Releases: PM100Fun/NetNavr
Release list
v0.2.33
Oversized Core response streams now return invalid_response without waiting for cancellation to settle. Cleanup rejection is handled, and reader locks are released after successful or failed reads.
Regression tests cover pending/rejected cancellation on both endpoints and reader lock release. Workspace tests: 110 passed, 3 expected Windows skips; type checks and Shell build passed; dependency audit 0 vulnerabilities. PR #45 and main CI passed.
v0.2.32
Require an exact application/json media type for Core health and node responses. Reject prefix lookalikes such as application/jsonp before parsing and cancel their bodies. Preserve case-insensitive matching and JSON parameters.
Regression reproduced before the fix. Full verify: 108 passed, 3 expected Windows skips. Shell build and dependency audit (0 vulnerabilities) passed. PR #43 and main CI passed.
v0.2.31
Cancel unread Core JSON response bodies when Content-Length is invalid or oversized. Cleanup failures do not replace the original diagnostic or request ID.
Regression coverage spans both health and node endpoints, four rejected lengths, and successful/rejected cancellation. Full workspace verify (106 passed, 3 expected Windows skips), Shell build, and dependency audit (0 vulnerabilities) passed. PR #42 and main CI passed.
v0.2.30
Core health/node response body reads now report offline/timeout when the shared deadline expires, instead of invalid_response. Includes regression coverage for both endpoints.
Validation: full workspace verify, Shell build, and dependency audit passed. PR #41 and main CI passed.
Source release; no production deployment.
v0.2.29
v0.2.29
- Update workspace version to 0.2.29.
- Ensure desktop Core status handling cancels unread response bodies for non-2xx and non-JSON responses.
- Add regression coverage for response-body cleanup.
- Main CI passed on merge commit
19c8b826f62c8ecb186c2e67604a93255f3a6669.
NetNavr v0.2.28
Shell workspace configuration hardening
- reject explicitly empty or whitespace-only
NETNAVR_SHELL_WORKSPACEvalues before the standalone Agent Server starts - prevent a blank workspace setting from silently falling back to the current directory
- add regression coverage and document the workspace configuration contract in English and Chinese
Verification
- PR #39 CI: 2/2
verifyjobs passed - main CI for
8e65d164f49c0c6bfc82301d5b4b0f4d49c9803b: passed - local Core, Pay, Shell Server/Web/Desktop tests and Shell checks/builds passed
- high-level dependency audit: 0 vulnerabilities
NetNavr v0.2.27
Shell port configuration hardening
- reject empty, whitespace-only, decimal, scientific-notation, negative, and out-of-range standalone Shell
PORTvalues before the Agent Server binds - add regression coverage for malformed environment values
- document the validated
0-through-65535decimal port contract in English and Chinese READMEs
Verification
- PR #38 CI: 2/2
verifyjobs passed - main CI for
13dcb4c3daa6b8e1197bb585ac9bb286da667fb2: passed - local Core, Pay, Shell Server/Web/Desktop tests and Shell checks/builds passed
NetNavr v0.2.26
Shell request-target connection handling
NetNavr v0.2.26 closes the Shell diagnostic HTTP connection after returning a structured 400 for a request target that cannot be parsed as a URL. Shell also consumes the invalid request stream before responding, matching the Core and Pay boundary behavior.
Validation
- PR #37 required
verifychecks passed before squash merge. - Post-merge
mainCI and tag CI passed on the release commit. - A fresh clone from
v0.2.26reran the full workspace verify, Shell build, and high-severity npm audit successfully. - On Windows, the existing POSIX-only tests were skipped by their platform guards.
NetNavr v0.2.25
Core request-target connection handling
NetNavr v0.2.25 closes the Core HTTP connection after returning a structured 400 for a request target that cannot be parsed as a URL. Core also consumes the invalid request stream before responding, keeping the boundary explicit and preventing reuse of the malformed-target connection.
Validation
- PR #36 required
verifychecks passed before squash merge. - Post-merge
mainCI and tag CI passed on the release commit. - A fresh clone from
v0.2.25reran the full workspace verify, Shell build, and high-severity npm audit successfully. - On Windows, the existing POSIX-only tests were skipped by their platform guards.
v0.2.24 - Core data directory configuration validation
Changes
- Reject empty and whitespace-only NETNAVR_CORE_DATA_DIR values before Core opens storage.
- Move Core environment parsing into a focused, directly tested config module.
- Preserve the default port/data behavior and exact nonblank data-directory paths.
- Workspace 0.2.24; bilingual Core capability notes updated.
Verification
- New regression coverage rejects empty, whitespace-only, and NUL-containing data-directory values and preserves valid paths.
- Full workspace: 98 passing, 3 expected Windows platform skips.
- Clean install, npm audit (0 vulnerabilities), TypeScript checks, Shell build, PR #35 CI, main CI, and an independent clone all passed.
Boundaries
Pre-alpha local loopback prototype only. No production deployment, real-funds qualification, schema or recovery changes. Dependabot PR #31 remains separate.