Skip to content

Loki Mode

v7.77.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents aider anthropic autonomous ci-cd claude
+13 more
cline code-review devops gemini github-action github-issues loki-mode multi-agent openai-codex openapi pull-request-review sdlc spec-driven-development

Affected surfaces

auth breaking_upgrade

Summary

AI summary

Fixed indefinite council dispatch hangs and secured /lab routes under enterprise auth.

Full changelog

WAVE13-TAIL hardening: council timeout, /lab auth, memory + durability

Final wave-13 bug-fix batch. Council 3/3.

  • Council dispatch timeout (HIGH regression): the Phase C completion-council
    dispatch (autonomy/lib/voter-agents.sh) invoked claude --agents with no
    timeout, so a hung dispatch stalled the entire run indefinitely. It is now
    wrapped in timeout ${LOKI_COUNCIL_REVIEW_TIMEOUT:-600} (parity with the
    heuristic path); a timeout (exit 124) or any non-zero exit falls back to the
    heuristic council and can never become a false COMPLETE.
  • Dashboard /lab auth (HIGH, enterprise-auth mode): the Purple Lab sub-app
    mounted at /lab bypassed the dashboard's auth because Starlette does not
    propagate a parent app's auth to a mounted sub-app, leaving file write/delete
    and process-spawn routes reachable unauthenticated when LOKI_ENTERPRISE_AUTH
    was on. A mount-boundary ASGI guard now enforces the same scoped token as the
    dashboard for all /lab/* requests; with auth off it is a pass-through (local
    dashboards unchanged). Read endpoints that were missing require_scope("read")
    (and /api/logs) are now consistent with their gated siblings.
  • Memory: bounded the keyword-search episodic scan (was unbounded); removed the
    consolidation lock-file unlink that reintroduced a flock+unlink inode race
    (two consolidations could run concurrently); load_episode now sanitizes the
    episode id symmetrically with save_episode; store_episode validates the date
    string.
  • Bun runtime durability: atomic writers now fsync the temp file before rename
    and fsync the parent directory after, so tmp+rename gives durability not just
    ordering. Subprocess stdout reads are capped at 16 MB.

local-ci 85/0. Memory 28 + 9 tests, loki-ts 1098 tests, council quorum 7/7 all
green; dashboard auth behavior verified (off = pass-through, on = 401/403/200).

Security Fixes

  • /lab sub‑app now enforces dashboard authentication when LOKI_ENTERPRISE_AUTH is enabled, preventing unauthenticated file write/delete and process‑spawn access

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Loki Mode

Get notified when new releases ship.

Sign up free

About Loki Mode

Multi-agent autonomous SDLC framework. Spec to deployed app. PRD, GitHub issue, OpenAPI/JSON/YAML, or one-line brief. 5 AI providers, 11 quality gates.

All releases →

Related context

Beta — feedback welcome: [email protected]