v0.24.0
·
1118 commits
to agent-main
since this release
What's Changed
- fix(website): fix the hero session figure and refresh stale docs by @danieljhkim in #2259
- fix(deps): bump rmcp to 2.2.0 (GHSA-9g45-5xwm-f3wc) by @danieljhkim in #2260
- feat(website): lead the homepage with the agent-driven flow by @danieljhkim in #2262
- chore(deps): bump devalue from 5.8.2 to 5.9.2 in /website in the npm_and_yarn group across 1 directory by @dependabot[bot] in #2261
- fix(website): make the hero transcript readable by @danieljhkim in #2263
- docs(readme): lead with the agent-driven loop by @danieljhkim in #2264
- [auto-task] Doc duties — validate the least-recently-validated docs by @orbit-agent-01 in #2265
- [ci-failure-sweep] Fix red CI: CI / Coverage (informational) / Collect workspace coverage by @orbit-agent-01 in #2266
- [auto-task] Doc duties — validate the least-recently-validated docs by @orbit-agent-01 in #2267
- Align final-QA crew contract test with authorized Opus configuration by @orbit-agent-01 in #2268
- [code-review] Memoised bwrap probe pins a transient namespace failure for the process lifetime, permanently failing sandboxed dispatch by @orbit-agent-01 in #2269
- [security-review] Dashboard never validates the Host header, so DNS rebinding lets any website read every API GET by @orbit-agent-01 in #2270
- [qa-sweep]
orbit auto-task liston a TTY hides the STATE column when every definition is disabled by @orbit-agent-01 in #2271 - [ci-failure-sweep] Fix red CI: CI / Check / Clippy / Test / Run CI guardrails by @orbit-agent-01 in #2272
- [distributed-drain v1] Retire terminal failed-run triage while preserving authorized in-run recovery by @orbit-agent-01 in #2273
- [distributed-drain v1] Preserve declared missing-file context through task storage, projections and locks by @orbit-agent-01 in #2274
- [qa-sweep] GET /api/routines returns 500 when the systemd user bus is unavailable by @orbit-agent-01 in #2275
- [security-review] Env-value redaction misses AUTHORIZATION / AUTHZ / OAUTH variables: only a standalone AUTH segment counts as sensitive by @orbit-agent-01 in #2276
- [ci-failure-sweep] Fix red CI: CI / Check / Clippy / Test / Run CI guardrails by @orbit-agent-01 in #2277
- [qa-sweep] Make task-start provenance test deterministic under managed worker identity by @orbit-agent-01 in #2278
- [distributed-drain v1] Retire epic execution with safe legacy migration and retained task hierarchy by @orbit-agent-01 in #2279
- [code-review] Dashboard
/healthz?detailed=trueskips the Host gate, so DNS rebinding still reads workspace names and host paths by @orbit-agent-01 in #2280 - [distributed-drain v1] Establish recoverable task/reservation commit boundary before admission by @orbit-agent-01 in #2281
- [code-review]
orbit-coresweep tests fail intermittently under full-suite parallelism with an empty SweepOutcome by @orbit-agent-01 in #2282 - [code-review]
task lintreports a non-existent gate: empty context_files is an error citing an admission refusal that never fires by @orbit-agent-01 in #2283 - [friction-curation] Document that nested bwrap cannot create user namespaces inside agent-executor worktrees by @orbit-agent-01 in #2284
- [friction-curation] Document the python workaround for reading website/dist when Claude Read/grep denies generated output by @orbit-agent-01 in #2285
- [friction-curation] Document stage-attach-remove for QA evidence that lives outside workspace_root by @orbit-agent-01 in #2286
- [code-review] Epic root with inherited-only context is admitted unserialized, contradicting the retirement's "not eligible until repaired" promise by @orbit-agent-01 in #2287
- Keep persistent MCP clients usable across upgrades or refuse before schema changes strand them by @orbit-agent-01 in #2288
- [code-review] v20's migration doc comment was orphaned onto
apply_task_commit_journal, leaving v20 undocumented and v21 mis-described by @orbit-agent-01 in #2289 - [code-review]
show_workspace_claimmutates reservation rows outside the commit boundary by @orbit-agent-01 in #2290 - Remove website validation guidance that routes around a file-read permission denial by @orbit-agent-01 in #2291
- Add
skill-validationauto-task: recurring review and repair of the shipped Orbit skills by @orbit-agent-01 in #2292 - Resolve same-host cross-workspace dependencies consistently during task preparation and admission by @orbit-agent-01 in #2293
- [qa-sweep] HEAD generation pin requires a writable global root, so
--rootscratch init fails with EROFS in agent-executor sandboxes by @orbit-agent-01 in #2294 - ci-failure-sweep: bare head-SHA fingerprint lets any open task mentioning the commit suppress an unrelated CI failure by @orbit-agent-01 in #2296
- [friction-curation] Teach agents to confirm orbit.task.add with a compact id projection, not truncated JSON by @orbit-agent-01 in #2297
- [ci-failure-sweep] Fix red CI: CI / Coverage (informational) / Collect workspace coverage by @orbit-agent-01 in #2298
- Restore macOS sandboxed nested Orbit calls under executable-generation admission by @orbit-agent-01 in #2299
- Dashboard: Audit Summary 24h pane omits the tool call failure rate by @orbit-agent-01 in #2300
- feat(dashboard): regroup the auto-drain pane around what an operator can act on by @danieljhkim in #2295
- [distributed-drain v1] Add atomic distributed admission, durable claims and replayable receipts by @orbit-agent-01 in #2302
- [code-scanning-sweep] Fix rust/path-injection at 3 locations in crates/orbit-common/src/fs/generation.rs by @orbit-agent-01 in #2303
- orbit web connect: grant operator capability to the remote dashboard server by default by @orbit-agent-01 in #2304
- [ci-failure-sweep] Fix red CI: CI / Check / Clippy / Test / Run CI guardrails by @orbit-agent-01 in #2305
- feat(dashboard): move Auto-drain under Work beside Tasks by @danieljhkim in #2301
- feat(dashboard): one row vocabulary for Routines, Auto-tasks and a projected Jobs pane by @danieljhkim in #2306
- [ci-failure-sweep] Fix red CI: CI / Check / Clippy / Test / Run CI guardrails by @orbit-agent-01 in #2307
- Federated MCP:
orbit mcp serve --federated --operatorpropagates operator to every destination; remove destination-side caller authorization by @orbit-agent-01 in #2308 - [distributed-drain v1] Fence claim writes and add idempotent settlement, inspection and deliberate recovery by @orbit-agent-01 in #2309
- [code-scanning-sweep] Fix rust/path-injection at 4 locations in crates/orbit-common/src/fs/generation.rs by @orbit-agent-01 in #2310
- Restore artifact provenance build after caller authorization removal by @orbit-agent-01 in #2311
- [distributed-drain v1] Expose key-bound claim lifecycle APIs with read-only preflight and receipt lookup by @orbit-agent-01 in #2312
- fix: Recover a pending task-commit marker on job resume instead of refusing [ORB-12575] by @orbit-agent-01 in #2313
- [code-review]
orbit updateacquires generation admission on the host-global root while every client pins--root/ORBIT_ROOT, so an upgrade can replace the binary under live MCP clients by @orbit-agent-01 in #2314 - docs(plugin): require search-before-add only for finding-driven filings by @danieljhkim in #2315
- [distributed-drain v1] Accept typed handoffs and persist approval, revocation and landing-start requests by @orbit-agent-01 in #2316
- [code-review] Generation-root normalization round-trips the path through
to_string_lossy, silently rewriting non-UTF-8 roots and refusing legitimate..-containing component names by @orbit-agent-01 in #2318 - [code-review]
orbit.drain.probereportsadmits: truefor a call admission would refuse, andinvalid_inputfor fields the caller never declared by @orbit-agent-01 in #2320 - Refactor Orbit skills into task, orchestration and setup workflows by @orbit-agent-01 in #2319
- [distributed-drain v1] Route worker coordination to owner and propagate authenticated execution provenance by @orbit-agent-01 in #2321
- Migrate inline test block in tool_host/artifact_redaction.rs to sibling tests/ (440 lines) by @orbit-agent-01 in #2322
- Migrate inline test block in application/skill.rs to sibling tests/ (487 lines) by @orbit-agent-01 in #2323
- Migrate inline test block in bootstrap/activity.rs to sibling tests/ (831 lines) by @orbit-agent-01 in #2324
- [code-review]
orbit update --root/ORBIT_ROOTnow admits against the override root only, so it replaces ~/.orbit/bin/orbit under live host-global-pinned clients by @orbit-agent-01 in #2325 - Migrate inline test block in application/routine.rs to sibling tests/ (475 lines) by @orbit-agent-01 in #2327
- Migrate inline test block in bootstrap/init.rs to sibling tests/ (764 lines) by @orbit-agent-01 in #2330
- Weighted entries for complexity crew pools (name:weight) by @orbit-agent-01 in #2331
- [code-review]
orbit.drain.claimsis unreachable from every surface, so the documented operator recovery command always fails by @orbit-agent-01 in #2332 - Migrate 5 moderate inline test blocks (100–200 lines) to sibling tests/ by @orbit-agent-01 in #2328
- Batch-migrate 12 small inline test blocks (<100 lines) to sibling tests/ by @orbit-agent-01 in #2333
- [BLOCKED] [distributed-drain v1] Implement pull drain, unique leaf binding and exact local capacity accounting by @orbit-agent-01 in #2329
- [code-review] The drain read-only surface refuses every
orbit tool runcall because the CLI session carries no capabilities by @orbit-agent-01 in #2334 - Add
xhardtask complexity tier with its crew pool and a pilot escalation guard by @orbit-agent-01 in #2335 - [ci-failure-sweep] Fix red CI: macOS Platform / macOS Sandbox / Run executable-generation admission tests by @orbit-agent-01 in #2336
- [code-review] Any /proc probe failure in
current_worker_bindingaborts everyOrbitRuntime::openonce a worker binding table exists by @orbit-agent-01 in #2337 - [code-review] An unwritable host-global generation record fails
orbit update --rootonly after the executable is replaced by @orbit-agent-01 in #2338 - [code-review] A crew whose name contains
:can be defined and used, but putting it in a complexity pool now refuses every command in the workspace by @orbit-agent-01 in #2339 - [distributed-drain v1] Consume authorized owner handoffs and reconcile uncertain PR, local and no-diff landing by @orbit-agent-01 in #2340
- [code-review] The task pilot's complexity cap refuses a re-statement of an operator's
xhardand silently demotes it by @orbit-agent-01 in #2341 - [ci-failure-sweep] Fix red CI: CI / Coverage (informational) / Collect workspace coverage by @orbit-agent-01 in #2342
- Apply complexity crew pools to ordinary ship admission, not only
run autoby @orbit-agent-01 in #2343 - Core product identity groundwork and research composition fixture by @danieljhkim in #2344
- [distributed-drain v1] Executable claimed PR/owner-local leaf pipelines and real owner, launcher and handoff adapters by @orbit-agent-01 in #2345
- [code-review] A config that already names a crew with
:is bricked by the new crew-name check, with no CLI left that can remove it by @orbit-agent-01 in #2346 - [code-review] Owner landing judges containment against a remote-tracking ref it never fetches, so a stale
origin/<landing branch>stops valid landings by @orbit-agent-01 in #2347 - [code-review] A second owner landing attempt can never republish its merge intent, so a handoff whose first merge failed is stuck forever by @orbit-agent-01 in #2348
- [distributed-drain v1] Mixed legacy/claimed admission integration and end-to-end pull-drain acceptance fixtures by @orbit-agent-01 in #2349
- [code-review] Discovery-mode
orbit run ship --allow-crewstill excludes crew-less tasks against the default crew, so the pool routing ORB-12606 added never reaches auto mode by @orbit-agent-01 in #2350 - [code-review]
workflow.required_validation_commandsis the only config setting missing from the user-facing config reference by @orbit-agent-01 in #2351 - [code-review] Four claimed-leaf refusal messages carry an 18-space gap mid-sentence, so the operator-visible text is mangled by @orbit-agent-01 in #2352
- Dashboard: render task comments as a full-width Markdown thread with collapse by @orbit-agent-01 in #2353
- [code-review] A pr-mode claimed leaf can never validate:
pr_openpublishespr_numberas a JSON string anddelivery()reads it withas_u64by @orbit-agent-01 in #2354 - [code-review] The claimed leaf resolves its base branch without the run's sync mode, so a remote-sync (pr) claim compares
origin/<base>against the stale local<base>by @orbit-agent-01 in #2355 - Dashboard: move comment thread into the main column as a collapsible, scroll-capped block by @orbit-agent-01 in #2356
- Dashboard: right dock grows with the viewport, is resizable, and log lines / locked-file paths scroll horizontally instead of truncating by @orbit-agent-01 in #2357
- [code-review] Comment-outline
IntersectionObservers are never disconnected, so an open task detail leaks one observer set per 30 s refresh by @orbit-agent-01 in #2358 - [distributed-drain v1] Integrate complete claim lifecycle across explicit drains and retained ship-sweep entry points by @orbit-agent-01 in #2359
- [distributed-drain v1] Document setup and operator workflow in runbook, Orbit skill and website by @orbit-agent-01 in #2360
- [code-review] Shared drain occupancy counts unreconciled leaf runs, so one orphaned
task_pr_pipelinerow permanently eats a drain slot by @orbit-agent-01 in #2361 - [code-review] Dock width is clamped against the viewport, not the grid, so on an ultrawide display the splitter can squeeze the task list to zero and overflow the clipped pane by @orbit-agent-01 in #2362
- [code-review] The dock splitter takes the dock's grid cell, so
#side-dockis auto-placed into a second grid row on the Tasks tab by @orbit-agent-01 in #2363 - Worktree fingerprint fails on untracked symlinks: hash-object follows links instead of hashing link text by @orbit-agent-01 in #2364
- [code-review] A
#comment-hash makes every dashboard poll re-scroll and re-expand the comment thread by @orbit-agent-01 in #2365 - [code-review] Claimed leaf observation pins the live
origin/<base>tip, so a base advance during validation refuses a valid candidate by @orbit-agent-01 in #2366 - [auto-task] Doc duties — validate the least-recently-validated docs by @orbit-agent-01 in #2367
- [code-review] The new
setup/distributed-drain.mdskill reference is not inDEFAULT_SKILL_FILES, so six shipped skill files link to a file Orbit never installs by @orbit-agent-01 in #2368 - [distributed-drain v1] Show claim provenance and controlled handoff actions in dashboard by @orbit-agent-01 in #2369
- [friction-curation] Gate mcp_roundtrip Connection and SNAPSHOT_RELATIVE_PATH with the tests that use them by @orbit-agent-01 in #2370
- [friction-curation] git_commit already-landed path must accept a sibling-landed CI repair covering the same HEAD by @orbit-agent-01 in #2371
- [friction-curation] Writable auto-task CRUD in a managed worktree must write definition YAML to the worktree local_root by @orbit-agent-01 in #2372
- [friction-curation] orbit task reindex must skip empty stub bundle directories instead of failing the workspace closed by @orbit-agent-01 in #2373
- Task list and undispatched crew projections report default_crew instead of the run-recorded or pool-routed crew by @orbit-agent-01 in #2376
- [friction-curation] Add no-diff-expected to the skill-validation auto-task template so clean no-op runs can commit by @orbit-agent-01 in #2378
- [friction-curation] Make stale_companion doctor test hermetic against a host-managed search companion by @orbit-agent-01 in #2379
- [code-review] Distributed claim console cache survives a workspace switch, hiding the owner's handoff actions by @orbit-agent-01 in #2380
- [code-review] Dashboard "Recover claim" hardwires
blocked, so the documentedbacklogretry transition is unreachable by @orbit-agent-01 in #2381 - [code-review] orbit task reindex deletes any bundle directory missing task.yaml, including data-bearing partial copies by @orbit-agent-01 in #2382
- [code-review] Distributed claim console cache is repopulated by an in-flight read from the previous workspace by @orbit-agent-01 in #2383
- [code-review] Review gate mis-parses
git status -zrename records: phantom path downgrades the review, non-ASCII old path panics by @orbit-agent-01 in #2384 - [code-review]
orbit doctorstill classifies data-bearing bundle directories as empty stubs and prescribes a reindex that now refuses them by @orbit-agent-01 in #2385 - [code-review] no-diff-expected on the skill-validation auto-task silently discards a run whose worktree HEAD moved, stranding its corrections by @orbit-agent-01 in #2386
- [security-review] deny.toml carries three advisory exceptions that no longer match any crate, including a removed git2 dependency by @orbit-agent-01 in #2387
- [security-review] Vendored dashboard JS (DOMPurify 3.4.8, marked 18.0.5) has no dependency record or advisory monitoring by @orbit-agent-01 in #2388
- [code-review]
check-dashboard-vendor.pynever readspackage-lock.json, so the only artifact GitHub's security alerts see can drift or be deleted with CI green by @orbit-agent-01 in #2391 - [code-review]
no-diff-expectedbypasses the changed-HEAD guard for any HEAD, so an unreconcilable worktree is delivered asalready_committedby @orbit-agent-01 in #2392 - [security-review] Apply Dependabot bumps to vendored dashboard JS: DOMPurify 3.4.8 to 3.4.15, marked 18.0.5 to 18.0.13 by @orbit-agent-01 in #2393
- Skip minting the periodic code-review and qa-sweep auto-tasks when nothing changed since the last completed sweep by @orbit-agent-01 in #2394
- [code-review] Route the code-review auto-task as hard complexity via the pool instead of a medium task pinned to opus by @orbit-agent-01 in #2395
- [BLOCKED] Stop scaffolding ghost workspace dirs (.orbit/state/diagnostics, .orbit/knowledge) and drop their WorkspacePaths fields by @orbit-agent-01 in #2396
- Generation admission: admit read-only commands from a differing executable when the store schema matches by @orbit-agent-01 in #2397
- Tests: stop pinning operator config (auto-task complexity/crew/cron tables, prompt prose) — assert invariants only by @orbit-agent-01 in #2398
- [ci-failure-sweep] Fix red CI: CI / Coverage (informational) / Collect workspace coverage by @orbit-agent-01 in #2399
- Redesign
orbit config showtext output: grouped sections, per-key descriptions, honest provenance by @orbit-agent-01 in #2400 - Ship/auto/pilot default base branch ignores the registered workspace base_branch (uses [workflow] base_branch config) by @orbit-agent-01 in #2401
- Assign the pool-drawn crew at task creation, never on the backlog -> in-progress transition by @orbit-agent-01 in #2402
- Config: warn and ignore an invalid optional crew property (e.g. effort) instead of failing every command by @orbit-agent-01 in #2403
- Ignore all of
.orbit/in git: config.toml, routines, auto_tasks, resources become per-user, not repo-versioned by @orbit-agent-01 in #2404 - Remove the unused plugin/agents subagent definitions from the Claude plugin by @orbit-agent-01 in #2406
- Dashboard: add a Config tab (grouped effective settings, provenance, inline edit to the workspace file) by @orbit-agent-01 in #2405
- Dashboard Auto-drain view: pad the Operation Mode panel body and add a "Stop admissions" button for the live drain by @orbit-agent-01 in #2407
- context_files guard: auto-relax for a worker updating its own task from its worktree, and make the rejection name
allow_missing_contextby @orbit-agent-01 in #2408 - orbit init: drop the seeded custom and system crews, prompt for default_crew/system_crew by name, scaffold empty complexity pools by @orbit-agent-01 in #2409
- orbit.task.show: accept the
terminalfield selector and allowwith_contexttogether withfieldsby @orbit-agent-01 in #2410 - Remove workflow.pilot_max_complexity and the task-pilot complexity ceiling by @orbit-agent-01 in #2411
- Advertise friction tag vocabulary, title limit, complexity aliases in tool schemas; accept
