v0.1.0
Install or upgrade on Linux (systemd):
curl -fsSL https://raw.githubusercontent.com/nucleusv/linux-mcp-daemon/main/scripts/install.sh | sudo bash -s -- --version v0.1.0Container image: ghcr.io/nucleusv/linux-mcp-daemon:0.1.0 (linux/amd64, linux/arm64).
Changelog
Security
- 73aec77 feat(security): native sysctl, and per-user sysctl write restrictions
- 9068ad8 feat(security): per-tool network destination restrictions for curl/ping
- 3a7c7ac fix(security): input validation audit across all tools and resources
- 64d1948 fix(security): sysctl write-policy check must fail closed; accept numeric values
- c2e8212 refactor(security): drop sysctl.read_only; testuser gets glob write_keys
Features
- a36f6b8 feat(cli): gracefully format nested JSON arrays and objects in table outputs
- 887e38c feat(cli): recursively render nested arrays of objects as subtables
- 0b9ab97 feat(cli): set list as default command for groups
- 095e9c5 feat(linuxctl): bash/zsh completion, MCP_SERVER, table/json/yaml fixes
- 20b65bc feat(release): versioned builds, release pipeline, install script
- ea10d7d feat(tools): add disks/mounts, users/list, and logs/logins
- f0eb4a2 feat(tools): add services/list tool for listing systemd services
- d746824 feat: add automatic host-access for containerized deployments, system/packages tool, and fix multiple registry/config bugs
- bf3596d feat: add disks/iostat tool to read /proc/diskstats
- 3cea2cc feat: add disks://{name}/stats resource
- 421b741 feat: add fdisk, smartctl, lsblk, traceroute to system tools pack
- 448a44c feat: add network statistics to interfaces resource
- 2f508a4 feat: add network://interfaces/{name} resource template
- 816f7e2 feat: add robust binary file detection logic and fix curl build
- 4be3a4a feat: complete implementation of file group tools (create, update, find, type)
- 1a23cd5 feat: disks/list renders an lsblk-style device tree
- 127b062 feat: implement files/read precision streaming with line and byte offsets
- 8691e56 feat: implement files/stat and files/content resource endpoints with strict context truncation
- 95d52b5 feat: implement linuxctl verb/group grammar, UID pinning, docs restructure
- 2cb0c80 feat: implement process resource templates
- f06f5e6 feat: implement system operations & debugging pack (dbus services, journalctl, dmesg, sysctl)
- ae51714 feat: local-only linuxctl mcpd user/token admin, salted token hashes
- 5f9d96d feat: processes/top - a native
top -b -n 1; syscall.Kill for delete
Bug fixes
- 1394f72 fix(auth): protect cached resources from being served to unauthorized users by adding pre-authorization checks
- 80f154c fix(config): update mcp-sudo.yaml to use valid array structure for static resources
- 3a60057 fix(docs): escape curly braces for MDX
- 63bb872 fix(linuxctl): readable YAML from mcpd user create; accurate next steps
- 1838355 fix(linuxctl,top): table/wide rendering - column order, cells, top layout
- 619478d fix(mcp): split resourceTemplates into official resources/templates/list JSON-RPC protocol endpoint
- d2d6c7e fix(network): correctly export ReadRoutes signature and add routes package import
- a66d458 fix(tools): remove literal backslashes from OutputFormat json struct tags
- 66008d7 fix: add ARM64 fallbacks for cpuinfo extraction
- 73d4316 fix: build mcpd for the actual target architecture, not hardcoded arm64
- 4b6efcc fix: linuxctl arg parsing and rpc schema updates
- 25760da fix: native disks/partitions, journal-control gaps, linuxctl table formatting
- edf625f fix: packages lists packages; interfaces read in a worker; disks/health usable
- 3d2ad2d fix: rename get mcp meta-group to get mcp-api (avoid mcpd confusion
- 91b0990 fix: resolve JSON formatting errors in cpu/list and disks/usage tools
- 55b1130 fix: resolve sudoConfig undefined compilation error
- c604f3d fix: setns(CLONE_NEWNS) fails to compile on linux/amd64
Other
- e892ea9 Add README
- bab3e07 Add inline Go documentation to tool parameter structs
- d773496 Add man pages for mcpd and linuxctl
- 9c7ee45 Add pure Go disk_free and disk_usage tools
- 0c92d74 Add tools_group metadata to tool schemas
- c298169 CLI: Add 'linuxctl stdio' command to proxy JSON-RPC between Claude Desktop and Daemon
- abceed1 CLI: Add smart positional argument mapping for path parameters
- 6869e7a CLI: Drop verb, support / syntax with suffix matching
- 7c7299c CLI: Implement syntax based on tools_group metadata
- 582d1b9 CLI: Refactor linuxctl to use kubectl Verb + Resource paradigm
- afceeb8 CLI: Refactor linuxctl to use tools_group dynamic command tree
- e6d9473 Change base image to ubuntu and install tools
- 8e2e480 Daemon: Implement MCP initialization and ping lifecycle methods
- 399b621 Docs: Add Configuration section for daemon.yaml and mcp-sudo.yaml
- 845f8e7 Docs: Update linuxctl man pages for new / syntax
- b619101 Feature: Implement native TLS support in daemon
- c2dab8d Feature: Support concurrent HTTP and HTTPS port binding
- c7b1435 Finish Phase 2: MCP Protocol Compliance and Isolated Resources
- 4f36992 Finish Phase 3: Implement devices as isolated worker resources
- 4e7a0a1 Fix worker permission denied by moving mcpd out of /root
- 5e9d1f3 Fix: Force rollout restart in deploy script to ensure new local image layers are loaded by Kubernetes
- 4da8c1d Fix: Set deployment strategy to Recreate to avoid hostNetwork port conflicts during rollouts
- 3b426bd Implement Ephemeral Workers, get_sudo_rules, and Dynamic Sudo Discovery
- 588e06f Implement Phase 5: Native Network tools (ping, arp, curl, nslookup)
- 78375e8 Implement SSE, JSON-RPC routing, Rate Limiter and list_directory tool
- 96413c8 Implement Singleflight caching and advanced du parameters
- f61acf0 Implement advanced parameters for du and df tools
- 988120d Implement deep nesting group/action/name folder structure
- e76d557 Implement per-tool timeout overrides in daemon config
- ddb08c9 Implement worker timeouts via context.WithTimeout
- cc5c70d Initial commit
- 19c84ae Initialize docs-website with Vite and premium design
- 22882f5 Install man-db and add man pages to Docker image
- a54ce32 Migrate documentation site to Docusaurus and serve via daemon
- 671b1e1 Move struct documentation inline
- 02d122b Pipeline: Use dynamic container tags to fix stale Kubernetes deployments and dynamically map expected doc routes in tests
- 74cc88b Refactor tools into subpackages
- 4629382 Refactor: Move docs-website into docs/website
- cc8de53 Refactor: Update mcp-sudo.yaml to use privileged map schema with paths validation
- 679f3fb Rename du.go to disk_usage.go and df.go to disk_free.go
- 58f98a3 Restructure plan directory into tools and resources
- f4e36d5 Scripts: Add master run_all.sh script to build, deploy, and test the entire stack
- 954607c Tests: Add end-to-end integration testing for MCP SSE protocol and documentation server
- 44b739d Tests: Add get_disk_space to linuxctl test suite
- d18950e Tests: Add linuxctl test and master test runner script
- c250bb8 Tests: Add retry logic to test_docs.sh to prevent race conditions during Kubernetes rollouts
- bea13da Tests: Fix old disk-space reference in test suite
- cffe68c Tests: Prevent curl connection failures from crashing test_docs.sh under bash set -e
- 82dbcbf Tests: Print full output of linuxctl commands during integration tests
- 4edaf91 Tests: Remove flaky nested configuration routes from test_docs.sh
- 8c804f1 Tools: Rename get_disk_space to get_disk_free to match 'df' Unix standard
- 9a87f33 Update Go module name and fix gitignore
- 9c0bb3b Update READMEs with parameter descriptions
- 2a0c694 Vertically align inline struct comments
- 9fe1636 build: put the local linuxctl binary in a gitignored executables/ folder
- 325a807 docs(plan): update linux-admin-roadmap.md to reflect shipped items
- cfd7c98 perf: cap resource cache TTLs at 60s, network resources at 5s
- 33b7c30 refactor(cpu): rename get_load_average to load_average
- b9c99e0 refactor(disks): rename blocks to block-devices in filepath and daemon
- f1459d8 refactor(disks): rename get_blocks to blocks
- 67dee5f refactor(memory): rename get_memory_usage to memory_usage to support CLI nested path
- 287c734 refactor(network): rename get_connections to list_connections and support nested tool paths in linuxctl
- f5b0d03 refactor(processes): rename get_processes to list_processes and update linuxctl command prefix matching
- 1ed516b refactor(processes): rewrite list_processes to be fully native Go parsing /proc instead of exec.Command('ps')
- 2857750 refactor(resources): rename os://hostname to system://hostname, add system://timezone and system://locale
- 1235f84 refactor: break down processJSONRPC using switch statement
- 7630021 refactor: convert if/else chain to switch in handleResourcesRead
- 52e9977 refactor: modularize static resource handlers into internal/resources
- 8339c0a refactor: move rpc logic to internal/rpc package
- fd48cca refactor: rename cpu/info to cpu/list and disks/block-devices to disks/list
- 97bef2b refactor: rename ctl tools to control (journal-control, system-control)
- 067e22f refactor: rename tools to be semantic (performance, health, partitions, trace-path)
- 0d55039 refactor: simplify giant if blocks in main.go and rpc.go to maps
- ce9ce6f refactor: split rpc.go into smaller files
- 74ff0ef test(linuxctl): gracefully handle expected failures on dmi resource in VMs without DMI support
- 0088ba0 test(mcp): update assertion to handle list_files output correctly
- 5f16588 test: add manual_review=yes/no parameter to run_all.sh
- e19e101 test: fix tests and resource privilege keys
- 0c2b410 test: update nslookup to query google.com for diverse record types