Fixes#6619: OMP-owned remote/mobile terminals no longer flicker their tab
label between "OMP" and "Pi".
OMP wraps Pi, so it emits Pi-identity OSC titles and status frames during
active work. On the host, in mirrored remote tabs, and in the title-derived
sidebar rows, those frames were stored verbatim — so an OMP-launched pane
alternated between "OMP" (launch identity) and "Pi" (live frame). The fix
introduces a shared owner-normalization helper (agent-title-owner.ts) that
rewrites Pi-compatible titles/status entries to the authoritative launch
owner, but only when the incoming and owner profiles share the same
titleIdentityGroup — so true Pi sessions, unrelated agents, and custom titles
are left untouched.
Maintainer hardening on top of the original change:
- Skip the new getForegroundProcess probe entirely when launchAgent is already
known (it is only ever the owner fallback when launchAgent is unknown), and
gate the onPtyData trigger on a real status transition rather than per-frame
braille-spinner title churn — avoiding a relay round-trip per output frame on
SSH/daemon-backed terminals.
- Make the foreground refresh fire-and-forget on the mobile listing hot path
(listTerminals/getWorktreePs) so latency does not grow per session and a
throwing snapshot listener cannot abort the liveness sweep.
- Added regression tests + a Why comment on the renderer owner precedence.
Verified: 829 tests pass; node/web/cli typechecks clean; oxlint clean;
reproduced the flicker against main as a negative control and confirmed the
live renderer build collapses interleaved OMP/Pi frames to a stable OMP label
with zero Pi leaks while leaving true-Pi/unrelated/custom titles unchanged.
Co-authored-by: Dvitash <dvitash3414@gmail.com>
* Gate punctuation forwarding on input source feature
Ensure ASCII and CJK direct punctuation keys are only treated as keydown
candidates if `forwardAsciiPunctuation` is enabled in the current input
source features. This avoids forwarding punctuation when the feature is
disabled, satisfying requirements where certain input methods (such as
Vietnamese) should not have punctuation forwarding enabled.
* Fix macOS IME input mode detection
Previously, the terminal IME workaround only forwarded punctuation for
macOS CJK input methods. This generalizes the system into a native text
forwarder that also handles:
- Short text replacements for Vietnamese input methods (Telex, VNI).
- Synthesized Unicode inputs with unreliable physical key metadata.
This prevents xterm's kitty keyboard protocol from encoding and
canceling these keydowns before the native glyphs can be committed.
The rich markdown editor rebuilt the entire Table-of-Contents outline on
every content change by running a full-document remark parse
(buildMarkdownTableOfContents), then discarded the result whenever the TOC
panel was closed — which is the default state. The parse is driven by the
300ms-debounced serialize path, so it fired ~3x/sec during sustained typing,
with cost scaling linearly with document size.
Gate the memo on showTableOfContents so the parse only runs when the panel is
actually open. Including showTableOfContents in the deps rebuilds the outline
the moment the panel opens, so there is no stale TOC.
Benchmark (config/scripts/markdown-toc-parse-benchmark.mjs), per content
change while typing:
175 KiB doc / 200 headings -> ~65 ms median (13.2 s cumulative over a
~1 min typing burst)
351 KiB doc / 400 headings -> ~138 ms median (27.8 s cumulative)
With the fix this drops to ~0 ms while the panel is closed.
Adds a unit test proving the parse is skipped (and a stable empty-array
reference returned) while closed, and still runs when open.
Co-authored-by: Orca <help@stably.ai>
Opening a file to edit on a remote SSH host could fail with "Access denied: path resolves outside allowed directories" and stay stuck. Right after a session restore the SSH repo has not hydrated, so the owner lookup returns undefined ("owner unknown"); the editor treated that like null ("local") and read the remote path off the local filesystem, then the retry gate excluded "access denied" so the error latched permanently.
Distinguish "owner not yet known" from "definitely local": when the worktree's backing repo has not hydrated, fail with a retryable owner-not-ready error instead of a local read, and retry it on a steady cadence bounded to ~2 min. If the host never connects, surface a truthful terminal message with a Retry button rather than retrying forever; a successful read at any point recovers immediately. Hydrated local repos resolve to null and are unaffected. The defect is platform-agnostic; Windows just surfaces the race most often.
Closes#6648
* docs: add Android emulation design spec
Adds the design for first-class Android emulator support as a cross-platform
peer of the iOS simulator feature: an extracted EmulatorBackend interface
(iOS + Android), full AVD lifecycle management via the Android SDK, a live
scrcpy H.264 pane decoded in-renderer with WebCodecs, the full control surface
(tap/gesture/type/buttons/rotate), accessibility tree, app install/launch,
runtime permissions, logcat, and a dedicated orca-emulator-android skill.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* refactor(emulator): add EmulatorBackend interface + backend/codec session tags
First step of multi-backend emulator support: introduce the EmulatorBackend
type and tag each session with its backend kind + stream codec, defaulting to
ios/mjpeg so existing serve-sim behavior is unchanged.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* refactor(emulator): extract IosEmulatorBackend and make the bridge a router
Move the serve-sim/simctl device + helper + input mechanics out of
EmulatorBridge into IosEmulatorBackend (implementing EmulatorBackend). The
bridge now owns the session registry and lifecycle orchestration and routes
each command to the backend that owns the target device. iOS behavior is
unchanged; the existing bridge tests pass untouched and the backend gains its
own input-op coverage.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(emulator): add pure Android leaf modules (sdk/adb/avd/scrcpy/input/ax)
Dependency-injected building blocks for the Android emulator backend, each unit-
tested in isolation: SDK + tool discovery, adb device/output parsing, AVD list +
boot arg building, scrcpy control-socket byte encoders, normalized<->pixel +
keycode mapping, and a uiautomator XML accessibility-tree parser. Not yet wired;
AndroidEmulatorBackend composes these in the next phase.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* refactor(emulator): gate availability on the iOS backend + lock it with tests
inspectEmulatorAvailability now decides iOS host support via the registered iOS
backend instead of a bare platform literal, routing the decision through the
multi-backend seam. Output shape and all messages are unchanged (the settings
pane still reads simctl/serveSim). Adds the previously-missing regression tests
covering the unsupported, ready, no-devices, and tool-failure paths.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(emulator): add Android app/permissions/logcat arg builders
Pure adb arg-builders + a logcat line parser for app install/launch, runtime
permission grant/revoke/reset, and logcat capture. Unit-tested in isolation;
wired into AndroidEmulatorBackend's capability verbs in a later phase.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(emulator): AndroidEmulatorBackend device management + unified device list
Adds the Android backend (registered alongside iOS in the bridge): SDK-gated
host support, device/AVD discovery and merge, AVD boot + boot-completion wait,
shutdown, and tap/swipe/type/button/rotate/exec via `adb shell input` so control
works without the scrcpy server (the live H.264 stream lands in the streaming
phase). Surfaces everything through a new cross-platform `orca emulator devices`
command (RPC emulator.listDevices -> bridge.listAllDevices) with a platform
column. Device inventory is split into its own module to keep files focused.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(emulator): Android capability verbs (install/launch/permissions/ax/logcat)
Wires the Android capability operations into AndroidEmulatorBackend and exposes
them through a capability-gated bridge router (runCapability), RPC, and CLI:
- orca emulator install/launch/permissions/ax/logcat
Capabilities are advertised per backend; calling one on a backend that lacks it
(e.g. iOS) fails with emulator_unsupported instead of a silent no-op. Input ops
and capability ops are split into focused modules to keep files under the
line cap; the runtime shares one target-param type.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* docs(skill): add orca-emulator-android skill + cross-ref from iOS skill
Documents the cross-platform Android emulator control surface (devices, input,
hardware buttons, rotate, install/launch, permissions, ax, logcat) driveable via
the orca CLI today, and notes the live visual pane is in development. Points the
iOS skill's "when not to use" at the new Android skill.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(emulator): Android live-pane streaming scaffolding (scrcpy + WebCodecs)
Builds the H.264 video path as scaffolding: scrcpy frame/codec-meta parsing,
server-deploy arg builders, control-protocol encoders (committed earlier), the
stream session (server + sockets), a video pub/sub registry, the
emulator:videoStream* IPC channel, and a renderer WebCodecs->canvas hook. Pure
framing/deploy/registry are unit-tested; the socket/WebCodecs/jar integration is
clearly flagged UNVERIFIED and the remaining wiring (startSession, preload,
pane codec branch, packaging the jar) is documented in
docs/android-emulation-streaming.md.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* docs: fix streaming notes doc path in video-stream hook comment
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* chore(emulator): add diagnostic probes for Android testing
Adds an emulator-probe logger (console + temp file at
os.tmpdir()/orca-android-emu-probe.log) and wires probes at four layers so
errors surface during manual testing: every emulator.* RPC call + error (RPC
dispatcher), every adb/emulator command + non-zero exit (command runner), and
the scrcpy session + video-stream IPC lifecycle. Temporary diagnostics; remove
or gate behind a flag once the Android pane is validated.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(emulator): show Mobile Emulator settings cross-platform + aggregate Android availability
The Mobile Emulator settings section is no longer macOS-gated (Android works on
Windows/Linux), and inspectEmulatorAvailability now aggregates the iOS and
Android backends: Android devices/AVDs appear in the device list and a host
without iOS gets the Android setup message instead of "requires macOS".
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): show Mobile Emulator sidebar nav entry on non-mac desktops
The settings sidebar nav registered the Mobile Emulator entry behind isMac, so
it stayed hidden on Windows/Linux even after the section content was ungated.
Widen it to showDesktopOnlySettings to match the section.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(emulator): wire Android startSession to scrcpy + client-downloaded jar
AndroidEmulatorBackend.startSession now boots the device, ensures the scrcpy
server jar (downloaded by the client into the per-user cache on first use, not
bundled), starts a ScrcpyStreamSession, and feeds its H.264 frames to the video
registry; stopHelperForDevice tears it down. Sessions carry their backend kind
so worktree-active routing picks the right backend. Boot, host SDK discovery,
and the stream starter are split into focused modules to stay under the line cap.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): stop the iOS backend from claiming Android devices off-mac
iOS ownsDevice now returns false unless the host supports it, so on Windows an
Android serial routes to the Android backend instead of erroring with
"requires macOS". Backend-for-device fallback prefers a host-supported backend.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): scrcpy scid 31-bit + retry video socket until server delivers
Two fixes validated against a real emulator: scrcpy parses scid as a signed
32-bit hex int, so mask to 31 bits + pad to 8 digits (8-byte values overflowed
and the server exited). And adb accepts the forwarded TCP connection before the
server's abstract socket exists then resets it, so retry the video socket until
it actually delivers the dummy byte before connecting control. H.264 meta now
arrives (576x1280). Adds socket/server-exit diagnostics probes.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(emulator): render the Android H.264 pane via WebCodecs
Wires the live Android pane end-to-end: preload exposes emulator video stream
APIs; the pane's device list uses the unified emulator.listDevices (Android +
iOS); and emulator-screen-stream-content renders a WebCodecs <canvas> for
scrcpy:// sessions (H.264, SPS/PPS prepended to the first keyframe) instead of
the MJPEG <img>. The video hook reports the stream size for the device frame.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(emulator): buffer the current GOP for late video subscribers
The renderer subscribes after attach already started the scrcpy stream, so the
registry now caches the current GOP (keyframe + following deltas) alongside the
codec meta and config, and replays it on subscribe. A pane opened mid-stream
decodes from the keyframe immediately instead of showing black until scrcpy's
next periodic keyframe (~10s). Refreshes the now-validated session doc comment.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): show New Mobile Emulator tab action off macOS
The tab create menu and its dropdown item gated the New Mobile Emulator action
on isMacOs, hiding it on Windows/Linux where Android emulation is now supported.
