Commit Graph
55 Commits
Author SHA1 Message Date
Neil f7b1f9d8be fix(opencode): select tmux status on the execution host
Track the attested tmux selected pane in the canonical status store and fence retired refreshes after asynchronous root resolution.

Fixes #10039.
2026-10-02 20:41:24 -07:00
NeilandAhmed Nagy fee8143d61 fix(opencode): atomically install status plugin entrypoints
Retain complete status plugin files during replacement, symlinks and existing permissions, including legacy Windows directory permission recovery.

Fixes #24121. Continues #24131; permission-recovery review credited to pullfrog.

Co-authored-by: Ahmed Nagy <ahmednagy25t@gmail.com>
2026-10-02 20:41:21 -07:00
Jinwoo Hong b06f40f3ba fix(opencode): read the binder's session store off the main thread; ship the reader worker in orcad (#24638)
* fix(opencode): read the binder's session store on the foreign SQLite reader worker (STA-9122)

Before: the OpenCode session binder listed new sessions from opencode.db with
node:sqlite on the main thread every 60 s (and on SessionStart kicks), so a
large or contended store could stall the app the same way Cursor's did.

After: the read is a pure openCodeBinderSessions reader in
foreign-sqlite-readers/readers/, run only on the worker. The binder's
correlation, pane snapshot and process sweep stay where they were.

- The binder round awaits listSessions and re-checks its generation right
  after, so a stop() during the read discards the round before it touches the
  unbound map or the watermark.
- The client's in-flight dedupe key now includes the cursor, so a stale round
  from before a restart cannot hand its rows to the restarted round.
- Idle teardown is per reader. The binder lane keeps its thread for 120 s,
  longer than its 60 s poll, so the thread is not respawned every round.
- A timeout, crash, malformed reply or unstartable worker resolves to [] (no
  sessions), the value the old read already returned on failure.
- An absent store still reads as [] without a log line, and a permission or
  corrupt-file failure still logs (kept from #24577, now in the reader: it
  stats the path and throws anything but ENOENT/ENOTDIR to the client's log).
- The binder lane inherits #24572's limits from the shared lane: no respawn
  until a timed-out worker has exited, 2 consecutive deaths, a queue cap of
  8. Its timeout stays 60 s, matching its poll.
- dispatch switches on the destructured kind, so a new kind without a case
  still fails to compile.

orcad: the hook server runs there too, so orcad now ships
foreign-sqlite-reader-entry.js beside orcad.js (ORCAD_ARTIFACTS, built as an
orcad child). build-orcad runs a smoke check that starts the built worker
under the build's Node and under the pinned runtime, and does a real binder
read on a fixture DB, a Cursor read of a missing file and an OpenCode history
list. The OpenCode history scanner uses the same entry and was bundled into
orcad without it, so on orcad it always failed closed; it can now run.

Tests: reader (cursor, same-ms ids, OpenCode 2 rows, missing then created,
corrupt, inaccessible directory), retirement gate for the binder lane, dispatch
routing, client lane (rows, failure -> [], dedupe per cursor, own thread, idle
teardown default and override), binder loop with an async listSessions
(failure -> [], stop during the read), orcad path resolution through orcad's
host adapters, artifact list, and the smoke check against good, missing and
non-reading entries.

* test(opencode): cover the binder read deadline with fake timers and name the failure test accurately (STA-9122)
2026-10-02 19:58:29 -04:00
Neil 8765f8c9b1 fix(opencode): preserve turn outcomes and avoid auto permission attention (#24612)
* fix(opencode): retain failed and stopped TUI turn outcomes

Adapt the root verdict proposal from brennanb2025 in PR #23105 to the current TUI-owned lifecycle, keeping hook-store authority and existing mainAgent semantics.

* fix(opencode): let auto-approved permissions settle before attention

* fix(opencode): reconcile cached outcomes with completed session turns

* fix(opencode): bind terminal verdicts to ending event timestamps

* fix(opencode): publish approval cards for permission requests
2026-10-02 05:02:03 -07:00
Neilanddrakeo338 cb03a0545a fix(opencode): keep absent session stores quiet (#24577)
* fix(opencode): skip absent session stores without warning

* fix(opencode): retain warnings for inaccessible session stores

---------

Co-authored-by: drakeo338 <paranoyouz@gmail.com>
2026-10-02 04:56:12 -07:00
Brennan Benson 3727100cc9 fix(opencode): report OpenCode 2 status from each pane's own TUI (#23722)
* fix(opencode): report OpenCode 2 status from each pane's TUI

OpenCode 2 serves every pane from one shared server whose env names only
the pane that started it, so every same-folder pane's work showed on that
pane, and the plugin's single aggregate swallowed the Idle of a pane whose
turn ended while another pane was busy.

Install the status plugin a second time as an OpenCode 2 TUI plugin
(plugins/<name>-tui/tui.js, written only when its bytes differ, locally,
in overlays and in the SSH/WSL relay installs). In a TUI process setup()
runs the same engine, fed through the same event translation as the
server, but only for root sessions this pane owns: the route's session
from when it starts (or when the route reaches it while running, hydrated
from the TUI's session status) until it settles, is deleted, or the TUI
exits. The server plugin stands down in any serve process when the TUI
copy is installed beside it; a relay that predates the TUI copy keeps the
old behavior. OpenCode 1 loads no plugin directories and is unchanged.

Delete the session-to-pane binder, registry, client sweep and ingest
reattribution: with every post stamped by its own pane nothing is left
for them to correct.

Known gap: OpenCode 2 `opencode run` in a pane has no TUI, so it reports
no pane status.

* fix(opencode): settle missed OpenCode 2 turn ends and order TUI installs

- The TUI copy now settles an owned root whose run the TUI's session data
  reports ended, with no pending permission or form, when the engine still
  holds it busy. An execution end missed across a service restart or
  reconnect no longer leaves the pane Working until the TUI exits.
- The TUI copy stays idle without ORCA_PANE_KEY. post() cannot report without
  it, so OpenCode 2 TUIs outside Orca no longer run the route poll and engine.
- Installers write the TUI copy before the server plugin file. The server
  decides at load whether to stand down, so a reload between the two writes
  now finds the TUI copy.

* fix(opencode): reconcile OpenCode 2 TUI status only once queued events drain

The TUI's session data applies each event before this plugin's queued handling
reaches it, so settling against it mid-backlog published a false Done before a
fast turn's later steps (Working, Done, Working, Done). Reconcile only when no
event is queued; a mismatch then is a start or end missed across a reconnect,
and both directions are now re-derived (a missed start left the pane on Done).

Also install the TUI copy beside the server plugin in the retired shared hooks
dir, so a TUI or service still loading that dir reports per pane instead of
leaving the service reporting under its starter pane.

* fix(opencode): keep OpenCode 2 TUI panes silent on plugin dispose

A TUI plugin hot reload disposes the plugin while the pane's turn keeps
running. The server path already passes sessionsOutliveDispose so dispose
publishes nothing; the TUI adapter now does the same, or every TUI reload
would still show a false Done. Also refreshes the generated-bytes digest
after rebasing onto the write-if-changed installers.

* fix(opencode): refresh installed OpenCode status plugins at app start

After an Orca upgrade, an OpenCode 2 service that was already running kept
the previous plugin, and with it the old wrong-pane status, until any new
terminal pane rewrote the file. OpenCode 2 reloads a plugin whose file
changes, so Orca now refreshes its existing installs once after the first
window shows: the global config dir, source overlays and the retired shared
dir, TUI copy first. It reuses the per-pane writers, which skip unchanged
files, never creates an install the user did not have, and honours the
status-hook and per-agent switches. An SSH relay does the same for its
canonical install when Orca connects and ships the plugin sources.

The plugin source assembly moves to its own module (re-exported unchanged)
to keep hook-service.ts under the line limit.

* fix(opencode): derive each OpenCode 2 pane's status from its TUI session data

The TUI copy of the status plugin translated OpenCode events into the
server-side engine and then patched the engine's latches back toward the
TUI's own session data: a settle on every tick, a queued-event counter, a
re-assert, synthetic Busy and Idle. Each review found another place where
the two copies disagreed: a missed end left the pane Working, a backlog of
slow posts flickered Done, a missed start showed Done mid-turn, a turn held
only by a subagent never settled, and a request answered while disconnected
pinned Needs input.

The TUI reporter now reads the pane's level straight from the session data
OpenCode keeps current (and re-hydrates on reconnect) on every event and on
a 100 ms tick: for each root session this pane owns, Needs input (an open
permission, else form, anywhere in its family while it runs) outranks
Working (any family member running) outranks Done. It posts one status per
level change through the plugin's existing delivery functions (retry,
dedupe, message-part throttle, ordering), so the wire and Orca's ingest are
unchanged. Ownership is kept in OpenCode's storage.memory, which survives a
plugin hot reload, so a turn that ends during a reload still shows Done;
dispose publishes nothing, and a level the old generation could not deliver
is re-posted by the next. On reconnect it re-syncs blockers for the owned
sessions OpenCode would not re-sync itself, ignoring requests already
answered. Events are handled synchronously, so a slow post can no longer
hold up event processing. The server path, OpenCode 1 and mimo are
unchanged.

* fix(opencode): keep an OpenCode 2 pane on Needs input while its root streams text

Orca treats every OpenCode MessagePart as Working. While a background
subagent waits on a permission or form, the root session can keep streaming
reply text, and the TUI reporter forwarded that text as a MessagePart. The
pane then flipped from Needs input to Working, and nothing restored it until
the level changed, so the user could miss the open request.

Skip reply text while the pane's level is Needs input, as the reporter
already does for queued prompts.

* fix(opencode): leave OpenCode 2 step events to the server path's own change

The shared-server translation re-derived Working from session.step.started.
The pane reporter no longer uses it, so it only changed the server path and
duplicated a separate open change. Drop it; server behaviour matches main.

* fix(opencode): reset an OpenCode 2 pane to idle when its TUI starts

Before this change, a pane could keep a status an earlier process left on
it. The case that matters is an upgrade mid-turn: the old shared-service
plugin posted pane B's turn under pane A's key, then stood down, and pane
A's TUI loaded the new reporter owning nothing, so it never posted and A
showed a wrong Working until its own next turn.

A freshly started reporter that owns no running turn now posts the host's
existing session-start boundary once, which the host shows as connected
idle: no completion, no notification, and an unseen Done it lands on stays
unread. A plugin hot reload keeps its memory and skips it, and where
OpenCode keeps no plugin memory it is never sent.

* fix(opencode): keep OpenCode 1 serve + attach sessions on the attaching pane

OpenCode 1 `opencode serve` in one pane plus `opencode attach` in others
reports every session from the serve process, whose environment names only
the serve pane. Before this branch the session-to-pane binder moved those
posts to the attaching pane; deleting it for OpenCode 2 put them back on the
serve pane.

Restore the binder, registry, correlation and client sweep for OpenCode 1
(and mimo-code, which it also served), gated so OpenCode 2 never uses it:

- The status plugin now sends `opencodeMajor: 2` on every post from a process
  whose loader called setup(), which only OpenCode 2 does. The host skips the
  binder (no rewrite, no kicked round) for any post that carries it. OpenCode 1
  and older plugins send nothing and keep the previous behaviour.
- The binder reads only OpenCode 1's `session` table. OpenCode 2 writes
  `session_v2`, so its sessions never bind; on a database both versions wrote,
  OpenCode 1 sessions are no longer hidden behind the v2 table.

OpenCode-1-only; it goes when OpenCode 1 support is removed.

* fix(opencode): show OpenCode 2 `opencode run` as Working, then Done, on its own pane

OpenCode 2's `opencode run` loads no plugin, and the shared service that
runs its session cannot tell which pane it belongs to, so a pane running it
showed nothing.

The runtime now reports it from the pane's own process lifetime. On the
pane's OSC 133 command start (main already parses 133 for every local PTY;
the start callback was never wired), after the pane tracker's 350 ms settle
it reads the foreground process name through the existing foreground
reader, and only when that name is OpenCode, the foreground command line
from one fresh shell-foreground process-table capture. An `opencode run`
posts Working through the existing terminal-status path into the hook
server's store; the pane's 133;D (or the daemon's background fact) posts
Done, marked interrupted on Ctrl-C. No polling.

Exclusive with plugin reporting: each write carries the command's start
time, and the store drops it once a hook has written the pane since then,
so an OpenCode 1 `run` (in-process plugin) or a server plugin without the
TUI copy owns its command alone and there is never a second Done.

Local macOS and Linux panes only; SSH, WSL and Windows panes stay silent
because their foreground cannot be read on this host.

* fixup! fix(opencode): show OpenCode 2 `opencode run` as Working, then Done, on its own pane

Type the selected descendants as process-table rows; ReturnType of the generic collector widened them to bare identity rows.

* fix(opencode): keep an `opencode run` pane's Done after the command exits

The run's Done was published inside the chunk that carried its OSC 133;D,
before the chunk's command-finished fact. The renderer drops an exited
agent's row on command-finished when the row has not changed since that
fact arrived, so it took the Done as the stale row and dropped it, in the
renderer and in main.

Publish the run's Done after the chunk's side-effect facts are emitted (and
after the daemon's background fact). The renderer then sees command-finished
while the row is still Working, and the Done that follows counts as a change,
so it stays, the same way a hook Done that lands after exit already does.

* fix(opencode): let an `opencode run` revive a pane Orca retired

When an agent Orca launched exits, command completion retires the pane, and
only a hook new-turn event revived it. A later `opencode run` in that pane
posts no hook, so its process-lifetime Working was refused and the pane
stayed silent.

A process-lifetime Working is posted only after a fresh OSC 133;C and the
pane's own foreground argv prove a new OpenCode run, which is at least as
strong as a hook new turn. The store now revives the retired pane on it the
same way: it clears the retirement, drops the launch-token fence, and rebinds
the observation. OSC status and a lone process Done still cannot write a
retired pane, and a closed tab stays closed.

* fix(opencode): report `opencode run` on local Windows panes too

The run producer skipped every Windows pane, although Orca already resolves
a Windows pane's foreground agent from the native process table. On main an
OpenCode 2 `run` showed there (on the service's pane); on this branch it was
silent.

The argv read now has a Windows branch: one fresh native table read
(windows-process-table, no interpreter spawn), the same foreground identity
the Windows resolver already computes, and the command line of the process
that identity names. It runs only after the name read says OpenCode. Local
Windows panes whose shell prints OSC 133 C/D (PowerShell with PSReadLine,
Git Bash with Orca's wrapper) now go Working, then Done; cmd.exe prints no
markers and stays silent. SSH and WSL panes stay silent.

* fix(opencode): re-read an `opencode run` foreground on the pane tracker's ladder

The producer read the pane's foreground once, 350 ms after the command
started. A wrapper, a shim or `sleep 1; opencode run` execs OpenCode later,
so those runs stayed silent. The renderer's pane tracker already re-reads a
command's foreground at 350, then 1200, then 6000 ms for exactly this.

Move those delays to one shared module and use it from both. The producer
re-reads only while the foreground is a non-shell process that is not
OpenCode, and at most on those three rungs; no new polling.

* fix(opencode): end an armed `opencode run` when the next command starts

A new OSC 133;C in a pane whose `opencode run` was still armed dropped the
armed state without a Done, so a run whose 133;D never arrived left the pane
on Working. A new command start proves the previous command ended, so it now
posts that run's Done (not marked interrupted: no exit code is known) before
the new command is inspected.

* fix(opencode): skip the session-start row inside an OpenCode 1 `run` process

OpenCode 1 `run` loads the status plugin in its own process, and the plugin
posts SessionStart when the run's session is created. The host lands that as
an idle session boundary, so a pane the run producer had already shown as
Working blinked idle before the plugin's Busy.

The plugin now skips SessionStart when its own process is a `run`, read from
its argv the same way isOpenCodeRunCommand reads a pane's foreground (first
positional after global options, past the compiled binary's entry path). A
`run` session goes Busy at once, and its first prompt part still revives a
retired pane and resets the turn caches. The TUI and `serve` still post it,
and OpenCode 2's `run` loads no plugin.

* chore(opencode): say where the plugin's opencodeMajor comes from

The field is set when OpenCode's loader calls setup(), which only OpenCode 2
does; the plugin never reads OpenCode's version. Say so at the field. Comment
only; the generated plugin is unchanged.

* test(opencode): type the late-Done pane fixture without bare casts

The new renderer test passed its fixtures with `as never`; use the checked
fixture-tuple cast with a SAFETY note, like the sibling pty-connection tests.

* fix(opencode): keep `opencode run` silent when OpenCode status is turned off

The run producer ignored the status-hooks switch, so a user who turned
status off globally or for OpenCode (#23667) still got a run's Working and
Done. It now checks isAgentStatusHooksEnabledForAgent for the run's agent
(opencode or opencode2), the same predicate the plugin install honours,
before reading argv or posting anything.

* test(opencode): read the late-Done row without an untyped property access

The mock store types agentStatusByPaneKey values as unknown, so reading
`.state` failed tc:web. Assert the row with toMatchObject instead.

* perf(opencode): read a command's foreground only while it could become `opencode run`

Two costs the run producer paid on every command in every local pane:

- The retry ladder re-read the foreground (a process-table capture on the
  local provider) for any non-shell program still running, including other
  agents, editors and dev servers, up to three times. It now re-reads only
  while the foreground is still the shell (the command has not exec'd yet)
  or an unrecognised launcher that may still exec OpenCode (node, bun, bunx,
  npx, npm, pnpm, pnpx, yarn). Any other program is read once.
- With OpenCode status turned off for both opencode and opencode2, it still
  set the timer and read the foreground only to discard the result. It now
  returns before any timer or read. The per-agent check after the name read
  stays for the case where only one of them is off.

* fix(opencode): let a new hook turn end a pane's process-exit completion

A confirmed agent process exit records a pane-wide completion identity that
names only the agent. Hook Dones are matched against it by agent alone, and
only a working title cleared it, so in a pane whose agent paints no working
title (OpenCode) every later hook-reported Done was treated as already
notified: no notification and no unread mark. An unreported exit (a status-off
`opencode run`, or quitting an idle client) was enough to set it.

A fresh hook Working now clears a process-exit identity, since a new turn
cannot be a duplicate of an earlier exit. Hook identities stay, so
same-turn and replay dedupe is unchanged.

* refactor(opencode): share the foreground read schedule as one value

The pane tracker's import of the two shared foreground-read delays took
four lines where its old local constants took three, which put the file
one line over max-lines once merged with main. Export the settle delay
and retry ladder as one object so each consumer imports a single name.
No behaviour change: same 350 ms settle and 1200/6000 ms retries.
2026-09-30 15:37:18 -07:00
Neil 6194a7a1b6 test: drop private-internal and boundary-census tests with behavioral owners (#23941)
Fourth audit wave, cut short by a session restart, so this lands the verified
subset rather than the full batch.

Removes private-predicate cases whose behavior is already covered through the
module's real entry point, and de-exports the seams they reached for. Also drops
three whole files whose every case was a duplicate or a call-shape grep.

The source-grep vein is close to exhausted. One auditor reviewed 15 remaining
flagged files and deleted nothing: what is left is mostly legitimate
architectural ratchets that no type checker and no behavioral test can reach —
AST fences banning `as`/`any` in an RPC operation region, discovered-vs-listed
set equality over subscription sites, count ceilings on unchecked reply readers,
and assertions on generated WebView bundles (no CDN URL, no `</script`
tokenizer escape, parses at the Chrome 74 floor). Those stay.
2026-09-29 16:35:49 -07:00
Neil 31012aeb09 test: remove assertion-free probes, copied inventories and export-shape checks (#23816)
Second audit wave, targeting three more junk patterns:

- assertion-free cases that run code and assert nothing, so they pass no
  matter what the code does;
- inventory literals re-typed from a production declaration, where the only
  way the assertion can fail is someone editing one of the two copies;
- export key-set and export-shape loops (`typeof x === 'function'` over every
  export) that restate what TypeScript already enforces.

Yield is much smaller than wave 1 on purpose: the assertion-free scanner has
a high false-positive rate, because many flagged blocks assert through a
shared helper or their oracle is "this must not throw". Those were kept.

`mobileWebCheckArgs` in `config/scripts/run-mobile-web-app-checks.mjs` is
de-exported — after the inventory comparison went away, nothing outside the
module read it.
2026-09-29 02:21:47 -07:00
Brennan Benson 2ae7c00e84 fix(opencode): keep OpenCode 2 panes Working across plugin reloads (#23700)
* fix(opencode): keep OpenCode 2 panes Working across plugin reloads

OpenCode 2 disposes and re-sets-up every plugin whenever its plugins dir
changes, while sessions keep running. The status plugin published a final
Idle on dispose, so a pane read Done mid-turn. Orca also rewrote the plugin
file on every PTY spawn, so opening any terminal triggered that reload.

Dispose now releases the factory's bookkeeping without publishing a
verdict; the next lifecycle event settles the pane, and Orca's ended-process
reconciliation still retires panes whose agent exited. The plugin file is
written only when its bytes differ.

* fix(opencode): skip rewriting an unchanged plugin in the SSH relay install too

The relay's canonical-config install still unlinked and rewrote the status plugin on every OpenCode launch over SSH, which restarts every plugin in a remote OpenCode 2 server. Share one install-currency check (lstat + the existing byte comparison) between the local and relay writers, and pin write-if-changed with mtime so the tests also fail on filesystems that reuse a freed inode.

* fix(opencode): keep the final Idle when OpenCode 1 tears its instance down

OpenCode 1 disposes a plugin only when it tears the instance down, and that
teardown cancels every running session, so the Idle published on dispose is
true there; the cancelled run's own idle may never reach the plugin. Only
OpenCode 2 disposes on a hot reload while turns keep running. The generated
module serves both hosts, so the OpenCode 2 setup() entry point now tells the
shared factory that sessions outlive disposal; the server() path keeps the
previous disposal behaviour, including the hand-off to a surviving factory.

* fix(opencode): compare a symlinked plugin by its target before rewriting

OpenCode 2 loads plugins through file-level symlinks and reads the revision
from the target's mtime, so a user whose Orca plugin file is a symlink (per-file
dotfile managers) failed the regular-file check and got a write through the
link, and a reload, on every spawn. The config-dir and relay installs now skip
the write when the resolved target already has Orca's bytes; when stale they
behave as before. Only the per-source overlay keeps the regular-file check,
since a link there mirrors a user entry. Installers also skip the write inside
a guarded block rather than returning early, so later install steps still run.

* test(opencode): skip the plugin symlink tests on Windows like their neighbours

Creating a file symlink on Windows needs Developer Mode or admin rights.

* test(opencode): stub fetch without a type assertion in the dispose host test
2026-09-28 21:09:13 -07:00
OrcaWinandm4air 813aff8f8a fix(opencode): stop OpenCode 2 loading a stale plugin from the retired shared hooks dir (#23500)
* fix(opencode): stop OpenCode 2 loading a stale plugin from the retired shared hooks dir

Before 1.4.209 Orca pointed OPENCODE_CONFIG_DIR at <userData>/opencode-hooks/shared
and wrote a server()-only status plugin there. 1.4.209 moved the plugin to OpenCode's
global config dir and 1.4.210 added the v2 setup() export, but nothing rewrote the
old file. Shells, daemon-persisted panes and OpenCode 2 background services that
still carry that OPENCODE_CONFIG_DIR load only that dir under OpenCode 2 (it replaces
the global dir), so the v2 loader rejects the stale plugin with "Plugin must export a
default definition with an id and an effect or setup function" and pane status dies.

- Refresh the plugin in the retired shared dir (only when it already exists and its
  content differs) so OpenCode processes started later from old shells load the dual
  v1/v2 export. Runs on OpenCode pane spawns and on any spawn that inherits the
  retired dir, even with agent status hooks off.
- Drop an inherited OPENCODE_CONFIG_DIR / ORCA_OPENCODE_* marker that points at the
  retired dir when building a new pane env, so new panes use global discovery.

Limitation: an OpenCode 2 background service already running from an old pane keeps
its cached copy of the stale module even after the file is rewritten (verified with
opencode2 v2.0.18). It must be restarted (`opencode service restart`); a restart from
a new Orca pane then picks up the global config because the env is stripped.

* fix(opencode): harden legacy plugin repair and inherited config cleanup

* fix(opencode): preserve daemon-owned user config during legacy cleanup

* fix(opencode): sanitize inherited sources and repair unseen legacy copies

* test(opencode): update shared PTY mocks for legacy repair

* test(opencode): annotate shared repair mock signature

---------

Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
2026-09-28 14:55:42 -07:00
ee6281ff79 fix: dispose OpenCode 2 hooks after prompt setup and cleanup failures (#23209)
* fix: dispose OpenCode 2 hooks after prompt setup and cleanup failures

* test: pin reviewed OpenCode setup cleanup bytes

* fix(i18n): restore diff note draft catalog entries

* test: isolate historical hourly build version inputs

* test: align historical package input with shared CI repair

* test: inject hourly package version without module mocking

* test: share the hourly package input contract across CI repairs

* test(windows): verify NSIS policy with native PowerShell modules

---------

Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
Co-authored-by: OrcaWin <alpha-eng@stably.ai>
2026-09-26 15:30:41 -07:00
Neil 8ddad49ae5 fix(opencode): retire a subagent's blocker when the root turn ends (#22604)
A descendant's question is stored under its own sourceSessionID but displayed on
the root session it rolls up to. clearAttentionForSession matches only the
source, so the root's own idle could never retire it: the blocker outlived the
turn that raised it and pinned the pane on "needs input" with nothing left to
answer. The lead agent truthfully reports no pending question, because the
blocker belongs to a child it does not know about (#22371).

Add clearAttentionForTurnEnd, matching the source id or the rolled-up root, and
use it only from the idle branch. Scoped to turn end deliberately: a live
blocker must still outrank the root going Busy, since a subagent can be waiting
on the user while the root keeps working — widening the existing clear broke
exactly that test, which is what surfaced the right scope.

Shared with the OpenCode family, so mimo-code gets the same fix; both pinned
plugin digests move.

New test fails without the change: after the root turn ends the last post is
still AskUserQuestion instead of SessionIdle.
2026-09-23 23:45:50 -07:00
Neil 57bf732a42 test(opencode): cover the opencode2 host-env branch and stop inheriting ORCA_OPENCODE_AGENT (#22547)
* test(opencode): pin per-major OpenCode overlay selection on WSL and the relay

OpenCode 2 dies with "Duplicate plugin ID" when two plugin files share an id,
so which overlay a guest or remote pane is pointed at decides whether the agent
starts. Nothing failed if that selection regressed:

- the WSL spawn path never asserted which major it asks the guest relay for,
  and the shared pty-ipc mock had no openCode2HookService at all, so no test
  could reach the opencode2 branch of buildPtyHostEnv;
- requestGuestOpenCodeOverlayDir had no coverage for the v2 guest dir;
- PluginOverlayManager had no case for a remote config root that still holds
  the other major's stale Orca plugin.

Tests only; no behavior change. Each new case was mutation-checked against the
production line it guards.

* test(opencode): stop the plugin contract test inheriting ORCA_OPENCODE_AGENT

The generated plugin self-disables when ORCA_OPENCODE_AGENT names a different
major, and the contract test saved and restored that variable without ever
setting it. Run from a shell that has it — which is any shell inside an Orca
OpenCode pane, i.e. how this repo is usually developed — the plugin returned an
empty hook set and the contract failed for the wrong reason.

Delete it in beforeEach, the way the opencode2 setup test already pins it.
Verified the file passes with the variable set to either major and unset;
before this it failed for two of the three.
2026-09-23 20:08:34 -07:00
Neil b0ae7d18a0 fix(opencode2): resolve subagent session lineage so child work stops taking over the pane (#22444)
OpenCode 2's plugin adapter unwraps a single-property `{ data }` success schema,
so `ctx.session.get` resolves to the bare session record. The shared lineage
lookup only accepts `result?.data?.id === sessionID`, and OpenCode 2 has no
`session.list` fallback, so `resolveRootSessionID` returned null for every
session and `childState` was permanently null.

With unknown lineage `canFailOpen` is true for attention events, so a subagent's
`permission.asked`/`question.asked` fell through and pinned an un-evictable
blocker keyed to the child's own session id — publishing a subagent as if it
were a root. Observed in hook posts: SessionBusy for a child session id whose
`session_v2` row carries a parent.

Envelope the result in the OC2 client shim so the shared lineage module works
unchanged; OpenCode 1 already receives enveloped results and is untouched.

Also adds `opencode2` to the double-Escape interrupt list, extracted into one
shared helper so the server inference and renderer gate cannot drift. A single
Escape was inferring an interrupt, and Escape is how the Subagents dock closes.

7 of 11 new lineage tests fail without the shim.
2026-09-23 20:08:01 -07:00
Neil 8352752e54 fix(opencode): give the opencode2 status plugin a distinct id (#22544)
* fix(opencode): fail-open plugin setup and distinct opencode2 plugin id

setup() threw when OpenCode 2 probed it without a full context, which the
TUI reported as an 'orca-opencode-status' plugin failure. Both plugin files
also shared one id while living in the same config dir.

* fix(opencode): drop unused oxlint-disable in setup fail-open test

* test(opencode): pin distinct plugin ids for the shared global config dir

Orca installs both family plugins into one global plugins dir, so a shared
plugin id makes OpenCode 2 fail the later one with 'Duplicate plugin ID'.
2026-09-23 17:51:00 -07:00
Neil f1eb1913a6 fix(opencode2): block the pane on every session-owned form (#22548)
#22399 admitted an OpenCode 2 form.created as a pane blocker only when
metadata.kind === "question". On v2.0.15 that is an allow-list on a field
with no contract: packages/schema/src/form.ts declares Metadata as an open
Schema.Record and metadata itself as optional, and the public
POST /api/session/:sessionID/form endpoint lets any client raise a real
blocking form on a real session with no metadata. Orca dropped those, so
the pane painted no blocker while OpenCode waited forever.

Invert the default. Every form whose owner is a real session blocks;
only a form owned by the "global" MCP-elicitation sentinel is dropped,
because that owner is not a session and never goes idle, so its blocker
could not be retired. That also restores websearch.provider as a blocker:
it carries the real context.sessionID, session idle retires it, and while
it is pending the agent is genuinely stalled on the user.

Resolution is unchanged: clearAttentionForResolution keys on the exact
form id plus source session, so a resolution for a dropped form matches
nothing and cannot retire a live blocker.
2026-09-23 13:52:41 -07:00
Neil 0afc66ebd3 fix(opencode2): only treat the question tool's form as a pane blocker (#22399)
* fix(opencode2): only treat the question tool's form as a pane blocker

OpenCode 2 has one form primitive and several producers, and Orca's setup
bridge mapped every `form.created` to `question.asked` — the un-evictable
"the pane owner must answer this" blocker. Against opencode v2.0.12 only
`metadata.kind === "question"` is the agent's question tool; `websearch.provider`
is a provider picker and `mcp-elicitation` is an MCP server prompt raised on
sessionID "global", which is not a session and so can never be retired by that
session going idle.

Admit only the question kind, remember the admitted form ids, and drop
`form.replied`/`form.cancelled` for forms that were never admitted so an
ignored form's resolution cannot retire a live blocker.

Evidence (live v2.0.12 capture, real TUI in a PTY against `opencode serve`)
in docs/bug-reproductions/opencode2-form-created-kinds. That capture also
shows the reported Subagents/Shell/Terminals dock and the agent picker emit
no server event at all, so they were never the `form.created` source.

Refs #22371

* refactor(opencode2): drop the unreachable form-resolution guard

Review was right that the admitted-form-id set defended against nothing.
`clearAttentionForResolution` builds the exact key
[factoryID, "AskUserQuestion", form.id, sourceSessionID] and returns null on a
miss, with no session-wide fallback, and form ids are unique — so a resolution
for a form Orca ignored already matches no live blocker. The guard's comment
claimed a collision the key structure rules out, which is worse than no comment.

Removes the set, its FIFO eviction helper, and the claim; the kind check on
form.created is the whole fix. The end-to-end test stays: it pins the behavior
that an MCP form raised and cancelled leaves a live question blocker standing,
which is the property worth holding regardless of how it is achieved.
2026-09-22 22:08:01 -07:00
Neil 1dcbd4e65d test(opencode): pin the installed OpenCode plugin to a v2-loadable default export (#22389)
OpenCode 2 installs under the plain `opencode` executable name and its plugin
loader requires the default export to carry `setup` (or `effect`) alongside an
`id`; the v1 loader requires `server`. The emitted plugin source already carries
both, but nothing asserted it on the file Orca actually installs into OpenCode's
config directory — the exact surface that regressed in #22234.

Load the installed file as an ES module and assert its default export satisfies
both loaders. Reverting getOpenCodePluginSource() to the v1-only options makes
this test fail with "expected undefined to be type of 'function'".
2026-09-22 21:27:46 -07:00
Neil 1a3f4e88c0 fix(opencode): support v2 plugins under plain executable name
Supports OpenCode 2 installed as opencode, including plugin loading and quick-command submission.
2026-09-21 14:29:04 -07:00
Neil 7b97551acf fix(opencode): isolate v1/v2 plugins and preserve WSL config (#21900)
* fix(opencode): include cache read and write usage totals

* fix(opencode): satisfy aggregate query safety checks

* chore(i18n): refresh runtime English catalog

* fix(opencode): isolate plugin variants and preserve WSL config
2026-09-20 21:09:23 -07:00
Pablo Werlangandorca-agent 646fa3645f fix(opencode): attribute shared-server sessions to their panes (#21577)
* docs: allow-list opencode tool-readout follow-up note

* fix(opencode): attribute shared-server sessions to their panes

The v2 shared server stamps every hook post with its own frozen pane,
so all panes' status lands on the starter pane (#21359).

- shared: session->pane registry plus ingest-time envelope rewrite;
  bound sessions resolve to their real pane, tab and live launch token
  before disposition, unbound sessions keep the stamped identity.
- main: binder poll (SQLite session store, PTY-registry pane snapshots,
  argv-aware client sweep) with directory-containment plus
  client-lifetime correlation; 60s loop plus debounced SessionStart kick,
  wired into the hook server lifecycle.

* fix(opencode): newest-wins pane dedupe, macOS private/tmp normalization

Live verification against the dev instance found two binder gaps: remint
rows for one pane counted as an ambiguous tie, and /tmp vs /private/tmp
spellings never met on macOS.

