verify-gguf: fail closed by default when no strong layer ran (magic-only verdict) — deferred until the next MAJOR release
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 15/100
Direzione di ricerca
Read the deferral row at docs/roadmap/risks-and-decisions.md:259 and the exit-code rule in error-handling.md (rule 3) to see why the default stays at exit 0 for now. Do not start until #891 lands C-3 and C-4 and a MAJOR release is scheduled. Done means verify-gguf exits non-zero when no strong layer ran, the opt-out is documented, and the CHANGELOG names F-W20260729-TRUST-04-default.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Deferred work ·
F-W20260729-TRUST-04-default· severity Medium · cost ~1 h · recorded indocs/roadmap/risks-and-decisions.md:259
Summary
Decision C-3 adds an opt-in --require-strong-layer (Phase 16 S5) and keeps a magic-only verdict at exit 0 by default, because flipping the default breaks the jq -e '.valid' recipe the manual recommends, which error-handling.md rule 3 makes a MAJOR change. This issue is the flip itself: a run in which neither the GGUF metadata parse nor a SHA-256 sidecar check happened must not exit 0 by default.
Condition or budget
The next MAJOR release, after Phase 16 S5 (#891) lands C-3 and C-4 — the exporter then writes the sidecar, so the strong layer is present by default and the flip is nearly free.
State today (re-checked 2026-10-09)
No --require-strong-layer flag exists yet, the exporter writes no .gguf.sha256, and a magic-only check still returns valid=True; the package is at 0.11.1rc1.
Related
#83 (magic-only acceptance; lists the non-zero exit only as an alternative) and #84 (the exporter writing the sidecar).
Acceptance criteria
- With no strong layer,
verify-ggufexits non-zero by default; the opt-out is documented and the release notes name the MAJOR change. - The row is removed from the deferral table and the CHANGELOG names its ID (the table's removal contract).
Recorded in docs/roadmap/risks-and-decisions.md (read at f94595f) and re-checked against the code on 2026-10-09. The row leaves that table only when the fix is on main, the CHANGELOG names its ID and any promised guard exists.
- Lingua principale
- Python
- Stelle
- 9
- Fork
- 1
- Merge medio
- 4h 3m
- PR unite (30g)
- 3
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di HodeTech/ForgeLM
-
area: dev-tooling bug severity: low source: roadmap wave: 4
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
area: site bug good first issue severity: low source: review-2026-09 wave: 4
Difficoltà 2/5 1-3 ore Idoneità per principianti 66/100
-
documentation good first issue severity: medium source: review-2026-09 wave: 3
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
documentation good first issue severity: low source: review-2026-09 wave: 4
Difficoltà 1/5 1-3 ore Idoneità per principianti 80/100
-
documentation severity: medium source: review-2026-09 wave: 3
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
Tutte le issue di HodeTech/ForgeLM
Issue simili
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
topoteretes/cognee#5647 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
Sendspin/sendspin-python-cli#291 ·
I maintainer di solito rispondono entro 6 giorni
-
Assertion-shape guard fails on development: vacuous recorded-iteration assertion in the assetLinks batch_get helper testForse già presa Una pull request collegata a questa issue è aperta o già unita. Apertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
awslabs/visual-asset-management-system#414 ·
I maintainer di solito rispondono entro 1 giorno
-
bug v1 v2
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
modelcontextprotocol/python-sdk#3670 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
aicell-lab/bioengine#232 ·
I maintainer di solito rispondono entro 1 giorno