Repository navigation
[pull] main from Alishahryar1:main - #257
Merged
Merged
Conversation
## Why Code sessions can stop after a storage failure with only a UI notice, losing the exception needed to diagnose it. Stream and response cleanup failures are currently hidden at DEBUG. ## How Log the first transition to failed Code storage at ERROR with the original exception, operation, session ID, and available run ID. Mark that transition before asynchronous cleanup so later handlers do not log it again. Promote shared stream-close and response-resource cleanup failures to WARNING. Preserve exception messages, tracebacks, and request context in native Loguru records while retaining response and cancellation behavior. <!-- greptile_comment --> <!-- greptile_summary --> <h2><a href="https://app.greptile.com/api/retrigger?id=71616312"><picture><source media="(prefers-color-scheme: dark)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/RetriggerDark.svg?v=2"><source media="(prefers-color-scheme: light)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"><img alt="Retrigger" src="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2" align="right"></picture></a>Confidence Score: 3/5</h2> <!-- greptile-risk --> Not safe to merge until exception details are made safe to log. <h2><a href="https://app.greptile.com/api/ide/codex?prompt=IMPORTANT%3A%20Work%20in%20the%20repository%20%22alishahryar1%2Ffree-claude-code%22%20on%20the%20existing%20branch%20%22ali%2Fsession-cleanup-failure-logs%22.%20Checkout%20that%20branch%20%E2%80%94%20do%20NOT%20create%20a%20new%20branch%20or%20open%20a%20new%20PR.%20Push%20your%20changes%20to%20%22ali%2Fsession-cleanup-failure-logs%22.%0A%0A%23%23%23%20Issue%201%0Asrc%2Ffree_claude_code%2Fcore%2Ftrace.py%3A85%0AIf%20a%20stream-close%20exception%20contains%20a%20credential%2C%20this%20warning%20attaches%20the%20unredacted%20exception%20to%20the%20default%20JSON%20log.%20The%20credential%20is%20retained%20in%20both%20the%20exception%20value%20and%20formatted%20traceback%2C%20exposing%20it%20to%20anyone%20with%20access%20to%20those%20logs.%20Redact%20exception%20details%20before%20writing%20this%20warning%3B%20this%20disclosure%20must%20be%20fixed%20before%20merging.%0A%0A**How%20this%20was%20verified%3A**%20A%20stream-close%20exception%20containing%20a%20dummy%20credential%20appeared%20unredacted%20in%20the%20JSON%20log%20record.%0A%0A---%0A%0AFor%20each%20issue%20above%2C%20determine%20whether%20it%20is%20valid%20and%20should%20be%20fixed.%20If%20so%2C%20fix%20it%20directly.&repo=alishahryar1%2Ffree-claude-code&pr=1948&platform=github"><picture><source media="(prefers-color-scheme: dark)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/FixAllInCodexDark.svg?v=7"><source media="(prefers-color-scheme: light)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/FixAllInCodex.svg?v=7"><img alt="Fix All in Codex" src="https://greptile-static-assets.s3.amazonaws.com/badges/FixAllInCodex.svg?v=7" align="right"></picture></a>Findings</h2> 1. <img alt="P1" src="https://greptile-static-assets.s3.amazonaws.com/badges/p1.svg?v=9" align="top"> <img alt="Security" src="https://greptile-static-assets.s3.amazonaws.com/badges/Security.svg?v=2" align="top"> **Stream errors expose credentials** <a href="https://github.com/Alishahryar1/free-claude-code/pull/1948#discussion_r4138098074">▶</a> <details open><summary>Summary</summary> The PR makes cleanup and storage failures more visible. Operators need those failure records without retaining credentials from exception messages, but the new stream-close warning can write a credential into the default JSON log. This must be fixed before merging. </details> <!-- greptile_confidence_score:3 --> <sub>Reviews (1) · Last reviewed commit: ["patch: Log stopped Code sessions and cle..."](https://github.com/alishahryar1/free-claude-code/commit/388339529ba80708d12d5aa6cff61182044df5be)</sub> <!-- /greptile_comment -->
## Why Retained logs can contain several FCC runs, including restarts in the same process. The startup message does not identify the installed version, and log records cannot be matched to the runtime instance shown in Admin status. Updater tests discard the prepared dependency cache for every case. SQLite ownership tests run schema migrations inside a short synchronization window, making them sensitive to slow storage. ## How Add the installed FCC version and existing runtime instance ID to a structured `server.starting` record. Scope the Uvicorn run and ASGI calls with that instance ID so request logs, background tasks, and context-aware workers inherit it. Restore the previous logging context when each scope exits. Bind the selected server's instance ID to browser-handoff warnings for automatic opening, tray actions, and reuse of an existing server. Capture the ID when queuing the action so delayed warnings retain their original instance after a restart. Reuse uv's configured dependency cache across isolated updater installations and shorten the test HTTP server's shutdown polling interval. Copy a pristine schema prepared outside the SQLite ownership tests' synchronization window. <!-- greptile_comment --> <!-- greptile_summary --> <h2><a href="https://app.greptile.com/api/retrigger?id=71655381"><picture><source media="(prefers-color-scheme: dark)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/RetriggerDark.svg?v=2"><source media="(prefers-color-scheme: light)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"><img alt="Retrigger" src="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2" align="right"></picture></a>Confidence Score: 5/5</h2> <!-- greptile-risk --> No outstanding findings block merging. <details open><summary>Summary</summary> The PR adds instance-aware startup and server logging, carries the instance ID into Admin browser warnings, and updates the updater and SQLite test setup. No new actionable issues were identified. </details> <!-- greptile_confidence_score:5 --> <sub>Reviews (3) · Last reviewed commit: ["test: Reuse updater cache and prepare SQ..."](https://github.com/alishahryar1/free-claude-code/commit/c758e1a21102f7d0404276aacb33a47928009834)</sub> <!-- /greptile_comment -->
## Why At the default INFO level, FCC still builds request snapshots and recursively copies trace fields before Loguru discards the DEBUG record. API handlers also serialize full request bodies even when raw-payload logging is disabled. ## How Use Loguru's lazy arguments to construct and sanitize trace payloads after level filtering. Pass payload factories through Messages, Responses, automatic web search, token-count tracing, and Chat request tracing so logging-only serialization runs when needed. DEBUG records retain their existing payload structure and correlation fields. <!-- greptile_comment --> <!-- greptile_summary --> <h2><a href="https://app.greptile.com/api/retrigger?id=71720466"><picture><source media="(prefers-color-scheme: dark)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/RetriggerDark.svg?v=2"><source media="(prefers-color-scheme: light)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"><img alt="Retrigger" src="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2" align="right"></picture></a>Confidence Score: 4/5</h2> <!-- greptile-risk --> The confirmed memory concern is non-blocking and does not by itself prevent merging. What we checked: - T-Rex produced a proof for a posted P2 finding and linked it to the corresponding review comment. <a href="https://www.greptile.com/trex"><img alt="T-Rex" src="https://greptile-static-assets.s3.amazonaws.com/trex/trex_green.svg" height="16" align="absmiddle"></a> - T-Rex ran in-process ASGI memory measurements and documented memory usage with and without outcome middleware, validating the behavior described in the P2 proof. <a href="https://www.greptile.com/trex"><img alt="T-Rex" src="https://greptile-static-assets.s3.amazonaws.com/trex/trex_green.svg" height="16" align="absmiddle"></a> - T-Rex posted a proof for a posted P1 finding. <a href="https://www.greptile.com/trex"><img alt="T-Rex" src="https://greptile-static-assets.s3.amazonaws.com/trex/trex_green.svg" height="16" align="absmiddle"></a> - T-Rex validated API error handling for cleanup records, confirming the synthetic credential is omitted when LOG_API_ERROR_TRACEBACKS=false. <a href="https://www.greptile.com/trex"><img alt="T-Rex" src="https://greptile-static-assets.s3.amazonaws.com/trex/trex_green.svg" height="16" align="absmiddle"></a> <details open><summary>Summary</summary> The PR defers DEBUG payload construction and adds final inference-outcome logging. The new outcome observer buffers successful streaming events until their delimiter, increasing memory use and processing time for large events. </details> <!-- greptile_confidence_score:4 --> <sub>Reviews (1) · Last reviewed commit: ["patch: Defer disabled debug payload cons..."](https://github.com/alishahryar1/free-claude-code/commit/bb830d1b8e3306153587751f5a13b5f7f1d5e6f8)</sub> <!-- /greptile_comment -->
## Why Claude Desktop 3p limits tool network access to the inference endpoint when `coworkEgressAllowedHosts` is absent. FCC creates a localhost gateway profile without that setting, so Cowork Web Fetch rejects public sites with `cowork-egress-blocked` even though inference and web search work. Fixes #1947. ## How Default the setting to `["*"]` when creating, reconnecting, or refreshing an FCC profile that lacks it. Preserve existing values, including restricted domain lists and an empty list. This intentionally allows tool network access for Cowork fetching, shell commands and package installs, and Code sessions through Desktop's supported configuration. <!-- greptile_comment --> <!-- greptile_summary --> <h2><a href="https://app.greptile.com/api/retrigger?id=71779313"><picture><source media="(prefers-color-scheme: dark)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/RetriggerDark.svg?v=2"><source media="(prefers-color-scheme: light)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"><img alt="Retrigger" src="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2" align="right"></picture></a>Confidence Score: 4/5</h2> <!-- greptile-risk --> The missing guidance is non-blocking; the review does not identify a reason to prevent merging. <h2><a href="https://app.greptile.com/api/ide/codex?prompt=IMPORTANT%3A%20Work%20in%20the%20repository%20%22alishahryar1%2Ffree-claude-code%22%20on%20the%20existing%20branch%20%22ali%2Fdesktop-cowork-egress%22.%20Checkout%20that%20branch%20%E2%80%94%20do%20NOT%20create%20a%20new%20branch%20or%20open%20a%20new%20PR.%20Push%20your%20changes%20to%20%22ali%2Fdesktop-cowork-egress%22.%0A%0A%23%23%23%20Issue%201%0Asrc%2Ffree_claude_code%2Fharnesses%2Fclaude_desktop_integration.py%3A299%0AConnecting%20or%20refreshing%20an%20FCC%20profile%20with%20no%20egress%20setting%20now%20writes%20%60coworkEgressAllowedHosts%3A%20%5B%22*%22%5D%60%2C%20allowing%20Cowork%20and%20Code%20tools%20to%20reach%20any%20hostname%20subject%20to%20other%20network%20controls.%20The%20Desktop%20setup%20instructions%20do%20not%20disclose%20this%20default%20or%20explain%20how%20to%20set%20an%20empty%20or%20restricted%20host%20list.%20Users%20who%20want%20limited%20tool%20access%20may%20connect%20without%20realizing%20they%20need%20to%20configure%20it.%20This%20guidance%20can%20be%20added%20without%20blocking%20the%20change.%0A%0ANote%3A%20If%20this%20suggestion%20doesn't%20match%20your%20team's%20coding%20style%2C%20reply%20to%20this%20and%20let%20me%20know.%20I'll%20remember%20it%20for%20next%20time!%0A%0A---%0A%0AFor%20each%20issue%20above%2C%20determine%20whether%20it%20is%20valid%20and%20should%20be%20fixed.%20If%20so%2C%20fix%20it%20directly.&repo=alishahryar1%2Ffree-claude-code&pr=1953&platform=github"><picture><source media="(prefers-color-scheme: dark)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/FixAllInCodexDark.svg?v=7"><source media="(prefers-color-scheme: light)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/FixAllInCodex.svg?v=7"><img alt="Fix All in Codex" src="https://greptile-static-assets.s3.amazonaws.com/badges/FixAllInCodex.svg?v=7" align="right"></picture></a>Findings</h2> 1. <img alt="P2" src="https://greptile-static-assets.s3.amazonaws.com/badges/p2.svg?v=9" align="top"> **Document Desktop network access** <a href="https://github.com/Alishahryar1/free-claude-code/pull/1953#discussion_r4139924951">▶</a> <details open><summary>Summary</summary> The PR gives FCC Claude Desktop profiles without an explicit egress policy unrestricted host access for Cowork and Code tools, while preserving explicit policies. The Desktop setup instructions do not explain the new default or how to restrict it. This documentation concern is non-blocking. </details> <!-- greptile_confidence_score:4 --> <sub>Reviews (1) · Last reviewed commit: ["patch: Allow tool network access in Clau..."](https://github.com/alishahryar1/free-claude-code/commit/2492b02a1cde7a0b453a29a98b4b72a6e1069269)</sub> <!-- /greptile_comment -->
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please sponsor : )