* perf(git): bound git subprocess execution with an atomic admission scheduler
Field traces (#16038, #11363) show Windows freeze storms driven by unbounded
concurrent git children (12+ at once, 50-65s status convoys for 25+ minutes).
Admit every main-process git child against atomic per-budget base+headroom
counters (general / network / per-route), with reserved interactive capacity,
ordering-only aging, close-bound permit release, a 120s fail-safe read timeout
that feeds scheduler backoff, tier plumbing through every option carrier, and
coalesced+jittered visibility pollers. Killswitch: ORCA_GIT_ADMISSION_DISABLED=1.
Storm harness A/B: max concurrent children 65 -> 6, interactive p95 791ms -> 88ms;
output-parity battery byte-identical with admission on vs off.
* test(git): run the admission output-parity battery on every platform
Parity needs real git, not the storm harness's PATH stub, so it must not share
that file's POSIX gate - Windows is the platform where parity evidence matters.
* fix(git): preserve interactive admission invariants
* perf(git): keep admission queue drains linear
* fix(git): close final admission gaps
* perf(git): bound eligible route selection
* fix(merge): remove unrelated stale snapshot changes
* fix(git): preserve refresh lifecycle authority
* test(git): align admission lifetime contracts
* fix(git): harden admission across runtime paths
* fix(git): restore freshness for bulk status reads
* test(git): repoint delete-dialog source pins after admission plumbing
The hydration effect now orders its targets through
orderDeleteWorktreeStatusHydrationTargets and passes includeLineStats
alongside the abort signal, so both literal anchors stopped matching.
The invariants are unchanged and still pinned: dropping the signal, the
main-worktree/folder filter, or getState-instead-of-subscribe each
still reddens this test.
* Fix git admission tier propagation and lock ordering
Decode optional Git status tiers permissively and default runtime RPC status reads to the status lane while preserving renderer caller intent.
Acquire the FETCH_HEAD mutex before atomic admission so same-repository fetch waiters hold no global or route permits.
Preserve automatic pull-request refresh reasons, keep explicit hosted-review refreshes interactive, remove the dead candidate tier, and keep relay scheduling unchanged.
Use tier-aware status lease keys because a shared lease cannot be safely promoted after its admission request is queued or granted.
* test: align expectations with admission plumbing
* refactor(child-process): move the process contract types to process-spec
run-process.ts crossed its line cap after gaining the termination observer;
the public types and defaults move out with re-exports so no caller changes.
* chore: restore pnpm-lock.yaml to main (unintended local drift)
---------
Co-authored-by: Merge Sim <sim@local>
* fix(remote): focus host-delegated split panes
Return the authoritative leaf identity from terminal.split, record viewer-local focus intent behind the captured pairing revision, and replay the mirrored layout before focusing the exact pane. Preserve old-host fallback and prevent delayed split responses from stealing focus after the viewer moves away.
Add deterministic runtime, renderer, concurrency, compatibility, and headed paired-Electron coverage for Cmd+D, header splits, and immediate PTY input routing.
Fixes#16510
* fix(remote): preserve split focus across tab groups
Resolve the initiating source tab and leaf from the remote PTY, while keeping the viewer's current focus as a separate anti-steal baseline. This lets context-menu/header splits from non-focused group tabs focus their result without allowing delayed responses to override a later navigation.
* test(remote): drive split focus with key events
* test(remote): use the platform split shortcut
* fix(remote): fence concurrent split focus intent
* fix(remote): harden split focus ordering
* fix(remote): preserve split focus after runtime refactor
* fix(remote): fence stale split focus gestures
* test(remote): keep split focus regression within line budget
main (#17161) reduced daemon-init.ts to a re-export barrel, so this branch's three
hooks moved to daemon-provider-state.ts, which now owns the module-level adapter:
- strandedDegradedProvider declared beside adapter
- replaceDaemonProvider retains an outgoing DegradedDaemonPtyProvider
- localPtysSurviveQuit added there and re-exported through the daemon-init barrel,
which is what src/main/index.ts and the fresh-import test harness both load
hasLiveFallbackPtys reads in-process state the execution host owns and is total,
so the survival answer has no "could not ask" case to collapse: it is a local
predicate, not a liveness verdict, and it still refuses to skip the quit warning
whenever a retired provider's app-owned shells are still running.
Two review threads on #17090.
The {accountId} marker is a shape, not a type, so createIssue rewrote any
customFields value that merely looked like a user. The renderer already knows
Jira's verdict — schema.type 'user', or an array of them — so it now sends that
key list and the host rewrites only those keys. A key it was not told about is
unknown, and unknown is left exactly as it arrived.
normalizeJiraUserSearchResult cast each users entry to JiraUser without checking
it, so a row with no accountId or displayName reached the picker, which keys and
labels rows by both. Each entry is decoded now; one unreadable row fails the whole
search into the unexpected-response path this PR already built, because a filtered
list would look like the site's full answer.
Moved the Jira IPC argument normalization into its own module to stay under the
300-line cap without a suppression.
Creating a Jira issue was impossible whenever a project marked Reporter
required. Jira's createmeta returns `reporter` with `schema.type: "user"`
and no `allowedValues`, so the create dialog rendered it as a plain text
Input and never searched anyone; whatever was typed left the renderer as a
bare string, which Jira Cloud rejects with "Reporter is required." — the
same for a pasted accountId.
- render a searched picker for any user-typed create field, scoped to the
target project (create has no issue key, so the existing issue-scoped
assignable search could not be reused as-is)
- report a failed user search in the dropdown instead of showing it empty,
including an unrecognized payload from an older paired host
- carry a picked user as a provider-neutral marker the execution host
resolves to Cloud `{id}` or Server/DC `{name}`, matching what updateIssue
already does for assignees
- keep a typed or pasted account id selectable, since Jira accepts one the
directory search never surfaced
- name the still-blank required fields under the form instead of leaving
Create disabled with no explanation
`jira.listAssignableUsers` keeps its array shape for paired older clients.
* fix(browser): close guest-owned split tab
* fix: check sourceId before toggling floating panel on close
The empty-panel toggle is the ambient fallback only. Guest-initiated
closes (with sourceId) target the main workspace and should not toggle
the panel.
* test(browser-split-shortcuts): remove terminal-mirrors close test and un
Removes test case that verified Cmd+W closes guest-owned browser splits when
active-tab mirrors point to a terminal, along with the helper function and
unused fixture properties that only that test required.
The quit decision reads two values through one reader, but only
`localPtysSurviveQuit` was defended against a malformed-but-truthy input.
Relaxing `isQuitting` to a bare truthiness check reddened nothing across the
131-test suite, while the same relaxation on its sibling redden 5.
`isQuitting` is not just the conjunct's other half: `collectWindowClosePtyIds`
drops SSH-backed panes from the evidence on a quit, so a truthy non-boolean
coerced to a yes closes over remote work with no probe and no warning, even
while the survival answer is a clean no. That third pin covers the read site
the two unit pins cannot.
The rule that only an explicit yes is a yes had two expressions. The one in
resolveLocalPtysSurviveQuit answers a typed in-process getter with a single
production call site whose every path returns a boolean literal: instrumented
across 35,022 tests it was evaluated 6 times, saw 'boolean' 6 times, and
discriminated 0 times, and both deleting the check and swapping it for Boolean()
reddened 0 of 115 while inverting it reddened 5. Deleted, since even a type
violation there is caught downstream.
The expression that survives is readWindowCloseRequestPayload, on the IPC hop
where the answer really is unknown. Its own tests were green, but its only
production call site was inline in the api object and no test in the tree
imported it — forwarding the raw payload instead reddened 0 of 11,136. Extracted
so the hop is reachable, and pinned: bypassing the reader now reddens 7,
weakening it to Boolean() 5, acking after the callback 1, echoing a raw
requestId 1, and dropping the unsubscribe 1.
Quitting skipped the running-process confirmation unconditionally. That is
correct in exactly one state: with the daemon adapter installed, quit's
killAllPty() is a no-op against it and the shells are the daemon's children,
which it declines to retire while a session is live — observed in production
with a daemon and its PTY shells up 12 days against an app main started that
morning. The bypass was written for that world but was never conditional on
it, so in the degraded states — daemon init threw, the fail-open elapsed, or
DegradedDaemonPtyProvider is installed and spawns fresh sessions in-process —
the same silent quit killed live local processes with no warning and no way
for the user to tell the two apart. Measured in an isolated node-pty probe:
the foreground worker died both on an explicit kill and on a bare parent exit,
while a detached-fork control survived. "There is no kill call" is not
protection.
Main now answers the one fact the renderer cannot see and sends it on
window:close-requested as localPtysSurviveQuit, resolved per request from the
existing daemonOwnsFreshPersistentPtys() — the adapter is installed, swapped
and lost over a run, so a value captured at window creation would be stale. A
quit skips the confirmation only on an explicit yes: a missing getter, a
throwing read, an absent or non-boolean wire field all resolve to "does not
survive" and ask, because an undetermined answer is not a yes.
No fourth reading of "is anything running" — the probe is the one #17044 and
#17077 settled, anyPtyBlocksWindowClose over readPtyProcessInspectionEvidence,
with the whole verdict vocabulary unchanged. Pane selection moves next to it
as collectWindowClosePtyIds. A quit drops panes on a RESOLVED SSH target:
shutdown marks the lease detached rather than terminated and the remote shell
is nohup-detached, so quitting ends nothing there and probing would only make
the quit slower. Only a resolved target — getConnectionIdFromState answers
undefined while the backing repo has not hydrated, and an unresolved host is
not evidence the work survives, so those panes stay in.
Nothing changes for an ordinary window close, which still probes every pane on
its execution host, and nothing changes on a quit with a healthy daemon. No
platform-specific behaviour is added: the gate is the same on all three, and
the win32 minimize-to-tray branch still short-circuits ahead of it. No new
stream opcode; the payload gains one optional-by-absence boolean that older
readers already fall safe on.
* feat(native-chat): port structured Codex sessions from restructure-recovery
Rebuilds the desktop structured native-chat implementation from
brennanb2025/native-chat-restructure-recovery (tip 4e31c08db3) on top of
current main as a single commit, scoped to the local Codex path.
Ported:
- Structured agent-session core: durable record store + single-writer lease,
canonical journal, agent-session wire host/attach/eviction/subscribers,
`agentSession.*` RPC surface (registered via ALL_RPC_METHODS; host-side
mobile allowlist included for wire compat), pty write gate, transcript
additions, and the Codex app-server adapter/launch resolution.
- Renderer: NativeChatStructuredSession view/composer stack, structured
launch path with the single-flight guard, local structured session tabs
sync, activation gate + structured inventory (read-only
`agentSession.handoffStatus` probe), agent-session tabs in the tab strip,
AI-vault structured session activation, and the settings pane with the
parent Experimental Chat UI toggle plus the nested "Use updated structured
native chat" toggle. New sessions require both flags, agent codex, no
prompt, and a local non-WSL, non-Windows-host execution host
(structured-native-chat-availability).
- Fixes 72c013cea6 (verified Codex launch recovery), 8ddbaf5e3d (defer
native terminal view switching affordances), and 4e31c08db3 (release the
launch gate after a visibility retry) with their regression tests,
including the third-launch-after-retry guard case.
- Cross-version agent-session wire test + CI lane, packaging entries
(proper-lockfile, agent-tooling asar excludes), and the wire-compat doc
section.
Deliberately not ported: mobile/ changes, the Claude structured runtime
(only the claude-transcript-branch-proof and claude-structured-owner-identity
leaf modules remain, backing the kept TUI-recovery arms), the terminal↔chat
adoption/handoff flow (`agentSession.adoptTerminal`/`requestHandoff`, the
handoff request engine, TUI adoption machinery, orca-runtime adoption
methods), renderer switching affordances and their dead leftovers, the
hook/subagent-status refactor cluster, and unrelated branch changes. The
crash-during-acquisition recovery path (restart handoff adjudication,
restore/reverse re-acquire, lease schema handoff keys) is kept because every
plain direct launch depends on it; a trimmed handoff coordinator exposes
only status/restore/close.
Branch edits that targeted files main has since split (ipc/pty.ts,
worktrees.ts, rpc/methods/terminal.ts, useIpcEvents, pty-connection,
store/slices/terminals.ts, runtime-types, web preload) were re-applied to
the split modules, preserving main's newer logic (Windows CIM fallback,
browser tab close rework, cold-restore resume flow, dispatcher threading).
Known seam: the mobile clipboard image-provenance CONSUMER gate ships
(agentSession.send refuses unproven mobile image refs with
agent_session_image_untrusted) but the producer hunk in
rpc/methods/clipboard.ts stays with the unported mobile cluster, so mobile
image sends into structured chat fail closed until that side ports.
* fix(native-chat): trust only authenticated local image uploads
* fix(build): preserve Windows process-tree patch application
* test(windows): include process creation time in addon fixture
* fix(build): run windows-process-tree node-gyp from the physical package dir
gyp expands the node-addon-api dependency by probing node, whose cwd
resolves to the package's physical directory in the store, so the emitted
target is a store-relative ../../../../node-addon-api@... hop. gyp then
resolves that hop against the rebuild cwd; from the node_modules
symlink/junction it escapes the store and configure fails with
"node_addon_api.gyp not found" (run 32999886072).
Rebuild from realpath(package dir) so both bases agree, matching how the
package manager itself runs native install scripts. The regression test
replays gyp's expansion+resolution against the planned cwd and fails
without the fix.
* fix(native-chat): keep chat tabs visible through terminal closes and empty-worktree launches
Two proven blockers in the native Codex tab contract:
closeTerminalTab pre-empted the canonical unified close. With one terminal
left it deactivated the worktree on a terminal/editor/browser-only check,
blanking a workspace that still held a renderable agent-session tab; with
two or more it pre-picked a successor from terminal entities only,
re-stamping the group active before closeUnifiedTab's MRU/neighbor repair
could land on the chat tab. Successor choice now defers to the unified
contract whenever the terminal has a unified row, and deactivation is
gated on the unified renderable count (matching leaveWorktreeIfEmpty),
with the legacy pre-pick kept only for terminals without a unified row.
A structured session created on an empty worktree was published into the
host's headless group while preserveLocalLayout froze the local layout,
leaving the tab in store but permanently off screen. A preserveLocalLayout
owner now always takes client-owned placement — repairing a rendered
leaf whose group record is missing, or materializing a rendered group on a
truly empty worktree — and applies the client-derived layout repair while
still rejecting host-authored layout.
Regression tests drive the real store through closeTerminalTab (git
worktree and folder workspace) and the real snapshot applier for the
empty-worktree adoption states; all fail without the fixes.
* fix(native-chat): close stale turns and retry rejected sends
* fix(native-chat): retire hosted rows on structured tab activation
* fix(native-chat): preserve rpc defaults across main merge
* chore: format remote wire compatibility guide
* test(native-chat): cover retry after unconfirmed send
* fix(native-chat): reload outbox on session switch
* docs(settings): disclose structured chat platform limits
* fix(native-chat): await Codex launch-home preparation
* fix(codex): align child-process allowlist with async trust bridge
* test(identity): update inventory for tab surface refactor
* fix(windows): preserve process-tree CRLF patch sources
* fix(native-chat): anchor an unmatched chat echo where it was sent (#16117)
* fix(native-chat): anchor an unmatched chat echo where it was sent
The reported symptom was old user messages replaying below every new turn, so the
conversation read as scrambled. The cause was not that the echo failed to match a
transcript row. Claude consumes a mid-turn send through a `queued_command`
attachment and writes no `type:"user"` record for it, so some echoes can never
match, and no amount of matching will change that. The cause was WHERE an
unmatched echo rendered: buildMobileNativeChatTransientData appended every pending
item after the entire transcript, so it re-read below each turn that landed
afterwards.
Render each echo directly after the transcript row it was sent against, using the
baseline the send already captures. An unmatched echo is then at worst a duplicate
in the right position rather than a scrambled one, and it stays visible. Echoes
sharing an anchor keep send order; a send with no baseline, or one whose anchor
folding dropped, still falls back to the tail.
Deliberately NOT fixed by deleting the echo. Inferring from send ordering that an
echo can never match, then removing it, loses the user's own text for a message
the agent did receive, and it cannot fire in the common case anyway - measured
drain groups are 1,017 of size 1 against 55 larger. It also escalates an existing
gap: the count pass has no baseline-tail guard, unlike the glue pass, while
`messages` is a 40-row window that head-trims, resets on reconnect and grows at
the front on loadEarlier, so a false landing there would license deleting a
DIFFERENT outstanding message.
That count-pass gap is real and left for a separate change; anchoring makes its
worst case a duplicate in place rather than a scrambled conversation.
* fix(native-chat): preserve folded echo anchors
* fix(native-chat): preserve forward-folded echo anchors
* fix(native-chat): keep leading folded echoes in place
* fix(workspace-cleanup): show git status for every row (#16690)
* fix(native-chat): refuse structured chat on every Windows execution path
canUseStructuredNativeChat only refused win32 when a project runtime
resolved, so folder-workspace keys (and other keys with no project
runtime) failed open into structured chat on Windows. Fail closed on
win32 unconditionally after the host check, matching the settings copy:
local macOS/Linux only; Windows/WSL/SSH stay on terminal chat.
* fix(native-chat): restore runtime refusals behind the win32 gate
506d375de3 replaced the project-runtime checks with a bare platform test,
so a WSL or repair-required runtime resolution would no longer refuse
structured chat off-win32. Keep the unconditional win32 refusal and
re-run the runtime resolution after it, so the gate does not depend on
the resolver's own platform guard. Tests inject WSL and repair-required
resolutions on darwin/linux and fail against the regressed gate.
* fix structured session journal durability
* fix structured tab active pointer after restart
* fix(native-chat): await optional lease renewal callbacks
* refactor(skills): extract install error messages
* fix(agent-session): harden recovery ownership
* fix(native-chat): retain panes across tab activation
* fix(native-chat): address round-one review findings
* test(native-chat): align integration coverage after main merge
* fix(native-chat): harden round-two reliability
* fix(native-chat): harden round-three reliability
* fix(native-chat): close round-four recovery gaps
* fix(native-chat): separate bounded journal key forms
* fix(native-chat): reset outbox error in render on session switch
The switch effect adjusted error state after the sessionId prop changed,
tripping react-doctor's no-adjust-state-on-prop-change on the changed-code
gate and flashing the old session's banner for a frame. Reset it with the
render-time previous-value guard instead.
* fix(native-chat): invalidate stale outbox settlements
* test(native-chat): restore settled-error session-switch regression
a6e2379bd1 replaced this test with the in-flight settlement race test,
leaving the render-time error reset unpinned: deleting the reset block
still passed the whole native-chat suite. Keep both scenarios pinned;
they are distinct (settled error clears on switch vs stale settlement
invalidated in the commit-to-passive window).
* test(wire): make release checkouts race safe
* test(wire): pin cross-process checkout single-flight and importer specifier contract
* test(wire): harden release checkout lifecycle
* fix(build): drop CR-byte residue from windows-process-tree patch
The two trailing CR bytes on the patch's deletion lines are a proven
no-op: pnpm hashes patches CRLF-normalized (both forms hash to the
lockfile's 946ffb2b) and materializes this package without applying the
patch in either form, so the load-bearing build edits come solely from
applyWindowsProcessTreeBuildFixes() (#16947), which handles both source
EOL forms. Restore byte-identity with main and repin the contract test
to the post-#16947 reality: LF-only patch bytes plus lockfile hash sync.
* fix(native-chat): skip empty startup recovery
* Fix draft review sidebar actions
* Drop unused React import in draft actions test
The automatic JSX runtime makes the default React import dead, and
tsconfig.tc.web.json failed the branch on TS6133.
* Add localization keys for draft review actions
The new Ready for review controls introduced five untranslated keys and
the static analysis job requires them present in en.json.
* Name the draft action for what it does
The button read 'Ready for review', which states a status rather than an
action, directly under a header already showing the PR state. The i18n
key (markReady), the in-flight label ('Marking ready...') and the success
toast ('marked ready for review') all already used the verb.
A failed pgrep/ps probe on a relay host resolved as
{foregroundProcess: null|fallback, hasChildProcesses: false}, which the
agent-completion monitor read as positive exit evidence and turned into
a process-exit completion. Probes now return live/unverifiable/exited
verdicts, the relay publishes them in a new optional processEvidence
field beside byte-identical legacy fields, and the monitor refuses to
treat an unverifiable probe as exit evidence.
* fix(pty): key buffered pre-attach exits on the PTY incarnation, not a clock
A restarted SSH relay renumbers PTYs from pty-1, so a fresh spawn is routinely
handed an id whose previous shell is still emitting a late exit. #16970 stopped
that exit blanking the new tab by dating every buffered record and dropping
anything older than the spawn request. That fence is a clock, so it cannot judge
a stale exit that arrives AFTER the request left — the residual risk #16970
documented.
Thread the incarnation main already puts on the pty:exit payload (and the
pty:spawn reply) through preload to the pre-handler buffer, so a buffered exit
names which lifetime of the id died. An exit disagreeing with the incarnation
now attaching is discarded whenever it arrived.
Only a positive disagreement discards: absence stays "unknown", never a
mismatch, so hosts that predate the field keep #16970's behaviour exactly. The
fence is retained for the two cases with no incarnation to compare — buffered
bytes (pty:data carries none) and unnamed exits.
No wire change: incarnationId was already published on the relay's pty.exit
notification and pty.spawn reply, and already forwarded over the in-process
pty:exit / pty:spawn IPC. Only the preload types and the renderer read it now.
* fix(pty): read the incarnation through the shared guard, not truthiness
A malformed incarnation is evidence of nothing, so it must read as "unknown"
rather than as a value that disagrees with every well-formed one — otherwise a
non-string on the payload would discard the very exits the buffer exists to
deliver. Route both the record and the comparison through the existing
isPtyIncarnationId guard.
* refactor(pty): name the bounded-map helper after what it does
It evicts the oldest entry when the map is full and the id is new; it reserves
nothing. Rename only — no behaviour change.
* fix(pty): key the buffered-exit STORAGE on the incarnation too, not just the check
Review caught a swallowed exit. Keying only the comparison on the incarnation
while the storage stayed one slot per pty id left the two races this buffer
exists for able to cancel each other out:
1. the freshly spawned shell dies before the pane attaches -> its exit (X) is
buffered;
2. the relay flushes the previous owner's exit for the same recycled id (W),
which OVERWRITES X in the single slot;
3. the spawn reply names X, so the identity discard drops W -- the only
record left.
registerExit then finds nothing and the pane binds to a PTY that is dead and
will never be reported dead: a hang instead of the blank tab #16970 fixed.
Store one record per lifetime, capped at 4 per id, so W can never evict X. A
duplicate exit for a lifetime replaces that lifetime's record rather than
crowding out another's; drain still delivers the newest survivor, preserving
the last-write-wins behaviour a single slot always had.
* fix(pty): filter buffered exits by lifetime inside the buffer, not at call sites
Review found the identity was enforced only where connectIpcPty calls the
discard, while preHandlerPtyExit has several other consumers. The severe one is
registerEagerPtyBuffer: both background launchers spawn directly and then drain
whatever is buffered for the returned id, so a relay-recycled id holding the
previous owner's exit tore a freshly launched agent session down seconds after
it started -- no fence, no admitPtyId, no identity check at all.
Move the rule into the buffer: every read goes through
admissiblePreHandlerPtyExits, so a record proven to belong to another lifetime
is unreachable by construction rather than because each caller remembered to
discard first. hasPreHandlerPtyExit/drainPreHandlerPtyExit take the asking
lifetime; registerEagerPtyBuffer and registerExit thread it through, and both
background launchers pass the incarnation their own spawn returned.
A reader that cannot name an incarnation still sees everything, which is the
honest answer -- it holds no evidence to discriminate with. That keeps the
pre-spawn fast path in connectIpcPty behaving exactly as it does today; see the
PR for the consumers this still does not cover.
* chore: drop unrelated formatter churn in reliability-gates.jsonc
Repo-wide oxfmt reindented pre-existing entries in a file this change never
touches. Keep the diff to the PTY incarnation work.
* fix(browser-preview): require explicit preview capabilities (STA-5758)
Scope document reads to approved directories, confirm external links before opening them, revoke grants with tab lifecycle, and keep document-preview session state rollback-safe across mixed client/runtime versions.
* Harden document preview lifecycle and permissions
* Document preview DNS prefetch residual
* Make preview E2E guest focus explicit
* fix(browser-preview): entry-file-only authority for root-level docs, contained chip layout, re-issued gate paths (STA-5758)
A grant whose document directory is its own request base — a doc at the
workspace root, or outside any workspace — now reads nothing but the entry
file until the reader approves a directory, at both the lexical and the
canonical containment pass. The DNS-prefetch residual can only beacon what
the page can read, and a root-level document could previously read the
whole worktree silently.
The identity chip's host badge overflowed the chip's layout box under
squeeze (Linux CI): every row member can now shrink and truncate, verified
by a width sweep in isolated Chromium down to ~120px chips.
The Allow banner says what it grants: 'Allow folder', reading files in the
named directory, for the life of the preview.
The reliability-gate manifest command, testFiles entry, assertion refs and
dated evidence naming the deleted doc-preview-external-link-bridge.test.ts
are re-issued at doc-preview-external-link-confirmation.test.ts with a
fresh 189/189 run; the focus-gate assertion text follows the shipped gate.
* fix(browser-preview): hide the chip identity row below 24rem instead of clipping it, ellipsize the host badge, catalog the new i18n keys (STA-5758)
CI's preview pane leaves the chip ~40px: no truncation shows anything
there, so the Workspace-file label and host badge now hide whole below a
24rem container threshold sized so that visible implies contained. The
badge text gains an inner text box — text directly inside the flex pill
clipped both ends with no ellipsis. The e2e geometry oracle asserts
containment when the row shows and the threshold when it does not.
verify:localization-catalog: the hardening's new preview keys (and the
renamed allowDirectory) join en.json via sync:localization-catalog.
* feat(browser-preview): batch blocked folders into one access decision (STA-5758)
Sequential per-folder banners trained the allow reflex without adding
judgment — a reader cannot weigh assets/ against data/. The banner now
accumulates every folder a load surfaces, names them (three, then a
count, full list in the title), and grants exactly that set with one
Allow-N-folders click and one reload. Dismiss fences the whole named
set. The map lives behind a ref with a version tick so a dismissal
fences an offer landing in the same event batch.
* fix(workspaces): add collision-safe worktree identity
* fix(workspaces): read worktree metadata per host and repair ambiguous identities
The canonical identity store landed write-only: getWorktreeMetaForHost had no
production callers while setWorktreeMetaForHost kept the legacy projection only
for the first known owner, so a second host's edits persisted and were never
read back. Wire the listing paths through host-qualified reads.
An ambiguous alias was also unrecoverable — reads returned undefined and writes
threw forever, and the throw escaped the detected-worktree loop, emptying the
whole repo's sidebar. Fail open onto the most recently active instance instead.
- collapse ambiguous aliases deterministically and persist the repair
- reclaim identity rows in the metadata GC so they cannot outlive their locator
or resurrect onto a worktree recreated at the same path
- drop every host's rows when a locator is removed outright, not just the owner's
- honour an explicit instanceId so the stale-lineage rotation guard still works
- scope a rename to the moving host; other hosts keep their own locator
- prefer the project host setup matching the repo's own execution host, so a
repoId registered on two hosts no longer stamps the wrong one durably
- reject an unencoded `|` in a host id, the invariant the alias delimiter needs
- drop the never-populated hostGeneration from the canonical key
* fix(workspaces): close remaining identity review gaps
* fix(workspaces): close remaining review gaps
* fix(workspaces): address review and CI regressions
* test(workspaces): update host-qualified metadata expectations
* fix(workspaces): preserve ambiguous identity records
* fix(workspaces): snapshot metadata during listing
* test(workspaces): mirror listing metadata snapshot in windows fixture
* fix(workspaces): preserve identity routing for metadata writes
* fix(workspaces): scope stale metadata cleanup by host
* fix(workspaces): rekey identities on SSH readoption
* fix(workspaces): fail closed for ambiguous board ids
* perf(workspaces): snapshot metadata across catalog listing
* fix(workspaces): retain neighboring manual order updates
* test(workspaces): cover ambiguous board id index
* fix(persistence): harden host-qualified worktree metadata
* refactor(shared): split project host setup lookup
* refactor(workspaces): simplify host-qualified metadata
* Add all-host automations with scoped ownership and multi-authority suppo
Enable automations to run on multiple hosts (SSH targets and local) with
owner-fenced mutations, scoped list queries per host, and conflict
resolution. Introduces desktop and runtime authorities as distinct
automation storage owners, with per-host caching, invalidation, and
retry scheduling on the renderer. Captures registration generations for
SSH hosts to survive re-adoption. Adds CLI support for destination
selection and conflict recovery.
* Filter automation create projects by destination host
Only offer projects available on the selected destination, preventing
the mismatches that would fail at submit time. Auto-adjust the project
selection if it becomes unavailable when the destination changes.
* Add runtime storage authority support for automations
- Support both runtime and desktop as automation storage authorities
- Make owner preconditions optional for legacy-client compatibility
- Cache automation list projections to improve performance
- Add per-row repo/worktree resolution for cross-authority collisions
- Extend automation.list RPC to always include owner metadata
* Replace child_process.execFile with runProcess for external automations
- Migrate external-manager to use cross-platform runProcess wrapper per child-process safety policy
- Abstract electron app/ipcMain APIs in orca-runtime via environment accessors
- Install fake app environment in automation tests for consistent setup
- Reorganize imports to use specific module paths (ssh-target-registry, agent-detection, browser-error)
- Remove external-manager from child-process import allowlists (no longer violates direct import)
* Unify desktop automation CRUD onto the local runtime RPC surface
The desktop authority now speaks the same automation.* RPC contract as
remote runtimes, via callRuntimeRpc({kind:'local'}) -> runtime:call ->
the shared RpcDispatcher. The automations:list/listRuns/create/update/
delete/runNow IPC arms, their preload members, and every renderer
desktop-vs-runtime transport fork are retired; the runtime methods are
the single implementation of scoped lists, owner fencing, and change
publication for both transports (mobile clients already exercised them).
The desktop probe scheduler's priority lease survives the move as an
AutomationService hook the IPC registration installs and the runtime
methods take, so Orca's own automation traffic still parks queued
external-manager probes.
External-manager scope arms and dispatch-loop plumbing stay on IPC by
design; automation change events keep their existing channels (renderer
ingestion already converges them by authority).
* Remove automation ghost SSH tombstone scanning
This functionality for synthesizing tombstones for automation-referenced SSH
targets is no longer needed as part of the automation system refactoring.
* Refuse orphan automations at dispatch time, not migration time
Remove migration-time disabling of orphan automations and the `enabledDecidedBy` field. Dispatch now refuses orphans at runtime instead, simplifying state management and UI. Orphans are left unstamped and enabled; dispatch refuses to run them via `resolveAutomationRunTarget`.
* Show all automations in flat table with unified filter menu
- Replace host picker component with comprehensive Filters menu supporting status, last run, agent, and host filters
- Flatten automation list layout to single table instead of host-grouped sections
- Add Host column to display execution host for each automation
- Display active filters as removable pills below toolbar
- Delete unused AutomationHostPicker* components
* Add automation owner fencing and destination validation
- New AUTOMATION_OWNER_FENCING_RUNTIME_CAPABILITY for owner preconditions; legacy clients get owner metadata snapshotted at RPC boundary for compatibility
- Editor captures and revalidates automation destination before save, preventing silent retargeting if SSH infrastructure changes mid-edit
- SSH target types now isolate renderer-authored fields; generation is server-owned and stripped by IPC handlers
* Route automation recovery actions to the origin host
When an automation action fails due to owner fencing, recovery verbs
("Update server", "Reconnect") must run on the host where the refusal
originated: the row's captured owner for row operations, or the
destination the create dialog captured, not the list's filtered host.
* Remove external manager scope limitation notices
Consolidate create destination eligibility checks with a unified predicate
and fix the bug where desktop repo IDs could be sent to runtime hosts where
they cannot resolve.
* Persist only store-derived automation contexts, not client-perspective o
Store contexts must never be based on client-provided runContext or sourceContext
values—clients speak a different perspective (e.g., 'runtime:<id>' for host IDs
they assign), and persisting those makes the store projection orphan automations
it actually owns. Derived contexts now take precedence in create and update paths,
with explicit null still honored to clear a value. Tests verify this by simulating
drift after storage and confirming that moves re-derive while toggles preserve.
* fix(crash-reporting): see the renderer memory the heap counters never report
Windows renderer crash 36048e26 arrived with 618MB of private renderer memory
and a `renderer_memory` breadcrumb reporting a 150MB V8 heap. Both numbers were
right: xterm scrollback lives in `Uint32Array` backing stores and glyph atlases
live in GPU transfer buffers, and neither is counted by `usedHeapSize`,
`mallocedMemory`, or Blink's allocator.
That made the report unanalyzable. `renderer_memory_highwater` is the crumb
carrying the subsystem census that names what grew, and it is armed on
`usedHeapSize / heapSizeLimit`. At 150MB of a 4192MB limit that ratio is 3.6% —
nowhere near the 60% mark — so the census never reached a single one of these
reports.
Measured on Windows (6 worktrees x 4 terminal tabs, 8000 lines each, this app
at 4218d505): filling 24 mounted panes moved the renderer working set from
210MB to 656MB while `usedJSHeapSize` stayed at 43MB for the whole run.
Sample the renderer's own OS footprint through `process.getProcessMemoryInfo()`
(available in the sandboxed preload) and:
- report `privateMB`, `residentMB`, and `outsideHeapMB` — the footprint minus
everything V8 and Blink admit to holding — on every `renderer_memory` crumb;
- arm the highwater census on private-footprint marks (600MB / 1000MB) as well
as the heap ratio, so growth outside the JS heap now carries the pane and
store census that names it.
The footprint read is async, so a sample annotates with the previous read and
refreshes in the background: one interval of staleness is irrelevant to a
footprint trend, and awaiting it would make every sample reentrant. A shell
without the bridge, or a runtime that withholds the read, keeps sampling
exactly as before.
Retained-breadcrumb keys now distinguish the two threshold ladders; keying only
on `thresholdPct` collapsed every footprint crumb onto one slot.
crash-diagnostics.ts split at the max-lines budget: memory sampling moves to
renderer-memory-sampling.ts and the shared payload shaping to
crash-breadcrumb-data.ts.
* fix(crash-reporting): retain all renderer memory marks
* fix(native-chat): stop the spinner on a not-yet-flushed transcript
A brand-new agent session can take minutes to write its first JSONL line,
and one that is never prompted never writes it at all. The host emitted no
stream frame until the file resolved, so every native-chat client sat on a
bare spinner with the composer enabled but the transcript blank -- forever,
in the never-prompted case.
The resolve poll now reports the transcript as pending after a short grace,
and both host handlers emit a `pending: true` snapshot. It is deliberately
not a plain empty snapshot: an empty window sold as a settled read would
capture over retained history and unblock consumers that require a
trustworthy transcript (the launch-draft adoption would re-offer a prompt
the agent may already have taken).
Clients render it as the "start a chat" empty state while keeping the read
unsettled -- `awaiting-transcript` on mobile, an `awaiting` read phase on
desktop, which also stops the seed loop expiring into an error card for a
session that is simply new. New optional field only, so older clients
ignore it and still stop spinning.
* fix(native-chat): negotiate pending transcript frames
* Add skill deletion with cross-platform transaction safety
Implements end-to-end skill removal with placement enumeration, dependency guards, and transactional recovery. Covers native, WSL, and remote hosts; users can delete canonical directories and alias placements (symlinked directories or files) in a single atomic batch. Includes UI selection flow, preview, confirmation, and results band. Block reasons (bundled, plugin, unowned, stale) gate deletions that would fail or contradict user intent.
* Organize IPC handlers into module subdirectories
Move register-core-handlers and skill-delete-ipc-handlers into
dedicated subdirectories for improved code organization and to
reduce the flat structure in src/main/ipc/.
* Make skill deletion recovery transactions idempotent
Defer journal cleanup until both staging removal and receipt cleanup succeed, leaving the journal in place for startup to retry if either operation fails. This ensures the recovery process is safe to run multiple times without leaving partially-deleted skills.
* Consolidate skill-delete files into dedicated module
Reorganize skill deletion functionality into a modular structure under
`src/main/skills/skill-delete/` with simplified file names. Remove the
redundant `skill-delete-` prefix from file names since they now live in
the dedicated directory. Update all import paths throughout the codebase
to reflect the new structure, including imports from IPC handlers and
RPC methods.
* Fix broken import paths and add deletion robustness improvements
Import paths using `..//'` were invalid and broken. Replace with explicit
module names (`skill-discovery-sources`, `skill-install-filesystem`, etc.)
to clarify dependencies.
- Bind WSL filesystem methods to preserve `this` context
- Keep recovery journal when rollback rename fails, so startup can retry
- Skip symlink-based tests on Windows where they cannot run
- Only treat ENOENT/ENOTDIR as empty directories; propagate other errors
- Fix cross-platform path parent calculation to handle drive roots
- Replace shared constant with localized string for user-facing message
- Use `runProcess` for WSL integration test instead of bare `execFile`
* Add batch limit for skill deletion and improve host availability checkin
- Limit concurrent deletions to prevent remote host overload
- Add retry logic for capability probing to handle transient unavailability
- Add reprobe() method to recheck capability after errors or user refresh
- Fix status logic: receipt cleanup is best-effort, completion depends only on content removal
- Improve error message for unreachable hosts
* fix(agent-status): retire panes whose agent process is gone (STA-4612)
Agent status can hold `working` on a pane where no work is outstanding, and
nothing closes the gap. A pane's Claude state is a join of a lead turn and three
latches — the subagent roster, the background-task gate and the session-cron gate
— and each is set by a hook and cleared only by another hook. Claude Code emits
no terminating hook on `/exit`, `/clear`, Ctrl+C, crash, SIGKILL or terminal
close, so every one of those latches is a claim with no owner and no expiry. The
join is also materialised at ingest time and persisted, so a stale `working`
survives restart and blocks hibernation, which requires `done`.
Registering `SessionEnd` is not the fix: it covers roughly a third of exit paths
(measured on 2.1.231/2.1.233; upstream anthropics/claude-code#17885 and #6428 are
both closed as not planned). Nor is a TTL — `AGENT_STATUS_STALE_AFTER_MS` only
decays the sidebar dot at read time while the stored row stays non-terminal.
So the backstop is built from evidence Orca already owns.
A session id that changes means the conversation was replaced. On the first hook
of the new session — whatever that hook is — the previous session's own claims
are void: its session crons and its one-shot subagents. Deliberately not voided:
the background-task gate (a background shell is an OS process that survives
`/clear`, and the previous inventory is positive evidence it was running), and
`confirmedTeammate` rows (persistent in-process teammates a lead swap cannot
end). The lead record is left to the incoming event's own fold.
A certified process exit retires the pane. Orca already does this on every
attributable PTY exit — `clearProviderPtyState` resolves the pane key and calls
`clearPaneState` — but that resolution depends on the spawn-time `ptyPaneKey`
mapping, which a restored or reattached PTY may never rebuild. Those panes keep
their row and latches for good. `onPtyExit` knows the keys teardown could not
resolve, so it reconciles them from its own records. The certificate is
`exitCode >= 0 || hostExitConfirmed || providerExitObserved`: a synthetic `-1`
from a failed stop is not a death (the PTY can have survived it), while a real
exit can also report `-1`, so neither the code nor the SSH surface predicate is
sufficient alone. `providerExitObserved` is additive and separate from
`hostExitConfirmed`, which also drives the liveness verdict and the SSH surface
decision.
A confirmed shell foreground is the `/exit` case: the agent died, the shell
lived. That already dropped the row, but through `agentStatus:drop`, which by its
own contract preserves a live pane's caches — so every latch survived and the
next event resolved the pane back to `working`. It now routes through the
reconciler instead, gated on a per-pane accepted-status generation rather than
row identity: the confirming process read can take seconds, and `updatedAt`
cannot order two writes inside one millisecond (the store deliberately admits
equal timestamps).
Cold start generalises the same way. The startup sweep required a restored
subagent roster, so a stranded lead row, background-task gate or cron gate — the
shapes with no child event left to reap them — were never candidates.
Hibernation needs no change: with the above, those rows become genuinely `done`
and the lockout resolves through the front door. A `restoredUnconfirmed` bypass
in the planner would let it reclaim the heap of an agent that may be working.
Not included: folding `background_tasks` from a child-attributed `SubagentStop`.
Writing its test surfaced #11838's deliberate assertion that child inventories
are not authoritative for lead-owned background work, and the listener says the
same — "background_tasks is trusted only where unambiguous". An empty list on a
`SubagentStop` does not prove the lead's shell ended, so the fold would have
cleared a gate on evidence that establishes nothing.
STA-4119's live-side question — whether a genuinely live background shell should
hold the lead row after the lead turn ends — is untouched. This change extends
gate-clearing to zero new triggers.
* fix(agent-status): make the confirmed-shell reconcile survive its own drop
The /exit leg never fired. `settleDeferredCommandFinishedStatusDrop` runs the
paired drop before the reconcile, and `dropAgentStatus` cleared the per-pane
accepted-status counter the reconcile's guard then read — so the guard compared
a live anchor against a zeroed counter and skipped itself on every pane that had
a status row, which is every pane worth reconciling. The existing test passed
only because it used a pane with no row, where the drop early-returns and both
sides read 0.
Stop keying the guard on a counter a sibling teardown path can reset: the
ordinal is now stamped on the row itself, derived from the row it replaces, so
there is no side table to clear and a batched burst lands the same ordinals as
the equivalent sequential writes. A removed row means "nothing reported", which
is exactly what the paired drop leaves behind.
Also:
- Keep the `providerSessionOnly` resume identity that the paired dismissal mints
when the shell outlived the agent; a certified PTY exit still takes it, since
there is no pane left to resume into.
- De-vacuum two guard tests. The confirmed-teammate pin never anchored a session
owner, so the void it claimed to survive never ran; the unavailable-inspection
pin asserted before the confirm ladder settled. Both now fail when their guard
is removed.
- Derive `hasLiveClaimsForPaneKey` from a predicate that lives beside
`clearPaneCacheState`, so a new latch cannot be added to the teardown and
silently missed by the claim check.
- Drop the unreachable compact-`trigger` clauses; SessionStart is the whole guard.
- Cover the connectionId arm of the exit certificate, where a provider-observed
death and a preserved SSH surface are deliberately independent.
* fix(agent-status): keep agent-status-types under its line cap
main already sits exactly at the 300-line max-lines cap for this file, so the single
`acceptedStatusSeq` field this branch adds pushed it to 301 once main's observation
facet merged in.
Declared the field as a mixin beside the observation facet instead. Both are per-write
facets mixed into `AgentStatusEntry` rather than fields a reporter supplies, so they
belong together — and the capped file loses a line rather than gaining one, since it
already imports from that module. No lint suppression.
* fix(agent-status): collapse the entry facets into one intersection
The previous attempt still tripped max-lines: two mixins on one intersection wrap
across two lines under oxfmt, so removing the field line bought nothing.
Expose a single AgentStatusRowFacets that already includes the observation facet, so
the entry intersects one short name on one line. The payload keeps intersecting the
observation facet alone — it must not carry the renderer-local ordinal.
Verified by formatting first and then linting, which is the order that catches this.
* fix(agent-status): retire resume authority with dead panes
Adds a configurable, unbound-by-default `dashboard.toggle` action that toggles the Agent Dashboard (in-window drawer or pop-out, per the existing mode setting).
- Wired through window-shortcut-policy, main-window dispatch, browser-guest dispatch, preload, and the renderer IPC handler.
- Opening the in-window drawer reveals the sidebar first; closing leaves it alone.
- Gated on the `experimentalAgentDashboardPopout` experiment, and the Settings shortcut row is hidden while that experiment is off.
* fix(agents): lift the pane retirement fence when a live PTY re-attaches (STA-4114)
A detach/reattach cycle retires the pane on both sides — the main hook
server's closedAgentStatusPaneKeys and the renderer's
recentlyRetiredAgentStatusPaneKeys — and nothing ever cleared either one.
The pane then rejected every later working/done event for the rest of its
life while Pi kept running normally in the same PTY.
Bind the fence to the fact it asserts: retirement claims the pane is gone,
and binding a live PTY to that exact pane disproves it. Clear both
tombstones at the spawn/attach chokepoint and at the daemon-backed reattach
path, so recovery does not depend on the agent starting another turn — a
pane re-attached mid-turn only has agent_end left to report, and one
re-attached while idle emits nothing at all. Closed-tab tombstones are a
separate, stronger claim and are deliberately left standing.
* test(agent-hooks): re-arm the idle re-attach test against a turn-boundary fix
The idle re-attach assertion posted only before_agent_start, which #14626
turns into a fence-lifting turn boundary. Under that change the test passes
whether or not restorePaneAuthority runs, so it stops pinning this PR's
mechanism. Assert first on agent_end — a non-turn event — so the test proves
the fence was already down when the hook arrived.
Verified: with restorePaneAuthority neutered AND before_agent_start added to
the restart predicate, the old assertion passes and the new one fails.
* fix(agents): lift a retired pane's whole fence, aliases included (STA-4114)
Retirement fences the pane, its resolved owner, and every alias of it, then
deletes those aliases. Restoring only the key handed to us left the rest
standing — and a detached pane's process keeps posting the key it launched
under (server.ts:1614), so the canonical re-attach case stayed suppressed
with the fence apparently lifted. Verified against the real omp binary: the
row came back under the stale launch pane instead of the detached owner.
Record what each retirement fenced and replay it as a unit, rebuilding the
aliases it deleted. Keys and aliases belonging to a closed tab are skipped,
so the stronger claim survives and a live process is never routed back into
a closed tab. The record is indexed by every fenced key and bounded at 1024
like the maps it mirrors; an evicted record degrades to the old behaviour.
Also records why the renderer's restore IPC is deliberately unguarded: that
map is not a mirror of main's (retirePtyAgentLaunchAuthority fences main
directly on command-finished and PTY exit, and nothing pushes it back), and
it is per-window and non-persisted, so gating the send on a local tombstone
reintroduces this bug for exactly those panes.
* fix(codex): stop a transient filesystem error from logging out the active account
A single unreadable read of a managed Codex home's ownership marker cleared the
user's active account selection, permanently. On Windows any exclusive lock —
Defender real-time scanning, a backup agent, a sync client — makes every read of
that marker fail with EBUSY, and the background rate-limit poll runs every 15
minutes plus once at every app start.
Root cause: the ownership gate answered two very different questions through one
channel. "This home is not ours" (a successful observation that failed a trust
check) and "we could not read it" both surfaced as a throw, which the caller
flattened to null, which three call sites took as proof the home was
untrustworthy and wrote activeCodexManagedAccountId: null.
Refusing to USE an unverified home is correct. Erasing the user's account
selection because a file was briefly locked is not.
The gate now returns a tri-state verdict. `untrusted` comes only from a proven
trust failure or a definitive ENOENT/ENOTDIR where absence is itself the
verdict; every other filesystem exception is `indeterminate`. Only `untrusted`
may touch persisted state.
Because `null` already meant "fall through to the system default" on both the
launch and poll paths, not-clearing on its own would have run a DIFFERENT
account behind a UI still showing the selected one. So the refusal needed real
channels rather than a sentinel:
- the poll returns an explicit skip; returning null would not have skipped at
all, since the fetcher maps null to ~/.codex and would have spawned a
token-refreshing app-server inside the user's real credential home
- pane launch throws a typed temporary-unavailability error that both PTY
implementations convert into a clean refusal with a retry message, including
the re-resolution after the async auth-readiness wait
- automatic session resume resolves the selected home eagerly, so an unreadable
account can no longer be silently replaced by another one in the ranking
- config-sync status reports a distinct managed-home-unavailable stall instead
of "synced", with a bounded renderer retry so it clears on its own
Also fixes the ticket's second symptom. The status bar's Sign in button called a
re-auth that captured the selection before login and restored it after, so
re-authenticating a deselected account restored `null` — a successful login that
left the account inactive, with no success toast to distinguish it from failure.
It now activates the account it just signed in, but only when the pre-login
selection was empty, so it cannot silently switch accounts for multi-account
users, and it runs the same restart prompt an explicit switch does.
No retry or grace window inside the synchronous gate: it runs on the Electron
main process in a loop over accounts, so a sleep there would freeze the UI.
Recovery is simply the next readable evaluation.
The WSL lane has the same class of defect, including one path that deletes a
credential mirror. It is pre-existing, unreachable from these host code paths,
and deliberately left for its own change; the host clearing sites cannot reach a
WSL account because getSelfContainedManagedHostAccount excludes them.
Fixes STA-4422
* test(codex): cover pending reset home ownership
* fix(terminal): preserve Option-composed ASCII input
* fix(terminal): preserve Option keyboard protocol semantics
* fix(terminal): complete Option keyboard event encoding
* fix(terminal): harden Option input encoding
* fix(terminal): close keyboard protocol fallback gaps
* test(terminal): prove Option-composed ASCII reaches the pty end to end
The Option-compose fix had unit coverage only. This drives a live Electron
pane whose kitty flags are armed by the application's own CSI > 1 u and
asserts the bytes at the pty boundary: composed `@` and Shift-layer `\`
arrive as text, configured Option-as-Alt still reports the layout-resolved
chord, and a non-ASCII glyph still reaches the app as its alt hotkey.
Restoring the pre-fix policy fails exactly the two composed-text scenarios.
Also records the ASCII rule's rationale where the rule lives, not only in a
test comment.
* refactor(terminal): drop the unread Option layers from the layout snapshot
The native helper computed an Option and Option+Shift character for every
key, shipped both over IPC, validated them in the parser and cached them in
the renderer — but no production caller ever asked for them. Only the base
and Shift layers are read, and Shift is the one the web layout map cannot
supply, which is why the helper exists at all.
Removing them halves the helper's UCKeyTranslate work per key and drops the
option parameter that six signatures were threading through for nobody.