mirror of
https://github.com/stablyai/orca.git
synced 2026-10-01 00:02:10 +00:00
* feat(agents): add first-class DeepSeek Harness (dsh) support Register DSH as a supervised Orca agent: catalog entry and detection for its dsh-tui profile, status/question hooks through DeepSeek's own Claude-Code hook bridge, composer-ready prompt delivery, session resume, headless Source Control AI, and title identity that no longer collides with Gemini's. * fix(dsh): reach Orca through DSH's credential scrub and stop reading its title as Gemini DSH runs command hooks through its own shell executor, which drops every env var whose name contains KEY, TOKEN, SECRET or PASSWORD — taking ORCA_PANE_KEY and ORCA_AGENT_LAUNCH_TOKEN with it, so every hook exited without posting. Mirror both onto scrub-safe aliases at spawn and restore them at the top of the DSH hook script. Its title collided too: DSH rests on the same glyph Gemini works on, so a resting DSH pane was relabelled Gemini CLI and reported working forever. Defer both the Gemini classifier and the title status detector on DSH's whale, in the base module both copies of that classifier read. * test(mobile): repin the session-route closure for the DSH agent icon * fix(dsh): address review — never splice user rows, cover remote panes, keep the diff off argv - findManagedDshPatchRegion paired an orphan start marker with a later block's end, so a truncated write made install/remove delete the user's own rows. Pair each end with the nearest preceding start; regression test fails without the fix. - The relay PTY env builder never applied the scrub-safe aliases, so remote DSH status silently never appeared even with the remote hook installed. - Source Control AI sent the whole diff on argv; send it over stdin with DSH's '-' marker. - dsh-tui/dst already chose the interactive profile, so a workspace folder named 'web' or 'plugin' no longer marks a live agent pane non-interactive. - Isolate USERPROFILE as well as HOME so a Windows run cannot edit the real home. - Drop the duplicate README badge and revert an incidental doc reformat. * refactor(dsh): share the managed-hooks reader and tighten the new modules Reuse before reimplementing: readManagedDshHookEvents was a near-verbatim copy of Muse's, with byte-identical private helpers. Both now call one readManagedHookEventsFromJson. Also: one readTextOrAbsent instead of two spellings of the same read (dropping an existsSync TOCTOU), one status() builder instead of four inline literals, rmSync(force) instead of exists-then-unlink, and a redundant empty-string guard before JSON.parse. The patch-file transforms lose their index juggling for a predicate plus a filter. * fix(dsh): refuse a flow-style patch file, keep its mode, and stop the relay inheriting a pane - applyManagedDshPatch matched only an exact `[]`, so `[] # keep empty` or a non-empty flow sequence got a block entry appended after it — invalid YAML that would leave DSH unable to load the user's own patch layer either. It now strips the token from an empty sequence (keeping a trailing comment) and returns null for a non-empty one; install reports that and changes nothing. - The patch rewrite dropped an owner-only file to the umask default (CWE-732); pass preserveMode. - The relay PTY env never dropped inherited pane identity the way the local and daemon builders do, so a spawn that specified none could inherit the relay's own and every agent's hook would report against that pane. * fix(dsh): keep the flow-style refusal in every status read, and scope the mode test to POSIX A refused patch file carries no managed region, so getStatus() fell through to a bare not_installed with detail null — the actionable 'rewrite it as a block sequence' message only ever reached the one-shot install() return. Export the predicate and check it first, behind one shared message constant. The owner-only mode assertion cannot hold on Windows, where chmod only toggles the read-only attribute and mode & 0o777 reads 0o666 for any writable file. * docs(readme): restore the DeepSeek Harness badge lost in the rebase * test(mobile): repin the session-route closure to the measured 4221 Measured, not derived: 4220 without the DSH icon entry, 4221 with it. Two of the three modules above main's 4218 pin are not this change's — they arrived with the mobile work after #22570 and were never repinned; the changelog records that split explicitly. * fix(dsh): settle tui-idle on the agent's own hook, so supervised workers see it ready Reported by a tester on the adhoc build: `terminal wait --for tui-idle` ran to its 90s timeout against an already-ready DSH composer, so a supervised worker never sees the agent as ready. Every existing tier reads the title, and DSH deliberately carries no title status: its rest prefix is Gemini's working glyph, so the detector reports none. A fresh first-party `done` is better evidence than any title anyway — it is the agent's own account of its own turn, and normalizeDshEvent drops subagent events, so it is the lead's. Scoped to DSH: for agents whose hooks report child turns, a mid-turn `done` is the #6011 class this file prevents. * test(daemon): record the DSH transcript's true-colour I2 divergences Adding the dsh-tui capture to __fixtures__ enrolled it in the serialize replay sweep, where it reports 10 I2 divergences and failed the unlisted-transcript default of 0. Every one is the same shape — visible-grid row=0, a 24-bit background the round trip does not restore to default — which is DSH's whale intro painting whole rows of true colour. Verified as an upstream limitation rather than a regression by replaying against the previous build (build-serialize-addon-at-ref.mjs --ref origin/main): I1 and I3 both hold. * fix(dsh): return the new tui-idle verdict from the first-party done lane Main refactored isTuiIdleSatisfied into evaluateTuiIdle, which returns a verdict rather than a boolean. The DSH lane still returned `true`; it is tier-1 positive evidence, so it returns READY_STRONG like the title/body lane above it. Re-verified the regression test still fails without the lane. * test(relay): pin the scrub-safe pane-identity aliases on the relay spawn path The relay builds a remote pane's env itself, so the alias mirroring there had no test: removing the call left every suite green while remote DSH status silently vanished. Both cases fail without it. * docs(dsh): point the hook service at the integration reference The reference doc had no inbound link from anywhere in the repo.
248 lines
14 KiB
JSON
248 lines
14 KiB
JSON
{
|
|
"extends": "@electron-toolkit/tsconfig/tsconfig.node.json",
|
|
"include": [
|
|
"../src/cli/**/*",
|
|
"../src/shared/**/*",
|
|
"../src/main/agent-state-file-reader.ts",
|
|
"../src/main/agent-hooks/grok-replay-guard.ts",
|
|
"../src/main/claude/hook-script.ts",
|
|
"../src/main/claude/claude-session-end-hook-capability.ts",
|
|
"../src/main/agent-hooks/hook-stdin-contract.ts",
|
|
"../src/main/agent-hooks/hook-post-command.ts",
|
|
"../src/main/agent-hooks/hook-config-write-path.ts",
|
|
"../src/main/agent-hooks/hooks-json-read.ts",
|
|
"../src/main/agent-hooks/installer-utils.ts",
|
|
"../src/main/agent-hooks/installer-utils-remote.ts",
|
|
"../src/main/agent-hooks/local-agent-cli-presence.ts",
|
|
"../src/main/agent-hooks/managed-toml-ownership.ts",
|
|
"../src/main/agent-hooks/managed-agent-hook-controls.ts",
|
|
"../src/main/agent-hooks/managed-agent-hook-registry.ts",
|
|
"../src/main/agent-hooks/managed-hook-script-refresh.ts",
|
|
"../src/main/agent-hooks/managed-hooks-json-events.ts",
|
|
"../src/main/agent-hooks/posix-hook-command.ts",
|
|
"../src/main/agent-hooks/runtime-home-hook-command.ts",
|
|
"../src/main/orca-profiles/profile-storage-paths.ts",
|
|
"../src/main/orca-profiles/profile-index-store.ts",
|
|
"../src/main/orca-profiles/profile-telemetry-consent-seed.ts",
|
|
"../src/main/orca-profiles/profile-legacy-state-import.ts",
|
|
"../src/main/persistence/profile-state/profile-state-migration.ts",
|
|
"../src/main/persistence/profile-state/profile-state-database-publication.ts",
|
|
"../src/main/persistence/profile-state/profile-state-database.ts",
|
|
"../src/main/persistence/profile-state/profile-state-database-errors.ts",
|
|
"../src/main/persistence/profile-state/profile-state-database-validation.ts",
|
|
"../src/main/persistence/profile-state/profile-state-database-schema.ts",
|
|
"../src/main/persistence/profile-state/profile-state-documents.ts",
|
|
"../src/main/persistence/profile-state/legacy-json/profile-state-json-acceptance.ts",
|
|
"../src/main/persistence/profile-state/profile-state-revision.ts",
|
|
"../src/main/persistence/profile-state/profile-state-read-snapshot.ts",
|
|
"../src/main/persistence/profile-state/profile-state-sqlite-authority.ts",
|
|
"../src/main/persistence/profile-state/legacy-json/profile-state-authority-exports.ts",
|
|
"../src/main/persistence/profile-state/profile-state-complete-replacements.ts",
|
|
"../src/main/persistence/profile-state/profile-state-revision-readmission.ts",
|
|
"../src/main/persistence/profile-state/profile-state-writer-protocol.ts",
|
|
"../src/main/persistence/loading-store/profile-state-authority.ts",
|
|
"../src/main/persistence/profile-state/profile-state-automation-runs-migration.ts",
|
|
"../src/main/persistence/profile-state/profile-state-document-reader.ts",
|
|
"../src/main/persistence/profile-state/profile-state-document-validation.ts",
|
|
"../src/main/persistence/profile-state/profile-state-domain-writes.ts",
|
|
"../src/main/persistence/profile-state/profile-state-write-transaction.ts",
|
|
"../src/main/persistence/profile-state/profile-state-domain-write-validation.ts",
|
|
"../src/main/persistence/profile-state/profile-state-domain-reader.ts",
|
|
"../src/main/persistence/profile-state/profile-state-automation-runs.ts",
|
|
"../src/main/persistence/profile-state/profile-state-automation-runs-model.ts",
|
|
"../src/main/persistence/profile-state/profile-state-automation-runs-payload.ts",
|
|
"../src/main/persistence/profile-state/profile-state-automation-runs-reader.ts",
|
|
"../src/main/persistence/profile-state/profile-state-automation-runs-storage.ts",
|
|
"../src/main/persistence/profile-state/profile-state-automation-runs-validation.ts",
|
|
"../src/main/persistence/profile-state/profile-state-automation-runs-writer.ts",
|
|
"../src/main/persistence/profile-state/profile-state-offline-settings.ts",
|
|
"../src/main/persistence/profile-state/legacy-json/profile-state-export-path.ts",
|
|
"../src/main/persistence/profile-state/legacy-json/profile-state-legacy-backup-path.ts",
|
|
"../src/main/persistence/profile-state/profile-state-backup-path.ts",
|
|
"../src/main/persistence/profile-state/profile-state-backup-rotation.ts",
|
|
"../src/main/persistence/profile-state/profile-state-backup-job.ts",
|
|
"../src/main/persistence/profile-state/profile-state-backup-worker.ts",
|
|
"../src/main/persistence/profile-state/profile-state-backup-worker-entry.ts",
|
|
"../src/main/worker-thread-entry-path.ts",
|
|
"../src/main/persistence/profile-state/profile-state-database-snapshot.ts",
|
|
"../src/main/persistence/profile-state/profile-state-database-recovery.ts",
|
|
"../src/main/persistence/profile-state/profile-state-recovery-required.ts",
|
|
"../src/main/persistence/profile-state/legacy-json/profile-state-recovery.ts",
|
|
"../src/main/persistence/profile-state/profile-state-recovery-copy.ts",
|
|
"../src/main/persistence/profile-state/profile-state-recovery-command.ts",
|
|
"../src/main/orca-profiles/profile-project-move-record.ts",
|
|
"../src/main/orca-profiles/profile-project-domain-changes.ts",
|
|
"../src/main/persistence/profile-state/profile-state-active-location.ts",
|
|
"../src/main/persistence/profile-state/profile-state-access.ts",
|
|
"../src/main/persistence/profile-state/profile-state-access-owner.ts",
|
|
"../src/main/persistence/profile-state/profile-state-access-identity.ts",
|
|
"../src/main/windows-native-registry.ts",
|
|
"../src/main/windows/windows-command-line-recovery-health.ts",
|
|
"../src/main/windows/windows-process-table.ts",
|
|
"../src/main/windows/windows-process-table-cim-scan.ts",
|
|
"../src/main/daemon/daemon-process-start-time.ts",
|
|
"../src/main/daemon/daemon-process-identity-query.ts",
|
|
"../src/main/startup/startup-diagnostics.ts",
|
|
"../src/main/persistence/profile-state/legacy-json/profile-state-versioned-export.ts",
|
|
"../src/main/persistence/profile-state/profile-state-backup-temporary-files.ts",
|
|
"../src/main/persistence/profile-state/profile-state-database-quarantine.ts",
|
|
"../src/main/persistence/profile-state/profile-state-storage-classification.ts",
|
|
"../src/main/durable-file-write.ts",
|
|
"../src/shared/secure-file.ts",
|
|
"../src/main/sqlite/harden-database-files.ts",
|
|
"../src/main/startup/http1-compatibility-marker.ts",
|
|
"../src/main/startup/http1-compatibility-profile-state.ts",
|
|
"../src/main/agent-hooks/windows-direct-cmd-hook-command.ts",
|
|
"../src/main/agent-hooks/windows-powershell-hook-launcher.ts",
|
|
"../src/main/amp/agent-status-plugin-source.ts",
|
|
"../src/main/amp/hook-service.ts",
|
|
"../src/main/amp/managed-plugin-install-status.ts",
|
|
"../src/main/antigravity/hook-events.ts",
|
|
"../src/main/antigravity/hook-script.ts",
|
|
"../src/main/antigravity/hook-service.ts",
|
|
"../src/main/antigravity/hooks-json-bundle.ts",
|
|
"../src/main/claude/hook-settings.ts",
|
|
"../src/main/claude/hook-service.ts",
|
|
"../src/main/claude/statusline-script.ts",
|
|
"../src/main/claude-accounts/keychain.ts",
|
|
"../src/main/macos-keychain/generic-password.ts",
|
|
"../src/main/codex/codex-app-server-capability-cache.ts",
|
|
"../src/main/codex/codex-app-server-capability-signal.ts",
|
|
"../src/main/codex/codex-app-server-client.ts",
|
|
"../src/main/codex/codex-app-server-process-tree-kill.ts",
|
|
"../src/main/codex/codex-app-server-record-reader.ts",
|
|
"../src/main/codex/codex-app-server-session.ts",
|
|
"../src/main/codex/codex-config-mirror.ts",
|
|
"../src/main/codex/codex-config-path-reference-rewrite.ts",
|
|
"../src/main/codex/codex-config-settings-preservation.ts",
|
|
"../src/main/codex/codex-config-settings-removal.ts",
|
|
"../src/main/codex/codex-config-settings-upsert.ts",
|
|
"../src/main/codex/codex-daemon-socket-path-guard.ts",
|
|
"../src/main/codex/codex-home-paths.ts",
|
|
"../src/main/codex/codex-hook-definition.ts",
|
|
"../src/main/codex/codex-managed-home-resource-copy-marker.ts",
|
|
"../src/main/codex/codex-managed-trust-grant-plan.ts",
|
|
"../src/main/codex/codex-path-observation.ts",
|
|
"../src/main/codex/codex-hook-identity.ts",
|
|
"../src/main/codex/codex-hook-legacy-cleanup.ts",
|
|
"../src/main/codex/codex-hook-local-install.ts",
|
|
"../src/main/codex/codex-hook-local-maintenance.ts",
|
|
"../src/main/codex/codex-hook-remote-install.ts",
|
|
"../src/main/codex/codex-hook-script.ts",
|
|
"../src/main/codex/codex-hook-service-implementation.ts",
|
|
"../src/main/codex/codex-hook-status.ts",
|
|
"../src/main/codex/codex-hook-system-trust.ts",
|
|
"../src/main/codex/codex-hook-trust-cleanup.ts",
|
|
"../src/main/codex/codex-hook-trust-grant.ts",
|
|
"../src/main/codex/codex-hook-trust-queue.ts",
|
|
"../src/main/codex/codex-hook-user-mirroring.ts",
|
|
"../src/main/codex/codex-hook-wsl-runtime.ts",
|
|
"../src/main/codex/codex-managed-trust-reconciliation.ts",
|
|
"../src/main/codex/codex-process-exit-deadline.ts",
|
|
"../src/main/codex/codex-state-db.ts",
|
|
"../src/main/codex/codex-trust-identity.ts",
|
|
"../src/main/codex/codex-trust-config-rollback.ts",
|
|
"../src/main/codex/codex-trust-config-mutation-queue.ts",
|
|
"../src/main/codex/codex-trust-grant-telemetry.ts",
|
|
"../src/main/codex/codex-trust-grant-host.ts",
|
|
"../src/main/codex/codex-trust-grant-ledger.ts",
|
|
"../src/main/codex/codex-user-hook-trust-rebase-client.ts",
|
|
"../src/main/codex/codex-user-hook-trust-rebase.ts",
|
|
"../src/main/codex/codex-wsl-hook-install-plan.ts",
|
|
"../src/main/codex/config-settings-baseline.ts",
|
|
"../src/main/codex/config-settings-conflict-resolution.ts",
|
|
"../src/main/codex/config-plugin-registration-promotion.ts",
|
|
"../src/main/codex/config-toml-plugin-registration-tables.ts",
|
|
"../src/main/codex/config-toml-promoted-setting-values.ts",
|
|
"../src/main/codex/config-settings-promotion.ts",
|
|
"../src/main/codex/config-settings-promotion-write-target.ts",
|
|
"../src/main/codex/config-sync-stall.ts",
|
|
"../src/main/codex/config-toml-atomic-write.ts",
|
|
"../src/main/codex/config-toml-deprecated-hook-flag.ts",
|
|
"../src/main/codex/config-toml-hook-trust-blocks.ts",
|
|
"../src/main/codex/config-toml-hook-trust-edit.ts",
|
|
"../src/main/codex/config-toml-hook-trust-read.ts",
|
|
"../src/main/codex/config-toml-key-path.ts",
|
|
"../src/main/codex/config-toml-line-scan.ts",
|
|
"../src/main/codex/config-toml-mcp-servers.ts",
|
|
"../src/main/codex/config-toml-project-trust.ts",
|
|
"../src/main/codex/config-toml-runtime-owned-sections.ts",
|
|
"../src/main/codex/config-toml-syntax.ts",
|
|
"../src/main/codex/config-toml-trust.ts",
|
|
"../src/main/codex/hook-service.ts",
|
|
"../src/main/codex/hook-trust-promotion.ts",
|
|
"../src/main/codex/managed-home-shell-preflight.ts",
|
|
"../src/main/codex-accounts/fs-utils.ts",
|
|
"../src/main/codex-accounts/wsl-codex-command.ts",
|
|
"../src/main/codex-cli/command.ts",
|
|
"../src/main/command-code/command-code-managed-script.ts",
|
|
"../src/main/command-code/hook-service.ts",
|
|
"../src/main/copilot/copilot-managed-hook-definitions.ts",
|
|
"../src/main/copilot/copilot-managed-script.ts",
|
|
"../src/main/copilot/copilot-remote-hook-install.ts",
|
|
"../src/main/copilot/hook-service.ts",
|
|
"../src/main/cursor/hook-events.ts",
|
|
"../src/main/cursor/hook-script.ts",
|
|
"../src/main/cursor/hook-service.ts",
|
|
"../src/main/droid/hook-service.ts",
|
|
"../src/main/gemini/hook-service.ts",
|
|
"../src/main/grok/grok-hook-config.ts",
|
|
"../src/main/grok/grok-hook-config-cleanup.ts",
|
|
"../src/main/grok/grok-hook-config-file.ts",
|
|
"../src/main/grok/grok-hook-owners.ts",
|
|
"../src/main/grok/grok-hook-remote-install.ts",
|
|
"../src/main/grok/grok-hook-script.ts",
|
|
"../src/main/grok/grok-hook-symlink-cleanup-marker.ts",
|
|
"../src/main/grok/hook-service.ts",
|
|
"../src/main/grok/windows-grok-hook-script.ts",
|
|
"../src/main/devin/hook-settings.ts",
|
|
"../src/main/devin/hook-service.ts",
|
|
"../src/main/devin/hook-config-json.ts",
|
|
"../src/main/hermes/hermes-config-document.ts",
|
|
"../src/main/hermes/hermes-config-source-edits.ts",
|
|
"../src/main/hermes/hermes-config-yaml.ts",
|
|
"../src/main/hermes/hermes-home-filesystem.ts",
|
|
"../src/main/hermes/hermes-managed-plugin-source.ts",
|
|
"../src/main/hermes/hook-service.ts",
|
|
"../src/main/git-bash.ts",
|
|
"../src/main/in-flight-run-dedupe.ts",
|
|
"../src/main/kimi/hook-service.ts",
|
|
"../src/main/kimi/kimi-hook-config-toml.ts",
|
|
"../src/main/dsh/dsh-home-patch.ts",
|
|
"../src/main/dsh/hook-service.ts",
|
|
"../src/main/dsh/hook-settings.ts",
|
|
"../src/main/muse/hook-config-json.ts",
|
|
"../src/main/muse/hook-service.ts",
|
|
"../src/main/muse/hook-settings.ts",
|
|
"../src/main/zcode/hook-config-json.ts",
|
|
"../src/main/zcode/hook-service.ts",
|
|
"../src/main/zcode/hook-settings.ts",
|
|
"../src/main/openclaude/hook-service.ts",
|
|
"../src/main/rolling-file-backup.ts",
|
|
"../src/main/startup/hydrate-shell-path.ts",
|
|
"../src/main/startup/windows-shell-path-ownership.ts",
|
|
// Why: serve-electron-flag-parity.test.ts checks the Electron-side serve argv rewrite against this
|
|
// project's serve spec; the module has no imports, so listing it pulls in nothing else.
|
|
"../src/main/startup/serve-mode-argv.ts",
|
|
// The parity test keeps this import-free list aligned with COMMAND_SPECS.
|
|
"../src/main/startup/cli-command-names.ts",
|
|
"../src/main/runtime/runtime-metadata.ts",
|
|
"../src/main/sqlite/sync-database.ts",
|
|
"../src/main/sqlite/bun-readonly-wal.ts",
|
|
"../src/main/sqlite/sqlite-statement.ts",
|
|
"../src/main/sqlite/sqlite-integer-reader.ts",
|
|
"../src/main/sqlite/node-sqlite-statement.ts",
|
|
"../src/main/sqlite/bun-sqlite-statement.ts",
|
|
"../src/main/sqlite/bun-sqlite-database.ts",
|
|
"../src/main/win32-utils.ts"
|
|
],
|
|
"compilerOptions": {
|
|
"composite": true,
|
|
// TypeScript 7 removed node10 resolution; Node16 preserves CommonJS emit for this package.
|
|
"module": "Node16",
|
|
"moduleResolution": "Node16",
|
|
"rootDir": "../src",
|
|
"outDir": "../out"
|
|
}
|
|
}
|