verifyModelChecksum#

lsst.ts.wep.utils.verifyModelChecksum(key, path, expectedSha256)#

Compute a model file’s SHA-256 and verify it against an expected value.

Parameters:
  • key (str) – Name of the config field the file comes from (e.g. "wavenetPath"), used to make error messages identify which model is at fault.

  • path (str) – Path to the model file to hash and verify.

  • expectedSha256 (str) – Expected SHA-256 hex digest. Case-insensitive, may be whitespace-padded and may carry a leading sha256:. If empty or None skip the comparison (the digest is still computed and returned), so local or experimental runs that do not pin a checksum are unaffected.

Returns:

The actual SHA-256 hex digest of the file. Returning it lets callers hash the file once and reuse the digest for provenance recording.

Return type:

str

Raises:
  • ValueError – If expectedSha256 is set but is not a 64-character hex digest.

  • RuntimeError – If the file cannot be read (e.g. a directory or missing file), or if its SHA-256 digest does not match expectedSha256.

Notes

This guards against loading the wrong model version and against loading a git-lfs pointer stub that was never fetched (which hashes to something other than the real weights).