fix: enforce MLflow artifact backend allowlist - #1564
Conversation
Performance BenchmarksCompared
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 824b057962
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex Please publish the already-validated local repair for all six unresolved review threads on this PR. The exact current-main local head is Required behavior:
Post-merge local validation: |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 824b057962
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Summary
Testing
Committed changes as |
|
Published remote head Key follow-ups beyond the original threads:
Validation: 76 MLflow integration tests, 3 affected CLI tests, scoped Ruff/mypy, Prettier, and diff check all pass. Resolving the six threads now; CI can continue asynchronously. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 99f3ff8462
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Addressed the P1 fail-closed review finding in published head Every delegated run/logged-model artifact target is now mandatory: the first exception, non-string path, Focused validation:
The inline thread is resolved. CI is running on the new head; continuing the PR queue per the audit workflow. |
|
Addressed the incomplete-scan review finding in
Focused validation:
Published tree: |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a65c598291
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
d034060 to
2dbdcac
Compare
|
Addressed both new review threads in |
|
Addressed both remaining review findings in live head |
2dbdcac to
ea4841a
Compare
|
Critical audit follow-up published at The review found an additional non-local fallback bypass: MLflow classifies remote Validation: the complete associated MLflow/CLI slice passes ( |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ea4841ad5f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…flow-uri-allowlist-review-edges
Pull request was converted to draft
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e0ba1688c3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Critical audit complete and published in Additional issues found and fixed during current-main integration:
Focused validation: 179 MLflow integration tests, 12 MLflow CLI tests, scoped mypy, Ruff, and diff checks all clean. The full local suite was intentionally left to CI per review instructions. All existing inline threads remain resolved. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f56567b437
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| not validated_path | ||
| or posixpath.isabs(validated_path) | ||
| or ntpath.isabs(validated_path) | ||
| or ntpath.splitdrive(validated_path)[0] |
There was a problem hiding this comment.
Reject Windows ADS paths before delegated downloads
On Windows, this only rejects drive-qualified paths, so an artifact path like model.pkl:payload still reaches download_artifacts() for an allowlisted non-standard repository. Such a downloader can write an NTFS alternate data stream under staging; the later directory validation/walk will not enumerate that stream, so the scan can pass without inspecting the downloaded payload. Reject : in delegated artifact paths on Windows before delegating the download.
Useful? React with 👍 / 👎.
| if target.optional_when_missing and not artifact_paths: | ||
| continue |
There was a problem hiding this comment.
Fail closed on empty mandatory MLflow listings
If a mandatory allowlisted standard MLflow target lists zero files, this falls through and _download_validated_mlflow_files() returns an empty staging dir, so an absent or transiently empty listing is scanned as clean without downloading artifacts. Fail closed unless optional. guidance
Useful? React with 👍 / 👎.
Summary
MODELAUDIT_MLFLOW_ALLOWED_ARTIFACT_URISSecurity review
Validation
f56567b4374e95cdce48773e24b00ff8daec66a221956abfe97ec8312bb4f6312b5da99ec0fa640e4f6a61017b696f533136eec1bb197bcc3b5e9d2btests/integrations/test_mlflow_integration.py:179 passed12 passed, 244 deselectedgit diff --check: clean