* fix(settings): keep full installed font list
* fix(settings): bound font picker rendering
* Fix redundant font queries and handle partial state in worktree purge
- Latch the loaded state even when the returned font list is empty, preventing font-less systems from reissuing font listing calls on every picker interaction.
- Add null-tolerance for `ptyIdsByTabId` when building worktree purge state to support callers that pass partial AppState.
---------
Co-authored-by: Jinjing <6427696+AmethystLiang@users.noreply.github.com>
Deleting a config-sourced SSH target had no lasting effect: the Manage-SSH pane
re-imports ~/.ssh/config on open, and the import was a pure upsert with no record
of deletions, so the just-deleted host was re-inserted verbatim from the config
that still exists on disk.
Persist a `deletedSshConfigAliases` tombstone set:
- Deleting a config-managed target (source 'ssh-config', or an adopted legacy
import) records its alias; manual targets are never tombstoned.
- The passive on-open sync skips tombstoned aliases, so a deleted host stays
deleted.
- Re-adding or editing a target reclaims its alias, and the explicit Import
action (`reAdopt`) clears all tombstones to deliberately re-adopt config.
This also fixes the edit-then-reappear case: editing a config host to `manual`
already reserved its current alias, and reclaim covers alias changes.
* fix(github): route PR merges through repo owner
- Use repo-owner runtime settings before source-context overrides in PR actions
- Keep headless/runtime repos on runtime RPC instead of local gh:mergePR
- Add source-boundary coverage for merge routing and Windows-safe newline matching
* fix(github): preserve repo-owner merge routing
- Apply task-source runtime overrides only when they resolve to a runtime host
- Keep runtime-owned repos from being downgraded to local gh:mergePR
- Guard the routing contract with source-boundary coverage
- Important because non-runtime source contexts could recreate the issue #6957 access-denied path
* test(github): add behavioral regression test for repo-owner merge routing
Mirrors PRActionsPanel's merge-routing decision through the real
repo-runtime-owner/task-source helpers so a revert to source-only
routing (issue #6957) fails here. Covers the runtime-owned repo with a
local GitHub source view and the local-repo-while-runtime-focused case.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
Co-authored-by: Orca <help@stably.ai>
Regression guard for the runtime-agent-list fix: asserts the composer's
detectedAgentList selector and detection effect resolve SSH -> runtime ->
local in that order, so a runtime-owned repo shows the paired runtime's
agents instead of the local machine's.
Co-authored-by: Orca <help@stably.ai>
* feat(ai-vault): add OMP sessions to the AI Vault session browser
Adds OMP ("Oh My Pi") to the AI Vault/Agents catalog so historical
.omp/agent/sessions/**/*.jsonl transcripts are discovered, parsed, and
resumable from the right-sidebar session browser — locally and over SSH.
- Discovery mirrors Pi (OMP_CODING_AGENT_DIR env, WSL home roots, per-agent
limit) in both the local scanner and the remote/SSH scanner.
- Parses OMP's message-graph JSONL via the shared graph parser (new
MessageGraphAgent type), capturing the model from model_change.model (OMP's
key, not Pi's modelId) or the assistant message, and tokens from usage.
- Routes OMP through the incremental parse cache so ~5s rescans resume from
the last byte instead of re-reading whole transcripts.
- Resumes by absolute transcript path (`omp --resume <path>`) so it resolves
regardless of which session-dir root (custom OMP_CODING_AGENT_DIR / WSL
store) the file was discovered under; threaded through both the scanner and
the renderer's local resume/copy rebuild.
- Renderer reuses the existing OmpIcon/catalog/grouping; adds overflow-x-hidden
so long worktree chips never widen the sidebar.
Generalizes normalizePiSessionsDir -> normalizeAgentSessionsDir. Verified
end-to-end against 10 real ~/.omp transcripts and rendered in the app.
Co-authored-by: gatsby74 <166927047+gatsby74@users.noreply.github.com>
* fix: make AI Vault parse-cache agent switch explicit
---------
Co-authored-by: gatsby74 <166927047+gatsby74@users.noreply.github.com>
Co-authored-by: Jinjing <6427696+AmethystLiang@users.noreply.github.com>
oxlint already fails any file over max-lines that is not suppressed, so the
only way to grow past the budget is to add an eslint/oxlint-disable max-lines
comment or a per-file max-lines bump in mobile/.oxlintrc.json. This adds a CI
gate that freezes the current set of suppressions (config/max-lines-baseline.txt,
355 grandfathered entries) and fails the build when a NEW one appears — with a
loud, actionable message pointing at 'split the file'. Existing oversized files
are untouched; the baseline may only shrink (pnpm check:max-lines-ratchet --prune).
Wired into the root lint script and as a dedicated pr.yml step. Unit-tested
(15 cases) and verified against all three failure paths + clean-tree pass.
Co-authored-by: Orca <help@stably.ai>
retainedAgentsByPaneKey snapshots a completed agent (a full AgentStatusEntry
— up to ~24KB of prompt/message text — plus a TerminalTab) per ephemeral
paneKey. paneKeys never recur, and the map is pruned only on worktree removal
or manual dismissal, so a long-lived worktree in a busy multi-agent /
orchestration session grows it without bound. This is the dominant
large-payload driver of the renderer JS-heap OOM seen in the Windows crash
bundles (heap climbing to the 3586 MB V8 old-space limit under continuous
multi-agent work).
Cap the map with insertion-order (== retention-order) FIFO eviction, mirroring
capRecordByInsertionOrder in github.ts: the newest completions survive; the
oldest simply stop showing in the recently-completed overlay. retainAgents is
the only path that grows the map, so capping there fully bounds it.
Adds a leak regression test that drives the production retainAgents path with
distinct ephemeral paneKeys and asserts the map stays bounded — fails before
this change (grows to N), passes after (capped at MAX_RETAINED_AGENTS).
Co-authored-by: Neil <neil@stably.ai>
* fix(renderer): raise renderer V8 heap toward the 4GB pointer-compression cage
Renderer OOM ('renderer crashed'/'oom', exit 5 / 0xE0000008 / SIGTRAP) is the
dominant crash in the crash channel: the renderer JS heap reaches Chromium's
default V8 old-space ceiling (~RAM/4) and V8 aborts. Two adversarial leak hunts
(13 agents across every renderer subsystem) found no unbounded GB-scale leak, so
this is a capacity ceiling, not a leak.
Chromium sizes the renderer heap at ~RAM/4, leaving 8-15GB machines well under
V8's ~4GB pointer-compression cage (an 8GB machine caps near 2.2GB). Reclaim that
unused headroom via --max-old-space-size in a focused startup module, gated on
physical RAM (>=8GB, ~40% of RAM, floor 3072MB, capped at the real 4096MB cage).
16GB+ machines are already at the cage so this is a no-op for them; low-RAM
machines keep the default to avoid trading a clean OOM for OS memory-pressure
kills.
Overridable with ORCA_RENDERER_HEAP_MB (number to force, default/off/0 to opt
out). Verified on Electron 42.3.3: the main-process js-flags switch propagates to
the renderer V8 and is honored up to the 4096MB cage (5000/12288 -> 4096).
Co-authored-by: Orca <help@stably.ai>
* fix(renderer): address CodeRabbit — floor-to-0 override + Linux 8GB gate
- parseRendererHeapOverrideMb: a fractional override in (0,1) floored to 0 and
emitted an invalid --max-old-space-size=0; treat floored-to-0 as an opt-out.
- Lower the RAM gate from 8 to 7.5 GiB: os.totalmem() on Linux reports MemTotal
(excludes kernel/firmware-reserved RAM), so a real 8 GB box reports ~7.7 GiB
and was wrongly excluded from the headroom — the exact crashing population.
7.5 still cleanly excludes 6 GB machines (report ~5.7 GiB).
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
110 files carried an eslint/oxlint-disable max-lines directive but are
already under the default max-lines budget (300 .ts / 400 .tsx / 600 .mjs
/ 800 test), so the suppression is dead. Removing it restores real
max-lines coverage on these files with zero behavior change.
Each removed directive had max-lines as its only rule; verified via a
full oxlint run (0 max-lines violations, 0 new errors). Diff is pure
deletions (200 lines, 0 additions) — no code touched.
Co-authored-by: Orca <help@stably.ai>