mirror of
https://github.com/stablyai/orca.git
synced 2026-09-29 16:02:50 +00:00
The audit record claimed a declarative registry prototype covered Tasks, Files, and Session and proved metadata, grants, and typed calls can be generated. No prototype existed: bridge-operation-registry.ts was an operation-name list with a capability enum and a membership check, consumed only by bridge-contract.ts and one test. Withdraw the claim, reopen the checklist item, and add a 2026-09-01 addendum recording the cleanup this branch landed, referenced by merge subject. Also correct three factual conflicts with the code: - The rollback runbook told support to direct users to the retained native workspace route while its own Safety Invariants said the hybrid candidate has no such fallback. Scope that step to the native-default build, since isRetiredNativeWorkspaceRoute redirects every /h/... workspace route to /hybrid in a hybrid build. - The architecture reference described the Android network fence as load blocking only, omitted that a sub-threshold WebView process restart now retires the capability broker, and did not say that the Android bridge accepts a message on the origin host derived from activeSessionId with the fragment as a secondary check. Name the build scripts that run each delivery step while there. - The remaining-work tracker did not record that the native store suites now run in CI, or that hosted-mobile-webview-ssh.spec.ts is excluded from the ubuntu e2e lane because no hosted runner has a simulator and Docker at once. mobile/README.md needed no change: every entrypoint in its e2e and native store tables resolves to a real script. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb