* feat(sidebar): add jump-to-top button for hard upward scrolling
Detect intentional hard scroll-up gestures (wheel or scrollbar drag) and
offer a one-click jump-to-top affordance. Auto-hide after idle to avoid
persistent visual clutter. Addresses the common case of fast navigation
through long worktree lists ranked by agent activity.
* test(sidebar): improve scroll-to-top detection for active gestures
Only detect velocity from active scrollbar drag or touch, not
programmatic scrolls. Return focus to list after jump-to-top. Add
comprehensive hook tests with gesture simulation. Improve cumulative
down-delta tracking for dismissal.
* test(sidebar): add scroll-to-top gesture detection tests
Add comprehensive test coverage for the hard-upward-scroll detection hook,
verifying idle timer behavior, gesture suppression, scrollability checks,
and cleanup on unmount. Extract the post-jump suppression window into a
named constant for maintainability.
Adds GitHub stacked pull request creation: a contextual "Stack this PR above #N" option that appears only when the selected base branch has an open PR, plus the main-process stack preflight and registration.
Also reworks the create-review composer for cohesion: shadcn Checkbox and Label primitives, base label above a full-width searchable combobox with attached results, keyboard navigation, and a unified field skin, spacing and typography scale.
Verified end to end against real GitHub: extending an existing stack and creating a new one.
* feat(bitbucket): connect Bitbucket from Settings with encrypted credential storage
Bitbucket Cloud was the only review provider with no in-app auth: GitHub and
GitLab delegate to the gh/glab CLIs, but Bitbucket has no comparable
first-party CLI, so the only option was ORCA_BITBUCKET_* env vars plus a
restart (discussion #5364).
Adds a Connect/Edit/Disconnect flow on the Bitbucket integration card,
modeled on Linear and Jira:
- Credentials are verified against /user before they are persisted, so a
dead token is rejected inline instead of silently stored.
- The secret is encrypted with safeStorage (0600 plaintext fallback when no
OS keyring); non-secret metadata lives in a separate plaintext file so
status reads render the connected account without decrypting. Opening
Settings therefore never triggers a keychain prompt.
- Env vars keep precedence over stored credentials, so existing headless and
SSH setups are unaffected. Env-managed connections hide Disconnect.
- connect/disconnect reset the preflight cache, so no relaunch is needed.
The Bitbucket card moves to its own file to stay under the tsx max-lines cap.
* feat(bitbucket): support creating pull requests from Orca
Bitbucket was the only configured provider whose Create button reported
"This repository provider does not support creating a pull request from
Orca" — supportsReviewCreation was false and the forge provider had no
createReview, so even a correctly authenticated setup was blocked.
Adds createBitbucketPullRequest against POST /repositories/{ws}/{repo}/
pullrequests, using the same env-first / stored-credential resolution as PR
lookups (extracted into resolve-auth.ts so both share one path).
Bitbucket Cloud has no draft pull requests, so a draft request is rejected
with a clear message rather than silently publishing a live PR.
* fix(bitbucket): hide the draft toggle where drafts do not exist, plus review fixes
Bitbucket Cloud has no draft pull requests, so the composer no longer offers
the toggle for it and forces the flag off at submit — better than failing
after the user has filled the form in.
Review fixes:
- writeFileSync's `mode` only applies when it creates the file, so rewriting
a credential kept whatever permissions it already had. chmod after every
write, for the secret and the metadata.
- An explicit ORCA_BITBUCKET_API_BASE_URL now wins over a stored base URL.
Env precedence is per-setting, not all-or-nothing.
- Enter in the credentials dialog only submits from a text field, so it no
longer hijacks Cancel and the docs link.
- Replace the chmod-based delete-failure test with a mocked unlinkSync: file
modes are not portable to Windows and elevated runners unlink anyway.
* fix(bitbucket): stop a merged pull request from blocking the branch's next one
Reported on #5832: with a merged PR on a branch, Create reported "Pull
request already exists" and offered no way forward.
The branch lookup queries every PR state and returns the most recently
updated one, so a merged PR came back as the branch's current review and
eligibility blocked on it. Bitbucket only discarded such a match on the repo
default branch (#9171), while GitHub already drops any merged PR it matched
by branch alone — "a merged PR without an explicit link is just a historical
branch match, not implicit review context".
Applies that rule to Bitbucket. An explicitly linked review still resolves
through the linked-number fallback, so merging a PR Orca knows about keeps
showing it.
* fix(bitbucket): add bitbucket to the shared review-creation provider list
Reported on #5832: on a Bitbucket repo with no existing PR, Create still
said "This repository provider does not support creating a pull request
from Orca", even after the forge provider gained createReview.
There are two capability lists. Enabling supportsReviewCreation on the forge
provider was necessary but not sufficient — the blocker and the whole
renderer read the separate shared list, which never included bitbucket.
Adds it, gives Bitbucket its own provider name so review copy stops saying
"GitHub", and asserts the two lists agree so they cannot drift apart again.
* fix(bitbucket): persist pull request links after creation
* fix(bitbucket): fetch linked pull requests by number first
* fix(i18n): use generated Bitbucket integration keys
* test(bitbucket): cover forge creation delegation
* fix(bitbucket): fall back when linked pull request is stale
* docs(bitbucket): explain notFoundIsNull and fix a garbled permissions comment
notFoundIsNull arrived without the rationale its sibling flag carries, and
reads as a bare `true` at the only call site that opts in.
* fix(bitbucket): address review findings before merge
Two of these made the feature unusable in real setups:
- Create PR checked GitHub authentication for Bitbucket. isProviderAuthenticated
fell through to isGitHubAuthenticated, which was unreachable while Bitbucket
could not create reviews at all. Anyone with Bitbucket connected but no
`gh auth login` got auth_required with no way forward.
- The draft flag was only gated in ChecksPanel, not the two SourceControl call
sites. With "create as draft" saved as a default, the composer hides the
toggle for Bitbucket, so the flag could not be cleared and creation failed
every time. Bitbucket now ignores draft instead of rejecting it.
Also:
- Blocked-create copy said "GitHub is not authenticated. Run gh auth login" on
Bitbucket repos, in both the main-process and renderer paths.
- A decryption failure resolved to an anonymous config and queried anyway; a
private repo answers 404, which reads as "no pull request" and offers Create
for a branch that already has one. Requests now fail closed.
- Hiding non-open implicit branch matches was too broad: a declined PR became
permanently invisible off the default branch. Scoped to merged, restoring the
default-branch rule (#9171) for the rest.
- A failed disconnect rejected unhandled and the card silently re-rendered as
connected; a partial delete left the secret live in memory for the session.
- The credentials dialog refused to open on a remote runtime, so a local repo
could never store a credential. Now only the storage note changes, matching
the Jira dialog.
---------
Co-authored-by: devatnull <59279509+devatnull@users.noreply.github.com>
* fix(terminal): retain WebGL for recently hidden worktrees
Suspending a hidden worktree disposes every pane's WebGL addon, so every
switch-back presents DOM-renderer frames (unfloored ~5% wider advance, and
the channel through which any poisoned cell metrics reach the screen) until
reattach completes — 0.5-3s on loaded sessions. Keep the live addons for the
most recently hidden worktrees instead: LRU capped at 6 contexts (Chromium
allows ~16/page, visible worktrees use 1-4), least-recent evicted to dispose
exactly as before. Reveal then has no renderer swap and nothing to flash.
Window-occlusion callers pass no retention context and are unchanged.
* fix(terminal): pause retained hidden cursor work
* fix(terminal): preserve retained WebGL through deferred rebuilds
* fix(terminal): explain a dead terminal host instead of leaking a socket error
When the daemon that owned a session has exited, resuming that terminal surfaced
the raw connect error for its endpoint — on Windows a named pipe path, since a pipe
disappears with its server process — in a red toast ending in "file an issue". The
session is unrecoverable and the text is unactionable.
Translate it at the daemon boundary into terminal_host_gone, following the existing
terminal_pane_owner_unverified path, and humanize it in the toast. Suppress the
issue link for a condition Orca can fully explain.
Covers the remote-host case: the conversion sits in attachStablePaneOwner, the first
catch a paired client's resume reaches before the error is serialized onto the wire.
* fix(terminal): preserve host-gone errors across versions
* fix(terminal): scope host-gone error matching
* refactor(terminal): derive the host-gone test and replace forms from one source
Two regex literals matched the same token with subtly different shapes
(capturing vs non-capturing, consuming vs lookahead), so an edit to one could
silently drift from the other. Build both from a single source string; the test
form stays non-global so it carries no lastIndex state between calls.
* test(terminal): cover host-gone regex boundaries
* test(terminal): isolate leading host-gone boundaries
Forward-slash //wsl.localhost links opened as a different path string than
the Files sidebar's backslash UNC, so file watchers did not refresh the
editor. Canonicalize WSL UNC to \\wsl.localhost\... at map time.
Fixes#13349
* fix(mobile-markdown): enable keyboard dismissal while editing
Allow users to dismiss the soft keyboard while composing markdown content. Extract the MarkdownReader component into its own file and add WebView-based caret preservation to restore the cursor position after the keyboard closes. This prevents the editor from losing focus and erasing the user's selected caret location when the keyboard hides.
* improve test
The scanner service runs under ELECTRON_RUN_AS_NODE and cannot access
packed files in app.asar. Without unpacking, the worker entry fails to
spawn, causing all OpenCode sessions to disappear in packaged builds.
Use color-mix to blend selection highlight instead of flat accent, making the keyboard cursor visible on light popover surfaces in both light and dark modes. Fix race condition in selection handling where deferred query lag could break arrow navigation by always accepting cmdk's internal cursor updates.
* Strengthen plain-node-entry-guard with entry name validation
- Add buildStart hook to validate guarded entry names exist in rollup
inputs, preventing stale names from silently stopping guards
- Extend electron require detection to subpaths (electron/main, etc)
- Improve smoke test signal/exit handling and use constants
- Add comprehensive tests for entry validation and new behaviors
* Add SIGKILL escalation to plain-node-entry-guard timeout
Switch from spawnSync to async spawn to properly handle daemons that trap
SIGTERM. spawnSync's timeout only sends the signal and waits, so a daemon
that ignores SIGTERM causes the build to hang. The new runDaemonEntry
function escalates to SIGKILL after a grace period to enforce the deadline.
Configurable timeouts and grace periods via SmokeTimings type; closeBundle
hook becomes async to support the change.
* fix(feedback): pre-include Orca version and OS in errors and feedback
Make terminal errors and Send Feedback carry easy-to-copy client
environment details so bug reports include build and platform context
without a follow-up ask.
* fix(feedback): satisfy exhaustive-deps in environment prefill hook
Destructure hook params so useEffect/useLayoutEffect dependency lists
are complete and the changed-code quality gate passes.
* fix(preload): stop importing node:os in sandboxed preload
Sandboxed Electron preloads cannot require node:os. That import crashed
the whole preload script, leaving window.api undefined and taking down
App chrome (dock badge, preflight). Keep platform.get on process APIs
only, and guard best-effort badge/preflight callers when api is missing.
* fix(feedback): count text typed below the env footer
Strip only the prefilled Orca/OS/Shell block for Send validation so
users who click past the footer and type can still submit.
## What this changes
Two renderer inputs were trusted because their TypeScript types said they were valid. Both are now validated at the boundary that owns them.
**Terminal cursor style.** `normalizeTerminalCursorStyleDefault` preserved any non-null migration-stamped value without checking it against the actual enum, so a runtime value outside `bar | block | underline` survived into `terminal.options.cursorStyle`. It now enum-checks and falls back to `block`. Applied on both read paths (desktop `Store` load, web `getStoredSettings`) and both write paths (`Store.updateSettings`, web `settings.set`), so an unsupported value cannot reach persistence, the `settings:changed` publication, or xterm.
