JumpStartModel ignores tolerate_vulnerable_model and tolerate_deprecated_model: get_jumpstart_configs does not forward the flags #6130

Description

@evakravi

PySDK Version

  • PySDK V2 (2.x)
  • PySDK V3 (3.x)

Describe the bug

get_jumpstart_configs accepts no tolerate_vulnerable_model or tolerate_deprecated_model argument. It calls verify_model_region_and_return_specs without them, so the callee falls back to its False defaults and re-runs the model gate:

# sagemaker/jumpstart/utils.pydefget_jumpstart_configs(
region: str,
model_id: str,
model_version: str,
config_names: Optional[List[str]] =None,
sagemaker_session: Optional[Session] =constants.DEFAULT_JUMPSTART_SAGEMAKER_SESSION,
scope: enums.JumpStartScriptScope=enums.JumpStartScriptScope.INFERENCE,
model_type: enums.JumpStartModelType=enums.JumpStartModelType.OPEN_WEIGHTS,
hub_arn: Optional[str] =None,
) ->Dict[str, JumpStartMetadataConfig]:
model_specs=verify_model_region_and_return_specs(
region=region,
model_id=model_id,
version=model_version,
sagemaker_session=sagemaker_session,
scope=scope,
model_type=model_type,
hub_arn=hub_arn,
) # <-- tolerate_vulnerable_model / tolerate_deprecated_model not forwarded

JumpStartModel.__init__ calls it as its final statement, after super().__init__() has already succeeded:

# sagemaker/jumpstart/model.pyself._metadata_configs=get_jumpstart_configs(
region=self.region,
model_id=self.model_id,
model_version=self.model_version,
sagemaker_session=self.sagemaker_session,
model_type=self.model_type,
hub_arn=self.hub_arn,
)

So JumpStartModel(..., tolerate_vulnerable_model=True) raises VulnerableJumpStartModelError anyway. The constructor honors the flag through every other lookup and then discards it on the last line. The same applies to tolerate_deprecated_model and DeprecatedJumpStartModelError.

The flags are unusable for any flagged model: the object cannot be constructed, so deploy is unreachable. The failure is also non-obvious, because the traceback points at utils.py inside the gate rather than at anything the caller passed.

To reproduce

Any model whose specs carry inference_vulnerable: true reproduces this. tolerate_vulnerable_model=True is ignored:

fromsagemaker.jumpstart.modelimportJumpStartModel# Any model_id whose specs set inference_vulnerable=true.model=JumpStartModel(
model_id="<vulnerable-model-id>",
tolerate_vulnerable_model=True,
tolerate_deprecated_model=True,
)
sagemaker.jumpstart.exceptions.VulnerableJumpStartModelError: Version '1.0.0' of JumpStart model
'<vulnerable-model-id>' has at least 1 vulnerable dependency in the inference script.
...
List of vulnerabilities: CVE-2024-11393
/site-packages/sagemaker/jumpstart/utils.py:726: VulnerableJumpStartModelError

The dropped argument is visible without a flagged model:

>>>importinspect>>>fromsagemaker.jumpstart.utilsimportget_jumpstart_configs>>> [pforpininspect.signature(get_jumpstart_configs).parametersif"tolerate"inp]
[]

Expected behavior

tolerate_vulnerable_model=True and tolerate_deprecated_model=True suppress the gate through the whole constructor, including the metadata config lookup. Construction completes and deploy proceeds.

Empty configs are a reasonable result for a flagged model. _metadata_configs feeds only list_deployment_configs and the benchmark metrics helpers, so no other code path degrades.

Suggested fix: add the two parameters to get_jumpstart_configs, default both to False to preserve current behavior for existing callers, and forward them to verify_model_region_and_return_specs. Then pass self.tolerate_vulnerable_model and self.tolerate_deprecated_model at the JumpStartModel.__init__ call site. Both attributes are already set earlier in that constructor, so no new plumbing is needed.

JumpStartEstimator.list_training_configs has the same gap and would be fixed by the same signature change.

Screenshots or logs

Included above.

System information

  • SageMaker Python SDK version: 2.257.1 and 2.257.5 confirmed; the same code is present on master at sagemaker-core/src/sagemaker/core/jumpstart/utils.py, so 3.x is affected
  • Framework name (eg. PyTorch) or algorithm (eg. KMeans): JumpStart (JumpStartModel, JumpStartEstimator)
  • Framework version: n/a
  • Python version: 3.10
  • CPU or GPU: both
  • Custom Docker image (Y/N): N

Additional context

In 3.x the same get_jumpstart_configs has no tolerance parameters, and ModelBuilder._ensure_metadata_configs in sagemaker-serve/src/sagemaker/serve/model_builder_utils.py calls it without them, so a flagged model raises there too.

This blocked a release pipeline that deploys JumpStart models for validation. Such a pipeline must deploy a model that is flagged, precisely because it needs to test the model, which is what the tolerance flags are for.

The only workaround we found is to replace the lookup and swallow the two gate errors. It is fragile, because it depends on SDK internals and on which modules bound the name at import time:

importsagemaker.jumpstart.estimatorimportsagemaker.jumpstart.modelimportsagemaker.jumpstart.utilsfromsagemaker.jumpstart.exceptionsimportDeprecatedJumpStartModelError, VulnerableJumpStartModelError_original=sagemaker.jumpstart.utils.get_jumpstart_configsdef_tolerant_get_jumpstart_configs(*args, **kwargs):
try:
return_original(*args, **kwargs)
except (VulnerableJumpStartModelError, DeprecatedJumpStartModelError):
return {}
# Each module that imported the name by value needs the replacement.formodulein (sagemaker.jumpstart.utils, sagemaker.jumpstart.model, sagemaker.jumpstart.estimator):
module.get_jumpstart_configs=_tolerant_get_jumpstart_configs

Worth noting that in the case that prompted this, the vulnerability flag was itself inherited from an inference script bundle the model never runs. That is a separate metadata concern. The SDK bug is that the documented escape hatch does not work.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
       blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
      }
      } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
      })();
      (function(){
      try {
      var __m = "github.com";
      var __re = new RegExp('^' + "github\\.com" + '
      
      Skip to content

      JumpStartModel ignores tolerate_vulnerable_model and tolerate_deprecated_model: get_jumpstart_configs does not forward the flags #6130

      Description

      @evakravi

      PySDK Version

      • PySDK V2 (2.x)
      • PySDK V3 (3.x)

      Describe the bug

      get_jumpstart_configs accepts no tolerate_vulnerable_model or tolerate_deprecated_model argument. It calls verify_model_region_and_return_specs without them, so the callee falls back to its False defaults and re-runs the model gate:

      # sagemaker/jumpstart/utils.pydefget_jumpstart_configs(
      region: str,
      model_id: str,
      model_version: str,
      config_names: Optional[List[str]] =None,
      sagemaker_session: Optional[Session] =constants.DEFAULT_JUMPSTART_SAGEMAKER_SESSION,
      scope: enums.JumpStartScriptScope=enums.JumpStartScriptScope.INFERENCE,
      model_type: enums.JumpStartModelType=enums.JumpStartModelType.OPEN_WEIGHTS,
      hub_arn: Optional[str] =None,
      ) ->Dict[str, JumpStartMetadataConfig]:
      model_specs=verify_model_region_and_return_specs(
      region=region,
      model_id=model_id,
      version=model_version,
      sagemaker_session=sagemaker_session,
      scope=scope,
      model_type=model_type,
      hub_arn=hub_arn,
      ) # <-- tolerate_vulnerable_model / tolerate_deprecated_model not forwarded

      JumpStartModel.__init__ calls it as its final statement, after super().__init__() has already succeeded:

      # sagemaker/jumpstart/model.pyself._metadata_configs=get_jumpstart_configs(
      region=self.region,
      model_id=self.model_id,
      model_version=self.model_version,
      sagemaker_session=self.sagemaker_session,
      model_type=self.model_type,
      hub_arn=self.hub_arn,
      )

      So JumpStartModel(..., tolerate_vulnerable_model=True) raises VulnerableJumpStartModelError anyway. The constructor honors the flag through every other lookup and then discards it on the last line. The same applies to tolerate_deprecated_model and DeprecatedJumpStartModelError.

      The flags are unusable for any flagged model: the object cannot be constructed, so deploy is unreachable. The failure is also non-obvious, because the traceback points at utils.py inside the gate rather than at anything the caller passed.

      To reproduce

      Any model whose specs carry inference_vulnerable: true reproduces this. tolerate_vulnerable_model=True is ignored:

      fromsagemaker.jumpstart.modelimportJumpStartModel# Any model_id whose specs set inference_vulnerable=true.model=JumpStartModel(
      model_id="<vulnerable-model-id>",
      tolerate_vulnerable_model=True,
      tolerate_deprecated_model=True,
      )
      sagemaker.jumpstart.exceptions.VulnerableJumpStartModelError: Version '1.0.0' of JumpStart model
      '<vulnerable-model-id>' has at least 1 vulnerable dependency in the inference script.
      ...
      List of vulnerabilities: CVE-2024-11393
      /site-packages/sagemaker/jumpstart/utils.py:726: VulnerableJumpStartModelError
      

      The dropped argument is visible without a flagged model:

      >>>importinspect>>>fromsagemaker.jumpstart.utilsimportget_jumpstart_configs>>> [pforpininspect.signature(get_jumpstart_configs).parametersif"tolerate"inp]
      []

      Expected behavior

      tolerate_vulnerable_model=True and tolerate_deprecated_model=True suppress the gate through the whole constructor, including the metadata config lookup. Construction completes and deploy proceeds.

      Empty configs are a reasonable result for a flagged model. _metadata_configs feeds only list_deployment_configs and the benchmark metrics helpers, so no other code path degrades.

      Suggested fix: add the two parameters to get_jumpstart_configs, default both to False to preserve current behavior for existing callers, and forward them to verify_model_region_and_return_specs. Then pass self.tolerate_vulnerable_model and self.tolerate_deprecated_model at the JumpStartModel.__init__ call site. Both attributes are already set earlier in that constructor, so no new plumbing is needed.

      JumpStartEstimator.list_training_configs has the same gap and would be fixed by the same signature change.

      Screenshots or logs

      Included above.

      System information

      • SageMaker Python SDK version: 2.257.1 and 2.257.5 confirmed; the same code is present on master at sagemaker-core/src/sagemaker/core/jumpstart/utils.py, so 3.x is affected
      • Framework name (eg. PyTorch) or algorithm (eg. KMeans): JumpStart (JumpStartModel, JumpStartEstimator)
      • Framework version: n/a
      • Python version: 3.10
      • CPU or GPU: both
      • Custom Docker image (Y/N): N

      Additional context

      In 3.x the same get_jumpstart_configs has no tolerance parameters, and ModelBuilder._ensure_metadata_configs in sagemaker-serve/src/sagemaker/serve/model_builder_utils.py calls it without them, so a flagged model raises there too.

      This blocked a release pipeline that deploys JumpStart models for validation. Such a pipeline must deploy a model that is flagged, precisely because it needs to test the model, which is what the tolerance flags are for.

      The only workaround we found is to replace the lookup and swallow the two gate errors. It is fragile, because it depends on SDK internals and on which modules bound the name at import time:

      importsagemaker.jumpstart.estimatorimportsagemaker.jumpstart.modelimportsagemaker.jumpstart.utilsfromsagemaker.jumpstart.exceptionsimportDeprecatedJumpStartModelError, VulnerableJumpStartModelError_original=sagemaker.jumpstart.utils.get_jumpstart_configsdef_tolerant_get_jumpstart_configs(*args, **kwargs):
      try:
      return_original(*args, **kwargs)
      except (VulnerableJumpStartModelError, DeprecatedJumpStartModelError):
      return {}
      # Each module that imported the name by value needs the replacement.formodulein (sagemaker.jumpstart.utils, sagemaker.jumpstart.model, sagemaker.jumpstart.estimator):
      module.get_jumpstart_configs=_tolerant_get_jumpstart_configs

      Worth noting that in the case that prompted this, the vulnerability flag was itself inherited from an inference script bundle the model never runs. That is a separate metadata concern. The SDK bug is that the documented escape hatch does not work.

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        No labels
        No labels

        Type

        No type

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
          Skip to content

          JumpStartModel ignores tolerate_vulnerable_model and tolerate_deprecated_model: get_jumpstart_configs does not forward the flags #6130

          Description

          @evakravi

          PySDK Version

          • PySDK V2 (2.x)
          • PySDK V3 (3.x)

          Describe the bug

          get_jumpstart_configs accepts no tolerate_vulnerable_model or tolerate_deprecated_model argument. It calls verify_model_region_and_return_specs without them, so the callee falls back to its False defaults and re-runs the model gate:

          # sagemaker/jumpstart/utils.pydefget_jumpstart_configs(
          region: str,
          model_id: str,
          model_version: str,
          config_names: Optional[List[str]] =None,
          sagemaker_session: Optional[Session] =constants.DEFAULT_JUMPSTART_SAGEMAKER_SESSION,
          scope: enums.JumpStartScriptScope=enums.JumpStartScriptScope.INFERENCE,
          model_type: enums.JumpStartModelType=enums.JumpStartModelType.OPEN_WEIGHTS,
          hub_arn: Optional[str] =None,
          ) ->Dict[str, JumpStartMetadataConfig]:
          model_specs=verify_model_region_and_return_specs(
          region=region,
          model_id=model_id,
          version=model_version,
          sagemaker_session=sagemaker_session,
          scope=scope,
          model_type=model_type,
          hub_arn=hub_arn,
          ) # <-- tolerate_vulnerable_model / tolerate_deprecated_model not forwarded

          JumpStartModel.__init__ calls it as its final statement, after super().__init__() has already succeeded:

          # sagemaker/jumpstart/model.pyself._metadata_configs=get_jumpstart_configs(
          region=self.region,
          model_id=self.model_id,
          model_version=self.model_version,
          sagemaker_session=self.sagemaker_session,
          model_type=self.model_type,
          hub_arn=self.hub_arn,
          )

          So JumpStartModel(..., tolerate_vulnerable_model=True) raises VulnerableJumpStartModelError anyway. The constructor honors the flag through every other lookup and then discards it on the last line. The same applies to tolerate_deprecated_model and DeprecatedJumpStartModelError.

          The flags are unusable for any flagged model: the object cannot be constructed, so deploy is unreachable. The failure is also non-obvious, because the traceback points at utils.py inside the gate rather than at anything the caller passed.

          To reproduce

          Any model whose specs carry inference_vulnerable: true reproduces this. tolerate_vulnerable_model=True is ignored:

          fromsagemaker.jumpstart.modelimportJumpStartModel# Any model_id whose specs set inference_vulnerable=true.model=JumpStartModel(
          model_id="<vulnerable-model-id>",
          tolerate_vulnerable_model=True,
          tolerate_deprecated_model=True,
          )
          sagemaker.jumpstart.exceptions.VulnerableJumpStartModelError: Version '1.0.0' of JumpStart model
          '<vulnerable-model-id>' has at least 1 vulnerable dependency in the inference script.
          ...
          List of vulnerabilities: CVE-2024-11393
          /site-packages/sagemaker/jumpstart/utils.py:726: VulnerableJumpStartModelError
          

          The dropped argument is visible without a flagged model:

          >>>importinspect>>>fromsagemaker.jumpstart.utilsimportget_jumpstart_configs>>> [pforpininspect.signature(get_jumpstart_configs).parametersif"tolerate"inp]
          []

          Expected behavior

          tolerate_vulnerable_model=True and tolerate_deprecated_model=True suppress the gate through the whole constructor, including the metadata config lookup. Construction completes and deploy proceeds.

          Empty configs are a reasonable result for a flagged model. _metadata_configs feeds only list_deployment_configs and the benchmark metrics helpers, so no other code path degrades.

          Suggested fix: add the two parameters to get_jumpstart_configs, default both to False to preserve current behavior for existing callers, and forward them to verify_model_region_and_return_specs. Then pass self.tolerate_vulnerable_model and self.tolerate_deprecated_model at the JumpStartModel.__init__ call site. Both attributes are already set earlier in that constructor, so no new plumbing is needed.

          JumpStartEstimator.list_training_configs has the same gap and would be fixed by the same signature change.

          Screenshots or logs

          Included above.

          System information

          • SageMaker Python SDK version: 2.257.1 and 2.257.5 confirmed; the same code is present on master at sagemaker-core/src/sagemaker/core/jumpstart/utils.py, so 3.x is affected
          • Framework name (eg. PyTorch) or algorithm (eg. KMeans): JumpStart (JumpStartModel, JumpStartEstimator)
          • Framework version: n/a
          • Python version: 3.10
          • CPU or GPU: both
          • Custom Docker image (Y/N): N

          Additional context

          In 3.x the same get_jumpstart_configs has no tolerance parameters, and ModelBuilder._ensure_metadata_configs in sagemaker-serve/src/sagemaker/serve/model_builder_utils.py calls it without them, so a flagged model raises there too.

          This blocked a release pipeline that deploys JumpStart models for validation. Such a pipeline must deploy a model that is flagged, precisely because it needs to test the model, which is what the tolerance flags are for.

          The only workaround we found is to replace the lookup and swallow the two gate errors. It is fragile, because it depends on SDK internals and on which modules bound the name at import time:

          importsagemaker.jumpstart.estimatorimportsagemaker.jumpstart.modelimportsagemaker.jumpstart.utilsfromsagemaker.jumpstart.exceptionsimportDeprecatedJumpStartModelError, VulnerableJumpStartModelError_original=sagemaker.jumpstart.utils.get_jumpstart_configsdef_tolerant_get_jumpstart_configs(*args, **kwargs):
          try:
          return_original(*args, **kwargs)
          except (VulnerableJumpStartModelError, DeprecatedJumpStartModelError):
          return {}
          # Each module that imported the name by value needs the replacement.formodulein (sagemaker.jumpstart.utils, sagemaker.jumpstart.model, sagemaker.jumpstart.estimator):
          module.get_jumpstart_configs=_tolerant_get_jumpstart_configs

          Worth noting that in the case that prompted this, the vulnerability flag was itself inherited from an inference script bundle the model never runs. That is a separate metadata concern. The SDK bug is that the documented escape hatch does not work.

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            No labels
            No labels

            Type

            No type

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              JumpStartModel ignores tolerate_vulnerable_model and tolerate_deprecated_model: get_jumpstart_configs does not forward the flags #6130

              Description

              @evakravi

              PySDK Version

              • PySDK V2 (2.x)
              • PySDK V3 (3.x)

              Describe the bug

              get_jumpstart_configs accepts no tolerate_vulnerable_model or tolerate_deprecated_model argument. It calls verify_model_region_and_return_specs without them, so the callee falls back to its False defaults and re-runs the model gate:

              # sagemaker/jumpstart/utils.pydefget_jumpstart_configs(
              region: str,
              model_id: str,
              model_version: str,
              config_names: Optional[List[str]] =None,
              sagemaker_session: Optional[Session] =constants.DEFAULT_JUMPSTART_SAGEMAKER_SESSION,
              scope: enums.JumpStartScriptScope=enums.JumpStartScriptScope.INFERENCE,
              model_type: enums.JumpStartModelType=enums.JumpStartModelType.OPEN_WEIGHTS,
              hub_arn: Optional[str] =None,
              ) ->Dict[str, JumpStartMetadataConfig]:
              model_specs=verify_model_region_and_return_specs(
              region=region,
              model_id=model_id,
              version=model_version,
              sagemaker_session=sagemaker_session,
              scope=scope,
              model_type=model_type,
              hub_arn=hub_arn,
              ) # <-- tolerate_vulnerable_model / tolerate_deprecated_model not forwarded

              JumpStartModel.__init__ calls it as its final statement, after super().__init__() has already succeeded:

              # sagemaker/jumpstart/model.pyself._metadata_configs=get_jumpstart_configs(
              region=self.region,
              model_id=self.model_id,
              model_version=self.model_version,
              sagemaker_session=self.sagemaker_session,
              model_type=self.model_type,
              hub_arn=self.hub_arn,
              )

              So JumpStartModel(..., tolerate_vulnerable_model=True) raises VulnerableJumpStartModelError anyway. The constructor honors the flag through every other lookup and then discards it on the last line. The same applies to tolerate_deprecated_model and DeprecatedJumpStartModelError.

              The flags are unusable for any flagged model: the object cannot be constructed, so deploy is unreachable. The failure is also non-obvious, because the traceback points at utils.py inside the gate rather than at anything the caller passed.

              To reproduce

              Any model whose specs carry inference_vulnerable: true reproduces this. tolerate_vulnerable_model=True is ignored:

              fromsagemaker.jumpstart.modelimportJumpStartModel# Any model_id whose specs set inference_vulnerable=true.model=JumpStartModel(
              model_id="<vulnerable-model-id>",
              tolerate_vulnerable_model=True,
              tolerate_deprecated_model=True,
              )
              sagemaker.jumpstart.exceptions.VulnerableJumpStartModelError: Version '1.0.0' of JumpStart model
              '<vulnerable-model-id>' has at least 1 vulnerable dependency in the inference script.
              ...
              List of vulnerabilities: CVE-2024-11393
              /site-packages/sagemaker/jumpstart/utils.py:726: VulnerableJumpStartModelError
              

              The dropped argument is visible without a flagged model:

              >>>importinspect>>>fromsagemaker.jumpstart.utilsimportget_jumpstart_configs>>> [pforpininspect.signature(get_jumpstart_configs).parametersif"tolerate"inp]
              []

              Expected behavior

              tolerate_vulnerable_model=True and tolerate_deprecated_model=True suppress the gate through the whole constructor, including the metadata config lookup. Construction completes and deploy proceeds.

              Empty configs are a reasonable result for a flagged model. _metadata_configs feeds only list_deployment_configs and the benchmark metrics helpers, so no other code path degrades.

              Suggested fix: add the two parameters to get_jumpstart_configs, default both to False to preserve current behavior for existing callers, and forward them to verify_model_region_and_return_specs. Then pass self.tolerate_vulnerable_model and self.tolerate_deprecated_model at the JumpStartModel.__init__ call site. Both attributes are already set earlier in that constructor, so no new plumbing is needed.

              JumpStartEstimator.list_training_configs has the same gap and would be fixed by the same signature change.

              Screenshots or logs

              Included above.

              System information

              • SageMaker Python SDK version: 2.257.1 and 2.257.5 confirmed; the same code is present on master at sagemaker-core/src/sagemaker/core/jumpstart/utils.py, so 3.x is affected
              • Framework name (eg. PyTorch) or algorithm (eg. KMeans): JumpStart (JumpStartModel, JumpStartEstimator)
              • Framework version: n/a
              • Python version: 3.10
              • CPU or GPU: both
              • Custom Docker image (Y/N): N

              Additional context

              In 3.x the same get_jumpstart_configs has no tolerance parameters, and ModelBuilder._ensure_metadata_configs in sagemaker-serve/src/sagemaker/serve/model_builder_utils.py calls it without them, so a flagged model raises there too.

              This blocked a release pipeline that deploys JumpStart models for validation. Such a pipeline must deploy a model that is flagged, precisely because it needs to test the model, which is what the tolerance flags are for.

              The only workaround we found is to replace the lookup and swallow the two gate errors. It is fragile, because it depends on SDK internals and on which modules bound the name at import time:

              importsagemaker.jumpstart.estimatorimportsagemaker.jumpstart.modelimportsagemaker.jumpstart.utilsfromsagemaker.jumpstart.exceptionsimportDeprecatedJumpStartModelError, VulnerableJumpStartModelError_original=sagemaker.jumpstart.utils.get_jumpstart_configsdef_tolerant_get_jumpstart_configs(*args, **kwargs):
              try:
              return_original(*args, **kwargs)
              except (VulnerableJumpStartModelError, DeprecatedJumpStartModelError):
              return {}
              # Each module that imported the name by value needs the replacement.formodulein (sagemaker.jumpstart.utils, sagemaker.jumpstart.model, sagemaker.jumpstart.estimator):
              module.get_jumpstart_configs=_tolerant_get_jumpstart_configs

              Worth noting that in the case that prompted this, the vulnerability flag was itself inherited from an inference script bundle the model never runs. That is a separate metadata concern. The SDK bug is that the documented escape hatch does not work.

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                No labels
                No labels

                Type

                No type

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions

                  , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
                  Skip to content

                  JumpStartModel ignores tolerate_vulnerable_model and tolerate_deprecated_model: get_jumpstart_configs does not forward the flags #6130

                  Description

                  @evakravi

                  PySDK Version

                  • PySDK V2 (2.x)
                  • PySDK V3 (3.x)

                  Describe the bug

                  get_jumpstart_configs accepts no tolerate_vulnerable_model or tolerate_deprecated_model argument. It calls verify_model_region_and_return_specs without them, so the callee falls back to its False defaults and re-runs the model gate:

                  # sagemaker/jumpstart/utils.pydefget_jumpstart_configs(
                  region: str,
                  model_id: str,
                  model_version: str,
                  config_names: Optional[List[str]] =None,
                  sagemaker_session: Optional[Session] =constants.DEFAULT_JUMPSTART_SAGEMAKER_SESSION,
                  scope: enums.JumpStartScriptScope=enums.JumpStartScriptScope.INFERENCE,
                  model_type: enums.JumpStartModelType=enums.JumpStartModelType.OPEN_WEIGHTS,
                  hub_arn: Optional[str] =None,
                  ) ->Dict[str, JumpStartMetadataConfig]:
                  model_specs=verify_model_region_and_return_specs(
                  region=region,
                  model_id=model_id,
                  version=model_version,
                  sagemaker_session=sagemaker_session,
                  scope=scope,
                  model_type=model_type,
                  hub_arn=hub_arn,
                  ) # <-- tolerate_vulnerable_model / tolerate_deprecated_model not forwarded

                  JumpStartModel.__init__ calls it as its final statement, after super().__init__() has already succeeded:

                  # sagemaker/jumpstart/model.pyself._metadata_configs=get_jumpstart_configs(
                  region=self.region,
                  model_id=self.model_id,
                  model_version=self.model_version,
                  sagemaker_session=self.sagemaker_session,
                  model_type=self.model_type,
                  hub_arn=self.hub_arn,
                  )

                  So JumpStartModel(..., tolerate_vulnerable_model=True) raises VulnerableJumpStartModelError anyway. The constructor honors the flag through every other lookup and then discards it on the last line. The same applies to tolerate_deprecated_model and DeprecatedJumpStartModelError.

                  The flags are unusable for any flagged model: the object cannot be constructed, so deploy is unreachable. The failure is also non-obvious, because the traceback points at utils.py inside the gate rather than at anything the caller passed.

                  To reproduce

                  Any model whose specs carry inference_vulnerable: true reproduces this. tolerate_vulnerable_model=True is ignored:

                  fromsagemaker.jumpstart.modelimportJumpStartModel# Any model_id whose specs set inference_vulnerable=true.model=JumpStartModel(
                  model_id="<vulnerable-model-id>",
                  tolerate_vulnerable_model=True,
                  tolerate_deprecated_model=True,
                  )
                  sagemaker.jumpstart.exceptions.VulnerableJumpStartModelError: Version '1.0.0' of JumpStart model
                  '<vulnerable-model-id>' has at least 1 vulnerable dependency in the inference script.
                  ...
                  List of vulnerabilities: CVE-2024-11393
                  /site-packages/sagemaker/jumpstart/utils.py:726: VulnerableJumpStartModelError
                  

                  The dropped argument is visible without a flagged model:

                  >>>importinspect>>>fromsagemaker.jumpstart.utilsimportget_jumpstart_configs>>> [pforpininspect.signature(get_jumpstart_configs).parametersif"tolerate"inp]
                  []

                  Expected behavior

                  tolerate_vulnerable_model=True and tolerate_deprecated_model=True suppress the gate through the whole constructor, including the metadata config lookup. Construction completes and deploy proceeds.

                  Empty configs are a reasonable result for a flagged model. _metadata_configs feeds only list_deployment_configs and the benchmark metrics helpers, so no other code path degrades.

                  Suggested fix: add the two parameters to get_jumpstart_configs, default both to False to preserve current behavior for existing callers, and forward them to verify_model_region_and_return_specs. Then pass self.tolerate_vulnerable_model and self.tolerate_deprecated_model at the JumpStartModel.__init__ call site. Both attributes are already set earlier in that constructor, so no new plumbing is needed.

                  JumpStartEstimator.list_training_configs has the same gap and would be fixed by the same signature change.

                  Screenshots or logs

                  Included above.

                  System information

                  • SageMaker Python SDK version: 2.257.1 and 2.257.5 confirmed; the same code is present on master at sagemaker-core/src/sagemaker/core/jumpstart/utils.py, so 3.x is affected
                  • Framework name (eg. PyTorch) or algorithm (eg. KMeans): JumpStart (JumpStartModel, JumpStartEstimator)
                  • Framework version: n/a
                  • Python version: 3.10
                  • CPU or GPU: both
                  • Custom Docker image (Y/N): N

                  Additional context

                  In 3.x the same get_jumpstart_configs has no tolerance parameters, and ModelBuilder._ensure_metadata_configs in sagemaker-serve/src/sagemaker/serve/model_builder_utils.py calls it without them, so a flagged model raises there too.

                  This blocked a release pipeline that deploys JumpStart models for validation. Such a pipeline must deploy a model that is flagged, precisely because it needs to test the model, which is what the tolerance flags are for.

                  The only workaround we found is to replace the lookup and swallow the two gate errors. It is fragile, because it depends on SDK internals and on which modules bound the name at import time:

                  importsagemaker.jumpstart.estimatorimportsagemaker.jumpstart.modelimportsagemaker.jumpstart.utilsfromsagemaker.jumpstart.exceptionsimportDeprecatedJumpStartModelError, VulnerableJumpStartModelError_original=sagemaker.jumpstart.utils.get_jumpstart_configsdef_tolerant_get_jumpstart_configs(*args, **kwargs):
                  try:
                  return_original(*args, **kwargs)
                  except (VulnerableJumpStartModelError, DeprecatedJumpStartModelError):
                  return {}
                  # Each module that imported the name by value needs the replacement.formodulein (sagemaker.jumpstart.utils, sagemaker.jumpstart.model, sagemaker.jumpstart.estimator):
                  module.get_jumpstart_configs=_tolerant_get_jumpstart_configs

                  Worth noting that in the case that prompted this, the vulnerability flag was itself inherited from an inference script bundle the model never runs. That is a separate metadata concern. The SDK bug is that the documented escape hatch does not work.

                  Metadata

                  Metadata

                  Assignees

                  No one assigned

                    Labels

                    No labels
                    No labels

                    Type

                    No type

                    Projects

                    No projects

                      Milestone

                      No milestone

                      Relationships

                      None yet

                      Development

                      No branches or pull requests

                      Issue actions

                      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                      Skip to content

                      JumpStartModel ignores tolerate_vulnerable_model and tolerate_deprecated_model: get_jumpstart_configs does not forward the flags #6130

                      Description

                      @evakravi

                      PySDK Version

                      • PySDK V2 (2.x)
                      • PySDK V3 (3.x)

                      Describe the bug

                      get_jumpstart_configs accepts no tolerate_vulnerable_model or tolerate_deprecated_model argument. It calls verify_model_region_and_return_specs without them, so the callee falls back to its False defaults and re-runs the model gate:

