Orca v0.5.1
Fixes for the v0.5.0 terminal UI and runtime: shell commands run under the
macOS sandbox again on macOS 26, and the macOS sandbox lets tools read their
own configuration; external tools are no longer stopped after one second;
edits show their diff in the approval and the tool row; output expands with
Ctrl+O, so a message can start with "e"; the welcome screen, help, and Full
Access dialog fit small windows; and fixes cover background agents,
orca attach, and the session picker.
Changes
macOS sandbox
- Shell commands run under Seatbelt again on macOS 26. The sandbox check
aborted there, so Orca judged the sandbox unavailable and removed the shell
tool in every mode butfull-auto. - The workspace sandbox lets commands read outside the workspace again, as on
Linux, sogitcan read~/.gitconfig, tools installed under your home
directory are found, and$TMPDIRand/tmpare writable. Writes stay
limited to the workspace, the temporary directories, and granted roots, and
~/.ssh,~/.orca, and configured denied roots stay unreadable. - A failed command whose output shows a sandbox denial carries a
sandbox_diagnosticnote in its result, such as that a gitindex.lock
"Operation not permitted" error is not a stale lock to delete.
Tool calls and approvals
- An external tool in
~/.orca/toolsruns until it exits or is cancelled.
Since v0.4.31 each one was stopped after one second, so a tool that took
longer failed with "timed out after 1s" before doing its work.
[tools] shell_timeout_secsstill caps them when set. - An edit or file write shows its diff in the approval panel and in the tool
row, and a resumed session keeps each tool row's name, target, and diff. - Permission rules match a tool call's target even when the provider sends
none, since the target is now taken from the call's arguments. - Denying an approval ends the turn with a short note instead of an error
card. - Text after a file path or a code span is no longer redacted as if it were a
secret, and inline HTML in a reply is shown as text.
Terminal UI
Ctrl+Oexpands the latest collapsed output andCtrl+Shift+Oall of it.
eandEused to do this and swallowed the first letter of a message.- An expanded row past 40 lines says how much of the output it shows.
- The help panel scrolls in a short window. The welcome screen picks a layout
that fits the window, and it updates when the mode or window size changes.
The Full Access confirmation always shows both choices. - Each model call's reasoning gets its own row, and a blank line of spaces in
a code block takes one row. Shift+Tabno longer writes a notice per press,Escdoes nothing before
the first message, and a command given the wrong arguments says how to write
it.- A conversation started with
/newis named after its first prompt. - Notices name background tasks by their name, not their id, and a finished
agent no longer shows its last activity as current. Agent phases read
"thinking" rather than "phase: Thinking". ?can be typed into the session picker's filter, counts agree with their
nouns, clicks on a popup's border stay in the popup, the setup key field has
rounded corners, and an MCP server's link is shown in full.Ctrl+Entersteers a turn Orca started itself, such as a queued message, and
Ctrl+Cwhile an agent's conversation is in view leaves the agent's turn
running.
Sessions and background agents
/resumeno longer lists the threads subagents ran in, andlatest
(orca exec resume latest) names the newest conversation rather than a
subagent thread written after it.- An agent stopped while it waited on an approval no longer stays "running",
and an agent the task registry settled keeps its resume and retry controls. - A shell session marked to outlive its task keeps that lifetime after the
task file is reread, so closing the conversation no longer stops it. - The agent progress poll no longer delays other commands when it runs long.
orca attach and the ACP daemon
orca attachexits with status 1 and says why once it cannot attach or has
used up its reconnect attempts, instead of leaving an unresponsive TUI.- The daemon's socket is private from the moment it appears, so a client
connecting at startup no longer finds it with the default mode and refuses
it. - The daemon exits on a signal even if its shutdown stalls, within 10 seconds
or at a second signal.
Release and evaluation tooling
- The release check compares the npm package's optional dependencies by
name, because the registry no longer returns them in publish order; the
v0.5.0 check failed on the order alone. - The repo-fix harness passes the task prompt on stdin, so a commit message
never runs in the host shell, and the scorer reads nextest results.
Compatibility
- Keys. Collapsed output expands with
Ctrl+OandCtrl+Shift+O
instead ofeandE. - macOS sandbox reads. Commands in the workspace sandbox can read files
outside the workspace, as on Linux and as before v0.4.6. Denied roots are
unchanged. - External tool time limit. External tools have no time limit unless
[tools] shell_timeout_secssets one, as for shell commands. A tool that
hangs runs until you cancel the turn. command/execwithexternalSandbox. It is refused rather than run on
the host, as it has been since the capability refactor; the test that
expected otherwise has been corrected.
Existing configurations and conversation history remain readable.
Verification
cargo fmt --all -- --check
cargo clippy --workspace --all-targets --locked -j 1
node --test scripts/test-validate-runtime-surface-contract.mjs
node scripts/validate-runtime-surface-contract.mjs
node --test scripts/test-validate-windows-platform-boundaries.mjs
node scripts/validate-windows-platform-boundaries.mjs
node scripts/release/verify-version-sync.mjs
node scripts/release/test-verify-version-sync.mjs
node scripts/release/test-stage-npm.mjs
node scripts/release/test-verify-published.mjs
cargo nextest run -p orca-tui --lib --locked --profile ci-serial --retries 0
cargo nextest run --test tui_pty_contract --locked --profile ci-serial --retries 0
cargo nextest run --workspace --all-targets --locked --profile ci --no-fail-fast --retries 0
npm --prefix site run build
npm --prefix site run check:seoUpgrade
npm install -g @blade-ai/orca@0.5.1
orca --versionFull Changelog: v0.5.0...v0.5.1