Skip to content

v3.55.0 — MCP HTTP auth gate, hive gating, policy ledger anchor

Choose a tag to compare

@ruvnet ruvnet released this 07 Oct 18:03
· 186 commits to main since this release
2ab3f99

Ruflo 3.55.0

Minor release. It contains one security behaviour change that can break existing setups: ruflo mcp start -t http on a non-loopback host now refuses to start without a token.

Security

  • MCP HTTP transport (#3598, #3599). Binding off loopback (--host 0.0.0.0, a LAN IP, ::) now exits 1 unless RUFLO_MCP_HTTP_TOKEN / --auth-token-file / --auth-token is set, or you opt out with RUFLO_MCP_ALLOW_UNAUTHENTICATED_HTTP=1. With a token, /rpc, /mcp and /info require Authorization: Bearer <token> (constant-time compare); /health stays public and minimal. Also fixes a fail-open in @claude-flow/mcp 3.1.0 where auth enabled with an empty token list accepted any bearer value.
    What is not fixed: loopback with no token is still unauthenticated. Any local process can call every tool, and DNS rebinding is not blocked (no Host allow-list). Set a token whenever you use the HTTP transport. A valid token grants every tool; there is no per-tool authorization.
  • Hive-mind gating (#3338, #3339, ADR-476). Remote (HTTP/WebSocket) callers now need an operator credential for spawn, consensus propose, broadcast, shutdown, memory set/delete and optimize-memory. Local stdio/CLI users need nothing. hive-mind_init no longer returns hiveToken. For a local caller this is a speed bump, not a boundary: a prompt-injected agent that can read .claude-flow/hive-mind/ can read the secret.
  • Policy ledger anchor (#3602, #3886, ADR-475). Deleting the anchor fields in state.json and truncating receipts no longer verifies as valid. A hash-chained anchor log plus a mirror under ~/.config/ruflo/policy-trust/ now detect it. ruflo policy verify --establish-anchor (interactive TTY only) is the logged repair path. Limit: an attacker who can rewrite both the project directory and ~/.config/ruflo can still delete every anchor and receipt or forge a coherent log; stronger evidence needs an external witness. A pre-#3568 ledger with receipts and no anchor now fails policy transactions until you run policy verify --establish-anchor.

Fixes

Breaking changes

  • Off-loopback MCP HTTP binds (for example Docker with --host 0.0.0.0) need a token or the explicit opt-out.
  • hive-mind_init no longer returns hiveToken.

Packages

@claude-flow/cli, claude-flow, ruflo 3.55.0. Leaves: shared 3.0.2, memory 3.0.1, swarm 3.0.1, security 3.0.2, mcp 3.1.0, plugin-agent-federation 1.0.1.
Plugins: ruflo-adr 0.5.4, ruflo-goals 0.4.3, ruflo-cost-tracker 0.27.2, ruflo-metaharness 0.2.4, ruflo-console 0.36.1, ruflo-mods 0.3.15.

Full changelog: CHANGELOG.md. Release PR: #3890.

Gist: https://gist.github.com/ruvnet/172e077daf43f6efd6532cd8191862d5