v6.2.0 — full code audit: reliability, security ordering, real test suite
A full audit of the codebase (~9,500 lines) drove this release: two classes of live bug fixed, a security guard that only existed in dead code wired into the live path, ~900 lines of dead code removed, and the placeholder test replaced with a 30-test suite.
Fixed
- MCP protocol corruption —
DatabaseManagerlogged to stdout (the JSON-RPC channel), including on everyexecute_command. All logging now goes to stderr. - Pipe deadlocks — every spawn site waited for exit before reading pipes; children writing > ~64 KB deadlocked permanently. New shared
runProcess()drains pipes concurrently. - Unbounded hangs — execution timeouts added everywhere (pipeline/SSH 600s, file-watch 300s, AppleScript 30s) with SIGTERM → SIGKILL escalation; blocking waits moved off the Swift cooperative pool.
- Interactive-command guard now runs on the live execute path —
vim, baressh,topetc. are blocked with a helpful message instead of hanging the capture script. Pipe-spanning patterns (curl … | sh) can now match. - Security ordering — blocked commands were saved to history before the block check (recorded as executed). Checks now run first and cover the full command including the
cdprefix;working_directoryis escaped against quote-breakout. - Database hardening — serial queue +
SQLITE_OPEN_FULLMUTEX, NULL-handle guards,PRAGMA user_versionschema versioning, and retention cleanup that actually runs at startup (commands + analytics; the cleanup paths previously had no callers). - FileWatcher — suspended-source cancel crash, unbalanced suspend/resume, and actor-blocking command execution all fixed.
- Schema/handler mismatches —
open_terminal_tabhonoursworking_directory; numeric parameters accept JSON numbers as declared.
Removed
- The vestigial
--port/-poption (the TCP listener it configured was retired in v6.0). Remove it from your MCP configargsif present.
Tests
- 30-test suite: detector table tests, DB round-trips + 50-writer concurrency, large-output no-deadlock proof, timeout termination, live injection-prevention check, output-capture script executed for real.
Upgrading: rebuild with ./build.sh, then rm -rf "/Applications/Claude Command Runner.app" && cp -R .build/release/claude-command-runner.app "/Applications/Claude Command Runner.app" and restart Claude Desktop. TCC grants persist if you sign with the same identity.
See CHANGELOG.md for the full list.