Skip to content

v0.3.3

Choose a tag to compare

@github-actions github-actions released this 26 Sep 10:02
· 23 commits to main since this release

Install or upgrade on Linux (systemd):

curl -fsSL https://raw.githubusercontent.com/nucleusv/linux-mcp-daemon/main/scripts/install.sh | sudo bash -s -- --version v0.3.3

Or install a package below: sudo apt install ./linux-mcp-daemon_0.3.3_amd64.deb / sudo dnf install ./linux-mcp-daemon-0.3.3-1.x86_64.rpm (arm64: _arm64.deb / .aarch64.rpm) - next steps.

Container image: ghcr.io/nucleusv/linux-mcp-daemon:0.3.3 (linux/amd64, linux/arm64).

Changelog

Security

  • fc2e55d fix(security): a uid 0 MCP user is a config error
  • 003c9f6 fix(security): refuse MCP users that map to a uid 0 account

Features

  • 0d63cae feat(linuxctl): -k / -tls-insecure / MCP_TLS_INSECURE replace -insecure / MCP_INSECURE
  • 2061c52 feat(linuxctl): errors to stderr, and -silent / -s to drop them
  • f065434 feat: TLS by default, with a generated self-signed certificate
  • ac90d7b feat: penguin logo; the image no longer bundles the docs site
  • 9c2a826 feat: processes/list and processes/top JSON in bytes
  • b486952 feat: sizes in bytes by default everywhere, human_readable for units

Bug fixes

  • 9785164 fix(install.sh): the security note follows the installed config
  • 890ce58 fix(rpc): disks/free, disks/usage and files/list descriptions say sizes are bytes by default
  • 717a63e fix: findings from the live tool-by-tool test on the systemd host

Other

  • 8d8125c docs(ci): /next/ is for checking docs before a release - not in versions.json
  • c085f33 docs(site): blue-grey call to action and a navy 'unreleased' banner
  • afec62f docs(site): colors from the penguin logo
  • d2bfc76 docs(site): label the current release 'vX.Y.Z (current)'
  • a0ac42e docs(site): the newest release is labelled 'current' in the version menu
  • 922a5ca docs(site): version menu - 'current (vX.Y.Z)' first, older releases below, main last
  • b3c07e7 docs(site): versioned docs - latest release at the root, each release under /vX.Y.Z/, main under /next/
  • 59b9a40 docs(site): versions.json lists every version with its URL, in menu order
  • bdc9dfa investigations: backlog 27 - disks/usage prints the path first
  • fd964e1 investigations: backlog item 26, compare with two other Linux MCP servers
  • cc3b1a3 investigations: item 26 findings - os-mcp and Mohabdo21/linux-mcp compared
  • b096134 release: per-release notes from docs/release-notes/.md, v0.3.3's upgrade notes
  • 1094ed2 test(connections): TestMatchesSS retries until ss and /proc agree

Upgrading from 0.3.2

  • Sizes are bytes by default in every tool's text output; human_readable: true gives df -h/free -h-style units. JSON field renames: processes/list rss_kb → rss_bytes; processes/top mem_mib/swap_mib → mem_bytes/swap_bytes, virt_kib/res_kib/shr_kib → virt_bytes/res_bytes/shr_bytes.
  • TLS is on by default for new installs (a generated self-signed certificate on 9091; plain HTTP off). An existing daemon.yaml without a server.http block keeps serving plain HTTP as before. linuxctl defaults to https://localhost:9091 and trusts the server by MCP_TLS_FINGERPRINT or MCP_CA_CERT (linuxctl describe mcpd tls shows the fingerprint).
  • An MCP user whose OS account is root (uid 0) is a config error - mcpd won't start with one. Map MCP users to unprivileged accounts and grant root per tool.
  • Root grants on path tools need paths: (files/*, disks/usage, disks/free; paths: ["/"] for everything) - an error on reload and linuxctl edit, a warning at startup.
  • linuxctl: -insecure/MCP_INSECURE are now -tls-insecure/-k/MCP_TLS_INSECURE; errors go to stderr, -silent/-s drops them.
  • The container image no longer serves /docs/; the documentation is at https://nucleusv.github.io/linux-mcp-daemon/ (now versioned - this release's is at https://nucleusv.github.io/linux-mcp-daemon/v0.3.3/).

New: Permissions and Risks - read it before granting root.