Adds Command Code hook installation, status normalization, launch seeding, and terminal-output fallback detection for working/done sidebar status. Includes review hardening for long-running tool repaint cadence and prompt sanitization across split ANSI chunks.
Reverts the hidden terminal pressure changes from #2661 to restore the prior terminal rendering path while the fullscreen TUI regression is handled separately.
* Surface dev-server URLs in workspace ports panel
Why: the OS scanner only sees `127.0.0.1:3001`, so clicking a Vite
port in the panel opens the wrong host/protocol when the dev server
binds with a custom hostname or HTTPS (e.g. `https://local.getmontecarlo.com:3001/`).
We now watch PTY output for advertised origins and prefer them at
display, copy, and open time. Falls back to the OS-derived address.
The watcher taps the central `runtime.onPtyData` path so it sees local,
daemon-backed, and SSH PTYs uniformly. URL candidates are validated with
`new URL()`, sanitized to origin only (no path/query/fragment/userinfo),
and gated by listener-PID validation so stale entries get evicted when
a different process reuses the port.
SSH `DetectedPort` enrichment is out of scope here — that panel uses
separate data shapes and port-forwarding may rewrite the local port,
making naive URL reuse incorrect. Tracked as a follow-up.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Extend advertised-URL enrichment to SSH ports
Why: the first cut only enriched the local workspace ports panel. SSH
worktrees use a separate panel with `DetectedPort` and `PortForwardEntry`
shapes scanned by the remote relay, so the same dev-server banners that
flow through Orca's SSH PTYs were captured by the watcher but never
surfaced.
The renderer-side SSH scanner doesn't know which worktreeId the watcher
keyed an entry under, so a small helper walks the store to find every
worktree attached to a given connection and asks the watcher for the
best match per port (custom DNS host > loopback > LAN IP, https and
recency as tie-breakers). Enrichment runs at every broadcast and list
site in src/main/ipc/ssh.ts.
For a forwarded SSH port, the open action now uses
`advertisedProtocol://customHost:localPort`. We deliberately reuse the
local forward port — the remote port number is not reachable from the
local machine — and we only reuse the host when it's a custom DNS name
(IP literals and the remote's `localhost` get ignored, falling back to
127.0.0.1 like before). Loopback advertisements from the remote box are
a no-op because they don't translate to the local browser.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Address Codex review of advertised-URL enrichment
Four findings from the post-implementation review:
- Watcher rejects wildcard advertised hosts (`0.0.0.0`, `::`, `*`). The
OS scanner already normalizes wildcards to localhost for the connect
host; if a dev server prints `http://0.0.0.0:3000/` verbatim we keep
that sensible default instead of letting the watcher overwrite it
with a host the browser can't open.
- Pre-bind pending buffer is now capped at 32 distinct PTY IDs with
LRU eviction. Spawn-failure paths could otherwise leave never-bound
entries forever — per-PTY 16 KiB bound was the only guard.
- `clearProviderPtyState` now calls `advertisedUrlWatcher.unbindPty`.
SSH reattach failures, `clearPtyOwnershipForConnection`, and daemon
spawn-failure cleanup bypass `runtime.onPtyExit`; routing through the
central provider teardown plugs those holes (and is idempotent with
the existing `onPtyExit` hook for natural exits).
- `lookupBest` accepts an optional current listener PID and runs the
same pin-then-evict logic as `lookup`. `enrichSshDetectedPorts`
threads `DetectedPort.pid` through so a stale advertised URL gets
evicted on remote port reuse. Forward enrichment stays best-effort
(forwards are persisted config, not observed listeners — detected
enrichment is the eviction path).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix: refresh SSH ports when advertised URLs change
Co-authored-by: Orca <help@stably.ai>
* fix: show advertised URLs in port rows
Co-authored-by: Orca <help@stably.ai>
* fix: address advertised URL review issues
Co-authored-by: Orca <help@stably.ai>
* fix: tighten advertised URL cache handling
Co-authored-by: Orca <help@stably.ai>
* fix: align advertised URL edge cases
Co-authored-by: Orca <help@stably.ai>
* fix: handle advertised URL cache invalidation
Co-authored-by: Orca <help@stably.ai>
* fix: show status port action tooltips
Co-authored-by: Orca <help@stably.ai>
* fix: keep port action tooltips above popover
Co-authored-by: Orca <help@stably.ai>
* fix: clear port action focus after click
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
Co-authored-by: Orca <help@stably.ai>
* fix: address pr-bug-scan validated finding from #2504
Narrowed App.tsx early return so it only suppresses chords the floating panel actually claims (Cmd+T/W, Cmd+Shift+B/M); B/L/Shift+E/F/G now reach app branches.
* Let floating terminals receive shell control chords
- Track floating xterm focus in the main process so Ctrl+B/Cmd+B and
sidebar-adjacent chords can pass through to SSH and tmux
- Share renderer shortcut targeting logic for floating panel shortcuts
- Cover focus routing and shortcut ownership with tests
---------
Co-authored-by: orca-bug-scan-bot <orca-bug-scan-bot@stably.ai>
Co-authored-by: Jinjing <6427696+AmethystLiang@users.noreply.github.com>
- Use fallback PR numbers after branch lookup misses, including detached HEAD
- Preserve review cards for forked or deleted-head PRs across manual refreshes
- Clear stale GitHub PR cache entries when unlinking worktree review metadata
* feat: add GitLab Issues tab and workspace creation for issues/MRs
- Extend TaskPage GitLab section with Issues | MRs tabs (outside card)
plus a repo selector via RepoMultiCombobox, matching the GitHub UX.
- Add separate IPC paths: listIssues (with "Assigned to me" filter)
and listMRs (with Open/Closed/Merged/All filters).
- Add "Start workspace" (→) button to every GitLab row and
"Create workspace" action inside GitLabItemDialog for both issues
and MRs.
- Extend CreateWorktreeArgs / worktree.create RPC to accept
linkedGitLabMR and linkedGitLabIssue, and wire them through
the runtime, IPC, preload, and renderer store slices.
- Fix self-hosted GitLab support by falling back to glab CLI
(issue view / mr view / issue list / mr list) when the remote
host is not in getGlabKnownHosts().
- Update useComposerState to initialise GitLab-linked context
from initialLinkedWorkItem.
* Remove logs
* fix: address GitLab issues review findings
---------
Co-authored-by: Neil <4138956+nwparker@users.noreply.github.com>
- Fix workspace space cache and git status cleanup checks
- Treat browser tabs as workspace delete blockers
- Move deletion readiness into shared presentation logic so tests cover it
- Preserve explicit empty git status entries for clean worktrees
- Add package manager cache cleanup to space manager
- Detect npm, pnpm, Yarn, and Bun caches from lockfiles during scans
- Add explicit cleanup IPC for safe and aggressive cache actions
- Support local, SSH, and Windows command execution paths safely
- Tighten workspace deletion decisions with git, editor, agent, and terminal state
* Create PRs directly from Source Control
- Replace the modal flow with an inline PR composer in the sidebar
- Keep PR creation state and validation scoped per worktree
- Rename the recovery action to clarify it only pushes before creating PRs
* Clean up fork PR remotes after worktree deletion
- Track Orca-created push target remotes in worktree metadata
- Reuse ownership markers when later worktrees share the same fork remote
- Fetch only the selected PR base instead of every remote before drafting PRs
- Mirror local branch cleanup for SSH worktree deletion
* Stabilize pull request creation flow
- Keep PR actions and composer fields locked while generation or creation is in flight
- Refresh git status, branch comparison, and history after remote actions settle
- Disable push-only actions on diverged branches so users sync first
* Make PR context generation read-only
- Stop rebasing or probing HEAD before collecting PR draft context
- Allow git operations on known repo roots without refreshing worktree cache
Co-authored-by: Orca <help@stably.ai>
* fix: address review findings
---------
Co-authored-by: Orca <help@stably.ai>
* feat: add notification sound volume slider
Custom audio files vary widely in loudness; the new 0-100% slider in
Settings → Notifications lets the user lower an over-amplified sound
without re-encoding the file.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* fix: harden notification sound volume setting
---------
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Co-authored-by: Neil <4138956+nwparker@users.noreply.github.com>
* Squashed commits
- WIP: uncommitted changes before rebase
- ci
- Show inline PR check details in task drawer
- Add a Checks tab that opens from the PR checks cell and expands runs inline
- Fetch check output, annotations, and workflow job steps through IPC/RPC
- Improve markdown/comment wrapping so long PR content stays within the drawer
* Use app-styled confirmations for PR actions (#2324)
Co-authored-by: Orca <help@stably.ai>
* fix: pr-bug-scan validated finding from #2274 (#2296)
Co-authored-by: orca-bug-scan-bot <orca-bug-scan-bot@stably.ai>
---------
Co-authored-by: Jinwoo Hong <73622457+Jinwoo-H@users.noreply.github.com>
Co-authored-by: Orca <help@stably.ai>
Co-authored-by: buf0-bot[bot] <252831055+buf0-bot[bot]@users.noreply.github.com>
Co-authored-by: orca-bug-scan-bot <orca-bug-scan-bot@stably.ai>