* fix: authorize guarded sends to active ConPTY agents
* Fix stale-handle rejection using controller-less status checks and contr
- Distinguish `terminal_handle_stale` (PTY rebind mid-check) from `terminal_exited`
so callers get an accurate reason instead of a generic `terminal_not_writable`.
- Move the PTY binding assertion to always run after the fresh foreground read,
even when no controller is present, closing a gap where a rebind during a
controller-less check went undetected.
- Call `confirmForegroundProcess` through its owning controller instance so the
method keeps its `this` receiver instead of being invoked unbound.
- Update reliability gates and design doc to reflect the new test coverage and
corrected error semantics.
* rm design doc
* Fix mobile terminal query reply authority
* fix(terminal): harden mobile query reply handoffs
* fix(terminal): exclude passive mobile query responders
* fix(terminal): gate mobile query replies on host capability
Older hosts strip terminal.send's inputKind (zod drops unknown keys), so a
forwarded xterm reply would land as ordinary floor-taking shell input. Hosts
now advertise terminal.query-reply-input.v1 via status.get and mobile drops
replies unless the host advertises it (pre-fix behavior). Also documents the
bounded desktop-to-mobile handoff double-reply residual.
Co-authored-by: Orca <help@stably.ai>
* fix(terminal): advance snapshot seq across recovery snapshots
The pending-overflow recovery loop trims buffered output against
recovery.seq while query replay and boundary strips kept using the
initial snapshot seq. Unreachable under today's control flow (no await
separates the initial-overflow consume from the loop), but the stale
seq would silently drop covered query replies if that ordering ever
changes. Track the seq that actually covered the buffered chunks.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* fix(terminal): send CSI-u Shift+Enter to kitty TUIs (droid) on Windows (#7620)
On Windows, Shift+Enter was always sent as the Alt+Enter byte ESC+CR (added in
#2418 for Codex, which reads win32-input-mode and ignores CSI-u). droid speaks
the kitty keyboard protocol, parses CSI-u directly, and treats ESC+CR as a plain
Enter — so Shift+Enter SUBMITTED the message instead of inserting a newline.
droid works in other terminals (Windows Terminal, Warp) because those honor
win32-input-mode / kitty; Orca (xterm.js) withholds kitty from local Windows
ConPTY panes and emits neither.
Make the Windows Shift+Enter byte pane-aware: latch whether a pane's program
advertised the kitty keyboard protocol (query CSI ? u, push CSI > .. u, or set
CSI = .. u) and send CSI-u (\x1b[13;2u) to those panes, keeping the
Codex-compatible ESC+CR for win32-input-mode-only TUIs. Non-Windows is unchanged
(always CSI-u).
Verified end-to-end against the real droid and Codex CLIs through the actual
production functions: droid now newlines, Codex still newlines.
* fix(terminal): route Windows Shift+Enter safely for Droid
---------
Co-authored-by: Neil <neil@stably.ai>
Co-authored-by: Neil <4138956+nwparker@users.noreply.github.com>
* fix(terminal): reset PTY delivery accounting across renderer lifecycle resets (frozen panes)
Panes froze permanently because main's PTY->renderer flow control leaked
its unacked in-flight byte counters and pending backlog across renderer
reloads/crashes: the lifecycle reset cleared only visibility hints, daemon
PTYs outlive the page, and the new page never acks the dead page's bytes,
so any pty with >=512KB unacked at reload time was delivery-gated forever
(proven by dev repro: counter pinned at exactly 524288; one manual ackData
of the leaked bytes instantly unfroze the pane).
Fix: (1) zero in-flight counters + pending backlog on every main-frame
renderer lifecycle reset (panes rebuild losslessly from main's
authoritative snapshot on reattach); (2) hold PTY sends until the new
page's pty:data listener signals ready (pty:rendererDispatcherReady), so
boot-window output accrues in the capped backlog instead of being
counted-but-dropped; (3) 10s self-heal watchdog + reconcile-on-handshake
backstop so a missed reset (subframe-overlapped reload emits no
did-start-loading) or lost handshake can never itself freeze delivery;
(4) derive the active-renderer-pty report reactively so in-place rebinds
keep the interactive reserve; (5) expose reset/gate state in the delivery
debug snapshot for future diagnosis.
