* feat(relay): fence and drain file and git response streams on shutdown Third T1 slice of the #16741 port: the relay's two detached stream producers can now be fenced and awaited, not just flagged. RelayStreamRegistry (fs.readFileStream): - disposeAll permanently fences register/beginOperation (relay_file_stream_shutdown_fenced), waits for every close and for every admitted operation, and rejects with relay_file_stream_shutdown_incomplete while any handle is still unclosed, so a later disposeAll retries only the failed handles. - release coalesces concurrent callers onto one close, tolerates only EBADF as already-closed, and keeps a failed-close entry (aborted) for retry. - beginOperation / releaseUnregisteredHandle let work that opens a handle before registration be drained too (wired in the next commit). GitResponseStreamRegistry: disposeAll fences startStream (relay_response_stream_shutdown_fenced); disposeAllAndWait also awaits every scheduled or in-flight pump, and an aborted pump no longer publishes git.responseEnd after its final chunk write settles. reserveTerminalFrameSlot moves unchanged into fs-stream-terminal-frame-slots and now holds a registry operation per slot, so shutdown also waits for undelivered fs.streamEnd/fs.streamError frames. No wire change: no new methods, fields, or opcodes. Mixed versions are unaffected; a fenced relay answers with an ordinary request error. Porting note (source: #16741 heada68b6f3531, merge-base 277c289bd4; T1 per the track manifest): - Taken verbatim: fs-stream-registry delta, git-response-stream delta, fs-stream-registry-shutdown.test, git-response-stream-shutdown.test. - Adapted: Promise.withResolvers replaced with plain promises (the relay bundle targets node18). fs-stream-terminal-frame-slots is extracted from the reserveTerminalFrameSlot that main already has inline in fs-handler-file-read (keeping its rationale comment) rather than added as a second copy. The EBADF check uses a type guard instead of a cast, and the tests' stub casts carry SAFETY rationales. - Dropped: nothing. * feat(relay): drain detached file and git response streams with owned processes Wires the stream registries into relay shutdown. The dispatcher's RelayWorkAdmission drain (#24181) ends once fs.readFileStream answers its metadata or a handler answers a git response-stream sentinel; the pumps and file descriptors behind those answers are detached producers it does not see. RelayRuntimeServices.disposeOwnedProcesses now also awaits GitResponseStreamRegistry.disposeAllAndWait and FsHandler.disposeFileStreams, and rejects with relay_owned_process_shutdown_incomplete if either fails, so the grace lifecycle defers shutdown (its existing catch path) instead of exiting with an unclosed fd; the next attempt retries only failed handles. fs.readFileStream now holds a registry operation across metadata preparation (including the binary-prefix probe handle) and across each pump, closes pre-registration handles through releaseUnregisteredHandle, releases its terminal-frame slot even when the handle close fails, and publishes no terminal frame for a stream that was aborted or went stale while its last read was in flight. Behavior today: the grace/SIGTERM shutdown path already calls disposeOwnedProcesses after PTY disposal, so a shutdown now also waits for in-flight stream pumps and queued terminal frames (which settle on client close or dispatcher disposal). After disposal, stream requests are refused with a fenced error; if shutdown is deferred by a failed close, the relay stays up with streams fenced, matching #16741's one-way drain. No wire change. Porting note (source: #16741 heada68b6f3531, merge-base 277c289bd4; these files are T2 in the track manifest, taken here only as far as the stream drain needs them): - Taken verbatim: fs-handler-file-read delta, fs-handler-utils isBinaryFilePrefix releaseHandle parameter, fs-handler disposeFileStreams. - Adapted: relay-runtime-services takes only the responseStreams field and the response/file-stream drains in disposeOwnedProcesses. Skill-upload and AI Vault cleanup stay log-and-continue rather than joining the aggregate failure. Added a fs-handler-stream test proving disposeFileStreams waits for an undelivered terminal frame and fences new reads. - Dropped (left for T2): agentExecHandler disposal, disposeWatchers, the ownership-transfer adapter/capture wiring, and the relay-grace-lifecycle beginWorkDrain -> disposeOwnedProcesses -> beginWorkDrain sequence. * test(relay): cover the stream drains in disposeOwnedProcesses disposeOwnedProcesses now waits for the git response-stream and file-stream drains and rejects with relay_owned_process_shutdown_incomplete when either fails, but nothing exercised that path: relay-daemon tests stub the whole runtime. These tests pin that shutdown is not acknowledged before either drain settles, that both drain failures are aggregated after every owner was attempted (and a retry succeeds), and that skill/AI Vault failures stay log-and-continue in this slice. Porting note (source: #16741 heada68b6f3531, src/relay/relay-runtime-owned-process-shutdown.test.ts, T2 in the track manifest): - Taken: the prototype-stub fixture, the "does not acknowledge cleanup before %s have settled" case (responses, fileStreams), and the no-vault-service case. - Adapted: Promise.withResolvers replaced with a plain promise; the fixture cast carries a SAFETY rationale; the retry case targets the stream drains instead of skill/vault, and a new case pins skill/vault as log-and-continue to match this slice's adaptation. - Dropped (left for T2): agentExecHandler and disposeWatchers cases, and skill/vault aggregate-failure cases. --------- Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
Orca
中文 · 日本語 · 한국어 · Español · Français · Português
The AI Orchestrator for 100x builders.
Run Codex, ClaudeCode, OpenCode or Pi side-by-side — each in its own worktree, tracked in one place.
Download Orca
Features
Also in the box:
- Quick open — Search across worktrees, files, agents, commands, and repo context without leaving your flow.
- Account switcher & usage tracking — See Claude and Codex usage and rate-limit resets, and hot-swap accounts without re-logging in.
- Rich repo previews — Preview Markdown, images, PDFs, and repo docs in the workspace.
- Computer Use — Let agents operate desktop apps and visible UI when a workflow needs real interaction.
- Notifications and unread state — Know when an agent finishes or needs attention, then mark threads unread to come back later.
- And many, many more — we ship daily, so this list is perpetually behind. The changelog is the real feature list.
Supported Agents
Works with any CLI agent — if it runs in a terminal, it runs in Orca.
Claude Code
Codex
Grok
Cursor
GitHub Copilot
Muse
DeepSeek Harness
ZCode
OpenCode
MiMo Code
Amp
OpenClaude
Antigravity
Pi
oh-my-pi
Hermes Agent
Devin
Goose
Auggie
Autohand Code
Charm
Cline
CodeBuddy
Codebuff
Freebuff
Command Code
Continue
Droid
Kilocode
Kimi
Kiro
Mistral Vibe
Qwen Code
Rovo Dev
+ any CLI agent
Install
Desktop — macOS, Windows, Linux
- Download from onOrca.dev
- Or grab a build directly: macOS Apple Silicon · macOS Intel · Windows (.exe) · Linux AppImage · All builds
- Running
orca serveon a headless Linux server? See the headless Linux server guide.
Or via a package manager:
# macOS (Homebrew)
brew install --cask stablyai/orca/orca
# Arch Linux (AUR) — or stably-orca-git to build from source
yay -S stably-orca-bin
Mobile Companion — iOS, Android
Pair with your desktop app to monitor and steer your agents from your phone.
- iOS: Download on the App Store
- Android: Download APK 0.0.50 · Install guide
Community & Support
-
Discord: Join the community on Discord.
-
Twitter / X: Follow @orca_build for updates and announcements.
-
WeChat: Scan to join the Orca community WeChat group 11.
-
Feedback & Ideas: We ship fast. Missing something? Request a new feature.
-
Privacy: See the privacy & telemetry docs for what anonymous usage data Orca collects and how to opt out.
-
Show Support: Star this repo to follow along with our daily ships.
Developing
Want to contribute or run locally? See our CONTRIBUTING.md guide.
The relay that pairs the mobile app with a desktop host is also in this repository under
cloud/, with a separate pnpm workspace and setup guide.
Signed Builds
Windows code signing sponored/provided by SignPath.io, certificate by SignPath Foundation.
License
Orca is free and open source under the MIT License.










