Skip to content

v0.6.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 01:49
· 402 commits to main since this release

The hardening release: the findings of a full audit of the code against
other harnesses' bug trackers and the platform documentation, fixed.

Security

  • The Model API backend's file tools resolve every path through the file
    system before using it: a symbolic link or junction inside the workspace
    that leads outside it is refused, for reads as well as writes, and the
    search skips such files. Edit Review and the rewind check the same way
    before writing a file back. Windows alternate data streams (a.txt:x),
    device names (NUL, COM1) and names ending in a dot or a space are
    refused.
  • On the Model API backend, a committed AGENTS.md, CLAUDE.md, memory
    index or project skill that is a link leading outside the workspace is
    skipped, with the reason in the log; its target used to reach the model.
  • Protected writes: on the Model API backend, writing git's hooks and
    config, .husky, .vscode, .idea, .devcontainer, CI workflows,
    .agents, AGENTS.md, CLAUDE.md, .envrc or .gitmodules shows an
    approval card in every mode but Bypass, whatever the session's "always
    allow" rules say. Auto used to write them without asking.
  • No git in Restricted Mode: a repository's own .git/config can name
    programs git runs, and the @ mention index and the Model API prompt ran
    git status and log on the first message in an untrusted folder. git, bash
    and PowerShell are now started by absolute path from absolute PATH
    entries only (never a copy inside the workspace), and the Muse Code CLI
    search skips empty and relative PATH entries too; a relative
    museBinaryPath is refused. git runs with a 15-second timeout and without
    taking the index lock (GIT_OPTIONAL_LOCKS=0).
  • "Always allow in this session" on a shell command now allows that exact
    command line, not every later command. An approval choice the card never
    offered is refused instead of counting as a yes.
  • Bypass permissions ends in every open conversation as soon as
    allowDangerouslySkipPermissions is turned off. In a remote window (where
    a dev container definition can write machine settings) a conversation
    never starts in Bypass, and entering it asks once.
  • Resuming a conversation that ran on a contributor-tier model asks as
    choosing one does, or, in a confidential workspace, moves it to a
    standard model.
  • The shell tool's environment drops the editor's internal variables
    (ELECTRON_RUN_AS_NODE, VSCODE_* IPC handles) exactly as VS Code's own
    terminal does, and Windows PowerShell gets its own module path.
  • The log redacts JWTs, basic credentials, token and password fields and
    credentials in URLs; a muse serve stderr chunk is capped in the log;
    the diagnostics report writes the home directory as ~.
  • The release workflow checks the tag (manifest version, on main) before
    building, hands the Marketplace token to one step after an install that
    runs no package scripts, and keeps no token in checkouts.
  • npm audit still blocks releases, with a reviewed, expiring exception
    list for advisories that have no fix.

Added

  • THIRD_PARTY_NOTICES.txt ships in the package.
  • museSpark.cleanupPeriodDays (default 30, as Claude Code's
    cleanupPeriodDays): Model API conversations idle longer are deleted
    when a window lists them; 0 keeps them.

Fixed

  • Edit automatically now does what it says: plain file-write approvals
    are answered for you (the row says "Edit automatically"); protected
    writes, escalations and commands still show the card. It behaved like
    Manual before.
  • The search and list_files glob no longer builds a regular expression:
    a crafted 37-character pattern held the extension host for 25 seconds.
    Matching is linear, [!x] negates and braces nest.
  • The Modes menu describes each mode truthfully per backend (Muse Code's
    Manual applies in-workspace edits without asking; the Model API's Auto
    has no safety-check model).
  • On Windows the focus and new-tab shortcuts are Ctrl+Alt+Esc and
    Ctrl+Shift+Alt+Esc; Windows takes Ctrl+Esc and Ctrl+Shift+Esc
    itself. The walkthrough, the getting-started tips and the composer's
    placeholder name them.
  • Dictation says why it is unavailable in a remote window; the Windows
    helper no longer inherits PowerShell 7's module path; a write to a dead
    helper no longer throws.
  • On macOS, dictation names the app macOS asks, separates speech from
    microphone refusals, and explains an early exit.
  • The crash screen's Reload brings the conversation back as it was: the
    transcript, a waiting approval or question and the running turn. A state
    that crashes the panel twice is dropped instead of looping.
  • A stopped or failed turn no longer leaves the reply streaming, tools
    running or cards clickable; a tool it cut off reads "Interrupted".
  • "Rewind code to here" no longer unwinds a subagent's earlier edits after
    the Agent map has read the agent's transcript.
  • New Conversation from its keybinding clears the panel too, and acts on
    the panel you last used.
  • With an input method (Chinese, Japanese, Korean), Enter commits the
    candidate instead of sending the message or picking a mention.
  • Typing and streaming no longer re-render the whole transcript; a code
    block being written is highlighted once, when it is complete.
  • A resumed conversation's thoughts read "Thought", not "Thinking…".
  • The transcript stays at the end when its content grows without a new row.
  • A tab restored after a window reload keeps its conversation until the
    resume succeeds.
  • A refused message's images no longer linger unseen in the panel's host;
    they come back to the composer when the host still holds them.
  • A question card posts one answer however often Submit is pressed, and
    opens again when the answer is refused.
  • Screen readers get one announcement per event.
  • Dialogs keep Tab inside and the chat behind them is inert; message menus
    close on a click outside; right-click on a selection offers Copy.
  • The History dialog's keys keep working after Show archived.
  • Images over 10 MB, or past 20, are refused before they are read, and the
    banner says why.
  • Relative links in a reply open the workspace file at the lines they name.
  • Right-to-left text reads right to left.
  • Reduced motion stops every animation.
  • Tasks with the same text no longer collide; approval feedback starts empty
    on each step; Windows line ends no longer show in diffs; diffs over 256 KB
    keep their line numbers.
  • A shell command that times out or is stopped now ends with everything it
    started (a process group on macOS and Linux, taskkill /T on Windows),
    and a command that leaves a background process running (server &)
    returns when it exits instead of holding the turn open; Stop reaches a
    running command. A flood of output keeps its beginning and its end. On
    Windows each command runs in a job object of its own, so Stop and a
    timeout end everything it started at once, including a program it was
    starting at that moment and one a launcher left behind (taskkill missed
    those: they ran on, and one stayed suspended for good); a command that
    ends normally still leaves its background processes running. Where
    Windows policy forbids the job helper, the log says so and a sweep of the
    process table stands in.
  • A restart the extension makes (trust granted, a setting changed, a
    sign-in) no longer looks like a crash that blocks every panel: the running
    turn is cancelled, and the next message continues the same conversation.
    After a real crash the turn ends with the reason and the next message
    restarts Muse Code and continues; only an exit that restarting cannot fix
    (a configuration Muse Code refuses, a build without the SDK surface) is
    shown as an error.
  • Muse Code gets deadlines: 30 seconds to start, 60 per command (three
    minutes to load, copy or compact a session), so a wedged CLI no longer
    hangs sign-in, switching or sign-out.
  • When Muse Code closes or evicts a session, the next message resumes it
    instead of failing; two quick messages start one session; two panels on
    the same session no longer silence (or, on the Model API backend, cancel)
    each other when one closes; a panel closed while its session starts keeps
    nothing running.
  • Signing in with the browser waits for a new sign-in, not a stale
    credential file, and pressing the button twice opens one terminal; a
    broken OS keyring no longer blocks the Muse Code backend.
  • Model API retries show in the transcript ("Attempt 2/5 failed …"), Stop
    cuts a retry wait short, and a Retry-After given as a date is honoured.
  • The IDE tool server restarts if its first start failed, and the session
    that needed it waits for it; a failing request answers 500.
  • New Conversation after a crash or a restart starts a new session
    instead of continuing the old one with its first message.
  • Resuming a conversation that was waiting on an approval or a question
    shows its card again, and a turn that was running when you resumed can be
    stopped and steered. Each prompt shows one card, however often Muse Code
    announces it, and a second panel on the same conversation sees the cards
    still open.
  • A decision or answer that arrives after the request moved on says so as
    information instead of an error; a refused decision opens the card again;
    a request Muse Code no longer holds loses its card. A step already closed
    by an "always" decision is no longer asked again.
  • Updates Muse Code could not deliver are recovered by reloading the
    conversation; a queued message Muse Code withdrew reads "Not sent"; a
    model the account cannot serve, and a message another client withdrew,
    are notices. Unexpected notifications are logged once each.
  • On the Model API backend, a tool that fails (a missing folder, a disk
    error) or a call Stop cuts off no longer breaks the rest of the
    conversation; write_file creates the folders it needs; a message typed
    while the final answer streams gets its own answer; a compaction runs as
    a turn, so messages sent meanwhile wait and Stop cancels it; Stop ends
    each queued message with a reason; a refusal shows its words.
  • Account & usage shows the conversation's totals on both backends (Muse
    Code showed the last request only); the cached rows appear where they can
    be counted.
  • A message too large for Muse Code (10 MiB, images included) is refused
    with the reason instead of hanging; its images stay in the composer.
  • Output pages and Revert patches no longer break a character in two; a
    binary output says so instead of showing base64.
  • The Model API stream tolerates data: [DONE], empty keep-alives and a
    line break split across two reads.
  • Revert and Rewind code no longer trash a file after an edit that
    only added lines to it (such as an import at the top); a created file you
    have added to since keeps your lines; lines an edit deleted are put back
    only where the file still matches, never at a line that moved; a file's
    BOM survives.
  • On the Model API backend, edits keep a file's Windows line breaks, BOM and
    final line break, and a multi-line change matches a CRLF file; a file
    that is not UTF-8 text (binary, UTF-16, Latin-1) is refused instead of
    rewritten; a file with unsaved editor changes is left alone; write_file
    replaces an existing file only after reading it; writes are atomic, go
    through a symbolic link to the file it leads to, keep a script's
    permissions and refuse a read-only file.
  • A shell command's flood of output keeps its end and its exit line; a
    search that runs out of time returns what it found; Windows PowerShell
    output is UTF-8, so accents and symbols no longer come back garbled.
  • With autosave off, the panel names the files whose unsaved changes Muse
    will not see.
  • Edit Review without an open folder says to open it, instead of resolving
    paths against the extension's own directory.
  • On the Model API backend, rules files (AGENTS.md, CLAUDE.md), skill
    files and the memory index saved as UTF-16 (as Windows PowerShell's >
    writes them) load correctly; one that is not text is skipped with a line
    in the log, and no longer hides the other skills. Skill folders that are
    symbolic links or junctions load.
  • The Problems-panel tool reports only the workspace's files, by relative
    path, shortens very long messages, and answers a malformed request with an
    error.
  • @ mentions of paths with spaces, # or quotes are written in quotes
    (@"my notes/a b.md"#5-10), and the mention menu searches names with
    spaces.
  • Multi-root workspaces: the first folder is the root for the open-file
    chip, the mention list and search, drops, diagnostics and file links; a
    file in another folder is mentioned by its absolute path.
  • Files dropped onto the panel in a remote window (SSH, WSL, containers)
    are mapped as VS Code's own URI transformer maps them, so they insert
    mentions; this is unit-tested, not yet tried in a real remote window.

Changed

  • Integration tests run on the latest VS Code and on the 1.125 floor;
    semgrep and PSScriptAnalyzer are pinned (its install from the PowerShell
    Gallery tried three times); every CI job has a timeout; four
    commands are hidden from the Command Palette where they cannot act; the
    categories are AI and Chat.
  • museSpark.museBinaryPath, museSpark.environmentVariables and VS
    Code's http.proxy / http.noProxy restart Muse Code when changed; the
    proxy is handed to it when neither its environment nor
    museSpark.environmentVariables sets one, in any case.
  • On Windows with Muse Code 1.3.0, which refuses both, the panel no longer
    offers Rename and Fork (meta-models/muse-code-sdk#30, #31); "Rewind code
    to here" stays.
  • The Model API backend keeps only its conversations' list in memory and
    reads a conversation when it is opened; a file a crash left half-written
    is removed, and a save Windows briefly refuses is tried again.
  • Muse Code commands no longer stay in memory after they are answered (the
    SDK kept every one, images included, for the life of the process).
  • The Model API shell tool applies terminal.integrated.env.* as VS Code's
    terminal does.
  • On Windows the CLI always starts as muse-bin-<version>.exe (the newest
    one when .muse-version is missing), never through its PowerShell
    launcher, which left the CLI running when closed.
  • The sign-in and TUI terminals use /bin/sh off Windows, whatever the
    default shell.
  • The CLI's credential file, settings file and personal skills are looked
    up where the CLI itself looks, including an XDG_CONFIG_HOME set in
    museSpark.environmentVariables.
  • The extension stops Muse Code in deactivate, awaited by VS Code.