Bugfix 1.5.7
release-tag / release-image (push) Successful in 6m16s

This commit is contained in:
2026-08-27 12:50:24 +02:00
parent f7f3460f6c
commit 5899989228
11 changed files with 332 additions and 18 deletions
+5
View File
@@ -46,3 +46,8 @@ Für einen realen Research→Staging-Smoke-Test zusätzlich verifizieren:
2. Staging-Synthese und Claim-Verifikation bleiben bei nicht reparierbarem JSON fail-closed.
3. Der resultierende Draft enthält weiterhin `human_review_required=true` und `auto_reply=false`.
4. Source-Authority und Claim-Verifikation aus v1.5.5 bleiben bestanden; JSON-Robustheit darf diese Gates nicht umgehen.
## v1.5.7 Identifier-Grounding Zusatzgate
Bei Windows-/Vendor-Artikeln dürfen normale Slash-Komposita oder URL-Pfade kein `source-unverified identifiers` auslösen. Echte CLI-Switches in Code-Spans/Fences bleiben source-verifiziert. Vor Go-Live mindestens einen Goal-Lauf mit `BIOS-/UEFI`-ähnlicher Prosa und einen Lauf mit einem belegten Slash-Command prüfen.
+15
View File
@@ -0,0 +1,15 @@
# Migration v1.5.6 → v1.5.7
v1.5.7 is a drop-in identifier-grounding fix. No storage migration is required and no new environment variable is mandatory. Existing goals, memories, synapses, research history and staging drafts remain intact.
1. Build/publish the v1.5.7 images through the normal Gitea pipeline.
2. Set `IMAGE_TAG=1.5.7`.
3. Pull and recreate NeuroForge and its worker:
```bash
docker compose --profile research pull neuroforge neuroforge-worker
docker compose --profile research up -d --force-recreate neuroforge neuroforge-worker
```
4. Do not delete volumes.
5. Let the previously blocked goals run again. Their existing evidence can be reused.
+17
View File
@@ -0,0 +1,17 @@
# GLPI NeuroForge Mega v1.5.7
v1.5.7 fixes a production-grounding false positive observed during live BitLocker, DISM and FortiClient goal revalidation. The v1.5.6 critical-identifier scanner treated every slash-prefixed word as a possible CLI switch, so normal German compounds and URL-path fragments such as `BIOS-/UEFI`, `/portal-konfiguration` or `/interaktionsbereiche` could block an otherwise grounded staging draft.
## Identifier-grounding hardening
- Slash-prefixed identifiers are no longer extracted globally from prose.
- CLI-style slash switches are extracted only from Markdown code spans/fences, where the author/model explicitly marks the content as code.
- URL paths, filesystem-like fragments and hyphen/slash compounds are not treated as command switches.
- Real code-marked switches remain fail-closed: an invented option such as `DISM /MagicRepair` is rejected unless it occurs in the evidence bundle.
- Sourced switches such as `/Online`, `/Cleanup-Image` and `/RestoreHealth` continue to pass.
- Existing global checks for error codes, CVEs, KB identifiers and version numbers remain unchanged.
- The v1.5.5 source-authority/claim-verification gates and the v1.5.6 strict structured-JSON path remain fully active.
## Regression coverage
Tests reproduce `BIOS-/UEFI`, `Web-/Portal-Konfiguration`, URL-path text, an invented code-marked `/MagicRepair` switch and a sourced `/RestoreHealth` command. Test, vet, build and race gates are required before packaging.