You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Provider responses must now contain visible non-whitespace assistant text or at least one valid tool call; empty, whitespace-only, reasoning-only, usage-only, truncated, filtered, and contradictory completions fail visibly instead of silently ending a turn.
Active provider generation now has a ten-minute total deadline in addition to the existing connection and inactivity timeouts.
The total generation deadline is preserved across connection and stream_options compatibility retries; deterministic localhost coverage keeps the stream active while proving the original deadline still wins.
Tool-loop finalization now has a distinct Finalizing safely state, retains the safety trigger reason, explains denied post-finalization tool calls accurately, and gives explicit non-replay continuation guidance.
Raw file patches now verify retained proposal integrity before Apply and reread, hash-check, and revalidate exact destination bytes after replacement.
Verified replacement now has explicit not-committed, committed, committed-with-cleanup-warning, and recovery-failure outcomes across file, scene, Input Map, main-scene, and ProjectSettings mutations.
The About page can copy a strict-allowlist diagnostic report containing Orca/Godot versions and coarse provider/request state without credentials, endpoint addresses, project data, conversation content, model output, logs, or file changes.
Plan turns can request one explicit, turn-bound transition to Work mode when the user asked for implementation or execution. Approval continues the same task with Work tools on the next provider request; rejection remains in Plan, and every project mutation still requires its normal separate approval.
Runtime loop detection now ignores elapsed-time and observation-cursor churn, warns before the tool-round boundary, gives each observation a recommended next action, and performs one controller-owned cleanup of an exact same-turn Orca process before safe finalization.
stop_game now returns bounded final run output, diagnostics, state, and verification evidence so routine cleanup does not require another diagnostics round.
Multi-call tool batches are now limited to known independent read-only operations. Work-mode requests, task updates, reviewed mutations, process control, observations, verifications, and unknown tools require singleton batches and are rejected atomically otherwise.
Successful task updates now refresh exactly one request-scoped checklist before continuation or finalization, while failed and cleared updates preserve or remove that context correctly.
Completed tool turns that exceed the full-schema context budget now attempt one no-tools safe finalization; if that cannot fit, Orca emits a deterministic sanitized local checkpoint containing only bounded receipts, tasks, and coarse cleanup outcome.
Automatic finalization cleanup is now bound to the exact active run ID launched in that turn, exposes only a fixed coarse outcome, and cannot stop a newer replacement run. Bounded stop_game evidence explicitly labels omitted diagnostics and truncated output tails.
Fixed
Fixed DeepSeek-compatible reasoning-only or empty completions removing the working state without displaying an answer or error.
Fixed empty tool-loop finalization responses ending without a visible outcome.
Fixed file-patch recovery states hiding the guarded Revert action.
Fixed committed writes being reported as failed when private-backup cleanup failed, and fixed uncertain replacement failures being reported or persisted as successful mutations.
Cleanup-only warnings no longer weaken typed live-state conflict checks; recovery-copy guidance is retained as bounded project-relative session metadata.
Fixed delayed stream and terminal callbacks from an older provider request being able to mutate a newer controller turn or chat UI state. Tool follow-ups now receive distinct provider request IDs while retaining one turn ID.
Fixed synchronous workflow and terminal signal handlers being able to launch an orphan request or have an ending turn clear ownership belonging to a reentrantly started turn.
Fixed plain Enter being silently swallowed while a request is active; follow-up drafts now remain editable and survive matching completion, failure, and cancellation while Stop remains explicit.
Fixed Expanded Diff retaining exclusive window ownership while Apply or Reject synchronously triggered editor work, which could collide with Godot reload or confirmation dialogs.
Tests
Added empty, whitespace-only, reasoning-only, tool-only, truncated, filtered, and terminal-ownership transport regressions.
Added real GDScript patch lifecycle coverage and exact duplicate class/local variable validation regressions.
Added tool-loop trigger, finalization-state, denied-provider-text, explicit-continuation, and empty-finalization coverage.
Added transport, compatibility-probe, controller, and chat-window ownership regressions for stale and duplicate callbacks, follow-up identity, cancellation, and synchronous configuration failures.
Added thinking/finalizing cancellation, terminal reentry, duplicate history/usage/message, and stale second-step probe failure/cancellation regressions.
Added active-composer, real Stop-button, draft-preservation, stale-control-state, request diagnostic lifecycle, and adversarial diagnostic privacy regressions.