Skip to content

v0.1.2 — deferred product scope + review follow-ups

Choose a tag to compare

@techeretic techeretic released this 28 Aug 17:17
· 49 commits to master since this release

Closes the entire tracked scope opened after v0.1.1. v0.1.1 (b5fdfd2, 2026-08-23) was the security-fix cut (the 7 private GHSA advisories); v0.1.2 ships everything since it — the 12 review follow-up fixes (issues #1–#12), the docs consolidation (#13), and the six deferred product/hardening items (#14–#19 + the #16 approval-UX v2 half). No new security advisories in this cut: it is a feature/hardening release. 308/308 tests, typecheck + build green, in-process conformance + the Docker/Firejail boundary×mode matrix (byte-identical signatures) green.

Deferred product scope

Issue What landed
#14 HTML report format — preferences.default_report_format: "html" renders the same (claims, gaps) as a deterministic HTML view (Markdown stays the source of truth, SD-06); unimplemented formats fail closed at config load. DOCX/XLSX/PDF remain the documented template for future renderers.
#15 Recurring report templates — templates.json registry (validated by the same orchestratorRequestSchema + legal-tool catalog as any ad-hoc request); sandy run <template> and POST /run {"template"}; audited template_run.
#16 Write-back (Q6), complete — v1 core: admin write_allowlist (always a subset of the read allowlist, CP-02) + PolicyApprovalGate with single-use, per-write, audited approvals; default ReadOnlyGate (refuse all writes). v2 half: a first-class consent flow (sandy.write.approve / sandy.write.revoke tools; sandy.write surfaces needsApproval for legal-but-unapproved tasks), approval expiry/revocation (policy.approval_ttl_seconds, default 1800s, capped at a day; explicit expiresAt may only shorten; new audited reasons approval-expired / approval-revoked), and per-arg constraints on allowlist entries (ajv-checked, strict: true — a malformed constraint fails closed, never a no-op).
#17 SANDY_REAL_MODEL conformance leg — opt-in real-GGUF leg of the sandbox matrix (Firejail, no-egress); skipped, never failed, when the model/runtime is absent, so CI stays green.
#18 In-service hard memory bound — opt-in sandbox.enforce_memory_limit: true wraps the bundled model in a cgroup v2 child with memory.max = sandbox.max_memory_mb; fails closed (degraded) where there is no cgroup delegation. The default ceiling is still the service manager's cgroup.
#19 Multi-turn / agentic planning — opt-in preferences.max_planning_rounds (1–5): after each gather pass the model re-plans from the rounds gathered so far; every follow-up round passes the same schema + legal-tool-catalog gate as round 1; nothing-new de-dup; bounded, audited (standalone_replan), consolidated into one re-rendered report.

Review follow-ups (issues #1–#12) + docs (#13)

  • #1 egress-allowlist default-port matching · #2 undo audited (AU-01) · #3 deleteDirectory() dry-run consistency · #4 byte-exact binary undo · #5 model child killed on a failed invocation · #6 report-write failure surfaces reportError without discarding claims/gaps · #7 SessionCache.get() check-then-act race closed · #8 JSONL audit write failures surfaced · #9 narrate prompt-injection threat model documented · #10 API worker event-driven wake (no busy-poll) · #11 Apache-2.0 LICENSE · #12 hostname-allowlist DNS-rebinding limitation documented.
  • #13 status-doc consolidation: explicit doc roles (DIARY = history, NEXT_STEPS = forward-looking state + roadmap, README = headline + links).

Verification

  • npm run typecheck && npm test && npm run build → 308/308.
  • Conformance: in-process (6/6) + the Docker/Firejail boundary × mode matrix (plugin + standalone) with the byte-identical-signature identity check — the no-egress and runtime-agnosticity guarantees hold for both modes, now including the write-back path.
  • The launch success criterion (zero network egress outside declared MCP endpoints) is unchanged: write-back routes only through the existing MCP manager + NetworkGuard.