Skip to content

[pull] main from Alishahryar1:main - #257

Merged
pull[bot] merged 4 commits into
Co-Contribute-OpenSource:mainfrom
Alishahryar1:main
Sep 30, 2026
Merged

pull[bot] merged 4 commits into
Co-Contribute-OpenSource:mainfrom
Alishahryar1:main

Conversation

@pull

@pull pull Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

## Why

Code sessions can stop after a storage failure with only a UI notice,
losing the exception needed to diagnose it. Stream and response cleanup
failures are currently hidden at DEBUG.

## How

Log the first transition to failed Code storage at ERROR with the
original exception, operation, session ID, and available run ID. Mark
that transition before asynchronous cleanup so later handlers do not log
it again.

Promote shared stream-close and response-resource cleanup failures to
WARNING. Preserve exception messages, tracebacks, and request context in
native Loguru records while retaining response and cancellation
behavior.


<!-- greptile_comment -->

<!-- greptile_summary -->

<h2><a
href="https://app.greptile.com/api/retrigger?id=71616312"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/RetriggerDark.svg?v=2"><source
media="(prefers-color-scheme: light)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"><img
alt="Retrigger"
src="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"
align="right"></picture></a>Confidence Score: 3/5</h2>

<!-- greptile-risk -->

Not safe to merge until exception details are made safe to log.

<h2><a
href="https://app.greptile.com/api/ide/codex?prompt=IMPORTANT%3A%20Work%20in%20the%20repository%20%22alishahryar1%2Ffree-claude-code%22%20on%20the%20existing%20branch%20%22ali%2Fsession-cleanup-failure-logs%22.%20Checkout%20that%20branch%20%E2%80%94%20do%20NOT%20create%20a%20new%20branch%20or%20open%20a%20new%20PR.%20Push%20your%20changes%20to%20%22ali%2Fsession-cleanup-failure-logs%22.%0A%0A%23%23%23%20Issue%201%0Asrc%2Ffree_claude_code%2Fcore%2Ftrace.py%3A85%0AIf%20a%20stream-close%20exception%20contains%20a%20credential%2C%20this%20warning%20attaches%20the%20unredacted%20exception%20to%20the%20default%20JSON%20log.%20The%20credential%20is%20retained%20in%20both%20the%20exception%20value%20and%20formatted%20traceback%2C%20exposing%20it%20to%20anyone%20with%20access%20to%20those%20logs.%20Redact%20exception%20details%20before%20writing%20this%20warning%3B%20this%20disclosure%20must%20be%20fixed%20before%20merging.%0A%0A**How%20this%20was%20verified%3A**%20A%20stream-close%20exception%20containing%20a%20dummy%20credential%20appeared%20unredacted%20in%20the%20JSON%20log%20record.%0A%0A---%0A%0AFor%20each%20issue%20above%2C%20determine%20whether%20it%20is%20valid%20and%20should%20be%20fixed.%20If%20so%2C%20fix%20it%20directly.&repo=alishahryar1%2Ffree-claude-code&pr=1948&platform=github"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/FixAllInCodexDark.svg?v=7"><source
media="(prefers-color-scheme: light)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/FixAllInCodex.svg?v=7"><img
alt="Fix All in Codex"
src="https://greptile-static-assets.s3.amazonaws.com/badges/FixAllInCodex.svg?v=7"
align="right"></picture></a>Findings</h2>

1. <img alt="P1"
src="https://greptile-static-assets.s3.amazonaws.com/badges/p1.svg?v=9"
align="top">&nbsp;<img alt="Security"
src="https://greptile-static-assets.s3.amazonaws.com/badges/Security.svg?v=2"
align="top">&nbsp;**Stream errors expose credentials** <a
href="https://github.com/Alishahryar1/free-claude-code/pull/1948#discussion_r4138098074">▶</a>

<details open><summary>Summary</summary>

The PR makes cleanup and storage failures more visible. Operators need
those failure records without retaining credentials from exception
messages, but the new stream-close warning can write a credential into
the default JSON log. This must be fixed before merging.
</details>

<!-- greptile_confidence_score:3 -->

<sub>Reviews (1) · Last reviewed commit: ["patch: Log stopped Code
sessions and
cle..."](https://github.com/alishahryar1/free-claude-code/commit/388339529ba80708d12d5aa6cff61182044df5be)</sub>

<!-- /greptile_comment -->
## Why

Retained logs can contain several FCC runs, including restarts in the
same process. The startup message does not identify the installed
version, and log records cannot be matched to the runtime instance shown
in Admin status.

Updater tests discard the prepared dependency cache for every case.
SQLite ownership tests run schema migrations inside a short
synchronization window, making them sensitive to slow storage.

## How

Add the installed FCC version and existing runtime instance ID to a
structured `server.starting` record. Scope the Uvicorn run and ASGI
calls with that instance ID so request logs, background tasks, and
context-aware workers inherit it. Restore the previous logging context
when each scope exits.

Bind the selected server's instance ID to browser-handoff warnings for
automatic opening, tray actions, and reuse of an existing server.
Capture the ID when queuing the action so delayed warnings retain their
original instance after a restart.

Reuse uv's configured dependency cache across isolated updater
installations and shorten the test HTTP server's shutdown polling
interval. Copy a pristine schema prepared outside the SQLite ownership
tests' synchronization window.


<!-- greptile_comment -->

<!-- greptile_summary -->

<h2><a
href="https://app.greptile.com/api/retrigger?id=71655381"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/RetriggerDark.svg?v=2"><source
media="(prefers-color-scheme: light)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"><img
alt="Retrigger"
src="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"
align="right"></picture></a>Confidence Score: 5/5</h2>

<!-- greptile-risk -->

No outstanding findings block merging.

<details open><summary>Summary</summary>

The PR adds instance-aware startup and server logging, carries the
instance ID into Admin browser warnings, and updates the updater and
SQLite test setup. No new actionable issues were identified.
</details>

<!-- greptile_confidence_score:5 -->

<sub>Reviews (3) · Last reviewed commit: ["test: Reuse updater cache and
prepare
SQ..."](https://github.com/alishahryar1/free-claude-code/commit/c758e1a21102f7d0404276aacb33a47928009834)</sub>

<!-- /greptile_comment -->
## Why

At the default INFO level, FCC still builds request snapshots and
recursively copies trace fields before Loguru discards the DEBUG record.
API handlers also serialize full request bodies even when raw-payload
logging is disabled.

## How

Use Loguru's lazy arguments to construct and sanitize trace payloads
after level filtering. Pass payload factories through Messages,
Responses, automatic web search, token-count tracing, and Chat request
tracing so logging-only serialization runs when needed. DEBUG records
retain their existing payload structure and correlation fields.


<!-- greptile_comment -->

<!-- greptile_summary -->

<h2><a
href="https://app.greptile.com/api/retrigger?id=71720466"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/RetriggerDark.svg?v=2"><source
media="(prefers-color-scheme: light)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"><img
alt="Retrigger"
src="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"
align="right"></picture></a>Confidence Score: 4/5</h2>

<!-- greptile-risk -->

The confirmed memory concern is non-blocking and does not by itself
prevent merging.

What we checked:
- T-Rex produced a proof for a posted P2 finding and linked it to the
corresponding review comment. <a
href="https://www.greptile.com/trex"><img alt="T-Rex"
src="https://greptile-static-assets.s3.amazonaws.com/trex/trex_green.svg"
height="16" align="absmiddle"></a>
- T-Rex ran in-process ASGI memory measurements and documented memory
usage with and without outcome middleware, validating the behavior
described in the P2 proof. <a href="https://www.greptile.com/trex"><img
alt="T-Rex"
src="https://greptile-static-assets.s3.amazonaws.com/trex/trex_green.svg"
height="16" align="absmiddle"></a>
- T-Rex posted a proof for a posted P1 finding. <a
href="https://www.greptile.com/trex"><img alt="T-Rex"
src="https://greptile-static-assets.s3.amazonaws.com/trex/trex_green.svg"
height="16" align="absmiddle"></a>
- T-Rex validated API error handling for cleanup records, confirming the
synthetic credential is omitted when LOG_API_ERROR_TRACEBACKS=false. <a
href="https://www.greptile.com/trex"><img alt="T-Rex"
src="https://greptile-static-assets.s3.amazonaws.com/trex/trex_green.svg"
height="16" align="absmiddle"></a>

<details open><summary>Summary</summary>

The PR defers DEBUG payload construction and adds final
inference-outcome logging. The new outcome observer buffers successful
streaming events until their delimiter, increasing memory use and
processing time for large events.
</details>

<!-- greptile_confidence_score:4 -->

<sub>Reviews (1) · Last reviewed commit: ["patch: Defer disabled debug
payload
cons..."](https://github.com/alishahryar1/free-claude-code/commit/bb830d1b8e3306153587751f5a13b5f7f1d5e6f8)</sub>

<!-- /greptile_comment -->
## Why

Claude Desktop 3p limits tool network access to the inference endpoint
when `coworkEgressAllowedHosts` is absent. FCC creates a localhost
gateway profile without that setting, so Cowork Web Fetch rejects public
sites with `cowork-egress-blocked` even though inference and web search
work. Fixes #1947.

## How

Default the setting to `["*"]` when creating, reconnecting, or
refreshing an FCC profile that lacks it. Preserve existing values,
including restricted domain lists and an empty list. This intentionally
allows tool network access for Cowork fetching, shell commands and
package installs, and Code sessions through Desktop's supported
configuration.


<!-- greptile_comment -->

<!-- greptile_summary -->

<h2><a
href="https://app.greptile.com/api/retrigger?id=71779313"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/RetriggerDark.svg?v=2"><source
media="(prefers-color-scheme: light)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"><img
alt="Retrigger"
src="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"
align="right"></picture></a>Confidence Score: 4/5</h2>

<!-- greptile-risk -->

The missing guidance is non-blocking; the review does not identify a
reason to prevent merging.

<h2><a
href="https://app.greptile.com/api/ide/codex?prompt=IMPORTANT%3A%20Work%20in%20the%20repository%20%22alishahryar1%2Ffree-claude-code%22%20on%20the%20existing%20branch%20%22ali%2Fdesktop-cowork-egress%22.%20Checkout%20that%20branch%20%E2%80%94%20do%20NOT%20create%20a%20new%20branch%20or%20open%20a%20new%20PR.%20Push%20your%20changes%20to%20%22ali%2Fdesktop-cowork-egress%22.%0A%0A%23%23%23%20Issue%201%0Asrc%2Ffree_claude_code%2Fharnesses%2Fclaude_desktop_integration.py%3A299%0AConnecting%20or%20refreshing%20an%20FCC%20profile%20with%20no%20egress%20setting%20now%20writes%20%60coworkEgressAllowedHosts%3A%20%5B%22*%22%5D%60%2C%20allowing%20Cowork%20and%20Code%20tools%20to%20reach%20any%20hostname%20subject%20to%20other%20network%20controls.%20The%20Desktop%20setup%20instructions%20do%20not%20disclose%20this%20default%20or%20explain%20how%20to%20set%20an%20empty%20or%20restricted%20host%20list.%20Users%20who%20want%20limited%20tool%20access%20may%20connect%20without%20realizing%20they%20need%20to%20configure%20it.%20This%20guidance%20can%20be%20added%20without%20blocking%20the%20change.%0A%0ANote%3A%20If%20this%20suggestion%20doesn't%20match%20your%20team's%20coding%20style%2C%20reply%20to%20this%20and%20let%20me%20know.%20I'll%20remember%20it%20for%20next%20time!%0A%0A---%0A%0AFor%20each%20issue%20above%2C%20determine%20whether%20it%20is%20valid%20and%20should%20be%20fixed.%20If%20so%2C%20fix%20it%20directly.&repo=alishahryar1%2Ffree-claude-code&pr=1953&platform=github"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/FixAllInCodexDark.svg?v=7"><source
media="(prefers-color-scheme: light)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/FixAllInCodex.svg?v=7"><img
alt="Fix All in Codex"
src="https://greptile-static-assets.s3.amazonaws.com/badges/FixAllInCodex.svg?v=7"
align="right"></picture></a>Findings</h2>

1. <img alt="P2"
src="https://greptile-static-assets.s3.amazonaws.com/badges/p2.svg?v=9"
align="top">&nbsp;**Document Desktop network access** <a
href="https://github.com/Alishahryar1/free-claude-code/pull/1953#discussion_r4139924951">▶</a>

<details open><summary>Summary</summary>

The PR gives FCC Claude Desktop profiles without an explicit egress
policy unrestricted host access for Cowork and Code tools, while
preserving explicit policies. The Desktop setup instructions do not
explain the new default or how to restrict it. This documentation
concern is non-blocking.
</details>

<!-- greptile_confidence_score:4 -->

<sub>Reviews (1) · Last reviewed commit: ["patch: Allow tool network
access in
Clau..."](https://github.com/alishahryar1/free-claude-code/commit/2492b02a1cde7a0b453a29a98b4b72a6e1069269)</sub>

<!-- /greptile_comment -->
@pull pull Bot locked and limited conversation to collaborators Sep 30, 2026
@pull pull Bot added the ⤵️ pull label Sep 30, 2026
@pull
pull Bot merged commit 549918e into Co-Contribute-OpenSource:main Sep 30, 2026

This branch had an error being deployed

1 failed deployment
pypi — 549918e2 Deployed Sep 30, 2026 by pull[bot] via Publish to PyPI #14
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant