Commit Graph
1234 Commits
Author SHA1 Message Date
Sergey Galuza fa3fd8eb3a refactor(shared-manager): tighten canonical identity capture
Build the canonical identity from the stat getCanonicalFile already
takes, instead of a second lstat of the same inode. One syscall less,
and mode, mtime and identity now describe the same moment rather than
two adjacent ones.

Assert in the adoption race tests that the foreign writer never fired.
It writes only when the canonical path is observed empty, so a zero
count states the invariant the fix establishes - the path is never left
without a regular file - instead of only checking the final content.

Built [OnSteroids](https://onsteroids.ai)
2026-08-23 08:32:39 +02:00
Sergey Galuza 00a4dceb94 fix(shared-manager): publish adopted settings by replacement
Adoption moved the canonical settings.json aside with rename() and left
the path empty until publication, roughly 100 ms later. Claude Code or a
second `ccs` starting inside that window found no file and seeded an
empty placeholder; publication then failed with EEXIST because link() is
no-replace, and the rollback published a backup and unlinked the claim,
destroying the only remaining copy of the user's settings. Recovering
meant digging through sidecar files by hand.

Publish by replacement instead: write a temp file next to the canonical
inode and rename() it over the target, so the path always holds a regular
file and no placeholder can be seeded. A compare-and-swap guard on
(ino, mtime, size) runs immediately before the rename and refuses to
publish when the canonical inode changed since it was read, so a writer
that got there first is still never clobbered. The pre-image backup is
published before the replacement, keeping the old content recoverable if
publication is interrupted.

Drops the canonical claim entirely along with restoreCanonicalClaim, and
folds the two identical sidecar publishers into one helper.
recoverOrphanedCanonicalClaim stays, since claims written by older
versions may still be on disk.

New tests cover both writers seen in the incident: Claude Code seeding
`{}` with a trailing newline, and a second `ccs` seeding the 2-byte
variant from shared-dir-linker. Four tests that pinned the claim-based
design were rewritten, among them `preserves a canonical write that
lands during no-replace publication`, whose intent is now enforced by
the CAS guard instead of by an EEXIST from a no-replace link.

Built [OnSteroids](https://onsteroids.ai)
2026-08-23 08:32:26 +02:00
Kai (Tam Nhu) Tran ae1559aeb0 fix(ci): publish dev releases with public access for scoped package (#1715) 2026-08-20 12:14:14 -04:00
Kai (Tam Nhu) Tran 95faef5960 Merge pull request #1710 from kaitranntt/kai/fix/1703-image-analysis-original-backend-route
fix(image-analysis): route original backend at CLIProxy root
2026-08-19 17:43:27 -04:00
Tam Nhu Tran c43cd6caf5 fix(update): detect pnpm v9+ global store layouts
Fixes #1706
2026-08-19 16:43:15 -04:00
Tam Nhu Tran afa663b5b2 fix(image-analysis): route original backend at CLIProxy root
Fixes #1703
2026-08-19 16:43:15 -04:00
Kai (Tam Nhu) Tran 3997dbd258 Merge pull request #1708 from aaron-tsar/fix/image-analysis-profile-backends-launch
fix(image-analysis): honor configured profile_backends at launch
2026-08-19 16:35:08 -04:00
Aaron VuandClaude fe3447f487 fix(image-analysis): honor configured profile_backends at launch
resolveImageAnalysisRuntimeStatus defaulted to DEFAULT_IMAGE_ANALYSIS_CONFIG
when callers omitted the config argument. That constant ships empty
profile_backends and a gemini fallback_backend, so the launch paths that call
it without a config (settings profile dispatch and headless delegation) never
saw user-configured mappings.

A profile mapped to another backend still resolved to gemini, failed the
Gemini auth check, and silently dropped to native Read. Profiles whose model
has no vision support could not read images at all, even with a reachable
CLIProxy and an authenticated backend.

getImageAnalysisHookEnv already reads the saved config, so the launch env and
the runtime status disagreed on the same launch: CCS_IMAGE_ANALYSIS_BACKEND_ID
carried the mapped backend while the status object reported native-read.

Default to getImageAnalysisConfig() so both read the same source. Callers that
pass an explicit config keep their existing behavior.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-17 15:27:02 +07:00
Marc-oss-hubandClaude ea7906b975 feat(api): add OrcaRouter provider preset
Add a named 'orcarouter' preset to the shared provider catalog mirroring
the existing OpenRouter entry: OpenAI-compatible base URL
https://api.orcarouter.ai/v1, default model openai/gpt-5.5, sk-orca-...
key placeholder, and a dashboard icon. Regenerate the throw-error
baseline for the line shift in provider-preset-catalog.ts.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-13 22:29:17 +08:00
Tam Nhu Tran 54c3e86e89 fix(docker): target live cliproxy compose stack 2026-08-10 22:13:29 -04:00
Tam Nhu Tran fc56ecaac4 fix(cliproxy): finish concurrent update recovery 2026-08-10 22:13:29 -04:00
Tam Nhu Tran 4502e5d503 fix(cliproxy): harden update recovery paths 2026-08-10 22:13:29 -04:00
Tam Nhu Tran 8e4def4713 fix(cliproxy): keep proxy available during updates 2026-08-10 22:13:29 -04:00
Tam Nhu Tran 54efb82055 fix(auth): guard shared linking against instance replacement 2026-08-08 23:06:29 -04:00
Tam Nhu Tran 5f9db033e7 chore: merge origin/dev into issue #1688
# Conflicts:
#	docs/reports/hardening-inventory.json
#	docs/reports/hardening-inventory.md
2026-08-08 22:29:46 -04:00
Tam Nhu Tran 0ddeb09955 chore(dev): merge v8.8.1-dev.20 for issue 1686 2026-08-08 22:09:27 -04:00
Tam Nhu Tran ce8ad269f0 chore(merge): sync dev release v8.8.1-dev.19 2026-08-08 21:48:56 -04:00
Tam Nhu Tran 4d5449a493 Merge remote-tracking branch 'origin/dev' into kai/review/pr-1691
# Conflicts:
#	docs/reports/hardening-inventory.json
#	docs/reports/hardening-inventory.md
2026-08-08 21:31:32 -04:00
Tam Nhu Tran 1a80717f99 fix(bar): harden lifecycle process handling 2026-08-08 21:17:51 -04:00
Tam Nhu Tran 6841025bb4 feat(auth): share canonical Claude memory
Refs #1688
2026-08-08 21:17:32 -04:00
Tam Nhu Tran d8210cf011 fix(proxy): stabilize upstream fetch transport
Refs #1686
2026-08-08 21:17:13 -04:00
Tam Nhu Tran 6721d47502 fix(auth): preserve explicit resume session continuity
Refs #1685
2026-08-08 21:17:01 -04:00
Tam Nhu Tran 59eec74f40 chore: merge released dev into PR #1690 2026-08-08 21:14:50 -04:00
Tam Nhu Tran da2de60015 fix(bar): bound native credential and quota waits 2026-08-08 21:12:28 -04:00
Tam Nhu Tran c621241a2e test(proxy): harden system message ordering
Cover supported late-system and tool-result ordering invariants.

Refs #1687
2026-08-08 20:59:37 -04:00
poomscandClaude Fable 5 d27b53f235 fix(bar): keep sticky port across ccs bar stop via launch.json fallback
`ccs bar stop` deletes bar.json, so a bar.json-only sticky port is lost on
every stop/start cycle: the next launch reverted to 3000 and the probe could
no longer find a server still running on the previously chosen port.
resolveBarPort now falls back to the --port recorded in launch.json (written
by launch, not deleted by stop), which restores both the sticky port and
probe discovery after a stop.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-08 14:50:18 +07:00
poomscandClaude Fable 5 833473c5f6 fix(bar): treat cached quota rows as stale once their reset passes
A cached row whose next_reset has passed describes the previous quota
window — the quota snapped back at the boundary, so serving it for the rest
of the 10-min TTL shows wrong percentages and an already-elapsed reset time
in the bar. Both the per-profile TTL short-circuit and the rotating-slot
eligibility now mark such rows stale. Guarded by cachedAt < resetAt so a
post-reset payload that still reports a past reset cannot refetch-loop.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-08 14:43:52 +07:00
poomscandClaude Fable 5 a5a5b742e4 fix(bar): stop false re-auth on non-default native subscription profiles
Fixes the two collector-side root causes of #1601:

1. Claude per-profile credential reads were file-only, but on macOS Claude
   Code stores the OAuth token for an isolated CLAUDE_CONFIG_DIR in a
   per-directory Keychain item ("Claude Code-credentials-<sha256(dir)[0..8]>").
   The .credentials.json file never exists, so every isolated profile was
   parked with needsReauth:true forever. The reader now falls back to that
   Keychain item (file-first, same security-CLI read the shipped global
   fallback already performs; TTL-gated so it is not on every /summary).

2. Non-default profiles were cache-only forever, so they could never leave
   the parked state even with valid credentials. getNativeAccountRows now
   gives each surface ONE rotating live slot: the stalest eligible
   non-default profile is refreshed per pass, skipping profiles inside
   breaker/reauth cooldowns. Every account converges to real quota within a
   few polls while the per-pass upstream budget stays constant (<= 2 calls
   per surface regardless of profile count). Codex named profiles with valid
   auth but sparse payloads now yield an active quota-less row instead of a
   false needsReauth row.

Non-default rows keep paused:true (dimmed) even when freshly refreshed so
only the default renders active and rows do not flicker between polls.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-08 14:18:00 +07:00
poomscandClaude Fable 5 34608ce291 feat(bar): support --port for ccs bar with sticky port persistence
ccs bar always forced the dashboard onto port 3000 (first free of a
hardcoded candidate list), which collides with other local dev servers, and
bar.json was rewritten to 3000 on every launch.

- `ccs bar [launch] --port N` runs the server on exactly N: reuses a live
  server already on N, moves a running server from another port (SIGTERM via
  server.pid, wait for exit), errors clearly when N is busy or the value is
  invalid.
- The chosen port is persisted into launch.json args, so the Swift app
  self-starts the server on the same port.
- Without --port, launch and serve now try the port recorded in bar.json
  first (sticky), so the server keeps coming back on the port the user last
  chose instead of reverting to 3000.
- Bare flags (`ccs bar --port N`) route to the launch subcommand; --port is
  documented in `ccs bar --help`.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-08 14:09:58 +07:00
sn4p.dev b720231077 fix(proxy): hoist duplicate system messages before coalescing
Claude Code sends the system prompt as the top-level `system` field and,
separately, sends skill/plugin listings as `role: "system"` entries inside
`messages` (#1459 made the transformer accept those). `transform()`
unconditionally prepends the top-level field, so once both are present the
OpenAI-compat payload ends up with two `system` messages that are not
adjacent. `coalesceMessages` only merges consecutive same-role messages and
explicitly skips `system`, so it cannot fix this.

Strict OpenAI-compatible backends (LiteLLM among them) reject that shape with:
  400 A 'system' message can only appear at index 0 of the messages array.

Add `hoistSystemMessages`, run before `coalesceMessages`, which extracts every
`system` message in encounter order and reinserts a single merged one at
index 0. Content-preserving, no behavior change when at most one system
message is present.
2026-08-06 11:28:18 +02:00
Tam Nhu Tran 7ae617f0ee fix(shared-manager): preserve diverged files safely 2026-08-02 20:21:09 -04:00
Nelson Melo fa6b27f159 fix(shared-manager): adopt diverged plugin registry files in linkInstancePlugins
The same atomic-rename divergence occurs in the plugins subtree: a
plugin install inside a session rewrites plugins/installed_plugins.json,
replacing the instance-level symlink with a regular file. The per-launch
relink then discarded it, so the plugin was effectively uninstalled on
every relaunch while settings.json still marked it enabled — sessions
then fail with 'Unknown skill: <plugin>:<skill>'.

Move adoptDivergedFileContent to fs-helpers (avoids a circular import)
and apply it to file-type plugin entries before re-linking.
2026-07-31 13:40:23 -04:00
Nelson Melo 481f013ec2 fix(shared-manager): adopt diverged settings.json content before re-linking
Claude Code saves settings.json atomically (temp file + rename), which
replaces the managed shared symlink with a regular file holding the
user's latest changes (see #57). The launch-time relink then deleted
that file without reading it, silently reverting plugin enables and any
other in-session settings change on every profile relaunch.

Adopt the diverged file's content into the canonical ~/.claude file
(with a .bak-ccs-adopt backup) before restoring the symlink, at both
the shared-level and instance-level reconciliation points.

Fixes #1681
2026-07-31 12:14:29 -04:00
Tam Nhu Tran 26c1393c16 ci(review): configure explicit reasoning effort 2026-07-31 10:32:32 -04:00
Tam Nhu Tran c107a6752c test(cliproxy): cover auto compact windows 2026-07-29 13:46:53 -04:00
Kai (Tam Nhu) Tran 236471100c Merge pull request #1676 from kaitranntt/kai/fix/1648-disabled-websearch-steering
fix(websearch): honor disabled steering per launch
2026-07-29 13:44:56 -04:00
Tam Nhu Tran 92fb66c47b test(cliproxy): cover Claude quota probe 429s 2026-07-29 13:22:21 -04:00
Tam Nhu Tran 9f5706c275 test(websearch): cover disabled launch snapshots 2026-07-29 13:22:21 -04:00
Tam Nhu Tran d700030018 test(cliproxy): cover concurrent state writers 2026-07-29 12:52:03 -04:00
Kenneth Wong ee90dd2640 feat: support claude opus 5 2026-07-27 15:07:26 +08:00
Kai (Tam Nhu) Tran b09f8191f3 Merge pull request #1669 from kaitranntt/kai/docs/1666-pruning-freshness
docs: prune stale guides and enforce freshness
2026-07-26 22:09:35 -04:00
Tam Nhu Tran 8dc6b817b2 test(docs): enforce documentation freshness 2026-07-26 09:36:01 -04:00
Tam Nhu Tran 306a8276b3 fix(metrics): enforce exact runtime inventory 2026-07-26 09:36:00 -04:00
Tam Nhu Tran 1e11335348 docs(contributing): align test and UI guidance 2026-07-26 09:34:18 -04:00
Tam Nhu Tran 2d909a162f Merge remote-tracking branch 'origin/dev' into kai/review/pr-1655-retry-followup 2026-07-22 15:08:11 -04:00
Tam Nhu Tran 480b79551b fix: apply cliproxy retry settings safely 2026-07-22 15:08:06 -04:00
Kai (Tam Nhu) Tran 9cbf02b1be Merge pull request #1652 from minhbi245/feat/fable-tier-mapping
feat(ui): add fable tier row in model mapping
2026-07-22 14:59:24 -04:00
Tam Nhu Tran f7241d0874 fix: propagate fable model mapping across runtime paths 2026-07-22 14:58:57 -04:00
Kai (Tam Nhu) Tran 3608bf71a1 feat: rebrand CCS as Claude Codex Switch (#1658)
Closes #1657
2026-07-22 14:23:42 -04:00
milesnguyen2405 b27a007229 feat(ui): add fable tier row in model mapping 2026-07-22 14:51:40 +07:00