feat(models): add pinned backend manifests and offline verification

This commit is contained in:
baketnk committed 2026-09-24 22:16:13 -04:00
1 parent 07c03ea27e
commit 5cbbda3ec2
8 files changed
+589 -53

No files matched your search

+20 -20
View File
@@ -1,7 +1,6 @@
#!/usr/bin/env python3
"""Explicit setup only: fetch the pinned ~178 MB Redux weights; never used by runtime."""
import argparse
import hashlib
import os
from pathlib import Path
import sys
@@ -9,14 +8,7 @@ import tempfile
import urllib.request
sys.path.insert(0, str(Path(__file__).resolve().parents[1] / "python"))
from frameyap.model_files import FILES, REVISION
def matches(path, size, digest):
if not path.is_file() or path.is_symlink() or path.stat().st_size != size:
return False
with path.open("rb") as stream:
return hashlib.file_digest(stream, "sha256").hexdigest() == digest
from frameyap.model_files import check_file, check_model, load_backends
def main():
@@ -26,30 +18,38 @@ def main():
dest = args.destination.expanduser().absolute()
if dest.is_symlink():
parser.error("destination must not be a symlink")
backend = load_backends()["redux"]
dest.mkdir(mode=0o700, parents=True, exist_ok=True)
for name, (size, digest) in FILES.items():
target = dest / name
if matches(target, size, digest):
for item in backend.files:
target = dest / item.path
reason, _ = check_file(dest, item)
if reason is None:
continue
if target.exists() or target.is_symlink():
parser.error(f"existing mismatched file: {target}; move it aside explicitly")
url = f"https://huggingface.co/moondream/parakeet-redux/resolve/{REVISION}/{name}"
if reason != "missing_files":
parser.error(f"existing mismatched or unsafe file: {target}; move it aside explicitly")
# This explicit Redux-only tool does not implement a generic model downloader.
url = f"{backend.source}/resolve/{backend.revision}/{item.path}"
fd, temp = tempfile.mkstemp(prefix=".download-", dir=dest)
try:
with os.fdopen(fd, "wb") as output, urllib.request.urlopen(url, timeout=60) as source:
total = 0
while chunk := source.read(1024 * 1024):
total += len(chunk)
if total > size:
if total > item.size:
raise ValueError("download exceeded pinned size")
output.write(chunk)
if not matches(Path(temp), size, digest):
raise ValueError(f"pinned SHA-256/size mismatch: {name}")
if check_file(dest, item)[0] != "missing_files":
parser.error(f"destination changed during download: {target}")
# Check the temporary file using the same pinned verifier before install.
if check_file(dest, type(item)(Path(temp).name, item.size, item.sha256))[0] is not None:
raise ValueError(f"pinned SHA-256/size mismatch: {item.path}")
os.replace(temp, target)
finally:
Path(temp).unlink(missing_ok=True)
print(f"Pinned Redux {REVISION} verified in {dest}")
print("Model attribution: moondream/parakeet-redux, CC-BY-4.0; see downloaded README.md.")
if check_model(backend, dest)["state"] != "installed_verified":
raise ValueError("pinned model verification failed")
print(f"Pinned Redux {backend.revision} verified in {dest}")
print(f"Model attribution: {backend.attribution} License: {backend.license_id}.")
if __name__ == "__main__":