Skip to content

fix: preserve active HF correlation findings - #1551

Merged
mldangelo-oai merged 6 commits into
mainfrom
mdangelo/codex/fix-hf-whitelist-active-findings
Jun 9, 2026
Merged

mldangelo-oai merged 6 commits into
mainfrom
mdangelo/codex/fix-hf-whitelist-active-findings

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Jun 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • preserve only same-fragment command/network correlations for trusted Hugging Face models
  • keep exact CatBoost, LightGBM, and RKNN active-correlation findings CRITICAL
  • leave unrelated cross-fragment command/network near matches eligible for whitelist downgrade
  • retain whitelist provenance when findings are relayed so late operational/inconclusive metadata restores the original severity
  • avoid mutating caller-owned details or erasing unrelated original_severity evidence
  • invalidate pre-fix cached severities with cache schema 2.2

Critical review fixes

  • replaced display-name-only exemptions with producer-supplied same_fragment_correlation evidence
  • added malicious same-fragment positives and benign cross-fragment/cross-line negatives
  • preserved valid INFO downgrade markers through result composition
  • scrub stale internal markers only from fresh higher-severity findings
  • kept RKNN command-only and policy-grade URL findings whitelist-eligible

Validation

  • affected base/cache/CatBoost/LightGBM/RKNN modules: 263 passed
  • scoped Ruff check and format check: clean
  • scoped mypy: clean across 10 changed source/test files
  • git diff --check: clean
  • unresolved inline review threads: 0
  • full suite intentionally left to CI per review workflow

Published state

  • current main: dfaedd1f0a1d8d2a47f1a6bacd5dd2945a7407ed
  • head: 7cdf0ed8757ac275a2911cd1b849880a1cd52a32
  • exact verified tree: d29b49d84d0b8836080d92f21b9222bc5f180eb0

CI is left to run while the randomized PR review queue continues.

@github-actions

github-actions Bot commented Jun 8, 2026 •

Copy link
Copy Markdown
Contributor

Workflow run and artifacts

Performance Benchmarks

Compared 12 shared benchmarks with a regression threshold of 15%.
Status: 0 regressions, 0 improved, 12 stable, 0 new, 0 missing.
Aggregate shared-benchmark median: 1.378s -> 1.334s (-3.2%).

Workload Benchmark Target Size Files Baseline Current Change Status
suspicious-pickle-intake tests/benchmarks/test_scan_benchmarks.py::test_scan_suspicious_pickle_intake suspicious-intake 183.8 KiB 4 124.01ms 117.77ms -5.0% stable
clean-training-checkpoint tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_clean_training_checkpoint safe_large 278.2 KiB 1 110.98ms 105.72ms -4.7% stable
duplicate-heavy-registry tests/benchmarks/test_scan_benchmarks.py::test_scan_duplicate_registry_snapshot registry-snapshot 915.2 KiB 13 382.66ms 365.42ms -4.5% stable
warm-cache-rescan tests/benchmarks/test_scan_benchmarks.py::test_scan_warm_cached_repository_rescan release-candidate 547.3 KiB 32 97.15ms 101.21ms +4.2% stable
single-checkpoint-preflight tests/benchmarks/test_scan_benchmarks.py::test_scan_single_checkpoint_before_load single_checkpoint.pkl 183.0 KiB 1 69.70ms 66.96ms -3.9% stable
chunked-upload-stream tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_chunked_upload_stream chunked_stream 278.2 KiB 1 113.39ms 109.54ms -3.4% stable
direct-malicious-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_direct_malicious_upload malicious_reduce 52 B 1 514.7us 497.6us -3.3% stable
mixed-model-repository tests/benchmarks/test_scan_benchmarks.py::test_scan_release_candidate_repository release-candidate 547.3 KiB 32 477.52ms 464.52ms -2.7% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_raw] nested_raw 78 B 1 524.2us 515.4us -1.7% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_hex] nested_hex 130 B 1 564.9us 557.0us -1.4% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_base64] nested_base64 98 B 1 535.4us 528.5us -1.3% stable
padded-multi-stream-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_padded_multi_stream_upload multi_stream_padded 4.1 KiB 1 615.0us 612.8us -0.4% stable

@mldangelo-oai
mldangelo-oai marked this pull request as ready for review June 8, 2026 21:13
@mldangelo-oai mldangelo-oai changed the title fix: preserve critical findings for hf whitelists fix: preserve active HF correlation findings Jun 8, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 147eb5ab56

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/scanners/base.py
@mldangelo-oai
mldangelo-oai marked this pull request as draft June 9, 2026 10:24

Copy link
Copy Markdown
Contributor Author

Critical re-review published as 7cdf0ed8 (tree d29b49d8) on current main (dfaedd1f). The review fixed two blockers: display-name-only correlation exemptions could hard-fail trusted models on unrelated CatBoost/LightGBM fragments, and relayed INFO findings lost the provenance required for late fail-closed severity restoration. Correlation exemptions now require producer-supplied same-fragment evidence; valid downgrade markers survive composition, while stale markers and unrelated original_severity evidence are handled safely. Focused QA: 263 passed; scoped Ruff, format, mypy, and diff checks clean. All live inline threads remain resolved.

@mldangelo-oai
mldangelo-oai marked this pull request as ready for review June 9, 2026 13:00
@mldangelo-oai
mldangelo-oai merged commit 603c782 into main Jun 9, 2026
26 of 27 checks passed
@mldangelo-oai
mldangelo-oai deleted the mdangelo/codex/fix-hf-whitelist-active-findings branch June 9, 2026 13:01
@github-actions github-actions Bot mentioned this pull request Jun 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant