CHANGELOG_v4.md
CHANGELOG_v4.md
This file supersedes
CHANGELOG_v3.md(rotated out on 01.10.2026 after the v3 file grew past a comfortable single-session read size (~67 KB / โ2 read chunks); same house pattern as the v1 โ v2 hand-off and the v2 โ v3 rotation of 20.09). At rotation, the ten newest v3 entries (the uncommitted rev-3x pile from FIX #33 through WALK-ABORT) were carried into this file verbatim; per owner order 01.10 (~21:xx), all of those pre-today entries have since been dumped back todocs/history/CHANGELOG_v3.md, where their bodies remain (the archive body was verified byte-identical before the dump โ rotation had left a duplicate copy, now deduped). This file now holds ONLY entries dated 01.10.2026 and later. New entries are added at the top of THIS file.
Current release: v1.9.18 (package.json + manifest.json; revision 33, owner publish pending โ revision 30 was published to GitHub 15.09): version sticky per 21.09 owner decision; the rev-3x pile (FIX-35c, WALK-ABORT, and today's CONTAMINATION-FIX + jest flag-independence arc) folds into the next Hub publish โ pre-today entries of the pile live in docs/history/CHANGELOG_v3.md after the 01.10 dump-back. Newest arcs (both 28.09 evening, in archive): FIX-35c โ isSafeRegex's self-hanging clause-1 meta-regex removed; ReDoS gate hang-proof by linear-by-construction scans (the two same-day lockups were root-caused in the GATE itself); 56/860 gate owner-verified = freshest bench before today. Newest arc (01.10, top entry): CONTAMINATION-FIX follow-up C โ session-memory read guards across the remaining resume surfaces + Edit-C regression suite; canon gate now 58 suites / 874 tests.
executeProjectSwitch session-memory path + jest flag independence; canon gate 57/866 โ 58 suites / 874 testsContext: parts A/B of the CONTAMINATION-FIX arc (session-memory read guards on project-switch paths, Gap-1 class in src/tools/contextManagementTools.ts) had closed earlier today and were triple-verified: hermetic unit suites + full gate 57/866 owner-run twice (~17:52 and ~18:06 โ canon moved from 30.09's 56/860 by exactly +1 suite / +4 tests stateManagerRefreshProject + 2 B1/B2, zero unexplained drift). Edit-C covers the ONE remaining unguarded resume surface: the session-memory READ path inside executeProjectSwitch (Gap-2b) โ a stale/foreign store must degrade to self-describing output, never throw. Same-day companion arc (jest flag trap): an owner targeted re-run of 6 suites WITHOUT the V8 flag surfaced 3 NEW failures in tests/restoreSessionContext.test.ts ("A dynamic import callback was invoked without --experimental-vm-modules") although the same file had been green under npm test minutes earlier โ root cause proven: package.json scripts carry --experimental-vm-modules, plain npx jest invocations do not, and TS 5.9 (module=NodeNext + "type":"commonjs") keeps native dynamic imports untranspiled; repo precedent for the identical trap already existed (tests/fileSearch.test.ts:201).
Changes:
Tests: NEW hermetic suite tests/sessionMemoryReadGuards.test.ts (215 lines / 8 tests, zero .each()): A/B tmpdir working dirs per test; static imports ONLY โ deliberately flag-independent by construction. Pins: the eight read-guard cases incl. the Gap-2b regression (foreign/stale store on the executeProjectSwitch path degrades without throwing).
Verification: โ
GATES GREEN, owner-run 01.10 โ targeted npx jest tests/sessionMemoryReadGuards.test.ts = 8/8 (~20:1x); canonical npm test = 58 suites / 874 tests ALL GREEN in ~21.5 s, exactly canon 57/866 + the new suite (delta accounted line-by-line per house rule, zero unexplained drift) โ post-fix re-gate ~20:3x IDENTICAL at 58/874 after the lint close (confirms runtime-neutrality); npx tsc --noEmit clean; ESLint 0 problems post-fix. Flag-independence directly proven: plain npx jest tests/restoreSessionContext.test.ts (NO --experimental-vm-modules) = 12/12 in 0.58 s (~18:2x). HOUSE RULE reaffirmed: npm test is the ONLY canonical invocation โ bare npx jest <suites> must never be presented as an equivalent without flag caveats.
Versioning: no bump โ v1.9.18 sticky per 21.09 owner decision; manifest revision stays at 33; this entry + parts A/B + the jest/require fix fold into the Item-A commit batch (owner-held). Doc sweep executed same pass (~20:5x, owner GO "update all docs"): README badge/table/test-command โ verified 874/58 ยท package.json description โ verified 874/58 ยท ARCHITECTURE tree test-count comment โ verified 874/58 ยท RELEASE_NOTES.md untouched (append-only release history). CHANGELOG rotation v3โv4 executed in the same pass.
This file supersedes
CHANGELOG_v3.md(rotated out on 01.10.2026 after the v3 file grew past a comfortable single-session read size (~67 KB / โ2 read chunks); same house pattern as the v1 โ v2 hand-off and the v2 โ v3 rotation of 20.09). At rotation, the ten newest v3 entries (the uncommitted rev-3x pile from FIX #33 through WALK-ABORT) were carried into this file verbatim; per owner order 01.10 (~21:xx), all of those pre-today entries have since been dumped back todocs/history/CHANGELOG_v3.md, where their bodies remain (the archive body was verified byte-identical before the dump โ rotation had left a duplicate copy, now deduped). This file now holds ONLY entries dated 01.10.2026 and later. New entries are added at the top of THIS file.
Current release: v1.9.18 (package.json + manifest.json; revision 33, owner publish pending โ revision 30 was published to GitHub 15.09): version sticky per 21.09 owner decision; the rev-3x pile (FIX-35c, WALK-ABORT, and today's CONTAMINATION-FIX + jest flag-independence arc) folds into the next Hub publish โ pre-today entries of the pile live in docs/history/CHANGELOG_v3.md after the 01.10 dump-back. Newest arcs (both 28.09 evening, in archive): FIX-35c โ isSafeRegex's self-hanging clause-1 meta-regex removed; ReDoS gate hang-proof by linear-by-construction scans (the two same-day lockups were root-caused in the GATE itself); 56/860 gate owner-verified = freshest bench before today. Newest arc (01.10, top entry): CONTAMINATION-FIX follow-up C โ session-memory read guards across the remaining resume surfaces + Edit-C regression suite; canon gate now 58 suites / 874 tests.
executeProjectSwitch session-memory path + jest flag independence; canon gate 57/866 โ 58 suites / 874 testsContext: parts A/B of the CONTAMINATION-FIX arc (session-memory read guards on project-switch paths, Gap-1 class in src/tools/contextManagementTools.ts) had closed earlier today and were triple-verified: hermetic unit suites + full gate 57/866 owner-run twice (~17:52 and ~18:06 โ canon moved from 30.09's 56/860 by exactly +1 suite / +4 tests stateManagerRefreshProject + 2 B1/B2, zero unexplained drift). Edit-C covers the ONE remaining unguarded resume surface: the session-memory READ path inside executeProjectSwitch (Gap-2b) โ a stale/foreign store must degrade to self-describing output, never throw. Same-day companion arc (jest flag trap): an owner targeted re-run of 6 suites WITHOUT the V8 flag surfaced 3 NEW failures in tests/restoreSessionContext.test.ts ("A dynamic import callback was invoked without --experimental-vm-modules") although the same file had been green under npm test minutes earlier โ root cause proven: package.json scripts carry --experimental-vm-modules, plain npx jest invocations do not, and TS 5.9 (module=NodeNext + "type":"commonjs") keeps native dynamic imports untranspiled; repo precedent for the identical trap already existed (tests/fileSearch.test.ts:201).
Changes:
Tests: NEW hermetic suite tests/sessionMemoryReadGuards.test.ts (215 lines / 8 tests, zero .each()): A/B tmpdir working dirs per test; static imports ONLY โ deliberately flag-independent by construction. Pins: the eight read-guard cases incl. the Gap-2b regression (foreign/stale store on the executeProjectSwitch path degrades without throwing).
Verification: โ
GATES GREEN, owner-run 01.10 โ targeted npx jest tests/sessionMemoryReadGuards.test.ts = 8/8 (~20:1x); canonical npm test = 58 suites / 874 tests ALL GREEN in ~21.5 s, exactly canon 57/866 + the new suite (delta accounted line-by-line per house rule, zero unexplained drift) โ post-fix re-gate ~20:3x IDENTICAL at 58/874 after the lint close (confirms runtime-neutrality); npx tsc --noEmit clean; ESLint 0 problems post-fix. Flag-independence directly proven: plain npx jest tests/restoreSessionContext.test.ts (NO --experimental-vm-modules) = 12/12 in 0.58 s (~18:2x). HOUSE RULE reaffirmed: npm test is the ONLY canonical invocation โ bare npx jest <suites> must never be presented as an equivalent without flag caveats.
Versioning: no bump โ v1.9.18 sticky per 21.09 owner decision; manifest revision stays at 33; this entry + parts A/B + the jest/require fix fold into the Item-A commit batch (owner-held). Doc sweep executed same pass (~20:5x, owner GO "update all docs"): README badge/table/test-command โ verified 874/58 ยท package.json description โ verified 874/58 ยท ARCHITECTURE tree test-count comment โ verified 874/58 ยท RELEASE_NOTES.md untouched (append-only release history). CHANGELOG rotation v3โv4 executed in the same pass.
src/tools/contextManagementTools.ts โ read-guard on the project-switch session-memory path (Gap-2b); no behavior change beyond the guarded degradation contract.jest.config.cjs): per-file moduleNameMapper keys for the Edit-C suite's static imports (RC#4 class โ first-match-wins ordering before the tools-mock fallback).tests/restoreSessionContext.test.ts, test file only): all three native await import('@msgpack/msgpack') sites replaced with CJS require() (+ typeof cast) โ verified @msgpack/msgpack@3.1.3 is dual-format (main = dist.cjs), so require() works under plain Node and jest with OR without the flag. Repo-wide scan: zero other native dynamic-import call sites in any of the 57 test files.src/promptPreprocessor.ts L536, Edit-C region): 2ร @typescript-eslint/no-unnecessary-type-assertion โ redundant as string casts after a typeof guard in extractLatestSessionSummary; casts removed + explanatory comment (byte-exact what eslint --fix would emit; no other reformatting).src/tools/contextManagementTools.ts โ read-guard on the project-switch session-memory path (Gap-2b); no behavior change beyond the guarded degradation contract.jest.config.cjs): per-file moduleNameMapper keys for the Edit-C suite's static imports (RC#4 class โ first-match-wins ordering before the tools-mock fallback).tests/restoreSessionContext.test.ts, test file only): all three native await import('@msgpack/msgpack') sites replaced with CJS require() (+ typeof cast) โ verified @msgpack/msgpack@3.1.3 is dual-format (main = dist.cjs), so require() works under plain Node and jest with OR without the flag. Repo-wide scan: zero other native dynamic-import call sites in any of the 57 test files.src/promptPreprocessor.ts L536, Edit-C region): 2ร @typescript-eslint/no-unnecessary-type-assertion โ redundant as string casts after a typeof guard in extractLatestSessionSummary; casts removed + explanatory comment (byte-exact what eslint --fix would emit; no other reformatting).