: 'ms',
+ baseline: 676.3,
+ candidate: 13.7,
+ status: 'improved'
+ })
+ ])
+ )
+ })
+
+ it('rejects invalid benchmark artifacts before comparing partial metrics', () => {
+ const dir = makeTempDir()
+ const baselinePath = writeArtifact(dir, 'split-invalid.json', {
+ label: 'invalid split',
+ status: 'failed',
+ valid: false,
+ headlineMs: { shortcutToFocusP50: 0 }
+ })
+ const candidatePath = writeArtifact(dir, 'split-valid.json', {
+ label: 'valid split',
+ status: 'passed',
+ valid: true,
+ headlineMs: { shortcutToFocusP50: 10 }
+ })
+
+ expect(() => comparePaths(baselinePath, candidatePath)).toThrow(
+ 'split-invalid.json: benchmark artifact is marked invalid'
+ )
+ })
+
it('compares numeric Playwright annotation metrics and omits metadata fields', () => {
const dir = makeTempDir()
const baselinePath = writeArtifact(dir, 'baseline-playwright.json', {
diff --git a/config/scripts/compare-benchmark-artifacts.mjs b/config/scripts/compare-benchmark-artifacts.mjs
index 3dc29355670..7e3a9eb759e 100644
--- a/config/scripts/compare-benchmark-artifacts.mjs
+++ b/config/scripts/compare-benchmark-artifacts.mjs
@@ -74,6 +74,9 @@ export function readBenchmarkArtifact(path) {
}
export function normalizeBenchmarkArtifact(path, artifact = readBenchmarkArtifact(path)) {
+ if (artifact?.valid === false || artifact?.status === 'failed') {
+ throw new Error(`${path}: benchmark artifact is marked invalid`)
+ }
if (artifact?.summaryMedianMs != null) {
return normalizeNumericObject(path, artifact, 'startup', artifact.summaryMedianMs, () => 'ms')
}
@@ -82,6 +85,15 @@ export function normalizeBenchmarkArtifact(path, artifact = readBenchmarkArtifac
key.endsWith('Count') || key.endsWith('After') ? 'count' : 'ms'
)
}
+ if (artifact?.headlineMs != null) {
+ return normalizeNumericObject(
+ path,
+ artifact,
+ 'terminal-split-activation',
+ artifact.headlineMs,
+ () => 'ms'
+ )
+ }
if (artifact?.suites != null) {
return normalizePlaywrightArtifact(path, artifact)
}
@@ -89,7 +101,7 @@ export function normalizeBenchmarkArtifact(path, artifact = readBenchmarkArtifac
return normalizeSummaryArtifact(path, artifact)
}
throw new Error(
- `${path}: unsupported benchmark artifact; expected summaryMedianMs, summaryMedian, Playwright suites, or top-level summary`
+ `${path}: unsupported benchmark artifact; expected summaryMedianMs, summaryMedian, headlineMs, Playwright suites, or top-level summary`
)
}
diff --git a/config/scripts/computer-use-skill-guidance.test.mjs b/config/scripts/computer-use-skill-guidance.test.mjs
index 1e2415a773f..006813840c7 100644
--- a/config/scripts/computer-use-skill-guidance.test.mjs
+++ b/config/scripts/computer-use-skill-guidance.test.mjs
@@ -12,11 +12,33 @@ const stubPath = join(projectDir, 'skills', 'computer-use', 'SKILL.md')
const bundledGuide = BUNDLED_SKILL_GUIDES.find((guide) => guide.name === 'computer-use')?.markdown
describe('computer-use skill guidance', () => {
+ it('keeps discovery scoped to desktop control and out of the embedded browser', () => {
+ const frontmatter = /^---\n([\s\S]*?)\n---\n/u.exec(readFileSync(guidePath, 'utf8'))?.[1] ?? ''
+ const description = frontmatter.replace(/\s+/gu, ' ')
+
+ expect(description).toContain('OS/window-level inspection and input')
+ expect(description).toContain('external browser window')
+ expect(description).toContain("Do not use for Orca's embedded browser")
+ expect(description).toContain('page-only browser automation')
+ expect(description).toContain("`orca-cli` for Orca's embedded pages")
+ expect(description).toContain(
+ 'page-automation tool such as Playwright or CDP for external pages'
+ )
+ expect(description).not.toContain('read Slack')
+ expect(description).not.toContain('get app state')
+
+ const orcaCli = readFileSync(join(projectDir, 'skill-guides', 'orca-cli.md'), 'utf8').replace(
+ /\s+/gu,
+ ' '
+ )
+ expect(orcaCli).toContain('browser embedded inside the Orca app')
+ })
+
it('keeps web-app targeting on the computer-use surface', () => {
const skill = readFileSync(guidePath, 'utf8')
expect(skill).toContain('Use this skill for desktop UI through `orca computer`')
- expect(skill).toContain('operate the desktop browser app/window that contains the page')
+ expect(skill).toContain('external desktop browser window that needs desktop-level control')
expect(skill).not.toContain('orca goto')
expect(skill).not.toContain('orca snapshot')
expect(skill).not.toContain('orca click')
diff --git a/config/scripts/orca-cli-skill-guidance.test.mjs b/config/scripts/orca-cli-skill-guidance.test.mjs
index 56f7ddf86e6..28c50c2daf3 100644
--- a/config/scripts/orca-cli-skill-guidance.test.mjs
+++ b/config/scripts/orca-cli-skill-guidance.test.mjs
@@ -18,6 +18,24 @@ function readSkill(path = guidePath) {
}
describe('orca CLI skill guidance', () => {
+ it('keeps external browser routing at the OS/page boundary', () => {
+ const skill = readSkill(guidePath)
+ const description = skill.replace(/\s+/gu, ' ')
+
+ expect(description).toContain(
+ 'Use Computer Use for external browser windows, webviews, or desktop UI only when the task requires OS/window-level control such as focus, menus, dialogs, coordinates, or screenshots.'
+ )
+ expect(description).toContain(
+ "`orca-cli` for Orca's embedded pages and a page-automation tool such as Playwright or CDP for external pages."
+ )
+ expect(skill).toContain(
+ 'For external Chrome/Safari/webviews or Orca app chrome/settings, use the Computer Use skill/tool only when the task requires OS/window-level control'
+ )
+ expect(skill).toContain(
+ "Use `orca-cli` for Orca's embedded pages and a page-automation tool such as Playwright or CDP for external pages"
+ )
+ })
+
it('keeps independent worktree lineage separate from Git base selection', () => {
const skill = readSkill()
diff --git a/config/scripts/orchestration-skill-guidance.test.mjs b/config/scripts/orchestration-skill-guidance.test.mjs
index 4eaf7d5753e..9d86471bc00 100644
--- a/config/scripts/orchestration-skill-guidance.test.mjs
+++ b/config/scripts/orchestration-skill-guidance.test.mjs
@@ -25,6 +25,17 @@ function getSection(markdown, heading) {
}
describe('orchestration skill guidance', () => {
+ it('keeps external browser routing at the OS/page boundary', () => {
+ const description = readFileSync(guidePath, 'utf8').replace(/\s+/gu, ' ')
+
+ expect(description).toContain(
+ "Use Computer Use for external browser windows, webviews, Orca app UI, or desktop UI outside Orca's embedded browser only when the task requires OS/window-level control such as focus, menus, dialogs, coordinates, or screenshots."
+ )
+ expect(description).toContain(
+ "`orca-cli` for Orca's embedded pages and a page-automation tool such as Playwright or CDP for external pages."
+ )
+ })
+
it('requires Orca runtime state before claiming a worker was orchestrated', () => {
const skill = readSkill()
const toolBoundary = getSection(skill, 'Tool Boundary')
diff --git a/config/scripts/pr-e2e-gate-contract.test.mjs b/config/scripts/pr-e2e-gate-contract.test.mjs
index 4ad2132d683..25461b25f76 100644
--- a/config/scripts/pr-e2e-gate-contract.test.mjs
+++ b/config/scripts/pr-e2e-gate-contract.test.mjs
@@ -316,7 +316,9 @@ describe('PR E2E gate contract', () => {
selectPrE2eSpecs(['src/renderer/src/hooks/remote-workspace-session-merge.test.ts'])
).toEqual([])
expect(
- selectPrE2eSpecs(['src/renderer/src/hooks/remote-workspace-target-sync-test-harness.ts'])
+ selectPrE2eSpecs([
+ 'src/renderer/src/hooks/__tests__/remote-workspace-target-sync-test-harness.ts'
+ ])
).toEqual([])
})
diff --git a/config/scripts/rebuild-native-deps-node-pty.test.mjs b/config/scripts/rebuild-native-deps-node-pty.test.mjs
index 665ac0312ab..09e38853371 100644
--- a/config/scripts/rebuild-native-deps-node-pty.test.mjs
+++ b/config/scripts/rebuild-native-deps-node-pty.test.mjs
@@ -1,4 +1,5 @@
-import { existsSync, readFileSync, rmSync } from 'node:fs'
+import { existsSync, readFileSync } from 'node:fs'
+import { removeTreeSync } from '../../src/shared/windows-transient-lock-removal.ts'
import { join } from 'node:path'
import { describe, expect, it } from 'vitest'
@@ -44,7 +45,7 @@ describe('rebuild-native-deps patched node-pty rebuild', () => {
)
expect(existsSync(rebuildLogPath)).toBe(false)
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
}
)
@@ -80,7 +81,7 @@ describe('rebuild-native-deps patched node-pty rebuild', () => {
)
).toBe('// napi.h\n')
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
})
@@ -104,7 +105,7 @@ describe('rebuild-native-deps patched node-pty rebuild', () => {
expect(readFileSync(join(runtimeDir, 'conpty.dll'), 'utf8')).toBe('conpty.dll x64')
expect(readFileSync(join(runtimeDir, 'OpenConsole.exe'), 'utf8')).toBe('OpenConsole.exe x64')
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
})
@@ -132,7 +133,7 @@ describe('rebuild-native-deps patched node-pty rebuild', () => {
const rebuildCall = JSON.parse(readFileSync(rebuildLogPath, 'utf8').trim())
expect(rebuildCall.onlyModules).toEqual(['windows-native-registry'])
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
}
)
@@ -162,7 +163,7 @@ describe('rebuild-native-deps patched node-pty rebuild', () => {
const rebuildCall = JSON.parse(readFileSync(rebuildLogPath, 'utf8').trim())
expect(rebuildCall.onlyModules).toEqual(['node-pty'])
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
}
)
@@ -193,7 +194,7 @@ describe('rebuild-native-deps patched node-pty rebuild', () => {
expect(rebuildCall.ignoreModules).toEqual(['cpu-features'])
expect(rebuildCall.force).toBe(true)
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
}
)
@@ -221,7 +222,7 @@ describe('rebuild-native-deps patched node-pty rebuild', () => {
)
expect(existsSync(rebuildLogPath)).toBe(false)
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
}
)
@@ -251,7 +252,7 @@ describe('rebuild-native-deps patched node-pty rebuild', () => {
expect(rebuildCall.onlyModules).toEqual(['node-pty'])
expect(rebuildCall.force).toBe(true)
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
}
)
diff --git a/config/scripts/rebuild-native-deps.test.mjs b/config/scripts/rebuild-native-deps.test.mjs
index cddab2ee9f0..d4db08d3e2e 100644
--- a/config/scripts/rebuild-native-deps.test.mjs
+++ b/config/scripts/rebuild-native-deps.test.mjs
@@ -1,6 +1,7 @@
import { existsSync, mkdirSync, readFileSync, rmSync, writeFileSync } from 'node:fs'
import { join } from 'node:path'
import { describe, expect, it } from 'vitest'
+import { removeTreeSync } from '../../src/shared/windows-transient-lock-removal.ts'
import {
mkTempProject,
@@ -36,7 +37,7 @@ describe('rebuild-native-deps Electron install fallback', () => {
'download attempted\n'
)
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
})
@@ -60,7 +61,7 @@ describe('rebuild-native-deps Electron install fallback', () => {
'Continuing postinstall because Electron binary installation failed'
)
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
})
@@ -81,7 +82,7 @@ describe('rebuild-native-deps Electron install fallback', () => {
'Continuing postinstall because Electron binary installation failed'
)
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
})
@@ -117,7 +118,7 @@ describe('rebuild-native-deps Electron install fallback', () => {
'stale-path'
)
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
})
@@ -141,7 +142,7 @@ describe('rebuild-native-deps Electron install fallback', () => {
'platform=linux arch=arm64\ndownload attempted\n'
)
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
})
@@ -162,7 +163,7 @@ describe('rebuild-native-deps Electron install fallback', () => {
expect(result.status, result.stderr).toBe(0)
expect(existsSync(join(projectDir, 'electron-get.log'))).toBe(false)
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
})
@@ -188,7 +189,7 @@ describe('rebuild-native-deps Electron install fallback', () => {
'electron.exe'
)
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
})
@@ -209,7 +210,7 @@ describe('rebuild-native-deps Electron install fallback', () => {
'platform=linux arch=x64'
)
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
})
@@ -230,7 +231,7 @@ describe('rebuild-native-deps Electron install fallback', () => {
expect(result.stdout).toContain('Repaired Electron path.txt -> electron')
expect(existsSync(join(projectDir, 'electron-get.log'))).toBe(false)
} finally {
- rmSync(projectDir, { recursive: true, force: true })
+ removeTreeSync(projectDir)
}
})
})
diff --git a/config/scripts/release-cut-token-permissions.test.mjs b/config/scripts/release-cut-token-permissions.test.mjs
index f18b2b26eba..f2f544a8f27 100644
--- a/config/scripts/release-cut-token-permissions.test.mjs
+++ b/config/scripts/release-cut-token-permissions.test.mjs
@@ -31,6 +31,7 @@ const EXPECTED_MATRIX = {
},
[`${RELEASE_WORKFLOW}#post-release-e2e`]: { actions: 'write' },
[`${RELEASE_WORKFLOW}#publish-release`]: { contents: 'write' },
+ [`${RELEASE_WORKFLOW}#release-preflight`]: { contents: 'read' },
[`${RELEASE_WORKFLOW}#skill-sharing-linux-floor-release-gate`]: { contents: 'read' },
[`${RELEASE_WORKFLOW}#skill-sharing-release-gate`]: { contents: 'read' },
[`${RELEASE_WORKFLOW}#terminal-rendering-golden`]: { contents: 'read' },
diff --git a/config/scripts/skill-sharing-release-workflow.test.mjs b/config/scripts/skill-sharing-release-workflow.test.mjs
index b6611a1aa18..2978b058305 100644
--- a/config/scripts/skill-sharing-release-workflow.test.mjs
+++ b/config/scripts/skill-sharing-release-workflow.test.mjs
@@ -10,6 +10,27 @@ function stepNamed(job, name) {
}
describe('skill-sharing release workflow', () => {
+ it('keeps artifact builds behind every blocking release gate', () => {
+ const preflight = workflow.jobs['release-preflight']
+ const build = workflow.jobs.build
+ const macBuild = workflow.jobs['build-mac']
+
+ expect(preflight.needs).toEqual([
+ 'cut',
+ 'terminal-rendering-golden',
+ 'skill-sharing-release-gate',
+ 'skill-sharing-linux-floor-release-gate'
+ ])
+ expect(preflight.if).toContain('always()')
+ expect(preflight.if).toContain("needs.terminal-rendering-golden.result == 'success'")
+ expect(preflight.if).toContain("needs.skill-sharing-release-gate.result == 'success'")
+ expect(preflight.if).toContain(
+ "needs.skill-sharing-linux-floor-release-gate.result == 'success'"
+ )
+ expect(build.needs).toContain('release-preflight')
+ expect(macBuild.needs).toContain('release-preflight')
+ })
+
it('blocks publication on native Windows, macOS, and the Linux floor', () => {
const platform = workflow.jobs['skill-sharing-release-gate']
const linux = workflow.jobs['skill-sharing-linux-floor-release-gate']
diff --git a/config/tsconfig.cli.json b/config/tsconfig.cli.json
index 439a465dc3e..93d556602f8 100644
--- a/config/tsconfig.cli.json
+++ b/config/tsconfig.cli.json
@@ -117,6 +117,7 @@
"../src/main/hermes/hermes-home-filesystem.ts",
"../src/main/hermes/hermes-managed-plugin-source.ts",
"../src/main/hermes/hook-service.ts",
+ "../src/main/in-flight-run-dedupe.ts",
"../src/main/kimi/hook-service.ts",
"../src/main/kimi/kimi-hook-config-toml.ts",
"../src/main/openclaude/hook-service.ts",
diff --git a/config/tsconfig.tc.web.json b/config/tsconfig.tc.web.json
index 3dcc8b43a34..8ac4c7754bb 100644
--- a/config/tsconfig.tc.web.json
+++ b/config/tsconfig.tc.web.json
@@ -10,6 +10,7 @@
"../src/main/gitlab/mappers.ts",
"../src/main/ipc/worktree-branch-name.ts",
"../src/main/ipc/worktree-logic.ts",
+ "../src/main/ipc/worktree-display-name.ts",
"../src/main/ipc/worktree-linked-work-item-metadata.ts",
"../src/main/ipc/worktree-metadata-merge.ts",
"../src/main/ipc/worktree-path-comparison.ts",
diff --git a/docs/site/content/docs/agents/glm-agent.mdx b/docs/site/content/docs/agents/glm-agent.mdx
index a7105e63354..8feed727d81 100644
--- a/docs/site/content/docs/agents/glm-agent.mdx
+++ b/docs/site/content/docs/agents/glm-agent.mdx
@@ -3,18 +3,22 @@ title: How to use GLM-5.2 in Orca ADE
description: Configure Claude Code and other CLI agent harnesses to run GLM-5.2 inside Orca worktrees.
---
-import { Callout } from '@/components/docs/prose';
+import { Callout } from '@/components/docs/prose'
GLM-5.2 works in Orca through the agent harness you already use. Configure GLM-5.2 in Claude Code, OpenCode, Cline, Kilo Code, Roo Code, Droid, OpenClaw, or another CLI agent, then launch that agent from Orca's picker.
Orca supplies the isolated worktree, terminal panes, browser tab, review flow, and session management. Your [Z.ai CodePlan subscription](https://z.ai/subscribe) and agent config supply the model access.
-You need an active [Z.ai CodePlan subscription](https://z.ai/subscribe) with GLM Coding Plan access before configuring GLM-5.2 in an agent harness. OpenAI-compatible harnesses also need a Z.ai API key. Orca does not include or resell GLM access.
+ You need an active [Z.ai CodePlan subscription](https://z.ai/subscribe) with GLM Coding Plan
+ access before configuring GLM-5.2 in an agent harness. OpenAI-compatible harnesses also need a
+ Z.ai API key. Orca does not include or resell GLM access.
-This page documents the GLM-5.2 configuration tested with Orca. Z.ai's [model guide](https://docs.z.ai/devpack/latest-model) may list newer models; verify model names, context limits, and harness compatibility there before substituting one.
+ This page documents the GLM-5.2 configuration tested with Orca. Z.ai's [model
+ guide](https://docs.z.ai/devpack/latest-model) may list newer models; verify model names, context
+ limits, and harness compatibility there before substituting one.
## Claude Code
diff --git a/docs/site/content/docs/agents/hibernation.mdx b/docs/site/content/docs/agents/hibernation.mdx
index 646f2e4ebdf..4e63d96bfc7 100644
--- a/docs/site/content/docs/agents/hibernation.mdx
+++ b/docs/site/content/docs/agents/hibernation.mdx
@@ -3,12 +3,13 @@ title: Agent hibernation
description: Let Orca pause idle background agent terminals and auto-resume them when you reopen the worktree.
---
-import { Callout } from '@/components/docs/prose';
+import { Callout } from '@/components/docs/prose'
When you keep dozens of worktrees open, idle agents add up — each one is a live PTY holding a model session in memory. Agent hibernation lets Orca quietly stop those terminals once they've been done and untouched long enough, then resume the same session the next time you open the worktree.
-Agent hibernation is off by default. Turn it on under **Settings → Experimental → Agent hibernation** while we keep tuning the safety model.
+ Agent hibernation is off by default. Turn it on under **Settings → Experimental → Agent
+ hibernation** while we keep tuning the safety model.
## What gets hibernated
diff --git a/docs/site/content/docs/agents/hooks-memory.mdx b/docs/site/content/docs/agents/hooks-memory.mdx
index dbacca765b3..303d56343da 100644
--- a/docs/site/content/docs/agents/hooks-memory.mdx
+++ b/docs/site/content/docs/agents/hooks-memory.mdx
@@ -2,7 +2,7 @@
title: Agent hooks & memory
---
-import { Callout } from '@/components/docs/prose';
+import { Callout } from '@/components/docs/prose'
Orca plays nicely with the agent hook and memory conventions Claude Code and Codex already use — it reads them, respects them, and gives you a UI for the ones that make sense in an IDE context.
@@ -27,5 +27,6 @@ Claude's `CLAUDE.md` and Codex's `AGENTS.md` (at repo root or nested) are left a
Hook endpoints are written to disk (`{userData}/agent-hooks/endpoint.env` on POSIX, `endpoint.cmd` on Windows) and re-sourced on every hook invocation, so long-lived agent sessions keep reaching the live Orca server even after an app restart — no more dead-port POSTs from a PTY that outlived the previous session.
-The Orca CLI exposes a commented worktree status field agents can update themselves. See [Worktree checkpoints](/docs/cli/worktree-checkpoints).
+ The Orca CLI exposes a commented worktree status field agents can update themselves. See [Worktree
+ checkpoints](/docs/cli/worktree-checkpoints).
diff --git a/docs/site/content/docs/agents/native-chat.mdx b/docs/site/content/docs/agents/native-chat.mdx
index 392a702a17c..1a812697e0a 100644
--- a/docs/site/content/docs/agents/native-chat.mdx
+++ b/docs/site/content/docs/agents/native-chat.mdx
@@ -3,7 +3,7 @@ title: Chat UI (native chat)
description: Optional chat surface over supported agent terminals — skills, model pickers, and transcript view.
---
-import { Callout } from '@/components/docs/prose';
+import { Callout } from '@/components/docs/prose'
Chat UI is an experimental view layered on supported agent terminal sessions. The terminal remains the source of truth; Chat UI is a structured transcript + composer for the same PTY. Transcript decoding covers **Claude**, **Codex**, **Grok**, and **OMP** — OMP sessions open in Chat UI like the others instead of staying raw-terminal-only.
@@ -30,5 +30,6 @@ When Claude shows an **AskUserQuestion** (or similar structured permission/quest
Chat UI ships on desktop for supported local and remote (paired server) agent sessions. The [mobile companion](/docs/mobile) reuses chat-style transcript patterns for the same paired sessions.
-Transcript fidelity, streaming, and terminal parity are still under active tuning. Prefer the raw TUI when you need every OSC/status detail.
+ Transcript fidelity, streaming, and terminal parity are still under active tuning. Prefer the raw
+ TUI when you need every OSC/status detail.
diff --git a/docs/site/content/docs/agents/session-history.mdx b/docs/site/content/docs/agents/session-history.mdx
index d6d5b785b61..0756b2448a5 100644
--- a/docs/site/content/docs/agents/session-history.mdx
+++ b/docs/site/content/docs/agents/session-history.mdx
@@ -3,7 +3,7 @@ title: Agent session history
description: Browse and resume past Claude, Codex, Cursor, Gemini, and other agent sessions from Orca's right sidebar.
---
-import { Callout } from '@/components/docs/prose';
+import { Callout } from '@/components/docs/prose'
Orca scans the on-disk session transcripts that supported agent CLIs leave behind and lists them in a right-sidebar panel called **Agent Session History**. Pick a past session, click **Resume**, and Orca runs the agent's resume command in a fresh terminal — same `cwd`, same session ID, no manual `--resume` flag wrangling.
@@ -39,13 +39,16 @@ Click a session row to open its details: working directory, branch, model, messa
- **Resume** — opens a new terminal in the session's `cwd` and runs the agent's resume command (e.g. `claude --resume `, `codex resume `, `pi --session `, `prime-agent --resume `, `cursor-agent --resume `, `acli rovodev run --restore `). Codex sessions also re-export `CODEX_HOME` when the original session set one.
Pi resumes from the on-disk session file reported by its hooks (`--session `), not from a bare session id. If that file is missing, Resume is unavailable for that row even when a session id exists.
+
- **Copy resume command** — copies the same shell command to the clipboard for use in an external terminal.
- **Copy session ID** / **Copy log path** — for scripting or attaching transcripts to bug reports.
- **Open log** / **Reveal log** — open the raw transcript file in Orca, or jump to it in your OS file manager.
- **Open cwd** — open the session's working directory as a workspace.
-Resume runs the agent CLI on the machine where Orca is rendering. If you're connected to a remote workspace, switch back to a local one (or use **Copy resume command** and run it on the remote yourself) before clicking **Resume**.
+ Resume runs the agent CLI on the machine where Orca is rendering. If you're connected to a remote
+ workspace, switch back to a local one (or use **Copy resume command** and run it on the remote
+ yourself) before clicking **Resume**.
## Where the transcripts come from
diff --git a/docs/site/content/docs/agents/supported.mdx b/docs/site/content/docs/agents/supported.mdx
index a13f118b049..1d2f4964577 100644
--- a/docs/site/content/docs/agents/supported.mdx
+++ b/docs/site/content/docs/agents/supported.mdx
@@ -3,12 +3,15 @@ title: Supported agents
description: Every agent Orca ships with out of the box.
---
-import { Callout } from '@/components/docs/prose';
+import { Callout } from '@/components/docs/prose'
Orca works with **any CLI agent** — the agent combobox just launches a process in a terminal. The following ship preconfigured in the built-in agent picker with one-click launch/setup; deeper hooks, status, usage tracking, and account switching are noted where supported.
-The defaults below pass each agent's permission-bypass flag for new launches. A worktree is an isolated checkout, not a security sandbox: the agent can still access files and network resources available to its process. Choose **Manual** in **Settings → Agents → Agent Permissions** unless you intentionally trust the agent and the task.
+ The defaults below pass each agent's permission-bypass flag for new launches. A worktree is an
+ isolated checkout, not a security sandbox: the agent can still access files and network resources
+ available to its process. Choose **Manual** in **Settings → Agents → Agent Permissions** unless
+ you intentionally trust the agent and the task.
## Permissions default
@@ -19,40 +22,40 @@ Use **Settings → Agents → Agent Permissions** when you want to switch all un
To restore prompts for one agent only, edit that agent's default arguments or environment in Settings. Orca treats a non-empty custom value as an explicit override and opts that agent out of future permission-mode migrations.
