Skip to content

chore(deps): Update dependency anthropic to >=0.104.1 - #6

Merged
lusoris merged 1 commit into
masterfrom
renovate/anthropic-0.x
May 28, 2026
Merged

lusoris merged 1 commit into
masterfrom
renovate/anthropic-0.x

Conversation

@renovate

@renovate renovate Bot commented May 28, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
anthropic >=0.103.1 → >=0.104.1 age confidence

Release Notes

anthropics/anthropic-sdk-python (anthropic)

v0.104.1

Compare Source

Full Changelog: v0.104.0...v0.104.1

Bug Fixes
  • streaming: carry encrypted_content through beta compaction accumulator (#​1821) (f7a720c)

v0.104.0

Compare Source

Full Changelog: v0.104.0...v0.104.1

Bug Fixes
  • streaming: carry encrypted_content through beta compaction accumulator (#​1821) (f7a720c)

Configuration

📅 Schedule: (in timezone Europe/Vienna)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from lusoris as a code owner May 28, 2026 10:53
@lusoris
lusoris merged commit f11014b into master May 28, 2026
26 of 57 checks passed
@lusoris
lusoris deleted the renovate/anthropic-0.x branch May 28, 2026 12:03
lusoris added a commit that referenced this pull request May 31, 2026
The vmafx-operator was the last of 25 Go binaries on the fork still
using the kubebuilder-template-default zap logger. All other binaries
(vmafx-server, vmafx-controller, vmafx-tune, MCP server, …) already
log via the standard library's log/slog package. This change retires
the holdout so the fork has a single, uniform logging stack across
its entire Go surface.

main.go now installs a slog.NewJSONHandler against os.Stderr and
bridges it into controller-runtime via logr.FromSlogHandler. The
envtest suite_test.go uses slog.NewTextHandler against GinkgoWriter
for the same reason.

go.uber.org/zap is removed from direct dependencies (it remains
present as an indirect transitive dep of sigs.k8s.io/controller-runtime
internals; that is upstream's choice and unaffected). go-logr/zapr
and go.uber.org/multierr are dropped from go.mod entirely.
github.com/go-logr/logr is promoted to a direct dependency.

ADR-0108 deliverables:
- Research digest: no digest needed — mechanical 1-importer refactor.
- Decision matrix: no alternatives — only-one-way fix (replace with
  the slog handler all other binaries already use).
- AGENTS.md invariant: cmd/vmafx-operator/AGENTS.md gains rule #6
  documenting the slog bridge for future kubebuilder re-syncs.
- Reproducer: KUBEBUILDER_ASSETS=\$(setup-envtest use 1.31 -p path) \\
  go test ./cmd/vmafx-operator/...
- CHANGELOG fragment: changelog.d/changed/zap-to-slog-uniform.md.
- Rebase note: docs/rebase-notes.md head entry covers re-applying
  the slog bridge after a kubebuilder template re-scaffold.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request May 31, 2026
The vmafx-operator was the last of 25 Go binaries on the fork still
using the kubebuilder-template-default zap logger. All other binaries
(vmafx-server, vmafx-controller, vmafx-tune, MCP server, …) already
log via the standard library's log/slog package. This change retires
the holdout so the fork has a single, uniform logging stack across
its entire Go surface.

main.go now installs a slog.NewJSONHandler against os.Stderr and
bridges it into controller-runtime via logr.FromSlogHandler. The
envtest suite_test.go uses slog.NewTextHandler against GinkgoWriter
for the same reason.

go.uber.org/zap is removed from direct dependencies (it remains
present as an indirect transitive dep of sigs.k8s.io/controller-runtime
internals; that is upstream's choice and unaffected). go-logr/zapr
and go.uber.org/multierr are dropped from go.mod entirely.
github.com/go-logr/logr is promoted to a direct dependency.

ADR-0108 deliverables:
- Research digest: no digest needed — mechanical 1-importer refactor.
- Decision matrix: no alternatives — only-one-way fix (replace with
  the slog handler all other binaries already use).
- AGENTS.md invariant: cmd/vmafx-operator/AGENTS.md gains rule #6
  documenting the slog bridge for future kubebuilder re-syncs.
- Reproducer: KUBEBUILDER_ASSETS=\$(setup-envtest use 1.31 -p path) \\
  go test ./cmd/vmafx-operator/...
- CHANGELOG fragment: changelog.d/changed/zap-to-slog-uniform.md.
- Rebase note: docs/rebase-notes.md head entry covers re-applying
  the slog bridge after a kubebuilder template re-scaffold.