Gate on mobileEmulatorEnabled + onNewSimulatorTab (already cross-platform) so
the action appears wherever a mobile emulator backend is available.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): open the Mobile Emulator tab off macOS
openMobileEmulatorTab and ensureSimulatorTab both returned null unless the host
was macOS, so the New Mobile Emulator action no-opped on Windows/Linux even
though the menu entry showed. Drop the isMacOsHost early-returns; the
mobileEmulatorEnabled setting and backend availability already gate the feature.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): resolve a default attach device across backends
emulatorAttach with no device fell back only to the iOS listSimulators picker
(empty on Windows/Linux), so the pane's no-device launch flow errored. Extract
resolveDefaultAttachDevice: iOS default first, else the first booted (else
first) device across host backends, so Android attaches without an explicit
device. Split into its own module to stay under the line cap.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): render the pane off macOS instead of an unavailable wall
EmulatorPane short-circuited to the "macOS only" EmulatorUnavailablePane on any
non-Mac host, blocking the now-working Android pane. Always render the pane
content; its device discovery and error surface handle a missing backend.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): let attach boot a shut-down AVD with a stale active session
getReusableActiveForWorktree called resolveDeviceId on the requested device,
which throws for a not-yet-booted Android AVD, aborting the attach. Guard it so
a resolve failure means "not the active device" and the attach falls through to
a fresh boot — so picking a shut-down AVD in the pane and hitting Connect boots
it via ensureBooted instead of erroring.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): launch the AVD detached instead of via execFile
bootAndroidDevice started the emulator through the command runner (execFile with
a timeout + 1MB stdout maxBuffer), which kills the long-running, verbose emulator
process — so booting an AVD from the pane never actually came up. Spawn it
detached with no stdio and unref it so it outlives the call, mirroring how the
scrcpy server is launched.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): dedupe concurrent attaches into one scrcpy stream
Extract AndroidStreamController to own the per-serial scrcpy lifecycle and
dedupe starts: concurrent attaches (e.g. the pane's auto-attach racing the tab
launch) now share one in-flight start and reuse the live stream instead of
spawning a second scrcpy server that fights for the port and kills the first.
Also initialize the registry GOP buffer in register() (latent type error).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): boot the AVD headless without a console window
The detached spawn opened a Windows console (showing the emulator's verbose
qemu/netsim logs) and a redundant native emulator window. Pass windowsHide and
run the emulator with -no-window so it boots headless — the scrcpy pane is the
view, matching how iOS hides Simulator.app.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): boot the AVD with a hidden console, not detached
detached: true sets DETACHED_PROCESS, which gives the console-subsystem emulator
no console — so it and its qemu/netsim children pop their own visible cmd window
that windowsHide can't suppress. Drop detached and rely on windowsHide
(CREATE_NO_WINDOW = hidden console) + unref; spawn already keeps it alive past
the launch call, and managed emulators are shut down on app quit.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): keep Android emulators alive when switching devices
Attaching a different device shut down the active one (shutdownDevice: true),
which for Android meant killing the running emulator and cold-booting the target
(~60s) on every switch — and switching back. Add bridge.stopActiveForSwitch:
Android emulators stay running for instant switch-back, while iOS simulators are
still replaced. Switching to an already-running emulator is now immediate.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* perf(emulator): only resize the video canvas when dimensions change
The decoder output handler set canvas.width/height on every frame, which
reallocates the canvas backing store and forces an object-contain reflow each
frame — a needless per-frame cost. Resize only when the frame dimensions
actually change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(emulator): genericize copy + add Android Studio setup link
Replace iOS-only wording (Xcode/Simulator/iPhone) in the pane and settings with
backend-neutral copy so Android reads correctly on every platform. When no
emulator is available, the Mobile Emulator settings now show a "Download Android
Studio" link plus setup guidance (ANDROID_HOME / default install path). Removes
the now-unused, macOS-only EmulatorUnavailablePane.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(emulator): show emulator SDK status in settings
The backend availability now reports the resolved Android SDK path, aggregated
into emulator.availability as an `android` block. The Mobile Emulator settings
render an "Emulator SDKs" card showing Android SDK (detected at <path> / not
found, with a Download Android Studio link) and, on macOS, iOS Simulator (Xcode)
status — mirroring the agent-control card.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(emulator): locate a custom Android SDK folder from settings
Add an androidSdkPath setting and a "Locate SDK folder…" / Clear action in the
emulator SDK status card. The path is applied as the highest-priority discovery
candidate (falls back if invalid), and the backend's SDK is re-resolved on use
via a new AndroidSdkState — so locating or installing the SDK takes effect on
Refresh without restarting Orca. Guards the status card against older runtimes.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): settle the scrcpy video socket once to stop retry storms
A failed TCP connect emits both 'error' and 'close', so retry ran twice and
scheduled openVideoSocket(attempt+1) twice — fanning out into an exponential
connection storm while waiting for the server to start listening. A runaway
chain could then hit attempt 100 and fail/close a stream that had already
connected. Replace the delivered flag with a single settled latch so each
socket retries (or delivers) exactly once.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): address CodeRabbit review findings
- avd-boot: handle spawn 'error' (an unhandled ChildProcess error crashed the
main process); validate the target is a known AVD before launching.
