Harden local integrations and fix model downloads - #3
Draft
AdelEnazi1117 wants to merge 1 commit into
Draft
Conversation
AdelEnazi1117
force-pushed
the
security/harden-v0.3.0
branch
from
August 17, 2026 01:03
7042a85 to
d79ff71
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
This patch hardens Halen's local integration, plugin, logging, and release boundaries, and fixes the built-in model download failure reported by v0.3.0.
Why
/tmppath and mirror sensitive values. It now uses a private Application Support directory, descriptor-based no-follow file handling, mode0600, bounded in-place truncation, and redaction at sensitive call sites.mainbranch while enforcing the size and SHA-256 of older bytes. Gemmamainchanged, causing the exact size error in Settings and an eventual checksum failure. Both model URLs now use immutable commits while retaining exact size and SHA-256 validation.User impact
4,715,414,688bytes, SHA-256eb29c851...d52a2) and works independently of later upstreammainchanges.Verification
swift build --disable-keychain --disable-netrcbash -n scripts/*.shshellcheckon changed release scriptsscripts/test-release-verifiers.shgit diff --checkFull
swift testcould not run locally because this machine has Command Line Tools but not the full Xcode XCTest module. A clean local llama.xcframework rebuild is similarly Xcode-only; the source commit fetch/pin and deterministic verifier tests pass here, and CI should run the complete suite.