Repository navigation
Releases: My-Denia/WuwaTerm
Release list
v0.6.0
0.6.0
Highlights
- Site: Chinese and English interface support, plus a full Markdown review-report export.
- Site: filter and navigate findings, then jump to exact source or target spans.
- Data: the Arikatsu 3.7.0 candidate contains 11,329 extracted records.
Added
- Site: the whole interface renders in Chinese and English. A topbar toggle
switches in place without reloading, keeps the manuscript, choices, active
finding, expansion state and report currency, and sends no request. The
preference persists in onewuwaterm-langcookie read server-side, so the
first paint matches the choice with no hydration mismatch; first visits
default to Chinese and missing translations fall back to Chinese copy.
Interface language never changes the manuscript, translation direction,
terms or evidence. The storage scanner allows exactly that one
content-pinned cookie write and rejects everything else. - Site: the review workbench exports a readable Markdown snapshot of the
full report (wuwaterm-report.md) beside the manuscript JSON, result JSON
and translation TXT. It is generated locally without requests, is never
clipped by the findings filter, and states the report's own rule version,
dictionary revision, source commit, revisions and request id — never the
app version. Current, stale-edited and imported-untrusted reports carry
distinct wording; zero findings and zero coverage keep their true meaning
and nothing certifies sentence meaning. User text is rendered as literals
inside code spans and fences, so report structure, links and HTML cannot
be forged. - Site:
npm run test:builtruns the landing, review-v2 journey,
shared-quota accounting, parser-rejection, 404, redaction and fail-closed
checks against the real production build artifact (dist/) through the
wrangler test harness with a synthetic upstream and local D1 — no real
model calls and no beta quota.WUWATERM_BROWSER_BUILT=1 npm run test:browserserves the built bundle to the Playwright suite instead of
the dev server, and CI runs both. - Site: a review report with several findings can be filtered by verdict,
stepped through with previous/next, and jumped to an exact source or target
span. Candidate source file and id expand locally. Filtering, navigation,
jumps, and that expansion do not send a review request or change the
report, choices, manuscript, or export. - Site: the public page can show the dictionary version reported by the
service that is actually running. The panel stays unread until the visitor
opens it, so a page view does not spend a meta admission. The site accepts
the current/v1/metabody and a later body that adds game version,
resource version, and changelist. Absent version fields and a failed read
stay unknown; the page does not fill them from the repository pin. - API:
GET /v1/metaaddssource_game_version,source_resource_version,
andsource_changelistfrom the open database. A database that never
recorded those keys returns null. The route does not copy the active source
profile.
Fixed
- Site: imported CRLF manuscripts now locate the exact source and translation
terms and record manually selected alignment ranges in the report's original
coordinates. Saved manuscript and translation bytes retain their line endings.
The English header also wraps within narrow content widths, including a
390-pixel viewport with a classic scrollbar. - Site: a finding displayed after a verdict filter hides the previous active
finding now becomes the navigation selection. Returning to a broader filter
preserves it; an empty filter retains the last selection without displaying
a finding. Navigation remains local and does not change report exports. - Site: replace the vulnerable
bracesresolution with a transparent,
repository-owned 3.0.3 security patch that bounds nested pattern and direct
AST traversal. Both build/lint dependency paths use it; the audit policy is
unchanged. Keep the temporary fork until a verified upstream fix can replace it. - Site: pin Next.js to 16.3.6, the patched release for
GHSA-vcvr-r3jv-pc5j in Node.jsnext/ogimage generation. Refresh only
its locked runtime packages and platform compilers; the site continues to
use its static Open Graph image. - Site: the locked
brace-expansioncopies move to 1.1.21 and 5.0.12, the
patched releases for GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7, and
GHSA-q2hr-2g5m-vwhr. The two copies stay on their existing major lines, and
no direct site dependency changes. - Site: sending a translation to review now preserves an identical manuscript,
asks before replacing existing work, and keeps a recoverable undo snapshot.
Cancelling a handoff leaves any running check intact; replacing a manuscript
rejects late results from its previous check.
