Add runnable Windows local AI development setup - #104
Open
Michael Von Hippel (Kixantrix) wants to merge 23 commits into
Open
Michael Von Hippel (Kixantrix) wants to merge 23 commits into
Michael Von Hippel (Kixantrix) wants to merge 23 commits into
Conversation
Add independent CUDA, Foundry Local, PyTorch, llama.cpp, and Ollama flows with architecture-aware installation, model-free smoke tests, shared decision helpers, unit coverage, and documentation. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Support CUDA and GPU-backed PyTorch on RTX Spark ARM64, resolve current llama.cpp ARM64 assets, and make every AI flow run an end-to-end kernel or model inference by default. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Retry locked installer cleanup without masking results, harden ARM64 MSVC discovery, and update llama.cpp b10867 inference arguments and diagnostics. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use the verified Build Tools bootstrapper in modify mode, wait for installer completion, and require the architecture-native compiler before CUDA or Triton setup continues. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Put the Visual Studio Installer directory on the child command PATH so VsDevCmd can resolve its bundled vswhere.exe under hardened executable lookup policies. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Validate exact installed package versions before pip work, cache the pinned ARM64 wheel after one verified download, and keep tensor and Triton readiness probes on every run. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Replace AI DSC acquisition with PR microsoft#93-style PowerShell setup, add AMD ROCm and Intel AI flows, centralize provider promotion metadata, and emit portable hardware acceptance reports. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Distinguish absent, outdated, and current packages; use exact upgrade operations with module-to-CLI fallback; and make package evidence schema-tolerant. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use explicit native command results instead of inherited LASTEXITCODE and make Ollama managed-process cleanup tolerant of empty and already-exited processes. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Parse llama benchmark JSON after diagnostic prefixes, retain raw backend diagnostics, normalize Foundry cache paths, and force UTF-8 standalone capture. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Add exhaustive supported-cell resolution, vendor-native llama.cpp backends, self-contained PyTorch ROCm/XPU paths, deterministic adapter selection, and strict hardware evidence reporting. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Add a self-contained plan/apply/report workflow, complete vendor assignments, evidence return criteria, and final N1X Ollama acceptance. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Bound native executions, warm up OpenCL before inference, correct provider and JSON parsing, and pin the policy-approved Qualcomm llama.cpp build. Update partner commands and regression coverage. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0c9c6f4f-4ef5-4ca6-acda-43c5632d325f
Verify unsigned source is blocked, Microsoft-signed release scripts load in Windows PowerShell and PowerShell 7, and signed AI flows are exercised automatically after the sign cycle. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Lead with hardware-selected PyTorch and optional model runtimes, add a pinned coding demo and neural forward smoke, track stable-channel candidates behind real workload qualification, and validate the AllSigned production contract. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Route local-ai through the verified Windows Dev Config bootstrap, authenticate non-PowerShell workload content with a signed hash manifest, propagate scenario blockers, and document every transitive acquisition. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Restore the protected local AI dispatcher on the latest bootstrap architecture and convert the official ARM64 archive into an atomic per-user application with PATH, startup, upgrade, uninstall, and live readiness evidence. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Update the executable capability matrix and signed content hash for the managed ARM64 startup/install tuple. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Michael Von Hippel (Kixantrix)
force-pushed
the
mihippel-microsoft-windows-ai-setup-workloads
branch
from
September 29, 2026 17:52
8ea8bb1 to
ca06e37
Compare
Import Microsoft.PowerShell.Utility explicitly so the protected Windows PowerShell scenario does not depend on first-use module autoloading. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Capture verified child bootstrap output across UAC so scenario and workstation handoff failures remain actionable without changing the signed-file relaunch model. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject unsigned and hash-mismatched release scripts, require the Microsoft signer, and use actual AllSigned execution to handle hosted-runner certificate-chain differences. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use actual host execution as the signature contract and validate the Microsoft signer whenever the hosted Authenticode API exposes its certificate. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep development dispatcher files out of the signed production tree and normalize signed release probes to the repository's CRLF release contract before strict AllSigned validation. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Deliverable
Add a runnable Windows local-AI development scenario plus independent vendor/runtime flows:
This supersedes closed #98. That PR targeted #93's feature branch; #93 has since merged into
mainand its branch was deleted. This branch was rebuilt onto currentmainand preserves the final AI implementation and physical validation.Non-goals
Scenario and exact commands
Recommended product-level run through the protected Windows Dev Config bootstrap:
For this unsigned PR branch before the sign cycle:
The dispatcher downloads, verifies, protects, and copies the complete Workloads
tree plus shared Windows Dev Config helper steps. Microsoft-signed PowerShell
authenticates a content-hash manifest for every catalog/Python/C++/CUDA/config
input, and bootstrap reverifies the protected copy before launch. It elevates
the apply run and launches only the local-AI scenario—not the full workstation
setup. Unsigned branch tests use
%ProgramData%\CalmOS-Development; theproduction signed
%ProgramData%\CalmOSpayload remains isolated.Repository-level equivalent:
.\Workloads\local-ai\install.ps1Expected sentinels include:
Select one optional runtime when needed:
Product-level plan/runtime examples:
Dependency graph and transitive acquisition
Drivers are prerequisites and are never replaced.
local-ailocal-ai -Runtime LlamaCpplocal-ai -Runtime Ollamalocal-ai -Runtime Foundrypytorchcudarocmintel-aillama.cppollama%LOCALAPPDATA%\Programs\Ollama, never emulates the x64 setup EXE or selects a portable WinGet payload, and preserves models by default on uninstall.foundryStandalone native-development flows remain available:
Quick local-model validation uses small Qwen models and real inference. An optional coding demonstration stays out of the default install:
It downloads the pinned Apache-2.0 Qwen2.5-Coder-1.5B-Instruct Q4_K_M GGUF (1,117,320,768 bytes, immutable revision and SHA-256), generates a Python
group_anagramsimplementation, and emitsCODING_DEMO_READY.Acquisition behavior
triton-windows==3.8.0.post28community-stable buildtriton-xpu==3.8.0Stable-channel status
Nvidia.CUDA39af79e5e136c4e0de03bba816bda60fd7b70aad033e37ecaacf9f2e2c982442, 3,711,598,920 bytescu126/cu130indexes2.15.0.dev...+cu134wheelnvtorch_oottorch 2.14.0 + torchvision 0.29.0 + torchaudio 2.11.0triton-windows==3.8.0.post28torch.compileon Intel GPUMicrosoft.FoundryLocal0.10.3Ollama.Ollamaollama-windows-arm64.zip, converted into a managed Dev Config applicationArtifact existence is not sufficient for promotion. Candidate metadata, hashes, triggers, and tracking state are centralized in
src/Workloads/_common/ai-catalog.psd1, so promotion remains a resolver/data change after real workload qualification.Hardware and backend coverage
Same-vendor adapter targeting uses CUDA/ROCm/explicit PyTorch
-DeviceIndex, llama.cpp-Device, OpenVINO-OpenVinoDeviceId, or oneAPI-SyclDeviceSelector.Real hardware evidence
NVIDIA RTX Spark N1X, Windows ARM64
2.15.0.dev20260904+cu134, NumPy 2.5.2: CUDA tensor and minimal neural model forward on the N1X.triton-windows 3.8.0.post28: JIT vector-add kernel.gpu_info,backends=CUDA, 29/29 actual layers offloaded, real Qwen inference.CPUExecutionProviderfallback on the tested catalog/runtime.ollama-windows-arm64.zipinstalled under%LOCALAPPDATA%\Programs\Ollama; native ARM64 PE, release digestb49aa49306da9bae5b7498f320f76bd2a13739c3105bcb6e115a26f0dfd10d67, install manifest, PATH/HKCU startup, persistent127.0.0.1:11434endpoint, verified qwen3:0.6b digest, real inference, and/api/ps100% GPU. Idempotent rerun returnedalready-current; model-preserving uninstall and reinstall passed.Qualcomm Adreno X1-85, Windows ARM64
result.ready=true, 29/29 layers offloaded, real Qwen inference.result.ready=true,WebGPUExecutionProvider, selected GPU, no fallback.Partner hardware remains pending for NVIDIA x64, AMD x64, and Intel x64 GPU/NPU.
Signed production and AllSigned testing
RemoteSigned, matching currentmain.src/tests/ai-common/all-signed.ps1proves unsignedsrc/entry points are rejected underAllSignedand valid Microsoft-signed release workloads load in Windows PowerShell 5.1 and PowerShell 7 with per-process publisher consent.-PlanOnlyentry point in both hosts.src/explicitly follow the documented temporaryCurrentUser Bypassprocedure and restore the prior policy afterward.Validation
bootstrap.ps1 -Scenario local-ai -AllowUnsigned -PlanOnlypath completed through UAC, protected copy, content verification, and child routing with no blockers (using the documented temporaryCurrentUserBypass in both PowerShell hosts, then restoring it).git diff --checkpassed.Remaining gaps