Back to Ruflo

Ruflo v3.32.32: Governed Flywheel Candidates and Explicit Autopilot Scope

v3/docs/releases/v3.32.32.md

3.32.403.0 KB
Original Source

Ruflo v3.32.32: Governed Flywheel Candidates and Explicit Autopilot Scope

Ruflo's self-improvement loop should explore useful candidates without relaxing its promotion guardrails, and Autopilot should never search a broader task surface than the operator requested. v3.32.32 fixes both contracts.

The Flywheel safety envelope now describes the complete retrieval policy that the built-in proposer actually emits. Valid candidates can reach evaluation again, while every tunable value remains bounded and promotion remains subject to signed receipts, policy authorization, and the atomic transaction gate.

Autopilot now treats explicitly configured task sources strictly. Misspelled, empty, or unsupported sources fail with a useful error instead of silently falling back to every default source. Recovery from absent or damaged legacy state remains backward compatible.

Install or upgrade

bash
npm install --global [email protected]
ruflo doctor

Or run without a global installation:

bash
npx [email protected] --version

Configure an exact Autopilot scope

The supported sources are team-tasks, swarm-tasks, and file-checklist.

bash
ruflo autopilot config \
  --task-sources swarm-tasks,file-checklist

Unsupported input now exits unsuccessfully and leaves the stored configuration unchanged:

bash
ruflo autopilot config --task-sources issues

Evaluate governed Flywheel candidates

bash
ruflo metaharness flywheel status
ruflo metaharness flywheel run --proposer local

The local proposer can now produce admissible full-policy candidates over alpha, subjectWeight, mmrLambda, bodyWeight, and typePenaltyFactor. Evaluation still cannot authorize promotion. Promotion requires an accepted receipt, trusted signing key, current baseline, matching ledger head, policy authorization, and explicit confirmation.

Compatibility

  • Existing valid Autopilot state continues to load unchanged.
  • Missing or corrupt persisted task-source state still recovers to the legacy defaults; only new explicit configuration is validated strictly.
  • The retrieval safety-envelope reference advances to v2. Old v1 receipts should be re-evaluated under the new envelope.
  • The release remains the standard three-package train: @claude-flow/cli, claude-flow, and ruflo.

Release note

v3.32.31 was reserved by an immutable Git tag, but its release pipeline stopped at helper-manifest verification before any npm publication. v3.32.32 contains the same reviewed fixes with the correctly versioned and signed helper manifest.

Validation contract

Release acceptance requires:

  • full CI for the Flywheel and Autopilot fixes;
  • combined focused tests;
  • version-lockstep validation across all three public packages;
  • signed helper-manifest verification;
  • immutable tarball construction and bundled-runtime inspection;
  • fresh-install CLI, policy, daemon, Codex initialization, and wrapper smokes;
  • registry integrity verification and aligned latest, alpha, and v3alpha tags.