Commit Graph
8614 Commits
Author SHA1 Message Date
38e82b4fff Fix AI Vault scanning for runtime hosts (#7631)
* Fix AI Vault runtime host scanning

* fix runtime ai vault response validation

* test runtime ai vault validation more loosely

* fix(ai-vault): harden runtime host scanning

Co-authored-by: Orca <help@stably.ai>

* fix(ai-vault): resume runtime host sessions

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
Co-authored-by: Orca <help@stably.ai>
2026-07-08 11:20:26 -07:00
github-actions[bot] ea652a1ffe Update README downloads badge 2026-07-08 12:50:39 +00:00
github-actions[bot] 745765bb96 release: v1.4.129-rc.1 v1.4.129-rc.1 2026-07-08 09:34:47 +00:00
14ac945c50 fix(main): detect CJK input source via cfprefsd on macOS 15 (#7572)
* fix(main): detect CJK input source via cfprefsd on macOS 15

macOS 15's `plutil -extract <key> json` aborts with "invalid object in
plist for destination format" on the AppleSelectedInputSources array even
though it is all strings, so the selected-input-source probe threw and fell
back to the keyboard layout id (com.apple.keylayout.US). That disabled
forwardAsciiPunctuation, so third-party IMEs (Sogou, Doubao) sent half-width
,.? to the PTY instead of full-width ,。? in terminal panes and agent chat.
Apple's built-in IME happened not to trip the plutil bug.

Read the live prefs via `defaults export` (cfprefsd) and extract as xml1
before converting the clean subtree to JSON, dodging both the plutil json
bug and the stale on-disk plist. The parser and CJK term list are unchanged.

* fix(main): reap CJK input-source probe process group on timeout

Run the macOS input-source probe via detached spawn and SIGKILL the whole
process group on timeout so a wedged cfprefsd can't orphan the defaults/plutil
pipeline stages (the probe re-runs on every window focus-in). Pin absolute
/usr/bin paths, guard the stdout stream, and cover the non-zero-exit, spawn-
failure, and timeout fallbacks in tests.

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: su'qiang <nslogname@MacBook-Pro.local>
Co-authored-by: Jinjing <6427696+AmethystLiang@users.noreply.github.com>
Co-authored-by: Orca <help@stably.ai>
2026-07-08 02:24:41 -07:00
Ken FukuyamaandJinjing 45931a716e Allow browser annotations to target existing agents (#7347)
* Allow browser annotations to target existing agents

* Update browser annotation send tooltip

* test: guard browser annotation send menu wiring

---------

Co-authored-by: Jinjing <6427696+AmethystLiang@users.noreply.github.com>
2026-07-08 01:35:37 -07:00
Brennan BensonandOrca c0091c07c3 perf(ssh): visibility-gate and back off the remote port scanner (#7610)
Co-authored-by: Orca <help@stably.ai>
2026-07-07 21:42:12 -07:00
a09a00f066 fix(pty): load omp status extension in wsl shells (#7642)
Co-authored-by: Orca <help@stably.ai>
Co-authored-by: Brennan Benson <79079362+brennanb2025@users.noreply.github.com>
2026-07-07 21:24:08 -07:00
2ce77d9098 fix(runtime): keep same-path imports host-qualified (#7395)
* fix(runtime): keep same-path imports host-qualified (#7018)

* review: harden runtime repo host match against SSH-repo hijack

An unstamped repo with a connectionId is an SSH repo (resolves to
ssh:<id>), so a same-path runtime import must not adopt it into a
runtime/local host. Match/adopt an unstamped repo only when it has no
connectionId, mirroring the existing local-IPC dedup guard
(src/main/ipc/repos.ts). Adds a regression test that fails without the
guard (SSH repo hijacked into runtime host).

Co-authored-by: Orca <help@stably.ai>

* review: only runtime hosts backfill an unstamped repo

A legacy unstamped repo is indistinguishable from a genuine local repo
(both have null executionHostId and connectionId). Restrict the adoption
branch to runtime incoming hosts so a local/ssh import at a colliding
path can never re-attribute a real local project to the wrong host.
Runtime is the only host that lost its identity to the pre-#7018
path-only import and needs the backfill. Adds a regression test.

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
Co-authored-by: Orca <help@stably.ai>
2026-07-07 20:45:55 -07:00
Jinwoo HongandOrca 8368e946df Fix orchestration agent prompt injection (#7758)
Co-authored-by: Orca <help@stably.ai>
2026-07-07 19:50:57 -07:00
Jinwoo Hong dfc12f2cf6 fix(watcher): isolate @parcel/watcher in a forked process so native crashes can't kill the app (#7547) (#7757) 2026-07-07 22:10:22 -04:00
Jinwoo HongandOrca 98bee1b419 Fix un-removable SSH ghost worktrees after host remove/re-add (#7753)
Co-authored-by: Orca <help@stably.ai>
2026-07-07 19:01:42 -07:00
Jinjing 7385494560 Add backup WeChat QR to main README 2026-07-07 18:42:57 -07:00
Jinjing 01f6cb6de9 Add backup WeChat QR image 2026-07-07 18:41:10 -07:00
github-actions[bot] 5c3c2f2b3d release: v1.4.129-rc.0 v1.4.129-rc.0 2026-07-08 00:55:27 +00:00
Brennan BensonandOrca f311539f9c Split agent-detection into title status/display/identity domain modules (title evidence plan, PR 3) (#7612)
Co-authored-by: Orca <help@stably.ai>
2026-07-07 17:50:37 -07:00
Luis Sebastian Urrutia Fuentes 37ba94a228 fix(i18n): polish Spanish locale copy (#7422) 2026-07-07 17:10:53 -07:00
Brennan BensonandOrca 482bfbc9bb Keep editor tabs in sync with external file changes instead of silently dropping them (#7591)
Co-authored-by: Orca <help@stably.ai>
2026-07-07 17:10:40 -07:00
Jinjing 9cc177b8ea Update mobile Android APK links to 0.0.24 (#7756) 2026-07-07 17:05:24 -07:00
c1d8086a04 fix(omp): migrate legacy overlay state (#7735)
* fix(omp): migrate legacy overlay state

* fix(omp): harden legacy overlay migration

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
Co-authored-by: Orca <help@stably.ai>
2026-07-07 16:55:08 -07:00
Jinwoo HongandOrca 79d0de9c33 fix(terminal): remote query-reply corruption (#7329) + snapshot grid-width repaint (#7279) (#7736)
Co-authored-by: Orca <help@stably.ai>
2026-07-07 16:42:43 -07:00
Jinwoo Hong c256a5a417 Windows terminal update-survival (single consolidated PR) (#7538) 2026-07-07 19:21:07 -04:00
Brennan BensonandOrca 46fe1b5799 Prepare mobile 0.0.25 (#7751)
Co-authored-by: Orca <help@stably.ai>
2026-07-07 16:05:18 -07:00
Brennan BensonandOrca d8df9c818f fix(terminal): allow terminals to spawn outside the worktree (#7685) (#7750)
Co-authored-by: Orca <help@stably.ai>
2026-07-07 15:34:29 -07:00
Brennan Benson c4db3ca51d Fix mobile "phone size" Restore buttons doing nothing (#7749) 2026-07-07 15:31:34 -07:00
github-actions[bot] 1b66de0426 release: v1.4.127-rc.5 v1.4.127-rc.5 2026-07-07 22:14:27 +00:00
Brennan BensonandOrca 46dcfd33ea Fix offline runtime worktree refresh call fanout (#7660)
Co-authored-by: Orca <help@stably.ai>
2026-07-07 14:53:56 -07:00
Brennan BensonandOrca 9e03e28d37 Stop unreachable-runtime request storms (negative cache, stable hook deps, subscribe backoff) (#7743)
Co-authored-by: Orca <help@stably.ai>
2026-07-07 14:50:44 -07:00
Brennan BensonandOrca d9225c5ccd fix(github): route all PR mutations through the repo's owner host (#7739)
Co-authored-by: Orca <help@stably.ai>
2026-07-07 14:43:31 -07:00
Jinwoo HongandOrca 5790793649 fix(agent-hooks): install Droid & Copilot managed hooks over SSH (#7253) (#7744)
Co-authored-by: Orca <help@stably.ai>
2026-07-07 14:21:23 -07:00
bea9b38544 Fix OMP worktree title identity flicker
* Fix OMP worktree title identity flicker

* Add headless fresh pairing server script

* Harden fresh pairing server script startup

* Default fresh pairing server to reachable address

* review: harden OMP tab identity validation

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
Co-authored-by: Orca <help@stably.ai>
2026-07-07 13:51:25 -07:00
Brennan BensonandOrca ee6405052a Keep terminals created from Orca Mobile alive when the desktop renderer is throttled or stalled (#7664)
Co-authored-by: Orca <help@stably.ai>
2026-07-07 13:17:13 -07:00
Brennan BensonandOrca 0fe20ddff9 Fix Monaco Peek References preview collapse (#7662)
Co-authored-by: Orca <help@stably.ai>
2026-07-07 12:55:41 -07:00
Brennan BensonandOrca fed545d330 Stop wiping the shared WebGL glyph atlas on plain window refocus (#7604)
Co-authored-by: Orca <help@stably.ai>
2026-07-07 12:43:53 -07:00
Jinjing 599f9f2138 Update WeChat community info in localized READMEs
- Remove the WeChat community section from the Portuguese translation.
- Add the main and backup WeChat QR codes to the Chinese translation.
2026-07-07 12:33:52 -07:00
Jinjing 0f7658d77c Make center split divider more visible (#7701)
* fix: address review findings

* Improve split divider contrast and refactor tab split context menus

- Increase contrast of `--tab-group-split-divider` colors in light and
  dark modes to achieve at least 3:1 contrast against `--card`.
- Refactor `TerminalTabSplitMenuSection` to use the shared
  `TabWorkspaceLayoutMenuSection` for moving tabs between splits.
- Clarify terminal-specific split action labels in the context menu.
- Remove redundant icon margins in `EditorFileTabContextMenu`.
2026-07-07 12:12:00 -07:00
github-actions[bot] 2dad1f04f3 Update README downloads badge 2026-07-07 18:57:48 +00:00
github-actions[bot] cf7fb4f7bb Update README downloads badge 2026-07-07 07:28:26 +00:00
Neil af59239c1a test(e2e): relax hidden PTY timer drift gate 2026-07-06 23:01:51 -07:00
github-actions[bot] eed0058168 release: v1.4.127-rc.0 v1.4.127-rc.0 2026-07-07 05:04:32 +00:00
JinjingandOrca 544bca5202 fix: terminal IME candidate selection and text commit on Linux (#7634)
* fix terminal IME candidate selection and text commit on Linux

Sogou Pinyin and fcitx on Linux failed in Orca's terminal because bare
229 keydowns were swallowed, and empty composition updates prematurely
deactivated tracking. This led to dropped Chinese text or leaked Space/digit
candidate-selection keys reaching the PTY.

- Allow bare 229 keydowns to bypass suppression on Linux so xterm can diff
  and commit text.
- Prevent empty compositionupdate events from prematurely deactivating
  the composition tracker.
- Suppress and preventDefault candidate-selection keys (Space and digits)
  during active composition and a brief post-composition window.
- Add comprehensive unit tests and an Electron CDP-driven E2E repro.

* fix: register IME gate command as direct spec-file invocation

The reliability-gate checker rejects --grep title selectors and requires
every evidenceRun command to match a gate command. Drop the --grep from
the e2e gate command and its evidence run, and remove the stale 3-file
evidence run superseded by the full 7-file run.

Co-authored-by: Orca <help@stably.ai>

* Guard overlapping and post-composition Linux IME candidate keys

- Track pending candidate key releases in a Map instead of a single
  slot to support overlapping selector key events without stranding.
- Apply the candidate selection guard to post-composition key releases
  that arrive after compositionend, preventing digits/Space from
  leaking into the PTY.
- Restrict the Linux/Sogou candidate selection guard to Linux to
  prevent interference on macOS and Windows.
- Exclude Shift+Space from candidate selection key checks.

* Guard held-key IME candidate repeats and scope policy to desktop Linux

- Keep auto-repeat keydowns for a candidate key suppressed past the
  250ms guard window until its corresponding keyup event is received.
- Clear stale pending releases on fresh non-repeat keydowns to avoid
  guarding the wrong key events.
- Exclude Android and ChromeOS user agents from desktop Linux-specific
  IME candidate key suppression behaviors.
- Ensure the composition tracker is activated unconditionally on
  compositionupdate events.

* Clean up IME reference and extract shared test event fixture

- Remove the obsolete Linux Sogou Pinyin IME reference document.
- Extract the fully-defaulted XtermBypassEvent helper into a shared
  fixture file to keep the policy test suites in sync.
- Add a test verifying that Shift+Space (fcitx full-/half-width toggle)
  is not suppressed as an IME candidate key.

---------

Co-authored-by: Orca <help@stably.ai>
2026-07-06 22:03:39 -07:00
Brennan BensonandOrca 46a67cb2eb perf(source-control): cache PR conflict-summary derivation and throttle base fetch (#7606)
Co-authored-by: Orca <help@stably.ai>
2026-07-06 22:02:59 -07:00
Jinwoo HongandOrca e33f31689b Make Codex session-history source home configurable (host + WSL) (#7629)
Co-authored-by: Orca <help@stably.ai>
2026-07-06 21:47:02 -07:00
Brennan BensonandOrca 82eeac6194 Keep GitHub PR status working when the rate-limit budget can't be read (GHES with rate limiting disabled) (#7632)
Co-authored-by: Orca <help@stably.ai>
2026-07-06 21:45:10 -07:00
Jinjing aa0993f546 Improve remote connection terminal error msg and session restore recovery (#7661)
* Robustify SSH terminal reconnect and session restore recovery

- Release the replay guard after a fallback timeout to prevent permanent
  keyboard input lockouts when an unmounted terminal never parses.
- Verify backing process liveness on PTY attach and reap stale entries
  so dead shells cleanly trigger a fresh pane spawn.
- Normalize connection IDs during restore to prevent spurious mismatch
  errors, and treat true mismatches as expired sessions instead of crashing.

* Route disconnected SSH terminal panes through deferred connection gate

Avoid spawning SSH terminal processes against disconnected targets,
which otherwise throws "No PTY provider" and leaves panes stranded.

- Intercept spawning via a new connect gate that triggers the deferred
  connection flow when the SSH target is disconnected.
- Fall back to composite worktree IDs during cold-start hydration to
  ensure deferred SSH session IDs are properly stashed.
- Retry spawning and remounting terminal panes upon SSH reconnect if
  they are stranded or failed to spawn.
2026-07-06 21:41:23 -07:00
Pablo AlbrechtandClaude Opus 4.8 1a4232fe96 fix(tabs): keep the worktree's remembered active tab on switch-back (#7385)
When returning to a worktree in the sidebar, the active tab reset to the
first tab instead of the one the user left on. Three fallback sites derived
the active tab from the first tab rather than the per-worktree remembered
selection (activeTabIdByWorktree):

- reconcileWorktreeTabModel: promoting legacy runtime terminals into a
  freshly-ensured group seeded activeTabId from restoredLegacyTabs[0].
- Terminal.tsx active-terminal repair: reset to tabs[0]; a repair firing on
  a transient worktree-switch render permanently clobbered the selection to
  Terminal 1.
- hydrateLegacyFormat: used the global session.activeTabId, so every
  worktree except the last-focused one lost its terminal on restart.

All three now honor activeTabIdByWorktree before falling back to the first
tab. Adds fails-old/passes-new regression tests.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-06 21:40:40 -07:00
Neil 6a4e6ce28a perf(ssh): bound the system-ssh port-forward stderr tail (#7647)
The stderr handler in system-ssh-port-forward-provider.ts stays attached
for the forward process's entire lifetime and appends every chunk to an
unbounded string, only ever read to build the exit-error detail. A
chatty/warning-spamming remote sshd over a long-lived `ssh -N -L`
forward could grow it without bound.

Fix: keep only the most-recent 64 KB tail, mirroring
MAX_RELAY_STARTUP_BUFFER_BYTES in ssh-relay-deploy-helpers.ts. The tail
is what the error message surfaces anyway.

Test (red->green): emitting >64 KB of stderr then exiting keeps the
recent tail marker and drops the oldest, detail bounded below the
produced size; without the cap the whole string is retained.
2026-07-06 21:28:15 -07:00
Neil 54c4959830 perf(mobile): cap the scheduled-notification map + tap-dedup set (#7646)
scheduledNotificationsByHostAndNotificationId (mobile-notifications.ts)
retained one entry per scheduled desktop notification. The key embeds
notificationId, which carries a per-completion timestamp
(buildAgentNotificationId), so every agent-task-complete inserts a new,
never-reused key. Entries are removed only when the desktop sends a
matching dismiss — which a remote mobile user (not sitting at the
desktop) frequently never receives — so the module-level map grew for
the app's whole lifetime. Small per entry, but genuinely unbounded.

Fix: bound the map to the 256 most-recent SETTLED entries (never evict
one mid-schedule). A settled entry only retains a small identifier used
for later programmatic dismissal, which is unnecessary for long-past
completions, so eviction has no user-visible effect.

Also FIFO-cap RootLayout's handledNotificationIdsRef tap-dedup Set
(RootLayout never unmounts, so it otherwise grew one id per tapped
notification forever).

Test (red->green): with the cap at 1, scheduling a second notification
evicts the first, so a later dismiss for the evicted id is a no-op while
the retained one still dismisses; without the cap the old entry survives.
2026-07-06 21:28:09 -07:00
Neil d0403d808e perf(renderer): FIFO-cap recentlyClosedAgentStatusTabIds (#7645)
recentlyClosedAgentStatusTabIds (agent-status store) suppresses late
hook/status events for a just-closed terminal tab. It was only ever
added to — one `true` entry per agent-tab close, keyed by the ephemeral
tabId, never deleted or capped — so it grew for the renderer's whole
session. It's the renderer twin of the main-process
closedAgentStatusTabIds set that #7561 already FIFO-capped.

Fix: bound it to the 1024 most-recent closed tabs via delete-then-set
LRU with oldest-key eviction (Record key order is insertion order),
mirroring #7561. A status event for a tab closed >1024 tabs ago cannot
still arrive, so suppression behavior is unchanged.

Test (red->green): closing 1029 tabs leaves exactly 1024 markers with
the oldest evicted and the most-recent retained; without the cap all
1029 persist.
2026-07-06 21:28:03 -07:00
Neil 8936225889 perf(native-chat): LRU-bound the pending-send and command-marker scope caches (#7643)
Two module-level caches in native-chat-pending.ts capped their per-key
arrays (8 entries) but never bounded the KEY count:

- commandMarkerCache — keyed by paneKey\0agent\0sessionId; sessionId
  changes on every /clear and paneKey embeds an ephemeral leafId, so a
  distinct key was stranded per (pane, session) for the renderer's whole
  life. Only test-only clear() ever removed keys.
- pendingSendCache — self-cleans on the normal empty-drain path, but a
  pane closed with an unconfirmed send (agent crash / early close) left
  its non-empty entry keyed forever.

Route both writes through the existing setBoundedScopeCacheEntry LRU
helper (cap 128) that #7566 already applied to the draft/attachment
caches in the same folder — same pattern, same file family, was just
missed here. Values are tiny so this is a slow leak, but real and
unbounded.

Tests (red->green): appending 133 distinct scopes evicts the oldest and
keeps the most-recent 128; without the cap all 133 survive.
2026-07-06 21:27:57 -07:00
Jinjing 7842a48090 Pin PR comments list header when scrolling checks panel (#7657)
Keep the filter and add-comment actions reachable while reading long
threads in the sidebar. Also add a test to verify the sticky classes
are applied.
2026-07-06 21:22:08 -07:00