CCCC v0.4.40 Release Notes
CCCC v0.4.40 introduces CCCC Connect, workspace file browsing and editing, and a clearer, steadier Web workbench. It also improves Actor/Profile configuration, runtime recovery and Voice diagnostics.
Connect supports instances under one account, selected Groups belonging to different members, and Direct Group connections without an account. Each instance continues to own its Groups, files, Actors and history. Local CCCC use does not require an account.
One Account, Multiple Instances
Link each instance to the same CCCC account in Settings → Account. Background discovery and communication follow that account binding; there is no Network to create or pair of Groups to configure. Link only instances whose Groups may communicate with every other instance on the account.
Each instance needs a reachable HTTPS Web address. Remote Access, previously called Reach, provides the managed tunnel route. Linking an account and seeing an instance in the directory do not by themselves prove that its tunnel is online. Account settings distinguish directory confirmation, route availability, and tunnel status.
Local account linking automatically prepares administrator access, preserving existing credentials. Verified localhost setup no longer asks users to copy a bootstrap code; remote first setup still requires host proof. Instance names can be edited in Account settings, using the same name as the website device list. Newly linked instances use the machine hostname as an initial name when available. The sidebar labels the current instance and nests Groups under their instance; message sources show the originating instance, Group, and Actor. Existing names and historical messages are preserved.
Open Remote Groups in the Workbench
When the current Web session has administrator access, other account instances appear in the sidebar. Choose an instance and enter that instance's own administrator Access Token. The entry instance's Token does not unlock another instance, and account membership does not grant browser administration rights. A restricted Token keeps the browser in a single-instance view without changing the account's background collaboration grant.
Remote Groups use the target instance's native Web interface, including messages, interactive terminals, uploads, downloads, and Presentation. Only the active remote instance remains connected. Previously opened Group lists stay available in the sidebar, with independent collapse controls. Opening a cached Group rechecks access and can reuse its valid login in the same entry-site partition.
Embedded views require distinct HTTPS hostnames and browser support for partitioned cookies. Different ports on the same hostname are insufficient. Open microphone features in the target's standalone page. Browser Token revocation closes the affected access without stopping Actors or background collaboration.
Embedded event streams, terminals, and Presentation connections also expire with their embedding authorization or device binding, even if the target Token is still valid. The server enforces this independently of page cleanup.
Connect a Group with Another Member
Open Group connections in the current Group’s settings or sidebar ⋮ menu to invite another member using their Member ID. Each member selects their own Group and confirms on the account website. Both Groups can discover Actors and exchange messages, replies and files; the connection does not grant remote administration, terminals or full history. A Group can have multiple connections without granting access to its other Groups or automatically forwarding messages between connections.
Either member can disconnect. Repeated approvals converge to one connection; device retirement and Group replacement invalidate old authority, and reconnecting never revives old queued work. This flow requires the compatible account Worker and its additive 0011 database migration.
Direct Group Connections Without an Account
Use Group connections → Direct connection to connect two selected Groups over a reachable LAN, VPN or existing network route. One instance accepts incoming connections; the other can join without opening an inbound port. Exchange a short-lived invitation through a trusted channel, then explicitly approve the requesting Group. Management Web interfaces can stay on localhost.
Direct connections use the same durable messages, replies, small files and receipts as account connections. They do not share administrator Tokens or grant terminals, workspace browsing, full history or arbitrary tools. Pairing and accepted messages survive restarts. Either administrator can disconnect; an offline Direct route does not silently fall back to an account connection. CCCC does not provide a relay or change firewall/router settings.
Selecting a connected #Group in the composer preserves its instance and Group identity, including through saved drafts and late Voice dictation. The reference helps local Agents use the correct destination; typing it does not itself send a remote message or grant access. Connected Actor names are available through @.
Workspace Files, Documents and Git
The Files sidebar browses the Group's active workspace, with path lookup, directory navigation, Git status and change inspection. Desktop users can edit text files and manage files and folders; phone layouts provide read-only browsing. Unsaved edits survive file navigation, and saving checks whether the file changed on disk before overwriting it.
