The incumbent probe printed `HOLDERS_SOURCE=lsof` before running `lsof`, then discarded its exit status and stderr. Any `lsof` that ended with empty stdout for a reason other than "nobody holds it" therefore parsed as verdict `exited`, evidence `no-holder`, `holdersEnumerable: true` — a positive claim of absence the host never made. `classifySupersededRelay` turns that claim into `rm -f` on the socket inode, so it can unlink a path a live relay is still holding. Measured on Debian 12 against a real NFS mount whose server is blackholed: condition wall exit stdout stderr holder found no network mounts 141ms 0 pid - yes NFS healthy 143ms 0 pid - yes NFS wedged (hard) >120s KILL - - no (blocked) NFS wedged, -w >120s KILL - - no (blocked) NFS wedged, -S 2 >120s KILL - - no (blocked) any host, -b 2ms 1 - status error no (WRONG) nothing holds it fast 1 - - n/a (correct) Two things follow. `-w` and `-S` do not address the blocking, and `-b` reports no holder for a socket a live process is holding even on a host with no network mounts, so neither is a fix. And because `-t` exits 1 both for "nobody holds it" and for "could not answer", only the diagnostics separate the two. Today the block is what protects us: the probe dies before `PROBE_END`, the sentinel check fails, and the verdict is `unverifiable`. That safety is accidental, and it is spent the moment anyone bounds the probe — a `timeout` around the wedged case yields empty stdout and empty stderr, which the old script read as `exited`. So the script now decides `HOLDERS_SOURCE` after `lsof` has run: it merges stderr into stdout, treats any non-numeric word or any exit outside lsof's own 0/1 as a failure to answer, and emits `HOLDERS_SOURCE=error` — which the parser already reads as not enumerable, hence `unverifiable`. Pids lsof did report are still honoured, and an absent path stays exempt, so healthy hosts are unchanged and the reap never becomes more permissive. Per docs/reference/ssh-execution-boundary.md, a probe that could not answer is `unverifiable`, never `exited`. This does not make husks reapable on a host with a wedged mount — lsof still blocks there and the verdict stays `unverifiable`. Leaking husks is the correct failure mode; unlinking a held socket is not. A `/proc/net/unix` + `/proc/*/fd` enumeration answered that host correctly in 45ms and is the Linux-only follow-up.
Orca
中文 · 日本語 · 한국어 · Español · Français · Português
The AI Orchestrator for 100x builders.
Run Codex, ClaudeCode, OpenCode or Pi side-by-side — each in its own worktree, tracked in one place.
Download Orca
Features
Also in the box:
- Quick open — Search across worktrees, files, agents, commands, and repo context without leaving your flow.
- Account switcher & usage tracking — See Claude and Codex usage and rate-limit resets, and hot-swap accounts without re-logging in.
- Rich repo previews — Preview Markdown, images, PDFs, and repo docs in the workspace.
- Computer Use — Let agents operate desktop apps and visible UI when a workflow needs real interaction.
- Notifications and unread state — Know when an agent finishes or needs attention, then mark threads unread to come back later.
- And many, many more — we ship daily, so this list is perpetually behind. The changelog is the real feature list.
Supported Agents
Works with any CLI agent — if it runs in a terminal, it runs in Orca.
Claude Code
Codex
Grok
Cursor
GitHub Copilot
OpenCode
MiMo Code
Amp
OpenClaude
Antigravity
Pi
oh-my-pi
Hermes Agent
Devin
Goose
Auggie
Autohand Code
Charm
Cline
Codebuff
Command Code
Continue
Droid
Kilocode
Kimi
Kiro
Mistral Vibe
Qwen Code
Rovo Dev
+ any CLI agent
Install
Desktop — macOS, Windows, Linux
- Download from onOrca.dev
- Or grab a build directly: macOS Apple Silicon · macOS Intel · Windows (.exe) · Linux AppImage · All builds
- Running
orca serveon a headless Linux server? See the headless Linux server guide.
Or via a package manager:
# macOS (Homebrew)
brew install --cask stablyai/orca/orca
# Arch Linux (AUR) — or stably-orca-git to build from source
yay -S stably-orca-bin
Mobile Companion — iOS, Android
Pair with your desktop app to monitor and steer your agents from your phone.
- iOS: Download on the App Store or join TestFlight
- Android: Download APK 0.0.48 · Install guide
Community & Support
-
Discord: Join the community on Discord.
-
Twitter / X: Follow @orca_build for updates and announcements.
-
WeChat: Scan to join the Orca community WeChat group 8. Group 8 may be full; if so, scan the Group 9 QR code instead.
-
Feedback & Ideas: We ship fast. Missing something? Request a new feature.
-
Privacy: See the privacy & telemetry docs for what anonymous usage data Orca collects and how to opt out.
-
Show Support: Star this repo to follow along with our daily ships.
Developing
Want to contribute or run locally? See our CONTRIBUTING.md guide.
The relay that pairs the mobile app with a desktop host is also in this repository under
cloud/, with a separate pnpm workspace and setup guide.
Signed Builds
Windows code signing sponored/provided by SignPath.io, certificate by SignPath Foundation.
License
Orca is free and open source under the MIT License.












