Skip to content

fix(cosmos3): default trust_remote_code to False in tokenizer load - #1571

Open
AmirF194 wants to merge 1 commit into
ModelTC:mainfrom
AmirF194:fix/1559-cosmos3-trust-remote-code-default
Open

AmirF194 wants to merge 1 commit into
ModelTC:mainfrom
AmirF194:fix/1559-cosmos3-trust-remote-code-default

Conversation

@AmirF194

Copy link
Copy Markdown

Fixes the first sink from the report: Cosmos3Runner.load_text_encoder hard-coded trust_remote_code=True with no way to turn it off, so a bundle's tokenizer_config.json auto_map ran unconditionally. It now reads trust_remote_code from config and defaults to False; set it explicitly if your tokenizer genuinely needs custom code.

Scope: this only covers the Cosmos3 tokenizer load. I didn't touch the metadata model_cls substitution in set_config.py or the other trust_remote_code=True calls in motus/model.py and paint_pipeline.py that the report also flags, those need an allowlist and their own review, so I left them out and used Refs instead of Fixes on the issue.

Added two tests: default is False, and the same failure shows on main today; explicit opt-in still works. Ran them plus ruff check/ruff format in a CPU-only container (SKIP_PLATFORM_CHECK=1, no GPU available here), both clean.

Cosmos3Runner.load_text_encoder hard-coded trust_remote_code=True with no
override, so a model bundle's tokenizer_config.json auto_map ran
unconditionally regardless of caller intent. It now reads trust_remote_code
from config and defaults to False.

Refs ModelTC#1559
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant