@@ -11,6 +11,35 @@ matching `## [X.Y.Z]` section (plus install instructions). Do not maintain
1111parallel copies under ` docs/ ` or ` scripts/notes/ ` . At cut time: rename
1212` ## [Unreleased] ` to ` ## [X.Y.Z] - YYYY-MM-DD ` , then run the release script.
1313
14+ ## [ 0.2.102] - 2026-08-22
15+
16+ ### Permissions
17+
18+ - ** Workspace containment returns canonical real paths.** Writers receive the
19+ realpath from the containment allow, closing the symlink-retarget window
20+ between check and write; the write-path allowlist compares both sides in
21+ canonical space so symlinked cwds don't false-deny.
22+
23+ - ** Dangling or looping symlink components fail closed.** A path component
24+ that exists but cannot resolve (dangling link, symlink loop) is denied by
25+ containment and the write-path allowlist instead of being treated as a
26+ missing tail; genuinely-new file paths still resolve via the nearest real
27+ ancestor.
28+
29+ ### Trust
30+
31+ - ** Project-trust stores are keyed by realpath.** The same repo reached via
32+ symlink twins (e.g. ` /tmp ` vs ` /private/tmp ` ) now finds the same grants;
33+ the saved ` repo ` field and validity compare canonicalize consistently.
34+
35+ ### TUI
36+
37+ - ** Typeahead popups no longer leak queued permission gates.** Both the
38+ @-mention popup and the slash-command palette refresh their suggestion
39+ lists in place instead of close+reopen, so a queued gate can't open (and
40+ swallow keys) mid-filter. Zero matches shows "(no matches)" without
41+ releasing the popup; Enter there preserves the typed text.
42+
1443## [ 0.2.101] - 2026-08-22
1544
1645### Permissions
0 commit comments