Commit Graph
10244 Commits
Author SHA1 Message Date
Jinwoo-H 0032074fd7 skills: keep only the orchestration guide rewrite in this PR
The seven non-orchestration guide rewrites, the shared stub fragment, and their guards move to a separate PR. The orca-cli cross-guide pin follows the worktree-selector rule into the orchestration placement reference.
2026-09-04 18:17:37 -04:00
Jinwoo-H ff99288d37 Merge branch 'skills-optimization' into orchestration-v3 2026-09-04 17:53:40 -04:00
Jinwoo-H 5bcc79923c skills: spell every invocation ORCA, restore the auth-home rule, restate dense sentences plainly 2026-09-04 17:53:28 -04:00
Jinwoo-H 3ebda3f0b7 skills: reconcile integrated guards, name the emulator_no_active recovery 2026-09-04 17:36:25 -04:00
Jinwoo-H 3753fac07e Merge branch 'skills-fix-env' into skills-optimization
# Conflicts:
#	config/scripts/generate-bundled-skill-guides.test.mjs
#	skill-stubs/orca-per-workspace-env.md
2026-09-04 17:34:30 -04:00
Jinwoo-H fe7d20f569 Merge branch 'skills-fix-linear-emu' into skills-optimization
# Conflicts:
#	config/scripts/generate-bundled-skill-guides.test.mjs
2026-09-04 17:34:01 -04:00
Jinwoo-H e3df3bbfe4 Merge branch 'skills-fix-cli' into skills-optimization
# Conflicts:
#	config/scripts/generate-bundled-skill-guides.test.mjs
2026-09-04 17:33:42 -04:00
Jinwoo-H b087216bcd Merge branch 'skills-fix-orch' into skills-optimization 2026-09-04 17:33:05 -04:00
Jinwoo-H b129932e6d Merge branch 'skills-fix-guards' into skills-optimization 2026-09-04 17:33:05 -04:00
Jinwoo-H a66bd9dc5a docs(skills): split per-workspace-env guide into a kernel plus references
Apply the Change findings from the skill review.

Correctness:
- relayGracePeriodSeconds now states that 0 is unbounded (the relay stays up
  until explicitly terminated) and names the accepted domain, 0 or 60..604800
  from EphemeralVmRecipeSshTargetSchema. Removed from the SSH exemplar so the
  omitted default and a written value cannot disagree.
- The SSH exemplar carries only the required fields. jumpHost/proxyCommand
  exclusivity is stated once, where the choice is made.
- The provisioned-root snippet fetches "$ORCA_REPO_URL", the remote Orca
  resolved the base ref against, not origin.
- portForwards entries name localPort/remoteHost/remotePort and optional label
  against the strict SavedPortForwardSchema.
- The free doctor gate is clear only with no fail and no warn; buildDoctorResult
  leaves ok true with warnings.
- The worked auth check uses the status command's exit code by default via a
  sentinel, since a provider CLI need not propagate a remote exit code. The grep
  recipe stays as the named fallback and matches a shell variable, so no
  pipefail/SIGPIPE hazard remains.

Structure:
- One outcome spine with a joined done bar, and one autonomy envelope replacing
  the four money restatements, the five checkpoint rationales, and Boundaries.
- Quick-start deleted; the numbered sequence is the single copy.
- Kernel keeps what must fire without a read; the four worked examples and the
  failure modes move to skill-guides/orca-per-workspace-env/references/.
- Description replaced with the review's proposal; the ORCA placeholder rule is
  stated once and the Claude Code bang prefix is fenced as a harness adapter.

The generator test's reference assertions are generalized per guide, and the
Vercel name-building pins are repointed to the file that now carries them.
2026-09-04 17:29:44 -04:00
Jinwoo-H 30d8dd6ce8 test(skills): report reference-routing mismatches as text, not arrays 2026-09-04 17:25:19 -04:00
Jinwoo-H 47e5e2ba68 docs(skills): correct linear and emulator skill guides
Emulator: drop the camera-injection verb (it does not exist in
src/cli/specs/emulator.ts), drop iOS permissions (the iOS backend
declares permissions: false so the bridge throws emulator_unsupported),
fix the Android permissions positional order and remove the nonexistent
list op, and delete the stale 'visual pane in development' status and
the 'once the attach/active flow lands' qualifier. State the wrapped-verb
and backend-capability conditions once, add an outcome spine, and drop
the ASCII diagrams and identity prose.

Linear: delete the 27-line Common Commands mirror of --help, replace the
verb-keyed unconfirmed-write rules with the payload-keyed condition that
covers every write verb, add a skill-level done bar for all five
branches, and move examples onto the ORCA placeholder.

All four descriptions rewritten off body-owned detail.
2026-09-04 17:25:06 -04:00
Jinwoo-H dca9336a4a test(skills): guard guide-to-CLI parity, description shape, references, and size 2026-09-04 17:24:12 -04:00
Jinwoo-H 1dabd8724d refactor(skills): single-author the shared discovery-stub blocks
The resolver ladder, the ORCA placeholder rule, the no-guessing paragraph,
and the older-binary fallback frame were authored eight times each and had
already drifted where they were re-copied. Move them into one fragment,
skill-stubs/_shared/cli-resolution.md, and have each per-topic stub mark
where they land with `<!-- shared: <id> -->`.

The projected skills/<name>/SKILL.md is byte-identical for all eight topics,
so no manifest revision moves.
2026-09-04 17:23:29 -04:00
Jinwoo-H 47e3bf4ac1 docs(skills): give orca-cli and computer-use an outcome spine and conditional references
Applies the Change findings from the orca-cli / computer-use skill review.

orca-cli guide:
- Delete the duplicated mobile-emulator tail and the second `Next Action`; the
  emulator now routes through one conditional-references row.
- State the handoff done bar once, and state the `terminal wait` gate with its
  failure direction beside the recipe: `terminal wait` prints an ordinary result
  envelope on timeout and signals the unsatisfied wait only through the exit
  code, so an agent could send a brief into a half-started TUI.
- State the one-agent-handle invariant once in Worktrees; the Terminals copy and
  the two restatements are gone.
- Drop the executable-resolution ladder the discovery stub owns and keep one
  placeholder rule, in the shape `skill-guides/orchestration.md` uses.
- Move the reconstructible command catalogs (browser, automations, artifact and
  skill publishing) behind `skills get orca-cli --full`; the routing paragraph,
  the untrusted-page-content rule and the artifact publish gate stay inline.
- 424 always-loaded lines to 260.

computer-use guide: promote the verification vocabulary to a done bar, and drop
its copy of the resolver ladder.

Repointed the generator's resolver-phrase assertions for these two guides to the
stub projections that now own the ladder, and generalized the bundled-reference
assertions beyond orchestration.
2026-09-04 17:23:11 -04:00
Jinwoo-H 610baee9d4 skills(orchestration): state the outcome spine's consumer and one positive-proof condition
Applies the Change findings from the orchestration skill review.

- Outcome names the next consumer (the requesting user) and the turn-end report
  contract, and states the positive-proof condition once beside Safe failure.
- The three wait/release gates cite that condition instead of carrying divergent
  case lists.
- Drops the kernel's third copy of the worker_done command; the runtime preamble
  owns it at the point of use and worker-contract.md owns it behind the gate.
- Drops messaging-and-gates.md's duplicate coordinator delivery loop block; the
  paragraph below it already states the --terminal delta as a condition.
- worker-start gets an ordered failure hatch naming failedStage and
  residualResources.
- Conditional references describes what --full returns instead of promising
  selective loading; the worker-contract gate row states the condition the kernel
  does not decide.
- Moves the worktree-selector form to placement-and-remote.md, where an exact
  selector is consumed, and aligns worker-contract.md on the kernel's
  capability-first question-TUI wording.

Pins move with the facts: the worker_done flag spellings to worker-contract.md's
recipe case, the worktree-id form to the placement reference.
2026-09-04 17:20:34 -04:00
Jinwoo-H 70b4811267 fix(orchestration): start shipped pre-v32 databases at their own version
The two v32 recovery columns sat in the unversioned post-v6 list, so every
shipped database stamped below 32 failed the completeness check, resolved its
start version to the v6 floor, and replayed the whole chain; on a real v30
profile the v23 resource backfill then synthesized 68 phantom retained workers.
Versioning the entries at 32 starts that database at 30.

Also puts the superseded-Attempt fence back ahead of the pane guard: a paneless
loser cannot run-use either, so the stop signal must win over the rebind advice.
2026-09-04 16:19:20 -04:00
Jinwoo-H b2918cd857 Merge branch 'integrate-final' into orchestration-v3 2026-09-04 16:01:13 -04:00
Jinwoo-H f1e6c0d9e3 fix(orchestration): report a paneless caller before the settled-Attempt fence
The superseded-Attempt fence ran ahead of the stable_pane_required guard, so a
terminal that had only lost its pane binding was told it had been re-attached and
to stop, and lost the run-use recovery data. The fence message and the worker
contract now also cover the no-successor case they already fired on.
2026-09-04 15:59:49 -04:00
Jinwoo-H e443ed63ae Merge branch 'fix-final-surface' into integrate-final
# Conflicts:
#	src/cli/bundled-skill-guides.ts
2026-09-04 15:44:27 -04:00
Jinwoo-H 76060da9d1 Merge branch 'fix-final-projection' into integrate-final 2026-09-04 15:44:16 -04:00
Jinwoo-H dbff4f7d1f Merge branch 'fix-final-dispatch' into integrate-final 2026-09-04 15:44:16 -04:00
Jinwoo-H 4a09ba3ad7 docs(orchestration): say an empty check never means you were replaced
The worker contract calls an empty check a checkpoint rather than a failure, so
a fenced worker had no sentence telling it that consumer_fenced, not silence, is
how it learns the Task moved. Pinned next to the existing consumer_fenced pin.
2026-09-04 15:41:29 -04:00
Jinwoo-H 779dde6eda fix(orchestration): re-read the generation before minting a Delivery
The pre-wait readDelivery used the generation snapshotted at call start with no
re-read, unlike the post-wait guard. A re-attach landing on either await above
it (the direct-mail snapshot route, or the mailbox revalidation) therefore
created a Delivery at the pre-bump generation. Nothing re-fences an outstanding
Delivery except the next re-attach, so from then on the legitimate worker's
getOrCreateMailboxDelivery saw an outstanding Delivery at a generation that is
not its own and threw consumer_fenced on every later check.

Re-read live inside readDelivery, which covers both call sites. Also pins the
three mutants a review sweep found surviving: dropping the post-wait re-read,
and pinning either the local or the federated consumer generation to 0.
2026-09-04 15:41:18 -04:00
Jinwoo-H e2fc063b2f fix(orchestration): tell a superseded worker it lost the Dispatch
After worker-abandon plus worker-start --retry-of onto another terminal, the old
worker's check found no active Dispatch and no bound Run, had a live pane so
stable_pane_required never fired, and fell through to its direct mailbox with
{count: 0}. That is byte-identical to "no mail", which the worker contract calls
a checkpoint rather than a failure, so the loser kept editing files the new
owner now owned until its worker_done was rejected.

A consuming check whose handle's latest Dispatch settled as failed or
circuit_broken now raises consumer_fenced. A completed Attempt is not fenced:
that terminal is free again and may still receive direct mail. Retries need no
separate successor lookup — every settle that makes an Attempt retry-eligible
(abandon, stop, fail) also drives its Dispatch row to failed or circuit_broken.
--peek and --all stay open so the terminal can still inspect its own inbox.
2026-09-04 15:40:41 -04:00
Jinwoo-H ae7b9699e6 fix(orchestration): fence a check whose pane no longer owns the Dispatch
orchestration.check resolved the caller's Dispatch by handle first, so a stale
worker process still holding the row's assignee_handle read and acked the
mailbox of the pane the Dispatch had been re-attached to. The v36 consumer
generation cannot see this: check-worker reads the generation from the live row,
so the loser always presents the current one.

Refuse the mailbox to a caller whose pane is not equivalent to the row's
assignee_pane_key, both where identity is resolved and on the mid-call
revalidation. Every mode is fenced, including --peek: this caller is not the
mailbox's consumer at all, so it must not read the new owner's instructions.
The comparison is skipped when the caller has no pane or the row never recorded
one, and a PTY restart keeps the same leaf id, so a legitimately restarted
worker is still served.
2026-09-04 15:40:02 -04:00
Jinwoo-H a379f65cb9 fix(orchestration): stop a context-only self-dispatch counting as nesting depth
A coordinator that ran dispatch --to its own terminal became its own depth-1
assignee, so every later worker-start from it failed the nesting cap and only an
undocumented worker-abandon restored it. Dispatch rows recorded the assignee but
never the creator, so depth could not tell bookkeeping from delegation; v37 adds
creator_handle/creator_pane_key and a row whose recorded creator is its own
assignee is no longer a nesting parent or a child's creator Attempt. Pre-v37 rows
carry no creator and keep counting. The depth cap also reached the CLI as
runtime_error with its next steps dropped, because its code was missing from the
structured passthrough set.
2026-09-04 15:37:29 -04:00
Jinwoo-H 36685faf86 refactor(orchestration): name the disposed close error once instead of in both predicates
isTransient and isMissing both matched disposed, so the two read as
disjoint while one silently shadowed the other. A disposed endpoint is
genuinely both, and only the host observation decides which; pin the
certified-exit outcome that had no coverage.
2026-09-04 15:36:14 -04:00
Jinwoo-H 2b21ce5ce2 docs(orchestration): enumerate remote workers on the kernel stall path
A coordinator that never loads a reference read unverifiable for every
--on <environment> worker. Fits the existing wrap, so the 202-line budget
is unchanged.
2026-09-04 15:34:26 -04:00
Jinwoo-H 4d36cba55d refactor(orchestration): drop the unused worker terminal resource count
countWorkerTerminalResources has no caller repo-wide, and three exports
were only ever read inside their own module.
2026-09-04 15:34:20 -04:00
Jinwoo-H 118228bc0d fix(orchestration): give the per-pane attention verdict the full liveness subject
The attention context passed no workerStage and no resource releaseState to
projectLiveness, so a released worker's pane could classify live from a
stale agent status while worker-list called the same dispatch exited.
2026-09-04 15:32:59 -04:00
Jinwoo-H 5f92f8c220 fix(orchestration): keep dispatch.task_id on the workerShow receipt
exposeDispatchContext renamed task_id to taskId, and every shipped CLI
prints value.dispatch.task_id, so an older paired CLI against an updated
host printed task=undefined. Publish both spellings. exposeWorker's dropped
columns have no reader in main's src/cli, which reads only state and stage.
2026-09-04 15:30:44 -04:00
Jinwoo-H 8e28b7de61 docs(orchestration): stop the kernel from looping on an informational nextAction
For a healthy in-progress worker the projection returns nextAction
{kind:'inspect', argv:['orchestration','worker-show','--dispatch',<same id>]}
with attention.requiresAction false, and the kernel told the coordinator to
follow the literal argv. Raises the kernel line budget 200 -> 202: the
paragraph had zero slack and no existing guidance was worth cutting.
2026-09-04 15:30:09 -04:00
Jinwoo-H a2796a5b88 fix(orchestration): give federated worker-show the execution host's verdict
projectFleetWorker reads only the local push-fed status snapshot, so a worker
started --on <environment> carried the host's real observation next to a
fabricated projection: unverifiable liveness, host.kind local, and a
worker-show self-loop. Apply the host observation the same way
worker-list --include-remote does, and let the host verdict re-derive
nextAction so a proven remote exit no longer reads as inspect. The federated
branch moves to its own module to stay under max-lines.
2026-09-04 15:27:58 -04:00
Jinwoo-H 2ed2c15e87 fix(orchestration): let worker-start --retry-of resume a context-only attempt
An attempt created by plain orchestration.dispatch has no worker_dispatches row,
so the retry precondition rejected it outright while the same abandon-then-retry
route worked for a worker-start attempt. Abandon leaves both kinds blocked, so
the Task stranded with no route back. The settled check now reads the Dispatch
row when there is no worker row.
2026-09-04 15:26:14 -04:00
Jinwoo-H a4f416f5b4 docs(orchestration): state that --types is a wake condition, not a batch filter
check --types without --wait returned an unmatched type. wakeTypes is an
existence probe in getOrCreateMailboxDelivery; the batch query that
follows has no type predicate, so a Delivery is never filtered. Behavior
is correct; only the guide and --help were silent.
2026-09-04 15:25:13 -04:00
Jinwoo-H cbe2d378fb docs(orchestration): name --include-remote on the guides' enumeration paths
The stall path told coordinators to enumerate with plain worker-list, but
a worker started --on <environment> reads unverifiable without
--include-remote. Also names page.nextCursor for fleets past 100 rows.
2026-09-04 15:24:31 -04:00
Jinwoo-H 8437ae2a99 fix(orchestration): decide a self-targeted --inject dispatch before agent detection
The no-recognized-agent rejection advised dispatching without --inject and
sending the prompt manually, which is exactly what the coordinator guard
forbids, so the same self-target input got opposite instructions depending on
whether an agent happened to be detected in the pane. The coordinator guard now
runs first. The flat dispatch-authority mock in manual-dispatch-observation gave
the coordinator handle the worker's pane, which authority never does per handle.
2026-09-04 15:23:45 -04:00
Jinwoo-H e587416932 fix(orchestration): envelope ask --json like every sibling verb
ask printed a bare {answer, messageId} on success but the standard
{id, ok, error, _meta} on failure, so an agent reading result got
undefined. Routes success through printResult.
2026-09-04 15:22:23 -04:00
Jinwoo-H a16f5c0f2c fix(orchestration): resolve the dispatch self-guard caller pane through dispatch authority
The assignee side of the --inject coordinator guard prefers
getOrchestrationDispatchAuthority().paneKey while the caller side used only
getTerminalPaneKey(), which returns null for a handle whose record carries
another runtime id or that is reachable only through the window-graph leaf. A
legacy-adopted coordinator reaches the guard with callerPane === null, so the
pane arm went inert and an alias handle for the coordinator's own pane took the
injected preamble.
2026-09-04 15:21:59 -04:00
Jinwoo-H 8505079a67 fix(orchestration): drop the worker-show self-loop from a live worker's next action
A live, running worker with nothing pending fell through to the inspect
bucket, so worker-show's own receipt told the coordinator to run worker-show
on the same Dispatch. A healthy running worker owes no next action.
2026-09-04 15:21:55 -04:00
Jinwoo-H c2c242dd8a fix(orchestration): stop certifying an unproven process exit
An unproven stop wrote stage=process_exited with termination_reason=unknown,
and the fleet projection read that stage alone as a death certificate, so
worker-list and worker-show published liveness=exited and nextAction=recover
for a possibly-live agent. Only certify the stage when the cause was observed.
2026-09-04 15:21:13 -04:00
Jinwoo-H 5d3dbfadab feat(orchestration): print the worker-list next action in text output
worker-list is the enumerating command the guides point at, but its text
rows omitted projection.nextAction.argv, so non-JSON callers could not
follow the documented loop. worker-show already prints it.
2026-09-04 15:20:40 -04:00
Jinwoo-H 453f093467 test(orchestration): pin the run receipt internal-column strip
exposeRun had zero coverage: emptying INTERNAL_RUN_COLUMNS left every
suite green. Adds a unit pin on the column set plus an RPC-level pin
through orchestration.runCreate.
2026-09-04 15:19:47 -04:00
Jinwoo-H 9806af4258 Merge remote-tracking branch 'origin/main' into orchestration-v3
# Conflicts:
#	config/scripts/skill-description-length.test.mjs
#	resources/skills/current-manifest.json
#	resources/skills/snapshot-registry.json
#	skill-guides/orchestration.md
#	skills/orchestration/SKILL.md
#	src/cli/bundled-skill-guides.ts
2026-09-04 14:28:08 -04:00
Jinwoo Hong 3e4fd4a7af Shorten orchestration skill description under the Agent Skills 1024-char limit (#18683)
* Shorten orchestration skill description under the Agent Skills 1024-char limit

The folded description was 1038 chars, so spec-conforming installers such
as SkillStar rejected the bundled orchestration skill. Drop the two clauses
already covered elsewhere in the same description: "decomposing work across
agents" (implied by "structured multi-agent coordination") and "automation
of the browser embedded inside Orca" (restated by the locked `orca-cli`
embedded-pages sentence). Every routing trigger asserted by
orchestration-skill-guidance.test.mjs, the orca-cli handoff boundary, and
the Computer Use boundary are unchanged. Result: 958 chars.

Add config/scripts/skill-description-length.test.mjs, which parses every
skills/*/SKILL.md frontmatter with `yaml` and fails on an empty or >1024
char description, so the regression cannot return. orca-cli sits at 1015
and is left as is.

Fixes #17935

* Keep the embedded browser in the orchestration description's orca-cli routing

Restores the word "browser" in the orca-cli sentence ("and the Orca embedded
browser") so agents scanning for it still route embedded-browser control to
orca-cli. Description is 985 chars, 39 under the spec limit.
2026-09-04 14:27:07 -04:00
Jinwoo-H d571ab154f docs(orchestration): tell a fenced worker to stop instead of retrying check 2026-09-04 14:09:48 -04:00
Jinwoo-H 04ce320e58 test(orchestration): assert takeover pane binding on the Run row, not the receipt 2026-09-04 14:09:08 -04:00
Jinwoo-H 4eb6ae1bc5 Merge branch 'w4-fencing' into orchestration-v3 2026-09-04 14:06:52 -04:00
Jinwoo-H aaafdd4710 test(orchestration): pin dispatch mailbox consumer fencing
10 of the 11 cases fail on 11ff626467; the survivor is the restarted-worker case the constant was protecting.
2026-09-04 14:05:53 -04:00