v3.0.3 — the bridge holds up at its edges
The bridge holds up at its edges
An end-to-end audit drove the stdio server against real agy and a hostile fake, and found about fifty ways it could leak work, repeat a write, or report the wrong thing. Each fix ships with a test that failed before it.
- Disconnect and SIGTERM now kill running agy. Before, a client that quit left detached agy runs going with permissions skipped. The bridge also exits when stdin closes.
- A run is repeated only if the tree is provably unchanged. Network retries, quota failover and warm-session fallbacks used to re-send a write that may already have landed. They now report
Not retriedorNot failed overinstead. - The read-only check sees more. It fingerprints contents, modes and untracked files across
cwdand every added directory. Files git ignores are still not covered. AGY_ALLOWED_ROOTSresolves paths the way the OS does.root/link/..can no longer escape through a symlink.- Errors say what happened. A missing
cwdis no longer reported as agy not installed, and a stray429or401in agy's log no longer triggers quota or login handling. - Inputs are bounded. Blank prompts, prompts too large for argv, ids starting with
-, oversized fan-outs and timeouts too large for Node's timers are rejected up front. - Smaller fixes. A 60s floor on quota cooldowns, a pinned model bypasses its cooldown, usage of failed attempts is counted, logs live in a private per-process directory, and the cooldown store survives concurrent writers.
Update the skills with:
npx --package @pymodel/claude-agy-mcp claude-agy-mcp-install-skillsFull changelog: v3.0.2...v3.0.3