- [Claude Cowork Compaction Lifecycle Hardening & Tool Schema Overhead Alignment] Eliminate Negative-Gap Deadlocks, Close Immunity Lease Leaks & Add State Pool Governance (PR #3604):
- Account for Tool Schema & Description in Overhead: Fully incorporate tool
descriptionandinput_schematoken costs incalculate_claude_fixed_overhead, ensuring dynamictarget_limitmaintains solvable margins and eliminating client-sidecompactionImpossiblecrashes or infinite retry deadlocks under complex MCP tools. - Strict Expiration of Compaction Immunity Leases: Strictly return
falseonce a lease expires, closing the permanent immunity loophole caused by falling back to weak continuation matching and ensuring subsequent context spikes trigger future compaction cycles normally. - Remove Premature Message Count Condition: Removed the simplistic
num_msgs < 50completion rule from manual compaction, strictly requiring real context token drops (below 85%) or summary completion signals to avoid spoofed 200 OK responses on initial large prompts. - Cross-Turn Session Correlation & Capacity Pruning: Introduced
PENDING_COMPACT_SESSIONS(120s TTL) to align divergent session hashes during summary requests; enforced a 1000-entry capacity limit and 300s TTL eviction on the manual compact state map. (Thanks to @cubelikeplayDaniel)
- Account for Tool Schema & Description in Overhead: Fully incorporate tool
- [macOS Patch Signing Safety Rollback & Official Cert Preservation] Eliminate AMFI SIGKILL 137 Crashes & Retain Official Signatures on Revert (PR #3603):
- Automatic Atomic Rollback on Codesign Failure: When patching the Claude binary on macOS, automatically restore the
.bakbackup and set0o755permissions if codesign or deep bundle signing fails, preventing corrupt unsigned binaries on disk from triggering kernel-level AMFI SIGKILL (137) crashes. - Preserve Official Developer Certificates on Revert: Replaced destructive ad-hoc re-signing on restore with non-destructive
codesign --verify --verbose=2verification, retaining Anthropic's official developer certificate and Keychain authorization. (Thanks to @cubelikeplayDaniel)
- Automatic Atomic Rollback on Codesign Failure: When patching the Claude binary on macOS, automatically restore the
- [Account Pool Lock Governance & Project ID Probe Isolation] Release invalid_grant Shard Lock, Isolate Probe Locks & Add Negative Cache (PR #3602):
- Release Shard Lock to Prevent Deadlocks: Explicitly drop DashMap shard locks before invoking
disable_account, eliminating self-deadlocks on re-entrant shard access. - Isolate Project ID Probes & 5-Minute Negative Cache: Separated project ID probes into dedicated per-account locks to avoid blocking background OAuth token refreshes, and introduced a 5-minute negative cache for failed or timed-out probes with cleanup on account removal. (Thanks to @cubelikeplayDaniel)
- Release Shard Lock to Prevent Deadlocks: Explicitly drop DashMap shard locks before invoking
- [Gemini Upstream Stream Error Propagation & Synthetic 200 Prevention] Propagate Upstream Status Codes, Block Empty STOP Candidates & Prevent Cache Poisoning (PR #3601):
- Real-Time Upstream Error Propagation: Parse incoming SSE error payloads (such as 504 Deadline Exceeded, 503 Unavailable, 429 Rate Limit) and pass through true HTTP status codes and structured Gemini error JSON, preventing artificial 200 OK responses with empty candidates.
- Guard Against Premature Stream Interruption: Prevent aborted streams from generating synthetic
STOPcandidate responses, protecting the thinking cache from poisoned empty entries. (Thanks to @cubelikeplayDaniel)
- [Kernel-Level Client Process Detection & Isolated Storage Path] Prevent Wrapper Script Misidentification, Path Panics & Isolate state.vscdb (PR #3600, Fixes #3598):
- Kernel Process Identification Over argv[0]: Identify processes using kernel-reported binary paths rather than user-mutable
argv[0], preventing script-wrapped Antigravity IDE instances from being misidentified as Classic. - Safe Directory Traversal for .app Bundles: Replaced byte-sliced
.find(".app")with parent path traversal, preventing panics on non-ASCII paths or command-line parameters. - Strictly Isolate state.vscdb Path: Target
state.vscdbalongside the activestorage_path, preventing IDE account switching from polluting Classic's database. (Thanks to @cubelikeplayDaniel)
- Kernel Process Identification Over argv[0]: Identify processes using kernel-reported binary paths rather than user-mutable
- [Project Specification Update & Pre-Flight Scope Clarification]:
- Refined
AGENTS.mdinto full English with neutral wording, specifying that pre-flight checks are run on demand only when tagging final releases, and excluded during daily tasks, code reviews, and minor fixes.