Source files such as .ts open as text rather than being mistaken for video. Document and media previews use the appropriate reader. Downloads preserve non-ASCII filenames, including Chinese and Japanese names.
See the Web UI guide for file operations and access boundaries.
Steadier Readers and Terminals
Files and Presentation share a resizable sidebar with consistent headers and controls. Each Group remembers its width and Presentation density. Drag inward or use the collapse button to keep four compact slots visible; expand for image, text and table previews. Previews do not mark updates as read or start interactive viewers. Files keeps its usable width and unsaved edits when switching panels; phones retain a full-screen surface.
Workspace-linked PDF and HTML readers reload on an explicit Refresh or a new publication, so background checks no longer repeatedly flash or reset the reader. Image and Markdown refreshes keep the last loaded content during temporary failures and show when it is stale; missing resources or lost permission clear it.
Terminal paging and Group switching retain up to 32 hidden terminals for five minutes, including their connections and scrollback. Hidden terminals cannot send input or resize the runtime; the active writer synchronizes its dimensions when shown again. Larger paging targets and swiping the Actor title area improve navigation without taking over terminal-body gestures.
Durable Cross-Instance Messages
Actors use cccc_connect to discover eligible instances and their Groups and Actors. cccc_message_send and small-file sends accept an explicit destination instance and Group. Replies use the received local Event ID to return to the original sender.
Accepted outgoing messages persist across restarts. Retries retain the original delivery identity, preventing a retry from creating another received message. Offline or slow peers do not block healthy peers. Delivery and storage limits produce explicit failure or unconfirmed outcomes instead of waiting indefinitely.
Queued means the source accepted responsibility for delivery; sent means the target Group confirmed receipt. Neither means an Actor has completed the task. Cancelling a request to reply closes its reply obligation without retracting the message or stopping the receiving Actor.
Remote replies update the original request's status as they arrive, including when browsing history. Replies are matched to the original remote instance, Actor, and generation; a local Actor with the same name cannot fulfill them.
Manual Group Bridge Is Retired
The old manual Group Bridge configuration, pairing routes, remote tool sessions, and dedicated MCP tools are removed. They are not silently converted into Connect grants. Ordinary cross-Group communication within one instance remains.
On upgrade, old pending Bridge operations receive retirement outcomes before their dedicated state and credentials are cleaned up. Historical messages remain readable; actions requiring the retired connection are disabled. Downgrading the executable alone does not restore retired Bridge connections.
Automatic Web updates and cross-instance Voice integration are not included in this release.
Mattermost IM Connector
Connect a Group to Mattermost from its Settings → IM Bridge tab using a dedicated Bot Token and site URL. The native connector supports channel and thread authorization, attachments, streaming replies, and processing reactions through outbound REST and WebSocket connections. No public callback or extra service is required.
Use a separate Bot for each Group. Authorized chats share that Group's context; a private chat is not a separate confidential session. See the Mattermost setup guide for setup and recovery boundaries.
Clearer Account and Content Navigation
Account linkage is shown separately from tunnel connectivity. Temporary directory refresh failures retain navigation with an explicit status while authorization expiry still blocks access. Group rows show explicit connection counts. Account identity labels and return navigation depend on the account-service version; older compatible services continue to support discovery and Group messaging.
Expanded images, Mermaid diagrams and Presentation imagery share fit-to-window, actual-size, button/pinch zoom and drag panning, with native wheel scrolling, keyboard navigation and modal focus restoration. PDF and interactive browser controls keep their native behavior.
Dark mode uses lighter charcoal surfaces, clearer boundaries and more visible input outlines. Reading controls, message identities, recipients and actions follow the text-size preference. Settings reduce redundant container nesting while keeping scope, permissions and independent resources clear.
Search distinguishes an unsubmitted query, loading, no matches and errors. Settings refreshes preserve edited fields and selections, with save feedback near the operation. Project Context gives shared tasks and Agent reports clearer priority; saved report freshness is distinct from live Runtime state.
Voice Secretary gives Doc, Ask and Prompt their own working space while preserving document drafts. Activity links reveal the linked document without changing an active recording's target. Expanded Prompt controls remain accessible on short screens. Codex Voice settings use a bounded reading width and clearer empty states.
Actor, Profile and Runtime Reliability
Linked Actors can be renamed, switch Profiles and convert to Custom without rejecting Actor-local capability settings. Profiles own their effective runtime and environment; conversion snapshots that configuration and its private values. Unchanged command arguments retain spaces, quotes and empty arguments. Saving a draft as a Profile includes staged secret changes, and partial failures retry against the same Profile instead of creating duplicates or accepting stale secrets.
Stopping and restarting follows the registered runtime even after configuration changes. Failed cleanup remains visible and retryable; a surviving terminal cannot make a disconnected managed session appear healthy. Managed Actors stop concurrently during daemon shutdown, with bounded provider-stop confirmation and owned-process cleanup.
Grok configures CCCC MCP through its native registry before launch, so CCCC startup no longer depends on a stale inherited Claude MCP entry. Readiness checks include the effective executable, arguments, Actor environment and native policy, catching conflicting overrides or blocked registrations before starting the Actor. Grok's general ability to read Claude configuration remains available.
Claude session recovery handles native Agent View bookkeeping and empty resumed sessions more consistently. ChatGPT Web Model opens profiles for non-ASCII Actor IDs and respects the instance-wide singleton across Profile changes and imports. On Linux and Windows, interactive browser startup uses an explicit local debugging port, matching macOS. Reopening sign-in does not reload it, and delivery waits for sign-in or human verification instead of treating unrelated input fields as ready. This does not bypass provider security checks or guarantee provider availability.
Codex Voice startup and disconnect failures now identify the affected stage or connection with bounded diagnostics that exclude credentials and conversation content. These changes improve diagnosis; they do not claim that every provider or Windows background disconnect has been eliminated.
Build and Rollout Notes
Antigravity retains its native interactive terminal and automatic PTY delivery, without a per-process Web confirmation step or footer-text matching. Complete native login and workspace setup before sending tasks. PTY submission does not prove that the model received or completed the task; previously accepted or uncertain deliveries are not automatically replayed. Antigravity configures and verifies CCCC MCP with native agy mcp add before launch. A conflicting project entry or malformed config produces an explicit setup error. The first task keeps the full bootstrap, with a brief delay before its payload is written to avoid the observed initialization race. Later tasks retain a conditional initialization reminder. This remains best-effort native PTY delivery, rather than a provider acknowledgement protocol. Extracted installations supply the owning CCCC launcher on Actor PATH; the shared MCP registration inherits each instance's own Actor environment.
Antigravity startup preparation also disables its native feedback survey through showFeedbackSurvey in user settings, because the rating prompt can consume automatically delivered terminal input. Other preferences are preserved. This also disables surveys in standalone AGY sessions for that user; it does not turn a PTY write into a model receipt.
The Web build script now resolves the invoking package directory at runtime. Reusing a compiled build script across source checkouts no longer sends generated Web assets into a different checkout.
Build diagnostics distinguish the CLI, daemon and Web bundle actually in use. Source fingerprints include compiled resources; debug Web builds report the files they serve from disk, while packaged builds report their embedded bundle. This helps identify stale binaries or tabs without confusing source identity with a binary checksum.
Deploy the compatible account-service update and its additive database migration before distributing Connect clients. Connect registration and discovery require CCCC 0.4.40 or later. Existing account and Remote Access routes retain their previous version policy until the operator explicitly enables the common client minimum. Raise that minimum only after upgrade instructions and client artifacts are available.
Validation includes the Rust and Web regression suites, isolated browser workflows, the Linux package and installer, and native Windows lifecycle smoke tests in CI. An isolated upgrade using the published 0.4.39 Linux binary preserves history, unread mail, Profiles and private configuration through a second restart; pending Bridge work receives its retirement outcome once.
Native Windows/macOS release-package acceptance and real OAuth, provider Voice, public-tunnel and cross-network journeys are not established by those local tests.
See the Connect guide for setup and access boundaries.