v0.22.0
·
1141 commits
to agent-main
since this release
What's Changed
- [qa-sweep] orbit mcp init/remove never name the checkout they wrote, so registry-resolved writes land silently elsewhere by @orbit-agent-01 in #1929
- [qa-sweep] orbit run ship TASK-ID reports success when the named task is excluded, and no human-readable surface says why by @orbit-agent-01 in #1930
- [qa-sweep] task export/import/reindex --workspace cannot name a task-registry workspace id, so the documented import recipe lands tasks the target host cannot read by @orbit-agent-01 in #1931
- [code-review] the GitShim child-process fixture passes vacuously when its hand-written test-name literal goes stale by @orbit-agent-01 in #1932
- [code-review] tool enable/disable now refuses every registry-inactive builtin, stranding an already-disabled one and breaking its CLI wrapper with no recovery by @orbit-agent-01 in #1933
- [qa-sweep] doctor's missing-task-registry guard never fires, so --fix-orphan-task-stores still deletes live task bundles by @orbit-agent-01 in #1934
- [code-review] orbit mcp init/remove let the current directory outrank an explicit --root, silently writing MCP config into the wrong checkout by @orbit-agent-01 in #1935
- [code-review] doctor's orphan-task-store check treats a stale task-registry binding as a claim, so it never reports the leftovers it exists for by @orbit-agent-01 in #1936
- Owner-wins cross-host task sync: import policy that overwrites only foreign-prefix bundles by @orbit-agent-01 in #1937
- [code-review] the new mcp init/remove summary names the checkout even under --scope home, where nothing is written there by @orbit-agent-01 in #1939
- [auto-task] Doc duties — validate the least-recently-validated docs by @orbit-agent-01 in #1940
- [code-review] orbit mcp init/remove refuse a shared Orbit root outright, so a multi-checkout --root layout can no longer register MCP at all by @orbit-agent-01 in #1938
- Delivered task worktrees (≈13 GB each with target/) linger up to 2 h after done+merged; reclaim them at delivery instead of relying on hourly GC by @orbit-agent-01 in #1941
- orbit-search install test fixture accepts exactly one connection, so companion_install_streams_a_slow_one_mebibyte_download flakes under load by @orbit-agent-01 in #1942
- [code-review] owner-wins sync wedges permanently if a mirror's bundle directory is missing: every later run fails and lands nothing by @orbit-agent-01 in #1943
- [code-review] doctor deletes a populated task-store partition whenever the bound checkout is momentarily unreachable, destroying its task bundles by @orbit-agent-01 in #1944
- Auto-task SkipIfOpen dedupe counts a 'someday' instance as open, silently blocking every later mint of that auto-task by @orbit-agent-01 in #1945
- [code-review] the orphan-task-store repair still reports "empty" partitions after it started deleting populated ones by @orbit-agent-01 in #1946
- Fix red CI on agent-main: worktree_gc_routing test still expects the pre-ORB-12140 'older_than_hours: 24' seeded default by @orbit-agent-01 in #1947
- [code-review] a workspace registered without a checkout (every cross-host import mirror) lost its partition claim, so doctor warns about it forever by @orbit-agent-01 in #1948
- [qa-sweep] orbit mcp init --claude writes config paths Claude Code does not read, so the Orbit MCP server is never registered by @orbit-agent-01 in #1949
- [qa-sweep] after task-index loss in the external-root layout, the checkout's own tasks vanish silently and
orbit task reindexrefuses to rebuild them by @orbit-agent-01 in #1950 - [qa-sweep] owner-wins import fails with a raw "task bundle already exists" error when the task index is lost, and the failed run still leaves the source workspace registered by @orbit-agent-01 in #1951