noteon every status transition by @orbit-agent-01 in #2412 - fix: exclude no-diff-expected auto-tasks from automatic task-pilot discovery by @orbit-agent-01 in #2413
- Give workers a sanctioned run-scoped scratch dir (
.orbit/tmp/) thatorbit.task.artifact.putaccepts by @orbit-agent-01 in #2414 - [code-review] Read-only generation join refuses every command in a root with no orbit.db by @orbit-agent-01 in #2415
- [code-review] Dashboard config writes skip validate_for_set, persisting a crew property admission ignores by @orbit-agent-01 in #2416
- Fold host.toml into config.toml as [machine], drop
orbit host, and rename host→machine across the codebase by @orbit-agent-01 in #2417 - Seed task_pilot as a preparation_eligible state routine and make eligibility configurable by @orbit-agent-01 in #2418
- chore: move test fixtures off .orbit/resources and untrack it [ORB-12747] by @orbit-agent-01 in #2419
- Batch due preparation_eligible members into one task-pilot run by @orbit-agent-01 in #2420
- chore: stop blocking handoff on pre-existing baseline failures and AGENTS.md-contradicting criteria [ORB-12750] by @orbit-agent-01 in #2421
- refactor: remove the
orbit docscorpus feature [ORB-12741] by @orbit-agent-01 in #2422 - Remove the semantic search stack (companion, embeddings, hybrid, similar) while keeping FTS5 BM25 task search by @orbit-agent-01 in #2424
- fix: green the agent-main baseline (10 tests red since 2026-09-20 20:38) by @orbit-agent-01 in #2423
- [code-scanning-sweep] Fix rust/path-injection in crates/orbit-config/src/store.rs by @orbit-agent-01 in #2425
- [code-scanning-sweep] Fix rust/path-injection at 2 locations across 2 files by @orbit-agent-01 in #2426
- Plugin standard phase 1: plugin.yaml v2 manifest,
orbit pluginlifecycle, plugin tools reach MCP tools/list by @orbit-agent-01 in #2427 - Fix red CI: clippy needless_match in plugin_host.rs breaks
Run CI guardrailson agent-main by @orbit-agent-01 in #2428 - Fix red CI: codex implement prompt exceeds the 2500-token budget (representative_activity_prompts_fit_budget_and_preserve_contracts) by @orbit-agent-01 in #2429
- [code-scanning-sweep] Fix rust/path-injection in crates/orbit-config/src/lib.rs by @orbit-agent-01 in #2430
- [code-scanning-sweep] Fix rust/path-injection in crates/orbit-automation/src/routines/loader.rs by @orbit-agent-01 in #2431
- Plugin standard phase 2: grant enforcement, sandboxed exec backend with versioned envelope,
mcpbackend proxy by @orbit-agent-01 in #2432 - Restore the two agent_implement contract clauses dropped by the token-budget compaction (2 red tests on agent-main) by @orbit-agent-01 in #2433
- Plugin tool dispatch resolves its caller as
unknownin tests: CapabilityDenied reds agent-main on Linux and macOS by @orbit-agent-01 in #2434 - Partition task-pilot bundles by crew: mixed-crew eligible set deadlocks the state-driven pilot routine by @orbit-agent-01 in #2435
- Plugin standard phase 3: plugin definitions (activities, jobs, routines, auto-tasks), skills,
[plugins.<ns>]config,plugin.tool_callaction by @orbit-agent-01 in #2436 - Remove operation mode 1/4: dashboard panel, /api/operation/* and website content by @orbit-agent-01 in #2437
- Remove operation mode 2/4:
orbit operationCLI group,run auto --grant, and the orbit.operation.* tools by @orbit-agent-01 in #2438 - [security-review] [security] mcp plugin backend reuses a session across callers with different allowed_tools by @orbit-agent-01 in #2439
- [security-review]
orbit plugin add/synccopy_tree dereferences symlinks, so a plugin source can pull/proc/self/environor any readable file into the plugin root the sandbox lets the backend read by @orbit-agent-01 in #2440 - [security-review] Plugin
env_passcopies any parent variable by name, including the privilege-bearingORBIT_OPERATOR/ORBIT_WORKSPACE_CLAIM_TOKENthatallowlisted_child_envexcludes on purpose by @orbit-agent-01 in #2441 - Remove operation mode 3/4: governance module, application/operation/* and the grant checks in admission and recovery by @orbit-agent-01 in #2442
- [security-review] [security] ORBIT_ALLOWED_TOOLS is enforced by an environment variable the sandboxed child can unset by @orbit-agent-01 in #2443
- Remove operation mode 4/4: config keys, operation_grants table migration, docs and skills by @orbit-agent-01 in #2444
- [security-review] [security] Confine the orbit_tools sandbox to named paths instead of write_tree on the Orbit global root by @orbit-agent-01 in #2445
- [security-review] [security] A plugin must not be able to escalate its own grants by writing its
pluginsstore row by @orbit-agent-01 in #2446 - [security-review] Plugin loader never verifies
manifest_digest, so grants recorded by name apply to whateverplugin.yamlis on disk and audit rows attest a digest that did not run by @orbit-agent-01 in #2447 - Fix red CI: plugin_loader fixture declares
skills: [skills/graph]but the directory does not exist (4 tests failing since plugin phase 3) by @orbit-agent-01 in #2448 - Plugin standard phase 4: schema-derived
orbit <ns> <verb>CLI, dashboard plugin panels and links,orbit plugin testandscaffoldby @orbit-agent-01 in #2449 - [full-code-review] A plugin's
spec.skillsdirectory name is linked into~/.claude/skillsunnamespaced, so a plugin with no grants replaces Orbit's ownorbitskill host-wide by @orbit-agent-01 in #2450 - Fix red CI: phase 4 added a
pluginsdashboard tab but the two dashboard_assets nav assertions still expect the old tab list by @orbit-agent-01 in #2451 - [full-code-review]
orbit plugin add git+<url>copies the clone's.gitinto the install root, so a credential-bearing remote URL lands in the tree the plugin backend can always read by @orbit-agent-01 in #2452 - [full-code-review] Plugin tool names are registered from the store row's
first_partybut validated against the manifest's claim, so a row that disagrees registers a plugin tool over a built-in by @orbit-agent-01 in #2453 - [full-code-review]
is_first_party_remotesubstring-matchesgithub.com/constellation-works/anywhere in the URL, so an attacker-hosted repo verifies as first-party and claims the reservedorbit.<ns>.*namespace by @orbit-agent-01 in #2454 - [full-code-review] ORB-12761's crew-homogeneity filter is inert on the
execution_failedtrigger, which hard-codescrew: None, while the shared submission comment claims it applies to both by @orbit-agent-01 in #2455 - [full-code-review] Two
input_schemaproperties that kebab-case to the same flag take down the wholeorbitCLI in a debug build and silently drop a property in release by @orbit-agent-01 in #2456 - [full-code-review] ORB-12775 moved the plugin callback gate from ORBIT_ALLOWED_TOOLS to ORBIT_PLUGIN — another variable the sandboxed child controls — and the gate is skipped on the MCP entry point by @orbit-agent-01 in #2458
- [full-code-review]
orbit plugin enable --grantunions with the stored row and writes the ORB-12778 witness over the union, so the refusal message's own recovery command launders an injected grant set by @orbit-agent-01 in #2459 - [full-code-review] The operation-mode removal left
operation.stopandoperation.revokeregistered in GOVERNED_OPERATIONS with no caller by @orbit-agent-01 in #2457 - [full-code-review] The ORB-12778 grant witness binds only name/enabled/grants, so a tampered
pluginsrow relocates the install and runs a manifest of its choosing under the authorized grant names by @orbit-agent-01 in #2460 - [full-code-review]
permissions.fs.writemay name any child of the Orbit global root, so thefsgrant reopensplugins/.grants,bin/and other plugins' install trees that ORB-12777/ORB-12778 rely on being unwritable by @orbit-agent-01 in #2461 - [plugin-review] [security]
orbit plugin test <dir>self-grants everything the manifest requests, includingunsandboxed, absolute write roots andnetwork: anyby @orbit-agent-01 in #2462 - Make grok-4.7 the default Grok model (effort validation, pricing, docs, seeded config) by @orbit-agent-01 in #2463
- [plugin-review] [security]
permissions.fs.writeon{{workspace}}can rewrite.orbit/and.git/, and the hostcreate_dir_alls every write root before spawn by @orbit-agent-01 in #2464 - [friction-curation] already-landed.json must document the flattened validation-check object by @orbit-agent-01 in #2465
- [plugin-review]
orbit plugin removeleaves dangling skill links, never disables first, prints plain text under --format json, and a later re-add can never relink by @orbit-agent-01 in #2466 - [plugin-review] [security]
orbit plugin addof a new version rebinds carried grants to the new manifest's wider request; addorbit plugin upgradewith a permission diff by @orbit-agent-01 in #2467 - [plugin-review]
orbit plugin testcan never certify anorigin: orbitplugin (validates with the non-first-party policy) by @orbit-agent-01 in #2468 - [full-code-review] Object-valued reserved properties still create duplicate clap argument IDs by @orbit-agent-01 in #2469
- [plugin-review] Callback session records:
starttimewritten but never compared (pid reuse), one unreadable file aborts the ancestry scan, non-atomic rewrite, no garbage collection by @orbit-agent-01 in #2470 - [ci-red] every_fleet_model_string_is_priced fails: grok-4.7's price row starts after the test's fixed probe date by @orbit-agent-01 in #2471
- [full-code-review] Plugin removal follows the hostile install_path that the loader just refused by @orbit-agent-01 in #2472
- [plugin-review] [security] First-party
origin: orbitis spoofable for directory sources via the candidate's own.git/configremote; a test asserts the spoof as correct by @orbit-agent-01 in #2473 - [plugin-review] Host-level plugin load (CLI groups, MCP tools/list, global tool exec) ignores every
[plugins.<ns>]config section by @orbit-agent-01 in #2474 - [plugin-review]
orbit plugin syncconverges one way only: never disables, never seeds a second workspace, reinstalls every run on a namespace mismatch, and auto-enables from a committed file with no grant review by @orbit-agent-01 in #2475 - [ci-red] ORB-12760 pushed the codex implement prompt over its 2500-token budget (2536) by @orbit-agent-01 in #2476
- [plugin-review]
register_inactive_toolsruns beforevalidate_loaded_plugin, so a tampered on-disk manifest can displace another plugin's or an external tool's registry entry by @orbit-agent-01 in #2477 - [full-code-review] Callback session identity disappears after a backend descendant changes process group by @orbit-agent-01 in #2478
- [plugin-review]
orbit plugin scaffoldprints a next step the vendoring rule refuses, andorbit plugin migrateemits null fields and acommand:that fails its own validate step by @orbit-agent-01 in #2479 - [ci-red] [security] After ORB-12821 a forged plugin callback to orbit.search fails argument validation instead of the orbit_tools allowlist by @orbit-agent-01 in #2480
- [plugin-review] Pin file version ranges: the scope doc's own
version: "0.4.x"example is refused and breaksorbit plugin sync; a test rewrites the example instead of fixing it by @orbit-agent-01 in #2481 - [full-code-review] Missing fs.write tails below symlinks bypass the protected-global-root guard by @orbit-agent-01 in #2482
- [plugin-review]
orbit plugin enablereports Active for a plugin the next load will refuse;requires.orbitis never checked on enable; row+witness written before contributions can fail by @orbit-agent-01 in #2483 - [plugin-review] [security]
git+plugin sources reachgit cloneunhardened: ext:: transport and option injection from the committed pin file by @orbit-agent-01 in #2484 - [plugin-review] Validate
cli.verb/cli.positional, run the flag-collision check on resolved$refschemas, and compile tool input/output schemas once at load by @orbit-agent-01 in #2485 - [ci-red] ORB-12814's write-root containment and ORB-12816's consent gate disagree: two plugin-test consent tests fail on the merged tree by @orbit-agent-01 in #2486
- [ci-red] ORB-12863's write-root rule breaks five mcp_roundtrip plugin tests: Orbit's own state/audit root is no longer materialized by @orbit-agent-01 in #2487
- [ci-red] ORB-12812's git+ URL allow-list refuses the local origin used by add_from_a_git_source_excludes_the_clone_metadata by @orbit-agent-01 in #2488
- [plugin-review] Plugin-standard test coverage gaps: ancestry child, git+ sources, workspace .orbit write, two-workspace MCP, exec timeout, nested $ref, sandbox tests green-by-skip by @orbit-agent-01 in #2489
- [full-code-review] Plugin sync installs an unverified source identity and reports a mismatching pin as satisfied by @orbit-agent-01 in #2490
- [full-qa-sweep] Plugin skill links are written into the real
$HOME, so--rootdoes not isolate them and everycargo testrun leaves dangling links in~/.claude/skillsby @orbit-agent-01 in #2491 - [plugin-review] Plugin install swaps trees non-atomically under a live row; old version directories are never garbage-collected;
removeleaves the namespace family behind by @orbit-agent-01 in #2492 - [plugin-review] One
render_fs_rootsfor validate, registration, call time and conformance: the four passes disagree on relative paths, config value types and defaults vs effective config by @orbit-agent-01 in #2493 - [plugin-standard] graph-example fixture pins requires.orbit >=0.24.0 against a 0.23.0 host by @orbit-agent-01 in #2494
- [full-qa-sweep]
orbit plugin add --enablediscards the whole enable report, so seeded schedules, skill links and link failures are invisible on the path the scaffold recommends by @orbit-agent-01 in #2495 - [ci-red] Settle the plugin write-root materialization rule once: three more tests fail on <global_root>/tasks by @orbit-agent-01 in #2496
- [ci-red] After ORB-12822, plugin migrate no longer yields a first-party manifest and migrate_folds_the_orbit_graph_sidecars fails by @orbit-agent-01 in #2497
- [plugin-review] Grant ergonomics: no way to revoke to the empty set, unknown grant names in a row are dropped silently, and
--grant allfrom the doc is not accepted by @orbit-agent-01 in #2498 - [plugin-standard] [security] Plain CLI reads from a plugin child bypass permissions.orbit_tools by @orbit-agent-01 in #2499
- [friction-curation] An enabled delivery auto-task this host can never admit reads as
enabledinauto-task listandokinorbit doctorby @orbit-agent-01 in #2500 - One
agent_implement.yamlcontract phrase is pinned by two suites that cannot see each other, and it has broken CI twice in two days by @orbit-agent-01 in #2501 - [full-qa-sweep] A refused plugin row logs
ERROR … could not audit the refused plugin row: attempt to write a readonly databaseon every command, including ones whose audit row is written by @orbit-agent-01 in #2502 - [full-code-review] Callback sessions do not bind the caller's effective tool ceiling by @orbit-agent-01 in #2503
- [full-code-review] Colliding plugin definition names overwrite another plugin's seeded schedules by @orbit-agent-01 in #2504
- [ci-red] ORB-12801's callback schema v2 bump reds three tests and hides v1 leftovers from plugin doctor by @orbit-agent-01 in #2505
- [plugin-review] mcp plugin backend: session key ignores workspace/cwd,
tools/callcarries no context, one mutex serialises every session, server-initiated requests are dropped by @orbit-agent-01 in #2506 - [plugin-review] Schema-derived CLI: boolean flags swallow the next positional, a property named
json/opsflips the output mode, andcli.positionaldrops the flag the scaffold template promises by @orbit-agent-01 in #2507 - [plugin-review] Dashboard plugin state is frozen at runtime build, panel polling spawns every backend and writes an audit row per refresh with no output cap, and the markdown-sanitiser test runs without DOMPurify by @orbit-agent-01 in #2508
- [plugin-review] Every
orbitinvocation walks and hashes every enabled plugin tree two or three times and tries an audit insert on a read-only store; share one host load by @orbit-agent-01 in #2509 - [plugin-standard] Pass the effective [plugins.] config to exec backends and MCP backends by @orbit-agent-01 in #2510
- [plugin-standard] Digest-pinned HTTPS archive plugin sources so a compiled plugin can ship a binary by @orbit-agent-01 in #2511
- [plugin-review] Feature: path-scoped fs grants (
--grant fs=<root>[,<root>]) recorded in the witness and intersected with the manifest's request at profile compile time by @orbit-agent-01 in #2512 - [plugin-review] Small plugin-standard correctness cleanups: doctor exit code,
*in a directory glob component,_in namespace/verb collides MCP names, unterminated template, host_api policy, deadvalidate_plugin_sectionsby @orbit-agent-01 in #2513 - [plugin-review] Feature: pass the plugin callback credential as an inherited file descriptor instead of an environment variable plus process ancestry by @orbit-agent-01 in #2514
- [plugin-review] Feature: plugin author ergonomics —
orbit plugin validate --render,orbit <ns> <verb> --explain,orbit plugin test --case/--update-goldens,{{workspace}}substitution and error-case goldens by @orbit-agent-01 in #2515 - [ci-red] ORB-12841 added plugin.legacy_callback_identity without regenerating the four config show snapshots by @orbit-agent-01 in #2516
- [plugin-review] Plugin standard doc drift: reconcile 1_scope.md and plugins.md with what phases 1-4 shipped by @orbit-agent-01 in #2517
- [ci-red] Every plugin backend spawn fails EBADFD: the inherited-fd hook from ORB-12841 is latent-broken by @orbit-agent-01 in #2518
- macOS: a green delivery fails as cleanup_denied when the worker's move of ignored scratch to ~/.Trash is sandbox-denied by @orbit-agent-01 in #2519
- Workspace discovery: treat .orbit/config.yaml (workspace identity) as the initialized-root marker, not config.toml by @orbit-agent-01 in #2520
- Onboard current flagship models for the opus, luna and sol crews by @orbit-agent-01 in #2521
- [code-scanning-sweep] Fix rust/path-injection in crates/orbit-core/src/runtime/plugin_grants.rs by @orbit-agent-01 in #2522
- [code-scanning-sweep] Fix rust/path-injection at 4 locations across 2 files by @orbit-agent-01 in #2523
- MCP workspace selector: don't forward
workspaceinto plugin tool input, and advertise required selector/query in unbound-session schemas by @orbit-agent-01 in #2524 - Dashboard polish: compact task status/crew selects, legible task links in Auto-tasks/Routines, drop Scoreboard 'Notable completions' by @orbit-agent-01 in #2525
- docs: RCA for the 2026-09-23 cross-crate test-worker OOM outage by @orbit-agent-01 in #2526
- Contain pipeline worker runs in a bounded cgroup so one runaway run cannot OOM the host by @orbit-agent-01 in #2527
- CLI root help: dissolve 'Definitions' (job/tool → Operate, plugin → Environment) and remove
orbit activity,orbit executor,orbit policyby @orbit-agent-01 in #2528 - [auto-task] Doc duties — validate the least-recently-validated docs by @orbit-agent-01 in #2529
- Dashboard: fold the Auto-drain tab into the Tasks right dock as a compact first card; rename the dock's Status tab to Drain by @orbit-agent-01 in #2530
- Bind the MCP workspace for source-inspection (task-pilot) provider sessions so their first orbit.* call doesn't fail for a missing selector by @orbit-agent-01 in #2532
- Pipeline worker spawn must never re-exec a test binary from downstream crates' tests by @orbit-agent-01 in #2533
- [BLOCKED] [code-scanning-sweep] Fix rust/path-injection at 3 locations across 3 files by @orbit-agent-01 in #2531
- Dashboard: enable the Jobs pane Run button (POST /api/jobs/:id/run) by @orbit-agent-01 in #2534
- [code-scanning-sweep] Fix rust/command-line-injection in crates/orbit-core/src/application/job/pipeline/worker/scope.rs by @orbit-agent-01 in #2535
- Worker memory limits: one typed parser in orbit-config; a bad limit must never silently disable containment by @orbit-agent-01 in #2536
- Dashboard job Run must submit catalog ids only, never probe the filesystem (CodeQL #460/#461) by @orbit-agent-01 in #2537
- Fix macOS dead_code warnings: from_proc_cgroup and relocate_clear_of_targets have Linux-only callers by @orbit-agent-01 in #2538
Full Changelog: v0.23.0...v0.24.0