The inline AI-note draft card in the diff view used a fourth, hand-rolled
box-shadow tier with raw rgba values instead of the documented shadow-xs
token, so it didn't track theme/token updates like the rest of the UI.
Restated the value under `.dark` too, since it shares selector specificity
with `.orca-diff-comment-popover`'s dark shadow later in the file and would
otherwise lose the cascade to that unrelated rule.
* fix(kimi): don't crash if config.toml is deleted mid-write
writeConfigToml checked existsSync(configPath) then called statSync(configPath)
to preserve the file's mode, with no error handling in between. If the file
was deleted in that window (e.g. a concurrent uninstall), statSync threw
ENOENT and the exception escaped install()/getStatus() uncaught.
Now a missing-file stat during that race is treated the same as a missing
file at the check: fall back to the default 0o600 mode and continue the
write. Any other stat error still throws, preserving the existing
mode-read-failure behavior.
* fix(kimi): use isDefinitiveAbsence for the config delete-race check
Reuse the repo's canonical absence check instead of a hand-rolled ENOENT
comparison, per review feedback on #23293. isDefinitiveAbsence also covers
ENOTDIR (an ancestor directory replaced by a file), which the inline check
missed but is equally "the config is definitively not there."
* perf: avoid rescanning partial notebook output frames
* perf(notebook): stream bridge frames and skip the unused size accounting
The reader buffered every record of a chunk before delivering the first one, and
asked the framer for byte accounting it can never use. An unbounded line limit
cannot reject, so the per-segment `Buffer.byteLength` and the rejection-prefix
retention were pure overhead for the notebook and Codex readers; both are now
skipped once, behind a hoisted check. Frames are handed to the consumer as each
line completes, so the first output of a chunk paints without waiting for the
last.
The dropped buffer only ever preserved a trailing partial record across a
consumer throw, which cannot help: that throw leaves the stdout 'data' listener
and takes main down with it. Rejections are no longer discarded either — the
bridge keeps fd 1 to itself, so an unreadable line means the frame channel is
damaged and now says so.
Tests move into notebook-kernel.test.ts beside the reader's existing coverage,
and add the never-terminated record and a guard that no record bytes are
measured when no limit applies.
Co-authored-by: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
The WSL "is this path gone?" probe decided a path was missing by matching
GNU coreutils' exact wording, `stat: cannot statx ...`. BusyBox writes
`stat: can't stat ...`, so on an Alpine-style distro a successful orphaned
worktree delete was still reported as a permanent failure, on every retry.
Match only the trailing strerror text, which is POSIX and already pinned to
English by the probe's LC_ALL=C. Permission failures still report failure.
* perf: bound wildcard segment work in nested repository scans
* perf: bound the ** path walk in nested repository scans, not just one segment
The wildcard-segment fix left the larger blowup in place. A short .gitignore line
made only of `**` segments still costs exponential work in the outer path walk:
`**/**/.../z` at 24 segments and 73 characters, against an eight-segment
candidate, takes about 49 million recursive calls and ~150 ms here — larger than
the 25 ms single-segment case this branch removes. Rules are inherited down the
tree and re-checked for every directory, so that price is per directory, the
runtime's 15s scan timeout fires, and the user silently gets a short repo list.
Two independent bounds, both kept:
- `**` spans zero or more segments, so `**/**` accepts exactly what `**` accepts.
Parsing now collapses a run of them to one segment, taking the reported shape
from 49M recursive calls to 26 matcher steps.
- The walk memoizes on (pattern index, candidate index), so no other arrangement
of `**` can reintroduce the blowup. A rule holding at most one `**` is already
linear and skips the table, because allocating it costs more than the walk it
would save on the shapes real ignore files contain.
The budget suite's process-CPU ceiling is replaced by a matcher step counter read
through `readNestedRepoGlobMatchSteps`, so an algorithmic regression fails the
suite rather than passing on a fast machine. Each bound has its own budget case,
and each fails when only the other is applied.
The equivalence oracle now also covers multi-segment and anchored patterns
including `**`, checked against the pre-change per-segment expression walking
uncollapsed segments. Code-unit and metacharacter cases are unchanged.
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
Replace the copy-a-command startup dialog for diverged JSON/SQLite profile
state with Use SQLite / Use JSON buttons. The choice relaunches Orca into the
locked recovery preflight, applies it, then starts normally. Adds a
current-sqlite recovery selector (and --current-sqlite CLI flag) that archives
the diverged JSON and republishes it from SQLite.
Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
* perf(relay): release canceled AI Vault startup requests
* test: pin the historical hourly package version fixture
* test: provide the historical package version through build options
* test(ai-vault): cover delayed readiness rejection across restart
* perf: stop scanning shared paths when suggestions are full
* fix(i18n): restore diff note draft catalog entries
* fix(windows): synchronize native terminal table lifetime
* fix: restore catalog entries required by the current CI baseline
* fix(i18n): make AI the recipient of diff notes
* fix(ci): preserve focused Playwright file selection
* test(ci): require focused commands on every platform
Assert each golden platform step and its focused arguments before deduplicating Playwright discovery probes.
* test: pin the historical hourly package version fixture
* test: provide the historical package version through build options
* test(windows): retain PTY stress failure evidence
---------
Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
* fix(ssh): suppress workspace echoes acknowledged during stale reads
* fix(ssh): preserve newer workspace observations during resync
* fix(ssh): retain newer own acknowledgements during stale reads
* fix(ssh): deliver peer snapshots cached by rejected patches during stale reads
A stale-revision patch reply caches the peer snapshot under a new host
observation token, but the renderer only records a conflict and blocks
uploads. Suppressing an identical stale read then left the peer change
unapplied. Only suppress when the intervening write kept the pre-read
token, which is what a contiguous own acknowledgement does.
---------
Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
* test(persistence): start the fault timer after the real worker is ready
* test(orcad): preserve launcher startup phase evidence on timeout
* test: isolate historical hourly build version inputs
* test: align historical package input with shared CI repair
* test: inject hourly package version without module mocking
* test: share the hourly package input contract across CI repairs
---------
Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
* fix: close abandoned static web readers and align AI note labels
* test: pin the historical hourly package version fixture
* test: provide the historical package version through build options
* fix: cancel abandoned relay searches
* fix: restore catalog entries required by the current CI baseline
* fix(i18n): make AI the recipient of diff notes
* fix(windows): ship the process-table addon to the relocated daemon host
The Windows terminal daemon runs from a copy of the app under
%LOCALAPPDATA%\Orca\daemon-host\<version>. That copy took node-pty but not
@vscode/windows-process-tree, so the daemon's bare require of the addon found
nothing and every process-table read (foreground tracking, descendant sweeps)
fell back to a powershell.exe Get-CimInstance scan (#16905).
- Copy the addon's runtime files (package.json, lib/, the .node binary) into
the host; the ~25MB of gyp intermediates beside them are filtered out.
- Treat a host missing those files as unmaterialized, so hosts built before
this are rebuilt, and skip relocation if the install itself lacks them.
- Log the daemon's native/CIM capability at startup and warn once when the
process table falls back to CIM.
Revives #19525 on current main.
* test(windows): locate update-survival loss before relaunch
* test(windows): preserve daemon tree before update-survival proof
* test(windows): distinguish Electron exit from launcher close timeout
* test(windows): verify process exit when inherited pipes delay close
* test(windows): trace installer process checks in isolated survival runs
* fix(windows): probe process-query capability before installer sweep
* fix(windows): match installer probe and process-check profile behavior
* fix(windows): use NSIS separators for the process-check include
* test(windows): dismiss session-search overlay in survival harness
---------
Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
Toolbar buttons fold into a dropdown menu when space is constrained,
preserving minimum address bar width. ArtifactPublishButton gains
controlled popover state with optional virtual anchoring. Tour-pinned
tools stay visible while others fold in priority order.
* fix: release dictation session listeners when speech workers exit
* fix(i18n): restore diff note draft catalog entries
* fix(i18n): make AI the recipient of diff notes
* test(persistence): start the fault timer after the real worker is ready
---------
Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
Co-authored-by: OrcaWin <alpha-eng@stably.ai>
* docs: clarify native chat document ownership
* fix: restore catalog entries required by the current CI baseline
* fix(i18n): make AI the recipient of diff notes
* fix: fence callbacks from retired emulator streams
* fix: restore catalog entries required by the current CI baseline
* fix(i18n): make AI the recipient of diff notes
* fix: observe abandoned linked-issue lookups on desktop and runtime
* fix: restore catalog entries required by the current CI baseline
* fix(i18n): make AI the recipient of diff notes
* fix(i18n): restore diff note draft catalog entries
* fix(i18n): make AI the recipient of diff notes
---------
Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
Co-authored-by: Neil <neil@stably.ai>