Skip to content

release: v0.48.0 — bareguard 0.19 default translator, exposeMalformedArgs - #55

Merged
hamr0 merged 5 commits into
mainfrom
feat/bareguard-019-translator
Sep 29, 2026
Merged

hamr0 merged 5 commits into
mainfrom
feat/bareguard-019-translator

Conversation

@hamr0

@hamr0 hamr0 commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Summary

  • bareguard 0.19 default translator (BREAKING): the six createShellTools primitives now map to bareguard's fs/bash shapes by default (read/write/edit with resolveToolPath'd path; bash with cmd), tool on every action. Any missing/unresolvable path → '' → denied via fs.invalidPath. Peer floor → bareguard >=0.19.0 <1.0.0.
  • filterTools probes tool identity only — never a path-less translated shape (which bareguard would skip, not deny).
  • exposeMalformedArgs (OpenAI + Ollama, opt-in): raw malformed function.arguments on malformedToolCall.rawArguments, 500-char cap, rawTruncated.
  • CHANGELOG upgrade notes: bareguard's net check now applies to any tool with a url arg; bash.allow is a plain prefix match (word-boundary fix coming in bareguard 0.19.1).

Verification

  • npm test 1327 pass / 0 fail / 2 skip (exit 0); typecheck, check:primitives, check:lockfile exit 0.
  • /debrief (2 rounds) + /branch-review (ready, no blockers, fail-first 4/4 files, secrets-history clean).

🤖 Generated with Claude Code

hamr0 and others added 5 commits September 28, 2026 22:05
Default actionTranslator now emits bareguard's primitive shapes with the
tool name on every action: shell_read/grep -> read, shell_write -> write,
shell_edit -> edit (path via resolveToolPath; a missing/bad path becomes ''
so the gate denies fs.invalidPath), shell_run/exec -> bash. filterTools
filters by tool identity only; scope is enforced per call. Requires
bareguard >=0.19.0 (0.15 ignores `tool`). Example sets readScope/writeScope.

exposeMalformedArgs (OpenAI + Ollama, default off): malformedToolCall
carries rawArguments (verbatim, 500-char cap) + rawTruncated, through
Loop.run().

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RNVyxYsxAMaxUW1wZk1H4b
…, bash.allow prefix match

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
bareagent.context.md still claimed a genuinely-absent tool path is left
undefined (bareguard's path-less-skip behavior) — the exact claim commit
3794c99 already corrected in CHANGELOG.md and CLAUDE.md, but missed here.
safeToolPath normalizes every missing/malformed path to '' uniformly
(fs.invalidPath denies unconditionally); align this doc with the shipped
code and the branch's own corrective commit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…Args

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@hamr0
hamr0 merged commit 03db98b into main Sep 29, 2026
2 checks passed
@hamr0
hamr0 deleted the feat/bareguard-019-translator branch September 29, 2026 06:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant