* feat(relay): route relay handlers through RelayWorkAdmission First consumer of the T1 work-drain seam: every request and notification handler registered on the relay dispatcher now runs under RelayWorkAdmission, and the dispatcher exposes beginWorkDrain(exclude?) and assertActiveWorkContext(context). RequestContext gains an optional transportGeneration, stamped from client.generation for both requests and notifications, so later producers can pin publication to one transport. Behavior today is unchanged: nothing in production calls beginWorkDrain yet (the shutdown/reset caller is T3), so admission never closes. Decision: pty.cancelDelivery joins the drain request allowlist. #16741 omits it. It only retires an existing source delivery (closes the ledger record, releases retained spans, wakes the publication so it drops its record), it cannot open a delivery or produce output, and a retry replays the remembered proof instead of mutating again. It is the request-shaped sibling of pty.ackData / pty.setDeliveryPaused, which are already allowlisted. Refusing it during a drain would make the client's cancellation proof fail (ssh_source_cancellation_proof_invalid) and leave the delivery retained until detach, turning a provable cancel into an unverifiable one. Revisit only if live ownership transfer (T7, deferred) needs a frozen source ledger. Porting note (source: #16741 heada68b6f3531, merge-base 277c289bd4; T1 per the track manifest): - Taken verbatim: dispatcher-client-state onRequest/onNotification wrapping, beginWorkDrain, assertActiveWorkContext; dispatcher-contract transportGeneration; dispatcher-rpc-routing generation stamping. - Adapted: RelayWorkAdmission.run is no longer an async function. It returns the handler's own promise and tracks completion on the side, because an async wrapper adds microtask turns to every relay response and broke existing tests on this base that await one turn after feed() (workspace-session-handler, pty-handler ownership/retired-surface). Refusal and sync throws still surface as rejections. - dispatcher-work-drain.test: kept the four dispatcher-only cases; replaced the two RelayGraceLifecycle.prepareShutdown cases with dispatcher-level equivalents (initiator exclusion, copied/settled context rejection); dropped the real-shutdown case (prepareShutdown/finishShutdown is T3). Added cases for transportGeneration stamping and pty.cancelDelivery during drain. Wire compatibility: no new RPC fields, methods, or opcodes on the wire. transportGeneration is relay-internal. Once a later track calls beginWorkDrain, a refused request gets an ordinary JSON-RPC error (-32000 relay_work_admission_closed) and a refused notification is dropped, which old and new clients already handle as a failed call. * feat(relay): settle producer notifications and add the producer publication drain Second T1 consumer slice: relay producer publication can now be proven, not just enqueued. publishProducerNotification takes optional onSettled, settledTransportGeneration and isStillAdmitted, and settles exactly once on every path (sink completion, disposal, missing client, PTY admission refusal, capacity refusal, serialization failure) while keeping its existing boolean return and throw contract. assertSettledProducerTransport refuses a replaced or closed client generation and a sink without write callbacks. RelayProducerPublicationDrain builds on the landed TransportPublicationDrain: each publish is counted until its local write completes, and the drain fails sticky once the owner's authority or the transport generation changes, even for frames already queued behind backpressure (isStillAdmitted is rechecked at dequeue through the frame codec and producer transport). Existing producers (watcher events, agent hook envelopes, workspace snapshots) pass none of the new options and behave as before. The drain has no production caller yet; the browser network tunnel (T4) is its first. Porting note (source: #16741 heada68b6f3531, merge-base 277c289bd4; T1 per the track manifest): - Taken verbatim: dispatcher-client-writer supportsWriteCallback, dispatcher-frame-codec publicationAdmission, dispatcher-producer-transport isStillAdmitted plumbing, dispatcher-notification-publication settlement, relay-producer-publication-drain, and both tests (relay-producer-publication-drain.test, dispatcher-producer-settlement.test). These files were unchanged on this base since the merge-base, so the upstream hunks applied cleanly. - Adapted: nothing needed; the new code uses no Promise.withResolvers or Bun APIs, so it stays within the relay bundle's Node 18 floor. - Not in this slice: fs/git stream shutdown, ws-transport / node-websocket-lifecycle / websocket-transport-limits, renderer flow-controller deltas (later T1 slices). Wire compatibility: no new RPC fields, methods, or opcodes. Settlement, generation checks and admission are relay-local; a client of any version sees the same notification frames it does today, and a frame refused by the new checks is simply not sent, as a capacity refusal already is. --------- Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
Orca
中文 · 日本語 · 한국어 · Español · Français · Português
The AI Orchestrator for 100x builders.
Run Codex, ClaudeCode, OpenCode or Pi side-by-side — each in its own worktree, tracked in one place.
Download Orca
Features
Also in the box:
- Quick open — Search across worktrees, files, agents, commands, and repo context without leaving your flow.
- Account switcher & usage tracking — See Claude and Codex usage and rate-limit resets, and hot-swap accounts without re-logging in.
- Rich repo previews — Preview Markdown, images, PDFs, and repo docs in the workspace.
- Computer Use — Let agents operate desktop apps and visible UI when a workflow needs real interaction.
- Notifications and unread state — Know when an agent finishes or needs attention, then mark threads unread to come back later.
- And many, many more — we ship daily, so this list is perpetually behind. The changelog is the real feature list.
Supported Agents
Works with any CLI agent — if it runs in a terminal, it runs in Orca.
Claude Code
Codex
Grok
Cursor
GitHub Copilot
Muse
DeepSeek Harness
ZCode
OpenCode
MiMo Code
Amp
OpenClaude
Antigravity
Pi
oh-my-pi
Hermes Agent
Devin
Goose
Auggie
Autohand Code
Charm
Cline
CodeBuddy
Codebuff
Freebuff
Command Code
Continue
Droid
Kilocode
Kimi
Kiro
Mistral Vibe
Qwen Code
Rovo Dev
+ any CLI agent
Install
Desktop — macOS, Windows, Linux
- Download from onOrca.dev
- Or grab a build directly: macOS Apple Silicon · macOS Intel · Windows (.exe) · Linux AppImage · All builds
- Running
orca serveon a headless Linux server? See the headless Linux server guide.
Or via a package manager:
# macOS (Homebrew)
brew install --cask stablyai/orca/orca
# Arch Linux (AUR) — or stably-orca-git to build from source
yay -S stably-orca-bin
Mobile Companion — iOS, Android
Pair with your desktop app to monitor and steer your agents from your phone.
- iOS: Download on the App Store
- Android: Download APK 0.0.50 · Install guide
Community & Support
-
Discord: Join the community on Discord.
-
Twitter / X: Follow @orca_build for updates and announcements.
-
WeChat: Scan to join the Orca community WeChat group 11.
-
Feedback & Ideas: We ship fast. Missing something? Request a new feature.
-
Privacy: See the privacy & telemetry docs for what anonymous usage data Orca collects and how to opt out.
-
Show Support: Star this repo to follow along with our daily ships.
Developing
Want to contribute or run locally? See our CONTRIBUTING.md guide.
The relay that pairs the mobile app with a desktop host is also in this repository under
cloud/, with a separate pnpm workspace and setup guide.
Signed Builds
Windows code signing sponored/provided by SignPath.io, certificate by SignPath Foundation.
License
Orca is free and open source under the MIT License.










