Pull Request已成功合入, 合并人@ascend-robot
(感谢 liuyutong 的贡献)变更摘要
本 PR 主要围绕 LLM 示例代码中远程模型自定义代码执行的风险进行收敛:删除多个训练脚本中硬编码的 trust_remote_code=True,使 Transformers 已原生支持的模型默认不执行模型仓自定义 Python 代码;仅在 Baichuan2 中保留该能力并改为默认关闭的显式开关,同时引入 revision 约束以固定远程 commit。此外清理了样例中的个人绝对路径默认值,并修复相关文件的 EOF 换行与尾随空格问题。
主要改动
- Baichuan2 训练脚本参数化远程代码控制:
train_baichuan2_7B.py中将AutoTokenizer.from_pretrained与AutoModelForCausalLM.from_pretrained的trust_remote_code=True替换为revision=self.args.revision与trust_remote_code=self.args.trust_remote_code,由命令行参数决定是否执行模型仓自定义代码。 - 新增
--trust-remote-code与--revision命令行参数:build_argparser()新增默认关闭的--trust-remote-code(action="store_true")和默认None的--revision;main()中新增校验,当开启远程代码且model_path非本地目录时,revision必须为 40 位十六进制完整 commit hash,否则通过parser.error拒绝执行。 - 移除其他模型样例中的
trust_remote_code=True:train_glm4_9B.py、train_gpt_oss_20B.py、train_llama3.py、train_mamba2_7B.py、train_qwen2vl.py、train_qwen3_4B.py中模型、tokenizer 或 processor 加载处的该参数均被删除,改为使用原生实现。 - 将个人绝对模型路径默认值改为必填参数:
train_mamba2_7B.py的--model_path与train_qwen2vl.py的--model_name_or_path由硬编码默认路径改为required=True。 - 启动脚本与文件格式修正:
run_baichuan2.sh新增"$@"以透传外部参数,并对涉及文件补齐末尾换行、清理尾随空格。


Thanks for your pull-request.
The full list of commands accepted by me can be found at here.
You can get sig-info at here.
You can self-configure the PR merge rules for this repository. For more details, please refer to Here.
PR Approval Progress
✅ Congratulations! All modules have met the lgtm and approve requirements.
Module Approval Details
| module | lgtm status | approve status |
|---|---|---|
| **/*.md | ✅ chenrayray, li_jing_hw (2/2) | ✅ li_jing_hw, chenrayray (2/1) |
| repo-Ascend/pytorch | ✅ chenrayray, li_jing_hw (2/2) | ✅ chenrayray, li_jing_hw (2/1) |
💡 Tip:
- Committer can comment
/approveor/lgtm- Commenting
/approveimplies both code review (lgtm) and intent to merge (approve)
CLA Signature Pass
liuyutong_bury, thanks for your pull request. All authors of the commits have signed the CLA. 👍


Linking Issue Notice
@liuyutong_bury , the pull request must be linked to at least one issue.
If an issue has already been linked, but the needs-issue label remains, you can remove the label by commenting /check-issue .


当前仓库存在以下 保护分支 :
评论 /sync <branch1> <branch2> ... 可将当前 PR 修改同步到其它分支(创建同步 PR):
a) 如果当前 PR 是 Open 状态,同步操作将延迟到 PR 被合并时执行
b) 如果当前 PR 已经 Merged,将立即执行同步操作
注意:
- /sync 命令可以指定同步到多个分支,仅最后一个 /sync 命令生效
- 如果创建的同步 PR 不正确,可通过向同步 PR 的源分支提交轻量级 PR 完善,或使用 /close 命令关闭


ascend docs pipeline is running...


| 阶段 | 任务名 | 状态 | 详情 |
|---|---|---|---|
| 编译构建 | Build_X86 | ✅ COMPLETED | >>> |
| Build_ARM | ✅ COMPLETED | >>> | |
| Build_X86_torchair | ⚪ IGNORED | >>> | |
| Build_ARM_torchair | ⚪ IGNORED | >>> | |
| patch_test | ⚪ IGNORED | >>> | |
| Build_X86_213 | ⚪ IGNORED | >>> | |
| Build_ARM_213 | ⚪ IGNORED | >>> | |
| 恶意代码检查 | Antipoison | ✅ COMPLETED | >>> |
| 编码安全与规范检查 | codecheck_pre-commit | ✅ COMPLETED | >>> |
| check_error | ✅ COMPLETED | >>> | |
| lintrunner | ✅ COMPLETED | >>> | |
| 开源片段检查 | SCA | ✅ COMPLETED | >>> |
| 开发者测试 | UT_ARM_A3_Part_01 | ⚪ IGNORED | >>> |
| UT_ARM_A3_Part_02 | ⚪ IGNORED | >>> | |
| UT_ARM_A2_Part_01 | ✅ COMPLETED | >>> | |
| UT_ARM_A2_Part_02 | ✅ COMPLETED | >>> | |
| UT_ARM_A2_Part_03 | ⚪ IGNORED | >>> | |
| UT_inductor_Part_01 | ⚪ IGNORED | >>> | |
| UT_inductor_Part_02 | ⚪ IGNORED | >>> | |
| UT_inductor_Part_03 | ⚪ IGNORED | >>> | |
| UT_inductor_Part_04 | ⚪ IGNORED | >>> | |
| UT_DIST_ARM_Part_01 | ⚪ IGNORED | >>> | |
| UT_DIST_ARM_Part_02 | ⚪ IGNORED | >>> | |
| UT_DIST_ARM_Part_03 | ⚪ IGNORED | >>> | |
| UT_DIST_ARM_Part_04 | ⚪ IGNORED | >>> | |
| UT_ARM_A2_Select_Part_01 | ⚪ IGNORED | >>> | |
| UT_ARM_A2_Select_Part_02 | ⚪ IGNORED | >>> | |
| UT_inductor_Part1_213 | ⚪ IGNORED | >>> | |
| 流水线 | PR-pipeline_pytorch | ✅ COMPLETED | >>> |
- compile、compile_inductor、compile_torchair : 运行流水线
- retry : 重试流水线所有失败子任务
- retry <任务名> : 仅重试指定失败子任务
- stop : 停止流水线


/approve


/approve


【合入来源】
关联 Issue:Fixes #5082
https://gitcode.com/Ascend/pytorch/issues/5082
【修改方案】
trust_remote_code=True,避免默认执行模型仓自定义 Python 代码。--trust-remote-code显式开关;远程仓启用时必须通过--revision固定完整 commit hash,本地模型目录不强制 revision。【资料变更】
涉及。Baichuan2 README 新增远程代码执行风险声明与固定 revision 要求;GLM4 README 说明使用 Transformers 内置实现,不执行模型仓自定义代码。
【接口变更】
涉及命令行参数变更:
--trust-remote-code,默认关闭。--revision;远程模型开启远程代码时必须提供完整的 40 位 commit hash。--model_path和 Qwen2VL 的--model_name_or_path改为必填参数。【功能验证】
transformers==4.57.1环境下完成 Mamba2、Qwen3、Qwen2VL、Llama3、GPT-OSS 原生配置/tokenizer/processor 加载 smoke 验证。trust_remote_code=False;远程路径开启开关但未提供固定 revision 时,会在模型加载前拒绝执行。py_compile。bash -n。git diff --check、EOF 换行、尾随空格、Tab、120 字符行长及硬编码trust_remote_code=True扫描通过。【CheckList】