v0.3.3
Install or upgrade on Linux (systemd):
curl -fsSL https://raw.githubusercontent.com/nucleusv/linux-mcp-daemon/main/scripts/install.sh | sudo bash -s -- --version v0.3.3Or install a package below: sudo apt install ./linux-mcp-daemon_0.3.3_amd64.deb / sudo dnf install ./linux-mcp-daemon-0.3.3-1.x86_64.rpm (arm64: _arm64.deb / .aarch64.rpm) - next steps.
Container image: ghcr.io/nucleusv/linux-mcp-daemon:0.3.3 (linux/amd64, linux/arm64).
Changelog
Security
- fc2e55d fix(security): a uid 0 MCP user is a config error
- 003c9f6 fix(security): refuse MCP users that map to a uid 0 account
Features
- 0d63cae feat(linuxctl): -k / -tls-insecure / MCP_TLS_INSECURE replace -insecure / MCP_INSECURE
- 2061c52 feat(linuxctl): errors to stderr, and -silent / -s to drop them
- f065434 feat: TLS by default, with a generated self-signed certificate
- ac90d7b feat: penguin logo; the image no longer bundles the docs site
- 9c2a826 feat: processes/list and processes/top JSON in bytes
- b486952 feat: sizes in bytes by default everywhere, human_readable for units
Bug fixes
- 9785164 fix(install.sh): the security note follows the installed config
- 890ce58 fix(rpc): disks/free, disks/usage and files/list descriptions say sizes are bytes by default
- 717a63e fix: findings from the live tool-by-tool test on the systemd host
Other
- 8d8125c docs(ci): /next/ is for checking docs before a release - not in versions.json
- c085f33 docs(site): blue-grey call to action and a navy 'unreleased' banner
- afec62f docs(site): colors from the penguin logo
- d2bfc76 docs(site): label the current release 'vX.Y.Z (current)'
- a0ac42e docs(site): the newest release is labelled 'current' in the version menu
- 922a5ca docs(site): version menu - 'current (vX.Y.Z)' first, older releases below, main last
- b3c07e7 docs(site): versioned docs - latest release at the root, each release under /vX.Y.Z/, main under /next/
- 59b9a40 docs(site): versions.json lists every version with its URL, in menu order
- bdc9dfa investigations: backlog 27 - disks/usage prints the path first
- fd964e1 investigations: backlog item 26, compare with two other Linux MCP servers
- cc3b1a3 investigations: item 26 findings - os-mcp and Mohabdo21/linux-mcp compared
- b096134 release: per-release notes from docs/release-notes/.md, v0.3.3's upgrade notes
- 1094ed2 test(connections): TestMatchesSS retries until ss and /proc agree
Upgrading from 0.3.2
- Sizes are bytes by default in every tool's text output;
human_readable: truegivesdf -h/free -h-style units. JSON field renames:processes/listrss_kb→rss_bytes;processes/topmem_mib/swap_mib→mem_bytes/swap_bytes,virt_kib/res_kib/shr_kib→virt_bytes/res_bytes/shr_bytes. - TLS is on by default for new installs (a generated self-signed certificate on 9091; plain HTTP off). An existing
daemon.yamlwithout aserver.httpblock keeps serving plain HTTP as before.linuxctldefaults tohttps://localhost:9091and trusts the server byMCP_TLS_FINGERPRINTorMCP_CA_CERT(linuxctl describe mcpd tlsshows the fingerprint). - An MCP user whose OS account is root (uid 0) is a config error - mcpd won't start with one. Map MCP users to unprivileged accounts and grant root per tool.
- Root grants on path tools need
paths:(files/*,disks/usage,disks/free;paths: ["/"]for everything) - an error on reload andlinuxctl edit, a warning at startup. - linuxctl:
-insecure/MCP_INSECUREare now-tls-insecure/-k/MCP_TLS_INSECURE; errors go to stderr,-silent/-sdrops them. - The container image no longer serves
/docs/; the documentation is at https://nucleusv.github.io/linux-mcp-daemon/ (now versioned - this release's is at https://nucleusv.github.io/linux-mcp-daemon/v0.3.3/).
New: Permissions and Risks - read it before granting root.