Game Data
- data: pin Arikatsu 3.7.0 — the active source profile moves to Wuthering
Waves 3.7.0 / resource 3.7.8 / changelist 8975829 at exact upstream commit
9218d612ad815e398e064e577e42aaf878899968(previously 3.6.0 / 3.6.4 /
8464573 at6ce8d5eda49f2930da84d8846c144432142c7465). The upstream README
at that commit labels the checkout Global / Release; that label is the data
repository's own status line. The candidate built from that checkout carries
11329 extracted records, up from 10951, with 378 added terms, 0 removed and
1 changed zh/en pair. The removed set is empty because the diff matches
source keys: nothing present at 3.6 was dropped. The one change is an
English spelling correction on the existing speaker row
Speaker_800543_Name:Panicked Lolo Logistics Staffbecomes
Panicked Lollo Logistics Staff. Category deltas are echo +26, item +60,
location +17, resonator +5, skill +20, sonata +3, speaker +245 and weapon +2.
New resonator source rows are not all new names:心 / Hsinand
锁暝 / Suomingalready occurred in 3.6,维里奈 / Verinagains another
source key, and the new strings are棠宁 / Tangningand
心狐·漂泊者 / Moon Fox: Rover. Offline gates (verify_db.py,
verify_seed_terms.py,verify_exact_hits.py,verify_idempotent_build.py)
pass on this candidate. - The required representative exact pair stays
景燃 -> Jingran. It was
re-measured on the 3.7 candidate and is still single-valued in both
directions.穗穗 -> Suisuistays retired for the same reason as in 3.6.
棠宁 -> Tangningis a new pair that is also single-valued both ways; it
is the measured new-term sample, not a second required check. - A 3.6 review manuscript does not keep its certification under this
dictionary. The content-derived dictionary revisions differ, a saved 3.6
resolution context is rejected as stale byreview-v2, and the site
manuscript reconciler marks the imported choice pending until the user
confirms it against the fresh basis. A fresh check on the 3.7 candidate
can accept the same sentence once its context carries the new revision. - Generated databases and raw game data are excluded from release artifacts.
Operators buildterms.dblocally from the pinned source.
Supported Game Data
- Source profile: arikatsu
- Source repository: https://github.com/Arikatsu/WutheringWaves_Data.git
- Pinned source commit: 9218d612ad815e398e064e577e42aaf878899968
- GameVer: 3.7.0
- ResVer: 3.7.8
- Changelist: 8975829
Validation
Every asset in this release was built and checked by the release
workflow from the exact commit named below:
- source commit:
cfe07f7bb90cf0555755cfabae28eb6f3eed86c9 python -m build,python -m twine check --strict dist/*python scripts/check_package_artifacts.py dist/*.whl dist/*.tar.gz- clean-venv install, import and CLI smoke for both the wheel and the sdist
- desktop client test suite on Windows, then the packaged executable's
own--self-checkstart-up rehearsal sha256sum -c SHA256SUMSover the downloadable build outputs
Privacy And LLM
Exact database hits do not call the LLM. Free-text sentence translation
can call an OpenAI-compatible endpoint only when the operator configures
one. Do not include tokens, API keys, chat IDs, owner IDs, .env files,
runtime settings, deployment logs, or host names, addresses and paths
that identify a deployment in release materials.
Assets
This release attaches five files:
SHA256SUMSWuwaTerm-0.2.0-windows-x64.ziprelease-manifest.jsonwuwaterm-0.6.0-py3-none-any.whlwuwaterm-0.6.0.tar.gz
Verify the downloads with sha256sum -c SHA256SUMS.
release-manifest.json records the source commit, the client version,
the data pin and the container image digests this release was built from.
The Windows desktop client in the zip is UNSIGNED: no code signing is
performed on it at any point. Windows SmartScreen will warn about an
unrecognised publisher; continue through More info then Run anyway only
if you trust this download, after checking its checksum.
Container images built from the same commit. The tags listed here are
the immutable sha tags pushed while this release was still a draft.
The vX.Y.Z and X.Y tags are applied to these exact digests only
after a maintainer publishes the draft:
ghcr.io/my-denia/wuwaterm:sha-cfe07f7(digestsha256:4af3630238944718fe7673343b5e4c1304333271076c4c80e68029503ebc1ab9)ghcr.io/my-denia/wuwaterm-builder:sha-cfe07f7(digestsha256:08aa538dbaf50d3b36830ea896f3dfc4b09d06d6ea7b5528db64cb4fddccba75)
The runtime image needs a locally built terms.db; the builder image is
what builds it. Verify the image pull works for you before relying on it;
if it is denied, build the images from a source checkout at this tag.
Distribution Boundary
This release distributes source code, the Python package artifacts, the
desktop client binary and container images. It does not distribute
generated SQLite databases, generated TextMap files, or Wuthering Waves
game data. The MIT license covers this project's sou...
v0.5.0
0.5.0
The public product and main catch up to a tagged release. WuwaTerm is an
unofficial, independent fan project: look up official Chinese and English
Wuthering Waves terms, translate a sentence with those names locked, or review
a translation you already have.
Try it: https://wuwaterm.denia-official.chatgpt.site (anonymous public beta,
one shared first-come pool, no SLA). Windows client:
WuwaTerm-0.2.0-windows-x64.zip on this release (unsigned). Self-host and
docs: docs/self-hosting.md and
docs/README.md.
Highlights
- Public beta. No-account lookup, term-locked translation, and review on
the shared site above (#96, #98, #104, #105, #109). - Review workbench. Paste a source string and an existing translation;
dictionary-first findings, no model call (POST /v1/reviews; default
review-v1, opt-inreview-v2) (#110). - Resumable manuscripts. Save or import a local bilingual draft and recheck
current dictionary evidence before reusing saved choices (#111). - Bidirectional term locks. English-to-Chinese placeholder instructions
keep locked tokens for official-term restoration (#108). - API and deploy.
/v1/termsreturns the backend-ranked exact-to-fuzzy
list (the unpublished 0.4.1 package line). Transactional runtime-only deploys
can update bot and API without rebuilding the terminology database (#97,
#107). - Repository front door. Bilingual landing READMEs and a docs index (#112).
Also in this release
- Owner chat allowlisting is
/grant;/authorizeis gone (#95). - The desktop client's CJK-literal gate covers the whole
ui/package (#93,
#94). - GHCR
vX.Y.ZandX.Yimage tags are applied only after this GitHub
Release is published; a discarded draft leaves onlysha-<7>registry tags
(#88).
Supported Game Data
- Source profile: arikatsu
- Source repository: https://github.com/Arikatsu/WutheringWaves_Data.git
- Pinned source commit: 6ce8d5eda49f2930da84d8846c144432142c7465
- GameVer: 3.6.0
- ResVer: 3.6.4
- Changelist: 8464573
Validation
Every asset in this release was built and checked by the release
workflow from the exact commit named below:
- source commit:
e00afb63b6e045785f144c662a53856c0a81a15e python -m build,python -m twine check --strict dist/*python scripts/check_package_artifacts.py dist/*.whl dist/*.tar.gz- clean-venv install, import and CLI smoke for both the wheel and the sdist
- desktop client test suite on Windows, then the packaged executable's
own--self-checkstart-up rehearsal sha256sum -c SHA256SUMSover the downloadable build outputs
Privacy And LLM
Exact database hits do not call the LLM. Free-text sentence translation
can call an OpenAI-compatible endpoint only when the operator configures
one. Do not include tokens, API keys, chat IDs, owner IDs, .env files,
runtime settings, deployment logs, or host names, addresses and paths
that identify a deployment in release materials.
Assets
This release attaches five files:
SHA256SUMSWuwaTerm-0.2.0-windows-x64.ziprelease-manifest.jsonwuwaterm-0.5.0-py3-none-any.whlwuwaterm-0.5.0.tar.gz
Verify the downloads with sha256sum -c SHA256SUMS.
release-manifest.json records the source commit, the client version,
the data pin and the container image digests this release was built from.
The Windows desktop client in the zip is UNSIGNED: no code signing is
performed on it at any point. Windows SmartScreen will warn about an
unrecognised publisher; continue through More info then Run anyway only
if you trust this download, after checking its checksum.
Container images built from the same commit. The tags listed here are
the immutable sha tags pushed while this release was still a draft.
The vX.Y.Z and X.Y tags are applied to these exact digests only
after a maintainer publishes the draft:
ghcr.io/my-denia/wuwaterm:sha-e00afb6(digestsha256:12ad2ad198aa9d7fca1f0f82dc153dcb45bf025a8b98fe0147b9b5739216fc3d)ghcr.io/my-denia/wuwaterm-builder:sha-e00afb6(digestsha256:3988f9e973f171d60450fd7259de0db5c7e3f0b8629ff12c49e4b5405afe9cfd)
The runtime image needs a locally built terms.db; the builder image is
what builds it. Verify the image pull works for you before relying on it;
if it is denied, build the images from a source checkout at this tag.
Distribution Boundary
This release distributes source code, the Python package artifacts, the
desktop client binary and container images. It does not distribute
generated SQLite databases, generated TextMap files, or Wuthering Waves
game data. The MIT license covers this project's source code only, not
Wuthering Waves game data or in-game terminology.
Known Limitations
- WuwaTerm is an unofficial, independent fan project. It is not
affiliated with, authorized by, or endorsed by Kuro Games. - Release artifacts remain self-hosting inputs. A separate anonymous
public beta is available at https://wuwaterm.denia-official.chatgpt.site;
it uses one shared, first-come pool and has no SLA or per-visitor
fairness guarantee. - Live Telegram operation requires maintainer-provided credentials and
chat configuration. - Free-text sentence translation requires an external OpenAI-compatible
endpoint. - The desktop client is built and tested on Windows x64 only, and it is
not code-signed.
v0.4.0
0.4.0
Presentation, distribution and data release. A third presentation layer — an
owner-private web interface running inside the API process and off by default —
joins the Telegram bot and the HTTP API; the game-data pin moves to Wuthering
Waves 3.6.0 / resource 3.6.4 / changelist 8464573 at upstream commit
6ce8d5eda49f2930da84d8846c144432142c7465; the desktop client becomes 0.2.0 and
is published as a release asset for the first time; and every release asset is
now built by a workflow from one reviewed commit rather than by hand. The
project also gains its governance entries, a generic self-hosting guide separate
from the owner's own runbook, and one command that runs every offline gate.
Game Data
- data: pin Arikatsu 3.6.0 — the active source profile moves to Wuthering
Waves 3.6.0 / resource 3.6.4 / changelist 8464573 at exact upstream commit
6ce8d5eda49f2930da84d8846c144432142c7465(previously 3.5.0 / 3.5.5 /
8059200 atdae29691c04ef0f48d0810b5d244fb0b37288c60). The candidate built
from that checkout carries 10951 extracted records, up from 10691, with 260
added terms, 0 removed and 6 changed zh/en pairs; the offline gates
(verify_db.py,verify_seed_terms.py,verify_exact_hits.py,
verify_idempotent_build.py) all pass on it anddiff_terms_db.pyreports
no removed term. - The required representative exact pair is now
景燃 -> Jingran, a resonator
that is new at 3.6 and single-valued in both directions in the built
database. The 3.5 pair穗穗 -> Suisuiwas retired because 3.6 adds a second
speaker row穗穗(通讯中) -> Suisui, which makes the reverse direction
ambiguous and would fail the check on a correct build. The verifier's tests
gained a case for that failure shape (a second zh row carrying the same en). - No production data is shipped by this change: deployments pick the new pin
up throughdeploy/vps-update.sh, which refreshes the checkout and rebuilds
and re-verifies the candidate on the target host.
HTTP API / Web Presentation Layer
- New: an owner-private web presentation layer. A mobile-first browser
interface for dictionary lookup and sentence translation, mounted inside the
API process as a sub-application over the same protocol-neutral pipeline the
Telegram bot and the HTTP API already use. It is off by default: with
WUWATERM_API_WEB_ENABLEDunset there is no route, no sub-application and no
entry in the published API document, and the process behaves exactly as it
did before the layer existed. When enabled it requires a device credential
held server-side (WUWATERM_API_WEB_DEVICE_TOKEN) and a marker the reverse
proxy injects on every proxied request (WUWATERM_API_WEB_EDGE_SECRET);
without that marker it refuses everything, so reaching the loopback port
directly does not get past the front door. Session lifetime and the ceiling
on live sessions areWUWATERM_API_WEB_SESSION_TTL_SECONDSand
WUWATERM_API_WEB_MAX_SESSIONS. The surface ships no page scripts and the
browser holds only an opaque HttpOnly session cookie. Decision and cost:
ADR 0014; operation:
docs/web-presentation-layer.md. The layer
landed in an earlier pull request without an entry that introduced it; this
is that entry, written where the surface belongs rather than backdated. - Malformed serve-only numeric settings no longer block operator credential
commands such asdevice revoke:from_env()now retains their raw forms
while falling back safely, andservevalidates all eight values strictly
before logging, credential-store initialization, app construction or socket
serving. TERM_QUERY_MAX_LENGTHis defined once inwuwaterm_apiand imported by
both the JSON routes and the web views (previously 200 vs a local 120).- The web surface envelope now matches the mount path exactly or its
children only, so a future sibling like/wuwaterm-webhooksis not
rewritten as a web page. - Restyled the owner-private web surface (markup unchanged): ink-and-gold
palette with a sharp 3px geometry, underline tabs, gold provenance heading
on result cards, gold focus rings, and a brand bar across the viewport top.
All previous functional rules stand: system fonts only, zero scripts, one
round trip, 16px inputs,pre-wrapresults.
Channel Adapter
- Capacity-driven channel skips (
queue_full,llm_budget) now DM the bot
owner, rate-limited to one notice per 10-minute window with the suppressed
count folded in. Content gates stay silent by design; only degradation the
owner could not otherwise see is reported. The notice carries counts and
internal reason vocabulary only, never post text, and its own delivery
failure is swallowed into the log. - Edits now yield to new posts near LLM-budget exhaustion: an edit is
admitted only if the remaining per-minute budget covers its calls plus a
two-call headroom (skipped:edit_yield). A yielded edit delays refreshing
an already-delivered translation; a rejected new post would mean no
translation at all.ChannelRuntime.budget_remainingexposes the read-only
reading the gate uses; admission itself still goes throughreserve. - Edit-token bookkeeping is now bounded: tokens share the entry TTL and are
pruned onbegin_edititself, so edits skipped before any remember
(content gates) no longer accumulate in-process forever. - Reply-index persistence no longer runs on the event loop. Payloads are
snapshotted on the loop thread and the write (tmp file + fsync + replace +
directory fsync) is offloaded, single-flight, coalescing multi-chunk bursts
into the latest snapshot. Sync callers keep the original inline semantics. - An edit whose tracked reply still exists but rejects the in-place edit
("uneditable", distinct from "gone") now deletes that reply instead of
leaving it visible but untracked — an orphan that no later edit could ever
update again. The no-repost-on-gone policy is unchanged. - Review follow-ups (PR #76): the capacity-notice cooldown and pending count
are now committed only after the owner DM actually sends; a transient
failure keeps the count and re-arms after a 60-second retry delay instead
of silencing alerts for the whole 10-minute window. A successful notice
clears only the skips it reported, so skips that arrive while the DM is in
flight survive into the next notice instead of being silently zeroed. - Edit-token registration is deferred to the moment an edit actually starts
its first LLM call (the dictionary fast path registers just before its
emit), so an edit rejected by any bail path —edit_yield,queue_full,
llm_budget, staleness or authorization rechecks — no longer supersedes an
admitted in-flight edit whose completed translation was then dropped as
stale with nothing replacing it. - The reply index gains
aflush(), wired to the application's
post_shutdownhook: an offloaded save still queued at shutdown is drained
(and a cancelled one rewritten inline from memory), and the flush waits out
an executor write already in flight so an older snapshot cannot replace the
final one on disk. Replies remembered just before exit survive the restart
instead of causing duplicate translations. The flush also runs when the
translator close raises (independentfinally), and the offloaded writer
now uses a dedicated single-worker executor whose futures can be awaited
safely — a job cancelled while still queued raises immediately instead of
hanging the shutdown flush. - The edit budget-yield gate is capped by the configured per-minute
capacity: atWUWATERM_CHANNEL_LLM_CALLS_PER_MINUTEof 1-3 the
required+headroom sum is unreachable even on a fresh window, which would
have yielded every edit forever; a completely unused window now always
admits one edit. - A multi-chunk edit whose later tracked reply rejects edits ("uneditable")
now deletes that reply instead of dropping it from the rebuilt index while
leaving it visible — the same orphan the first-chunk path already handles.
When that delete itself fails, the id stays tracked as a trailing stale
extra rather than at the chunk position, so the next edit does not map a
fresh chunk onto the still-uneditable reply. - The capacity owner notice now reports per-reason counts
(e.g.llm_budget ×2、queue_full ×1) instead of labelling the whole
aggregated count with whichever reason happened to trigger the notice. - Web stylesheet: decorative glyphs are literal Unicode again — CSS
code-point escapes like\25C6in a plain Python string parse as octal
control characters, so the heading diamonds and em-dashes rendered as
mojibake since the restyle.
Telegram Bot
- The dictionary stage (exact + full-table fuzzy over sqlite) now runs off
the event loop via the pipeline's existingoffloadseam, matching what
the HTTP adapter already did; a fuzzy lookup can no longer stall every
concurrent handler.
Desktop Client
- The client is 0.2.0, the first version distributed as a release asset:
WuwaTerm-<version>-windows-x64.zip, the one-folder build, listed in
SHA256SUMS. It is not code-signed — SmartScreen will warn on first run,
andclient/README.mdsays so and shows what to do. - Compatibility contract: client 0.2.x speaks HTTP API
v1, served by wuwaterm
0.3.0 or newer. The client checks it on the/v1/metareply the status view
already fetches when the owner presses 刷新 — no new request, and none at
startup: an unconfigured client still sends nothing. A server reporting an
API version this client does not support gets a warning naming both versions,
while the service facts stay on screen and the client keeps working.
Distribution And Release Pipeline
- New
.github/workflows/release.ymlbuilds every release asset from one
reviewed commit: the wheel and the sdist (with...
v0.3.0
v0.3.0
API-first release: one protocol-neutral application layer now serves two
presentation adapters - the existing Telegram bot and a new versioned HTTP
API with revocable device-principal authentication - plus a Windows desktop
client that consumes the API. See CHANGELOG.md for the complete list,
including the Upgrading From 0.2.1 section.
Highlights
- New wuwaterm_api package: a versioned, plain-text HTTP surface
(POST /v1/translations, GET /v1/terms, GET /v1/meta, plus health probes)
served by the same dictionary-first pipeline as the bot, with a stable
error envelope, request ids, per-device rate limits, a committed OpenAPI
snapshot and a contract drift gate. - Revocable device credentials: devices are registered by an operator with
shell access; the secret is supplied on standard input and only a salted
scrypt verifier is stored, so the service never produces or prints
credential material. Structured per-request completion records carry a
redacted principal and never the credential, the device id, or the
translated text. - Windows desktop client (client/): exact lookup, sentence translation,
direction control, mid-flight cancellation, service status, and stable
error rendering. The device credential lives only in the Windows
Credential Manager. A missing or unusable settings file leaves the client
in an explicit unconfigured state - the window says which server address
is in use, or that none is configured - and settings saves are atomic. - Deployment: a second, loopback-only Compose service runs the API; the
transactional updater and rollback cover both serving containers;
publication happens through a reverse-proxy path route the host already
serves. SSH remains an operations channel only - it is never the product
transport, and revoking an API device never touches SSH access. - Architecture: docs/architecture.md rewritten for the multi-adapter
system; new decision records 0009-0012 cover the HTTP adapter,
device-principal authentication, the client stack, and the transport
selection with its threat model and migration path.
Supported Game Data
- Source profile: arikatsu
- Source repository: https://github.com/Arikatsu/WutheringWaves_Data
- Pinned source commit: dae29691c04ef0f48d0810b5d244fb0b37288c60
- GameVer: 3.5.0
- ResVer: 3.5.5
- Changelist: 8059200
Validation
- python scripts/check_repo_hygiene.py
- python scripts/check_non_goals.py
- python scripts/check_architecture_boundaries.py
- python scripts/check_api_contract.py
- python -m pytest
- Packaging: build + twine check --strict + scripts/check_package_artifacts.py
- clean-venv install/import/CLI smoke for both the wheel and the sdist
Privacy And LLM
Exact database hits do not call the LLM. Free-text sentence translation can
call an OpenAI-compatible endpoint only when the operator configures one. Do
not include tokens, API keys, chat IDs, owner IDs, .env files, runtime
settings, or deployment logs in release materials.
Assets
This release attaches the audited source-only Python package artifacts built
from the exact release commit: one wheel, one sdist, and SHA256SUMS. Verify
downloads with sha256sum -c SHA256SUMS.
Distribution Boundary
This release distributes source code only. It does not distribute generated
SQLite databases, generated TextMap files, or Wuthering Waves game data, and
no desktop-client executable is attached; the client is built from source
with client/build.ps1 or taken from the CI build artifact.
Known Limitations
- Self-hosted; no public hosted service is provided.
- Live Telegram operation requires maintainer-provided credentials and chat
configuration. - Free-text sentence translation requires an external OpenAI-compatible
endpoint. - The HTTP API serves operator-registered devices; there is no public
registration.
v0.2.1
v0.2.1
Maintenance release packaging post-v0.2.0 production hardening from PRs #41–#45.
Game-data pin is unchanged (Wuthering Waves 3.5.0 / resource 3.5.5 / changelist
8059200 at dae29691c04ef0f48d0810b5d244fb0b37288c60).
Highlights
- Channel LLM content-shape failures retry once as plain text instead of
dropping the post;invalid_api_responseis split from content-shape
invalid_response; budget-of-1 deployments remain correct. - Inline
/tr <text>preserves Telegram rich-text entities; normalization /
term-lock / fuzzy correctness fixes for wrong translations; delivery and
observability hardening on linked-channel paths (#41–#43). - Maintainer architecture map, ADRs 0001–0008, and fail-closed import-boundary
guard wired into local validation and CI (#44–#45; no intentional runtime
behavior change in those two PRs).
Supported Game Data
- Source profile: arikatsu
- Source repository: https://github.com/Arikatsu/WutheringWaves_Data
- Pinned source commit: dae29691c04ef0f48d0810b5d244fb0b37288c60
- GameVer: 3.5.0
- ResVer: 3.5.5
- Changelist: 8059200
Validation
python scripts/check_repo_hygiene.pypython scripts/check_non_goals.pypython scripts/check_architecture_boundaries.pypython -m pytest- Packaging: build + twine check --strict +
scripts/check_package_artifacts.py- clean-venv install/import/CLI smoke for wheel and sdist
Privacy And LLM
Exact database hits do not call the LLM. Free-text sentence translation can call
an OpenAI-compatible endpoint only when the operator configures one. Do not
include tokens, API keys, chat IDs, owner IDs, .env files, runtime settings, or
deployment logs in release materials.
Assets
This release attaches the audited source-only Python package artifacts built
from the exact release commit: one wheel, one sdist, and SHA256SUMS. Verify
downloads with sha256sum -c SHA256SUMS.
Distribution Boundary
This release distributes source code only. It does not distribute generated
SQLite databases, generated TextMap files, or Wuthering Waves game data.
Known Limitations
- Self-hosted bot; no public hosted service is provided.
- Live Telegram operation requires maintainer-provided credentials and chat
configuration. - Free-text sentence translation requires an external OpenAI-compatible
endpoint.
v0.2.0
v0.2.0
Production hardening release: Wuthering Waves 3.5 data pin, transactional VPS
deployment, Telegram structural safety, and default CI packaging gates.
Highlights
- Active source profile updated to Wuthering Waves 3.5.0 / resource 3.5.5 /
changelist 8059200 at exact upstream commit
dae29691c04ef0f48d0810b5d244fb0b37288c60, with provenance recorded in
generated DB metadata and read-only strong candidate verification gates. - VPS updates are now transactional around a separately verified candidate
database and an immutable revision-labelled runtime image, with DB/image/
pointer rollback and an immutable deployment manifest. Builder containers no
longer receive the runtime.env. - Every Telegram HTML tag, attribute, link, custom emoji id, and entity is
protected with opaque structural placeholders; structural drift fails closed.
Bounded linked-channel admission, atomic multi-chunk LLM call budgets,
post-queue freshness/authorization checks, and privacy-safe outcome telemetry. - Default CI now blocks lockfile drift, packaging regressions (wheel/sdist
build, strict metadata, clean-venv install, content audit), Docker
runtime/builder boundary breaks, and deploy config/script failures.
Supported Game Data
- Source profile: arikatsu
- Source repository: https://github.com/Arikatsu/WutheringWaves_Data
- Pinned source commit: dae29691c04ef0f48d0810b5d244fb0b37288c60
- GameVer: 3.5.0
- ResVer: 3.5.5
- Changelist: 8059200
Upgrading From v0.1.0
- The deployment target must be a clean Git checkout with
originandmain;
exported non-Git copies are intentionally not deployable. Use
deploy/vps-update.shfor live upgrades; seedocs/deployment.md. - Runtime state (
chat_settings.json,channel_replies.json) moved from
data/tostate/; the updater and runtime perform a validated one-time
migration and never overwrite existing state. - The runtime image only runs the bot; data refresh/build/verify commands moved
to the builder image (wuwaterm-builder). - Rebuild the terms database with the 3.5 pin via the transactional updater;
seedocs/data-refresh.md.
Validation
python scripts/check_repo_hygiene.pypython scripts/check_non_goals.pypython -m pytestpython scripts/check_package_artifacts.py dist/*.whl dist/*.tar.gzpython scripts/verify_db.py data/terms.candidate.db --profile arikatsu
Assets
This release attaches the audited source-only Python package artifacts built
from the exact release commit: one wheel, one sdist, and SHA256SUMS. Verify
with sha256sum -c SHA256SUMS.
Privacy And LLM
Exact database hits do not call the LLM. Free-text sentence translation can
call an OpenAI-compatible endpoint only when the operator configures one. No
tokens, API keys, chat IDs, owner IDs, .env files, runtime settings, or
deployment logs are included in release materials.
Distribution Boundary
This release distributes source code only. It does not distribute generated
SQLite databases, generated TextMap files, or Wuthering Waves game data. The
MIT license covers this project's source code only, not Wuthering Waves game
data or in-game terminology.
Known Limitations
- Self-hosted bot; no public hosted service is provided.
- Live Telegram operation requires maintainer-provided credentials and chat
configuration. - Free-text sentence translation requires an external OpenAI-compatible
endpoint.
v0.1.0
v0.1.0
Supported Game Data
- Source profile: arikatsu
- Source repository: https://github.com/Arikatsu/WutheringWaves_Data
- Pinned source commit: 58ec43698d2b4e188cb285467ce1ae887612dd92
- GameVer: 3.4.0
- ResVer: 3.4.13
Validation
Release target: 6d509d0
Local validation on the release-finalization PR branch:
.venv/bin/python -m pytest— 361 passed.venv/bin/python scripts/check_repo_hygiene.py— repo hygiene ok.venv/bin/python scripts/check_non_goals.py— non-goal guard okgit diff --check— passed- Local tracked-Markdown relative link check — checked 8 Markdown files; local relative links ok
GitHub validation:
- PR #31 CI run passed on Python 3.11 and 3.12 before merge.
- Claude review reported no blocking issues on the final PR head.
- Codex P2 feedback was addressed; the remaining review thread is outdated.
Privacy And LLM
Exact database hits do not call the LLM. Free-text sentence translation can call
an OpenAI-compatible endpoint only when the operator configures one. Do not
include tokens, API keys, chat IDs, owner IDs, .env files, runtime settings, or
deployment logs in release materials.
Distribution Boundary
This release distributes source code only. It does not include generated SQLite
databases, generated TextMap files, or Wuthering Waves game data as release
assets.
Known Limitations
- Self-hosted bot; no public hosted service is provided.
- Live Telegram operation requires maintainer-provided credentials and chat configuration.
- Free-text sentence translation requires an external OpenAI-compatible endpoint.