                      # sagemaker/jumpstart/utils.pydefget_jumpstart_configs(
                      region: str,
                      model_id: str,
                      model_version: str,
                      config_names: Optional[List[str]] =None,
                      sagemaker_session: Optional[Session] =constants.DEFAULT_JUMPSTART_SAGEMAKER_SESSION,
                      scope: enums.JumpStartScriptScope=enums.JumpStartScriptScope.INFERENCE,
                      model_type: enums.JumpStartModelType=enums.JumpStartModelType.OPEN_WEIGHTS,
                      hub_arn: Optional[str] =None,
                      ) ->Dict[str, JumpStartMetadataConfig]:
                      model_specs=verify_model_region_and_return_specs(
                      region=region,
                      model_id=model_id,
                      version=model_version,
                      sagemaker_session=sagemaker_session,
                      scope=scope,
                      model_type=model_type,
                      hub_arn=hub_arn,
                      ) # <-- tolerate_vulnerable_model / tolerate_deprecated_model not forwarded

                      JumpStartModel.__init__ calls it as its final statement, after super().__init__() has already succeeded:

                      # sagemaker/jumpstart/model.pyself._metadata_configs=get_jumpstart_configs(
                      region=self.region,
                      model_id=self.model_id,
                      model_version=self.model_version,
                      sagemaker_session=self.sagemaker_session,
                      model_type=self.model_type,
                      hub_arn=self.hub_arn,
                      )

                      So JumpStartModel(..., tolerate_vulnerable_model=True) raises VulnerableJumpStartModelError anyway. The constructor honors the flag through every other lookup and then discards it on the last line. The same applies to tolerate_deprecated_model and DeprecatedJumpStartModelError.

                      The flags are unusable for any flagged model: the object cannot be constructed, so deploy is unreachable. The failure is also non-obvious, because the traceback points at utils.py inside the gate rather than at anything the caller passed.

                      To reproduce

                      Any model whose specs carry inference_vulnerable: true reproduces this. tolerate_vulnerable_model=True is ignored:

                      fromsagemaker.jumpstart.modelimportJumpStartModel# Any model_id whose specs set inference_vulnerable=true.model=JumpStartModel(
                      model_id="<vulnerable-model-id>",
                      tolerate_vulnerable_model=True,
                      tolerate_deprecated_model=True,
                      )
                      sagemaker.jumpstart.exceptions.VulnerableJumpStartModelError: Version '1.0.0' of JumpStart model
                      '<vulnerable-model-id>' has at least 1 vulnerable dependency in the inference script.
                      ...
                      List of vulnerabilities: CVE-2024-11393
                      /site-packages/sagemaker/jumpstart/utils.py:726: VulnerableJumpStartModelError
                      

                      The dropped argument is visible without a flagged model:

                      >>>importinspect>>>fromsagemaker.jumpstart.utilsimportget_jumpstart_configs>>> [pforpininspect.signature(get_jumpstart_configs).parametersif"tolerate"inp]
                      []

                      Expected behavior

                      tolerate_vulnerable_model=True and tolerate_deprecated_model=True suppress the gate through the whole constructor, including the metadata config lookup. Construction completes and deploy proceeds.

                      Empty configs are a reasonable result for a flagged model. _metadata_configs feeds only list_deployment_configs and the benchmark metrics helpers, so no other code path degrades.

                      Suggested fix: add the two parameters to get_jumpstart_configs, default both to False to preserve current behavior for existing callers, and forward them to verify_model_region_and_return_specs. Then pass self.tolerate_vulnerable_model and self.tolerate_deprecated_model at the JumpStartModel.__init__ call site. Both attributes are already set earlier in that constructor, so no new plumbing is needed.

                      JumpStartEstimator.list_training_configs has the same gap and would be fixed by the same signature change.

                      Screenshots or logs

                      Included above.

                      System information

                      • SageMaker Python SDK version: 2.257.1 and 2.257.5 confirmed; the same code is present on master at sagemaker-core/src/sagemaker/core/jumpstart/utils.py, so 3.x is affected
                      • Framework name (eg. PyTorch) or algorithm (eg. KMeans): JumpStart (JumpStartModel, JumpStartEstimator)
                      • Framework version: n/a
                      • Python version: 3.10
                      • CPU or GPU: both
                      • Custom Docker image (Y/N): N

                      Additional context

                      In 3.x the same get_jumpstart_configs has no tolerance parameters, and ModelBuilder._ensure_metadata_configs in sagemaker-serve/src/sagemaker/serve/model_builder_utils.py calls it without them, so a flagged model raises there too.

                      This blocked a release pipeline that deploys JumpStart models for validation. Such a pipeline must deploy a model that is flagged, precisely because it needs to test the model, which is what the tolerance flags are for.

                      The only workaround we found is to replace the lookup and swallow the two gate errors. It is fragile, because it depends on SDK internals and on which modules bound the name at import time:

                      importsagemaker.jumpstart.estimatorimportsagemaker.jumpstart.modelimportsagemaker.jumpstart.utilsfromsagemaker.jumpstart.exceptionsimportDeprecatedJumpStartModelError, VulnerableJumpStartModelError_original=sagemaker.jumpstart.utils.get_jumpstart_configsdef_tolerant_get_jumpstart_configs(*args, **kwargs):
                      try:
                      return_original(*args, **kwargs)
                      except (VulnerableJumpStartModelError, DeprecatedJumpStartModelError):
                      return {}
                      # Each module that imported the name by value needs the replacement.formodulein (sagemaker.jumpstart.utils, sagemaker.jumpstart.model, sagemaker.jumpstart.estimator):
                      module.get_jumpstart_configs=_tolerant_get_jumpstart_configs

                      Worth noting that in the case that prompted this, the vulnerability flag was itself inherited from an inference script bundle the model never runs. That is a separate metadata concern. The SDK bug is that the documented escape hatch does not work.

                      Metadata

                      Metadata

                      Assignees

                      No one assigned

                        Labels

                        No labels
                        No labels

                        Type

                        No type

                        Projects

                        No projects

                          Milestone

                          No milestone

                          Relationships

                          None yet

                          Development

                          No branches or pull requests

                          Issue actions

                          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                          Skip to content

                          JumpStartModel ignores tolerate_vulnerable_model and tolerate_deprecated_model: get_jumpstart_configs does not forward the flags #6130

                          Description

                          @evakravi

                          PySDK Version

                          • PySDK V2 (2.x)
                          • PySDK V3 (3.x)

                          Describe the bug

                          get_jumpstart_configs accepts no tolerate_vulnerable_model or tolerate_deprecated_model argument. It calls verify_model_region_and_return_specs without them, so the callee falls back to its False defaults and re-runs the model gate:

                          # sagemaker/jumpstart/utils.pydefget_jumpstart_configs(
                          region: str,
                          model_id: str,
                          model_version: str,
                          config_names: Optional[List[str]] =None,
                          sagemaker_session: Optional[Session] =constants.DEFAULT_JUMPSTART_SAGEMAKER_SESSION,
                          scope: enums.JumpStartScriptScope=enums.JumpStartScriptScope.INFERENCE,
                          model_type: enums.JumpStartModelType=enums.JumpStartModelType.OPEN_WEIGHTS,
                          hub_arn: Optional[str] =None,
                          ) ->Dict[str, JumpStartMetadataConfig]:
                          model_specs=verify_model_region_and_return_specs(
                          region=region,
                          model_id=model_id,
                          version=model_version,
                          sagemaker_session=sagemaker_session,
                          scope=scope,
                          model_type=model_type,
                          hub_arn=hub_arn,
                          ) # <-- tolerate_vulnerable_model / tolerate_deprecated_model not forwarded

                          JumpStartModel.__init__ calls it as its final statement, after super().__init__() has already succeeded:

                          # sagemaker/jumpstart/model.pyself._metadata_configs=get_jumpstart_configs(
                          region=self.region,
                          model_id=self.model_id,
                          model_version=self.model_version,
                          sagemaker_session=self.sagemaker_session,
                          model_type=self.model_type,
                          hub_arn=self.hub_arn,
                          )

                          So JumpStartModel(..., tolerate_vulnerable_model=True) raises VulnerableJumpStartModelError anyway. The constructor honors the flag through every other lookup and then discards it on the last line. The same applies to tolerate_deprecated_model and DeprecatedJumpStartModelError.

                          The flags are unusable for any flagged model: the object cannot be constructed, so deploy is unreachable. The failure is also non-obvious, because the traceback points at utils.py inside the gate rather than at anything the caller passed.

                          To reproduce

                          Any model whose specs carry inference_vulnerable: true reproduces this. tolerate_vulnerable_model=True is ignored:

                          fromsagemaker.jumpstart.modelimportJumpStartModel# Any model_id whose specs set inference_vulnerable=true.model=JumpStartModel(
                          model_id="<vulnerable-model-id>",
                          tolerate_vulnerable_model=True,
                          tolerate_deprecated_model=True,
                          )
                          sagemaker.jumpstart.exceptions.VulnerableJumpStartModelError: Version '1.0.0' of JumpStart model
                          '<vulnerable-model-id>' has at least 1 vulnerable dependency in the inference script.
                          ...
                          List of vulnerabilities: CVE-2024-11393
                          /site-packages/sagemaker/jumpstart/utils.py:726: VulnerableJumpStartModelError
                          

                          The dropped argument is visible without a flagged model:

                          >>>importinspect>>>fromsagemaker.jumpstart.utilsimportget_jumpstart_configs>>> [pforpininspect.signature(get_jumpstart_configs).parametersif"tolerate"inp]
                          []

                          Expected behavior

                          tolerate_vulnerable_model=True and tolerate_deprecated_model=True suppress the gate through the whole constructor, including the metadata config lookup. Construction completes and deploy proceeds.

                          Empty configs are a reasonable result for a flagged model. _metadata_configs feeds only list_deployment_configs and the benchmark metrics helpers, so no other code path degrades.

                          Suggested fix: add the two parameters to get_jumpstart_configs, default both to False to preserve current behavior for existing callers, and forward them to verify_model_region_and_return_specs. Then pass self.tolerate_vulnerable_model and self.tolerate_deprecated_model at the JumpStartModel.__init__ call site. Both attributes are already set earlier in that constructor, so no new plumbing is needed.

                          JumpStartEstimator.list_training_configs has the same gap and would be fixed by the same signature change.

                          Screenshots or logs

                          Included above.

                          System information

                          • SageMaker Python SDK version: 2.257.1 and 2.257.5 confirmed; the same code is present on master at sagemaker-core/src/sagemaker/core/jumpstart/utils.py, so 3.x is affected
                          • Framework name (eg. PyTorch) or algorithm (eg. KMeans): JumpStart (JumpStartModel, JumpStartEstimator)
                          • Framework version: n/a
                          • Python version: 3.10
                          • CPU or GPU: both
                          • Custom Docker image (Y/N): N

                          Additional context

                          In 3.x the same get_jumpstart_configs has no tolerance parameters, and ModelBuilder._ensure_metadata_configs in sagemaker-serve/src/sagemaker/serve/model_builder_utils.py calls it without them, so a flagged model raises there too.

                          This blocked a release pipeline that deploys JumpStart models for validation. Such a pipeline must deploy a model that is flagged, precisely because it needs to test the model, which is what the tolerance flags are for.

                          The only workaround we found is to replace the lookup and swallow the two gate errors. It is fragile, because it depends on SDK internals and on which modules bound the name at import time:

                          importsagemaker.jumpstart.estimatorimportsagemaker.jumpstart.modelimportsagemaker.jumpstart.utilsfromsagemaker.jumpstart.exceptionsimportDeprecatedJumpStartModelError, VulnerableJumpStartModelError_original=sagemaker.jumpstart.utils.get_jumpstart_configsdef_tolerant_get_jumpstart_configs(*args, **kwargs):
                          try:
                          return_original(*args, **kwargs)
                          except (VulnerableJumpStartModelError, DeprecatedJumpStartModelError):
                          return {}
                          # Each module that imported the name by value needs the replacement.formodulein (sagemaker.jumpstart.utils, sagemaker.jumpstart.model, sagemaker.jumpstart.estimator):
                          module.get_jumpstart_configs=_tolerant_get_jumpstart_configs

                          Worth noting that in the case that prompted this, the vulnerability flag was itself inherited from an inference script bundle the model never runs. That is a separate metadata concern. The SDK bug is that the documented escape hatch does not work.

                          Metadata

                          Metadata

                          Assignees

                          No one assigned

                            Labels

                            No labels
                            No labels

                            Type

                            No type

                            Projects

                            No projects

                              Milestone

                              No milestone

                              Relationships

                              None yet

                              Development

                              No branches or pull requests

                              Issue actions

                              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                              Skip to content

                              JumpStartModel ignores tolerate_vulnerable_model and tolerate_deprecated_model: get_jumpstart_configs does not forward the flags #6130

                              Description

                              @evakravi

                              PySDK Version

                              • PySDK V2 (2.x)
                              • PySDK V3 (3.x)

                              Describe the bug

                              get_jumpstart_configs accepts no tolerate_vulnerable_model or tolerate_deprecated_model argument. It calls verify_model_region_and_return_specs without them, so the callee falls back to its False defaults and re-runs the model gate:

                              # sagemaker/jumpstart/utils.pydefget_jumpstart_configs(
                              region: str,
                              model_id: str,
                              model_version: str,
                              config_names: Optional[List[str]] =None,
                              sagemaker_session: Optional[Session] =constants.DEFAULT_JUMPSTART_SAGEMAKER_SESSION,
                              scope: enums.JumpStartScriptScope=enums.JumpStartScriptScope.INFERENCE,
                              model_type: enums.JumpStartModelType=enums.JumpStartModelType.OPEN_WEIGHTS,
                              hub_arn: Optional[str] =None,
                              ) ->Dict[str, JumpStartMetadataConfig]:
                              model_specs=verify_model_region_and_return_specs(
                              region=region,
                              model_id=model_id,
                              version=model_version,
                              sagemaker_session=sagemaker_session,
                              scope=scope,
                              model_type=model_type,
                              hub_arn=hub_arn,
                              ) # <-- tolerate_vulnerable_model / tolerate_deprecated_model not forwarded

                              JumpStartModel.__init__ calls it as its final statement, after super().__init__() has already succeeded:

                              # sagemaker/jumpstart/model.pyself._metadata_configs=get_jumpstart_configs(
                              region=self.region,
                              model_id=self.model_id,
                              model_version=self.model_version,
                              sagemaker_session=self.sagemaker_session,
                              model_type=self.model_type,
                              hub_arn=self.hub_arn,
                              )

                              So JumpStartModel(..., tolerate_vulnerable_model=True) raises VulnerableJumpStartModelError anyway. The constructor honors the flag through every other lookup and then discards it on the last line. The same applies to tolerate_deprecated_model and DeprecatedJumpStartModelError.

                              The flags are unusable for any flagged model: the object cannot be constructed, so deploy is unreachable. The failure is also non-obvious, because the traceback points at utils.py inside the gate rather than at anything the caller passed.

                              To reproduce

                              Any model whose specs carry inference_vulnerable: true reproduces this. tolerate_vulnerable_model=True is ignored:

                              fromsagemaker.jumpstart.modelimportJumpStartModel# Any model_id whose specs set inference_vulnerable=true.model=JumpStartModel(
                              model_id="<vulnerable-model-id>",
                              tolerate_vulnerable_model=True,
                              tolerate_deprecated_model=True,
                              )
                              sagemaker.jumpstart.exceptions.VulnerableJumpStartModelError: Version '1.0.0' of JumpStart model
                              '<vulnerable-model-id>' has at least 1 vulnerable dependency in the inference script.
                              ...
                              List of vulnerabilities: CVE-2024-11393
                              /site-packages/sagemaker/jumpstart/utils.py:726: VulnerableJumpStartModelError
                              

                              The dropped argument is visible without a flagged model:

                              >>>importinspect>>>fromsagemaker.jumpstart.utilsimportget_jumpstart_configs>>> [pforpininspect.signature(get_jumpstart_configs).parametersif"tolerate"inp]
                              []

                              Expected behavior

                              tolerate_vulnerable_model=True and tolerate_deprecated_model=True suppress the gate through the whole constructor, including the metadata config lookup. Construction completes and deploy proceeds.

                              Empty configs are a reasonable result for a flagged model. _metadata_configs feeds only list_deployment_configs and the benchmark metrics helpers, so no other code path degrades.

                              Suggested fix: add the two parameters to get_jumpstart_configs, default both to False to preserve current behavior for existing callers, and forward them to verify_model_region_and_return_specs. Then pass self.tolerate_vulnerable_model and self.tolerate_deprecated_model at the JumpStartModel.__init__ call site. Both attributes are already set earlier in that constructor, so no new plumbing is needed.

                              JumpStartEstimator.list_training_configs has the same gap and would be fixed by the same signature change.

                              Screenshots or logs

                              Included above.

                              System information

                              • SageMaker Python SDK version: 2.257.1 and 2.257.5 confirmed; the same code is present on master at sagemaker-core/src/sagemaker/core/jumpstart/utils.py, so 3.x is affected
                              • Framework name (eg. PyTorch) or algorithm (eg. KMeans): JumpStart (JumpStartModel, JumpStartEstimator)
                              • Framework version: n/a
                              • Python version: 3.10
                              • CPU or GPU: both
                              • Custom Docker image (Y/N): N

                              Additional context

                              In 3.x the same get_jumpstart_configs has no tolerance parameters, and ModelBuilder._ensure_metadata_configs in sagemaker-serve/src/sagemaker/serve/model_builder_utils.py calls it without them, so a flagged model raises there too.

                              This blocked a release pipeline that deploys JumpStart models for validation. Such a pipeline must deploy a model that is flagged, precisely because it needs to test the model, which is what the tolerance flags are for.

                              The only workaround we found is to replace the lookup and swallow the two gate errors. It is fragile, because it depends on SDK internals and on which modules bound the name at import time:

                              importsagemaker.jumpstart.estimatorimportsagemaker.jumpstart.modelimportsagemaker.jumpstart.utilsfromsagemaker.jumpstart.exceptionsimportDeprecatedJumpStartModelError, VulnerableJumpStartModelError_original=sagemaker.jumpstart.utils.get_jumpstart_configsdef_tolerant_get_jumpstart_configs(*args, **kwargs):
                              try:
                              return_original(*args, **kwargs)
                              except (VulnerableJumpStartModelError, DeprecatedJumpStartModelError):
                              return {}
                              # Each module that imported the name by value needs the replacement.formodulein (sagemaker.jumpstart.utils, sagemaker.jumpstart.model, sagemaker.jumpstart.estimator):
                              module.get_jumpstart_configs=_tolerant_get_jumpstart_configs

                              Worth noting that in the case that prompted this, the vulnerability flag was itself inherited from an inference script bundle the model never runs. That is a separate metadata concern. The SDK bug is that the documented escape hatch does not work.

                              Metadata

                              Metadata

                              Assignees

                              No one assigned

                                Labels

                                No labels
                                No labels

                                Type

                                No type

                                Projects

                                No projects

                                  Milestone

                                  No milestone

                                  Relationships

                                  None yet

                                  Development

                                  No branches or pull requests

                                  Issue actions