* fix(provider): honor configured output budget for direct Anthropic providers
Anthropic-format providers connecting directly to an upstream could not set a
reply output budget: the field was hidden in the UI, stripped before
persistence, and dropped by a local-proxy-only gate at request build time, so
low-cap relay upstreams returned 400/truncation with no user recourse.
Surface the budget for Anthropic, persist it as a budget-only object so stale
OpenAI-compatibility options cannot leak, and remove only the numeric gate in
getConfiguredProviderOutputBudget. getOutputBudgetHeaders keeps its local-proxy
guard so the internal provenance header never reaches an external provider.
Adds kernel/desktop unit tests for the direct-budget path and the provenance
non-leak.
* fix(provider): disable optional manual thinking below its token minimum
---------
Co-authored-by: gugugaga <267102352+omazili-guga@users.noreply.github.com>
Co-authored-by: 程序员阿江(Relakkes) <relakkes@gmail.com>
* fix(swarm): serialize team config writes under the file lock
Route every team config.json mutation through mutateTeamFileAsync so each update reads its snapshot inside the lock, and publish via a same-directory temp file + rename with bounded Windows retry instead of truncating the live file. Await the now-async writers in the UI and CLI callers.
* test(teams): cover TeamsDialog mode cycling and teammate removal
The changed-lines gate scored TeamsDialog.tsx as 0/20 because no test
imported it, so the new async removeMemberFromTeam/setMemberMode paths went
unrecorded in LCOV. Drive both the list and detail views through input
handlers and keybindings, including the rejection paths, to bring
changed-lines coverage from 84.91% to 93.53%.
A referenced ReadSession walked backward through the whole transcript and scanned it from the start, which starved the sidebar poll into a flashing load-failure banner. Bound that read and keep a failed list refresh off the sidebar.
Startup metadata could recreate the source placeholder after the CLI had written the conversation into its worktree. Open and update the file that already contains the conversation.
A Chinese @ query scanned the whole session table twice and then ran a body search, so every other request queued behind it. Cap that scan, skip the body lookup once the budget is spent, and stream session clears and trims instead of holding the transcript in memory.
The sidebar's "using standard history" notice flickered because a busy
passive checkpoint marked the index degraded, and the next reconciliation
cleared it again, bouncing the session list between the index and a full
JSONL scan. Incremental reconciliation now keeps serving a snapshot that
already has committed rows, and a transient SQLITE_BUSY no longer changes
the public state.
A zero timeout let a session poll WaitSessions in a tight loop. Short requests now wait the 10s minimum and report the clamp, while a newer revision still returns immediately.
The bounded history window stitched pages behind the scrollbar and dropped
rows from the far end, which made big sessions flicker and lag. Load the
transcript in one byte-bounded response, keep it as a single mounted array,
and remember disclosure choices across virtualized row remounts.
Drop the collapsible collaboration panel and show cross-session deliveries as ordinary user bubbles with a source label, while created sessions carry titles immediately.
Grok 4.7 shipped with a faster variant (grok-4.7-build-fast), and the
gateway's /v1/models feed no longer advertises grok-composer-2.5-fast.
Resolving reasoning effort against the bundled catalog alone gave a model
newer than this build no effort at all, and the request transform reads
that as a model which rejects the parameter and strips the whole reasoning
block. Selecting xhigh on 4.7 therefore ran at the upstream default, while
the picker and the server-side validation both accepted the choice. Effort
now resolves against the live catalog first, and a model neither catalog
describes keeps the requested effort instead of losing it.
The runtime catalog pointer moves into the dependency-free catalog module
so the request transform can read it without an import cycle back through
fetch.ts.
Both bundled catalogs gain 4.7 and its fast variant and default to
grok-4.7, and the retired composer model migrates pinned sessions to that
default rather than sending an ID the gateway no longer serves.