Skip to content

v2.0.0

Choose a tag to compare

@github-actions github-actions released this 30 Jul 02:38
· 199 commits to main since this release

Pull Requests

  • perf: fix startup disconnects, slow teardown, and bloated profile clone (#11)
  • feat: add stealth-chrome-devtools ops CLI (cleanup, profiles, status, doctor, serve) (#12)

Commits

  • e65c5d6 W11 fix: screen doc-example paths under BOTH path conventions
  • b5ae81e Merge W12: security-boundary evidence (negative tests + contract security section)
  • 2fa0c97 Merge W11: docs-as-tests (README/RUNBOOK examples executed, not trusted)
  • addedaa Merge W7: eight deterministic dynamic-site shapes (MQ-114..121) with ledger binding
  • 3501909 Merge W6: canary repro lane (soak-lane absence declared, not faked)
  • a3a54c4 RELEASE-7 W7: make the MQ->node map, and MQ-116's split, explicit
  • a8dc471 RELEASE-7 W7: emit MQ-114..121 into the evidence ledger, not just the prose
  • 2f6e813 RELEASE-5: stop chasing the F-779 percentage; state the durable claim
  • 3be448b RELEASE-5: name a probable mechanism for F-779 instead of shrugging at it
  • a0addc8 RELEASE-7 W7: drop a duplicate MQ-119 body re-read (flake risk, no coverage)
  • e0c0654 RELEASE-12: say where the section-6 evidence actually runs
  • bec2a51 RELEASE-7 W7: eight deterministic site shapes (MQ-114…121)
  • 7a3f546 RELEASE-5: F-779 reproduced on a docs-only commit — correct the rate (2/6)
  • db8a060 RELEASE-12: security and filesystem trust-boundary gate
  • 5f5582e RELEASE-11: executable docs reuse the release evidence source
  • 7c65374 RELEASE-5: explain the three red PRs that look like a FIX-B regression (F-780)
  • 68cdd7f RELEASE-6: read-only scheduled observation and local fixture repro metadata
  • a97c970 RELEASE 2.0.0: sync uv.lock to the version pyproject already declares
  • 2e7cd33 RELEASE-5: record the macOS gate flake the 2.0.0 re-run exposed (F-779)
  • 6a8fa79 RELEASE-5: re-run the gate to arbitrate the macOS teardown flake
  • d13997e RELEASE-5: regenerate the contract at 2.0.0
  • 30700bb RELEASE-5: generate the contract at 2.0.0, the version it actually describes
  • 5c2505a RELEASE-5: merge the 2.0.0 version bump into the W5 contract line
  • 5028d66 RELEASE-5 W5: record the Linux cold-spawn flake where it actually landed
  • b8fabad RELEASE integration: back off between cold-start warmup attempts
  • 5bc09e9 RELEASE-5 W5: fix the PRODUCER of the node ids, and stop "unqualified" reading as "untested"
  • be115b8 RELEASE 2.0.0: stop shipping 14 MB of demo media and audit docs in the sdist
  • bece37f RELEASE 2.0.0: record the per-tool verification depth honestly
  • 05e1a6b RELEASE-5 W5: a drift failure prints the diff, not just the word "stale"
  • 57609e3 RELEASE-5 W5: claim the cookie tools, and write the contract as a SHIPPING one
  • 6fcaaa0 RELEASE 2.0.0: version bump and changelog
  • 5a4bb11 RELEASE-5 W5: qualify the cookie round trip, and say what that costs
  • bf6b640 RELEASE-5 W5: take the get_cookies transport success path (PR #52)
  • c674fe5 RELEASE-5: generated qualified release contract and tool evidence ledger
  • eaa574e RELEASE W5-prep: real-transport get_cookies success path
  • ff35ae3 RELEASE integration: make offline-stealth a real lane, not an empty one
  • aa40384 RELEASE integration: merge the W4/FIX-D stealth line
  • ff3c8b7 RELEASE integration: merge W3 packaging line into the FIX-E/F line
  • c2b94ae RELEASE-FIX-F: the swallowed half of the F-771 tab family (F-775)
  • 080d16d RELEASE-FIX-F F0: RED-first pins for F-775 (the swallowed F-771 siblings)
  • 295c8de RELEASE-3 W3: pin the release topology so publish cannot silently regress
  • 6c619ab RELEASE-FIX-D D1-D3: mask the headless User-Agent (F-770), and record F-774
  • 2dacc05 RELEASE-3 W3: macOS install-smoke is a DECLARED PARTIAL cell (F-773)
  • 0b90124 RELEASE-FIX-D D0b: warm Chrome before the isolated stealth lane
  • 6620252 RELEASE-FIX-E: list_tabs survives tab rediscovery (F-771)
  • 2e589b7 RELEASE-3 W3: build once, gate those exact files, publish those exact files
  • 127dc9c RELEASE-3 W3: the one home for artifact facts + exact-artifact install smoke
  • f8e9bce RELEASE-FIX-D D0: measure all four F-770 User-Agent leak vectors
  • d57eac7 RELEASE-FIX-E E0: RED-first pins for F-771 (list_tabs after close_tab)
  • 95ddb75 RELEASE-2 W2: route F-773 and land macOS transport as a DECLARED gap
  • ff9339d RELEASE-2 W2: instrument the macOS stall (Chrome's own log + live process tree)
  • 52ac985 RELEASE-2 W2: run the gate workspace under RUNNER_TEMP on CI (macOS single-variable test)
  • d5348d6 RELEASE-FIX-C C2: hermetic pins for the F-772 interception-arming contract
  • c58f51c RELEASE-FIX-C C1: never enable Fetch with nothing to intercept (F-772)
  • 57d3001 RELEASE-FIX-C: plan for F-772 (catch-all Fetch interception hangs macOS navigation)
  • 27df5e3 RELEASE-2 W2: separate paused-Fetch from unreachable-port; back off the cold-launch retry
  • 6dc8f78 RELEASE-2 W2: probe about:blank vs http to isolate the macOS navigate stall
  • 4231dd5 RELEASE-2 W2: record fixture-server hits; drop the flag the product strips
  • 38f16c2 RELEASE-2 W2: pin F-771 (list_tabs after close_tab), dump backend logs on failure
  • 1f1c727 RELEASE-2 W2: warm the page load too, retry the cold launch, mock-keychain on macOS
  • b0e9444 RELEASE-2 W2: absorb macOS Chrome cold start in the journey harness (test-side only)
  • c2b3088 RELEASE-4: acceptance-complete offline stealth probe plus informational detectors (G-D)
  • c56de0b RELEASE-2 W2: fix two defects the first three-OS run exposed (test-side only)
  • f5a2b1b RELEASE-2 W2: move session-root env to step level (runner context invalid at job level)
  • 0ec4393 RELEASE-2: required Ubuntu-x64 Windows-x64 macOS-arm64 release gate (G-B)
  • 8ec46ef RELEASE-2 W2: runner/Chrome resolvers + per-OS lifecycle & identity evidence
  • 11dc582 RELEASE-FIX-B: flip plan status to EXECUTED (C1 f81ff8f, C2 585ebf2)
  • 585ebf2 RELEASE-FIX-B C2 (B1): flip the W1 transport xfail — journey green over real stdio
  • f81ff8f RELEASE-FIX-B C1 (B1): make app_lifespan session-reentrant; bind teardown to process end
  • 6592efe RELEASE-1 W1: land plan_RELEASE_FIX_B (finding B1 triage + fix design)
  • d32a268 RELEASE-1 W1: real-stdio release-gate harness + transport E2E (catches B1)
  • 4a47d0c RELEASE-1: flip plan_RELEASE status to GO (Phase-0 re-proven at 83afe42)
  • 83afe42 Merge pull request #41 from DevinoSolutions/audit/release-fix-a
  • b532b1b RELEASE-FIX-A C8 (A12): pin proxy creds not percent-decoded (fix owned by W-B3)
  • d35fbfa RELEASE-FIX-A C7 (A11): tz-aware UTC defaults for BrowserInstance timestamps
  • 74b297f RELEASE-FIX-A C6 (A4): wire the real JS->Python bindingCalled round-trip
  • c326f19 RELEASE-FIX-A C5 (A7): bound close_instance Phase-2 tab close
  • 76eef80 RELEASE-FIX-A C4 (A3): docs — DESIGN §6 request-store bounding
  • ee53b4d RELEASE-FIX-A C4 (A3): bound retained request count + post_data bytes
  • f3acd9e RELEASE-FIX-A C3 (A6): JSON-encode the $SELECTOR placeholder at the substitution site
  • 96519b9 RELEASE-FIX-A C2 (A5): bind matched_styles for pseudo/inheritance-only styles calls
  • 7d5315b RELEASE-FIX-A C1 (A1): route query_elements/get_page_content select_all through recovery; stop swallowing -32000 into []
  • f20ec5b RELEASE-FIX-A: land Tier-A fix plan + final-review triage
  • 484e143 Merge pull request #40 from DevinoSolutions/audit/release-plan-landing
  • 5ba6a76 Land plan_RELEASE (E2E-9) + MANUAL_QA_PROTOCOL on main
  • 6b41c63 Merge pull request #39 from DevinoSolutions/audit/fixes-2026-07-02-m14
  • f0554ef M14-S8: doc-claim accuracy harness + validation-driven doc fixes
  • 2b81a67 M14-S7: retire stale point-in-time docs to audit/history/
  • a8b4c52 M14-S6: README repair — A1 renames, tool-count=94 provenance, venv-test caveat, doc links
  • 12eb09e M14-S5b: Touch 2 (F-741 A1 X-HARD) — rename colliding CLI 'session' labels + env var
  • 72edc3d M14-S5: Touch 1 (F-108) — derive tool counts from SECTION_TOOLS (option a)
  • 0ce7db8 M14-S4: CONTRIBUTING.md — clone/install/test + the REAL quality gate
  • e04f696 M14-S3: RUNBOOK.md — operator playbooks (verbs, logs, recovery, MCP smoke path)
  • 74d7279 M14-S2: CLAUDE.md — agent navigation map, glossary, conventions, tool-count provenance
  • 1c94dc2 M14-S1: DESIGN.md — architecture invariants, rationale, known-debt ledger
  • b80bd59 Merge pull request #38 from DevinoSolutions/audit/fixes-2026-07-02-m5b
  • 650e728 M5b-6: update progressive-tier E2E for the fix (was @characterization of broken)
  • b15d3c7 M5b-5: delete element_cloner.py; re-point last 2 tools; F-744 docstrings
  • 31bb07d M5b-4b: collapse the 8 _to_file methods to one _extract_and_save (F-141)
  • 0d0a1e2 M5b-4a: re-point file_based at the canonical engine + delete comprehensive
  • 0d95d6e M5b-3b: re-point clone_element_progressive at the canonical engine (F-143)
  • bcde88d M5b-3a: re-point clone_element_complete at the canonical engine
  • d67a26e M5b-2: re-point the 5 aspect tools + extract_complete_element_cdp at the engine
  • fa224fc M5b-1: build canonical extraction engine surface in CDPElementCloner (additive)
  • ac89b81 Merge PR #35: M4-Ph1+A1 server.py decomposition (C1-C5) + nodriver -32000 race fix
  • 6ab8962 fix: recover from nodriver -32000 stale-document race in selector resolution
  • c03b2fe Merge remote-tracking branch 'origin/main' into audit/fixes-2026-07-02-m4ph1
  • 69658ae M4-Ph1: grandfather browser_manager.py at 1532 (C4 spawn_browser seam)
  • 1317aa2 M4-Ph1 C5 _with_cdp_timeout canonical (F-164 server half): one CDP-timeout wrapper, enforced
  • d2ee1bf M4-Ph1 C4 spawn_browser sub-method pipeline (M13/F-208): testable seam, no behavior change
  • 49126ce audit(stage-3): C3b landed (1112dd1) — F-104 CLOSED via human "convert both" ruling; C3a (c52da3c) recorded
  • 1112dd1 M4-Ph1 C3b operation-specific error sweep (F-104 full closure): one raise-ToolError convention, no second way
  • c52da3c M4-Ph1 C3a tool_errors.py + _require_tab/_require_browser + F-761 instance-not-found cluster (F-761/F-746; F-104 mechanical half)
  • 22dd035 audit(stage-3): record C1 landed (2807b41) + C2 idempotency decision (4c0b69e), flagged for merge-gate
  • 4c0b69e M4-Ph1 C2 formalize tool_registry.py (F-101/F-505/F-612): one registration + section-gating mechanism
  • 2807b41 M4-Ph1 C1 extract clone_storage.py (F-201): move the 50-def clone-storage subsystem out of server.py
  • 3f36093 audit(stage-3): C1 LOC-budget ruling recorded — grandfather clone_storage.py @ actual LOC (human, 2026-07-12)
  • 5744b76 M4-Ph1 STEP0 packageize embedded/ + one absolute-import convention (F-701/F-604/F-613)
  • a09a870 audit(stage-3): M12a (PR #33) + E2E-8 (PR #34) merged; M4-Ph1 STEP 0 launched
  • 281ce1c Merge pull request #34 from DevinoSolutions/audit/fixes-2026-07-02-e2e8
  • c21fc04 Merge pull request #33 from DevinoSolutions/audit/fixes-2026-07-02-m12a
  • acb859c E2E-8 fixup: correct stale select_option docstring to match the pinned finding
  • 5b953bf E2E-8 interaction fidelity + completeness characterization (real trusted input, keyboard/form/rich-input/top-layer, unreachable-interaction census)
  • 1cd6451 M12a: honest first-match hook priority (F-163) + delete dead ResponseStageProcessor (F-721/F-742) + coverage ratchet 41->55
  • a565c5c audit(stage-3): E2E-7 merged (PR #32); E2E-8 + M12a launched in parallel
  • c74dae5 Merge pull request #32 from DevinoSolutions/audit/fixes-2026-07-02-harddom
  • c4d9a40 E2E-7 hard-DOM fixture + characterization walks (shadow DOM, iframes, contenteditable, multi-select, SVG/canvas/details)
  • 9675a32 audit(stage-3): plan_E2E merged (PR #31); hard-DOM extension (E2E-7) launched
  • bcfb4e6 Merge pull request #31 from DevinoSolutions/audit/fixes-2026-07-02-e2e
  • e3b0630 E2E-6 settle the post-navigation stale-document-node class systemically (finding 8)
  • a4872de E2E-5 harden two CDP propagation races surfaced by CI (findings 8/9)
  • f41efcf E2E-4 cdp-functions, dynamic-hooks, debugging + manifest + protocol tier (plan_E2E STEP 4)
  • 88d8609 E2E-3 data-tool E2E: network, extraction, progressive, file-extraction (plan_E2E STEP 3)
  • 8a16fb2 E2E-2 interaction E2E: browser-management, tabs, element-interaction, cookies (plan_E2E STEP 2)
  • f3083aa E2E-1 fixture web app + HTTP server fixture + hermetic smoke (plan_E2E STEP 1)
  • 3bc347b audit(stage-3): plan 8/12 merged (PR #30); user-directed E2E fixture-app plan launched
  • 8a7e55d Merge pull request #30 from DevinoSolutions/audit/fixes-2026-07-02-m6
  • 8a01ee8 M6-4 bug-prone tool characterization
  • f80351a M6-3 cloner output characterization (two-tier goldens)
  • 4b865db M6-2 dispatch characterization net
  • f8005c2 M6-1 hermetic tool-invocation harness (tests/fakes.py + conftest fixtures)
  • ddfe22d audit(stage-3): plan 7/12 merged (PR #29), plan 8/12 (M6) launched — bookkeeping
  • 40ec416 Merge pull request #29 from DevinoSolutions/audit/fixes-2026-07-02-m9
  • aba0b1d M9 byte-cap response-body store + capture opt-in default-off (F-605)
  • b225b1b audit(stage-3): plan 6/12 merged (PR #28), plan 7/12 (M9) launched — bookkeeping
  • 8a9a876 Merge pull request #28 from DevinoSolutions/audit/fixes-2026-07-02-m11a-m15
  • 5fcff8d M15 serialize BrowserInstance storage + rename + export constants
  • 07547fa M11a guarded ProcessCleanup init + _file_lock harden + pid-file relocation
  • 5c7dfd8 audit(stage-3): plan 5/12 merged (PR #27), plan 6/12 (M11a+M15) launched — bookkeeping
  • 096228f Merge pull request #27 from DevinoSolutions/audit/fixes-2026-07-02-m7
  • 0481aa8 audit(stage-3): plan 5/12 (M7) executed + reviewed — bookkeeping
  • ab2a124 M7-4 best-effort terminate_execution on python-exec timeout (F-164)
  • 695006e M7-3 get_tab/get_browser default to read-only touch_activity=False (F-745)
  • 0b3a05c M7-2 verify fallback_pid identity on non-recovery cleanup (F-608)
  • e30157e M7-1 offload close_instance kill to a worker thread under a real timeout (F-180)
  • fe1d3a9 audit(stage-3): plan 4/12 merged (PR #26), plan 5/12 (M7) launched — bookkeeping
  • 42229d6 Merge pull request #26 from DevinoSolutions/audit/fixes-2026-07-02-m2
  • ea1fe56 audit(stage-3): plan 4/12 (M2) executed + reviewed — bookkeeping
  • 3d4cf79 M2-3 log source-change eviction via stealth.proxy
  • 73d07ae M2-2 source-fingerprint reuse key (+version-aware test migration)
  • bdd65e9 M2-1 delete hot_reload + reload_status (+orphaned importlib) + deletion test
  • 63340b3 audit(stage-3): plan 3/12 merged (PR #25), plan 4/12 (M2) launched — bookkeeping
  • f2ab545 Merge pull request #25 from DevinoSolutions/audit/fixes-2026-07-02-m8
  • 8f62afe M8-fix: isolate LOCK_FILE in stop/restart test fixtures
  • 1f84188 audit(stage-3): plan 3/12 (M8+A1) executed + reviewed — bookkeeping
  • 95e1fe7 M8-8 restart selects port via _select_backend_port
  • 0cb25e9 M8-7 auto-port-fallback (F-509 spawn survives a squatter)
  • 8e7aba5 M8-6 kill-orphans verb
  • aacf2c9 M8-5 restart verb
  • 369e770 chore: refresh uv.lock to match gates-era pyproject
  • ba10938 M8-4 stop verb
  • 486baff M8-3 status/doctor surface pid+log+port (F-305/F-503/F-509-visibility)
  • 5327d76 M8-2 spawn env-scrub (reaping backend)
  • 31c544e M8-1 extract _terminate_backend
  • 3e4cfde audit(stage-3): plan 2/12 (M1) merged, Criticals closed on main; plan 3/12 (M8+A1) launched — bookkeeping
  • bcde11b Merge pull request #24 from DevinoSolutions/audit/fixes-2026-07-02-m1
  • 6f076b7 audit(stage-3): plan 2/12 (M1) executed + reviewed — bookkeeping
  • f06435b M1-4 status/doctor report responsive/wedged/down
  • f19daf1 M1-3 watchdog default app probe + await-aware + proxy WARNING
  • b0ed83d M1-2 discovery/reuse uses app probe (+version-aware test migration)
  • 44452d2 M1-1 single-shot app probe + LIVENESS_PROBE_TIMEOUT
  • 3c7b60c Merge pull request #23 from DevinoSolutions/audit/fixes-2026-07-02-m10a
  • 8ce700a Merge remote-tracking branch 'origin/main' into audit/fixes-2026-07-02-m10a
  • 37bb34c Merge pull request #22 from DevinoSolutions/audit/fixes-2026-07-02
  • 385e8cb audit(stage-3): plan 1/12 (M3+A1+M10a) executed — bookkeeping
  • 2ae766a M10a-8 regression guard: tests/test_no_silent_excepts.py
  • ffb6670 M10a-7d server.py dispatch silent excepts now log (F-181 rows 15-17)
  • 27c7d20 M10a-7c proxy/platform silent excepts now log (F-181 rows 11-14)
  • b7523b8 M10a-7b network/hooks silent excepts now log (F-181 rows 7-10)
  • 8a1f6db M10a-7a interaction hot path silent excepts now log (F-181 rows 1-6)
  • 81626e1 M10a-0 ring-less log_debug bridge
  • 3049061 M3-review: boot startup line + fail-open boot redirect
  • 77e8bee M3-6 F-204 LRU + F-183 cold-start tracing
  • b812b8b M3-5 correlation id via section_tool
  • f01d3c9 M3-4 debug_logger file bridge (unconditional)
  • 6b36625 M3-3 popen boot-log redirect
  • 54ccbb2 M3-2 backend file logging
  • 2cede1c M3-1 logging_setup module
  • 5e31b98 audit(stage-3): start — parked-items ledger + in-session execution record
  • b8b818e fix(gates): make the suppression-owner gate actually enforce (G-1/G-2) + pin husky (G-4)
  • 6c14b8a audit(phase-2): post-convergence re-audit results
  • c7a2952 chore(audit): re-stamp gates landed block + convergence bookkeeping
  • a482d42 chore(audit): adopt audit corpus into version control
  • e39be31 Merge pull request #21 from DevinoSolutions/fix/singleton-version-aware-backend
  • 9d2fb98 Merge pull request #20 from DevinoSolutions/quality/gates-2026-07-06
  • 6f42084 Merge pull request #13 from DevinoSolutions/chore/bump-v1.2.0
  • 3edac20 ci: rename checks for clarity
  • 3050e26 Merge remote-tracking branch 'origin/main' into quality/gates-2026-07-06
  • 32b52cb fix(ci): install sentry extra in CI + importorskip for optional dep test
  • e5e56ea docs: add opt-in Sentry error reporting setup to README
  • 4087ed8 chore(gates): stamp final HEAD SHA in state.json
  • 75825bb feat(gates): husky hooks + README dev-setup + bookkeeping (FINAL)
  • 491d019 ci(gates): quality job + dev extra pins + cov ratchet to 41
  • b583200 feat(gates): gate scripts — suppression-owner + file-budget checks
  • c63e16b feat(gates): vulture dead-code detection + allowlist
  • 28a9a2f feat(gates): ty strict type checker config + ANN/TID251 per-file-ignores
  • 93ea6a0 chore(gates): owner-tagged ruff suppressions + per-file-ignores
  • 5eefbbc fix(gates): mechanical ruff fixes — DTZ/PTH/SIM/E501/PLR2004/A001/PERF
  • e66acf1 style(gates): mechanical ruff fixes in unowned + M3-surface files
  • be98834 feat(gates): Sentry-ready observability module (off by default)
  • 61df987 refactor(gates): route every env read through the Settings model
  • 3801785 feat(gates): pydantic-settings Settings model - canonical env schema
  • e8e6c23 fix(gates): surface + retain BrowserManager background tasks (ruff RUF006)
  • d253a41 fix(gates): import psutil in server.py - real latent bug (ruff F821)
  • e4a13a4 chore(gates): ruff lint ruleset + banned-API + safe autofixes
  • 712eec3 style(gates): apply ruff format repo-wide
  • 2267b83 fix: don't await synchronous handle_response at 3 extraction call sites
  • 9778218 fix: write clone/screenshot output to a per-user dir, not inside the package
  • 3f08a0c test: cover debug_logger + platform_utils; ratchet coverage gate to 39
  • b7fbefc ci: add coverage gate (fail_under=38) + deps/hygiene
  • 2ab0b69 test: no-mock unit suites for hook/network/proxy/response subsystems
  • e5ced24 feat: recoverable trash-then-purge clone eviction
  • 0e49e26 fix(security): default the HTTP backend to loopback, not all interfaces
  • 04f0204 ci: run unit + integration tests on every pull request, not just main/dev
  • af4225b test: add no-mock E2E regression for over-cap sweep sparing live + legacy profiles
  • 8859d85 fix: reuse only a same-version backend and tear down the proxy when it dies
  • 83c7993 fix: never evict live, in-flight, or legacy-marked clones from the storage sweep
  • 0c4e753 fix: close stdio streams so the entrypoint actually exits on disconnect
  • 313acff docs: pin install to v1.0.0 (v1.1.0 has a known bug)
  • 0a74e09 fix: exit stdio proxy on client disconnect (stops entrypoint process leak)
  • 24eef48 @ chore: bump version to 1.2.0