| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| AI Runner 6.1.0 source code.tar.gz | 2026-09-11 | 12.1 MB | |
| AI Runner 6.1.0 source code.zip | 2026-09-11 | 15.0 MB | |
| README.md | 2026-09-11 | 2.6 kB | |
| Totals: 3 Items | 27.1 MB | 0 | |
AI Runner 6.1.0
This release adds a best-effort content-safety layer with two independent
enforcement points. It is defense-in-depth, not a guarantee — see
SECURITY.md for the full behavior.
Content-safety input gate
- Prompts are checked against a hash-based policy-terms data set at the daemon generation boundary, so the same gate applies to every entry point that reaches generation: the GUI, the versioned HTTP API, the legacy art route, and the LLM image tool.
- The matcher normalizes text (case, separators, diacritics, simple obfuscation) and compares SHA-256 hashes only. It never stores or logs prompt content, and a match produces a single generic rejection message with no side effects (no model unload, no job creation, no echo of the text).
- An optional semantic second signal is available and off by default
(
AIRUNNER_CONTENT_SAFETY_SEMANTIC). It runs only after a clean hash check and can only add a block; it never converts a block into an allow. - The repository ships an empty policy data set so no policy terms are
committed. Distributors must generate the data set out of band with
scripts/build_policy_terms.pybefore distributing; until then the input-side filter is inactive. Operators can point at a custom data file viaAIRUNNER_CONTENT_SAFETY_DATA.
Output filter now fails closed
- When the image safety filter is enabled but cannot render a verdict — the checker model is unavailable (for example unloaded mid-session) or the check raises — the batch is blacked out and every image is flagged as blocked rather than released unchecked. This applies to both SDXL and Z-Image.
- Disabling the filter (
nsfw_filter) remains a true no-op, and its confirmation dialog is unchanged. - Exception text is never logged; only the exception type is recorded.
Cleanup
- Removed the unwired safety-checker GUI worker, its runtime accessor, the
duplicate GUI nsfw checker module, and the dead
SAFETY_CHECKER_*signals and their handlers, leaving a single output-enforcement path.
Docs and packaging
- New "Content Safety" section in
SECURITY.mdand operator guidance inREADME.md. - The hashed policy data file is included in sdist/wheel builds.
Tests
88 content-safety tests pass: matcher/normalization, loader semantics, generator determinism and no-leak, route/worker/tool gate, output fail-closed, and a no-content-logging guard.