v0.2.1 — three correctness fixes
A patch release on v0.2.0 — three correctness fixes found by an external review of the repo (PR #49). No new capability, no breaking change, no change to the security invariants.
What's fixed
-
sandy run— a request without areportspec now writes its report. Previously a model-lesssandy runwhose request omittedreportgathered the data, printed the report to stdout, and wrote no file toreport_output_dir. Root cause: the report file write is gated onrequest.reportbeing present (it is not tied to the model narrate step), which a bare request does not set.sandy runis a report-producing verb, so it now always writes the default report (title = goal, timestamped filename) intoreport_output_dir— it never silently drops the artifact. The default is applied in the CLIrunpath only; the plugin'ssandy.gatherdeliberately stays file-less. -
sandy import— default staging anchors to the config dir, not the cwd.stageresolved.sandy-import/against the process cwd, so runningsandy importfrom another directory left a stray.sandy-import/<hash>.jsonbehind. The default now anchors to the config directory — the same anchor asreport_output_dir— so a run from any directory stages next tosandy.json. An explicit--stage-diroverride is honored verbatim (cwd-relative if given as a relative path). Staging stays config-free (the anchor comes from the declared config path; nothing must load). -
Egress-conformance fixture advertised a non-dialable host.
conformance/ep-server.mjsprintedhttp://0.0.0.0:<port>/mcpon ready; the in-process harness dials exactly that URL, and0.0.0.0is a valid bind wildcard but not a dialable destination on Linux, so the three egress tests hung there. It now advertises127.0.0.1while keeping the0.0.0.0bind — the Docker network-level harness is unaffected (it builds its URL from the EP container's IP, never the printed line, and still needs the all-interfaces bind to be reachable cross-container). Test-only:conformance/is not in the packagefilesand never ships.
Notes
- No security change. None of the three touches the egress path or the sandbox enforcer — the fixture fix only changes the address the in-process test dials. No new security advisories.
- Tests: +3 (one regression test per fix) — a
runwith noreportspec asserts exactly one file lands inreport_output_dir; import tests assert the default anchors to the config dir (not cwd) and that an explicit override is cwd-relative. - Verification:
npm run typecheck && npm test && npm run build→ 349/349 tests (was 346, +3), green. Real-binary smoke tests confirmed both CLI-facing fixes end-to-end. - Version bump
0.2.0 → 0.2.1inpackage.json,package-lock.json(top + root package only),plugin/.claude-plugin/plugin.json, and the two runtime identity strings. Docs updated (README Status,docs/NEXT_STEPS.md,docs/IMPORT_DESIGN.md, test counts).