Ruflo v3.32.36 — Trustworthy Signals, Portable Codex Workflows
Ruflo v3.32.36: Trustworthy Signals, Portable Codex Workflows
Ruflo v3.32.36 makes the information an agent sees line up with what the
runtime is actually doing. Embedding commands now disclose when they are using
the deterministic mock fallback, routing metrics distinguish confidence from
measured outcomes, swarm status reads canonical agent state, and learned
patterns preserve the task description that caused them.
The release also makes mixed Claude Code and Codex installations easier to
operate. Codex receives a native read-only Ruflo status skill, dual-mode memory
workers share one database path, large MCP catalogs can be filtered for
small-context models, and project/plugin hook overlap is claimed exactly once.
Hermetic witness verification and Node 24 MCP images strengthen the release
path without adding a runtime dependency.
Install or upgrade
npm install --global ruflo@3.32.36
ruflo doctorExisting projects remain compatible. The default MCP tool set is unchanged,
legacy memory state remains readable, explicit database-path overrides are
preserved, and mock embeddings remain available. The difference is that
degraded or unmeasured states are now reported honestly instead of being
presented as grounded semantic results or routing accuracy.
Use a smaller MCP catalog
Keep the default full catalog:
ruflo mcp startOr select only the capabilities a constrained model needs:
ruflo mcp start --tools memory,swarm,hooksThe equivalent environment form is useful in MCP host configuration:
CLAUDE_FLOW_MCP_TOOLS=memory,swarm,hooks ruflo mcp startSelectors accept categories, tool-name prefixes, and exact tool names. Ruflo
doctor now reports catalog/schema overhead so the selection can be measured.
Inspect grounded learning state
ruflo embeddings status
ruflo hooks metrics
ruflo swarm status
ruflo doctor --component memoryembeddings status identifies the active backend and whether semantic claims
are grounded. Hook metrics expose average confidence and observed outcome
success separately. The memory doctor checks structural integrity, content and
embedding coverage, Reflexion episode coverage, and feedback critiques.
To populate or repair the derived reasoning tables from existing memory:
ruflo memory distill run
ruflo memory distill statusRaw memory_entries and the SONA feed remain the operational write path.
reasoning_patterns, episodes, embeddings, critiques, and causal edges are
derived intelligence populated by distillation or the consolidate worker.
Codex and dual-mode projects
After initialization, Codex can invoke the native ruflo-status skill without
receiving Cursor-specific permission JSON. Dual-mode workers now use a shared
CLAUDE_FLOW_DB_PATH, including worker subprocesses and relative configuration
files, so bootstrap, writes, reads, policy checks, and background work observe
the same database.
The packaged Codex skill set now includes:
- swarm orchestration;
- memory management;
- SPARC methodology;
- security audit;
- GitHub automation;
- performance analysis.
Security and verification
- Witness signature verification uses Node's built-in Ed25519 support in a
source-only checkout and preserves the legacy exit-2 precondition for an
unbuilt full-tree verification. - Helper signing has one public-key source, supports a piped stdin key, uses
gcloud.cmdon Windows, validates Ed25519 keys, and redacts failures. - MCP bridge images use the supported Node 24 LTS line.
- MetaHarness wrappers preserve structured HIGH findings when the upstream
scanner exits non-zero. - Root and packaged hook helpers are byte-identical and covered by a signed
four-helper manifest.
What changed
- Reports the actual embedding backend and suppresses unsupported semantic
interpretations while the mock fallback is active. - Replaces misleading “Routing Accuracy” output with average confidence and
measured outcome-success signals. - Fixes learned-pattern success/failure counts and retains task descriptions in
the learning write. - Reads canonical per-agent IDs and statuses for
agent listand
swarm status. - Fixes statusline install discovery, numeric version comparison, project-root
resolution, and legacy nested-intelligence migration. - Keeps non-TTY spinner output clean and erases TTY spinner lines correctly.
- Deduplicates overlapping project/plugin post-edit and session-end side
effects using an atomic event claim. - Adds MCP tool filtering and schema-overhead diagnostics.
- Repairs dual-mode Codex memory-path consistency and packaged skill assets.
- Adds memory distillation episode embeddings, historical backfill, critique
preservation, and strict doctor coverage checks.
Validation
- All 23 V3 workspace packages built successfully.
- 171 changed-surface CLI tests passed.
- Codex passed 235 tests, security passed 559, and federation passed 640.
- Ruflo core hook integration passed 22/22, including duplicate-event
exactly-once behavior. - MetaHarness passed its complete plugin regression matrix, including
structured finding preservation. - Helper signing security, hermetic witness, MCP security lock, scan-format,
and 37 release invariants passed. - The stable release workflow additionally installs and tests immutable tarball
archives for@claude-flow/cli,claude-flow, andruflobefore publishing
those exact bytes.
This release resolves the current runtime and verification defects tracked in
#2847,
#2821,
#2818,
#2816,
#2814,
#2812,
#2811,
#2810,
#2809,
#2808,
#2807,
#2805,
#2766,
#2765,
#2750,
#2729,
#2726,
#2677,
#2675, and
#2674.