Commit Graph
4824 Commits
Author SHA1 Message Date
Kai (Tam Nhu) Tran 24582766fe Merge pull request #1727 from KennethWKZ/feat/claude-fable-5-1
feat(models): add Claude Fable 5.1 and correct Sonnet 5 pricing
2026-09-09 15:14:36 -06:00
Kenneth Wong 7ae7a5eba6 fix(extended-context): manage ANTHROPIC_DEFAULT_MODEL and keep the overlay in sync
Claude Code reads ANTHROPIC_DEFAULT_MODEL as its lowest-priority startup
model (after --model, ANTHROPIC_MODEL and the settings `model` field). It is
a plain model id, so behind a proxy a bare value is clamped to 200k exactly
like the tier keys. Add it to EXTRA_EXTENDED_CONTEXT_MODEL_ENV_KEYS so
--1m/--no-1m and the saved preference toggle it with the rest.

The `--settings` launch overlay only carried the routing keys plus the five
Anthropic tier keys. Claude Code applies the settings `env` block on top of
the process environment, so a bare CLAUDE_CODE_SUBAGENT_MODEL or
ANTHROPIC_DEFAULT_MODEL persisted on disk silently undid the resolved
--1m result (and a saved [1m] undid --no-1m). Overlay the extended-context
extra keys too.

Verified with a stub Claude binary reading the overlay file:

  ccs claude --no-1m -> ANTHROPIC_DEFAULT_MODEL=claude-opus-5, CLAUDE_CODE_SUBAGENT_MODEL=claude-sonnet-5
  ccs claude --1m    -> both keys suffixed with [1m]
2026-09-04 08:34:33 +08:00
Kenneth Wong 02c45e088a fix(extended-context): suffix the Fable tier and default it on 1M launches
The previous commit assumed Claude Code's fable resolver strips [1m] and
therefore never wrote the suffix into ANTHROPIC_DEFAULT_FABLE_MODEL. That
premise only holds when ANTHROPIC_BASE_URL is unset or points at
api.anthropic.com. Behind a proxy (CLIProxy, headroom, ...) Claude Code
2.1.259 does the opposite:

- the fable alias resolver passes the env value through untouched, so a
  saved `claude-fable-5-1[1m]` reaches the model picker as-is;
- the context-window resolver grants 1M unconditionally when the model id
  carries [1m], and otherwise trusts a natively-1M model only when the base
  URL is first-party. Bare `claude-fable-5-1` via 127.0.0.1 is clamped to
  200k even though CLIProxy's /v1/models advertises max_input_tokens 1M.

So the suffix is the only thing that turns the long window on for CCS, and
stripping it from the Fable key is what kept `ccs claude --model fable` at
200k. A headroom settings profile with the suffix saved on that key showed
the 1M window in the same Claude Code build, which is how the inversion was
caught.

Changes:

- Drop the suffix-stripping key guard; ANTHROPIC_DEFAULT_FABLE_MODEL now
  receives and keeps [1m] exactly like the opus/sonnet tiers.
- On a long-context launch (explicit --1m, or a saved [1m] on any Anthropic
  tier key) fill a missing Fable tier with the catalog Fable model plus
  [1m]. The model-neutral claude profile pins no Fable model, so `--model
  fable` used to fall back to Claude Code's bare default and lose the window
  even when every other tier asked for 1M. An explicit mapping always wins,
  --no-1m never fills, and providers without a catalog Fable model are left
  alone.
- Add getDefaultFableTierModel() to the model catalog for that default.

Verified with a stub Claude binary that dumps its environment:

  ccs claude --model fable          -> ANTHROPIC_DEFAULT_FABLE_MODEL=claude-fable-5-1[1m]
  ccs claude --1m                   -> ANTHROPIC_DEFAULT_FABLE_MODEL=claude-fable-5-1[1m]
  ccs claude --no-1m --model fable  -> no Fable tier written, ANTHROPIC_MODEL stripped
2026-09-04 02:48:15 +08:00
Kenneth Wong 2b780ceae3 fix(extended-context): never write [1m] into the Fable tier key
Claude Code resolves ANTHROPIC_DEFAULT_FABLE_MODEL through a resolver that
strips the [1m] suffix before use, unlike the opus/sonnet resolvers which
pass their env value through untouched. The stripped value is then treated
as an env-supplied default and held to the standard 200k window instead of
the model's native 1M, so writing [1m] into that key costs the long context
window rather than granting it.

Measured against a Claude Code 2.1.259 session (`/context` on a live proxy
endpoint):

  ANTHROPIC_MODEL=claude-fable-5-1[1m]               -> 1m window
  ANTHROPIC_MODEL=claude-fable-5-1                   -> 200k window
  ANTHROPIC_DEFAULT_FABLE_MODEL=claude-fable-5-1[1m] -> 200k window

The fix is key-scoped rather than model-scoped, since the suffix is what
grants 1M on every other key. Adds envKeyAcceptsExtendedContextSuffix() as
the single place recording which keys reject the suffix, enforces it as a
floor inside applyExtendedContextPreferenceToAnthropicModels() so no caller
can bypass it, and strips a previously saved suffix from that key on the
next launch through the auto path.

Also extends the preference to CLAUDE_CODE_SUBAGENT_MODEL. Subagent windows
come from the same resolver as the main loop (the Explore inheritCap bounds
the model tier, not the context window), so a bare subagent model id sits at
200k while the suffixed form gets 1M. The new key list is kept separate from
ANTHROPIC_MODEL_ENV_KEYS, which also drives routing, model-id normalization
and profile validation.

Claude-Session: https://claude.ai/code/session_01NPkafQjVf4pSwPBwBistGk
2026-09-03 17:08:23 +08:00
Kenneth Wong 3583b544d0 feat(models): add Claude Fable 5.1 and correct Sonnet 5 pricing
Register `claude-fable-5-1` in the CLIProxy model catalog, the dashboard
catalog, and the usage pricing registry.

Pricing is taken from Anthropic's official pricing page:

- Fable 5.1 base rates are $10/$50 per MTok with a $12.50 5m cache write,
  matching Fable 5.
- Cache hits bill at 0.025x base input ($0.25/MTok) rather than the
  standard 0.1x multiplier. Anthropic applies that reduced rate only to
  Fable 5.1 and Mythos 5.1, so this entry cannot derive its cache rates
  from CACHE_READ_MULTIPLIER.

This also corrects Claude Sonnet 5 from $3/$15 to $2/$10 (cache write
$2.50, cache read $0.20). The launch introductory rate became the
standard price and the increase scheduled for 2026-09-01 was cancelled,
so the previous entry over-reported Sonnet 5 usage cost by 50%.

Thinking on Fable 5.1 is always on and can only be steered through
effort levels, so the catalog entry exposes the same `low`..`max` level
surface as Fable 5 and Opus 5 instead of a manual token budget.

The GitHub Copilot catalog is deliberately left unchanged, since Copilot
availability for Fable 5.1 is not verified; surfacing it there would
offer a model the backend may reject.

Regenerates docs/reports/hardening-inventory.{json,md} so the ci-parity
gate matches the source tree.
2026-09-03 16:26:41 +08:00
github-actions[bot] 485c436958 chore(release): 8.9.0-dev.9 2026-08-27 03:05:30 +00:00
Tam Nhu Tran 0598d2a7ba fix(docs): format star history chart with valid sealed_token url 2026-08-26 23:01:17 -04:00
Tam Nhu Tran 583d0cf8fc fix(docs): update star history chart with encrypted sealed_token 2026-08-26 23:01:07 -04:00
github-actions[bot] 768be0db8a chore(release): 8.9.0-dev.8 2026-08-25 20:27:08 +00:00
Kai (Tam Nhu) Tran 83ccb21f8d Merge pull request #1723 from kaitranntt/kai/docs/hardening-inventory-and-75-quota-test
docs: refresh hardening inventory and add 75% quota test
2026-08-25 16:22:52 -04:00
github-actions[bot] d10b5653ff chore(release): 8.9.0-dev.7 2026-08-25 20:14:40 +00:00
Tam Nhu Tran eddc404f24 docs: refresh hardening inventory and add 75% quota test 2026-08-25 16:13:41 -04:00
Kai (Tam Nhu) Tran 253439e001 Merge pull request #1722 from kaitranntt/kai/fix/ascii-quota-bar-and-doctor-tests
fix(cliproxy): make formatQuotaBar pure ASCII and add doctor quota tests
2026-08-25 16:10:19 -04:00
github-actions[bot] 51c603b0aa chore(release): 8.9.0-dev.6 2026-08-25 20:07:25 +00:00
Tam Nhu Tran 745cb74318 fix(cliproxy): make formatQuotaBar pure ASCII and add doctor quota tests 2026-08-25 16:04:33 -04:00
Kai (Tam Nhu) Tran 8f87937e8a Merge pull request #1721 from kaitranntt/kai/fix/1716-websearch-probe-perf
fix(websearch): filter disabled legacy CLI probes and skip unused version fetching (#1716)
2026-08-25 16:02:43 -04:00
Kai (Tam Nhu) Tran 21f10c007b Merge pull request #1720 from kaitranntt/kai/fix/1714-quota-remaining-label
feat(cliproxy): clarify quota percentages are remaining in CLI output (#1714)
2026-08-25 16:02:40 -04:00
Tam Nhu Tran c0c36991d6 fix(websearch): format status.ts 2026-08-25 15:56:12 -04:00
Tam Nhu Tran f4911694e3 fix(websearch): filter disabled legacy CLI probes and skip unused version fetching
Closes #1716
2026-08-25 15:35:54 -04:00
Tam Nhu Tran eca266ad30 feat(cliproxy): clarify quota percentages are remaining in CLI output
Closes #1714
2026-08-25 15:35:23 -04:00
github-actions[bot] 65dc902299 chore(release): 8.9.0-dev.5 2026-08-25 18:54:51 +00:00
Kai (Tam Nhu) Tran a5aa9ac35f Merge pull request #1717 from mardausdennis/feat/collapsible-proxy-status-widget
feat(dashboard): collapse the CLIProxy status widget
2026-08-25 14:50:28 -04:00
Kai (Tam Nhu) Tran ff27a36b92 Merge pull request #1718 from sgaluza/fix/adopt-settings-publish-by-replacement
fix(shared-manager): publish adopted settings by replacement
2026-08-25 14:50:19 -04:00
Sergey Galuza 4a17f034e2 docs(shared-manager): note why the CAS mismatch raises EEXIST
The code is this file's marker for "a race was detected" - the same one
the reappeared-path and concurrent-replacement guards raise - not a
report that a no-replace link() or open('wx') hit an existing path. Say
so at the throw, so debugging by err.code does not send anyone looking
for a no-replace failure that never happened.

Built [OnSteroids](https://onsteroids.ai)
2026-08-23 08:33:06 +02:00
Sergey Galuza df52662a59 refactor(shared-manager): extract the durable temp write
createFileNoReplace and publishCanonicalContent carried the same
open-wx / fchmod / write / fsync / close block and the same cleanup
handler. Extract writeDurableTempFile and discardTempFile so each
publisher is left with only what distinguishes it: a no-replace link, or
the compare-and-swap guard and the rename.

Also spell out in publishCanonicalContent that its guard is read-then-act
rather than atomic. POSIX has no compare-and-swap rename, so the window
is narrowed from the ~100 ms the old claim-and-republish path left open
to two adjacent syscalls, not closed - and the pre-image sidecar is what
keeps that last outcome recoverable. Worth stating so the guard is not
mistaken for a strict guarantee later.

Built [OnSteroids](https://onsteroids.ai)
2026-08-23 08:32:53 +02:00
Sergey Galuza fa3fd8eb3a refactor(shared-manager): tighten canonical identity capture
Build the canonical identity from the stat getCanonicalFile already
takes, instead of a second lstat of the same inode. One syscall less,
and mode, mtime and identity now describe the same moment rather than
two adjacent ones.

Assert in the adoption race tests that the foreign writer never fired.
It writes only when the canonical path is observed empty, so a zero
count states the invariant the fix establishes - the path is never left
without a regular file - instead of only checking the final content.

Built [OnSteroids](https://onsteroids.ai)
2026-08-23 08:32:39 +02:00
Sergey Galuza 00a4dceb94 fix(shared-manager): publish adopted settings by replacement
Adoption moved the canonical settings.json aside with rename() and left
the path empty until publication, roughly 100 ms later. Claude Code or a
second `ccs` starting inside that window found no file and seeded an
empty placeholder; publication then failed with EEXIST because link() is
no-replace, and the rollback published a backup and unlinked the claim,
destroying the only remaining copy of the user's settings. Recovering
meant digging through sidecar files by hand.

Publish by replacement instead: write a temp file next to the canonical
inode and rename() it over the target, so the path always holds a regular
file and no placeholder can be seeded. A compare-and-swap guard on
(ino, mtime, size) runs immediately before the rename and refuses to
publish when the canonical inode changed since it was read, so a writer
that got there first is still never clobbered. The pre-image backup is
published before the replacement, keeping the old content recoverable if
publication is interrupted.

Drops the canonical claim entirely along with restoreCanonicalClaim, and
folds the two identical sidecar publishers into one helper.
recoverOrphanedCanonicalClaim stays, since claims written by older
versions may still be on disk.

New tests cover both writers seen in the incident: Claude Code seeding
`{}` with a trailing newline, and a second `ccs` seeding the 2-byte
variant from shared-dir-linker. Four tests that pinned the claim-based
design were rewritten, among them `preserves a canonical write that
lands during no-replace publication`, whose intent is now enforced by
the CAS guard instead of by an EEXIST from a no-replace link.

Built [OnSteroids](https://onsteroids.ai)
2026-08-23 08:32:26 +02:00
mardausdennis fde7bd83db feat(dashboard): collapse the CLIProxy status widget
ProxyStatusWidget sits outside the sidebar ScrollArea, so every row it
renders is taken from the provider list. With the proxy running and pool
routing on it renders ten stacked blocks, and the only Collapsible covers
version management, which is already closed in that state.

Add a chevron that collapses the whole widget in local and remote mode,
keeping the status row, version row and action buttons visible. The
preference is stored in localStorage and defaults to expanded, so
existing setups are unchanged. Opening version settings from a collapsed
widget expands it again.
2026-08-22 01:15:41 +02:00
github-actions[bot] a53980782f chore(release): 8.9.0-dev.4 2026-08-21 15:33:50 +00:00
Kai (Tam Nhu) Tran ae1559aeb0 fix(ci): publish dev releases with public access for scoped package (#1715) 2026-08-20 12:14:14 -04:00
Kai (Tam Nhu) Tran 95faef5960 Merge pull request #1710 from kaitranntt/kai/fix/1703-image-analysis-original-backend-route
fix(image-analysis): route original backend at CLIProxy root
2026-08-19 17:43:27 -04:00
Kai (Tam Nhu) Tran 9e2897e770 Merge pull request #1711 from kaitranntt/kai/fix/1706-pnpm-global-store-layout
fix(update): detect pnpm v9+ global store layouts
2026-08-19 17:33:49 -04:00
Tam Nhu Tran a4281cea1b docs: refresh hardening inventory after merge 2026-08-19 16:58:13 -04:00
Tam Nhu Tran 75c45b6043 merge dev: refresh hardening inventory base 2026-08-19 16:58:10 -04:00
Tam Nhu Tran c43cd6caf5 fix(update): detect pnpm v9+ global store layouts
Fixes #1706
2026-08-19 16:43:15 -04:00
Tam Nhu Tran afa663b5b2 fix(image-analysis): route original backend at CLIProxy root
Fixes #1703
2026-08-19 16:43:15 -04:00
Kai (Tam Nhu) Tran 9de6e11a03 Merge pull request #1709 from kaitranntt/kai/docs/hardening-inventory-refresh
docs: refresh hardening inventory counts
2026-08-19 16:43:07 -04:00
Tam Nhu Tran b9190a6e57 docs: refresh hardening inventory counts 2026-08-19 16:35:27 -04:00
Kai (Tam Nhu) Tran 3997dbd258 Merge pull request #1708 from aaron-tsar/fix/image-analysis-profile-backends-launch
fix(image-analysis): honor configured profile_backends at launch
2026-08-19 16:35:08 -04:00
Kai (Tam Nhu) Tran 3b652460ee Merge pull request #1707 from OctoBored/fix/star-history-chart
fix(README): update star history chart to use working domain
2026-08-19 16:34:49 -04:00
Kai (Tam Nhu) Tran 9d725fcebb Merge pull request #1702 from Marc-oss-hub/feat/orcarouter-preset
feat(api): add OrcaRouter provider preset
2026-08-19 16:32:29 -04:00
Kai (Tam Nhu) Tran 28d817a97e Merge pull request #1701 from minhbi245/feat/grok-4-6-selection
feat(cliproxy): add Grok 4.6 selection
2026-08-19 16:32:25 -04:00
Kai (Tam Nhu) Tran e10577804d Merge pull request #1704 from kaitranntt/kai/fix/delegation-stdout-flush
fix(delegation): flush stdout before exit to prevent piped output truncation
2026-08-19 16:32:20 -04:00
Aaron VuandClaude fe3447f487 fix(image-analysis): honor configured profile_backends at launch
resolveImageAnalysisRuntimeStatus defaulted to DEFAULT_IMAGE_ANALYSIS_CONFIG
when callers omitted the config argument. That constant ships empty
profile_backends and a gemini fallback_backend, so the launch paths that call
it without a config (settings profile dispatch and headless delegation) never
saw user-configured mappings.

A profile mapped to another backend still resolved to gemini, failed the
Gemini auth check, and silently dropped to native Read. Profiles whose model
has no vision support could not read images at all, even with a reachable
CLIProxy and an authenticated backend.

getImageAnalysisHookEnv already reads the saved config, so the launch env and
the runtime status disagreed on the same launch: CCS_IMAGE_ANALYSIS_BACKEND_ID
carried the mapped backend while the status object reported native-read.

Default to getImageAnalysisConfig() so both read the same source. Callers that
pass an explicit config keep their existing behavior.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-17 15:27:02 +07:00
OctoBored 6e3a16b84c fix(README): update star history chart to use working domain
The current star history chart is broken due to GitHub stargazer API restrictions. Switch to star-history.dera.page which uses an alternative data source and requires no API token.
2026-08-17 07:37:34 +00:00
Tam Nhu Tran 3e49834c9d fix(delegation): flush stdout before exit to prevent piped output truncation
console.log followed immediately by process.exit truncated piped output
at the pipe buffer (about 64 KiB) because stdout writes to pipes are
asynchronous. Interactive TTY runs were unaffected, so the bug only
surfaced for callers consuming ccs delegation output through a pipe,
such as scripts parsing --output-format json results from thinking
heavy GLM sessions.

Await an explicit stdout write callback before exiting in both route()
and _handleContinue().
2026-08-14 17:57:39 -04:00
Marc-oss-hubandClaude ea7906b975 feat(api): add OrcaRouter provider preset
Add a named 'orcarouter' preset to the shared provider catalog mirroring
the existing OpenRouter entry: OpenAI-compatible base URL
https://api.orcarouter.ai/v1, default model openai/gpt-5.5, sk-orca-...
key placeholder, and a dashboard icon. Regenerate the throw-error
baseline for the line shift in provider-preset-catalog.ts.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-13 22:29:17 +08:00
Khanh.NVMandClaude Fable 5 c30e9ca617 feat(cliproxy): add Grok 4.6 selection
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-13 16:23:24 +07:00
github-actions[bot] a0990e0ef1 chore(release): 8.9.0-dev.3 2026-08-11 02:24:22 +00:00
Kai (Tam Nhu) Tran 2ef2612df8 Merge pull request #1699 from kaitranntt/kai/fix/cliproxy-safe-updates-dev
fix(cliproxy): keep proxy continuously recoverable
2026-08-10 22:20:13 -04:00