| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-09-13 | 2.1 kB | |
| v6.1.1 source code.tar.gz | 2026-09-13 | 12.2 MB | |
| v6.1.1 source code.zip | 2026-09-13 | 15.1 MB | |
| Totals: 3 Items | 27.3 MB | 0 | |
Linux v1 release-prep batch
A batch of hardening, correctness fixes, and release-planning documentation, produced against the Linux v1 release tracker and independently code-reviewed before merge.
Fixes and hardening
- S01/S02: Authenticate the LLM WebSocket before accept; bound message size and rate-limit per principal (fixed: unbounded
max_tokenswhen omitted, missingextra="forbid", malformed-JSON handling). - D01/D02: Honor pinned model revisions and verify digests before load; resume only the same model artifact and promote it safely (fixed: a fail-open identity check on partial-file resume, and an unverified "already complete" promotion shortcut).
- D03: Return every image from a requested art batch, not just the first.
- D04: Validate art request resource limits before job creation (fixed:
cfg_scalerejected the documented0.0value for Z-Image Turbo). - O01/O02: Define and enforce an explicit offline egress policy, applied to model downloads and online tools (fixed: an error message pointing at a nonexistent Preferences control).
- O03: Make diagnostics private and user-controlled (fixed: the export could leak arbitrary exception-message content a denylist sanitizer couldn't catch; now an allowlisted failure-code shape).
- P01: Stop compiling Qt UI resources at app startup (fixed: a packaging regression that broke
pip installfrom the sdist).
Design and documentation
- B01: Desktop companion contracts and port-mapping design (fixed: a missing cancellation method, an incorrect assumption about Desktop's conversation model, and a non-persisting worked example).
- R01/R02: Desktop feature inventory matrix and hardware/model validation manifest (fixed: several citation errors in R01).
- R03: Corrected stale tooling paths in Copilot instructions.
All fixes were re-verified against their full test suites (186+ tests across the touched areas) before merge.
Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com