Two new chaos plugins, three engine/MCP fixes, one breaking default change.
See CHANGELOG.md for the full notes.
Highlights
Added
- ChaosBlob — S3-compatible-ish object-storage chaos server (PUT/GET/HEAD/DELETE/ListObjectsV2, blob-specific fault injection, metrics, CLI, presets, fixture, docs).
- ChaosSMTP — outbound-email chaos server. Stage-aware error injection across MAIL/RCPT/DATA, slow-reply latency, accepted-but-dropped messages, three capture modes (
metadata/discard/full), admin app, immutable captured-header policy, metrics, CLI, presets, fixture, docs. Mail is never relayed.
Changed (breaking)
server.workersdefault is now1(was4). Multi-worker mode is now opt-in and requires a file-backedmetrics.database; the previous default silently fragmented metrics across worker processes. Top-level config validators now rejectworkers > 1combined with an in-memory metrics database.
Fixed
- Engine: explicit
MalformedContentLengthrejection (closes the silent size-guard bypass caused byRequestBodyTooLargesubclassingValueError). - Engine: graceful config-handoff fallback when the temp file is gone (shared
engine/config_handoff.pyhelper used by blob/llm/web). - LLM MCP
analyze_latency: percentiles now computed over the full population (was the smallest-100 lower tail). - LLM completions: non-object JSON body returns
400 invalid_request_error. - Admin
/admin/configPOST: unknown sections and non-object values rejected with400. - LLM
X-Fake-Template: hardened against helper errors;random_words(...)hard-capped to 10 000 words. - MCP SQL
query(): row cap enforced viafetchmany, defeatingLIMIT -1bypasses. - MCP analyzer: now truly read-only (
file:...?mode=ro, no WAL/SHM side files).
Removed (security)
- Pre-authorised
rm -rf $REPO/.git && git initpermission entry from.claude/settings.local.json.