Fail closed on unknown Kokoro TTS runtime hashes - #55
Draft
Blackspirits wants to merge 2 commits into
Draft
Blackspirits wants to merge 2 commits into
Blackspirits wants to merge 2 commits into
Conversation
Owner
Author
|
Independent adversarial re-check on current upstream base: confirmed all four Kokoro TTS runtime hashes against the official |
This was referenced Sep 12, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The Kokoro TTS runtime archive is already checked against
DownloadHashManager, but its integrity helper currently returns without verification when the platform key/digest cannot be resolved or when the stream is empty. That can turn a future resolver/registry mismatch into an unauthenticated unpack.This change:
Validation
sha256:asset digests published by the officialniksedk/kokoro.cppreleasev0.1.2; all four matchBase is upstream
9be10e12d0f04655f2f134718b00679f89b2b15f.This PR supersedes internal draft #46.
AI assistance: ChatGPT was used to independently re-audit the Kokoro TTS runtime integrity/unpack path on current upstream, compare current registry hashes with official release asset digests, strengthen fail-closed verification, and add regression coverage.