Skip to content

fix: avoid exact-budget cloud pickle false positives - #1595

Merged
mldangelo-oai merged 5 commits into
mainfrom
mdangelo/codex/fix-cloud-sniff-boundary
Jun 9, 2026
Merged

mldangelo-oai merged 5 commits into
mainfrom
mdangelo/codex/fix-cloud-sniff-boundary

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Jun 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • distinguish complete cloud objects from budget-truncated prefixes before accepting protocol-less Pickle routing
  • extend cached probes when the complete object fits the remaining shared sniff budget
  • preserve an already strong prefix-only Pickle route when optional size proof or prefix extension is unavailable
  • reject contradictory tail-size evidence and corroborate claimed EOF with one extra byte when budget permits
  • charge every transferred sniff chunk immediately, including bytes returned before a later transport failure

False-positive / false-negative audit

  • exact-budget benign content is reclassified using the complete object when size can be proven
  • exact-budget and delayed-security-opcode malicious Pickles remain routed
  • an underreported SEEK_END/tell() result cannot suppress a dangerous tail
  • stale-low metadata is covered by a one-byte EOF probe when capacity remains
  • partial failed extension reads remain included in the later acquisition budget
  • inconclusive benign near-matches still fail closed when optional proof is unavailable
  • all reads remain bounded by the shared sniff budget

Validation

  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run --frozen pytest -q tests/utils/sources/test_cloud_storage.py: 290 passed
  • scoped Ruff check and format: clean
  • scoped mypy: clean
  • git diff --check: clean

All inline review threads are resolved. Exact published head: 349f6c4781b04f5a260b72ef1f2839f66cdf4ce5. Exact tree: 30b106bec1ce2a77d3b17f9816a2d854fd2777e0.

@mldangelo-oai
mldangelo-oai requested a review from mldangelo June 9, 2026 05:51
@mldangelo-oai
mldangelo-oai enabled auto-merge (squash) June 9, 2026 05:53
@github-actions

github-actions Bot commented Jun 9, 2026 •

Copy link
Copy Markdown
Contributor

Workflow run and artifacts

Performance Benchmarks

Compared 12 shared benchmarks with a regression threshold of 15%.
Status: 0 regressions, 0 improved, 12 stable, 0 new, 0 missing.
Aggregate shared-benchmark median: 827.65ms -> 799.99ms (-3.3%).

Workload Benchmark Target Size Files Baseline Current Change Status
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_hex] nested_hex 130 B 1 234.4us 267.9us +14.3% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_base64] nested_base64 98 B 1 233.5us 259.1us +11.0% stable
mixed-model-repository tests/benchmarks/test_scan_benchmarks.py::test_scan_release_candidate_repository release-candidate 547.3 KiB 32 280.34ms 260.11ms -7.2% stable
direct-malicious-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_direct_malicious_upload malicious_reduce 52 B 1 226.5us 238.7us +5.4% stable
clean-training-checkpoint tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_clean_training_checkpoint safe_large 278.2 KiB 1 69.65ms 73.37ms +5.3% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_raw] nested_raw 78 B 1 234.8us 247.0us +5.2% stable
warm-cache-rescan tests/benchmarks/test_scan_benchmarks.py::test_scan_warm_cached_repository_rescan release-candidate 547.3 KiB 32 60.16ms 57.19ms -4.9% stable
padded-multi-stream-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_padded_multi_stream_upload multi_stream_padded 4.1 KiB 1 266.4us 278.8us +4.6% stable
suspicious-pickle-intake tests/benchmarks/test_scan_benchmarks.py::test_scan_suspicious_pickle_intake suspicious-intake 183.8 KiB 4 73.01ms 69.93ms -4.2% stable
single-checkpoint-preflight tests/benchmarks/test_scan_benchmarks.py::test_scan_single_checkpoint_before_load single_checkpoint.pkl 183.0 KiB 1 37.73ms 36.76ms -2.6% stable
duplicate-heavy-registry tests/benchmarks/test_scan_benchmarks.py::test_scan_duplicate_registry_snapshot registry-snapshot 915.2 KiB 13 234.54ms 229.60ms -2.1% stable
chunked-upload-stream tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_chunked_upload_stream chunked_stream 278.2 KiB 1 71.02ms 71.73ms +1.0% stable

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c64835ad97

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/utils/sources/cloud_storage.py Outdated
Comment thread modelaudit/utils/sources/cloud_storage.py Outdated
@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/fix-cloud-sniff-boundary branch from 3889423 to 030d56d Compare June 9, 2026 08:22

Copy link
Copy Markdown
Contributor Author

Critical follow-up found one remaining false-positive edge in the no-tail-seek fallback. The branch preserved any prefix-only Pickle classification when EOF proof failed, so a benign 8-byte PNG was labeled as Pickle. The fallback now re-evaluates the cached bytes as a complete sample: a strong malicious Pickle signal is preserved, while ambiguous benign content fails closed with a classification error. Added the benign counterpart to the existing malicious backend regression. Complete cloud-storage module: 276 passed; scoped Ruff/format/mypy/diff checks are clean. Exact tree: 3fdd9bf36f47dceef1de704a9e246ba511305885.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 030d56d3f7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/utils/sources/cloud_storage.py
Comment thread modelaudit/utils/sources/cloud_storage.py Outdated
@mldangelo-oai
mldangelo-oai merged commit 350baa0 into main Jun 9, 2026
24 of 27 checks passed
@mldangelo-oai
mldangelo-oai deleted the mdangelo/codex/fix-cloud-sniff-boundary branch June 9, 2026 09:36

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 349f6c4781

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

detected_format == "pickle"
and sniff_budget is not None
and sniff_budget.remaining_bytes == 0
sniff_budget is not None

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Cover exact-size proof without max_size

Without max_size, selective routing has sniff_budget=None, so this size proof is skipped; a benign protocol-less-looking object exactly 8 KiB still returns pickle_routing_inconclusive/pickle before EOF can be proven. Please cover that default path too, per guidance.

Useful? React with 👍 / 👎.

@github-actions github-actions Bot mentioned this pull request Jun 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant