scode v0.2.0
What's new
Added
- JSON audit log header — Log files now start with a machine-readable
#json:line containing session metadata (command, blocked/allowed paths, timestamps). Extract withhead -1 log | sed 's/^#json://' | jq .. Legacy comment header preserved for backward compatibility. - Property-based JS test suite — 82 tests for the shell tokenizer and
--no-sandboxinjector using fast-check (test/no-sandbox.test.js). make test-jstarget —make testnow runs both JS and bats suites. Gracefully skips when Node < 18.13 ornode_modulesis missing; setSCODE_REQUIRE_JS_TESTS=1to force failure in CI.- Exhaustive YAML parser edge-case matrix (12 new tests).
- Exhaustive audit-log parser edge-case matrix (17 new tests).
Fixed
--blocknow deniesprocess-execon macOS — previously only deniedfile-read*/file-write*, so a blocked binary could still be executed. Now blocks execution too.-pflag parsing —command -p chromiumandtime -p chromiumno longer break because-pwas consuming the next argument.bash -c -- "cmd"handling — Both JS preload injection and bash harness detection now correctly handle--after-c.- Harness detection skips
execand env assignments — Patterns likeexec claude,FOO=bar claude,A=1 B=2 claudenow correctly detect the harness.
Changed
- Restructured
lib/no-sandbox.jsfor testability (pure functions above production guards, conditionalmodule.exports). - Log header written by shared
write_log_header_json()across macOS and Linux. - Log file first line is now
#json:{...}instead of# scode session:. Legacy comment header follows on subsequent lines.
Full Changelog: v0.1.1...v0.2.0