ImageEdit trusted only two per-session directories: the bridge upload dir
and its own generated-images dir. Neither is where a user's image actually
lands. An @-mentioned file keeps its original path anywhere on disk, and a
pasted or dropped image goes to ~/.claude/image-cache/<sessionId>/, so every
image a user supplied was refused.
The tool description made it worse by pointing the model at
[Image source: ...] paths, which are exactly the image-cache paths the check
then rejected. The model followed the description, got refused, and asked
users to re-attach a file they had just attached.
Record images the user names explicitly in a session-scoped registry, and
trust the paste directory by location. Paths the model found on its own — a
Glob hit, a path read out of a file — stay refused, which is what the
original root-dir check was protecting against.
Claude-Session: https://claude.ai/code/session_01ArehnJt4QLb83xkEukqNFX
The menu poured out everything LaunchServices returns. Measured on the dev
machine: 26 applications for a `.csv`, 24 for `.md`, 16 for `.pdf` — 34, 32 and
24 menu rows once the system default, six IDEs, the copy entries and Finder were
added. Most of it was not installed software but browser cores staged in caches:
three copies of Chrome for Testing (playwright, agent-browser), two of
BitBrowser, Warp's autoupdate directory, a LibreOffice shipped inside a runtime.
`discoverNativeApplications` deduped by `appPath` while the target id came from
`bundleId || appPath`, so the two disagreed. Copies of one bundle each survived
the filter and then collapsed onto a single id: duplicate React keys, and
`openTarget`'s `find` always returning the first record — clicking the second
copy launched the first. The keys are one function now, so they cannot drift
again.
What replaces the dump is a ranking, not a whitelist. A whitelist of install
directories was the obvious fix and it is wrong: Safari really lives in
`/System/Volumes/Preboot/Cryptexes/App/System/Applications`, so it would have
silently dropped the default browser for HTML. Location became one sort key
among five — `isDefault`, an extension-to-bundle-id table (`pdf` → Preview,
`docx` → Word/Pages), location tier, Spotlight's `kMDItemUseCount`, name — and
the list is cut to five. Cache copies never accumulate a launch count, because
nothing execs them through LaunchServices; every tier still ships, so a
misjudged location sorts lower instead of disappearing.
Icons never rendered, and not only the discovered ones. `TargetIcon` pointed an
`<img src>` at `/api/open-targets/icons/…`, which is a cross-origin no-cors
subresource: no Authorization header, so the server's fetch-metadata policy
answers 401 and Chrome drops it as ERR_BLOCKED_BY_ORB. The same URL returns 200
from a terminal, which is what hid this. Icons now come through the credential
path as blob URLs, with hits and misses both cached — a miss costs a `sips` run
per row otherwise. Same failure and same fix as d14866f6d, which never reached
this branch.
The rest of the menu:
- The system-default row is named after the application it will actually open,
but still launches through the system-default target. Only that path carries
the guard that refuses to hand an executable to the shell.
- A file type nothing can edit no longer offers an editor. Reusing the
workspace preview gate rather than writing a third extension table.
- One editor is guaranteed a slot and the rest fill what the applications
leave. On Windows and Linux there is no application list, so a hard cap of
one would have dropped installed editors for nothing.
- The file manager is named per platform instead of interpolating the server's
label, which produced "在 Explorer 中显示" — an English name inside a Chinese
sentence, and not what Windows calls it. Same shape as #1236.
- `max-height` and a scrollbar. That needed `useDismissable` to stop treating a
scroll inside the overlay as a viewport change: the listener is on capture,
so the menu closed the instant the user reached for its own scrollbar.
Deliverables written by a shell command reach the transcript again. The
checkpoint records only the file-editing tools, so `Write plan.md` plus
`python make_report.py` lost the report: the mention did not match a changed
file and was dropped. Document formats now survive that lookup — not Markdown or
images, which this product reads as much as it writes. A bare filename is
anchored to the directory the turn wrote into, since the prose gives the
directory once and then lists basenames; without that the card rendered and
could not be opened.
And when a path really is gone, the click says so. Those failures landed in
floating promises, so a stale reference did nothing at all and read as a broken
button.
Claude-Session: https://claude.ai/code/session_019nFuRvsozQcErtGjVkzZCN
- preserve readable single-image previews while keeping multi-image layouts compact
- give assistant output images one sandboxed rendering owner
- reject unsafe Markdown images before the browser can request them
Requesting worktree isolation in a workspace with no git repository and
no WorktreeCreate hook failed every subagent it was asked for, so a
whole workflow run came back with nothing. Isolation is best-effort, not
a precondition for running: the agent now runs in the workspace
directory instead, and the skip is reported rather than hidden — once
per run in the workflow log, and in the Agent tool's result.
Explicit entry points that ask for a worktree (EnterWorktree, --worktree,
bridge worktree mode) still fail loudly. Deliberate divergence from
upstream, which hard-fails this path in both the Agent tool and the
workflow harness.
Materialize the question card directly from a permission request when the
streamed tool block has not arrived yet. Upsert by tool-use id so either event
order produces one visible, answerable card without requiring a refresh.
Remove model-bound thinking and redacted thinking blocks from the in-memory
request history when a resumed session changes models. Preserve the persisted
transcript and leave same-model histories untouched.
Two stacked issues kept grok-4.6 requests at high effort even when the
UI selected xhigh: the effort capability table had no Grok entries, so
resolveAppliedEffort clamped xhigh to high; and an explicit --effort
flag never overrode CLAUDE_CODE_EFFORT_LEVEL env for main-loop queries.
Resolve Grok capabilities from the bundled Grok catalog and wire
effortValueOverridesEnv through the REPL for explicit CLI effort.
normalizeRuntimeSelection dropped the effort level whenever the selected
Grok model was missing from the bundled desktop catalog (e.g. grok-4.6),
so the reasoning effort slider snapped back to the default on every drag.
Preserve effort for live-catalog models and let the server validate it,
and sync the bundled desktop catalog with grok-4.6 as the new default.
Add grok-4.6 to the bundled fallback catalog with specs from the live
/v1/models endpoint (500k context, high default effort, xhigh..low
effort levels) and make it the default main model for the Grok Official
provider.
The workbench described a team run in ways the underlying data did not
support, so a member marked "已完成" led to an agent that was still
streaming, and the feed reported no communication for a team that had
just handed out all of its work.
A teammate rewrites its entire transcript every turn, leaving a chain of
`agent-<id>.jsonl` fragments where each repeats its predecessor. The
reader concatenated all of them, and `fragmentScopedId` gave the same
entry a different id per fragment, so id-based deduplication downstream
could not collapse them: one member replayed its work up to eight times
and kept growing. Drop a fragment whose entries are a strict prefix of
another's, ignoring only the four fields a rewrite restamps (agentId,
slug, cwd, promptId). Independent resumes reuse entry ids for different
work, so identity comes from content and those fragments all survive.
The activity path scoped tool ids per fragment before deduplicating,
which split a call from its result across two scopes; it now folds
first.
Member activity came from owning an `in_progress` task. A teammate marks
a task started and can then end its turn, and an umbrella task stays open
across every turn beneath it, so every member read as permanently
working. Report the runner's own turn markers as a `TeamMemberActivity`
separate from `status`, falling back to a transcript-write probe only for
backends that record no markers, and let the workbench say `unknown`
rather than guess.
The remaining corrections follow from the same principle -- show what the
data says:
- A member is drawn once, on the task it most recently started, instead
of on every task it owns; other cards carry an owner chip.
- Opening a task card describes the task; reaching its owner is now a
deliberate second click.
- Cards lead with dependency depth. A task id records the order the lead
wrote tasks down, so review work planned first showed "#1" while
hanging off the bottom of the graph.
- Task handovers are communication, not lifecycle noise, and self-claims
read differently from assignments. Repeated idle notices fold into a
count.
- A blocker missing from the task list counts as resolved, matching
`claimTask`, instead of stranding its dependents in `blocked`.
- Batch-completed tasks record their owner. Automatic ownership only
triggered on `in_progress`, so work closed without ever starting had
none; announcing an already-finished task is skipped so an idle
teammate is not woken for it.
- Transcript pages expose the `TaskUpdate` calls that bound each task,
so a member conversation can be read as the tasks it worked through.
Atlas Cloud now sponsors the project, so give it the same treatment as
the other sponsors: mark the preset featured to move it into the sponsor
row, and add the cc-haha campaign link behind the "get API key" button.
Reorder the preset to sit last in that row, matching the README.
Add Atlas Cloud to the sponsor tables in both README.md and
README.zh-CN.md, using a cc-haha-specific campaign link. Ship
light/dark logo variants so the wordmark stays visible in both
GitHub themes.