Skip to content

CCCC v0.4.41 Release Notes ​

CCCC v0.4.41 expands browser-based collaboration with multiple ChatGPT Actors and the new Grok Bot Web Model runtime. It also adds a Voice Secretary document library, native file handoff through MCP, and fixes for message routing, browser delivery, runtime startup and configuration recovery.

Upgrading an existing ChatGPT Web Model setup requires attention: replace the old Actor-specific connectors with one shared ChatGPT connector, then connect each Actor's conversation. Existing conversations and CCCC history are retained.

Multiple ChatGPT Actors, One Login and Connector ​

ChatGPT Actors now share one dedicated CCCC browser login and one authenticated MCP connector. Each Actor keeps its own persistent window and verified conversation; delivery does not depend on switching an active tab.

  • Configure shared login and the connector in Settings → Global → Web Model. Choose each Actor's conversation in that Actor's settings.
  • Starting an unpaired Actor automatically sends one setup message, verifies the returned receipt in that Actor's window, and then delivers queued tasks. No copied pairing code or preliminary pairing click is required. Any approval requested by ChatGPT remains under your control.
  • Normal restarts reuse verified bindings. Failed, cancelled or interrupted setup attempts expose an explicit retry instead of repeatedly sending setup messages.
  • Changing a conversation preserves the previous binding until verification succeeds. Opening the viewer no longer interrupts first-time pairing, including Actors created before generation identities were introduced.
  • Conversation routing uses the host's conversation metadata and the current Actor binding. Missing identity never falls back to another Actor. Connector setup also protects one-time credentials from stale reads and duplicate clicks.

See the ChatGPT Web Model guide for setup, metadata requirements and recovery.

Grok Bot Web Model ​

grok_web_model is CCCC's second browser-based Actor runtime. Grok Actors share a dedicated Grok login and one Grok MCP connector, separate from ChatGPT. Each Actor uses its own existing https://grok.com/bot/<UUID> URL and browser window. CCCC does not create Bots automatically.

Save the Bot URL and start the Actor. Grok does not need a pairing message: CCCC supplies an Actor routing credential with each delivered task, and Grok includes it in its CCCC tool calls. Nested code-mode calls inherit the validated Actor context. This is possession-based authority; sharing that credential grants the same Actor access and does not prove which Bot made a call.

Bot URLs belong to individual Actors, including Actors linked to a Runtime Profile. Changing the URL or retiring the binding invalidates the old credential; ordinary restarts preserve it. Group copies do not carry these credentials.

The Grok Bot guide includes setup, tool-discovery troubleshooting and the current validation limits.

Browser Delivery and Settings Recovery ​

This release addresses several distinct causes of stalled, misidentified or interrupted browser deliveries:

  • Submission requires evidence. Confirmation uses the current batch's exact marker in a user message. Older messages reappearing, assistant quotations or an emptied composer do not count as a successful send.
  • Manual sends can unblock later work. CCCC can recognize a staged message after you send it manually in the bound conversation. Check and resume is available beside unverified messages. Explicit continuation releases later work without replaying the uncertain batch.
  • Drafts and pending work stay protected. Text and attachment-only drafts are checked before navigation or replacement. Duplicate wake-ups retain one active worker per Actor, and unresolved completion state prevents replacing a binding underneath pending delivery.
  • Background windows use the verified Send control. Conversation, draft, receipt and button state are checked together before activation, without relying on native pointer delivery or adding blind repeat clicks.
  • Slow pages stay visible and closable. Login and Actor windows appear while the provider site is loading; task delivery separately waits for readiness. Closing the shared login window leaves Actor windows and saved login intact. Signing out still affects Actors sharing that login.
  • Browser ownership survives lifecycle changes. Stale page handles are skipped only after confirming that their targets disappeared. Closed-window state retires with the Actor generation. Cleanup reads only registered browser owners, and graceful VNC shutdown releases shared-memory resources across restarts.

Actor settings load the saved runtime through every entry point, including the conversation shortcut. Web Model editors hide unused CLI commands and environment fields while retaining notes, presets and capabilities.

You can edit settings while an Actor runs. Grok URL changes use the editor's single Save action; Save & apply confirms the stop/save/restart sequence. The URL field appears immediately when selecting Grok, works with linked Profiles, and aligns an existing idle window after saving. Failed steps retain the draft and track what was already saved, so retrying or restoring the previous runtime remains possible. A clean editor shows Done.

ChatGPT conversation changes remain explicit connection operations: they handle the pause in place and offer Start Actor after verification. Opening shared settings preserves the Actor draft, and modal keyboard focus stays contained during an in-flight operation.

A Voice Secretary Document Library ​

Voice documents can be organized in persistent folders, renamed, archived, previewed and restored. Folders expand into a tree; drag documents into or out of folders and reorder folders among unfiled documents. Touch dragging uses a long press, and menu actions provide an alternative to dragging. Renaming changes the display title without moving the Markdown file.

Archive retains the file. Delete permanently removes the Markdown file after confirmation; it is not another form of archive. Historical ledger and transcript records remain. Failed deletion rolls back file/index changes where possible, while stale saves, transcript writes and archive requests cannot revive a deleted document. A restore from another client becomes visible through normal refresh.

Document menus support keyboard activation, the default document uses a compact badge, and overlapping refreshes no longer leave content stuck on “Loading”. Library operations cannot update a different Group after navigation.

Live original transcription appears in the activity feed on wide screens and in Transcript on narrow screens. The recording outline follows microphone volume without re-rendering the composer on every audio frame. External ASR failures report bounded provider error codes, including quota categories, while keeping private provider error text out of the UI and logs.

Voice Analyst notifications have shorter repeated reminders while preserving source attribution and instruction boundaries. Embedded Voice calls can carry bounded application context, such as language and current subject, through Realtime and Analyst delegation. This context grants no additional tool access. Grok CLI managed sessions also handle long input without exhausting their admission buffer while awaiting completion.

Native Files and More Predictable MCP Tools ​

Local file reads now return original PNG, JPEG and WebP data as native MCP images, and PDF/PPTX files as embedded MCP resources for a compatible host's file reader. Direct reads, attachments and code mode preserve native results with bounded output; CCCC does not extract, render or convert these files locally. Host support determines which formats can actually be consumed.

  • cccc_file is read-only; cccc_file_send explicitly sends an attachment. Tool descriptions, permissions and errors distinguish these effects.
  • Shell and command sessions honor working directories, child environments, wait durations, hard deadlines and output budgets. Output is incremental, final pages remain readable after exit, and timeout/termination cleans up owned work.
  • Code-mode result deadlines return while nested tools continue; subsequent waits collect their results, and termination cancels pending work. Import-like text in strings, comments and templates is accepted without enabling Node module loading.
  • Repository inspection honors scope, filters, case, context, pagination and budgets, with explicit incomplete-result information. Read-only inspection rejects edits and does not follow directory symlinks.
  • File editing returns whole-file hashes for stale-write checks, validates batch replacements before writing, and preserves executable permissions. Patches support anchors, ordered hunks, EOF markers, moves and new directories while rejecting ambiguous matches and destination conflicts. mkdir honors exist_ok.
  • Nested management calls preserve their explicit target Actor while revalidating the caller, preventing an operation intended for another Actor from acting on the caller instead.

Workspace path restrictions and Actor identity are not an operating-system sandbox for shell or Git subprocesses. Existing host-user permissions still apply.

Everyday Workbench, Runtime and IM Fixes ​

  • Recipients stay selected. Normal recipients are remembered per Group for the current Web page session. Replies and temporary cross-Group destinations do not replace that selection. Late send responses cannot switch the active Group or erase a newer draft, and failed sends retain their original routing.
  • Conversation reading uses the available width. Long messages retain directional gutters, short messages keep their natural size, and resizing preserves reading position. Connection feedback shares the Group status dot.
  • Settings browsing stays passive. Tabs load on demand and preserve drafts; hidden Connect and Voice notification views pause display reads. Opening IM settings does not start a Weixin bridge. Successful QR login survives a bridge startup failure so it can be retried.
  • Managed startup is more reliable. Codex sub-agent thread events no longer stop the parent Actor. Claude can present workspace-trust approval through its terminal and resume startup after approval, including early approval and Windows USERPROFILE paths. Stop/removal cancels pending recovery.
  • Running Actors can be removed directly. Removal stops the Actor before deleting it, with the behavior stated in the confirmation.
  • Weixin replies survive restarts. Reply context tokens persist in owner-only storage, and outbound failures enter the rotating Group IM bridge log. These tokens are excluded from both Group export and import.
  • Direct Group connection setup is simpler. Address editing, invitation sharing and Back navigation have clearer, smaller controls.

Upgrade and Validation Notes ​

  1. Restart CCCC after updating, then refresh the Web UI so the executable and frontend are from the same version.
  2. For an old Actor-specific ChatGPT connector setup, create the shared connector in global settings, add it to ChatGPT once, enable it in each intended conversation and reconnect those Actors. Old credentials are not promoted to shared authority. Conversations and historical messages are preserved.
  3. Refresh the connector's tool catalog after upgrading. Integrations that used cccc_file to send attachments must use cccc_file_send. Browser refresh alone does not refresh a provider's registered MCP schema.
  4. Grok requires an existing Bot URL for each Actor. Keep Actor routing credentials private. Copied Groups require Web Model connections to be configured again.
  5. Use Archive for recoverable Voice document storage. Delete now removes the document file permanently.

Local validation covers Rust regression tests, frontend unit/component checks, repository contracts, and isolated desktop/mobile browser flows against the packaged Linux/WSL application. Two real Grok Bots also passed isolated credential routing probes; those probes do not establish the complete product delivery/reply loop. Real-provider continuous delivery and native Windows/macOS acceptance remain release checks. Provider sign-in, approvals, MCP availability and safety decisions remain outside CCCC's control; this release does not bypass them or guarantee that every model call will be accepted. ChatGPT's existing GPT Pro image workaround remains experimental and is not used for Grok.

For contributors, the new contribution guide consolidates setup and verification. IPC documentation covers the new Voice library and Web Model routing contracts. Command/browser fixtures now wait for observable completion instead of fixed timing assumptions. The old checked-in Playwright fixture harness and its CI/nightly jobs have been retired; frontend tests and native Rust browser/session tests remain, with affected UI flows requiring real browser acceptance.

Full source comparison

Released under the Apache-2.0 License.