Skip to content

fix(safetensors): accept empty tensor offsets - #1607

Merged
mldangelo-oai merged 12 commits into
mainfrom
mdangelo/codex/fix-empty-safetensor-offsets
Jun 10, 2026
Merged

mldangelo-oai merged 12 commits into
mainfrom
mdangelo/codex/fix-empty-safetensor-offsets

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Jun 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • accept equal SafeTensors offsets for supported empty tensors
  • retain negative-offset, reversed-range, upper-bound, shape, continuity, and full-data-coverage checks
  • match upstream native usize offset and bit-size overflow validation
  • add an official safetensors.numpy round-trip regression, malformed zero-byte negative control, deterministic equal-start ordering coverage, and simulated native-width regressions

Real-world reproduction

The AgentBox Hugging Face audit found the same false-positive critical finding in three pinned FP8 artifacts from:

Comfy-Org/Wan_2.2_ComfyUI_Repackaged@f97505f0d38bea4897c970db66cb5f97f73676de

The scaled_fp8 tensor has shape [0] and equal in-bounds offsets. The pinned control artifact is 14,296,064,656 bytes with SHA-256 aa2f6b6f4cfc8a75a273a075db31730530f93320a996b153b8825205c3a3c498. Its exact 181,600-byte header prefix has SHA-256 fa2be54fd2d897749cd61fcadfdefead28fe958b9376d8d5ec91bd68289da031.

The SafeTensors format specification explicitly permits tensors with a zero dimension and defines stored byte size as END - BEGIN.

After this change, a sparse exact-header replay passes offset and size validation with no issues. A tensor with shape [1] and offsets [0, 0] still fails critically because its expected four bytes do not match the zero-byte range.

Validation

  • 67 passed in tests/scanners/test_safetensors_scanner.py with both safetensors==0.7.0 and the supported floor safetensors==0.4.0
  • full Ruff format and autofix lint passes (418 files)
  • full mypy pass (473 source files)
  • benign empty-tensor round trip, malformed nonempty zero-byte range, and malicious metadata paths all pass their focused regressions
  • broader non-slow suite reached 12,890 passed, 381 skipped before two local baseline/environment failures: the read-only sandbox blocks /home/dev-user/.modelaudit (the cache test passes with writable HOME), and a merged-main cached-shard alias test fails independently of the tensor-entry delta; fresh CI is the authoritative cross-platform run

@github-actions

github-actions Bot commented Jun 10, 2026 •

Copy link
Copy Markdown
Contributor

Workflow run and artifacts

Performance Benchmarks

Compared 12 shared benchmarks with a regression threshold of 15%.
Status: 0 regressions, 0 improved, 12 stable, 0 new, 0 missing.
Aggregate shared-benchmark median: 1.419s -> 1.417s (-0.2%).

Workload Benchmark Target Size Files Baseline Current Change Status
direct-malicious-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_direct_malicious_upload malicious_reduce 52 B 1 429.4us 458.8us +6.9% stable
padded-multi-stream-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_padded_multi_stream_upload multi_stream_padded 4.1 KiB 1 568.0us 538.9us -5.1% stable
warm-cache-rescan tests/benchmarks/test_scan_benchmarks.py::test_scan_warm_cached_repository_rescan release-candidate 547.3 KiB 32 96.77ms 92.10ms -4.8% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_base64] nested_base64 98 B 1 459.8us 467.6us +1.7% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_raw] nested_raw 78 B 1 468.7us 473.8us +1.1% stable
single-checkpoint-preflight tests/benchmarks/test_scan_benchmarks.py::test_scan_single_checkpoint_before_load single_checkpoint.pkl 183.0 KiB 1 72.70ms 72.19ms -0.7% stable
chunked-upload-stream tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_chunked_upload_stream chunked_stream 278.2 KiB 1 114.99ms 115.76ms +0.7% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_hex] nested_hex 130 B 1 487.4us 490.4us +0.6% stable
clean-training-checkpoint tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_clean_training_checkpoint safe_large 278.2 KiB 1 111.93ms 112.23ms +0.3% stable
duplicate-heavy-registry tests/benchmarks/test_scan_benchmarks.py::test_scan_duplicate_registry_snapshot registry-snapshot 915.2 KiB 13 401.30ms 402.13ms +0.2% stable
mixed-model-repository tests/benchmarks/test_scan_benchmarks.py::test_scan_release_candidate_repository release-candidate 547.3 KiB 32 476.18ms 476.96ms +0.2% stable
suspicious-pickle-intake tests/benchmarks/test_scan_benchmarks.py::test_scan_suspicious_pickle_intake suspicious-intake 183.8 KiB 4 142.93ms 142.97ms +0.0% stable

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 84cf296b57

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/scanners/safetensors_scanner.py Outdated
@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Please review exact head f6144de0dabeac4919e9786317c98d19a6945d09 after merging latest origin/main. Focus on equal-offset empty tensors, native usize offset bounds, bit-width overflow parity with safetensors, and dependency-floor-compatible regressions.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Nice work!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai
mldangelo-oai enabled auto-merge (squash) June 10, 2026 14:21
@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review\n\nPlease review exact head d632d621205eb7b5934d9388639bf17772fa5e53 after merging current origin/main.

@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Please review exact head d632d621205eb7b5934d9388639bf17772fa5e53 after merging current origin/main.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d632d62120

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/scanners/safetensors_scanner.py
Comment thread modelaudit/scanners/safetensors_scanner.py Outdated
@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Please review exact head 57ce2d3ac81582eaa63d867f753c0fe9f64ddb8f after addressing both review threads and merging current origin/main (c7690976719aabdd3152948a26c1ec07d9294b1f).

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Breezy!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Please review exact head 572f1f71393c12d95fb1b401f23d94318d401e5f after merging latest origin/main (e407fb4fbc9837cea928ef20a95d34c4b0a9c42a).

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep it up!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Please review exact head 77cd7943c46f6a77131d0ba810845f37b38d1743 after merging latest origin/main (22bc654b6a01dd396c45ea1428a73ddac866ad3a).

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep it up!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai
mldangelo-oai merged commit 9d547bb into main Jun 10, 2026
28 of 32 checks passed
@mldangelo-oai
mldangelo-oai deleted the mdangelo/codex/fix-empty-safetensor-offsets branch June 10, 2026 16:12
@github-actions github-actions Bot mentioned this pull request Jun 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant