Skip to content

Add kind: "llm" and publish first-party llm packages - #232

Merged
HereLiesAz merged 1 commit into
mainfrom
claude/amazing-fermi-3o92qn-llm
Sep 27, 2026
Merged

HereLiesAz merged 1 commit into
mainfrom
claude/amazing-fermi-3o92qn-llm

Conversation

@HereLiesAz

Copy link
Copy Markdown
Owner

Implements spec/llm.md (still Proposed) and puts llm packages on the store.

What changed

  • SDK (packages/sdk/src/llm.ts, public.ts): LlmManifest types; Kind now includes "llm"; Manifest gains an llm block.
  • Verifier (packages/azp/src/llm.ts): validateLlmManifest covers every rule in § Verification, and verifyAzp calls it for kind:"llm". role and workflow packages now refuse an llm block. submit-check accepts the kind. Tests are in llm.test.ts.
  • Store:
    • Cards show the tier (HOSTED or PRIVATE SANDBOX).
    • The detail page gets a "Before you install" box: where prompts go, data handling (operator, terms, whether the model is pinned), the model licence, download size, runner requirements, and the setup token's permissions.
    • export-catalog and the Worker type now carry the llm block.
  • Packages: 12 of them under registry/local/com.hereliesaz.azphalt.llm.*, generated from one table by pnpm --filter @azphalt/storefront gen-llm-packages.
    • Endpoint tier:
      • Kilo, LLM7 and OVHcloud: keyless, with an optional key.
      • OpenRouter free, Groq, Cerebras, Z.ai and Mistral: key required.
      • dataHandling says may-train only where that is documented (Kilo, OpenRouter free, Mistral free tier). The rest say unknown.
    • Sandbox-weights tier: Qwen2.5 1.5B, Qwen2.5 Coder 1.5B, SmolLM2 1.7B and Phi-3.5 Mini, as Q4_K_M GGUF on llama.cpp b11218, every fetch pinned by sha256.
    • Shared runner files:
      • setup/setup.sh downloads each file and checks its sha256, failing closed. It re-checks a restored cache too.
      • setup/run.py implements the runner protocol: check-run progress, the azphalt-llm-result artifact, and rolling-delimiter translation with HMAC tags. It rejects output that contains a tag.
      • setup/workflow.yml pins its actions to SHAs. Its permissions are contents: read, checks: write, identical to run.permissions.
  • build-catalog: --only now accepts a folder package's id (it used to demand a lockfile entry).
  • Spec: status line updated. Documented the sandbox layout (llm/<id>/), the task JSON, and how sessionKey and base32 are encoded. The docs/specs mirror is synced.

Verification

  • azp 128/128, submit-check 12/12, storefront-worker 32/32 and storefront 5/5 tests pass. Typecheck is clean on all touched packages.
  • verifyAzp passes on all 12 built .azp files.
  • Ran the runner for real in this container:
    • Kilo (keyless) with a tagged untrusted segment carrying an injected <|im_start|>: completed.
    • LLM7 setup op: completed.
    • SmolLM2 through llama.cpp: downloaded and checksum-verified, then answered "Paris".
  • build-catalog --check: the 12 llm entries match. It still reports 3 remote packages as stale (hello-lut, cool-noir, teal-orange); they were already stale on main, and this PR doesn't touch them.

Not in this PR

  • The Compose store app (storefront-cmp) does not show the llm disclosure yet.
  • No host installs these yet (provisioning the sandbox repo, dispatching the runner).
  • No "llm" registry profile or conformance profile yet.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv


Generated by Claude Code

SDK types, verifier (spec/llm.md § Verification) with tests, store
disclosure of tier, data handling, model licence and setup token
permissions, and twelve generated packages: eight free hosted endpoints
and four open-weight models on pinned llama.cpp in a private Actions
sandbox. build-catalog --only now accepts folder packages.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv
@vercel

vercel Bot commented Sep 27, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
azphalt Error Error Sep 27, 2026 4:48pm UTC

Copy link
Copy Markdown
Owner Author

Vercel azphalt deployment error is not this PR's: the Next.js storefront was retired and production is the Cloudflare Worker, so the leftover Vercel project fails on every push. Fix is user-side — delete or disconnect the Vercel project. No code change here.


Generated by Claude Code

@cloudflare-workers-and-pages

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Failed ❌

View logs ↗
5b51e82 2026-09-27T16:48:27.628Z View logs ↗

@HereLiesAz

Copy link
Copy Markdown
Owner Author

OpenCode security review

⚠️ Review unavailable. Neither model answered; see the shared workflow run. This is not a finding about the pull request.

Copy link
Copy Markdown
Owner Author

Both red validate_node checks are trackers reporting validate_node: cancelled. The central run they both point to was cancelled by the concurrency group when duplicate dispatches arrived (the same thing happened on #231). No test ran, so this isn't a code failure. Two tracker Start jobs are still running, and the real node validation should come in through them. Locally, azp (128/128), submit-check (12/12), storefront-worker (32/32) and storefront (5/5) all pass, and typecheck is clean.

Workers Builds: azphalt finished in 0 s, so it failed before any build ran. That points to the Cloudflare dashboard build settings, not this diff. github-advanced-security is the Copilot check, which fails on every PR until Copilot is disabled.

I'll re-check once the remaining runs report.


Generated by Claude Code

Copy link
Copy Markdown
Owner Author

CodeQL analyze (java-kotlin) is failing in the shared workflow, not in this PR's code. android-actions/setup-android@v3 tries to install the SDK tools package, sdkmanager can't find it any more, and the job stops before analysis starts. The workflow lives in HereLiesAz/workflows, so it can't be ported into this PR. The fix is HereLiesAz/workflows#86, and after it merges this check will pass on its next run.

The OpenCode security review reported "unavailable" because GEMINI_API_KEY isn't set in the workflows azphalt environment yet. That's a missing secret, not a finding about this PR.


Generated by Claude Code

Copy link
Copy Markdown
Owner Author

Update on validate_node: both of its runs ended with the shared run cancelled, so Node validation never ran on this head. Other runs didn't pick it up either. I tried to re-run the failed jobs and got 403 Resource not accessible by integration, so the re-run has to come from the repo UI: Re-run failed jobs on https://github.com/HereLiesAz/azphalt/actions/runs/36334565300. I'm keeping this PR watched.


Generated by Claude Code

@HereLiesAz
HereLiesAz marked this pull request as ready for review September 27, 2026 18:02

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @HereLiesAz, your pull request is larger than the review limit of 150,000 diff characters

@HereLiesAz
HereLiesAz merged commit 42583f4 into main Sep 27, 2026
22 of 29 checks passed
@HereLiesAz
HereLiesAz deleted the claude/amazing-fermi-3o92qn-llm branch September 27, 2026 18:03

This branch had an error being deployed

1 failed deployment
Preview — 5b51e82b Deployed Sep 27, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants