Repository navigation
Pin LAME downloads to SHA-256, with a reviewed pin list that follows upstream - #11
Merged
Merged
Conversation
…erified cached binaries The MP3 fallback downloaded an encoder and ran it with no integrity check beyond "--version prints something". - Each built-in source now carries the SHA-256 of the exact archive. A download that does not match is deleted before anything is extracted or run, and a source with no hash is refused. - Homebrew bottles are fetched directly by their pinned digest instead of resolving a mutable tag through two manifests. - AUTOMIX_LAME_DOWNLOAD_URL and AUTOMIX_LAME_VERSION now require AUTOMIX_LAME_DOWNLOAD_SHA256. - The cached binary is used only when a marker written by a verified install still matches it, so binaries cached before this change are downloaded again. - Windows on ARM uses the x64 build; its previous URL returns 404. Debian and Homebrew hashes come from their published indexes. rarewares.org publishes none, so the two Windows pins are the files as served on 2026-10-05. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…in list Fixed pins alone break the MP3 fallback when an upstream replaces a file (Debian stable has already moved to 3.100-6+b3 and Homebrew to LAME 4.0). - assets/lame-pins.json is the current pin list. The app reads it from master before downloading and tries those sources first; the built-in pins remain as the fallback when the list is unreachable, invalid, or names a build that does not run on the machine. - The list may only name files under the known rarewares.org and Debian locations, or a Homebrew bottle digest. One bad entry rejects the list. - tools/update_lame_pins.py regenerates the list from Debian's package index, the Homebrew bottle index and the rarewares.org files. - A weekly workflow runs it and opens a pull request when pins change. It is not merged automatically. - AUTOMIX_LAME_SKIP_PIN_UPDATE=1 keeps the app on the built-in pins. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…Linux bottle sources The app copies just bin/lame out of a Homebrew bottle. Checked against the real bottles and on an Apple-silicon Mac: - 3.100 macOS bottles link only system libraries and run. - 4.0 macOS bottles need Homebrew's libmpg123 and fail to launch, so publishing them only added a wasted download before the fallback. - Linux bottles of both versions use a Homebrew placeholder as their loader path and can never run, so the built-in Linux bottle sources were dead and are removed. Linux uses the Debian package. The updater now downloads each candidate bottle, checks it against its digest and skips it when the encoder still points at a Homebrew path. A platform with no usable bottle is left out of the published list and the app uses its built-in pin. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…lame-hash-pin # Conflicts: # CMakeLists.txt
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
The MP3 fallback downloads a LAME encoder and runs it. Until now the only check was that
lame --versionprinted something.Pinning (
a07d5dd)AUTOMIX_LAME_DOWNLOAD_URLandAUTOMIX_LAME_VERSIONnow requireAUTOMIX_LAME_DOWNLOAD_SHA256.Pins that follow upstream
assets/lame-pins.jsonis the current pin list. The app reads it frommasterbefore downloading and tries those sources first. The built-in pins stay as the fallback.tools/update_lame_pins.pyregenerates the list;.github/workflows/lame_pins.ymlruns it weekly and opens a pull request when pins change. Nothing is merged automatically.AUTOMIX_LAME_SKIP_PIN_UPDATE=1keeps the app on the built-in pins.Reviewer notes
masterdoes not compile with native ONNX enabled until Tensor inference, opt-in vocal separation, GPU runtime, and cross-platform CI #9 lands, so this branch is based onfeat/tensor-inference.mastercan change which file is accepted, within the allowed hosts. That is why the workflow opens a pull request instead of committing.3.100-6+b3and Homebrew at LAME 4.0, whose macOS bottles start at macOS 14. Older Macs fall back to the built-in 3.100 bottles when the 4.0 one fails its--versioncheck.master, which 404s until this is merged there.Tests
ctest -C Release: 100% passed out of 267; the two known tensor-probe tests skip. Four new tests cover pin validity, the checked-in list, rejection of redirecting lists, and mismatch handling. Repo and workflow hygiene checks pass.🤖 Generated with Claude Code