Skip to content

LLAP v0.0.158

Choose a tag to compare

@troykelly troykelly released this 06 Sep 18:10

LLAP 0.0.158

Install

(
set -euo pipefail
install_dir="$(mktemp -d)"
verified_dir=""
cleanup_install() {
  local status=$?
  trap - EXIT
  exec 3<&- 4<&- 5<&- 6<&- 7<&- 8<&- 9<&- 10<&- 11<&- 12<&-
  rm -rf "$install_dir"
  [[ -z "$verified_dir" ]] || rm -rf "$verified_dir"
  return "$status"
}
trap cleanup_install EXIT
base_url="https://github.com/LLM-API-Proxy/llap/releases/download/v0.0.158"
command -v gpg >/dev/null 2>&1 || {
  printf '%s\n' 'Install GnuPG first (macOS: brew install gnupg; Linux: use your package manager).' >&2
  exit 1
}
if ! command -v sha256sum >/dev/null 2>&1 \
  && ! command -v shasum >/dev/null 2>&1; then
  printf '%s\n' 'sha256sum or shasum is required.' >&2
  exit 1
fi
command -v cp >/dev/null 2>&1 || { printf '%s\n' 'cp is required.' >&2; exit 1; }
command -v cmp >/dev/null 2>&1 || { printf '%s\n' 'cmp is required.' >&2; exit 1; }
[[ -r /dev/fd/0 ]] || { printf '%s\n' '/dev/fd is required.' >&2; exit 1; }
hash_file() {
  if command -v sha256sum >/dev/null 2>&1; then
    sha256sum -- "$1" | awk '{ print $1 }'
  else
    shasum -a 256 -- "$1" | awk '{ print $1 }'
  fi
}
assert_verified_bundle_unchanged() {
  [[ "${verified_dir}/install.sh" -ef /dev/fd/7 \
    && "${verified_dir}/install.sh" -ef /dev/fd/8 \
    && "${verified_dir}/install.sh" -ef /dev/fd/9 ]] || {
    printf '%s\n' 'Captured installer identity changed during verification.' >&2
    exit 1
  }
  [[ "$(hash_file "${verified_dir}/install.sh")" == "$captured_installer_hash" \
    && "$(hash_file "${verified_dir}/SHA256SUMS")" == "$captured_checksums_hash" \
    && "$(hash_file "${verified_dir}/SHA256SUMS.sig")" == "$captured_signature_hash" \
    && "$(hash_file "${verified_dir}/release-signing.pub.asc")" == "$captured_key_hash" ]] || {
    printf '%s\n' 'Captured installer bundle changed during verification.' >&2
    exit 1
  }
  for artifact in install.sh SHA256SUMS SHA256SUMS.sig release-signing.pub.asc; do
    cmp -s "${install_dir}/${artifact}" "${verified_dir}/${artifact}" || {
      printf '%s\n' "${artifact} changed during verification." >&2
      exit 1
    }
  done
}
for artifact in install.sh SHA256SUMS SHA256SUMS.sig release-signing.pub.asc; do
  curl --disable -fsSL "${base_url}/${artifact}" -o "${install_dir}/${artifact}"
done

verified_dir="$(mktemp -d)"
exec 3< "${install_dir}/install.sh"
exec 4< "${install_dir}/SHA256SUMS"
exec 5< "${install_dir}/SHA256SUMS.sig"
exec 6< "${install_dir}/release-signing.pub.asc"
cp /dev/fd/3 "${verified_dir}/install.sh"
cp /dev/fd/4 "${verified_dir}/SHA256SUMS"
cp /dev/fd/5 "${verified_dir}/SHA256SUMS.sig"
cp /dev/fd/6 "${verified_dir}/release-signing.pub.asc"
exec 3<&- 4<&- 5<&- 6<&-
captured_installer_hash="$(hash_file "${verified_dir}/install.sh")"
captured_checksums_hash="$(hash_file "${verified_dir}/SHA256SUMS")"
captured_signature_hash="$(hash_file "${verified_dir}/SHA256SUMS.sig")"
captured_key_hash="$(hash_file "${verified_dir}/release-signing.pub.asc")"
exec 7< "${verified_dir}/install.sh"
exec 8< "${verified_dir}/install.sh"
exec 9< "${verified_dir}/install.sh"
exec 10< "${verified_dir}/SHA256SUMS"
exec 11< "${verified_dir}/SHA256SUMS"
exec 12< "${verified_dir}/SHA256SUMS.sig"

release_fingerprint="4F2BBCD92F7AEC826BF4C156D6443D2B4B6AB71F"
actual_fingerprint="$(
  gpg --batch --no-autostart --show-keys --with-colons \
    "${verified_dir}/release-signing.pub.asc" 2>/dev/null \
    | awk -F: '$1 == "fpr" { print toupper($10); exit }'
)"
[[ "$actual_fingerprint" == "$release_fingerprint" ]]

gpg_home="${verified_dir}/gnupg"
mkdir -m 0700 "$gpg_home"
printf 'no-autostart\n' > "${gpg_home}/common.conf"
gpg --batch --no-autostart --homedir "$gpg_home" \
  --import "${verified_dir}/release-signing.pub.asc" >/dev/null
signature_status="$(
  gpg --batch --no-autostart --homedir "$gpg_home" --status-fd 1 \
    --verify /dev/fd/12 /dev/fd/10 \
    2>/dev/null
)"
valid_fingerprint="$(awk '$1 == "[GNUPG:]" && $2 == "VALIDSIG" { print toupper($3); exit }' <<< "$signature_status")"
primary_fingerprint="$(awk '$1 == "[GNUPG:]" && $2 == "VALIDSIG" { print toupper($NF); exit }' <<< "$signature_status")"
[[ "$valid_fingerprint" == "$release_fingerprint" || "$primary_fingerprint" == "$release_fingerprint" ]]

checksum_record="$(awk 'NF == 2 && $2 == "install.sh" { count++; hash = $1 } END { print count + 0, hash }' /dev/fd/11)"
entry_count="${checksum_record%% *}"
expected_hash="${checksum_record#* }"
[[ "$entry_count" == "1" && "$expected_hash" =~ ^[[:xdigit:]]{64}$ ]]
actual_hash="$(hash_file /dev/fd/7)"
[[ "$(printf '%s' "$actual_hash" | tr 'A-F' 'a-f')" == \
  "$(printf '%s' "$expected_hash" | tr 'A-F' 'a-f')" ]]
assert_verified_bundle_unchanged

if [[ $EUID -ne 0 ]]; then
  command -v sudo >/dev/null 2>&1 || {
    printf '%s\n' 'sudo is required for a non-root installation.' >&2
    exit 1
  }
  printf '%s\n' 'Installer verified. Authenticating for privileged installation...'
  sudo -v || {
    printf '%s\n' 'Privilege authentication failed; installer was not executed.' >&2
    exit 1
  }
  # Authentication can prompt and yield control. Recheck every mutable path and
  # the captured installer inode before executing the already-verified FDs.
  assert_verified_bundle_unchanged
fi
exec 7<&- 10<&- 11<&- 12<&-
rm -rf "$verified_dir"
verified_dir=""
installer_status=0
SCRIPT_PATH=/dev/fd/9 bash /dev/fd/8 || installer_status=$?
exec 8<&- 9<&-
exit "$installer_status"
)

CLI Binaries

Platform Download
Linux amd64 llap-linux-amd64
Linux arm64 llap-linux-arm64
macOS amd64 llap-darwin-amd64
macOS arm64 llap-darwin-arm64

Container Images

docker pull ghcr.io/llm-api-proxy/server:0.0.158

Published from core@1a569c568dc4b99566cf6962ce4a9f12e223d418.