Skip to content

build: estate pin upgrade (ruflo 3.51.1, Claude Code 2.1.288, agentic-qe, wrangler, solid-pod-rs alpha.12; mermaid/web-researcher held) - #17

Merged
jjohare merged 3 commits into
mainfrom
ruflo/pins-3.51.1
Oct 3, 2026
Merged

jjohare merged 3 commits into
mainfrom
ruflo/pins-3.51.1

Conversation

@jjohare

@jjohare jjohare commented Oct 3, 2026

Copy link
Copy Markdown

Three commits. Do not merge before the host rebuild (./agentbox.sh rebuild) materialises both FODs. Nix was not evaluated here, so the image is unverified.

Pins

before after
ruflo / @claude-flow/cli 3.47.0 3.51.1 (published 2026-10-02T16:17Z, inside the 72 h window)
Claude Code 2.1.285 (stable) 2.1.288 (latest; ~1 day old, inside the 3-day cool-off)
ruvector 0.3.3 unchanged (npm latest)
mcp/ruvnet-brain lock — unchanged (npm audit: 0 findings)

Both freshness exceptions are deliberate: ruflo-console (the 3.51 mods) needs Claude Code 2.1.287+.

Hash method (proved on the existing pins first)

  • ruflo tarball, flat sha256 → SRI: 3.47.0 sha256-3uiMa…ZxM= reproduces the pin; 3.51.1 sha256-vKkzPdeUUxh1cvtDUMuvdjIbJI3I44CQEr4JavXLpB4=
  • ruflo nodeModulesHash: NAR sha256 of the FOD tree (unpacked tarball + lock, npm ci --production --ignore-scripts --legacy-peer-deps, npm 10.9.9). 3.47.0 sha256-Wd//…YEg= reproduces the pin; 3.51.1 sha256-NMX4U+qBrQ+1P87EBlBp+QeBGBPRoXShqpcgV31CXCw=, identical on two clean installs
  • Claude Code: 2.1.285 x64 sha256-M9rR…PSk= and arm64 sha256-JPrH…Fz0= reproduce the pins. For 2.1.288, x64 sha256-ApgGi2…ZAw= and arm64 sha256-NZq2oF…udU= each equal the checksum in Anthropic's manifest.json.

Regression (3.47.0 vs 3.51.1, each run in a scratch prefix)

All identical exit codes. Calls: --version (ruflo and the claude-flow alias), hooks route (match and no-match, text and JSON), hooks pre-command, hooks post-command, hooks pre-edit, hooks post-edit, hooks session-restore, hooks session-end, swarm status, memory stats --format json, memory list --format json --limit 5, init --help, mcp start --help.

  • hooks route text output is unchanged, so the adapter's ROUTE_SIGNAL filter still matches. The JSON form only gains matched.
  • hooks_route MCP now returns matched:false at 30% when nothing matches. Nothing in the repo thresholds on it: the adapter uses the CLI, and the orchestration proxy denies hooks_*.
  • Orchestration proxy, live, with the real createOrchestrationProxy (swarm,agent): 21 tools forwarded, no denied tool leaked, and swarm_status/agent_list answer on both versions. The 11 unit tests pass.
  • Model-router console --dry-run (it imports ruvector/model-router.js, neural-router.js and agent-execute-core.js from the closure): every import resolves and it picks the same model. Confidence moves 0.599 → 0.507 (upstream calibration). Nothing gates on that value.
  • .claude/helpers memory/router/session become .cjs. hook-handler.cjs, which registered-hooks.txt prunes, is unchanged.
  • Behaviour change: ruflo init now enables the mods by default. It writes project enabledPlugins ×3, extraKnownMarketplaces.ruflo and env.CLAUDE_CODE_ENABLE_FUNCTION_HOOKS=1, then runs claude plugin install. That bypasses the manifest gate on function hooks. cf-init and agentbox-init now pass --no-mods, and tests/config/ruflo-init-no-mods.test.sh guards both (negative control fails as it should).
  • npm audit --omit=dev: 8 high both before and after (sharp/libvips, braces, toml, all transitive upstream). No new findings.

Gates

adr-index-gen --check and --check-index are OK, and adr-ratchet is OK. 13 stale ADRs were re-verified with dated notes; for ADR-2093/2121, the factrail plugin passes claude plugin validate --strict under 2.1.288 with an unchanged hook surface.

🤖 Generated by Claude Code

claude and others added 3 commits October 3, 2026 12:46
ruflo 3.51.x mods (ruflo-console) need Claude Code 2.1.287+. 2.1.288 is
the `latest` channel pointer (stable is still 2.1.285) and ~1 day past its
build stamp, inside the 3-day cool-off; taken for that floor.

Hash method (fetchurl flat sha256 = sha256 of the downloaded bytes, SRI):
proved by reproducing the existing pin first:
  2.1.285 linux-x64   sha256-M9rR7GFaLgjMeLSU8FwRDkmRbeLHnXjsh5nr9GsjPSk= (matches pin and manifest 33dad1ec…3d29)
  2.1.285 linux-arm64 sha256-JPrHd0m+09kTZda2kVqkuCThQxjstrwXrbwZLwHJFz0= (matches pin and manifest 24fac777…173d)
New pins, each equal to the 2.1.288 manifest.json checksum:
  2.1.288 linux-x64   sha256-ApgGi2huf9uvlAKnpYe7f0nAsOCE3gn2kUWgcZIHZAw= (0298068b…640c)
  2.1.288 linux-arm64 sha256-NZq2oFj83pdB3/VJeaIS/RNM346M/C+N4CvDULniudU= (359ab6a0…b9d5)

Image unverified until the host rebuild runs.

Co-Authored-By: jjohare <github@thedreamlab.uk>
npm latest; published 2026-10-02T16:17Z, inside the 72-hour window, taken
for the ruflo mods (ruflo-console needs Claude Code 2.1.287+, previous
commit). Lock: registry tarball unpacked, `npm install --package-lock-only
--ignore-scripts --legacy-peer-deps --before=2026-10-02T16:20:00Z` (no
transitive newer than the root); 682 entries, 0 added, 0 removed, 28
version changes (the @claude-flow/* alphas go to 3.0.x GA, MCP sdk 1.31.0,
@ruvector/router 0.1.32, ruvllm 2.7.0, hono 4.13.12).

Hash method, proved on the existing pin before computing the new one:
  tarball (fetchurl flat sha256 of the .tgz, SRI):
    ruflo-3.47.0.tgz sha256-3uiMaPAmDPypDYSLjmuLpRerQVqZWAWcgjF3yczjZxM= (= pin)
    ruflo-3.51.1.tgz sha256-vKkzPdeUUxh1cvtDUMuvdjIbJI3I44CQEr4JavXLpB4=
  nodeModulesHash (NAR sha256 of the FOD tree: tarball unpacked, lock
  copied, `npm ci --production --ignore-scripts --legacy-peer-deps`, npm
  10.9.9 / node 22.23.3):
    3.47.0 sha256-Wd//CPe78tLakvglOGGkC3u+uS2Y2olsRieAdlKfYEg= (= pin)
    3.51.1 sha256-NMX4U+qBrQ+1P87EBlBp+QeBGBPRoXShqpcgV31CXCw= (identical on two clean installs)

Upstream behaviour change the image must absorb: `ruflo init` now enables
the mods by default (project enabledPlugins x3, extraKnownMarketplaces.ruflo,
env.CLAUDE_CODE_ENABLE_FUNCTION_HOOKS=1, then `claude plugin install`),
which bypasses the manifest gate on function hooks. The image's own init
calls (cf-init, agentbox-init) now pass --no-mods; opting in stays explicit
(`ruflo mods install`). tests/config/ruflo-init-no-mods.test.sh guards the
call sites (and fails on a grep error rather than passing) and, given a 3.51+
CLI, proves --no-mods writes none of the three keys.

hooks_route now answers `matched:false` at 30% on no match. No consumer
thresholds it: the hook adapter filters the CLI `hooks route` text, whose
format is unchanged (the JSON form only gains `matched`), and the
orchestration proxy denies hooks_*.

Image unverified until the host rebuild runs.

Co-Authored-By: jjohare <github@thedreamlab.uk>
…2.1.288 pins (daba195)

11 records tripped by flake.nix (the rufloPkg pin only) and ADR-2093/2121 by
lib/claude-code-binary.nix. For the latter the baked factrail plugin passes
`claude plugin validate --strict` under 2.1.288 with the same hook surface as
2.1.285. ADR-2092 notes that the image's init calls now pass --no-mods.
No decision changes.

Co-Authored-By: jjohare <github@thedreamlab.uk>
@jjohare
jjohare merged commit 497e95a into main Oct 3, 2026
11 checks passed
@jjohare
jjohare deleted the ruflo/pins-3.51.1 branch October 3, 2026 12:54
@jjohare jjohare changed the title build: ruflo 3.51.1, Claude Code 2.1.288 build: estate pin upgrade (ruflo 3.51.1, Claude Code 2.1.288, agentic-qe, wrangler, solid-pod-rs alpha.12; mermaid/web-researcher held) Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants