Claude Code reads ANTHROPIC_DEFAULT_MODEL as its lowest-priority startup
model (after --model, ANTHROPIC_MODEL and the settings `model` field). It is
a plain model id, so behind a proxy a bare value is clamped to 200k exactly
like the tier keys. Add it to EXTRA_EXTENDED_CONTEXT_MODEL_ENV_KEYS so
--1m/--no-1m and the saved preference toggle it with the rest.
The `--settings` launch overlay only carried the routing keys plus the five
Anthropic tier keys. Claude Code applies the settings `env` block on top of
the process environment, so a bare CLAUDE_CODE_SUBAGENT_MODEL or
ANTHROPIC_DEFAULT_MODEL persisted on disk silently undid the resolved
--1m result (and a saved [1m] undid --no-1m). Overlay the extended-context
extra keys too.
Verified with a stub Claude binary reading the overlay file:
ccs claude --no-1m -> ANTHROPIC_DEFAULT_MODEL=claude-opus-5, CLAUDE_CODE_SUBAGENT_MODEL=claude-sonnet-5
ccs claude --1m -> both keys suffixed with [1m]
The previous commit assumed Claude Code's fable resolver strips [1m] and
therefore never wrote the suffix into ANTHROPIC_DEFAULT_FABLE_MODEL. That
premise only holds when ANTHROPIC_BASE_URL is unset or points at
api.anthropic.com. Behind a proxy (CLIProxy, headroom, ...) Claude Code
2.1.259 does the opposite:
- the fable alias resolver passes the env value through untouched, so a
saved `claude-fable-5-1[1m]` reaches the model picker as-is;
- the context-window resolver grants 1M unconditionally when the model id
carries [1m], and otherwise trusts a natively-1M model only when the base
URL is first-party. Bare `claude-fable-5-1` via 127.0.0.1 is clamped to
200k even though CLIProxy's /v1/models advertises max_input_tokens 1M.
So the suffix is the only thing that turns the long window on for CCS, and
stripping it from the Fable key is what kept `ccs claude --model fable` at
200k. A headroom settings profile with the suffix saved on that key showed
the 1M window in the same Claude Code build, which is how the inversion was
caught.
Changes:
- Drop the suffix-stripping key guard; ANTHROPIC_DEFAULT_FABLE_MODEL now
receives and keeps [1m] exactly like the opus/sonnet tiers.
- On a long-context launch (explicit --1m, or a saved [1m] on any Anthropic
tier key) fill a missing Fable tier with the catalog Fable model plus
[1m]. The model-neutral claude profile pins no Fable model, so `--model
fable` used to fall back to Claude Code's bare default and lose the window
even when every other tier asked for 1M. An explicit mapping always wins,
--no-1m never fills, and providers without a catalog Fable model are left
alone.
- Add getDefaultFableTierModel() to the model catalog for that default.
Verified with a stub Claude binary that dumps its environment:
ccs claude --model fable -> ANTHROPIC_DEFAULT_FABLE_MODEL=claude-fable-5-1[1m]
ccs claude --1m -> ANTHROPIC_DEFAULT_FABLE_MODEL=claude-fable-5-1[1m]
ccs claude --no-1m --model fable -> no Fable tier written, ANTHROPIC_MODEL stripped
Claude Code resolves ANTHROPIC_DEFAULT_FABLE_MODEL through a resolver that
strips the [1m] suffix before use, unlike the opus/sonnet resolvers which
pass their env value through untouched. The stripped value is then treated
as an env-supplied default and held to the standard 200k window instead of
the model's native 1M, so writing [1m] into that key costs the long context
window rather than granting it.
Measured against a Claude Code 2.1.259 session (`/context` on a live proxy
endpoint):
ANTHROPIC_MODEL=claude-fable-5-1[1m] -> 1m window
ANTHROPIC_MODEL=claude-fable-5-1 -> 200k window
ANTHROPIC_DEFAULT_FABLE_MODEL=claude-fable-5-1[1m] -> 200k window
The fix is key-scoped rather than model-scoped, since the suffix is what
grants 1M on every other key. Adds envKeyAcceptsExtendedContextSuffix() as
the single place recording which keys reject the suffix, enforces it as a
floor inside applyExtendedContextPreferenceToAnthropicModels() so no caller
can bypass it, and strips a previously saved suffix from that key on the
next launch through the auto path.
Also extends the preference to CLAUDE_CODE_SUBAGENT_MODEL. Subagent windows
come from the same resolver as the main loop (the Explore inheritCap bounds
the model tier, not the context window), so a bare subagent model id sits at
200k while the suffixed form gets 1M. The new key list is kept separate from
ANTHROPIC_MODEL_ENV_KEYS, which also drives routing, model-id normalization
and profile validation.
Claude-Session: https://claude.ai/code/session_01NPkafQjVf4pSwPBwBistGk
Register `claude-fable-5-1` in the CLIProxy model catalog, the dashboard
catalog, and the usage pricing registry.
Pricing is taken from Anthropic's official pricing page:
- Fable 5.1 base rates are $10/$50 per MTok with a $12.50 5m cache write,
matching Fable 5.
- Cache hits bill at 0.025x base input ($0.25/MTok) rather than the
standard 0.1x multiplier. Anthropic applies that reduced rate only to
Fable 5.1 and Mythos 5.1, so this entry cannot derive its cache rates
from CACHE_READ_MULTIPLIER.
This also corrects Claude Sonnet 5 from $3/$15 to $2/$10 (cache write
$2.50, cache read $0.20). The launch introductory rate became the
standard price and the increase scheduled for 2026-09-01 was cancelled,
so the previous entry over-reported Sonnet 5 usage cost by 50%.
Thinking on Fable 5.1 is always on and can only be steered through
effort levels, so the catalog entry exposes the same `low`..`max` level
surface as Fable 5 and Opus 5 instead of a manual token budget.
The GitHub Copilot catalog is deliberately left unchanged, since Copilot
availability for Fable 5.1 is not verified; surfacing it there would
offer a model the backend may reject.
Regenerates docs/reports/hardening-inventory.{json,md} so the ci-parity
gate matches the source tree.
The code is this file's marker for "a race was detected" - the same one
the reappeared-path and concurrent-replacement guards raise - not a
report that a no-replace link() or open('wx') hit an existing path. Say
so at the throw, so debugging by err.code does not send anyone looking
for a no-replace failure that never happened.
Built [OnSteroids](https://onsteroids.ai)
createFileNoReplace and publishCanonicalContent carried the same
open-wx / fchmod / write / fsync / close block and the same cleanup
handler. Extract writeDurableTempFile and discardTempFile so each
publisher is left with only what distinguishes it: a no-replace link, or
the compare-and-swap guard and the rename.
Also spell out in publishCanonicalContent that its guard is read-then-act
rather than atomic. POSIX has no compare-and-swap rename, so the window
is narrowed from the ~100 ms the old claim-and-republish path left open
to two adjacent syscalls, not closed - and the pre-image sidecar is what
keeps that last outcome recoverable. Worth stating so the guard is not
mistaken for a strict guarantee later.
Built [OnSteroids](https://onsteroids.ai)
Build the canonical identity from the stat getCanonicalFile already
takes, instead of a second lstat of the same inode. One syscall less,
and mode, mtime and identity now describe the same moment rather than
two adjacent ones.
Assert in the adoption race tests that the foreign writer never fired.
It writes only when the canonical path is observed empty, so a zero
count states the invariant the fix establishes - the path is never left
without a regular file - instead of only checking the final content.
Built [OnSteroids](https://onsteroids.ai)
Adoption moved the canonical settings.json aside with rename() and left
the path empty until publication, roughly 100 ms later. Claude Code or a
second `ccs` starting inside that window found no file and seeded an
empty placeholder; publication then failed with EEXIST because link() is
no-replace, and the rollback published a backup and unlinked the claim,
destroying the only remaining copy of the user's settings. Recovering
meant digging through sidecar files by hand.
Publish by replacement instead: write a temp file next to the canonical
inode and rename() it over the target, so the path always holds a regular
file and no placeholder can be seeded. A compare-and-swap guard on
(ino, mtime, size) runs immediately before the rename and refuses to
publish when the canonical inode changed since it was read, so a writer
that got there first is still never clobbered. The pre-image backup is
published before the replacement, keeping the old content recoverable if
publication is interrupted.
Drops the canonical claim entirely along with restoreCanonicalClaim, and
folds the two identical sidecar publishers into one helper.
recoverOrphanedCanonicalClaim stays, since claims written by older
versions may still be on disk.
New tests cover both writers seen in the incident: Claude Code seeding
`{}` with a trailing newline, and a second `ccs` seeding the 2-byte
variant from shared-dir-linker. Four tests that pinned the claim-based
design were rewritten, among them `preserves a canonical write that
lands during no-replace publication`, whose intent is now enforced by
the CAS guard instead of by an EEXIST from a no-replace link.
Built [OnSteroids](https://onsteroids.ai)
ProxyStatusWidget sits outside the sidebar ScrollArea, so every row it
renders is taken from the provider list. With the proxy running and pool
routing on it renders ten stacked blocks, and the only Collapsible covers
version management, which is already closed in that state.
Add a chevron that collapses the whole widget in local and remote mode,
keeping the status row, version row and action buttons visible. The
preference is stored in localStorage and defaults to expanded, so
existing setups are unchanged. Opening version settings from a collapsed
widget expands it again.