Skip to content

GNN 4.0.1

Choose a tag to compare

@docxology docxology released this 07 Oct 19:56
17c72cf

GNN 4.0.1 resolves the remaining issue reports and patches the sixteen known GitHub security findings carried after 4.0.0. It improves bounded GUI parsing, dependency resolution, subprocess input delivery, and source-bound documentation without changing the 25-step workflow or silently normalizing scientific examples.

GNN 4 workflow, model notation, numerical execution and evidence overview; original 4.0.0 illustration

Fixes

  • GUI1 replaces the four polynomial markdown regex sites with a linear scanner, limits admitted input to 8,388,608 characters, and rejects oversized exports before replacing the previous file. Differential, hostile-growth and bound callback checks support the change; CodeQL confirms the four findings fixed on main.
  • The lock upgrades fsspec 2026.6.0, jupyterlab 4.6.4, multidict 6.9.1, tornado 6.5.9 and virtualenv 21.7.13, plus its required python-discovery 1.6.1 dependency. All 346 unrelated locked package records are unchanged. Transitive security floors are UV resolver constraints, so ordinary pip does not consume them.
  • Slow-reading children receive complete UTF-8 input through an owned private temporary descriptor, with cleanup preserved on cancellation, timeout and close errors. LLM summaries now report selected/discovered sources, prompts N/M, unfinished work, model, provider and budgets, and distinguish structural output from native response completion.
  • The six corrected probability examples have retained literal-value round trips and independent numerical witnesses. The manifest/index and manuscript now describe the declared hierarchical and contingent T-maze JAX contracts accurately, with unsupported backends explicit.
  • Duplicate Step 16 global analysis dispatch is resolved. The former 10×/identical-output acceptance target is retired: current analysis produces additional numerical and visual evidence, and the recorded contemporary comparison is slower. No speed improvement is claimed.

Verified delivery

Release source: 17c72cf0f98d7d3bbf0159d1b1cce8c77c4e4daf; annotated tag v4.0.1.

All required GNN, FEP and GEO hosted checks passed at the exact revisions recorded in verification.json. The full local GNN suite passed 7,789 cases plus 10 subtests with 57 optional-tool skips; the hosted default matrix, pipeline/MCP selections and extras gates are recorded separately and overlap. The 31-page manuscript and all seven figures passed custody, numerical-source, font, reference and finite visual review. Wheel and source archive contents were compared byte-for-byte to Git; assets and checksums are retained below.

Issues #236, #241 and #250 include their individual acceptance receipts and qualifications. GitHub reports zero open issues, zero open Dependabot alerts and zero open CodeQL alerts after the maintenance merge. Secret scanning is disabled in this repository; no settings or credentials were changed.

Scope retained

The configured smollm2:135m-instruct-q4_K_S completed the bounded N4 specimen, while exact larger-source requests exceed its 4096-token runtime context. The 38-source missing-model control correctly reports 0/342 native prompts and unfinished work. Full-corpus native LLM completion remains future capability S1; source truncation, model substitution and paid-provider execution are not claimed. Generic posterior checks cover float32/64; the three semantic-contract native runs use float64. FEP source-pair drift checks, native Lean theorem statements and generated-runner execution remain separate evidence planes.

The original 4.0.0 tag, release assets and image remain intact. This is a GitHub release; no PyPI upload, paid service or new archival DOI is claimed.