Commit Graph
4675 Commits
Author SHA1 Message Date
Jinwoo-HandOrca a03918156d Merge origin/main (#6954 typed OMP title flicker fix) into orca-performance
The fix patched main's direct title-update block in onPtyData — an
architecture the term-speed-2 chain replaced with the per-PTY title
tracker. Resolution keeps the tracker and ports the fix's semantics into
applyTrackedPtyTitle: foreground-owner probe with title-observation
sequencing on status transitions, same-status compatible-title changes
reuse the pending probe, and mobile snapshot fan-out is deferred until
the probe settles (delayPtyBackedMobileSnapshotForForegroundAgent).
Renderer side keeps the chain's shared handleCommandFinished (side-
effect authority routing) and grafts the fix's
clearCommandInferredPaneAgentAfterPtySideEffects() call.

Validation: #6954's own 760+ lines of merged tests pass against the
tracker port (574 runtime + 344 pty-connection/lifecycle); full battery
5,661 green (1 documented pre-existing WSL failure); typecheck clean.

Co-authored-by: Orca <help@stably.ai>
2026-07-03 04:05:31 -04:00
Jinwoo-HandOrca d55df1e3ad Merge origin/main (v1.4.120 + #7205) into orca-performance
Conflict resolutions:
- terminal-stream-protocol: Metadata keeps opcode 12 (shipped to mobile
  in v1.4.120); branch-only Ack renumbers to 13.
- scheduler: keep HIGH_PRIORITY_MAX_WRITES_PER_DRAIN=8 (perf fix) over
  main's 2 (#7139 landed there with the old constant).
- headless-emulator: keep chain structure (scanner classes, query-reply
  forwarding); graft main's pathFlavor/remotePosixFileUriAuthority OSC7
  options through TerminalOscCwdTitleScanner. Main's
  TerminalPrivateModeTracker is logic-identical to the chain's
  TerminalMouseModeMirror (kept, with pre-filter).
- orca-runtime: keep chain factory; graft main's pathFlavor wiring and
  snapshot cwd fallback; keep both teardown lines.
- pty-connection: keep both chain reconcile and main's ordered-seq
  tracking; clear the chain's restored-snapshot baseline on pty exit
  (same seq-domain boundary main's reset enforces) — fixes revive with
  restarted seq counter dropping chunks as duplicates.
- subscribe-buffer tests: updated to merged semantics — main's inline
  overflow recovery ships current data as the FIRST snapshot; the
  chain's resized/pending-output-overflow follow-up remains as backstop.

Validation: typecheck clean; 7,548 tests green across daemon/ipc/
runtime/pane-manager/terminal-pane/shared/mobile-transport (1 documented
pre-existing WSL failure).

Co-authored-by: Orca <help@stably.ai>
2026-07-03 03:34:59 -04:00
Dvitash 0ff2c09002 Fix typed OMP remote title flicker (#6954) 2026-07-03 00:26:37 -07:00
Neil f1bcb77392 fix: parse Claude Fable current-week usage
Claude Code 2.1.199 renders the Fable plan bucket as Current week (Fable), while Orca only parsed a standalone Fable heading. Accept weekly-style Fable headings as the distinct Fable weekly meter while keeping broader Fable-weekly copy as a section boundary to avoid false positives.

Validation:
- pnpm exec vitest run --config config/vitest.config.ts src/main/rate-limits/claude-pty.test.ts src/main/rate-limits/claude-fetcher.test.ts src/main/rate-limits/service.test.ts src/renderer/src/components/status-bar/tooltip.test.ts src/renderer/src/components/status-bar/inline-usage-bars.test.tsx
- pnpm run typecheck
- pnpm exec oxlint src/main/rate-limits/claude-pty.ts src/main/rate-limits/claude-pty.test.ts src/main/rate-limits/claude-fetcher.ts src/main/rate-limits/claude-fetcher.test.ts src/main/rate-limits/service.ts src/main/rate-limits/service.test.ts src/renderer/src/components/status-bar/tooltip.test.ts src/renderer/src/components/status-bar/inline-usage-bars.test.tsx
- git diff --check HEAD~1..HEAD
- live local Claude fetcher returned fableWeekly: 62
2026-07-03 00:16:19 -07:00
Jinwoo-HandOrca 348aeb3250 Add producer-side PTY flow control (watermarks + protocol v19)
Main now pauses the actual PTY when a pane's renderer-pending backlog
crosses the 256KB high watermark and resumes once it drains below the
32KB low watermark (wide hysteresis band so a draining queue cannot flap
pause/resume per flush slice). node-pty pause() stops the pty fd read, so
the kernel/ConPTY buffer fills and a flooding shell blocks on write —
flood-induced buffered lag becomes shell blocking instead of unbounded
main-process buffering (terminal-performance-initiative §5).

Transport: new fire-and-forget pausePty/resumePty daemon notifications
(protocol v19; 18 added to PREVIOUS_DAEMON_PROTOCOL_VERSIONS), routed
DaemonServer -> TerminalHost -> Session -> subprocess pause()/resume().
LocalPtyProvider pauses node-pty directly. Router/degraded providers
forward; IPtyProvider gains optional pauseProducer/resumeProducer.

Safety invariants:
- Lost-resume failsafe: daemon Session auto-resumes 5s after a pause with
  no matching resume; main re-asserts the pause at most once per 5s while
  still above the high watermark, so a lost resume can never wedge a shell
  and a sustained flood stays throttled.
- Resume on every teardown path: Session kill/exit/dispose/detach; main
  releases on pty exit and on window-destroyed bookkeeping wipes; the
  adapter owes paused sessions a resumePty on the next connect after a
  socket drop.
- Providers without support (SSH relay, legacy protocol <= v18) no-op
  silently, and the scrollback-scaled pending-output cap still bounds
  main memory when pause is unavailable.
- Kill switch: PRODUCER_FLOW_CONTROL_ENABLED in ipc/pty.ts flips the
  whole mechanism off in one line.

daemon-errors.ts is split out of types.ts to stay under the max-lines cap.

Tests: watermark transitions/hysteresis/re-assert (controller unit),
lost-resume failsafe + resume-on-kill/exit/dispose/detach (session),
notification routing + v18 gating + reconnect owed-resume (adapter),
direct pause/resume (local provider), and a flood test asserting pause
fires once, pending stays bounded at HIGH + one chunk, and resume fires
once after drain (ipc/pty).

Co-authored-by: Orca <help@stably.ai>
2026-07-03 02:48:01 -04:00
Jinwoo HongandOrca 10e8f86899 Coalesce PTY input write bursts (#7205)
Co-authored-by: Orca <help@stably.ai>
2026-07-02 23:43:35 -07:00
Mark Xian 2848c5daf4 Fix rename inputs committing on CJK IME Enter confirmation (#6980)
Fixes #6980.
2026-07-02 23:37:12 -07:00
Rod Boev 09fc57e113 fix(browser): keep CDP reload from closing Orca browser tabs
Fix the per-tab CDP proxy reload path so raw Page.reload keeps the Orca browser tab alive. Lifecycle priming is bounded and root reloads use the same safer webContents reload behavior as Orca's own browser reload path.
2026-07-02 23:24:24 -07:00
Jinwoo-HandOrca 71c89da9bb Pre-filter daemon OSC/mouse scanners for introducer-free chunks
Skips the scan-tail copy and full-chunk walks when a chunk cannot contain
an OSC or private-mode sequence (single native includes() checks), with
split-sequence correctness preserved via explicit tail retention. Strictly
positive micro-optimization on the daemon per-chunk path; 641 daemon tests
green (1 pre-existing WSL failure unrelated).

Co-authored-by: Orca <help@stably.ai>
2026-07-03 02:07:21 -04:00
NeilandOrca fa94065a81 Recover exported terminal handles from live PTYs (#7162)
* Recover exported terminal handles from live PTYs

* Guard terminal-handle adoption: first-wins, no collisions

Discovery adoption of ORCA_TERMINAL_HANDLE is now skipped when the pty
already has a handle bound this session (re-keying would strand waiters
registered under the old handle) or when the reported handle is already
bound to a different pty (provider-reported values are not trusted to be
collision-free). Also adds the relay why-comment and PtyProcessSummary
type alias from review feedback.

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Orca <help@stably.ai>
2026-07-02 23:06:32 -07:00
Jinwoo-HandOrca a5052c35f3 Merge nwparker/term-speed-2-architecture-docs into orca-performance base
Revives the terminal model/view architecture chain (hidden view parking,
hidden delivery gate, side-effect authority in main, model query authority
— all kill-switched, defaults on) on top of orca-performance's terminal
performance fixes. 34 conflicted files resolved with these decisions:

- Both sides' features kept and kill-switchable. orca-performance's fixes
  preserved exactly: parse-clocked scheduler drains (9e8bb2243), windowed
  retained-tail redraw (4e08a28cd), throttled wait-blocked check
  (66f20258e), #7139/#7150 cooperative drain, backlog caps, wedge guards,
  and probe-certified replay release.
- orca-runtime.ts onPtyData: chain's per-PTY title tracker + side-effect
  facts replace the inline OSC title blocks; our scheduleWaitBlockedCheck
  and redraw-cursor plumbing retained; refreshPtyForegroundAgent re-grafted
  into applyTrackedPtyTitle on status transitions.
- pty.ts: chain's hidden-gate drop sites, restore markers, initiallyHidden
  spawn marking, ConPTY DA1 record, and view-attribute/delivery-interest IPC
  wired through our newer spawn/delivery structure. The chain's flat 2 MB
  pending cap was NOT taken: our scrollback-scaled cap (#7150, empty-drop +
  droppedOutput sentinel) wins and now also emits the chain's one-per-episode
  pty:modelRestoreNeeded 'pending-cap' marker when the gate is enabled. Our
  8 MB renderer in-flight high water kept over the chain's 2 MB.
- pty-connection.ts: chain's gate sync, model-restore channel, side-effect
  fact consumer, and post-restore seq reconciliation composed with our
  hidden-startup query grammar, synchronized-frame latency machinery, and
  probe-certified restore. Phase 6 (skip-grammar deletion) intentionally NOT
  taken: our side evolved that grammar past the chain's base and #7150
  machinery builds on it; with the gate on it is dormant (main drops hidden
  bytes), with switches off it remains the byte-identical fallback.
- Shared module moves adopted (agent-title-*, github-links, bell detector,
  command-code, PR-link detector) with our newer bounded regex-free OSC
  parsers wired through the chain's scanner classes; our pi-synthetic/Devin/
  MiMo agent additions ported into the split modules.
- daemon-pty-adapter: chain's sleep-restore cache + our checkpoint cooldown,
  teardown flag, and oscLinks-carrying cold-restore payload combined.
- rpc/methods/terminal.ts: chain's ACK-gated multiplex output + recovery
  snapshots composed with our budgeted mobile snapshots and resize re-stream.
- Tests adapted only where they encoded superseded cadence: watermark counts
  (2 MB->8 MB), pending-cap trim -> empty-drop sentinel, initial snapshot
  frame seq (layout seq -> snapshot output seq), mock module paths.

Contract tests: 881 passed. Renderer terminal suites: 1895 passed.
Full main runtime+ipc: 2974 passed. Typecheck (3 configs) clean.
Pre-existing baseline failures (pty-subprocess WSL, PR sidebar, Linear
prompt, SidebarToolbar) are unrelated and fail identically on 7839fb9db.

Co-authored-by: Orca <help@stably.ai>
2026-07-03 01:44:20 -04:00
Brennan BensonandOrca d65c938529 Keep runtime mirror sized with desktop terminal resizes (#7192)
Co-authored-by: Orca <help@stably.ai>
2026-07-02 22:42:49 -07:00
Neil 0fd2d67c69 Allow manual sorting of Project Groups (#7191) 2026-07-02 22:23:18 -07:00
Neil b523c5311f fix: show Claude Fable usage in account switcher
Show Fable usage in inactive Claude account switcher previews by supplementing OAuth usage with scoped Claude CLI /usage data, with macOS scoped Keychain safety checks and compact preview layout coverage.

Validation:
- pnpm exec vitest run --config config/vitest.config.ts src/main/rate-limits/claude-fetcher.test.ts src/main/rate-limits/service.test.ts src/renderer/src/components/status-bar/inline-usage-bars.test.tsx src/renderer/src/components/status-bar/tooltip.test.ts
- pnpm run typecheck
- pnpm exec oxlint src/main/rate-limits/claude-fetcher.ts src/main/rate-limits/claude-fetcher.test.ts src/main/rate-limits/service.ts src/main/rate-limits/service.test.ts src/renderer/src/components/status-bar/StatusBar.tsx src/renderer/src/components/status-bar/inline-usage-bars.test.tsx
- git diff --check HEAD~1..HEAD
2026-07-02 22:18:12 -07:00
NeilandOrca 4caea00f16 Skip the synchronous cold-restore replay for live daemon sessions in doSpawn (#7105)
Co-authored-by: Orca <help@stably.ai>
2026-07-02 22:04:05 -07:00
Neil 185b768609 Add rich Markdown spellcheck setting (#7103) 2026-07-02 21:59:41 -07:00
NeilandOrca 4c4cbf2d76 Fix Vim alternate-screen terminal redraw recovery (#7142)
* Fix Vim alternate-screen terminal redraw recovery

* Decide alternate-screen atlas recovery from parsed buffer state

Replace the raw-chunk scan for alternate-screen enter sequences with the
xterm parser's own verdict: in-place rewrite chunks check
buffer.active.type (plus a parse-time buffer-switch count) inside the
write callback, where the buffer is authoritative. Covers enter/exit
sequences split across PTY chunk boundaries and full enter-exit cycles
coalesced into one write, and deletes the hand-rolled CSI parser.

Adds regression tests from a real captured vim session (including a
CSI sequence split at a 1024-byte PTY read boundary) and a contract
pin against the real @xterm/headless parser.

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Orca <help@stably.ai>
2026-07-02 21:59:17 -07:00
Jinwoo-HandOrca 66f20258e3 Throttle the terminal wait-blocked check off the PTY hot path
Post-windowed-tail attribution (findings log 2026-07-03): the blocked-
reason complex — two full-tail buildTerminalWaitText builds plus
toLowerCase and multi-pattern scans per chunk, existing only to stamp
waitBlockedAt — consumed ~85% of onPtyData's remaining cost (~700-790ms/s
under an agent-TUI flood).

The check now runs at a 50ms cadence over coalesced chunks (PTY chunk
boundaries are arbitrary, so coalescing preserves semantics), with a
trailing-edge timer so burst-final state is always evaluated, and an
immediate bypass when the incoming chunk (plus a 31-char split carry)
contains a prompt keyword — so actionable-prompt stamping stays
per-chunk-immediate while keyword-free flood frames skip the complex
entirely. Previous wait text is cached per pty instead of rebuilt, and
state is cleared at both pty teardown sites.

1,415 runtime tests green (including the cross-chunk prompt test, which
exercises the keyword bypass), typecheck and lint clean.

Co-authored-by: Orca <help@stably.ai>
2026-07-03 00:35:51 -04:00
Jinwoo HongandOrca 827d2bb6aa Refine TUI wheel scroll feel (#7179)
Co-authored-by: Orca <help@stably.ai>
2026-07-02 21:27:16 -07:00
Brennan BensonandOrca 3e4ace0562 Fix Codex pane output tearing after app occlusion (#7173)
Co-authored-by: Orca <help@stably.ai>
2026-07-02 21:00:03 -07:00
Brennan BensonandNeil 0ea354d454 Keep terminals responsive under agent output load (#7139)
Co-authored-by: Neil <neil@stably.ai>
2026-07-02 20:39:49 -07:00
Jinwoo-HandOrca 4e08a28cdf Window the retained-tail redraw path to the cursor's reach
Attribution (findings log 2026-07-03): main's onPtyData consumed ~93% of
the event loop under an agent-TUI flood, and the dominant term was
appendNormalizedToMultilineTailBuffer + finalizeRetainedTerminalRows
materializing ~2x tail-length row objects plus a per-row trailing-space
regex on every chunk — 0.888ms/chunk at the 2,000-line cap, on every
Claude-Code-shaped frame (cursor-up + erase-below).