* fix(opencode): review fixes — newest-wins worktree, drop dead constant

- applyBinderOwnerships now overwrites per-pane worktree, matching the
  round's newest-wins pane dedupe; a remint's live row wins over a stale
  row (pinned by test).
- remove the unused OPENCODE_CLIENT_PRE_CREATE_WINDOW_MS export and the
  nowMs residue from clientCouldCreate.
- give the per-pane launch-token cache its own named cap constant.

* fix(opencode): address thread review — cursor, native table, tokens, lifecycle

- composite (time_created, id) store cursor advanced past handled rows
  only, so same-millisecond pagination and full unbound maps no longer
  drop sessions silently.
- Windows sweep reads the native process table instead of forking
  powershell.exe; quote-aware argv parsing on both platforms.
- directory keys via normalizeRuntimePathForComparison (Windows
  case-fold, POSIX backslash literals) plus narrow macOS /tmp|/var|/etc
  aliases and lexical dot-segment resolution.
- bound sessions always take the stored pane token (never the frozen
  stamp); token tracking runs after resolution.
- binder generation guard discards post-stop rounds; first round runs
  immediately at loop start.
- unbind/move use exact pane-key match; pane launch-token cache gets its
  own cap constant.
- move the tool-readout note out of this PR for its own branch.

* fix(opencode): second review round — executable field, worktree scope, round lifecycle

- POSIX sweep reads comm= alongside args= and classifies on the
  kernel executable name, so unquoted install paths with spaces no
  longer split argv[0] and reject the client; Windows rows carry the
  native table name. Degrades to argv[0] when comm is unavailable.
- bound sessions take only the binding's worktree (never the stamped
  pane's), so a worktree-less binding cannot file a row under the
  wrong worktree.
- the binder generation is captured before the round body and the
  running flag clears only for the current generation, so an obsolete
  post-stop round cannot admit an overlapping round.

---------

Co-authored-by: orca-agent <orca-agent@local>
2026-09-20 20:06:55 -07:00
Neil 438744ca77 fix(opencode): preserve global config discovery (#21854) 2026-09-20 17:58:37 -07:00
NeilandXiro The Dev ee354a35d7 feat(agents): add OpenCode 2 beta support (#21418)
* feat(agents): add OpenCode 2 beta support

Co-authored-by: Xiro The Dev <lethanhtrung.trungle@gmail.com>

* fix(opencode2): support current plugin lifecycle and session storage

* fix(opencode2): preserve lifecycle ordering and full session capture

* test(opencode2): cover setup event bridge

* test(opencode2): cover setup event bridge

* test(browser): satisfy anti-slop naming check

* test(opencode2): cover live form lifecycle

* fix(relay): preserve OMP config directory selection

* test(opencode2): avoid assertions in bridge fixture

* fix(rebase): retain OMP resume and fresh launch behavior

* test: align upstream OMP resume expectations

* test(opencode2): verify rejected form closes waiting state

---------

Co-authored-by: Xiro The Dev <lethanhtrung.trungle@gmail.com>
2026-09-19 17:49:03 -07:00
Neil bfdec26352 fix(lint): enable anti-slop/no-object-parameters (#20781)
The rule rejects the broad `object` type on any function input (declarations,
expressions, arrows, methods, call/construct signatures, function types), plus
local aliases and unions that resolve to `object`. `object` accepts every
non-primitive while exposing no properties, so it documents nothing and pushes
callers into assertions at the boundary.

Fixes all 185 violations across src, config, tests and mobile, and flips the
rule from "off" to "error" in config/oxlint-anti-slop.json.

Approach: replace each `object` input with the type its owner already has.
Most sites took an existing domain type or a type-only import (36 added);
40 new aliases name shapes that had none. Where a value is genuinely only
compared by reference, it gets a named identity token instead of a shape --
`Record<string, never>`, the built-in `WeakKey`, or a `unique symbol` brand,
matching the branding already used in src/shared. Same treatment for WeakMap
and Map key parameters. Two `as unknown as` casts became unnecessary once the
parameter carried a real type and were removed; no new casts were added.

Suppressions added: none. No `oxlint-disable` for this rule anywhere, and no
max-lines disable or per-file bump.

Three files sat exactly at their max-lines cap, so the added type imports were
made line-neutral rather than suppressed:
- src/main/ipc/browser.ts exports the existing guest-registration args type
  (renamed BrowserGuestArgs) so browser.test.ts reuses it on one line.
- pane-scroll.ts takes TerminalScrollIntentTarget through the existing
  pane-manager-types import via a type-only re-export.
- direct-rpc-client.ts drops the identity parameter entirely: the session
  check moved into the sendProbe callback that owns the token.

Verified: anti-slop config reports zero violations over src config tests
mobile; run-typecheck-projects-in-parallel exits 0; 144 affected test files
pass (1749 tests); oxlint and oxfmt clean on all changed files. Mobile has no
runnable test/typecheck target in this worktree (expo is not installed), so
its 6 files were typechecked against a standalone config and diffed against
the base branch -- error sets are byte-identical, including test files.
2026-09-15 01:59:58 -07:00
Neil 48e63c015f refactor agent config and auth services (#16195)
* refactor: split agent config and auth services

* chore: repoint wsl and global-fetch guards at split module paths

* fix: restore merge-base Claude CLI error propagation

Drop the secret-redaction rewriting added to Claude CLI error paths in the
refactor: spawn errors again reject with the original Error (preserving
.code/.errno/.syscall/.stack) and command output/auth-status logs are no
longer rewritten.
2026-08-24 23:15:01 -07:00
Brennan Benson ab3b1d07cd reland(opencode): session continuity without the command-finished deferral (STA-4557) (#15350)
* reland(opencode): session continuity without the command-finished deferral (STA-4557)

Relands #14866 (reverted in #14943) minus its `orca-runtime.ts` change, which
is what caused the revert.

## Why the original runtime change was wrong

`retirePtyAgentLaunchAuthorityAfterCommandFinished` deferred launch-authority
retirement behind an async foreground read, on the premise that OpenCode emits
`command-finished` while still in the foreground. Raw PTY capture disproves it:
OpenCode emits no OSC 133 of its own, and Orca's shell wrappers emit exactly one
`133;D` per pane — at OpenCode's exit — under both zsh and bash. The event being
deferred past only ever fires at exit, which is exactly when authority should be
retired. Both call sites stay on the synchronous `retirePtyAgentLaunchAuthority`.

## Why the deferral was unsafe

`confirmPtyAgentExit` uses the same async-foreground pattern four lines away, but
its early return means "don't record an exit" — conservative. The deferral copied
that shape into a site where the early return means "don't revoke a secret". Same
code, inverted consequence: every guard failed open, so a stale or racing read
silently kept a finished session's authority alive, and the pane's persisted
`launchTokenHash` was never scrubbed — so it rehydrated as `restored` authority
after an app restart.

## Why the deferral's guards could not have worked

`ORCA_AGENT_LAUNCH_TOKEN` lives in the PTY environment, so every process started
in that shell inherits it — both sessions in a reused pane post the same token. A
pane-lifetime bearer secret cannot be a session identity baseline, by
construction, and `incarnationId` tracks the PTY, not the agent. The only field
that separates sessions is the provider `sessionID`.

## What lands

- Status/session-boundary work from #14866: opencode emits `SessionStart` for
  root sessions (mimo-code does not), launch-token fencing, and `SessionStart`
  as an opencode turn boundary.
- The two `server.ts` fixes from #14941: re-fence a still-authorized pane on a
  tokened `SessionStart`, and restore mimo-code's explicit-prompt restart
  boundary (mimo emits no `SessionStart`, so opencode-only stranded its panes).
  #14941's re-poll hunk is dropped along with the code it patched.
- Five regression tests in `opencode-finished-session-authority.test.ts`. They
  pass here and all five go red if the deferral is re-added.

* chore: drop incidental reformatting of files unrelated to this PR
2026-08-23 15:24:25 -07:00
Neil 0bbc6c80e8 refactor(host): route app paths and version through an AppEnvironment port (#16019)
* refactor(host): route app paths and version through an AppEnvironment port

`app.getPath('userData')` is the single largest Electron coupling in the main
process — 37 call sites — and it is one of the things stopping the Orca runtime
from booting on plain Node. Give it the same treatment as SecretStore.

- `src/shared/app-environment.ts` — the port plus a settable registry, covering
  the members the runtime's module graph actually reads: paths, app path,
  version, packaged flag, shutdown hook, exit, and Chromium process metrics.
  `getAppEnvironment()` throws until installed, for the same reason the secret
  store does: a silent default resolves `userData` to the wrong directory and the
  caller writes real state there before anyone notices. No `node:` imports,
  because `src/shared/**` is in the web build graph.
- `src/main/host/electron-app-environment.ts` — the desktop adapter, a
  pass-through to `electron.app`.
- 9 modules migrated: telemetry, opencode/mimo/pi hook services,
  terminal-history-paths, terminal-scrollback-snapshots, cli-installer,
  clipboard-image-temp-file, memory/collector.

Deliberately NOT migrated: `src/main/browser/**`. That cluster is Chromium-
adjacent by nature — cookie jars, download destinations, offscreen pages — and a
Node backend does not ship it at all, so porting it buys nothing and churns
heavily-mocked suites. Also left alone for now: the call sites that additionally
touch `app.asar` path literals or `app.setName`, which need more than a
mechanical swap.

`getAppMetrics` stays on the port rather than being injected because
memory/collector.ts is its only caller and reads it from module scope; a Node
host returns [], having no Chromium processes to measure.

Test wiring: the secret-store setup file becomes `vitest-host-ports-setup.ts` and
installs both ports, exporting `fakeAppEnvironment`/`installFakeAppEnvironment`
so suites needing one specific member state only that instead of restating all
seven — which is boilerplate, and had pushed one suite past the max-lines budget.

Verified: 159 files / 1651 tests pass across every touched area; `tsc` clean on
both the node and web projects; `oxlint` clean.

* fix(typecheck): list the vitest host-ports setup in the node project

Three suites import `installFakeAppEnvironment` from config/scripts, but that
directory is outside tsconfig.node.json's include list, so composite typecheck
failed with TS6307. Listing the one file matches how this config already pins
individual files it needs.

Local `tsc --composite false` does not reproduce this — only `pnpm typecheck`
does, which is what CI runs.

* refactor(host): drop two unused AppEnvironment exports

hasAppEnvironment() and resetAppEnvironmentForTests() had zero callers. The
secret-store equivalents are used, so these were mirror-symmetry rather than
need; add them back when something actually needs them.

* test(terminal-history): install the AppEnvironment fake instead of mocking electron

These three suites mocked `electron.app.getPath` to point at a fixture dir. The
production module now reads the port, so the mock was inert and the global test
default's temp dir won — which broke the WSL path assertions and every deletion
count.

Found by a full-suite run, not by the targeted checks around the migrated modules,
which is the argument for running the whole suite on a refactor this wide.

* test(host-ports): remove the per-environment temp dir on teardown

The setup allocated a mkdtemp directory at module scope, which vitest evaluates
once per test *environment* — one per test file, not one per worker. Nothing
removed them, so a full 6,000-file run left thousands behind.

Proven: with an isolated TMPDIR, a three-file run previously added directories and
now leaves zero.

* fix(app-environment): anchor the installed environment to a realm global

Same reason as the SecretStore: vi.resetModules() rebuilds the module registry,
and an environment installed before the reset read back as uninstalled.
2026-08-22 21:12:23 -07:00
Brennan Benson c303d36228 fix(opencode): keep the pane working while a background subagent runs (#9692) (#14712) 2026-08-17 15:32:17 -07:00
Brennan Benson c4e188a25f fix(opencode): emit a default export the plugin loader accepts (STA-3097) (#14612)
OpenCode resolves a plugin file through either a named factory export or the
module default export. The generated orca-opencode-status.js only carried the
named export, so the default-export loader had nothing to read.

Verified against opencode 1.18.18: a default of { id, setup } is refused with
"must default export an object with server()", while { id, server } loads. Emit
that shape and keep the named export so the factory loader is unaffected.
2026-08-17 15:18:40 -07:00
Jinjing ef1224c4f7 Revert "Preserve OpenCode session across command completion, control SessionS…" (#14943)
This reverts commit 1da1bdc01c.
2026-08-16 12:33:28 -07:00
Jinjing 1da1bdc01c Preserve OpenCode session across command completion, control SessionStart emission (#14866)
* Preserve OpenCode session across command completion

- Add session start events and launch token tracking to establish session boundaries
- Defer retiring launch authority until OpenCode process actually exits, not just when a command finishes
- Fence previous tokens after restarts to prevent status updates from stale sessions
- Maps SessionStart as a session boundary for proper turn/state management

* Emit SessionStart only from OpenCode, not mimo-code

Restrict SessionStart lifecycle events to OpenCode exclusively. Mimo-code no longer emits SessionStart, as it should rely on OpenCode for session boundary signals. This prevents duplicate lifecycle events that could interfere with pane authority tracking and session state management. Also tighten foreground process result validation to reject stale results after title observation changes, fixing a race where a delayed foreground read from a previous cycle would incorrectly retire authority.
2026-08-16 10:01:27 -07:00
Jinjing 05206046f6 chore: condense code comments (#12008)
* chore: condense code comments

* chore: shorten more code comments

* clarify PTY agent session descendant cleanup behavior

Refine the comment on ptyAgentSessionIds to more accurately describe
when agent sessions sweep their descendant process trees and note the
exception on immediate Windows shutdown.
2026-08-01 14:24:31 -07:00
c6c6c71196 fix(opencode): use cross-platform data directory (#10362)
* fix(opencode): use cross-platform data directory

* fix(opencode): honor in-memory database override

* fix(opencode): harden database discovery coverage

* test(opencode): reproduce Windows session discovery

---------

Co-authored-by: OrcaWin <alpha-eng@stably.ai>
Co-authored-by: OrcaWin <293788423+OrcaWin@users.noreply.github.com>
2026-07-28 19:58:49 -07:00
Neil 54ed8c2311 fix(opencode): harden lifecycle status delivery (#11017) 2026-07-27 23:34:59 -07:00
NeilandOrca aab112933e Revert "fix(memory): bound OOM-prone accumulators (#10179)" (#10255)
Co-authored-by: Orca <help@stably.ai>
2026-07-23 18:35:31 -07:00
Neil 8f40ddf328 fix(memory): bound OOM-prone accumulators (#10179) 2026-07-23 06:22:56 -07:00
NeilandOrca 190de8223e refactor(comments): slim verbose comments in main integrations (git/providers/…) (#9543)
Collapse multi-line explanatory comment blocks into single-line "why" statements
per AGENTS.md ("Document the Why, Briefly"): drop restatements of the code and
mechanism narration; keep the non-obvious reason, external refs, and directives.

