Repository navigation
Releases: Quazmoz/InferBridge
Release list
InferBridge 1.0.0
InferBridge 1.0.0
First stable release of InferBridge, including the accumulated beta work and the following updates since 0.11.0-beta.1.
Highlights
- Discover compatible OpenVINO models already present on disk and adopt them into the local model library without copying model files.
- Improve local model import, status refresh, evidence identity, and action grouping.
- Harden model conversion by bounding noisy diagnostics and preserving progress when subprocesses emit oversized output.
- Improve chat stream recovery, engine handoff safety, and crowded-header layout behavior.
Compatibility and security
- Existing settings, model files, caches, and data schema remain compatible. The current data schema is 1.
- The Windows installer and portable package are unsigned and make no Authenticode signing claim. Windows may show
Unknown publisher; verify downloaded files against the published SHA-256 checksums before running them. - Mock smoke tests and CI do not certify real CPU, GPU, or NPU performance, driver behavior, installer upgrade behavior, Authenticode trust, or SmartScreen reputation. See
docs/COMPATIBILITY_MATRIX.mdanddocs/KNOWN_ISSUES.mdfor the current evidence and limitations.
InferBridge 0.11.0-beta.1
InferBridge 0.11.0-beta.1
Fixes two issues reproduced during local OpenVINO hardware testing and rebuilds the beta.
Fixes
- Prevents HTTP 500 after NPU stream cancellation by waiting for engine recovery before prompt construction and token accounting. Applies the same model lease to Responses requests, tool retries, and context-budget inspection, and retains it until cancelled tokenizer workers finish.
- Prevents GenAI from applying a second chat template to already formatted prompts, which could exceed the NPU prompt limit even when the app's token budget passed.
- Makes the Benchmark Lab browser regression select CPU explicitly so it works on machines with GPU and NPU devices as well as CPU-only CI workers.
- Removes a live Hugging Face dependency from the custom embedding registration unit regression; access checks remain covered separately.
- Skips the real Hugging Face progress-bar regression when optional conversion dependencies are absent in minimal-runtime CI; qualified Windows builds still execute it.
- Retains the active Hugging Face download progress and preparation watchdog fix from 0.11.0-beta.
Validation and compatibility
- Local source validation: 1,333 unit tests passed, 20 skipped; 39 Chromium browser checks passed.
- Ruff lint, formatting, dependency consistency, and all 37 injected JavaScript blocks passed.
- Fixes Windows certification report generation when a device is unavailable or its server fails to start.
- Existing settings, model files, downloaded caches, and data schema remain compatible.
- Real CPU, GPU, and NPU API and prompt-capacity checks passed on the local validation machine. GPU compiled-cache reuse failed its fingerprint check and remains unverified.
- See
docs/certification/LOCAL_AUDIT_2026_09_18.mdfor hardware results and verification limits. - This beta is unsigned and makes no Authenticode signing claim.
InferBridge 0.11.0-beta
InferBridge 0.11.0-beta
Fixes active model downloads being cancelled after ten minutes because Hugging Face download progress was hidden in the packaged application.
Fixes
- Restores live download progress in the Windows converter so active transfers reach the preparation watchdog and UI.
- Enables line-oriented Hugging Face progress for source conversions with captured output.
- Covers the packaged stream with a real Hugging Face progress bar regression check.
Recovery and compatibility
- Existing settings, models, and downloaded cache entries remain compatible. Use Resume preparation after upgrading to reuse cached files.
- Diagnostics exports are stored in
%LOCALAPPDATA%\InferBridge\diagnosticsfor installed mode, ordata\diagnosticsbeside the executable for portable mode. - This is a beta prerelease. Unsigned artifacts make no Authenticode signing claim.
InferBridge 0.10.0-beta.1
InferBridge 0.10.0-beta.1
InferBridge 0.10.0-beta.1 is the first beta after 0.9.6. It expands the hardware-advisor workflow into a Benchmark Lab, strengthens benchmark evidence and resource-safety handling, improves model recovery and storage resilience, and hardens the development and release qualification path.
This is a beta pre-release. Release artifacts may be unsigned; if they are unsigned, Windows may report an unknown publisher and SmartScreen may warn. Verify downloads against the published SHA-256 checksums.
Benchmark Lab and hardware guidance
- Adds a dedicated Benchmark Lab in the browser UI for repeatable local model/device measurements.
- Adds bounded benchmark requests, resource-safety checks, and regression coverage around benchmark execution.
- Improves benchmark evidence persistence and ranking so recommendations distinguish measured local evidence from expected compatibility.
- Refines hardware-advisor device profiles, automatic benchmark behavior, and profile ranking.
- Adds Chromium behavior coverage for the Benchmark Lab.
Reliability and recovery
- Improves model-recovery UI behavior and recovery-state handling.
- Hardens storage-state handling and adds resilience coverage for damaged or partially written state.
- Improves model-converter compatibility and associated regression coverage.
- Extends model-resolution and advisor-evidence resilience tests.
API and integration quality
- Extends OpenAI-compatible API behavior covered by the external contract smoke suite.
- Adds Hermes Agent integration guidance and refreshes integration documentation.
- Adds repository-level agent tooling guidance for supported coding assistants without changing InferBridge's runtime architecture.
Release and CI hardening
- Keeps the pinned Windows release baseline separate from the latest-compatible dependency canary.
- Exercises the source suite on Python 3.11 through 3.14, Chromium browser behavior, external API contracts, and Windows release/security harnesses.
- Fixes the release publisher to target the canonical
Quazmoz/InferBridgerepository instead of the legacy pre-rename repository path. - Keeps the qualified OpenVINO release stack pinned; newer dependency stacks remain canary inputs until explicitly qualified.
Compatibility
- Persistent data schema remains version 1.
- Existing 0.9.6 models, settings, caches, browser state, benchmark evidence, and diagnostics remain compatible.
- Installer identity and installation location remain unchanged for in-place upgrades.
- OpenVINO GenAI remains the inference runtime. No Docker, Ollama, llama.cpp, GGUF, or cloud-inference dependency is introduced.
Qualification
The last code-changing development snapshot before this beta preparation passed the qualified Windows release baseline, latest-compatible Windows canary, external API contract smoke, Python 3.11-3.14 test matrix, Chromium browser behavior suite, and Windows release/security harness. The beta version and release-publisher corrections introduced during promotion preparation must also pass CI before the branch is promoted.
Mock and source validation do not prove physical-device behavior. Before stable promotion, validate a fresh install and in-place upgrade on real Windows hardware and confirm the available CPU/GPU/NPU paths with mock mode disabled. Authenticode claims are valid only when the signing gate succeeds.
Qualification status at publication
This unsigned beta was published at the maintainer's explicit request with known qualification failures. CPU qualification passed. GPU compiled-cache reuse failed in the full Windows harness; NPU cancellation recovery can cause subsequent Chat/Responses requests to fail with HTTP 500; AUTO lifecycle unload failed with HTTP 409. A correction is under review in #50 and is not included in these artifacts. Actual installer execution, clean-machine upgrade/uninstall, SmartScreen, and Authenticode trust were not verified.
InferBridge 0.9.6
InferBridge 0.9.6
InferBridge 0.9.6 promotes the 0.9.6 beta line to stable with hardened Windows startup and installation, stronger local security boundaries, more resilient model and storage lifecycle handling, expanded OpenAI-compatible APIs, and privacy-safe support workflows.
This release is unsigned. Windows will report an unknown publisher and SmartScreen may warn on first launch. No Authenticode signing claim is made in the release metadata. Verify downloaded artifacts against the published SHA-256 checksums.
Highlights
- Adds connection management, conversation management, storage management, runtime health, and expanded Responses API capabilities.
- Hardens desktop API keys, browser authentication, LAN exposure, local-request validation, credential handling, and path safety.
- Improves model preparation, cancellation, recovery, quantization guidance, embeddings lifecycle safety, and device-aware runtime diagnostics.
- Hardens the Windows installer and frozen first-launch path with installed-runtime bootstrap validation and semantic-version downgrade protection.
- Adds System Doctor feedback entry points and privacy-safe copyable diagnostics without uploading prompts, history, credentials, logs, or model files.
- Expands Windows CI and regression coverage across packaging, installer, lifecycle, security, UI, storage, recovery, and resilience contracts.
Compatibility
- Persistent data schema remains version 1.
- Existing 0.9.5 and 0.9.6 beta models, settings, caches, browser history, onboarding state, and diagnostics remain compatible.
- Installer identity and installation location remain unchanged for in-place upgrades.
- OpenVINO GenAI remains the inference runtime, with CPU, GPU, and NPU availability determined by the installed runtime and drivers.
Validation scope
The release build runs the repository's source tests, lint and format gates, packaged bootstrap and native checks, and packaged mock smoke test. Mock validation does not prove behavior on every physical CPU, GPU, NPU, driver, or Windows installation. These artifacts are not Authenticode signed; signature and publisher-trust validation are intentionally not claimed.
InferBridge 0.9.5
InferBridge 0.9.5
This is a full release, not a pre-release. It supersedes 0.8.0 as the current
stable version.
Its artifacts are unsigned. Windows reports an unknown publisher and SmartScreen may warn
on first launch. Nothing in this release has been Authenticode signed, and no signing claim is
made anywhere in its metadata. Verify downloads against the published SHA-256 checksums. A
signed build will have to advance the version, because published tags and assets are immutable.
Everything below shipped only as 0.9.x pre-releases until now. 0.9.0 through 0.9.3 were never
published as stable, and 0.9.0 was written as a planned stable record that no tag
ever carried; 0.9.5 is the release that actually delivers that content to the stable channel.
The code in this release is the code from 0.9.3-beta.2 with no functional change. The only
source differences are in test and lint hygiene, described under
Release gate below.
Model preparation is transactional
A conversion that was cancelled, ran out of disk, or was interrupted by an upgrade could leave
partially written OpenVINO output in the live model directory, and that output was then treated
as a converted model.
- Exports are staged, then published. Conversion writes into a sibling staging directory,
the result is validated, and only then does it replace the live directory, through a bounded
backup and rollback window. A previously working model survives a failed or cancelled
reconversion. - Publication is hardened for Windows. Replacement retries transient sharing violations and
access denials rather than failing on the first antivirus or Explorer lock, and clears
read-only attributes it encounters. - Packaged conversions run inside the same transaction. The packaged converter path
previously bypassed staging; conversions launched from the installed or portable build now get
the same guarantee as source runs. - Preparing the same model twice is blocked across processes. An installed instance and a
portable one could previously convert the same model into the same directory simultaneously.
Preparation now takes a cross-process lock on the output directory, and the second process
fails fast telling you to wait or close the other instance.
Incomplete model directories are no longer treated as models
A partially written export can contain an IR XML file before its weights or configuration are on
disk. That directory previously counted as downloaded, so retries skipped conversion and handed
an incomplete artifact to the native OpenVINO loader.
- One shared readiness check in
runtime/model_artifacts.pyvalidates that the IR XML is a
complete document, that its paired weights file exists and is non-empty, and that the model
configuration is present and parseable. Catalog, recovery, and load paths all use it, so they
can no longer disagree about whether a model is ready. - The check stays cheap. It probes bounded regions of the IR XML rather than parsing
multi-gigabyte files, so catalog listing is not slowed down. - Recovery classifies staged output correctly. Interrupted staging is reported as recoverable
output instead of being missed, and recovery cleans it up.
Symbolic links and Windows junctions are refused
Deletion and recovery cleanup previously followed reparse points, so a model directory that was
really a junction could have caused deletion outside model storage. Junctions are invisible to
is_symlink(), so link detection now reads file attributes directly.
- Model deletion refuses to act through a symbolic link or junction and asks you to remove the
link manually after confirming its target. - Recovery cleanup refuses the same, refuses paths that are not directories, and refuses staged
paths that fall outside the configured model directory.
Installing over an existing installation, and uninstalling, both work
Two reported installer defects had one cause: the tray launcher and its server child are
windowed processes with no top-level window, so Restart Manager had nothing to send a close
message to and reported that applications could not be shut down. Nothing else stopped the
application, so upgrade failed on locked files and uninstall left files behind while reporting
success.
- Setup and the uninstaller stop a running instance before touching any file.
PrepareToInstallandInitializeUninstalldetect a live instance through its lock file, ask
it to exit through its own tray command file, and wait up to 15 seconds. - An instance that will not exit is terminated. Termination is reached only while the
installed instance still holds its lock, so an unrelated portable instance is normally
untouched. - The tray honours an external quit request. The command-file handler previously only set the
stop event, ending the status poller while the tray message loop kept running and kept holding
installation files. It now performs the same full shutdown as the tray menu's Quit. - Uninstall removes what it previously left behind — compiled Python caches and anything left
by an interrupted upgrade — with attribute clearing and bounded retries, then removes the
emptied program directory. - Uninstall reports what it could not remove. Every removal result is checked and any
surviving path is named, instead of being discarded while the uninstaller claims success. - Start with Windows is removed on uninstall. The
Runentry previously survived, so Windows
kept trying to launch a deleted executable at every logon.
Packaged model conversion works
The installed and portable builds of 0.9.3-beta.1 and earlier could not prepare any model.
Every conversion failed with Conversion failed: could not get source code seconds in, before a
single byte was downloaded, while the same conversion succeeded from a source checkout.
- The bundle ships Python sources for the conversion packages.
optimum-cli export openvino
importsoptimum.intel.openvinofirst, which applies a Transformers decorator that reads its
decorated function's source withinspect.getsource, andimport torchtokenizes its own
configuration modules the same way. Shipping only bytecode meantlinecachefound no lines and
Python raisedOSError. This adds roughly 9 MB. - Release validation imports the export chain. The packaged smoke test previously walked only
Optimum's CLI registration namespace, which never imports Optimum Intel, so the build passed
while every conversion was broken. A missing source file now fails the build instead of the
user's first download. - Long packaged downloads no longer fail mid-flight.
tqdmand the Transformers loader
redrew on the helper's stderr with carriage returns and no newline, and the server reads that
pipe withasyncio.StreamReader.readline, which raises once its 64 KiB buffer fills without a
separator. In-process Optimum output is now split into whole lines. - Packaged conversions report real progress. Download and quantization percentages reach the
UI instead of one static "Running packaged OpenVINO conversion…" message for the whole export. - Packaged Optimum CLI discovery is gated at build time. The build now requires the packaged
Optimum CLI to actually discover the OpenVINO export command through the same namespace scan
the CLI uses; bundling the registration module is not sufficient if PyInstaller leaves it
outside that scan. - The OpenVINO tokenizer runtime is bundled and packaged DLL search paths are registered.
Tokenizer runtime failures are classified distinctly, and a tokenizer packaging fault no longer
triggers pointless retries against other devices. - Frozen helper failures name their origin. A windowed helper cannot show a traceback, so
failures now report the exception type and the originating file and line, with no bundle path
included.
Device switches no longer interrupt the loaded model
Switching a loaded model to another device previously took the model's lock before compiling the
replacement, so the model was unavailable for the entire compilation.
- The loaded engine stays usable while the replacement compiles. The lock is taken only for
the short handoff at the end, and it is re-validated in case the engine was replaced while
waiting. - The catalog reports the switch honestly. A loaded model that is switching devices is shown
as loading and cannot be unloaded, instead of appearing idle and unloadable. - Unload is rejected during a switch, which previously raced the load task. Shutdown can
still force cleanup after its generation drain timeout.
Model preparation recovery
- Persists sanitized recovery state after interrupted, cancelled, or failed conversion and
loading operations, and distinguishes reusable Hugging Face source cache data from incomplete
or complete OpenVINO conversion output. - Adds a WebGUI recovery screen with resume, failed-stage retry, fresh-download restart,
incomplete-output cleanup, and sanitized failure details. - Keeps recovery actions operation-scoped with stale recovery-ID rejection behind the existing
API-key and browser-origin protections, and refuses to remove complete models, symbolic links,
paths outside the configured model directory, or the model-directory root. - Preserves stream cancellation precedence when a cancellation and a recovery race.
- Cleanup is resilient on Windows. Transient
rmtreefailures retry with a bounded backoff,
the read-only attribute is cleared before retrying, symbolic links are checked before existence
so a dangling link is refused rather than treated as an absent directory, and a cleanup that
cannot complete raises a bounded, actionable conflict naming no local path while preserving the
recovery record.
See Model preparation recovery for the r...
InferBridge 0.9.3-beta.2
InferBridge 0.9.3-beta.2
This is a beta pre-release and its artifacts are unsigned. Windows will report an
unknown publisher. Install it only if you accept that. Nothing in this release has been
Authenticode signed, and no signing claim is made anywhere in its metadata.
It fixes a defect that made the installed and portable builds unable to prepare any model.
Every conversion failed with Conversion failed: could not get source code a few seconds
in, before a single byte was downloaded, while the same conversion succeeded from a source
checkout. If you installed 0.9.3-beta.1 or earlier and no model would download, this is
that bug.
Packaged model conversion works again
optimum-cli export openvino imports optimum.intel.openvino before it downloads
anything. Importing it applies a Transformers decorator that reads the source of the
function it decorates with inspect.getsource, and import torch tokenizes its own
configuration modules the same way. The packaged build shipped only bytecode for Optimum,
Optimum Intel, NNCF, and Hugging Face Hub, so linecache found no lines for those modules
and Python raised OSError: could not get source code during the import. That is why the
failure was invisible from a source checkout, where the .py files exist on disk.
- The bundle now ships Python sources for the conversion packages, and for torch's
configuration modules explicitly rather than relying on a third-party PyInstaller hook to
keep collecting them. This adds roughly 9 MB. - Release validation now imports the export chain. The packaged smoke test previously
only walked Optimum's CLI registration namespace, which never imports Optimum Intel, so
the build passed while every conversion was broken. It now imports
optimum.exporters.openvinoandoptimum.intel.openvinoinside the frozen bundle, and a
missing source file fails the build instead of the user's first model download.
Long packaged downloads no longer fail mid-flight
A packaged conversion runs Optimum inside the helper process, so tqdm and the Transformers
loader redrew directly on the helper's stderr using carriage returns and no newline. The
server reads that pipe with asyncio.StreamReader.readline, which raises once its 64 KiB
buffer fills without a separator, so a large download would have failed while healthy. This
was unreachable until the import failure above was fixed.
- In-process Optimum output is now split into whole lines through the same emitter the
source subprocess path already used. - Packaged conversions report real progress. Download and quantization percentages now
reach the UI instead of one static "Running packaged OpenVINO conversion…" message for the
entire export. - Standard output stays a pure JSON Lines progress channel in packaged mode, matching
the documented converter protocol.
Frozen helper failures name their origin
A windowed helper cannot show a traceback, and the server surfaces only the tail of its
output, so could not get source code arrived with no exception type and no indication of
which module raised it. Helper failures now report the exception type and the file name and
line they came from, with no bundle path included.
Validation performed for this pre-release
This build was produced with -SkipTests. Lint, the Python test suite, the source mock
API contract validator, and the packaged mock smoke tests were not run as part of the
release build.
The fix was verified against a real packaged build before this release was cut. Driving the
installed application's own HTTP API, with no mock, tinyllama-1.1b-chat-int4 downloaded,
converted to INT4 OpenVINO IR, loaded, and generated a completion. The packaged native and
conversion-import smoke test passes, and the failure was confirmed to reproduce on the
0.9.3-beta.1 binary before the change.
Release provenance, the model library manifest, and SHA-256 checksums are verified
independently of the build.
The two pre-existing red items recorded in 0.9.3-beta.1 are unchanged and
still present: the unsorted import block in tests/test_lifecycle_delete_safety.py, and
tests/test_model_recovery_cleanup.py::test_incomplete_output_rejects_a_dangling_link_before_exists_check,
whose fixture fakes is_symlink() on a path it never creates. Neither is affected by this
release.
Not verified
Authenticode signing (these artifacts are unsigned), real Intel GPU or NPU execution of a
packaged conversion, installer upgrade and downgrade on a real Windows installation, and
conversion of models other than the one exercised above. A signed stable build must advance
the version; see 0.9.0 for the planned stable release record.
InferBridge 0.9.3-beta.1
InferBridge 0.9.3-beta.1
This is a beta pre-release and its artifacts are unsigned. Windows will report an
unknown publisher. Install it only if you accept that. Nothing in this release has been
Authenticode signed, and no signing claim is made anywhere in its metadata.
It is a model lifecycle release. A model conversion that was cancelled, ran out of disk, or
was interrupted by an upgrade could previously leave partially written OpenVINO output in
the live model directory, and that output was then treated as a converted model. This
release makes conversion output transactional, validates it before it is published, and
refuses several unsafe filesystem operations that could have followed a link out of the
model directory.
Converted models are now published transactionally
Optimum writes many files over a long export. Writing them directly into the live model
directory means any interruption mixes partial output with a previously runnable model.
- Exports are staged, then published. Conversion writes into a sibling staging
directory. The result is validated, and only then does it replace the live directory,
through a bounded backup and rollback window. A previously working model survives a
failed or cancelled reconversion. - Publication is hardened for Windows. Replacement retries transient sharing
violations and access denials rather than failing on the first antivirus or Explorer
lock, and clears read-only attributes it encounters. - Packaged conversions run inside the same transaction. The packaged converter path
previously bypassed staging; conversions launched from the installed or portable build
now get the same guarantee as source runs.
Incomplete model directories are no longer treated as models
A partially written export can contain an IR XML file before its weights or configuration
are on disk. That directory previously counted as "downloaded", so retries skipped
conversion and handed an incomplete artifact to the native OpenVINO loader.
- One shared readiness check.
runtime/model_artifacts.pyvalidates that the IR XML is
a complete document, that its paired weights file exists and is non-empty, and that the
model configuration is present and parseable. Catalog, recovery, and load paths all use
it, so they can no longer disagree about whether a model is ready. - The check stays cheap. It probes bounded regions of the IR XML rather than parsing
multi-gigabyte files, so catalog listing is not slowed down. - Recovery classifies staged output correctly. Interrupted staging is now reported as
recoverable output instead of being missed, and recovery cleans it up.
Preparing the same model twice is now blocked across processes
Two InferBridge processes — an installed instance and a portable one, for example — could
previously convert the same model into the same directory at the same time. Model
preparation now takes a cross-process lock on the output directory. The second process
fails fast with a message telling you to wait or close the other instance.
Symbolic links and Windows junctions are refused
Deletion and recovery cleanup previously followed reparse points, so a model directory
that was really a junction could have caused deletion outside model storage. Junctions are
also invisible to is_symlink(), so link detection now reads file attributes directly.
- Model deletion refuses to act through a symbolic link or junction and asks you to remove
the link manually after confirming its target. - Recovery cleanup refuses the same, refuses paths that are not directories, and refuses
staged paths that fall outside the configured model directory.
Device switches no longer interrupt the loaded model
Switching a loaded model to another device previously took the model's lock before
compiling the replacement, so the model was unavailable for the entire compilation.
- The loaded engine stays usable while the replacement compiles. The lock is now taken
only for the short handoff at the end, and it is re-validated in case the engine was
replaced while waiting. - The catalog reports the switch honestly. A loaded model that is switching devices is
shown as loading and cannot be unloaded, instead of appearing idle and unloadable. - Unload is rejected during a switch. Unloading a model that is still loading or
switching devices previously raced the load task; it now returns a clear error. Shutdown
can still force cleanup after its generation drain timeout. - Progress copy is accurate on first load. "The currently loaded model remains
available…" was shown even when nothing was loaded yet. A first load now says "First load
can take several minutes…".
Clearer conversion failures
- Disk exhaustion is named as such, with a note that cached downloads and any
previously working model are preserved where possible. - Windows file locking produces a message about closing other instances, Explorer
windows, and antivirus scans, rather than a rawWinError 32. - A concurrent preparation in another process is reported as exactly that.
- Repeated wrappers are collapsed. Errors no longer read
Conversion failed: RuntimeError: Conversion failed: …. - Converter diagnostics are bounded, so a converter that emits a large volume of output
no longer grows memory without limit.
Continuous integration
A focused Windows Model Lifecycle workflow runs the download, convert, load, and recovery
regressions on windows-latest, because most of the behaviour above is Windows-specific
and was previously only covered on Linux.
Validation performed for this pre-release
This build was produced with -SkipTests. Lint, the Python test suite, the source mock
API contract validator, and the packaged mock smoke tests were not run as part of the
release build. The changes in this release were verified manually on Windows 11 build 26200
before the build was cut.
Release provenance, the model library manifest, and SHA-256 checksums are verified
independently of the build and did pass, so the artifact set is confirmed to be internally
consistent and built from this exact commit.
Continuous integration on this commit is red, with failures that are all in test code
or pre-existing:
tests/test_lifecycle_delete_safety.pyhas an unsorted import block that fails
ruff check.tests/test_model_recovery_cleanup.py::test_incomplete_output_rejects_a_dangling_link_before_exists_check
fails because the test fakesis_symlink()on a path it never creates, so the
lstat()that precedes the check raises and the guard correctly declines to fire. A real
dangling link is still rejected; the fixture, not the shipped guard, is wrong.- Four Chromium browser tests fail. They also failed at the
v0.9.2-beta.1tag, and
nothing underweb/orbrowser_tests/changed in this release.
Not verified
Authenticode signing (these artifacts are unsigned), real Intel CPU, GPU, or NPU execution,
installer upgrade and downgrade on a real Windows installation, and conversion behaviour
against real disk-full and antivirus-lock conditions rather than simulated ones. Those
checks require the documented Windows release and hardware certification procedures. A
signed stable build must advance the version; see 0.9.0 for the planned stable
release record.
InferBridge 0.9.2-beta.1
InferBridge 0.9.2-beta.1
This is a beta pre-release and its artifacts are unsigned. Windows will report an
unknown publisher. Install it only if you accept that. Nothing in this release has been
Authenticode signed, and no signing claim is made anywhere in its metadata.
It fixes two reported installer defects: installing over an existing installation failed,
and uninstalling left files behind while reporting success. Both had the same cause.
Why both failures happened
The tray launcher and the server child it starts are windowed processes with no
top-level window. Restart Manager closes a running application by sending a close
message to its top-level windows, so it had nothing to send to and reported:
RestartManager found an application using one of our files: InferBridge
Some applications could not be shut down.
Nothing else stopped the application, so:
- Upgrade failed. The running processes kept every file under the program directory
open. Setup could not replace them and offered only Retry or Abort. Aborting after Setup
had begun could also leave the previous installation partly removed, because deleted
files are not restored by a rollback. - Uninstall left files behind. The same open handles blocked removal of the program
directory, and the user-data removal discarded its result entirely, so the uninstaller
reported success while the program directory and potentially gigabytes of model data
remained on disk.
Fixes
- Setup and the uninstaller now stop a running instance before touching any file.
PrepareToInstallandInitializeUninstalldetect a live instance through its lock
file, ask it to exit through its own tray command file, and wait up to 15 seconds. - An instance that will not exit is terminated. A release older than this one ignores
the shutdown request and a hung instance cannot honour it. Setup can fall back to a
forced Restart Manager pass, but the uninstaller performs no Restart Manager pass at
all, so both paths end the process directly instead of proceeding with the files still
locked. Termination is reached only while the installed instance still holds its lock,
so an unrelated portable instance is normally untouched. CloseApplications=forceadditionally lets Setup release files held by any other
process, scoped by Restart Manager to processes holding files under the program
directory.- The tray now honours an external quit request. The command-file handler only set the
stop event, which ends the status poller but leaves the tray message loop running, so
the process kept holding its installation files. It now performs the same full shutdown
as the tray menu's Quit: stop the server, stop the icon, exit. - Uninstall removes what it previously left behind. Payload not recorded at install
time — compiled Python caches, and anything left by an interrupted upgrade — is now
removed explicitly, with attribute clearing and bounded retries for read-only files and
transient antivirus locks. The emptied program directory is removed too, which the
uninstaller could not do while it was still removing its own files. - Uninstall reports what it could not remove. Every removal result is now checked, and
any path that survives is named so it can be deleted manually, instead of being silently
discarded while the uninstaller claims success. - Start with Windows is removed on uninstall. The
Runentry survived uninstall, so
Windows kept trying to launch a deleted executable at every logon. Both the current and
legacy value names are removed.
Upgrading from an earlier release
Because releases before this one ignore the shutdown request, the first upgrade onto this
version relies on the force backstop and closes the running application without a clean
server stop. Later upgrades shut down gracefully first.
If an earlier failed upgrade left a partly removed installation, install this release over
it. Setup replaces the program directory contents; models, settings, logs, and benchmark
data live outside it and are preserved.
A model conversion running at the moment of an upgrade is interrupted. Incomplete
conversion output is detected and offered for recovery on the next start; it is never
presented as a valid model.
Validation performed for this pre-release
Ruff lint and formatting, the full Python test suite, and the composed-page JavaScript
syntax check all pass. The external mock API contract validator passes against a
source-run server. Packaged installed-mode and portable-mode mock smoke tests run as part
of the release build. Release provenance and SHA-256 checksums are verified independently
of the build.
The upgrade and uninstall paths were exercised on Windows 11 build 26200 against a real
installation with the application running, reproducing the reported failures first and
confirming they no longer occur:
- Installing over a running earlier release completed with no "unable to automatically
close all applications" prompt, replacing all 6,309 program files. - Uninstalling with the application running reported
Removed all? Yes, left no program
files behind, ended both processes, and removed the Start Menu shortcut and the
uninstall registry entry. The same scenario previously left 54 files, both processes
running, and reported success.
The "remove user data" branch of the uninstall prompt was not exercised interactively; a
silent uninstall takes the documented default of keeping user data.
Not verified
Authenticode signing (these artifacts are unsigned), real Intel CPU, GPU, or NPU
execution, upgrade behaviour from every historical release, and uninstall behaviour with a
model conversion in progress. Those checks require the documented Windows release and
hardware certification procedures. A signed stable build must advance the version; see
0.9.0 for the planned stable release record.
InferBridge 0.9.1-beta.1
InferBridge 0.9.1-beta.1
This is a beta pre-release and its artifacts are unsigned. Windows will report an
unknown publisher. Install it only if you accept that. Nothing in this release has been
Authenticode signed, and no signing claim is made anywhere in its metadata.
It is a maintenance pre-release on top of 0.9.0-beta.1. No new feature
areas were added. The changes are a repaired release and update browser panel, valid
browser-client markup, a packaged windowed-startup fix, Windows model-recovery cleanup
resilience, packaged Optimum CLI discovery validation, completion of the InferBridge
rename on three surfaces the 0.7.0 rename missed, and a corrected release-status section
in the README.
Fixes
- The release and update panel never worked. A missing closing parenthesis in the
injected release script meant the browser refused to parse that entire<script>
element, so the About and update surface silently did nothing: no version or build
detail, no update check, no download link, and no signature statement. The expression is
now balanced and the panel renders. - The packaged launcher aborted its own native validation when started without a
console. The frozen runtime hook gave up silently when it could not duplicate a
standard descriptor, leavingsys.stdoutandsys.stderrasNone. Packaged
third-party code writes to and flushes those streams unconditionally, so the new
packaged Optimum check raisedAttributeErrorand exited with the runtime-failure code.
The hook now falls back to a discard stream, so a windowed process never carries a
Nonestandard stream. - The browser client shipped invalid markup. The custom-model modal was missing one
closing</div>, so every injected script and style element — 38 of them — was nested
inside a hidden,aria-hiddenmodal overlay instead of the document body. Scripts and
styles still executed, but any injected visible markup would have been silently hidden.
The composed page now parses with balanced tags and no duplicate element ids. - Continuous integration syntax-checked a hand-maintained list of ten injected browser
scripts, and the release script was never added to it, which is why the first defect
above shipped. The check now parses every inline script in the fully composed page, so a
newly injected surface is covered automatically. Companion tests assert the composed
page's tag balance, unique element ids, and that injected surfaces attach to the body. - The Windows system tray tooltip still rendered the former product name. It now uses the
canonical display name, matching every other desktop surface and the identity inventory. - The private
/desktop/instancepayload and the model-library definition export both
reported"application": "OpenVINO Windows LLM". Both now report the current product
name. No consumer matches on that field; the launcher's duplicate-instance check uses
the instance nonce. - The external API contract validator titled its generated report with the former product
name. README.mdadvertised0.6.1as the current stable release and0.7.0as an
unpublished development version, which had been wrong sincev0.7.0shipped. It now
records0.8.0as the current stable release, links the current beta artifacts, states
that no published InferBridge artifact is signed, and indexes the release notes.
Hardening carried in this pre-release
These landed after the v0.9.0-beta.1 tag was cut and appear in a published artifact for
the first time here.
Model recovery cleanup on Windows
- Retries transient
rmtreefailures with a bounded backoff, so a Hugging Face cache or an
incomplete OpenVINO output directory briefly held by Windows Search, antivirus, or a
recently exited converter is removed instead of surfacing a raw filesystem error. - Clears the Windows read-only attribute before retrying a failed removal, with fallbacks
for the Windows/Python combinations that do not implementfollow_symlinksforchmod
orstat. - Checks for symbolic links before existence, so a dangling link is refused rather than
silently treated as an absent model directory. - Raises a bounded, actionable conflict that names no local path when cleanup cannot
complete, and preserves the recovery record so the operation stays retryable.
Packaged Optimum CLI discovery
- Bundles the
optimum.commands.registernamespace modules and gates the release build on
the packaged Optimum CLI actually discovering the OpenVINO export command through the
same namespace scan thatoptimum-cli export openvinouses. Bundling the registration
module is not sufficient on its own if PyInstaller leaves it outside that filesystem
scan, and the failure would previously have appeared only on a user's first conversion. - This gate had never run in a packaged build before this release. Its first execution is
what exposed the windowed standard-stream defect fixed above.
Repository hygiene
- Removed a dead private watchdog helper and applied the project's own lint and formatting
rules to the files that had drifted.
Validation performed for this pre-release
Ruff lint and formatting, the full Python test suite, and the composed-page JavaScript
syntax check all pass. The external mock API contract validator passes against a
source-run server in the full profile with embeddings, benchmarks, and lifecycle
exercised. Packaged installed-mode and portable-mode mock smoke tests run as part of the
release build. Release provenance and SHA-256 checksums are verified independently of the
build.
The repaired release panel is verified by parsing, not by a browser interaction test. Its
rendered content on real update metadata has not been exercised end to end.
Not verified
Authenticode signing (these artifacts are unsigned), installer upgrade and downgrade on a
real Windows installation, real Intel CPU, GPU, or NPU execution, tokenizer behavior for
every converted model, and recovery behavior with every Hugging Face cache and checkpoint
layout. Those checks require the documented Windows release and hardware certification
procedures. A signed stable build must advance the version; see 0.9.0 for the
planned stable release record.