What's New
Closes 3 originally-scheduled GitHub issues plus 7 v0.40.1 long-tail UX papercuts. No new schema fields, no new trainers — pure polish.
Originally scheduled (3 issues):
- #36 — Eval-gate dashboard row. New pure formatter
format_gate_row(state)insoup_cli/monitoring/display.pyrenders a one-liner likeGate: helpfulness 7.8 ✓ | math 0.82 ✗ (-0.06) | STOPfor the live training panel. Hidden when eval-gate is disabled. Explicitpassed is Trueso a missing field renders neutral, not a false-y red ✗. Supportsstop/warnaction suffixes. - #50 —
--hf-resumeprefers local newer.prepare_hf_resumenow skipssnapshot_downloadentirely when the highest localcheckpoint-Nis greater-or-equal to the remote highest-N. Saves bandwidth and never overwrites a fresher local checkpoint with stale Hub state. - #51 —
soup deploy hf-space --template-dir <path>. Supply your ownapp.py+README.md(+ optionalrequirements.txt) instead of the built-ingradio-chat/streamlit-chat. Containment-checked, repo-id substitution validated before render, 256 KB cap per file, symlinks rejected (TOCTOU defence).
v0.40.1 carry-overs (7 papercuts):
soup quickstart --output DIR— route data, config, and run dir under any directory you choose.soup runs --cwd-only— restrict listing to runs whoseoutput_diris under cwd; the global~/.soup/experiments.dbview is still default.soup infer/soup benchaccept HF ids — when the local model path is missing AND the value isn't path-like (no./,/,~,C:\), it falls through to a HuggingFace download viatransformers.from_pretrained. Path-like-but-missing surfaces a friendlyFileNotFoundError.- CLI flag aliases —
data filter --min-coherence(alias for--coherence);data split --trainaccepted (informational, train is the implicit remainder);data register / unregisteraccept positional<name>and<path>alongside the--name/--pathoptions, with conflict detection. --log-levelplumbing complete —apply_logging_levelnow sets the root logger so third-party libraries (transformers / peft / trl) actually respect QUIET and DEBUG. The four tiers no longer produce byte-identical output.soup data dedup --threshold— verified already-exposed; no code change.- ONNX/AWQ/GPTQ/TensorRT install hints — verified already-correct; no code change.
Install / Upgrade
pip install --upgrade soup-cli
PyPI auto-publishes via Trusted Publisher OIDC on tag push (~1–2 min). GHCR Docker image rebuilds on the release event (~10–15 min).
Security
render_custom_template_dir(soup_cli/utils/hf_space.py) —is_under_cwdcontainment,validate_repo_idBEFORE{MODEL_REPO}substitution (matches v0.29.0 Part F policy), per-file 256 KB cap (matches v0.39.0 Part E policy), closed allowlist (app.py/README.md/requirements.txtonly), symlinks + non-regular files rejected viaos.lstat + stat.S_ISLNK(matches v0.33.0 #22 prune_checkpoints TOCTOU policy).prepare_hf_resume—_find_highest_local_checkpointreadsoutput_dirafter the caller'sis_under_cwdvalidation; silently drops non-directories + OSError.- Path-containment standardisation. Several pre-existing pre-v0.40.2 sites switched from
Path.resolve() + relative_to()to sharedis_under_cwd(os.path.realpath + commonpath) for Windows 8.3 short-name safety:commands/data.py:register_data,commands/bench.pyprompts file,commands/infer.py --output(late-evaluated to preserve test contracts). commands/runs.py:_filter_runs_by_cwd— usesos.path.realpath + commonpath, catches(ValueError, OSError)so cross-drive paths on Windows (D:\runsvsC:\project) drop silently rather than crash.commands/quickstart.py --output—is_under_cwdcontainment beforemkdir(parents=True); rejects out-of-cwd targets with friendly message.
Known Limitations
- Custom HF Space templates always create the Space with
space_sdk="gradio"regardless of the suppliedapp.py. Use--template streamlit-chatwith the inline registry for Streamlit Spaces. Tracked for v0.40.3+. _resolve_model_sourcereturns("hf", repo_id)withoutvalidate_repo_id;transformers.from_pretrainedwill raise loudly on malformed ids, but a friendlier early-rejection could be added later.--trust-remote-codeopt-in surface still excludes the 10 non-SFT trainers + 5 commands tracked under issue #63 (carry-over from v0.36.0).
Tests
4720 → 4756 (+36) across two new files (tests/test_v0402_part_a.py, tests/test_v0402_part_b.py). Five review agents (python / code / security / tdd / verification) all clean after fixes.