Skip to content

v3.39.3 β€” agentbbs CLI detection + probe shell hardening

Choose a tag to compare

@ruvnet ruvnet released this 09 Sep 20:26
· 10 commits to main since this release

Patch release shipping #3250.

Fixed

  • federation_bbs_* tools were unconditionally degraded. All four tools (register / publish / watch / human_join) gated on await import('agentbbs'). The published agentbbs package is a CLI-only launcher β€” its tarball contains only bin/agentbbs.js, package.json and README.md, with no main, no exports, and no root index.js for Node to fall back to. That import could never resolve, so the tools reported degraded: true no matter whether agentbbs was installed and working. Replaced with a subprocess presence probe.
  • Probe shell gated to win32. The follow-up hardening: shell: true was unconditional while the probed binary comes from AGENTBBS_BIN, and under a shell that argument is command-interpreted β€” a crafted value ran a trailing command (verified locally). POSIX now spawns without a shell; Windows keeps cmd.exe so the agentbbs.cmd shim still resolves via PATHEXT. Matches the existing convention in browser-tools.ts, commands/init.ts and init/helpers-generator.ts.
  • @noble/ed25519 no longer externalized in tests. It is a hard dependency of @claude-flow/cli, not an optional one, and externalizing it broke dynamic-import resolution under Vite's SSR transform.

Scope

This makes the Phase 1 local room/envelope surface functional when agentbbs is genuinely installed. It does not implement cross-host federation β€” that remains Phase 2+.

Install

npx ruflo@latest

All three packages (@claude-flow/cli, claude-flow, ruflo) are at 3.39.3 on latest, alpha, and v3alpha.

πŸ€– Generated with RuFlo

https://claude.ai/code/session_013u4pmL9ZUAXb6usVQgNo67