Skip to content

Pin LAME downloads to SHA-256, with a reviewed pin list that follows upstream - #11

Merged
soficis merged 4 commits into
feat/tensor-inferencefrom
fix/lame-hash-pin
Oct 5, 2026
Merged

soficis merged 4 commits into
feat/tensor-inferencefrom
fix/lame-hash-pin

Conversation

@soficis

@soficis soficis commented Oct 5, 2026

Copy link
Copy Markdown
Owner

What changed

The MP3 fallback downloads a LAME encoder and runs it. Until now the only check was that lame --version printed something.

Pinning (a07d5dd)

  • Every built-in source carries the SHA-256 of the exact archive. A mismatch deletes the download before anything is extracted or run; a source with no hash is refused.
  • Homebrew bottles are fetched directly by pinned digest, replacing two manifest lookups through a mutable tag.
  • The cached encoder is used only when a marker written by a verified install still matches it, so encoders cached before this change are downloaded again once.
  • AUTOMIX_LAME_DOWNLOAD_URL and AUTOMIX_LAME_VERSION now require AUTOMIX_LAME_DOWNLOAD_SHA256.
  • Windows on ARM uses the x64 build; its previous URL returns 404.

Pins that follow upstream

  • assets/lame-pins.json is the current pin list. The app reads it from master before downloading and tries those sources first. The built-in pins stay as the fallback.
  • The list can only name files under the known rarewares.org and Debian paths, or a Homebrew bottle digest. One bad entry rejects the whole list.
  • tools/update_lame_pins.py regenerates the list; .github/workflows/lame_pins.yml runs it weekly and opens a pull request when pins change. Nothing is merged automatically.
  • AUTOMIX_LAME_SKIP_PIN_UPDATE=1 keeps the app on the built-in pins.

Reviewer notes

  • Stacked on Tensor inference, opt-in vocal separation, GPU runtime, and cross-platform CI #9. master does not compile with native ONNX enabled until Tensor inference, opt-in vocal separation, GPU runtime, and cross-platform CI #9 lands, so this branch is based on feat/tensor-inference.
  • The repo becomes a runtime trust root for the encoder. Whoever can merge to master can change which file is accepted, within the allowed hosts. That is why the workflow opens a pull request instead of committing.
  • Windows pins have no independent source. rarewares.org publishes no hashes; the two pins are the files as served on 2026-10-05, and the updater can only re-hash the same URLs. A new Windows build needs a manual URL change.
  • The published list already differs from the built-in pins: Debian stable is at 3.100-6+b3 and Homebrew at LAME 4.0, whose macOS bottles start at macOS 14. Older Macs fall back to the built-in 3.100 bottles when the 4.0 one fails its --version check.
  • Not exercised: a real end-to-end download in the app, the workflow itself (it needs "Allow GitHub Actions to create pull requests" enabled in repo settings), and the fetch of the list from master, which 404s until this is merged there.

Tests

ctest -C Release: 100% passed out of 267; the two known tensor-probe tests skip. Four new tests cover pin validity, the checked-in list, rejection of redirecting lists, and mismatch handling. Repo and workflow hygiene checks pass.

🤖 Generated with Claude Code

soficis and others added 4 commits October 5, 2026 17:12
…erified cached binaries

The MP3 fallback downloaded an encoder and ran it with no integrity check
beyond "--version prints something".

- Each built-in source now carries the SHA-256 of the exact archive. A
  download that does not match is deleted before anything is extracted
  or run, and a source with no hash is refused.
- Homebrew bottles are fetched directly by their pinned digest instead of
  resolving a mutable tag through two manifests.
- AUTOMIX_LAME_DOWNLOAD_URL and AUTOMIX_LAME_VERSION now require
  AUTOMIX_LAME_DOWNLOAD_SHA256.
- The cached binary is used only when a marker written by a verified
  install still matches it, so binaries cached before this change are
  downloaded again.
- Windows on ARM uses the x64 build; its previous URL returns 404.

Debian and Homebrew hashes come from their published indexes. rarewares.org
publishes none, so the two Windows pins are the files as served on
2026-10-05.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…in list

Fixed pins alone break the MP3 fallback when an upstream replaces a file
(Debian stable has already moved to 3.100-6+b3 and Homebrew to LAME 4.0).

- assets/lame-pins.json is the current pin list. The app reads it from
  master before downloading and tries those sources first; the built-in
  pins remain as the fallback when the list is unreachable, invalid, or
  names a build that does not run on the machine.
- The list may only name files under the known rarewares.org and Debian
  locations, or a Homebrew bottle digest. One bad entry rejects the list.
- tools/update_lame_pins.py regenerates the list from Debian's package
  index, the Homebrew bottle index and the rarewares.org files.
- A weekly workflow runs it and opens a pull request when pins change.
  It is not merged automatically.
- AUTOMIX_LAME_SKIP_PIN_UPDATE=1 keeps the app on the built-in pins.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…Linux bottle sources

The app copies just bin/lame out of a Homebrew bottle. Checked against the
real bottles and on an Apple-silicon Mac:

- 3.100 macOS bottles link only system libraries and run.
- 4.0 macOS bottles need Homebrew's libmpg123 and fail to launch, so
  publishing them only added a wasted download before the fallback.
- Linux bottles of both versions use a Homebrew placeholder as their
  loader path and can never run, so the built-in Linux bottle sources
  were dead and are removed. Linux uses the Debian package.

The updater now downloads each candidate bottle, checks it against its
digest and skips it when the encoder still points at a Homebrew path. A
platform with no usable bottle is left out of the published list and the
app uses its built-in pin.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@soficis
soficis merged commit fa83a97 into feat/tensor-inference Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant