Local model and UAIX work stay on the device.
- Publishes Phase 3.684 current-package evidence: Desktop 0.2.242.0 was installed with the expected identity, launched as a packaged process, and passed the exact beginner-first Settings dogfood matrix.
- Publishes beginner-first Settings evidence: Simple mode exposes Appearance, Plugins, Local actions, Startup, Remote access, and Shared memory while Advanced mode reveals General, Downloads, Account email, Runtime, Command gate, Feature flags, search, and diagnostics.
- Publishes least-surprise local-action evidence: AI desktop control remains visible in Simple mode, while command execution and trusted-machine auto approval remain discoverable only after the owner selects Advanced.
- Publishes optional-plugin evidence: the Plugins surface shows exactly two stable rows, RemoteEndpoints.com and MemoryEndpoints.com, with user summaries, install states, and advanced technical disclosures; unknown accepted plugin manifests do not grow the user tab bar.
- Publishes responsive shell evidence: Simple/Advanced mode, security status, and Settings remain visible without overlap at a 700 by 700 viewport.
- Carries independent Phase 3.684 verification: 1,749 unit tests, 47 security tests, and 68 integration tests passed; one integration scaffold was intentionally skipped. Eight focused beginner-first Settings static tests passed.
- Carries Phase 3.683 protected remote local-approval dogfood as historical exact 0.2.241.0 evidence; it was not rerun or re-claimed for the 0.2.242.0 UI package.
- Binds every protected remote action to the authenticated session, instruction SHA-256, current local manual or auto-approval policy, and execution-time target-app revalidation; no public page can self-approve.
- Claims no generated or scored Dogfood Suite rows for 0.2.242.0 and keeps the full package-specific 1000/1000 result gate open at prompt 0001.
- Binds cumulative Dogfood Suite evidence to the exact Connect app version as well as the prompt contract. Missing or mismatched versions restart at prompt 0001 and cannot contribute historical rows.
- Carries protected typed remote actions for window listing, approved HTTPS URLs, bounded waits, allowlisted application launch, window focus, text entry, hotkeys, pointer movement, and pointer clicks. Whole sequences are preflighted before step one, limited to 20 actions and 60 cumulative wait seconds, and expose no direct shell API.
- Carries Phase 3.683 interactive-input dogfood as historical blocked evidence because the controlled fixture could not obtain a foreground target; keyboard, hotkey, pointer move, and pointer click execution are not claimed for 0.2.242.0.
- Keeps prior package Dogfood Suite rows as historical evidence only. Desktop 0.2.242.0 starts package-specific scoring at prompt 0001 and carries forward zero completed rows.
- Publishes Phase 3.570 chat thinking/follow-up evidence: Desktop 0.2.181.0 keeps Enter, Disabled/Ready/Thinking state, follow-up allowed/disabled copy, detailed action status, and one-run approval visible in the installed Chat action stack.
- Publishes Phase 3.570 UI responsiveness evidence: Chat yields to the UI after setting Thinking so the installed app visibly changes state before local model or worker work continues.
- Publishes Phase 3.568 chat-first evidence: Desktop 0.2.179.0 opens with a visible response window, message box, Enter button, memory setup gate, approval checkbox, disabled-state explanation, and Thinking status after Enter.
- Publishes Phase 3.568 dogfood prompt timeout evidence: the in-app Dogfood Suite keeps 1000 rerunnable AI prompts and writes a provider/runtime failure report instead of hanging when a full-model scoring prompt exceeds the 60-second per-prompt timeout.
- Publishes Phase 3.568 chat-gate evidence: the installed app generated the 1000-prompt bundle, prepared local chat gates, counted 1000 prompts, and kept full-model execution disabled until runtime and worker approvals are present.
- Carries Phase 3.665 endpoint-plugin evidence: RemoteEndpoints.com and MemoryEndpoints.com are current selectable optional plugins, each requires a separate accepted install manifest, and plugin install does not grant runtime authority by itself.
- Carries Phase 3.682 MemoryEndpoints client evidence as historical exact 0.2.239.0 proof: the plugin-owned Settings tab uses an ephemeral password input and current-user Windows Credential Manager. A real production workspace key and hosted submit/search success are not claimed for 0.2.242.0.
- Publishes Phase 3.547 installed simple-mode evidence: Desktop 0.2.159.0 starts on Dashboard with collapsed navigation, Simple home status, Phase 3.547 visible, Advanced off, and no legacy small-model picker copy.
- Publishes Phase 3.547 local-model home evidence: the installed app exposes local/browser privacy framing, Choose a local model, model status pills, and starter actions without legacy small-model extension picker copy.
- Publishes Phase 3.547 Advanced/Simple toggle evidence: installed UI Automation toggled Advanced on to reveal Advanced Options, then toggled back to simple home.
- Publishes Phase 3.547 update-aware installer evidence: the checksum-backed standard .exe setup detects newer payloads as updates while preserving Install, Update, Repair, Fresh install, and Uninstall choices before setup runs.
- Publishes Phase 3.547 quiet setup dogfood evidence: quiet install/update with launch passed for 0.2.159.0.
- Carries launch update-check behavior: installed app writes display-safe approved LocalEndpoints.com release metadata evidence on launch without auto-downloading or auto-installing.
- Publishes Phase 3.543 single-EXE package evidence: Desktop 0.2.155.0 is now served as a checksum-backed standard .exe setup artifact that embeds the local-test signed MSIX payload, extracts successfully, quiet-installs successfully, preserves the public no-runtime boundary, and keeps production distribution signing unclaimed.