Comments-only — verified no code changed via a Babel/esbuild comment-strip
token-equality gate against origin/main; typecheck and oxlint clean.

Area: main — git, source-control, providers & integrations. 40 files changed, 1432 insertions(+), 4473 deletions(-).

Co-authored-by: Orca <help@stably.ai>
2026-07-20 03:18:28 -07:00
NeilandOrca e33b2006f4 Remove stale max-lines lint disables from files under the limit (#7548)
110 files carried an eslint/oxlint-disable max-lines directive but are
already under the default max-lines budget (300 .ts / 400 .tsx / 600 .mjs
/ 800 test), so the suppression is dead. Removing it restores real
max-lines coverage on these files with zero behavior change.

Each removed directive had max-lines as its only rule; verified via a
full oxlint run (0 max-lines violations, 0 new errors). Diff is pure
deletions (200 lines, 0 additions) — no code touched.

Co-authored-by: Orca <help@stably.ai>
2026-07-06 02:12:32 -07:00
NeilandOrca 46646d7ff1 chore(lint): upgrade oxlint to 1.71 + enable 7 new rules (autofixed backlog) (#6841)
* chore(lint): upgrade oxlint to 1.71 and enable 7 new rules

Upgrade oxlint 1.67.0 -> 1.71.0 (1.72 was blocked by the repo's 3-day
minimum-release-age supply-chain guard; nothing here needs it). The
bump is a no-op on the existing config.

Enable 3 error rules (backlog autofixed to zero in this commit) and
4 warn rules (surface signal without gating CI):

error (autofixed, behavior-preserving):
- unicorn/prefer-node-protocol        (~1531 sites: bare builtin -> node:)
- typescript/no-import-type-side-effects (~36: all-inline-type -> import type)
- unicorn/no-array-reverse            (19: copy-then-reverse -> toReversed)

warn (real signal, current fires are test-only/correct):
- unicorn/no-array-fill-with-reference-type  (aliasing footgun guard)
- typescript/no-unsafe-function-type         (bans bare Function type)
- unicorn/prefer-array-flat-map              (map().flat() -> flatMap())
- unicorn/prefer-regexp-test                 (.match() in bool ctx -> .test())

mobile/.oxlintrc.json extends root, so it inherits all 7; the autofix
ran from root and covered mobile/ too.

Verification (all green): oxlint 0 errors (root+mobile+aux configs),
oxfmt clean, typecheck (node+cli+web), vitest 22795 passed / 0 failed,
builds (electron-vite + web + cli) succeed. node: rewrites confirmed to
skip embedded SSH/CLI string payloads (AST-only); all toReversed sites
verified to operate on fresh copies or write-once locals.

* chore(lint): bump mobile oxlint to 1.71 so inherited rules parse

mobile/ is a standalone pnpm project pinning its own oxlint@1.67, which
lacks unicorn/no-array-fill-with-reference-type (needs >=1.70). Since
mobile/.oxlintrc.json extends the root config, mobile CI's 'cd mobile &&
oxlint' failed to parse the new rule. Bump mobile to match root (1.71).

Verified in mobile/: oxlint 0 errors, oxfmt --check clean, tsc --noEmit
pass, vitest 978 passed / 0 failed.

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Orca <help@stably.ai>
2026-06-29 22:38:29 -07:00
0c0367ea88 feat(agents): native Xiaomi MiMo Code support (#6239)
* feat(agents): native Xiaomi MiMo Code support

Add mimo-code TUI agent (detect mimo, --prompt, --session resume).
Inject MIMOCODE_HOME overlay and /hook/mimo-code status plugin on mimo
launch when agent status hooks are enabled; restore via shell-ready
wrappers. Reuse OpenCode-family hook normalization in the listener.

SSH remote MiMo hook overlays are not included (local/daemon first).

Closes #6220

* fix(mimo): remirror overlay config idempotently

rmSync overlay config before mirror so a second mimo launch does not
hit EEXIST in mirrorEntry and fall back to the user MIMOCODE_HOME.

* review: harden mimo code support

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Doan Bac Tam <24356000+doanbactam@users.noreply.github.com>
Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
Co-authored-by: Orca <help@stably.ai>
2026-06-24 00:17:49 -07:00
Brennan BensonandOrca fe8fe16c83 Preserve agent settings when sleeping sessions resume (#5916)
Co-authored-by: Orca <help@stably.ai>
2026-06-21 16:44:58 -07:00
Jinwoo Hong 5f6b454c3a perf(windows): fix 60s startup ACL walk and OpenCode streaming freeze, with benchmark harnesses (#5124) 2026-06-10 16:41:22 -04:00
Jinwoo HongandOrca 3ef63c972a Persist agent session metadata for workspace resume (#4706)
Co-authored-by: Orca <help@stably.ai>
2026-06-07 19:41:25 -07:00
Jinwoo Hong 92d8946209 Avoid OpenCode config cleanup freezes on Windows (#4526) 2026-06-02 21:20:13 -04:00
Brennan BensonandOrca 423a6d11e3 Track agent prompt sent from agent hooks (#3033)
Co-authored-by: Orca <help@stably.ai>
2026-05-29 12:45:34 -07:00
Neil b1c03b1281 Tighten Bitbucket environment handling 2026-05-14 15:20:00 -07:00
Brennan BensonandOrca 952ee7a6ec fix(opencode): mirror user OPENCODE_CONFIG_DIR via per-PTY overlay (#1595)
Co-authored-by: Orca <help@stably.ai>
2026-05-08 12:12:19 -07:00
Brennan BensonandOrca 85b125f6bf feat(opencode): map question.asked to waiting state (#1406)
Co-authored-by: Orca <help@stably.ai>
2026-05-04 16:09:34 -07:00
Brennan BensonandOrca 4279fc8075 feat(agent-hooks): on-disk endpoint discovery for surviving PTYs (v2) (#1196)
Co-authored-by: Orca <help@stably.ai>
2026-04-27 21:49:18 -07:00
Brennan BensonandOrca 8347b3099d test(opencode): add buildPtyEnv/clearPty round-trip coverage (#1162)
Co-authored-by: Orca <help@stably.ai>
2026-04-27 00:07:19 -07:00