Orca v0.3.17
Orca v0.3.17
Orca v0.3.17 makes execution-budget accounting durable across process
restart, provider suspension, approval continuation, and settlement retries.
The operation journal now owns the immutable budget and cumulative usage;
in-memory snapshots are no longer recovery authority.
What Changed
- Durable budget facts. Journal schema v2 adds cumulative
budget.usagerecords and stores the operation'sBudgetSpecin
operation.started. Turn and tool admission, tool settlement, provider
cost, wall-time sync, and child receipt merge flush their usage boundary
before returning. - Restart restores the original deadline. Reopening an operation restores
turns, tool calls, cost, and elapsed wall time from the journal. Wall time
includes suspension and process downtime, and a caller cannot silently
replace the operation's original budget on resume. - Exactly-once provider cost settlement. Provider usage is keyed by the
stable response item identity. Retrying settlement after a crash or flush
failure does not charge the same response twice, while each retry still
publishes a fresh wall-time snapshot. - Correct foreground provider deltas. A foreground response charges the
increase in itsCostTrackeracross that provider call. It no longer
subtracts the restored controller's unrelated cumulative baseline, which
could reduce a valid response charge to zero after recovery. - Atomic fair child leases. Concurrent children split the parent's actual
remaining turns, tool calls, and cost before any reservation is published.
Allocation fails atomically when a finite dimension cannot cover the whole
batch; capacity is never fabricated with a floor of one. - One wall-clock deadline. Concurrent child elapsed times are not summed.
Every child enforces the parent's remaining wall deadline, including after
a provider response with no billable usage. - Complete child receipts and terminal projection. Child turns, tools,
nested work, and provider cost reach the parent even when later result
persistence fails. Typed live, recovered, and legacy task mirrors all map a
durable budget stop tobudget_exhausted. - Retry-safe hosted cancellation. Hosted resumable generations defer their
Cancelledjournal terminal until the host knows whether a queued resume
will replace that generation. Tool admission accounting uses a monotonic
operation-local count, so a provider may reuse a tool-call id for a retry
without triggering a false duplicate-accounting failure.
Compatibility
CLI flags and public JSONL envelopes are unchanged. Operation journals are
intentionally incompatible: v0.3.17 writes schema v2 and explicitly rejects
v1 or mixed-version records. Existing saved sessions remain readable, but an
in-flight v1 operation journal cannot be continued; start a fresh operation
from the saved session boundary instead.
Verification
cargo test -p orca-runtime --all-targets --locked
cargo test -p orca-runtime --test execution_journal --locked
cargo test -p orca-runtime --test budget_resume_contract --locked
cargo test -p orca-runtime --test budget_lease_contract --locked
cargo fmt --all -- --check
node scripts/release/verify-version-sync.mjs
git diff --checkUpgrade
npm install -g @blade-ai/orca@0.3.17
orca --versionFull Changelog: v0.3.16...v0.3.17