- Publishes Phase 3.542 package evidence: Desktop 0.2.155.0 is a local-test signed tester ZIP with RemoteEndpoints protected dispatch UX, Pending Actions Queue, plain dashboard states, trusted-machine auto approval emergency stop, package validation, Release build, MSIX publish, local test signing, MSIX worker payload validation, UAIX.LmRuntime package-feed validation, independent ZIP safety validation, tester ZIP discovery, and exact installed-app RemoteEndpoints dogfood evidence passed.
- Carries Phase 3.542 source hardening: RemoteEndpoints.com protected control is authenticated, locally enabled, Connect-approved, policy-bound desktop control; local-only desktop features do not require a website account, RemoteEndpoints.com login, device login, cloud connection, or network access.
- Carries Phase 3.542 validation: package builder passed; strict tester discovery passed; independent ZIP safety validation passed; independent MSIX worker payload validation passed; UAIX.LmRuntime package-feed validation passed; full .NET tests passed; full Python/static validation passed; formatter verification passed; install/launch, RemoteEndpoints protocol, RemoteEndpoints live session, and AI desktop-control trusted-auto-approval UI smokes passed.
- Publishes Phase 3.542 exact installed-app evidence: Desktop 0.2.155.0 passed install/launch, RemoteEndpoints protocol handoff, live RemoteEndpoints authenticated session dogfood, and AI desktop-control Settings smoke with trusted-machine auto approval emergency-stop checks while keeping command dispatch closed and native GPU execution unclaimed.
- Publishes Phase 3.539 package evidence: Desktop 0.2.154.0 is a local-test signed tester ZIP with Start Here beginner actions, advanced expert options, package validation, Release build, MSIX publish, local test signing, MSIX worker payload validation, UAIX.LmRuntime package-feed validation, independent ZIP safety validation, tester ZIP discovery, ZIP CRC validation, publish pickup ZIP read-through, and exact installed-app smoke evidence passed.
- Carries Phase 3.539 source hardening: Start Here leads with See a Safe Preview, Set Up Local Workspace, and Open Local Models while diagnostics stay discoverable behind Advanced options for experts.
- Carries Phase 3.539 validation: package builder passed; strict tester discovery passed; independent ZIP safety validation passed; independent MSIX worker payload validation passed; ZIP CRC test passed; UAIX.LmRuntime package-feed validation passed; exact install/launch, operator shell with Start Here checks, Models source-discovery UI, AI desktop-control, and GGUF CPU-managed smokes passed.
- Publishes Phase 3.539 exact installed-app smoke evidence: Desktop 0.2.154.0 passed install/launch, operator shell and Start Here UI automation, Models source-discovery UI, AI desktop-control, and GGUF CPU-managed local runtime smokes while keeping command dispatch closed and native GPU execution unclaimed.
- Publishes Phase 3.537 package evidence: Desktop 0.2.152.0 is a local-test signed tester ZIP with LocalModelRegistryActivationReadinessProjection, LocalModelRegistryUninstallReadinessProjection, registry lifecycle readiness delegated from ModelsViewModel to Core, package validation, Release build, MSIX publish, local test signing, MSIX worker payload validation, UAIX.LmRuntime package-feed validation, independent ZIP safety validation, tester ZIP discovery, ZIP CRC validation, publish pickup ZIP read-through, and exact installed-app smoke evidence passed.
- Carries Phase 3.537 source hardening: LocalModelRegistryActivationReadinessProjection and LocalModelRegistryUninstallReadinessProjection own selected registry entry activation/uninstall readiness while activation readiness preserves LocalModelRegistryEntryTrustEvidence.ForActivationSelection.
- Carries Phase 3.537 validation: package builder passed; strict tester discovery passed; independent ZIP safety validation passed; independent MSIX worker payload validation passed; ZIP CRC test passed; UAIX.LmRuntime package-feed validation passed; exact install/launch, operator shell, Models source-discovery UI, AI desktop-control, and GGUF CPU-managed smokes passed; and the desktop coverage gate remained above 93 percent.
- Publishes Phase 3.537 exact installed-app smoke evidence: Desktop 0.2.152.0 passed install/launch, operator shell, Models source-discovery UI, AI desktop-control, and GGUF CPU-managed local runtime smokes while keeping command dispatch closed and native GPU execution unclaimed.
- Publishes Phase 3.519 package evidence: Desktop 0.2.151.0 is a local-test signed tester ZIP with LocalModelUaixMemoryRunReadiness, Models page UAIX memory readiness status, nine-gate Hub run readiness, package validation, Release build, MSIX publish, local test signing, MSIX worker payload validation, UAIX.LmRuntime package-feed validation, independent ZIP safety validation, tester ZIP discovery, ZIP CRC validation, publish pickup ZIP read-through, exact installed-app smoke evidence, and desktop coverage gate validation passed.
- Carries Phase 3.519 source hardening: LocalModelUaixMemoryRunReadiness owns loaded .uaix, .uai/persona.uai, and Documents-backed wiki root readiness for Models page Hub runs.
- Carries Phase 3.519 validation: package builder passed; strict tester discovery passed; independent ZIP safety validation passed; independent MSIX worker payload validation passed; ZIP CRC test passed; UAIX.LmRuntime package-feed validation passed; exact install/launch, operator shell, Models source-discovery UI, AI desktop-control, and GGUF CPU-managed smokes passed; and the desktop coverage gate remained above 93 percent.
- Publishes Phase 3.519 exact installed-app smoke evidence: Desktop 0.2.151.0 passed install/launch, operator shell, Models source-discovery UI, AI desktop-control, and GGUF CPU-managed local runtime smokes while keeping command dispatch closed and native GPU execution unclaimed.
- Publishes Phase 3.518 package evidence: Desktop 0.2.150.0 is a local-test signed tester ZIP with local-control surface state value objects, package validation, Release build, MSIX publish, local test signing, MSIX worker payload validation, UAIX.LmRuntime package-feed validation, independent ZIP safety validation, tester ZIP discovery, ZIP CRC validation, publish pickup ZIP read-through, exact installed-app smoke evidence, and desktop coverage gate validation passed.
- Carries Phase 3.518 source hardening: local-control capability state is centralized so AI desktop-control and command execution capability surfaces share one display-safe status contract while command dispatch remains closed until owner approval, a named .uaix load session, a selected wiki memory root, and app-local audit evidence exist.
- Carries Phase 3.518 validation: package builder passed; strict tester discovery passed; independent ZIP safety validation passed; independent MSIX worker payload validation passed; ZIP CRC test passed; UAIX.LmRuntime package-feed validation passed; exact install/launch, operator shell, Models source-discovery UI, AI desktop-control, and GGUF CPU-managed smokes passed; and the desktop coverage gate remained above 93 percent.
- Publishes Phase 3.518 exact installed-app smoke evidence: Desktop 0.2.150.0 passed install/launch, operator shell, Models source-discovery UI, AI desktop-control, and GGUF CPU-managed local runtime smokes while keeping command dispatch closed and native GPU execution unclaimed.
- Publishes Phase 3.517 package evidence: Desktop 0.2.149.0 is a local-test signed tester ZIP with LocalModelFirstRunGuide .uaix, persona.uai, and Documents-backed wiki root readiness rows, locked LocalModelHubRunLifecycleSummary status, package validation, Release build, MSIX publish, local test signing, MSIX worker payload validation, UAIX.LmRuntime package-feed validation, independent ZIP safety validation, tester ZIP discovery, ZIP CRC validation, publish pickup ZIP read-through, and desktop coverage gate validation passed.
- Carries Phase 3.517 source hardening: LocalModelFirstRunGuide names Required For .uaix Package, Required For persona.uai, and Required For Documents Wiki Root before model choice, download, activation, runtime, worker, and privacy gates.
- Carries Phase 3.517 validation: focused first-run guide tests passed with 22 tests; full C# unit project passed with 1314 tests; full Python/static checks passed with 249 passed and 2 skipped; formatter verification passed; Release build passed with 0 warnings and 0 errors; package builder, strict tester discovery, independent ZIP safety validation, independent MSIX worker payload validation, ZIP CRC test, UAIX.LmRuntime package-feed validation, exact installed-app smokes, and 93.21 percent desktop coverage gate passed.
- Publishes Phase 3.517 exact installed-app smoke evidence: Desktop 0.2.149.0 passed install/launch, operator shell, Models source-discovery UI, AI desktop-control, and GGUF CPU-managed local runtime smokes while keeping command dispatch closed and native GPU execution unclaimed.
- Publishes Phase 3.516 package evidence: Desktop 0.2.148.0 is a local-test signed tester ZIP with LocalModelHubCatalogCandidateSelectionSummary, saved catalog selection summaries, Models UI ready/blocked action evidence, package validation, Release build, MSIX publish, local test signing, MSIX worker payload validation, UAIX.LmRuntime package-feed validation, independent ZIP safety validation, tester ZIP discovery, and ZIP CRC validation passed.
- Carries Phase 3.516 source hardening: LocalModelHubCatalogCandidateSelectionSummary centralizes display-safe Hugging Face GGUF selection decisions for raw Hub candidates and saved catalog entries, including Required For Safe Local Model Selection, ready/blocked state, status text, primary action label, evidence text, and display-safe findings.
- Carries Phase 3.516 validation: focused Hub catalog tests passed with 5 tests; full C# unit project passed with 1314 tests; focused Hugging Face static tests passed with 2 tests; full Python/static checks passed with 249 passed and 2 skipped; formatter verification passed; Debug app build passed with 0 warnings and 0 errors; package builder, strict tester discovery, independent ZIP safety validation, independent MSIX worker payload validation, ZIP CRC test, UAIX.LmRuntime package-feed validation, and exact installed-app smokes passed.
- Publishes Phase 3.516 exact installed-app smoke evidence: Desktop 0.2.148.0 passed install/launch, operator shell, Models source-discovery UI, AI desktop-control, and GGUF CPU-managed local runtime smokes while keeping command dispatch closed and native GPU execution unclaimed.
- Publishes Phase 3.515 package evidence: Desktop 0.2.147.0 is a local-test signed tester ZIP with package validation, Release build, MSIX publish, local test signing, MSIX worker payload validation, UAIX.LmRuntime package-feed validation, independent ZIP safety validation, tester ZIP discovery, and exact installed-app smoke passed for the Models Checklist Evidence Smoke Fix package.
- Carries Phase 3.515 source hardening: LocalModelFirstRunGuide.ChecklistEvidenceText, ModelsViewModel.HubRunReadinessChecklistEvidenceText, LocalEndpoint.Models.FirstRunGuide.ChecklistEvidence, and LocalEndpoint.Models.HubRun.ReadinessChecklistEvidence give smoke automation stable display-safe evidence for readiness checklist content.
- Carries Phase 3.515 validation: focused installed-app Models UI smoke automation discovery and deployment static tests passed with 50 tests; focused LocalModelFirstRunGuide tests passed with 22 tests; formatter verification passed; package build validation passed; strict tester discovery passed; independent ZIP safety validation passed; and exact installed-app install/launch, Models UI, operator shell, AI desktop-control, and GGUF CPU-managed smokes passed.
- Publishes Phase 3.514 package evidence: Desktop 0.2.146.0 is a local-test signed tester ZIP with package validation, Release build, MSIX publish, local test signing, MSIX worker payload validation, UAIX.LmRuntime package-feed validation, independent ZIP safety validation, and tester ZIP discovery passed for the First Local Chat Action Card package.
- Carries Phase 3.514 source hardening: LocalModelHubRunReadinessCard projects one first-chat next action from LocalModelHubRunReadinessSummary; Models UI binds it through ModelsViewModel.HubRunReadinessCard and exposes LocalEndpoint.Models.HubRun.ReadinessCard automation IDs.
- Carries Phase 3.514 validation: focused LocalModelFirstRunGuide tests passed with 22 tests; focused Hugging Face/static package tests passed with 6 tests; full C# unit tests passed with 1313 tests; full Python/static checks passed with 249 passed and 2 skipped; formatter verification passed; and the WinUI app Debug build passed with 0 warnings and 0 errors.
- Carries Phase 3.514 UX research intake: first-time users need one visible next action, SHA-256-backed tester download instructions, and plain-language local-only boundaries before detailed engineering ledgers.
- Publishes Phase 3.512 package evidence: Desktop 0.2.145.0 is a local-test signed tester ZIP with full package validation, formatter verification, Release build, MSIX publish, local test signing, worker payload validation, UAIX.LmRuntime package-feed validation, independent ZIP safety validation, and tester ZIP discovery passed for the First Local Chat Readiness Progress package.
- Carries Phase 3.512 source hardening: LocalModelHubRunReadinessSummary now exposes ReadyChecklistItemCount, TotalChecklistItemCount, and ProgressText from the same display-safe readiness checklist rows; Models UI binds ProgressText through LocalEndpoint.Models.HubRun.ReadinessProgress so first-time users can see how many required gates are ready before row-level review.
- Carries Phase 3.512 validation: focused LocalModelFirstRunGuide tests passed with 20 tests; focused installed-app Models UI smoke automation discovery and deployment static tests passed with 6 tests; WinUI app Debug build passed with 0 warnings and 0 errors; full C# unit tests passed with 1311 tests; full Python/static checks passed with 249 passed and 2 skipped; formatter verification passed; and the 93% desktop owned-source coverage gate passed at 93.17%.
- Carries Phase 3.511 source hardening: ModelsViewModel now constructs RunHubWorkflowCommand with CanRunHubWorkflow, refreshes command availability whenever Hub run readiness changes, and keeps RunHubWorkflowAsync fail-closed by returning LocalModelHubRunReadinessSummary.DisplayText when readiness is blocked.
- Carries Phase 3.511 validation: focused command-binding static test passed; focused LocalModelFirstRunGuide tests passed with 20 tests; WinUI app Debug build passed with 0 warnings and 0 errors; full C# unit tests passed with 1311 tests; full Python/static checks passed with 249 passed and 2 skipped; formatter verification passed; and the 93% desktop owned-source coverage gate passed at 93.17%.
- Carries Phase 3.510 source hardening: LocalModelHubRunReadinessSummary now includes display-safe LocalModelHubRunReadinessChecklistItem rows for prompt text, local model identity, download gate, activation gate, runtime gate, and worker gate; Models UI binds those rows through LocalEndpoint.Models.HubRun.ReadinessChecklist.
- Carries Phase 3.510 safety hardening: Hub run readiness now requires ModelIdentityReady before Ready can be true, so checked approvals without a visible local-ready catalog entry, catalog candidate, or active verified local model remain blocked.
- Carries Phase 3.510 validation: focused LocalModelFirstRunGuide tests passed with 20 tests; focused installed-app Models UI smoke automation discovery and deployment static tests passed with 5 tests; WinUI app Debug build passed with 0 warnings and 0 errors; full C# unit tests passed with 1311 tests; full Python/static checks passed with 248 passed and 2 skipped; formatter verification passed; and the 93% desktop owned-source coverage gate passed at 93.17%.
- Carries Phase 3.509 source hardening: installed-app Models UI smoke automation now requires LocalEndpoint.Models.FirstRunGuide.ChecklistTitle, LocalEndpoint.Models.FirstRunGuide.Checklist, and LocalEndpoint.Models.HubRun.ReadinessStatus in the live automation report before Find-LocalEndpointInstalledAppModelsSourceDiscoveryUiSmokeAutomation.ps1 can accept the report as strict passed evidence.
- Carries Phase 3.509 validation: focused installed-app Models UI smoke automation discovery and deployment static tests passed with 5 tests; full Python/static checks passed with 248 passed and 2 skipped; focused LocalModelFirstRunGuide tests passed with 18 tests; formatter verification passed; and the 93% desktop owned-source coverage gate passed at 93.15%.
- Carries Phase 3.508 source hardening: LocalModelFirstRunGuide now projects a Required For First Local Chat checklist through LocalModelFirstRunChecklistItem so Models UI can show prompt text, local-ready GGUF selection or active verified model reuse, systems-without-GPUs compatibility, systems-with-GPUs compatibility, download approval, activation approval, runtime approval, worker approval, and prompt/response privacy boundaries without wall-text guidance.
- Carries Phase 3.508 validation: focused LocalModelFirstRunGuide tests passed; full C# unit tests passed with 1309 tests; WinUI app Debug build passed with 0 warnings and 0 errors; full Python/static checks passed with 248 passed and 2 skipped; touched formatter verification passed; and the 93% desktop owned-source coverage gate passed at 93.15%.
- Carries Phase 3.507 source hardening: CommandExecutionCapabilityPreferenceEvidence now validates active scoped command gate receipts during settings normalization and resets stale or mismatched gate receipts back to scope-required state before command dispatch evidence can be reused.
- Carries Phase 3.507 validation: focused command execution capability, local desktop-control policy, JSON settings store, command gate binding, and settings persistence tests passed; full C# unit tests, full Python/static checks, formatter verification, diff whitespace checks, and the 93% desktop owned-source coverage gate passed at 93.14%.
- Carries Phase 3.506 source hardening: LocalModelHubRunWorkflowPhaseStateDefinition now names NotStarted, Passed, Blocked, and Skipped as the only accepted Hub run progress states while LocalModelHubRunProgressRecorder validates state text before evidence emission and LocalModelHubRunWorkflowService consumes named state definitions instead of raw state strings.
- Carries Phase 3.506 validation: first-run guide tests cover stable phase-state order, unique state values, PassedWhen gate mapping, FromValue lookup, and unknown-state rejection; focused tests, full C# unit tests, full Python/static checks, touched formatter verification, diff whitespace checks, and the 93% desktop owned-source coverage gate passed at 93.13%.
- Carries Phase 3.505 source hardening: LocalModelHubRunWorkflowPhaseDefinition now names prompt gate, Hub browse, catalog save, registry reuse, download approval, download intake, registry entry resolution, activation approval, verified activation, provider start, worker stream, and terminal phase identities while LocalModelHubRunProgressRecorder consumes those definitions for UI, CLI, service, and smoke evidence without carrying prompt or generated text content.
- Carries Phase 3.505 validation: first-run guide tests cover phase definition order, unique phase keys, non-empty labels, and the named recorder overload; focused tests, full C# unit tests, full Python/static checks, touched formatter verification, diff whitespace checks, and the 93% desktop owned-source coverage gate passed at 93.13%.
- Carries Phase 3.504 source hardening: LocalModelHubRunLifecycleSummary and LocalModelHubRunTerminalSummary now project browse, download, activation, run, outcome, token count, terminal kind, and progress phase status through named domain contracts for UI, CLI, and smoke evidence without carrying prompt or generated text content.
- Carries Phase 3.504 validation: Local model first-run guide tests cover lifecycle default state, active-model progress state, completed terminal status, blocked terminal status, generated-text display availability, and display-safe evidence boundaries while the desktop owned-source coverage gate remains above 93%.
- Carries Phase 3.501 historical installed-app evidence: exact package 0.2.144.0 passed install/launch smoke, operator shell smoke, Models source-discovery UI automation smoke, GGUF CPU-managed smoke, and AI desktop-control smoke with command dispatch still closed.
- Carries Phase 3.501 source hardening: Hub run workflow phase states now route through named release constants with regression coverage so evidence state strings cannot drift across Hub run progress and first-run guide surfaces.
- Publishes Phase 3.500 package evidence: Desktop 0.2.143.0 is a local-test signed tester ZIP with full .NET/static validation, formatter verification, Release build, MSIX publish, local test signing, worker payload validation, UAIX.LmRuntime package-feed validation, independent ZIP safety validation, and exact installed-app smoke evidence passed for install/launch, operator shell, Models UI, GGUF CPU-managed runtime, and AI desktop-control.
- Carries Phase 3.500 installed-app evidence: exact package 0.2.143.0 passed install/launch smoke, operator shell smoke, Models source-discovery UI automation smoke, GGUF CPU-managed smoke, and AI desktop-control smoke with command dispatch still closed.
- Carries Phase 3.500 source hardening: onboarding wizard shell status, UTC timestamps, state-panel transitions, navigation status updates, and operator-state Required For strings now route through named helpers/value-object methods with regression coverage.
- Carries Phase 3.498 operator shell and Hub run readiness as historical context: the package preserved operator-first navigation while keeping Hugging Face browse, download, activate, .uaix load, runtime readiness, and local GGUF run states visible for invited tester smoke.
- Carries Phase 3.496 Start screen local model path polish: Browse Local Models routes first-time users to Local Capabilities while preserving local-only Hugging Face metadata and verified download boundaries.
- Carries Phase 3.495 operator workspace CTA polish: the ready workspace uses Review Proposed Action and Open Approval Queue, state previews live under operator state coverage, and Developer Mode still reveals advanced diagnostics without granting new permissions.
- Carries Phase 3.492 operator-control-center semantic polish: Standard Mode uses human-clear local-security labels, NoOp review action copy is Acknowledge & Discard, and Developer Mode still reveals advanced diagnostics without granting new permissions.
- Publishes Phase 3.490 package evidence: Desktop 0.2.135.0 is a local-test signed tester ZIP with full .NET/static validation, formatter verification, Release build, MSIX publish, local test signing, worker payload validation, UAIX.LmRuntime package-feed validation, independent ZIP safety validation, and exact installed-app smoke evidence passed.
- Carries Phase 3.490 installed-app evidence: exact package 0.2.135.0 passed install/launch smoke, operator-first shell smoke, Models source-discovery UI automation smoke, GGUF CPU-managed smoke, and AI desktop-control smoke with command dispatch still closed.
- Carries Phase 3.490 operator-first shell hardening: Standard Mode shows Start, Approvals, Agent Status, Local Capabilities, Memory, Audit Log, and Settings while Developer Mode reveals Chat Control, Action Queue, and GGUF Smoke routes without granting new permissions.
- Carries the Phase 3.490 desktop UI redesign brief into public accounting: LocalEndpoint Connect is being shaped as an operator-first local AI control center where humans approve, audit, and govern local AI desktop actions before anything touches the machine.
- Carries Phase 3.489 Models UI automation accessibility hardening as historical context: lifecycle and Hub run automation IDs are exposed through visible text controls so UI Automation can verify browse, download, activate, and run-local affordances in the installed app.
- Publishes Phase 3.481 package evidence: Desktop 0.2.130.0 is a local-test signed tester ZIP for the Hugging Face chat-run CLI path, with full .NET tests, Python/static validation, formatter verification, Release build, MSIX publish, local test signing, MSIX worker payload validation, UAIX.LmRuntime package-feed validation, and ZIP archive validation passed.
- Carries Phase 3.481 installed-app evidence: exact package 0.2.130.0 passed install/launch smoke, GGUF UI smoke, AI desktop-control settings smoke, and Models source-discovery UI smoke.
- Carries Phase 3.482 source/dev evidence: Desktop browsed Hugging Face Hub for `tinyllamas`, filtered local-download-ready GGUF candidates, downloaded `Agnuxo/tiny-llama-Spanish_English_raspberry_pi_GGUF_16bit` / `unsloth.F16.gguf`, verified SHA-256 `2d7bed89e72ee66f683f7f2aa7b7f355e7a2f9d1cecd7acc5b3b8c0c243a1057`, activated the content-addressed model, loaded `HelpfulAssistant.uaix`, and completed a local `models chat run` through UAIX.LmRuntime.
- Hugging Face Hub support is local catalog metadata plus owner-approved local GGUF download; hosted Inference Endpoints, Spaces, Gradio APIs, provider APIs, prompt upload, token-authenticated hosted execution, billing-facing endpoint lifecycle, and public website model execution remain outside the LocalEndpoint.com public boundary.
- Runs as a custom LocalEndpoint Desktop app for local downloaded models; it does not rely on hosted provider APIs or paid third-party inference services.
- Loads portable .uaix agent packages and expands their .uai memory files inside the local desktop boundary.
- Lets separate desktop app instances load different .uaix packages so distinct agents can keep distinct local state and model choices.
- persona.uai is Required For All LocalEndpoint Desktop Packages.
- Shows package file roles as Required For {agent type or workflow} so agent memory does not rely on weak wording.
- Keeps per-load long-term wiki memory roots portable, shareable, and Documents-backed by default.
- Carries Phase 3.376 K80 driver proof-readiness accounting: bounded CUDA driver memory-operation proof passed on Tesla K80 at cuda:0 while worker launch, model session allocation, prompt tokenization, inference, and GGUF GPU inference claims remain blocked.
- Carries Phase 3.373 shared provider-marker boundary accounting: folder sidecar writing, package-folder inspection, hard-blocked file checks, direct intake scan classification, and sidecar JSON inspection share LocalModelSidecarEvidence provider/API marker detection.
- Carries Phase 3.367 native package-lane adoption checklist accounting: modern CUDA and Tesla K80 lanes expose expected native binary, proof receipt, and generation execution artifact file names while worker launch, model session allocation, prompt tokenization, and inference remain blocked.
- Carries Phase 3.372 catalog download handoff sidecar policy: downloaded license and inventory sidecars are parsed as raw JSON and checked for hidden command execution, provider/API/runtime declarations, blocked source types, local-use proof, accepted format, revision, and hardware fit before intake processing can promote the artifact.
- Carries Phase 3.366 reviewed-manifest artifact file-name binding: native generation execution artifact file names are reviewed against the already-reviewed package manifest identity, not receipt-declared identity.
- Carries Phase 3.361 native generation action-plan UI accounting: the Runtime page projects native package-lane counts, Tesla K80 lane state, denied runtime authority flags, and per-lane evidence while keeping package-lane evidence display-only.
- Carries Phase 3.364 package-feed verifier accounting: native generation proof artifacts must use the package-bound file name `<packageId>.<packageVersion>.native-generation-execution-artifact.json` before proof receipt adoption can advance.
- Carries Phase 3.351 Tesla K80 evidence-runner accounting: the desktop source has a repeatable script that captures nvidia-smi, proves bounded K80 CUDA driver memory-operation evidence on this workstation, and keeps GGUF GPU generation pending without making GPU hardware required for other systems.
- Carries Phase 3.358 installed-app smoke accounting: elevated sideload install and packaged launch smoke, Models source-discovery UI smoke, and GGUF smoke automation pass against the installed 0.2.98.0 app after loading the required UAIX profile.
- Carries Phase 3.349 deployment accounting: the public desktop ZIP is versioned as 0.2.96.0 and validates direct Add-AppxPackage install/launch smoke without reusing the prior package version.
- Carries Phase 3.346 source accounting: folder-stage package receipt evidence binds source folder display name, intake package relative path, staged file evidence SHA-256, and stage package evidence SHA-256 before runtime execution can advance.
- Current source consumes UAIX.LmRuntime.LocalEndpoint 3.3.29 from the local UAIX NuGet feed for the bounded managed GGUF worker path.
- Current source consumes UAIX.LmRuntime.Backends.Cuda 3.3.29 for LocalEndpoint-owned CUDA probe diagnostics without claiming GGUF GPU inference.
- The public NuGet package family is verified at 3.3.29 for the tracked runtime package set; LocalEndpoint.com records that package status while keeping runtime authority, package parsing, prompt assembly, policy, registry, audit, provider calls, telemetry, and model execution outside the public website.
- Validates local model license sidecars, inventory sidecars, SHA-256 values, byte counts, accepted formats, and hardware fit before intake.
- Stores reviewed model snapshots as immutable content-addressed local artifacts and records AlreadyStored evidence for unchanged snapshots.
- Requires converted GGUF or ONNX outputs to re-enter model intake as new immutable snapshots with sidecars, hashes, revision evidence, and hardware-fit evidence.
- Carries the selected chat model entry as RequestedModelEntryId and blocks stale selected models before worker session allocation, token streaming, or inference.
- Blocks sidecar drift, duplicate content conflicts, unsafe safetensors conversion paths, legacy external GGUF CLI launches, provider APIs, hosted inference, model upload, telemetry, shell execution, and command execution.
- Uses UAIX.LmRuntime as a bounded managed local GGUF worker adapter after LocalEndpoint has assembled and approved the request context.
- Preserves session and turn identity across worker start, stream, token, and terminal evidence so local JSONL events remain traceable.
- Computes a display-safe RequestHandoffSha256 provider request fingerprint at turn start and blocks start-to-stream request drift before worker handoff.
- Creates LocalChatViabilityEvidence before worker envelope creation and records a blocked no-op when runtime readiness, model selection, offload, local API binding, memory authority, UAIX authority flags, or public-site boundary state do not fit the local worker envelope.
- Carries Phase 3.338 public-safe tester package accounting: local API provider activation requires ReadyForWorker gate state, runtime execution approval, streaming support, explicit approval, and Disabled, NamedPipe, or Loopback127001 binding evidence before worker-backed local API streaming can be exposed.
- Carries Phase 3.300 public-safe tester package accounting: the package evidence proves UAIX.LmRuntime 3.3.26 local-feed resolution, 13 managed worker runtime payload entries, 0 legacy runtime artifacts, LocalChatViabilityEvidence, K80 diagnostic target-match evidence, runtime selector identity binding, tester package discovery evidence, actual GPU and K80 smoke proof surfaces, K80 GGUF generation preflight evidence, CPU/no-GPU compatible non-blocking proof rows, native package entry safety, duplicate-entry blocking, symlink-entry blocking, unexpected executable payload blocking, and closed provider/API/network/telemetry/command/runtime-by-default flags.
- Keeps Converted Output Evidence Automation IDs and stable Models UI automation IDs in the public accounting so installed-app smoke reruns can inspect evidence readouts, not only buttons.
- Carries Phase 3.225 source accounting: current source consumes UAIX.LmRuntime.LocalEndpoint 3.3.26 and UAIX.LmRuntime.Backends.Cuda 3.3.26, surfaces LocalEndpoint-owned CUDA probe diagnostics, and keeps actual K80 GGUF inference unclaimed.
- Carries Phase 3.227 source accounting: Runtime, Settings, and Chat expose local owner backend/device selector intent while readiness, provider request fingerprints, and worker session projections preserve selector identity without claiming GPU inference.
- Carries Phase 3.232 source accounting: the `models runtime inventory` CLI reports CPU managed runtime as selectable and CUDA Tesla K80 as visible diagnostic-only inventory until native GGUF inference assets and runtime proof are loaded.
- Carries Phase 3.243 source accounting: CUDA native and Tesla K80 legacy native asset package lanes are visible in runtime inventory, CLI output, and Runtime page UI with GenerationAssetsAccepted=false until reviewed native generation binaries, package-bound generation execution evidence, and terminal token proof all agree.
- Carries Phase 3.243 source accounting: package-bound generation execution evidence is Required For native lane acceptance; raw execution SHA-256 strings are diagnostic-only and cannot satisfy GPU generation readiness.
- Carries Phase 3.249 source accounting: native generation proof receipts bind package identity, package SHA-256, native binary identity, runtime library identity, and generation execution proof.
- Carries Phase 3.250 source accounting: `models runtime inventory` and the Runtime page expose proof receipt presence, proof receipt SHA-256, and proof receipt identity acceptance.
- Carries Phase 3.251 source accounting: GPU generation readiness requires at least one native package lane with accepted proof receipt identity before any GPU handoff can proceed.
- Carries Phase 3.259 source accounting: release evidence validation and tester handoff packets preserve tester ZIP discovery plus UAIX.LmRuntime package-feed facts, and deployment package evidence fails when release evidence hashes, local-feed restore, required runtime package counts, native package facts, native generation asset facts, or proof receipt facts are missing or weak.
- Carries Phase 3.261 source accounting: active GGUF model identity evidence is Required For Active GGUF Model Smoke Evidence, and malformed active model identity blocks public-safe smoke readiness before any GPU claim can be made.
- Carries Phase 3.263 source accounting: native generation proof receipts must name a display-safe same-feed JSON artifact file whose SHA-256 matches the receipt before proof evidence can advance.
- Carries Phase 3.264 source accounting: native generation artifact evidence is accepted only when artifact schema, package identity, native binary identity, runtime library identity, and generation execution identity match the proof receipt.
- Carries Phase 3.265 source accounting: LocalEndpoint-owned native generation artifacts are rejected when they contain non-identity fields such as prompt text, generated text, or command lines.
- Carries Phase 3.266 source accounting: the package-feed verifier rejects native generation artifact JSON that is not limited to the identity contract before proof receipt evidence can pass.
- Carries Phase 3.267 source accounting: native generation artifact identity-only review is a core-domain value object and duplicate identity fields block before artifact payload materialization.
- Carries Phase 3.268 source accounting: the package-feed verifier reads raw proof artifact JSON property names so duplicate identity fields block release proof evidence before payload identity values are read.
- Carries Phase 3.281 source accounting: native backend selection requires accepted package-lane readiness, not raw generation asset acceptance alone.
- Carries Phase 3.291 source accounting: native package feed evidence rejects unsafe entry names, duplicate entries, symlink entries, and unexpected executable payloads before manifest evidence can advance.
- Carries Phase 3.293 source accounting: local model source-root discovery reports structured skipped linked-folder and unreadable-folder counts without copying files, processing artifacts, or enabling runtime execution.
- Carries Phase 3.294 source accounting: K80 diagnostic target requirement and target match are visible while ActualGpuExecutionEvidencePresent=false and GGUF GPU inference remains unclaimed.
- Carries Phase 3.295 source accounting: K80 GGUF worker generation proof requires terminal token output, completed token agreement, and runtime adapter GPU device evidence before any K80 execution claim.
- Carries Phase 3.296 source accounting: local model intake blocks associated GGUF enumeration drift after scan with VerificationBlocked evidence, no content-addressed storage write, no intake cleanup, and RuntimeExecutionAllowed=false.
- Carries Phase 3.297 source accounting: actual GPU execution claims require reviewed runtime adapter backend and device IDs to match the selected offload plan backend and device IDs.
- Carries Phase 3.302 source accounting: runtime selector normalization creates display-safe local audit evidence when unsupported offload values or malformed backend/device selectors are corrected before persistence.
- Carries Phase 3.303 source accounting: `models runtime k80-proof-readiness --approve --integration-enabled` proves bounded Tesla K80 CUDA driver memory-operation evidence while blocking GGUF worker launch, model session allocation, prompt tokenization, inference, and GPU inference claims until native package-lane and terminal/runtime device-use evidence pass.
- Carries Phase 3.304 source accounting: local model intake review-folder evidence reports PackageFileCount and PackageFileName rows from the package file set, excluding unselected sibling model artifacts before package-folder staging.
- Carries Phase 3.306 source accounting: GGUF worker package readiness requires supported and matching worker contract identity, verified engine package availability, manifest evidence receipt identity, engine manifest identity, executable identity, file inventory identity, positive package file count, and closed shell/network/provider API/telemetry/command-execution flags before smoke readiness can pass.
- Carries Phase 3.307 source accounting: reliable desktop deployment package ZIP creation uses System.IO.Compression.ZipArchive with safe entry validation, duplicate-entry blocking, source-root containment, and Windows PowerShell 5.1 compatible string checks.
- Carries Phase 3.301 source accounting: persisted runtime backend/device settings normalize before load/save, malformed selectors are cleared before persistence, display-safe CPU settings round-trip for UI use, and CPU-only worker handoff remains selector-cleared before execution.
- Carries Phase 3.312 source accounting: UAIX.LmRuntime 3.3.28 generation results carry managed CPU device-use evidence, and CUDA/K80 generation claims remain blocked until selected device identity, generation device identity, reviewed native binaries, proof receipts, ordered token observations, completed-token comparison, and actual GPU device-use evidence agree.
- Carries Phase 3.313 source accounting: K80 proof-readiness CLI evidence can be exported as display-safe JSON for deployment smoke gates without exposing local worker paths or weakening GGUF worker launch, model allocation, prompt tokenization, inference, or GPU claim gates.
- Carries Phase 3.315 source accounting: K80 proof-readiness JSON and text output include named requirement records with display-safe evidence state, evidence count, and evidence identity fields for CUDA driver proof, GGUF preflight, GPU handoff, native package lane readiness, Tesla K80 package lane readiness, terminal token evidence, completed-token result, ordered token observations, completed-token comparison, actual GPU runtime device-use evidence, and GPU/no-GPU compatibility.
- Carries Phase 3.316 source accounting: `models runtime readiness --approve` grants runtime readiness only for the current local command evaluation, exposes the active model and worker capability evidence, preserves closed website/network/telemetry/unverified-model flags, supports named-pipe or loopback local API binding only after explicit approval, and leaves stored registry runtime authority false.
- Carries Phase 3.318 source accounting: `models runtime k80-proof-readiness --approve --integration-enabled --export <evidence-json>` writes checksum-backed display-safe K80 readiness evidence, rejects invalid export paths before probing CUDA, omits local worker and fixture paths from the JSON evidence, and keeps actual K80 GGUF inference unclaimed.
- Carries Phase 3.324 source accounting: K80 proof-readiness rows now surface display-safe package-lane identity and reviewed generation binary candidate text when proof receipt identity is absent, so marker-only native package blockers are visible in Runtime UI, CLI text, and CLI JSON evidence.
- Carries Phase 3.330 source accounting: local model folder review, source discovery, and staging share one app-local target-package availability boundary, so occupied package names block before copy and RuntimeExecutionAllowed remains false.
- Carries Phase 3.332 source accounting: native CUDA and LegacyK80 contracts require packageVersion plus version-bound proof receipt filenames before native generation evidence can advance, while reviewed native generation binaries remain blocked.
- Carries Phase 3.328 source accounting: Runtime UI applies CPU and GPU selector candidates from local inventory as display-safe edit suggestions only; applying a selector candidate does not save settings, approve runtime readiness, launch workers, allocate model sessions, tokenize prompts, or claim GPU inference.
- Keeps prompt text and generated text out of registry, audit, and public evidence artifacts.