Files
buzz/deny.toml
240cdd3ea1 chore: mesh upgrade, clean up legacy special case code, simplify model selection for mesh (#5289)
Shared compute now has exactly two model choices: MeshLLM's virtual
`mesh`
model, or a model you name. Buzz picks between them in one place, and
buzz-agent no longer knows meshes exist.

## What changed

- **MeshLLM v0.74.0 → v0.75.1.** v0.75.0 added
`degrade_to_single_model`, so a
  `model=mesh` request is answered by one served model when there is no
committee to form, instead of failing. v0.75.1 adds Mesh-LLM#1196, which
skips stale pre-0.75 runtime cache entries rather than aborting startup
on
them — without it, anyone who had run mesh on 0.73/0.74 could not start.
- **Deleted the client-side mesh catalog probe.** buzz-agent used to
poll
`/v1/models` (5s TTL, 30s cooldown, two-observation debounce) to decide
whether `mesh` was safe to send. MeshLLM now decides per request, so the
  polling, its hysteresis, and its 503 fallback are gone.
- **One mapping point.** `relay_mesh_wire_model()` turns the stored
value into
a wire name: `auto` becomes `mesh`, a named model passes through. The
spawn
env, the ACP harness, and the readiness probe all use it, so they cannot
disagree — previously `BUZZ_ACP_MODEL` and the probe both said `auto`, a
name
  the mesh does not advertise.
- **Removed the `nostr-relay-pool` advisory exception.** #5404 allowed
RUSTSEC-2026-0243 "after mesh-llm migrates to nostr-sdk >= 0.45".
v0.75.1
does, so the retired crate is gone from both lockfiles and the exception
  would only mask a future advisory for it.
- **Deleted `scripts/ensure-mesh-native-runtime.sh`** and its six
justfile call
sites. It built llama.cpp from source into the runtime cache; the app
already
  downloads the signed release runtime itself, and CI never called it.

## Why it is better

**−639 lines of Rust.** Availability is decided by the node that knows
the
answer, per request, instead of by a client cache that could be stale
for up to
30 seconds. A second worker joining now takes effect on the next request
rather
than after two confirming probes.

## Behaviour change

A 503 on an explicit `mesh` request takes the ordinary transport retry
under
the same model instead of failing over to a second one — there is no
second
model to fail over to now. MoA repairs partial committee results
internally
before it reaches that point.

## Validation

`crates/buzz-relay/examples/mesh_agent_e2e.rs` now sends `mesh` where it
previously sent `auto` or the physical model id, so no leg was covering
what
Buzz actually puts on the wire. 4/4 on gemma-4-E4B, gemma-4-26B-A4B, and
Qwen3-8B — including a real ACP tool call through `mesh` into
buzz-dev-mcp,
asserted by reading the written file back off disk.

Hand-tested in the desktop app on both gemma-4 sizes: picked Auto, agent
logged
`model_id=mesh`, replied in channel.

## Not covered

A committee that forms and then loses a worker returns 502, and that
needs two
workers to reproduce — not testable on one machine.

---------

Signed-off-by: Michael Neale <michael.neale@gmail.com>
Co-authored-by: Michael Neale <michael.neale@gmail.com>
2026-08-11 11:40:07 -04:00

93 lines
3.2 KiB
TOML

[advisories]
ignore = [
# instant 0.1.13 — unmaintained crate. Transitive dep: nostr → instant.
# Will be resolved when nostr crate updates its dependencies.
{ id = "RUSTSEC-2024-0384", reason = "transitive dep via nostr; no upstream fix available" },
# paste 1.0.15 — unmaintained. Transitive dep: mesh-llm → iroh → netlink-* → paste.
# No safe upgrade available; tracked for upstream (iroh/netlink) replacement.
{ id = "RUSTSEC-2024-0436", reason = "transitive dep via mesh-llm → iroh → netlink; no upstream fix available" },
# quick-xml < 0.41: quadratic runtime on duplicate-attribute check (0194) and
# unbounded namespace-declaration allocation in NsReader (0195). Both DoS-class,
# requiring attacker-controlled XML. Our two locked versions only parse trusted
# input: 0.38.4 (rust-s3/aws-creds — responses from our own S3/MinIO endpoint)
# and 0.39.4 (mesh-llm → iroh → netdev → plist — local macOS system plists).
# Patched release (>= 0.41.0) is unreachable until rust-s3 and plist/netdev bump;
# remove these when upstream catches up.
{ id = "RUSTSEC-2026-0194", reason = "transitive via rust-s3 and mesh-llm→plist; trusted-input XML only; no upstream fix available yet" },
{ id = "RUSTSEC-2026-0195", reason = "transitive via rust-s3 and mesh-llm→plist; trusted-input XML only; no upstream fix available yet" },
]
[licenses]
allow = [
"MIT",
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"BSD-2-Clause",
"BSD-3-Clause",
"ISC",
"Unicode-3.0",
"Unicode-DFS-2016",
"Zlib",
"OpenSSL",
"CC0-1.0",
"CDLA-Permissive-2.0",
"MITNFA",
"MPL-2.0",
"BSL-1.0",
"Unlicense",
# minicbor's permissive, OSI-approved license. Used for strict App Attest
# assertion CBOR parsing and also transitively by appattest.
"BlueOak-1.0.0",
# bzip2/libbzip2's permissive BSD-like license. New via desktop zip/bzip2
# transitive deps; compatible with Apache-2.0 distribution.
"bzip2-1.0.6",
]
confidence-threshold = 0.8
# mesh-llm workspace crates (pinned git dep) omit a per-crate `license` field in
# their manifests, so cargo-deny reports them as unlicensed. The mesh-llm repo is
# licensed "MIT OR Apache-2.0" (workspace Cargo.toml + top-level LICENSE = Apache-2.0);
# clarify each pulled-in member to that expression. Remove once mesh sets the field
# upstream (filed).
[[licenses.clarify]]
crate = "mesh-llm-config"
expression = "MIT OR Apache-2.0"
license-files = []
[[licenses.clarify]]
crate = "mesh-llm-gpu-bench"
expression = "MIT OR Apache-2.0"
license-files = []
[[licenses.clarify]]
crate = "mesh-llm-host-runtime"
expression = "MIT OR Apache-2.0"
license-files = []
[[licenses.clarify]]
crate = "mesh-llm-plugin"
expression = "MIT OR Apache-2.0"
license-files = []
[[licenses.clarify]]
crate = "mesh-llm-system"
expression = "MIT OR Apache-2.0"
license-files = []
[[licenses.clarify]]
crate = "mesh-mixture-of-agents"
expression = "MIT OR Apache-2.0"
license-files = []
[[licenses.clarify]]
crate = "buzz-desktop"
expression = "Apache-2.0"
license-files = []
[licenses.private]
ignore = true
[bans]
multiple-versions = "warn"
wildcards = "allow"