| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-09-13 | 1.4 kB | |
| v6.1.2 source code.tar.gz | 2026-09-13 | 12.2 MB | |
| v6.1.2 source code.zip | 2026-09-13 | 15.1 MB | |
| Totals: 3 Items | 27.3 MB | 0 | |
Hotfix: D02 download-integrity regression from v6.1.1
An independent review of v6.1.1 found that the D02 download-integrity fix shipped in that release had a second, exploitable fail-open path: a previously-recorded empty identity sidecar (written when a server gives no ETag/Last-Modified) was incorrectly treated as matching a current response that also lacks an identity header. For any server that never sends those headers, this meant every resume attempt could still splice mismatched bytes into a "completed" download — the exact class of bug the original D02 fix was meant to close.
Impact: if you downloaded or resumed a curated model download under v6.1.1 against a server without ETag/Last-Modified support, re-verify or re-download that file under v6.1.2.
Fix: a resume is now only trusted when both sides report a real, non-empty, matching identity. A server that never provides any identity header can no longer use the resume optimization at all — every such resume now discards and restarts from scratch. This is the correct tradeoff until real per-file digest verification (a separate, larger gap — most curated models have no pinned SHA256 today) closes it independently of server-provided headers.
See PR [#2170] for the full writeup and reproduction.
Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com