Pull Request已成功合入, 合并人@ascend-robot
(感谢 liuyutong 的贡献)变更摘要
本次变更聚焦于收敛大模型示例中远程模型代码的执行权限:在 transformers==4.57.1 已原生支持的模型上统一移除 trust_remote_code=True,改为使用内置实现加载模型与 tokenizer;对仍需自定义架构的 Baichuan2,则将其改为受控的显式开关。同时清理示例脚本中的个人绝对路径、修复文件尾随空格与 EOF 换行问题,并同步更新相关说明文档。
主要改动
- 移除原生支持模型的远程代码执行: 在
train_glm4_9B.py、train_gpt_oss_20B.py、train_llama3.py、train_qwen3_4B.py、train_mamba2_7B.py、train_qwen2vl.py中删除AutoModelForCausalLM.from_pretrained、AutoTokenizer.from_pretrained、processor 等加载调用里的trust_remote_code=True,避免默认执行模型仓自定义 Python 代码。 - Baichuan2 新增显式远程代码开关与 revision 约束:
train_baichuan2_7B.py新增--trust-remote-code(默认关闭)与--revision参数,加载时传入revision与trust_remote_code;main中当开启远程代码且model_path非本地目录时,要求--revision为完整的 40 位 commit hash,否则在模型加载前以parser.error拒绝执行。 - 示例脚本参数与启动脚本调整:
train_mamba2_7B.py的--model_path、train_qwen2vl.py的--model_name_or_path由个人绝对路径默认值改为required=True必填参数;run_baichuan2.sh增加"$@"以透传命令行参数。 - 文档与文件规范性修复: 按 PR 描述更新 Baichuan2/GLM4 README,说明远程代码执行风险、可信来源与固定 revision 要求以及原生 GLM4 模型要求;同时为多个涉及文件补齐 EOF 换行、清理尾随空格。


Thanks for your pull-request.
The full list of commands accepted by me can be found at here.
You can get sig-info at here.
You can self-configure the PR merge rules for this repository. For more details, please refer to Here.
PR Approval Progress
✅ Congratulations! All modules have met the lgtm and approve requirements.
Module Approval Details
| module | lgtm status | approve status |
|---|---|---|
| **/*.md | ✅ chenrayray, li_jing_hw (2/2) | ✅ chenrayray, li_jing_hw (2/1) |
| repo-Ascend/pytorch | ✅ chenrayray, li_jing_hw (2/2) | ✅ chenrayray, li_jing_hw (2/1) |
💡 Tip:
- Committer can comment
/approveor/lgtm- Commenting
/approveimplies both code review (lgtm) and intent to merge (approve)
CLA Signature Pass
liuyutong_bury, thanks for your pull request. All authors of the commits have signed the CLA. 👍


Linking Issue Notice
@liuyutong_bury , the pull request must be linked to at least one issue.
If an issue has already been linked, but the needs-issue label remains, you can remove the label by commenting /check-issue .


当前仓库存在以下 保护分支 :
评论 /sync <branch1> <branch2> ... 可将当前 PR 修改同步到其它分支(创建同步 PR):
a) 如果当前 PR 是 Open 状态,同步操作将延迟到 PR 被合并时执行
b) 如果当前 PR 已经 Merged,将立即执行同步操作
注意:
- /sync 命令可以指定同步到多个分支,仅最后一个 /sync 命令生效
- 如果创建的同步 PR 不正确,可通过向同步 PR 的源分支提交轻量级 PR 完善,或使用 /close 命令关闭


ascend docs pipeline is running...


/approve


/approve




【合入来源】
关联 Issue:Fixes #5082
https://gitcode.com/Ascend/pytorch/issues/5082
【修改方案】
trust_remote_code=True,避免默认执行模型仓自定义 Python 代码。--trust-remote-code显式开关;远程仓启用时必须通过--revision固定完整 commit hash,本地模型目录不强制 revision。【资料变更】
涉及。Baichuan2 README 新增远程代码执行风险声明与固定 revision 要求;GLM4 README 说明使用 Transformers 内置实现,不执行模型仓自定义代码。
【接口变更】
涉及命令行参数变更:
--trust-remote-code,默认关闭。--revision;远程模型开启远程代码时必须提供完整的 40 位 commit hash。--model_path和 Qwen2VL 的--model_name_or_path改为必填参数。【功能验证】
transformers==4.57.1环境下完成 Mamba2、Qwen3、Qwen2VL、Llama3、GPT-OSS 原生配置/tokenizer/processor 加载 smoke 验证。trust_remote_code=False;远程路径开启开关但未提供固定 revision 时,会在模型加载前拒绝执行。py_compile。bash -n。git diff --check、EOF 换行、尾随空格、Tab、120 字符行长及硬编码trust_remote_code=True扫描通过。【CheckList】