mirror of
https://github.com/stablyai/orca.git
synced 2026-10-09 00:02:39 +00:00
* feat(claude): add dormant profile setup and history sharing
* fix(claude): make profile setup one gated, typed, fail-safe entry
Review round 1 of the dormant profile setup found that the pieces could
be called without their safety checks, that one failed write or an
unreadable bookkeeping file could silently stop sharing for good, and
that Windows prompt history could bring back history the user cleared.
- One entry, provisionClaudeAccountProfile: the profile gate (namespace,
no linked components, outside ~/.claude and ~/.config/claude, and an
ownership marker beside the home naming the account and target) runs
first and refuses before creating anything; then history sharing,
config provisioning, and the hook install after the settings merge.
Results come back per surface with closed warning codes instead of
message text.
- The sharing ledger is keyed by surface name, records a value only
after its write succeeded, and an unreadable ledger starts empty and
is rewritten instead of blocking every surface.
- The profile state file goes through the same locked writer as folder
trust (Claude's <file>.lock plus the in-process queue), generalized as
updateClaudeGlobalConfig. Onboarding and trust are still applied when
the personal state file is unreadable.
- WSL descriptors build guest POSIX paths; the state-file path style
follows the injected platform.
- Orca's managed statusLine has one owner in a profile: the settings
merge never shares it, a user's own statusLine is shared over it, and
the profile installer follows the default home's slot so a default
opt-out reaches every profile. remove() takes the same destination;
the remote installer cannot accept one.
- Prompt history compares file identity (bigint dev+ino) on every
platform, never drains the shared file into itself, drains retained
copies in generation order, never reuses a stale cursor, and on Windows
keeps a replaced default's old copy aside instead of replaying it.
Directory merges keep going past a failed entry.
* fix(claude): share the user's own hooks and keep merged history whole
A user's own Claude hooks in ~/.claude (notifications, formatters) did
not run under a managed account, because the whole hooks key stayed
private. They are now shared like any other settings key: Orca's own
hook entries and its managed statusLine are stripped from both the
personal value and the profile's current value before the per-key
ledger comparison, so they never travel through the merge and never make
the key look user-owned. Orca entries already in the profile are kept on
write, and the profile hook installer adds them on top as before.
Prompt history: merged bytes that lack a final newline are terminated,
so Claude's next record no longer fuses onto the last merged line. When
a CLI rewrote the profile's history file (old records plus new), only
the lines past the part it shares with the default history are added,
instead of the whole file again.
* fix(claude): close review round 2 gaps in profile setup
Hooks and statusLine sharing:
- When ~/.claude holds only Orca's hook entries, the user's shared hooks
now read as an empty value instead of a missing key. Removing the
user's last own hook in ~/.claude therefore reaches profiles that
never edited it, and deleting the only shared hook inside a profile
stays deleted.
- A custom statusLine Orca shared, and the profile never edited, goes
away when the default home drops it. When a shared custom line
replaced Orca's line in a profile, the profile's statusline marker is
dropped so Orca's line comes back once the default returns to it; a
profile that opted out stays opted out. No other key gains deletion.
- install/remove/getStatus with a profile directory refuse when it is
the default home, or its settings.json resolves to the default one,
instead of editing System Default's hooks and opt-out state.
- The profile statusline rule reads the default settings under the
userHome passed to the setup entry, not os.homedir().
Profile state and ownership:
- A malformed `projects` value skips only folder trust (new warning
code trust-refused); onboarding and shared keys still apply.
- The ownership marker stores only host-local facts (account, runtime,
distro). The execution host id is the caller's view of the host, so
it stays in the in-memory descriptor and is not compared.
Prompt history interruption paths:
- With no cursor yet, a retained copy starts past the bytes it shares
with the default history, so an interrupted share no longer replays
the whole history.
- A retained name for the shared file itself is removed with its cursor
instead of lingering until a later scrub makes it look new.
- The Windows link record is read three-state: unreadable stops the
share instead of reading as "no link". If the record cannot be
written after linking, the fresh link is undone.
- An unreadable retained copy is reported and no longer blocks linking.
* build(cli): list the new Claude hook modules in the CLI project
hook-service.ts and hook-settings.ts are compiled into the packaged CLI
project, which lists every file explicitly. The statusline policy and
profile destination modules they now import were missing, so the CLI
typecheck failed with TS6307. The CLI still loads hook-service through
the existing managed-agent-hook-controls build entry, which bundles
both modules; neither imports electron.
* fix(claude): close review round 3 regressions in profile setup
- A profile whose hooks hold only Orca's entries and that sharing never
recorded is no longer treated as a user edit, so the user's first own
hook in ~/.claude reaches it (for example when the profile was set up
before ~/.claude had any hooks).
- A retained prompt-history file is removed as a second name for the
shared file only when the default history does not itself link to it;
otherwise it holds the only copy and is kept.
- Default-home checks compare file identity: the profile hook
destination check uses device and inode, and the profile/default
separation check resolves on-disk case, so a case-only alias of
~/.claude is refused on case-insensitive filesystems.
- A test pins that an unreadable leftover session tree no longer blocks
linking.
* fix(claude): let shared keys leave a profile when ~/.claude drops them
QA found that removing a setting from ~/.claude never reached a managed
account: deleting the whole `hooks` block left the user's hook running
there. Only statusLine followed the default away.
Every shared key now follows the same rule through the existing per-key
ledger: when a key disappears from ~/.claude/settings.json (or
mcpServers/theme from the personal state file), it is removed from the
profile if the profile still holds exactly what Orca last shared. A
value changed inside the account is kept. Keys Orca never shared,
including denylisted ones, are never touched. Deleting the whole hooks
block removes the user's shared hooks and keeps Orca's own entries. A
missing source counts as empty; an unreadable source removes nothing.
* feat(claude): add dormant profile routing and account consumers
* fix(claude): drop the dormant profile selection RPC; clients negotiate by capability
Restores the inline mobile allowlist so its source-scan guard sees every
accounts.* method again, and the generated params catalog to generator order.
* fix(claude): guard the claude shell function and honour a hand-exported config dir
The function is defined only in a routed pane where claude is a real
executable (the codex function's guard), re-reads the pointer only while
CLAUDE_CONFIG_DIR is unset or still Orca's injected twin, accepts Git Bash
drive paths, and starts on its own line after the fish/PowerShell codex text.
* fix(claude): spawn-time profile env, total account listing, setup at lifecycle triggers
Round-1 review fixes for the dormant profile routing:
- Panes get the selected profile's CLAUDE_CONFIG_DIR plus an Orca twin at
spawn, so nested shells and scripts inherit the account; System Default
injects nothing and its home is the inherited CLAUDE_CONFIG_DIR.
- An absent routing owner is System Default, never a throw; AI Vault and
session-search scans receive profile roots from their parent, and the
capability is advertised only where an owner is installed.
- Account listing never throws: per-account readiness, a stale pointer is
republished in the background and reported on the snapshot.
- Profiles are set up at select and startup; a launch only sets up one that
never was, and a worker fault on a prepared profile is a warning. The
Claude version probe is cached per binary identity.
- Pre-trust goes through the existing deadline- and realpath-guarded writer
against the launch env's profile config.
- Skill discovery keeps a caller's Claude root and a broken Claude selection
no longer fails other providers.
- The durable record carries a provider-neutral launchAccountHome, read
through one helper by the launch fallback and the model catalog.
* test(claude): pin the version-probe cache, launch-account record and temp-home readers
* test(claude): pin dormant bash rc text alongside fish and PowerShell
* test(claude): read the fish launch init without a nullable index
* fix(claude): withdraw the profile pointer when a selection cannot be published
A pointer left naming the previous account would launch it silently; a
missing pointer makes the claude function refuse visibly. A newer selection
that raced the failed one keeps its pointer.
* fix(claude): read the fish profile pointer with read -z for fish older than 3.4
Shell tests skip system config and abort unless claude resolves to the fake.
* fix(claude): only the newest publish withdraws the pointer; total config dir lookup
- An overtaken publish that fails leaves the newer selection's pointer.
- The runtime config dir falls back to the legacy home for an unresolvable
account or a WSL target, so skill roots never fail for other providers.
- WSL guest reader roots merge verbatim, never realpathed on this thread.
- History readers include ~/.claude, where step-1 setup pools profile history.
- System Default ignores a config dir an outer Orca injected (twin-marked).
* fix(claude): System Default launches and probes use the structured create resolver
A Claude agent-env CLAUDE_CONFIG_DIR the create path stored is now the home
the launch pins and the model probe accepts.
* test(claude): type the System Default launch record as an agent-session record
* fix(claude): install profile hook scripts under the setup job's home
A worker thread's os.homedir() ignores its own env, so the hook and
statusline scripts now go under the home the job names. The worker test pins
the process HOME to a sentinel, refuses to run unless the worker sees it, and
asserts nothing lands there.
* test(claude): skip shell cases whose shell the runner lacks
* fix(claude): remove env vars in the PowerShell claude function instead of setting null
On .NET 9+ (pwsh 7.5+) SetEnvironmentVariable with $null creates an empty
variable, so stripped auth vars reached claude as empty strings and the
restore left CLAUDE_CONFIG_DIR empty in the user's session.
* feat(claude): add dormant WSL guest profile setup
* fix(claude): open WSL panes without guest calls and coalesce same-profile publishes
A WSL pane now gets the same non-throwing, guest-free spawn env as a host
pane; only select, startup and Claude launches publish into the guest.
Overlapping publishes of one target share the newest publish while the
selection still names the same profile, instead of failing as superseded.
Publish issues name their WSL distro and drop out when the target is no
longer routed. A late inspect from an older selection no longer replaces
the newer one's verification, a failed guest request evicts the cached
guest, and readiness is derived per account from the guest's owned homes.
* fix(claude): roll back only the target whose selection failed
With profiles, a failed select or remove republishes just its own target
instead of running startup over every WSL distro, and a rollback failure is
logged instead of replacing the error that caused the rollback.
* fix(claude): scan WSL profile history only in running distros
Vault and usage scans pass Claude profile roots through the same
running-distro filter as every other WSL root, so a stopped distro's UNC
paths are never walked.
* fix(wsl): ship the Claude profile helper only in the WSL bundle dir
The helper only ever runs inside WSL from the desktop, so it moves out of
the SSH relay artifacts (no upload, no relay version change) into
out/relay/wsl beside the other WSL-only guest bundles. The three WSL bundle
resolvers share one candidate list.
* fix(wsl): refuse old glibc before downloading, and keep the shared download per caller
The pinned Node runtime needs glibc 2.28, so a distro below the floor is
refused before any download with a message naming both versions, as SSH
hosts are. The shared download again owns its own deadline and each caller
waits on its own signal, and the OpenCode reader keeps its architecture
error text.
* fix(claude): bound each WSL guest operation and run the helper through the WSL runner
A cached guest no longer carries its 180 s preparation deadline into later
requests. The helper runs through runWslProcess (stdin payload, WSL_UTF8),
the distro is confirmed running once per preparation and once per request,
a failed `claude --version` probe continues with an unknown version like
native setup, the helper resolves from the WSL bundle dir, and the guest
entry decodes stdin once so split UTF-8 survives.
* test(claude): cover WSL profile pre-trust routing and its deadline
* refactor(claude): drop WSL refresh cleanup that the failed publish's withdraw already does
* fix(claude): catch rollback failures only when profiles route the selection
With the gate off, select and remove surface the rollback error exactly as
before; only profile routing logs it and keeps the original error.
* fix(claude): give every WSL pane a guest-relative Claude profile pointer
WSL panes now always carry `~/.local/share/orca/claude-profiles/selected-wsl`,
which the bash/zsh and fish claude functions expand against the guest $HOME
at each invocation, so a pane opened before Orca has met the distro still
follows the selected account instead of falling back to ~/.claude. Absolute
pointers are untouched, PowerShell is unchanged, and a missing pointer file or
profile still refuses visibly. CLAUDE_CONFIG_DIR is set at spawn only when the
selection resolves without a guest call.
* test(claude): assert a missing guest-relative pointer refuses with a visible message
* test(claude): type the WSL runner mock in the transport test
* fix(claude): route only WSL distros that hold an Orca account, and re-derive their publish
A WSL distro is routed only while host settings hold an Orca Claude account
for it, decided from settings with no guest call. An unrouted distro behaves
as before profiles: its panes get no pointer or profile env, and a Claude
launch is System Default with no guest prepare. A distro that loses its last
account has its pointer withdrawn best-effort so older panes stop launching
the removed account.
A routed distro without a current publish (for example stopped at startup)
gets one non-blocking background publish from its next pane spawn, coalesced
per target; its failure stays that distro's issue and a later success clears
it. A late setup result from an older publish no longer replaces the newer
selection's verification. The owner contract moves to its own module so the
routing service stays under the size limit.
* fix(claude): read WSL profile history in native chat and adoption only in running distros
Native chat resolves Claude transcripts from host roots first and reads WSL
profile roots only after a miss, filtered to running distros like Codex's WSL
homes. Structured adoption candidates go through the same filter.
* fix(claude): target registration rollbacks and keep their errors in profile mode
A failed add or re-authentication rolls back only the account's own target.
With profiles, a failed re-authentication rollback is logged instead of
replacing the original error; with the gate off both behave as before.
* fix(claude): spell the guest pointer location once and keep set -u safe
The guest helper, the withdraw script and the pane pointer all derive from
one home-relative constant, and the posix claude function reads ${HOME:-}
so `set -u` with HOME unset refuses cleanly instead of aborting.
* test(claude): cover the IPC preflight and daemon WSLENV paths for WSL profile env
The renderer preflight is tested for wsl.exe and Windows shells with a \\wsl$
cwd (which always launch wsl.exe) and with the gate off, the daemon launch
plan imports the pointer and profile home without a WSLENV flag, and the
Windows launch test uses the guest-relative pointer production sends.
* fix(wsl): report why the guest runtime failed, with download context and trimmed stderr
The install's promote output is classified with the SSH classifier, so a
self-test failure shows the exit code and the loader's words (for example a
missing libstdc++ on Alpine) and a security-software change is named. A failed
runtime download says it was Orca's Node runtime for WSL, while a checksum
mismatch keeps its own text. Guest stderr is trimmed before it reaches a
refusal message.
* test(claude): pin that pointer retirement never runs for host targets or with the gate off
* test(claude): give the routed WSL preflight fixture its required authMethod
* fix(claude): let the pane-triggered WSL publish repair a distro stopped at startup
"Distro not running" is now a typed refusal: it never withdraws the pointer
(the distro's last pointer cannot be stale, and a withdraw racing the boot
could delete a valid one) and never records a distro issue. The background
publish a pane fires now waits a few seconds for the pane's own spawn to boot
the distro, probing three times, and is dropped silently and re-armed if the
distro stays down. It joins any publish already in flight for that target
instead of preparing the guest a second time. Per-target generations and
pointer-write ordering move to ClaudeProfilePointerQueue so the routing
service stays under the size limit.
* fix(claude): remove the last selected WSL account without a guest publish
With profiles, removal writes the account list and the selection in one
update, so a distro losing its last account is already unrouted when it syncs
and its pointer is retired best-effort. Removal no longer needs the distro to
be running or able to run Orca's runtime. The gate-off order is unchanged.
* fix(claude): keep native chat's legacy Claude roots first and unfiltered
Only roots added by WSL profiles are read after a miss and filtered to
running distros; a host CLAUDE_CONFIG_DIR on a \\wsl$ share is searched first
and unfiltered, as before profiles.
* test(claude): cover stopped-at-startup repair, launch join and last-account removal end to end
* test(claude): assert no running probe before the pane has had a turn to boot the distro
* fix(claude): let user-initiated profile work boot an idle-stopped WSL distro
WSL distros idle-stop on their own, and the legacy path boots them with its
spawn or \\wsl$ write. With profiles on, a Claude launch, a select, a remove,
a failed-change rollback and the retire after removing a distro's last
account now skip the running pre-check and let their first bounded guest
command (`wsl -d <distro> --exec ...` through runWslProcess) boot the
distro. They refuse only if that command fails, with wsl.exe's own reason,
for example a distro that does not exist. Startup, the pane-triggered repair
and the history readers keep the running pre-check and its typed refusal, so
background work never boots a distro. With the gate off nothing changes.
* fix(claude): let startup join a launch or select already publishing a WSL distro
Startup no longer overtakes a user's in-flight publish for the same target,
so a launch that is booting an idle-stopped distro is not handed startup's
"not running" refusal.
* fix(claude): remove accounts of a WSL distro that no longer exists, and name the helper once
wsl.exe's own failures (exit 0xFFFFFFFF, empty stderr, the diagnostic and its
WSL_E_* code on stdout) are now read by one shared reader used by the git
runner and the WSL profile transport, so profile refusals show wsl.exe's
message. WSL_E_DISTRO_NOT_FOUND becomes ClaudeProfileHostMissingError: with
profiles, removing an account from a distro that no longer exists keeps the
removal and logs a warning, while select and launch still refuse visibly.
The helper's file name is defined once in shared/relay-artifacts.ts and used
by the relay build and the transport.
* fix(claude): give plain fish tabs the claude function through the codex hand-off
Main now gives a plain fish tab Orca's codex function through a vendor_conf.d
snippet instead of a -C init. The claude function only rode the -C path, so a
plain fish tab would not re-read the account selection per invocation once
profiles are on. Define it at the first prompt beside codex; it stays empty
while the profile gate is off.
* fix(claude): share personal rules, themes, workflows and keybindings into account profiles
A managed account launches Claude with its own config folder, so user-level
rules/, custom themes/ (which a shared `custom:<slug>` theme points at),
personal workflows/ and keybindings.json silently stopped applying. Link the
three directories like skills and commands, and copy keybindings.json with the
same edit-preserving ledger as CLAUDE.md. routines/ stays unshared: routines
belong to the claude.ai account and the folder holds per-run state.
* test(claude): wait for the running child to read its account before switching
The test switched the selection after a fixed 20 ms, so under load the backgrounded claude
had not yet read the pointer and picked up the new account. The stand-in now marks when it has
started, and the test waits for that mark (bounded) before switching.
* fix(claude): accept WSL setup warnings for every shared Claude file
The guest reply schema listed CLAUDE.md by name, so a warning about the newly shared
keybindings.json would have rejected the whole reply. It now takes the shared-file list
from provisioning, like the shared folders.
* fix(claude): import the personal CLAUDE.md into account profiles instead of copying it
Claude also loads ~/.claude/CLAUDE.md as a parent folder's memory for any project under home,
so a copied account CLAUDE.md made every such session read the user's instructions twice
(checked live with Claude 2.1.288). An @~/.claude/CLAUDE.md import resolves to the same real
file, which Claude loads once from home, from projects under home and from folders outside it.
* refactor(claude): simplify account profile setup toward the prior art
- Windows keeps each account's history private; drop the hardlink, link
record and conflict-copy machinery that only Windows reached.
- Share hooks and statusLine as ordinary settings keys: Orca writes the
same entries into every folder, so the installer finds them present.
Drops the Orca-entry carve-out, the per-profile statusline follow
logic and its marker.
- Unreadable ledger is just an empty ledger.
- Share from the user's own CLAUDE_CONFIG_DIR when they set one (marked
so Orca's injected value is never mistaken for it), and refuse a
profile at or around it.
- Pin the one canonical profile path spelling in a test.
* refactor(claude): route launches through one account router, superset-shaped
Replace the routing service, owner interface, setup worker thread, reader-root
merging, persisted launch account and capability string with one
ClaudeProfileRouter: the pointer is written first and setup runs best-effort
after it (superset's order); a missing pointer means System default.
The claude shell function re-reads the pointer on every launch, refuses only
a selected account whose folder is missing, and prints a note when the user's
own CLAUDE_CONFIG_DIR overrides the selected account in that terminal.
Still dormant: claudeProfileRoutingEnabled() is false.
* test(claude): type router test settings instead of casting
* fix(claude): run account setup on a worker thread, never Electron main
publish() writes the pointer and starts setup in the background, so neither
startup nor an account switch blocks on a history merge. Each setup runs in a
one-shot worker (the profile-state backup worker's pattern); one setup per
account at a time, reused by later requests. A launch waits only for a folder
that was never set up, and refuses with a clear message if that setup fails.
* fix(claude): do not await the synchronous pointer publish
* refactor(claude): route WSL distros through a small guest router on the Step 2 shape
Replaces the WSL owner/transport/guest-inspect stack with ClaudeWslProfileRouter:
publish writes the guest pointer with one sh command and kicks Step 1's setup
best-effort; prepareLaunch checks the folder over the distro share and waits only
for a never-set-up folder; preparation returns main's WSL shape, so trust, rate
limits and readers need no new code. Setup runs as Linux in the guest on Orca's
pinned Node via a bundled helper (argv in, exit code out), without hooks.
Restores OpenCode's WSL runtime prep, git's wsl-host-failure, wsl-runner,
workspace trust, readers and account selection/registration to Step 2.
Names the guest pointer per Orca build so dev and packaged never share it.
* test(claude): give the routing launch test the merged resolver deps and handle shape
* test(claude): type the WSL routing mock's original() without an inline import()
* fix(claude-accounts): dedupe merged prompt history, drop drained copies, link setup folders by path
- Prompt-history drain appends only lines the shared file lacks, so a purge never re-adds lines.
- A set-aside history copy whose saved offset reaches its end is deleted on the next run.
- Setup folders link to the default home's own entry, not its resolved target.
- The profile gate and folder creation run once, in provisionClaudeAccountProfile.
- installHooks receives only configDir; drop a duplicate test key that fails CI.
* fix(claude-accounts): refuse a routed resume whose transcript is in another account; zsh claude function; setup timeout
- With account routing, a chat resume checks its transcript is in the launch folder; a missing one
with a stored leaf refuses with historyInOtherAccount instead of starting fresh.
- The launch folder of a selected account comes from prepareLaunch(); the resolver stays for System default.
- zsh panes get the claude function like bash, fish and PowerShell (empty while routing is off).
- The setup worker is terminated after 60 s so a later launch can retry.
- Document that the setup marker means setup started, not finished.
* fix(claude-accounts): write the WSL account pointer before a launch returns; one relay bundle candidate list
- prepareLaunch awaits writePointer, so a missing or stale guest pointer cannot run another account.
- Startup's WSL republish runs inside serializeMutation, like rollback.
- relayBundleCandidates takes 'wsl'; the hook relay, browser relay and Claude helper use it, and
wsl-relay-bundle-dirs.ts is gone.
- One setup-marker path helper for host and WSL; the guest pointer path is home-relative and only
the pane value carries '~/'; drop a no-op esbuild external.
* fix(claude-accounts): refuse a routed resume only when the transcript is found in another folder
A transcript found in no known folder keeps the old stored-leaf resume.
* fix(claude-accounts): a WSL launch writes the pointer for the selection current at write time; bound the pointer read
A selection made while a launch waited on setup was overwritten by the launch's stale account.
A hung \\wsl.localhost read no longer stalls startup's serialized publish.
* fix(claude-accounts): record installed hooks as Orca-shared; skip symlink tests on Windows
After Orca installs its hooks into an account, record the account's hooks in
the settings ledger so a later run can still bring the user's own hooks in.
Tests that create real symlinks now skip on Windows.
* fix(claude-accounts): trim the which-account file in the PowerShell claude function
Co-Authored-By: Claude <noreply@anthropic.com>
* test(claude-accounts): spell the user's own config folder as an absolute path on every platform
Co-Authored-By: Claude <noreply@anthropic.com>
* test(claude): skip the POSIX-only WSL profile test on Windows
A WSL profile's data root is a POSIX path, so building one from a Windows
temp dir fails the absolute-path check there.
---------
Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
Co-authored-by: Claude <noreply@anthropic.com>
128 lines
6.6 KiB
TypeScript
128 lines
6.6 KiB
TypeScript
import { claudeProfileRoutingEnabled } from './claude-profile-routing'
|
|
const authHeaderWords = 'authorization|x-api-key|api-key|bearer'
|
|
const posixAuthHeaderPattern = authHeaderWords
|
|
.split('|')
|
|
.map((word) => `*${word.replace(/[a-z]/g, (letter) => `[${letter}${letter.toUpperCase()}]`)}*`)
|
|
.join('|')
|
|
const OVERRIDE_NOTE =
|
|
'Orca: CLAUDE_CONFIG_DIR is set in this shell, so the Claude account selected in Orca is not used here.'
|
|
const MISSING_NOTE =
|
|
"Orca: the selected Claude account's folder is missing. Sign in to it again or choose another account."
|
|
|
|
/**
|
|
* `claude` re-reads the which-account file on every launch, so a switch reaches open terminals
|
|
* (superset's wrapper rule). Defined only in a pane Orca routed (pointer env set) where `claude` is
|
|
* a real executable. A missing or empty file is System default; a CLAUDE_CONFIG_DIR the user set,
|
|
* as opposed to Orca's twin-marked value, wins.
|
|
*/
|
|
export function getPosixClaudeShellFunction(): string {
|
|
if (!claudeProfileRoutingEnabled()) {
|
|
return ''
|
|
}
|
|
return `__orca_claude_binary="$(unalias claude 2>/dev/null || :; command -v claude 2>/dev/null || :)"
|
|
if [[ -n "\${ORCA_CLAUDE_PROFILE_POINTER:-}" && -n "\${__orca_claude_binary:-}" && -x "\${__orca_claude_binary}" ]]; then
|
|
function claude {
|
|
local __orca_claude_home __orca_claude_pointer="\${ORCA_CLAUDE_PROFILE_POINTER:-}"
|
|
# Why: a WSL pane's pointer is relative to the guest home, which the host cannot know at spawn.
|
|
case "$__orca_claude_pointer" in '~/'*) __orca_claude_pointer="\${HOME:-}/\${__orca_claude_pointer#??}" ;; esac
|
|
__orca_claude_home="$(cat "$__orca_claude_pointer" 2>/dev/null || :)"
|
|
if [ -n "\${CLAUDE_CONFIG_DIR:-}" ] && [ "$CLAUDE_CONFIG_DIR" != "\${ORCA_CLAUDE_INJECTED_CONFIG_DIR:-}" ]; then
|
|
[ -z "$__orca_claude_home" ] || [ "$__orca_claude_home" = "$CLAUDE_CONFIG_DIR" ] || printf '%s\\n' '${OVERRIDE_NOTE}' >&2
|
|
command claude "$@"; return
|
|
fi
|
|
if [ -z "$__orca_claude_home" ]; then
|
|
( unset CLAUDE_CONFIG_DIR ORCA_CLAUDE_INJECTED_CONFIG_DIR; command claude "$@" ); return
|
|
fi
|
|
if [ ! -d "$__orca_claude_home" ]; then printf '%s\\n' "${MISSING_NOTE}" >&2; return 1; fi
|
|
( unset ANTHROPIC_API_KEY ANTHROPIC_AUTH_TOKEN CLAUDE_CODE_OAUTH_TOKEN AWS_BEARER_TOKEN_BEDROCK; case "\${ANTHROPIC_CUSTOM_HEADERS:-}" in ${posixAuthHeaderPattern}) unset ANTHROPIC_CUSTOM_HEADERS ;; esac; export CLAUDE_CONFIG_DIR="$__orca_claude_home" ORCA_CLAUDE_INJECTED_CONFIG_DIR="$__orca_claude_home"; command claude "$@" )
|
|
}
|
|
fi
|
|
unset __orca_claude_binary
|
|
`
|
|
}
|
|
|
|
/** Leading newline: the codex fragment it follows ends without one. */
|
|
export function getFishClaudeShellFunction(): string {
|
|
if (!claudeProfileRoutingEnabled()) {
|
|
return ''
|
|
}
|
|
return `
|
|
set -l __orca_claude_type (type -t claude 2>/dev/null)
|
|
if test -n "$ORCA_CLAUDE_PROFILE_POINTER"; and test "$__orca_claude_type" = file
|
|
function claude
|
|
# Why: a WSL pane's pointer is relative to the guest home, which the host cannot know at spawn.
|
|
set -l pointer (string replace -r '^~/' "$HOME/" -- "$ORCA_CLAUDE_PROFILE_POINTER")
|
|
set -l profile (cat "$pointer" 2>/dev/null)
|
|
if test -n "$CLAUDE_CONFIG_DIR"; and test "$CLAUDE_CONFIG_DIR" != "$ORCA_CLAUDE_INJECTED_CONFIG_DIR"
|
|
if test -n "$profile"; and test "$profile" != "$CLAUDE_CONFIG_DIR"
|
|
echo '${OVERRIDE_NOTE}' >&2
|
|
end
|
|
command claude $argv
|
|
return $status
|
|
end
|
|
if test -z "$profile"
|
|
env -u CLAUDE_CONFIG_DIR -u ORCA_CLAUDE_INJECTED_CONFIG_DIR claude $argv
|
|
return $status
|
|
end
|
|
if not test -d "$profile"
|
|
echo "${MISSING_NOTE}" >&2; return 1
|
|
end
|
|
set -l headers
|
|
if string match -irq '${authHeaderWords}' -- "$ANTHROPIC_CUSTOM_HEADERS"
|
|
set headers -u ANTHROPIC_CUSTOM_HEADERS
|
|
end
|
|
env $headers -u ANTHROPIC_API_KEY -u ANTHROPIC_AUTH_TOKEN -u CLAUDE_CODE_OAUTH_TOKEN -u AWS_BEARER_TOKEN_BEDROCK CLAUDE_CONFIG_DIR="$profile" ORCA_CLAUDE_INJECTED_CONFIG_DIR="$profile" claude $argv
|
|
end
|
|
end
|
|
set -e __orca_claude_type
|
|
`
|
|
}
|
|
|
|
/** Leading newline: the codex fragment it follows ends without one. */
|
|
export function getPowerShellClaudeShellFunction(): string {
|
|
if (!claudeProfileRoutingEnabled()) {
|
|
return ''
|
|
}
|
|
return `
|
|
$orcaClaudeCommand = Get-Command claude -ErrorAction SilentlyContinue | Select-Object -First 1
|
|
if ($env:ORCA_CLAUDE_PROFILE_POINTER -and $orcaClaudeCommand -and
|
|
$orcaClaudeCommand.CommandType -in @("Application", "ExternalScript")) {
|
|
function Global:claude {
|
|
$names = @('CLAUDE_CONFIG_DIR', 'ORCA_CLAUDE_INJECTED_CONFIG_DIR', 'ANTHROPIC_API_KEY', 'ANTHROPIC_AUTH_TOKEN', 'CLAUDE_CODE_OAUTH_TOKEN', 'AWS_BEARER_TOKEN_BEDROCK', 'ANTHROPIC_CUSTOM_HEADERS')
|
|
$saved = @{}
|
|
foreach ($name in $names) { $saved[$name] = [Environment]::GetEnvironmentVariable($name, 'Process') }
|
|
try {
|
|
$orcaClaudeHome = ''
|
|
if ($env:ORCA_CLAUDE_PROFILE_POINTER -and (Test-Path -LiteralPath $env:ORCA_CLAUDE_PROFILE_POINTER -PathType Leaf)) {
|
|
$orcaClaudeHome = [IO.File]::ReadAllText($env:ORCA_CLAUDE_PROFILE_POINTER).TrimEnd()
|
|
}
|
|
if ($env:CLAUDE_CONFIG_DIR -and $env:CLAUDE_CONFIG_DIR -ne $env:ORCA_CLAUDE_INJECTED_CONFIG_DIR) {
|
|
if ($orcaClaudeHome -and $orcaClaudeHome -ne $env:CLAUDE_CONFIG_DIR) { [Console]::Error.WriteLine('${OVERRIDE_NOTE}') }
|
|
} elseif (-not $orcaClaudeHome) {
|
|
Remove-Item Env:CLAUDE_CONFIG_DIR, Env:ORCA_CLAUDE_INJECTED_CONFIG_DIR -ErrorAction SilentlyContinue
|
|
} elseif (-not [IO.Directory]::Exists($orcaClaudeHome)) {
|
|
throw "${MISSING_NOTE}"
|
|
} else {
|
|
foreach ($name in $names) {
|
|
if ($name -ne 'ANTHROPIC_CUSTOM_HEADERS' -or $env:ANTHROPIC_CUSTOM_HEADERS -match '${authHeaderWords}') { Remove-Item -LiteralPath "Env:$name" -ErrorAction SilentlyContinue }
|
|
}
|
|
$env:CLAUDE_CONFIG_DIR = $orcaClaudeHome
|
|
$env:ORCA_CLAUDE_INJECTED_CONFIG_DIR = $orcaClaudeHome
|
|
}
|
|
$binary = Get-Command claude -CommandType Application,ExternalScript -ErrorAction Stop | Select-Object -First 1
|
|
if ($MyInvocation.ExpectingInput) { $input | & $binary.Source @args } else { & $binary.Source @args }
|
|
$global:LASTEXITCODE = $LASTEXITCODE
|
|
} catch { $global:LASTEXITCODE = 1; Write-Error $_ -ErrorAction Continue }
|
|
finally {
|
|
# Why Remove-Item: on .NET 9+ a $null value (passed as "") creates the variable empty instead of deleting it.
|
|
foreach ($name in $names) {
|
|
if ($null -eq $saved[$name]) { Remove-Item -LiteralPath "Env:$name" -ErrorAction SilentlyContinue }
|
|
else { [Environment]::SetEnvironmentVariable($name, $saved[$name], 'Process') }
|
|
}
|
|
}
|
|
}
|
|
}
|
|
Remove-Variable orcaClaudeCommand -ErrorAction SilentlyContinue
|
|
`
|
|
}
|