LLAP v0.0.158
LLAP 0.0.158
Install
(
set -euo pipefail
install_dir="$(mktemp -d)"
verified_dir=""
cleanup_install() {
local status=$?
trap - EXIT
exec 3<&- 4<&- 5<&- 6<&- 7<&- 8<&- 9<&- 10<&- 11<&- 12<&-
rm -rf "$install_dir"
[[ -z "$verified_dir" ]] || rm -rf "$verified_dir"
return "$status"
}
trap cleanup_install EXIT
base_url="https://github.com/LLM-API-Proxy/llap/releases/download/v0.0.158"
command -v gpg >/dev/null 2>&1 || {
printf '%s\n' 'Install GnuPG first (macOS: brew install gnupg; Linux: use your package manager).' >&2
exit 1
}
if ! command -v sha256sum >/dev/null 2>&1 \
&& ! command -v shasum >/dev/null 2>&1; then
printf '%s\n' 'sha256sum or shasum is required.' >&2
exit 1
fi
command -v cp >/dev/null 2>&1 || { printf '%s\n' 'cp is required.' >&2; exit 1; }
command -v cmp >/dev/null 2>&1 || { printf '%s\n' 'cmp is required.' >&2; exit 1; }
[[ -r /dev/fd/0 ]] || { printf '%s\n' '/dev/fd is required.' >&2; exit 1; }
hash_file() {
if command -v sha256sum >/dev/null 2>&1; then
sha256sum -- "$1" | awk '{ print $1 }'
else
shasum -a 256 -- "$1" | awk '{ print $1 }'
fi
}
assert_verified_bundle_unchanged() {
[[ "${verified_dir}/install.sh" -ef /dev/fd/7 \
&& "${verified_dir}/install.sh" -ef /dev/fd/8 \
&& "${verified_dir}/install.sh" -ef /dev/fd/9 ]] || {
printf '%s\n' 'Captured installer identity changed during verification.' >&2
exit 1
}
[[ "$(hash_file "${verified_dir}/install.sh")" == "$captured_installer_hash" \
&& "$(hash_file "${verified_dir}/SHA256SUMS")" == "$captured_checksums_hash" \
&& "$(hash_file "${verified_dir}/SHA256SUMS.sig")" == "$captured_signature_hash" \
&& "$(hash_file "${verified_dir}/release-signing.pub.asc")" == "$captured_key_hash" ]] || {
printf '%s\n' 'Captured installer bundle changed during verification.' >&2
exit 1
}
for artifact in install.sh SHA256SUMS SHA256SUMS.sig release-signing.pub.asc; do
cmp -s "${install_dir}/${artifact}" "${verified_dir}/${artifact}" || {
printf '%s\n' "${artifact} changed during verification." >&2
exit 1
}
done
}
for artifact in install.sh SHA256SUMS SHA256SUMS.sig release-signing.pub.asc; do
curl --disable -fsSL "${base_url}/${artifact}" -o "${install_dir}/${artifact}"
done
verified_dir="$(mktemp -d)"
exec 3< "${install_dir}/install.sh"
exec 4< "${install_dir}/SHA256SUMS"
exec 5< "${install_dir}/SHA256SUMS.sig"
exec 6< "${install_dir}/release-signing.pub.asc"
cp /dev/fd/3 "${verified_dir}/install.sh"
cp /dev/fd/4 "${verified_dir}/SHA256SUMS"
cp /dev/fd/5 "${verified_dir}/SHA256SUMS.sig"
cp /dev/fd/6 "${verified_dir}/release-signing.pub.asc"
exec 3<&- 4<&- 5<&- 6<&-
captured_installer_hash="$(hash_file "${verified_dir}/install.sh")"
captured_checksums_hash="$(hash_file "${verified_dir}/SHA256SUMS")"
captured_signature_hash="$(hash_file "${verified_dir}/SHA256SUMS.sig")"
captured_key_hash="$(hash_file "${verified_dir}/release-signing.pub.asc")"
exec 7< "${verified_dir}/install.sh"
exec 8< "${verified_dir}/install.sh"
exec 9< "${verified_dir}/install.sh"
exec 10< "${verified_dir}/SHA256SUMS"
exec 11< "${verified_dir}/SHA256SUMS"
exec 12< "${verified_dir}/SHA256SUMS.sig"
release_fingerprint="4F2BBCD92F7AEC826BF4C156D6443D2B4B6AB71F"
actual_fingerprint="$(
gpg --batch --no-autostart --show-keys --with-colons \
"${verified_dir}/release-signing.pub.asc" 2>/dev/null \
| awk -F: '$1 == "fpr" { print toupper($10); exit }'
)"
[[ "$actual_fingerprint" == "$release_fingerprint" ]]
gpg_home="${verified_dir}/gnupg"
mkdir -m 0700 "$gpg_home"
printf 'no-autostart\n' > "${gpg_home}/common.conf"
gpg --batch --no-autostart --homedir "$gpg_home" \
--import "${verified_dir}/release-signing.pub.asc" >/dev/null
signature_status="$(
gpg --batch --no-autostart --homedir "$gpg_home" --status-fd 1 \
--verify /dev/fd/12 /dev/fd/10 \
2>/dev/null
)"
valid_fingerprint="$(awk '$1 == "[GNUPG:]" && $2 == "VALIDSIG" { print toupper($3); exit }' <<< "$signature_status")"
primary_fingerprint="$(awk '$1 == "[GNUPG:]" && $2 == "VALIDSIG" { print toupper($NF); exit }' <<< "$signature_status")"
[[ "$valid_fingerprint" == "$release_fingerprint" || "$primary_fingerprint" == "$release_fingerprint" ]]
checksum_record="$(awk 'NF == 2 && $2 == "install.sh" { count++; hash = $1 } END { print count + 0, hash }' /dev/fd/11)"
entry_count="${checksum_record%% *}"
expected_hash="${checksum_record#* }"
[[ "$entry_count" == "1" && "$expected_hash" =~ ^[[:xdigit:]]{64}$ ]]
actual_hash="$(hash_file /dev/fd/7)"
[[ "$(printf '%s' "$actual_hash" | tr 'A-F' 'a-f')" == \
"$(printf '%s' "$expected_hash" | tr 'A-F' 'a-f')" ]]
assert_verified_bundle_unchanged
if [[ $EUID -ne 0 ]]; then
command -v sudo >/dev/null 2>&1 || {
printf '%s\n' 'sudo is required for a non-root installation.' >&2
exit 1
}
printf '%s\n' 'Installer verified. Authenticating for privileged installation...'
sudo -v || {
printf '%s\n' 'Privilege authentication failed; installer was not executed.' >&2
exit 1
}
# Authentication can prompt and yield control. Recheck every mutable path and
# the captured installer inode before executing the already-verified FDs.
assert_verified_bundle_unchanged
fi
exec 7<&- 10<&- 11<&- 12<&-
rm -rf "$verified_dir"
verified_dir=""
installer_status=0
SCRIPT_PATH=/dev/fd/9 bash /dev/fd/8 || installer_status=$?
exec 8<&- 9<&-
exit "$installer_status"
)CLI Binaries
| Platform | Download |
|---|---|
| Linux amd64 | llap-linux-amd64 |
| Linux arm64 | llap-linux-arm64 |
| macOS amd64 | llap-darwin-amd64 |
| macOS arm64 | llap-darwin-arm64 |
Container Images
docker pull ghcr.io/llm-api-proxy/server:0.0.158Published from core@1a569c568dc4b99566cf6962ce4a9f12e223d418.