Skip to content

Fix CLI target parsing and Tool protocol/save contracts - #893

Merged
nedtwigg merged 9 commits into
spec-cleanup-host-contractsfrom
spec-cleanup-cli-tools
Oct 2, 2026
Merged

nedtwigg merged 9 commits into
spec-cleanup-host-contractsfrom
spec-cleanup-cli-tools

Conversation

@nedtwigg

@nedtwigg nedtwigg commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Audit the CLI, Tool, and built-in Tool contracts against their producers and consumers. Correct cross-window addressing, protocol bounds, save-channel generations, and folder truncation; let canonical types own syntax and shape.

Fix browser target parsing, reject oversized or terminal-injecting OSC payloads, and prevent a replaced iframe connection from answering an old save. Built-in Windows editor saves stage bytes with Node and preserve destination permissions through native File.Replace. Bound retries for Windows sharing errors in Tool-trust JSON commits.

Validation: existing CLI, Tool protocol, built-in viewer/save, and control-server suites; strict library types and host bundles. Current platform CI and bot review pass. Stacked on #892.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Deploying mouseterm with  Cloudflare Pages  Cloudflare Pages

Latest commit: ac48a4b
Status: ✅  Deploy successful!
Preview URL: https://c53fcbdd.mouseterm.pages.dev
Branch Preview URL: https://spec-cleanup-cli-tools.mouseterm.pages.dev

View logs

@nedtwigg
nedtwigg added this pull request to stack #896 October 2, 2026 05:05
nedtwigg and others added 2 commits October 1, 2026 22:43
The original Windows save staged each draft in an owner-only directory
created by compiling a C# CreateDirectoryW P/Invoke through PowerShell
Add-Type. Every save spawned PowerShell twice and compiled C#, failed
outright with no fallback under Constrained Language Mode, and ran in no
CI job, all to keep draft bytes private in the rare case of a restrictive
document ACL inside a readable directory.

Node now writes the draft beside the document, and one
[IO.File]::Replace call swaps it in with an original-file backup, which
still fixes the EPERM rename and preserves the document's ACL. An
unconfirmed replacement still keeps both the draft and the backup. A
Windows draft now inherits its directory's ACL until the swap; the spec
says so.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@nedtwigg
nedtwigg merged commit 5ce9132 into main Oct 2, 2026
9 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants