Skip to content

Commit a2c18e4

Browse files
Fix: Block deferred-computation exploit and harden validator (#64)
* Fix: Block deferred-computation exploit and harden validator - AST scanner: reject forbidden dunder method definitions (e.g. def __getattribute__) that bypassed the existing ast.Attribute check - _validate_return_type: expand MRO proxy detection to cover __getattribute__, __get__, __set__, __set_name__ in addition to __getattr__ - Add timing guard on final_state access to detect training compute deferred into state gathering (rejects if >50% of training wall_time) - Harden final_state dict-value proxy detection with same expanded hook set - Basilica polling: reuse single httpx client, increase read timeout to 60s, dynamic max_consecutive_errors based on remaining time budget - Set cudnn.deterministic=True, cudnn.benchmark=False for reproducibility - Remove wall_time rank divergence check (use min across ranks instead) - Bump docker memory in simulate_validator.py to 400g Made-with: Cursor * Fix arbos container cleanup killing unrelated containers The _post_run_cleanup in LocalDockerTester was killing ALL templar-eval containers by filtering on ancestor image. This caused manual test runs and other instances to be SIGKILL'd (exit 137) mid-execution. Now each arbos session labels its containers and only cleans up its own. Also remove unnecessary --memory and --shm-size from simulate_validator docker examples (--ipc=host already handles shared memory, and the memory limit was not the cause of the crashes). Made-with: Cursor * Align arbos BasilicaTester with production runner Switch from low-level create_deployment_async to deploy_async, add log streaming, result validation, proper exception handling (DeploymentTimeout/DeploymentFailed), and update stale defaults. Made-with: Cursor
1 parent 2564704 commit a2c18e4

4 files changed

Lines changed: 408 additions & 147 deletions

File tree

0 commit comments

Comments
 (0)