Review follow-ups on the image-generation PR: - ControlNet: resolve_controlnet accepts a bare owner/name repo without the non-GGUF base trust gate, and _controlnet_pipe hands it straight to from_pretrained. A malicious pickle .bin would deserialize on load, so run the same Hugging Face malware preflight (evaluate_file_security) the chat and export loaders use before any remote ControlNet load; local dirs are exempt. - Dataset thumbnails: key the cache on the full filename instead of the stem so sample.png and sample.jpg no longer collide on one .thumbs file (which could serve or delete the wrong image); the delete cleanup globs the same key. - Diffusion training start: mirror start_training's API-key guard so an API client cannot start training (which frees VRAM by unloading chat) while an inference request is streaming; it now returns 409 before any GPU is freed. - Model picker: include the curated safetensors row keys in the recommended roving key list so arrow-key navigation reaches those rows instead of hitting the duplicate option-missing id. Tests: ControlNet malware gate (remote blocked before from_pretrained, local skipped), thumbnail same-stem cache separation, API-key diffusion-start 409 before GPU free. Full diffusion suites green. |
||
|---|---|---|
| .. | ||
| backend | ||
| frontend | ||
| src-tauri | ||
| __init__.py | ||
| install_llama_prebuilt.py | ||
| install_node_prebuilt.py | ||
| install_python_stack.py | ||
| install_sd_cpp_prebuilt.py | ||
| LICENSE.AGPL-3.0 | ||
| node_prebuilt_pins.json | ||
| package-lock.json | ||
| package.json | ||
| setup.bat | ||
| setup.ps1 | ||
| setup.sh | ||
| Unsloth_Studio_Colab.ipynb | ||