Unconfigured teammates were spawned as claude-opus-4-8, so mapped
third-party providers such as cc-switch DeepSeek billed the expensive
fallback. Agent page aliases now resolve through the provider mapping.
A building or empty local index used to fall through to a full transcript scan, so opening the sidebar or traces page could sit on GET /api/sessions until the 120s client timeout. Serve partial SQLite rows instead, look up trace titles by session id, and treat client disconnects as 499.
Print-mode team leads were treating mailbox permission asks as ordinary chat, so desktop members hung forever with no approval UI. Forward those requests through the existing can_use_tool host prompt and label them with the teammate name.
The test-connection row is a flex row where the result text kept its default
`min-width: auto`, so a long upstream error forced every pixel of overflow onto
the button. Because `size="sm"` pins the height at h-6, the label wrapped and
the button rendered as a squashed two-line block.
Pin the button with `shrink-0 whitespace-nowrap` and let the error text take the
remaining width (`min-w-0 flex-1 break-words`) so long messages, including
unbreakable URLs, wrap inside the row.
The sidebar shell's permanent compositing layer dropped macOS app-region
hits around the traffic lights. The workspace header slot also marked its
leftover titlebar space as no-drag, so the empty strip could not move the
window on either platform.
The fold button was shown whenever a project was marked expanded, including
short lists auto-expanded by history paging. Keep it only above the 6-session
threshold. Replace the composer percentage chip with a compact ring.
PUBLIC_ACCESS_CONSENT_VERSION moved to 2 when remote provider management
landed, but the Electron IPC validator still accepted only the literal 1.
The renderer sends the constant, so publicAccessStart was rejected as an
invalid payload in the preload guard and again in the main-process handler,
before PublicAccessManager saw the request at all. That rejection bypasses
the manager's error classification, so the settings page could only show the
generic "operation failed" line while the state stayed disabled: public
access could not be enabled, and autoStart could never become eligible
because consent v2 was never persisted.
Validate against the shared constant instead of a copy of its value, and
stop pinning the stale literal in the tests that let this drift through:
capabilities.test.ts and electronHost.test.ts now send the constant and
reject the previous, next and non-numeric versions.
The skills tab mounted the connector catalog as a featured row above the
skill market, and that row was the only place the five curated packages
(frontend design, canvas design, generative art, webapp testing, MCP
builder) were offered. Stop mounting it, so the tab renders the market
alone and those packages have no entry point left in the UI.
The featured slot on Market and MarketHome stays in place, and the
catalog, bundle lock and installer under src/services/connectors are
untouched: restoring the row is a change to one branch of ExtensionMarket,
packages already installed keep working, and their mentions still resolve.
The ExtensionMarket test now asserts the tab does not mount the catalog
again.
The context panel could say what was in the window but nothing about what the
session had spent: no total token count, no cache hit rate, no generation speed.
The numbers were already on the wire — translateCliUsage picked four token
buckets out of the CLI's result message and dropped duration_ms, duration_api_ms
and num_turns with them — and nothing anywhere accumulated how long the model
spent emitting tokens rather than waiting on prefill.
Measure that span where it happens: a decode span opens at the first generated
delta and closes at message_stop, rides the stream_event up to QueryEngine, and
accumulates in cost-tracker beside totalAPIDuration, including the project
config restore path so it survives a CLI restart. Tokens/sec is output over that
span, never over wall clock, which would divide by tool execution time.
The totals needed fixing before they were worth showing. Claude Code persists one
JSONL line per content block of a reply and repeats the whole usage object on
every one, so summing lines overstated real transcripts by 2.2x — and
chooseRicherUsage prefers the larger of two snapshots, so the inspector actively
selected the inflated one. The transcript readers and the renderer's history
summary now deduplicate on usageAccounting's key, the rule stats.ts and the
activity index already use.
The panel polls a usageOnly inspection mode while it is open and stops when it
closes: one get_session_usage control, no skills-directory scan, no transcript
re-read, and no request stacked behind one that has not answered.
When a text-only model rejects an image with wording the classifier
doesn't recognize, the 400 fell through to a generic API error with no
businessErrorCode, so normalizeMessagesForAPI never stripped the image
and every later turn on that model re-failed the same way. And when the
wording did match, the strip anchor applied forever — switching to a
vision-capable model still replayed history with the image removed.
Classify any 400/422 on a request that actually carried image blocks as
image_unsupported when no more specific classifier matched, and gate the
error-anchored strip to the model that produced the error (sourceModel):
the same model keeps stripping and heals, a different model replays the
image, and a misclassified anchor only ever affects its own model.
Clear stale MCP authentication and discovery failures after successful connections.
Verify plugin skills and MCP tools in active chats across all connector types,
and remove stale tools using normalized server names.
Cover all 54 catalog entries with offline runtime and lifecycle regressions.
Session resume migrates file-history backups with link(), leaving the
resumed session's copies sharing inodes with the previous session
(nlink > 1). The restore guard refused to read any linked backup, so the
last completed turn diffed an unreadable before-state against live disk
and reported every carried file as newly changed — old files resurfaced
as output cards under the latest reply, and rewind restore refused the
same backups. Sever the link on first access by atomically replacing the
name with a private copy, keeping the nlink guard intact.
The @ and / menus each carried their own icon fallback — skills rendered as a
sparkle in one and a box in the other — so the same entry changed shape
depending on which menu opened it. Both now share one vocabulary, and the @
menu shows the source labels the slash menu already had.
Brand icons were resolved against the document root, which only worked while
`base` was `/`; the packaged renderer loads from file://, where
`/connectors/x.svg` points outside the bundle. Connector rows also opened the
detail view and started installing in the same click — installation now
happens only from the detail action.
The fallback command list no longer offers commands the headless CLI cannot
run (`clear`, `vim`, `commit`, `pr`, …): selecting one only produced
"Unknown skill". Of the 59 compiled commands, 16 support the headless path a
desktop session drives. An unprioritised menu also opened on the CLI's
bundled skills (`update-config`, `debug`, `batch`), so desktop-owned commands
now lead instead.
With the workspace panel open, the titlebar's right section was paper right
up to a 16px notch of sidebar grey welded to the window's top-right corner.
The paper was painted by the window header, but the drag gutter — and, on
Windows, the window controls — are its transparent siblings inside the same
frame, so whatever their parent showed came through. Closed, that is
invisible: the whole strip is the sidebar's ground and the gutter just
continues it. Open, it is a strip of trough next to a white panel.
The frame now owns the ground for everything above the panel, so the header,
the gutter and the native controls share one surface.
The trailing icon was the only hit area on an assistant output card, so
opening a generated file meant aiming at a 32px target on the far right while
the file name and path sat inert. The row body is now a real button — icon,
name, badge and path all open the target, with a pointer cursor, a row hover
fill and a keyboard focus ring, and a label that names the file.
The open-with control is untouched and still opens its menu without also
opening the file. Text inside the row is no longer drag-selectable, which is
how browsers treat buttons; the path stays copyable from the open-with menu.
A single click in the file tree opened a VSCode-style preview tab, and the
next click replaced it — picking four files left one tab, which read as a
hard limit. Every pick now opens a permanent tab (repeat picks of one path
still dedup in the store), and the blank-placeholder takeover extends from
blank browser tabs to the empty Files launcher, so the first pick fills the
launcher tab instead of stranding it.
Output cards and Open-with menus for files like README-拍摄大纲.md rendered
fine but died silently on click: card creation reads real paths from the turn
checkpoint, while the click route ran parseFilePathRef whose segment charset
was ASCII-only, classifying the href as `ignored`.
parseFilePathRef now matches on a Unicode-tolerant segment set — the whole
string is already delimited by the markdown span or href, so the prose-bleed
concern that keeps the prose scanner ASCII-only does not apply.
Multi-question prompts get a Next button at the end of the action bar,
disabled until the question on screen is answered. Picking a single-select
option advances on its own, matching ChatGPT's ask_user_input card;
multi-select, free text and the last question stay put, and nothing
auto-submits.
Add mobile provider and General settings while preserving desktop behavior.
Harden remote credential handling, ngrok session ownership and consent upgrades.
Use a native Electron menu with validated host actions and lifecycle cancellation. Preserve browser state, persistent annotations, and disabled page actions on blank tabs.
Replaces the two-mode right-side panel (files ↔ browser) with one controller
that owns layout, navigation and resource lifetime for four content kinds:
files, browser pages, Git review and terminals. Follows the Codex desktop
reference captured in the workspace-refactor plan.
The old panel conflated three things that have different lifetimes: a UI tab,
the content it shows, and the process behind it. That is why switching modes
destroyed a live page, why a second link overwrote the first, and why the
toolbar button reported "show workspace" while the workspace was already open.
Splitting them is the whole change:
- workspaceStore layout, docks, tab order, preview/pinned, focus
- workspaceContentStore / workspaceReviewStore file and diff data
- host services webContents and PTYs, keyed by resource id, never by tab id
Consequences that fall out of the split:
- Hiding the panel, switching tabs and switching tasks keep every page and PTY
alive; only closing a tab releases them.
- A terminal moves between the side and bottom docks without restarting.
- Pages live in a shared persistent partition with native navigation history;
popups become sibling tabs in the task that opened them.
- Review names both sides of every comparison and performs real index and
working-tree writes, guarded by a snapshot token and a backup-first revert.
Also adds versioned workspace persistence with a forward migration: terminals
come back stopped and restartable, pages reload lazily, and nothing holding
content, cookies or handles is written to storage.
The previous implementation is no longer reachable but is left in place: the new
file tab does not yet reproduce workspace search, quick-open or the changed-file
view, so removing it now would lose those. Real three-platform Electron
acceptance (plan item A10) has not been performed; all evidence here is
deterministic tests, type checks and a packaging smoke.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Approving a plan only sent the plan's addRules, so the CLI restored the mode
from prePlanMode and fell back to default when a session had nothing to
restore (it was launched in plan mode) — implementation then asked for
permission on every tool call. The desktop plan dialog now offers "Approve &
auto-accept edits" and "Approve & bypass permissions", mirroring the official
terminal dialog, and pins the chosen mode through a setMode permission update.
A mode delivered through a permission update also skipped the plan exit
transition: ExitPlanMode's cleanup only ran while the mode was still plan, so
the exit flags, the exit/re-entry reminders, the auto-mode teardown and the
rules stripped on entry were left half-applied. That path now reuses the same
transition the CLI runs for its own switches, and refuses bypassPermissions
when the session cannot use it.
Fixes#1254
Validation: new PermissionUpdate regressions plus the plan dialog tests;
src/utils/permissions + src/services/tools + src/cli 103 passed; check:policy
330 passed; desktop suite 330 files passed; compiled claude-sidecar smoke
passed; real-CLI A/B keeps the exit state identical with and without the pinned
mode.
Remove getAttributionTexts/getEnhancedPRAttribution and the three prompt
injection sites (BashTool system prompt, /commit, /commit-push-pr) so commit
messages and PR bodies no longer carry Co-Authored-By or "Generated with
Claude Code".
attribution and includeCoAuthoredBy stay in the settings schema as
deprecated, ignored fields: validateSettingsFileContent() parses with
.strict(), and dropping them outright would make existing settings files
invalid and silently disable the settings edit guard for those users.
The desktop injects CLAUDE_STREAM_MAX_DURATION_MS=600000, a wall-clock cap
that no incoming chunk resets. Slow local models (LM Studio / qwen3) and very
large generations legitimately keep streaming thinking_delta past ten minutes,
so the stream was killed mid-response even though it was alive and producing
content (#1307, #1275). Raising "请求超时" could not help: the cap was
hardcoded, and the first-token budget it was meant to raise was silently
bounded by that same 600s.
Derive the cap from the user's request timeout, never below the existing 600s
default so the #766 trickle protection is not tightened when a short first-byte
budget is configured. Push the derived value through the per-turn env hot
update as well — otherwise a session that is already running keeps its spawn
time 600s no matter what the user configures, which is exactly the retry path
the reports describe.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Prevent carried-forward checkpoints from attributing old edits to later
chat-only turns while retaining legacy snapshot evidence. Default file
summaries to collapsed and preserve disclosure state and return focus.
Fixes#1305
(cherry picked from commit d03898d5203fa73d3c6c9ac66ca8c1c23ee36a59)
Route native-only changes through macOS checks and verify relocated cursor resources in final packages. Reject resources that escape the app and exercise visible click feedback against a disposable native receiver.
Connect the regressions to required checks and capture shell fixture output through temporary files.
Resolve optional click animation assets from the running helper bundle.
Avoid SwiftPM Bundle.module's fatal fallback to a build-machine path so
visible clicks can return successfully and keep the daemon alive.
Keep procedural feedback when optional frames are absent or unreadable.
Add an input-free resource probe and run it against relocated release and
staged helper apps. Cover standard Resources copying and reject probes
that load from an external build directory.
Validation: 524 XCTest and 15 Swift Testing cases passed, including eight
new resource regressions. Build fixtures, compiled sidecar smoke, Electron
checks, local packaging and final relocated-package probes passed.