CCCC v0.4.40 Release Notes
CCCC v0.4.40 introduces CCCC Connect, workspace file browsing and editing, and a
clearer, steadier Web workbench. It also improves Actor/Profile configuration,
runtime recovery and Voice diagnostics.
Connect supports instances under one account, selected Groups belonging to
different members, and Direct Group connections without an account. Each
instance continues to own its Groups, files, Actors and history. Local CCCC use
does not require an account.
One Account, Multiple Instances
Link each instance to the same CCCC account in Settings → Account. Background
discovery and communication follow that account binding; there is no Network to
create or pair of Groups to configure. Link only instances whose Groups may
communicate with every other instance on the account.
Each instance needs a reachable HTTPS Web address. Remote Access, previously
called Reach, provides the managed tunnel route. Linking an account and seeing an
instance in the directory do not by themselves prove that its tunnel is online.
Account settings distinguish directory confirmation, route availability, and
tunnel status.
Local account linking automatically prepares administrator access, preserving
existing credentials. Verified localhost setup no longer asks users to copy a
bootstrap code; remote first setup still requires host proof. Instance names can
be edited in Account settings, using the same name as the website device list.
Newly linked instances use the machine hostname as an initial name when available.
The sidebar labels the current instance and nests Groups under their instance;
message sources show the originating instance, Group, and Actor. Existing names
and historical messages are preserved.
Open Remote Groups in the Workbench
When the current Web session has administrator access, other account instances
appear in the sidebar. Choose an instance and enter that instance's own
administrator Access Token. The entry instance's Token does not unlock another
instance, and account membership does not grant browser administration rights.
A restricted Token keeps the browser in a single-instance view without changing
the account's background collaboration grant.
Remote Groups use the target instance's native Web interface, including messages,
interactive terminals, uploads, downloads, and Presentation. Only the active
remote instance remains connected. Previously opened Group lists stay available
in the sidebar, with independent collapse controls. Opening a cached Group
rechecks access and can reuse its valid login in the same entry-site partition.
Embedded views require distinct HTTPS hostnames and browser support for
partitioned cookies. Different ports on the same hostname are insufficient.
Open microphone features in the target's standalone page. Browser Token
revocation closes the affected access without stopping Actors or background
collaboration.
Embedded event streams, terminals, and Presentation connections also expire
with their embedding authorization or device binding, even if the target Token
is still valid. The server enforces this independently of page cleanup.
Connect a Group with Another Member
Open Group connections in the current Group’s settings or sidebar ⋮ menu
to invite another member using their Member ID. Each member selects their own Group and confirms on the
account website. Both Groups can discover Actors and exchange messages, replies
and files; the connection does not grant remote administration, terminals or
full history. A Group can have multiple connections without granting access to
its other Groups or automatically forwarding messages between connections.
Either member can disconnect. Repeated approvals converge to one connection;
device retirement and Group replacement invalidate old authority, and reconnecting
never revives old queued work. This flow requires the compatible account Worker
and its additive 0011 database migration.
Direct Group Connections Without an Account
Use Group connections → Direct connection to connect two selected Groups
over a reachable LAN, VPN or existing network route. One instance accepts incoming
connections; the other can join without opening an inbound port. Exchange a
short-lived invitation through a trusted channel, then explicitly approve the
requesting Group. Management Web interfaces can stay on localhost.
Direct connections use the same durable messages, replies, small files and receipts
as account connections. They do not share administrator Tokens or grant terminals,
workspace browsing, full history or arbitrary tools. Pairing and accepted messages
survive restarts. Either administrator can disconnect; an offline Direct route
does not silently fall back to an account connection. CCCC does not provide a
relay or change firewall/router settings.
Selecting a connected #Group in the composer preserves its instance and Group
identity, including through saved drafts and late Voice dictation. The reference
helps local Agents use the correct destination; typing it does not itself send a
remote message or grant access. Connected Actor names are available through @.
Workspace Files, Documents and Git
The Files sidebar browses the Group's active workspace, with path lookup,
directory navigation, Git status and change inspection. Desktop users can edit
text files and manage files and folders; phone layouts provide read-only browsing.
Unsaved edits survive file navigation, and saving checks whether the file changed
on disk before overwriting it.
Source files such as .ts open as text rather than being mistaken for video.
Document and media previews use the appropriate reader. Downloads preserve
non-ASCII filenames, including Chinese and Japanese names.
See the Web UI guide for file operations and access boundaries.
Steadier Readers and Terminals
Files and Presentation share a resizable sidebar with consistent headers and controls.
Each Group remembers its width and Presentation density. Drag inward or use the collapse
button to keep four compact slots visible; expand for image, text and table previews.
Previews do not mark updates as read or start interactive viewers. Files keeps its usable
width and unsaved edits when switching panels; phones retain a full-screen surface.
Workspace-linked PDF and HTML readers reload on an explicit Refresh or a new
publication, so background checks no longer repeatedly flash or reset the reader.
Image and Markdown refreshes keep the last loaded content during temporary
failures and show when it is stale; missing resources or lost permission clear it.
Terminal paging and Group switching retain up to 32 hidden terminals for five
minutes, including their connections and scrollback. Hidden terminals cannot
send input or resize the runtime; the active writer synchronizes its dimensions
when shown again. Larger paging targets and swiping the Actor title area improve
navigation without taking over terminal-body gestures.
Durable Cross-Instance Messages
Actors use cccc_connect to discover eligible instances and their Groups and
Actors. cccc_message_send and small-file sends accept an explicit destination
instance and Group. Replies use the received local Event ID to return to the
original sender.
Accepted outgoing messages persist across restarts. Retries retain the original
delivery identity, preventing a retry from creating another received message.
Offline or slow peers do not block healthy peers. Delivery and storage limits
produce explicit failure or unconfirmed outcomes instead of waiting indefinitely.
Queued means the source accepted responsibility for delivery; sent means the
target Group confirmed receipt. Neither means an Actor has completed the task.
Cancelling a request to reply closes its reply obligation without retracting the
message or stopping the receiving Actor.
Remote replies update the original request's status as they arrive, including
when browsing history. Replies are matched to the original remote instance,
Actor, and generation; a local Actor with the same name cannot fulfill them.
Manual Group Bridge Is Retired
The old manual Group Bridge configuration, pairing routes, remote tool sessions,
and dedicated MCP tools are removed. They are not silently converted into
Connect grants. Ordinary cross-Group communication within one instance remains.
On upgrade, old pending Bridge operations receive retirement outcomes before
their dedicated state and credentials are cleaned up. Historical messages remain
readable; actions requiring the retired connection are disabled. Downgrading the
executable alone does not restore retired Bridge connections.
Automatic Web updates and cross-instance Voice integration are not included
in this release.
Mattermost IM Connector
Connect a Group to Mattermost from its Settings → IM Bridge tab using a
dedicated Bot Token and site URL. The native connector supports channel and
thread authorization, attachments, streaming replies, and processing reactions
through outbound REST and WebSocket connections. No public callback or extra
service is required.
Use a separate Bot for each Group. Authorized chats share that Group's context;
a private chat is not a separate confidential session. See the
Mattermost setup guide for setup and recovery
boundaries.
Clearer Account and Content Navigation
Account linkage is shown separately from tunnel connectivity. Temporary directory
refresh failures retain navigation with an explicit status while authorization
expiry still blocks access. Group rows show explicit connection counts. Account
identity labels and return navigation depend on the account-service version; older
compatible services continue to support discovery and Group messaging.
Expanded images, Mermaid diagrams and Presentation imagery share fit-to-window,
actual-size, button/pinch zoom and drag panning, with native wheel scrolling,
keyboard navigation and modal focus restoration. PDF and interactive browser controls keep their native behavior.
Dark mode uses lighter charcoal surfaces, clearer boundaries and more visible
input outlines. Reading controls, message identities, recipients and actions
follow the text-size preference. Settings reduce redundant container nesting
while keeping scope, permissions and independent resources clear.
Search distinguishes an unsubmitted query, loading, no matches and errors. Settings
refreshes preserve edited fields and selections, with save feedback near the
operation. Project Context gives shared tasks and Agent reports clearer priority;
saved report freshness is distinct from live Runtime state.
