From e8cdade2c55fae41ff54722fb3134bf245ecfeba Mon Sep 17 00:00:00 2001 From: Tony Giorgio Date: Wed, 20 May 2026 16:24:43 -0500 Subject: [PATCH] Harden ONNX Runtime fetches --- .../scripts/build-ios-onnxruntime-all.sh | 38 ++++++++++-- .../scripts/build-ios-onnxruntime.sh | 61 ++++++++++--------- .../src-tauri/scripts/onnxruntime-pins.sh | 37 +++++++++++ .../scripts/provide-linux-onnxruntime.sh | 56 +++++++++++++++-- 4 files changed, 152 insertions(+), 40 deletions(-) create mode 100644 frontend/src-tauri/scripts/onnxruntime-pins.sh diff --git a/frontend/src-tauri/scripts/build-ios-onnxruntime-all.sh b/frontend/src-tauri/scripts/build-ios-onnxruntime-all.sh index 390c2aa89..110bf9ade 100755 --- a/frontend/src-tauri/scripts/build-ios-onnxruntime-all.sh +++ b/frontend/src-tauri/scripts/build-ios-onnxruntime-all.sh @@ -14,8 +14,11 @@ set -e SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +source "${SCRIPT_DIR}/onnxruntime-pins.sh" + TAURI_DIR="$(dirname "$SCRIPT_DIR")" ORT_VERSION="${1:-1.22.2}" +ORT_COMMIT="${ORT_COMMIT:-$(onnxruntime_ios_commit_for_version "${ORT_VERSION}")}" BUILD_DIR="${TAURI_DIR}/onnxruntime-build" OUTPUT_DIR="${TAURI_DIR}/onnxruntime-ios" XCFRAMEWORK_DIR="${OUTPUT_DIR}/onnxruntime.xcframework" @@ -26,6 +29,7 @@ echo "========================================" echo "Building ONNX Runtime ${ORT_VERSION} for iOS" echo "(Device + Simulator)" echo "========================================" +echo "Source commit: ${ORT_COMMIT}" echo "Build directory: ${BUILD_DIR}" echo "Output directory: ${OUTPUT_DIR}" echo "" @@ -46,13 +50,37 @@ fi mkdir -p "$BUILD_DIR" cd "$BUILD_DIR" -# Clone ONNX Runtime +# Clone and check out ONNX Runtime at the pinned source commit. +checkout_onnxruntime_source() { + if [ ! -d "onnxruntime/.git" ]; then + rm -rf onnxruntime + git init onnxruntime + fi + + ( + cd onnxruntime + if ! git remote get-url origin >/dev/null 2>&1; then + git remote add origin https://github.com/microsoft/onnxruntime.git + fi + git fetch --depth 1 origin "${ORT_COMMIT}" + git checkout --detach FETCH_HEAD + git submodule update --init --recursive + + local actual_commit + actual_commit="$(git rev-parse HEAD)" + if [ "${actual_commit}" != "${ORT_COMMIT}" ]; then + echo "Expected ONNX Runtime commit ${ORT_COMMIT}, got ${actual_commit}" >&2 + return 1 + fi + ) +} + clone_with_retry() { local max_attempts=3 local attempt=1 while [ $attempt -le $max_attempts ]; do echo "Attempt $attempt of $max_attempts..." - if git clone --depth 1 --branch "v${ORT_VERSION}" --recursive https://github.com/microsoft/onnxruntime.git; then + if checkout_onnxruntime_source; then return 0 fi sleep 10 @@ -61,10 +89,8 @@ clone_with_retry() { return 1 } -if [ ! -d "onnxruntime" ]; then - echo "Cloning ONNX Runtime repository..." - clone_with_retry -fi +echo "Checking out ONNX Runtime repository..." +clone_with_retry cd onnxruntime diff --git a/frontend/src-tauri/scripts/build-ios-onnxruntime.sh b/frontend/src-tauri/scripts/build-ios-onnxruntime.sh index 8ae0971b2..1fb463fae 100755 --- a/frontend/src-tauri/scripts/build-ios-onnxruntime.sh +++ b/frontend/src-tauri/scripts/build-ios-onnxruntime.sh @@ -14,9 +14,12 @@ set -e SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +source "${SCRIPT_DIR}/onnxruntime-pins.sh" + TAURI_DIR="$(dirname "$SCRIPT_DIR")" # Use latest 1.22.2 - older versions have Eigen hash mismatch issues with GitLab ORT_VERSION="${1:-1.22.2}" +ORT_COMMIT="${ORT_COMMIT:-$(onnxruntime_ios_commit_for_version "${ORT_VERSION}")}" BUILD_DIR="${TAURI_DIR}/onnxruntime-build" OUTPUT_DIR="${TAURI_DIR}/onnxruntime-ios" XCFRAMEWORK_DIR="${OUTPUT_DIR}/onnxruntime.xcframework" @@ -27,6 +30,7 @@ IOS_DEPLOYMENT_TARGET="13.0" echo "========================================" echo "Building ONNX Runtime ${ORT_VERSION} for iOS" echo "========================================" +echo "Source commit: ${ORT_COMMIT}" echo "Build directory: ${BUILD_DIR}" echo "Output directory: ${OUTPUT_DIR}" echo "iOS deployment target: ${IOS_DEPLOYMENT_TARGET}" @@ -49,50 +53,49 @@ fi mkdir -p "$BUILD_DIR" cd "$BUILD_DIR" -# Clone ONNX Runtime if not already cloned (with retry for transient network errors) -clone_with_retry() { - local max_attempts=3 - local attempt=1 - while [ $attempt -le $max_attempts ]; do - echo "Attempt $attempt of $max_attempts..." - if git clone --depth 1 --branch "v${ORT_VERSION}" --recursive https://github.com/microsoft/onnxruntime.git; then - return 0 +# Clone and check out ONNX Runtime at the pinned source commit. +checkout_onnxruntime_source() { + if [ ! -d "onnxruntime/.git" ]; then + rm -rf onnxruntime + git init onnxruntime + fi + + ( + cd onnxruntime + if ! git remote get-url origin >/dev/null 2>&1; then + git remote add origin https://github.com/microsoft/onnxruntime.git fi - echo "Clone failed, waiting 10 seconds before retry..." - sleep 10 - attempt=$((attempt + 1)) - done - echo "Failed to clone after $max_attempts attempts" - return 1 + git fetch --depth 1 origin "${ORT_COMMIT}" + git checkout --detach FETCH_HEAD + git submodule update --init --recursive + + local actual_commit + actual_commit="$(git rev-parse HEAD)" + if [ "${actual_commit}" != "${ORT_COMMIT}" ]; then + echo "Expected ONNX Runtime commit ${ORT_COMMIT}, got ${actual_commit}" >&2 + return 1 + fi + ) } -submodule_update_with_retry() { +clone_with_retry() { local max_attempts=3 local attempt=1 while [ $attempt -le $max_attempts ]; do echo "Attempt $attempt of $max_attempts..." - if git submodule update --init --recursive; then + if checkout_onnxruntime_source; then return 0 fi - echo "Submodule update failed, waiting 10 seconds before retry..." + echo "Clone failed, waiting 10 seconds before retry..." sleep 10 attempt=$((attempt + 1)) done - echo "Failed to update submodules after $max_attempts attempts" + echo "Failed to clone after $max_attempts attempts" return 1 } -if [ ! -d "onnxruntime" ]; then - echo "Cloning ONNX Runtime repository..." - clone_with_retry -else - echo "ONNX Runtime repository already cloned" - cd onnxruntime - git fetch --tags - git checkout "v${ORT_VERSION}" - submodule_update_with_retry - cd .. -fi +echo "Checking out ONNX Runtime repository..." +clone_with_retry cd onnxruntime diff --git a/frontend/src-tauri/scripts/onnxruntime-pins.sh b/frontend/src-tauri/scripts/onnxruntime-pins.sh new file mode 100644 index 000000000..e1fc595b2 --- /dev/null +++ b/frontend/src-tauri/scripts/onnxruntime-pins.sh @@ -0,0 +1,37 @@ +#!/usr/bin/env bash + +onnxruntime_linux_x64_archive_sha256_for_version() { + case "$1" in + 1.22.0) + printf '%s\n' "8344d55f93d5bc5021ce342db50f62079daf39aaafb5d311a451846228be49b3" + ;; + *) + echo "No pinned Linux x64 ONNX Runtime archive SHA-256 for version '$1'." >&2 + return 1 + ;; + esac +} + +onnxruntime_linux_x64_dylib_sha256_for_version() { + case "$1" in + 1.22.0) + printf '%s\n' "3da6146e14e7b8aaec625dde11d6114c7457c87a5f93d744897da8781e35c673" + ;; + *) + echo "No pinned Linux x64 ONNX Runtime shared-library SHA-256 for version '$1'." >&2 + return 1 + ;; + esac +} + +onnxruntime_ios_commit_for_version() { + case "$1" in + 1.22.2) + printf '%s\n' "5630b081cd25e4eccc7516a652ff956e51676794" + ;; + *) + echo "No pinned ONNX Runtime iOS source commit for version '$1'." >&2 + return 1 + ;; + esac +} diff --git a/frontend/src-tauri/scripts/provide-linux-onnxruntime.sh b/frontend/src-tauri/scripts/provide-linux-onnxruntime.sh index 0872c9ed4..39bbfd076 100755 --- a/frontend/src-tauri/scripts/provide-linux-onnxruntime.sh +++ b/frontend/src-tauri/scripts/provide-linux-onnxruntime.sh @@ -2,18 +2,64 @@ set -euo pipefail ORT_VERSION="${ORT_VERSION:-1.22.0}" -TAURI_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +source "${SCRIPT_DIR}/onnxruntime-pins.sh" + +TAURI_DIR="$(cd "${SCRIPT_DIR}/.." && pwd)" ORT_ROOT="${TAURI_DIR}/onnxruntime-linux" ORT_DIR="${ORT_ROOT}/onnxruntime-linux-x64-${ORT_VERSION}" +ORT_ARCHIVE="onnxruntime-linux-x64-${ORT_VERSION}.tgz" +ORT_URL="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/microsoft/onnxruntime/releases/download/v${ORT_VERSION}/${ORT_ARCHIVE}" +ORT_DYLIB="${ORT_DIR}/lib/libonnxruntime.so.${ORT_VERSION}" +ORT_ARCHIVE_SHA256="$(onnxruntime_linux_x64_archive_sha256_for_version "${ORT_VERSION}")" +ORT_DYLIB_SHA256="$(onnxruntime_linux_x64_dylib_sha256_for_version "${ORT_VERSION}")" + +sha256_file() { + local path="$1" + + if command -v sha256sum >/dev/null 2>&1; then + sha256sum "${path}" | awk '{print $1}' + elif command -v shasum >/dev/null 2>&1; then + shasum -a 256 "${path}" | awk '{print $1}' + elif command -v openssl >/dev/null 2>&1; then + openssl dgst -sha256 -r "${path}" | awk '{print $1}' + else + echo "No SHA-256 tool found. Install sha256sum, shasum, or openssl." >&2 + return 1 + fi +} + +verify_sha256() { + local label="$1" + local path="$2" + local expected="$3" + local actual -if [ ! -f "${ORT_DIR}/lib/libonnxruntime.so" ]; then + actual="$(sha256_file "${path}")" + if [ "${actual}" != "${expected}" ]; then + echo "${label} SHA-256 mismatch for ${path}" >&2 + echo "expected: ${expected}" >&2 + echo "actual: ${actual}" >&2 + return 1 + fi +} + +if [ ! -f "${ORT_DYLIB}" ]; then rm -rf "${ORT_ROOT}" mkdir -p "${ORT_ROOT}" + archive_path="${ORT_ROOT}/${ORT_ARCHIVE}" + curl -fL --retry 5 --retry-delay 2 --retry-all-errors \ - "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/microsoft/onnxruntime/releases/download/v${ORT_VERSION}/onnxruntime-linux-x64-${ORT_VERSION}.tgz" \ - | tar -xz -C "${ORT_ROOT}" + "${ORT_URL}" \ + --output "${archive_path}" + + verify_sha256 "ONNX Runtime archive" "${archive_path}" "${ORT_ARCHIVE_SHA256}" + tar -xzf "${archive_path}" -C "${ORT_ROOT}" + rm -f "${archive_path}" fi +verify_sha256 "ONNX Runtime shared library" "${ORT_DYLIB}" "${ORT_DYLIB_SHA256}" + echo "ORT_LIB_LOCATION=${ORT_DIR}" echo "ORT_SKIP_DOWNLOAD=true" -echo "ORT_DYLIB_PATH=${ORT_DIR}/lib/libonnxruntime.so.${ORT_VERSION}" +echo "ORT_DYLIB_PATH=${ORT_DYLIB}"