Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
45 commits
Select commit Hold shift + click to select a range
eabab35
docs(plan): Branch 3 Ruflo support window code-level plan
pacphi Sep 27, 2026
b976c04
feat(upstream): record the Ruflo support window on its dependency policy
pacphi Sep 27, 2026
70790c3
feat(versions): support a rolling window of Ruflo minors (n-5, at lea…
pacphi Sep 27, 2026
afc42eb
feat(upstream): hold workaround removals until the oldest supported R…
pacphi Sep 27, 2026
73f3010
refactor(statusline): remove the retired CVE-counter overlay
pacphi Sep 27, 2026
b6d3740
docs(status): drop the stale "#2986 pending" note
pacphi Sep 27, 2026
4b2f698
docs(adr): record the Ruflo support window (ADR-0041 §7)
pacphi Sep 27, 2026
fcf4669
feat(status): show whether Ruflo's backup and distillation are running
pacphi Sep 27, 2026
a9d59cd
feat(ruflo-daemon): enable auto-start with Ruflo's supported daemon s…
pacphi Sep 27, 2026
5ef0564
docs(ruflo-daemon): document managed daemon settings and start-on-use
pacphi Sep 27, 2026
dbd2bb2
fix(status): offer the daemon repair only where sync performs it
pacphi Sep 27, 2026
0fa60cc
fix(security): stop reporting defend as non-functional when Ruflo shi…
pacphi Sep 27, 2026
bd9eb73
feat(setup): drop the init opt-out suppression on Ruflo 3.46.0 and newer
pacphi Sep 27, 2026
4f76df3
fix(ruflo-components): governance is enforced on stdio from Ruflo 3.46.0
pacphi Sep 27, 2026
a13c3b1
feat(ruflo-components): keep ak's MCP policy file out of git
pacphi Sep 27, 2026
861a943
chore(upstream): retire ruvnet/ruflo#3166 (doctor reports agent-brows…
pacphi Sep 27, 2026
e6d7b7d
chore(upstream): record the partial #3193 fix shipped in Ruflo 3.46.0
pacphi Sep 27, 2026
ceac98b
docs(ci): correct the nightly note for ruvnet/ruflo#2885
pacphi Sep 27, 2026
e52d08b
docs(adr): record governance on stdio and the security wording (ADR-0…
pacphi Sep 27, 2026
457088b
test(ruflo-components): keep the git-exclude tests portable to Windows
pacphi Sep 27, 2026
99714e6
docs(upgrading): ak keeps its MCP policy file out of git
pacphi Sep 27, 2026
518b4be
feat(ruflo-mcp): a Claude mode that pins only the memory location
pacphi Sep 27, 2026
8c91658
feat(mcp): route Claude Code's Ruflo MCP through ak x ruflo-mcp
pacphi Sep 27, 2026
8966a18
fix(memory): Claude-side harvest and setup use the user-level store o…
pacphi Sep 27, 2026
ec6c936
feat(sync): remove ak's old setup probe rows once, with a backup and …
pacphi Sep 27, 2026
e794652
docs(audit): record Branch 3 decisions and the Claude launcher route
pacphi Sep 27, 2026
3fae179
docs(adr): ADR-0017 no longer calls ruflo mcp start ak's Claude and C…
pacphi Sep 27, 2026
2d150cd
fix(ruflo-mcp): start ruflo through the resolved Windows shim
pacphi Sep 27, 2026
3615eb4
fix(status): report a daemon config.json ak leaves to the user
pacphi Sep 27, 2026
a5cef18
fix(daemons): offer the macOS threshold fix only when ak manages it
pacphi Sep 27, 2026
564c126
fix(status): make the mcp fixes manual while ak is not on PATH
pacphi Sep 27, 2026
f1efde4
docs: status names a held daemon key and the ak-on-PATH step
pacphi Sep 27, 2026
68206cf
test: keep Branch 3's tests inside the suite's sandbox rules
pacphi Sep 27, 2026
a4323cd
fix(mcp): register the Claude launcher only when the PATH ak supports it
pacphi Sep 27, 2026
f271c88
test(mcp): convergence expects Claude Code's launcher registration
pacphi Sep 27, 2026
57e05c3
fix(codex-mcp): disable Codex's imported copy of Claude Code's launch…
pacphi Sep 27, 2026
1277370
fix(ruflo-daemon): manage daemon settings only in a durable Ruflo pro…
pacphi Sep 27, 2026
b953d10
docs(audit): mark Branch 3's resolved open items and record fix round 2
pacphi Sep 27, 2026
21dde92
docs(upgrading): the PATH ak needs a launcher that takes --host
pacphi Sep 27, 2026
6fd1efd
chore(upstream-watch): register the four threads filed on 2026-09-27
pacphi Sep 27, 2026
3023d5c
feat(upstream-watch): hold AgentDB fixes until the oldest supported R…
pacphi Sep 27, 2026
a91d957
docs(schema): document supportWindow and the <major>.<minor>.x affect…
pacphi Sep 27, 2026
8cf1871
docs(audit): record decision B3-D5
pacphi Sep 27, 2026
6fdc989
test(memory): close the WAL holder before the fixture folder is removed
pacphi Sep 27, 2026
bb07bc2
test(docs): read ADR headers with LF line endings in the living-plan …
pacphi Sep 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion .agents/skills/upstream-status/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,9 @@ dependency policies, constraints, and the `watch` list of upstream threads.

For each item give the id, title, URL and a one-line reason: who replied and when, which
release, or which ak change is pending. Give "Fixed upstream, not yet released",
"Waiting on upstream" and "Unmapped (no ak change recorded)" as counts only, unless asked.
"Released, waiting for the support window", "Waiting on upstream" and
"Unmapped (no ak change recorded)" as counts only, unless asked. A held item is not
dispatched: the oldest Ruflo in the support window (`supportWindow.floor`) predates its fix.
4. Offer the next actions that fit:
- Draft a reply to an upstream thread. Show the draft; do not post it.
- Dispatch a released item: branch `upstream/<id>` from `main`, make the entry's `adjustment`
Expand Down
4 changes: 3 additions & 1 deletion .claude/skills/upstream-status/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,9 @@ dependency policies, constraints, and the `watch` list of upstream threads.

For each item give the id, title, URL and a one-line reason: who replied and when, which
release, or which ak change is pending. Give "Fixed upstream, not yet released",
"Waiting on upstream" and "Unmapped (no ak change recorded)" as counts only, unless asked.
"Released, waiting for the support window", "Waiting on upstream" and
"Unmapped (no ak change recorded)" as counts only, unless asked. A held item is not
dispatched: the oldest Ruflo in the support window (`supportWindow.floor`) predates its fix.
4. Offer the next actions that fit:
- Draft a reply to an upstream thread. Show the draft; do not post it.
- Dispatch a released item: branch `upstream/<id>` from `main`, make the entry's `adjustment`
Expand Down
6 changes: 5 additions & 1 deletion .github/workflows/nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -78,7 +78,11 @@ jobs:
} >> "$GITHUB_STEP_SUMMARY"

# Non-blocking: a native libc++abi mutex abort on macos-latest poisons ruflo
# exit codes, tracked upstream at ruvnet/ruflo#2885 (open as of 2026-08-13).
# exit codes, tracked upstream at ruvnet/ruflo#2885 (open; the Aug 31 triage
# points at better-sqlite3 with onnxruntime-node on macOS arm64). A hosted
# probe on 2026-09-27 (Ruflo 3.46.1, run 36333572972) aborted 10/10 with the
# default settings and 10/10 with single-threaded ONNX Runtime sessions, so
# that mitigation does not help (issuecomment-5857781254).
# Scope is NOT neural-train-specific: upstream evidence (2026-08-12) shows the
# same teardown abort on store-touching commands (`memory search` → correct
# output, rc 134), so an `x verify memory` step added here would need the same
Expand Down
3 changes: 2 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -175,7 +175,8 @@ One of those is worth calling out:

Projects set up by the kit get an append-only footer under ruflo's own status line,
with segments reflecting their documented presence and metric checks: 🧠 SONA patterns/trajectories (+
live micro-LoRA Δ‖W‖), 📈 route-RL metrics, 🛡 aidefence, 🧿 RuvNet Brain KB,
live micro-LoRA Δ‖W‖), 📈 route-RL metrics, a ⚠ aidefence OFF alarm (only when Ruflo has no
prompt-injection engine at all), 🧿 RuvNet Brain KB,
⚙ machine-wide daemon count, and 🎓 Agentic-QE stats.

That rich, command-backed footer is a Claude Code surface. Codex supports a
Expand Down
4 changes: 2 additions & 2 deletions docs/DASHBOARD.md
Original file line number Diff line number Diff line change
Expand Up @@ -184,8 +184,8 @@ memory durability fix, and the funnel toggle — get one card each in Overview >
shows the state badge beside its plain-language meaning (and the action to take, when one
applies), the current value and who controls it, an expandable "what it does" with its benefit,
cost, and how to change it in `kit.json`, and the live evidence behind the state: which picker a
`hooks route` probe reported, MCP calls audited and refused in the last 24 hours (zero on ruflo
≤ 3.44.0, which does not yet enforce the policy on stdio launches; see
`hooks route` probe reported, MCP calls audited and refused in the last 24 hours (zero on Ruflo
below 3.46.0, which does not enforce the policy on stdio launches; see
[ADR-0058](adr/0058-managed-ruflo-components.md)), whether the
learning engine is loaded, or the funnel's deciding source. The panel header repeats the same
count and ruflo version `ak status` reports, so the two never disagree. Encryption at rest shows
Expand Down
10 changes: 5 additions & 5 deletions docs/HOST-SUPPORT.md
Original file line number Diff line number Diff line change
Expand Up @@ -107,9 +107,9 @@ Official extension references: [Claude hooks](https://code.claude.com/docs/en/ho
| Ruflo capability | Claude Code | Codex | OpenCode |
| --- | --- | --- | --- |
| Upstream host orientation | **Native:** primary/reference CLI surface | **Native + managed:** upstream backend/plugin pieces plus agentic-kit integration | **Managed:** no equivalent upstream backend flag |
| Ruflo MCP tools | Native registration | Managed Ruflo MCP registration | Connected managed MCP; compact lazy `ak_ruflo_*` provider projection |
| Ruflo browser executor | Process-scoped trusted agent-browser config | Same config inherited by `ak x ruflo-mcp` | Same config in the receipt-owned MCP environment |
| Shared Ruflo memory | Same project store | Same project store | Same project store when pointed at the same Ruflo server |
| Ruflo MCP tools | Managed user-scope registration through `ak x ruflo-mcp --host claude` | Managed Ruflo MCP registration through `ak x ruflo-mcp` | Connected managed MCP; compact lazy `ak_ruflo_*` provider projection |
| Ruflo browser executor | Process-scoped trusted agent-browser config, set by the launcher | Same config inherited by `ak x ruflo-mcp` | Same config in the receipt-owned MCP environment |
| Shared Ruflo memory | Same project store; the user-level store outside projects | Same project store; the user-level store outside projects | Same project store when pointed at the same Ruflo server |
| Agents and skills | Upstream Claude assets | Codex-compatible skills/plugin assets and generated guidance | Receipt-owned lazy profile catalogue through one stock `ak-specialist`; stock skills loaded on demand |
| Lifecycle hooks | Native Claude hooks | Codex hooks/plugin surfaces | OpenCode events translated by `ruflo-hooks.js` |
| Inference-backend flag | `ENABLE_CLAUDE_CODE` | `ENABLE_CODEX` | None |
Expand All @@ -132,8 +132,8 @@ The dated upstream risk inventory includes:
([#2638](https://github.com/ruvnet/ruflo/issues/2638));
- init and plugin installation can duplicate assets or hooks
([#2640](https://github.com/ruvnet/ruflo/issues/2640));
- published 3.38.21 ignores its Codex/skills init opt-out flags
([#3167](https://github.com/ruvnet/ruflo/issues/3167));
- Ruflo below 3.46.0 ignores its Codex/skills init opt-out flags, so `ak setup` adds scripted
mode and `RUFLO_NO_SKILLS_SH=1` there ([#3167](https://github.com/ruvnet/ruflo/issues/3167));
- dual-host marketplace parity remains incomplete
([#2854](https://github.com/ruvnet/ruflo/issues/2854)); and
- hierarchical AgentDB writes can report success without durable persistence
Expand Down
12 changes: 7 additions & 5 deletions docs/MANAGED-TOOLS.md
Original file line number Diff line number Diff line change
Expand Up @@ -117,7 +117,7 @@ version supports; `ak status` reports the real state, never a bare label.
| --- | --- | --- | --- |
| Typesafe agent picker | on | 3.43.0 | global `@ruvector/typesafe` package + `CLAUDE_FLOW_ROUTER_TYPESAFE=1` |
| MiniLM agent picker | on | 3.44.0 | `CLAUDE_FLOW_ROUTER_EMBEDDER=minilm` |
| MCP tool governance | on; 120 calls/min, audit on | 3.42.0 | project `.harness/mcp-policy.json` + project-scoped `RUFLO_MCP_ENFORCE_POLICY=1` (not yet enforced on stdio launches by ruflo ≤ 3.44.0) |
| MCP tool governance | on; 120 calls/min, audit on | 3.42.0 | project `.harness/mcp-policy.json` + project-scoped `RUFLO_MCP_ENFORCE_POLICY=1` (enforced on stdio launches from Ruflo 3.46.0) |
| Learning profile | `balanced` | 3.42.1 | `RUFLO_INTELLIGENCE_MODE=balanced` |
| MetaHarness turn-credit | on | 3.36.0 | nothing to apply; ak confirms ruflo's bundled dependency resolves |
| Memory durability fix (#2887) | on | 3.36.0 | nothing to apply; ak confirms `@claude-flow/memory` ≥ 3.0.0-alpha.22 |
Expand All @@ -144,10 +144,12 @@ components in the same settings file. If you delete a value ak set, `ak status`

The governance policy file is enforced only when it carries ak's own `_about` marker; a
project's own pre-existing `.harness/mcp-policy.json` is left alone and reported `user-managed`.
Ruflo 3.44.0 and earlier do not apply the policy on the stdio MCP launches Claude Code, Codex and
OpenCode use (ADR-0058 upstream request 6): ak writes the file and the variable so they are ready
when ruflo wires enforcement, and the component reports `unknown` until then, because no audit
records appear.
Ruflo 3.46.0 and newer apply the policy on the stdio MCP launches Claude Code, Codex and OpenCode
use: calls beyond the cap are refused and every call is audited. Older Ruflo does not apply it on
those launches, so there the component reports `unknown`, because no audit records appear. ak
keeps its own policy file out of git with one line in the repository's `.git/info/exclude`
(never `.gitignore`, and never the whole `.harness/` folder, which other tools use for files they
commit); removing the policy removes that line.

Every state `ak status`, `ak setup`, and the dashboard show carries its meaning and, where one
applies, the fix:
Expand Down
37 changes: 23 additions & 14 deletions docs/SETUP.md
Original file line number Diff line number Diff line change
Expand Up @@ -122,13 +122,14 @@ versions. The table below describes the current contract.
| Path or state | Existing project | New/empty project |
| --- | --- | --- |
| Application source, `package.json`, and arbitrary project files | Not intentionally changed by agentic-kit. | No application is scaffolded. |
| `.claude/settings.json` | Regenerated by `ruflo init --full --force`; agentic-kit then disables `claudeFlow.daemon.autoStart` if it is `true`, and AQE may merge its hooks/settings. Ruflo also reads that `false` as "do not start the daemon when a `ruflo` command runs", so the daemon, and with it memory backup and distillation, runs only when started ([details](TROUBLESHOOTING.md#memory-backup-and-distillation)). Custom content can be at risk. | Created with Ruflo settings, then normalized and optionally extended by AQE. |
| `.claude/settings.json` | Regenerated by `ruflo init --full --force`, which writes `claudeFlow.daemon.autoStart: false`. Agentic-kit turns that `false` into `true`, so Ruflo starts the project daemon (and with it memory backup and distillation) on the next `ruflo` command, and keeps the old value to restore on `ak uninstall`. To keep it off, set `rufloDaemon.autoStart` to `false` in `kit.json` ([details](TROUBLESHOOTING.md#memory-backup-and-distillation)). AQE may merge its hooks/settings. Custom content can be at risk. | Created with Ruflo settings, then normalized and optionally extended by AQE. |
| `.claude/settings.local.json` | Valid existing JSON is preserved and merged with an absolute `env.CLAUDE_FLOW_DB_PATH`. A one-time `.bak` is created before agentic-kit writes it. Invalid JSON is treated as empty. | Created with the absolute memory path. |
| `.claude/skills/`, `.claude/commands/`, `.claude/agents/`, `.claude/helpers/` | Ruflo's matching generated assets are overwritten; AQE assets are then added or refreshed. Unrelated extra files are generally not swept. | Generated and populated. |
| `CLAUDE.md` | Agentic-kit captures the pre-init bytes before Ruflo runs, restores user-authored prose outside its own sentinels, and reconciles the bounded managed projection before and after AQE. An exact old unsentineled lean stub is migrated; a near-match is preserved. In an AGENTS-only repository, the created file is the one-line `@AGENTS.md` reference. | Created only when required: bounded managed guidance, or a one-line `@AGENTS.md` reference when that is the existing project guidance source. |
| `.mcp.json` | Ruflo force-init regenerates this file before agentic-kit removes project-local `ruflo`, `claude-flow`, `ruv-swarm`, and `flow-nexus` entries. The file is deleted if those are the only remaining content. AQE may subsequently add its own server. Because regeneration happens first, pre-existing custom MCP entries can be lost; preserve them separately and restore them after setup. | Temporarily generated and sanitized; it may be absent afterward unless AQE or another retained entry needs it. |
| Claude's project-local `ruflo` MCP registration | Removed with `claude mcp remove ruflo -s local`; agentic-kit offers user-scope registration instead. | Same behavior. |
| `.claude-flow/` generated config and runtime support files | Ruflo-generated files are refreshed. Agentic-kit initializes memory and swarm state, starts the local-only daemon (it ends itself after 12 hours), and injects/heals the status-line footer. | Created and initialized. |
| `.claude-flow/config.json` | Before starting the daemon, agentic-kit adds only the flat keys the installed Ruflo needs: `"daemon.idleSecs": 0` below Ruflo 3.46.0, and `"daemon.resourceThresholds.minFreeMemoryPercent": 0` on macOS. Other keys are kept. A file that is not a readable JSON object, or a key that holds your own value, is left alone, and `ak status` names the key to set yourself. `ak sync` removes a key once the installed Ruflo no longer needs it, and `ak uninstall` removes them all. | Created only when a key is needed (always on macOS). |
| `.swarm/memory.db` and adjacent memory stores | Initialized or migrated in place. Agentic-kit writes a disposable verification record, confirms the on-disk row, and removes only that probe. | Created/initialized and verified. |
| `.agentic-qe/` and AQE integration assets | With AQE enabled, `aqe init --auto` migrates or refreshes its database, configuration, workers, skills, agents, hooks, and platform integrations. Generated assets can change with the installed AQE version. | Created and initialized when AQE is enabled. |
| Oversized `.agentic-qe/*.rvf` stores | An RVF file over 2 GiB and its `.lock`, `.idmap.json`, and `.manifest.json` sidecars are removed before AQE initialization. Normal-sized stores are left to AQE. | Normally not applicable. |
Expand All @@ -145,8 +146,9 @@ their supported initializer arguments. AQE owns and updates its guidance block.
Setup with Codex enabled inventories the effective user Codex MCP configuration
even in machine-only mode. When project setup is active it inventories that
project's Codex MCP configuration too. An exact recursive
`[mcp_servers.codex]` entry and the exact deprecated `claude-flow` Ruflo
transport are listed in the setup trust manifest, backed up, corrected only after
`[mcp_servers.codex]` entry and an exact `claude-flow` Ruflo alias (the deprecated
`ruflo mcp start` transport, or a copy of Claude Code's `ak x ruflo-mcp --host claude`
registration that Codex's Claude import added) are listed in the setup trust manifest, backed up, corrected only after
the setup confirmation (or `--yes`), and re-probed before setup may report
success. The recursive entry is removed; the `claude-flow` alias is replaced by a
disabled placeholder so Codex's Claude config import cannot add it back. A fresh recovery copy captures the immediate pre-repair bytes; symlinked
Expand Down Expand Up @@ -175,10 +177,11 @@ The project guidance result is defined by ownership, not by which initializer ra
Agentic-QE's `BEGIN AGENTIC-QE CODEX` block is owned by Agentic-QE, not by this merge engine. Setup
uses a bounded compatibility guard and reconciles around AQE initialization, but does not claim
arbitrary AQE content. Ruflo is called with `--no-global`, `--no-codex-detect`, and
`--no-skills-sh` to declare the machine/Codex ownership boundary. Published Ruflo 3.38.21 does not
honor the two hyphenated skill flags ([ruflo #3167](https://github.com/ruvnet/ruflo/issues/3167)),
so agentic-kit additionally uses scripted `--format json` mode and `RUFLO_NO_SKILLS_SH=1`; both
independently suppress the optional projections in that release. Existing unreceipted skills
`--no-skills-sh` to declare the machine/Codex ownership boundary. Ruflo below 3.46.0 does not
honor the two hyphenated flags ([ruflo #3167](https://github.com/ruvnet/ruflo/issues/3167)), so
on those versions agentic-kit also uses scripted `--format json` mode and `RUFLO_NO_SKILLS_SH=1`;
both independently suppress the optional projections. On Ruflo 3.46.0 and newer the flags alone
are passed. Existing unreceipted skills
remain review-only. A future upgrade may remove a stale projection only when its path and
last-written digest are receipt-owned and the file is still unchanged. Generated settings, skills,
agents and hooks remain subject to the upstream ownership and overwrite warnings in the table above.
Expand Down Expand Up @@ -246,13 +249,19 @@ never touches the plugin cache or Claude Code's plugin state. `ak status` reads
enabled bundles to report known placement, hook, and skill portability problems.

All enabled hosts converge on the same project-scoped Ruflo memory contract.
Claude receives the absolute `CLAUDE_FLOW_DB_PATH` in project settings. Codex's
user-scoped Ruflo MCP registration launches `ak x ruflo-mcp`, which derives the
pin from the workspace at process start: the Git repository, else the folder
itself. When Codex starts at the filesystem root, in the home folder itself, in a
temporary root or inside a tool's own folder (`~/.codex`, `~/.claude`, `~/.config`,
and similar), the launcher uses one user-level store, `~/.claude-flow/memory`,
instead of creating `.swarm` there. OpenCode's managed MCP gateway and
Claude receives the absolute `CLAUDE_FLOW_DB_PATH` in project settings. The
user-scoped Ruflo MCP registrations of Claude Code (`ak x ruflo-mcp --host claude`)
and Codex (`ak x ruflo-mcp`) start ak's launcher, which derives the pin from the
workspace at process start: the Git repository, else the folder itself. Ruflo
starts at that root, so a session opened in a subfolder uses the repository's
store and MCP policy file. When a session starts at the filesystem root, in the
home folder itself, in a temporary root or inside a tool's own folder (`~/.codex`,
`~/.claude`, `~/.config`, and similar), the launcher uses one user-level store,
`~/.claude-flow/memory`, instead of creating `.swarm` there. `ak x harvest`
follows the same rule, and `ak setup --project` refuses in such a folder. The
Claude registration needs `ak` on the `PATH` Claude Code starts with, at a version whose
launcher takes `--host` (ak checks `ak x ruflo-mcp --help`); otherwise setup and sync leave
the existing registration in place and say so. OpenCode's managed MCP gateway and
lifecycle bridge receive its project directory and set the same absolute pin.
Ruflo's MCP tools use `.swarm/agentdb-memory.db` beside the pinned
`.swarm/memory.db`; that sibling is the native store, not configuration drift.
Expand Down
Loading
Loading