Skip to content

fix(hub): verify download integrity and atomically promote models (fixes #113) - #151

Merged
BerryUIKI merged 1 commit into
devfrom
bugfix/113-verify-download-integrity-and-atomic-promotion
Oct 4, 2026
Merged

BerryUIKI merged 1 commit into
devfrom
bugfix/113-verify-download-integrity-and-atomic-promotion

Conversation

@BerryUIKI

Copy link
Copy Markdown
Owner

Closes #113.

Changes

  • Validated \Content-Range\ headers upon resume to ensure server resumed from \existing_bytes; if incompatible or HTTP 200 returned, cleanly reset and redownload from byte 0.
  • Added pre-promotion expected size check against declared \model.size_bytes\ or server total.
  • Added SHA-256 integrity verification comparing downloaded chunked hash against \model.sha256.
  • Replaced destructive \ arget_path.unlink()\ with atomic \Path.replace()\ on the destination, preserving any prior file if verification or promotion fails.
  • Added regression tests covering size mismatch rejection, SHA-256 mismatch rejection, and atomic replacement preservation.

@BerryUIKI
BerryUIKI merged commit ae1c278 into dev Oct 4, 2026
3 checks passed
@BerryUIKI
BerryUIKI deleted the bugfix/113-verify-download-integrity-and-atomic-promotion branch October 5, 2026 19:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant