- [Gemini Thought-Signature Hardening & Pipeline Defense] Enforce Priority for functionCall Thought Signatures, Full-History Outbound Auto-Heal Gatekeeper, and Streaming Thinking Auto-Heal (Fixes #3529, Fixes #3531, Ref #3535, Thanks to @EricZhou05, @Mortalit):
- Prioritized Extraction for Mixed Tool Turns: Fixed a traversal ordering vulnerability in
finalize_gemini_contents_thinking_with_sessionandplace_turn_signature_scoped. When an assistant turn contains both commentarytextandfunctionCall, signature extraction strictly prioritizesfunctionCallparts under Gemini targets, preventing commentary text from stealing signatures and bypassing SQLite/L1 cache penetration recovery. - Parallel Tool Call Signature Preservation: Refined non-anchor part sanitation. While ensuring signatures on
textandthoughtparts are cleaned, valid signatures already present on subsequentfunctionCallparts in parallel tool calling turns are strictly preserved. - Full-History Outbound Auto-Heal Gatekeeper (Pipeline First): Expanded
InboundThinkingPipelineoutbound gatekeeper to scan the entire conversation history. Any historical or activefunctionCallmissing a signature is automatically backfilled with Google's official sentinelskip_thought_signature_validator, completely eliminating Google HTTP 400 errors across long-context sessions. - Streaming Thinking Auto-Heal Gatekeeper: Added a streaming auto-heal guard: when a model in deep-thinking mode emits only thinking blocks without any text content, the stream automatically injects a neutral compliant text block at the end, preventing downstream client validation crashes.
- Normalized Fallback Text for Thinking Auto-Heal: Unified all thinking recovery fallback text to
"task ready", eliminating secondary 400 errors triggered by empty strings, dots, or invalid characters.
- Prioritized Extraction for Mixed Tool Turns: Fixed a traversal ordering vulnerability in
- [Claude Cowork Unbounded Context Bloat Mitigation & One-Shot Reactive Compaction] Introduce Pure One-Shot State Machine Eradicating Lifetime Immunity and 357k Context Leak (Fixes #3563, Ref #3566, Thanks to @cubelikeplayDaniel):
- Pure One-Shot State Machine (One-Shot Immunity Token): Overcame the critical limitation in Claude Desktop Cowork mode where interactive
/compactcommands are unavailable and local auto-compact settings are ignored. The gateway injects an intelligent 400 fake alarm when context exceeds thresholds (>= 200k), activating the client's internalReactive Compactpipeline; immunity tokens are strictly valid for the single retry request following compaction and are consumed immediately, permanently eliminating 357k context leaks and driving round 2 and round 3 compactions reliably. - Tail Directive & Compaction Header Verification: Narrowed prompt text scanning in
is_compaction_requestfrom global messages to solely the active tail message (messages.last()) alongside the officialx-stainless-helper: compactionheader, eliminating false positives from historical summary text.
- Pure One-Shot State Machine (One-Shot Immunity Token): Overcame the critical limitation in Claude Desktop Cowork mode where interactive
- [Universal Token Estimator, Serde Defaults & Terminal Turn Safety] Eliminate Context-Trimming Blindness & Gemini 400 Deadlocks (Fixes #3561, #3562, Thanks to @cubelikeplayDaniel):
- Protocol-Agnostic Token Estimator & High-Concurrency Cache (
PipelineTokenEstimator, Fixes #3562): IntroducedPipelineTokenEstimatorwith request-SHA256 global in-memory caching (TokenEstimationCache), supporting Canonical Gemini IR, Claude, and OpenAI native payloads with sub-0.05ms execution on cache hits. - Anthropic Count Tokens API Alignment (Fixes #3562): Strictly aligned
/v1/messages/count_tokensto return only{"input_tokens": n}, removing redundantoutput_tokensfields to eliminate downstream SDK type errors and context-trimming blindness. - Serde Deserialization Default Tolerances (Fixes #3561): Added
#[serde(default = "default_empty_object")]forToolUse.inputand#[serde(default)]forToolResult.content, hardening against omitted fields inServerToolUseandWebSearchToolResultto permanently eliminateHTTP 400 untagged enum MessageContenterrors. - Terminal Turn Safety Normalization (Fixes #3561): Upgraded
ensure_gemini_payload_ends_with_user: whenever the terminal turn ends withmodel/assistant(includingfunctionCallor normalizedfunctionResponse), automatically append a compliantuserturn to prevent Google Gemini400 Requests ending with a model turn are not supported.
- Protocol-Agnostic Token Estimator & High-Concurrency Cache (
- [Forced Tool Choice Restoration & Concurrent Multimodal Continuity] Pipeline First Clean Wire, Stable Partitioning & Router Fixes:
- Restored Forced Tool Choice (tool_choice / toolConfig) Across All Protocols (Fixes #3562, Thanks to @cubelikeplayDaniel): Enforced the "send if present, omit if absent" Pipeline First principle, removing unconditional stripping of
toolConfigin the inbound pipeline; addedtool_choiceinClaudeRequestand mapped it to GeminifunctionCallingConfigto fully restore forced tool choices for frameworks like LangChain and LlamaIndex. - Inbound Stable Partition for Concurrent Multimodal tool_results (Fixes #3560, Ref #3094, Thanks to @Xueshen6): Implemented protocol-agnostic Stable Partition in
normalize_function_response_roles: ensures allfunctionResponseblocks remain contiguous at the front while accompanying media parts (inlineData) are appended cleanly at the end, completely resolving tool state machine interruptions when concurrently returning multiple images with Claude models. - Router Model Mapping Fix (Fixes #3551, Thanks to @patton174): Removed erroneous reverse-mapping rules from real upstream IDs (
gemini-pro-agent) back to public names (gemini-3.1-pro-high), resolving 400 INVALID_ARGUMENT errors. - Single Winner Session Decision & Orthogonal Dual-Key Isolation (Fixes #3554, Ref #3561, Thanks to @relifenoxiao):
x-claude-code-session-idranks first inPRODUCT_SESSION_HEADERS.affinity_keyfirmly pins the upstream Google account for 90%+ KV cache hit rates, whilestore_keyisolates thinking stores to prevent concurrent sub-agent conflicts.
- Restored Forced Tool Choice (tool_choice / toolConfig) Across All Protocols (Fixes #3562, Thanks to @cubelikeplayDaniel): Enforced the "send if present, omit if absent" Pipeline First principle, removing unconditional stripping of
- [Multimodal Sliding Window, Terminal Transparency & UI Redesign] Uncapped Image Limits, Multimodal Eviction & Dedicated Model Config Panel:
- Multimodal Context Sliding Window & Uncapped Image Limits (Fixes #3545, Thanks to @jeikl): Removed the hardcoded
const MAX_INPUT_IMAGES = 16limit; supports count-based and memory-based image eviction to quietly replace expired historical screenshots with structured placeholders, halting context bloat while preserving current vision. - 100% Plaintext Transparency for Terminal/Code Tools & Strict Magic Bytes Guard (PR #3542, Fixes #3540): Command execution and file operation tools are completely exempted from multimodal extraction; enforced strict image header magic bytes and structural integrity checks (PNG
IEND, JPEG\xff\xd9), rejecting truncated images and plaintext Base64. - UI Architecture Redesign & Top-level "Model Configuration" Panel (Thanks to @jeikl): Expanded top navigation into four core modules, relocated Thinking Settings into "Model Configuration" and collapsed by default, added a dedicated "Specific Agent Settings" section featuring Claude Desktop Cowork thresholds, and upgraded the internal error ring buffer (
InternalErrorWindow). - Bidirectional Bottleneck Constraints & Faithful 5H Quota Rendering (Fixes #3556, Fixes #3564): Fixed 5H view distortion caused by weekly quota overriding, supporting seamless
[ Weighted | 5H Rolling | 7-Day Weekly ]lens toggles, faithfully rendering real 5H rolling percentages with[Weekly Limit: xx%]annotations.
- Multimodal Context Sliding Window & Uncapped Image Limits (Fixes #3545, Thanks to @jeikl): Removed the hardcoded
- [Antigravity CLI Token Sync & System Robustness] Native agy Credential Sync, Headless Self-Healing & Client Probing:
- Antigravity CLI (agy) Native Token Sync & Millisecond Expiry Defense (Fixes #3567, Thanks to @brushax): Real-time bidirectional synchronization of
~/.gemini/antigravity-cli/antigravity-oauth-token, and hardened timestamp parsing against millisecond/microsecond values (> 2,000,000,000). - Headless Mode Empty Config Self-Healing (Fixes #3548): Automatically initializes default configurations when
gui_config.jsonis missing or 0 bytes, preventing EOF panics. - Client Detection & Pure Proxy Account Switching (Fixes #3530): Expanded cross-platform installation paths and PATH scanning; safely completes account switching even if native client binaries are absent.
- Architecture Decoupling & Cleanup: Completely stripped legacy z.ai providers and local MCP tooling, slimming down both backend and frontend to maintain pure-pipe architecture.
- Antigravity CLI (agy) Native Token Sync & Millisecond Expiry Defense (Fixes #3567, Thanks to @brushax): Real-time bidirectional synchronization of
- [Gemini 思维链与签名体系终极加固] 确立混合轮次优先从 functionCall 提取签名的铁律,出站门禁全历史扫描覆盖,并实现流式纯思考空回复自愈门禁 (Fixes #3529, Fixes #3531, Ref #3535, Thanks to @EricZhou05, @Mortalit):
- 混合轮次工具调用签名优先提取: 彻底修复当 assistant 轮次同时包含说明正文(
text)与工具调用(functionCall)时线性遍历导致的签名争抢漏洞。确立 Gemini 目标下强制优先从functionCall提取合法凭据的铁律,杜绝说明正文抢先霸占签名并反向绕过 SQLite/L1 工具签名缓存穿透找回机制。 - 并发工具调用(Parallel Tool Calls)签名保护: 优化非锚点部件清洗逻辑,在清除误挂在正文或思考块上签名的同时,严格保留并发多工具调用中后续
functionCall已有的合法签名,避免并发工具因签名被清空触发上游拦截。 - 出站终审安全自愈门禁全历史覆盖 (Pipeline First):
InboundThinkingPipeline出站门禁升级为全历史扫描,无论是当前活跃轮次还是深层历史(如多轮对话第 200+ 轮)的远古工具调用,出站前一律自动补齐 Google 官方合法哨兵skip_thought_signature_validator,100% 免疫深度长历史因签名丢失导致的 Google HTTP 400 校验报错。 - 纯思考空回复流式自愈门禁 (Streaming Thinking Auto-Heal): 引入流式管道自愈守卫:当模型在开启深度思考时仅输出了思维链内容(
thought)而未生成任何正文内容时,流式管道自动在尾部补齐合法正文,杜绝下游 Agent 客户端因空内容块触发校验异常崩溃。 - 思考自愈兜底正文规范化: 将所有思考自愈兜底正文统一规范为合法中性的
"task ready",杜绝空文本、点号或非法字符引发的二次 400 校验拦截。
- 混合轮次工具调用签名优先提取: 彻底修复当 assistant 轮次同时包含说明正文(
- [Claude Cowork 响应式单次自愈闭环] 引入纯单次消费型自愈免死状态机,彻底消灭「一次压缩终身免死」与 357k 穿透死锁 (Fixes #3563, Ref #3566, Thanks to @cubelikeplayDaniel):
- 纯单次消费型状态机 (Pure One-Shot State Machine): 针对 Claude Desktop Cowork 模式无法主动
/compact且忽略配置导致长任务卡死的顽疾,网关智能伪装超限 400 假报警触发其内置的被动自愈。重构为纯单次消费型状态机,免死令牌仅对紧随压缩成功后的第 1 次重试请求有效,放行后立即原子核销;彻底根除“一次压缩终身免死”引发的 357k 上下文漏网穿透,驱动客户端顺利进入第 2、第 3 轮自愈,实现无限轮次健康运转。 - 末尾消息与专属 Header 确权加固: 压缩请求识别严格限定为仅检测当前末尾消息(
messages.last())和专属头x-stainless-helper: compaction,彻底切断历史第 0 消息旧<summary>造成的请求属性混淆。
- 纯单次消费型状态机 (Pure One-Shot State Machine): 针对 Claude Desktop Cowork 模式无法主动
- [流水线通用 Token 估算引擎、Serde 缺省容错与空回合保护] 彻底消除 Agent 算力致盲与 400 校验死锁 (Fixes #3561, #3562, Thanks to @cubelikeplayDaniel):
- 协议无关通用 Token 估算引擎与全局高并发缓存 (
PipelineTokenEstimator, Fixes #3562): 在流水线核心层引入跨协议通用的PipelineTokenEstimator与基于请求特征 SHA256 摘要的全局高并发内存缓存(TokenEstimationCache),统一支持 Canonical Gemini IR、Claude、OpenAI 原生报文及多模态媒体计算;缓存命中< 0.05ms极速返回。 - Claude
/v1/messages/count_tokens官方 Schema 严格合规 (Fixes #3562): 接入通用估算引擎,严格遵循 Anthropic 规范仅返回{"input_tokens": n},彻底移除非标冗余output_tokens字段,杜绝下游 SDK 类型校验报错。 - Serde 反序列化缺省字段容错 (Fixes #3561): 为
ToolUse.input补充缺省空对象{},为ToolResult.content补充#[serde(default)]容错,并防御ServerToolUse与WebSearchToolResult的边缘缺省字段,彻底根治 Claude Code CLI 发起无参工具或空回执时的HTTP 400 untagged enum MessageContent。 - 终态轮次安全规整(空回合保护)(Fixes #3561): 重构
ensure_gemini_payload_ends_with_user防御逻辑:只要流水线规整后末尾轮次为model/assistant(无论含文本、functionCall还是工具回执functionResponse),一律自动追加合规中性的user兜底引导轮,彻底杜绝 Google Gemini 上游400 Requests ending with a model turn are not supported。
- 协议无关通用 Token 估算引擎与全局高并发缓存 (
- [强制工具调用全协议恢复与并发多图连续性治理] 贯彻 Pipeline 纯净线缆,消除多模态插队截断与反向映射缺陷:
- 全协议强制工具调用(tool_choice / toolConfig)彻底恢复 (Fixes #3562, Thanks to @cubelikeplayDaniel): 贯彻“客户端有就传,没有就不传”原则,彻底废除进站流水线一刀切强行剥除
toolConfig的逻辑;在ClaudeRequest中补齐tool_choice声明并规范映射为 Gemini 的functionCallingConfig,彻底恢复各大 Agent 框架(LangChain、LlamaIndex 等)强制调用指定工具的核心能力。 - 进站流水线通用稳定双阶段分区(并发多图修复)(Fixes #3560, Ref #3094, Thanks to @Xueshen6): 在
normalize_function_response_roles中实施严格的协议无关稳定双阶段分区,保证所有functionResponse连续置顶在前,所有随行多模态媒体(inlineData)统一延后沉底;彻底解决单轮并发返回多张图片时inlineData插队导致 Claude 家族模型 400 崩溃的问题。 - Router 模型映射修复 (Fixes #3551, Thanks to @patton174): 修正系统默认映射逻辑,剔除将真实上游 ID(
gemini-pro-agent)反向映回客户端公开名(gemini-3.1-pro-high)的错误规则,彻底解决由此导致的上游 400 INVALID_ARGUMENT 异常。 - 统一会话单一赢家与双键正交隔离 (Fixes #3554, Ref #3561, Thanks to @relifenoxiao): 在
PRODUCT_SESSION_HEADERS第一顺位识别x-claude-code-session-id等生态专属头;affinity_key恒定锁定同一 Google 上游账号保持 90%+ KV Cache 命中率,store_key保留因果锚点隔离思维库防止并发踩踏。
- 全协议强制工具调用(tool_choice / toolConfig)彻底恢复 (Fixes #3562, Thanks to @cubelikeplayDaniel): 贯彻“客户端有就传,没有就不传”原则,彻底废除进站流水线一刀切强行剥除
- [全新多模态历史保鲜、终端透明化与 UI 重构] 废除 16 张硬编码限制,多模态脱水保鲜与模型配置面板上线:
- 多模态保鲜滑动窗口与 16 张限制解禁 (Fixes #3545, Thanks to @jeikl): 彻底移除
const MAX_INPUT_IMAGES = 16硬编码拦截;原生支持按张数或按累积内存脱水保鲜,超限历史旧图静默替换为结构化占位符,支持图片直链正交子开关。 - 终端与代码类工具 100% 原生纯文本透传与强 Magic Bytes 校验 (PR #3542, Fixes #3540): 命令执行与文件操作类工具彻底豁免多模态提取;强制验证真实图片文件头魔数与文件结构完整性,拒收断头破损图片与纯文本 Base64 片段。
- UI 架构重构与“模型配置”顶级面板 (Thanks to @jeikl): 顶部导航新增「模型配置」顶级菜单,思考设置迁入并默认折叠,提供全新多模态设置面板与 Claude Desktop Cowork 门限调节面板;升级内部报错滑动窗口环形缓冲区 (
InternalErrorWindow)。 - 双向木桶约束与真实 5H 配额呈现 (Fixes #3556, Fixes #3564): 修复 5H 视图被周配额强制覆盖导致数字失真的缺陷,全面支持三态透镜切换,忠实呈现真实 5H 滚动百分比与周限约束角标。
- 多模态保鲜滑动窗口与 16 张限制解禁 (Fixes #3545, Thanks to @jeikl): 彻底移除
- [Antigravity CLI 原生凭据同步与系统健壮性加固] 打通 agy 凭证文件,无头空配置自愈与纯代理切号容错:
- Antigravity CLI (agy) 原生凭证双向同步与毫秒级过期防御 (Fixes #3567, Thanks to @brushax): 跨平台实时双向同步原生凭证文件
~/.gemini/antigravity-cli/antigravity-oauth-token,并严密防范毫秒级/微秒级时间戳(> 2,000,000,000)导致的凭据提前过期。 - 无头模式空配置自愈 (Fixes #3548): 配置文件不存在、0 字节或仅有空白时,自动使用默认配置并原子写回,杜绝 EOF 处崩溃。
- 客户端探测与纯代理切号容错 (Fixes #3530): 补齐跨平台安装路径与 PATH 扫描;未安装客户端时凭据写入成功后安全完成切号。
- 网关架构净化与第三方解耦: 彻底剥离遗留的 z.ai 提供商与本地 MCP 服务工具链,后端与前端全面瘦身,回归纯净线缆。
- Antigravity CLI (agy) 原生凭证双向同步与毫秒级过期防御 (Fixes #3567, Thanks to @brushax): 跨平台实时双向同步原生凭证文件
What's Changed
- fix(proxy): 对齐官方 HAR 工具链拓扑并隔离多轮工具签名防跨轮串扰 by @lbjlaq in #3541
- fix(proxy): 终端与代码工具输出恢复原生纯文本透传并强校验图片文件头魔数 (fixes #3540) by @lbjlaq in #3542
- fix(proxy): 按 Windows 桌面端报文收掉 toolConfig 与工具重排 by @jeikl in #3544
- perf(ci): cache Rust dependencies in release workflow build matrix / 在 release 流水线矩阵中启用 Rust 依赖缓存 by @relifenoxiao in #3552
- fix(integration): sync agy native file credentials (~/.gemini/antigravity-cli/antigravity-oauth-token) by @brushax in #3567
- fix(proxy): fix thought_signature 400 on mixed tool calls by @EricZhou05 in #3568
New Contributors
- @lbjlaq made their first contribution in #3541
- @EricZhou05 made their first contribution in #3568
Full Changelog: v4.8.4...v4.8.7