Download Latest Version v6.1.3 source code.zip (15.1 MB) Google Add to Preferred Sources
Home / v6.1.0
Name Modified Size InfoDownloads / Week
Parent folder
AI Runner 6.1.0 source code.tar.gz 2026-09-11 12.1 MB
AI Runner 6.1.0 source code.zip 2026-09-11 15.0 MB
README.md 2026-09-11 2.6 kB
Totals: 3 Items   27.1 MB 0

AI Runner 6.1.0

This release adds a best-effort content-safety layer with two independent enforcement points. It is defense-in-depth, not a guarantee — see SECURITY.md for the full behavior.

Content-safety input gate

  • Prompts are checked against a hash-based policy-terms data set at the daemon generation boundary, so the same gate applies to every entry point that reaches generation: the GUI, the versioned HTTP API, the legacy art route, and the LLM image tool.
  • The matcher normalizes text (case, separators, diacritics, simple obfuscation) and compares SHA-256 hashes only. It never stores or logs prompt content, and a match produces a single generic rejection message with no side effects (no model unload, no job creation, no echo of the text).
  • An optional semantic second signal is available and off by default (AIRUNNER_CONTENT_SAFETY_SEMANTIC). It runs only after a clean hash check and can only add a block; it never converts a block into an allow.
  • The repository ships an empty policy data set so no policy terms are committed. Distributors must generate the data set out of band with scripts/build_policy_terms.py before distributing; until then the input-side filter is inactive. Operators can point at a custom data file via AIRUNNER_CONTENT_SAFETY_DATA.

Output filter now fails closed

  • When the image safety filter is enabled but cannot render a verdict — the checker model is unavailable (for example unloaded mid-session) or the check raises — the batch is blacked out and every image is flagged as blocked rather than released unchecked. This applies to both SDXL and Z-Image.
  • Disabling the filter (nsfw_filter) remains a true no-op, and its confirmation dialog is unchanged.
  • Exception text is never logged; only the exception type is recorded.

Cleanup

  • Removed the unwired safety-checker GUI worker, its runtime accessor, the duplicate GUI nsfw checker module, and the dead SAFETY_CHECKER_* signals and their handlers, leaving a single output-enforcement path.

Docs and packaging

  • New "Content Safety" section in SECURITY.md and operator guidance in README.md.
  • The hashed policy data file is included in sdist/wheel builds.

Tests

88 content-safety tests pass: matcher/normalization, loader semantics, generator determinism and no-leak, route/worker/tool gate, output fail-closed, and a no-content-logging guard.

Source: README.md, updated 2026-09-11