v0.6.0
The hardening release: the findings of a full audit of the code against
other harnesses' bug trackers and the platform documentation, fixed.
Security
- The Model API backend's file tools resolve every path through the file
system before using it: a symbolic link or junction inside the workspace
that leads outside it is refused, for reads as well as writes, and the
search skips such files. Edit Review and the rewind check the same way
before writing a file back. Windows alternate data streams (a.txt:x),
device names (NUL,COM1) and names ending in a dot or a space are
refused. - On the Model API backend, a committed
AGENTS.md,CLAUDE.md, memory
index or project skill that is a link leading outside the workspace is
skipped, with the reason in the log; its target used to reach the model. - Protected writes: on the Model API backend, writing git's hooks and
config,.husky,.vscode,.idea,.devcontainer, CI workflows,
.agents,AGENTS.md,CLAUDE.md,.envrcor.gitmodulesshows an
approval card in every mode but Bypass, whatever the session's "always
allow" rules say. Auto used to write them without asking. - No
gitin Restricted Mode: a repository's own.git/configcan name
programs git runs, and the@mention index and the Model API prompt ran
git status and log on the first message in an untrusted folder. git, bash
and PowerShell are now started by absolute path from absolutePATH
entries only (never a copy inside the workspace), and the Muse Code CLI
search skips empty and relativePATHentries too; a relative
museBinaryPathis refused. git runs with a 15-second timeout and without
taking the index lock (GIT_OPTIONAL_LOCKS=0). - "Always allow in this session" on a shell command now allows that exact
command line, not every later command. An approval choice the card never
offered is refused instead of counting as a yes. - Bypass permissions ends in every open conversation as soon as
allowDangerouslySkipPermissionsis turned off. In a remote window (where
a dev container definition can write machine settings) a conversation
never starts in Bypass, and entering it asks once. - Resuming a conversation that ran on a contributor-tier model asks as
choosing one does, or, in a confidential workspace, moves it to a
standard model. - The shell tool's environment drops the editor's internal variables
(ELECTRON_RUN_AS_NODE,VSCODE_*IPC handles) exactly as VS Code's own
terminal does, and Windows PowerShell gets its own module path. - The log redacts JWTs, basic credentials, token and password fields and
credentials in URLs; amuse servestderr chunk is capped in the log;
the diagnostics report writes the home directory as~. - The release workflow checks the tag (manifest version, on
main) before
building, hands the Marketplace token to one step after an install that
runs no package scripts, and keeps no token in checkouts. npm auditstill blocks releases, with a reviewed, expiring exception
list for advisories that have no fix.
Added
THIRD_PARTY_NOTICES.txtships in the package.museSpark.cleanupPeriodDays(default 30, as Claude Code's
cleanupPeriodDays): Model API conversations idle longer are deleted
when a window lists them; 0 keeps them.
Fixed
- Edit automatically now does what it says: plain file-write approvals
are answered for you (the row says "Edit automatically"); protected
writes, escalations and commands still show the card. It behaved like
Manual before. - The
searchandlist_filesglob no longer builds a regular expression:
a crafted 37-character pattern held the extension host for 25 seconds.
Matching is linear,[!x]negates and braces nest. - The Modes menu describes each mode truthfully per backend (Muse Code's
Manual applies in-workspace edits without asking; the Model API's Auto
has no safety-check model). - On Windows the focus and new-tab shortcuts are
Ctrl+Alt+Escand
Ctrl+Shift+Alt+Esc; Windows takesCtrl+EscandCtrl+Shift+Esc
itself. The walkthrough, the getting-started tips and the composer's
placeholder name them. - Dictation says why it is unavailable in a remote window; the Windows
helper no longer inherits PowerShell 7's module path; a write to a dead
helper no longer throws. - On macOS, dictation names the app macOS asks, separates speech from
microphone refusals, and explains an early exit. - The crash screen's Reload brings the conversation back as it was: the
transcript, a waiting approval or question and the running turn. A state
that crashes the panel twice is dropped instead of looping. - A stopped or failed turn no longer leaves the reply streaming, tools
running or cards clickable; a tool it cut off reads "Interrupted". - "Rewind code to here" no longer unwinds a subagent's earlier edits after
the Agent map has read the agent's transcript. - New Conversation from its keybinding clears the panel too, and acts on
the panel you last used. - With an input method (Chinese, Japanese, Korean), Enter commits the
candidate instead of sending the message or picking a mention. - Typing and streaming no longer re-render the whole transcript; a code
block being written is highlighted once, when it is complete. - A resumed conversation's thoughts read "Thought", not "Thinking…".
- The transcript stays at the end when its content grows without a new row.
- A tab restored after a window reload keeps its conversation until the
resume succeeds. - A refused message's images no longer linger unseen in the panel's host;
they come back to the composer when the host still holds them. - A question card posts one answer however often Submit is pressed, and
opens again when the answer is refused. - Screen readers get one announcement per event.
- Dialogs keep Tab inside and the chat behind them is inert; message menus
close on a click outside; right-click on a selection offers Copy. - The History dialog's keys keep working after Show archived.
- Images over 10 MB, or past 20, are refused before they are read, and the
banner says why. - Relative links in a reply open the workspace file at the lines they name.
- Right-to-left text reads right to left.
- Reduced motion stops every animation.
- Tasks with the same text no longer collide; approval feedback starts empty
on each step; Windows line ends no longer show in diffs; diffs over 256 KB
keep their line numbers. - A shell command that times out or is stopped now ends with everything it
started (a process group on macOS and Linux,taskkill /Ton Windows),
and a command that leaves a background process running (server &)
returns when it exits instead of holding the turn open; Stop reaches a
running command. A flood of output keeps its beginning and its end. On
Windows each command runs in a job object of its own, so Stop and a
timeout end everything it started at once, including a program it was
starting at that moment and one a launcher left behind (taskkillmissed
those: they ran on, and one stayed suspended for good); a command that
ends normally still leaves its background processes running. Where
Windows policy forbids the job helper, the log says so and a sweep of the
process table stands in. - A restart the extension makes (trust granted, a setting changed, a
sign-in) no longer looks like a crash that blocks every panel: the running
turn is cancelled, and the next message continues the same conversation.
After a real crash the turn ends with the reason and the next message
restarts Muse Code and continues; only an exit that restarting cannot fix
(a configuration Muse Code refuses, a build without the SDK surface) is
shown as an error. - Muse Code gets deadlines: 30 seconds to start, 60 per command (three
minutes to load, copy or compact a session), so a wedged CLI no longer
hangs sign-in, switching or sign-out. - When Muse Code closes or evicts a session, the next message resumes it
instead of failing; two quick messages start one session; two panels on
the same session no longer silence (or, on the Model API backend, cancel)
each other when one closes; a panel closed while its session starts keeps
nothing running. - Signing in with the browser waits for a new sign-in, not a stale
credential file, and pressing the button twice opens one terminal; a
broken OS keyring no longer blocks the Muse Code backend. - Model API retries show in the transcript ("Attempt 2/5 failed …"), Stop
cuts a retry wait short, and aRetry-Aftergiven as a date is honoured. - The IDE tool server restarts if its first start failed, and the session
that needed it waits for it; a failing request answers 500. - New Conversation after a crash or a restart starts a new session
instead of continuing the old one with its first message. - Resuming a conversation that was waiting on an approval or a question
shows its card again, and a turn that was running when you resumed can be
stopped and steered. Each prompt shows one card, however often Muse Code
announces it, and a second panel on the same conversation sees the cards
still open. - A decision or answer that arrives after the request moved on says so as
information instead of an error; a refused decision opens the card again;
a request Muse Code no longer holds loses its card. A step already closed
by an "always" decision is no longer asked again. - Updates Muse Code could not deliver are recovered by reloading the
conversation; a queued message Muse Code withdrew reads "Not sent"; a
model the account cannot serve, and a message another client withdrew,
are notices. Unexpected notifications are logged once each. - On the Model API backend, a tool that fails (a missing folder, a disk
error) or a call Stop cuts off no longer breaks the rest of the
conversation;write_filecreates the folders it needs; a message typed
while the final answer streams gets its own answer; a compaction runs as
a turn, so messages sent meanwhile wait and Stop cancels it; Stop ends
each queued message with a reason; a refusal shows its words. - Account & usage shows the conversation's totals on both backends (Muse
Code showed the last request only); the cached rows appear where they can
be counted. - A message too large for Muse Code (10 MiB, images included) is refused
with the reason instead of hanging; its images stay in the composer. - Output pages and Revert patches no longer break a character in two; a
binary output says so instead of showing base64. - The Model API stream tolerates
data: [DONE], empty keep-alives and a
line break split across two reads. - Revert and Rewind code no longer trash a file after an edit that
only added lines to it (such as an import at the top); a created file you
have added to since keeps your lines; lines an edit deleted are put back
only where the file still matches, never at a line that moved; a file's
BOM survives. - On the Model API backend, edits keep a file's Windows line breaks, BOM and
final line break, and a multi-line change matches a CRLF file; a file
that is not UTF-8 text (binary, UTF-16, Latin-1) is refused instead of
rewritten; a file with unsaved editor changes is left alone;write_file
replaces an existing file only after reading it; writes are atomic, go
through a symbolic link to the file it leads to, keep a script's
permissions and refuse a read-only file. - A shell command's flood of output keeps its end and its exit line; a
search that runs out of time returns what it found; Windows PowerShell
output is UTF-8, so accents and symbols no longer come back garbled. - With autosave off, the panel names the files whose unsaved changes Muse
will not see. - Edit Review without an open folder says to open it, instead of resolving
paths against the extension's own directory. - On the Model API backend, rules files (
AGENTS.md,CLAUDE.md), skill
files and the memory index saved as UTF-16 (as Windows PowerShell's>
writes them) load correctly; one that is not text is skipped with a line
in the log, and no longer hides the other skills. Skill folders that are
symbolic links or junctions load. - The Problems-panel tool reports only the workspace's files, by relative
path, shortens very long messages, and answers a malformed request with an
error. @mentions of paths with spaces,#or quotes are written in quotes
(@"my notes/a b.md"#5-10), and the mention menu searches names with
spaces.- Multi-root workspaces: the first folder is the root for the open-file
chip, the mention list and search, drops, diagnostics and file links; a
file in another folder is mentioned by its absolute path. - Files dropped onto the panel in a remote window (SSH, WSL, containers)
are mapped as VS Code's own URI transformer maps them, so they insert
mentions; this is unit-tested, not yet tried in a real remote window.
Changed
- Integration tests run on the latest VS Code and on the 1.125 floor;
semgrep and PSScriptAnalyzer are pinned (its install from the PowerShell
Gallery tried three times); every CI job has a timeout; four
commands are hidden from the Command Palette where they cannot act; the
categories are AI and Chat. museSpark.museBinaryPath,museSpark.environmentVariablesand VS
Code'shttp.proxy/http.noProxyrestart Muse Code when changed; the
proxy is handed to it when neither its environment nor
museSpark.environmentVariablessets one, in any case.- On Windows with Muse Code 1.3.0, which refuses both, the panel no longer
offers Rename and Fork (meta-models/muse-code-sdk#30, #31); "Rewind code
to here" stays. - The Model API backend keeps only its conversations' list in memory and
reads a conversation when it is opened; a file a crash left half-written
is removed, and a save Windows briefly refuses is tried again. - Muse Code commands no longer stay in memory after they are answered (the
SDK kept every one, images included, for the life of the process). - The Model API shell tool applies
terminal.integrated.env.*as VS Code's
terminal does. - On Windows the CLI always starts as
muse-bin-<version>.exe(the newest
one when.muse-versionis missing), never through its PowerShell
launcher, which left the CLI running when closed. - The sign-in and TUI terminals use
/bin/shoff Windows, whatever the
default shell. - The CLI's credential file, settings file and personal skills are looked
up where the CLI itself looks, including anXDG_CONFIG_HOMEset in
museSpark.environmentVariables. - The extension stops Muse Code in
deactivate, awaited by VS Code.