feat: add SHA256 verification for direct downloads

Store SHA256 hashes when running update scripts and verify them
when downloading files at build time. This improves security by
detecting unexpected changes to downloaded artifacts.

Platforms covered: macOS (CPython, PyPy, GraalPy), iOS, Android,
virtualenv, and python-build-standalone. Windows (nuget) and
Linux (Docker) are excluded.

SHA256 sources per platform:
- macOS/iOS/Android CPython (python.org): sha256_sum from API
- GraalPy: .sha256 sidecar assets from GitHub releases
- python-build-standalone: SHA256SUMS file in release
- PyPy, BeeWare iOS, Maven (Chaquopy): stream-download and compute

Changes:
- cibuildwheel/util/file.py: add sha256 param to download()
- cibuildwheel/platforms/{macos,ios,android}.py: add sha256 to
  PythonConfiguration and pass to download()
- cibuildwheel/venv.py: read sha256 from toml and pass to download()
- cibuildwheel/util/python_build_standalone.py: add sha256 to
  PythonBuildStandaloneAsset and pass to download()
- cibuildwheel/resources/build-platforms.toml: add sha256 fields
- cibuildwheel/resources/virtualenv.toml: add sha256 field
- cibuildwheel/resources/python-build-standalone-releases.json: add sha256
- bin/update_pythons.py: compute/store sha256 per source strategy
- bin/update_virtualenv.py: compute sha256 by streaming download
- bin/update_python_build_standalone.py: parse SHA256SUMS file

Closes #908

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Assisted-by: copilot-cli:claude-sonnet-4.6
This commit is contained in:
Henry Schreiner
2026-05-28 11:03:52 -04:00
co-authored by Copilot
parent e3e7cc9e07
commit 97537fe937
12 changed files with 536 additions and 259 deletions
+45 -4
View File
@@ -15,12 +15,13 @@
from __future__ import annotations
import difflib
import hashlib
import logging
import operator
import re
import tomllib
from pathlib import Path
from typing import Any, Final, Literal, TypedDict
from typing import Any, Final, Literal, NotRequired, TypedDict
from xml.etree import ElementTree as ET
import click
@@ -56,6 +57,7 @@ class Config(TypedDict):
class ConfigUrl(Config):
url: str
sha256: NotRequired[str]
class ConfigPyodide(Config):
@@ -179,10 +181,23 @@ class GraalPyVersions:
]
if urls:
(url,) = urls
# Fetch sha256 from the ".sha256" sidecar asset in the same release
sha256 = ""
sha256_asset_name = url.rsplit("/", 1)[-1] + ".sha256"
sha256_urls = [
rf["browser_download_url"]
for rf in release["assets"]
if rf["name"] == sha256_asset_name
]
if sha256_urls:
sha256_response = requests.get(sha256_urls[0])
sha256_response.raise_for_status()
sha256 = sha256_response.text.strip().split()[0]
return ConfigUrl(
identifier=identifier,
version=f"{version.major}.{version.minor}",
url=url,
sha256=sha256,
)
return None
@@ -298,12 +313,14 @@ class CPythonVersions:
uri = self.versions_dict[new_version]
files = [rf for rf in self.files_info if rf["release"] == uri]
urls = [rf["url"] for rf in files if file_ident in rf["url"]]
if urls:
matching = [rf for rf in files if file_ident in rf["url"]]
if matching:
rf = matching[0]
return ConfigUrl(
identifier=identifier,
version=f"{new_version.major}.{new_version.minor}",
url=urls[0],
url=rf["url"],
sha256=rf.get("sha256_sum", ""),
)
return None
@@ -448,6 +465,16 @@ class AllVersions:
self.pyodide = PyodideVersions()
def _stream_sha256(self, url: str) -> str:
"""Download a file (streaming) and return its SHA256 hex digest."""
log.debug("Computing sha256 for %s by streaming download...", url)
response = requests.get(url, stream=True)
response.raise_for_status()
hasher = hashlib.sha256()
for chunk in response.iter_content(65536):
hasher.update(chunk)
return hasher.hexdigest()
def update_config(self, config: MutableMapping[str, str]) -> None:
identifier = config["identifier"]
version = Version(config["version"])
@@ -505,6 +532,20 @@ class AllVersions:
)
assert config_update is not None, f"{identifier} not found!"
# Fill in sha256 for URL-based configs if not already provided by the
# update_version_* method (e.g. PyPy, BeeWare iOS, Maven have no sidecar).
# Widen the type to allow arbitrary key access on the underlying dict.
config_update_dict: dict[str, str] = config_update # type: ignore[assignment]
if "url" in config_update_dict and "sha256" not in config_update_dict:
url = config_update_dict["url"]
existing_sha256 = config.get("sha256", "")
if url == config.get("url") and existing_sha256:
# URL unchanged — preserve the existing sha256
config_update_dict["sha256"] = existing_sha256
else:
config_update_dict["sha256"] = self._stream_sha256(url)
if config_update != config:
log.info(" Updated %s to %s", config, config_update)
config.clear()