Voice Secretary gives Doc, Ask and Prompt their own working space while preserving
document drafts. Activity links reveal the linked document without changing an
active recording's target. Expanded Prompt controls remain accessible on short
screens. Codex Voice settings use a bounded reading width and clearer empty states.
Actor, Profile and Runtime Reliability
Linked Actors can be renamed, switch Profiles and convert to Custom without
rejecting Actor-local capability settings. Profiles own their effective runtime
and environment; conversion snapshots that configuration and its private values.
Unchanged command arguments retain spaces, quotes and empty arguments. Saving a
draft as a Profile includes staged secret changes, and partial failures retry
against the same Profile instead of creating duplicates or accepting stale secrets.
Stopping and restarting follows the registered runtime even after configuration
changes. Failed cleanup remains visible and retryable; a surviving terminal cannot
make a disconnected managed session appear healthy. Managed Actors stop
concurrently during daemon shutdown, with bounded provider-stop confirmation and
owned-process cleanup.
Grok configures CCCC MCP through its native registry before launch, so CCCC startup
no longer depends on a stale inherited Claude MCP entry. Readiness checks include
the effective executable, arguments, Actor environment and native policy, catching
conflicting overrides or blocked registrations before starting the Actor. Grok's
general ability to read Claude configuration remains available.
Claude session recovery handles native Agent View bookkeeping and empty resumed
sessions more consistently. ChatGPT Web Model opens profiles for non-ASCII Actor
IDs and respects the instance-wide singleton across Profile changes and imports.
On Linux and Windows, interactive browser startup uses an explicit local debugging
port, matching macOS. Reopening sign-in does not reload it, and delivery waits for
sign-in or human verification instead of treating unrelated input fields as ready.
This does not bypass provider security checks or guarantee provider availability.
Codex Voice startup and disconnect failures now identify the affected stage or
connection with bounded diagnostics that exclude credentials and conversation
content. These changes improve diagnosis; they do not claim that every provider
or Windows background disconnect has been eliminated.
Build and Rollout Notes
Antigravity retains its native interactive terminal and automatic PTY delivery,
without a per-process Web confirmation step or footer-text matching. Complete
native login and workspace setup before sending tasks. PTY submission does not
prove that the model received or completed the task; previously accepted or
uncertain deliveries are not automatically replayed.
Antigravity configures and verifies CCCC MCP with native agy mcp add before
launch. A conflicting project entry or malformed config produces an explicit
setup error. The first task keeps the full bootstrap, with a brief delay before
its payload is written to avoid the observed initialization race. Later tasks
retain a conditional initialization reminder. This remains best-effort native
PTY delivery, rather than a provider acknowledgement protocol.
Extracted installations supply the owning CCCC launcher on Actor PATH; the
shared MCP registration inherits each instance's own Actor environment.
Antigravity startup preparation also disables its native feedback survey through
showFeedbackSurvey in user settings, because the rating prompt can consume
automatically delivered terminal input. Other preferences are preserved. This
also disables surveys in standalone AGY sessions for that user; it does not
turn a PTY write into a model receipt.
The Web build script now resolves the invoking package directory at runtime.
Reusing a compiled build script across source checkouts no longer sends generated
Web assets into a different checkout.
Build diagnostics distinguish the CLI, daemon and Web bundle actually in use.
Source fingerprints include compiled resources; debug Web builds report the files
they serve from disk, while packaged builds report their embedded bundle. This
helps identify stale binaries or tabs without confusing source identity with a
binary checksum.
Deploy the compatible account-service update and its additive database migration
before distributing Connect clients. Connect registration and discovery require
CCCC 0.4.40 or later. Existing account and Remote Access routes retain their
previous version policy until the operator explicitly enables the common client
minimum. Raise that minimum only after upgrade instructions and client artifacts
are available.
Validation includes the Rust and Web regression suites, isolated browser workflows,
the Linux package and installer, and native Windows lifecycle smoke tests in CI.
An isolated upgrade using the published 0.4.39 Linux binary preserves history,
unread mail, Profiles and private configuration through a second restart; pending
Bridge work receives its retirement outcome once.
Native Windows/macOS release-package acceptance and real OAuth, provider Voice,
public-tunnel and cross-network journeys are not established by those local tests.
See the Connect guide for setup and access boundaries.