* feat(gitlab): add foundational glab runner, types, and issue operations
First slice of GitLab support, mirroring src/main/github/ structurally
without refactoring the working GitHub path.
- runner: add glabExecFileAsync parallel to ghExecFileAsync (same WSL
routing and retry policy; HTTP-status / network classification is
provider-agnostic so the existing helpers are reused).
- types: GitLabProjectRef carries host alongside path so self-hosted
instances and nested groups round-trip through the IPC layer. Mirror
shapes for MR/issue/work-item/comment/file/assignable-user.
- gitlab/gl-utils: concurrency limiter, error classification, project-ref
resolution honoring upstream/origin preference, and known-host
discovery via `glab auth status` so non-gitlab.com remotes are
recognized after the user authenticates.
- gitlab/mappers: pipeline-job → check-status mapping, MR state
resolution (including draft inferred from `Draft:`/`WIP:` title
prefix), and pipeline rollup.
- gitlab/issues: full issue CRUD via `glab api` against URL-encoded
project paths, with the same upstream/origin preference semantics as
the GitHub side.
63 unit tests passing across gl-utils / mappers / issues. Both
typecheck:node and typecheck:web clean.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(gitlab): preflight glab auth check and URL parser
- preflight: probe `glab --version` + `glab auth status` alongside the
existing gh checks. PreflightStatus.glab is optional so renderer call
sites that only render git/gh keep typechecking; consumers gating on
GitLab affordances opt in via `glab?.authenticated`.
- gitlab-links: parse GitLab issue and merge-request URLs honoring (a)
arbitrary self-hosted hosts via the project-internal `/-/` separator
rather than locking to gitlab.com, (b) nested group paths, and (c)
GitLab's `!42` MR convention alongside `#42`.
26 unit tests added (5 new preflight cases, 21 URL-parser cases). Full
typecheck (node + cli + web) clean. Pre-existing runtime/orchestration
test failures unrelated to this branch — Node 25 vs the project's
pinned Node 24 engine.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(gitlab): MR list/get + paginated `glab api -i` helper
Lean mirror of github/client.ts focused on the workspace-from-MR
keystone. Adopts GitLab-native filter semantics (Open / Merged /
Closed / All) instead of porting GitHub's search-DSL — that path is
covered by the upcoming My Todos surface.
- gl-utils: glabApiWithHeaders + parseGlabApiResponse for strict
pagination via X-Total / X-Total-Pages on `glab api -i` output.
CRLF / LF tolerant; status line never leaks into the headers map.
- types: MRListState, GitLabPagedResult<T>, ListMergeRequestsResult.
- mappers: mapMRToWorkItem + mapIssueToWorkItem produce the unified
GitLabWorkItem shape the picker consumes. isCrossRepository derived
from source_project_id !== target_project_id; deterministic id
fallback when the per-MR detail endpoint omits global id.
- client: getAuthenticatedViewer, getMergeRequest (with head pipeline
rolled up), getMergeRequestForBranch (mirrors github/getPRForBranch
semantics including refs/heads/ stripping and detached-HEAD guard),
listMergeRequests (paginated), getWorkItemByProjectRef (paste-URL
flow). Re-exports issues + projectRef helpers so callers don't have
to know the gl-utils module split.
35 new tests (98 total in src/main/gitlab/), full typecheck clean.
Tests split into client.test.ts + client-mr.test.ts to stay under the
oxlint max-lines budget — matches github/client*.test.ts pattern.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(gitlab): worktrees:resolveMrBase IPC + linkedGitLab* persistence
The workspace-from-MR keystone. Mirror of worktrees:resolvePrBase
shape and semantics — caller passes mrIid (with optional source_branch
/ isCrossRepository hints), handler returns either a remote/branch
ref (same-project MRs) or a SHA fetched from
refs/merge-requests/<iid>/head (fork MRs).
- types: linkedGitLabMR / linkedGitLabIssue on Worktree + WorktreeMeta.
Marked optional so existing test fixtures and persisted older
worktrees that pre-date these fields keep typechecking and loading
without a migration.
- persistence: getDefaultWorktreeMeta initializes both fields to null.
- worktree-logic: mergeWorktree carries them through from meta.
- worktrees IPC: resolveMrBase mirrors resolvePrBase. Resolves the
GitLab project via getProjectRef + known-host discovery, fetches the
MR work-item to derive source_branch + isCrossRepository when those
hints aren't provided, and uses GitLab's refs/merge-requests/<iid>/head
for fork MRs (parallel of GitHub's refs/pull/<N>/head).
- tests: 6 fixture updates for the new optional fields. Full
typecheck (node + cli + web) clean; 165 tests passing across
src/main/gitlab/, preflight, worktree-logic, and gitlab-links.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(gitlab): IPC channels + preload bindings (gl.*)
Wire the GitLab backend to the renderer. Lean v1 surface — issues
CRUD, MR list/get/getForBranch, viewer, project slug, paste-URL
work-item lookup. Skips workItemDetails / listWorkItems-combined /
listTodos until the matching backend pieces land.
- main/ipc/gitlab.ts: thirteen handlers under the `gitlab:*` channel
prefix with the same assertRegisteredRepo guard the gh handlers use.
listIssues unwraps the structured result envelope to bare items[]
to match window.api.gh.listIssues' shape; consumers that need the
classified error can graduate to the envelope later.
- main/ipc/register-core-handlers.ts: register alongside gh.
- preload/api-types.ts: typed `gl: { ... }` block parallel to the
existing `gh: { ... }`. Imports the new GitLab types so renderer
code consuming the preload gets full inference.
- preload/index.ts: runtime `gl: { ... }` exposes wired to ipcRenderer.
Full typecheck (node + cli + web) clean.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(gitlab): workspace-from-MR via paste-URL (keystone end-to-end)
The first user-visible GitLab moment. Pasting a GitLab issue or MR URL
into the workspace name field now resolves through the full pipeline
to a created workspace with the right base ref and linkedGitLab*
persisted. The dedicated GitLab tab + state-filter chips remain a
follow-up; everything below it is wired.
- shared/lib/new-workspace.ts: LinkedWorkItemSummary.type accepts
`'mr'` alongside `'issue' | 'pr'`. Renderer code that switches on
type explicitly handles each kind.
- ui store slice: NewWorkspaceDraft mirrors the new linked slots so
drafts persist GitLab selections across navigation. Optional fields
for backward compatibility with drafts saved before this branch.
- useComposerState:
- linkedGitLabIssue / linkedGitLabMR state, draft persistence,
repo-switch reset, applyWorktreeMeta wiring.
- applyLinkedGitLabWorkItem mirrors applyLinkedWorkItem; reuses
getLinkedWorkItemSuggestedName by structurally projecting the
GitLab item onto the helper's input shape.
- handleSmartGitLabItemSelect parallels handleSmartGitHubItemSelect:
for picked MRs, calls window.api.worktrees.resolveMrBase to
resolve the base ref (refs/merge-requests/<iid>/head for fork
MRs) and threads it through handleBaseBranchMrSelect.
- "was MR !N" reset hint when a repo switch wipes a GitLab
selection — `!N` matches gitlab.com's MR-reference convention.
- preload: window.api.worktrees.resolveMrBase + window.api.gl.* are
already in. ComposerCardProps grows onSmartGitLabItemSelect (+
optional onBaseBranchMrSelect).
- SmartWorkspaceNameField:
- Paste-URL detection: parseGitLabIssueOrMRLink (host-agnostic via
`/-/` separator) → window.api.gl.workItemByPath → row in the
dropdown → click → forwarded to onGitLabItemSelect.
- SmartWorkspaceNameSelection union, RowEntry union, RowIcon,
RowLabel, SelectionIcon all carry the gitlab-mr / gitlab-issue
kinds. MR rows show `!N` prefix; issue rows show `#N`.
- Tab UI not added in this commit — paste-URL works in 'smart'
mode, the dedicated tab + Open/Merged/Closed/All chips lands
in a follow-up.
- NewWorkspaceComposerCard: forwards onSmartGitLabItemSelect to the
picker.
Full typecheck (node + cli + web) clean. 165 unit tests passing in
affected files.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(gitlab): GitLab tab in SmartWorkspaceNameField with state filter
The discoverable demo path. The picker now has a "GitLab" tab — when
selected it lists the project's MRs filtered by state via
`gitlab:listMRs`, with an Open / Merged / Closed / All chip strip
that mirrors gitlab.com's MR-page tab strip. Paste-URL detection in
'smart' mode is unchanged; the new tab simply makes the surface
discoverable without requiring a URL.
- SmartNameMode gains 'gitlab'; Gitlab icon (lucide) added to the
MODES array between GitHub and Branch.
- MrStateFilter / MR_STATE_FILTERS centralizes the four chip values
so the labels stay GitLab-native (Open vs the GraphQL 'opened').
- listMRs effect: fires when mode === 'gitlab' and no GitLab URL is
in the input, with the current state filter and a page-1 fetch
bounded by RESULT_LIMIT.
- Paste-URL effect now coexists with the list effect: it owns
gitlabItems while a URL is in the input, the list effect owns it
otherwise. Switching tabs no longer clears the list.
- Chip strip rendered above the popover's CommandList only when
mode === 'gitlab'. Buttons use the same Button component the rest
of the picker uses for visual consistency.
Full typecheck (node + cli + web) clean. 165 unit tests passing.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(gitlab): GitLab source on Tasks screen
The Tasks screen now offers GitLab as a third source alongside GitHub
and Linear. Selecting it surfaces MRs and issues for the primary
selected repo with a state filter (Open / Merged / Closed / All) that
mirrors gitlab.com's MR-page tab strip. Skips cross-repo aggregation,
search DSL, and Projects mode for v1 — those layers are GitHub-API-
shaped and would need a parallel store slice that is not worth porting
ahead of the actual demand for them.
- shared/types: GlobalSettings.defaultTaskSource accepts 'gitlab'.
- TaskPage:
- TaskSource union grows a 'gitlab' member; SOURCE_OPTIONS adds the
Gitlab icon between GitHub and Linear so the toolbar order matches
SmartWorkspaceNameField for cross-surface consistency.
- GITLAB_TASK_FILTERS centralizes the four chip values.
- Per-source state slim (matches Linear's pattern) — gitlabFilter,
gitlabItems, gitlabLoading, gitlabError, gitlabRefreshNonce.
- Data-fetch effect runs Promise.all over `window.api.gl.listMRs`
and `window.api.gl.listIssues` for the primary repo, merges and
sorts by updatedAt desc. 'merged' filter skips the issue fetch
(GitLab issues are 'opened' / 'closed' only).
- Filter bar block parallel to Linear's, with chips + a refresh
icon-button.
- List block: 5-column grid (ID / Title / Type+State / Updated /
Open-link). Row click opens the web URL — the GitLabItemDialog
is a follow-up commit, but the row affordance is enough for the
Tasks-screen demo.
- GitLab MRs render as `!N`; issues render as `#N` to match
gitlab.com's reference convention.
Full typecheck (node + cli + web) clean. 165 unit tests still
passing in affected files.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(gitlab): GitLabItemDialog (minimal) + Tasks screen wiring
Clicking a GitLab row on the Tasks screen now opens a side-sheet
preview with the item's title, state, author, and description body
rendered as markdown. "Open in browser" footer button stays as the
escape hatch; opening from the row is dialog-first now (matching the
GitHub side's row-click-to-dialog pattern). Files / comments /
pipeline tabs are deferred — they mirror substantial GitHub-side
surface area (work-item-details ~550 lines, GitHubItemDialog 2680
lines) and are not blocking the demo.
- types: MRInfo and GitLabIssueInfo gain optional description /
author / authorAvatarUrl. Optional because list endpoints strip
them; populated on detail-endpoint reads (`getMR` / `getIssue`).
- mappers: mapMRInfo and mapGitLabIssueInfo now pass description /
author / avatar through when present. Skipped (rather than
defaulted to '') so callers can distinguish "no body authored"
from "this came from a list".
- GitLabItemDialog: new ~200-line side sheet. Fetches the detail
payload via `window.api.gl.mr` / `gl.issue` on open; renders
CommentMarkdown for the description (reused from the GitHub
side); falls back to "No description." when the body is blank.
State badge tones picked locally — GitLab's MR state space is
wider than GitHub's so coupling them buys nothing.
- TaskPage: GitLab row now uses a div role=button with keyboard
handling so the inner Open-in-browser <button> nests cleanly
(HTML disallows nested <button>s, React would warn). Row click
sets gitlabDialogItem; the small ExternalLink icon stops
propagation so it still opens the URL.
Full typecheck (node + cli + web) clean. 165 unit tests passing in
affected files.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(gitlab): My Todos cross-project view on Tasks screen
The GitLab tab now has a Project | My Todos sub-toggle. "My Todos"
fetches gitlab.com/dashboard/todos via `glab api todos?state=pending`
and surfaces them in a separate table — action / title / project /
updated. This is the closest GitLab-native equivalent of GitHub's
notifications/inbox and lands in lieu of porting GitHub's search-DSL
which doesn't translate.
- shared/types: GitLabTodo type with action_name, target_type/iid,
target_url, project_path, author, updated_at. action_name kept as
open-ended string because new GitLab versions extend the verb set.
- gitlab/client.ts: listTodos uses `glab api --paginate todos?state=
pending&per_page=50`. User-scoped — cwd doesn't matter, but the
IPC path-validation guard still requires *some* registered repo
path so we keep the signature consistent with the rest of gl.*.
- IPC: `gitlab:todos` channel; preload `gl.todos`.
- TaskPage:
- gitlabView ('project' | 'todos') gates which list to render.
- Sub-toggle row above the chip strip; chips are hidden on the
Todos view since pending state has no Open/Merged/Closed axis.
- Refresh button serves both views (uses gitlabRefreshNonce).
- Todos table: 5-col grid, action verb (snake_case → spaces),
target title, project path (mono font for repo-likeness),
updated date, open-link icon. Row click opens target_url.
Full typecheck (node + cli + web) clean. 165 unit tests passing.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(gitlab): gitlabProjects settings (recents auto-tracked) + tests
Settings persistence for GitLab project preferences plus tests for
the surface added since the last green run.
- shared/types: GitLabProjectSettings { pinned, recent } and an
optional GlobalSettings.gitlabProjects slot. Optional for
backward compat with profiles saved before this branch — the
persistence merge fills the empty default.
- shared/gitlab-projects: pure helper computeNextGitLabRecents that
prepends-and-dedupes by host+path, caps at GITLAB_RECENTS_MAX
(10). Pulled out of the IPC handler so it tests without mocking
Store.
- gitlab IPC: workItemByPath handler now pushes the resolved
project ref onto recents on success. 404 / auth-fail lookups
do not pollute the list — recents reflects projects the user
actually read.
Tests added (12 new, 177 total passing in affected files):
- gitlab-projects.test: prepend, dedupe, host-vs-host distinct,
cap at max, no input mutation.
- client.test: listTodos mapping, defensive state coercion,
empty-on-error fallback, missing-target field defaults.
- mappers.test: description / author / authorAvatarUrl pass-
through on both mapMRInfo and mapGitLabIssueInfo, plus the
"absent vs blank" distinguishing assertion.
- mappers-workitem.test (split): mapMRToWorkItem + mapIssueToWorkItem
cases moved out of mappers.test.ts to keep both files under the
oxlint max-lines budget.
Full typecheck (node + cli + web) clean.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(gitlab): combined listWorkItems IPC + TaskPage refactor
Centralize the MR + issue merge logic that TaskPage was doing inline
into a single backend function and IPC channel. Future callers (the
picker's GitLab tab, any new widget) get the merge / sort / state-
mapping rule for free. The TaskPage effect drops from 60 lines of
inline orchestration to a single call.
- gitlab/issues: listIssues now accepts an IssueListState so the
combined caller can ask for closed / all instead of always opened.
CLI fallback path picks the right --opened / --closed / --all flag
per glab version. Existing callers keep the 'opened' default.
- gitlab/client: listWorkItems(state, page, perPage, preference) fans
out listMergeRequests + a raw issues fetch in parallel, merges by
updatedAt desc, returns a GitLabPagedResult<GitLabWorkItem>.
Bypasses listIssues for the issues side because IssueInfo strips
updated_at — the combined sort needs it.
state='merged' skips the issues fetch entirely (issues don't have
a merged lifecycle).
- IPC: new gitlab:listWorkItems handler.
- preload: gl.listWorkItems alongside gl.listMRs.
- TaskPage: GitLab fetch effect now calls gl.listWorkItems and stops
re-implementing the merge. Same UX, fewer moving parts.
Tests added (8 new in client-work-items.test.ts; +1 fix to
issues.test.ts for the new url-param order):
- merge ordering by updatedAt desc
- 'merged' state skips issues fetch
- closed / all state pass-through
- not_found envelope when project ref unresolved
- mr-error vs issue-side success interleaving
- combined error surfacing on either side failing
Full typecheck (node + cli + web) clean. 117 unit tests passing in
src/main/gitlab/ and src/shared/gitlab-projects.test.ts.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(gitlab): work-item-details + dialog Conversation/Pipeline tabs
Task 3 lean version. The minimal description-only dialog grows two
new tabs (Conversation / Pipeline) and four footer actions
(close / reopen / merge / comment). Files-tab and inline review-
comment positioning stay deferred — they mirror substantial GitHub-
side surface (GitHubItemDialog is 2680 lines, work-item-details.ts is
551) and the v1 demo doesn't need them.
- shared/types: GitLabPipelineJob (id, name, stage, status, webUrl,
duration), GitLabWorkItemDetails (item + body + comments[] +
pipelineJobs?[]). Mirrors GitHubWorkItemDetails layout.
- main/gitlab/work-item-details: getWorkItemDetails(repoPath, iid,
type) fans out parallel reads — issue: detail + discussions; MR:
detail + discussions, then pipeline jobs follow-up keyed off
head_pipeline.id. Discussion → MRComment flatten skips system
notes (auto-generated activity entries) so the conversation tab
shows only user content. Inline-review position carried through
as `path` + `line` for v1.5 to consume.
- main/gitlab/client: closeMR / reopenMR / mergeMR / addMRComment
mutations. mergeMR accepts the same 'merge' | 'squash' | 'rebase'
union as the GitHub side; close/reopen treat "already X" stderr
as success since the desired state is reached.
- IPC: gitlab:workItemDetails, closeMR, reopenMR, mergeMR,
addMRComment channels; preload `gl.*` bindings parallel.
- GitLabItemDialog rewrite: three Tabs (Description / Conversation /
Pipeline-MRs-only) + footer with comment composer + state-aware
Merge / Close / Reopen buttons. Cmd/Ctrl+Enter sends the comment
to match gitlab.com's textarea shortcut. Refresh icon in the
header re-fetches via a refreshNonce. eslint-disable max-lines on
the dialog matches the GitHub-side equivalent's reasoning.
Full typecheck (node + cli + web) clean. 184 unit tests passing.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(gitlab): sidebar icon, Smart-mix MRs, Integrations card, "Project MRs" rename
Four follow-up fixes that surfaced from smoke-testing:
- SidebarNav: GitLab icon next to GitHub / Linear in the Tasks-row
shortcut strip; clicks open the Tasks page already filtered to the
GitLab source. ui.ts taskPageData.taskSource union grows to accept
'gitlab' so the openTaskPage call typechecks.
- SmartWorkspaceNameField: list-MRs effect now fires in 'smart' mode
too, not just on the dedicated GitLab tab. The mixed picker
surfaces the user's project MRs alongside GitHub items. Paste-URL
effect still wins when a GitLab URL is in the input — the list
effect bails on parsedGlLink !== null.
- TaskPage: GitLab toggle relabels "Project" → "Project MRs" so the
pairing with "My Todos" reads more clearly.
- IntegrationsPane: new GitLab card mirroring the GitHub card —
status badge (checking / connected / not-installed / not-
authenticated), install link to gitlab.com/gitlab-org/cli, copy-
ready `glab auth login` block, learn-more link to the auth/login
doc, re-check button. Search-entry registered so settings search
finds it. eslint-disable max-lines justified by the same pattern
that already lives there for GitHub + Linear.
- preload: PreflightStatus.glab is optional on the type so older
payloads typecheck; consumers gate on the optional chain.
Full typecheck (node + cli + web) clean. 184 unit tests passing.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(gitlab): multi-repo aggregation on Tasks screen
Mirrors GitHub's cross-repo behavior. Previously the GitLab tab only
queried the first selected repo; now it fans out to every eligible
selected repo in parallel and merges results sorted by updatedAt
desc. The repo selector at the top of Tasks is the project picker —
it's the same one the GitHub tab uses, so the selection model is
consistent across providers.
- TaskPage gitlab fetch effect: Promise.allSettled across all
selectedRepos that aren't SSH-relay (folder-mode repos and remote
worktrees fall through). Each repo's project is resolved from its
own git remote by the main process; non-GitLab repos return
not_found which the renderer drops silently so a mixed selection
(GitHub + GitLab repos) doesn't surface false errors on the GitLab
tab.
- Per-row repoId tagging stays correct — items keep their source
repo's id through the merge, which matters for the dialog repoPath
resolution below.
- Banner display: only shown when EVERY eligible repo failed; partial
failure is signaled by the row count being lower, not a banner that
overshadows working repos.
- GitLabItemDialog repoPath: derived from the clicked item's
source repo (selectedRepos.find by repoId) instead of primaryRepo.
Without this, clicking an item from a non-primary repo would route
the detail fetch through the wrong repo's remote.
Full typecheck (node + cli + web) clean. 117 unit tests passing.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix(gitlab): swap MR icon to GitMerge for visual distinction
GitPullRequest (curved-merge) reads similar to GitBranch (forking
line) at the small sizes we use in the picker — feedback was that
MR rows looked like branch rows. GitMerge (arrow-merge-into-line)
reads as its own thing and matches gitlab.com's MR iconography, so
users coming from the web UI find it familiar.
GitHub PRs keep GitPullRequest — that matches github.com and keeps
provider attribution distinct from GitLab MRs at a glance:
GitHub PR: GitPullRequest (curved merge)
GitLab MR: GitMerge (arrow merge)
Branch: GitBranch (fork)
Issue: CircleDot (provider-agnostic)
- SmartWorkspaceNameField RowIcon + SelectionIcon: gitlab-mr →
GitMerge. github-pr stays GitPullRequest.
- GitLabItemDialog header icon: GitMerge for MRs.
Full typecheck (node + cli + web) clean. 117 unit tests passing.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* refactor(gitlab): split shared types + preload into per-provider files
Pre-emptive merge-conflict reduction. The two recent main syncs
each surfaced ~5 conflicts, all in the same handful of central
files where every provider lands code. Moving the GitLab footprint
into provider-scoped files cuts the conflict surface roughly in half
without changing any runtime behavior.
- shared/gitlab-types.ts (new, 272 lines): every standalone GitLab
type that previously lived in shared/types.ts —
GitLabProjectRef / MRState / MRMergeableState / MRCheckDetail /
MRInfo / GitLabReaction / MRComment / GitLabCommentResult /
GitLabIssueInfo / GitLabViewer / GitLabAssignableUser /
GitLabWorkItem / GitLabMRFile / GitLabProjectSettings /
GitLabTodo[TargetType] / GitLabPipelineJob /
GitLabWorkItemDetails / GitLabIssueUpdate / MRListState /
GitLabPagedResult / ListMergeRequestsResult.
- shared/types.ts: re-exports the GitLab types so existing call
sites importing from '../shared/types' keep working unchanged.
GitLabProjectSettings additionally imported locally for the
GlobalSettings.gitlabProjects field. Worktree.linkedGitLabMR /
WorktreeMeta.linkedGitLabIssue / GlobalSettings.defaultTaskSource
union member stay here — they're entangled with non-GitLab
structs and moving them out would just shuffle the conflict
vector to a different file.
- preload/gitlab.ts (new, 106 lines): the entire gl.* runtime
binding block — viewer / projectSlug / mrForBranch / mr /
listMRs / listWorkItems / issue / listIssues / createIssue /
updateIssue / addIssueComment / listLabels /
listAssignableUsers / todos / workItemDetails / closeMR /
reopenMR / mergeMR / addMRComment / workItemByPath. Exported as
`glApi`.
- preload/index.ts: imports `glApi` and inlines as `gl: glApi`,
shrinking the file by ~95 lines.
Net: the two files most prone to conflict on upstream sync
(shared/types.ts, preload/index.ts) lose ~360 lines of
GitLab-specific code that now live in their own files where main's
non-GitLab edits can't touch them.
Full typecheck (node + cli + web) clean. 190 unit tests passing
in src/main/gitlab/, src/shared/gitlab-projects.test.ts,
src/main/ipc/{preflight,worktree-logic}.test.ts,
src/renderer/src/lib/gitlab-links.test.ts.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix(gitlab): satisfy pnpm pre-flight (lint + handler-registration test)
- TaskPage: lift the selected-repos identity key into a useMemo so the
GitLab fetch effect's dep array no longer holds a complex expression
(oxlint exhaustive-deps).
- register-core-handlers.test: mock ./gitlab alongside ./github / ./linear
so registerGitLabHandlers doesn't try to call ipcMain.handle in a unit
test that fakes only individual handler modules.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(source-control): add Bitbucket hosted review support
* fix(source-control): align hosted review lookup with provider model
---------
Co-authored-by: Emilian Stoilkov <emilian.stoilkov@qaiware.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Improve mobile terminal streaming performance
Co-authored-by: Orca <help@stably.ai>
* Add mobile clear terminal action
Co-authored-by: Orca <help@stably.ai>
* Fix terminal connection test mock
Co-authored-by: Orca <help@stably.ai>
* WIP: mobile markdown tabs before rebase
Co-authored-by: Orca <help@stably.ai>
* Add mobile markdown editing
Co-authored-by: Orca <help@stably.ai>
* Harden mobile tab and markdown sync
Co-authored-by: Orca <help@stably.ai>
* Fix mobile terminal reconnect loading race
Co-authored-by: Orca <help@stably.ai>
* Polish mobile terminal keyboard behavior
Co-authored-by: Orca <help@stably.ai>
* Simplify mobile markdown editor chrome
Co-authored-by: Orca <help@stably.ai>
* Move mobile markdown actions to top
Co-authored-by: Orca <help@stably.ai>
* Use app modals for markdown discard
Co-authored-by: Orca <help@stably.ai>
* Dismiss keyboard before markdown confirmations
Co-authored-by: Orca <help@stably.ai>
* Add mobile file explorer
Co-authored-by: Orca <help@stably.ai>
* Fix mobile file explorer type narrowing
Co-authored-by: Orca <help@stably.ai>
* Fix mobile files navigation param
Co-authored-by: Orca <help@stably.ai>
* Show mobile files connection wait state
Co-authored-by: Orca <help@stably.ai>
* Preview text files on mobile
Co-authored-by: Orca <help@stably.ai>
* Simplify mobile file previews
Co-authored-by: Orca <help@stably.ai>
* Clarify unavailable mobile file types
Co-authored-by: Orca <help@stably.ai>
* Fix mobile subscription and preview review issues
Co-authored-by: Orca <help@stably.ai>
* Keep fallback terminals visible on mobile
Co-authored-by: Orca <help@stably.ai>
* Keep mobile terminal tap active
Co-authored-by: Orca <help@stably.ai>
* Preserve mobile terminal fallback order
Co-authored-by: Orca <help@stably.ai>
* Fix mobile session tab authority
Co-authored-by: Orca <help@stably.ai>
* Run mobile tests in mobile CI lane
Co-authored-by: Orca <help@stably.ai>
* Bump mobile app version to 0.0.7
Co-authored-by: Orca <help@stably.ai>
* Allow main window IPC wiring size
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
Added DeviceRegistry.rotatePendingDevice and threaded a 'rotate' option through the mobile:getPairingQR IPC + preload + MobilePane so explicit Regenerate clicks mint a fresh pending token instead of returning the same one.
Findings addressed:
- [medium] src/main/runtime/device-registry.ts:44-50 — 'Regenerate QR' no longer rotates the token
Rebased onto current main to resolve conflicts.
Co-authored-by: orca-bot <bot@stably.ai>
Fixed 6 findings: legacy fetch fallback for local-only bases, memoized canonical fetch key, recorded reconcile token before await, cleared token in finally, configurable publish remote, and fetch-failure-aware base ref error.
Rebased onto current main applying only the Fixer-summary files (worktree-remote.ts, orca-runtime.ts) to avoid silent reverts from a stale base.
Co-authored-by: neil <neil@nous.com>
Surface worktree creation immediately and reconcile remote base state
asynchronously, emitting drift/conflict events as fetches complete.
Co-authored-by: Orca <help@stably.ai>
host-store: write AsyncStorage metadata before SecureStore token to avoid orphaned keychain tokens on crash. mobile IPC: coalesce repeated getPairingQR calls onto a single pending device token via new DeviceRegistry.getOrCreatePendingDevice.
Findings addressed:
- [high] mobile/src/transport/host-store.ts — saveHost orders Keychain write before AsyncStorage — orphaned tokens on crash
- [low] src/main/ipc/mobile.ts:84-95 — getPairingQR creates a device token on every call, leaking pre-paired entries
Rebased onto current main to resolve conflicts; preserved tokenCache.set added on main.
Co-authored-by: orca-bot <bot@stably.ai>
Replace ProfileCreate.scope coerce-to-isolated transform with strict
z.enum(['isolated', 'imported']) so unknown scopes surface validation
errors instead of being silently rewritten.
Supersedes #1455 (which was branched off stale main and would have
reverted #1396).
Co-authored-by: Jinjing <jinjing@stably.ai>
* feat(cli): add browser tab profile controls
* feat(cli): add tab profile automation primitives
* refactor(cli): narrow tab profile automation scope
* chore: retrigger PR checks
* review: harden tab profile automation CLI
- Wait for tab re-registration after browser.tabSetProfile so a follow-up tab list --show-profile reads the new sessionProfileId from BrowserManager instead of the stale one from the previous webview
- Wait for tab registration after browser.tabProfileClone, matching browser.tabCreate, so the cloned browserPageId is operable when the CLI returns
- Short-circuit browser.tabSetProfile when the tab is already on the requested profile so we do not tear down and remount the webview for a no-op switch
- Switch TabShow.worktree from OptionalPlainString to OptionalString to match every other tab schema; empty --worktree should fall back to the active worktree, not pass through as the empty string
- Add max-lines disable to browser.test.ts (file grew past 300 lines after adding the new tab-profile and tab-show tests)
* review: fix useIpcEvents test setup for tab profile API
CI failure: useIpcEvents.test.ts threw at module load with TypeError: window.addEventListener is not a function. The chain: the rebased useIpcEvents.ts imports destroyPersistentWebview from webview-registry, which calls window.addEventListener at module load. The test stubs window via vi.stubGlobal as a plain object without addEventListener, so the typeof window check passes but the call throws.
- webview-registry.ts: tighten the module-load guard to also check that window.addEventListener is callable, so importing this module from a non-DOM-ish test env (vitest node env with stubbed window) does not throw at module load
- useIpcEvents.test.ts: add the new onRequestTabSetProfile and replyTabSetProfile stubs to all 8 window.api.ui mocks so the new IPC subscription registered by useIpcEvents resolves
* review: restore profile CRUD lost during rebase onto 1397-merged main
The rebase brought commit 3242aa27 (refactor: narrow tab profile automation scope) onto a main that already had the lifecycle CRUD from 1397. The refactor commit removes BrowserProfileList/Create/Delete types, runtime methods, RPC registrations and schemas, plus the help/specs entries, because those were the precursor versions in commit 1 of this branch. Post-rebase those removals land on the hardened versions inherited from main, breaking 1397.
Restore:
- runtime-types.ts: BrowserSessionProfile import; ProfileList/Create/Delete result types
- orca-runtime.ts: ProfileList/Create/Delete result type imports; browserProfileList/Create/Delete methods
- browser-core.ts: ProfileCreate, ProfileDelete schema imports; browser.profileList/profileCreate/profileDelete RPC registrations
- browser-schemas.ts: ProfileCreate, ProfileDelete zod schemas
- help.ts: list/create/delete subcommand lines under Browser Automation
- specs/browser-basic.ts: list/create/delete spec entries
---------
Co-authored-by: Nikolatesla-lj <Nikolatesla-lj@users.noreply.github.com>
Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
* feat(orchestration): transport keepalive + delivered_at split for check --wait
Implements the four §3 fixes from the check-wait design doc:
- §3.1 Transport keepalive: long-poll RPCs (orchestration.check --wait) emit
`{"_keepalive":true}` frames every 10s so neither server nor client tears
the socket down on idle. A `longPoll` admission counter capped at 16 fails
fast with `runtime_busy` when saturated; an AbortController wired through
the RPC dispatcher cancels the inner waiter the moment the socket closes.
- §3.2 delivered_at split: push-on-idle now stamps `delivered_at` instead of
flipping `read`, so the check caller remains the sole consumer of its
queue. Adds a synchronous idempotent schema migration that hard-fails on
error.
- §3.3 inbox/check parity: `orchestration inbox --terminal <handle>` and
`orchestration check --all` agree on the same rows (sequence DESC, no
mark-read). `check --unread=false` kept for one release as a compat shim.
- §3.4 CLI heartbeat: `orca orchestration check --wait` emits JSON heartbeat
lines to stderr every 15s so Claude Code's Bash tool sees continuous
output and doesn't auto-background the subprocess.
Tests: extends runtime-rpc, orca-runtime, envelope-schema, orchestration
method, and formatter suites; adds a subprocess test that spawns the built
CLI and verifies stderr line-flushing, heartbeat cadence, and stdout
cleanliness end-to-end.
Co-authored-by: Orca <help@stably.ai>
* feat(orchestration): preamble rules + heartbeat schema
- Preamble (#7, #15, #9): worker_done body ("3-sentence summary" + reportPath),
BEHAVIOR RULE #1 forbidding AskUserQuestion, heartbeat every 5 minutes with
taskId+dispatchId payload, AFTER YOU SEND grace window.
- Schema v2 migration: adds 'heartbeat' to messages.type CHECK, adds
dispatch_contexts.last_heartbeat_at, gated by user_version PRAGMA with
transactional rebuild + explicit CREATE INDEX to avoid silent perf regress.
- DB helpers: recordHeartbeat (dispatched-only), getStaleDispatches,
getThreadMessagesFor (thread+handle scoped for ask).
Co-authored-by: Orca <help@stably.ai>
* feat(orchestration): coordinator heartbeat + stale detector
Handle incoming 'heartbeat' messages by calling recordHeartbeat keyed on
payload.dispatchId (strict — log-and-skip if missing, no taskId fallback so
a straggler heartbeat from a previously-failed dispatch cannot mask a hung
retry per §5.3.4). On every tick after the 10-minute threshold, emit one
log per stale dispatched row — no auto-fail.
Also threads dispatchId through buildDispatchPreamble so workers can
attribute their heartbeats back to the correct dispatch context.
Co-authored-by: Orca <help@stably.ai>
* feat(orchestration): orca orchestration ask verb
Adds a CLI verb that sends a decision_gate message and blocks on the
coordinator's reply, scoped to the outbound message's thread. Group
addresses (@all, @idle, …) are rejected — fan-out questions must use
send --type decision_gate explicitly.
--json emits bare single-line JSON (bypassing printResult) so workers can
pipe `orca orchestration ask … --json | jq -r .answer` without unwrapping
an RPC envelope; human mode prints just the answer. On timeout the verb
exits 1 and returns {answer: null, timedOut: true}.
This is the CLI surface BEHAVIOR RULE #1 in the dispatch preamble points
workers at instead of AskUserQuestion.
Co-authored-by: Orca <help@stably.ai>
* feat(orchestration): QoL bundle — preamble visibility, status enum, dispatch cross-ref, inbox --full
Addresses four items from ORCHESTRATOR_FEEDBACK:
- #5 preamble visibility: `dispatch-show --preamble` regenerates the preamble
text for a task; `dispatch --inject --dry-run` previews without mutating
state; `dispatch --return-preamble` echoes the injected preamble in the JSON
response so coordinators can audit what a worker received.
- #6 status enum validation: CLI rejects unknown `task-update --status` values
with `invalid status '<x>', expected one of: pending, ready, dispatched,
completed, failed, blocked` before the RPC's generic Zod message. Valid
statuses are listed under Notes in `task-update --help`.
- #13 task-list dispatch cross-ref: `task-list --json` now includes
`assignee_handle` and `dispatch_id` for tasks in status=dispatched via a
read-only LEFT JOIN on dispatch_contexts. Non-dispatched rows keep their
legacy shape so existing consumers are unaffected.
- #14 inbox body visibility: `inbox --full` prints body + payload verbatim;
default output is unchanged (id/from/to/subject only).
No DB migrations; join-only change on dispatch_contexts so the sibling
preamble PR's `last_heartbeat_at` column addition will not conflict.
Co-authored-by: Orca <help@stably.ai>
* fix(worktree): prevent stale-base worktree creation and dispatch
Addresses feedback #16 per DESIGN_DOC_STALE_BASE_FIX.md §0. Four v1
components coordinated by a single shared fetch cache on the runtime:
1. Concurrent-fetch-with-gate in UI create path: `createLocalWorktree`
fires `git fetch` BEFORE the suffix loop / PR probe / path
resolution, then awaits right before `addWorktree` so the new branch
always spawns from a fresh remote tip. Renderer sees a two-phase
spinner via the new `createWorktree:progress` IPC event. The cache
is a `Map<repoPath::remote, Promise<void>>` + 30s success-only
timestamp on `OrcaRuntimeService` (§7.1 — shared with dispatch).
2. Dispatch pre-flight drift guard in `Coordinator.dispatchTask`:
probes `rev-list --left-right --count` against the target worktree
and silently returns (preserves `ready`, no circuit-breaker burn)
when `behind > 20` unless the task spec carries
`allow-stale-base: true`. Parsing strips the flag so it never leaks
into the worker's `--- TASK ---` block.
3. Preamble drift section: populated only when dispatch detected drift.
Workers see `--- BASE DRIFT ---` with the N-most-recent subjects
they don't have, so they can pull them in before running.
4. §3.3 Lifecycle: `.finally()` evicts Map entries on BOTH success and
rejection; timestamp is written ONLY on success. Prevents a single
DNS hiccup from wedging every future create on the repo until
restart, and keeps the freshness window honest.
Defers the DB `allow_stale_base` column (§0.2) and the create-time
warn toast; both can layer in later without migration.
Tests: 35 new/updated unit tests covering drift preamble, dispatch
refusal, spec-text flag parsing, fetch Map eviction after rejection,
freshness-window short-circuit, and concurrent-caller serialization.
Co-authored-by: Orca <help@stably.ai>
* test(orchestration): seed v2 DB in migration hard-fail test
After consolidating the schema bump, fresh DBs are initialized directly at
v3 via createTables(), so the v2→v3 ALTER TABLE is skipped on new installs
and the prior test's stub never fired. Seed a v2-shape file on disk so the
guarded ALTER actually runs and the "simulated migration failure" stub
propagates as intended.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* fix(runtime): kill all PTYs for a worktree on removal (design §4.3)
Worktree deletion only shut down renderer-tracked terminals, so PTYs owned
by background tabs, split panes, or pre-reload sessions survived the
removal and kept leaking memory. Introduce killAllProcessesForWorktree
with three sweeps (runtime leaves, provider-prefix scan of daemon session
ids, pty-registry by worktreeId) and wire it into both teardown paths:
the CLI-initiated removeManagedWorktree and the renderer-initiated
worktrees:remove IPC handler. OrcaRuntimeService gets a lazy
getLocalProvider thunk so construction order stays robust.
Co-authored-by: Orca <help@stably.ai>
* fix(renderer): purge worktree-scoped state on removal + hydration (design §4.4)
When a worktree is deleted, ~25 worktree-scoped maps (tabsByWorktree,
git caches, browser state, split-tab models, per-file editor drafts,
etc.) kept references to the gone worktree, so SessionsStatusSegment
kept mis-classifying orphaned PTYs as bound and dropdowns rendered stale
ids. Add purgeWorktreeTerminalState as a single atomic action that
wipes every scoped map plus cascades top-level actives. Fire it from
the worktrees:changed listener on the set-diff of removed ids, and once
more at hydration via fetchAllWorktrees to clean up persisted entries
from pre-fix sessions. The hydration-time purge is gated behind a
per-repo success check: a single transient IPC error or an all-empty
fetch defers the purge so a degraded launch cannot wipe legitimate
persisted state.
Co-authored-by: Orca <help@stably.ai>
* test(zombie-worktree): regression coverage for design §4.5
Adds tests for every layer of the zombie-worktree fix:
- worktree-teardown: unit coverage of the three-sweep helper including
best-effort error swallowing across provider/registry.
- orca-runtime: RPC-initiated removeManagedWorktree kills PTYs before
any git mutation + verifies the lazy getLocalProvider thunk resolves
on each call.
- worktrees IPC: renderer-initiated remove kills PTYs before git and
skips the kill helper for SSH-backed repos.
- renderer slice: fetchAllWorktrees defers the purge when any sibling
repo fetch fails or every repo returns empty (F1 regression);
happy-path fires the purge once and does not re-run on subsequent
calls. Direct purgeWorktreeTerminalState coverage pins the cascade
across worktree-keyed, tab-id-keyed, and file-id-keyed maps.
Co-authored-by: Orca <help@stably.ai>
* fix(runtime): log worktree-teardown kill counts (design §4.4 observability)
Breadcrumb lets ops distinguish a renderer-state-induced leak (diff-path
purge non-empty) from a backend-induced one (nothing to kill but memory
still pinned). Emit only when the sweep actually shut anything down so
steady-state logs stay quiet. Added at both call sites —
removeManagedWorktree (CLI path) and the worktrees:remove IPC handler.
Co-authored-by: Orca <help@stably.ai>
* test(zombie-worktree): fix ptyIdsByTabId seed shape to match production type
The purge unit test seeded ptyIdsByTabId as Record<string, string> when
the runtime type is Record<string, string[]>. The unit tests passed
because they never hit the UI renderer, but live e2e surfaced a
TypeError: (ptyIdsByTabId[tabId] ?? []).some is not a function.
Corrected to arrays; 21/21 tests still pass.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* fix(runtime): add single-instance lock + owned-metadata clear to prevent orca-runtime.json corruption
Closes#1312.
Every AppImage/.app relaunch was booting a fresh Electron main that clobbered
`<userData>/orca-runtime.json` and `agent-hooks/endpoint.env`. When the newest
instance quit, metadata pointed at a dead pid and `orca status` reported
`stale_bootstrap` even though the original Orca was still running. SIGKILL'd
predecessors also left orphaned `o-<pid>-*.sock` files in userData.
Three surgical changes:
1. `app.requestSingleInstanceLock()` in a new
`src/main/startup/single-instance-lock.ts` helper, wired into
`src/main/index.ts` after `configureDevUserDataPath(is.dev)` so dev and
packaged runs lock in separate namespaces. Losing instances focus the
primary's window via `second-instance` and quit without touching userData.
2. `clearRuntimeMetadataIfOwned(userData, pid, runtimeId)` in
`runtime-metadata.ts` — compares both pid AND runtimeId against the
current file before clearing, so the auto-updater handoff window never
erases the replacement process's fresh bootstrap. Called from a rewritten
`will-quit` handler that folds `runtimeRpc.stop()` + owned-clear into the
same `Promise.allSettled([disconnectDaemon, …]).then(app.quit)` chain
(inside the `!daemonDisconnectDone` guard so the second-pass re-entry
can't re-invoke stop+clear).
3. `sweepOrphanedRuntimeSockets()` in `runtime-rpc.ts` runs at the top of
`start()` on POSIX, using `process.kill(pid, 0)` to probe liveness and
remove `o-<dead-pid>-*.sock` orphans left by SIGKILL/OOM-kill.
Tests (37 new/updated):
- `single-instance-lock.test.ts` (3): lock-failed does not register listener;
lock-acquired registers exactly one; callback dispatches correctly.
- `runtime-metadata.test.ts` (+4): clearRuntimeMetadataIfOwned matched /
pid-mismatch / runtimeId-mismatch / no-file branches.
- `runtime-socket-sweep.test.ts` (4): own-pid-skip / alive-retain /
dead-sweep / regex-miss separated via synthetic ownPid=1; two
regex-invariant tests assert the sweep regex matches the real
`createRuntimeTransportMetadata` output (including the 'rt' fallback).
Design doc: `docs/fix-missing-single-instance-lock.md`.
Co-authored-by: Orca <help@stably.ai>
* fix(runtime): focus hidden windows on second-instance event
focus() alone is a silent no-op when the primary window is hidden
(close-to-tray on macOS via Cmd+W, or on a different macOS Space) or
behind other apps on Windows. Call show() before focus() so a second
launch attempt reliably surfaces the existing window regardless of
state.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* fix(hooks): generate worktree setup-runner from target worktree's orca.yaml
Extend getEffectiveHooks, getSetupCommandSource, and runHook with an
optional worktreePath parameter. When provided, loadHooks reads the
yaml from that path; otherwise it falls back to repo.path. Update
the worktree-creation paths in worktree-remote.ts and orca-runtime.ts
to thread the new worktreePath through after the worktree exists, so
the generated setup-runner reflects the yaml at the tip of the target
worktree's branch instead of the primary checkout's stale yaml.
Add a regression test in hooks.test.ts that mocks two distinct
orca.yaml files (primary and worktree) and asserts the worktree's
content wins when worktreePath is passed.
The legacy hooks:check IPC handler keeps reading from repo.path
unchanged.
Closes#1256
* fix(hooks): skip auto-setup when worktree script differs from preview
Add setupScriptsMatch helper that compares the primary checkout's
setup script (what the renderer shows the user before worktree
creation) to the target worktree's script (what would actually run
after creation). When they differ, createLocalWorktree skips the
auto-launch and logs a warning, so a base-branch yaml that introduces
or modifies setup commands cannot execute under the trust granted to
the primary's preview. CLI-created worktrees use the worktree-bound
load directly because trust is granted by the CLI invocation context,
which is annotated in orca-runtime.ts.
Adds regression coverage for both matching and differing script cases.
* test(hooks): add setupScriptsMatch to worktree IPC test mocks
The new setupScriptsMatch import in worktree-remote.ts means the
existing vi.mock('../hooks') blocks in worktrees.test.ts and
worktrees-windows.test.ts now need to expose it. Default the mock to
returning true so existing tests continue to exercise the run-setup
path; the new behavior gating is covered by the dedicated
setupScriptsMatch unit tests.
Audited and rebased PR 1138. Squashed to remove the original untrusted commit stack; hook execution now requires explicit UI trust or CLI --run-hooks opt-in.