Brennan Benson 31f103535f fix(orchestration): serve a /clear'd native-chat worker through the session running it (#25875)
* fix(orchestration): serve a /clear'd structured worker through the session running it

A structured (native chat) worker the user /clear'd keeps working in a
successor session, but orchestration kept acting on the session it was
started with, which the clear had closed. Terminal read and @idle status
lost the handle, worker-read and the release archive served the pre-clear
transcript, worker-show reported the worker exited, worker-stop closed the
already-closed session and left the successor running, mail and Dispatch
nudges were refused, and the idle sweep could put the successor to rest
while its Dispatch was open.

One forward walk over the durable session records now answers which
session runs a worker's conversation. Worker authority and custody are
judged on that session, so every caller holding a worker handle gets it by
default; reads, archive, observation, status, group addressing and the
incarnation liveness probe use it too. Stop closes the running session and
re-resolves, so a clear that commits while the close waits is followed to
its successor. The reverse direction (a successor's child env, user
takeover, the idle sweep) maps a session to its worker through the
lineage root. A successor's idle edge re-derives the worker's Dispatch
mailbox, and settlement forgets parked mail on every session of the
lineage, derived rather than stored.

When the running session cannot be found (host not installed, a
successor with no record, a looping chain) observation answers
unverifiable, never exited; readers refuse with session_caller_not_live
and stop closes nothing. worker-read and the archive warn that earlier
conversation from before a /clear is not included.

* fix(orchestration): close the review gaps in serving a /clear'd structured worker

Review of the first change found places where a /clear'd worker still
went wrong, plus a type gap that let the original bug shape compile:

- worker-stop refused a structured worker whose old session read
  exited mid-clear (stopped, but the successor not yet committed); it
  now goes to the clear-aware stop once identity and ownership are
  proven. The terminal (PTY) gate is unchanged.
- A worker stopped while its /clear successor had never run could never
  be released: no close writes death evidence for an agent that never
  started, so the probe read unverifiable forever. A released session
  that never started anything and whose chat is gone now reads exited;
  it stays unverifiable while the chat is listed.
- worker-read, terminal read and the release archive now read the
  worker's whole lineage, oldest session first, under the same page
  limit and byte bound, instead of only the running session. This
  replaces the "earlier conversation is not included" warning. Cursors
  key later sessions' items by session, so a cursor taken before a
  clear stays valid and continues into the successor.
- Pointer delivery re-derives a mailbox's target when an attempt ends;
  if a /clear moved it meanwhile, it delivers once to the new session.
- Custody and status reads take the resolved running session, and one
  typed hold (held, not held, unverifiable) replaces the rebuilt
  authority in terminal read, worker-show and group addressing.
- Smaller fixes: stop keeps an earlier close on its receipt; abandoning
  a side task no longer forgets the worker's parked mail; a release
  whose lineage cannot be verified ends release_unknown instead of
  staying requested forever; mail reach reports an unverifiable lineage
  as unverifiable, not ended; party resolution scans records once.

A /clear typed into a worker's chat is reported as a user takeover, the
same as any other message the user types there; a test pins it.

* fix(orchestration): tighten the never-ran rule and the follow-ups to /clear handling

Round-2 review of the /clear'd structured worker fixes found that the new
rule for "a session no agent ever ran is exited" was too loose, and two
of the new follow-ups missed a case:

- The rule now requires the founding fence, which every reservation
  moves. A reservation that a restart released without proof, or a
  failed first start whose exit was never proven, stays unverifiable
  instead of reading exited. It no longer asks whether the
  conversation is open (any history read opens it, which stranded a
  stop, read, release sequence), and it treats only an authoritative
  tab index without the chat as retired.
- Pointer delivery follows a mailbox a /clear moved on a thrown attempt
  too, keeping the attempt's own failure, and tries each session once.
- Releasing a retired worker whose newest session cannot be read keeps
  the readable earlier sessions' output and says the latest one was
  lost, instead of freezing an empty archive.
- worker-show judges status and addressability on one lineage walk.
- The worker-stop comment says plainly that any structured worker that
  reads exited (a crashed agent too) is closed and its chat hidden;
  tests cover that and a takeover reported by the successor session.

* fix(orchestration): keep a retired worker's earliest readable output across several lost sessions

Releasing a worker whose chat was retired and whose newest session
could not be read kept the earlier sessions' output only when exactly
one later session was lost; after two clears with both later journals
gone, release still froze an empty archive although the first session
held the worker's answer. The archive now walks back past every
unreadable later session, under the same page limit, and its warning
says how many later sessions could not be preserved.

The rule that reads a never-started session as exited also requires
that the record carries no fence floor: a copy restored from backup
may hide a reservation that the backup lost, so it stays unverifiable.

* test(orchestration): build the takeover test's session record from the shared fixture

The changed-code quality gate rejected the test's `as unknown as
AgentSessionRecord` stub, which this branch had touched. It now builds a
real record with agentSessionRecordFixture and a typed lease, so no
type assertion is needed.

* test(orchestration): give the cleared-worker pointer harness the sender-name dependency main added
2026-10-06 16:20:45 -07:00
2026-09-26 20:50:46 +00:00
2026-05-04 20:42:03 -07:00
2026-03-16 22:27:51 -07:00
2026-03-28 10:19:14 -07:00

Orca Orca

GitHub stars Total downloads across all releases License: MIT Join the Orca Discord Follow Orca on X Supported platforms: macOS, Windows, and Linux

中文 · 日本語 · 한국어 · Español · Français · Português

The AI Orchestrator for 100x builders.
Run Codex, ClaudeCode, OpenCode or Pi side-by-side — each in its own worktree, tracked in one place.

Download Orca

Orca desktop app running agents in parallel worktrees, with the Orca mobile companion app in the corner

Features

Mobile Companion

Monitor and steer your agents from your phone — get notified when an agent finishes and send follow-ups from anywhere.

iOS App Store · Android APK 0.0.52 · Docs →

Orca desktop with the mobile companion app

Parallel Worktrees

Fan one prompt across five agents, each in its own isolated git worktree — compare the results and merge the winner.

Docs →

Parallel worktree orchestration

Terminal Splits

Ghostty-class terminals with WebGL rendering, infinite splits, and scrollback that survives restarts.

Docs →

Terminal splits

Design Mode

Click any UI element in a real Chromium window to send its HTML, CSS, and a cropped screenshot straight into your agent's prompt.

Docs →

Embedded browser and Design Mode

GitHub & Linear, Native

Browse PRs, issues, and project boards in-app — open a worktree from any task and review without a context switch.

Docs →

GitHub and Linear task workflows in Orca

SSH Worktrees

Run agents on a beefy remote box with full file editing, git, and terminals — auto-reconnect and port forwarding included.

Docs →

Remote worktrees over SSH

Annotate AI Diffs

Drop comments on any diff line and ship them back to the agent — review, edit, and commit without leaving Orca.

Docs →

Annotate AI-generated diffs

Drag Files to Agents

VS Code's editor with autosave everywhere — drag files or images straight into an agent prompt.

Docs →

Drag files and images into an agent prompt

Orca CLI

Agents drive Orca too — script every workflow with orca worktree create, snapshot, click, and fill.

Docs →

Script Orca from the CLI

Also in the box:

  • Quick open — Search across worktrees, files, agents, commands, and repo context without leaving your flow.
  • Account switcher & usage tracking — See Claude and Codex usage and rate-limit resets, and hot-swap accounts without re-logging in.
  • Rich repo previews — Preview Markdown, images, PDFs, and repo docs in the workspace.
  • Computer Use — Let agents operate desktop apps and visible UI when a workflow needs real interaction.
  • Notifications and unread state — Know when an agent finishes or needs attention, then mark threads unread to come back later.
  • And many, many more — we ship daily, so this list is perpetually behind. The changelog is the real feature list.

Supported Agents

Works with any CLI agent — if it runs in a terminal, it runs in Orca.

Claude Code logo Claude Code   Codex logo Codex   Grok logo Grok   Cursor logo Cursor   GitHub Copilot logo GitHub Copilot   Muse logo Muse   DeepSeek Harness logo DeepSeek Harness   ZCode logo ZCode   OpenCode logo OpenCode   MiMo Code logo MiMo Code   Amp logo Amp   OpenClaude logo OpenClaude   Antigravity logo Antigravity   Pi logo Pi   oh-my-pi logo oh-my-pi   Hermes Agent logo Hermes Agent   Devin logo Devin   Goose logo Goose   Auggie logo Auggie   Autohand Code logo Autohand Code   Charm logo Charm   Cline logo Cline   CodeBuddy logo CodeBuddy   Codebuff logo Codebuff   Freebuff logo Freebuff   Command Code logo Command Code   Continue logo Continue   Droid logo Droid   Kilocode logo Kilocode   Kimi logo Kimi   Kiro logo Kiro   Mistral Vibe logo Mistral Vibe   Qwen Code logo Qwen Code   Rovo Dev logo Rovo Dev   + any CLI agent


Install

Desktop — macOS, Windows, Linux

Or via a package manager:

# macOS (Homebrew)
brew install --cask stablyai/orca/orca

# Arch Linux (AUR) — or stably-orca-git to build from source
yay -S stably-orca-bin

Mobile Companion — iOS, Android

Pair with your desktop app to monitor and steer your agents from your phone.


Community & Support

  • Discord: Join the community on Discord.

  • Twitter / X: Follow @orca_build for updates and announcements.

  • WeChat: Scan to join the Orca community WeChat group 11.

    WeChat group 11 QR code for the Orca community
  • Feedback & Ideas: We ship fast. Missing something? Request a new feature.

  • Privacy: See the privacy & telemetry docs for what anonymous usage data Orca collects and how to opt out.

  • Show Support: Star this repo to follow along with our daily ships.


Developing

Want to contribute or run locally? See our CONTRIBUTING.md guide.

The relay that pairs the mobile app with a desktop host is also in this repository under cloud/, with a separate pnpm workspace and setup guide.

Orca contributors

GitHub star history chart for stablyai/orca

Signed Builds

Windows code signing sponored/provided by SignPath.io, certificate by SignPath Foundation.

License

Orca is free and open source under the MIT License.

S
Description
Orca is the ADE for working with a fleet of parallel agents. Run any coding agent with your own subscription. Available on desktop, mobile and remote runtime.
Readme MIT
2 GiB
Languages
TypeScript 95.4%
JavaScript 3.9%
Swift 0.2%
HCL 0.1%
CSS 0.1%