-
Timmy daily review — 2026-08-27
Pre-ReleaseAll checks were successfulQuality gates / quality (push) Successful in 1m56sreleased this
2026-08-27 13:15:36 +00:00 | 0 commits to main since this releaseVerified rebuild; no source change
A fresh, fully gated rebuild of current
main. The source commit is unchanged from the previous dated release.Demonstrated feature path
- Mobile camera/picker cancellation recovers cleanly.
- Gallery and manual logging remain immediately available.
- Explicit consent precedes the synthetic photo-analysis request.
- AI is limited to a provisional visible Bristol form, broad color, image quality, and bounded confidence; the user must review and confirm.
- Hermes chat uses server-side session continuity and excludes photos.
- Urgent language is intercepted deterministically before Hermes.
Release evidence
- Exact commit:
5dac04b1e6097563afac469ac399a301a7d8d86a - Completed ticket / PR represented on current main: issue #11 / PR #66
- Model/profile shown in synthetic demo:
SmolVLM2-2.2B-Instruct/selfhost - Source archive SHA-256:
9318d7235a96ad5d880d435d56044c29f8353ea77d62aab3930ad842abb4dee0 - Demo video SHA-256:
0fa4a68003e73048c3a8aec344532c823b18dc0488f2c98fd111471f05f975f5
Passed gates
Unit/security tests; mobile green path; photo-first acceptance; mobile capture recovery; sleek Hermes chat acceptance; high-severity dependency audit; syntax checks; secret scan; forbidden-artifact scan; actual browser recording; H.264 720×1280/yuv420p probe; complete MP4 decode; contact-sheet and full-resolution-frame visual QC.
Known accuracy limitation
The open-weight VLM integration path is demonstrated with clearly synthetic fixture data. Bristol accuracy is not clinically validated. Timmy does not diagnose disease; user confirmation remains mandatory.
-
Timmy review release 2026-08-26
Pre-ReleaseAll checks were successfulQuality gates / quality (push) Successful in 1m56sreleased this
2026-08-26 12:22:14 +00:00 | 0 commits to main since this releaseReview release
- Version:
2026-08-26-5dac04b1e609 - Exact commit:
5dac04b1e6097563afac469ac399a301a7d8d86a - Completed ticket / PR: #11 / #66
- Vision profile / model shown:
selfhost/SmolVLM2-2.2B-Instruct(synthetic deterministic API fixture; no model weights included)
Tangible change demonstrated
The mobile photo flow now has separate Take photo and Choose from gallery controls. The real-app recording visibly cancels the camera picker, shows the recovery message, keeps gallery and manual logging available, selects a clearly synthetic Type-4 fixture from the gallery, and shows that analysis remains disabled until explicit consent. Touch indicators and on-screen explanations are burned into the demo.
Verified gates
- 67/67 unit and security tests
- mobile UI green path
- photo-first acceptance flow
- camera/gallery recovery at 390×844 and 393×852
- sleek Hermes-chat acceptance flow
- dependency audit: 0 high vulnerabilities
- syntax, diff hygiene, secret scan, and forbidden-artifact scan
- actual Playwright browser recording from the running app
- H.264/yuv420p 720×1280 media probe
- complete MP4 decode
- contact-sheet and full-resolution middle-frame visual QC
Receipts
- Source SHA-256:
ececea0418fddeaf69c525f9d08b63ff51064df15ec31eedc6dff7427c2e068f - Demo-video SHA-256:
e6cd5c865c4f5b570769885b39caa1036d1077f568e6dc0882ac3574cca0e099
Safety / accuracy boundary
Timmy may suggest only visible Bristol form, broad color, and image quality with bounded confidence and abstention. It does not diagnose disease or infer symptoms; user confirmation remains mandatory. Known limitation: open-weight VLM integration is exercised, but Bristol-form accuracy is not clinically validated. The demo uses synthetic data and deterministic responses, not a live model-quality benchmark.
- Version:
-
Timmy daily review 2026-08-25
Pre-ReleaseAll checks were successfulQuality gates / quality (push) Successful in 1m56sreleased this
2026-08-25 12:40:49 +00:00 | 3 commits to main since this releaseTimmy daily review — verified rebuild; no source change
- Target commit:
47294a98aa319d2badb41f817a65e044d2dbfe19 - Gates: 67/67 unit/security tests; mobile home→log→urgent→save; photo consent→synthetic suggestion→user confirmation; sleek Hermes chat; high-severity dependency audit; syntax, secret, and forbidden-artifact scans; real-browser recording; H.264 720×1280/yuv420p probe; complete MP4 decode; contact-sheet and full-resolution-frame visual QC.
- Source SHA-256:
9fd69b2abe8eaaa37b77e6300fcd3e1abfc4fbcb4f63cd7086df03b29c6b1b93 - Demo video SHA-256:
46186f37bb9edaf3fc9f4624473f982befc45204d1442c6d7c47be5f18f63e21 - Demo model/profile: synthetic deterministic fixture presenting
selfhost/SmolVLM2-2.2B-Instruct; this recording does not claim a live inference run. - Completed ticket/PR: none in this rebuild. PR #65 was reviewed and remains open because its exact-head review requests changes.
- Demonstrated features: explicit photo consent; bounded visible-form/broad-color/image-quality suggestion using clearly synthetic Type-4 data; mandatory user review before save; server-side Hermes contextual chat; deterministic urgent-language interception before Hermes.
- Safety/privacy: photos stay out of chat; no credentials, real medical images, model weights, or raw corpora are packaged. AI is limited to visible Bristol form, broad color, image quality, bounded confidence, and abstention. User confirmation remains mandatory.
- Known accuracy limitation: open-weight VLM integration acceptance is proven, but Bristol/color accuracy is not clinically validated and this release demonstration uses deterministic synthetic responses.
- Target commit:
-
Timmy daily review 2026-08-24
Pre-ReleaseAll checks were successfulQuality gates / quality (push) Successful in 1m56sreleased this
2026-08-24 12:55:25 +00:00 | 3 commits to main since this releaseTimmy the Talking Turd — daily review release 2026-08-24
verified rebuild; no source change
- Target commit:
47294a98aa319d2badb41f817a65e044d2dbfe19 - Source SHA-256:
99f9d8673b84fcf82db29eab3b11aee64557fa1dc10863af27d0f7aaa40696f6 - Demo-video SHA-256:
a1c2c1faea028a20c5ecf8e1b11bc2475fb829d9b3b8caa4f1c26765571d5162 - Vision model/profile shown:
SmolVLM2-2.2B-Instruct/selfhost(synthetic deterministic release fixture) - Completed ticket/PR in this release: none. PR #65 remains open because exact-head review requests changes; it was not merged.
Demonstrated features
The 24.16-second real-browser, 405×720 mobile recording visibly exercises the latest verified feature path with touch indicators and synthetic data: dominant photo-first logging; explicit upload consent; bounded AI suggestions for visible Bristol form, broad color, confidence, and image quality; mandatory user review before save; server-side Hermes contextual chat with photos excluded; and deterministic urgent-language interception before Hermes.
Gates
- Unit/security suite: passed
- Mobile UI acceptance: passed
- Photo-first acceptance: passed
- Sleek Hermes chat acceptance: passed
- Dependency audit at high severity: 0 vulnerabilities
- JavaScript, shell, and Python syntax checks: passed
- Secret scan and forbidden-artifact scan: passed
- H.264 720×1280, yuv420p media probe: passed
- Complete MP4 decode: passed
- Contact sheet and full-resolution middle-frame review: accepted; no clipping, padding, blank frames, sensitive data, unreadable copy, or misleading health claims observed
Known accuracy limitation
Open-weight VLM acceptance is proven, but Bristol accuracy is not clinically validated. AI remains bounded to visible form, broad color, image quality, confidence, and abstention. It does not diagnose disease; the user must confirm every suggestion.
- Target commit:
-
Timmy daily review — 2026-08-23
Pre-ReleaseAll checks were successfulQuality gates / quality (push) Successful in 1m56sreleased this
2026-08-23 13:04:16 +00:00 | 3 commits to main since this releaseTimmy review release 2026-08-23-47294a98aa31
verified rebuild; no source change since the 2026-08-22 dated release.
Demonstrated feature path
A real mobile browser recording replays the latest feature path with clearly synthetic data and visible touch indicators: private photo-first entry → bounded AI suggestion for visible Bristol form, broad color, confidence and image quality → explicit user confirmation → server-side Hermes chat over confirmed ledger context → deterministic urgent-language interception before Hermes.
Completed work represented by this commit
- Ticket #58 / merged PR #59: strict-CSP-compatible staging runtime configuration.
- No nightly PR was merged for this rebuild. PR #60 was held after exact-head review reproduced a fail-closed telemetry schema defect.
Verified gates
- Unit/security suite: passed
- Mobile UI acceptance: passed
- Photo-first acceptance: passed
- Sleek Hermes chat acceptance: passed
- Dependency audit (high): 0 vulnerabilities
- Syntax, diff, secret, and forbidden-artifact scans: passed
- Browser recording and final MP4 full decode: passed
- Media probe: H.264, yuv420p, 720×1280, 25 fps
- Contact sheet, full-resolution middle frame, and touch sequence: visually inspected and passed
Integrity
- Exact commit:
47294a98aa319d2badb41f817a65e044d2dbfe19 - Source archive SHA-256:
d1287dd382d154c7e2d77cf9ab48b9c503431601bc3480d1be4621819d4ae8b9 - Demo video SHA-256:
792c2140e6688c711ea991a0833034f3158f1df1a40ed98dedd5702a73ac1334 - Vision profile/model shown in the synthetic demo:
selfhost/SmolVLM2-2.2B-Instruct
Accuracy and safety boundary
AI is limited to visible Bristol form, broad color, image quality, bounded confidence, and abstention. It does not diagnose disease or infer symptoms. User confirmation remains mandatory. Known limitation: the open-weight VLM path is operationally accepted, but Bristol-form accuracy is not clinically validated.
-
Timmy daily review 2026-08-22
Pre-ReleaseAll checks were successfulQuality gates / quality (push) Successful in 1m56sreleased this
2026-08-22 12:51:19 +00:00 | 3 commits to main since this releaseTimmy review release 2026-08-22-47294a98aa31
verified rebuild; no source change since the previous dated release. Exact target commit:
47294a98aa319d2badb41f817a65e044d2dbfe19.Demonstrated feature path
- Synthetic photo → explicit upload consent → bounded AI suggestion (visible Bristol form, broad color, image quality)
- User reviews/corrects the suggestion before saving
- Authenticated server-side Hermes chat over confirmed text-only logs; photos remain outside chat
- Deterministic urgent-language interception before Hermes
- Operational nearest effect: the self-hosted bootstrap reports pinned model readiness before the photo flow begins
Verification
- Unit/security: 67/67 passed
- Mobile home/log/red-flag/save flow: passed
- Mobile photo/consent/suggestion/confirmation flow: passed
- Sleek Hermes chat flow: passed
- Dependency audit: 0 high vulnerabilities
- Syntax, secret scan, and forbidden-artifact scan: passed
- Browser demo: real app recording, complete decode passed, H.264/yuv420p 720×1280
- Contact sheet and full-resolution middle frame: visually inspected; no blank/clipped/sensitive/misleading frames
Receipts
- Source SHA-256:
1eafc075da581dd262da96267cfa5a7eeb107117736f8cfd2f3db799f910f6d6 - Demo-video SHA-256:
16a53c1695b443217742499bc3f73d3ea674a8d2264ae5cb9e276c2d42792daf - Vision profile/model:
selfhost/SmolVLM2-2.2B-Instruct - Completed ticket/PR represented by current main: issue #58 / PR #59; no PR merged during this rebuild
Known accuracy limitation
Open-weight VLM integration and the bounded UI flow are verified; Bristol classification accuracy is not clinically validated. The result is a visual suggestion, never a diagnosis, and user confirmation remains mandatory.
-
daily-2026-08-21.1
Pre-ReleaseAll checks were successfulQuality gates / quality (push) Successful in 1m56sreleased this
2026-08-21 15:12:16 +00:00 | 3 commits to main since this releasePrivate-staging release from clean merged main.
Verification: full unit/security suite; root and prefixed mobile acceptance; exact strict-CSP mobile acceptance; dependency audit (0 vulnerabilities); syntax/diff/secret/forbidden-artifact checks; full MP4 decode and visual inspection; live authenticated health and mobile staging smoke.
Phase 1: Hermes disabled; vision disabled; application binds only to 127.0.0.1:4174 behind authenticated HTTPS.
Source SHA-256: f30369e422a9d6c51ed70a0fc44c3a36123b42e7dd73ec134cfba763438718e4
Video SHA-256: 92d75e0491cdaa3192ab14fed7f2b2d0a388ecc4a7ad00f975cee5237a38a076Downloads
-
Timmy pinned private self-host bootstrap review — 2026-08-21
Pre-ReleaseAll checks were successfulQuality gates / quality (push) Successful in 1m45sreleased this
2026-08-21 12:59:31 +00:00 | 9 commits to main since this releaseReview release
Tangible change: a reproducible self-hosted SmolVLM2 bootstrap now pins the llama.cpp commit and both GGUF SHA-256 receipts, verifies downloads before use, keeps weights outside Git, binds to private loopback by default, and provides install/start/health/stop commands.
Demonstrated features: the real mobile app opens the photo-first flow; the on-screen release caption identifies the pinned verification and private-loopback operational effect; a clearly synthetic Type 4 fixture exercises explicit consent, bounded visible-form/broad-color/image-quality suggestion, user review, Hermes server-side chat, and deterministic urgent-language interception.
Completed work: issue #10; PR #52. Release-gate follow-up commit adds the new bootstrap script to mandatory shell syntax validation.
Model/profile: SmolVLM2-2.2B-Instruct;
selfhostprofile; synthetic deterministic provider fixture for the recorded review path. Model weights are not included.Gates: 49 unit/security tests; mobile home/log/safety flow; mobile photo/consent/suggestion flow; sleek shell + Hermes chat flow; high-severity dependency audit; JavaScript/Python/shell syntax; diff hygiene; secret scan; forbidden-artifact scan; real Chromium recording; H.264 720x1280 yuv420p probe; complete MP4 decode; contact-sheet and full-resolution middle-frame review. All passed.
Source SHA-256:
e56a206a49be49ca73eb6a0470d907b9d52936bd83ab22f0e321cadc5889947cDemo video SHA-256:
7d79853105f9b3df141bbda791a839a4cd0da4d1a507ad7bd0d4562e1a142681Known accuracy limitation: the open-weight VLM path is operationally accepted but Bristol accuracy is not clinically validated. Timmy only assists with visible Bristol form, broad color, and image quality, can abstain, never diagnoses, and requires user confirmation.
-
Timmy final deterministic chat-safety release - 2026-08-20.3
Pre-ReleaseAll checks were successfulQuality gates / quality (push) Successful in 1m26sreleased this
2026-08-20 17:19:52 +00:00 | 12 commits to main since this releaseFinal deterministic chat-safety release
Supersedes
daily-2026-08-20.1and.2.- Urgent screening runs in the browser and authoritative server before agent execution.
- Confirmed ledger symptom flags and note text are screened.
- A hostile frozen 41-expression vomiting matrix passed at detector, browser, and service layers.
- Urgent matrix cases produced zero Hermes calls.
- Six non-vomiting hurl/spew controls reached normal chat, proving interception is not overbroad.
- Feature demo visibly proves slang vomiting interception before Hermes.
Gates
- Independent final review: APPROVED
- 45/45 tests passed
- Three mobile browser suites passed
- Gitea PR CI passed
- Dependency audit: 0 vulnerabilities
- MP4: 720x1280, fully decoded and visually inspected
Source SHA-256:
d6a1f414ebeb6b9cf6f75ca7b109a06c0d3855aed187616b8ccc313f35d54708Video SHA-256:
3077f00db17095f011d0b9e3abf1766a2db3793256cd59c130c8c52b3e65cd97 -
SUPERSEDED - Timmy authoritative safety hotfix - 2026-08-20.2
Pre-ReleaseAll checks were successfulQuality gates / quality (push) Successful in 1m24sreleased this
2026-08-20 16:54:11 +00:00 | 14 commits to main since this releaseSUPERSEDED - DO NOT DEPLOY. Follow-up review found that the common past-tense phrase
I threw upstill bypassed deterministic screening. Use the forthcoming 2026-08-20.3 release.