Skip to content

Releases: willem445/orrerix

Orrerix v1.3.1-beta7

Orrerix v1.3.1-beta7 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 08 Oct 01:24
cca110f

Orrerix v1.3.1-beta7

Ctrl+C interrupts a running process again, compaction works on every CLI that has a compact command, and the #3498 refactor is complete.

✨ Highlights

⌨️ Ctrl+C interrupts again (#3595)

  • With no selection, Ctrl+C sends the interrupt to the running program, so a server in a PowerShell pane stops as it does in a plain terminal.
  • With a selection, Ctrl+C copies and clears the selection; the next Ctrl+C interrupts. A selection that has scrolled out of view no longer turns Ctrl+C into a copy.
  • Programs started from orrerix, including console programs opened from the files pane, no longer inherit "ignore Ctrl+C" from the app.

🗜️ Compaction for every CLI (#413)

  • orrerix sends each CLI its own compact command instead of assuming Claude's. A CLI with no compact command is never sent one.
  • Automatic compaction escalates only when the CLI reports a real context window. pi and Codex panes show tokens without a percent until their CLI reports one.
  • orrerix knows when a compact has finished from each CLI's own records: Claude's PostCompact hook (Claude Code 2.1.76 or newer only), the session rollout for Codex, and the session files for pi and opencode.

🔧 Also in this release

  • Codebase refactor finished, behaviour unchanged (#3498): orchestration/mod.rs went from about 66,700 lines to about 640 and is now a module map. OrchRegistry lives in registry/, the free functions in guardrails, ghshim, ghgate and clis/, and the review driver and workflow parser are split by concern in the engine crate. Every slice carried a parity proof, and the design notes, skills and comments point at the new locations.

🧪 Please check on this beta

  • Ctrl+C in a PowerShell pane: interrupt a running server; select text and copy, then interrupt; run a console program opened from the files pane and interrupt it.
  • Context label on pi and Codex panes: tokens with no percent until the CLI reports a window.
  • Compaction on a non-Claude pane: the compact lands, and the pane is marked done afterwards.
  • Carried from beta6: panes, the workflow pane and the group panel's model / effort / context label.

⚠️ Known in this build

  • #3660: the CLI version check behind the PostCompact gate has edge cases left; a version it cannot read is treated as too old, so the hook is not written.
  • #3434: a launcher fan-out that fails on one reused name leaves worktrees for the panes before it.
  • Carried: #3365, #3317, #2502, #2893, #2833, #2892, #3227, #3224.

⚠️ Unsigned installers: macOS will report the app as "damaged" (xattr -cr /Applications/Orrerix.app) and Windows SmartScreen will warn on first run — expected for these builds, not a regression.

ℹ️ Pre-release: npx orrerix stays on v1.3.0; no .msi for beta builds.

  • Windows: Orrerix_*-setup.exe
  • macOS: Orrerix_*_aarch64.dmg (Apple Silicon) or Orrerix_*_x64.dmg (Intel)
  • Linux: Orrerix_*.AppImage (portable), *.deb, or *.rpm

Orrerix v1.3.1-beta6

Orrerix v1.3.1-beta6 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 27 Sep 03:55
d228b1c

Orrerix v1.3.1-beta6

Every agent pane now shows its real model, effort and context window, the token chart works live, and the codebase's largest files are split into navigable modules. This beta is also the evaluation build for the refactored panes and the workflow pane.

✨ Highlights

🧠 Real model, effort and context window for every CLI (#993)

orrerix reads each pane's model, effort level and context usage from the CLI's own records instead of guessing from a model-name table:

  • Claude: from its status line. Your own status line is chained, so it still shows exactly as before in an orrerix pane. It is found in the project's local settings, then project settings, then user settings.
  • Codex: from its session rollout.
  • pi: from its session file. The context window comes from pi --list-models; a rounded value like 1.0M is read conservatively (never overstated).
  • opencode: from its database. opencode reports no context window, so its panes show tokens without a percent. This also fixes opencode's model showing as raw JSON.

The group panel's lifecycle row now reads model · effort · ctx NN% of <window> per agent (#3542).

📈 The token chart, fixed live (#3505)

  • Wheel zoom, drag pan and the hover readout work on the running app.
  • The per-pane tables are gone in favour of one group scorecard: tokens and cost per completed item, items per day, time-to-completion, review rounds and CI attempts, each with its n.
  • Trend plots sit under the main chart, tokens per completed item first.
  • Effort switches are now marked on the chart beside model switches (#3571).

⏱️ Pane cache-age timer (#3407)

Each agent pane shows how long ago it last made a model request, against its provider's prompt-cache TTL: hot → cooling → cold. Clicking it shows what the last wake cost and offers Compact now. The orchestrator also compacts before going idle with no work.

🔧 Also in this release

  • Workflow edits don't break the build: the dogfood tests check that .orrerix/workflow.yml is valid, not what its values are (#3510, #3513).
  • Codebase refactor, behaviour unchanged (#3498): tests/orchestration.rs (70k lines) became a directory of topic modules; the Tauri commands and most of OrchRegistry left orchestration/mod.rs for commands/ and registry/; pane.ts, workflowmodel.ts and workflowview.ts became focused modules. Every slice carried a parity proof. A file-size budget test now keeps files from regrowing.

🧪 Please check on this beta

  • Panes (the pane.ts split): open/close/split, badges and attention chips, the compose strip (type, paste, attach, voice), copy/paste, embedded views, dormant/respawn, restore after restart.
  • Workflow pane (the workflowview.ts split): edit a block and save, edges, knobs, the file picker, validation findings, comments kept on save.
  • Group panel: the model / effort / context label per agent.

⚠️ Known in this build

  • #3595: in a PowerShell pane, Ctrl+C can copy instead of interrupting a running process. A fix is in progress for the next beta; Ctrl+Shift+C copies reliably meanwhile.
  • #3434: a launcher fan-out that fails on one reused name leaves worktrees for the panes before it.
  • Carried: #3365, #3317, #2502, #2893, #2833, #2892, #3227, #3224.

⚠️ Unsigned installers: macOS will report the app as "damaged" (xattr -cr /Applications/Orrerix.app) and Windows SmartScreen will warn on first run — expected for these builds, not a regression.

ℹ️ Pre-release: npx orrerix stays on v1.3.0; no .msi for beta builds.

  • Windows: Orrerix_*-setup.exe
  • macOS: Orrerix_*_aarch64.dmg (Apple Silicon) or Orrerix_*_x64.dmg (Intel)
  • Linux: Orrerix_*.AppImage (portable), *.deb, or *.rpm

Orrerix v1.3.1-beta5

Orrerix v1.3.1-beta5 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 25 Sep 12:23
aeaa37e

Orrerix v1.3.1-beta5

The token chart is now an instrument you can steer — zoom, log scale, trends and per-item metrics — and compaction gets a setting of its own.

✨ Highlights

📈 An interactive token chart (#3475)

  • Zoom and pan: wheel zoom anchors at the cursor, and you drag to pan. A custom · reset chip takes you back to the preset.
  • Log scale and autoscale: a log toggle, plus a y-axis that autoscales to the visible window. A 1M-context orchestrator's cache reads no longer flatten every other line.
  • Output by default: the default counter is output tokens.
  • Hover readout: hovering shows the values under the cursor.
  • Marks: click a mark to fit a two-hour window around it, with before and after values.
  • Metrics:
    • Trend lines, and tables of token averages per pane, block, model and work item.
    • Tokens per completed item, and each role's share of them.
    • How long an item spends in each status.
    • Review rounds and CI attempts per item.
    • Every average names its population n.

🗜️ Compaction thresholds in the group panel (#3497)

Set the context level at which an orchestrator is compacted from the group panel. New groups default to 45%, and existing groups keep their stored setting.

🔧 Also in this release

  • Idle detection (#3426): a Claude Code input box holding only the CLI's grey suggested prompt now counts as idle, so deliveries are no longer held behind it.
  • Hidden window (#1141): the webview stays unthrottled while the window is hidden.
  • Allocation failures (#3469): poll-path reads fail soft on a refused allocation instead of aborting.
  • rustfmt lock (#3469): rustfmt is now a one-slot locked resource.
  • Workflow file (#3330): orrerix says once when the workflow file stops loading and the drivers fall back to reading it as off.
  • npm shim (#3477): the npm shim .cmd resolves its own directory, and stale generated shims are pruned.
  • Workflow editor (#3410): editing a workflow block keeps the comment lines above it.

⚠️ Known in this build


⚠️ Unsigned installers: macOS will report the app as "damaged" (xattr -cr /Applications/Orrerix.app) and Windows SmartScreen will warn on first run — expected for these builds, not a regression.

ℹ️ Pre-release: npx orrerix stays on v1.3.0; no .msi for beta builds.

  • Windows: Orrerix_*-setup.exe
  • macOS: Orrerix_*_aarch64.dmg (Apple Silicon) or Orrerix_*_x64.dmg (Intel)
  • Linux: Orrerix_*.AppImage (portable), *.deb, or *.rpm

Orrerix v1.3.1-beta4

Orrerix v1.3.1-beta4 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 24 Sep 18:38
3c83469

Orrerix v1.3.1-beta4

Codex workers can commit, the token chart is readable again, and agents clean up after themselves.

✨ Highlights

🤖 Codex workers commit and push (#3456)

A codex worker could edit its worktree but not commit: the worktree's git directory lives under the main clone's .git, outside codex's sandbox. The profile orrerix writes now grants that directory plus the shared objects, refs and logs, and seals commondir, config.worktree and the gitdir pointer read-only through a codex permissions profile, so a pane cannot redirect your git. Two documented costs: git push -u pushes but can't record the upstream, and deleting a branch git has packed fails. One residual: a rebase a pane left in progress runs its exec lines if you git rebase --continue it; don't continue a rebase you didn't start.

📈 Token chart fixes (#3449, #3415)

Lines no longer render as filled grey wedges (a CSS fill override), and colour slots go to blocks that actually spent, so the current roster gets distinct hues. New split by model chip, and a labelled mark wherever a pane's model changed mid-session; on claude the sample now carries the current model, not the priciest one seen.

🧹 Agents clean up, and write for humans (#3441, #3442, #3443)

Reviewer worktrees are reclaimed when the pane ends; a resumed worker keeps its branch, so it can close its own scratch PRs; and the agent templates now carry cleanup duties per role plus a human-first writing standard (short bodies, receipts folded away, an AI-on-behalf-of tail, fewer issues).

🔧 Also in this release

  • rustfmt check capped (#3469): workers no longer run rustfmt --check on files over 5,000 lines; on orchestration/mod.rs it took 16–23 GB and could exhaust the machine.

⚠️ Known in this build

  • #3469 part 3: a refused heap allocation still aborts orrerix rather than degrading.
  • #3434: a launcher fan-out that fails on one reused name leaves worktrees for the panes before it.
  • #3426: a delivery to an idle Claude Code pane can be held behind the CLI's grey suggested prompt.
  • Carried: #3365, #3317, #3330 (product half), #2502, #2893, #2833, #2892, #3227, #3224.

⚠️ Unsigned installers: macOS will report the app as "damaged" (xattr -cr /Applications/Orrerix.app) and Windows SmartScreen will warn on first run — expected for these builds, not a regression.

ℹ️ Pre-release: npx orrerix stays on v1.3.0; no .msi for beta builds.

  • Windows: Orrerix_*-setup.exe
  • macOS: Orrerix_*_aarch64.dmg (Apple Silicon) or Orrerix_*_x64.dmg (Intel)
  • Linux: Orrerix_*.AppImage (portable), *.deb, or *.rpm

v1.3.1-beta3

v1.3.1-beta3 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 24 Sep 02:00
938b214

Orrerix v1.3.1-beta3

Codex workers can do their job, and the review driver takes over more of the loop.

✨ Highlights

🤖 Codex worker panes work (#3405)

Three bugs stopped a codex worker the first time one ran, and all three are fixed:

  • orrerix's own tools are pre-approved. Codex asked for approval on every orrerix tool and then refused under approval_policy = "never". orrerix now writes default_tools_approval_mode = "approve" for its own server only.
  • gh works inside codex's elevated sandbox. Under [windows] sandbox = "elevated" codex runs commands as a separate Windows account that can't read your gh login. A codex group pane now gets GH_TOKEN, in the pane's environment only and never in its profile file. If reading the token fails, the pane still starts and the audit log says why.
    • Accepted cost: the credential crosses codex's sandbox boundary, and every process in the pane can read it.
    • A refreshed or revoked login needs a respawn: the token is read once, at spawn.
  • A published branch is checked out, not shadowed. Spawning onto a branch that exists only on origin now checks it out and tracks it. The launcher changes the same way: a worktree name that exists on origin is checked out. If that branch is behind main, the launch fails and names the branch; the orchestrator's way out is base: "origin/<branch>".

🔁 The review driver runs the nit loop (#3371)

Two opt-in driver: keys, both off by default:

  • driver.fix_nonblocking_rounds: N (0–3) hands a passed-with-nits PR back to its worker, waits for green, and re-briefs the reviewers. These rounds count against the usual three-round limit, which it never exceeds.
  • driver.auto_drive_on_done starts a drive when a worker reports done on its own PR. It is refused for scratch PRs, PRs already driven or parked, and PRs that already carry a verdict.

✅ Reviewers declare what they left open (#3388)

review_verdict takes open_findings: N, and list_verdicts shows it. A gate that is satisfied with CI green, where every required lane passed and declared 0, is the clean case: the driver submits it to the merge queue where the queue allows it. Any non-zero count a reviewer states, blocking or non-blocking, vetoes clean, so no nit is skipped silently.

🌿 Name a fork when you make it; see where it came from (#3368)

Fork session… now asks for a name, pre-filled <pane name> (fork). The Sessions browser shows fork lineage as a tree, with a ↰ return-to-parent button on the row and in the pane header. A closed Solo fork keeps its parent.

🔧 Also in this release

  • PR body check in CI (#3373): pr-body-check runs on every PR, including a description-only edit, and fails on a body claim that doesn't match the diff.
  • Smaller resident orchestrator prompt (#3370): procedure moved to the on-demand playbook; the rules stay resident.

⚠️ Known in this build

  • Launcher (#3434): a multi-pane launch that fails on one reused name leaves worktrees on disk for the panes before it, and resubmitting then fails with worktree path already exists.
  • Delivery queue (#3426): a delivery to an idle Claude Code pane can be held indefinitely when its input line shows the CLI's grey suggested prompt.
  • Codex (#3405): the fix is checked against codex's source at rust-v0.156.1. Your first real codex worker is the live check.
  • Carried from beta2: #3365, #3317, #3330 (product half), #2502, #2893, #2833, #2892, #3227, #3224.

⚠️ Unsigned installers: macOS will report the app as "damaged" (xattr -cr /Applications/Orrerix.app) and Windows SmartScreen will warn on first run — expected for these builds, not a regression.

ℹ️ Pre-release: npx orrerix stays on v1.3.0; no .msi for beta builds.

  • Windows: Orrerix_*-setup.exe
  • macOS: Orrerix_*_aarch64.dmg (Apple Silicon) or Orrerix_*_x64.dmg (Intel)
  • Linux: Orrerix_*.AppImage (portable), *.deb, or *.rpm

Orrerix v1.3.1-beta2

Orrerix v1.3.1-beta2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 23 Sep 04:29
efa381b

Orrerix v1.3.1-beta2

The To-Do pane grows up, and every harness that can fork a session gets the fork button.

✨ Highlights

✅ To-Do v2 (#3335)

The to-do list lives in the side dock too, in a compact layout. Rows carry tag chips in stable theme hues with a filtering tag rail; each task can take a colour (a small palette, shown as a stripe on the collapsed row); priority is a visible flag you cycle on the row, with a per-view by priority sort that keeps your manual order underneath; rows drag to reorder (Shift+↑/↓ still works), and the order-key gap now renumbers itself inside the same locked write instead of refusing when it runs out of room — which also fixed a latent case where a moved older item could land on the wrong side of its neighbour. Click anywhere on a row to expand it; the checkbox, chips, flag and swatch keep their own click. The colour is a new optional field on the stored item; existing todo.json files read unchanged.

🌿 Fork on every harness that can (#3318 F2)

Right-click → Fork session now works on Codex (codex fork <id>), pi (--fork) and opencode (--fork) panes as well as Claude Code — each through the vendor's own native fork, nothing copied. Orchestrators and leads get a fork_session MCP tool that forks a delegate into a new pane (inheriting its block, cut into a worktree on the source's branch), with a forked_from on the roster and an agent-fork audit row; a fork request from a lead's own pane opens a standalone pane beside it. Refused: a pane owned by a live review or plan drive, a CLI with no fork (Copilot, Gemini), and an orchestrator or manager source. No rejoin — a fork is a side quest; bring back what you keep by hand.

⚠️ Known in this build

  • Session fork: a plan-drive owner check fails open, and a lead self-fork request whose acknowledgement never arrives leaves an outcome-less audit row (#3365); the opencode cross-directory fork has not been exercised live.
  • To-Do: dropping a dragged row onto one deleted mid-drag is a silent no-op; title text does not drag-select in reorderable views.
  • Carried from beta1: #3317, #3330 (product half), #2502, #2893, #2833, #2892, #3227, #3224.

⚠️ Unsigned installers: macOS will report the app as "damaged" (xattr -cr /Applications/Orrerix.app) and Windows SmartScreen will warn on first run — expected for these builds, not a regression.

ℹ️ Pre-release: npx orrerix stays on v1.3.0; no .msi for beta builds.

  • Windows: Orrerix_*-setup.exe
  • macOS: Orrerix_*_aarch64.dmg (Apple Silicon) or Orrerix_*_x64.dmg (Intel)
  • Linux: Orrerix_*.AppImage (portable), *.deb, or *.rpm

Orrerix v1.3.1-beta1

Orrerix v1.3.1-beta1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 22 Sep 21:56
60ee956

Orrerix v1.3.1-beta1

A to-do station beside your agents, a way to mark the panes you are waiting on, a fork button on a Claude Code pane, and the first cut of delivery triage for the orchestrator's budget.

✨ Highlights

✅ The To-Do pane (#3263)

Alt+J opens a to-do list as a pane, not an overlay: a Global list and a per-workspace list you switch between, five views with live counts (My Day, Planned, Important, All, Completed), quick-add that parses tomorrow, fri, !high, #tag and shows the parse as chips before you press Enter, inline editing, reminders, undo through restore, and a completed archive. My Day resets at local midnight — by calendar day, so a DST transition is still one day (#3298). Every non-Solo agent gets todo_list / todo_add / todo_update / todo_complete / todo_delete / todo_restore, so an orchestrator or worker can groom the same list you do; the store is one versioned todo.json under the data root, written atomically and quarantined rather than clobbered when unreadable (#3285). The attribution dot on a row says which agent last touched it.

👁️ Watched panes (#3319)

Right-click a pane → Watch this pane, or Alt+H on the focused one. A watched pane is unmistakable on its own frame, in the dock chip and on the tab, survives a pane restore and an app restart, and is never cleared for you — it is your mark of "look here when I come back", separate from the agent-derived attention chip. A next-watched jump walks the marked panes.

🌿 Fork a Claude Code pane (#3318 F1)

Right-click a Claude Code pane → Fork session: a new pane opens on Claude's own --resume <id> --fork-session, so you can take a side quest without disturbing the original conversation. The fork flag is one-shot — the child's record becomes a plain resume line — and no transcript is ever copied or merged. Claude only in this build; codex / pi / opencode follow once the gesture has been used in anger.

🧾 Delivery triage for the orchestrator pane (#3304)

Each orchestrator wake re-reads a very large context; a census of this repo's own log found most wakes closing on the notice's leading shape with no decision in them. A rule tier at the one door every delivery passes now records those instead of typing them, and flushes them as one framed line at the next genuine wake or after max_defer_minutes; anything not positively recognised is delivered, and nothing is ever dropped (list_deferred reads the store back). A replay harness (scripts/orch-triage-eval.cjs) measures the tier against hand labels — the shipped rules score 0 false defers on this group's audit (#3324). Off by default: a triage: block in .orrerix/workflow.yml turns it on, and a build older than this one refuses a file that carries it (#3330).

📋 Task board rows for humans (#3261)

Titles capped for readability, an optional description that opens when you click the row, and a colour per kind so epics, features, stories and tasks read at a glance.

🔧 Under the hood

  • The review driver releases the panes a drive was started on at every terminal exit, including cancel — no more finished worker holding a delegate slot (#3250).
  • One documentation root: doc/ folded into docs/ (design notes and plans excluded from the site), the checked-in demo/ mock removed, and a layout guard that refuses either coming back (#3315).
  • gh shim ts_ms hardening and the shim's test residuals (#3249, #3259).
  • Three lessons from the To-Do epic distilled into CLAUDE.md (#3309).

⚠️ Known in this build

  • The review driver's path routing and the merge gate cannot enumerate a PR over ~100 files (GitHub pages the file list); such a PR merges from the GitHub UI (#3317).
  • A workflow file that fails to parse leaves the driver silently disabled instead of naming the error in the orchestrator pane (#3330).
  • Fork: whether --session-id <new> composes with --fork-session is unconfirmed live; the pre-mint arm ships behind one constant, and a wrong guess costs only a mis-recorded child id (#3331).
  • Carried: #2502, #2893, #2833, #2892, #3227, #3224.

⚠️ Unsigned installers: macOS will report the app as "damaged" (xattr -cr /Applications/Orrerix.app) and Windows SmartScreen will warn on first run — expected for these builds, not a regression.

ℹ️ Pre-release: npx orrerix stays on v1.3.0; no .msi for beta builds.

  • Windows: Orrerix_*-setup.exe
  • macOS: Orrerix_*_aarch64.dmg (Apple Silicon) or Orrerix_*_x64.dmg (Intel)
  • Linux: Orrerix_*.AppImage (portable), *.deb, or *.rpm

Orrerix v1.3.0

Choose a tag to compare

@github-actions github-actions released this 12 Sep 03:44
c73a498

Orrerix v1.3.0

The review loop runs in the engine, agent panes stop being terminals-only, and a repo can carry more than one workflow — twelve pre-release builds of daily-drive hardening, promoted to stable.

✨ Highlights

🤖 The review driver — the review loop without an orchestrator turn (#1778, #2811)

An orchestrator used to spend most of its turns routing: read a verdict, brief the worker, read the report, brief the reviewer, repeat — each turn re-paying the whole conversation on the most expensive model in the group. The driver does that loop in the engine: drive_review hands one PR to Orrerix, which waits for CI, spawns or resumes each reviewer lane the merge gate requires, hands findings, red runs and conflicts back to the worker's own session, and stops with one line at gate-satisfied, an escalate, or a bound. One pane per lane for the life of the drive (#2109); per-state time bounds rather than age (#2110); hand-backs that take over the live pane instead of opening a duplicate (#3203); a CONFLICTING hand-back that burns no reviewer round (#3176); provider usage-limit / credit refusals detected from pane text and held once across every affected drive (#3178, #3191); worker panes released wherever their report is consumed (#3115); and a restart that re-hands fixes back and re-briefs dead lanes from disk with no round re-charged — verified in a live drill on the final beta (#3196, #3228). Opt-in in this release: driver.enabled in your .orrerix/workflow.yml driver: block, editable from the workflow pane (#1869). Measured on the dogfood fleet: orchestrator share of Claude tokens 82 % → 35 % (#2011).

🧾 Orchestrator token diet (#3040, #1683, #1958)

Planners post their own plans to the issue (post_issue_comment); a fenced orrerix-plan block can be boarded and driven planner → worker → review with no orchestrator turn (behind driver.plan_enabled, default off); progress reports go to the audit log and the board instead of the orchestrator's pane; driver notices are one decision-grade line each; list_agents(live_only) / list_tasks(hot_only) re-syncs; agent-written PR bodies lead with a short human layer and fold the evidence under a <details> agent layer (#1968).

🧩 Harnesses: pi, Codex, structured panes (#2126, #2515, #2850)

pi joins as a fifth harness with a real thinking knob and now runs the dogfood standard tier (#2817); OpenAI Codex CLI is a first-class harness — launcher row, solo pane, workflow block, sessions browser, usage snapshot; and the first structured (non-PTY) agent pane path lands: a block with driver: structured on pi spawns it over --mode rpc through the engine's JSON-RPC adapter, rendered by a virtualised block list with dialog cards, activity and a usage ticker (#2986, #3101). opencode panes no longer lose their kickoff (#1591).

🗂️ Dynamic workflows and lead panes (#1689, #2519)

A repo can declare several workflow files; the launch pane offers a picker and the roster preview follows it; a running group shows drift and can Review & apply a switch, consent-preserving (#2659, #2933). Any agent pane can launch as a lead whose subagents become visible Orrerix panes bound to its tab (#2602).

🖥️ Panes and panels (#2116, #2122, #2191, #2368, #2137)

Per-pane Notes tied to the harness session; an Agents tab with working / idle / turn-done per pane, grouped and sortable; a pane header that folds into an overflow menu when narrow (an overlay — never a PTY resize); SSH panes with a key passphrase and a login shell on the remote; dismiss a question or needs-you item in place; Alt+K token charts and a scorecard pane (#2941, #3131); a compact task board.

🔒 Guard rails

gh pr close / reopen / --delete-branch refused for a PR whose head branch the calling agent does not own (#2985); every driver bound configurable and enforced; the [scratch] PR class runs one platform (#1755).

Since v1.2.0

This release rolls up twelve pre-release builds (v1.3.0-beta1 through beta12; beta2 shipped as a tag without a release page). Each published beta's own release notes carry the day-by-day detail and root causes.

⚠️ Known in this release

  • driver.enabled defaults off — the driver is opt-in; the default-on decision is #2811 S11.
  • The driver can leave a finished worker's pane alive after its report is consumed — harmless beyond a held delegate slot (#3250).
  • Carried: #2502, #2893, #2833, #2892, #3227, #3224.

⚠️ Unsigned installers: macOS will report the app as "damaged" (xattr -cr /Applications/Orrerix.app) and Windows SmartScreen will warn on first run — expected for these builds, not a regression.

ℹ️ npx orrerix resolves to this release.

  • Windows: Orrerix_*-setup.exe (installer) or Orrerix_*.msi
  • macOS: Orrerix_*_aarch64.dmg (Apple Silicon) or Orrerix_*_x64.dmg (Intel)
  • Linux: Orrerix_*.AppImage (portable), *.deb, or *.rpm

Or use the one-liner installers in the README.

Orrerix v1.3.0-beta12

Orrerix v1.3.0-beta12 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 08 Sep 18:29
21dc269

Orrerix v1.3.0-beta12

A small hardening beta on top of beta11: the two restart gaps the beta11 drill found, fixed, plus the three soak follow-ups. Candidate for the first 1.3.0 stable.

🚦 Review driver — restart reconcile reads the live roster

  • A drive whose panes died with the process no longer waits for them. At restart the reconcile now reads pane liveness from the roster instead of its own records: a review-wait lane whose pane is gone is re-briefed immediately by resuming its recorded session (rd-lane-spawned resumed:true why:restart, no round charged); a drive that had already pushed its fix (rd-kickback) but lost its worker pane treats the push as the fix delivered and briefs lanes on the next green instead of parking fix-stalled naming dead panes; and drive_review on a live drive with dead panes repairs it instead of refusing already-driven (#3225, #3226, #3228).

🔧 Also in this release

  • dialog attention row in the label/priority table + provider-limit positive-control fixtures per provider (#3190, #3222); gh-shim refusal names the longest-match owner, doc twins fixed (#3206, #3221); rd-conflicting comment covers the park tick and the arc-3 rustdoc matches the design note (#3175, #3220).

⚠️ Known in this build

  • The pane dialog card's answer path has no frontend caller yet (#3227); scratch branches must be named as descendants of the worker branch under the close-ownership rule (#3234); idle-detection plan (#3224).
  • driver.enabled still defaults OFF (opt-in) — the stable decision (#2811 S11).
  • Carried: #2502, #2893, #2833, #2892, #3202.

📦 Download & install

Download the asset for your platform below.

  • Windows: Orrerix_*-setup.exe (NSIS installer; no .msi on pre-releases). Installs over an existing Orrerix install.
  • macOS: Orrerix_*_aarch64.dmg (Apple Silicon) or Orrerix_*_x64.dmg (Intel) — unsigned; if macOS reports the app as damaged, run xattr -cr /Applications/Orrerix.app once.
  • Linux: Orrerix_*.AppImage (portable), *.deb, or *.rpm

Or use the one-liner installers in the README (they resolve the latest stable release — v1.2.0 — not this beta).


Full commit log: v1.3.0-beta11..v1.3.0-beta12. Installers are unsigned — macOS "damaged app" and Windows SmartScreen warnings are expected, not a regression.

Orrerix v1.3.0-beta11

Orrerix v1.3.0-beta11 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 08 Sep 01:43
1fbbf6c

Orrerix v1.3.0-beta11

A hardening beta on top of beta10: every review-driver defect found while dogfooding beta10 for a day, fixed, plus the two driver slices that landed just after the beta10 tag. This is the candidate for the first 1.3.0 stable.

🚦 Review driver — beta10 fixes

  • A hand-back takes over the live pane instead of resuming a duplicate. On beta10 a second red-CI hand-back could open a second (then third) pane on the same worker session, all writing one worktree — silent work loss. The driver now delivers the hand-back into the pane that is already there (rd-handback records pane: reused | taken-over | spawned) and never puts two live panes on one session; on report it releases every pane on that session, not just the one it resumed (#3203, #3208).
  • A CONFLICTING hand-back no longer burns an open reviewer round. A lane still reviewing when the PR goes CONFLICTING is briefed to stop and released on its report (rd-lane-stopped / rd-lane-released why:conflict), the round is not charged, and the lane is re-briefed clean at the rebased head (#3176, #3211).
  • A fix-wait drive survives a restart. After an orrerix restart the driver re-hands the fix back through the recorded worker session (rd-handback why:restart), bounded by fix_timeout_minutes, instead of sitting until fix-stalled (#2811 S10, #3196).

🧯 Provider limits, held once

  • A Claude usage-limit or OpenRouter credit refusal in any pane raises a provider-limit attention reason from per-provider patterns taken from real pane text (#3178), and every drive whose lanes run on that provider parks under ONE HeldReason::ProviderLimit with a single notice to the orchestrator — resumed explicitly with drive_review once the account is topped up (#3191). Both landed minutes after the beta10 tag, so this is their first build.

🔒 gh shim — ownership on close

  • gh pr close, gh pr reopen and any --delete-branch are refused for a PR whose head branch the calling agent does not own (its own worktree branch, or a /- or --separated descendant of it); the orchestrator is exempt; every close is audited with the agent id. Closes the class where a computed-number loop closed five live PRs (#2985, #3198).

🔧 Also in this release

  • Plan-drive docs and the {{REVIEW_DRIVER}} playbook fragment that had rendered empty in every new group since #1778 (#3161); driver gate-check reads mergeability (#3139, already in beta10); three new lessons in CLAUDE.md / ci-validate (#3185).

⚠️ Known in this build

  • Follow-ups filed from review, none blocking: #3214 (parked-pane take-over), #3206 (shim doc twins), #3210 (code-metrics cross-tree row), #3195 / #3190 (provider-limit residuals), #3175 / #3177 / #3160 / #3162 (doc nits).
  • Not yet decided: whether driver.enabled defaults ON for stable (#2811 S11) — the driver stays opt-in in this build.
  • Carried: #2502, #2893, #2833, #2892.

📦 Download & install

Download the asset for your platform below.

  • Windows: Orrerix_*-setup.exe (NSIS installer; no .msi on pre-releases). Installs over an existing Orrerix install.
  • macOS: Orrerix_*_aarch64.dmg (Apple Silicon) or Orrerix_*_x64.dmg (Intel) — unsigned; if macOS reports the app as damaged, run xattr -cr /Applications/Orrerix.app once.
  • Linux: Orrerix_*.AppImage (portable), *.deb, or *.rpm

Or use the one-liner installers in the README (they resolve the latest stable release — v1.2.0 — not this beta).


Full commit log: v1.3.0-beta10..v1.3.0-beta11. Installers are unsigned — macOS "damaged app" and Windows SmartScreen warnings are expected, not a regression.