Releases: danielbodart/chase
Releases · danielbodart/chase
Release list
v0.160.79
- Take frisket d6d5d7a, whose service-set session sends a connection forwarded to its own address on to 127.0.0.1 (nat output for pasta's splice, nat prerouting with route_localnet in the session's namespace for its tap), so a dev server listening on localhost alone is reached at its project's address, as auto now publishes it (10fb845)
v0.159.78
- Give a project one name, frisket's ..internal, answered on the host by frisket's DNS rather than written into /etc/hosts, and bind a session's published ports to its project's address: take frisket ed7f14c and flong 7a2f328; drop the first-come claim on an address (addresses.json), the hosts file chase read back (hosts, hostNames, "on this host ... only") and lib/docker.nix with its docker-address check, since nothing evaluates the rule in Nix any more and two projects at one address now both run, the relay keeping each to its own containers; a tier with a network sets flong's forwardAddress to 127.0.0.1 and exec gives
forward:ADDRESS, the approved Docker project's address or the one the checkout's origin names, soautopublishes a dev server there and nowhere else;chase dockershows the name asnames(5bd7f9f)
v0.158.77
- Say less at launch: a tier's guard says chase rather than agent-, naming the tier only in a refusal, so a mounted checkout is
chase: mounting DIR (TIER, MODE); the line beside an approval says where the project's Docker is without its ports, which the approval shows, and without the workspace, the checkout launched from; an app with no credential says nothing of where it came from, and one with a credential says which secret without the workspace; and the shell's own Docker banner goes, as it said the approval's line again (7a96d72)
v0.157.76
- Give each sandbox tier's container Claude Code's managed settings, apps.claude.managedSettings, in its own /etc and never the host's: by default allowManagedPermissionRulesOnly, so a project's checked-in deny list -- which blocks even in bypassPermissions mode -- and every other file's permission rules are ignored and the container is the only boundary, and permissions.defaultMode auto, Shift+Tab still cycling; each key a default of its own, so a tier can change one, add others or mkForce none (ca0a88b)
v0.156.75
- Take flong 4a6ad0a, which no longer warns about a guard, so a tier's guard -- the tier check and the nested-checkout gate -- builds without a warning (0dd779e)
v0.155.74
- Cut the README to what a configuration says: the terms it uses, an example, the commands, and a table for each level of settings -- chase, a tier, its rules, an app, the operations' answers, a grant -- with what each app does and takes in a page of its own under docs/apps, each a settings table, an example and what the app is for, linking to the design notes already in docs (9929745)
v0.154.73
- Say in the README what
trustdoes for each app that has it -- Claude Code's dialog answered in the seeded or the host's ~/.claude.json, codex told on its command line, mise naming the checkout in MISE_TRUSTED_CONFIG_PATHS -- and what each does without it, and have the module example's trusted saytrust = true, as examples/tiers.nix does (c34cc2f)
v0.153.72
- Trust a checkout in an app that asks -- Claude Code's folder-trust dialog, codex's, mise's -- only where its tier says
trust = true, at launch: a session of the workspace's or its own scope has it in the ~/.claude.json it is seeded with, one of the host's has it written to the host's file by the binds hook, codex gets its -c override, and mise MISE_TRUSTED_CONFIG_PATHS, nothing written to its records; a bare tier may say it too, and the wrapper then trusts the checkout's root on the host before the agent starts. Off, the default, each app asks as it would anywhere, so strict now asks where it used to trust every workspace silently, and the activation step that pre-trusted $HOME, every workspace group and chase.apps.claude.preTrustPaths goes with that option: which checkouts are trusted follows from the tier that sorts them, and the example's trusted says so (3c6fbe2)
v0.152.71
- Ship mise as one of chase's apps, configured as every other is: chase.apps.mise says the package and the configuration bound read-only, a tier turns it on with
enable, and its installs and downloads are kept at ascopethat follows the tier's caches unless it says otherwise --sessionoverlaying the host's,tiera store of the tier's own with its shims on PATH,hostthe host's, with the same mise at both paths so a shim either side writes runs on both -- while its state, whatmise trusthas trusted, is never kept: the host's is overlaid in every scope, and what a session trusts goes with it (f76c49b)
v0.151.70
- Say where every app keeps what it keeps with one word,
scope-- session, workspace, tier or host, session by default and each app offering what it can -- so Claude Code and codex are turned on byenablerather than a non-nullstate(shared is now host, isolated workspace, and a session's own is new for both, with codex a tier's too), Hugging Face'ssharedbecomes a scope that follows the tier's newcaches, and a tier may keep what its tools download for each workspace or for all of them under ~/.cache/chase/caches, the XDG cache and data homes and the variables of each tool that keeps its downloads elsewhere named in module.nix beside the CA variables; what is kept on the host at a workspace's or tier's scope is a store, a directory chase makes per tier, binds, fills with its files afresh and points the variables the module names at unless the container sets them, so chase knows nothing of any tool and a consumer's own app can keep one too, and the plugins overlay of a Claude Code that is not the host's is never made for a bare tier, whose refusal would otherwise be flong's missing user rather than chase's (178c4cc) - Move each app's machine-wide settings from chase.bindings. to chase.apps., cloudflare's wranglerPackage becoming package and gh and git getting one too, let a tier override any of them under its own apps. (lib/apps.nix's overrides, each defaulting to the machine's value), and make an app read-only and unauthenticated unless a tier says
authenticated = true, replacinganonymous: git, github and huggingface hold their credential only then, cloudflare's tier route exists only then while a project's own token keeps the tier's answers (ops.answers), git's credential is github's unless given its own, and every app's unbound credential is refused per tier by name, so the example's trusted says authenticated for git and github and strict says nothing (d3f35c9) - Call a grant's per-app section
appsrather thanbindings, the word the Nix side uses for the machine's own app settings, so chase.jsonc says"apps": { "cloudflare": … }, its refusals nameapps.<app>.<field>, a grant still sayingbindingsis refused withbindings is now appsrather than an unknown field, the app config'senvFromBindingbecomesenvFromGrant, and the jq golden file is written afresh without the entries no test asks for; every checkout's approval is asked again once, as the stored grant it is compared with names the old key (5caf8af)