Adds an experimental reliability gate
(pty-delivery.renderer-lifecycle-accounting-reset) with red/green-proven
regression tests for each branch of the fix.
* chore(reliability-gates): link PR #8034 as the gate's motivating fix
* fix(terminal): sender-guard the dispatcher-ready handshake; fix WSL gate wording
CodeRabbit: the reconcile backstop destructively clears delivery
accounting, so a straggler pty:rendererDispatcherReady from a dying
window's webContents must not reset the new window — reuse the pty:write
main-window sender check (+ regression test). Also resolve the
contradictory WSL coverage claim in the reliability gate notes (WSL rides
the same local/daemon pipeline; mobile/relay and SSH are separate paths).
After #7750 removed the containment guard, the residual #7239 failure mode
is a persisted/inherited startupCwd whose directory no longer exists: every
spawn dies with the provider's missing-directory error. Fresh local renderer
spawns now opt in (cwdFallback: 'worktree') to recover at the workspace root
with a generic in-terminal notice; reattach, SSH, remote-runtime, runtime/API
and mobile callers keep exact cwd semantics, and existing directories —
including outside the worktree (#7685) — spawn as requested.
Co-authored-by: Orca <help@stably.ai>
* fix terminal IME candidate selection and text commit on Linux
Sogou Pinyin and fcitx on Linux failed in Orca's terminal because bare
229 keydowns were swallowed, and empty composition updates prematurely
deactivated tracking. This led to dropped Chinese text or leaked Space/digit
candidate-selection keys reaching the PTY.
- Allow bare 229 keydowns to bypass suppression on Linux so xterm can diff
and commit text.
- Prevent empty compositionupdate events from prematurely deactivating
the composition tracker.
- Suppress and preventDefault candidate-selection keys (Space and digits)
during active composition and a brief post-composition window.
- Add comprehensive unit tests and an Electron CDP-driven E2E repro.
* fix: register IME gate command as direct spec-file invocation
The reliability-gate checker rejects --grep title selectors and requires
every evidenceRun command to match a gate command. Drop the --grep from
the e2e gate command and its evidence run, and remove the stale 3-file
evidence run superseded by the full 7-file run.
Co-authored-by: Orca <help@stably.ai>
* Guard overlapping and post-composition Linux IME candidate keys
- Track pending candidate key releases in a Map instead of a single
slot to support overlapping selector key events without stranding.
- Apply the candidate selection guard to post-composition key releases
that arrive after compositionend, preventing digits/Space from
leaking into the PTY.
- Restrict the Linux/Sogou candidate selection guard to Linux to
prevent interference on macOS and Windows.
- Exclude Shift+Space from candidate selection key checks.
* Guard held-key IME candidate repeats and scope policy to desktop Linux
- Keep auto-repeat keydowns for a candidate key suppressed past the
250ms guard window until its corresponding keyup event is received.
- Clear stale pending releases on fresh non-repeat keydowns to avoid
guarding the wrong key events.
- Exclude Android and ChromeOS user agents from desktop Linux-specific
IME candidate key suppression behaviors.
- Ensure the composition tracker is activated unconditionally on
compositionupdate events.
* Clean up IME reference and extract shared test event fixture
- Remove the obsolete Linux Sogou Pinyin IME reference document.
- Extract the fully-defaulted XtermBypassEvent helper into a shared
fixture file to keep the policy test suites in sync.
- Add a test verifying that Shift+Space (fcitx full-/half-width toggle)
is not suppressed as an IME candidate key.
---------
Co-authored-by: Orca <help@stably.ai>