LLM 0.1.0
Added
-
A mutation audit over the specification and implementation added 38 authored conformance
scenarios (the suite runs 462); every killable mutant is killed. -
Ordered fallback in
b10x-llm-routing:run_turntries a route's compatible targets in declared
order, bounded by attempts and deadline, and halts on visible output, ambiguous dispatch,
incompatible opaque state, an ineligible failure, cancellation or a caller's limit refusal. -
The Runpod adapter in
b10x-llm-runpod: single-flight startup, ordered GPU fallback, lost-create
adoption by a per-controller request id, readiness and crash-window recovery, ownership-safe
cleanup, proven against an in-process emulator. -
Streamed tool calls carry their announced name (
StreamEvent::ToolCallStarted) in the Chat,
Responses and Messages projections. -
Opaque continuation state ingress cannot attribute is carried as
Item::UnattributedOpaqueand
is never sent until a caller binds it; the envelopes move tollm.turn/3andllm.outcome/4
and older versions are refused by name. -
Neutral inference boundary in
b10x-llm-core: an object-safe asynchronousModel::turnport
taking one request, a caller-owned sink and a cancellation token; bounded text and tool items;
typed failures with independent dispatch evidence; and opaque continuation state bound to its
exact protocol, provider, account, endpoint, model and binding revision. -
Injected credential resolution in
b10x-llm-credentials: an opaqueSecretRef, request-time
resolution, zeroized and redacted material with no serialization, and a coordinated resolver that
refreshes only the credential generation actually rejected. -
Bounded single-attempt transport in
b10x-llm-http: HTTP and SSE with explicit deadlines, no
redirects, no automatic retries, and partial output preserved across failure. -
Provider bindings in
b10x-llm-providers: independent protocol, provider, authentication and
billing choices, including anonymous arbitrary endpoints. -
TOML catalog routing in
b10x-llm-routing: strictllm.catalog/1parsing, deterministic
configuration identity, ordered opt-in selection, capability and input-token admission, and a
safe explanation that resolves no secret and performs no request. -
Attributed usage pricing in
b10x-llm-cost: versionedllm.prices/1books, exact decimal
arithmetic overllm.usage/2observations,llm.cost/2reports with six separate accounting
bases, and unknown quantities preserved as unknown rather than zero. -
Optional local secret adapters behind the
file,keychainandnative-keychainfeatures:
explicitly mapped protected files on Linux and an explicitly injected or native credential store. -
Optional durable spending admission behind
b10x-llm-cost'ssqlitefeature: an immutable
single-ownerBudgetPolicy, reservations committed before dispatch, serialized concurrent
callers, cross-process owner exclusion, uncertain charges retained across restart, and compute
stop obligations. -
The Responses, Messages and Chat Completions protocol projections in
b10x-llm-responses,
b10x-llm-messagesandb10x-llm-chat, each for its declared supported subset: independent
authentication, billing and protocol choices survive translation; unsupported fields and
provider-specific opaque continuation state are preserved or refused rather than dropped; and
each adapter normalizes its wire's usage counts before producing neutral values, reporting a
partial quantity only where it is a valid lower bound. -
An authenticated single-owner gateway in
b10x-llm-gateway: nothing is decoded past the HTTP
head before an owner verifier accepts, apart from a closed liveness and readiness surface; the
route inventory is an immutable snapshot with no field for an endpoint URL, secret reference or
credential material; and start, drain and stop are deliberate. It performs no protocol
translation, proxies no model call, resolves no secret and reaches no network. -
The hosting lifecycle contract in
b10x-llm-provision, with an in-processFakeProviderthat
demonstrates it: resource identity qualified by the provider'sincarnationso a recycled name
cannot be adopted as the same resource, requested state kept strictly separate from observed
state, and a stop obligation that nothing but evidence discharges. It opens no socket, reads no
credential and allocates no cloud resource. -
Executable ESS verification for the
accounting,budget,chat,hosting,inference,
messages,responses,routingandsecretsdomains — every domain exceptcatalog, which
declares rather than observes — with recorded falsification evidence underdocs/verification/.
Two naming notes: the suite directorycontracts/pricing/exercises theaccountingdomain and
there is nopricingdomain; andgateway-authhas a falsification record but no ESS suite. -
Public documentation surface: a
b10x-docs/v4manifest, a Docusaurus documentation tree under
website/, this changelog, a proprietary licence notice, the shared Gates caller workflow and a
b10x-change/v1feed entry.
Changed
- The specification is at ESS source format
ess/13and the conformance runner uses ESS 0.35.0;
emitted payload fields the adapters observe are declaredgenerated. - The planning store is
aep.project/3on a tree Git merges, planned with AEP 0.60.0; CI installs
AEP 0.60.0. - The workspace version is 0.1.0.
- Pin every action revision in
.github/workflows/gate.ymlto an exact commit and name the
version beside it. Common Gates refuses a workflow whose action revisions are not exact commits
or Docker digests, so the repository's own gate had to be pinned before the shared caller could
be enabled. No step, trigger, permission or toolchain version changed:1.98.0moved from the
dtolnay/rust-toolchainref to itstoolchain:input, which is how the action takes it once
the ref is a commit.
Fixed
- Keep transport deadline and dispatch evidence deterministic.
- Release the spending ledger's owner lock after connection close.
- Compile the spending ledger's directory synchronization only on Unix.
- Preserve bound inference observations and partial usage costs.
Not yet implemented
The operator command line (llm-cli), the Modal hosting adapter (llm-modal) and protocol
translation in the gateway are not written yet. OpenAI and Anthropic access is unqualified: no live provider credential has been used
anywhere in this repository, so every guarantee above is held against fixtures, local sockets and
in-process fakes. No crate is published to a registry.