v0.3.4
Install or upgrade on Linux (systemd):
curl -fsSL https://raw.githubusercontent.com/nucleusv/linux-mcp-daemon/main/scripts/install.sh | sudo bash -s -- --version v0.3.4Or install a package below: sudo apt install ./linux-mcp-daemon_0.3.4_amd64.deb / sudo dnf install ./linux-mcp-daemon-0.3.4-1.x86_64.rpm (arm64: _arm64.deb / .aarch64.rpm) - next steps.
Container image: ghcr.io/nucleusv/linux-mcp-daemon:0.3.4 (linux/amd64, linux/arm64).
Changelog
Security
- 0b09c51 fix(security): a privileged call with no host in view fails instead of running inside the container
Bug fixes
- f3e7cb9 fix: clearer root hint and container error
Other
- 7e505b2 configs: comment every grant of the privileged reference block
- 8dcee77 docs(mcp-sudo): Docker's --privileged vs a call's privileged: true
- a593c42 docs(mcp-sudo): why paths: ["/"] follows symlinks; containers without --pid host now fail
- 2d4092b docs(site): Architecture right after Introduction in the sidebar
- ffdd727 release: v0.3.4 notes; v0.3.4 in the install commands
Upgrading from 0.3.3
- In a container, a privileged call now always reaches the host - or fails. With
worker.containerized: true(the container image's config), a container started without--pid hostsees its own PID 1; aprivileged: truecall used to run as root inside the container without an error, while the caller believed it acted on the host. It now fails withcannot switch to the host's filesystem - is the mcpd container running with --privileged --pid host?, and mcpd warns at startup. Start the container with--privileged --pid hostas the install shows; if mcpd runs directly on the host withworker.containerized: true, set it tofalse. Details. - Clearer messages: a permission error for a tool the user may run as root names the tool and where it's granted (
files/read is granted to you as root in mcp-sudo.yaml: retry with privileged: true). - Docs: the mcp-sudo page shows the full reference config with a comment on every grant, and explains Docker's
--privilegedversus a call'sprivileged: true.