v2.6.1
[2.6.1] — 2026-04-17
Phase 2C close-out release. This point release rolls up the post-v2.6.0 foundation hardening work, publishes the fresh corpus refresh baseline, and documents the semantic / driver caveats that were previously implicit.
Added
- Fresh corpus refresh baseline (
docs/carry_over_benchmark_v2.6.md,benchmark-results/2c6-fresh-full-final/aggregate.json,scripts/aggregate_corpus_metrics.py). The 1,123-target refresh is now published as a best-view aggregate across the fresh rerun waves. Final outcome: 1110 success / 4 partial / 9 fatal; successful runs areextraction=ok 1110/1110,inventory=sufficient 1110/1110,nonzero findings 1110/1110,nonzero CVE 1089/1110. - LLM driver degradation matrix (
docs/llm_driver_degradation_matrix.md). Documents the actual contract differences between Codex CLI, Claude API, Claude Code CLI, and Ollama, especially around system-prompt delivery and temperature handling. - Confidence semantic break note (
docs/confidence_semantic_break_v2.6.md). Makes the v2.5.x → v2.6+ shift explicit:confidenceis now evidence-only;priority_score/priority_inputscarry ranking semantics.
Changed
- README / README.ko baseline messaging. Tier 1 hero numbers now point at the fresh v2.6.1 corpus refresh, while Tier 2 remains explicitly carry-over until the pair-eval lane lands. The over-broad "False negative rate ≈ 0%" phrasing is replaced with a pending pair-eval note.
- Analyst copilot wording. Public docs now split the surface into
Explainability surface,Analyst-in-the-loop channel, andAutonomous reasoning (future)instead of presenting all LLM-related behavior as one undifferentiated capability. - Release governance helper (
scripts/release.sh). The helper is upgraded from a README-only version bumper into a release close-out utility that can synchronize pyproject, README badges, and CHANGELOG headers in dry-run/apply modes.
Fixed
- Synthesis finding reasoning trail inheritance (
findings.py). Top-level synthesis findings such asaiedge.findings.web.exec_sink_overlapnow inherit matched downstream evidence lineage instead of relying only on the stage-level aggregate summary. Matching prefers run-relative binary path, falls back to binary SHA-256, emits afindings/synthesis_matchsummary entry, and appends a deterministic top-K sample of representative downstream trail entries. - SBOM stage silent schema mismatch (
sbom.py). Vendor-stock firmware no longer silently returns 0 components because of staleinventory.file_list/string_hitsassumptions. The stage now walksinventory.rootsdirectly and falls back to direct binary reads via_extract_ascii_runs. - Relative
runs_roothandling increate_run()(run.py).runs_rootis resolved before path derivation so relative output roots still wire absolute firmware paths into extraction; regression coverage lives intests/test_create_run_relative_runs_root.py.
Verification
python3 -m py_compile scripts/aggregate_corpus_metrics.pypython3 scripts/check_doc_consistency.py- fresh corpus aggregate regenerated from
benchmark-results/2c6-fresh-full-v2*waves - representative firmware smoke coverage retained from 2C.1–2C.5 (R7000 lineage / SBOM pilot / verified-chain provenance)