**Plugin language packs.** The renderer stored the `listLanguagePacks()` IPC result without a runtime check, so a non-array response was assigned to state and later crashed its first array consumer on `.find`. Ingress now accepts only an array, drops members failing `isPluginLanguagePackRegistration`, keeps valid siblings in their original order, and logs which failure mode occurred. The registration guard requires `resourceLanguage` to equal `pluginLanguageResourceId(id)`, which keeps a pack with a missing or inconsistent identity out of i18next — that shape reproduces as `TypeError: Cannot read properties of undefined (reading 'includes')` with the guard removed.
Catalog validation is shape-only on this path (`validatePluginLanguagePackCatalogShape`), so revalidating an already-parsed catalog does not allocate a second copy of it. `isCatalogObject` also now requires a plain-object prototype, and the walk rejects repeated or cyclic object references.
## Root cause: partially known
Worth stating plainly, because the fix is defensive rather than causal:
- The non-array pack container and the out-of-enum cursor value are both reproduced directly by tests.
- Two additional field stacks are *consistent with* an invalid `resourceLanguage` and are blocked by this guard, but the reports do not prove that malformed registrations were their source.
- No production writer in current code or history emits an out-of-enum cursor style. The Ghostty config importer (`src/main/ghostty/mapper.ts`) already rejects unsupported `cursor-style` values. The original writer is unidentified.
Every in-tree producer supplies valid data, so these guards are no-ops on the current happy path. They are boundary hardening against a mutation we have not located, not a repair of a known writer.
## Trade-offs
- Malformed registrations are skipped with one warning rather than surfaced in the UI. Valid siblings keep their identity and order. Note the main-process registry already reports per-plugin parse errors, so this path only catches corruption after main has validated.
- Renderer ingress walks each catalog once per lazy load or `contentPacksChanged`. It does not run on render or terminal-output paths, but a maximum-size burst still costs tens of milliseconds synchronously. Pack count and plugin-ID length remain uncapped.
- An unsupported cursor value now renders and persists as `block`, so anyone relying on an undocumented third-party value loses it.
- Loading settings whose cursor style is absent or invalid now marks state dirty and rewrites once, matching the existing `terminalRightClickToPasteDefaultedForPlatform` pattern above it.
## Compatibility
`listLanguagePacks` is local `ipcMain`/`ipcRenderer` only and is not implemented in the web build, so nothing here crosses the remote wire — no RPC parameter, publication schema, stream frame, opcode, or capability changed. Validation is receiver-side at existing boundaries. Nothing is platform-, shell-, PTY-, native-module-, SSH-, WSL-, or worktree-dependent, and the web build normalizes on both read and write. Malformed plugin data is rejected before i18next sees it; no new permission, network path, executable input, or persistence schema was added.
## Verification
Locally on the final head: the 5 touched test files pass (591 tests), plus node and web typecheck, oxlint, and oxfmt. All GitHub required checks pass, including Windows packaging, static analysis, Git and wire compatibility, shell contracts, and all 32 Node 24/26 shards. The path-gated E2E job is skipped after its detector passed.
Scope note: an earlier revision generalized this hardening to `Project.sourceRepoIds` and profile transfer without field evidence. That scope was removed; the diff is cursor and plugin paths only.
* fix(e2e): repair seven specs whose assertions drifted from shipped behavior
The E2E suite could not collect at all until #13758, so these seven had been
failing unobserved. Each is a stale test, not a product defect — verified
individually against src/ rather than by making the assertion pass.
- worktree-jump-palette-filter: the palette placeholder gained chats and
terminals. Hoisted to one SEARCH_PLACEHOLDER const.
- tab-create-entry-file-paths: matched the omnibox by its translated
aria-label. Switched to aria-controls, which is structural and unlocalized.
- browser-local-https-certificate-trust: once a load settles, the toolbar
reload button relabels itself "Retry" alongside the failure overlay's own
Retry, so the slot-wide locator hit two elements and failed strict mode. The
test only ever passed inside the window where the toolbar still read "Stop".
Narrowed by visible text; the icon button has none.
- repro-7732-gitlab-checks-job-details: the activity-bar label carries a
failure suffix ("Checks — Error"), which an exact-name match stops seeing
precisely when the checks under test fail. Anchored regex, and bounded the
click so the poll retries instead of hanging on a label that flips mid-action.
- floating-tab-rename: the panel's open flag is persisted, so after the restart
the helper's blind toggle closed the panel it was about to assert on. Made it
idempotent.
- github-created-issue-start-prefill: starting an issue now routes through the
quick-create composer, so the launch command only forms once that is
submitted. The spec now drives it.
- ssh-config-host-import: P6 waited on "All hosts already in Orca", a string
that exists nowhere in src/ and never could have matched. P7 required the
tombstoned host to be absent, but listing it behind a "Removed from Orca"
badge is deliberate — see the rationale at ssh-config-host-picker.ts:54 and
the unit test already pinning it. Both retargeted; P7 still proves the host
is excluded from bulk re-adoption, which is what it was for.
Verified locally: all seven pass. github-created-issue-start-prefill cannot be
verified on a machine whose gh resolves to an Orca terminal-attribution shim,
since hydrateShellPath puts that ahead of the fixture's fake gh; CI has no shim.
Three further failures are NOT addressed here. Adversarial review found the
obvious test-side fix for each would have masked a real product bug, so they
are being fixed in the product instead.
* fix(e2e): configure the issue spec's git remote before Electron launches
The spec added origin inside the test body, after the orcaPage fixture had
already launched the app and added the repo. "New GitHub issue" is disabled
when no repo is task-eligible, and eligibility is decided by the git remote
probe alone: repos.add runs detectRepoIconAndUpstream, and a settled "no
remote" writes gitRemoteIdentity = null, which is the ineligible marker.
Background enrichment then suppresses re-probing that location for five
minutes, so a remote added afterwards can never recover the button.
It passed only when the shared seeded repo happened to already carry an origin
from an earlier spec in the same worker — github-cli-stall-repro adds one,
source-control-create-pr-intent-switch removes one — which is why it passed in
the sharded lane and failed in the changed-specs lane.
Moved to test.beforeAll, whose worker-scoped testRepoPath runs before the
test-scoped Electron fixtures. Reproduced the failure against a fresh
origin-less repo, then confirmed the fix on the same, including --repeat-each=2.
Note the earlier attribution was wrong: the local failure at this line was
never the gh attribution shim. The button's enabled state reads `git remote -v`
and never consults gh, so a shim can only bite later, at issue creation.
Forward the renderer's already-pinned {mergeBase, headOid} to the SSH relay so a single-file branch diff reads the two blobs directly instead of rediscovering live HEAD. Six sequential git processes become two concurrent reads, and a branch move mid-review no longer changes which revision is displayed.
Equivalence with the legacy route is proven against real Git across 14 change types; wire compatibility is proven over a real SSH socket against relay bundles built from main and from the pre-merge-base.
Once V8 optimizes the calling function, `String.prototype.codePointAt` on a
sliced string pairs a trailing high surrogate with the code unit that follows
the SLICE inside its parent, returning a code point the string does not
contain. Every UTF-8 byte scan built on `codePointAt` therefore reported one
byte too many for a prefix slice cut mid-pair, but only after tier-up, which
is what made terminal-stream-byte-length.test.ts fail intermittently on the
same commit.
Read the units explicitly with `charCodeAt`, which stays bounds-correct in
every tier, via a shared `readUtf8CodePointAt`.
* perf(renderer): keep catalog array identity and path-status cache on no-op refetches
mergeByIdentity always allocated a fresh array, so project-group and folder-workspace
refetches replaced state by reference even when nothing changed, refiring a forced
folderWorkspace.getPathStatus sweep per row on every repos:changed.
Unchanged merges now return the previous array, and the paired
folderWorkspacePathStatuses resets are gated on the same check so a no-op refetch
neither clears the cache nor needs to refill it. Real catalog changes clear and
refire exactly as before.
Co-authored-by: Orca <help@stably.ai>
* refactor(renderer): make the catalog arrays readonly
The identity guard can now return the caller's array, so a future in-place push or
sort on state.projectGroups / state.folderWorkspaces would alias store state. Typing
the merge helpers and the slice fields readonly removes both `as T[]` casts the guard
introduced and adds none, matching what #13744 did for state.repos.
Partial test fixtures cast the element rather than the array, so no `as unknown as`
laundering is needed.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
setRuntimeEnvironmentStatus always cloned runtimeStatusByEnvironmentId, so a re-probe
returning an identical status still invalidated every subscriber. It now returns the
state unchanged when the computed entry matches the stored one.
checkedAt is excluded from the comparison: it is Date.now() per probe and no consumer
reads it, so including it would make the guard dead code. Generation advance and the
disconnect toasts still run on every call.
Co-authored-by: Orca <help@stably.ai>
prepare() recompiled every statement, so orchestration reads re-parsed the same SQL
on the main thread. Adds a bounded LRU keyed by SQL, cleared on close() and before
schema-changing exec().
Wildcard selects are excluded: node:sqlite builds the first post-schema-change row
from stale column names, so a reused SELECT * can silently drop a freshly added
column. PRAGMAs stay uncached.
Co-authored-by: Orca <help@stably.ai>
The stream-gating hook (#13608) and the subscription parking installer
(#13621) each reimplemented `isWindowVisible() || isDocumentVisibilityProvenStale()`
plus its visibilitychange + stale-recovery subscription, and each carried
its own 500ms park delay that agreed only by coincidence.
Extract both into `lib/window-park-visibility.ts` and leave the two
consumers as thin wrappers: `useWindowStreamVisible` feeds the snapshot
and subscribe into `useSyncExternalStore`, the parking installer calls
them imperatively. The subscribe now always uses the defensive
`typeof document` guard the parking side already had, and registers
stale recovery before the visibilitychange listener so the stale latch
is cleared before the callback reads it.
Both park delays now derive from one `WINDOW_HIDE_PARK_GRACE_MS`: they
debounce the same signal against the same user behaviour (a quick
app-switch round trip). The parking side's 8x reveal-side backoff stays
where it is - that models its own resume cost, not the grace window.
Renderer-authoritative gating (#13622 native chat, #13634 editor panels)
is deliberately left alone; it keys off Zustand routing state, not OS
visibility.
Also switch the active-runtime ref writes in web-session-tabs-sync to
`useLayoutEffect` so no resume event can land between paint and the
passive flush, and correct the stale comment above them - the install
effect reads neither ref (both readers are gated on `isVisibilityResume`).
Mark invalidated diff content stale instead of dropping it, mirroring the file-content treatment from #13634. The diff read-generation fence (diffReadGenerationRef) already rejects a superseded read's write-back, so retaining the bytes and swapping them on arrival is safe and keeps every RPC saving -- it just stops the loading placeholder flashing on each reveal.
The git-status reload effect now treats a stale entry like a missing one so the lazy-load effect stays the single fetcher for it.
Co-authored-by: Orca <help@stably.ai>
* perf(native-chat): suspend hidden transcript streams
* fix(native-chat): keep assembly renders pure
* fix(native-chat): keep a transient error from stranding a revealed chat
- An error snapshot frame no longer latches frameArrived, so the in-flight
read can still seed the pane instead of leaving it on the error surface.
- Retained history is shown over a full-pane read error for the same source.
- The paged read window survives a hide/reveal; only a source change resets it.
Co-authored-by: Orca <help@stably.ai>
* fix(mobile): match the trimmed native-chat retention signature
The shared retention type no longer takes `loading`, so mobile's call was an
excess-property error that broke the mobile typecheck job. Dropping it also
lets mobile inherit the desktop behavior: a stream error or dropped client
keeps the last transcript instead of swapping it for the error empty state.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* perf(renderer): park hidden remote browser screencasts
* test(renderer): pin stale-visibility term and parked-unmount teardown
Restores the WHY behind the '|| isDocumentVisibilityProvenStale()' term the
emulator-module dedupe dropped, and pins it plus the close-tab-while-parked
path with tests. Extracts the lifecycle harness so the spec stays under
max-lines without a suppression.
Co-authored-by: Orca <help@stably.ai>
* fix(ci): exclude test-support modules from the localization audit
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* perf(remote): park hidden session mirrors
* perf(renderer): bound visibility resume cost and repair fences
- Back off the park delay after a park the user undoes quickly; each resume
re-enumerates every paired host, so short hide/reveal churn now stops
parking instead of paying that cost per cycle.
- Expire the active-worktree omission fence one visibility generation after
the inventory that set it, and name the unfiltered-inventory invariant it
depends on.
- Never skip the unchanged resume inventory for a worktree whose repair
replay is already armed.
Co-authored-by: Orca <help@stably.ai>
* fix(renderer): move active-runtime ref writes out of render
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* perf(editor): park hidden external reloads
* fix(editor): sync content refs after commit
* fix(editor): close post-commit ref window
* test(editor): cover commit-time visibility
* fix(editor): keep invalidated content visible and stop redundant reads
- Mark invalidated file content stale instead of dropping it so a reveal swaps
bytes in place; the read-generation fence already blocks stale write-backs.
- Skip the lazy read when the newest read for the tab is still outstanding, so
a worktree flip-flop cannot double-fetch.
- Stop claiming Cmd/Ctrl+S outside the workspace view, where no mounted panel
owns the request and the keystroke was silently swallowed.
A write landing during a full scan was recorded by the post-scan gate stat,
so the next tick saw a clean gate and the create/delete waited up to 15 ticks
(~30s) for the backstop. Sample each gate dir's signature before its listing
so a racing write reads as stale and forces one rescan on the next tick.
Also fixes the flaky 'retires stale marker probes' spec: a folder caught
mid-rm opened a pending-marker window that the swallowed gate change kept
alive for the whole backstop gap (43 probes vs the 30 budget).
Co-authored-by: Orca <help@stably.ai>
* Add copy button to quick commands with visual feedback
Quick command rows now display a copy button that copies the command body to clipboard. The button shows brief visual feedback ("Copied" or "Couldn't copy") and is disabled when the command body is empty. Includes desktop and mobile UI, tests, and full i18n support.
* fix(ci): unblock verify for quick-command copy button
Key feedback to the copied body so prop changes drop stale labels without
setState-in-effect, and mock expo-clipboard in the mobile list test.
* perf(renderer): dedupe remote status hydration
* fix(runtime-status): re-list host catalog when the listing goes stale
Coverage matching cannot observe catalog edits made by another client or the
orca CLI, so gate hydration on catalog listing age too.
Co-authored-by: Orca <help@stably.ai>
* test(runtime-status): reset the catalog listing clock between tests
The staleness guard keeps its last-listed timestamp in module scope, so the
TTL test left fake time behind and made every following test in the file
depend on its position. Add a reset hook, call it in beforeEach, and pin the
TTL invariant on an externally added host rather than the timer alone.
Also extracts the coverage predicate in fetchSettings and restores the WHY
comment about compat failures clearing on a reachable status.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* perf(codex): skip migration scans for nonshared reattaches
* fix(codex): require provenance to skip migration scans and bound ignored launches
Drops the exit-match escape hatch that skipped a scan without route provenance, and ages out ignored reattach launches on the existing 60s/256 lease policy so a lost exit can no longer pin an active launch (and its completion marker) for the process lifetime.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* perf(runtime): avoid forced SSH hydration on project refresh
* fix(runtime): backfill SSH states for targets learned without a state read
A failed-connect resync labelled a target with no ssh.getState, and the new
metadata-refresh gates then skipped it forever: no SSH chip and every worktree
mutation to that host failed the connection-generation check.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
#13314 landed terminal-macos-system-key-remap.spec.ts but its final commit,
"chore: drop non-mergeable IME e2e scratch files", deleted the three modules it
imports. The spec survived; terminal-ime-pane-arena, terminal-ime-cdp-composition
and terminal-ime-platform-policy did not.
Playwright resolves every spec before running any of them, so the unresolved
import is fatal for the whole run, not just that file: `playwright test --list`
on main reports "Total: 0 tests in 0 files". All ten scheduled E2E shards have
been failing at collection since, and the macOS system-key-remap coverage the PR
was for has never run once.
No typecheck project includes tests/, which is why this stayed invisible outside
the E2E lane.
Restored from the commit before the drop. pane-arena and platform-policy come
back verbatim; cdp-composition keeps only the four entry points this spec uses,
since the rest served specs that were not merged. Its doc comment is retargeted
accordingly — the composition-session drivers are the part that went.
Collection is back to 528 tests in 222 files and all six remap tests pass.
* perf(renderer): keep the repos array identity across no-op refetches
reconcileFetchedRepos deliberately returns the previous array when a refetch
changes nothing, so identity-keyed memos can skip work. Two later steps in the
same chain copied unconditionally and threw that identity away:
- reconcileReadoptedSshRepoRows spread the input on its no-prune path, which is
the common case.
- applyManualRepoOrder allocated a fresh array even when the saved order moved
nothing.
Both now return the input when they change nothing, so state.repos stays
referentially stable through fetchRepos, fetchRuntimeEnvironmentRepos,
fetchReposForAllHosts, and hydratePersistedUI.
Return type stays Repo[] with the same cast reconcileFetchedRepos already uses;
all four call sites only read the result.
Co-authored-by: Orca <help@stably.ai>
* refactor(renderer): make the store repos array readonly at the type level
Preserving the repos array identity means handing callers the same array that
is live store state, which previously relied on `as Repo[]` casts to launder
readonly inputs back into a mutable field. A cast is a footgun: the next person
to add a .push or .sort corrupts store state with no type error.
Widen RepoSlice['repos'] to readonly Repo[] and propagate honestly. Consumers
that only read take readonly Repo[]; genuine local accumulators are annotated
Repo[] and built from copies.
Removes all four pre-existing `as Repo[]` casts in the reconcile chain
(repo-identity-reconcile, superseded-ssh-repo-rows, manual-repo-order x2) —
this lands with fewer casts than main has today.
Type-only change; no runtime behavior differs.
Co-authored-by: Orca <help@stably.ai>
* fix(renderer): compare nested repo fields so reconciliation actually fires
Preserving the repos array identity was inert. reconcileFetchedRepos compares
repo fields with !==, but every repo the renderer receives carries nested
records that are new objects on every fetch:
- main's hydrateRepo unconditionally rebuilds hookSettings for every repo,
even a pristine one (persistence.ts:5109)
- IPC structured-clone (and the JSON hop for SSH/runtime hosts) reclones
gitRemoteIdentity, upstream, repoIcon, and the path arrays
So every repo compared unequal, `identical` went false on every refresh, and
the array was rebuilt regardless of the copies removed in the parent commit.
Compare nested plain records structurally instead. They are small sanitized
values; anything non-plain falls back to reference equality.
The end-to-end test previously passed for a fixture-only reason: its repo had
five scalar fields and the mock returned the same object both calls, the one
shape production never produces. It now uses a production-shaped repo and
fails without this change.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* fix(settings): paste bash-native skill setup under WSL PTY
WSL worktree setup terminals force wsl.exe even when shellOverride is
powershell.exe. Auto-pasting the PowerShell `& { wsl.exe ... }` wrapper
into bash fails with a leading-& syntax error (#13305). Rewrite that
wrapper to a bash login-shell script for setup-terminal paste only;
clipboard copy still keeps the PS host wrapper for manual use outside Orca.
* fix(settings): align skill paste with resolved PTY shell
* fix(onboarding): keep shell preparation out of render
---------
Co-authored-by: OrcaWin <293788423+OrcaWin@users.noreply.github.com>