Commit Graph
119 Commits
Author SHA1 Message Date
Neil 6e77c02fc6 fix: update Electron and revert UTF-8 write mitigations (#4598) 2026-06-03 16:45:01 -07:00
Neilandthiagomsoares 996b69dce0 Harden large app state UTF-8 writes (#4587)
* fix: write stats file in chunks to avoid Electron UTF-8 abort

orca-stats.json gains an event on every agent start/stop. After about a
month of use mine had grown to ~3.6k events / ~608 KB, and the app started
hard-crashing a few seconds after every launch (SIGTRAP, no catchable JS
stack):

    Assertion failed: (length + 1) <= (capacity())
    node::MaybeStackBuffer<char>::SetLengthAndZeroTerminate <- node::Utf8Value

The crash is in StatsCollector.writeToDiskSync(), which saves the whole
file in one writeFileSync(JSON.stringify(data)). Electron 42.3.2's bundled
Node aborts when encoding a string that large to UTF-8 in a single write;
stock Node 24 handles the same file fine and the data is well-formed, so
it's an Electron/Node encoding limit, not bad data. The save runs on a
debounce after agent_start, which restored agents fire on launch -- so it
crashed right after opening.

Write the JSON in 64 KB slices through one fd instead (never splitting a
surrogate pair), and lower MAX_EVENTS 10k -> 1k so the file can't grow back
this large. Lifetime aggregates are unaffected.

Verified by reproducing the abort standalone with the real 608 KB file
under ELECTRON_RUN_AS_NODE, confirming the chunked writer round-trips it
byte-for-byte with no crash, and running a patched build that loads the
file without crashing. The underlying encode abort is an Electron/Node bug
to report upstream.

* fix: harden stats JSON writes

* fix: chunk app state UTF-8 writes

* fix: stabilize status and terminal polling

---------

Co-authored-by: thiagomsoares <5190162+thiagomsoares@users.noreply.github.com>
2026-06-03 14:58:28 -07:00
Jinwoo HongandOrca 205494b7ba Fix file search match parsing (#4542)
Co-authored-by: Orca <help@stably.ai>
2026-06-02 22:11:37 -07:00
Jinjing d21e73301e Refresh cleanup base before forced branch deletion (#4462) 2026-06-02 01:08:11 -07:00
Jinwoo HongandOrca 71314c9326 Fix Mistral Vibe CLI detection (#4455)
Co-authored-by: Orca <help@stably.ai>
2026-06-02 02:49:40 -04:00
Jinjing 1304d6b630 fix: address review findings (#4325) 2026-05-31 16:03:55 -07:00
Jinwoo Hong 4cc0147005 Fix orchestration mail from WSL and SSH terminals (#3918) 2026-05-31 15:13:15 -04:00
Neil 93bba155de fix: cancel superseded relay exec children (#4283) 2026-05-31 10:54:28 -07:00
Neil a7e8471bf2 fix: bound relay hermes run count cache (#4278) 2026-05-31 10:48:16 -07:00
Neil b772a9ca42 fix: parse quick open git fallback paths losslessly (#4049) 2026-05-31 02:43:28 -07:00
Neil 8ba451e8dd fix: preserve newline worktree paths
Use porcelain-z worktree parsing with fallback line parsing so newline-containing worktree paths survive local and relay operations. Risk: low.
2026-05-31 01:50:16 -07:00
Jinwoo-HandOrca 3ae32ee9e6 test: cover relay diff traversal rejection
Co-authored-by: Orca <help@stably.ai>
2026-05-31 01:49:29 -07:00
Neil 6c9332004e fix: allow dot-dot-prefixed relay diff paths 2026-05-31 01:49:29 -07:00
Neil 45afdfc3c2 fix: allow hermes log paths with dot-dot names 2026-05-31 01:47:44 -07:00
Jinjing f0308a86e6 Fix PR workspace branch checkout (#4003) 2026-05-31 00:06:57 -07:00
Jinjing 5e7d097682 fix: address review findings (#3991) 2026-05-30 23:04:18 -07:00
Neil d23cd0e451 Hide Pi thinking in Orca overlays 2026-05-30 14:25:34 -07:00
Neil 1009ac9083 chore: update Electron to 42 (#3919) 2026-05-30 13:26:48 -07:00
Jinjing 5dc6947fc6 fix: address review findings (#3866) 2026-05-30 12:45:49 -07:00
Neil 3193ea5f16 Clean up relay git file listing listeners (#3834) 2026-05-30 11:49:20 -07:00
Neil 81d9bbe9b5 fix: settle relay agent exec timeouts (#3737) 2026-05-30 11:41:25 -07:00
Neil d05c3ada2d fix: time out relay rg availability probes (#3779) 2026-05-30 09:55:51 -07:00
Neil 8f6f59a654 perf: handle large relay status entry lists (#3773) 2026-05-30 09:44:45 -07:00
Neil 760f5c34ec perf: classify relay bulk discard paths safely (#3770) 2026-05-30 09:37:17 -07:00
Neil d313a58306 fix: settle relay rg file list timeouts (#3754) 2026-05-30 08:53:21 -07:00
Neil 26a65588d8 fix: settle relay rg search timeouts (#3734) 2026-05-30 08:12:18 -07:00
Neil 2d324d97fe fix: settle relay git grep timeouts (#3733) 2026-05-30 08:02:06 -07:00
Neil 786fecde19 fix: settle relay git file list timeouts (#3731) 2026-05-30 07:57:38 -07:00
1844a992e8 fix: pr-bug-scan validated finding from #2947 (#2965)
* fix: address pr-bug-scan validated finding from #2947

Prepended `:(literal)` pathspec magic to each path passed to `git clean -ffdx --` in both `cleanUntrackedPaths` call sites, so untracked filenames containing pathspec glob magic (`*`, `?`, `[`, `]`) a

* fix: literalize discard git pathspecs

---------

Co-authored-by: orca-bug-scan-bot <orca-bug-scan-bot@stably.ai>
Co-authored-by: Neil <4138956+nwparker@users.noreply.github.com>
2026-05-30 01:25:41 -07:00
buf0-bot[bot]andorca-bug-scan-bot 0524039d5b fix: address pr-bug-scan validated finding from #2138 (#2155)
Threaded operation tag through SSH executeCommitMessagePlan/cancelGenerateCommitMessage and relay lane key; reverted commit-message emptyResultName from 'details' to default.

Co-authored-by: orca-bug-scan-bot <orca-bug-scan-bot@stably.ai>
2026-05-30 00:50:45 -07:00
386fc42564 Add Source Control fast-forward action (#3364)
* Add source control fast-forward action

* Fix fast-forward overwrite error wording

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
Co-authored-by: Orca <help@stably.ai>
2026-05-30 02:06:12 -04:00
Brennan BensonandOrca 423a6d11e3 Track agent prompt sent from agent hooks (#3033)
Co-authored-by: Orca <help@stably.ai>
2026-05-29 12:45:34 -07:00
Neil 1236729b24 fix: abort relay requests on dispatcher dispose 2026-05-29 02:00:53 -07:00
Trevin Chow 10f97509ea fix: preserve unmerged branch when removing a worktree (#2927) (#2939)
fix: preserve unmerged branch when removing a worktree (#2927)
2026-05-28 20:19:53 -04:00
Jinjing 47dffe5308 fix: address review findings (#3014) 2026-05-28 16:13:45 -07:00
33650832e4 fix: prevent relay fs.rename from clobbering an existing destination (#2926) (#2937)
* fix: prevent relay fs.rename from clobbering an existing destination

The remote file-explorer rename path (provider.rename -> relay
fs.rename) called fs.rename unconditionally, silently overwriting any
file/folder already at the destination. The local rename already
guards via assertFileExplorerRenameDestinationAvailable; apply the
same guard on the relay to restore local/remote parity (case-only
renames on case-insensitive filesystems still allowed).

Moved the collision helper from src/main to src/shared so both the
main process and the remotely-deployed relay share one implementation.

Closes #2926

* review: make SSH safe rename explicit

- keep relay fs.rename raw and add fs.renameNoClobber for user-facing renames
- route SSH file-explorer rename paths through renameNoClobber
- add relay/provider/runtime regression coverage and stale-relay fail-closed handling
- verified live SSH rename behavior on openclaw 2

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
Co-authored-by: Orca <help@stably.ai>
2026-05-28 16:14:57 -04:00
a1a362700f fix: reject short SSH stream chunks instead of zero-filling reads (#2930) (#2948)
* fix: reject short SSH stream chunks instead of zero-filling reads

The stream reader validated chunk COUNT but not chunk byte length, so a
short chunk (e.g. a 1-byte final chunk for a 2-chunk file) passed the
count check and resolved with the pre-allocated buffer's tail left
zero-filled — silent corruption of remote file reads. Validate each
chunk's exact length, and add a last-line bytesReceived === totalSize
invariant guard before resolving.

Closes #2930

* review: harden SSH stream byte validation

- fill relay protocol chunks across short fs.read returns before emitting streamChunk
- cover short final and non-final client chunks
- add relay pump coverage for short reads before EOF
- verified lint, typecheck, targeted stream tests, relay round-trip, and Electron boot smoke

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
Co-authored-by: Orca <help@stably.ai>
2026-05-28 03:51:36 -04:00
Jinwoo HongandOrca d917240499 Guard untracked discard against symlink escapes (#2947)
Co-authored-by: Orca <help@stably.ai>
2026-05-27 19:48:27 -07:00
659fe79226 feat: add source control action to abort merge (#2092)
Co-authored-by: Orca <help@stably.ai>
Co-authored-by: brennanb2025 <brennankbenson@gmail.com>
2026-05-27 14:59:23 -07:00
Trevin Chowandbrennanb2025 a65f7b4216 feat: auto-rename workspace branch from the first prompt (#2888)
Co-authored-by: brennanb2025 <brennankbenson@gmail.com>
2026-05-27 14:09:43 -07:00
3c59c019fc fix(worktree): add SSH preflight check for dirty worktree before archive hooks (#2912)
Co-authored-by: Orca <help@stably.ai>
Co-authored-by: Prethish-Complyance <prethish@complyance.io>
Co-authored-by: brennanb2025 <brennankbenson@gmail.com>
2026-05-27 13:32:52 -07:00
Brennan BensonandOrca 54c2ef89da Handle force delete for orphaned worktree directories (#2757)
Co-authored-by: Orca <help@stably.ai>
2026-05-26 20:28:51 -07:00
Trevin ChowandNeil b2b5cac9a9 Add per-file line counts to the source control sidebar (#2865)
* Add per-file line counts to the source control sidebar

Show +N/-N (green/red) next to each file in the Changes, Untracked, and
Committed-on-branch sections so the magnitude of a change is visible at a
glance. Counts are computed per staging area via `git diff --numstat`;
untracked/new files count their full contents as additions and binary
files show no count.

Consolidate numstat parsing and binary-buffer detection into shared
modules reused by the local status path, the SSH/relay path, and the
existing branch-compare code. Include added/removed in the status-entry
equality check so the sidebar doesn't re-render on unchanged polls.

* fix: harden source control line counts

---------

Co-authored-by: Neil <4138956+nwparker@users.noreply.github.com>
2026-05-26 20:09:54 -07:00
Brennan BensonandOrca b7832c0790 Persist worktree creation base in git config (#2859)
Co-authored-by: Orca <help@stably.ai>
2026-05-26 15:54:07 -07:00
Neil eb579a0e54 Fix SSH sessions after host sleep 2026-05-26 14:53:16 -07:00
Neil 66a946d663 Fix Claude approval status clearing (#2833) 2026-05-26 13:13:38 -07:00
Neil ab80339158 Fix shell-launched OMP status hooks (#2821)
* Fix shell-launched OMP status hooks

* Update oh-my-pi branding

* Add OMP to mobile agent metadata
2026-05-25 22:20:15 -07:00
Neil 6b51b85519 Fix OMP agent status routing (#2815) 2026-05-25 19:32:15 -07:00
formatme efd75da5d6 Add OMP as first-class TUI agent
Adds OMP as a first-class TUI agent and keeps Pi/OMP overlay state isolated across local and relay PTY paths.\n\nValidated locally with focused Vitest coverage, typecheck, lint, git diff --check, and Electron manual verification using installed omp (omp/15.3.2).
2026-05-25 18:35:48 -07:00
Brennan Benson 5287a581a6 Revert "Allow OS metadata during worktree delete preflight" (#2776) 2026-05-24 23:23:31 -07:00