Repository navigation
Releases: DevNullInc/RenegadeSwarm
Release list
v0.3.0
RenegadeSwarm 0.3.0 Release Notes
Release: v0.3.0
Date: September 19, 2026
License: GNU General Public License v3.0 or later (GPL-3.0-or-later)
Target Platforms: Windows (x64), Linux (x64), macOS (Universal: Apple Silicon & Intel)
Executive Summary
RenegadeSwarm 0.3.0 marks a foundational milestone in decentralized AI model distribution. This release delivers our native P2P Model Search & Discovery Engine (renegade_swarm_discovery_v1), Background Packaging State Hoisting, a Multi-Tier Pre-Download Verification Handshake, and an Authenticated Loopback HTTP Daemon Bridge (127.0.0.1:5180) designed for secure, bi-directional synchronization with companion application RenegadeCMM.
This release hardens the application security boundary, ensuring private signing keys remain sealed in hardware-bound OS vaults, downloaded model pieces remain quarantined until cryptographically verified, and localhost API bridges require timing-safe cryptographic Bearer tokens.
Primary Subsystems & Features in RenegadeSwarm
1. Decentralized P2P Model Search & Discovery Engine
- BEP 10 Extended Discovery Handshake: Extends standard BitTorrent wire messaging with an application-level extension dictionary (
renegade_swarm_discovery_v1). Discovers, queries, and indexes AI models exclusively across active RenegadeSwarm peers while preserving full compatibility with open BitTorrent transfer swarms. - Discovery Engine (
src/main/engine/discoveryEngine.ts): Implements local catalog indexing, debounced peer broadcast queries, response deduplication, TTL result caching, and Web-of-Trust (WoT) trust-score calculation. - Dedicated Discovery View (
src/renderer/components/DiscoveryView.tsx): An in-app desktop catalog offering real-time keyword search, category filter chips (Checkpoints,LoRAs,GGUF/LLM,VAEs,ControlNets), and live seeder/leecher peer counts. - Unverified Community Safeguards: Displays an amber confirmation safeguard modal with explicit origin disclosures before initiating downloads for models signed by unrecognized public keys.
2. Packaging State Hoisting & Background Job Persistence
- Main Process PackageJobManager (
src/main/engine/packageJobManager.ts): Background job manager in Electron Main that handles model file reading, SHA-256 piece hashing, Ed25519 manifest signing, and swarm seeding asynchronously. - Tab-Switching Resilience: State is hoisted out of renderer component memory. Users can switch between views (Dashboard, Discovery, Settings, Transfers) while large (50GB+) model packaging jobs continue in the background.
- Real-Time Progress Streaming: Streams per-chunk hashing metrics and byte progress to the UI over push IPC channels (
swarm:packageProgress). - Graceful Abort & Cleanup: Implements cancellation tokens to terminate open file streams and purge temporary torrent staging files when packaging is cancelled.
3. Pre-Download Verification & Companion File Harvesting
- PreDownloadVerifier (
src/main/engine/preDownloadVerifier.ts): Inspects model hashes and creator provenance prior to committing disk space or downloading payload weights. - Multi-Registry Validation: Resolves model SHA-256 hashes against CivitAI (
/api/v1/model-versions/by-hash/:hash) and Hugging Face repositories with structured timeouts and branded User-Agent headers. - Custom Model Verification: Validates Ed25519 creator signatures on unindexed custom models against the local Web of Trust keyring, dropping blacklisted public keys immediately.
- Companion File Triplet Harvesting: Automatically discovers and generates companion metadata files (
<model_base>.sha256,<model_base>.civitai.info, and<model_base>.<ext>preview assets) upon promotion from quarantine. - Embedded AI Workflow Inspection: Extracts generation parameters, ComfyUI workflow graphs, Automatic1111 prompts, and LoRA trigger tags from image buffers.
Interoperability with Companion Application (RenegadeCMM)
RenegadeSwarm operates as an autonomous, decentralized BitTorrent client and model distribution engine. For users operating sister application RenegadeCMM (Core Model Manager) on the same workstation, RenegadeSwarm provides dedicated local inter-process bridges:
1. Authenticated Loopback HTTP Daemon Bridge (127.0.0.1:5180)
- Dedicated Daemon Endpoint: Listens strictly on
127.0.0.1:5180to receive status checks, window focus requests, and model download ingest notifications from RenegadeCMM. - Port Conflict Prevention: Internal Vite development server shifted to port
5181to prevent localhost port collisions during development. - Cryptographic Bearer Token Authentication: All mutating endpoints (
POST /api/ingest,POST /api/models/scan,POST /api/window/focus,GET /api/cmm/status) require a 32-byte cryptographic Bearer token (daemon.token). - Timing-Safe Constant-Time Comparison: Tokens are pre-hashed with SHA-256 and compared using
crypto.timingSafeEqualto eliminate timing-attack vulnerabilities. - Multi-Path Local Token Synchronization: Tokens are generated with restrictive permissions (
0600) and mirrored across well-known local paths (userData,%APPDATA%\RenegadeSwarm,~/.config/RenegadeSwarm,~/Library/Application Support/RenegadeSwarm). - Secret-Free Health Checks:
GET /api/healthis exposed openly on localhost for basic liveness monitoring without leaking tokens, private keys, or system metadata.
2. Local SQLite Cross-Database ATTACH
- Communicates directly with the local RenegadeCMM database (
renegadecmm.sqlite) using non-locking SQLiteATTACH DATABASEoperations when present, discovering model paths and metadata without cloud intermediaries or external relays.
Security Hardening & Process Isolation
- Machine-Bound Key Isolation (
safeStorage): Ed25519 private signing keys are encrypted at rest using native OS hardware modules (Windows DPAPI, macOS Keychain / Secure Enclave, Linux Secret Service). - Renderer IPC Boundary Sanitization: Raw private keys are stripped from all renderer IPC contracts (
UserIdentityPublic). The UI receives only public identity metadata. - Path Confinement: Enforces directory whitelisting (
cmmFolderRouter.isPathAllowed()) across all filesystem IPC channels to prevent path traversal. - Quarantine Ingestion Pipeline: Stages unverified torrent pieces in an isolated
.quarantine/staging directory until full SHA-256 piece validation passes. - Anti-Abuse Lockout: Enforces a mandatory 24-hour cooldown on Ed25519 identity regeneration to prevent Sybil attacks and Web-of-Trust blacklist evasion.
- Dependency & Parser Hygiene: AST-free HTML entity sanitization (
sanitizeAndDecodeHtml) and strict hex-encoded cache path enforcement. (Note:adm-zipis not utilized in RenegadeSwarm as transfers operate on raw SafeTensors/GGUF tensors and piece streams; companion app RenegadeCMM has been upgraded toadm-zip0.6.1).
Subsystem Architecture Overview
| Subsystem | Source Location | Security & Runtime Boundary |
|---|---|---|
| Daemon Server | src/main/engine/swarmDaemonServer.ts |
Loopback 127.0.0.1:5180, Bearer token auth, constant-time verification. |
| Auth Token Generator | src/main/engine/daemonAuthToken.ts |
Multi-path local sync, mode 0600, SHA-256 digest comparison. |
| Hardware Key Vault | src/main/engine/secureStorage.ts |
Electron safeStorage (DPAPI / Keychain / Secret Service), memory-only fallback. |
| Keyring Manager | src/main/engine/keyringManager.ts |
Ed25519 signing, 24-hour anti-abuse regeneration cooldown, public DTO stripping. |
| Packaging Engine | src/main/engine/packageJobManager.ts |
Main-process background worker, streaming SHA-256 chunk progress. |
| P2P Discovery | src/main/engine/discoveryEngine.ts |
BitTorrent BEP 10 extension framing (renegade_swarm_discovery_v1). |
| Path Router | src/main/cmm/cmmFolderRouter.ts |
Path confinement, directory whitelisting, active dialog session tracking. |
Verification & Test Results
- Test Suite: 145 unit and integration tests passing across 29 test suites (
npm test). - Static Analysis: Automated GitHub Actions CodeQL analysis configured with
security-and-qualityrulesets. - License Audit: 100% of codebase files verified compliant with GNU General Public License v3.0 (GPL-3.0-or-later) headers.
Installation & Artifact Packages
Direct Binary Downloads
Pre-built binaries are available under the Assets section below:
- Windows:
RenegadeSwarm-Setup-0.3.0.exe(NSIS Installer) /RenegadeSwarm-0.3.0-portable.exe - Linux:
RenegadeSwarm-0.3.0.AppImage/renegadeswarm-0.3.0.tar.gz - macOS:
RenegadeSwarm-0.3.0-universal.dmg(Universal binary for Apple Silicon & Intel)
Source Build
git clone https://github.com/DevNullInc/RenegadeSwarm.git
cd RenegadeSwarm
git checkout v0.3.0
npm ci
npm test
npm run electron:devFull Changelog: v0.2.0...v0.3.0
Full Changelog: v0.2.0...v0.3.0
Full Changelog: v0.2.0...v0.3.0
v0.2.0
🚀 What's New in RenegadeSwarm v0.2.0
RenegadeSwarm v0.2.0 introduces bidirectional metadata synchronization with RenegadeCMM, automated Hugging Face Model API fallback polling, strict verified metadata auto-locking, and authentic high-resolution vector branding across Windows, macOS, and Linux.
🌟 Release Highlights
1. 🔄 Seamless RenegadeCMM Bridge & SQLite Synchronization
- Cross-Database Backfill: Packaging an existing model from your library automatically retrieves or polls missing creator details, tags, descriptions, and IDs, then writes them back to your local CMM catalog (
cmm.local_models,cmm.civitai_models,cmm.civitai_versions) via SQLiteATTACH DATABASE. - Dynamic CMM Connectivity Badge: Real-time status indicator in the navbar displaying Connected (model count), Offline (Discovered on disk), or 1-Click Install RenegadeCMM link.
2. 🤗 Hugging Face Model API Fallback & LLM Auto-Detection
- Automated LLM Detection: Identifies GGUF, language, and conversational models, bypassing diffusion-centric CivitAI queries.
- Hugging Face Registry Polling: Queries
https://huggingface.co/api/modelsto extract authors, pipeline tags, base models, and descriptions directly into your package manifest. - Multi-Pass Text Sterilization: Recursively decodes and sterilizes HTML entities (
<,>,&), properly formatting prompt trigger syntax (e.g.<lora:ModelName:1.0>).
3. 🔒 Verified Metadata Auto-Locking & Database Write Isolation
- Tamper & Mismatch Protection: Auto-populated fields (Model Title, Type, Base Model, Creator, CivitAI/HF IDs) are automatically locked to prevent accidental misclassification (such as packaging a LoRA as a Checkpoint).
- Unlock Confirmation Dialog: Attempting to edit verified registry metadata presents a clear confirmation modal explaining potential swarm categorization risks.
- Database Write Protection: Manual overrides in the UI are strictly scoped to the local Swarm Manifest and will never overwrite or corrupt your local CMM SQLite database.
- Real-Time Diagnostics: Inline warning alerts if file signatures conflict with selected model types, plus a 1-click Re-lock & Restore button.
4. 🎨 Authentic 512x512 Vector Branding
- Replaced temporary build assets with official 512x512 icons and SVG vector artwork, meeting macOS Retina and Windows packaging standards.
📦 Installation & Setup
🪟 Windows
- Installer: Download and run
RenegadeSwarm-Setup-0.2.0.exe. - Portable: Alternatively, download
RenegadeSwarm-Portable-0.2.0.exefor a standalone executable that requires no installation.
Note on Windows SmartScreen: Because RenegadeSwarm is an open-source community tool without an expensive commercial EV certificate, SmartScreen may display a notice. Click More info ➔ Run anyway to launch.
🍏 macOS (Unsigned App Gatekeeper Setup)
Notice: Because maintainers do not hold a paid Apple Developer ID certificate, macOS binaries are community-distributed and require clearing Apple Gatekeeper's quarantine flag.
- Mount
RenegadeSwarm-0.2.0.dmgand dragRenegadeSwarm.appinto your/Applicationsfolder. - If macOS displays "RenegadeSwarm cannot be opened because the developer cannot be verified", clear the quarantine attribute using either method:
Option A: Terminal Command (Recommended — Fast)
Open Terminal and run:
xattr -cr /Applications/RenegadeSwarm.appOnce cleared, double-click RenegadeSwarm.app to launch normally.
Option B: macOS System Settings
- Click Cancel on the Gatekeeper alert.
- Open System Settings ➔ Privacy & Security and scroll down to Security.
- Click Open Anyway next to the notification stating
"RenegadeSwarm" was blocked from use. - Enter your Mac password or Touch ID to permanently permit execution.
🐧 Linux
# Universal AppImage
chmod +x RenegadeSwarm-0.2.0.AppImage
./RenegadeSwarm-0.2.0.AppImage
# Debian / Ubuntu package
sudo dpkg -i renegadeswarm_0.2.0_amd64.deb🧪 Quality & Verification
- Test Suite: 90/90 automated unit and integration tests passing across 19 suites in Vitest.
- License: 100% compliant with GNU General Public License v3.0 (GPL-3.0).
- Full Changelog: See CHANGELOG.md for full historical changes.
v0.1.0
RELEASE: v0.1.0 — decentralized AI model distribution network with ComfyUI & CMM sync
🚀 What's New in v0.1.0
RenegadeSwarm is an open-source, decentralized P2P model distribution engine engineered specifically for 50GB+ AI weights (Checkpoints, LoRAs, UNets, GGUFs, VAEs, Text Encoders) with automatic ComfyUI directory organization and seamless RenegadeCMM database integration.
🔑 Key Features & Protocol Capabilities
- Decentralized Model Distribution:
- BitTorrent BEP 3 wire protocol framing with memory-safe piece chunking (2MB–32MB).
- BEP 19 Web Seed fallbacks (Hugging Face & CivitAI direct HTTP/HTTPS endpoints).
- BEP 42 Sybil defense with IP-derived DHT Node ID verification and query rate limiting (<5 KB/s).
- Token Bucket bandwidth scheduler with configurable seeding ratio governor (auto-halt at ratio cap).
- Strict Opt-In Model Privacy & Seeding Governance:
- Default policy set to Opt-In Only (`autoSeedDownloads: false`).
- Automatic blacklist filters for `/private/`, `/drafts/`, `/wip/`, `/client/`, and `private_*` prefixes.
- Manifest builder sanitizes local paths via `path.basename()` to prevent username or disk leaks.
- Local transmission JSON-RPC adapter strictly bound to loopback `127.0.0.1`.
- Zero-Trust Security & Quarantine Isolation:
- Quarantine lifecycle state machine (`Quarantine → Validating → Queued → Active → Completed → Verified`).
- Pre-write in-memory SHA256 piece validation dropping corrupted or poisoned chunks before disk write.
- Multi-pass magic byte inspector for SafeTensors, GGUF, ONNX, and PyTorch headers.
- Strict Anti-Polyglot defense rejecting ZIP containers (`PK\x03\x04`) and executable binaries (PE `MZ`, ELF `\x7fELF`, Mach-O, scripts).
- Dual-layer full-file SHA256 digest validation before promotion to model folders.
- Ed25519 digital signatures binding model metadata to the BitTorrent `infoHash`.
- Atomic RenegadeCMM & ComfyUI Synchronization:
- Direct SQLite `ATTACH DATABASE '...renegadecmm.sqlite' AS cmm;` for zero-lag catalog updates.
- Path traversal protection with canonical CMM filename formatting (`model_author.extension`).
- Automatic folder routing into `checkpoints/`, `loras/`, `vae/`, `text_encoders/`, `unet/`, and `configs/`.
- Cross-Platform Packaging & CI/CD:
- Multi-platform build matrix generating Windows NSIS installer + Portable `.exe`, Linux `AppImage` + `.tar.gz`, and macOS `.dmg` + `.zip`.
- Automated GitHub Actions release pipeline triggered on version tags.
🛡️ Audits & Verified Standards
- Test Suite: 16 test suites / 67 unit & integration tests passing (100% success rate).
- Security Audits: Passed AI-Generated Code Audit, Senior SecOps Review, and Penetration Threat Modeling.
- Legal Compliance: Standardized GNU General Public License v3.0 headers across all 48 source files, Betamax non-liability safe-harbor notice, and GitHub-compliant SECURITY.md policy.
📬 Official Contact Channels
- Bug Reports: bug-report@renegadeinc.net
- General Inquiries: contact-us@renegadeinc.net
- Security Disclosures: security@renegadeinc.net
- Legal & Licensing: legal@renegadeinc.net"