Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
98 commits
Select commit Hold shift + click to select a range
09d56f3
feat: add EdgeGuard Cypher guard
toderian Jun 10, 2026
02362e5
feat: add EdgeGuard guarded API
toderian Jun 10, 2026
050f266
docs: add EdgeGuard playground WAR config
toderian Jun 10, 2026
39bd3a1
docs: document EdgeGuard playground tunnel secret
toderian Jun 10, 2026
af1e026
fix: wire EdgeGuard playground through semaphores
toderian Jun 10, 2026
09ef55b
fix: harden EdgeGuard API runtime wiring
toderian Jun 10, 2026
e1ef478
fix: restore edg3 dauth comms profile
toderian Jun 10, 2026
ba3897a
merge develop updates into EdgeGuard API branch
toderian Jun 16, 2026
ab725e1
chore: retarget edgeguard playground model
toderian Jun 18, 2026
af338e5
feat: add edgeguard empty-result broadening
toderian Jun 18, 2026
9b7b9ab
fix: harden edgeguard neo4j execution
toderian Jun 18, 2026
a1016d7
Merge remote-tracking branch 'origin/develop' into feature/egm-009-ed…
toderian Jun 22, 2026
c817a72
Merge remote-tracking branch 'origin/develop' into feature/egm-009-ed…
toderian Jun 30, 2026
580cf23
Merge remote-tracking branch 'origin/develop' into feature/egm-009-ed…
toderian Jun 30, 2026
d166f97
Merge remote-tracking branch 'origin/develop' into feature/egm-009-ed…
toderian Jul 1, 2026
2642879
feat: prepare EdgeGuard v0.9 guard context
toderian Jul 1, 2026
1662623
Merge remote-tracking branch 'origin/develop' into feature/egm-009-ed…
toderian Jul 2, 2026
e3b70da
Merge remote-tracking branch 'origin/develop' into feature/egm-009-ed…
toderian Jul 3, 2026
4ac6b19
feat(edgeguard): promote runtime model to v0.9 graph-intent GGUF
toderian Jul 6, 2026
cbaf2a1
feat(serving): resolve GGUF from HF by glob with subfolder support
toderian Jul 6, 2026
ec5965b
feat(edgeguard): retarget playground runtime to v0.10
toderian Jul 7, 2026
fd0813a
Merge remote-tracking branch 'origin/develop' into feature/egm-009-ed…
toderian Jul 9, 2026
2341828
fix(edgeguard): fail closed on empty inference responses
toderian Jul 10, 2026
aca5388
refactor(edgeguard): isolate cybersec edgeguard package
toderian Jul 10, 2026
f5016d1
feat: add EdgeGuard graph explanation API
toderian Jul 10, 2026
4194159
feat: expose EdgeGuard model comparison metadata
toderian Jul 13, 2026
1bdb52c
fix(edgeguard): align model worker runtime contract
toderian Jul 15, 2026
bfa8d6e
feat(edgeguard): gate CyberSecQwen catalog metadata
toderian Jul 15, 2026
ff98bd9
docs(edgeguard): add CyberSecQwen runtime stream
toderian Jul 15, 2026
9b38a69
feat(edgeguard): always expose CyberSecQwen metadata
toderian Jul 15, 2026
542d947
feat: center graph explanations on user questions
toderian Jul 16, 2026
eb8369a
Merge remote-tracking branch 'origin/develop' into feature/egm-009-ed…
toderian Jul 16, 2026
0a126c6
fix: accept prepared graph execution evidence
toderian Jul 16, 2026
e4e95f1
fix: fail fast on LLM context overflow
toderian Jul 16, 2026
22d683d
feat: generate summary-first graph explanations
toderian Jul 17, 2026
1322b5f
fix: address execute-plan review round 1
toderian Jul 17, 2026
a79f4d8
fix: address execute-plan review round 2
toderian Jul 17, 2026
df16b91
fix: address execute-plan review round 3
toderian Jul 17, 2026
13df29b
feat: bound graph explanation drafts
toderian Jul 17, 2026
61ecf1d
fix: ignore unrelated empty inference placeholders
toderian Jul 17, 2026
779419b
fix: harden bounded explanation transport
toderian Jul 17, 2026
87db3fb
fix: prioritize authoritative completion metadata
toderian Jul 17, 2026
3ea71f3
Merge remote-tracking branch 'origin/develop' into feature/egm-009-ed…
toderian Jul 19, 2026
fcfefdd
fix: raise graph explanation ceiling
toderian Jul 20, 2026
568d4c9
fix: make explanation audit unconditional
toderian Jul 20, 2026
4f7cfa2
feat: add graph explanation failure diagnostics
toderian Jul 20, 2026
7040e89
fix: close explanation diagnostic terminal gaps
toderian Jul 20, 2026
efe071d
fix: constrain graph explanation drafts
toderian Jul 20, 2026
dde875d
Revert "fix: constrain graph explanation drafts"
toderian Jul 20, 2026
3f43a78
fix: preserve complete bounded Cypher results
toderian Jul 20, 2026
b0786ea
fix: enforce explanation result provenance
toderian Jul 20, 2026
f28b110
fix: validate canonical explanation evidence
toderian Jul 20, 2026
41e27c6
fix: accept canonical zoned datetimes
toderian Jul 20, 2026
e65c88a
fix: fail closed before explanation mode selection
toderian Jul 20, 2026
3997d99
feat: add one-attempt benchmark inference mode
toderian Jul 20, 2026
1fdfc38
fix: close benchmark terminal requests
toderian Jul 20, 2026
a6daa1a
fix: forward benchmark mode through 5091
toderian Jul 20, 2026
9610902
fix: propagate benchmark telemetry through 5091
toderian Jul 20, 2026
6e1a797
feat: expose LLM serving readiness
toderian Jul 20, 2026
5442b18
fix: gate internal benchmark mode
toderian Jul 20, 2026
8e832f9
feat: report benchmark enablement state
toderian Jul 20, 2026
d121d93
feat: fingerprint loaded benchmark runtime
toderian Jul 21, 2026
3847133
fix: bind actual loaded llama runtime
toderian Jul 21, 2026
b01bf49
feat: attest loaded EdgeGuard worker code
toderian Jul 21, 2026
1f64190
fix: attest EdgeGuard worker base modules
toderian Jul 22, 2026
dead687
feat: add codec-neutral graph evidence core
toderian Jul 22, 2026
17fb770
fix: preserve graph evidence closure semantics
toderian Jul 22, 2026
15935a3
fix: preserve evidence entity encounter order
toderian Jul 22, 2026
7a45356
Merge remote-tracking branch 'origin/develop' into feature/egm-009-ed…
toderian Jul 22, 2026
57e153e
feat(edgeguard): productize graph-first explanations
toderian Jul 22, 2026
8607a44
fix(edgeguard): trace graph-first preflight failures
toderian Jul 22, 2026
7d27e93
fix(edgeguard): reject invalid native explain fields
toderian Jul 22, 2026
2233aa0
fix(edgeguard): make document hashes cross-runtime
toderian Jul 22, 2026
29a0ec3
fix(edgeguard): harden graph-first explain boundary
toderian Jul 23, 2026
85213e8
fix(edgeguard): bound provider receipt metadata
toderian Jul 23, 2026
93767a9
fix(edgeguard): safely transport evidence validation failures
toderian Jul 23, 2026
e070be7
test(edgeguard): cover thorough map topology
toderian Jul 23, 2026
d3114ff
fix(inference): process queued result alignment
toderian Jul 23, 2026
c72ce96
fix(edgeguard): admit bounded scalar property lists
toderian Jul 23, 2026
d1fec73
feat(edgeguard): port EGX/1 explain pipeline pure modules
toderian Jul 24, 2026
a04b47b
test(edgeguard): add offline suite for the EGX/1 explain pipeline
toderian Jul 24, 2026
6c96a79
feat(edgeguard): wire EGX/1 into the graph-first orchestrator
toderian Jul 24, 2026
2a8d3ef
fix(edgeguard): emit trace gate outcomes as plain booleans
toderian Jul 24, 2026
d448043
docs(edgeguard): describe the EGX/1 explanation profile
toderian Jul 24, 2026
7291848
fix(edgeguard): always measure explain call duration in the runtime
toderian Jul 24, 2026
64d1cd7
Merge remote-tracking branch 'origin/develop' into feature/egm-009-ed…
toderian Jul 24, 2026
f2208bf
feat(inference): add distinct base Qwen serving profile
toderian Jul 24, 2026
3181b60
fix(benchmark): bind seed and phase telemetry
toderian Jul 24, 2026
49d95dc
feat(edgeguard): isolate pinned llama serving profiles
toderian Jul 29, 2026
ccd3da6
fix(serving): restore generic llama behavior
toderian Jul 29, 2026
e4c5036
docs(edgeguard): align serving isolation examples
toderian Jul 29, 2026
9878bd5
fix(edgeguard): use generic llama serving
toderian Jul 29, 2026
5394d4a
chore(devcontainer): remove local EdgeGuard runtime scripts
toderian Jul 30, 2026
6735372
refactor(edgeguard): isolate queued-result alignment out of base_infe…
toderian Jul 30, 2026
eac5a08
Revert "refactor(edgeguard): isolate queued-result alignment out of b…
toderian Jul 30, 2026
5b2fd43
refactor(edgeguard): remove inactive benchmark scaffolding
toderian Aug 3, 2026
19323b7
refactor(edgeguard): remove benchmark API residue
toderian Aug 3, 2026
fdf5650
fix(edgeguard): name base Qwen3 serving explicitly
toderian Aug 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
63 changes: 63 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -695,3 +695,66 @@ Entry format:
- Details: `ThHfModelBase` keeps Transformers/PT as the default GPU and fallback path, but CPU-only `HF_RUNTIME=auto` now loads `artifact_manifest.json`, selects a declared ONNX Runtime artifact, downloads only safe allow-patterns, loads schema and contract decoder from HF artifacts, and exposes the decoded artifact contract through the existing text-classifier flow. Business API response shaping now passes through generic model/runtime metadata emitted by serving.
- Verification: `python3 -m unittest extensions.serving.test_th_hf_model_base extensions.serving.test_th_text_classifier extensions.serving.test_th_privacy_filter extensions.business.edge_inference_api.test_text_classifier_inference_api extensions.business.edge_inference_api.test_privacy_filter_inference_api`; `python3 -m py_compile extensions/serving/default_inference/nlp/th_hf_model_base.py extensions/business/edge_inference_api/text_classifier_inference_api.py`; required serving gate `python3 -m unittest extensions.serving.model_testing.test_llm_servings` currently fails at import with `ImportError: cannot import name 'Logger' from 'naeural_core'`.
- Links: `extensions/serving/default_inference/nlp/th_hf_model_base.py`, `extensions/business/edge_inference_api/text_classifier_inference_api.py`, `extensions/serving/test_th_hf_model_base.py`

- ID: `ML-20260707-001`
- Timestamp: `2026-07-07T20:44:27Z`
- Type: `discovery`
- Summary: EdgeGuard playground stream config can override serving-profile model defaults.
- Criticality: Operational deployment risk for EdgeGuard model cutovers; source constants and `/model` metadata can report a new target while the active inference stream still loads an older GGUF from persisted stream parameters.
- Details: During the EGM-029 v0.10 retarget, source defaults and `/model` metadata showed the v0.10 repo/file, but a live generation payload still identified the v0.9 GGUF until the active stream config `STARTUP_AI_ENGINE_PARAMS` was updated. For future cutovers, update both source defaults and the active stream configuration, then verify the returned generation `model` field, not only `/health` or `/model`.
- Verification: `curl -fsS http://127.0.0.1:5055/model`; generate through the playground server route and inspect the returned attempt `model` field after it calls the model-specific `LLM_INFERENCE_API`.
- Links: `extensions/business/cybersec/edgeguard/edgeguard_api.py`, `extensions/serving/default_inference/nlp/llama_cpp_edgeguard_qwen_4b.py`

- ID: `ML-20260710-001`
- Timestamp: `2026-07-10T04:15:31Z`
- Type: `change`
- Summary: Moved EdgeGuard cybersec runtime code into a dedicated `extensions/business/cybersec/edgeguard/` package.
- Criticality: Module-boundary and plugin-discovery change for EdgeGuard API, guard, playground config, and tests.
- Details: EdgeGuard-specific modules and tests now live outside `red_mesh`; generation is no longer owned by an EdgeGuard LLM-agent plugin or `EDGEGUARD_API /generate`. The playground server route calls model-specific `LLM_INFERENCE_API` workers directly, and `EDGEGUARD_API` stays as the safety facade for model metadata, prompt contract metadata, `/check_cypher`, Neo4j execution, and graph explanation. The serving profile remains under `extensions/serving/default_inference/nlp/` because it is discovered through the AI engine serving-process registry.
- Verification: `python3 -m unittest extensions.business.cybersec.edgeguard.tests.test_api extensions.business.cybersec.edgeguard.tests.test_cypher_guard extensions.business.cybersec.edgeguard.tests.test_native_api_semaphore_contract extensions.business.cybersec.red_mesh.test_native_api_semaphore_contract extensions.business.edge_inference_api.test_llm_inference_api`; `python3 -m py_compile ...`; `git diff --check`; `importlib.util.find_spec(...)` for the moved EdgeGuard modules.
- Links: `extensions/business/cybersec/edgeguard/edgeguard_api.py`, `extensions/business/cybersec/edgeguard/edgeguard_cypher_guard.py`, `extensions/business/cybersec/edgeguard/edgeguard_playground.md`, `extensions/serving/default_inference/nlp/llama_cpp_edgeguard_qwen_4b.py`

- ID: `ML-20260716-001`
- Timestamp: `2026-07-16T14:13:24Z`
- Type: `correction`
- Summary: Corrected EdgeGuard graph explanation so Neo4j transport stays in the authenticated Next.js route.
- Criticality: Security and runtime architecture correction affecting credential scope, Bolt-over-WSS compatibility, explanation availability without the edge-node Neo4j driver, and packet trust boundaries.
- Details: Corrects `ML-20260710-001` where it implied edge-node owns Neo4j execution for graph explanation. `EDGEGUARD_API` now prepares the validated primary/optional broadening queries and consumes only bounded serialized execution evidence. The Next.js route owns request-scoped credentials and Bolt-over-WSS execution. Edge-node recomputes query/count/flag consistency, rejects connection fields and malformed or oversized graphs, remaps raw graph IDs, sanitizes properties, validates `GraphEvidencePacket`, calls the localhost explanation worker, and validates `CaseExplanation`. Legacy direct-driver mode remains deprecated compatibility behavior only.
- Verification: `PYTHONDONTWRITEBYTECODE=1 python3 -m unittest extensions.business.cybersec.edgeguard.tests.test_api`; focused EdgeGuard/inference regression suite; `git diff --check`
- Links: `extensions/business/cybersec/edgeguard/edgeguard_api.py`, `extensions/business/cybersec/edgeguard/tests/test_api.py`, `extensions/business/cybersec/edgeguard/edgeguard_playground.md`, `AGENTS.md`

- ID: `ML-20260729-001`
- Timestamp: `2026-07-29T21:21:35Z`
- Type: `change`
- Summary: Isolated EdgeGuard llama.cpp behavior from generic serving.
- Criticality: Shared serving-boundary correction affecting generic RedMesh model loading/logging and EdgeGuard runtime identity, determinism, benchmark telemetry, and artifact pinning.
- Details: Generic `llama_cpp_base.py` is restored to `origin/develop` behavior, including local `MODEL_PATH`, `Llama.from_pretrained`, temperature fallback, retries, and raw output logging. EdgeGuard profiles now inherit a dedicated base that ignores `MODEL_PATH`, requires exact Hugging Face revisions and GGUF SHA-256 values, preserves explicit zero temperature and request seeds, emits the existing fingerprints/benchmark telemetry/context failures, and logs content-free diagnostics. `edgeguard.worker-code-identity.v2` keeps its shape and binds the new shared module through `llama_cpp_base_sha256`.
- Verification: `python3 -m unittest extensions.serving.test_cybersec_qwen_engine extensions.business.edge_inference_api.test_llm_inference_api extensions.business.edge_inference_api.test_base_inference_api_balancing` (75 passed); `python3 -m py_compile` for changed serving/API tests; `git diff --check`; `git diff --quiet origin/develop -- extensions/serving/default_inference/nlp/llama_cpp_base.py`.
- Links: `extensions/serving/default_inference/nlp/llama_cpp_edgeguard_base.py`, `extensions/serving/default_inference/nlp/llama_cpp_base.py`, `extensions/serving/base/base_llm_serving.py`, `extensions/serving/ai_engines/stable.py`

- ID: `ML-20260729-002`
- Timestamp: `2026-07-29T22:45:00Z`
- Type: `correction`
- Summary: Removed EdgeGuard-specific llama.cpp serving and returned all three workers to generic serving.
- Criticality: Corrects the shared serving boundary, local rollout contract, benchmark availability, runtime identity, and output-logging expectations introduced by `ML-20260729-001`.
- Details: Corrects `ML-20260729-001`: there is no EdgeGuard serving base, adapter, or CyberSec-only engine. The base and finetuned files are configuration-only profiles over the unmodified generic llama.cpp process; CyberSec uses the existing `cybersec_qwen_4b` profile. Local `MODEL_PATH` values select checksum-verified cached bytes operationally, with no runtime revision or SHA enforcement. Health keeps `runtime_fingerprint` and `worker_code_identity` keys but generic workers return `null`. Benchmark mode remains disabled and fails closed at the API gate. Temperature, seed, context-overflow, retry, and generated-output logging follow generic behavior.
- Verification: `python3 -m unittest extensions.serving.test_cybersec_qwen_engine extensions.business.edge_inference_api.test_llm_inference_api extensions.business.edge_inference_api.test_base_inference_api_balancing extensions.business.cybersec.edgeguard.tests.test_native_api_semaphore_contract` (71 passed); both generic base files match pinned `origin/develop` commit `dc80cab09471f4f64f10b132a43559adcf6dd328`.
- Links: `extensions/serving/default_inference/nlp/llama_cpp_base.py`, `extensions/serving/base/base_llm_serving.py`, `extensions/serving/default_inference/nlp/llama_cpp_base_qwen_4b.py`, `extensions/serving/default_inference/nlp/llama_cpp_edgeguard_qwen_4b.py`, `extensions/serving/default_inference/nlp/llama_cpp_cybersec_qwen_4b.py`, `extensions/serving/ai_engines/stable.py`

- ID: `ML-20260803-001`
- Timestamp: `2026-08-03T08:11:49Z`
- Type: `correction`
- Summary: Removed inactive EdgeGuard benchmark and attestation scaffolding while preserving an explicit fail-closed API guard.
- Criticality: Corrects the shared inference API boundary so generic serving is not presented as benchmark-capable or runtime-attested.
- Details: The historical sealed benchmark remains documentation-only. `LLM_INFERENCE_API` keeps an explicit default-off `benchmark_mode` parameter solely to reject `true` with a stable error and strips `false` before dispatch. Benchmark enablement, seed validation, telemetry handling, health readiness and identity claims, source hashing, and CyberSec worker hashing were removed. Ordinary inference envelopes and the generic llama.cpp serving implementation are unchanged.
- Verification: Focused inference and serving unit tests; live `edg3` health, disabled-mode rejection, and ordinary completion checks.
- Links: `extensions/business/edge_inference_api/llm_inference_api.py`, `extensions/business/edge_inference_api/test_llm_inference_api.py`, `extensions/serving/default_inference/nlp/llama_cpp_cybersec_qwen_4b.py`, `AGENTS.md`

- ID: `ML-20260803-002`
- Timestamp: `2026-08-03T09:53:00Z`
- Type: `correction`
- Summary: Removed benchmark mode entirely from the LLM inference API.
- Criticality: Corrects `ML-20260803-001`; generic inference no longer exposes, validates, rejects, strips, or otherwise interprets a benchmark control.
- Details: The four LLM completion endpoints have no `benchmark_mode` parameter or special benchmark path. Stale or unknown request input has no supported benchmark semantics. The dormant EdgeGuard UI path remains unavailable because generic workers expose no runtime proof fields. Any reactivation requires a new atomic API/UI/runtime implementation and a new unseen sealed set. The indexed queued-result alignment fix and attributable, content-safe invalid-empty response handling remain as ordinary inference reliability behavior.
- Verification: Focused balancing, LLM inference, serving-profile, and EdgeGuard API tests; scoped dead-symbol search; exact `llm_utils.py` parity with `origin/develop`; live `edg3` health and ordinary completion checks.
- Links: `extensions/business/edge_inference_api/llm_inference_api.py`, `extensions/business/edge_inference_api/base_inference_api.py`, `extensions/business/edge_inference_api/test_llm_inference_api.py`, `AGENTS.md`
Empty file.
Loading