- capability-ops: propagate adb non-zero exits for launch/permission/logcat and
check the uiautomator dump before reading (avoids stale XML).
- scrcpy-video-registry: actually replay the buffered GOP on subscribe so late
subscribers decode immediately.
- android-sdk-state: re-resolve host discovery every call so a changed SDK path
takes effect live (no restart).
- android-sdk-discovery: require both adb and the emulator binary.
- emulator-bridge: fall back to the platform-primary backend (Android off-mac)
so setup errors aren't iOS/CoreSimulator on Windows/Linux.
- scrcpy-server-download: dedupe concurrent first-use downloads + add a timeout.
- scrcpy-stream-session: idle-socket connect timeout; surface control-socket
errors instead of swallowing them.
- android-exec: pass the whole command so the device shell parses quotes/pipes.
- avd-manager: match emulator log prefixes exactly (keep AVD names like
PixelWARNINGTest).
- permissions: `pm reset-permissions` is global and takes no package argument.
- stream controller/starter: drop stale handles for dead streams; idempotent
teardown. use-emulator-video-stream: stopVideoStream returns Promise.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(emulator): populate the GOP buffer and reuse live scrcpy streams
Self-audit follow-ups in the same class as the CodeRabbit GOP-replay finding:
- scrcpy-video-registry: pushFrame never wrote to entry.gop, so the replay
loop added for late subscribers iterated an empty array — a no-op. Build the
GOP on ingest (start at each keyframe, append following deltas; don't buffer
deltas before the first keyframe). Adds tests for population, reset, and the
pre-keyframe guard.
- android backend: isSessionReusable was stubbed to always return false with a
"no persistent stream yet" note, but scrcpy streams are persistent now — so
every renderer remount tore down and respawned the server. Reuse a live
stream (scrcpyVideoRegistry.has) so remounts reconnect, matching iOS. The
device-mismatch check still runs first, so device switching is unaffected.
- Refresh stale comments that implied unfinished/unverified work.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* WIP: Changes before auto-review fixes
Co-authored-by: Orca <help@stably.ai>
* Refine mobile emulator availability settings
Co-authored-by: Orca <help@stably.ai>
* Address emulator review follow-ups
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
Co-authored-by: Orca <help@stably.ai>
A terminal pane that has ever run an agent keeps polling the OS process
table for completion detection even while HIDDEN. The cadence (750ms
active / 2000ms idle) did not depend on visibility, so a backgrounded
pane forked a `ps`-scan every ~750ms purely to keep the process-exit
backstop alive — wasting idle CPU, especially on shared SSH relays.
Follow-up to #6288 / PR #6667 (merged), which deduped scans WITHIN a
poll tick via a 500ms-TTL snapshot cache. This attacks the orthogonal
axis: the number of ticks a hidden pane runs.
Hidden panes now poll at a 3s cadence (HIDDEN_POLL_INTERVAL_MS). This is
safe because the process poll is only a BACKSTOP: the primary completion
signals — Orca-managed agent hooks (observeHookStatus, push via IPC) and
xterm title changes (observeTitle) — are event-driven and fire
regardless of poll cadence or visibility. Only a non-hooked agent with
no recognizable completion title relies solely on the poll; for that
case worst-case hidden completion-notification latency rises to ~2x3s
(~6s, repeat-idle-sample) from ~2x750ms.
Visible-pane cadence is unchanged (750ms). Becoming visible re-arms the
slow hidden timer at full cadence immediately, so switching back to a
throttled pane is not sluggish (scheduleNextPoll previously no-oped while
any timer was pending).
Measured inspection calls over 60s: hidden 78->20 (-74%); visible 78->78.
Co-authored-by: Orca <help@stably.ai>
* Support background and focused terminal presentation modes
* Add `presentation` field ('background' | 'focused') to terminal
creation to control focus behavior.
* Prevent terminal creation from stealing UI focus by default.
* Return discoverability warnings when default terminal presentation
fails, unless explicit background mode is selected.
* Update orchestration SKILL.md to clarify review-only worker
completion rules and named owner handoffs.
* Prevent background terminal sessions from auto-activating
Ensure that terminal tabs created with 'background' presentation (such
as background agent sessions or locally backed renderer transports) do
not automatically activate or get selected as the active tab on remote
or mobile sessions.
- Add a selectIfNoActiveTab option to control auto-activation on mobile
- Set presentation to 'background' for remote runtime transports and
agent background sessions
- Skip tab auto-selection when the presentation is background
* Keep background terminal create payloads focused
Avoid automatically managing or overwriting manually entered or prefilled
workspace names in the composer state. This ensures user-authored names
are preserved and not overridden by linked-item or AI-generated naming,
unless the prefilled name matches the linked work item seed.
* Wire terminal-initiated worktree navigation to back-and-forth stack
* Unify terminal-driven worktree activation and Cmd+J recency marking.
* Record worktree visits in the back/forward history stack unless navigating history.
* Resolve stale terminal focus and ignore late exits from old PTYs
- Repair the active terminal pane leaf selection when a pane's PTY exits, preventing focus from being stranded on a dead pane.
- Ensure stale, pruned, or unbound terminal leaves are not persisted as active in visual layouts or shutdown snapshots.
- Ignore late exit notifications and subscription end events from old PTY transports or remote stream handles after a reconnect or rebind.
* Prevent active terminal focus on dead panes and ignore stale PTY events
- Redirect active keyboard focus to a live, PTY-backed sibling pane
if the focused pane dies, fails to spawn, or is hydrated without a
live connection.
- Ignore stale data, replay messages, and subscription rejection errors
from older PTY sessions after a transport has reconnected.
- Avoid persisting stale PTY bindings and dead pane focus inside
terminal shutdown layout snapshots.
* Clear pending input when attaching a different remote terminal handle
When switching between different remote terminal handles, debounced input
meant for the previous terminal could get incorrectly flushed and sent
to the newly attached terminal.
Fix this by clearing the batcher's pending state (text and byte counts)
and invoking `inputBatcher.clear()` if the attached terminal handle
changes.
* Add window wake recovery hook for visible terminal panes
- Extract and enhance window focus and visibility change recovery logic
into a dedicated `useTerminalWindowWakeRecovery` hook.
- Recover the xterm renderer, input surface, and WebGL texture atlases
when macOS/display wakes or the window/tab regains focus.
- Schedule recovery steps with requestAnimationFrame to ensure the
terminal layout settles correctly.
* Fix mutable variable capturing in remote transport test
Avoid mutating a local `let` variable from inside a Promise executor
closure by wrapping the rejection callback in a `const` object.
* Prevent duplicate terminal wake recovery on overlapping window events
When window focus and visibility events fire concurrently, they can trigger multiple redundant wake recovery passes.
- Return early if a wake recovery frame is already scheduled.
- Keep the scheduled animation frame instead of canceling it to ensure we get a settled recovery pass.
Defect 1: the typed GitLab MR search query was dropped before reaching
the API. Thread query?: string end-to-end through the renderer effect,
the source-lookup, the preload/RPC args, and the desktop IPC handlers
(which previously passed a hardcoded undefined), and honor it on both the
glab REST path (&search=) and the cwd-inferred 'glab mr list' fallback.
Defect 2: when MR base resolution failed the renderer silently returned,
leaving baseBranch undefined so the worktree was created off the repo
default branch (origin/master) with no feedback. Surface the failure via
toast and clear stale base state, mirroring the GitHub PR path. Also make
resolveManagedMrBase resilient to an optional compare-base (target branch)
fetch failure: degrade gracefully by dropping compareBaseRef instead of
aborting, so a merged MR with a deleted target ref still resolves to its
valid source-branch base.
Fixes#6263
Co-authored-by: Orca <help@stably.ai>
* perf: dedupe relay process-table scans behind a short-TTL cache (#6288)
Agent foreground-process inspection runs `ps -axo pid=,ppid=,stat=,command=`
(a full system process-table scan) on a 750ms/2000ms per-pane cadence. On a
shared SSH relay every tracked agent terminal drives it, so concurrent panes
each forked their own `ps` — sustaining up to the per-second inspection cap of
full-table scans for as long as agents are open, pinning idle relay CPU and
amplified by AV process scanning. This is the CPU half of #6288 (PR #6564
covers the memory-leak half).
Memoize the scan behind a single in-flight promise + 500ms TTL shared by the
relay and local main-process call sites. 500ms sits below the active poll's
minimum inter-poll gap (~675ms after jitter), so a single pane never reuses a
snapshot older than it would have scanned itself — same data and freshness,
just deduplicated within the cadence window (worst case ~8 scans/sec -> ~2).
Failures are never cached (in-flight cleared on settle) so a transient `ps`
error retries and the existing best-effort fall-through is preserved. Windows
branches are untouched; no git-provider implications.
Co-authored-by: Orca <help@stably.ai>
* test: regression guard for #6288 ps-scan volume (repro + measurement)
Drives the real local foreground-inspection call site under the documented
750ms agent-completion cadence across 6 concurrently-inspecting agent panes
over a 30s window, counting actual `ps -axo pid=,ppid=,stat=,command=`
full-table scans.
Reproduces the waste on `main` (240 inspections -> 240 scans, 1.0/inspection;
the test fails there) and proves the fix (240 inspections -> 40 scans,
0.167/inspection — bounded by poll ticks, not pane count) while every pane
still resolves its foreground agent. Guards against regressing the cache back
to a per-call scan.
Co-authored-by: Orca <help@stably.ai>
* docs: clarify 500ms TTL covers cadence floor + tolerated event-driven staleness (#6288)
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
Fixes#6288. Bounds preload runtime subscription IPC listeners to one active dispatcher per renderer and releases subscription state on terminal cleanup paths.
Pi (pi.dev) and OMP are goal/mission agents whose normalizePiCompatibleEvent
maps milestone agent_end -> hook state 'done' while they are still working.
observeHookStatus gated the quiet window on `workingStatusObserved`, so these
intermediate 'done' events (workingStatusObserved === false) fell through to an
immediate "agent finished" notification while the TUI kept spinning, and a
follow-up working event could not cancel it.
Route Pi/OMP 'done' through the existing quiet window via a new
doneShouldUseQuietWindow() predicate (delegating to a shared
isPiCompatibleAgentType on the canonical PiAgentKind), so resumed work cancels
the premature notification. Codex and other turn-end-only producers keep their
immediate dispatch.
Also harden the process-exit backstop: skip the agent-evidence teardown while a
quiet-window 'done' is pending, otherwise a poll that finds the agent gone would
clear hasAgentRunEvidence and the timer would silently drop the real completion.
Co-authored-by: Orca <help@stably.ai>
Add Project → Browse folder on a monorepo subfolder (e.g. /tmp/monorepo/packages/web)
stored the subfolder as Repo.path because isGitRepo() uses
`git rev-parse --is-inside-work-tree`, which is true for any subdirectory.
Authoritative worktree resolution then snapped activation back to the repo root,
so the import identity mismatched and the first terminal landed at the repo root
rather than the selected subfolder.
Canonicalize local git imports to the actual repo root via getGitRepoRoot()
(mirroring the SSH import path that snaps to check.rootPath, including its
post-resolution dedup), and preserve the user-selected subfolder as a one-shot
initial terminal cwd consumed only by the first activation-created pane.
Selecting the repo root applies no override, and re-importing a subfolder of an
existing project dedupes.
Supersedes community PR #6362.
Fixes#6336
Co-authored-by: Rod Boev <rodboev@users.noreply.github.com>
* Remove tracked node_modules symlink
The node_modules directory was accidentally committed as a symlink
pointing to a developer's local absolute path. This breaks builds in
CI and on other developer environments.
* Fix direct launch remote test expectations
* fix(terminal): forward synthesized/dictated text dropped under kitty keyboard protocol
With xterm's kitty keyboard protocol active, xterm encodes a printable key
on keydown and preventDefaults it, which cancels Chromium's native
insertText on the helper textarea. The IME punctuation forwarder added in
#6417 was gated to CJK input sources (isEnabled), so on a non-CJK (e.g. U.S.
Latin) input source it never armed and any synthesized text — dictation,
text expanders, accessibility / CGEvent injection — was silently dropped
before reaching the PTY.
Part A: drop the CJK-only gate so the forwarder arms on macOS regardless of
input source (the drop affects every locale, not just CJK punctuation).
Part B: forward a standalone non-composing insertText that no key event
produced. Injected prose/words never satisfy the punctuation-keydown claim
path, so recover them from the helper-textarea input event, guarded against
double-send (key-activity attribution, unresolved claimed press), against
composition (insertCompositionText + composition-commit), and via
stopImmediatePropagation so xterm's own _inputEvent cannot also forward.
Fixes#6513
Co-authored-by: Orca <help@stably.ai>
* fix: broaden terminal injected text forwarding
---------
Co-authored-by: Orca <help@stably.ai>
Previously, transient errors during candidate branch discovery (such as
rate limits or network issues) were silently ignored, leading to a
false "no-pr" result and causing the sidebar PR state to flicker.
Now, track and return any pending error encountered during branch
lookups, propagating it as an upstream error if no PR is successfully
recovered.
* Migrate terminal scrollback setting from bytes to rows
Transition terminal scrollback configuration from a byte-based (MB)
limit to a row-based count to align with standard terminal emulator
behavior.
- Introduce a shared scrollback policy to handle normalization and
safe migration of legacy byte presets to row equivalents.
- Update persistence logic to automatically convert and clean up legacy
settings on startup and write-back.
- Refactor the advanced settings interface and localization strings
to let users configure scrollback in terms of rows (up to 50k).
- Live-apply row limit changes directly to mounted xterm instances
without recreating panes or restarting PTY sessions.
* Migrate terminal scrollback setting from bytes to rows
Transition terminal scrollback configuration from a byte-based (MB)
limit to a row-based count to align with standard terminal emulator
behavior.
- Introduce a shared scrollback policy to handle normalization and
safe migration of legacy byte presets to row equivalents.
- Update persistence logic to automatically convert and clean up legacy
settings on startup and write-back.
- Refactor the advanced settings interface and localization strings
to let users configure scrollback in terms of rows (up to 50k).
- Live-apply row limit changes directly to mounted xterm instances
without recreating panes or restarting PTY sessions.
* defer updating terminal scrollback rows until blur or Enter
Avoid committing terminal scrollback row setting changes on every
keystroke, which can trigger rapid updates with incomplete or
invalid numbers. Instead, manage a local draft state and commit to
settings only when the input is blurred or the user presses Enter.
* Replace automation pause/resume button with an on/off toggle
The External automations list showed two play-glyph icon buttons side by
side when a job was paused: a run button and a pause/resume button. Replace
the pause/resume button with an on/off Switch beside the Active/Paused badge,
leaving the action cluster with just Run, Edit, and Delete.
Co-authored-by: Orca <help@stably.ai>
* Document why the in-flight spinner matches both action keys
Co-authored-by: Orca <help@stably.ai>
* Move automation toggle to the trailing edge of the row
Co-authored-by: Orca <help@stably.ai>
* Align automation toggle to the right of the title line
Co-authored-by: Orca <help@stably.ai>
* Pin automation toggle to the row's right edge
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* fix(terminal): support Windows shell selection for SSH hosts
* fix(runtime): register SSH Windows capability preflight RPC
* fix(terminal): honor remote Git Bash and split preflight IPC seams
* fix(terminal): keep SSH Windows shell state tied to the selected host
* fix(terminal): preserve Windows SSH shell selection
---------
Co-authored-by: Jinwoo Hong <73622457+Jinwoo-H@users.noreply.github.com>
* Redesign the search button in the sidebar to look like a standard input field with a border, background, and absolute icon positioning.
* Replace the basic `<kbd>` label with `ShortcutKeyCombo` elements driven by `useShortcutKeyComboDetails`.
* Show the shortcut combinations when the search container is focused as well as hovered.
Follow-up to #6644. The merged fix used a single post-spawn
requestAnimationFrame, which did not fully close the first-mount column
race: the pane's real layout can keep changing for several frames (split
equalize, sidebar/title reflow), so a one-shot re-fit could still measure a
stale width and leave the PTY pinned. The golden 'during initial mount' e2e
test failed ~1 in 9 runs with the single-frame version.
Poll for up to 12 frames, forwarding the settled size to the PTY only when
it differs from what the PTY was last told (mirroring the existing
ResizeObserver stability loop). Each resize is gated on an actual change, so
a TUI sees at most a couple of SIGWINCH during startup, not a loop.
Verified: golden test passes 6/6 with repeat-each + retries; full spec
15/15. Without this change the single-frame version is intermittently flaky.
Co-authored-by: Orca <help@stably.ai>