Skip to content

v0.19.47

Choose a tag to compare

@TruVerifAI TruVerifAI released this 17 Sep 23:29
· 2 commits to main since this release

0.19.47 — FW1 test-round fixes: sandbox-honest doctor, codex config repair, complete uninstall

Client-only (no server change). Fixes surfaced by the 0.19.46 prod test round.

doctor

  • Every home-resolution site honors TVAI_HOME_OVERRIDE; the macOS Keychain probes are skipped under it. A sandboxed run no longer compares its fresh key against the real machine's configs (which produced false tools config STALE rows and exit 1). A pinning test bans raw os.homedir().

codex

  • A hand-added [mcp_servers.truverifai.*] subtable with no parent table made codex's ENTIRE config unloadable ("invalid transport"), breaking every codex plugin command. uninstall now removes the whole mcp_servers.truverifai namespace; init repairs the dangling state before any codex command (comment-tolerant parent detection); doctor flags it; the failure copy is honest.

uninstall

  • Also deletes host-added Bash(npx @truverifai/init:*) permission rules, and removes the Claude Code and Codex plugins via their own CLIs when available (best-effort, printed; desktop app gets the in-app step). Names its survivors. A 401 on a re-run revoke reads as "already revoked or not valid for this server", never a false verified-success.

smaller

  • The "blocked BEFORE it ran" deny note is unconditional (a chained command's prefix also never ran); the human-decision ask states the same.
  • Consent prompt: a mixed bad answer reports all problem classes in one message; a separators-only answer re-prompts.
  • The /panel-review FAQ renders repo URLs as links.

Published with provenance (OIDC, no token).