Skip to content

v0.2.0 — ChaosSMTP, ChaosBlob, engine/MCP fixes

Latest

Choose a tag to compare

@johnm-dta johnm-dta released this 24 May 18:05

Two new chaos plugins, three engine/MCP fixes, one breaking default change.

See CHANGELOG.md for the full notes.

Highlights

Added

  • ChaosBlob — S3-compatible-ish object-storage chaos server (PUT/GET/HEAD/DELETE/ListObjectsV2, blob-specific fault injection, metrics, CLI, presets, fixture, docs).
  • ChaosSMTP — outbound-email chaos server. Stage-aware error injection across MAIL/RCPT/DATA, slow-reply latency, accepted-but-dropped messages, three capture modes (metadata/discard/full), admin app, immutable captured-header policy, metrics, CLI, presets, fixture, docs. Mail is never relayed.

Changed (breaking)

  • server.workers default is now 1 (was 4). Multi-worker mode is now opt-in and requires a file-backed metrics.database; the previous default silently fragmented metrics across worker processes. Top-level config validators now reject workers > 1 combined with an in-memory metrics database.

Fixed

  • Engine: explicit MalformedContentLength rejection (closes the silent size-guard bypass caused by RequestBodyTooLarge subclassing ValueError).
  • Engine: graceful config-handoff fallback when the temp file is gone (shared engine/config_handoff.py helper used by blob/llm/web).
  • LLM MCP analyze_latency: percentiles now computed over the full population (was the smallest-100 lower tail).
  • LLM completions: non-object JSON body returns 400 invalid_request_error.
  • Admin /admin/config POST: unknown sections and non-object values rejected with 400.
  • LLM X-Fake-Template: hardened against helper errors; random_words(...) hard-capped to 10 000 words.
  • MCP SQL query(): row cap enforced via fetchmany, defeating LIMIT -1 bypasses.
  • MCP analyzer: now truly read-only (file:...?mode=ro, no WAL/SHM side files).

Removed (security)

  • Pre-authorised rm -rf $REPO/.git && git init permission entry from .claude/settings.local.json.