chore(release): v1.6.10 -- the office only shows what is really happening, and the server stops falling over - #253
Merged
Merged
Conversation
…ning, and the server stops falling over Cuts the 13 PRs merged since v1.6.9 (#240-#252): package.json and both package-lock.json root version fields 1.6.9 -> 1.6.10, the CHANGELOG narrative (leading with the OFFICE_ALLOWED_HOSTS upgrade note), and the release Ship History entry (oldest entry rotated to the archive; SSoT sequence 142 -> 143). No app code. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Thirteen pull requests since v1.6.9. Most come from a full-repo audit on 2026-09-26 (server,
hooks, client runtime), worked branch by branch with a fresh reviewer each round; the rest finish
the 2026-09-19 review and an external audit from 2026-09-24.
Fixed
GET http://[ HTTP/1.1threw inside the request handler and the process exited; it now gets
400and the server keepsrunning. (fix(server): a malformed request can no longer crash the server; SSE stays up; DNS-rebinding reads blocked #246)
timeout was racing the 30-second heartbeat, so the stream kept closing and reconnecting. (fix(server): a malformed request can no longer crash the server; SSE stays up; DNS-rebinding reads blocked #246)
while the ops agent was busy, and two-person scenes showed an empty banner for 20 seconds. Events
now fire only when everyone they need is genuinely free, and an agent who starts real work leaves
the scene instead of acting it out. (fix(office): events only fire when someone can actually perform them, and inference stops faking fresh signals #251)
stretch, it also wiped the agent's task and file and made it look freshly active; it now keeps the
real details and the real "since" time. (fix(office): events only fire when someone can actually perform them, and inference stops faking fresh signals #251)
minutes although it was still working; the office now trusts the server's "nothing changed"
answers and only clears an agent the server has also dropped (about five minutes). (fix(client): long tool calls stop looking idle, the live stream reconnects, and "done today" survives a closed tab #250)
while polling is working fine. (fix(client): long tool calls stop looking idle, the live stream reconnects, and "done today" survives a closed tab #250)
file; Codex now writes its own (
office-status-codex-*.json), and the Codex helper no longerhangs when run from a terminal. The two now appear as two sessions. (fix(hooks): Codex and Claude stop overwriting each other's status file; the Codex helper no longer hangs #247)
briefly locks the file instead of risking a half-written file. (fix(hooks): the status lock can't be stolen twice, writes survive Windows file locks, and search text stays out of labels #249)
~/.claudetoo, so Claude's own transcriptfiles showed up as a working agent; it also overwrote a webhook's
blockedstate after 10 seconds.Its CORS behaviour now matches production. (fix(vite): the dev server stops inventing agent status from ~/.claude and matches production CORS #248)
agent is blocked and needs you). (fix(office): no speech bubble for a speaker you cannot see (AVO-196) #240)
others were snapping straight to their last frame). (fix(office): the one-shot animations actually play now (AVO-197) #244)
Changed
Friday tea break was always winning the slot, so the meeting never happened. (fix(office): events only fire when someone can actually perform them, and inference stops faking fresh signals #251)
description shows the generic delegating label, instead of the raw query or prompt. (fix(hooks): the status lock can't be stolen twice, writes survive Windows file locks, and search text stays out of labels #249)
Housekeeping — not user-facing
(
OFFICE_MAX_SSE_CLIENTS); the dev server's single status clock and bridge-UI buttons from the2026-09-24 audit (fix(server/bridge): audit remediation and active status toggle regex fix #245);
bridge.jsand the generic bridge no longer forward spoofable fields;setup/uninstall keep a symlinked
settings.json; render-smoke really kills a stuck server;.gitignorefor the single-file build (chore(repo): ignore the single-file build's output directory #242). (fix(server/bridge): audit remediation and active status toggle regex fix #245, fix(server): a malformed request can no longer crash the server; SSE stays up; DNS-rebinding reads blocked #246, fix(hooks): the status lock can't be stolen twice, writes survive Windows file locks, and search text stays out of labels #249, fix(dev): OFFICE_ALLOWED_HOSTS now governs the dev server too; render-smoke really escalates a stuck server #252, chore(repo): ignore the single-file build's output directory #242, docs(backlog): AVO-197 — every one-shot SMIL animation in the office is dead #243)What this release does not claim
tool calls no longer looking idle.
second active role on one side can be hidden.
stricter check is planned.
one; the worst case is one lost status update, as before the lock existed.
🤖 Generated with Claude Code