Skip to content

v0.2.1 — three correctness fixes

Choose a tag to compare

@techeretic techeretic released this 24 Sep 05:58
· 30 commits to master since this release

A patch release on v0.2.0 — three correctness fixes found by an external review of the repo (PR #49). No new capability, no breaking change, no change to the security invariants.

What's fixed

  • sandy run — a request without a report spec now writes its report. Previously a model-less sandy run whose request omitted report gathered the data, printed the report to stdout, and wrote no file to report_output_dir. Root cause: the report file write is gated on request.report being present (it is not tied to the model narrate step), which a bare request does not set. sandy run is a report-producing verb, so it now always writes the default report (title = goal, timestamped filename) into report_output_dir — it never silently drops the artifact. The default is applied in the CLI run path only; the plugin's sandy.gather deliberately stays file-less.

  • sandy import — default staging anchors to the config dir, not the cwd. stage resolved .sandy-import/ against the process cwd, so running sandy import from another directory left a stray .sandy-import/<hash>.json behind. The default now anchors to the config directory — the same anchor as report_output_dir — so a run from any directory stages next to sandy.json. An explicit --stage-dir override is honored verbatim (cwd-relative if given as a relative path). Staging stays config-free (the anchor comes from the declared config path; nothing must load).

  • Egress-conformance fixture advertised a non-dialable host. conformance/ep-server.mjs printed http://0.0.0.0:<port>/mcp on ready; the in-process harness dials exactly that URL, and 0.0.0.0 is a valid bind wildcard but not a dialable destination on Linux, so the three egress tests hung there. It now advertises 127.0.0.1 while keeping the 0.0.0.0 bind — the Docker network-level harness is unaffected (it builds its URL from the EP container's IP, never the printed line, and still needs the all-interfaces bind to be reachable cross-container). Test-only: conformance/ is not in the package files and never ships.

Notes

  • No security change. None of the three touches the egress path or the sandbox enforcer — the fixture fix only changes the address the in-process test dials. No new security advisories.
  • Tests: +3 (one regression test per fix) — a run with no report spec asserts exactly one file lands in report_output_dir; import tests assert the default anchors to the config dir (not cwd) and that an explicit override is cwd-relative.
  • Verification: npm run typecheck && npm test && npm run build → 349/349 tests (was 346, +3), green. Real-binary smoke tests confirmed both CLI-facing fixes end-to-end.
  • Version bump 0.2.0 → 0.2.1 in package.json, package-lock.json (top + root package only), plugin/.claude-plugin/plugin.json, and the two runtime identity strings. Docs updated (README Status, docs/NEXT_STEPS.md, docs/IMPORT_DESIGN.md, test counts).