已合并
fix(benchmark): restrict remote model code execution #46980
fix(benchmark): restrict remote model code execution #46980
已合并
liuyutong创建于 8 天前
liuyutong
liuyutong成员
8 天前

【合入来源】

如有社区issue,请关联issue链接
请勿携带内部流程信息(需求链接、问题单、内部issue等)

关联 Issue:Fixes #5082
https://gitcode.com/Ascend/pytorch/issues/5082

【修改方案】

  1. 删除 Transformers 4.57.1 已原生支持模型的 trust_remote_code=True,避免默认执行模型仓自定义 Python 代码。
  2. Baichuan2 保留架构所需能力,但改为默认关闭的 --trust-remote-code 显式开关;远程仓启用时必须通过 --revision 固定完整 commit hash,本地模型目录不强制 revision。
  3. 删除 Mamba2 和 Qwen2VL 样例中的个人绝对模型路径,改为必填参数。
  4. 更新 Baichuan2/GLM4 README,说明远程代码风险、可信来源要求以及原生 GLM4 模型要求。
  5. 修复本次涉及文件的尾随空格和 EOF 换行问题。

【资料变更】

涉及。Baichuan2 README 新增远程代码执行风险声明与固定 revision 要求;GLM4 README 说明使用 Transformers 内置实现,不执行模型仓自定义代码。

【接口变更】

涉及命令行参数变更:

  • Baichuan2 新增 --trust-remote-code,默认关闭。
  • Baichuan2 新增 --revision;远程模型开启远程代码时必须提供完整的 40 位 commit hash。
  • Mamba2 的 --model_path 和 Qwen2VL 的 --model_name_or_path 改为必填参数。

【功能验证】

  • transformers==4.57.1 环境下完成 Mamba2、Qwen3、Qwen2VL、Llama3、GPT-OSS 原生配置/tokenizer/processor 加载 smoke 验证。
  • Baichuan2 参数默认值验证为 trust_remote_code=False;远程路径开启开关但未提供固定 revision 时,会在模型加载前拒绝执行。
  • 42 个分支相关 Python 文件通过 py_compile。
  • 6 个 Baichuan2 启动脚本通过 bash -n。
  • git diff --check、EOF 换行、尾随空格、Tab、120 字符行长及硬编码 trust_remote_code=True 扫描通过。
  • 未执行完整模型训练,待 PR 流水线进一步验证。

【CheckList】

PR提交人对以下CheckList自检项进行全量自检,自检通过或不涉及,均修改 [ ] 为 [x]

likedislike
Pull Request已成功合入, 合并人@ascend-robot
(感谢 liuyutong 的贡献)
liuyutongliuyutong成员
8 天前 创建了 pull request,commit 0ca66dc9
atomgit-bot
atomgit-bot
8 天前 评论:

变更摘要

本次变更聚焦于收敛大模型示例中远程模型代码的执行权限:在 transformers==4.57.1 已原生支持的模型上统一移除 trust_remote_code=True,改为使用内置实现加载模型与 tokenizer;对仍需自定义架构的 Baichuan2,则将其改为受控的显式开关。同时清理示例脚本中的个人绝对路径、修复文件尾随空格与 EOF 换行问题,并同步更新相关说明文档。

主要改动

  • 移除原生支持模型的远程代码执行: 在 train_glm4_9B.py、train_gpt_oss_20B.py、train_llama3.py、train_qwen3_4B.py、train_mamba2_7B.py、train_qwen2vl.py 中删除 AutoModelForCausalLM.from_pretrained、AutoTokenizer.from_pretrained、processor 等加载调用里的 trust_remote_code=True,避免默认执行模型仓自定义 Python 代码。
  • Baichuan2 新增显式远程代码开关与 revision 约束: train_baichuan2_7B.py 新增 --trust-remote-code(默认关闭)与 --revision 参数,加载时传入 revision 与 trust_remote_code;main 中当开启远程代码且 model_path 非本地目录时,要求 --revision 为完整的 40 位 commit hash,否则在模型加载前以 parser.error 拒绝执行。
  • 示例脚本参数与启动脚本调整: train_mamba2_7B.py 的 --model_path、train_qwen2vl.py 的 --model_name_or_path 由个人绝对路径默认值改为 required=True 必填参数;run_baichuan2.sh 增加 "$@" 以透传命令行参数。
  • 文档与文件规范性修复: 按 PR 描述更新 Baichuan2/GLM4 README,说明远程代码执行风险、可信来源与固定 revision 要求以及原生 GLM4 模型要求;同时为多个涉及文件补齐 EOF 换行、清理尾随空格。
likedislike
不准确?
atomgit-bot
atomgit-bot
8 天前 评论:

代码审查

✅ 未发现问题

likedislike
不准确?
ascend-robotascend-robot成员
8 天前 添加了label:ascend-cla/yes
ascend-robotascend-robot成员
8 天前 添加了label:needs-issue
ascend-robot
ascend-robot成员
8 天前 评论:

Thanks for your pull-request.
The full list of commands accepted by me can be found at here.
You can get sig-info at here.
You can self-configure the PR merge rules for this repository. For more details, please refer to Here.


PR Approval Progress

✅ Congratulations! All modules have met the lgtm and approve requirements.

Module Approval Details

module lgtm status approve status
**/*.md ✅ chenrayray, li_jing_hw (2/2) ✅ chenrayray, li_jing_hw (2/1)
repo-Ascend/pytorch ✅ chenrayray, li_jing_hw (2/2) ✅ chenrayray, li_jing_hw (2/1)

💡 Tip:

  • Committer can comment /approve or /lgtm
  • Commenting /approve implies both code review (lgtm) and intent to merge (approve)

CLA Signature Pass

liuyutong_bury, thanks for your pull request. All authors of the commits have signed the CLA. 👍

likedislike
ascend-robot
ascend-robot成员
8 天前 评论:

Linking Issue Notice

@liuyutong_bury , the pull request must be linked to at least one issue.
If an issue has already been linked, but the needs-issue label remains, you can remove the label by commenting /check-issue .

likedislike
ascend-robot
ascend-robot成员
8 天前 评论:

当前仓库存在以下 保护分支 :

Protected Branch Version Release
master
v2.10.0
v2.11.0
v2.12.0
v2.14.0-26.2.0
v2.13.0-26.2.0
v2.7.1-26.2.0
v2.7.1
v2.12.0-26.2.0
v2.10.0-26.2.0
v2.9.0-26.2.0
v2.11.0-26.2.0
v2.9.0
v2.7.1-26.1.0
v2.9.0-26.1.0
v2.11.0-26.1.0
v2.12.0-26.1.0
v2.10.0-26.1.0
ci-test
fix/te-rnumel-autoblockify-prea5

评论 /sync <branch1> <branch2> ... 可将当前 PR 修改同步到其它分支(创建同步 PR):
a) 如果当前 PR 是 Open 状态,同步操作将延迟到 PR 被合并时执行
b) 如果当前 PR 已经 Merged,将立即执行同步操作

注意:

  1. /sync 命令可以指定同步到多个分支,仅最后一个 /sync 命令生效
  2. 如果创建的同步 PR 不正确,可通过向同步 PR 的源分支提交轻量级 PR 完善,或使用 /close 命令关闭
likedislike
AtlasAccountAtlasAccount成员
8 天前 添加了label:ci-pipeline-running
ascend-robot
ascend-robot成员
8 天前 评论:

ascend docs pipeline is running...

likedislike
ascend-robotascend-robot成员
8 天前 添加了label:docs-ci-pipeline-running
ascend-robot
ascend-robot成员
8 天前 评论:

✅ 文档门禁通过!

检查项 检查结果 详情
markdownlint ✅ 已通过 查看详情
link-validity-check ✅ 已通过 查看详情
resource-existence-check ✅ 已通过 查看详情
tag-closed-check ✅ 已通过 查看详情
likedislike
ascend-robotascend-robot成员
8 天前 删除了label:docs-ci-pipeline-running
此处折叠了6条事件消息 查看更多
AtlasAccountAtlasAccount成员
8 天前 添加了label:ci-pipeline-passed
chenrayray
chenrayray成员
8 天前 评论:

/approve

likedislike
ascend-robotascend-robot成员
8 天前 添加了label:approved
li_jing_hw成员
8 天前 评论:

/approve

likedislike
ascend-robotascend-robot成员
8 天前 添加了label:lgtm
ascend-robotascend-robot成员
8 天前 合入了pull request
AtlasAccount
AtlasAccount成员
8 天前 评论:
流水线 pytorch_gitcode_PR_multiVersion#15594 [ commitID:affc4c24 ] 已完成
likedislike