`ccs bar stop` deletes bar.json, so a bar.json-only sticky port is lost on
every stop/start cycle: the next launch reverted to 3000 and the probe could
no longer find a server still running on the previously chosen port.
resolveBarPort now falls back to the --port recorded in launch.json (written
by launch, not deleted by stop), which restores both the sticky port and
probe discovery after a stop.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
A cached row whose next_reset has passed describes the previous quota
window — the quota snapped back at the boundary, so serving it for the rest
of the 10-min TTL shows wrong percentages and an already-elapsed reset time
in the bar. Both the per-profile TTL short-circuit and the rotating-slot
eligibility now mark such rows stale. Guarded by cachedAt < resetAt so a
post-reset payload that still reports a past reset cannot refetch-loop.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Fixes the two collector-side root causes of #1601:
1. Claude per-profile credential reads were file-only, but on macOS Claude
Code stores the OAuth token for an isolated CLAUDE_CONFIG_DIR in a
per-directory Keychain item ("Claude Code-credentials-<sha256(dir)[0..8]>").
The .credentials.json file never exists, so every isolated profile was
parked with needsReauth:true forever. The reader now falls back to that
Keychain item (file-first, same security-CLI read the shipped global
fallback already performs; TTL-gated so it is not on every /summary).
2. Non-default profiles were cache-only forever, so they could never leave
the parked state even with valid credentials. getNativeAccountRows now
gives each surface ONE rotating live slot: the stalest eligible
non-default profile is refreshed per pass, skipping profiles inside
breaker/reauth cooldowns. Every account converges to real quota within a
few polls while the per-pass upstream budget stays constant (<= 2 calls
per surface regardless of profile count). Codex named profiles with valid
auth but sparse payloads now yield an active quota-less row instead of a
false needsReauth row.
Non-default rows keep paused:true (dimmed) even when freshly refreshed so
only the default renders active and rows do not flicker between polls.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
ccs bar always forced the dashboard onto port 3000 (first free of a
hardcoded candidate list), which collides with other local dev servers, and
bar.json was rewritten to 3000 on every launch.
- `ccs bar [launch] --port N` runs the server on exactly N: reuses a live
server already on N, moves a running server from another port (SIGTERM via
server.pid, wait for exit), errors clearly when N is busy or the value is
invalid.
- The chosen port is persisted into launch.json args, so the Swift app
self-starts the server on the same port.
- Without --port, launch and serve now try the port recorded in bar.json
first (sticky), so the server keeps coming back on the port the user last
chose instead of reverting to 3000.
- Bare flags (`ccs bar --port N`) route to the launch subcommand; --port is
documented in `ccs bar --help`.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude Code sends the system prompt as the top-level `system` field and,
separately, sends skill/plugin listings as `role: "system"` entries inside
`messages` (#1459 made the transformer accept those). `transform()`
unconditionally prepends the top-level field, so once both are present the
OpenAI-compat payload ends up with two `system` messages that are not
adjacent. `coalesceMessages` only merges consecutive same-role messages and
explicitly skips `system`, so it cannot fix this.
Strict OpenAI-compatible backends (LiteLLM among them) reject that shape with:
400 A 'system' message can only appear at index 0 of the messages array.
Add `hoistSystemMessages`, run before `coalesceMessages`, which extracts every
`system` message in encounter order and reinserts a single merged one at
index 0. Content-preserving, no behavior change when at most one system
message is present.
The same atomic-rename divergence occurs in the plugins subtree: a
plugin install inside a session rewrites plugins/installed_plugins.json,
replacing the instance-level symlink with a regular file. The per-launch
relink then discarded it, so the plugin was effectively uninstalled on
every relaunch while settings.json still marked it enabled — sessions
then fail with 'Unknown skill: <plugin>:<skill>'.
Move adoptDivergedFileContent to fs-helpers (avoids a circular import)
and apply it to file-type plugin entries before re-linking.
Claude Code saves settings.json atomically (temp file + rename), which
replaces the managed shared symlink with a regular file holding the
user's latest changes (see #57). The launch-time relink then deleted
that file without reading it, silently reverting plugin enables and any
other in-session settings change on every profile relaunch.
Adopt the diverged file's content into the canonical ~/.claude file
(with a .bak-ccs-adopt backup) before restoring the symlink, at both
the shared-level and instance-level reconciliation points.
Fixes#1681