orion v0.7.6
August 28, 2026
Fixed
- Running more than one
orion watchat a time, one per project repository, no longer loses spend. The usage ledger and the repository registry were both load-modify-save with no lock and a shared.tmpfilename, so two Orion processes writing at once published whichever snapshot renamed last: measured at one run recorded out of twelve concurrent writers. Budget enforcement was therefore materially weaker than it appeared for anyone running two watchers, because spend accumulated far slower than reality and the weekly checkpoint fired late. Both now take a cross-process lock across the whole read-modify-write, and write through a per-process temp file so two writers can never interleave inside one (OR-138). - The lock is the one
internal/statehas used for the hook path since the beginning, lifted intointernal/procsafeso there is a single implementation rather than a second one growing beside it. Its behaviour is unchanged, including the part that matters most: a lock it cannot take degrades to an unserialized write that says so, and never blocks a watcher or returns a nil release function (OR-138).