The multiline algorithm now runs on a suffix window sized by the chunk's
maximum upward cursor excursion (plus the inherited redraw cursor and a
safety margin); the untouched prefix is shared by reference with a cheap
last-char trailing-space check to match the reference trim. Pathological
full-height cursor-ups fall back to the unwindowed implementation, which
is kept verbatim and exported as the reference for the 500-case
differential fuzz (retained-tail-redraw-window.equivalence.test.ts).

Micro-bench at a full 2,000-line tail: 0.888 -> 0.073 ms/chunk (12x).
1,415 runtime tests green, typecheck clean.

Co-authored-by: Orca <help@stably.ai>
2026-07-02 22:54:42 -04:00
Jinwoo-HandOrca 9e8bb22432 Parse-clock high-priority terminal drains instead of fixed-nap dripping
Attribution (task #9): the drain loop wrote at most 2x16KB then slept
4/16ms regardless of parse speed — an isolation bench (new
pane-terminal-output-scheduler-throughput.bench.test.ts) measures that
drip at 1.9 MB/s background / 27 MB/s foreground against xterm's
~103 MB/s parse rate, matching the baseline-jul02 end-to-end numbers
(agent-tui 2.0 MB/s in prod 1.4.91).

Fix: high-priority (visible-pane) drains now re-arm on xterm's
parse-completion callback and carry 8 writes per tick; the isolation
ceiling rises 27 -> 117.6 MB/s (parse-limited). Background cadence is
deliberately unchanged (2 MB/s drip protects the focused pane; hidden
delivery is term-speed-2's job). DRAIN_TIME_BUDGET_MS still bounds
per-tick work, preserving #7139's cooperative-drain intent.

Validation: 621 scheduler/guard/pty tests green, typecheck clean.

Co-authored-by: Orca <help@stably.ai>
2026-07-02 22:13:45 -04:00
Brennan Benson 087ad66aa2 Revert "Ship serve-sim camera dylib as data and materialize it at runtime" (#7172) 2026-07-02 18:46:00 -07:00
Brennan BensonandOrca f44cb3059b Ship serve-sim camera dylib as data and materialize it at runtime (#7168)
Co-authored-by: Orca <help@stably.ai>
2026-07-02 18:24:23 -07:00
Jinwoo-HandOrca e5511d87b8 Add pipeline-loss decomposition benches (headless xterm + daemon ingest)
Both isolate layers of the 51x agent-tui gap found in baseline-jul02:
bare @xterm/headless parses agent-tui at 103 MB/s and daemon Session
ingest (emulator + pending-output recording + fanout) at 103 MB/s —
on the byte stream the full Orca pipeline delivers at 2.0 MB/s.
Parser and daemon are exonerated; the loss is in main per-chunk
processing, delivery/ACK pacing, or renderer layers above xterm.

Co-authored-by: Orca <help@stably.ai>
2026-07-02 21:22:50 -04:00
Brennan BensonandOrca c06507ee30 Open terminal file links on mobile (#7134)
Co-authored-by: Orca <help@stably.ai>
2026-07-02 18:17:47 -07:00
dbd53ebb63 fix(emulator): recycle iOS simulators that wedge-boot without a display framebuffer (#7065)
* fix(emulator): recycle iOS simulators that wedge-boot without a display framebuffer

CoreSimulator can report a device Booted while its display IO ports never
came up (HID alive, no com.apple.framebuffer.display port), so
ensureSimulatorBooted passes and serve-sim --detach dies with 'No
framebuffer display descriptor found'. Reconnecting hits the same Booted
early-return, so the pane could never recover without a manual
simctl shutdown/boot.

startSession now recognizes that helper failure signature, recycles the
device once (shutdown + boot), and retries; if the display still fails to
come up it surfaces an actionable erase/recreate message instead of the
raw helper log dump.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* review: harden simulator framebuffer recovery

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Jinjing <6427696+AmethystLiang@users.noreply.github.com>
2026-07-02 18:13:33 -07:00
Brennan BensonandOrca 11ca4955ae Run the repo's Custom GitHub Issue Command when starting a workspace from an issue (#6827)
Co-authored-by: Orca <help@stably.ai>
2026-07-02 18:09:14 -07:00
Jinwoo Hong 78d3a37b90 Revert WebGL context retention (#7169) 2026-07-02 17:55:37 -07:00
Jinwoo-H 122811b3bc Merge PR #7153 (combined #7150 terminal freeze/memory fixes + #7139 cooperative drain) into orca-performance for extended testing 2026-07-02 20:53:08 -04:00
Neil 8e8a08ac7c fix: supplement Claude Fable usage from CLI (#7167) 2026-07-02 17:45:15 -07:00
Brennan BensonandNeil 99bc693cd5 Fix Codex config paths in managed runtime home (#7157)
* Fix mirrored Codex relative config paths

Orca mirrors ~/.codex/config.toml into a managed CODEX_HOME before launching Codex. Relative path-valued Codex settings were then resolved from the runtime home instead of the user's real Codex home, which made config loading fail in Orca while the same CLI worked in a normal terminal. Rewrite known relative path settings to absolute paths rooted at the system Codex home while preserving runtime-owned trust sections.

* Dedupe Codex TOML line scanner and include path rewrite in CLI tsconfig

* Harden Codex config path rewrite and cover managed account homes

- Track multiline arrays in the shared TOML line scanner so array lines
  are never mistaken for table headers or path keys
- Escape control characters and reject lone-surrogate unicode escapes so
  the rewritten runtime config always stays valid TOML
- Extend the rewrite allowlist with profiles.* file settings and
  debug.config_lockfile.* (both can abort Codex config loading)
- Rewrite relative paths when mirroring the canonical config into
  managed account homes (codex login CODEX_HOMEs), anchoring WSL
  accounts to the Linux-side ~/.codex with posix join semantics

---------

Co-authored-by: Neil <neil@stably.ai>
2026-07-02 17:01:41 -07:00
gatsby74 5da41d4ed6 [codex] Add file explorer open in terminal
Add an Open in Terminal action for file-explorer directories and preserve terminal startup cwd through restore/session paths.
2026-07-02 16:47:38 -07:00
Jinwoo-H 24e620624a Merge branch 'Jinwoo-H/performance-improvement-discord' into Jinwoo-H/test-7150-plus-7139 2026-07-02 19:40:58 -04:00
Jinwoo-HandOrca 5a33edd6ef Extract breadcrumb recording into a collection-safe leaf module
Playwright loads spec imports at collection time, and e2e specs import
terminal-module constants (e.g. terminal-attention.spec.ts pulls
POST_REPLAY_MODE_RESET from layout-serialization, whose chain reaches
replay-guard). The breadcrumb import added to the terminal modules made
that chain reach crash-diagnostics.ts, whose top-level import.meta.hot
and webview-registry import crash Playwright's transform
("ReferenceError: exports is not defined in ES module scope") — every
e2e shard failed at collection before running a single test.

Move recordRendererCrashBreadcrumb into crash-breadcrumb-recorder.ts
(type-only imports, no import.meta) and point the terminal modules and
their test mocks at it; crash-diagnostics re-exports for existing
callers. Full e2e suite collects again (262 tests / 94 files); unit
suites, typecheck, lint green. No runtime behavior change.

Co-authored-by: Orca <help@stably.ai>
2026-07-02 19:40:43 -04:00
Jinwoo-H 0ad23938d5 Merge remote-tracking branch 'origin/main' into Jinwoo-H/test-7150-plus-7139 2026-07-02 18:42:03 -04:00
Eren Çakar 801effa68e fix(claude): use Git Bash-safe hook fast path
Fixes #7116.

Use a forward-slash bare .cmd path for Claude/OpenClaude Windows hooks when the managed script path is Git-Bash-safe, avoiding the per-hook PowerShell startup overhead in the common case. Unsafe paths with spaces or shell metacharacters continue to use the encoded PowerShell launcher from #6078.

Keep Codex on its cmd.exe-safe fast path and leave the other agent integrations on the hardened encoded launcher.

Co-authored-by: Eren Çakar <hey@erencakar.com>
2026-07-02 15:42:01 -07:00
Jinwoo Hong 2ce9314acb Improve Windows terminal performance: retain WebGL contexts, warm first ConPTY (#7085) 2026-07-02 18:41:23 -04:00
Jinwoo-H fa107e21e5 Merge branch 'pr-7139-head' into Jinwoo-H/test-7150-plus-7139 2026-07-02 18:29:18 -04:00
Jinwoo-HandOrca 046caa95b0 Scale output backlog caps with the scrollback setting and breadcrumb drops
The 2 MB pending-output caps were flat, which risked dropping lines a
50k-row scrollback user would have retained. Both caps (main pendingData
and the renderer output queue) now derive from one shared policy:
max(2 MB, scrollbackRows x 120 chars) — 2 MB at the 5k default, 6 MB at
the 50k max. The main side reads the setting live via getSettings; the
renderer scheduler is configured where the terminal lifecycle already
reads the scrollback setting.

Every drop now records a rate-limited crash breadcrumb with dropped and
cap sizes (terminal_output_backlog_dropped in the renderer,
terminal_pending_output_dropped in main — no pty ids, session ids can
embed workspace paths). Field drop frequency and size decide whether the
cap constants need raising, replacing theory with data (#2836, #7017).

Backlog skip notices are now cap-agnostic since the limit varies.

Co-authored-by: Orca <help@stably.ai>
2026-07-02 18:20:11 -04:00
Jinwoo-HandOrca bdf798b439 Make replay-guard stall release probe-certified instead of time-based
The previous stall watchdog blindly released the input guard after 10s.
If a replay were genuinely still parsing on a starved machine, that
early release could leak xterm's auto-replies into the shell — and into
agent TUIs, where a leaked ESC reads as the user pressing Escape.

Replace the blind release with a probe: when a completion looks
overdue, enqueue an empty write behind the replay. xterm parses writes
in order, so every outcome is provably safe:
- probe parses after the replay completion ran: normal release already
  happened; probe is a no-op.
- probe parses but the replay completion never ran: all replay bytes
  have parsed, no further auto-replies can exist — the completion was
  genuinely lost. Release + breadcrumb.
- probe never parses (bounded wait): the pipeline is wedged, and a dead
  parser can never emit auto-replies, so releasing cannot leak input.
  Release + breadcrumb naming the pane as needing recovery.
While the probe is pending — a slow-but-alive replay — the guard now
HOLDS instead of releasing early; that case is pinned by a regression
test.

Co-authored-by: Orca <help@stably.ai>
2026-07-02 17:52:46 -04:00
Jinwoo-HandOrca 92abd8cfa7 Cap unbounded terminal output buffers in main and the foreground queue
Field evidence (Discord #performance / #2836): renderer memory climbs to
~1.5 GB and terminals freeze; a force reload does not help until memory
recovers. Two unbounded buffers matched that shape:

- Main-process pendingData grew by string concatenation without bound
  while the renderer could not receive (frozen, starved, mid-reload) —
  main-heap bloat a renderer reload cannot clear. Now capped at 2 MB per
  PTY: past the cap the buffered bytes are dropped and the entry stays
  O(1) until the renderer ACKs again, then a droppedOutput sentinel is
  delivered and the pane repaints from the authoritative main-owned
  buffer snapshot (existing hidden-output restore path) instead of
  continuing a stream with a silent gap.
- The renderer output scheduler capped only hidden-pane backlogs; the
  foreground path could queue a visible pane's flood without bound when
  the drain could not keep up. The 2 MB cap now applies to every
  foreground enqueue branch too, with a foreground-specific skip notice.

Verified: new main-side cap test (starve → flood → sentinel → normal
flow resumes), renderer sentinel-to-snapshot-restore test, two
foreground scheduler cap tests; full pty/terminal-pane/pane-manager
suites (1981 tests) and typecheck pass.

Co-authored-by: Orca <help@stably.ai>
2026-07-02 17:52:46 -04:00
Jinwoo-HandOrca 2c860af9ff Harden xterm write pipeline against sync-throw wedge that freezes panes
A synchronous exception escaping xterm's WriteBuffer loop permanently
wedges that terminal: _innerWrite has no try/catch around the parse
action or the write-completion callback, the tail re-schedule never
runs, and write() only re-arms on an empty buffer. The pane stops
rendering and, if a replay was in flight, the replay guard latches and
pty-connection's onData silently eats every keystroke — matching the
field reports (Discord #performance, issue #2836: content visible,
shell alive, daemon output.log flat). Both vectors verified against
vendored xterm 6.1.0-beta.287 in xterm-write-buffer-stall.repro.test.ts.

Three layers of defense:
- Guard every write-completion callback Orca hands xterm at the two
  choke points (writeForegroundTerminalChunk, writeBackgroundTerminalChunk),
  with settle and onParsed guarded separately so a WebGL/renderer
  failure during viewport settle cannot starve the replay-guard release.
- Guard all throwing-capable custom parser handlers (DA1, OSC 10/11,
  CSI ?h/?l mode reports, OSC 52 clipboard, OSC 7 cwd), degrading a
  throw to "not handled" — same escape class as
  terminal-link-provider-guard.ts.
- Replay-guard watchdog: each engagement releases exactly once, from
  xterm's completion or a 10s watchdog, so a lost completion (wedged
  pipeline, disposed-terminal race) cannot latch the guard on a live
  pane; replayIntoTerminalAsync resolves on either path so restore
  chains cannot hang. Force-releases record a crash breadcrumb.

All guard trips record rate-capped crash breadcrumbs, so the next field
occurrence names the throwing stack instead of failing silently.

Co-authored-by: Orca <help@stably.ai>
2026-07-02 17:52:46 -04:00
Jinwoo-HandOrca e293581e79 Add frozen-terminal repro harness and silent-drop regression tests
Investigation harness for the frozen-terminal reports (Discord
#performance, issue #2836): pane shows content, shell alive, daemon
output.log flat while typing.

- e2e: renderer crash -> auto-reload recovery and three restart/restore
  shapes (live daemon, SIGSTOP-wedged daemon, daemon killed between
  launches), each probing input at both drop layers. Post-crash phases
  drive the renderer from the main process because a crashed target
  severs Playwright's CDP session even though the app recovers.
- e2e helpers: layer-discriminating probes (direct pty.write vs
  transport input, plus pty:listSessions ownership-rebuild revival).
- unit repro: vendored xterm 6.1.0-beta.287 WriteBuffer permanently
  wedges when a sync throw escapes a write-completion callback or a
  custom parser handler (xterm-write-buffer-stall.repro.test.ts).
- unit repros for both silent input-drop layers: main drops writes for
  a live PTY once ptyOwnership loses the id (revived by listSessions),
  and the renderer transport stays unbound after a failed connect.
- pty.test.ts: unregister every leaked SSH provider id in afterEach so
  module-level provider state cannot leak across tests.

Co-authored-by: Orca <help@stably.ai>
2026-07-02 17:52:46 -04:00
Brennan Benson e44daf37a3 Match main terminal mirror character widths to the renderer (#7148) 2026-07-02 14:50:15 -07:00
Brandon Barker e6ca3087c5 perf(ssh): resolve node path concurrently with remote install state (#6952)
Run independent SSH relay bootstrap probes concurrently when the connection can safely support overlapping execs. Preserve the old sequential path for system SSH without reusable ControlMaster and for remotes that reject concurrent session channels.
2026-07-02 13:55:36 -07:00
Neil 15a151961e Keep terminals responsive under agent output load 2026-07-02 13:02:34 -07:00
Brennan BensonandOrca 186f6c9e3d Fix stale terminal frames on worktree return: clear alt screen on snapshot restore + WebGL reveal hardening (#7133)
Co-authored-by: Orca <help@stably.ai>
2026-07-02 12:11:27 -07:00
Brennan Benson 4c03924618 Show Git-created worktrees in external discovery (#7078) 2026-07-02 11:24:07 -07:00