fix: avoid exact-budget cloud pickle false positives - #1595
Conversation
Performance BenchmarksCompared
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c64835ad97
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
3889423 to
030d56d
Compare
|
Critical follow-up found one remaining false-positive edge in the no-tail-seek fallback. The branch preserved any prefix-only Pickle classification when EOF proof failed, so a benign 8-byte PNG was labeled as Pickle. The fallback now re-evaluates the cached bytes as a complete sample: a strong malicious Pickle signal is preserved, while ambiguous benign content fails closed with a classification error. Added the benign counterpart to the existing malicious backend regression. Complete cloud-storage module: 276 passed; scoped Ruff/format/mypy/diff checks are clean. Exact tree: |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 030d56d3f7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…oud-sniff-boundary
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 349f6c4781
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| detected_format == "pickle" | ||
| and sniff_budget is not None | ||
| and sniff_budget.remaining_bytes == 0 | ||
| sniff_budget is not None |
There was a problem hiding this comment.
Cover exact-size proof without max_size
Without max_size, selective routing has sniff_budget=None, so this size proof is skipped; a benign protocol-less-looking object exactly 8 KiB still returns pickle_routing_inconclusive/pickle before EOF can be proven. Please cover that default path too, per guidance.
Useful? React with 👍 / 👎.
Summary
False-positive / false-negative audit
SEEK_END/tell()result cannot suppress a dangerous tailValidation
PROMPTFOO_DISABLE_TELEMETRY=1 uv run --frozen pytest -q tests/utils/sources/test_cloud_storage.py: 290 passedgit diff --check: cleanAll inline review threads are resolved. Exact published head:
349f6c4781b04f5a260b72ef1f2839f66cdf4ce5. Exact tree:30b106bec1ce2a77d3b17f9816a2d854fd2777e0.