- Refined
- [Claude Cowork 压缩生命周期加固与工具 Schema 开销对齐] 解决负 Gap 压缩死锁、封死永久免死漏洞与状态池防泄漏 (PR #3604):
- 纳入工具 Schema 与 Description 核算开销: 固定开销估算(
calculate_claude_fixed_overhead)完整核算各工具description与input_schema的 Token 消耗,确保计算出的动态target_limit预留充足裕量,彻底根治复杂 MCP 工具下客户端因负/零initialTokenGap抛出compactionImpossible异常或无限卡死。 - 严格核销免死租约防失效穿透: 租约过期后严格返回
false,彻底封死因接续弱匹配回退导致的永久免死漏洞,确保会话后续超限时能正常进入下一轮自愈压缩。 - 剔除易误触的消息计数假完成判定: 移除手动压缩中轻率的
num_msgs < 50规则,严格以真实上下文显著回落(降至 85% 以下)或摘要完成信号判定压缩成功,防范大上下文初次请求伪造 200 OK。 - 跨轮次会话关联与容量修剪: 引入
PENDING_COMPACT_SESSIONS(120s TTL)对齐客户端摘要请求时的 session hash 偏移;为手动压缩池增加 1000 阈值容量防护与 300s TTL 淘汰清理。 (Thanks to @cubelikeplayDaniel)
- 纳入工具 Schema 与 Description 核算开销: 固定开销估算(
- [macOS 补丁签名容灾回滚与官方证书信任链保全] 根治 AMFI SIGKILL 137 闪退,还原无损保全官方签名 (PR #3603):
- 重签名失败自动原子回滚: 为 Claude 二进制注入补丁时,若 codesign 或 App Bundle deep 签名失败,立即原子将
.bak备份文件覆盖回原路径并恢复0o755权限,彻底杜绝磁盘残留签名损坏的二进制导致系统 AMFI 内核级杀进程(SIGKILL 137)。 - 还原原生保全官方证书链: 移除一键还原时破坏性的 ad-hoc 覆盖签名逻辑,改为非破坏性
codesign --verify --verbose=2校验,保全 Anthropic 官方开发者证书与系统 Keychain 授权。 (Thanks to @cubelikeplayDaniel)
- 重签名失败自动原子回滚: 为 Claude 二进制注入补丁时,若 codesign 或 App Bundle deep 签名失败,立即原子将
- [账号池锁治理与 Project ID 探测隔离] 释放 invalid_grant 分片锁防死锁,引入负缓存与独立探测锁 (PR #3602):
- 释放 DashMap 分片锁根除死锁: 在调用
disable_account前立即显式释放invalid_grant分片锁,彻底消灭重入导致的死锁假死。 - Project ID 探测独立加锁与 5 分钟负缓存: 将项目 ID 探测隔离至独立锁,避免被后台 OAuth 刷新阻塞;为探测失败引入 5 分钟负缓存,并在移除账号时代偿清理。 (Thanks to @cubelikeplayDaniel)
- 释放 DashMap 分片锁根除死锁: 在调用
- [Gemini 上游流错误透传与防伪造 200] 实时透传上游状态码,杜绝空候选 STOP 响应与缓存污染 (PR #3601):
- 实时透传进站错误事件: 深度解析 SSE 事件中的 504/503/429 等错误负载,真实透传上游 HTTP 状态码与结构化错误 JSON,杜绝生成人造的 200 OK 空候选。
- 防范异常流早断终止: 杜绝异常流中断时伪造
STOP终止响应,防止思考缓存数据库被脏数据污染。 (Thanks to @cubelikeplayDaniel)
- [客户端内核级进程识别与数据库精准隔离] 根除包装脚本误判与路径 Panic,隔离 state.vscdb (PR #3600, Fixes #3598):
- 内核路径识别替代 argv[0]: 基于内核报告的可执行文件路径识别进程,防止脚本调用 IDE 时被误判为 Classic。
- 安全目录遍历提取 .app Bundle: 移除基于字节切片的
.find(".app"),改用父级路径遍历,彻底杜绝非 ASCII 路径与特殊参数下的 Panic 崩溃。 - 精准隔离 state.vscdb 写入路径: 严格限定在当前写入的
storage_path同级,防止 IDE 账号切换污染 Classic 数据库。 (Thanks to @cubelikeplayDaniel)
- [项目规范更新与 Pre-flight 时机收敛]:
- 将
AGENTS.md规范调整为全英文中性表述,明确 Pre-flight 检查仅在最终发版打 Tag 时执行,日常任务、代码审查与简单调试均不触发。
- 将
What's Changed
- fix(process): 隔离各 IDE 目标 state.vscdb 并通过 proc_pidpath 精准识别进程二进制 (Fixes #3598) by @cubelikeplayDaniel in #3600
- fix(gemini): 穿透非流式收集器中的流错误响应并防止空块污染思考缓存 by @cubelikeplayDaniel in #3601
- fix(proxy): 释放 invalid_grant 分片锁避免自死锁,隔离 project_id 探测并引入 5 分钟负缓存 by @cubelikeplayDaniel in #3602
- fix(patch): macOS 注入重签名失败时自动回滚备份以防 AMFI 闪退,并在还原时保留官方证书 by @cubelikeplayDaniel in #3603
- fix(cowork): 纳入工具 Schema 核算开销、消除免死租约遗漏,加固压缩生命周期与状态修剪 by @cubelikeplayDaniel in #3604
Full Changelog: v4.9.4...v4.9.5-beta.0