Qwen3-4B, drinkme pack
A drinkme pack of Qwen/Qwen3-4B at commit 1cfa9a720891. drinkme stores the model's BF16 weights losslessly compressed and decodes them during inference, so the pack is smaller than the checkpoint and serves the same bits.
| Source | Qwen/Qwen3-4B at 1cfa9a7208912126459214e8b04321603b3df60c |
| Pack | v1/sip/1cfa9a7208912126459214e8b04321603b3df60c/ |
| Pack format | 1, compression profile sip (tiers 3, 8) |
| Bits per packed weight | 11.32 (BF16: 16) |
| Size | 5.94 GB, 74% of the 8.04 GB BF16 checkpoint |
| Packed by | drinkme 1.0.0 |
The pack is self-contained: besides the compressed Linear weights it carries the tensors the codec leaves uncompressed (embeddings, norms), the config, the tokenizer and the chat template, and it serves with no other download.
Serve it
drinkme serve --model Qwen3-4B
On a machine with no local pack of this commit, drinkme serve downloads this pack instead of the BF16 checkpoint, checks it as described below, and serves it; --no-hub-pack downloads the checkpoint and packs it locally instead. drinkme's README covers installation.
Check it yourself
The Hugging Face Hub publishes the SHA-256 of every weight file of Qwen/Qwen3-4B at commit 1cfa9a720891. drinkme rebuilds each of those files from the pack, byte for byte (its safetensors header, then every tensor: the compressed ones decoded, the others copied), hashes it without writing it out, and compares the hash with the one the Hub lists. It compares the embedded config and tokenizer files with the Hub's hashes the same way. drinkme serve runs this when it downloads the pack; to run it by hand:
hf download drinkme-packs/Qwen3-4B-drinkme --include 'v1/sip/1cfa9a7208912126459214e8b04321603b3df60c/*' --exclude 'v1/sip/1cfa9a7208912126459214e8b04321603b3df60c/upstream-verified.json' --local-dir drinkme-pack
drinkme verify --upstream --pack-dir drinkme-pack/v1/sip/1cfa9a7208912126459214e8b04321603b3df60c
It prints one line per file, MATCH, MISMATCH or NOT COVERED, and exits 0 only when every file matches. It writes its own receipt, upstream-verified.json, into the pack directory.
Receipt
The publisher's run (2026-10-02T02:51:08Z, drinkme 1.0.0, 4.96 s on the native decoder): MATCH. The full record is v1/sip/1cfa9a7208912126459214e8b04321603b3df60c/upstream-verified.json.
| Weight file | Bytes | SHA-256 published by the Hub | Rebuilt from the pack |
|---|---|---|---|
model-00001-of-00003.safetensors |
3,957,900,840 | 328a91d3122359d5547f9d79521205bc0a46e1f79a792dfe650e99fc2d651223 |
MATCH |
model-00002-of-00003.safetensors |
3,987,450,520 | 6cd087b316306a68c562436b5492edbcf6e16c6dba3a1308279caa5a58e21ca5 |
MATCH |
model-00003-of-00003.safetensors |
99,630,640 | e4bf436957184f4eeb86a80e9db394503f1f56446b2e6b7edeac5b81470f4ca1 |
MATCH |
Embedded files compared with the Hub's hashes: LICENSE MATCH, README.md MATCH, config.json MATCH, generation_config.json MATCH, merges.txt MATCH, tokenizer.json MATCH, tokenizer_config.json MATCH, vocab.json MATCH.
Licence
This pack contains Qwen3-4B's weights and tokenizer and is redistributed under the model's own licence, apache-2.0.
LICENSE copied byte for byte from Qwen/Qwen3-4B at 1cfa9a720891.
drinkme-packs is not affiliated with or endorsed by Alibaba Cloud or Qwen.
Changes: the upstream model*.safetensors files are not shipped as such. drinkme re-encoded their tensors losslessly into the files under v1/sip/1cfa9a7208912126459214e8b04321603b3df60c/ (t*.npz, checkpoint/remainder.safetensors, meta.json), from which drinkme verify --upstream rebuilds the original files byte for byte. Every other file under checkpoint/ is an unmodified copy from Qwen/Qwen3-4B at 1cfa9a720891.
drinkme itself is a separate project with its own licence.