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 2, 2026
…uite

The cmd/vmafx-operator/internal/controller envtest suite was hard-failing
in BeforeSuite with a nil-pointer deref from controlplane.(*APIServer).Stop
because the kubebuilder envtest control-plane binaries (etcd +
kube-apiserver + kubectl) were not on PATH. PRs #330, #341, and #362 all
called this out as a pre-existing failure they could not address inline.

Three-pronged fix:

1. Makefile gains a `setup-envtest` target that installs
   `sigs.k8s.io/controller-runtime/tools/setup-envtest@latest` and
   downloads the v1.31 control-plane bundle. A companion
   `setup-envtest-env` target prints the eval-friendly export line so
   developers can do `eval $(make -s setup-envtest-env)`.

2. .github/workflows/go-ci.yml installs setup-envtest and exports
   `KUBEBUILDER_ASSETS` via `$GITHUB_ENV` before `go test ./...`, so the
   operator suite runs for real in CI instead of skipping.

3. cmd/vmafx-operator/internal/controller/suite_test.go gains a
   top-of-`TestControllers` `t.Skip()` guard when `KUBEBUILDER_ASSETS`
   is unset, plus a nil-`testEnv` bailout in `AfterSuite` so the suite
   never panics on a fresh checkout where the assets are missing
   (defense in depth).

Local verification:
- `unset KUBEBUILDER_ASSETS && go test ./cmd/vmafx-operator/...` -> SKIP
  with an actionable message pointing at `make setup-envtest`.
- `eval $(make -s setup-envtest-env) && go test -v ./cmd/vmafx-operator/...`
  -> 3/3 specs pass in ~5 s.

AGENTS.md gains a new invariant #6 documenting the skip-safe envtest
pattern; rebase-notes.md, state.md, and a changelog fragment under
changelog.d/fixed/ are updated per ADR-0108 + CLAUDE.md r10/r13.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 2, 2026
…test + #446 SYCL parity round 3) (#528)

* chore(ci): audit per-file coverage overrides — tighten tiny_extractor_template.h 10 → 75

Periodic audit of `scripts/ci/coverage-check.sh`'s `PER_FILE_MIN` map
(ADR-0114). Three findings:

1. `core/src/dnn/tiny_extractor_template.h` — actual 77.4 %, override
   10 % (67.4 pp slack). Original 10 % cap was set when only one
   extractor (`feature_lpips.c`) instantiated the inline helpers; four
   extractors now do (`feature_lpips`, `fastdvdnet_pre`,
   `feature_mobilesal`, `feature_transnet_v2`). Tighten to 75 (2.4 pp
   slack, mirroring the 1.3-1.7 pp slack ADR-0114 used for the at-cap
   entries). Locks 65 pp of de-facto regression-coverage.

2. `core/src/dnn/ort_backend.c` — actual 77.8 %, override 78 % (at cap,
   currently failing on master). Keep at 78 — PR #338 in flight adds
   `vmaf_ort_output_name_at` unit test, lifting actual to 78.5 %
   without raising the bar (correct pattern per ADR-0114).

3. `core/src/dnn/dnn_api.c` — actual 78.0 %, override 78 % (at cap).
   Keep at 78 — structural ceiling rationale per ADR-0114 §Context
   unchanged.

No new override entries required. All other dnn/ files plus opt.c and
read_json_model.c clear the global 85 % critical floor
(dnn_attach_api.c 92 %, model_loader.c 87 %, onnx_scan.c 93 %,
op_allowlist.c 100 %, tensor_io.c 98 %, opt.c 100 %,
read_json_model.c 88 %).

ADR-0881 also codifies the recurring audit rule (tighten when slack
> 5 pp; keep at-cap; remove when actual ≥ global 85 % floor; audit
quarterly + before any PER_FILE_MIN edit). Audit procedure documented
in the companion research digest.

Reproducer:
  PKG_CONFIG_PATH=/path/to/onnxruntime/lib/pkgconfig \
    meson setup core/build-coverage core --buildtype=debug \
      -Db_coverage=true -Denable_cuda=false -Denable_sycl=false \
      -Denable_float=true -Denable_avx512=true -Denable_dnn=enabled \
      -Dc_args=-fprofile-update=atomic -Dcpp_args=-fprofile-update=atomic
  ninja -C core/build-coverage
  LD_LIBRARY_PATH=/path/to/onnxruntime/lib \
    meson test -C core/build-coverage --num-processes 1
  cd core && gcovr --root .. --filter 'src/.*' \
    --exclude '.*/test/.*' --exclude '.*/tests/.*' \
    --json-summary build-coverage/coverage.json build-coverage
  bash scripts/ci/coverage-check.sh core/build-coverage/coverage.json 37 85
  # Pre-audit: tiny_extractor_template.h reports "min 10%"
  # Post-audit: same file reports "min 75%" — gate enforces the new floor

Closes the ADR-0114 implicit follow-up "re-audit slack overrides on a
cadence so they don't rot".

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(ci,operator): install kubebuilder envtest binaries for operator suite

The cmd/vmafx-operator/internal/controller envtest suite was hard-failing
in BeforeSuite with a nil-pointer deref from controlplane.(*APIServer).Stop
because the kubebuilder envtest control-plane binaries (etcd +
kube-apiserver + kubectl) were not on PATH. PRs #330, #341, and #362 all
called this out as a pre-existing failure they could not address inline.

Three-pronged fix:

1. Makefile gains a `setup-envtest` target that installs
   `sigs.k8s.io/controller-runtime/tools/setup-envtest@latest` and
   downloads the v1.31 control-plane bundle. A companion
   `setup-envtest-env` target prints the eval-friendly export line so
   developers can do `eval $(make -s setup-envtest-env)`.

2. .github/workflows/go-ci.yml installs setup-envtest and exports
   `KUBEBUILDER_ASSETS` via `$GITHUB_ENV` before `go test ./...`, so the
   operator suite runs for real in CI instead of skipping.

3. cmd/vmafx-operator/internal/controller/suite_test.go gains a
   top-of-`TestControllers` `t.Skip()` guard when `KUBEBUILDER_ASSETS`
   is unset, plus a nil-`testEnv` bailout in `AfterSuite` so the suite
   never panics on a fresh checkout where the assets are missing
   (defense in depth).

Local verification:
- `unset KUBEBUILDER_ASSETS && go test ./cmd/vmafx-operator/...` -> SKIP
  with an actionable message pointing at `make setup-envtest`.
- `eval $(make -s setup-envtest-env) && go test -v ./cmd/vmafx-operator/...`
  -> 3/3 specs pass in ~5 s.

AGENTS.md gains a new invariant #6 documenting the skip-safe envtest
pattern; rebase-notes.md, state.md, and a changelog fragment under
changelog.d/fixed/ are updated per ADR-0108 + CLAUDE.md r10/r13.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* test(sycl): SYCL kernel parity coverage round 3 (5 new tests, ADR-0946)

Adds five new CPU-vs-SYCL parity tests under core/test/, extending
the SYCL parity coverage beyond rounds 1 (PR #351: integer psnr +
vif) and 2 (PR #376: integer adm / ciede / ssim / ms_ssim /
motion_v2).

New parity tests at ADR-0214 places=4 (1e-4) tolerance:

| Kernel              | New test                              | Headline score                            |
|---------------------|---------------------------------------|-------------------------------------------|
| float_psnr_sycl     | test_sycl_float_psnr_parity.c         | float_psnr                                |
| float_adm_sycl      | test_sycl_float_adm_parity.c          | VMAF_feature_adm2_score                   |
| float_vif_sycl      | test_sycl_float_vif_parity.c          | VMAF_feature_vif_scale0_score             |
| float_motion_sycl   | test_sycl_float_motion_parity.c       | VMAF_feature_motion2_score (idx 1)        |
| psnr_hvs_sycl       | test_sycl_psnr_hvs_parity.c           | psnr_hvs                                  |

Each mirrors the round-1 / round-2 pattern: 256x144 synthetic
YUV420P fixture, CPU + SYCL feature extractor, parity assertion
within ADR-0214 places=4, skip-on-no-device via
"[skip: no SYCL device]" printf.

Coverage trajectory: 50% (rounds 1+2) -> 78% (this PR).
Round-4 backlog: float_moment, speed_chroma, speed_temporal,
ssimulacra2 (need scaffold extensions for per-extractor config
dicts and ref_pic_90 fill before the same gate can be added).

Container compile-check evidence:

    docker exec vmaf-dev-mcp bash -lc '
      source /opt/intel/oneapi/setvars.sh --force >/dev/null 2>&1 && \
      cd /tmp/wt-sycl-r3 && \
      CC=icx CXX=icpx meson setup build-sycl-r3 core \
          -Denable_sycl=true -Denable_avx512=false -Db_lto=false && \
      ninja -C build-sycl-r3 \
          test/test_sycl_float_psnr_parity \
          test/test_sycl_float_adm_parity \
          test/test_sycl_float_vif_parity \
          test/test_sycl_float_motion_parity \
          test/test_sycl_psnr_hvs_parity'

All five executables compile + link clean with -Wall -Wextra under
icx/icpx. Registration sub-tests pass on this host; parity
sub-tests hit a pre-existing level_zero device-passthrough issue
(same as PR #376, not introduced by this PR).

Refs ADR-0946, ADR-0214, ADR-0868, ADR-0884.

* test(sycl): SYCL kernel parity coverage round 4 (4 new tests, ADR-0957) (#465)

Closes the SYCL kernel-coverage backlog enumerated in ADR-0946 by
adding four new CPU vs. SYCL parity tests under core/test/.

| Kernel              | New test                              | Tolerance              |
|---------------------|---------------------------------------|------------------------|
| float_moment_sycl   | test_sycl_float_moment_parity.c       | 1e-4 (ADR-0214 default)|
| speed_chroma_sycl   | test_sycl_speed_chroma_parity.c       | 1e-4 (ADR-0214 default)|
| speed_temporal_sycl | test_sycl_speed_temporal_parity.c     | 1e-4 (ADR-0214 default)|
| ssimulacra2_sycl    | test_sycl_ssimulacra2_parity.c        | 5e-3 (FEATURE_TOLERANCE)|

Each test mirrors the round-3 scaffold: 256x144 synthetic YUV420P
fixture, public vmaf_use_feature API with NULL options dict
(defaults match between CPU and SYCL for all four kernels),
parity assertion via fabs(cpu - sycl) <= TOL, skip-on-no-device
via "[skip: no SYCL device]" printf.

The SSIMULACRA2 fixture fills all three planes (the pipeline
consumes YUV -> linear-RGB -> XYB and chroma matters for the
headline score). The speed_temporal fixture submits two frames
(TEMPORAL flag means frame 0 emits 0.0) and asserts at index 1.

Discovery during round-4 implementation:
speed_chroma_sycl.cpp (752 LOC) and speed_temporal_sycl.cpp
(705 LOC) source files exist on disk but are NOT wired into
sycl_feature_sources in core/src/meson.build and their extractor
symbols are NOT declared/registered in
core/src/feature/feature_extractor.c. Both files appear complete
(no TODO/FIXME/-ENOSYS/stub markers) but ship as dormant
scaffold. Wiring them in is out of scope for a kernel-coverage
PR (it changes the production extractor surface). The two SpEED
parity tests are added in dormant form with a
"[skip: <name> not built into libvmaf]" guard that
auto-activates as a real parity gate the day a follow-up PR
wires the TUs into the build + registry.

Container compile-check evidence (CC=icx CXX=icpx,
enable_sycl=true, Intel Arc A380 visible):
- All four test executables link against libvmaf.a successfully.
- speed_chroma/temporal: pass (skip — dormant scaffold).
- float_moment / ssimulacra2: register-existence sub-test passes;
  parity sub-test hits the same pre-existing level_zero
  device-passthrough SIGSEGV that PR #446's round-3 tests hit on
  this dev container (not introduced by this PR). On a host with
  proper Intel-GPU passthrough or with no SYCL device, the tests
  pass / skip cleanly.

Coverage trajectory:
- Round 0 (pre-rounds): 2/18 (11%)
- Round 1 (#351): +2 = 4/18 (22%)
- Round 2 (#376): +5 = 9/18 (50%)
- Round 3 (#446): +5 = 14/18 (78%)
- Round 4 (this PR): +4 = 18/18 (100% of round-3 backlog;
  16 active + 2 dormant SpEED scaffolds)

Refs ADR-0957, ADR-0214, ADR-0867, ADR-0884, ADR-0946.

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>

* chore(ci): add changelog fragment for infra/CI bundle batch-1

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 27, 2026
…t + vmaf-tune stderr + eval shape guard (T-BUGHUNT-MCP-2026-06-27)

Bug-hunt sweep (mcp subsystem), 4 fixed / 2 already-fixed-and-skipped:

- mcp #1 (high): the Go cmd/vmafx-mcp streamable-HTTP transport had no auth,
  no body limit, and bound all interfaces — the Python ADR-0967 hardening was
  never ported. New cmd/vmafx-mcp/http_security.go adds a bearer-token
  middleware (VMAFX_MCP_HTTP_TOKEN, crypto/subtle constant-time compare,
  VMAFX_MCP_HTTP_NO_AUTH=1 opt-out, refuse-all 401 when neither is set), a
  4 MiB body limit (http.MaxBytesReader + Content-Length pre-flight -> 413),
  and a loopback-only default bind (VMAFX_MCP_HTTP_BIND, default 127.0.0.1,
  applied when mcp.http.addr has no host); wired into main.go runMCPTransport.
- mcp #3 (med): unify the score-precision default to "legacy" (%.6f, the
  C-CLI default per ADR-0119). The Python HTTP /v1/score path and the Go
  direct-cgo->subprocess fallback both defaulted to "17", diverging from the
  stdio path and the documented default.
- mcp #4 (low): add the pred/target shape-mismatch guard to the Go
  eval_model_on_split inline script (parity with Python _eval_model_on_split).
- mcp #5 (low): the three Go vmaf-tune wrappers now fold subprocess stderr
  into the error via a shared runVmafTune helper
  ("vmaf-tune <sub> exited <rc>: <stderr>"), instead of discarding it with
  exec.Output().

Skipped (already fixed in-tree): mcp #2 (subsample forwarding on
vmaf_score_encoded — scoreExtras.subsample) and mcp #6 (HTTP /v1/score strict
serializer — http_transport.py uses _dumps_strict).

Golden safety: no Netflix golden assertAlmostEqual value touched (MCP servers
only).

Reproducer:
  go test ./cmd/vmafx-mcp/        # TestSecurityMiddleware*, TestApplyBindHost,
                                  # TestRunVmafTune_*
  gosec ./cmd/vmafx-mcp/          # 0 issues
  PYTHONPATH=mcp-server/vmaf-mcp/src python -m pytest mcp-server/vmaf-mcp/tests -q
                                  # 451 passed, 2 skipped
                                  # (incl. test_score_precision_defaults_to_legacy)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 27, 2026
…t + vmaf-tune stderr + eval shape guard (T-BUGHUNT-MCP-2026-06-27)

Bug-hunt sweep (mcp subsystem), 4 fixed / 2 already-fixed-and-skipped:

- mcp #1 (high): the Go cmd/vmafx-mcp streamable-HTTP transport had no auth,
  no body limit, and bound all interfaces — the Python ADR-0967 hardening was
  never ported. New cmd/vmafx-mcp/http_security.go adds a bearer-token
  middleware (VMAFX_MCP_HTTP_TOKEN, crypto/subtle constant-time compare,
  VMAFX_MCP_HTTP_NO_AUTH=1 opt-out, refuse-all 401 when neither is set), a
  4 MiB body limit (http.MaxBytesReader + Content-Length pre-flight -> 413),
  and a loopback-only default bind (VMAFX_MCP_HTTP_BIND, default 127.0.0.1,
  applied when mcp.http.addr has no host); wired into main.go runMCPTransport.
- mcp #3 (med): unify the score-precision default to "legacy" (%.6f, the
  C-CLI default per ADR-0119). The Python HTTP /v1/score path and the Go
  direct-cgo->subprocess fallback both defaulted to "17", diverging from the
  stdio path and the documented default.
- mcp #4 (low): add the pred/target shape-mismatch guard to the Go
  eval_model_on_split inline script (parity with Python _eval_model_on_split).
- mcp #5 (low): the three Go vmaf-tune wrappers now fold subprocess stderr
  into the error via a shared runVmafTune helper
  ("vmaf-tune <sub> exited <rc>: <stderr>"), instead of discarding it with
  exec.Output().

Skipped (already fixed in-tree): mcp #2 (subsample forwarding on
vmaf_score_encoded — scoreExtras.subsample) and mcp #6 (HTTP /v1/score strict
serializer — http_transport.py uses _dumps_strict).

Golden safety: no Netflix golden assertAlmostEqual value touched (MCP servers
only).

Reproducer:
  go test ./cmd/vmafx-mcp/        # TestSecurityMiddleware*, TestApplyBindHost,
                                  # TestRunVmafTune_*
  gosec ./cmd/vmafx-mcp/          # 0 issues
  PYTHONPATH=mcp-server/vmaf-mcp/src python -m pytest mcp-server/vmaf-mcp/tests -q
                                  # 451 passed, 2 skipped
                                  # (incl. test_score_precision_defaults_to_legacy)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 27, 2026
…t + vmaf-tune stderr + eval shape guard (T-BUGHUNT-MCP-2026-06-27) (#1046)

Bug-hunt sweep (mcp subsystem), 4 fixed / 2 already-fixed-and-skipped:

- mcp #1 (high): the Go cmd/vmafx-mcp streamable-HTTP transport had no auth,
  no body limit, and bound all interfaces — the Python ADR-0967 hardening was
  never ported. New cmd/vmafx-mcp/http_security.go adds a bearer-token
  middleware (VMAFX_MCP_HTTP_TOKEN, crypto/subtle constant-time compare,
  VMAFX_MCP_HTTP_NO_AUTH=1 opt-out, refuse-all 401 when neither is set), a
  4 MiB body limit (http.MaxBytesReader + Content-Length pre-flight -> 413),
  and a loopback-only default bind (VMAFX_MCP_HTTP_BIND, default 127.0.0.1,
  applied when mcp.http.addr has no host); wired into main.go runMCPTransport.
- mcp #3 (med): unify the score-precision default to "legacy" (%.6f, the
  C-CLI default per ADR-0119). The Python HTTP /v1/score path and the Go
  direct-cgo->subprocess fallback both defaulted to "17", diverging from the
  stdio path and the documented default.
- mcp #4 (low): add the pred/target shape-mismatch guard to the Go
  eval_model_on_split inline script (parity with Python _eval_model_on_split).
- mcp #5 (low): the three Go vmaf-tune wrappers now fold subprocess stderr
  into the error via a shared runVmafTune helper
  ("vmaf-tune <sub> exited <rc>: <stderr>"), instead of discarding it with
  exec.Output().

Skipped (already fixed in-tree): mcp #2 (subsample forwarding on
vmaf_score_encoded — scoreExtras.subsample) and mcp #6 (HTTP /v1/score strict
serializer — http_transport.py uses _dumps_strict).

Golden safety: no Netflix golden assertAlmostEqual value touched (MCP servers
only).

Reproducer:
  go test ./cmd/vmafx-mcp/        # TestSecurityMiddleware*, TestApplyBindHost,
                                  # TestRunVmafTune_*
  gosec ./cmd/vmafx-mcp/          # 0 issues
  PYTHONPATH=mcp-server/vmaf-mcp/src python -m pytest mcp-server/vmaf-mcp/tests -q
                                  # 451 passed, 2 skipped
                                  # (incl. test_score_precision_defaults_to_legacy)

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
@lusoris lusoris added this to the 1.0.0 — First release milestone Sep 4, 2026
lusoris added a commit that referenced this pull request Sep 5, 2026
…-AV1-HDR knobs

- Land profile report audit findings #2-#10 in report.py and cli.py:
  - #2: Unify bitrate axis labels and tick formatting (Mbps/kbps).
  - #3: Render em-dash for failed rows with 0.0 values in HTML/Markdown.
  - #4: Assign VideoToolbox encoders to distinct palette slots (15-17).
  - #5 & #8: Deduplicate pareto annotations to lowest-bitrate point with bitrate.
  - #6: Add --json-sidecar CLI flag and ReportData.from_dict round-trip.
  - #7: Add picked CRF label to scatter plot and deduplicate legend entries.
  - #9: Strip timestamp and pin svg.hashsalt for byte-identical rendering.
  - #10: Add failed target markers and failure annotations to sweep chart.
- Document SVT-AV1-HDR tuning knobs and libsvtav1@svt-av1-hdr runtime variant
  in docs/usage/vmaf-tune.md and docs/usage/vmaf-tune-codec-adapters.md.
- Add comprehensive regression tests in tools/vmaf-tune/tests/test_report.py.
- Update docs/state.md, docs/rebase-notes.md, and changelog fragments.
lusoris added a commit that referenced this pull request Sep 5, 2026
…-AV1-HDR knobs

- Land profile report audit findings #2-#10 in report.py and cli.py:
  - #2: Unify bitrate axis labels and tick formatting (Mbps/kbps).
  - #3: Render em-dash for failed rows with 0.0 values in HTML/Markdown.
  - #4: Assign VideoToolbox encoders to distinct palette slots (15-17).
  - #5 & #8: Deduplicate pareto annotations to lowest-bitrate point with bitrate.
  - #6: Add --json-sidecar CLI flag and ReportData.from_dict round-trip.
  - #7: Add picked CRF label to scatter plot and deduplicate legend entries.
  - #9: Strip timestamp and pin svg.hashsalt for byte-identical rendering.
  - #10: Add failed target markers and failure annotations to sweep chart.
- Document SVT-AV1-HDR tuning knobs and libsvtav1@svt-av1-hdr runtime variant
  in docs/usage/vmaf-tune.md and docs/usage/vmaf-tune-codec-adapters.md.
- Add comprehensive regression tests in tools/vmaf-tune/tests/test_report.py.
- Update docs/state.md, docs/rebase-notes.md, and changelog fragments.
lusoris added a commit that referenced this pull request Sep 6, 2026
…-AV1-HDR knobs

- Land profile report audit findings #2-#10 in report.py and cli.py:
  - #2: Unify bitrate axis labels and tick formatting (Mbps/kbps).
  - #3: Render em-dash for failed rows with 0.0 values in HTML/Markdown.
  - #4: Assign VideoToolbox encoders to distinct palette slots (15-17).
  - #5 & #8: Deduplicate pareto annotations to lowest-bitrate point with bitrate.
  - #6: Add --json-sidecar CLI flag and ReportData.from_dict round-trip.
  - #7: Add picked CRF label to scatter plot and deduplicate legend entries.
  - #9: Strip timestamp and pin svg.hashsalt for byte-identical rendering.
  - #10: Add failed target markers and failure annotations to sweep chart.
- Document SVT-AV1-HDR tuning knobs and libsvtav1@svt-av1-hdr runtime variant
  in docs/usage/vmaf-tune.md and docs/usage/vmaf-tune-codec-adapters.md.
- Add comprehensive regression tests in tools/vmaf-tune/tests/test_report.py.
- Update docs/state.md, docs/rebase-notes.md, and changelog fragments.
lusoris added a commit that referenced this pull request Sep 6, 2026
…-AV1-HDR knobs

- Land profile report audit findings #2-#10 in report.py and cli.py:
  - #2: Unify bitrate axis labels and tick formatting (Mbps/kbps).
  - #3: Render em-dash for failed rows with 0.0 values in HTML/Markdown.
  - #4: Assign VideoToolbox encoders to distinct palette slots (15-17).
  - #5 & #8: Deduplicate pareto annotations to lowest-bitrate point with bitrate.
  - #6: Add --json-sidecar CLI flag and ReportData.from_dict round-trip.
  - #7: Add picked CRF label to scatter plot and deduplicate legend entries.
  - #9: Strip timestamp and pin svg.hashsalt for byte-identical rendering.
  - #10: Add failed target markers and failure annotations to sweep chart.
- Document SVT-AV1-HDR tuning knobs and libsvtav1@svt-av1-hdr runtime variant
  in docs/usage/vmaf-tune.md and docs/usage/vmaf-tune-codec-adapters.md.
- Add comprehensive regression tests in tools/vmaf-tune/tests/test_report.py.
- Update docs/state.md, docs/rebase-notes.md, and changelog fragments.
lusoris added a commit that referenced this pull request Sep 6, 2026
…-AV1-HDR knobs (#1296)

* fix(vmaf-tune): address report audit findings #2-#10 and document SVT-AV1-HDR knobs

- Land profile report audit findings #2-#10 in report.py and cli.py:
  - #2: Unify bitrate axis labels and tick formatting (Mbps/kbps).
  - #3: Render em-dash for failed rows with 0.0 values in HTML/Markdown.
  - #4: Assign VideoToolbox encoders to distinct palette slots (15-17).
  - #5 & #8: Deduplicate pareto annotations to lowest-bitrate point with bitrate.
  - #6: Add --json-sidecar CLI flag and ReportData.from_dict round-trip.
  - #7: Add picked CRF label to scatter plot and deduplicate legend entries.
  - #9: Strip timestamp and pin svg.hashsalt for byte-identical rendering.
  - #10: Add failed target markers and failure annotations to sweep chart.
- Document SVT-AV1-HDR tuning knobs and libsvtav1@svt-av1-hdr runtime variant
  in docs/usage/vmaf-tune.md and docs/usage/vmaf-tune-codec-adapters.md.
- Add comprehensive regression tests in tools/vmaf-tune/tests/test_report.py.
- Update docs/state.md, docs/rebase-notes.md, and changelog fragments.

* docs(vmaf-tune): correct SVT-AV1-HDR knob defaults against upstream Parameters.md

The first cut of the knob table carried three defaults that contradict
juliobbv-p/svt-av1-hdr Docs/Parameters.md @ 0033340 (tune=1 not 0,
sharp-tx=1 not 0, noise-adaptive-filtering=2 not 0) and omitted twelve
documented keys. Rebuild the table from the upstream parameter reference,
state the three injection points for the -svtav1-params string and the
ADR-0294 CRF/preset window the variant inherits, and drop the
'this PR' placeholders from docs/state.md so the ADR-0165 touch gate
accepts the rows.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* docs(state): drop the duplicate rows a keep-both rebase created

Each dropped row restates one origin/master already carries; master is the
authoritative record. Verified with scripts/ci/check-state-md-rows.sh.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Oct 1, 2026
…alert #6 (ADR-1389)

- Resolve CodeQL alert #1309 (cpp/include-non-header):
  Replace unity-inclusion of core/src/libvmaf.c in core/test/test_feature_backend_twin.c
  with direct linkage against libvmaf in core/test/meson.build and narrow internal test
  accessors in core/src/libvmaf_priv.h (vmaf_backend_twin_verdict_for_test,
  vmaf_context_fake_backend_for_test, vmaf_context_set_gpumask_for_test,
  vmaf_context_append_registered_feature_extractor_for_test, and
  vmaf_context_resolve_context_fallbacks_for_test) implemented statically in
  core/src/libvmaf.c.
- Add scripts/ci/check-no-non-header-includes.sh and test suite
  scripts/ci/tests/test-check-no-non-header-includes.sh, wired into
  .pre-commit-config.yaml and .github/workflows/rule-enforcement.yml to fail
  closed on non-header source inclusions in core/test/.
- Resolve OpenSSF Scorecard alert #6 (SAST):
  Under ADR-1389, run CodeQL (Actions) unconditionally on every pull request and
  master push in .github/workflows/security-scans.yml, ensuring 100% commit SAST
  coverage across docs-only and non-code PRs with negligible (~15-20s) overhead,
  and enforce it in .github/workflows/required-aggregator.yml.
- Update docs/state.md, changelog fragment, docs/rebase-notes.md, and ADR index.
lusoris added a commit that referenced this pull request Oct 1, 2026
…alert #6 (ADR-1389)

- Resolve CodeQL alert #1309 (cpp/include-non-header):
  Replace unity-inclusion of core/src/libvmaf.c in core/test/test_feature_backend_twin.c
  with direct linkage against libvmaf in core/test/meson.build and narrow internal test
  accessors in core/src/libvmaf_priv.h (vmaf_backend_twin_verdict_for_test,
  vmaf_context_fake_backend_for_test, vmaf_context_set_gpumask_for_test,
  vmaf_context_append_registered_feature_extractor_for_test, and
  vmaf_context_resolve_context_fallbacks_for_test) implemented statically in
  core/src/libvmaf.c.
- Add scripts/ci/check-no-non-header-includes.sh and test suite
  scripts/ci/tests/test-check-no-non-header-includes.sh, wired into
  .pre-commit-config.yaml and .github/workflows/rule-enforcement.yml to fail
  closed on non-header source inclusions in core/test/.
- Resolve OpenSSF Scorecard alert #6 (SAST):
  Under ADR-1389, run CodeQL (Actions) unconditionally on every pull request and
  master push in .github/workflows/security-scans.yml, ensuring 100% commit SAST
  coverage across docs-only and non-code PRs with negligible (~15-20s) overhead,
  and enforce it in .github/workflows/required-aggregator.yml.
- Update docs/state.md, changelog fragment, docs/rebase-notes.md, and ADR index.
lusoris added a commit that referenced this pull request Oct 1, 2026
…alert #6 (ADR-1389) (#1659)

* fix(security): resolve CodeQL include alert #1309 and Scorecard SAST alert #6 (ADR-1389)

- Resolve CodeQL alert #1309 (cpp/include-non-header):
  Replace unity-inclusion of core/src/libvmaf.c in core/test/test_feature_backend_twin.c
  with direct linkage against libvmaf in core/test/meson.build and narrow internal test
  accessors in core/src/libvmaf_priv.h (vmaf_backend_twin_verdict_for_test,
  vmaf_context_fake_backend_for_test, vmaf_context_set_gpumask_for_test,
  vmaf_context_append_registered_feature_extractor_for_test, and
  vmaf_context_resolve_context_fallbacks_for_test) implemented statically in
  core/src/libvmaf.c.
- Add scripts/ci/check-no-non-header-includes.sh and test suite
  scripts/ci/tests/test-check-no-non-header-includes.sh, wired into
  .pre-commit-config.yaml and .github/workflows/rule-enforcement.yml to fail
  closed on non-header source inclusions in core/test/.
- Resolve OpenSSF Scorecard alert #6 (SAST):
  Under ADR-1389, run CodeQL (Actions) unconditionally on every pull request and
  master push in .github/workflows/security-scans.yml, ensuring 100% commit SAST
  coverage across docs-only and non-code PRs with negligible (~15-20s) overhead,
  and enforce it in .github/workflows/required-aggregator.yml.
- Update docs/state.md, changelog fragment, docs/rebase-notes.md, and ADR index.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant