v0.2.6
A local rename can no longer leave a file under both its old and its new name on every peer. A sync pass materialized with a disk view captured before its peer step, so a rename landing in one window read as a file this machine never had and the old path was written back. Every materialization now protects exactly what the scan before it saw. The same rule stops a file created and removed inside one pass from coming back.
peers.tomlformat 2: each peer'sallowarray is the complete shell and exec policy. The machine-wideallow_shellandallow_execkeys are generated rollback mirrors that a restored 0.2.5 binary reads; editing them changes nothing. The old command flags are accepted and ignored.fabric update --tag v0.2.6resolves a suffix-free tag to its build. Binaries older than this release still need--urlwith--sha256.fabric execandfabric shellname the peer and the service when a policy refuses them, and exit 126.fabric doctorreports an intentional exec refusal as information, not as a problem.- Sync staging:
fabric sync stage,staged,publish, anddiscard. A staged file lives under the fabric home, outside every synced folder, so no build that has shipped publishes it until asked. A publish through the daemon is one reconcile per peer and refuses a file whose published version moved since it was staged.