Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/source-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -94,7 +94,7 @@ jobs:
working-directory: ${{ env.SOURCE_ROOT }}/electron
run: >-
node -e "require('node:child_process').execFileSync(require('electron'),
['scripts/smoke-settings-upgrade.cjs', 'v0.15.0-alpha.0'],
['scripts/smoke-settings-upgrade.cjs', 'v0.15.2-alpha.0'],
{stdio: 'inherit', windowsHide: true, timeout: 45000})"

- name: Package extracted Windows sources
Expand Down
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
<p>
<a href="https://www.bilibili.com/video/BV1783G6hEYY/"><img src="https://img.shields.io/badge/demo-Bilibili-b94b43?labelColor=191a1d&amp;logo=bilibili&amp;logoColor=e8e2d4" alt="Bilibili demo"/></a>
<a href="#architecture"><img src="https://img.shields.io/badge/architecture-current-444449?labelColor=191a1d" alt="Current architecture"/></a>
<a href="./docs/alpha-0.15.2.md"><img src="https://img.shields.io/badge/version-0.15.2_Alpha-b94b43?labelColor=191a1d" alt="0.15.2 Alpha"/></a>
<a href="./docs/alpha-0.16.md"><img src="https://img.shields.io/badge/version-0.16.0_Alpha-b94b43?labelColor=191a1d" alt="0.16.0 Alpha"/></a>
<a href="./LICENSE"><img src="https://img.shields.io/badge/license-AGPL--3.0-444449?labelColor=191a1d" alt="AGPL-3.0 license"/></a>
<br/>
<a href="#quick-start"><img src="https://img.shields.io/badge/Windows-reference-444449?labelColor=191a1d" alt="Windows — reference platform"/></a>
Expand Down Expand Up @@ -51,7 +51,7 @@ the Host owns identity, state, permissions, persistence, and recovery.

> [!IMPORTANT]
> This repository contains buildable, runnable source. This branch targets
> **0.15.2 Alpha**, not a packaged desktop release.
> **0.16.0 Alpha**, not a packaged desktop release.
> Amadeus first-party code is open-source under the
> [GNU Affero General Public License v3.0 (AGPL-3.0)](LICENSE).
> Third-party code and external assets retain their own terms.
Expand Down
4 changes: 2 additions & 2 deletions README_ZH.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
<p>
<a href="https://www.bilibili.com/video/BV1783G6hEYY/"><img src="https://img.shields.io/badge/demo-Bilibili-b94b43?labelColor=191a1d&amp;logo=bilibili&amp;logoColor=e8e2d4" alt="Bilibili demo"/></a>
<a href="#系统架构"><img src="https://img.shields.io/badge/architecture-current-444449?labelColor=191a1d" alt="系统架构"/></a>
<a href="./docs/alpha-0.15.2.md"><img src="https://img.shields.io/badge/version-0.15.2_Alpha-b94b43?labelColor=191a1d" alt="0.15.2 Alpha"/></a>
<a href="./docs/alpha-0.16.md"><img src="https://img.shields.io/badge/version-0.16.0_Alpha-b94b43?labelColor=191a1d" alt="0.16.0 Alpha"/></a>
<a href="./LICENSE"><img src="https://img.shields.io/badge/license-AGPL--3.0-444449?labelColor=191a1d" alt="AGPL-3.0 license"/></a>
<br/>
<a href="#快速开始"><img src="https://img.shields.io/badge/Windows-reference-444449?labelColor=191a1d" alt="Windows — 参考平台"/></a>
Expand Down Expand Up @@ -49,7 +49,7 @@ Amadeus 试图把这些体验连成一个闭环:
持久化与恢复。

> [!IMPORTANT]
> 本仓库包含可构建、可运行的公开源码,本分支为 **0.15.2 Alpha 候选版**,
> 本仓库包含可构建、可运行的公开源码,本分支为 **0.16.0 Alpha**,
> 不是带安装器的正式桌面发行版。Amadeus 第一方代码依据
> [GNU Affero General Public License v3.0(AGPL-3.0)](LICENSE) 开源。
> 第三方代码与外部资产保留各自条款。
Expand Down
159 changes: 159 additions & 0 deletions docs/alpha-0.16-acceptance.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,159 @@
# 0.16.0 Alpha acceptance record

Date: 2026-10-11 (Pacific/Auckland). Preparation baseline: `09aecfb`, including
merged #173 and #174. Comparison release: `v0.15.2-alpha.0`.

Release preparation uses a clean, isolated Git worktree. Uncommitted local voice
configuration, private runtime state and external media are excluded.

## Automated and source-package validation

The first preparation commit, `f6bb00c`, passed all 17 PR checks across eight
workflows: Python Windows, Electron Windows, Python Linux, Python macOS, local
model installation candidates, Windows ROCm candidate, optional character RAG,
and Source Release. The Source Release job installs locked dependencies, builds
and packages Electron, verifies native settings upgrade, and launches the
unpacked executable using the extracted source ZIP. Final publication must use
the final clean commit and its corresponding manifest/checksum.

Local checks with Python 3.12.10 and Node 22:

- Electron: **388/388** tests and TypeScript/Vite production build passed after
the compatible dependency repairs. The existing bundle-size advisory remains.
- Full isolated Python runner executed all discovered suites. Its retained raw
summary was 5358 passed / 20 skipped and a failing exit: `test_system_settings`
had 17 failures and `test_tts_emotion_references` had one. Both failures came
from test-created external-asset junctions while audio qualification was being
prepared. The product correctly rejected paths outside the asset root.
The junctions were removed; settings plus installed Pi runtime/web contracts
then passed **48**, with one optional skip; emotion-reference, Codex approval
cancellation and semantic-evidence tests passed **80**. The separate clean CI
run passed all three full-suite shards. The failed local run is not relabeled
as a green full run. Its aggregate collection and per-suite outcome counts do
not exactly reconcile, so no combined final test-count claim is derived.
- Environment verifier, Ruff, generated architecture views, whitespace checks
and third-party provenance release gate passed.
- Clean source archive: **3882 files**, zero policy errors or warnings at the
first preparation commit. Final release hashes come from the final manifest.

## Native desktop and upgrade

- Shipping model-less Electron launch: **11/11** checks passed, covering backend
startup, authentication, navigation, configuration visibility and clean exit.
- Actual settings from `v0.15.2-alpha.0`, with a synthetic native-encrypted
credential, survived upgrade and reopening. No personal profile was migrated.
- Native wallpaper composer and offline startup-settings GUI checks passed;
**13** Windows lifecycle contracts passed. The composer process emitted two
Chromium GPU-state diagnostics while exiting; its interaction assertions
passed. This is not a long-duration GPU or real Lively qualification.
- Extended native role journey: **17/17** checks passed. Two same-name roles
retained distinct IDs; pending selection did not change the running identity;
restart applied selection and edits; malformed-role recovery returned to
Kurisu while preserving the malformed user file; Chat reconnected and owned
processes exited. An initial local harness used the wrong role-directory
environment variable; a second attempt overlapped the asset-junction setup.
Both unsuccessful attempts are retained as instrument/setup failures. The
final run used the documented directory setting and clean model-less assets.
The six extra role assertions use a task-local extension; the ordinary shipped
smoke alone is claimed to cover only its original eleven assertions.

## Real models, actions and device playback

- Codex App Server 0.154.0: native **allow and deny each passed 8/8** assertions.
Allow continued the same WorkItem/Attempt and wrote the requested synthetic
file. Deny persisted refusal, closed the permission card and left it absent.
The first isolated attempts lacked the credential helper's explicit env-file
binding; those authentication failures were retained. Corrected tests used
the existing binding and disabled desktop-provider synchronization. The
initial test's managed non-secret provider path was restored afterward.
- Real Chat and Codex Work control: **10/10** assertions passed with the project
opened through the normal Session API. The initial request started one run;
progress inquiry was read-only; amendment delivery was recorded for that same
run; the final file contained exactly the amended text; WorkItem and Attempt
identity remained unchanged. The old harness first asked for a context switch
but never answered the resulting selection, then waited for the retired
`steer_queued` event despite an existing delivered input receipt. These failed
attempts remain recorded. The probe now checks the durable delivery receipt
and actual file result. This does not certify an unattended compound
context-switch-and-execute request or restore the obsolete event.
- Shipping Electron, DeepSeek V4 Flash and seeded AUIP Gomoku: **37/37**
structural checks passed. The journey played a complete round through real
player clicks and model actions, restarted, resigned, concluded, left the app
and returned to ordinary Chat. Accepted receipts, actor/app identity, bounded
experience history and the post-leave conversation were verified. The final
screenshot and role replies were inspected. This run deliberately disabled
TTS; the seeded application is a fixture, not Provider-generated software.
- Actual local GPT-SoVITS v3 checkpoint, Python 3.12.10, Torch 2.6.0+cu124 and
NVIDIA RTX 4070 Ti SUPER: one warmup plus four short VN replies produced nonzero
PCM written to the physical output device through the production VN bridge
and shared speech pipeline. Existing external voice assets and the installed
GPU environment were used with the candidate source in a separate extracted
directory. No media or machine configuration enters the source archive.

| Delivery | First successful device write | PCM peak |
| --- | ---: | ---: |
| Whole speech body | 2.463 s | 0.349 |
| First segment | 1.962 s | 0.520 |
| First segment | 1.765 s | 0.298 |
| Whole speech body | 1.682 s | 0.353 |

The old audio probe observed only the streaming method and missed complete-audio
playback. It now observes successful writes on the actual `PyAudio.Stream` class
used by `PyAudio.open`, covering both delivery paths. The old public `Stream`
alias is a different class in the installed PyAudio. Failed instrument runs were
not counted as passes. These timestamps measure device submission, not acoustic
arrival; there is no new latency target, percentile or regression conclusion.
The maintainer deferred a matched previous-release latency comparison for this
release. Human microphone recognition and subjective listening remain unverified.

Reproduction entry points (use isolated profiles and configured credentials):

```text
python -X utf8 tools/run_tests.py
npm test # electron/
npm run build # electron/
python -X utf8 tools/smoke_electron_model_less.py
python -X utf8 tools/e2e_codex_app_server_permission.py --decision allow_once
python -X utf8 tools/e2e_codex_app_server_permission.py --decision deny
python -X utf8 tools/e2e_codex_app_server_control.py
python -X utf8 tools/probes/measure_vn_audio_latency.py --live-model-and-audio --baseline-delivery whole-speak
```

The live Codex tests need `CODEX_APP_SERVER_PROVIDER_AUTH_ENV_FILE` to refer to
the configured credential source; set `CODEX_APP_SERVER_SYNC_DESKTOP_PROVIDER=0`
for isolated tests. Never log or publish that file. The audio command plays real
audio and requires the optional GPU/voice dependencies and separately installed
assets. It must not share asset setup with a clean model-less test run.

## Dependency audit disposition

Compatible Electron tooling repairs update concurrently 10.0.5 to 10.0.6
(shell-quote 1.9.0 to 1.12.0), http-cache-semantics 4.2.0 to 4.3.0, and joi
18.2.8 to 18.2.9. Electron has no remaining high/critical audit findings, but
eight moderate build-tool findings remain in the electron-builder/global-agent/
roarr/sprintf-js chain. No force downgrade or broad audit suppression was added.

Pi remains pinned to its qualified 0.86.1 runtime. Its upstream shrinkwrap
installs brace-expansion 5.0.9, retaining the denial-of-service advisories
[GHSA-q2hr-2g5m-vwhr](https://github.com/advisories/GHSA-q2hr-2g5m-vwhr),
[GHSA-qhr7-859c-m2p7](https://github.com/advisories/GHSA-qhr7-859c-m2p7), and
[GHSA-6j4f-fj2g-mc7p](https://github.com/advisories/GHSA-6j4f-fj2g-mc7p).
The audit groups these as one high-severity vulnerable package. A root override
did not repair it. An outer lockfile-only change made the audit green while a
fresh install still contained 5.0.9; that ineffective change was discarded.
Upstream 0.87.1's inspected package also retains 5.0.9. This remains a disclosed
dependency limitation, not a clean Pi audit or a claim of unreachable risk.

Python core/development audit reported no findings after the existing narrow CI
exemption (`PYSEC-2026-1845`; the tool reported two ignored advisory identities).
The project itself is not audited as a PyPI package. Optional GPU dependencies
were not upgraded or assigned a new vulnerability-free claim.

## Evidence boundaries

Deterministic suites, native desktop startup, extracted source installation,
real-model interaction, device playback and human microphone/listening checks
establish different facts. Missing optional dependencies and manual checks are
reported as skipped or unverified, never counted as passes. Raw logs, local
paths, credentials, conversations and runtime media remain outside the source
release; only sanitized aggregate results are recorded here.
99 changes: 99 additions & 0 deletions docs/alpha-0.16.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,99 @@
# 0.16.0 Alpha: unified Chat and local character management

Tag: `v0.16.0-alpha.0`; Python `0.16.0a0`; Electron `0.16.0-alpha.0`.
This is a source Alpha release. Model weights, character media, reference voices,
Live2D Cubism Core, credentials and desktop installers are not bundled.
The comparison baseline is `v0.15.2-alpha.0`.

## Changes

- **One Chat runtime.** Cooperative owns production Chat in both professional
and basic mode. Shared presentation retains streaming, expressions and speech;
the old Original orchestration path is retired. Provider handoffs preserve
shared constraints without expanding the assigned task's scope.
- **Local character management.** Settings can create and edit local roles,
select the next startup identity, and recover explicitly from an invalid role.
Conversations remain owned by their role; accepted Work retains its identity.
Settings groups identity, appearance and the existing Kurisu knowledge controls
under Characters, with voice configuration in its single Voice editor.
- **Experimental Live2D.** Optional local Live2D models use the existing render
and wallpaper path, including expression and mouth signals. Sprite remains
available. Users supply the model and Cubism Core under their respective terms.
- **Desktop and rendering.** Wallpaper and Render transitions share serialized
lifecycle ownership. Texture residency is bounded and BC7 frames can be cached.
SpriteForge framing uses the pack canvas; wallpaper preserves aspect ratio.
Connection editors have consistent save state and dark Render backgrounds.
- **Voice and history.** Speech aggregation accounts for ready audio and the
selected synthesis profile; idle output streams persist between turns.
Continuous voice can return to wake standby, Qwen3-ASR can remain in system
memory, and BERT loads only for Chinese GPT-SoVITS text. V3 emotion references
remain opt-in. Sessions retain complete history while Main Chat receives a
bounded recent window.
- **Configuration and recovery.** Setting declarations and built-in handler
registration share one catalog. Durable state writes, runtime diagnostics and
translation checks are strengthened. Restoring Watching mode preserves an
explicitly disabled vision setting.

## Install and upgrade

Use the source ZIP and the installation profile in [README](../README.md).
Extract into a new directory and run `uv sync --locked` with the complete set of
extras for your profile, then `npm ci` and `npm run build` in `electron/`.
Running only the core install command against an existing optional-model
environment removes extras; retain your full profile selection.

Before upgrading, stop incoming turns and drain or stop owned Work. Back up your
settings and persistent data. Keep external assets separate and configure their
locations in Settings. Do not copy caches or an entire old virtual environment.

The retired `COOPERATIVE_CHAT_ENABLED=false` no longer selects Original Chat.
Settings explains and acknowledges migration; an obsolete `.env` assignment
must be removed from that file. `COOPERATIVE_WORK_PLANNER_ENABLED=false` still
selects basic Cooperative. There is no hidden Original fallback.

Pure-local Chat uses `llama_server`; persistent `cli` sessions require migration.
The managed pure-local context defaults to 16384, while Hybrid keeps 4096.
Explicit saved values are preserved. Hybrid now uses its configured local head
alongside the remote role model. See [runtime migration](chat-runtime-convergence.md).

Role selection applies after restart. Appearance and voice remain application-wide;
creating a role does not create a separate voice, artwork or memory library.
See [character management](character-management.md) and
[Live2D setup](live2d_character_visuals.md).

For rollback, use a separate checkout or source directory of `v0.15.2-alpha.0`.
Do not overwrite newer history or Work receipts with an old database snapshot.
Acknowledging removal of the retired route setting does not restore that setting
when older software is started. Unknown external Provider outcomes remain unknown.

## Validation and known limits

The [0.16 acceptance record](alpha-0.16-acceptance.md) distinguishes this release's
checks from earlier feature evidence. Alpha does not imply that every model,
device, operating system or experimental surface has been qualified.

- Model-less CI does not establish microphone recognition, audible quality,
acoustic latency, GPU inference or long-duration resource stability.
- Browser cross-domain journeys and pure-local model task interpretation retain
recorded limitations; LM Studio/Ollama capacity behavior remains unqualified.
See the [runtime acceptance boundaries](chat-runtime-convergence.md#evidence-and-remaining-acceptance).
- Live2D and VN remain experimental. Live2D model physics/motions and external
wallpaper hosts depend on the supplied assets and environment.
- Per-role voice/appearance bindings, automatic asset installation and general
cross-session semantic memory are not part of this release.
- Platform and optional GPU-profile support remains limited to the evidence
documented in [installation profiles](install_profiles.md).
- Dependency audits are not clean: the pinned Pi runtime retains a known
brace-expansion denial-of-service risk, and Electron build tooling retains
moderate findings. See the [exact audit disposition](alpha-0.16-acceptance.md#dependency-audit-disposition).

## 中文摘要

0.16.0 Alpha 汇总自 0.15.2 以来的运行时与桌面更新:统一 Cooperative Chat,
加入本地角色管理、启动恢复和实验性 Live2D,整理角色与连接设置,改进纹理驻留、
语音调度、完整历史保存、配置声明及持久化可靠性。

这是源码预发布,不包含桌面安装器、模型权重、角色素材、参考语音、Cubism Core
或凭据。升级请使用新目录并保留完整的可选依赖配置;先停止输入和进行中的 Work。
旧 Original Chat 开关已退役,角色切换需重启,声音与外观仍为应用级设置。
已知限制和本轮实测范围见验收记录;既有单项测试不代表所有硬件与实验功能均已验收。
Loading
Loading