OPENNLP-1612 - DownloadUtil should validate checksum on download#658
Merged
mawiesne merged 1 commit intoapache:mainfrom Oct 7, 2024
Merged
OPENNLP-1612 - DownloadUtil should validate checksum on download#658mawiesne merged 1 commit intoapache:mainfrom
mawiesne merged 1 commit intoapache:mainfrom
Conversation
kinow
approved these changes
Oct 3, 2024
mawiesne
approved these changes
Oct 5, 2024
mawiesne
reviewed
Oct 5, 2024
| // Validate SHA512 checksum | ||
| final String actualChecksum = calculateSHA512(downloadedModel); | ||
| if (!actualChecksum.equalsIgnoreCase(expectedChecksum)) { | ||
| throw new IOException("SHA512 checksum validation failed. Expected: " |
Contributor
There was a problem hiding this comment.
Idea:
Could instead throw a more specific exception (type) here to indicate a validation step has failed. Might be helpful for the caller to decide if a retry of the download shall be attempted or not.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Thank you for contributing to Apache OpenNLP.
In order to streamline the review of the contribution we ask you
to ensure the following steps have been taken:
For all changes:
Is there a JIRA ticket associated with this PR? Is it referenced
in the commit message?
Does your PR title start with OPENNLP-XXXX where XXXX is the JIRA number you are trying to resolve? Pay particular attention to the hyphen "-" character.
Has your PR been rebased against the latest commit within the target branch (typically main)?
Is your initial contribution a single, squashed commit?
For code changes:
For documentation related changes:
Note:
Might help to identify issues with broken file downloads during EvalTests in #69