v13.10.2

tokio-rs/axumv13.10.2Jul 5, 2026by thedotmack

AI Summary

A patch release focused on cross-platform stability, worker/runtime correctness, and SQLite improvements.

Key Highlights

  • Worker host honors `CLAUDE_MEM_WORKER_HOST` with correct IPv6 literals.
  • Windows spawn shims remove the `shell:true` footgun.
  • SQLite settings get atomic writes and `busy_timeout` improvements.
  • Install fixes restore runtime modules previously causing `MODULE_NOT_FOUND`.

New Features

  • Worker host binding honors `CLAUDE_MEM_WORKER_HOST` with correct IPv6 handling
  • Worker identity convergence to prevent version skew
  • Windows spawn shims remove `shell:true` for safety
  • SQLite settings atomic writes and migration fixes
  • Install `repair` restores marketplace runtime root

Full Release Notes

Patch release focused on cross-platform stability and worker/runtime correctness.

## Fixes
- **Worker host**: clients now honor `CLAUDE_MEM_WORKER_HOST` (the address the server actually binds), with IPv6 literals bracketed correctly in health checks and display URLs.
- **Worker identity**: cache/marketplace/MCP/CLI/restart launches converge on one worker bundle (stops version-skew from two builds on one port).
- **Windows**: centralized spawn shims remove the `shell:true` footgun; codex hooks emit a Windows-executable command instead of a POSIX-only one.
- **Install**: `repair` now restores the marketplace runtime root (not just the cache); ships the `plugin/sqlite` runtime modules that were causing `MODULE_NOT_FOUND` on clean installs.
- **SQLite/settings**: atomic settings writes, `busy_timeout` to avoid `SQLITE_BUSY` under concurrent worker/hook access, a migration column re-check, and removal of an index create that could crash boot on legacy duplicate rows.
- **Supervisor**: preserves `HTTPS_PROXY` and Bedrock/Vertex skip-auth env for the SDK subprocess.
- **Worktree**: relative `gitdir:` pointers resolved correctly.

## Docs
- New Release Branches guide (main / core-dev / community-edge) with instructions for running the non-stable lines locally.

Deliberately excluded: client-side observer truncation (kept out per #3096) and project-identity re-keying (kept the #2663 repo-root key).