Skip to main content

orion v0.6.0

August 27, 2026

The first release where Orion's memory does something. Also the release that restores the branch model: agents merge into develop, and main moves only when a person promotes it.

Added​

  • Orion now proposes lessons by itself. When a branch whose CI went red is fixed and merged, orion collect files that as an observation — a mistake with its own correction attached, both seen by the system rather than inferred by an agent. The same observation twice becomes a proposal you are asked about; approve it with orion lessons approve <sig> and it enters the store, reject it and it is never raised again. orion lessons pending lists what is waiting.

    The cross-project memory has been shipping since v0.1 and had never held anything: every writer was a command a human had to remember to type, so nothing ever counted to two and nothing was ever lifted. The ranking, expiry and promotion downstream were all correct, and all operating on an empty list.

    Nothing is written without a yes. The store is append-only and injected into every session's CLAUDE.md, so a wrong lesson is durable and re-read forever — which is why an agent is allowed to observe, never to record.

Changed​

  • The generated sandbox settings are regenerated for every job, not only at adoption. A sandbox adopted before a policy fix used to keep the old policy until someone re-ran orion init — and the run that would benefit is the one that cannot know it should.

  • orion lessons list can no longer report an empty store as if it were a working one. When nothing has been recorded it now says whether anything has ever been observed, and how many proposals are waiting. An empty answer and a broken subsystem used to be the same output.

  • A lesson without a project is refused. Provenance — what happened, where, and when — is what makes a durable rule worth trusting later.

  • A run that correctly changes nothing is no longer reported as a failure. An agent that inspects the tree, finds the issue's work already present and declines to invent a diff now ends in a distinct no-op outcome: no orion-failed label, a tracker comment saying what it found and why it did nothing, the claim released, and the ticket moved off In Progress. Only an explicit NOTHING TO DO: line from the agent counts — an agent that stopped to ask a question is still blocked, and still labelled as one. Conflating the two teaches the reader that orion-failed sometimes means "fine, actually", which is how a failure label stops carrying information.

Fixed​

  • The sandbox no longer denies loopback binds. Any test that stands up a local HTTP server — Go's httptest, and its equivalent everywhere else — panicked on bind: operation not permitted, so those packages could not be tested inside a sandbox at all. Three of Orion's own failed that way on every run, and an agent had to recognise the failure as environmental and proceed anyway, which is a habit worth not teaching. The network allowlist is unchanged and still governs egress: a socket on 127.0.0.1 reaches nothing but the process that opened it.

  • Each sandbox now gets a persistent Go build cache at .orion/cache/go-build, provisioned once and shared by every job. The default cache is outside the sandbox's writable set, so runs had been redirecting GOCACHE to a fresh temp directory and recompiling the standard library from cold once per ticket.

  • A merged ticket is no longer worked a second time. orion work asks the forge whether the ticket's branch has already merged before it claims anything, and ends the run there if it has: labels cleared, ticket moved to Done, nothing spent. The claim label is meant to be the lock, but a label that was never cleared — or was cleared after the next tick had already read the queue — left a window in which a finished ticket was still workable, and a re-run costs a full agent at full token price to produce nothing. Asking the forge closes the window whichever way it opened. A check that cannot be made (no gh, no network) is a warning, not a merged branch, so the work still runs.


Download v0.6.0 · Staying current