Download verify_release.py from Voltline/vimeml-tiny-ja-v2.1: direct link, hf CLI and curl.
- Browser
- Download file 3 kB
-
https://huggingface.co/Voltline/vimeml-tiny-ja-v2.1/resolve/main/verify_release.py
- Command line
-
hf download hf://Voltline/vimeml-tiny-ja-v2.1/verify_release.py
-
curl -L -o verify_release.py https://huggingface.co/Voltline/vimeml-tiny-ja-v2.1/resolve/main/verify_release.py
3 kB
| """Verify the release inventory; optionally check file SHA256 digests.""" | |
| import argparse | |
| import hashlib | |
| import json | |
| from pathlib import Path, PurePosixPath | |
| def sha(path): | |
| with Path(path).open("rb") as stream: | |
| return hashlib.file_digest(stream, "sha256").hexdigest() | |
| def safe_path(root, name): | |
| relative = PurePosixPath(name) | |
| if (not name or "\\" in name or relative.is_absolute() | |
| or any(part in {".", ".."} for part in name.split("/"))): | |
| raise ValueError(f"Invalid release path: {name}") | |
| result = root.joinpath(*relative.parts) | |
| if not result.resolve().is_relative_to(root.resolve()) or result.is_symlink(): | |
| raise ValueError(f"Unsafe release path: {name}") | |
| return result | |
| def verify(directory, hashes=False): | |
| root = Path(directory).resolve() | |
| manifest = json.loads((root / "RELEASE.json").read_text(encoding="utf-8")) | |
| if manifest.get("format") != "vimeml_hf_release_v1" or manifest.get("license") != "gpl-2.0": | |
| raise ValueError("Unsupported release format or license.") | |
| sums = {} | |
| for line in (root / "SHA256SUMS.txt").read_text(encoding="utf-8").splitlines(): | |
| digest, name = line.split(" ", 1) | |
| if len(digest) != 64 or any(c not in "0123456789abcdef" for c in digest) or name in sums: | |
| raise ValueError("Invalid checksum entry.") | |
| sums[name] = digest | |
| if set(sums) != set(manifest["files"]) | {"RELEASE.json"}: | |
| raise ValueError("Checksum inventory differs from RELEASE.json.") | |
| for name, digest in sums.items(): | |
| path = safe_path(root, name) | |
| if not path.is_file(): | |
| raise ValueError(f"Missing release file: {name}") | |
| if name != "RELEASE.json": | |
| entry = manifest["files"][name] | |
| if entry["bytes"] != path.stat().st_size or entry["sha256"] != digest: | |
| raise ValueError(f"Release inventory mismatch: {name}") | |
| if hashes and sha(path) != digest: | |
| raise ValueError(f"Release checksum mismatch: {name}") | |
| expected = set(sums) | {"SHA256SUMS.txt"} | |
| actual = {p.relative_to(root).as_posix() for p in root.rglob("*") if p.is_file() | |
| and ".cache" not in p.relative_to(root).parts | |
| and "__pycache__" not in p.relative_to(root).parts | |
| and p.suffix != ".pyc" and p.relative_to(root).as_posix() != ".gitattributes"} | |
| if actual != expected: | |
| raise ValueError("Unexpected release file inventory.") | |
| return manifest, sorted(expected) | |
| def main(): | |
| parser = argparse.ArgumentParser(description=__doc__) | |
| parser.add_argument("--release", type=Path, default=Path(__file__).resolve().parent) | |
| parser.add_argument("--hashes", action="store_true", help="Also read and hash every payload file.") | |
| args = parser.parse_args() | |
| manifest, files = verify(args.release, hashes=args.hashes) | |
| print(f"Verified {len(files)} files: {manifest['repo_id']} / source {manifest['source_commit']}") | |
| if __name__ == "__main__": | |
| main() | |