v0.2.7 — SF_PROJECT_NODE_BIN opt-in + arm-tools argument wiring
Two live-incident fixes (TDD, outer-ring reviewed)
SF_PROJECT_NODE_BIN=1 — project-local node tools, safely
The 0.2.4 PATH-only security fix made arm.py --with-tools-installed node_modules/.bin tools invisible to the gates (live observation: npm add -D eslint ... succeeded, status still absent). New explicit opt-in resolves .bin with a containment hard stop — an entry whose realpath escapes node_modules/ is refused even under the opt-in; PATH always wins; the 0.2.4 venv opt-in semantics unchanged. Connected fix: arm.py tool_present no longer reports tools "present" that the gates would refuse to run (root-threaded: the positional path reports against the target project). Tests: 10 cases incl. the npm in-tree-symlink shape and the escaping-symlink refusal.
arm-tools no longer drops your flags
The template never referenced $ARGUMENTS, so pi substituted invocation flags nowhere — /solidforge:arm-tools --with-tools --scaffold-configs silently armed without either (live incident). The template now wires ${ARGUMENTS:-<none passed>} and instructs parsing from that line; verified against pi's actual renderer; smoke assertion prompt-arguments-wired guards it (smoke now 8 checks).
Also in this release
- Repo armed Layer 2 (dogfood): configs, gate devDeps, blueprint templates, constitution
- CC handoff doc:
docs/outflow/sf-project-node-bin-handoff.md(adoption at the CC maintainers' cadence) - Outer-ring review (fresh context): PASS with I1–I3 follow-ups — all fixed in-tree before release