Gitea has no /releases/latest/download/<file> shortcut (GitHub-only),
so the URL we wired up last commit served 404. Switch all user-facing
install commands to /raw/HEAD/install.{sh,ps1} -- the HEAD ref resolves
to the default branch (secure-main) without naming it, gives a stable
"always latest" URL, and survives a future branch rename.
With install no longer routed through release assets, the release
workflow becomes dead weight: secure-main is the curated branch (every
merge is manually reviewed), so every commit there is already vetted.
A separate tagged-release step duplicates that gate without adding new
information. Drop .gitea/workflows/release.yml; tag manually if you
ever want an immutable audit checkpoint.
The orphan v1.1.7-secure.1 tag + release is left in place as a
historical snapshot; harmless and can be deleted from the Gitea UI
later if desired.
The three .github/workflows files (release.yml, compat-daily.yml,
cache-cleanup-weekly.yml) all target the GitHub API:
- release.yml uses `gh release create`
- compat-daily.yml does `git push https://x-access-token@github.com/...`
to a `badges` branch
- cache-cleanup-weekly.yml uses `gh cache delete`
On Gitea Actions these silently mis-route to GitHub with a Gitea-issued
GITHUB_TOKEN, which github.com rejects ("Invalid username or token") —
so every scheduled run fails.
Drop them on secure-main (upstream main keeps them for the original
GitHub repo, untouched) and add .gitea/workflows/release.yml that:
- triggers on tag push v* or manual workflow_dispatch
- builds release notes from the changelog window since the prior tag
- creates the release via Gitea API, or refreshes assets if it already
exists (so re-runs are idempotent)
- attaches install.sh + install.ps1 so the README's
/releases/latest/download/install.{sh,ps1} URLs resolve
Tag a release with:
git tag v1.0.0 && git push origin v1.0.0
Commit 56bc5a7 was authored from a PowerShell session whose console code
page was cp1251 (Cyrillic), so PowerShell read the UTF-8 byte stream of
each touched file as cp1251 and re-saved it as UTF-8 -- adding a leading
EF BB BF BOM and double-encoding every multi-byte character (em-dash,
arrows, CJK). README headings, Chinese/Japanese link labels, and inline
hyphens all turned into vЂ" / в†' / дё-ж–' style mojibake.
Restore the eight affected files (READMEs, docs/clawgod-handbook/*,
*.html) from main's clean blobs, then re-apply the qomar.pw redirect
substitutions on top. Install URLs now point at
git.qomar.pw/omar/clawgod/releases/latest/download/install.{sh,ps1}
instead of /raw/branch/secure-main/... in both the markdown/HTML docs
and the patcher snippet inside install.sh / install.ps1 (the snippet
that rewrites `claude update`).
Note: this assumes a Gitea release pipeline publishes install.sh +
install.ps1 as assets under each tag. Without that, the new URLs 404.
Claude Code injects `x-anthropic-billing-header` (with a per-request `cch`
field) as the first system-prompt block. Anthropic's own server excludes
this block from prompt-cache key calculation via `cacheScope:null`, but
third-party Anthropic-compatible proxies (DeepSeek / OneAPI / Bedrock /
vLLM / etc.) fold it into the prefix hash. Result: the cached prefix
changes every request and cache hit rate drops to zero, multiplying
token consumption.
Wrapper now sets `CLAUDE_CODE_ATTRIBUTION_HEADER=0` whenever
`config.baseURL` is non-anthropic.com, mirroring the same check that
already gates `ANTHROPIC_AUTH_TOKEN` injection. Uses `??=` so users can
still force-enable via env if they need it. OAuth users on the default
Anthropic endpoint are unaffected — the header keeps working as intended
on the official server.
README (en/zh/jp): adds a "Third-Party Cache Fix" row to the Reliability
table, noting users no longer need to set this env var themselves.
Upstream rewrote the model-gate function in 2.1.139:
- ≤2.1.138: let Y=Dq();if(Y!=="firstParty"&&Y!=="anthropicAws")return!1;
- 2.1.139+: function wuH(H){let $=R7(H),q=Wq();if(q!=="firstParty"&&q!=="anthropicAws")return!1;...}
The if-gate itself is unchanged, but the surrounding `let` got merged
into a comma-list. Our regex required `let X=Y();` to be immediately
followed by `if(X!==...)`, so 2.1.139 stopped matching and the sentinel
flagged it as stale (daily compat-CI surfaced this as a hard failure).
Shrink the regex to match only the if-gate; leave `let` alone. Verified
to land 1 replacement on both 2.1.139 (local-ubuntu real install) and
2.1.138 (Node REPL on each shape). Downstream model allow-list runs as
before; a dead `let` variable remains but has no functional impact.
Fixed#69
Copilot review: StartsWith without a separator boundary could match
C:\Users\ab as a prefix of C:\Users\abc\..., producing a broken
%USERPROFILE% path. Normalize trailing slashes and check against
$userProfilePrefix ("$normalizedUserProfile\").
Replace resolved absolute paths (which embed the user profile directory
containing CJK characters) with %USERPROFILE% variable references in the
generated .cmd launcher. cmd.exe expands %USERPROFILE% at runtime, so the
batch file stays pure ASCII regardless of username codepage constraints.
Also switch Set-Content encoding from ASCII to Default as defense-in-depth
for the edge case where Bun lives outside the user profile.
Anthropic builds the native binary against Bun's canary channel; bun.sh
stable trails by one version. Bun < 1.3.14 panics on cli.original.cjs
with "Expected CommonJS module to have a function wrapper". The late
sanity check already detected this, but on Windows PowerShell wraps
native-command stderr as NativeCommandError, which under
$ErrorActionPreference='Stop' or `iex` terminated the script before our
friendly Write-Err block ran — users only saw the scary PS error and
filed issues against install.ps1 line 1197 itself.
- Add pre-flight $MinBunVersion / MIN_BUN_VERSION = 1.3.14 in both
install.sh and install.ps1, immediately after bun is located.
Reject below the floor before any npm download / patch / sanity step.
- Harden the late PS sanity check with try/catch + localized
ErrorActionPreference='Continue' as defense-in-depth, in case the
embedded Bun moves past our constant before we bump it.
- bash uses sort -V; PS uses [version] cast. Both strip canary suffix
before compare. PS cast is null-guarded against bun returning empty.
Closes#65
claude update was redirected to install.sh in v1.1.1, which still probed
npm-global / bun-global before falling back to the registry. Both
directories freeze the moment clawgod is installed (we patch out
claude update, so users never re-run npm install -g / bun add -g), so
detection picked the install-day binary forever — claude update never
actually upgraded anyone past their initial version.
Drop the npm-global and bun-global probes entirely (and the
scan_node_modules_root helper). install.sh and install.ps1 now always
fetch @anthropic-ai/claude-code-<platform>@latest from the npm registry,
so claude update genuinely tracks upstream releases.
Trade-off: ~60-90 MB tarball pulled even on first install. npm cache +
typical bandwidth keep this under 30s; correctness > one-time install
latency.
Upstream v2.1.123 reshaped the cautious-actions function from
function GSY(){return`# Executing actions with care\n...`}
into
function _j3(H){if(LE8(H)==="compact")return`...short`;return`...long`}
Both the new parameter list and the new "compact mode" early-return
branch broke our regex; sentinel still matched, so daily compat
workflow flagged 1 failed patch.
Update the regex to accept an optional parameter and an optional
if(...)return... compact branch. Verified against v2.1.88 (single
return, no args) and v2.1.123 (parameterized + branched).
Earlier wrapper set CLAUDE_CONFIG_DIR=~/.clawgod (and ~/.claude in OAuth
path), which made Claude Code read/write ~/.clawgod/.claude.json instead
of the native ~/.claude.json — breaking MCP config, session history, and
third-party tools like cc-switch that write to ~/.claude.json.
Drop the override and let Claude Code use its native paths. On first run
after upgrade, transparently rename ~/.clawgod/.claude.json -> ~/.claude.json
when the native file is absent, so the upgrade is seamless for existing
clawgod-only users.
Closes#52
compat-daily.yml writes a fresh ~/.npm cache entry per run (key
embeds github.run_id) and reads previous entries via restore-keys.
GitHub's 7-day inactivity expiry never fires — the daily restore-
keys match counts as access — so entries accumulate until the 10 GB
per-repo cap kicks in and LRU starts evicting useful caches.
Weekly purge: list every cache, delete it. Next compat-daily run
repopulates ~/.npm fresh from npm-registry (one extra ~80 MB
download per week, trivial cost). Sunday 04:00 UTC cron, with a
workflow_dispatch escape hatch for manual cleanup. `actions: write`
permission scoped to this workflow only.
Ctrl+F5 / cold loads previously showed a sequence of small flashes:
unstyled text first, SVG icons popping from 300×150 to their icon
size, then the hero h1 layout-shifting when Google Fonts Inter
swapped in. Each one came from a different async resource in the
loading chain — patching them one at a time was a losing game,
because every fix exposed the next link.
Root cause: web fonts are always a separately-fetched resource. No
CSS-only trick (size-adjust override, ascent/descent override) makes
the re-render imperceptible at hero-h1 sizes — at 80 px, even a few-
pixel metric delta is visible.
Replace Google Fonts with @fontsource-variable npm packages and let
Vite's assetsInlineLimit (100 MB) base64-inline the woff2 into the
stylesheet. Hand-written @font-face declarations restricted to the
latin weight-axis subset; the default index.css would have inlined
13 woff2s across cyrillic / greek / vietnamese — ~300 KB of dead
weight on a page that only renders ASCII.
Two related moves stacked in here because they're part of the same
"no async resource between HTML and first paint" rule:
- CSS now loaded via <link rel=stylesheet> in the HTML head, not
imported through main.ts. Importing through the deferred ES
module chained CSS behind the JS fetch and produced the same
unstyled-text flash for the same reason.
- Inline <svg>s gained explicit width / height attributes — without
them the browser rendered SVGs at the default 300×150 viewport
before CSS arrived, then snapped them to icon size.
The earlier metric-matched fallback @font-face declarations are
gone — they were a workaround for the async swap, no longer needed
once the font is synchronous with the CSS.
HTML grows from 31 KB / 9 KB gzipped to 150 KB / 99 KB gzipped.
One-time cost; cached after first visit; no third-party DNS or
font-CDN dependency.
Net result: first paint is the finished page on Ctrl+F5.
The previous build was client-side rendered: an empty <div id="app">
in the HTML, then JS would innerHTML the entire page on DOMContent-
Loaded. With the deferred module script, that meant first paint had
no hero h1 — it appeared a frame later, and the clamp(3rem, 8vw, 5rem)
sizing applied at exactly that moment. Felt jarring even on fast
connections, worse on slow ones.
Move all markup statically into web/index.html so first paint is the
finished page. main.ts is now progressive enhancement only:
- tab switching for the install widget
- copy-to-clipboard with secure-context fallback
- sticky-topbar shadow on scroll
- hydrate the verified-version pill from the daily-CI badge JSON
- hydrate the GitHub stargazer / total-download chips
The hero pill, install code blocks (token spans hand-written), and
all patch cards are now in the HTML directly, so the page renders
identically before and after the JS turn — no layout flash, no
content pop-in. Token highlighting, hover states, all the same.
Bundle sizes nearly even: 27.5 → 31.3 KB raw, 8.92 → 8.52 KB gzip
(repeated patch-card markup compresses tighter than the JS that
generated it).
data.ts is deleted — its sole role was feeding the JS template,
which no longer exists. Patches list lives in HTML now; future
additions are 4-line article blocks under the right section.
Two issues from the previous commit landed together:
- vite.config.ts had outDir: '../', which Vite refuses to honor
during build (`outDir must not be the same directory of root or
a parent directory`). dev still ran fine, but `npm run build`
would have failed on first attempt.
- The repo-root index.html was still the v1.0.x hand-written
11 KB version — the new Vite landing page never made it into
what GitHub Pages actually serves.
Fix: build to web/dist/ as Vite expects, then ship a tiny
closeBundle plugin (apply: 'build' so it stays out of dev) that
copyFileSyncs dist/index.html up to ../index.html. Single command:
cd web && npm run build
now produces a single inlined HTML (27.5 KB / 8.9 KB gzipped) and
plants it at the repo root, ready for the next push to flow
through GitHub Pages.
clawgod/index.html in this commit is that build output — overwriting
the previous hand-written page so clawgod.0chen.cc serves the
rebuilt landing page.
Replace the single-file index.html at the repo root with a proper
Vite + TS project under web/ that builds back to a single inlined
index.html via vite-plugin-singlefile. GitHub Pages keeps serving
the same path; deploy posture unchanged.
Visual:
- Sticky topbar, twin radial-gradient backdrop fixed under scroll,
Inter + JetBrains Mono. Adaptive container width: 880 default →
1120 @ ≥1200 → 1280 @ ≥1440 (patches auto-fill 3 → 4 columns).
- Hero pill reads `Verified on Claude Code <version>` from the same
`badges` branch JSON the README badge consumes.
- 4-chip stats row in hero: GitHub @0chencc, X @0chencc, live
stargazers, summed asset download_count — populated via GitHub
REST on load, formatted with k/M suffix, tabular-nums to avoid
layout shift on update.
- Install one-liners tokenized (cmd / flag / url / op / arg) with
per-token coloring; URL gets a desaturated slate (--code-url) so
it reads as classified without stealing attention.
- Copy button two-tier: Clipboard API in secure contexts, hidden-
textarea + execCommand fallback for plain-http LAN access. The
earlier single-tier silently failed on the dev server's LAN IP.
Copied / failed states colored.
- Patches grid grows a fourth section (Routing) for the v1.1.1
`claude update` redirect; four How-it-works cards summarize
Extract → Patch → Launch → Stay-current. Footer adds a
maintainer cell with @0chencc + GitHub/X icon links.
- Custom thin scrollbars (webkit + firefox) with green hover on
code blocks. prefers-reduced-motion respected.
CSS split across 7 partials (tokens / base / layout / hero /
sections / responsive / index) so future work can edit one role
without scrolling a 700-line monolith.
node_modules / dist / .vite cache gitignored. Dev server runs with
--host so phones on LAN can preview responsive layouts.
The Update section in README{,_ZH,_JP}.md still claimed cli.cjs's
drift detection would auto-re-patch on next launch — that block was
removed in v1.1.1. Rewrite the section to describe the actual flow:
running `claude update` triggers the patched redirect into
install.{sh,ps1}, which pulls @anthropic-ai/claude-code-<plat>@latest
from npm. The end result for the user is the same as a vanilla
upgrade — current Claude, with patches applied — in one command.
install.{sh,ps1}'s post-install footer mirrors that explanation so
users learn about the redirect at install time, not after they get
confused by `claude update` doing more than they expected.
For users who'd rather not take that on faith, expose the
latest-verified Claude version directly: compat-daily.yml now
force-pushes a {schemaVersion, label, message, color} JSON to a
dedicated `badges` branch after every successful run, and a
shields.io endpoint badge in all three READMEs reads it. The branch
holds nothing else and is never read as source — same posture as
published-by-CI badges in other public repos. Skipped on PRs (fork
PRs lack the token).
Three classes of bugs collapse into one fix:
1. `claude update` was actively destructive — its "unknown install
type" fallback overwrote ~/.bun/bin/bun on macOS (downgrading the
user's Bun and crashing cli.original.cjs with "Expected CommonJS
module to have a function wrapper") and wrote the new binary
outside our scan path on Windows ("Successfully updated" without
actually updating anything visible to clawgod). Patched to redirect
into clawgod's own install.{sh,ps1} as the single self-update path.
PowerShell 5.1 specifics handled inline: use `irm` not `iwr` (its
-useb mode returns byte[] for .Content, choking `iex`); read
HTTPS_PROXY/HTTP_PROXY from env explicitly and pass via `-Proxy`
(PS 5.1's iwr only reads IE settings, ignoring env); ship the
PowerShell payload via `-EncodedCommand` to bypass arg quoting.
2. Stale install sources removed:
- `~/.local/share/claude/versions/` and `Programs\claude-code` only
ever grow on a healthy clawgod install (`claude update` is now
patched out). Picking from them = pinning to whatever was
downloaded on first run, forever.
- `claude.orig` / `claude.orig.exe` backups are a frozen snapshot.
They exist for `--uninstall` to restore vanilla Claude, never as
a fresh install source.
Detection now always routes to npm-global → bun-global → npm-
registry, all of which carry actually-current versions.
3. cli.cjs's drift detection scanned the same stale `versions/` and
could only retract a fresher version install.{sh,ps1} just pulled
from npm registry, putting users into an infinite re-patch loop.
Removed entirely. The patched `claude update` → install.{sh,ps1}
redirect is now the single version-upgrade entry point.
install.{sh,ps1} now sanity-checks bun's ability to load
cli.original.cjs before writing the launcher and fails fast when the
user's Bun lags Anthropic's embedded canary (currently 1.3.14, while
bun.sh's stable still ships 1.3.13). The error message spells out
exactly which `bun upgrade --canary` path to take, including the
scoop case where the bun shim refuses self-replace.
release.yml gets `FORCE_JAVASCRIPT_ACTIONS_TO_NODE24` for parity with
compat-daily.yml — never run JS-based actions on Node 20 across our
workflows.
Fixes#51
Daily CI exposed a second set -e trap: under bash 5, `X=$(which foo)`
where `foo` isn't installed lets `which`'s exit code 1 carry through
the assignment and trips errexit. Switch both lookups (install path
and uninstall path) to `$(command -v claude 2>/dev/null || true)` —
POSIX builtin, robust on minimal images that no longer ship `which`,
and explicit about the miss being non-fatal.
While here, harden compat-daily.yml:
- Force JS-based actions onto Node 24 (FORCE_JAVASCRIPT_ACTIONS_TO_NODE24)
and align scripts via actions/setup-node@v4 — silences the deprecation
warning and keeps patch.mjs / extract-natives.mjs on the same runtime.
- Replace the curl-install + bun-upgrade dance with oven-sh/setup-bun@v2
(canary), which already caches the binary by commit hash.
- Cache ~/.npm so the ~80 MB claude-code-<plat> tarball is only re-fetched
on actual upstream bumps, not every run.
Under `set -e`, both fallback scan calls (npm-global, bun-global) sat
in positions where `scan_node_modules_root` returning 1 on a clean
miss was the final command of a `&&` list / then-block, so the script
exited before ever reaching the npm-registry fallback. The daily CI
run on a clean Linux runner caught this — locally it stayed hidden
because there was always a bun-global hit on the second scan.
Both calls now `|| true` and fall through to the npm-registry path.
Also drop the multi-OS matrix from compat-daily.yml. A Linux failure
is a near-certain proxy for cross-platform breakage upstream, and
macOS / Windows runner minutes cost 10x / 2x — not the right shape
for a daily scout.
Smoke-test install.sh end-to-end on Ubuntu (x64+arm) and macOS
(Intel+Apple Silicon) every morning. Asserts patch.mjs reports
"0 failed" and that `claude --version` boots without the Bun
CJS-wrapper panic surfaced by the v2.1.121 / Bun 1.3.14 upgrade.
Thanks @shadow1ng for the suggestion that a daily CI run is the
right shape to catch upstream Bun-version drift before users do.
Three shields.io badges at the top of each README, all linking to the
releases page. Latest pulls the most recent release tag, Released
shows its publish date, Downloads is the cumulative asset download
count across all releases.
Two issues hit Windows users who hadn't installed via the official
claude.ai/install.ps1:
1. The native binary search only looked at the official installer paths
(versions/, claude.orig.exe). Users who had previously run
`npm install -g @anthropic-ai/claude-code` had a perfectly good
binary on disk — at <npm root -g>/@anthropic-ai/claude-code/bin/
claude.exe, or at the per-platform package — but we ignored it and
forced them to run a separate official install. We now scan
`npm root -g` and `~/.bun/install/global/node_modules` before
reaching for the registry. The npm wrapper postinstall keeps the
filename as claude.exe on every OS (upstream quirk), so we look for
that exact name regardless of platform; the per-platform package's
binary is named per OS convention (claude on Unix, claude.exe on
Windows).
2. The registry fallback shelled out to `npm pack` + `tar`, then
silenced both with `2>$null`. On Windows a missing tar.exe (older
Win10 builds) or a `& npm` PowerShell shim quirk produced a flat
"Failed to download" with no diagnostic. The fallback is now an
inline Node script that hits registry.npmjs.org directly via
https.get, gunzips the tarball, and parses the POSIX tar header.
Errors propagate intact (HTTP status, network errors, parse errors)
so the failure message tells you what actually broke.
While here: the Unix-side scanner only looks at darwin-*/linux-*
platform packages (no win32 paths leaking into install.sh) and the
Windows-side scanner only looks at win32-* paths.
Refs #50 (the markers-missing extractor fix already shipped; this
addresses the follow-up "binary not found" path users hit after
clawgod located a binary that wasn't there).
Ultraplan
The previous regex required isEnabled:()=>!1 and a literal `description:`
field. Every Claude Code version since v2.1.92 has used a getter
(`get description(){...}`) and a function-call gate (e.g. ()=>la(),
()=>bc(), ()=>yn()). optional:true silently masked the miss across
~30 releases — Ultraplan has effectively never been patched until now.
New pattern matches both shapes and is no longer optional.
npm fallback (install.sh)
When ~/.local/share/claude/versions/ is empty, the installer now pulls
the platform-specific tarball (@anthropic-ai/claude-code-<platform>)
from the npm registry, extracts the binary into a tempdir, and reuses
it as the cli.js source. Users can install ClawGod without running
claude.ai/install.sh first. Drift detection still treats versions/ as
the canonical source; the tempdir is deleted after install.
Verified: v2.1.92 / v2.1.110 / v2.1.119 all 24 applied, 0 failed
(Ultraplan now genuinely enabled at runtime). End-to-end npm fallback
tested by hiding versions/ and confirming a fresh install pulls
v2.1.114 from npm and patches cleanly.
Refs #48 (closed instead of merging that PR — its Node runtime can't
execute the extracted cli.js because it depends on Bun.* APIs and on
`ws`, both of which Node lacks).
Closes#24
Pushing a tag matching v* now creates / updates a GitHub release with
install.sh and install.ps1 attached, plus auto-generated changelog
(commit log between prev and current tag) and standard install
snippets in the body. Idempotent: re-pushing a tag updates the
existing release rather than failing.
For routine patch releases this replaces the manual `gh release create`
flow. For larger releases that need a hand-written narrative, you can
still overwrite the body via `gh release edit` afterward.
Anthropic stopped shipping cli.js in the npm package starting v2.1.113;
the package became a thin loader that dispatches to a per-platform Bun
standalone binary. The previous installer cp'd cli.js from the npm
tarball, which is why every install on v2.1.113+ fails with ENOENT.
This release rewrites the install pipeline to extract cli.js source
directly from the user's locally-installed Bun standalone binary
(__BUN segment, anchored on the file:///$bunfs/.../cli.js path),
rewrites virtual /$bunfs paths to local vendor/, runs cli.js under Bun
runtime instead of Node, and reapplies the existing 23 regex patches.
Highlights
- Extract cli.js from Mach-O / ELF / PE __BUN segment (the same source
Bun bundled at build time — not stale, not injected).
- Auto-install Bun runtime; require ripgrep up front (Bun's bundled rg
is unreachable when running extracted cli.js outside the standalone
bundle, so we depend on system rg).
- Wrapper now stamps the source version and detects drift on every
launch. When the user upgrades Claude Code, ClawGod transparently
re-extracts and re-patches before invoking the user's command.
- Patcher made resilient: regex tokens widened to [\\w$]+ for Bun's
newer minified identifiers; updated message-list filter and
auto-mode patches for v2.1.119 source shape; sentinel-based
verification catches future silent regex misses.
- New `clawgod` command alongside `claude` — unambiguous entry point
that survives Windows .exe / .cmd shadowing and official
self-update overwriting `claude`.
- Critical fix: launcher write no longer follows symlinks. Previously
`echo > $CLAUDE_BIN` clobbered the real binary when $CLAUDE_BIN was
the official symlink to ~/.local/share/claude/versions/<v>; we now
rm the entry first.
- Default features.json adds tengu_prompt_cache_1h_config allowlist
so 1h prompt cache actually engages (fixes silent 5m TTL fallback
that drove cache_creation token waste).
Verified: macOS arm64 against v2.1.117/2.1.118/2.1.119 native binaries;
23 patches applied with 0 failures; auto-repatch correctly handles
version transitions; claude / clawgod / claude.orig coexist cleanly.
Closes#40Closes#41Closes#42Closes#43Closes#45
- Patcher now requires sentinel absence (not just 0 regex matches) to
declare a patch "already applied", catching the v2.1.110 regression
where filter regexes silently missed their targets and the patcher
still reported success.
- Attachment filter regex extended to match v2.1.92+ form
(fn()!=="ant"&&paY.has(...)); marked optional since paY is empty in
current versions, making the filter effectively a no-op.
- Message list filter split into legacy ternary and v2.1.92+ s_8
branches so both old and new source shapes patch cleanly.
- Unique check only fails on >1 matches; 0 matches now fall through to
sentinel verification instead of being reported as success.
- Added sentinels for USER_TYPE, CYBER_RISK_INSTRUCTION, URL
restriction, and cautious-actions patches.
Verified: v2.1.92 and v2.1.110 both patch clean (23 applied, 0 failed);
re-running on a patched file correctly reports "already applied" via
sentinel without false positives.
- Requirements now lists OAuth login OR an API key in
~/.clawgod/provider.json as valid startup paths, instead of
implying claude auth login is mandatory
- New Configuration / 配置 / 設定 section documents provider.json
fields (apiKey / baseURL / model / smallModel / timeoutMs) and
explains the two wrapper paths: forced env override + config
isolation when apiKey is set vs OAuth reuse of ~/.claude when
apiKey is empty, plus auto-injected ANTHROPIC_AUTH_TOKEN for
non-Anthropic baseURL gateways
- Applied identically to README.md, README_ZH.md, README_JP.md
Fixes#38Closes#38
- Launcher now prints a clean error + reinstall hint when
~/.clawgod/cli.js is missing, instead of the Node module loader
stack trace users see after deleting the install dir.
- Patcher drops the firstParty/anthropicAws gate in iG6 so
third-party API users can use auto-mode.
- Wrapper force-sets CLAUDE_CONFIG_DIR=~/.clawgod when provider.json
has an apiKey, preventing ~/.claude/settings.json from shadowing
base URL / model. OAuth users keep ~/.claude so subagents and
skills continue to work.
Closes#19Closes#23Closes#27Closes#31
Refs #22
Refs #29
Refs #30
- Embed extract-natives.mjs in install.sh/install.ps1 to pull
image-processor, audio-capture, computer-use-*, url-handler .node
modules out of the user's local Bun single-file binary
(Mach-O/ELF/PE), enabling Voice Mode / Computer Use on the npm build
- Add tengu_prompt_cache_1h_config allowlist ["*"] to default
features.json so IuY() grants 1h TTL; previously empty allowlist
silently downgraded all requests to 5m cache, causing heavy
cache_creation token burn after short idle periods
- Fix: grep whole file instead of head -1 when checking if claude
is a ClawGod launcher (head -1 only reads #!/bin/bash, never
matches "clawgod" which is on line 2)
- Add: Computer Use gate bypass (bypass GrowthBook override)
- Add: Voice Mode enable (bypass GrowthBook kill switch)
- Add: tengu_malort_pedway and tengu_amber_quartz_disabled to
default features.json
Fixes#20