Skip to content

v0.2.7 — SF_PROJECT_NODE_BIN opt-in + arm-tools argument wiring

Choose a tag to compare

@maskshell maskshell released this 04 Sep 14:54
· 21 commits to master since this release
v0.2.7
9a3b4a5

Two live-incident fixes (TDD, outer-ring reviewed)

SF_PROJECT_NODE_BIN=1 — project-local node tools, safely

The 0.2.4 PATH-only security fix made arm.py --with-tools-installed node_modules/.bin tools invisible to the gates (live observation: npm add -D eslint ... succeeded, status still absent). New explicit opt-in resolves .bin with a containment hard stop — an entry whose realpath escapes node_modules/ is refused even under the opt-in; PATH always wins; the 0.2.4 venv opt-in semantics unchanged. Connected fix: arm.py tool_present no longer reports tools "present" that the gates would refuse to run (root-threaded: the positional path reports against the target project). Tests: 10 cases incl. the npm in-tree-symlink shape and the escaping-symlink refusal.

arm-tools no longer drops your flags

The template never referenced $ARGUMENTS, so pi substituted invocation flags nowhere — /solidforge:arm-tools --with-tools --scaffold-configs silently armed without either (live incident). The template now wires ${ARGUMENTS:-<none passed>} and instructs parsing from that line; verified against pi's actual renderer; smoke assertion prompt-arguments-wired guards it (smoke now 8 checks).

Also in this release

  • Repo armed Layer 2 (dogfood): configs, gate devDeps, blueprint templates, constitution
  • CC handoff doc: docs/outflow/sf-project-node-bin-handoff.md (adoption at the CC maintainers' cadence)
  • Outer-ring review (fresh context): PASS with I1–I3 follow-ups — all fixed in-tree before release