Add llama.cpp backend, model gateway, URL relay and browser view

Four features, plus a latent bug fix.

llama.cpp backend. Claude Code only ever speaks the Anthropic Messages
API — confirmed empirically by pointing it at a logging server, which
received POST /v1/messages?beta=true. llama-server implements that
natively (verified in its README, alongside --port default 8080), so
this is a plain base-URL backend with no translation shim, the same
shape as Ollama. Its --api-key defaults to none, so the auth token is a
placeholder Claude Code requires and llama-server ignores.

Model alias fix. ANTHROPIC_DEFAULT_HAIKU_MODEL is documented as "also
used for background functionality", and Triple-C set none of the alias
vars. So on every custom-endpoint backend, Claude Code resolved `haiku`
to an Anthropic model id and sent it to a local server that does not
have it — background features failed silently. All four
ANTHROPIC_DEFAULT_{OPUS,SONNET,HAIKU,FABLE}_MODEL vars are now pinned to
the backend's configured model, with an optional Haiku override, and
blanked for Anthropic and Bedrock so those keep Claude Code's defaults.
The deprecated ANTHROPIC_SMALL_FAST_MODEL is never emitted. Existing
Ollama and OpenAI-Compatible containers are recreated once so the new
env reaches them; the snapshot is preserved.

Model gateway. Optional LiteLLM sibling container, off by default,
mirroring stt.rs — this is what makes real OpenAI usable, since
api.openai.com has no /v1/messages. Pinned to v1.96.0 by tag and digest:
the 1.82.7/1.82.8 malware was PyPI-only and never affected the official
images, which is precisely why this builds FROM the image rather than
pip-installing, but 1.84.0 is still the floor for proxy CVEs (API-key
SQLi, Host-header auth bypass, MCP auth bypass). Binds 0.0.0.0 because
project containers consume it, and therefore always sets a master_key —
LiteLLM without one accepts any key. The provider key lives in the OS
keychain and is uploaded into a volume, never an image layer or label.

URL relay. A container-side xdg-open/BROWSER shim opens URLs in the
host's browser. Uses an OSC sequence to /dev/tty rather than a printed
sentinel, because the shim usually runs as a grandchild of a process
capturing its children's output. Degrades to printing the URL when no
terminal is attached, so scheduled tasks do not hang. Only http/https,
with control characters rejected before new URL() — which strips
newlines, so java\nscript: would otherwise parse as javascript:. Nothing
auto-opens; the user confirms. The web terminal shows a tap-to-open
banner instead, since that browser may be a phone across a tunnel.

Browser view. A Project Home tab that watches and takes over the browser
Claude drives with Playwright, using Playwright's own dashboard. Zero
image cost — Playwright stays user-installed. It does not reuse the auth
bridge's PortForward, which binds an unauthenticated port: correct for a
throwaway OAuth listener, wrong for mouse and keyboard control of a
browser in a passwordless-sudo container. Instead a token-gated loopback
proxy checks Host, then token or a forbidden-header origin signal,
before a byte reaches the container. Host ports are confined to
47820..=47827 so CSP frame-src can enumerate them rather than widening
to a wildcard, with a test asserting the two agree.

188 frontend tests, 107 Rust tests, both builds clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-08-09 16:55:28 -07:00
co-authored by Claude Opus 5
parent 7d00390e1f
commit cc5f691677
46 changed files with 6194 additions and 61 deletions
+155
View File
@@ -0,0 +1,155 @@
/**
* URL relay — host side of `container/triple-c-open`.
*
* A CLI inside the container has no browser. When it wants to open a URL
* (`gh auth login`, `aws sso login`, `gcloud auth login`, anything honouring
* `$BROWSER` or shelling out to `xdg-open`), the container-side shim writes
*
* ESC ] 7777 ; open ; <base64(url)> BEL
*
* to its controlling terminal. xterm.js routes that to an OSC 7777 handler,
* which lands here.
*
* THE CONTAINER IS THE UNTRUSTED SIDE OF THIS BOUNDARY. Everything arriving
* over the relay is attacker-controlled if the sandboxed agent misbehaves, so
* this module is a validator first and a convenience second:
*
* - only `http:` and `https:` survive — `file:`, `javascript:`, `data:` and
* every custom/registered URI handler are rejected. A container able to
* make the host open arbitrary schemes could reach local files, in-page
* script, or any protocol handler the OS has registered, which is a real
* escalation out of the sandbox.
* - embedded credentials (`https://user:pass@host`) are rejected: they are a
* display-spoofing vector in the confirmation toast and in the address bar.
* - control characters, whitespace and oversized payloads are rejected before
* parsing, so the relay can't be used to smuggle escape sequences or to
* push a megabyte of text into the UI.
* - the URL is returned in WHATWG-normalized form, so what the user is shown
* in the toast is exactly what gets opened.
*
* Opening is never automatic — see `RelayRateLimiter` and the confirmation
* toast in TerminalView.
*/
/** Private OSC identifier used by the relay. Chosen to avoid the numbers in
* common use (0-19, 22, 52, 104, 110-119, 133, 777, 1337). */
export const URL_RELAY_OSC = 7777;
/** Hard cap on a relayed URL. Real OAuth URLs run to a few hundred chars. */
export const MAX_RELAY_URL_LENGTH = 8192;
/**
* Validate a URL the container asked the host to open.
*
* @returns the normalized URL, or `null` if it must not be opened.
*/
export function sanitizeRelayUrl(raw: unknown): string | null {
if (typeof raw !== "string") return null;
const candidate = raw.trim();
if (candidate.length === 0) return null;
if (candidate.length > MAX_RELAY_URL_LENGTH) return null;
// No whitespace or control characters anywhere. Rejecting these before
// parsing matters: `new URL()` silently strips tabs/newlines, so
// "java\nscript:alert(1)" would otherwise parse as a javascript: URL.
// eslint-disable-next-line no-control-regex
if (/[\s\u0000-\u0020\u007f]/.test(candidate)) return null;
let parsed: URL;
try {
parsed = new URL(candidate);
} catch {
return null;
}
// Scheme allowlist. Nothing else, ever.
if (parsed.protocol !== "http:" && parsed.protocol !== "https:") return null;
// A special-scheme URL with no host is nonsense and, on some platforms,
// resolves in surprising ways.
if (parsed.hostname === "") return null;
// Embedded credentials spoof the displayed origin.
if (parsed.username !== "" || parsed.password !== "") return null;
const normalized = parsed.toString();
if (normalized.length > MAX_RELAY_URL_LENGTH) return null;
return normalized;
}
/**
* Parse the payload of an OSC 7777 sequence (everything between `ESC]7777;`
* and the terminator).
*
* Expected shape: `open;<base64(url)>`. The URL is base64-encoded so that a
* `;`, a BEL or an ESC inside it cannot break out of the sequence.
*
* @returns the validated URL, or `null` if the payload is malformed or the
* URL fails {@link sanitizeRelayUrl}.
*/
export function parseUrlRelayOsc(data: string): string | null {
if (typeof data !== "string") return null;
const sep = data.indexOf(";");
if (sep === -1) return null;
const verb = data.slice(0, sep);
if (verb !== "open") return null;
const payload = data.slice(sep + 1);
if (payload.length === 0) return null;
// base64 of the length cap, plus slack for padding.
if (payload.length > MAX_RELAY_URL_LENGTH * 2) return null;
if (!/^[A-Za-z0-9+/]+=*$/.test(payload)) return null;
let decoded: string;
try {
const binary = atob(payload);
const bytes = Uint8Array.from(binary, (c) => c.charCodeAt(0));
decoded = new TextDecoder("utf-8", { fatal: true }).decode(bytes);
} catch {
return null;
}
return sanitizeRelayUrl(decoded);
}
/**
* Throttles relay requests so a runaway (or hostile) process in the container
* can't bury the UI in prompts.
*
* Two limits: a sliding window on total requests, and a short dedup window so
* a retry loop around a single URL produces one prompt rather than twenty.
*/
export class RelayRateLimiter {
private readonly maxInWindow: number;
private readonly windowMs: number;
private readonly dedupeMs: number;
private timestamps: number[] = [];
private lastUrl: string | null = null;
private lastUrlAt = 0;
constructor(maxInWindow = 5, windowMs = 10_000, dedupeMs = 5_000) {
this.maxInWindow = maxInWindow;
this.windowMs = windowMs;
this.dedupeMs = dedupeMs;
}
/** @returns true if this request should be surfaced to the user. */
allow(url: string, now: number = Date.now()): boolean {
if (url === this.lastUrl && now - this.lastUrlAt < this.dedupeMs) {
this.lastUrlAt = now;
return false;
}
this.timestamps = this.timestamps.filter((t) => now - t < this.windowMs);
if (this.timestamps.length >= this.maxInWindow) return false;
this.timestamps.push(now);
this.lastUrl = url;
this.lastUrlAt = now;
return true;
}
}