f3217dca4b
Co-authored-by: Alice <alice@prismshadow.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1.5 KiB
1.5 KiB
Tooling and hardening: in-place upgrades, request validation and core test coverage
penguin updateupgrades an existing install in place.penguin update [--check] [--release <tag>] [-y|--yes]resolves the newest version from the GitHub Releases API (the same sourceinstall.shresolvesreleases/latest/downloadagainst) and upgrades using the mechanism the install actually came from, detected from the real path of the running CLI rather than guessed: a tarball install re-runs the official installer preserving its install dir and whether it bundles a Node runtime; a global npm/pnpm/yarn/bun install runs that manager's global install, and prints the command instead of guessing when the manager cannot be identified; a source checkout is refused with a pointer togit pulland a rebuild. Without-yit prints the mechanism, target version and install dir and asks for confirmation, and a non-TTY stdin requires--yesrather than blocking. The data root is never touched — onlybin,lib,webandnodeare replaced. The target flag is--release, not--version, because the CLI's own-v, --versiontakes precedence over a subcommand option of the same name.- The server now validates
positiveIntParamandoptionalDateParaminputs instead of trusting query strings — malformed paging/date parameters return a clean 400 rather than leaking into SQL or arithmetic. - Core gained dedicated unit tests for
CappedTextBufferandToolCallIdAllocator, two small pure modules that previously had no direct coverage.