fix(safetensors): prefer bounded framing over zlib magic - #1623
Conversation
Performance BenchmarksCompared
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 988dd28e70
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…fetensors-zlib-routing
|
Exact head @codex review |
|
@codex review |
…fetensors-zlib-routing
|
Refreshed exact head @codex review |
|
Codex Review: Didn't find any major issues. Breezy! ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
…fetensors-zlib-routing
|
Exact current head @codex review |
|
Codex Review: Didn't find any major issues. Delightful! ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
…fetensors-zlib-routing
|
Exact current head @codex review |
|
Codex Review: Didn't find any major issues. Nice work! ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
…fetensors-zlib-routing
|
Exact current head @codex review |
|
Codex Review: Didn't find any major issues. Keep them coming! ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Summary
78 9c)Root cause
File routing checked compression magic before strong SafeTensors framing. A valid SafeTensors header length such as
0x9c78therefore looked like zlib and bypassed the SafeTensors scanner.Validation
PROMPTFOO_DISABLE_TELEMETRY=1 PYTHONPATH=$PWD /Users/mdangelo/code/modelaudit/.venv/bin/python -m pytest tests/scanners/test_safetensors_scanner.py tests/utils/file/test_filetype.py -q(383 passed)PYTHONPATH=$PWD /Users/mdangelo/code/modelaudit/.venv/bin/python -m mypy modelaudit/utils/file/detection.py tests/scanners/test_safetensors_scanner.py tests/utils/file/test_filetype.py(Success: no issues found)git diff --checkpassedThe regression test demonstrates that the
78 9cfixture now reaches the SafeTensors scanner and still reports malicious metadata, while the existing compression-routing suite covers genuine zlib controls.