Buckets:

hf-doc-build/doc-dev / kernels /pr_754 /en /cli-verify-signature.md
|
download
raw
1.94 kB

kernels verify-signature

Use kernels verify-signature to verify the metadata signature and check that kernel files match the digest embedded in the metadata.

Usage

kernels verify-signature <repo_id> <version> [--all-variants] \
  [--filter-unsigned] [--filter-no-digest]

What It Does

  • Checks that the signing identity in metadata.json.sigstore is approved.
  • Verifies that metadata.json is not tampered with, using the signature in metadata.json.sigstore.
  • Verifies that other kernel files are not tampered with, using the digest in metadata.json.

Examples

Verify version 1 of the kernels-community/relu kernel. Only checks the variant that is compatible with the current system:

kernels verify-signature kernels-community/relu 1

Verify all build variants of the same kernel:

kernels verify-signature kernels-community/relu 1 --all-variants

Example Output

$ kernels verify-signature kernels-community/relu 1
✅ torch211-cxx11-cu126-x86_64-linux: kernel metadata is correctly signed
$ kernels verify-signature kernels-community/flash-attn2 1
❌ torch211-cxx11-cu126-x86_64-linux: cannot verify kernel integrity, signature not found

Options

Option Description
--all-variants Verify all build variants of each kernel instead of just the variant that is compatible with the current system.
--filter-no-digest Skip variants that do not have a digest in the metadata (typically older builds that precede code signing).
--filter-unsigned Skip variants that do not have a detached signature (typically older builds that precede code signing).

Xet Storage Details

Size:
1.94 kB
·
Xet hash:
5c8f00ef33c8db273d882d708235fc606e0cd0886bfc845bc42983efb0d4b5f5

Xet efficiently stores files, intelligently splitting them into unique chunks and accelerating uploads and downloads. More info.