- [qa-sweep] a checkout deleted without teardown is undiagnosable and unreclaimable: doctor calls its task partition claimed and workspace remove refuses every selector by @orbit-agent-01 in #1952
- [friction-curation] Honor an explicit workspace selector in migrate --dry-run by @orbit-agent-01 in #1953
- [code-review] epic_pipeline worktrees are never reclaimed: delivery cleanup and the (now 1 h) GC backstop cannot derive an epic worktree's path by @orbit-agent-01 in #1954
- [code-review] dashboard still counts a
somedayauto-task instance as an open duplicate, contradicting the scheduler's skip_if_open rule by @orbit-agent-01 in #1955 - Fix red CI on agent-main: init_report::requested_mcp_records_none_detected_when_no_providers_exist returns 'configured' on every push since 5d821d0 by @orbit-agent-01 in #1956
- ci-failure-sweep files duplicate repairs: it ignores an existing repair task for the same failing runs unless it filed it, and files one task per failing job for a single failing test by @orbit-agent-01 in #1957
- [code-review] owner-wins import overwrites a local-prefix task whose registry binding is missing by @orbit-agent-01 in #1958
- [qa-sweep] Flaky under load:
update::tests::stage::rollback_replaces_a_running_executable_atomicallyspawns a freshly copied executable without the ETXTBSY retry ORB-11340 added elsewhere by @orbit-agent-01 in #1959 - [qa-sweep]
orbit workspace removestill refuses a deleted checkout: its positional collides with the global--workspacearg, so the runtime binds to the workspace being removed by @orbit-agent-01 in #1960 - [code-review]
orbit mcp init/remove --claude --scope homerewrites all of~/.claude.jsonwith an unlocked, non-atomic write by @orbit-agent-01 in #1961 - [qa-sweep]
orbit doctor --fix-orphan-task-storeshelp still promises "partitions that still hold task bundles are never deleted" while the repair deletes them by @orbit-agent-01 in #1962 - [qa-sweep]
make testfails at HEAD: the ORB-12158 dashboard assertion looks for "Open duplicate No" but the harness DOM renders "Open duplicateNo" by @orbit-agent-01 in #1964 - [qa-sweep]
orbit task listreports a lost task index asinvalid_input, rendering "invalid input:" inside the recovery sentence by @orbit-agent-01 in #1965 - [qa-sweep] In the shared external-root layout a deleted checkout's task partition is claimed forever:
workspace initwrites no checkout binding, so doctor can never classify it stale by @orbit-agent-01 in #1966 - [code-review] the repo's tracked
.claude.jsonis dead after the MCP path revert, andorbit mcp init --claudenow deletes it by @orbit-agent-01 in #1967 - task.update --context accepts file: selectors that do not exist in the checkout, so a typo silently ships a task with dead context by @orbit-agent-01 in #1968
- orbit task list silently truncates at --limit (default 50) with no notice or total, hiding older open tasks by @orbit-agent-01 in #1969
- [code-review] ORB-12170 left two
orbit_dirdescriptions of the task-partition evidence rule stale, one of them inside the runbook it updated by @orbit-agent-01 in #1970 - [code-review] ci-failure-sweep: a completed repair silently suppresses a later recurrence of the same named test for 30 days by @orbit-agent-01 in #1971
- [code-review]
orbit mcp init/remove --claude --scope homelocks~/..claude.json.lock, not Claude Code's~/.claude.json.lock, so the ORB-12165 lock excludes nothing by @orbit-agent-01 in #1972 - CI push runs check out the branch tip (github.ref_name) instead of github.sha, so queued runs test a different commit than the one they report on by @orbit-agent-01 in #1973
- Fix red CI on agent-main: ORB-12168 context-selector validation runs inside core add_task/update_task and breaks 5 orbit-core tests that seed fixture tasks by @orbit-agent-01 in #1974
- [code-review]
orbit task list --jsonsilently changed from a bare array to an object envelope, breaking the frozen per-command--jsonbyte contract by @orbit-agent-01 in #1975 - [qa-sweep] The ORB-12168 selector guard validates against the registered checkout, so a job-run worktree agent cannot declare a file it just created by @orbit-agent-01 in #1976
- [qa-sweep]
task add --workspace-pathcanonicalizes context selectors against a sub-directory that is never persisted, so every reader resolves them from the wrong root by @orbit-agent-01 in #1977 - [qa-sweep] The ORB-12177 truncation fix landed only on the CLI: MCP
orbit.task.liststill silently caps at 50 with no total, no truncated flag, and different ordering by @orbit-agent-01 in #1978 - [qa-sweep] The ORB-12168 context-selector guard skips the dashboard API: POST/PATCH /api/tasks still accept selectors the CLI and MCP tools reject by @orbit-agent-01 in #1979
- [code-review]
orbit task list --jsontruncates silently again: the truncation notice never reaches a json/ndjson caller by @orbit-agent-01 in #1980 - [code-review]
orbit tool run orbit.task.list --fields id,titlereturns{}: the ORB-12195 envelope broke top-level field projection by @orbit-agent-01 in #1981 - [qa-sweep]
orbit.task.addstill validates context selectors against a workspace sub-path, so the MCP tool both stores dead selectors and rejects valid ones by @orbit-agent-01 in #1982 - [code-review] The
orbit task listtruncation notice now prints above the table instead of after it by @orbit-agent-01 in #1983 - [code-review] After ORB-12208 the whole
workspace_pathselector-root path is dead:normalize_workspace_pathis unreachable and its error names a dashboard field that no longer exists by @orbit-agent-01 in #1984 - [code-review] ORB-12211 left two vestigial test remnants of the removed
TaskAddParams::workspace_path: an orphan comment that still promises the field's guarantee, and an assertion that now proves nothing by @orbit-agent-01 in #1985 - [qa-sweep] The ORB-12168 context-selector guard never checks a
symbol:selector's symbol, sosymbol:<existing file>#<typo>:fnships dead on every surface by @orbit-agent-01 in #1986 - [qa-sweep] Every
--workspacecommand calls a registered-but-invalidworkspace an "unknown workspace selector", so the deleted checkout ORB-12150 made diagnosable is still uninspectable by @orbit-agent-01 in #1987 - [qa-sweep]
make testfails at HEAD: ORB-12215 changed three MCP tool parameter descriptions without regeneratingmcp_tools_list.jsonby @orbit-agent-01 in #1988 - [qa-sweep] With a shared external Orbit root, a call from outside the checkout validates context selectors against
parent(<orbit-root>), so real selectors are rejected and data-directory paths are stored by @orbit-agent-01 in #1989 - [friction-curation] Warn task authors that an acceptance criterion outside the task's workspace cannot be satisfied in a managed run by @orbit-agent-01 in #1990
- [friction-curation] Correct the QA-sweep guidance that produces unusable or false validation evidence by @orbit-agent-01 in #1991
- [qa-sweep]
orbit workspace removere-hides the orphan task partition ORB-12170 just made visible: doctor flips back took, the confirmed repair reclaims nothing, and the task bundles are stranded by @orbit-agent-01 in #1992 - [friction-curation] Count worktree status from untrimmed porcelain output by @orbit-agent-01 in #1993
- [friction-curation] Flag an over-attached task-pilot context proposal instead of applying it silently by @orbit-agent-01 in #1994
- [friction-curation] Bound an interactive orbit init prompt when stdin is open but never answers by @orbit-agent-01 in #1996
- [ci-failure-sweep] Fix red CI: CI / Coverage (informational) / Collect workspace coverage by @orbit-agent-01 in #1997
- docs(design): clock consolidation — one host tick for routines and auto-tasks, no host pins, no source role by @orbit-agent-01 in #1995
- [friction-curation] Name the task-store partition id distinctly from the workspace-registry id by @orbit-agent-01 in #1999
- docs(design): cite ORB-12233 as the clock-consolidation implementation task by @orbit-agent-01 in #1998
- task-pilot: stop returning
unassessedcomplexity when selectors and rationale are already established by @orbit-agent-01 in #2001 - [ci-failure-sweep] Fix red CI: CI / Check / Clippy / Test / Run CI guardrails by @orbit-agent-01 in #2002
- docs(design): cite ORB-12236/ORB-12237 for the clock consolidation split by @orbit-agent-01 in #2000
- Dashboard: inline-edit task complexity, description, tags, acceptance criteria, and context_files by @orbit-agent-01 in #2003
- [code-review] ORB-12232 added an
## UnreleasedCHANGELOG bullet during task execution, which RELEASING.md forbids and no guardrail catches by @orbit-agent-01 in #2004 - [code-review] The documented pre-review gate misses checked-in goldens: three of this window's merges were CI-failure repairs for help/description snapshot drift by @orbit-agent-01 in #2005
orbit run ship-sweep --dry-runreportsready backlog: 0for a workspace whoserun readinesslists eligible tasks by @orbit-agent-01 in #2006- Orbit/orb 12254 6aa4c606 by @danieljhkim in #2007
task locks: anunknowncaller mayreservebut notreleaseits own reservation;locks listcounts0 task(s)for a task-bound reservation by @orbit-agent-01 in #2008- Orbit/orb 12246 6aa4c5c8 by @danieljhkim in #2009
- Clock consolidation (1/2): remove routine
hosts:pins and[routines] role = "source"by @orbit-agent-01 in #2010 orbit.task.addaccepts unregisteredrequired_tools, then the field is immutable — the task can never be admitted or repaired by @orbit-agent-01 in #2011- [code-review]
--workspaceresolution saves the global registry outsidewith_registry_lock, so a concurrentworkspace initregistration can be lost by @orbit-agent-01 in #2012 - Shipped
friction-curationtemplate and an error message tell agents to runorbit.friction.resolve, a tool that is deliberately hidden from the registry by @orbit-agent-01 in #2013 orbit audit listshows 1,727deniedrows withtool,kind, anderrorall null — denials carry no reason by @orbit-agent-01 in #2014orbit.agent.invokeshould surface the effective provider sandbox and warn when it isdanger-full-accessby @orbit-agent-01 in #2015config show/config get --scope workspacereport a workspaceconfig.tomlthat does not exist;workspace showJSON hascheckout.owner_machine_id: nullby @orbit-agent-01 in #2017- Run records are inconsistent: worker-spawned runs persist no steps, routine fires are audited as
cli, state is spelledsucceededvssuccessby @orbit-agent-01 in #2018 - Search:
doctorflags unembedded docs; hybridmodereflects what ran;--pathJSON listsskipped_kinds[ORB-12259] by @orbit-agent-01 in #2016 - macOS sandbox hides keychain-backed provider logins (Copilot, Cursor); runs fail auth with no diagnosis by @orbit-agent-01 in #2019
- Human-driven surfaces record actor
unknown: bareorbit task add/archive/update --approve, operation grants, lock reservations, auto-task definitions by @orbit-agent-01 in #2020 - Review gate downgrades a fully-repaired, green review to
incompletewhen a reviewer repair touches a path outsidecontext_files, instead of widening the selectors it already permits the reviewer to widen by @orbit-agent-01 in #2021 orbit.task.artifact.getCLI surfaces (orbit tool run,orbit task artifact get) still resolveidcwd-locally, contradicting the "resolved globally by default" schema text by @orbit-agent-01 in #2022doctorand clock status are blind to a sweep unit that runs a different Orbit binary; a sweep that loads zero workspaces exits 0 by @orbit-agent-01 in #2023- Minted auto-tasks carry
complexity: "unassessed", a value the task enums reject;dedupehas three spellings across CLI, file, and show by @orbit-agent-01 in #2024 orbit tool run orbit.task.add/updatereturn thin projections while MCP returns the full task; unknown input keys are silently dropped by @orbit-agent-01 in #2025- Withdraw all orbit.operation.* verbs from the MCP surface by @orbit-agent-01 in #2026
- [ci-failure-sweep] Fix red CI: CI / Coverage (informational) / Collect workspace coverage by @orbit-agent-01 in #2027
- CLI polish from the 0.21.0 sweep:
job showprints Rust Debug for fan-in, staleif_revisionreturnsinternal_error,doctorgives three different remediations for stale auto-tasks,tool scaffold qa.echoregistersqaby @orbit-agent-01 in #2028 orbit.task.updateaccepts anystatusvalue with no lifecycle guard:proposed → doneanddone → proposedboth succeed by @orbit-agent-01 in #2029- Restore managed workspace resolution with a read-only global registry by @orbit-agent-01 in #2031
- [ci-failure-sweep] Fix red CI: CI / Check / Clippy / Test / Run CI guardrails by @orbit-agent-01 in #2032
- Land on-call review settings and strengthen the preparation crew by @orbit-agent-01 in #2033
- [BLOCKED] [code-review]
neutralize_inner_sandbox's doc comment was orphaned ontoapply_trusted_host_provider_sandbox, describing the opposite behavior by @orbit-agent-01 in #2030 - [code-review] Authorization audit rows record the OS username in
role, so denial-by-role aggregation fragments per account by @orbit-agent-01 in #2034 - [code-review]
invoke_and_waitadvertisesstatus: succeededbut the runtime now emitssuccess, so a workflow author's gate condition never matches by @orbit-agent-01 in #2035 - Refresh workspace friction-curation override so new tasks use current agent tools and skill guidance by @orbit-agent-01 in #2036
- [code-scanning-sweep] Fix rust/path-injection in crates/orbit-registry/src/workspace_registry/io.rs by @orbit-agent-01 in #2037
- [friction-curation] Attribute retired config warnings to the layer that contains the key by @orbit-agent-01 in #2038
- [auto-task] Doc duties — validate the least-recently-validated docs by @orbit-agent-01 in #2039
- [code-review]
triage_failed_runs' only authorized transition (blocked → done) is now refused by the task lifecycle table by @orbit-agent-01 in #2041 - COPILOT_DEFAULT_MODEL pins
claude-sonnet-4.5, which Copilot CLI 1.0.84 rejects; runs fail with an unsurfaced--modelerror by @orbit-agent-01 in #2042 - Split application/job/pipeline.rs (2.8k lines) into a pipeline/ module by concern by @orbit-agent-01 in #2043
- [code-review]
config get --scope Xandconfig show --scope Xnow report different values for the same unset key by @orbit-agent-01 in #2044 - Use the bounded ETXTBSY test helper for the provider PATH-resolution launcher fixture by @orbit-agent-01 in #2045
- [code-review] Synthetic gate/skip wait results still emit
status: "succeeded", a value the narrowedinvoke_and_waitoutput enum no longer declares by @orbit-agent-01 in #2046 - Clock consolidation (2/2):
orbit clocktick evaluates routines and auto-tasks in-process; retire the auto-task scheduler routine/job/activity by @orbit-agent-01 in #2047 - Limit dashboard status choices and undo to valid task lifecycle transitions by @orbit-agent-01 in #2048
- Recover detached worker startup from bounded SQLite contention and identify the failed store by @orbit-agent-01 in #2049
- Recover delivery review/QA consumers after settings changes without losing coverage debt by @orbit-agent-01 in #2050
- [code-review] Update stale gate integration expectation for canonical synthetic wait success by @orbit-agent-01 in #2051
- Remove redundant orbit.task.approve and orbit.task.start MCP tools in favor of orbit.task.update by @orbit-agent-01 in #2052
- [code-review] Remove artificial SQLite write admission and validate real worker bootstrap contention by @orbit-agent-01 in #2053
- Align nested ship supervision timeouts with admission and supported worker budgets by @orbit-agent-01 in #2054
- Fix Clippy drain_collect failure in automation recovery checkpoint test by @orbit-agent-01 in #2055
- Show per-task auto-drain readiness reasons and blockers in the dashboard by @orbit-agent-01 in #2056
- Host-registry overview still assigns identity DTOs to orbit-common by @orbit-agent-01 in #2057
- Extract PipelineWorkerSupervisor from OrbitRuntime's worker lifecycle methods by @orbit-agent-01 in #2058
- Add audited delivery history replay recovery after legitimate rebases by @orbit-agent-01 in #2059
- Distinguish unavailable native clock manager from a paused clock by @orbit-agent-01 in #2060
- Refresh all workspace-scoped dashboard state after a cross-workspace task jump by @orbit-agent-01 in #2061
- Stabilize and document the friction.list JSON response contract by @orbit-agent-01 in #2062
- Commit managed retirement of workspace auto-task scheduler by @orbit-agent-01 in #2063
- Make clock pause refuse an unavailable native manager by @orbit-agent-01 in #2065
- Guard orphan finalization with durable provider descendants by @orbit-agent-01 in #2067
- [ci-failure-sweep] Fix red CI: CI / Check / Clippy / Test / Run CI guardrails by @orbit-agent-01 in #2068
- Isolate web routine tests from native clock manager availability by @orbit-agent-01 in #2069
- [BLOCKED] Isolate workspace-init git subprocess tests from shared process state by @orbit-agent-01 in #2066
- Record successful provider completion before post-exit run reconciliation by @orbit-agent-01 in #2071
- Serialize provider-return SQLite refresh behind the shared writer mutex by @orbit-agent-01 in #2072
- Restore managed read-only task and search access to the authoritative SQLite store by @orbit-agent-01 in #2073
- [code-review] Lease the validated canonical SQLite path for in-root runtime aliases by @orbit-agent-01 in #2074
- Repair managed SQLite CannotOpen after WAL lease deployment using actual envelope evidence by @orbit-agent-01 in #2075
- Preserve unresolved orphan debt when replaying equivalent delivery history by @orbit-agent-01 in #2070
- [qa-sweep]
orbit config show --scope effective --jsonlistsexecution.env.inheritundersettings, butorbit config get execution.env.inheritrejects it as an unknown config key by @orbit-agent-01 in #2076 - [qa-sweep] ORB-12292 gated the dashboard
archivebutton onstatus_transitions, sodoneandrejectedtasks — the only ones worth archiving — no longer offer archive in the UI by @orbit-agent-01 in #2077 - [qa-sweep] ORB-12268's
orbit.task.updatelifecycle routing refuses every field edit alongsidestatus: backlog/in-progress, mislabels a plainsomeday -> backlogedit as the "guarded approval transition", and blocks the one-call plan+transition the CLI still accepts by @orbit-agent-01 in #2078 - [code-review] Systemd bus-unavailable diagnostic is misclassified as a disabled clock, reintroducing the false "paused" report by @orbit-agent-01 in #2081
- feat(dashboard): lead the task detail side column with details by @danieljhkim in #2079
- [qa-sweep]
orbit clock tick --dry-runreportserror — automation_deferred: evidence_unavailablefor disabled delivery auto-tasks that the real tick reports asdisabledby @orbit-agent-01 in #2082 - [auto-task] Doc duties — validate the least-recently-validated docs by @orbit-agent-01 in #2083
- [code-review]
orbit.task.updatepicks the guarded start body by payload shape, so an unrelated field edit bypasses the pickup-state refusal by @orbit-agent-01 in #2084 - workspace teardown: require an explicit <workspace_id> argument instead of resolving the target from cwd by @orbit-agent-01 in #2085
- [friction-curation] Make test-build-budget hermetic when nested under build-budget.py by @orbit-agent-01 in #2086
- [auto-task] Doc duties — validate the least-recently-validated docs by @orbit-agent-01 in #2087
- Delivery auto-task consumers: add
auto-task reset, and self-healhistory_divergedvia automatic replay proof + friction instead of silent per-tick deferral by @orbit-agent-01 in #2088 - Prepare v0.22.0 release by @orbit-agent-01 in #2089
Full Changelog: v0.21.0...v0.22.0