fix(fetch): validate remote metadata before resumed publication - #24
Open
DivyamTalwar wants to merge 1 commit into
Open
DivyamTalwar wants to merge 1 commit into
DivyamTalwar wants to merge 1 commit into
Conversation
Address FedericoTs#23 with focused regression coverage. AI-assisted implementation and isolated source review; exact validation and remaining platform limitations are recorded in the draft PR. Signed-off-by: Divyam Talwar <divyamtalwar0@gmail.com>
DivyamTalwar
marked this pull request as ready for review
September 19, 2026 22:01
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #23.
Validate successful positive HEAD metadata before it can drive length decisions, and check resumed Content-Range and actual response length before accepting bytes. Invalid range bodies preserve the known prefix. Forced requests validate metadata before deletion. Existing unforced files retain the previous presence fallback on unavailable metadata, but are explicitly labelled NOT VERIFIED instead of being certified complete.
Testing
Base:
252e5193902d466726da9af75047dfffff2ae662. Debian 12 Linux aarch64 in a nonroot disposable container, Python 3.11. The full existing smoke exits 0 with eight explicitly reported pre-existing optional research/hardware skips. It also prints baseline diagnostic skips where simulator/research dependencies are absent; no skipped check is counted as a pass. No Windows run or GPU/real-model benchmark is claimed.The same final test files fail against unchanged production; the corrected branch gives:
python tests/smoke.py ruff check quantprobe ruff format --check quantprobe # Bandit medium-severity checks on changed package modules git diff --checkAll applicable commands above exited 0 locally. The snapshot is a complete upstream checkout plus this branch's exact changed-file bytes; no test is a copied production-function reimplementation. External I/O is mocked where stated. Dependencies and lockfiles are unchanged.
Security And Data Access
No credential, production-data, authentication, read-only guardrail or privileged workflow changes are included. Tests use synthetic inputs and disposable paths. No new benchmark, fitted law, or hardware capability is claimed.
Notes
Byte-range and size checks are not content authentication, digest verification or ETag continuity. Existing unforced cached files remain usable offline without being declared verified; new downloads and partial promotion require valid metadata. Oversized old partials are left intact with a recovery message. Forced-refresh preservation, total request budgeting and missing-parent support remain separate contributions. The standalone weights/hf_fetch.py is unchanged.
AI-assisted implementation, isolated same-provider source review, and controller regression checks are disclosed. They are not maintainer approval, cross-vendor certification, or hosted CI. One focused, signed-off commit; no generated logs, personal config, model weights or worktree state is included.
Draft pending upstream CI and maintainer review. Companion changes touching the same module/test hook may require rebasing as they land; no combined branch is being submitted.