b514e0074597bcc78f674ddce22073b40d124157
13
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
b5824c6611 |
Providers as data; add Ollama and Custom endpoints
Every gateway provider is now an entry in providers.json - endpoint and auth template, how its model list is read, how it is probed before a switch, what setup asks, which doctor checks apply, and its title, colour and logo - installed next to the presets and read by all three consumers: the bash CLI (through cm-json.py), the Windows script, and the bar widget (through health.json). anthropic stays built in; it is the native login, not a gateway. Behaviour that differs in kind stays in code, chosen by name from the entry: catalogue parsers (openrouter, lmstudio, ollama, openai, static), probe rules (always, lenient, local), and named doctor checks. A provider that reuses them is an entry and a default preset, with no code. The widget draws providers from health.json, so a new one needs no QML change and no shell restart. The existing three are unchanged in behaviour: their blank presets come out byte-identical from the file, and setup, doctor, models and the picker run the same checks through the generic paths. Ollama: local server on :11434, placeholder token, one model for every tier, models from /api/tags. doctor reads the context each loaded model actually runs with (/api/ps) and its maximum (/api/show), because Ollama defaults to 4096 tokens unless OLLAMA_CONTEXT_LENGTH is set and silently truncates past it. A bare model name matches its :latest tag. Custom: any Anthropic-compatible endpoint. Ships with no address and is refused until it has one; key optional; models from /v1/models when the endpoint has a list, and a lenient probe so a proxy without one is not blocked. Also: preflight (and Set-ClaudeMode on Windows) refuses a preset with no server address; the server form, setup and set-auth use each provider's own default URL, key name and placeholder token instead of LM Studio's; the Windows build gains the no-models and no-address guards it never had. Tested on Linux against fake Ollama/Custom servers, and on Windows 5.1 in a USERPROFILE sandbox on winbox. 1.12.0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
c5c3fc57d9 |
Choose which preset claude-mode <provider> picks
Omitting the preset used a fixed name per provider (default, zai, lmstudio). It can now be chosen: claude-mode preset default what each picks, and why claude-mode preset default openrouter cheap claude-mode preset default openrouter --clear The choice is stored in ~/.claude-mode/defaults.json and read first by default_preset_for, while its file still exists. A choice whose file is gone falls back to the built-in name, and if that is gone too, to the first preset by name, as before. Renaming a chosen preset moves the choice with it, and deleting it clears the choice. The terminal menu marks what resolve_preset would actually pick. health.json publishes defaultPresetFor (what each provider resolves to, in the CLI's order) and defaultPresetChosen (the explicit choices only). The panel sorts and tags from it, and the editor gains Make default / Clear default. preset new, rename and rm now refresh health.json, so the bar follows edits made in a terminal too. This changes existing CLI behaviour only once a default is chosen. The Windows build does not read defaults.json yet. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
de9f10a8c2 |
Create, duplicate, rename and delete presets from the panel
Each provider's preset list ends in "New ... preset...", and the preset editor gains Duplicate, Rename and Delete. New asks for a name and what to start from: a copy of one of that provider's presets, or a blank template. Delete is greyed out, with the reason, on the preset in use, and warns when it would leave a provider with no preset at all. CLI: - preset rename <name> <new>: the new name is hard-linked in, state.json is repointed, and only then does the old name go. - preset new <name> --provider <p> [--blank]: with a provider and no source it copies that provider's own default instead of the OpenRouter-only `default`; --blank starts from the scaffold. - valid_preset_name on every preset subcommand: no slash, no leading dot. `preset show ../../etc/passwd` used to print the file. - preset rm warns when it removes a provider's last preset. - preflight refuses a preset with every tier empty. Otherwise a blank preset would switch cleanly and Claude Code would ask the gateway for its default Anthropic models, billed at full price on OpenRouter. The panel's blocked card offers "Edit preset..." for it. The key helper now reads the active preset in a single open (new cm-json auth-of) and re-reads state.json once on a miss. Renaming the active preset could otherwise catch a running session between reading the old name and opening the file: 1 failure in 51 key fetches in a race test before, 0 in 118 across 60 renames after. It could also briefly hand out the openrouter key for a preset that uses another. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
83b59f34a1 |
Edit a preset's tiers from the bar panel
The gear on every preset row now opens an editor: the four tiers with the model each maps to, and for each one field that filters the provider's catalogue as you type (every word must match; arrows and Enter work), listed inline with context length and price, and that also takes any id typed by hand. LM Studio's server form moves one click inside the editor. The panel card moves from PopupCard to KeyboardPanel. PopupCard is an xdg-popup, which only receives keys after focus is routed through its parent surface, so no text field in it could ever be typed into - the existing server URL form included. KeyboardPanel primes layer-shell keyboard focus on open, which is why every shell panel with a text field uses it. Esc now closes the panel. The picker reads ~/.claude-mode/models-cache.json, which or_catalogue and lms_catalogue now write as a side effect, so models, doctor, setup and the menu's picker all keep it fresh and the panel never hits the network itself. One node per provider with its own fetchedAt/ok; a failed fetch keeps the old list, an LM Studio list is tied to its server, and no key or key name is ever stored. `models` gains --preset, --refresh and --json, and the Z.AI list now lives in one place. A tier edit to the active preset re-applies without the running-sessions prompt: that prompt guards against the endpoint or key moving, and a tier edit moves neither (preset url/auth still ask). A failed re-apply now says the edit was saved. `preset set` on an unknown name no longer creates it. Panel edits run through one chain that stops on the first failure and refreshes health.json at the end. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
cbd3b1d8a9 |
Dismiss broken sessions, and hide ones untouched for a week
A broken session that will never be repaired kept the bar's warning dot lit forever. repair-session now takes --ignore/--unignore/--unignore-all/--ignored, recorded in ~/.claude-mode/ignored-sessions.json, and the scan hides broken transcripts older than --max-age days (default 7, 0 disables, CM_IGNORE_AGE_DAYS sets it). Hidden sessions move to a separate ignored[] list with a reason, and --all always names how many it held back. A repair clears the session's dismissal, and entries whose transcript is gone are pruned, so a session that breaks again is never silently hidden. The panel gets an Ignore button beside Repair and a collapsed "hidden (N)" section with Restore. The dot still counts broken sessions only. Bumps to 1.10.0 and fixes the widget manifest, which still said 1.8.0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
b60c00450c |
Quote the apiKeyHelper path, and say why the helper failed
apiKeyHelper is a shell command line, not a path, so the raw value written into settings.json was split at the first space. A Windows profile named "Mohammed Ahmed" produced an attempt to run C:\Users\Mohammed, surfacing as "your apiKeyHelper script is failing" with nothing to go on. Quote the value when it contains anything a shell cares about, and leave it bare otherwise so no existing settings.json churns on the next switch. The POSIX port had the same bug against a /Users/First Last home; shlex.quote has exactly the wanted "leave ordinary paths alone" behaviour. doctor could not see any of this. It quoted the path itself before running it, so it exercised a command line Claude Code never uses and passed while the real one failed. It now reads the string out of settings.json, reports it when it is not what a switch would write, and runs that string through a shell. The helper itself exited 1 in silence on four distinct faults - no state, no preset, no key, undecryptable key - collapsing them into one indistinguishable message. Each now names itself on stderr, which is what /status displays. The DPAPI case says what it actually means: a key stored by a different Windows account than the one Claude Code runs as. Success paths stay silent, so stdout still carries the key and nothing else. Also make install.ps1 survive a Restricted execution policy: piped through iex it is not subject to the policy, but invoking the installed script for the key prompt is, which is where a fresh install died. Set Process scope for the install, offer to set CurrentUser to RemoteSigned, and clear the mark-of-the-web that Expand-Archive can leave on the extracted scripts. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
4c36f4d00b |
Notice broken sessions in the bar, and offer to repair them there
Nothing tells you a session is unresumable until you try to resume it, and by then you have usually forgotten which one it was. The widget now scans every project on a timer and whenever the panel opens, marks its icon when something needs fixing, and lists the affected sessions with a repair button that says what it will drop and what it will keep before doing anything. The scan had to get roughly eighty times cheaper first. Classifying a transcript needs two facts - what its last message id is, and whether any Anthropic id exists at all - and the first settles the common case alone. Reading the tail of each file and only opening the whole thing when the tail already looks wrong takes the sweep from ~5s to ~60ms across 59 transcripts, which is the difference between something that can sit on a timer and something that cannot. `--all` uses the same path, and `--json` exposes it. The badge is a dot beside the mark rather than a recolouring of it: this widget's job is to report which provider is active, and tinting it red to mean something else entirely would be a lie about that. Verified by planting a genuinely corrupted transcript, watching the scan find it and the dot appear, then removing it and watching both clear. |
||
|
|
43cef6bf9e |
Scan every project for broken transcripts, and stop crying wolf
repair-session only ever listed the project you were standing in, which is a poor place to start from when the thing you cannot resume is a session whose project you no longer remember. --all drops the working-directory scoping and checks all of them. (A named session id was already looked up across every project; only the listing was scoped.) The first version of that scan reported 16 of 59 transcripts as unresumable, which was true in the narrowest sense and useless in every other. Checking them: 5 had never received an assistant reply at all, and 10 had run start to finish on a gateway, so every id in them is that provider's by design. Those resume perfectly well under the provider they were born on, have nothing to truncate back to, and are only a problem if you try to resume them as Anthropic. Calling either of them damage buries the one case that is. So the verdict now carries a kind - healthy, repairable, gateway-native, synthetic-only, no-messages - and only `repairable` is reported or acted on: a transcript with a genuine msg_ message and junk after it. Across the same 59 it now correctly reports nothing to repair, while still classifying the real corrupted transcript from the incident as repairable with 108 lines to drop. A gateway-native session asked about directly now says what it is and that there is nothing to fix, rather than failing with "no Anthropic-issued message". |
||
|
|
a14418b5d9 |
Keep the turns a repair cuts, and hand them back to the session
Truncating the transcript is the mechanical fix, but the turns being cut are the work itself. Losing the conversation that produced a morning's changes is most of the damage, and a session that resumes with a hole in its memory is barely resumed - it has no idea what it just did or what it was asked. So --apply now writes the dropped turns out as <session>.recovered-<stamp>.md, a readable record of what was asked, what was answered and what was run, and appends the same text back to the truncated transcript as a single note. Tool results are deliberately excluded: they are most of a transcript by volume and the least useful part of a summary. The note is a user entry marked isMeta - the marker Claude Code already uses for its own local-command caveats, meaning context rather than something to answer - and carries no message.id, so it cannot recreate the previous_message_id condition being repaired. Verified on the real corrupted transcript: 1921 lines in, 1813 kept plus the note, chained to the last good assistant uuid, no id on the message, and the file reads back as healthy. The generated digest recovers the actual instruction that was lost in the incident, which is the thing that made this worth doing. --no-reinject writes the markdown but leaves the session alone. |
||
|
|
a4afa55580 |
Ask before switching while sessions are live, and recover the ones already broken
Acts on docs/incident-mode-switch-corrupts-live-sessions.md, which is added here as the record of why. The report identifies a consequence that was not modelled. A failed call is recoverable; a *successful* one may not be. If a running session takes even one completion from the provider being switched to - which happens when that mode matches the base URL it already had cached - that provider's message-id format lands in its transcript. OpenRouter issues `gen-<epoch>-<rand>` where Anthropic issues `msg_...`, and native Anthropic then refuses to resume the session at all, with a 400 naming previous_message_id. The only way back is to truncate the transcript, losing every turn after the cut. That happened here, and was fixed by hand. Two changes follow. Sessions are now settled before the write, not reported after it. A switch with anything running stops, names the sessions, explains what is about to happen to them, and offers restart (the only answer that ends with everything on the mode the bar now claims), close, proceed anyway, or abort - defaulting to abort. Non-interactively it refuses outright unless given --yes. The old after-the-fact reporter is deleted rather than left as a second, contradictory account. `claude-mode repair-session` replaces the hand surgery: it finds a project's transcripts, reports which are resumable, and on --apply backs the file up and truncates to the last Anthropic-issued message. Verified against the real corrupted transcript from the incident - it reproduces the manual cut exactly, 1921 lines to 1813, dropping the two `gen-` completions and the error placeholders after them, leaving a transcript that ends on a genuine msg_ id. It refuses a transcript written to in the last 90 seconds, since that one belongs to a session still running. The panel passes --yes, having already asked in its own card, and that card now names the transcript risk rather than only the inconvenient one. Requirement 4 of the report - documenting the mechanism - landed in 9c301e1; the README now carries the unrecoverable half as well. |
||
|
|
9ff9b82c25 |
One preset per mode, and a first-run setup that fills it in
The openrouter default moves its hot tiers: opus to z-ai/glm-5.3-flash and sonnet to deepseek/deepseek-v4-flash-0731. haiku and fable are unchanged. `cheap` and `lmstudio-qwen` are gone, leaving exactly one preset per mode so `claude-mode <mode>` is never ambiguous and there is no menu to read before the thing you asked for happens. The surviving lmstudio preset keeps the Qwen3.6 model rather than KAT-Coder: the two differed mainly in that KAT's chat template carries the message-order assertion this README already warns about, so between two presets that had to become one, the one that is known to work won. More presets are still a `preset new` away; the shipped set is a starting point, not a ceiling. Which is the other half of this. A shipped preset was never a working configuration - OpenRouter and Z.AI have no key stored, and lmstudio's model ids were whatever happened to be installed on the machine this was packaged on. That was left for the user to discover through a failure. Now the shipped presets carry `configured: false`, preflight blocks on it, and `claude-mode setup <mode>` walks through what is actually needed: key, server URL and auth for LM Studio, then models chosen from the provider's own catalogue rather than typed from memory. A switch that trips this in a terminal offers to run setup there and then instead of printing a command to type next. Absent means configured, deliberately: presets that predate this and any built by hand with `preset new` do not suddenly start demanding a wizard. The panel gets a "Set up <mode>…" button that hands the whole flow to a terminal, since a bar popup can host neither a hidden key prompt nor a filter-select list. Two bugs found while testing it, both real: ask_value printed its prompt to stdout while being called inside $( ), so the prompt text came back glued to the front of the answer and set-url rejected the result. Moved to stderr, which is why warn and err already go there. lms_catalogue never sent the API key. On a server with authentication switched on - the case just added support for - /api/v0/models answers 401 like anything else, so the catalogue came back empty and every caller silently concluded the server had no models installed. It now sends the preset's credential, as do the three other call sites that read it. |
||
|
|
da50a3c7e5 |
Linux port: theme-aware TUI, switch preflight, session control
Four changes to the POSIX build, found while getting it working on Omarchy. Colour follows the desktop theme. The sixteen ANSI slots carry no guarantee about relative brightness and monochrome themes exploit that: under Omarchy's Solitude, slot 36 (headings) resolves to #707070 and slot 31 (FAIL) to #565d60, which against #cacccc body text on a #101315 ground is 3.8:1 and 2.8:1 where the body text is 11.6:1. Headings rendered as fine print and errors as the quietest thing on screen. The palette is now derived from the theme's own colors.toml, with each role measured against the background it will actually be drawn on and lifted toward the foreground when it falls short - hue kept where the theme has any, weight substituted where it does not. Headings go 3.8:1 -> 9.4:1 and FAIL 2.8:1 -> 5.2:1. Falls back to the ANSI slots off Omarchy, with the two roles the slots get wrong corrected. health.json was only ever written by a switch, so a fresh install had none at all and any reader had to guess. It is now refreshed by `status` and seeded at install, and `claude-mode health` forces it. The installer also copies VERSION, which cm_version() has always read and nothing ever wrote - every health.json until now reported 0.0.0. Preflight, because a switch that cannot work does not fail loudly: it succeeds, and every session started afterwards breaks in a way that points at Claude Code rather than at here. Keys, the helper, the preset's provider and the server are all checked before the write. LM Studio is the sharp case - its token is an inline placeholder, so nothing about the switch needs the server to exist. Session control, because Claude Code reads settings.json once at startup: a switch leaves running sessions on the old provider until they are restarted, and one mid-request can lose that turn outright. `sessions` lists them, `--stop` and `--restart` act on them behind a confirmation, `--dry-run` shows the plan. Sessions are found through /proc/<pid>/exe rather than by process name, which would sweep up every shell that merely mentions claude - including the one this runs from. Two exclusions: the calling session, and forks of a session. A busy session spawns children off its own binary that inherit the same exe, and without filtering those the count climbed and fell with load - it read 2, 5, 11 and 40 for the same two sessions before the parent check went in. LM Studio is no longer assumed to be on this machine. `preset url` and `preset auth` move it to a LAN box, a tunnel or a proxy and turn authentication on, and the probe distinguishes ok / auth / notfound / refused, because "start the server" and "your key is wrong" are opposite remedies. It is probed wherever it lives - a sleeping LAN box is exactly as absent as an empty loopback port - while remote gateways are not, since those being briefly unreachable is the network's problem and a missing key never fixes itself. |
||
|
|
112068314c |
Import claude-code-switcher from the Windows build
Source of truth so far has been c:\Users\smoido\projects\cli on the Windows box, which has no git history of its own. This is that tree copied verbatim over SSH, minus dist/ - the PowerShell build, the POSIX port under linux/, and the presets both share. Recorded as its own commit so that everything after it is a reviewable diff rather than an undifferentiated first drop. |