orion v0.8.4
August 31, 2026
Fixed
- Every supervised run on macOS failed to authenticate on v0.8.3. OR-213
gave each run a curated
CLAUDE_CONFIG_DIR, and on macOS such a directory can never log in: the CLI wants.claude.jsonINSIDE the config directory while the operator's own lives at~/.claude.json, outside~/.claude/, and the Keychain credentials are not reached for a non-default directory. Supplying.claude.jsonis necessary and still not sufficient. The result wasclaude is not authenticatedon every ticket while the operator's own CLI worked normally, and re-authenticating could not fix it. - Orion no longer builds a curated directory on macOS. It inherits the operator's configuration there and says so on every run, because a run that is not capability-curated must not be silent about it: the whole plugin surface is in scope, which is what OR-213 exists to prevent. Linux and CI are unchanged and stay curated.
linkCredentialsno longer returns silently when it finds nothing to carry over. That silence is why this shipped: the code assumed an absent.credentials.jsonmeant the platform kept credentials elsewhere and all was well, and said nothing when the assumption was wrong.