Skip to content

Orca v0.5.1

Choose a tag to compare

@github-actions github-actions released this 27 Sep 08:37
· 35 commits to main since this release

Fixes for the v0.5.0 terminal UI and runtime: shell commands run under the
macOS sandbox again on macOS 26, and the macOS sandbox lets tools read their
own configuration; external tools are no longer stopped after one second;
edits show their diff in the approval and the tool row; output expands with
Ctrl+O, so a message can start with "e"; the welcome screen, help, and Full
Access dialog fit small windows; and fixes cover background agents,
orca attach, and the session picker.

Changes

macOS sandbox

  • Shell commands run under Seatbelt again on macOS 26. The sandbox check
    aborted there, so Orca judged the sandbox unavailable and removed the shell
    tool in every mode but full-auto.
  • The workspace sandbox lets commands read outside the workspace again, as on
    Linux, so git can read ~/.gitconfig, tools installed under your home
    directory are found, and $TMPDIR and /tmp are writable. Writes stay
    limited to the workspace, the temporary directories, and granted roots, and
    ~/.ssh, ~/.orca, and configured denied roots stay unreadable.
  • A failed command whose output shows a sandbox denial carries a
    sandbox_diagnostic note in its result, such as that a git index.lock
    "Operation not permitted" error is not a stale lock to delete.

Tool calls and approvals

  • An external tool in ~/.orca/tools runs until it exits or is cancelled.
    Since v0.4.31 each one was stopped after one second, so a tool that took
    longer failed with "timed out after 1s" before doing its work.
    [tools] shell_timeout_secs still caps them when set.
  • An edit or file write shows its diff in the approval panel and in the tool
    row, and a resumed session keeps each tool row's name, target, and diff.
  • Permission rules match a tool call's target even when the provider sends
    none, since the target is now taken from the call's arguments.
  • Denying an approval ends the turn with a short note instead of an error
    card.
  • Text after a file path or a code span is no longer redacted as if it were a
    secret, and inline HTML in a reply is shown as text.

Terminal UI

  • Ctrl+O expands the latest collapsed output and Ctrl+Shift+O all of it.
    e and E used to do this and swallowed the first letter of a message.
  • An expanded row past 40 lines says how much of the output it shows.
  • The help panel scrolls in a short window. The welcome screen picks a layout
    that fits the window, and it updates when the mode or window size changes.
    The Full Access confirmation always shows both choices.
  • Each model call's reasoning gets its own row, and a blank line of spaces in
    a code block takes one row.
  • Shift+Tab no longer writes a notice per press, Esc does nothing before
    the first message, and a command given the wrong arguments says how to write
    it.
  • A conversation started with /new is named after its first prompt.
  • Notices name background tasks by their name, not their id, and a finished
    agent no longer shows its last activity as current. Agent phases read
    "thinking" rather than "phase: Thinking".
  • ? can be typed into the session picker's filter, counts agree with their
    nouns, clicks on a popup's border stay in the popup, the setup key field has
    rounded corners, and an MCP server's link is shown in full.
  • Ctrl+Enter steers a turn Orca started itself, such as a queued message, and
    Ctrl+C while an agent's conversation is in view leaves the agent's turn
    running.

Sessions and background agents

  • /resume no longer lists the threads subagents ran in, and latest
    (orca exec resume latest) names the newest conversation rather than a
    subagent thread written after it.
  • An agent stopped while it waited on an approval no longer stays "running",
    and an agent the task registry settled keeps its resume and retry controls.
  • A shell session marked to outlive its task keeps that lifetime after the
    task file is reread, so closing the conversation no longer stops it.
  • The agent progress poll no longer delays other commands when it runs long.

orca attach and the ACP daemon

  • orca attach exits with status 1 and says why once it cannot attach or has
    used up its reconnect attempts, instead of leaving an unresponsive TUI.
  • The daemon's socket is private from the moment it appears, so a client
    connecting at startup no longer finds it with the default mode and refuses
    it.
  • The daemon exits on a signal even if its shutdown stalls, within 10 seconds
    or at a second signal.

Release and evaluation tooling

  • The release check compares the npm package's optional dependencies by
    name, because the registry no longer returns them in publish order; the
    v0.5.0 check failed on the order alone.
  • The repo-fix harness passes the task prompt on stdin, so a commit message
    never runs in the host shell, and the scorer reads nextest results.

Compatibility

  • Keys. Collapsed output expands with Ctrl+O and Ctrl+Shift+O
    instead of e and E.
  • macOS sandbox reads. Commands in the workspace sandbox can read files
    outside the workspace, as on Linux and as before v0.4.6. Denied roots are
    unchanged.
  • External tool time limit. External tools have no time limit unless
    [tools] shell_timeout_secs sets one, as for shell commands. A tool that
    hangs runs until you cancel the turn.
  • command/exec with externalSandbox. It is refused rather than run on
    the host, as it has been since the capability refactor; the test that
    expected otherwise has been corrected.

Existing configurations and conversation history remain readable.

Verification

cargo fmt --all -- --check
cargo clippy --workspace --all-targets --locked -j 1
node --test scripts/test-validate-runtime-surface-contract.mjs
node scripts/validate-runtime-surface-contract.mjs
node --test scripts/test-validate-windows-platform-boundaries.mjs
node scripts/validate-windows-platform-boundaries.mjs
node scripts/release/verify-version-sync.mjs
node scripts/release/test-verify-version-sync.mjs
node scripts/release/test-stage-npm.mjs
node scripts/release/test-verify-published.mjs
cargo nextest run -p orca-tui --lib --locked --profile ci-serial --retries 0
cargo nextest run --test tui_pty_contract --locked --profile ci-serial --retries 0
cargo nextest run --workspace --all-targets --locked --profile ci --no-fail-fast --retries 0
npm --prefix site run build
npm --prefix site run check:seo

Upgrade

npm install -g @blade-ai/orca@0.5.1
orca --version

Full Changelog: v0.5.0...v0.5.1