Repository navigation
v3.55.0 — MCP HTTP auth gate, hive gating, policy ledger anchor
Ruflo 3.55.0
Minor release. It contains one security behaviour change that can break existing setups: ruflo mcp start -t http on a non-loopback host now refuses to start without a token.
Security
- MCP HTTP transport (#3598, #3599). Binding off loopback (
--host 0.0.0.0, a LAN IP,::) now exits 1 unlessRUFLO_MCP_HTTP_TOKEN/--auth-token-file/--auth-tokenis set, or you opt out withRUFLO_MCP_ALLOW_UNAUTHENTICATED_HTTP=1. With a token,/rpc,/mcpand/inforequireAuthorization: Bearer <token>(constant-time compare);/healthstays public and minimal. Also fixes a fail-open in@claude-flow/mcp3.1.0 where auth enabled with an empty token list accepted any bearer value.
What is not fixed: loopback with no token is still unauthenticated. Any local process can call every tool, and DNS rebinding is not blocked (noHostallow-list). Set a token whenever you use the HTTP transport. A valid token grants every tool; there is no per-tool authorization. - Hive-mind gating (#3338, #3339, ADR-476). Remote (HTTP/WebSocket) callers now need an operator credential for
spawn,consensus propose,broadcast,shutdown,memory set/deleteandoptimize-memory. Local stdio/CLI users need nothing.hive-mind_initno longer returnshiveToken. For a local caller this is a speed bump, not a boundary: a prompt-injected agent that can read.claude-flow/hive-mind/can read the secret. - Policy ledger anchor (#3602, #3886, ADR-475). Deleting the anchor fields in
state.jsonand truncating receipts no longer verifies as valid. A hash-chained anchor log plus a mirror under~/.config/ruflo/policy-trust/now detect it.ruflo policy verify --establish-anchor(interactive TTY only) is the logged repair path. Limit: an attacker who can rewrite both the project directory and~/.config/ruflocan still delete every anchor and receipt or forge a coherent log; stronger evidence needs an external witness. A pre-#3568 ledger with receipts and no anchor now fails policy transactions until you runpolicy verify --establish-anchor.
Fixes
- Shared resilience batch (#3885; #3676 #3674 #3668 #3670 #3682 #3672 #3593 #3592),
@claude-flow/shared3.0.2, thanks @rudycelekli. - Byzantine quorums intersect for every cluster size (#3560, #3587), federation sends use current peer trust (#3561, #3588), both @rudycelekli;
@claude-flow/swarm3.0.1 also fixes thespawnAgent()pool registration (#3539) and the event-drivenMessageBus(#3563). - CLI: string options keep their declared value (#3594, #3601), config cache isolated per project (#3590, #3591), nested config defaults cloned (#3595, #3600), hive consensus errors surface (#3609, #3654),
daemon start --workershonoured (#3547, #3875). - Plugins prefer the installed ruflo CLI (#3558, #3559, @HF-teamdev) and ruflo-adr edge keys are accepted by the memory validator (#3633, #3636, @drakeo338).
@claude-flow/memory3.0.1:mmrRerank()caches cosine max-similarity (#3516, #3517).
Breaking changes
- Off-loopback MCP HTTP binds (for example Docker with
--host 0.0.0.0) need a token or the explicit opt-out. hive-mind_initno longer returnshiveToken.
Packages
@claude-flow/cli, claude-flow, ruflo 3.55.0. Leaves: shared 3.0.2, memory 3.0.1, swarm 3.0.1, security 3.0.2, mcp 3.1.0, plugin-agent-federation 1.0.1.
Plugins: ruflo-adr 0.5.4, ruflo-goals 0.4.3, ruflo-cost-tracker 0.27.2, ruflo-metaharness 0.2.4, ruflo-console 0.36.1, ruflo-mods 0.3.15.
Full changelog: CHANGELOG.md. Release PR: #3890.
Gist: https://gist.github.com/ruvnet/172e077daf43f6efd6532cd8191862d5