-| Agent | Notes | Docs |
-| --- | --- | --- |
-| Claude Code | Deep integration: usage, hot-swap, hooks | [Anthropic](https://docs.anthropic.com/claude/docs/claude-code) |
-| Claude Agent Teams | Disabled by default — enable under Settings → Agents to launch via `orca claude-teams` with native panes for each teammate | [Anthropic](https://code.claude.com/docs/agent-teams) |
-| Codex | Deep integration: usage, hot-swap | [OpenAI](https://github.com/openai/codex) |
-| Grok | Auto-setup | [xAI](https://x.ai/cli) |
-| GitHub Copilot CLI | Auto-setup | [GitHub](https://docs.github.com/en/copilot/how-tos/set-up/install-copilot-cli) |
-| OpenCode | Auto-setup, status | [OpenCode](https://opencode.ai/docs/cli/) |
-| Pi | Auto-setup, hooks, status | [Pi](https://pi.dev) |
-| OMP | Auto-setup, hooks, status | [OMP](https://omp.sh) |
-| Prime Agent | Auto-setup, hooks, status, session history | [Prime Intellect](https://github.com/PrimeIntellect-ai/prime-agent) |
-| Gemini | Auto-setup | [Google](https://github.com/google-gemini/gemini-cli) |
-| Antigravity | Auto-setup, hooks, status | [Google](https://antigravity.google/docs/cli-overview) |
-| Ante | Auto-setup, status | [Ante](https://github.com/AntigmaLabs/ante-preview) |
-| Aider | Auto-setup | [Aider](https://aider.chat/docs/) |
-| Goose | Auto-setup | [Block](https://block.github.io/goose/docs/quickstart/) |
-| Amp | Auto-setup | [Amp](https://ampcode.com/manual#install) |
-| Kilocode | Auto-setup | [Kilo](https://kilo.ai/docs/cli) |
-| Kiro | Auto-setup | [Kiro](https://kiro.dev/docs/cli/) |
-| Charm Crush | Auto-setup | [Charm](https://github.com/charmbracelet/crush) |
-| Auggie | Auto-setup | [Augment](https://docs.augmentcode.com/cli/overview) |
-| Autohand | Auto-setup | [Autohand](https://github.com/autohandai/code-cli) |
-| Cline | Auto-setup | [Cline](https://docs.cline.bot/cline-cli/overview) |
-| Codebuff | Auto-setup | [Codebuff](https://www.codebuff.com/docs/help/quick-start) |
-| Command Code | Auto-setup, status | [Command Code](https://commandcode.ai/docs/quickstart) |
-| Continue | Auto-setup | [Continue](https://docs.continue.dev/guides/cli) |
-| Cursor CLI | Deep integration | [Cursor](https://cursor.com/cli) |
-| Devin | Auto-setup | [Devin](https://devin.ai/cli) |
-| Droid (Factory) | Auto-setup, hooks, status | [Factory](https://docs.factory.ai/cli/getting-started/quickstart) |
-| Kimi | Auto-setup | [Moonshot](https://www.kimi.com/code/docs/en/kimi-code-cli/getting-started.html) |
-| Mistral Vibe | Auto-setup | [Mistral](https://github.com/mistralai/mistral-vibe) |
-| MiniMax | Auto-setup, usage tracking, rate-limit tracking | [MiniMax](https://www.minimax.chat) |
-| Qwen Code | Auto-setup via the installed `qwen` executable | [Qwen](https://github.com/QwenLM/qwen-code) |
-| Rovo Dev | Auto-setup | [Atlassian](https://support.atlassian.com/rovo/docs/install-and-run-rovo-dev-cli-on-your-device/) |
-| Hermes | Auto-setup | [Nous](https://hermes-agent.nousresearch.com/docs/) |
-| OpenClaw | Auto-setup | [OpenClaw](https://github.com/openclaw/openclaw) |
-| Trae | Auto-setup via `traecli` (TRAE CN CLI) | [Trae](https://www.trae.ai/) |
+| Agent | Notes | Docs |
+| ------------------ | -------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------- |
+| Claude Code | Deep integration: usage, hot-swap, hooks | [Anthropic](https://docs.anthropic.com/claude/docs/claude-code) |
+| Claude Agent Teams | Disabled by default — enable under Settings → Agents to launch via `orca claude-teams` with native panes for each teammate | [Anthropic](https://code.claude.com/docs/agent-teams) |
+| Codex | Deep integration: usage, hot-swap | [OpenAI](https://github.com/openai/codex) |
+| Grok | Auto-setup | [xAI](https://x.ai/cli) |
+| GitHub Copilot CLI | Auto-setup | [GitHub](https://docs.github.com/en/copilot/how-tos/set-up/install-copilot-cli) |
+| OpenCode | Auto-setup, status | [OpenCode](https://opencode.ai/docs/cli/) |
+| Pi | Auto-setup, hooks, status | [Pi](https://pi.dev) |
+| OMP | Auto-setup, hooks, status | [OMP](https://omp.sh) |
+| Prime Agent | Auto-setup, hooks, status, session history | [Prime Intellect](https://github.com/PrimeIntellect-ai/prime-agent) |
+| Gemini | Auto-setup | [Google](https://github.com/google-gemini/gemini-cli) |
+| Antigravity | Auto-setup, hooks, status | [Google](https://antigravity.google/docs/cli-overview) |
+| Ante | Auto-setup, status | [Ante](https://github.com/AntigmaLabs/ante-preview) |
+| Aider | Auto-setup | [Aider](https://aider.chat/docs/) |
+| Goose | Auto-setup | [Block](https://block.github.io/goose/docs/quickstart/) |
+| Amp | Auto-setup | [Amp](https://ampcode.com/manual#install) |
+| Kilocode | Auto-setup | [Kilo](https://kilo.ai/docs/cli) |
+| Kiro | Auto-setup | [Kiro](https://kiro.dev/docs/cli/) |
+| Charm Crush | Auto-setup | [Charm](https://github.com/charmbracelet/crush) |
+| Auggie | Auto-setup | [Augment](https://docs.augmentcode.com/cli/overview) |
+| Autohand | Auto-setup | [Autohand](https://github.com/autohandai/code-cli) |
+| Cline | Auto-setup | [Cline](https://docs.cline.bot/cline-cli/overview) |
+| Codebuff | Auto-setup | [Codebuff](https://www.codebuff.com/docs/help/quick-start) |
+| Command Code | Auto-setup, status | [Command Code](https://commandcode.ai/docs/quickstart) |
+| Continue | Auto-setup | [Continue](https://docs.continue.dev/guides/cli) |
+| Cursor CLI | Deep integration | [Cursor](https://cursor.com/cli) |
+| Devin | Auto-setup | [Devin](https://devin.ai/cli) |
+| Droid (Factory) | Auto-setup, hooks, status | [Factory](https://docs.factory.ai/cli/getting-started/quickstart) |
+| Kimi | Auto-setup | [Moonshot](https://www.kimi.com/code/docs/en/kimi-code-cli/getting-started.html) |
+| Mistral Vibe | Auto-setup | [Mistral](https://github.com/mistralai/mistral-vibe) |
+| MiniMax | Auto-setup, usage tracking, rate-limit tracking | [MiniMax](https://www.minimax.chat) |
+| Qwen Code | Auto-setup via the installed `qwen` executable | [Qwen](https://github.com/QwenLM/qwen-code) |
+| Rovo Dev | Auto-setup | [Atlassian](https://support.atlassian.com/rovo/docs/install-and-run-rovo-dev-cli-on-your-device/) |
+| Hermes | Auto-setup | [Nous](https://hermes-agent.nousresearch.com/docs/) |
+| OpenClaw | Auto-setup | [OpenClaw](https://github.com/openclaw/openclaw) |
+| Trae | Auto-setup via `traecli` (TRAE CN CLI) | [Trae](https://www.trae.ai/) |
diff --git a/docs/site/content/docs/agents/usage-tracking.mdx b/docs/site/content/docs/agents/usage-tracking.mdx
index 8a9e5c83528..6aa491b4a4a 100644
--- a/docs/site/content/docs/agents/usage-tracking.mdx
+++ b/docs/site/content/docs/agents/usage-tracking.mdx
@@ -16,7 +16,7 @@ Orca reads the local usage state each agent maintains on disk (under `~/.claude`
## Multi-account accounting
-The status bar always reflects the *active* account. Other configured accounts are visible in the account switcher with their own usage.
+The status bar always reflects the _active_ account. Other configured accounts are visible in the account switcher with their own usage.
## Usage roster
diff --git a/docs/site/content/docs/browser/design-mode.mdx b/docs/site/content/docs/browser/design-mode.mdx
index 8db703e1cc3..2bd8318db63 100644
--- a/docs/site/content/docs/browser/design-mode.mdx
+++ b/docs/site/content/docs/browser/design-mode.mdx
@@ -2,11 +2,14 @@
title: Design Mode
---
-import { ImagePlaceholder } from '@/components/docs/prose';
+import { ImagePlaceholder } from '@/components/docs/prose'
Design Mode turns the Orca browser into a pointer-to-code tool. Toggle it on, click any UI element on the rendered page, and the element drops into the agent chat as rich context — with its DOM, computed styles, and a screenshot.
-
+
## Turn it on
diff --git a/docs/site/content/docs/browser/overview.mdx b/docs/site/content/docs/browser/overview.mdx
index 37a657c2d24..d248318da69 100644
--- a/docs/site/content/docs/browser/overview.mdx
+++ b/docs/site/content/docs/browser/overview.mdx
@@ -2,11 +2,14 @@
title: Per-worktree browser
---
-import { ImagePlaceholder } from '@/components/docs/prose';
+import { ImagePlaceholder } from '@/components/docs/prose'
Every Orca worktree has its own browser. It's a real Chromium window — address bar, history, devtools — embedded in a pane. Tabs are scoped to the worktree, so the app you're building against stays out of the way of your other work.
-
+
## Controls
diff --git a/docs/site/content/docs/cli/computer-use.mdx b/docs/site/content/docs/cli/computer-use.mdx
index 7fc332fc828..089600aae0a 100644
--- a/docs/site/content/docs/cli/computer-use.mdx
+++ b/docs/site/content/docs/cli/computer-use.mdx
@@ -3,12 +3,14 @@ title: Computer use
description: Drive local desktop apps from an agent via accessibility trees, screenshots, and safe UI actions.
---
-import { Callout } from '@/components/docs/prose';
+import { Callout } from '@/components/docs/prose'
The `orca computer` CLI lets an agent inspect and control native desktop apps — list running apps, read accessibility trees, click controls, set values, type text, scroll, and take screenshots. Use it when a task needs to operate the OS or a third-party app rather than a terminal or the built-in browser.
-Computer use ships native helpers per platform and requires Accessibility (and on macOS, Screen Recording) permission. The command surface is stable enough for skills to build against, but flag names may still shift.
+ Computer use ships native helpers per platform and requires Accessibility (and on macOS, Screen
+ Recording) permission. The command surface is stable enough for skills to build against, but flag
+ names may still shift.
## First-time setup
diff --git a/docs/site/content/docs/cli/orchestration.mdx b/docs/site/content/docs/cli/orchestration.mdx
index c634eae8056..df093fab901 100644
--- a/docs/site/content/docs/cli/orchestration.mdx
+++ b/docs/site/content/docs/cli/orchestration.mdx
@@ -3,18 +3,21 @@ title: Orchestration
description: Coordinate agents with Runs, tasks, supervised workers, messages, and decision gates.
---
-import { Callout } from '@/components/docs/prose';
+import { Callout } from '@/components/docs/prose'
Orchestration is Orca's structured multi-agent layer: a **Run** (namespace + coordinator inbox), **Tasks**, **Dispatches**, supervised **workers**, messages, and decision gates.
Use it when you need ownership, completion tracking, or a DAG. For one-off prompts, use `orca terminal send`. For full ownership handoffs without supervision, use worktree/terminal commands from the `orca-cli` skill.
-Enable orchestration under Settings → Experimental before using these commands. The CLI talks to the running Orca runtime, so `orca status --json` should succeed first.
+ Enable orchestration under Settings → Experimental before using these commands. The CLI talks to
+ the running Orca runtime, so `orca status --json` should succeed first.
-`orca orchestration run` and `run-stop` (and `coordinator-start` / `coordinator-stop`) perform **no effects**. They return recovery text pointing at `orca skills get orchestration --full`. Use the Run + worker-start flow below.
+ `orca orchestration run` and `run-stop` (and `coordinator-start` / `coordinator-stop`) perform
+ **no effects**. They return recovery text pointing at `orca skills get orchestration --full`. Use
+ the Run + worker-start flow below.
## Core model
diff --git a/docs/site/content/docs/cli/overview.mdx b/docs/site/content/docs/cli/overview.mdx
index aeadfdd5572..3248e89e1eb 100644
--- a/docs/site/content/docs/cli/overview.mdx
+++ b/docs/site/content/docs/cli/overview.mdx
@@ -10,7 +10,7 @@ keywords:
- agent CLI
---
-import { Callout } from '@/components/docs/prose';
+import { Callout } from '@/components/docs/prose'
The Orca CLI is the `orca` command-line interface for scripting a running Orca editor from any shell. Use it to create and inspect worktrees, drive agent terminals, open files and diffs, automate the built-in browser, run scheduled automations, share HTML/Markdown artifacts, and control Orca-native tools from scripts or AI agents.
@@ -118,5 +118,7 @@ orca emulator kill --json
Use `--worktree `, `--device `, or `--emulator ` when a script needs an explicit target.
-For the full command surface including tabs, waits, cookies, and frames, see [Orca CLI reference](/docs/cli/reference), then install the Orca CLI skill (see [Skills registry](/docs/cli/skills)) and point your agent at it.
+ For the full command surface including tabs, waits, cookies, and frames, see [Orca CLI
+ reference](/docs/cli/reference), then install the Orca CLI skill (see [Skills
+ registry](/docs/cli/skills)) and point your agent at it.
diff --git a/docs/site/content/docs/cli/reference.mdx b/docs/site/content/docs/cli/reference.mdx
index 2f3e5d3ec2a..3df0773a4a7 100644
--- a/docs/site/content/docs/cli/reference.mdx
+++ b/docs/site/content/docs/cli/reference.mdx
@@ -3,7 +3,7 @@ title: Orca CLI reference
description: Commands, selectors, and agent-friendly patterns for driving Orca from a shell.
---
-import { Callout } from '@/components/docs/prose';
+import { Callout } from '@/components/docs/prose'
The `orca` CLI talks to a running Orca runtime. Use it when a shell script or agent needs to inspect worktrees, launch terminals, open files, automate the built-in browser, or report progress back into Orca.
@@ -116,7 +116,8 @@ orca terminal close --terminal --json
Omit `--terminal` to target the active terminal in the current worktree. Read before sending when you are not sure what the terminal is waiting for.
-Terminal handles are runtime-scoped. If Orca restarts or a command reports a stale terminal handle, run `orca terminal list --json` and reacquire the handle.
+ Terminal handles are runtime-scoped. If Orca restarts or a command reports a stale terminal
+ handle, run `orca terminal list --json` and reacquire the handle.
`terminal list` reports each terminal's `executionHostId` when Orca can verify it, plus a result-level `hostScope` with covered and omitted host IDs. Treat a missing host identity or scope as **unverifiable**, not local. A missing terminal is evidence that it exited only when its execution host is listed in `hostScope.hostIds`.
diff --git a/docs/site/content/docs/cli/skills.mdx b/docs/site/content/docs/cli/skills.mdx
index efb99d4a5ee..639b5099119 100644
--- a/docs/site/content/docs/cli/skills.mdx
+++ b/docs/site/content/docs/cli/skills.mdx
@@ -12,21 +12,21 @@ keywords:
- orca-emulator-android skill
---
-Orca ships **skills** that agents install into their skill directories. Public install packages are **hybrid discovery stubs**: short `SKILL.md` files that tell the agent *when* to engage Orca and how to load the full guide from the running CLI. Command flags live in the binary so they cannot drift from the app version.
+Orca ships **skills** that agents install into their skill directories. Public install packages are **hybrid discovery stubs**: short `SKILL.md` files that tell the agent _when_ to engage Orca and how to load the full guide from the running CLI. Command flags live in the binary so they cannot drift from the app version.
## Installable Orca skills
Use `npx skills add` with the public Orca repo and the skill name. Default agent setup usually installs `orca-cli`, `computer-use`, and `orchestration`.
-| Skill | Install | Use it for |
-| --- | --- | --- |
-| [`orca-cli`](#orca-cli) | `npx skills add https://github.com/stablyai/orca --skill orca-cli --global` | Worktrees, terminals, files, automations, embedded browser. |
-| [`orchestration`](#orchestration) | `npx skills add https://github.com/stablyai/orca --skill orchestration --global` | Multi-agent Runs, tasks, supervised workers, messages, gates. |
-| [`computer-use`](#computer-use) | `npx skills add https://github.com/stablyai/orca --skill computer-use --global` | Desktop apps via accessibility trees and safe UI actions. |
-| [`orca-linear`](#orca-linear) | `npx skills add https://github.com/stablyai/orca --skill orca-linear --global` | Linear ticket read/write through `orca linear`. |
-| [`orca-emulator`](#orca-emulator) | `npx skills add https://github.com/stablyai/orca --skill orca-emulator --global` | iOS Simulator control. |
-| [`orca-emulator-android`](#orca-emulator-android) | `npx skills add https://github.com/stablyai/orca --skill orca-emulator-android --global` | Android emulator/device via adb. |
-| [`orca-per-workspace-env`](#orca-per-workspace-env) | `npx skills add https://github.com/stablyai/orca --skill orca-per-workspace-env --global` | Per-workspace environment recipes (`orca.yaml`). |
+| Skill | Install | Use it for |
+| --------------------------------------------------- | ----------------------------------------------------------------------------------------- | ------------------------------------------------------------- |
+| [`orca-cli`](#orca-cli) | `npx skills add https://github.com/stablyai/orca --skill orca-cli --global` | Worktrees, terminals, files, automations, embedded browser. |
+| [`orchestration`](#orchestration) | `npx skills add https://github.com/stablyai/orca --skill orchestration --global` | Multi-agent Runs, tasks, supervised workers, messages, gates. |
+| [`computer-use`](#computer-use) | `npx skills add https://github.com/stablyai/orca --skill computer-use --global` | Desktop apps via accessibility trees and safe UI actions. |
+| [`orca-linear`](#orca-linear) | `npx skills add https://github.com/stablyai/orca --skill orca-linear --global` | Linear ticket read/write through `orca linear`. |
+| [`orca-emulator`](#orca-emulator) | `npx skills add https://github.com/stablyai/orca --skill orca-emulator --global` | iOS Simulator control. |
+| [`orca-emulator-android`](#orca-emulator-android) | `npx skills add https://github.com/stablyai/orca --skill orca-emulator-android --global` | Android emulator/device via adb. |
+| [`orca-per-workspace-env`](#orca-per-workspace-env) | `npx skills add https://github.com/stablyai/orca --skill orca-per-workspace-env --global` | Per-workspace environment recipes (`orca.yaml`). |
## Hybrid stubs vs the live guide
diff --git a/docs/site/content/docs/editing/markdown.mdx b/docs/site/content/docs/editing/markdown.mdx
index cf62a9d949a..a84c3991611 100644
--- a/docs/site/content/docs/editing/markdown.mdx
+++ b/docs/site/content/docs/editing/markdown.mdx
@@ -34,12 +34,12 @@ YAML and TOML front matter is shown in the rich editor and rendered preview by d
In rich markdown tables:
-| Key | Behavior |
-| --- | --- |
-| **Tab** / **Shift-Tab** | Next / previous cell; Tab past the last cell inserts a row |
-| **Enter** | Move to the cell below; on the last row, add a row |
-| **Backspace** on a fully empty row | Delete the row (or the whole table if it is the last row) |
-| **Backspace** in an empty cell when the row still has content | Step to the previous cell |
+| Key | Behavior |
+| ------------------------------------------------------------- | ---------------------------------------------------------- |
+| **Tab** / **Shift-Tab** | Next / previous cell; Tab past the last cell inserts a row |
+| **Enter** | Move to the cell below; on the last row, add a row |
+| **Backspace** on a fully empty row | Delete the row (or the whole table if it is the last row) |
+| **Backspace** in an empty cell when the row still has content | Step to the previous cell |
Use **Shift-Tab** to unindent a list item or the selected lines of a code block.
diff --git a/docs/site/content/docs/editing/viewers.mdx b/docs/site/content/docs/editing/viewers.mdx
index 20a21be1ca1..2b16d969887 100644
--- a/docs/site/content/docs/editing/viewers.mdx
+++ b/docs/site/content/docs/editing/viewers.mdx
@@ -2,7 +2,7 @@
title: HTML, Mermaid, PDF & image viewers
---
-import { Callout } from '@/components/docs/prose';
+import { Callout } from '@/components/docs/prose'
Orca includes built-in viewers for the formats that show up in most repos.
@@ -35,5 +35,6 @@ Scroll, zoom, and text selection. Useful for design docs checked into the repo.
`.ipynb` files open in a notebook viewer with rendered markdown, syntax-highlighted code cells, and saved outputs. Editing cells writes back to the on-disk `.ipynb` while preserving nbformat, so diffs stay clean.
-The notebook editor is marked beta. Cell execution and richer output rendering are still settling — file an issue if a notebook in your repo doesn't load cleanly.
+ The notebook editor is marked beta. Cell execution and richer output rendering are still settling
+ — file an issue if a notebook in your repo doesn't load cleanly.
diff --git a/docs/site/content/docs/first-session.mdx b/docs/site/content/docs/first-session.mdx
index ddd2e1a11f1..1d3cd3c909b 100644
--- a/docs/site/content/docs/first-session.mdx
+++ b/docs/site/content/docs/first-session.mdx
@@ -3,7 +3,7 @@ title: Your first 3-agent session
description: From empty app to three agents running in parallel in under five minutes.
---
-import { Callout } from '@/components/docs/prose';
+import { Callout } from '@/components/docs/prose'
This is the single most important page in the docs. By the end you'll have three agents running in parallel on three different approaches to the same task, with one PR shipped.
@@ -48,5 +48,6 @@ Once agents settle, open each worktree's diff view. Use [Annotate AI Diff](/docs
Commit and push directly from Orca — see [Commit & push from Orca](/docs/review/commit-push). The other two worktrees can be deleted with one click; their branches go with them.
-This flow — add → worktree → agent → split → diff → ship — is the whole of Orca. Every other page in these docs is a deeper look at one of those steps.
+ This flow — add → worktree → agent → split → diff → ship — is the whole of Orca. Every other page
+ in these docs is a deeper look at one of those steps.
diff --git a/docs/site/content/docs/github-errors.mdx b/docs/site/content/docs/github-errors.mdx
index a2139dac644..b6b758f102d 100644
--- a/docs/site/content/docs/github-errors.mdx
+++ b/docs/site/content/docs/github-errors.mdx
@@ -9,14 +9,14 @@ This page covers the errors you’ll see most often and how to fix them.
## Quick triage
-| What you see | Likely cause | First thing to try |
-| --- | --- | --- |
-| “GitHub is rate-limiting requests” / “rate limit exceeded (core)” | GitHub REST (core) quota exhausted for your user | Wait for reset; stop extra `gh` / agent / Orca usage; check [Settings → Git → GitHub API Budget](/docs/settings) |
-| “GitHub authentication is unavailable” / `gh auth` prompts | `gh` not logged in, expired token, or bad `GITHUB_TOKEN` | `gh auth status`, then `gh auth login` |
-| “GitHub did not allow access” / HTTP 403 (not rate limit) | Missing scopes or no access to the repo | Re-auth with `repo` (and needed org SSO); confirm you can open the PR in the browser |
-| “repository is unavailable” / HTTP 404 | Wrong remote, private repo without access, or renamed repo | Check `git remote -v` and browser access |
-| “GitHub is unreachable” / timeouts | Network, proxy, VPN, or GitHub outage | Check [githubstatus.com](https://www.githubstatus.com/); retry off VPN |
-| “GitHub CLI is unavailable” | `gh` missing from PATH Orca uses | Install `gh` and restart Orca |
+| What you see | Likely cause | First thing to try |
+| ----------------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- |
+| “GitHub is rate-limiting requests” / “rate limit exceeded (core)” | GitHub REST (core) quota exhausted for your user | Wait for reset; stop extra `gh` / agent / Orca usage; check [Settings → Git → GitHub API Budget](/docs/settings) |
+| “GitHub authentication is unavailable” / `gh auth` prompts | `gh` not logged in, expired token, or bad `GITHUB_TOKEN` | `gh auth status`, then `gh auth login` |
+| “GitHub did not allow access” / HTTP 403 (not rate limit) | Missing scopes or no access to the repo | Re-auth with `repo` (and needed org SSO); confirm you can open the PR in the browser |
+| “repository is unavailable” / HTTP 404 | Wrong remote, private repo without access, or renamed repo | Check `git remote -v` and browser access |
+| “GitHub is unreachable” / timeouts | Network, proxy, VPN, or GitHub outage | Check [githubstatus.com](https://www.githubstatus.com/); retry off VPN |
+| “GitHub CLI is unavailable” | `gh` missing from PATH Orca uses | Install `gh` and restart Orca |
## Rate limits (most common)
@@ -24,11 +24,11 @@ GitHub gives each **authenticated user** a shared hourly budget. **Every tool on
### Buckets Orca cares about
-| Bucket | What it covers | Typical limit (authenticated) |
-| --- | --- | --- |
-| **REST (core)** | Most PR/issue/API calls (`gh pr view`, checks metadata, many REST endpoints) | 5,000 / hour |
-| **GraphQL** | Project/Tasks and some richer PR queries | 5,000 points / hour |
-| **Search** | Search-driven lists | 30 / minute |
+| Bucket | What it covers | Typical limit (authenticated) |
+| --------------- | ---------------------------------------------------------------------------- | ----------------------------- |
+| **REST (core)** | Most PR/issue/API calls (`gh pr view`, checks metadata, many REST endpoints) | 5,000 / hour |
+| **GraphQL** | Project/Tasks and some richer PR queries | 5,000 points / hour |
+| **Search** | Search-driven lists | 30 / minute |
When a primary bucket is exhausted, GitHub returns HTTP **403** with a message like `API rate limit exceeded`. Orca classifies that as rate-limited, keeps the last known PR status when it can, and **stops spawning more `gh` calls** for a short window so a single limit doesn’t turn into a storm of failures.
@@ -106,11 +106,11 @@ GitHub auth is **per host**. Logging in on your laptop does not log in `gh` on a
## Permission and repository errors
-| Symptom | Meaning |
-| --- | --- |
-| HTTP 403 without “rate limit” | Token lacks scope or you’re not allowed to see the resource |
-| HTTP 404 / “could not resolve to a Repository” | Repo missing, renamed, or invisible to this token |
-| “resource not accessible by integration” | App/token type can’t perform that action |
+| Symptom | Meaning |
+| ---------------------------------------------- | ----------------------------------------------------------- |
+| HTTP 403 without “rate limit” | Token lacks scope or you’re not allowed to see the resource |
+| HTTP 404 / “could not resolve to a Repository” | Repo missing, renamed, or invisible to this token |
+| “resource not accessible by integration” | App/token type can’t perform that action |
Fixes:
diff --git a/docs/site/content/docs/index.mdx b/docs/site/content/docs/index.mdx
index 642189a686b..5f3f71483d8 100644
--- a/docs/site/content/docs/index.mdx
+++ b/docs/site/content/docs/index.mdx
@@ -1,9 +1,9 @@
---
title: What is Orca?
-description: "A 60-second pitch: who Orca is for and when to reach for it."
+description: 'A 60-second pitch: who Orca is for and when to reach for it.'
---
-import { Callout } from '@/components/docs/prose';
+import { Callout } from '@/components/docs/prose'
Orca is a desktop IDE for running multiple AI coding agents side by side. Every task gets its own git worktree, its own agent terminal, and its own browser tab — so you can fan out work across Claude Code, Codex, Cursor CLI, and friends without stashing, branch-juggling, or losing flow.
@@ -25,5 +25,7 @@ Orca is designed for people who already write code for a living and want to use
- **Not a hosted VPS product.** Orca runs on your desktop by default. Remote compute uses machines and cloud accounts you control — [SSH targets](/docs/ssh), [self-hosted Orca servers](/docs/remote-servers), or [Cloud VMs / per-workspace environments](/docs/ways-to-run#4-cloud-vms-per-workspace-environments).
-Head to [Install](/docs/install), then walk through [Your first 3-agent session](/docs/first-session) — the single most important page in these docs. When you're ready to move agents off the laptop, start with [Ways to run Orca](/docs/ways-to-run).
+ Head to [Install](/docs/install), then walk through [Your first 3-agent
+ session](/docs/first-session) — the single most important page in these docs. When you're ready to
+ move agents off the laptop, start with [Ways to run Orca](/docs/ways-to-run).
diff --git a/docs/site/content/docs/install.mdx b/docs/site/content/docs/install.mdx
index fc35c1ad34a..f710644d19e 100644
--- a/docs/site/content/docs/install.mdx
+++ b/docs/site/content/docs/install.mdx
@@ -3,7 +3,7 @@ title: Install
description: Download Orca for macOS, Windows, or Linux, and opt into RC builds.
---
-import { Callout } from '@/components/docs/prose';
+import { Callout } from '@/components/docs/prose'
## Download
@@ -21,17 +21,20 @@ import { Callout } from '@/components/docs/prose';