Release-note fact check — anthropic-experimental/sandbox-runtime

v0.0.66 → v0.0.67 · 23 commits · 148 files · +7237/−555 · judge: claude-cli/haiku
85solid
100
correctness
claims supported
50
completeness
churn documented
90
risk
100 − flag penalties
repo: TypeScript 99% · JavaScript 1% · Shell 0% · 1.6 MB code
release cadence ~6 d
baseline (5 rel.): median churn ±7797 Churn per release (oldest → newest) v0.0.62: 7797 v0.0.63: 10552 v0.0.64: 14212 v0.0.65: 3488 v0.0.66: 3812 · coverage 23% Note coverage % per release (oldest → newest) v0.0.62: 43 v0.0.63: 17 v0.0.64: 41 v0.0.65: 23 v0.0.66: 19

Score derivation — components, flag penalties and the hard cap, per SCORING.md

0255075100perfect releaseperfect release100correctness 100 × 0.45 weighted share of claims the diff supportscorrectness 100 × 0.450completeness 50 × 0.25 churn-weighted share of commits the notes covercompleteness 50 × 0.25−12.5risk 90 × 0.3 0 critical × −25 · 1 warn × −10risk 90 × 0.3−385/100 solid85/100 solid85

Claims at a glance

verified 8partial 0no-evidence 0contradicted 0skipped 0

Risk flags

WARN Undocumented changes in dependencies paths
package-lock.json, package.json
commits: ea824ecd, 21d8f75e

Diff map — tile = file, size = changed lines, color = documentation status, amber border = sensitive path, click opens the diff

src/sandbox/windows-sandbox-utils.ts ±1318 lines · evidence fns: parseWindowsBinShell, WindowsSandboxParams, repoRoot, getSrtWinPath, RunOpts, runSrtWin, runSrtWinJsonAllowFail, verifyWindowsWfpEgress, windowsTrustCa, WindowsInstallOptions (click to open the compare view)windows-sandbox-utils.tstest/sandbox/credential-mask-sigv4.test.ts ±823 lines · undocumented (click to open the compare view)credential-mask-sigv4.test.tstest/sandbox/winsrt.test.ts ±811 lines · evidence fns: hasTool, createTestConfig, describe, describe.if (click to open the compare view)winsrt.test.tstest/sandbox/credential-aws-pairs.test.ts ±645 lines · undocumented (click to open the compare view)credential-aws-pairs.test.tssrc/sandbox/credential-aws-pairs.ts ±383 lines · undocumented (click to open the compare view)credential-aws-pairs.tsvendor/srt-win-src/src/cli.rs ±370 lines · evidence fns: AceReleaseEntry, run (click to open the compare view)cli.rstest/sandbox/aws-sigv4.test.ts ±361 lines · undocumented (click to open the compare view)aws-sigv4.test.tssrc/sandbox/aws-sigv4.ts ±354 lines · undocumented (click to open the compare view)aws-sigv4.tsvendor/srt-win-src/src/path_id.rs ±290 lines · evidence fns: std::fmt::Display, canonicalize_path (click to open the compare view)path_id.rssrc/sandbox/sandbox-manager.ts ±251 lines · evidence fns: SandboxViolationStore, buildBodyCredentialInjector, startMuxProxyServer, initialize, isSandboxingEnabled, checkDependencies, getCredentialRestrictions, computeWindowsFsAccessSet, getAllowGitConfig, wrapWithSandbox (click to open the compare view)sandbox-manager.tssrc/sandbox/mitm-ca.ts ±215 lines · evidence fns: rsaSha256SignNative, loadCA, generateEphemeralCA (click to open the compare view)mitm-ca.tssrc/sandbox/sandbox-config.ts ±206 lines · evidence fns: z.object (click to open the compare view)sandbox-config.tsvendor/srt-win-src/src/logon.rs ±177 lines · evidence fns: spawn_runner, AsRawHandle (click to open the compare view)logon.rssrc/sandbox/tls-terminate-proxy.ts ±174 lines · undocumented fns: peekForClientHello, terminateAndForward, forwardUpstream (click to open the compare view)tls-terminate-proxy.src/sandbox/sandbox-utils.ts ±157 lines · evidence fns: stripExtendedPathPrefix, normalizePathForSandbox, generateProxyEnvVars (click to open the compare view)sandbox-utils.tsvendor/srt-win-src/ci/smoke-kill.ps1 ±145 lines · evidence (click to open the compare view)smoke-kill.ps1test/sandbox/glob-expand.test.ts ±136 lines · evidence fns: describe (click to open the compare view)glob-expand.tevendor/srt-win-src/ci/smoke-aces.ps1 ±85 lines · evidence (click to open the compare view)smoke-aces.ps1vendor/srt-win-src/src/state_db.rs ±77 lines · evidence fns: std::str::FromStr, ace_holders, open_db, Locked, recompose_at (click to open the compare view)state_db.rstest/sandbox/mitm-ca.test.ts ±72 lines · evidence fns: describe (click to open the compare view)mitm-ca.test.tssrc/cli.ts ±38 lines · evidence fns: main (click to open the compare view)src/index.ts ±34 lines · evidence (click to open the compare view)src/sandbox/linux-sandbox-utils.ts ±30 lines · evidence fns: LinuxSandboxParams, wrapCommandWithSandboxLinux (click to open the compare view)src/sandbox/macos-sandbox-utils.ts ±27 lines · evidence fns: MacOSSandboxParams, wrapCommandWithSandboxMacOS (click to open the compare view)test/sandbox/check-dependencies.test.ts ±26 lines · evidence fns: describe (click to open the compare view)vendor/srt-win-src/src/acl.rs ±21 lines · evidence · sensitive: auth/crypto fns: SbAce, SbAceSet (click to open the compare view)src/sandbox/http-proxy.ts ±20 lines · undocumented fns: HttpProxyServerOptions, createHttpProxyServer (click to open the compare view)test/fixtures/aws-sigv4-suite/README.md ±19 lines · undocumented (click to open the compare view)(18 smaller files) ±18 lines · unknown (click to open the compare view)test/fixtures/aws-sigv4-suite/post-sts-token/readme.txt ±15 lines · undocumented (click to open the compare view)src/sandbox/request-filter.ts ±11 lines · undocumented fns: decideAndRespond (click to open the compare view)vendor/srt-win-src/src/util.rs ±11 lines · covered fns: wstr (click to open the compare view)test/fixtures/aws-sigv4-suite/get-header-value-trim/get-header-value-trim.creq ±10 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-header-key-duplicate/get-header-key-duplicate.creq ±9 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-with-session-token/get-vanilla-with-session-token.creq ±9 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-sts-token/post-sts-header-before/post-sts-header-before.creq ±9 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-x-www-form-urlencoded/post-x-www-form-urlencoded.creq ±9 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-unreserved/get-unreserved.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-utf8/get-utf8.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-query-order-key-case/get-vanilla-query-order-key-case.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-query-unreserved/get-vanilla-query-unreserved.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-query/get-vanilla-query.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla/get-vanilla.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-relative-relative/get-relative-relative.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-relative/get-relative.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slash-dot-slash/get-slash-dot-slash.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slash-pointless-dot/get-slash-pointless-dot.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slash/get-slash.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slashes/get-slashes.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-space/get-space.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-special-character/get-special-character.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-sts-token/post-sts-header-after/post-sts-header-after.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-vanilla-query/post-vanilla-query.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-vanilla/post-vanilla.creq ±8 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-header-key-duplicate/get-header-key-duplicate.sreq ±7 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-x-www-form-urlencoded/post-x-www-form-urlencoded.sreq ±7 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-header-key-duplicate/get-header-key-duplicate.req ±6 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-header-value-trim/get-header-value-trim.sreq ±6 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-x-www-form-urlencoded/post-x-www-form-urlencoded.req ±6 lines · undocumented (click to open the compare view).gitattributes ±5 lines · undocumented (click to open the compare view).github/workflows/integration-tests.yml ±5 lines · evidence · sensitive: ci/build (click to open the compare view)test/fixtures/aws-sigv4-suite/get-header-value-trim/get-header-value-trim.req ±5 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-with-session-token/get-vanilla-with-session-token.sreq ±5 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-sts-token/post-sts-header-after/post-sts-header-after.sreq ±5 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-sts-token/post-sts-header-before/post-sts-header-before.sreq ±5 lines · undocumented (click to open the compare view)package-lock.json ±4 lines · undocumented · sensitive: dependencies (click to open the compare view)test/fixtures/aws-sigv4-suite/get-header-key-duplicate/get-header-key-duplicate.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-header-value-trim/get-header-value-trim.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-unreserved/get-unreserved.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-unreserved/get-unreserved.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-utf8/get-utf8.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-utf8/get-utf8.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-query-order-key-case/get-vanilla-query-order-key-case.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-query-order-key-case/get-vanilla-query-order-key-case.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-query-unreserved/get-vanilla-query-unreserved.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-query-unreserved/get-vanilla-query-unreserved.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-query/get-vanilla-query.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-query/get-vanilla-query.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-with-session-token/get-vanilla-with-session-token.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla/get-vanilla.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla/get-vanilla.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-relative-relative/get-relative-relative.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-relative-relative/get-relative-relative.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-relative/get-relative.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-relative/get-relative.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slash-dot-slash/get-slash-dot-slash.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slash-dot-slash/get-slash-dot-slash.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slash-pointless-dot/get-slash-pointless-dot.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slash-pointless-dot/get-slash-pointless-dot.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slash/get-slash.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slash/get-slash.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slashes/get-slashes.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slashes/get-slashes.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-space/get-space.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-space/get-space.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-special-character/get-special-character.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-special-character/get-special-character.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-sts-token/post-sts-header-after/post-sts-header-after.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-sts-token/post-sts-header-before/post-sts-header-before.req ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-sts-token/post-sts-header-before/post-sts-header-before.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-vanilla-query/post-vanilla-query.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-vanilla-query/post-vanilla-query.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-vanilla/post-vanilla.sreq ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-vanilla/post-vanilla.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-x-www-form-urlencoded/post-x-www-form-urlencoded.sts ±4 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-unreserved/get-unreserved.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-utf8/get-utf8.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-query-order-key-case/get-vanilla-query-order-key-case.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-query-unreserved/get-vanilla-query-unreserved.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-query/get-vanilla-query.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla-with-session-token/get-vanilla-with-session-token.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-vanilla/get-vanilla.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-relative-relative/get-relative-relative.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-relative/get-relative.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slash-dot-slash/get-slash-dot-slash.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slash-pointless-dot/get-slash-pointless-dot.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slash/get-slash.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-slashes/get-slashes.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-space/get-space.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/get-special-character/get-special-character.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/normalize-path/normalize-path.txt ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-sts-token/post-sts-header-after/post-sts-header-after.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-vanilla-query/post-vanilla-query.req ±3 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/post-vanilla/post-vanilla.req ±3 lines · undocumented (click to open the compare view)vendor/srt-win-src/ci/cleanup.ps1 ±3 lines · covered fns: param (click to open the compare view)package.json ±2 lines · undocumented · sensitive: dependencies (click to open the compare view)test/fixtures/aws-sigv4-suite/NOTICE ±2 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-header-key-duplicate/get-header-key-duplicate.authz ±1 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-header-value-trim/get-header-value-trim.authz ±1 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-unreserved/get-unreserved.authz ±1 lines · undocumented (click to open the compare view)test/fixtures/aws-sigv4-suite/get-utf8/get-utf8.authz ±1 lines · undocumented (click to open the compare view)
cited as evidence in documented commit undocumented unknown sensitive path (border)

Claims in detail

Windows

verified `git.safeDirectories` config — `safe.directory` without write grants; fixes dubious-ownership on subdirectory launches (also emits on macOS/Linux) (#403) 0.90
PR #403 is in the release range (aa9f6f3051); identifiers safe.directory, git.safeDirectories, macOS appear in its diff.
src/sandbox/linux-sandbox-utils.ts, src/sandbox/macos-sandbox-utils.ts, src/sandbox/sandbox-config.ts, src/sandbox/sandbox-manager.ts, src/sandbox/sandbox-utils.ts, src/sandbox/windows-sandbox-utils.ts
fns: LinuxSandboxParams, wrapCommandWithSandboxLinux, MacOSSandboxParams, wrapCommandWithSandboxMacOS, z.object, getAllowGitConfig, wrapWithSandbox, wrapWithSandboxArgv
commits: aa9f6f30
verified Deny targets that don't exist yet are materialized as placeholders and stamped, closing the create-past-a-deny hole; trailing `/` marks directory targets (#404) 0.95
New `create_placeholder_chain()` function in path_id.rs materializes missing intermediates and empty leaf for non-existent deny targets. In cli.rs, `canonicalize_ace_targets()` calls this when encountering `CanonError::NotFound` on deny targets, stamping leaf with full `SbAce::Deny` and intermediates with `SbAce::DenyDelete`. Trailing-separator handling: `leaf_is_dir = p.ends_with(['\\', '/'])` in cli.rs; smoke test A31(d) confirms trailing `\` materializes as directory. All changes integrated w
src/sandbox/sandbox-manager.ts, src/sandbox/windows-sandbox-utils.ts, test/sandbox/glob-expand.test.ts, vendor/srt-win-src/ci/smoke-aces.ps1, vendor/srt-win-src/src/acl.rs, vendor/srt-win-src/src/cli.rs
fns: computeWindowsFsAccessSet, wrapWithSandboxArgv, uninstallWindowsSandbox, describe, SbAce, SbAceSet, AceReleaseEntry, run
commits: 1172a926
verified Kill-chain hardening: broker error paths always reap the runner; CI smoke rows pin the no-survivors invariant (#405) 0.95
The new smoke-kill.ps1 script implements K1/K2 invariant tests asserting 'NO sandbox process survives the broker' and is wired into CI via integration-tests.yml. The logon.rs changes show the SpawnedChild guard is now never defused, with its Drop implementation calling TerminateProcess 'on every in-process exit', ensuring the runner is always reaped regardless of error paths or graceful exits.
vendor/srt-win-src/ci/smoke-kill.ps1, vendor/srt-win-src/src/logon.rs, .github/workflows/integration-tests.yml
fns: param, spawn_runner, wstr
commits: 5d9821c3
verified Persistent MITM CA: `ca.json` under the protected state dir, atomic writes, `notBefore`/`notAfter` validation, auto-load at `initialize()`, `generateCa`/`validateCaPair` exports (#406) 0.90
PR #406 is in the release range (29701f19e5); identifiers generateCa, validateCaPair, notBefore, notAfter appear in its diff.
src/index.ts, src/sandbox/mitm-ca.ts, src/sandbox/sandbox-manager.ts, src/sandbox/windows-sandbox-utils.ts, test/sandbox/mitm-ca.test.ts, test/sandbox/winsrt.test.ts
fns: rsaSha256SignNative, loadCA, generateEphemeralCA, z.object, initialize, windowsTrustCa, describe, describe.if
commits: 29701f19
verified **Breaking:** `windows.srtWin.path` is required — no implicit vendored-exe fallback; pass the exported `VENDORED_SRT_WIN_EXE` to use the packaged binary. Fact-only argv-too-long message (#413) 0.90
PR #413 is in the release range (86c3294541); identifiers VENDORED_SRT_WIN_EXE, windows.srtWin.path appear in its diff.
src/cli.ts, src/index.ts, src/sandbox/sandbox-config.ts, src/sandbox/windows-sandbox-utils.ts, test/sandbox/winsrt.test.ts
fns: main, z.object, WindowsSandboxParams, repoRoot, RunOpts, wrapCommandWithSandboxWindows, checkWindowsDependencies, hasTool
commits: 86c32945
verified Typed `WindowsSandboxError` codes with `.subcommand`, single-spawn `srt-win status --json` + `checkWindowsSandboxStatus()` (#414) 0.90
PR #414 is in the release range (c3eb609ca0); identifiers WindowsSandboxError, checkWindowsSandboxStatus, .subcommand appear in its diff.
src/index.ts, src/sandbox/sandbox-manager.ts, src/sandbox/windows-sandbox-utils.ts, test/sandbox/winsrt.test.ts
fns: initialize, parseWindowsBinShell, getSrtWinPath, runSrtWin, runSrtWinJsonAllowFail, getWindowsWfpStatus, verifyWindowsWfpEgress, windowsTrustCa
commits: c3eb609c
verified Typed `mapped_drive_cwd` error (exit 16) for network-drive working directories; the broker never stats UNC literals (#415) 0.95
The diff shows the typed error `MappedDriveCwd` struct in logon.rs for network-drive working directories, explicit exit code 16 in cli.rs (`std::process::exit(16)`), and a parser `parseWindowsSandboxError` in windows-sandbox-utils.ts that surfaces the error. The `isUncPath` function in sandbox-utils.ts with documentation stating 'The broker uses this to skip `stat`/`realpath` on UNC **literals**' and the test case 'passes UNC literals through without stat (broker never touches SMB)' directly con
src/sandbox/windows-sandbox-utils.ts, test/sandbox/glob-expand.test.ts, vendor/srt-win-src/src/cli.rs
fns: stripExtendedPathPrefix, normalizePathForSandbox, uninstallWindowsSandbox, expandWindowsFsPaths, describe, run, spawn_runner, AsRawHandle
commits: 482d46dd
verified Async dependency/status/install APIs (`checkDependenciesAsync` — additive, sync API unchanged); install/uninstall timeout default 120s; `windowsHide` on sync spawns (#395) 0.90
PR #395 is in the release range (030482795e); identifiers checkDependenciesAsync, windowsHide appear in its diff.
src/sandbox/sandbox-manager.ts, src/sandbox/windows-sandbox-utils.ts, test/sandbox/check-dependencies.test.ts, test/sandbox/winsrt.test.ts
fns: initialize, isSandboxingEnabled, checkDependencies, ISandboxManager, runSrtWin, runSrtWinJson, checkWindowsSandboxStatus, verifyWindowsWfpEgress
commits: 03048279

Undocumented commits

commitsubjectchurnfiles
ea824ecdMerge main (through v0.0.66, incl. #399 body substitution) into sigv4 branch+1251/−2915
7bff0524Add SigV4 signer, classifier, and official test-suite vectors+1182/−0116
51b0e001Add AWS credential pair registry and SigV4 re-sign planner+1028/−02
b3f458aeAdd end-to-end SigV4 re-sign integration and policy tests+544/−01
0da2dc3dCap the body buffer for SigV4 literal-hash re-signing at 64 MiB+158/−64
dcbe5ab5Wire SigV4 re-signing into the TLS-terminating proxy+92/−33
eb1d419bClose the presigned-policy bypass via a non-AWS Authorization header+76/−133
9ff64262Fix Bun stream corruption in the TLS-terminate relay (pull-mode reads)+78/−12
31156a27Fail closed when a signed header is stripped before re-signing+51/−52
21d8f75eRelease v0.0.67 (#422)+3/−32
e1bea57fMark vendored SigV4 test vectors linguist-generated+5/−01