Commit Graph
64 Commits
Author SHA1 Message Date
Neil 96f0c683eb Support multiple Linear workspaces (#1917) 2026-05-15 11:32:46 -07:00
Jinwoo Hong 618f39d179 Add web runtime client support 2026-05-15 05:44:25 -04:00
Neil f81b3f219f Add Gitea hosted review support 2026-05-15 01:56:05 -07:00
Neil 2d44ee83b4 Add Space manager V2 safeguards 2026-05-14 23:30:22 -07:00
Jinwoo HongandOrca a22717bb35 Refactor runtime app architecture (#1878)
Co-authored-by: Orca <help@stably.ai>
2026-05-14 23:13:37 -07:00
bca39bc928 Add GitLab and Bitbucket hosted review support (#1839)
* feat(gitlab): add foundational glab runner, types, and issue operations

First slice of GitLab support, mirroring src/main/github/ structurally
without refactoring the working GitHub path.

- runner: add glabExecFileAsync parallel to ghExecFileAsync (same WSL
  routing and retry policy; HTTP-status / network classification is
  provider-agnostic so the existing helpers are reused).
- types: GitLabProjectRef carries host alongside path so self-hosted
  instances and nested groups round-trip through the IPC layer. Mirror
  shapes for MR/issue/work-item/comment/file/assignable-user.
- gitlab/gl-utils: concurrency limiter, error classification, project-ref
  resolution honoring upstream/origin preference, and known-host
  discovery via `glab auth status` so non-gitlab.com remotes are
  recognized after the user authenticates.
- gitlab/mappers: pipeline-job → check-status mapping, MR state
  resolution (including draft inferred from `Draft:`/`WIP:` title
  prefix), and pipeline rollup.
- gitlab/issues: full issue CRUD via `glab api` against URL-encoded
  project paths, with the same upstream/origin preference semantics as
  the GitHub side.

63 unit tests passing across gl-utils / mappers / issues. Both
typecheck:node and typecheck:web clean.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(gitlab): preflight glab auth check and URL parser

- preflight: probe `glab --version` + `glab auth status` alongside the
  existing gh checks. PreflightStatus.glab is optional so renderer call
  sites that only render git/gh keep typechecking; consumers gating on
  GitLab affordances opt in via `glab?.authenticated`.
- gitlab-links: parse GitLab issue and merge-request URLs honoring (a)
  arbitrary self-hosted hosts via the project-internal `/-/` separator
  rather than locking to gitlab.com, (b) nested group paths, and (c)
  GitLab's `!42` MR convention alongside `#42`.

26 unit tests added (5 new preflight cases, 21 URL-parser cases). Full
typecheck (node + cli + web) clean. Pre-existing runtime/orchestration
test failures unrelated to this branch — Node 25 vs the project's
pinned Node 24 engine.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(gitlab): MR list/get + paginated `glab api -i` helper

Lean mirror of github/client.ts focused on the workspace-from-MR
keystone. Adopts GitLab-native filter semantics (Open / Merged /
Closed / All) instead of porting GitHub's search-DSL — that path is
covered by the upcoming My Todos surface.

- gl-utils: glabApiWithHeaders + parseGlabApiResponse for strict
  pagination via X-Total / X-Total-Pages on `glab api -i` output.
  CRLF / LF tolerant; status line never leaks into the headers map.
- types: MRListState, GitLabPagedResult<T>, ListMergeRequestsResult.
- mappers: mapMRToWorkItem + mapIssueToWorkItem produce the unified
  GitLabWorkItem shape the picker consumes. isCrossRepository derived
  from source_project_id !== target_project_id; deterministic id
  fallback when the per-MR detail endpoint omits global id.
- client: getAuthenticatedViewer, getMergeRequest (with head pipeline
  rolled up), getMergeRequestForBranch (mirrors github/getPRForBranch
  semantics including refs/heads/ stripping and detached-HEAD guard),
  listMergeRequests (paginated), getWorkItemByProjectRef (paste-URL
  flow). Re-exports issues + projectRef helpers so callers don't have
  to know the gl-utils module split.

35 new tests (98 total in src/main/gitlab/), full typecheck clean.
Tests split into client.test.ts + client-mr.test.ts to stay under the
oxlint max-lines budget — matches github/client*.test.ts pattern.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(gitlab): worktrees:resolveMrBase IPC + linkedGitLab* persistence

The workspace-from-MR keystone. Mirror of worktrees:resolvePrBase
shape and semantics — caller passes mrIid (with optional source_branch
/ isCrossRepository hints), handler returns either a remote/branch
ref (same-project MRs) or a SHA fetched from
refs/merge-requests/<iid>/head (fork MRs).

- types: linkedGitLabMR / linkedGitLabIssue on Worktree + WorktreeMeta.
  Marked optional so existing test fixtures and persisted older
  worktrees that pre-date these fields keep typechecking and loading
  without a migration.
- persistence: getDefaultWorktreeMeta initializes both fields to null.
- worktree-logic: mergeWorktree carries them through from meta.
- worktrees IPC: resolveMrBase mirrors resolvePrBase. Resolves the
  GitLab project via getProjectRef + known-host discovery, fetches the
  MR work-item to derive source_branch + isCrossRepository when those
  hints aren't provided, and uses GitLab's refs/merge-requests/<iid>/head
  for fork MRs (parallel of GitHub's refs/pull/<N>/head).
- tests: 6 fixture updates for the new optional fields. Full
  typecheck (node + cli + web) clean; 165 tests passing across
  src/main/gitlab/, preflight, worktree-logic, and gitlab-links.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(gitlab): IPC channels + preload bindings (gl.*)

Wire the GitLab backend to the renderer. Lean v1 surface — issues
CRUD, MR list/get/getForBranch, viewer, project slug, paste-URL
work-item lookup. Skips workItemDetails / listWorkItems-combined /
listTodos until the matching backend pieces land.

- main/ipc/gitlab.ts: thirteen handlers under the `gitlab:*` channel
  prefix with the same assertRegisteredRepo guard the gh handlers use.
  listIssues unwraps the structured result envelope to bare items[]
  to match window.api.gh.listIssues' shape; consumers that need the
  classified error can graduate to the envelope later.
- main/ipc/register-core-handlers.ts: register alongside gh.
- preload/api-types.ts: typed `gl: { ... }` block parallel to the
  existing `gh: { ... }`. Imports the new GitLab types so renderer
  code consuming the preload gets full inference.
- preload/index.ts: runtime `gl: { ... }` exposes wired to ipcRenderer.

Full typecheck (node + cli + web) clean.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(gitlab): workspace-from-MR via paste-URL (keystone end-to-end)

The first user-visible GitLab moment. Pasting a GitLab issue or MR URL
into the workspace name field now resolves through the full pipeline
to a created workspace with the right base ref and linkedGitLab*
persisted. The dedicated GitLab tab + state-filter chips remain a
follow-up; everything below it is wired.

- shared/lib/new-workspace.ts: LinkedWorkItemSummary.type accepts
  `'mr'` alongside `'issue' | 'pr'`. Renderer code that switches on
  type explicitly handles each kind.
- ui store slice: NewWorkspaceDraft mirrors the new linked slots so
  drafts persist GitLab selections across navigation. Optional fields
  for backward compatibility with drafts saved before this branch.
- useComposerState:
  - linkedGitLabIssue / linkedGitLabMR state, draft persistence,
    repo-switch reset, applyWorktreeMeta wiring.
  - applyLinkedGitLabWorkItem mirrors applyLinkedWorkItem; reuses
    getLinkedWorkItemSuggestedName by structurally projecting the
    GitLab item onto the helper's input shape.
  - handleSmartGitLabItemSelect parallels handleSmartGitHubItemSelect:
    for picked MRs, calls window.api.worktrees.resolveMrBase to
    resolve the base ref (refs/merge-requests/<iid>/head for fork
    MRs) and threads it through handleBaseBranchMrSelect.
  - "was MR !N" reset hint when a repo switch wipes a GitLab
    selection — `!N` matches gitlab.com's MR-reference convention.
- preload: window.api.worktrees.resolveMrBase + window.api.gl.* are
  already in. ComposerCardProps grows onSmartGitLabItemSelect (+
  optional onBaseBranchMrSelect).
- SmartWorkspaceNameField:
  - Paste-URL detection: parseGitLabIssueOrMRLink (host-agnostic via
    `/-/` separator) → window.api.gl.workItemByPath → row in the
    dropdown → click → forwarded to onGitLabItemSelect.
  - SmartWorkspaceNameSelection union, RowEntry union, RowIcon,
    RowLabel, SelectionIcon all carry the gitlab-mr / gitlab-issue
    kinds. MR rows show `!N` prefix; issue rows show `#N`.
  - Tab UI not added in this commit — paste-URL works in 'smart'
    mode, the dedicated tab + Open/Merged/Closed/All chips lands
    in a follow-up.
- NewWorkspaceComposerCard: forwards onSmartGitLabItemSelect to the
  picker.

Full typecheck (node + cli + web) clean. 165 unit tests passing in
affected files.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(gitlab): GitLab tab in SmartWorkspaceNameField with state filter

The discoverable demo path. The picker now has a "GitLab" tab — when
selected it lists the project's MRs filtered by state via
`gitlab:listMRs`, with an Open / Merged / Closed / All chip strip
that mirrors gitlab.com's MR-page tab strip. Paste-URL detection in
'smart' mode is unchanged; the new tab simply makes the surface
discoverable without requiring a URL.

- SmartNameMode gains 'gitlab'; Gitlab icon (lucide) added to the
  MODES array between GitHub and Branch.
- MrStateFilter / MR_STATE_FILTERS centralizes the four chip values
  so the labels stay GitLab-native (Open vs the GraphQL 'opened').
- listMRs effect: fires when mode === 'gitlab' and no GitLab URL is
  in the input, with the current state filter and a page-1 fetch
  bounded by RESULT_LIMIT.
- Paste-URL effect now coexists with the list effect: it owns
  gitlabItems while a URL is in the input, the list effect owns it
  otherwise. Switching tabs no longer clears the list.
- Chip strip rendered above the popover's CommandList only when
  mode === 'gitlab'. Buttons use the same Button component the rest
  of the picker uses for visual consistency.

Full typecheck (node + cli + web) clean. 165 unit tests passing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(gitlab): GitLab source on Tasks screen

The Tasks screen now offers GitLab as a third source alongside GitHub
and Linear. Selecting it surfaces MRs and issues for the primary
selected repo with a state filter (Open / Merged / Closed / All) that
mirrors gitlab.com's MR-page tab strip. Skips cross-repo aggregation,
search DSL, and Projects mode for v1 — those layers are GitHub-API-
shaped and would need a parallel store slice that is not worth porting
ahead of the actual demand for them.

- shared/types: GlobalSettings.defaultTaskSource accepts 'gitlab'.
- TaskPage:
  - TaskSource union grows a 'gitlab' member; SOURCE_OPTIONS adds the
    Gitlab icon between GitHub and Linear so the toolbar order matches
    SmartWorkspaceNameField for cross-surface consistency.
  - GITLAB_TASK_FILTERS centralizes the four chip values.
  - Per-source state slim (matches Linear's pattern) — gitlabFilter,
    gitlabItems, gitlabLoading, gitlabError, gitlabRefreshNonce.
  - Data-fetch effect runs Promise.all over `window.api.gl.listMRs`
    and `window.api.gl.listIssues` for the primary repo, merges and
    sorts by updatedAt desc. 'merged' filter skips the issue fetch
    (GitLab issues are 'opened' / 'closed' only).
  - Filter bar block parallel to Linear's, with chips + a refresh
    icon-button.
  - List block: 5-column grid (ID / Title / Type+State / Updated /
    Open-link). Row click opens the web URL — the GitLabItemDialog
    is a follow-up commit, but the row affordance is enough for the
    Tasks-screen demo.
  - GitLab MRs render as `!N`; issues render as `#N` to match
    gitlab.com's reference convention.

Full typecheck (node + cli + web) clean. 165 unit tests still
passing in affected files.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(gitlab): GitLabItemDialog (minimal) + Tasks screen wiring

Clicking a GitLab row on the Tasks screen now opens a side-sheet
preview with the item's title, state, author, and description body
rendered as markdown. "Open in browser" footer button stays as the
escape hatch; opening from the row is dialog-first now (matching the
GitHub side's row-click-to-dialog pattern). Files / comments /
pipeline tabs are deferred — they mirror substantial GitHub-side
surface area (work-item-details ~550 lines, GitHubItemDialog 2680
lines) and are not blocking the demo.

- types: MRInfo and GitLabIssueInfo gain optional description /
  author / authorAvatarUrl. Optional because list endpoints strip
  them; populated on detail-endpoint reads (`getMR` / `getIssue`).
- mappers: mapMRInfo and mapGitLabIssueInfo now pass description /
  author / avatar through when present. Skipped (rather than
  defaulted to '') so callers can distinguish "no body authored"
  from "this came from a list".
- GitLabItemDialog: new ~200-line side sheet. Fetches the detail
  payload via `window.api.gl.mr` / `gl.issue` on open; renders
  CommentMarkdown for the description (reused from the GitHub
  side); falls back to "No description." when the body is blank.
  State badge tones picked locally — GitLab's MR state space is
  wider than GitHub's so coupling them buys nothing.
- TaskPage: GitLab row now uses a div role=button with keyboard
  handling so the inner Open-in-browser <button> nests cleanly
  (HTML disallows nested <button>s, React would warn). Row click
  sets gitlabDialogItem; the small ExternalLink icon stops
  propagation so it still opens the URL.

Full typecheck (node + cli + web) clean. 165 unit tests passing in
affected files.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(gitlab): My Todos cross-project view on Tasks screen

The GitLab tab now has a Project | My Todos sub-toggle. "My Todos"
fetches gitlab.com/dashboard/todos via `glab api todos?state=pending`
and surfaces them in a separate table — action / title / project /
updated. This is the closest GitLab-native equivalent of GitHub's
notifications/inbox and lands in lieu of porting GitHub's search-DSL
which doesn't translate.

- shared/types: GitLabTodo type with action_name, target_type/iid,
  target_url, project_path, author, updated_at. action_name kept as
  open-ended string because new GitLab versions extend the verb set.
- gitlab/client.ts: listTodos uses `glab api --paginate todos?state=
  pending&per_page=50`. User-scoped — cwd doesn't matter, but the
  IPC path-validation guard still requires *some* registered repo
  path so we keep the signature consistent with the rest of gl.*.
- IPC: `gitlab:todos` channel; preload `gl.todos`.
- TaskPage:
  - gitlabView ('project' | 'todos') gates which list to render.
  - Sub-toggle row above the chip strip; chips are hidden on the
    Todos view since pending state has no Open/Merged/Closed axis.
  - Refresh button serves both views (uses gitlabRefreshNonce).
  - Todos table: 5-col grid, action verb (snake_case → spaces),
    target title, project path (mono font for repo-likeness),
    updated date, open-link icon. Row click opens target_url.

Full typecheck (node + cli + web) clean. 165 unit tests passing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(gitlab): gitlabProjects settings (recents auto-tracked) + tests

Settings persistence for GitLab project preferences plus tests for
the surface added since the last green run.

- shared/types: GitLabProjectSettings { pinned, recent } and an
  optional GlobalSettings.gitlabProjects slot. Optional for
  backward compat with profiles saved before this branch — the
  persistence merge fills the empty default.
- shared/gitlab-projects: pure helper computeNextGitLabRecents that
  prepends-and-dedupes by host+path, caps at GITLAB_RECENTS_MAX
  (10). Pulled out of the IPC handler so it tests without mocking
  Store.
- gitlab IPC: workItemByPath handler now pushes the resolved
  project ref onto recents on success. 404 / auth-fail lookups
  do not pollute the list — recents reflects projects the user
  actually read.

Tests added (12 new, 177 total passing in affected files):
- gitlab-projects.test: prepend, dedupe, host-vs-host distinct,
  cap at max, no input mutation.
- client.test: listTodos mapping, defensive state coercion,
  empty-on-error fallback, missing-target field defaults.
- mappers.test: description / author / authorAvatarUrl pass-
  through on both mapMRInfo and mapGitLabIssueInfo, plus the
  "absent vs blank" distinguishing assertion.
- mappers-workitem.test (split): mapMRToWorkItem + mapIssueToWorkItem
  cases moved out of mappers.test.ts to keep both files under the
  oxlint max-lines budget.

Full typecheck (node + cli + web) clean.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(gitlab): combined listWorkItems IPC + TaskPage refactor

Centralize the MR + issue merge logic that TaskPage was doing inline
into a single backend function and IPC channel. Future callers (the
picker's GitLab tab, any new widget) get the merge / sort / state-
mapping rule for free. The TaskPage effect drops from 60 lines of
inline orchestration to a single call.

- gitlab/issues: listIssues now accepts an IssueListState so the
  combined caller can ask for closed / all instead of always opened.
  CLI fallback path picks the right --opened / --closed / --all flag
  per glab version. Existing callers keep the 'opened' default.
- gitlab/client: listWorkItems(state, page, perPage, preference) fans
  out listMergeRequests + a raw issues fetch in parallel, merges by
  updatedAt desc, returns a GitLabPagedResult<GitLabWorkItem>.
  Bypasses listIssues for the issues side because IssueInfo strips
  updated_at — the combined sort needs it.
  state='merged' skips the issues fetch entirely (issues don't have
  a merged lifecycle).
- IPC: new gitlab:listWorkItems handler.
- preload: gl.listWorkItems alongside gl.listMRs.
- TaskPage: GitLab fetch effect now calls gl.listWorkItems and stops
  re-implementing the merge. Same UX, fewer moving parts.

Tests added (8 new in client-work-items.test.ts; +1 fix to
issues.test.ts for the new url-param order):
- merge ordering by updatedAt desc
- 'merged' state skips issues fetch
- closed / all state pass-through
- not_found envelope when project ref unresolved
- mr-error vs issue-side success interleaving
- combined error surfacing on either side failing

Full typecheck (node + cli + web) clean. 117 unit tests passing in
src/main/gitlab/ and src/shared/gitlab-projects.test.ts.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(gitlab): work-item-details + dialog Conversation/Pipeline tabs

Task 3 lean version. The minimal description-only dialog grows two
new tabs (Conversation / Pipeline) and four footer actions
(close / reopen / merge / comment). Files-tab and inline review-
comment positioning stay deferred — they mirror substantial GitHub-
side surface (GitHubItemDialog is 2680 lines, work-item-details.ts is
551) and the v1 demo doesn't need them.

- shared/types: GitLabPipelineJob (id, name, stage, status, webUrl,
  duration), GitLabWorkItemDetails (item + body + comments[] +
  pipelineJobs?[]). Mirrors GitHubWorkItemDetails layout.
- main/gitlab/work-item-details: getWorkItemDetails(repoPath, iid,
  type) fans out parallel reads — issue: detail + discussions; MR:
  detail + discussions, then pipeline jobs follow-up keyed off
  head_pipeline.id. Discussion → MRComment flatten skips system
  notes (auto-generated activity entries) so the conversation tab
  shows only user content. Inline-review position carried through
  as `path` + `line` for v1.5 to consume.
- main/gitlab/client: closeMR / reopenMR / mergeMR / addMRComment
  mutations. mergeMR accepts the same 'merge' | 'squash' | 'rebase'
  union as the GitHub side; close/reopen treat "already X" stderr
  as success since the desired state is reached.
- IPC: gitlab:workItemDetails, closeMR, reopenMR, mergeMR,
  addMRComment channels; preload `gl.*` bindings parallel.
- GitLabItemDialog rewrite: three Tabs (Description / Conversation /
  Pipeline-MRs-only) + footer with comment composer + state-aware
  Merge / Close / Reopen buttons. Cmd/Ctrl+Enter sends the comment
  to match gitlab.com's textarea shortcut. Refresh icon in the
  header re-fetches via a refreshNonce. eslint-disable max-lines on
  the dialog matches the GitHub-side equivalent's reasoning.

Full typecheck (node + cli + web) clean. 184 unit tests passing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(gitlab): sidebar icon, Smart-mix MRs, Integrations card, "Project MRs" rename

Four follow-up fixes that surfaced from smoke-testing:

- SidebarNav: GitLab icon next to GitHub / Linear in the Tasks-row
  shortcut strip; clicks open the Tasks page already filtered to the
  GitLab source. ui.ts taskPageData.taskSource union grows to accept
  'gitlab' so the openTaskPage call typechecks.
- SmartWorkspaceNameField: list-MRs effect now fires in 'smart' mode
  too, not just on the dedicated GitLab tab. The mixed picker
  surfaces the user's project MRs alongside GitHub items. Paste-URL
  effect still wins when a GitLab URL is in the input — the list
  effect bails on parsedGlLink !== null.
- TaskPage: GitLab toggle relabels "Project" → "Project MRs" so the
  pairing with "My Todos" reads more clearly.
- IntegrationsPane: new GitLab card mirroring the GitHub card —
  status badge (checking / connected / not-installed / not-
  authenticated), install link to gitlab.com/gitlab-org/cli, copy-
  ready `glab auth login` block, learn-more link to the auth/login
  doc, re-check button. Search-entry registered so settings search
  finds it. eslint-disable max-lines justified by the same pattern
  that already lives there for GitHub + Linear.
- preload: PreflightStatus.glab is optional on the type so older
  payloads typecheck; consumers gate on the optional chain.

Full typecheck (node + cli + web) clean. 184 unit tests passing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(gitlab): multi-repo aggregation on Tasks screen

Mirrors GitHub's cross-repo behavior. Previously the GitLab tab only
queried the first selected repo; now it fans out to every eligible
selected repo in parallel and merges results sorted by updatedAt
desc. The repo selector at the top of Tasks is the project picker —
it's the same one the GitHub tab uses, so the selection model is
consistent across providers.

- TaskPage gitlab fetch effect: Promise.allSettled across all
  selectedRepos that aren't SSH-relay (folder-mode repos and remote
  worktrees fall through). Each repo's project is resolved from its
  own git remote by the main process; non-GitLab repos return
  not_found which the renderer drops silently so a mixed selection
  (GitHub + GitLab repos) doesn't surface false errors on the GitLab
  tab.
- Per-row repoId tagging stays correct — items keep their source
  repo's id through the merge, which matters for the dialog repoPath
  resolution below.
- Banner display: only shown when EVERY eligible repo failed; partial
  failure is signaled by the row count being lower, not a banner that
  overshadows working repos.
- GitLabItemDialog repoPath: derived from the clicked item's
  source repo (selectedRepos.find by repoId) instead of primaryRepo.
  Without this, clicking an item from a non-primary repo would route
  the detail fetch through the wrong repo's remote.

Full typecheck (node + cli + web) clean. 117 unit tests passing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(gitlab): swap MR icon to GitMerge for visual distinction

GitPullRequest (curved-merge) reads similar to GitBranch (forking
line) at the small sizes we use in the picker — feedback was that
MR rows looked like branch rows. GitMerge (arrow-merge-into-line)
reads as its own thing and matches gitlab.com's MR iconography, so
users coming from the web UI find it familiar.

GitHub PRs keep GitPullRequest — that matches github.com and keeps
provider attribution distinct from GitLab MRs at a glance:
  GitHub PR: GitPullRequest (curved merge)
  GitLab MR: GitMerge (arrow merge)
  Branch:    GitBranch (fork)
  Issue:     CircleDot (provider-agnostic)

- SmartWorkspaceNameField RowIcon + SelectionIcon: gitlab-mr →
  GitMerge. github-pr stays GitPullRequest.
- GitLabItemDialog header icon: GitMerge for MRs.

Full typecheck (node + cli + web) clean. 117 unit tests passing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* refactor(gitlab): split shared types + preload into per-provider files

Pre-emptive merge-conflict reduction. The two recent main syncs
each surfaced ~5 conflicts, all in the same handful of central
files where every provider lands code. Moving the GitLab footprint
into provider-scoped files cuts the conflict surface roughly in half
without changing any runtime behavior.

- shared/gitlab-types.ts (new, 272 lines): every standalone GitLab
  type that previously lived in shared/types.ts —
  GitLabProjectRef / MRState / MRMergeableState / MRCheckDetail /
  MRInfo / GitLabReaction / MRComment / GitLabCommentResult /
  GitLabIssueInfo / GitLabViewer / GitLabAssignableUser /
  GitLabWorkItem / GitLabMRFile / GitLabProjectSettings /
  GitLabTodo[TargetType] / GitLabPipelineJob /
  GitLabWorkItemDetails / GitLabIssueUpdate / MRListState /
  GitLabPagedResult / ListMergeRequestsResult.
- shared/types.ts: re-exports the GitLab types so existing call
  sites importing from '../shared/types' keep working unchanged.
  GitLabProjectSettings additionally imported locally for the
  GlobalSettings.gitlabProjects field. Worktree.linkedGitLabMR /
  WorktreeMeta.linkedGitLabIssue / GlobalSettings.defaultTaskSource
  union member stay here — they're entangled with non-GitLab
  structs and moving them out would just shuffle the conflict
  vector to a different file.
- preload/gitlab.ts (new, 106 lines): the entire gl.* runtime
  binding block — viewer / projectSlug / mrForBranch / mr /
  listMRs / listWorkItems / issue / listIssues / createIssue /
  updateIssue / addIssueComment / listLabels /
  listAssignableUsers / todos / workItemDetails / closeMR /
  reopenMR / mergeMR / addMRComment / workItemByPath. Exported as
  `glApi`.
- preload/index.ts: imports `glApi` and inlines as `gl: glApi`,
  shrinking the file by ~95 lines.

Net: the two files most prone to conflict on upstream sync
(shared/types.ts, preload/index.ts) lose ~360 lines of
GitLab-specific code that now live in their own files where main's
non-GitLab edits can't touch them.

Full typecheck (node + cli + web) clean. 190 unit tests passing
in src/main/gitlab/, src/shared/gitlab-projects.test.ts,
src/main/ipc/{preflight,worktree-logic}.test.ts,
src/renderer/src/lib/gitlab-links.test.ts.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(gitlab): satisfy pnpm pre-flight (lint + handler-registration test)

- TaskPage: lift the selected-repos identity key into a useMemo so the
  GitLab fetch effect's dep array no longer holds a complex expression
  (oxlint exhaustive-deps).
- register-core-handlers.test: mock ./gitlab alongside ./github / ./linear
  so registerGitLabHandlers doesn't try to call ipcMain.handle in a unit
  test that fakes only individual handler modules.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(source-control): add Bitbucket hosted review support

* fix(source-control): align hosted review lookup with provider model

---------

Co-authored-by: Emilian Stoilkov <emilian.stoilkov@qaiware.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-14 15:09:52 -07:00
Jinwoo HongandOrca 151040f05f Add desktop-backed mobile voice dictation (#1869)
Co-authored-by: Orca <help@stably.ai>
2026-05-14 14:36:44 -07:00
Jinwoo HongandOrca c73fd2c90b Add project notes (#1861)
Co-authored-by: Orca <help@stably.ai>
2026-05-14 13:33:24 -07:00
Neil 11ce1647d1 test(rpc): use OS-assigned websocket test ports (#1835) 2026-05-14 01:18:32 -07:00
Brennan BensonandOrca 29e8eae70e perf(session): prune local terminal scrollback from persisted sessions (#1753)
Co-authored-by: Orca <help@stably.ai>
2026-05-13 16:34:44 -07:00
Brennan BensonandOrca 6e482a00d7 fix(terminal): set paneKey env on CLI-spawned terminals so agent status surfaces (#1727)
Co-authored-by: Orca <help@stably.ai>
2026-05-13 16:20:59 -07:00
Jinwoo HongandOrca 7944293815 Improve mobile terminal streaming performance (#1700)
* Improve mobile terminal streaming performance

Co-authored-by: Orca <help@stably.ai>

* Add mobile clear terminal action

Co-authored-by: Orca <help@stably.ai>

* Fix terminal connection test mock

Co-authored-by: Orca <help@stably.ai>

* WIP: mobile markdown tabs before rebase

Co-authored-by: Orca <help@stably.ai>

* Add mobile markdown editing

Co-authored-by: Orca <help@stably.ai>

* Harden mobile tab and markdown sync

Co-authored-by: Orca <help@stably.ai>

* Fix mobile terminal reconnect loading race

Co-authored-by: Orca <help@stably.ai>

* Polish mobile terminal keyboard behavior

Co-authored-by: Orca <help@stably.ai>

* Simplify mobile markdown editor chrome

Co-authored-by: Orca <help@stably.ai>

* Move mobile markdown actions to top

Co-authored-by: Orca <help@stably.ai>

* Use app modals for markdown discard

Co-authored-by: Orca <help@stably.ai>

* Dismiss keyboard before markdown confirmations

Co-authored-by: Orca <help@stably.ai>

* Add mobile file explorer

Co-authored-by: Orca <help@stably.ai>

* Fix mobile file explorer type narrowing

Co-authored-by: Orca <help@stably.ai>

* Fix mobile files navigation param

Co-authored-by: Orca <help@stably.ai>

* Show mobile files connection wait state

Co-authored-by: Orca <help@stably.ai>

* Preview text files on mobile

Co-authored-by: Orca <help@stably.ai>

* Simplify mobile file previews

Co-authored-by: Orca <help@stably.ai>

* Clarify unavailable mobile file types

Co-authored-by: Orca <help@stably.ai>

* Fix mobile subscription and preview review issues

Co-authored-by: Orca <help@stably.ai>

* Keep fallback terminals visible on mobile

Co-authored-by: Orca <help@stably.ai>

* Keep mobile terminal tap active

Co-authored-by: Orca <help@stably.ai>

* Preserve mobile terminal fallback order

Co-authored-by: Orca <help@stably.ai>

* Fix mobile session tab authority

Co-authored-by: Orca <help@stably.ai>

* Run mobile tests in mobile CI lane

Co-authored-by: Orca <help@stably.ai>

* Bump mobile app version to 0.0.7

Co-authored-by: Orca <help@stably.ai>

* Allow main window IPC wiring size

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Orca <help@stably.ai>
2026-05-12 14:38:12 -07:00
Jinwoo HongandOrca 82090831f6 Create Orca CLI terminals without stealing focus (#1707)
Co-authored-by: Orca <help@stably.ai>
2026-05-11 23:14:30 -07:00
Jinwoo HongandOrca 0f54103dda Add native computer-use automation (#1683)
Co-authored-by: Orca <help@stably.ai>
2026-05-11 14:20:08 -07:00
buf0-bot[bot]andorca-bot f8837fe3f3 fix: pr-bug-scan findings from #1562 (#1612)
Added DeviceRegistry.rotatePendingDevice and threaded a 'rotate' option through the mobile:getPairingQR IPC + preload + MobilePane so explicit Regenerate clicks mint a fresh pending token instead of returning the same one.

Findings addressed:
- [medium] src/main/runtime/device-registry.ts:44-50 — 'Regenerate QR' no longer rotates the token

Rebased onto current main to resolve conflicts.

Co-authored-by: orca-bot <bot@stably.ai>
2026-05-09 04:05:55 -07:00
buf0-bot[bot]andneil 6e91777f96 fix: pr-bug-scan findings from #1600 (#1619)
Fixed 6 findings: legacy fetch fallback for local-only bases, memoized canonical fetch key, recorded reconcile token before await, cleared token in finally, configurable publish remote, and fetch-failure-aware base ref error.

Rebased onto current main applying only the Fixer-summary files (worktree-remote.ts, orca-runtime.ts) to avoid silent reverts from a stale base.

Co-authored-by: neil <neil@nous.com>
2026-05-09 03:58:28 -07:00
JinjingandOrca 11b362c92d feat(worktree): optimistic create with reconciled base status (#1600)
Surface worktree creation immediately and reconcile remote base state
asynchronously, emitting drift/conflict events as fetches complete.

Co-authored-by: Orca <help@stably.ai>
2026-05-08 14:59:23 -07:00
Brennan BensonandOrca 2050fa87a0 feat(source-control): send all notes to agent in a new terminal tab (#1568)
Co-authored-by: Orca <help@stably.ai>
2026-05-08 13:52:08 -07:00
buf0-bot[bot]andorca-bot 57d095bf6f fix: pr-bug-scan findings from #1475 (#1562)
host-store: write AsyncStorage metadata before SecureStore token to avoid orphaned keychain tokens on crash. mobile IPC: coalesce repeated getPairingQR calls onto a single pending device token via new DeviceRegistry.getOrCreatePendingDevice.

Findings addressed:
- [high] mobile/src/transport/host-store.ts — saveHost orders Keychain write before AsyncStorage — orphaned tokens on crash
- [low] src/main/ipc/mobile.ts:84-95 — getPairingQR creates a device token on every call, leaking pre-paired entries

Rebased onto current main to resolve conflicts; preserved tokenCache.set added on main.

Co-authored-by: orca-bot <bot@stably.ai>
2026-05-07 23:11:03 -07:00
Jinwoo HongandOrca 22b63a0191 Mobile: indefinite phone-fit hold + configurable auto-restore (#1532)
Co-authored-by: Orca <help@stably.ai>
2026-05-07 16:47:31 -07:00
zerone0x 998815c2dd fix: allow omitted optional rpc schema fields with zod 4.4 (#1541) 2026-05-07 16:13:20 -07:00
7fb5363296 feat(cli): tab switch --focus surfaces the browser pane (#1498)
Co-authored-by: Orca <help@stably.ai>
Co-authored-by: Maciej Kobuszewski <maciej.kobuszewski@pergam.in>
Co-authored-by: Neil <4138956+nwparker@users.noreply.github.com>
Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
2026-05-07 01:48:39 -07:00
Neil 7b83b2dcdc fix: avoid repeated macOS privacy prompts (#1524)
* fix: avoid repeated macos privacy prompts

* fix: reduce background worktree permission probes

* chore: pin oxlint for ci

* fix: preserve optional rpc params with zod 4.4

* fix: preserve optional inline rpc params with zod 4.4
2026-05-06 23:30:03 -07:00
Neil 43a258951f fix(feedback): enforce anonymous submissions (#1528) 2026-05-06 23:23:58 -07:00
Jinwoo HongandOrca e83d92eede Mobile: server-authoritative phone-fit state machine + race fixes + UX cleanup (#1518)
Co-authored-by: Orca <help@stably.ai>
2026-05-06 21:54:23 -07:00
Neilandorca-bug-scan-bot 5dd48c7315 fix: address pr-bug-scan findings from #1396 (#1517)
Fix tab profile use-default fallback to default profile and destroy
all sibling webviews on workspace profile switch.

Reapplied on fresh origin/main; supersedes #1460.

Co-authored-by: orca-bug-scan-bot <orca-bug-scan-bot@stably.ai>
2026-05-06 17:19:26 -07:00
Jinwoo HongandOrca 07d10c8e8d fix(mobile): WS heartbeat to reap half-open mobile sockets (#1500)
Co-authored-by: Orca <help@stably.ai>
2026-05-06 02:05:38 -07:00
buf0-bot[bot]andJinjing d40a5ab6da fix(cli): make ProfileCreate.scope strict (pr-bug-scan #1397) (#1497)
Replace ProfileCreate.scope coerce-to-isolated transform with strict
z.enum(['isolated', 'imported']) so unknown scopes surface validation
errors instead of being silently rewritten.

Supersedes #1455 (which was branched off stale main and would have
reverted #1396).

Co-authored-by: Jinjing <jinjing@stably.ai>
2026-05-06 00:14:10 -07:00
Jinwoo HongandOrca 30b6aaf638 fix(terminal): close SIGKILL race for #217 + preserve scrollback on worktree sleep (#1454)
Co-authored-by: Orca <help@stably.ai>
2026-05-05 19:26:44 -07:00
Jinwoo HongandOrca 63e36d05fd chore(mobile): App Store prep — privacy manifest, debug-log cleanup, and protocol-version compat block (#1440)
Co-authored-by: Orca <help@stably.ai>
2026-05-05 19:23:56 -07:00
Brennan BensonandOrca 8de43cd3b4 fix(sidebar): stamp lastActivityAt on first worktree discovery (#905)
Co-authored-by: Orca <help@stably.ai>
2026-05-05 16:17:51 -07:00
Jinwoo HongandOrca f938ff185f feat(mobile): account switcher and rate-limit usage on mobile (#1467)
Co-authored-by: Orca <help@stably.ai>
2026-05-05 16:09:16 -07:00
Jinwoo HongandOrca cdd21423eb fix(mobile): unstick worktree spinner once agent exits, match desktop StatusIndicator (#1449)
Co-authored-by: Orca <help@stably.ai>
2026-05-05 12:43:47 -07:00
e623372cdb feat(cli): add tab profile controls and automation primitives (#1396)
* feat(cli): add browser tab profile controls

* feat(cli): add tab profile automation primitives

* refactor(cli): narrow tab profile automation scope

* chore: retrigger PR checks

* review: harden tab profile automation CLI

- Wait for tab re-registration after browser.tabSetProfile so a follow-up tab list --show-profile reads the new sessionProfileId from BrowserManager instead of the stale one from the previous webview
- Wait for tab registration after browser.tabProfileClone, matching browser.tabCreate, so the cloned browserPageId is operable when the CLI returns
- Short-circuit browser.tabSetProfile when the tab is already on the requested profile so we do not tear down and remount the webview for a no-op switch
- Switch TabShow.worktree from OptionalPlainString to OptionalString to match every other tab schema; empty --worktree should fall back to the active worktree, not pass through as the empty string
- Add max-lines disable to browser.test.ts (file grew past 300 lines after adding the new tab-profile and tab-show tests)

* review: fix useIpcEvents test setup for tab profile API

CI failure: useIpcEvents.test.ts threw at module load with TypeError: window.addEventListener is not a function. The chain: the rebased useIpcEvents.ts imports destroyPersistentWebview from webview-registry, which calls window.addEventListener at module load. The test stubs window via vi.stubGlobal as a plain object without addEventListener, so the typeof window check passes but the call throws.

- webview-registry.ts: tighten the module-load guard to also check that window.addEventListener is callable, so importing this module from a non-DOM-ish test env (vitest node env with stubbed window) does not throw at module load
- useIpcEvents.test.ts: add the new onRequestTabSetProfile and replyTabSetProfile stubs to all 8 window.api.ui mocks so the new IPC subscription registered by useIpcEvents resolves

* review: restore profile CRUD lost during rebase onto 1397-merged main

The rebase brought commit 3242aa27 (refactor: narrow tab profile automation scope) onto a main that already had the lifecycle CRUD from 1397. The refactor commit removes BrowserProfileList/Create/Delete types, runtime methods, RPC registrations and schemas, plus the help/specs entries, because those were the precursor versions in commit 1 of this branch. Post-rebase those removals land on the hardened versions inherited from main, breaking 1397.

Restore:
- runtime-types.ts: BrowserSessionProfile import; ProfileList/Create/Delete result types
- orca-runtime.ts: ProfileList/Create/Delete result type imports; browserProfileList/Create/Delete methods
- browser-core.ts: ProfileCreate, ProfileDelete schema imports; browser.profileList/profileCreate/profileDelete RPC registrations
- browser-schemas.ts: ProfileCreate, ProfileDelete zod schemas
- help.ts: list/create/delete subcommand lines under Browser Automation
- specs/browser-basic.ts: list/create/delete spec entries

---------

Co-authored-by: Nikolatesla-lj <Nikolatesla-lj@users.noreply.github.com>
Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
2026-05-04 23:46:23 -07:00
Jinwoo HongandOrca d1b26e2eb7 Mobile improvements: scrollback hydration, keyboard layout, and worktree-creation polish (#1423)
Co-authored-by: Orca <help@stably.ai>
2026-05-04 23:24:22 -07:00
9bf339eeb9 feat(cli): add tab profile lifecycle commands (#1397)
Co-authored-by: Orca <help@stably.ai>
Co-authored-by: Nikolatesla-lj <Nikolatesla-lj@users.noreply.github.com>
Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
2026-05-04 23:01:15 -07:00
Jinwoo HongandOrca fc578f5ea9 feat(mobile): Expo companion app [beta] (#1245)
Co-authored-by: Orca <help@stably.ai>
2026-05-04 13:08:27 -07:00
Jinwoo HongandOrca ea8ea08116 feat(orchestration): bundled improvements — check-wait, stale-base, preamble+ask, QoL (#1403)
* feat(orchestration): transport keepalive + delivered_at split for check --wait

Implements the four §3 fixes from the check-wait design doc:

- §3.1 Transport keepalive: long-poll RPCs (orchestration.check --wait) emit
  `{"_keepalive":true}` frames every 10s so neither server nor client tears
  the socket down on idle. A `longPoll` admission counter capped at 16 fails
  fast with `runtime_busy` when saturated; an AbortController wired through
  the RPC dispatcher cancels the inner waiter the moment the socket closes.
- §3.2 delivered_at split: push-on-idle now stamps `delivered_at` instead of
  flipping `read`, so the check caller remains the sole consumer of its
  queue. Adds a synchronous idempotent schema migration that hard-fails on
  error.
- §3.3 inbox/check parity: `orchestration inbox --terminal <handle>` and
  `orchestration check --all` agree on the same rows (sequence DESC, no
  mark-read). `check --unread=false` kept for one release as a compat shim.
- §3.4 CLI heartbeat: `orca orchestration check --wait` emits JSON heartbeat
  lines to stderr every 15s so Claude Code's Bash tool sees continuous
  output and doesn't auto-background the subprocess.

Tests: extends runtime-rpc, orca-runtime, envelope-schema, orchestration
method, and formatter suites; adds a subprocess test that spawns the built
CLI and verifies stderr line-flushing, heartbeat cadence, and stdout
cleanliness end-to-end.

Co-authored-by: Orca <help@stably.ai>

* feat(orchestration): preamble rules + heartbeat schema

- Preamble (#7, #15, #9): worker_done body ("3-sentence summary" + reportPath),
  BEHAVIOR RULE #1 forbidding AskUserQuestion, heartbeat every 5 minutes with
  taskId+dispatchId payload, AFTER YOU SEND grace window.
- Schema v2 migration: adds 'heartbeat' to messages.type CHECK, adds
  dispatch_contexts.last_heartbeat_at, gated by user_version PRAGMA with
  transactional rebuild + explicit CREATE INDEX to avoid silent perf regress.
- DB helpers: recordHeartbeat (dispatched-only), getStaleDispatches,
  getThreadMessagesFor (thread+handle scoped for ask).

Co-authored-by: Orca <help@stably.ai>

* feat(orchestration): coordinator heartbeat + stale detector

Handle incoming 'heartbeat' messages by calling recordHeartbeat keyed on
payload.dispatchId (strict — log-and-skip if missing, no taskId fallback so
a straggler heartbeat from a previously-failed dispatch cannot mask a hung
retry per §5.3.4). On every tick after the 10-minute threshold, emit one
log per stale dispatched row — no auto-fail.

Also threads dispatchId through buildDispatchPreamble so workers can
attribute their heartbeats back to the correct dispatch context.

Co-authored-by: Orca <help@stably.ai>

* feat(orchestration): orca orchestration ask verb

Adds a CLI verb that sends a decision_gate message and blocks on the
coordinator's reply, scoped to the outbound message's thread. Group
addresses (@all, @idle, …) are rejected — fan-out questions must use
send --type decision_gate explicitly.

--json emits bare single-line JSON (bypassing printResult) so workers can
pipe `orca orchestration ask … --json | jq -r .answer` without unwrapping
an RPC envelope; human mode prints just the answer. On timeout the verb
exits 1 and returns {answer: null, timedOut: true}.

This is the CLI surface BEHAVIOR RULE #1 in the dispatch preamble points
workers at instead of AskUserQuestion.

Co-authored-by: Orca <help@stably.ai>

* feat(orchestration): QoL bundle — preamble visibility, status enum, dispatch cross-ref, inbox --full

Addresses four items from ORCHESTRATOR_FEEDBACK:

- #5 preamble visibility: `dispatch-show --preamble` regenerates the preamble
  text for a task; `dispatch --inject --dry-run` previews without mutating
  state; `dispatch --return-preamble` echoes the injected preamble in the JSON
  response so coordinators can audit what a worker received.
- #6 status enum validation: CLI rejects unknown `task-update --status` values
  with `invalid status '<x>', expected one of: pending, ready, dispatched,
  completed, failed, blocked` before the RPC's generic Zod message. Valid
  statuses are listed under Notes in `task-update --help`.
- #13 task-list dispatch cross-ref: `task-list --json` now includes
  `assignee_handle` and `dispatch_id` for tasks in status=dispatched via a
  read-only LEFT JOIN on dispatch_contexts. Non-dispatched rows keep their
  legacy shape so existing consumers are unaffected.
- #14 inbox body visibility: `inbox --full` prints body + payload verbatim;
  default output is unchanged (id/from/to/subject only).

No DB migrations; join-only change on dispatch_contexts so the sibling
preamble PR's `last_heartbeat_at` column addition will not conflict.

Co-authored-by: Orca <help@stably.ai>

* fix(worktree): prevent stale-base worktree creation and dispatch

Addresses feedback #16 per DESIGN_DOC_STALE_BASE_FIX.md §0. Four v1
components coordinated by a single shared fetch cache on the runtime:

1. Concurrent-fetch-with-gate in UI create path: `createLocalWorktree`
   fires `git fetch` BEFORE the suffix loop / PR probe / path
   resolution, then awaits right before `addWorktree` so the new branch
   always spawns from a fresh remote tip. Renderer sees a two-phase
   spinner via the new `createWorktree:progress` IPC event. The cache
   is a `Map<repoPath::remote, Promise<void>>` + 30s success-only
   timestamp on `OrcaRuntimeService` (§7.1 — shared with dispatch).
2. Dispatch pre-flight drift guard in `Coordinator.dispatchTask`:
   probes `rev-list --left-right --count` against the target worktree
   and silently returns (preserves `ready`, no circuit-breaker burn)
   when `behind > 20` unless the task spec carries
   `allow-stale-base: true`. Parsing strips the flag so it never leaks
   into the worker's `--- TASK ---` block.
3. Preamble drift section: populated only when dispatch detected drift.
   Workers see `--- BASE DRIFT ---` with the N-most-recent subjects
   they don't have, so they can pull them in before running.
4. §3.3 Lifecycle: `.finally()` evicts Map entries on BOTH success and
   rejection; timestamp is written ONLY on success. Prevents a single
   DNS hiccup from wedging every future create on the repo until
   restart, and keeps the freshness window honest.

Defers the DB `allow_stale_base` column (§0.2) and the create-time
warn toast; both can layer in later without migration.

Tests: 35 new/updated unit tests covering drift preamble, dispatch
refusal, spec-text flag parsing, fetch Map eviction after rejection,
freshness-window short-circuit, and concurrent-caller serialization.

Co-authored-by: Orca <help@stably.ai>

* test(orchestration): seed v2 DB in migration hard-fail test

After consolidating the schema bump, fresh DBs are initialized directly at
v3 via createTables(), so the v2→v3 ALTER TABLE is skipped on new installs
and the prior test's stub never fired. Seed a v2-shape file on disk so the
guarded ALTER actually runs and the "simulated migration failure" stub
propagates as intended.

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Orca <help@stably.ai>
2026-05-04 12:10:53 -07:00
Jinwoo HongandOrca 66d596fe11 fix: zombie worktree PTY cleanup (issue #218) (#1376)
* fix(runtime): kill all PTYs for a worktree on removal (design §4.3)

Worktree deletion only shut down renderer-tracked terminals, so PTYs owned
by background tabs, split panes, or pre-reload sessions survived the
removal and kept leaking memory. Introduce killAllProcessesForWorktree
with three sweeps (runtime leaves, provider-prefix scan of daemon session
ids, pty-registry by worktreeId) and wire it into both teardown paths:
the CLI-initiated removeManagedWorktree and the renderer-initiated
worktrees:remove IPC handler. OrcaRuntimeService gets a lazy
getLocalProvider thunk so construction order stays robust.

Co-authored-by: Orca <help@stably.ai>

* fix(renderer): purge worktree-scoped state on removal + hydration (design §4.4)

When a worktree is deleted, ~25 worktree-scoped maps (tabsByWorktree,
git caches, browser state, split-tab models, per-file editor drafts,
etc.) kept references to the gone worktree, so SessionsStatusSegment
kept mis-classifying orphaned PTYs as bound and dropdowns rendered stale
ids. Add purgeWorktreeTerminalState as a single atomic action that
wipes every scoped map plus cascades top-level actives. Fire it from
the worktrees:changed listener on the set-diff of removed ids, and once
more at hydration via fetchAllWorktrees to clean up persisted entries
from pre-fix sessions. The hydration-time purge is gated behind a
per-repo success check: a single transient IPC error or an all-empty
fetch defers the purge so a degraded launch cannot wipe legitimate
persisted state.

Co-authored-by: Orca <help@stably.ai>

* test(zombie-worktree): regression coverage for design §4.5

Adds tests for every layer of the zombie-worktree fix:
- worktree-teardown: unit coverage of the three-sweep helper including
  best-effort error swallowing across provider/registry.
- orca-runtime: RPC-initiated removeManagedWorktree kills PTYs before
  any git mutation + verifies the lazy getLocalProvider thunk resolves
  on each call.
- worktrees IPC: renderer-initiated remove kills PTYs before git and
  skips the kill helper for SSH-backed repos.
- renderer slice: fetchAllWorktrees defers the purge when any sibling
  repo fetch fails or every repo returns empty (F1 regression);
  happy-path fires the purge once and does not re-run on subsequent
  calls. Direct purgeWorktreeTerminalState coverage pins the cascade
  across worktree-keyed, tab-id-keyed, and file-id-keyed maps.

Co-authored-by: Orca <help@stably.ai>

* fix(runtime): log worktree-teardown kill counts (design §4.4 observability)

Breadcrumb lets ops distinguish a renderer-state-induced leak (diff-path
purge non-empty) from a backend-induced one (nothing to kill but memory
still pinned). Emit only when the sweep actually shut anything down so
steady-state logs stay quiet. Added at both call sites —
removeManagedWorktree (CLI path) and the worktrees:remove IPC handler.

Co-authored-by: Orca <help@stably.ai>

* test(zombie-worktree): fix ptyIdsByTabId seed shape to match production type

The purge unit test seeded ptyIdsByTabId as Record<string, string> when
the runtime type is Record<string, string[]>. The unit tests passed
because they never hit the UI renderer, but live e2e surfaced a
TypeError: (ptyIdsByTabId[tabId] ?? []).some is not a function.

Corrected to arrays; 21/21 tests still pass.

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Orca <help@stably.ai>
2026-05-03 15:54:45 -07:00
Jinwoo HongandOrca 827b84d27a fix(runtime): add single-instance lock + owned-metadata clear (#1312) (#1326)
* fix(runtime): add single-instance lock + owned-metadata clear to prevent orca-runtime.json corruption

Closes #1312.

Every AppImage/.app relaunch was booting a fresh Electron main that clobbered
`<userData>/orca-runtime.json` and `agent-hooks/endpoint.env`. When the newest
instance quit, metadata pointed at a dead pid and `orca status` reported
`stale_bootstrap` even though the original Orca was still running. SIGKILL'd
predecessors also left orphaned `o-<pid>-*.sock` files in userData.

Three surgical changes:

1. `app.requestSingleInstanceLock()` in a new
   `src/main/startup/single-instance-lock.ts` helper, wired into
   `src/main/index.ts` after `configureDevUserDataPath(is.dev)` so dev and
   packaged runs lock in separate namespaces. Losing instances focus the
   primary's window via `second-instance` and quit without touching userData.

2. `clearRuntimeMetadataIfOwned(userData, pid, runtimeId)` in
   `runtime-metadata.ts` — compares both pid AND runtimeId against the
   current file before clearing, so the auto-updater handoff window never
   erases the replacement process's fresh bootstrap. Called from a rewritten
   `will-quit` handler that folds `runtimeRpc.stop()` + owned-clear into the
   same `Promise.allSettled([disconnectDaemon, …]).then(app.quit)` chain
   (inside the `!daemonDisconnectDone` guard so the second-pass re-entry
   can't re-invoke stop+clear).

3. `sweepOrphanedRuntimeSockets()` in `runtime-rpc.ts` runs at the top of
   `start()` on POSIX, using `process.kill(pid, 0)` to probe liveness and
   remove `o-<dead-pid>-*.sock` orphans left by SIGKILL/OOM-kill.

Tests (37 new/updated):
- `single-instance-lock.test.ts` (3): lock-failed does not register listener;
  lock-acquired registers exactly one; callback dispatches correctly.
- `runtime-metadata.test.ts` (+4): clearRuntimeMetadataIfOwned matched /
  pid-mismatch / runtimeId-mismatch / no-file branches.
- `runtime-socket-sweep.test.ts` (4): own-pid-skip / alive-retain /
  dead-sweep / regex-miss separated via synthetic ownPid=1; two
  regex-invariant tests assert the sweep regex matches the real
  `createRuntimeTransportMetadata` output (including the 'rt' fallback).

Design doc: `docs/fix-missing-single-instance-lock.md`.

Co-authored-by: Orca <help@stably.ai>

* fix(runtime): focus hidden windows on second-instance event

focus() alone is a silent no-op when the primary window is hidden
(close-to-tray on macOS via Cmd+W, or on a different macOS Space) or
behind other apps on Windows. Call show() before focus() so a second
launch attempt reliably surfaces the existing window regardless of
state.

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Orca <help@stably.ai>
2026-05-02 23:05:14 -07:00
Trevin Chow fd3e62603d fix(hooks): generate worktree setup-runner from target worktree's orca.yaml (#1280)
* fix(hooks): generate worktree setup-runner from target worktree's orca.yaml

Extend getEffectiveHooks, getSetupCommandSource, and runHook with an
optional worktreePath parameter. When provided, loadHooks reads the
yaml from that path; otherwise it falls back to repo.path. Update
the worktree-creation paths in worktree-remote.ts and orca-runtime.ts
to thread the new worktreePath through after the worktree exists, so
the generated setup-runner reflects the yaml at the tip of the target
worktree's branch instead of the primary checkout's stale yaml.

Add a regression test in hooks.test.ts that mocks two distinct
orca.yaml files (primary and worktree) and asserts the worktree's
content wins when worktreePath is passed.

The legacy hooks:check IPC handler keeps reading from repo.path
unchanged.

Closes #1256

* fix(hooks): skip auto-setup when worktree script differs from preview

Add setupScriptsMatch helper that compares the primary checkout's
setup script (what the renderer shows the user before worktree
creation) to the target worktree's script (what would actually run
after creation). When they differ, createLocalWorktree skips the
auto-launch and logs a warning, so a base-branch yaml that introduces
or modifies setup commands cannot execute under the trust granted to
the primary's preview. CLI-created worktrees use the worktree-bound
load directly because trust is granted by the CLI invocation context,
which is annotated in orca-runtime.ts.

Adds regression coverage for both matching and differing script cases.

* test(hooks): add setupScriptsMatch to worktree IPC test mocks

The new setupScriptsMatch import in worktree-remote.ts means the
existing vi.mock('../hooks') blocks in worktrees.test.ts and
worktrees-windows.test.ts now need to expose it. Default the mock to
returning true so existing tests continue to exercise the run-setup
path; the new behavior gating is covered by the dedicated
setupScriptsMatch unit tests.
2026-05-02 18:27:09 -07:00
Neil 020780c4dd feat(hooks): restore always-trust repo option
Restores repo-level always-trust for orca.yaml hooks and surfaces CLI warnings when --run-hooks is omitted and a hook is skipped.
2026-04-29 20:47:04 -07:00
mcd77 89f41bfda2 feat(hooks): gate orca.yaml execution on trust
Audited and rebased PR 1138. Squashed to remove the original untrusted commit stack; hook execution now requires explicit UI trust or CLI --run-hooks opt-in.
2026-04-29 18:29:53 -07:00
Jinwoo HongandOrca c9391e203f feat(orchestration): add inter-agent orchestration system (#1188)
Co-authored-by: Orca <help@stably.ai>
2026-04-28 12:21:31 -07:00
Jinwoo Hong e1270486cd feat: add Linear integration (#1007) 2026-04-23 14:54:32 -07:00
Neil 96c5ca2636 refactor(runtime): split runtime-rpc.ts into a schema-validated method registry (#980) 2026-04-23 00:27:20 -07:00
4f7b488d22 feat(cli): add terminal create, split, rename, focus, close, tui-idle wait (#734)
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
2026-04-22 17:51:32 -07:00
Neil ed32ca2c21 fix(worktrees): fail loudly when no default base ref is resolvable (#922) 2026-04-21 17:40:27 -07:00
Jinwoo Hong 7a9bc4ef6d feat: computer use via agent-browser CDP bridge (#856) 2026-04-20 20:56:14 -07:00
Jinwoo Hong 97f3cd5199 feat: add pinned worktrees to sidebar (#674) 2026-04-15 12:23:13 -07:00