- Validate line numbers as safe integers and reject values exceeding `Number.MAX_SAFE_INTEGER`.
- Impose a maximum expansion limit of 100,000 lines on patch ranges to prevent memory and CPU exhaustion.
- Inline delete range iteration directly into execution to avoid allocating intermediate anchor arrays.
- Updated CI workflows and GitHub actions to enhance Bazel cache keying, credential masking, and validation checks.
- Migrated dependency locking from Cargo.Bazel.lock to MODULE.bazel.lock using rules_rust crate_universe.
- Updated build configuration, documentation, and tooling scripts to reflect the lockfile and cache changes.
- Updated bazel cache key generation with v2 schema version and streamlined remote cache usage.
- Added native-inputs composite action to centralize change detection and artifact caching.
- Added a scheduled workflow to warm the hosted bazel disk cache.
- Split the rust validation job and integrated prebuilt native addon caching into the CI pipeline.
- Update isActionableDisable in usage-cli.ts to accept active accounts and check identity matches.
- Suppress credential disable tombstones when an active account exists for the same provider and identity.
- Add test coverage for suppressing tombstones when active accounts share the same identity.
Both PR heads carried discrete drive-by commits bumping only a test
timeout, unrelated to the Markdown-layout and HTML-asset fixes they
ship. Restored to the pre-merge state to keep the merged scope honest.
The guard now probes the full target before refusing, so an existing file
named like a selector list stays writable. Say so in the CHANGELOG entry
and the readSelectorListMisfire doc comment.
Probe the full target with probeLiteralPathExists before classifying it as a
mis-dispatched read-selector list, matching the single-selector guard, so an
existing POSIX file like 'report:1-2;archive:3-4' can still be overwritten.
The symmetric-padding change shrank the framed-block content width to
outputBlockContentWidth(width); the Ask renderer still pre-rendered its
question/result Markdown at the old width-2 budget, so maximal-width rows
re-wrapped inside the block and spilled a trailing fragment row.
Compiled Bun binaries autoload project dotenv files, so snapshotting Bun.env inside one captured the secrets as launcher-owned and forwarded them to every shell. Drop that branch and record launcher values, restoring an empty launcher value that Bun overwrote with a dotenv secret.
- filterChildShellEnv now also filters Bun-autoloaded .env.{NODE_ENV||development}
entries, closing the .env.production/.env.development leak into child shells.
- parseEnvLine skips backslash-escaped quotes when locating the closing
delimiter, restoring baseline/Bun-literal handling of values like JSON="{\"a\":1}"
that the new parser truncated.
- Adds a parseEnvFile regression test for escaped quotes.
startDaemonBrokerFromEnvironment now sets the kernel-visible name via
prctl, so restoring only process.title left the test runner's
/proc/self/comm as "omp daemon brok" for the rest of the Linux run.
applyAnthropicUsageExtras writes usage.cttl from cache_creation while
usage.cacheWrite is written from cache_creation_input_tokens; the two
are independent wire fields, so a partial or stale breakdown made the
unattributed remainder cost $0. Price the remainder at the flat 5m
rate so the ttl split can only re-price write tokens, never drop them.