Skip to content

Releases: PM100Fun/NetNavr

v0.2.33

Choose a tag to compare

@PM100Fun PM100Fun released this 27 Sep 03:51
ca6002d

Oversized Core response streams now return invalid_response without waiting for cancellation to settle. Cleanup rejection is handled, and reader locks are released after successful or failed reads.

Regression tests cover pending/rejected cancellation on both endpoints and reader lock release. Workspace tests: 110 passed, 3 expected Windows skips; type checks and Shell build passed; dependency audit 0 vulnerabilities. PR #45 and main CI passed.

v0.2.32

Choose a tag to compare

@PM100Fun PM100Fun released this 26 Sep 18:11
2b7eb1a

Require an exact application/json media type for Core health and node responses. Reject prefix lookalikes such as application/jsonp before parsing and cancel their bodies. Preserve case-insensitive matching and JSON parameters.

Regression reproduced before the fix. Full verify: 108 passed, 3 expected Windows skips. Shell build and dependency audit (0 vulnerabilities) passed. PR #43 and main CI passed.

v0.2.31

Choose a tag to compare

@PM100Fun PM100Fun released this 26 Sep 04:17
000f3e6

Cancel unread Core JSON response bodies when Content-Length is invalid or oversized. Cleanup failures do not replace the original diagnostic or request ID.

Regression coverage spans both health and node endpoints, four rejected lengths, and successful/rejected cancellation. Full workspace verify (106 passed, 3 expected Windows skips), Shell build, and dependency audit (0 vulnerabilities) passed. PR #42 and main CI passed.

v0.2.30

Choose a tag to compare

@PM100Fun PM100Fun released this 25 Sep 03:26
32f2db4

Core health/node response body reads now report offline/timeout when the shared deadline expires, instead of invalid_response. Includes regression coverage for both endpoints.

Validation: full workspace verify, Shell build, and dependency audit passed. PR #41 and main CI passed.

Source release; no production deployment.

v0.2.29

Choose a tag to compare

@PM100Fun PM100Fun released this 23 Sep 01:16
19c8b82

v0.2.29

  • Update workspace version to 0.2.29.
  • Ensure desktop Core status handling cancels unread response bodies for non-2xx and non-JSON responses.
  • Add regression coverage for response-body cleanup.
  • Main CI passed on merge commit 19c8b826f62c8ecb186c2e67604a93255f3a6669.

NetNavr v0.2.28

Choose a tag to compare

@PM100Fun PM100Fun released this 21 Sep 07:19
8e65d16

Shell workspace configuration hardening

  • reject explicitly empty or whitespace-only NETNAVR_SHELL_WORKSPACE values before the standalone Agent Server starts
  • prevent a blank workspace setting from silently falling back to the current directory
  • add regression coverage and document the workspace configuration contract in English and Chinese

Verification

  • PR #39 CI: 2/2 verify jobs passed
  • main CI for 8e65d164f49c0c6bfc82301d5b4b0f4d49c9803b: passed
  • local Core, Pay, Shell Server/Web/Desktop tests and Shell checks/builds passed
  • high-level dependency audit: 0 vulnerabilities

NetNavr v0.2.27

Choose a tag to compare

@PM100Fun PM100Fun released this 20 Sep 16:34
13dcb4c

Shell port configuration hardening

  • reject empty, whitespace-only, decimal, scientific-notation, negative, and out-of-range standalone Shell PORT values before the Agent Server binds
  • add regression coverage for malformed environment values
  • document the validated 0-through-65535 decimal port contract in English and Chinese READMEs

Verification

  • PR #38 CI: 2/2 verify jobs passed
  • main CI for 13dcb4c3daa6b8e1197bb585ac9bb286da667fb2: passed
  • local Core, Pay, Shell Server/Web/Desktop tests and Shell checks/builds passed

NetNavr v0.2.26

Choose a tag to compare

@PM100Fun PM100Fun released this 20 Sep 00:19
c5fc66c

Shell request-target connection handling

NetNavr v0.2.26 closes the Shell diagnostic HTTP connection after returning a structured 400 for a request target that cannot be parsed as a URL. Shell also consumes the invalid request stream before responding, matching the Core and Pay boundary behavior.

Validation

  • PR #37 required verify checks passed before squash merge.
  • Post-merge main CI and tag CI passed on the release commit.
  • A fresh clone from v0.2.26 reran the full workspace verify, Shell build, and high-severity npm audit successfully.
  • On Windows, the existing POSIX-only tests were skipped by their platform guards.

NetNavr v0.2.25

Choose a tag to compare

@PM100Fun PM100Fun released this 19 Sep 08:48
187fa2c

Core request-target connection handling

NetNavr v0.2.25 closes the Core HTTP connection after returning a structured 400 for a request target that cannot be parsed as a URL. Core also consumes the invalid request stream before responding, keeping the boundary explicit and preventing reuse of the malformed-target connection.

Validation

  • PR #36 required verify checks passed before squash merge.
  • Post-merge main CI and tag CI passed on the release commit.
  • A fresh clone from v0.2.25 reran the full workspace verify, Shell build, and high-severity npm audit successfully.
  • On Windows, the existing POSIX-only tests were skipped by their platform guards.

v0.2.24 - Core data directory configuration validation

Choose a tag to compare

@PM100Fun PM100Fun released this 17 Sep 05:47
cd3def9

Changes

  • Reject empty and whitespace-only NETNAVR_CORE_DATA_DIR values before Core opens storage.
  • Move Core environment parsing into a focused, directly tested config module.
  • Preserve the default port/data behavior and exact nonblank data-directory paths.
  • Workspace 0.2.24; bilingual Core capability notes updated.

Verification

  • New regression coverage rejects empty, whitespace-only, and NUL-containing data-directory values and preserves valid paths.
  • Full workspace: 98 passing, 3 expected Windows platform skips.
  • Clean install, npm audit (0 vulnerabilities), TypeScript checks, Shell build, PR #35 CI, main CI, and an independent clone all passed.

Boundaries

Pre-alpha local loopback prototype only. No production deployment, real-funds qualification, schema or recovery changes. Dependabot PR #31 remains separate.