CCCC v0.4.39 Release Notes
CCCC v0.4.39 improves restart recovery, remote access, and responsiveness in Groups with substantial history. It also strengthens task permissions, storage error handling, and cancellation across the Rust runtime and its Web and MCP interfaces.
Remote Access That Is Easier to Set Up and Restore
Reach setup in Settings → Web Access now separates three steps: linking this installation to your CCCC account, enabling its tunnel, and signing a browser into the device. Linking an account reserves an address; it does not make that address reachable until remote access is turned on.
The panel distinguishes a connected tunnel from one that is starting, disconnected, or awaiting confirmation. Connection checks are limited and show when the status was observed. A successful manual refresh clears an earlier confirmation warning. Turning remote access off remains available during connection problems, and the CLI presents the remote address only after the tunnel is confirmed connected.
Open Web and Copy admin sign-in link now work from passwordless localhost administration by reusing an existing Admin Access Token for the one-time sign-in exchange. They do not create another long-lived credential. Website account login and device access remain separate; revoking the backing token also invalidates outstanding links.
Previously enabled Reach now restores after CCCC restarts, once the local Web listener is ready. Recovery uses the installed helper and retries temporary account failures with bounded waits. Turning Reach off, unlinking the account, or shutting down prevents a late response from reopening the tunnel. Existing running helpers keep handling their own reconnection.
Manual HTTP access on a trusted LAN no longer requires an extra environment override; remote APIs still require an Admin Access Token. Public access should use HTTPS through a tunnel or reverse proxy.
Cookie-authenticated WebSockets retain source validation, including behind a reverse proxy. Explicit Bearer-authenticated WebSocket clients may connect without an Origin match, while token and Group permissions remain enforced.
A connected tunnel is connection evidence, not an end-to-end application check. Open Web from another network to verify remote access. See the Web UI guide for the setup and authentication flow.
Cloud Speech Recognition and Voice Workspace Improvements
Voice Secretary can use Bailian or Volcengine realtime ASR without installing local recognition models. Administrators configure provider credentials on the CCCC host; Group settings select the provider without exposing those credentials. Connection checks report provider access errors without returning private response bodies.
Cloud recording reuses the existing recording lease and transcript workflow. Live subtitles continue while document checkpoints follow the configured update interval or stop-only setting. Unconfirmed checkpoints retain their original IDs and must be recovered before a final revision is saved, including available segments from incomplete recordings. Failed browser retries return the remaining text to the originating composer for review. Separate recording sessions keep their own transcript identities. Recognized text recovered from a failed non-document recording returns to the originating composer for review.
Recognition selections now save automatically, with failed saves shown and rolled back in the panel. Saving settings does not restart a stopped Voice Secretary; enabling it remains an explicit action. Provider credentials retain separate Save and Clear controls. See the Voice Secretary guide.
Voice Secretary startup now recognizes managed Claude, Codex, Grok, OpenCode, and Kilo sessions instead of incorrectly stopping them after launch. Re-enabling a stopped secretary also restores its Actor's enabled state. Startup checks and the displayed running state follow the runtime owner's actual liveness.
On phones, Voice Secretary keeps its recording controls accessible while the activity feed and document content scroll independently. Desktop composers gain a draggable, keyboard-accessible height control that works even for empty drafts. Manual sizing stays in place while typing or clearing the input; double-click or Enter restores compact automatic sizing. Appearance menus preserve their containing settings panel, and Group import includes a directory picker that ignores stale responses.
More Reliable Actor Startup and Shutdown
Grok Build Actors restored after a CCCC restart now remain connected when the startup worker finishes. The same fix covers manual Actor startup, preserving the managed session after its request worker exits.
Managed Codex Actors and Voice Analyst disable Codex's startup update check by default, avoiding an update prompt during launch. An explicit -c check_for_update_on_startup=true override is still honored, and CCCC does not rewrite the user's global Codex configuration.
Codex Actor and Voice Analyst terminals also stop passing approval and sandbox overrides when attaching to the managed app-server. This avoids remote-resume permission conflicts while keeping execution policy on the server and attaching the terminal to the existing session.
A known configuration limitation remains with Codex CLI 0.154.0: -m / --model can leave managed sessions on their default model. The command form codex -c 'model="YOUR_MODEL_ID"' selected the requested model in isolated session tests; changing an Actor's launch configuration requires restarting that Actor. This does not verify account access to the model. Search, OSS-provider and native Profile flags also have limitations on this backend entry point. This release does not resolve those configuration differences.
Running Claude Actors and Voice Analyst can follow a transcript moved within the configured Claude project store. CCCC verifies the same session and the complete consumed history before continuing from the retained offset. Missing or incomplete destinations receive a bounded grace period; ambiguous or changed history still fails explicitly without replaying old input.
Actor startup and Group Bridge session callbacks no longer stall behind queued global operations that depend on them completing. Actor status notifications also retry a transition after a temporary ledger write failure without repeating successfully recorded transitions.
On Linux, a terminal blocked by an Actor that has stopped reading input remains responsive to cancellation and writer revocation. Input queued for an old Actor session cannot spill into its replacement after a restart.
Less Work for Large Group Histories
Delivery, recovery, completion, and reminder checks reuse the history index and retain only the results they need, reducing full-history copies. Reminder checks skip history access when no Actor is eligible for a reminder.
History snapshots validate and hash events in a streaming pass without building a full query index. Evicting a large index no longer holds the global cache lock while its memory is freed, reducing interference with other Groups. Terminal stream ingestion also avoids re-serializing unrelated history when checking replayed events.
These changes retain the existing ledger and snapshot formats. Cold queries can still require loading history; this release does not make every operation independent of Group size.
Stronger History and Task Consistency
Concurrent history queries now preserve committed events through index rebuilds and delayed append callbacks. Daemon and Web event followers retain unseen events across ledger rotation and refill instead of silently advancing past them.
Context files that are malformed or unreadable now produce explicit errors rather than being treated as empty state and overwritten. Snapshot and compaction operations likewise reject unreadable event records before publishing integrity metadata or rotating files.
Task ownership checks use the state produced by each preceding operation in the same batch. Whitespace in IDs, newly created tasks, and relinquished ownership can no longer bypass those checks. An invalid or unauthorized batch is rejected before writing its changes.
For clients using Context operations, a storage I/O failure can still leave some files updated: per-file atomic writes are not a transaction across all files. Such a failure invalidates older version tokens. Reload the current state before deciding what to retry. See the Context contract.
MCP Tools and Runtime Setup
Advertised coordination decision/handoff actions and Group Space sync now reach their handlers. Context snapshots honor include_archived, and tool descriptions match their actual results.
Short shell, Git, patch, and runtime setup commands now share bounded input, output, and exit handling. Timeouts and cancellation clean up their owned processes, including when a pipe is blocked. Shell and Git results explicitly report truncated output; setup checks reject incomplete output. Tailscale start/stop and DeepSeek's Node version probe also have deadlines.
Use cccc_exec_command for persistent foreground work. Its sessions belong to the MCP host and are cleaned up when that host exits; this does not stop Actor/Analyst sessions or sessions owned by another host. Cancelling a command does not undo changes it has already made.
Hermes setup now respects an explicit Actor or Profile HERMES_HOME instead of overwriting it with the host default. Daemon concurrency policies live beside their handlers, reducing duplicated operation lists and keeping read operations from unnecessarily blocking unrelated work.
Voice Lifecycle Fixes
Stopping Codex Voice during setup prevents late startup work and playback. A call returned after cancellation is released without disturbing a newer call or the retained Analyst session.
Voice Secretary speaker-label completion now goes through the daemon's session and event boundary. Temporary failures and lost replies can be retried without duplicate completion events.
Codex Voice remains experimental. Delivery to Realtime does not guarantee complete spoken narration; this release does not claim to remove that provider limitation.
Clearer Update Checks
cccc update --check now queries the latest published channel version and shows the current executable, installation owner, platform requirements, and next step. Pip and unmanaged installations can check without gaining permission to use the standalone updater. Network failures report an unknown update status instead of implying the installation is current. Use --check --offline for local details without a network request. Neither check changes the installation or running services.
The upgrade FAQ also explains why an older Python updater can remain on 0.4.35, how to require a native release explicitly, and when to investigate platform support, a pip mirror, or conflicting commands on PATH.
Upgrade
Shut down the running CCCC application before replacing its executable. If the daemon was started separately, stop it with cccc daemon stop.
For a website-installer-owned command:
cccc update --check
cccc updateFor a pip-owned command:
python -m pip install -U "cccc-pair>=0.4.39"Keep the existing installation channel. Restart CCCC normally, then verify:
cccc --version
cccc doctor
cccc daemon statusThe restart fixes take effect in the updated process. Reach restoration requires an already linked account, enabled remote access, an Admin Access Token, and the installed tunnel helper; it does not enable a previously disabled tunnel or install a missing helper automatically.
Supported native platforms remain Linux x86-64, Apple Silicon macOS, and Windows x86-64. Intel Mac installations should remain on v0.4.37.