mirror of
https://github.com/stablyai/orca.git
synced 2026-09-29 00:02:56 +00:00
The SSH partition move has two halves, and only one of them is the fix. Reading both partitions IS the repair for #12721: the remote merge can only refuse to delete tabs this client actually holds, and hydrating them out of `ssh:<targetId>` is what arms that defence. Moving the write is cleanup that collapses the #12723 double-ownership. Shipping both at once is what a downgrade cannot survive. Every previously shipped build reads SSH session state out of `local` alone and never enumerates `ssh:*`, so a client that has moved the rows looks empty to the older build -- unsaved editor drafts included -- and that build's publish then omits the workspace, which the relay applies as a wholesale replace-session overwrite. Exposure is launch-and-quit, not 'use an SSH workspace': routing reads the persisted repo catalog, so an offline target still moves on the quit checkpoint. So this release reads `ssh:<targetId>` and keeps writing SSH state where every shipped build looks for it. The four destination assertions now say `local` and each names the file that flips them; the invariants around them -- draft survival, tombstone semantics, contested-id rules, and an SSH claimant staying out of the rotating runtime partition -- are asserted destination-independently and hold in both releases. docs/reference/ssh-session-partition-move.md carries the argument and the N+1 checklist, including the fleet condition that gates it.