v0.99.15
Fixed
- Commit journal-backed keyed claim, task-update, release, handoff, checkpoint,
guard-denial, and resource mutations atomically with their canonical request
digest, exact replay response, event sequence range, and operation-evidence
outbox intent. Identical retries now converge after crashes and restarts;
changed-payload key reuse fails with a value-free idempotency conflict. - Keep strict rejection of exponent-overflow JSON while proving bound hub
sessions remain usable after the error; restore the complete A2A HTTP
compatibility re-export, ledger the new platform/optional skips, and retry
the exact JetBrains X11BadDrawabledisappearing-window race. - Generate and ship the permanent
synapse arm installuser-service template
withRestart=always, matching the documented contract so systemd re-arms
the exact-identity mailbox waiter after both clean and non-zero exits.
Security
- Bound semantic Git evidence commands to a ten-second deadline, eight MiB of
stdout, 64 KiB of stderr, isolated child-process teardown, and a minimal
non-interactive environment. Diff reads disable external diff and textconv,
every read disables repository-configured filesystem monitors, source reads
stop after the semantic parser ceiling, diagnostics strip terminal controls,
pipe-reader failures deny partial evidence, and unsafe per-file evidence
widens to a whole-file claim. - Bound file-claim wording to overlapping-grant refusal, documented provider
hook coverage, and the staged Git index gate; unsupported writers, host
fail-open behaviour, exfiltration, and external side effects remain explicit
residual risks rather than claimed guarantees. - Bound both outbound A2A HTTP clients to one MiB per response, 64 JSON nesting
levels, and 4,096 cumulative members without retaining hostile values. JSON
exponent overflow and non-finite receipt values now fail closed; CLI and file
receipts use strict RFC 8259 serialization, and every atomic-write setup step
is contained behind the stable value-free receipt error boundary. - Add
--a2a-token-filetoa2a-serve,a2a-client, and
a2a-interop-trace, backed by the shared same-descriptor owner-only secret
loader. Explicit--a2a-tokenretains precedence without opening the file;
rejected files produce value-free diagnostics. Both outbound clients now
refuse to send a bearer over plaintext HTTP unless the destination is a
literal loopback IP or--a2a-allow-insecure-httpexplicitly accepts the
cleartext risk. - Bind outbound webhook credentials to their exact normalized origin across
redirects. Credential-bearing 301/302/303 responses now fail closed instead
of becoming authenticated GET requests; 307/308 preserve method, body, and
sensitive headers only for the same scheme, canonical lowercase
ASCII/punycode hostname, and effective port; Unicode authority spellings fail
closed instead of relying on ambiguous IDNA mappings. Every HTTPS-to-HTTP
redirect is refused, redirect chains are capped at five, andAuthorization,
Proxy-Authorization,Cookie, andCookie2are recognized
case-insensitively without logging their values. - Enforce the A2A HTTP endpoint's advertised
Hostauthority on every route,
independently of browser Origin configuration. Requests with missing,
malformed, ambiguous, or hostile Host values now fail403before
authentication or routing; requests carryingOriginrequire an explicit
exact--allow-origin, while origin-less clients remain compatible through
the Host boundary. The CLI always derives authorities from--endpoint-url,
and direct HTTP handler construction fails closed without one. - Close the optional, default-off
a2a-serve --grpc-porteffective-policy gap:
the CLI now composes its selected shared bearer, native TLS/mTLS files,
concurrency ceiling, one-MiB request/response bounds, bounded JSON parser,
finite call-deadline ceiling with cancellation of pending hub work, stable
value-free errors, and listener cleanup across bind and start failures into
gRPC. The custom two-method
binding remainspartialprotocol support and the shared bearer is not
per-client identity or a method-level ACL.
Artifact checksums (SHA-256)
f04db219a2fa0b08560ec1cdb108a5795bd7476b4c8173c44f65e6c099b2e034 synapse_channel-0.99.15-py3-none-any.whl
0d8c847c9cb6a2d86f2c95ff5e5a05d44ba54114c98f2dd50b160d0d6da2ca71 synapse_channel-0.99.15.tar.gz
2fd95d0a3c04f87a0ee8d6364b31b37361da6ac0f1904c8a1e3c1da87d655d82 synapse-channel-v0.99.15-sbom.cdx.json