Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion src/sagemaker/local/image.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -40,6 +40,7 @@
import sagemaker.local.data
import sagemaker.local.utils
import sagemaker.utils
from sagemaker.utils import check_tarfile_data_filter_attribute

CONTAINER_PREFIX = "algo"
STUDIO_HOST_NAME = "sagemaker-local"
Expand DownExpand Up@@ -686,7 +687,8 @@ def _prepare_serving_volumes(self, model_location):
for filename in model_data_source.get_file_list():
if tarfile.is_tarfile(filename):
with tarfile.open(filename) as tar:
tar.extractall(path=model_data_source.get_root_dir())
check_tarfile_data_filter_attribute()
tar.extractall(path=model_data_source.get_root_dir(), filter="data")

volumes.append(_Volume(model_data_source.get_root_dir(), "/opt/ml/model"))

Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/djl_serving/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -20,7 +20,7 @@
from typing import List
from pathlib import Path

from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader
from sagemaker.djl_inference import DJLModel
from sagemaker.djl_inference.model import _read_existing_serving_properties
Expand DownExpand Up@@ -53,7 +53,8 @@ def _extract_js_resource(js_model_dir: str, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=js_model_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=js_model_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path):
Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/tgi/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,7 +19,7 @@
from pathlib import Path

from sagemaker.serve.utils.local_hardware import _check_disk_space, _check_docker_disk_usage
from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader

logger = logging.getLogger(__name__)
Expand All@@ -29,7 +29,8 @@ def _extract_js_resource(js_model_dir: str, code_dir: Path, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=code_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path) -> bool:
Expand Down
29 changes: 27 additions & 2 deletions src/sagemaker/utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -22,6 +22,7 @@
import random
import re
import shutil
import sys
import tarfile
import tempfile
import time
Expand DownExpand Up@@ -591,7 +592,8 @@ def _create_or_update_code_dir(
download_file_from_url(source_directory, local_code_path, sagemaker_session)

with tarfile.open(name=local_code_path, mode="r:gz") as t:
t.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=code_dir, filter="data")

elif source_directory:
if os.path.exists(code_dir):
Expand DownExpand Up@@ -628,7 +630,8 @@ def _extract_model(model_uri, sagemaker_session, tmp):
else:
local_model_path = model_uri.replace("file://", "")
with tarfile.open(name=local_model_path, mode="r:gz") as t:
t.extractall(path=tmp_model_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=tmp_model_dir, filter="data")
return tmp_model_dir


Expand DownExpand Up@@ -1489,3 +1492,25 @@ def format_tags(tags: Tags) -> List[TagsDict]:
return [{"Key": str(k), "Value": str(v)} for k, v in tags.items()]

return tags


class PythonVersionError(Exception):
"""Raise when a secure [/patched] version of Python is not used."""


def check_tarfile_data_filter_attribute():
"""Check if tarfile has data_filter utility.

Tarfile-data_filter utility has guardrails against untrusted de-serialisation.

Raises:
PythonVersionError: if `tarfile.data_filter` is not available.
"""
# The function and it's usages can be deprecated post support of python >= 3.12
if not hasattr(tarfile, "data_filter"):
raise PythonVersionError(
f"Since tarfile extraction is unsafe the operation is prohibited "
f"per PEP-721. Please update your Python [{sys.version}] "
f"to latest patch [refer to https://www.python.org/downloads/] "
f"to consume the security patch"
)
10 changes: 8 additions & 2 deletions src/sagemaker/workflow/_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,7 +32,12 @@
Step,
ConfigurableRetryStep,
)
from sagemaker.utils import _save_model, download_file_from_url, format_tags
from sagemaker.utils import (
_save_model,
download_file_from_url,
format_tags,
check_tarfile_data_filter_attribute,
)
from sagemaker.workflow.retry import RetryPolicy
from sagemaker.workflow.utilities import trim_request_dict

Expand DownExpand Up@@ -257,7 +262,8 @@ def _inject_repack_script_and_launcher(self):
download_file_from_url(self._source_dir, old_targz_path, self.sagemaker_session)

with tarfile.open(name=old_targz_path, mode="r:gz") as t:
t.extractall(path=targz_contents_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=targz_contents_dir, filter="data")

shutil.copy2(fname, os.path.join(targz_contents_dir, REPACK_SCRIPT))
with open(
Expand Down
5 changes: 4 additions & 1 deletion tests/integ/s3_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,6 +19,8 @@
import boto3
from six.moves.urllib.parse import urlparse

from sagemaker.utils import check_tarfile_data_filter_attribute


def assert_s3_files_exist(sagemaker_session, s3_url, files):
parsed_url = urlparse(s3_url)
Expand DownExpand Up@@ -55,4 +57,5 @@ def extract_files_from_s3(s3_url, tmpdir, sagemaker_session):
s3.Bucket(parsed_url.netloc).download_file(parsed_url.path.lstrip("/"), model)

with tarfile.open(model, "r") as tar_file:
tar_file.extractall(tmpdir)
check_tarfile_data_filter_attribute()
tar_file.extractall(tmpdir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -272,4 +272,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir)
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -156,4 +156,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=code_dir)
mock_resource_obj.extractall.assert_called_once_with(path=code_dir, filter="data")
5 changes: 3 additions & 2 deletions tests/unit/test_fw_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -24,7 +24,7 @@
from mock import Mock, patch

from sagemaker import fw_utils
from sagemaker.utils import name_from_image
from sagemaker.utils import name_from_image, check_tarfile_data_filter_attribute
from sagemaker.session_settings import SessionSettings
from sagemaker.instance_group import InstanceGroup

Expand DownExpand Up@@ -424,7 +424,8 @@ def list_tar_files(folder, tar_ball, tmpdir):
startpath = str(tmpdir.ensure(folder, dir=True))

with tarfile.open(name=tar_ball, mode="r:gz") as t:
t.extractall(path=startpath)
check_tarfile_data_filter_attribute()
t.extractall(path=startpath, filter="data")

def walk():
for root, dirs, files in os.walk(startpath):
Expand Down
14 changes: 14 additions & 0 deletions tests/unit/test_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,6 +42,8 @@
resolve_nested_dict_value_from_config,
update_list_of_dicts_with_values_from_config,
volume_size_supported,
PythonVersionError,
check_tarfile_data_filter_attribute,
)
from tests.unit.sagemaker.workflow.helpers import CustomStep
from sagemaker.workflow.parameters import ParameterString, ParameterInteger
Expand DownExpand Up@@ -1748,3 +1750,15 @@ def test_instance_family_from_full_instance_type(self):

for instance_type, family in instance_type_to_family_test_dict.items():
self.assertEqual(family, get_instance_type_family(instance_type))


class TestCheckTarfileDataFilterAttribute(TestCase):
def test_check_tarfile_data_filter_attribute_unhappy_case(self):
with pytest.raises(PythonVersionError):
with patch("tarfile.data_filter", None):
delattr(tarfile, "data_filter")
check_tarfile_data_filter_attribute()

def test_check_tarfile_data_filter_attribute_happy_case(self):
with patch("tarfile.data_filter", "some_value"):
check_tarfile_data_filter_attribute()
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion src/sagemaker/local/image.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -40,6 +40,7 @@
import sagemaker.local.data
import sagemaker.local.utils
import sagemaker.utils
from sagemaker.utils import check_tarfile_data_filter_attribute

CONTAINER_PREFIX = "algo"
STUDIO_HOST_NAME = "sagemaker-local"
Expand DownExpand Up@@ -686,7 +687,8 @@ def _prepare_serving_volumes(self, model_location):
for filename in model_data_source.get_file_list():
if tarfile.is_tarfile(filename):
with tarfile.open(filename) as tar:
tar.extractall(path=model_data_source.get_root_dir())
check_tarfile_data_filter_attribute()
tar.extractall(path=model_data_source.get_root_dir(), filter="data")

volumes.append(_Volume(model_data_source.get_root_dir(), "/opt/ml/model"))

Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/djl_serving/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -20,7 +20,7 @@
from typing import List
from pathlib import Path

from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader
from sagemaker.djl_inference import DJLModel
from sagemaker.djl_inference.model import _read_existing_serving_properties
Expand DownExpand Up@@ -53,7 +53,8 @@ def _extract_js_resource(js_model_dir: str, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=js_model_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=js_model_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path):
Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/tgi/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,7 +19,7 @@
from pathlib import Path

from sagemaker.serve.utils.local_hardware import _check_disk_space, _check_docker_disk_usage
from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader

logger = logging.getLogger(__name__)
Expand All@@ -29,7 +29,8 @@ def _extract_js_resource(js_model_dir: str, code_dir: Path, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=code_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path) -> bool:
Expand Down
29 changes: 27 additions & 2 deletions src/sagemaker/utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -22,6 +22,7 @@
import random
import re
import shutil
import sys
import tarfile
import tempfile
import time
Expand DownExpand Up@@ -591,7 +592,8 @@ def _create_or_update_code_dir(
download_file_from_url(source_directory, local_code_path, sagemaker_session)

with tarfile.open(name=local_code_path, mode="r:gz") as t:
t.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=code_dir, filter="data")

elif source_directory:
if os.path.exists(code_dir):
Expand DownExpand Up@@ -628,7 +630,8 @@ def _extract_model(model_uri, sagemaker_session, tmp):
else:
local_model_path = model_uri.replace("file://", "")
with tarfile.open(name=local_model_path, mode="r:gz") as t:
t.extractall(path=tmp_model_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=tmp_model_dir, filter="data")
return tmp_model_dir


Expand DownExpand Up@@ -1489,3 +1492,25 @@ def format_tags(tags: Tags) -> List[TagsDict]:
return [{"Key": str(k), "Value": str(v)} for k, v in tags.items()]

return tags


class PythonVersionError(Exception):
"""Raise when a secure [/patched] version of Python is not used."""


def check_tarfile_data_filter_attribute():
"""Check if tarfile has data_filter utility.

Tarfile-data_filter utility has guardrails against untrusted de-serialisation.

Raises:
PythonVersionError: if `tarfile.data_filter` is not available.
"""
# The function and it's usages can be deprecated post support of python >= 3.12
if not hasattr(tarfile, "data_filter"):
raise PythonVersionError(
f"Since tarfile extraction is unsafe the operation is prohibited "
f"per PEP-721. Please update your Python [{sys.version}] "
f"to latest patch [refer to https://www.python.org/downloads/] "
f"to consume the security patch"
)
10 changes: 8 additions & 2 deletions src/sagemaker/workflow/_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,7 +32,12 @@
Step,
ConfigurableRetryStep,
)
from sagemaker.utils import _save_model, download_file_from_url, format_tags
from sagemaker.utils import (
_save_model,
download_file_from_url,
format_tags,
check_tarfile_data_filter_attribute,
)
from sagemaker.workflow.retry import RetryPolicy
from sagemaker.workflow.utilities import trim_request_dict

Expand DownExpand Up@@ -257,7 +262,8 @@ def _inject_repack_script_and_launcher(self):
download_file_from_url(self._source_dir, old_targz_path, self.sagemaker_session)

with tarfile.open(name=old_targz_path, mode="r:gz") as t:
t.extractall(path=targz_contents_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=targz_contents_dir, filter="data")

shutil.copy2(fname, os.path.join(targz_contents_dir, REPACK_SCRIPT))
with open(
Expand Down
5 changes: 4 additions & 1 deletion tests/integ/s3_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,6 +19,8 @@
import boto3
from six.moves.urllib.parse import urlparse

from sagemaker.utils import check_tarfile_data_filter_attribute


def assert_s3_files_exist(sagemaker_session, s3_url, files):
parsed_url = urlparse(s3_url)
Expand DownExpand Up@@ -55,4 +57,5 @@ def extract_files_from_s3(s3_url, tmpdir, sagemaker_session):
s3.Bucket(parsed_url.netloc).download_file(parsed_url.path.lstrip("/"), model)

with tarfile.open(model, "r") as tar_file:
tar_file.extractall(tmpdir)
check_tarfile_data_filter_attribute()
tar_file.extractall(tmpdir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -272,4 +272,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir)
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -156,4 +156,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=code_dir)
mock_resource_obj.extractall.assert_called_once_with(path=code_dir, filter="data")
5 changes: 3 additions & 2 deletions tests/unit/test_fw_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -24,7 +24,7 @@
from mock import Mock, patch

from sagemaker import fw_utils
from sagemaker.utils import name_from_image
from sagemaker.utils import name_from_image, check_tarfile_data_filter_attribute
from sagemaker.session_settings import SessionSettings
from sagemaker.instance_group import InstanceGroup

Expand DownExpand Up@@ -424,7 +424,8 @@ def list_tar_files(folder, tar_ball, tmpdir):
startpath = str(tmpdir.ensure(folder, dir=True))

with tarfile.open(name=tar_ball, mode="r:gz") as t:
t.extractall(path=startpath)
check_tarfile_data_filter_attribute()
t.extractall(path=startpath, filter="data")

def walk():
for root, dirs, files in os.walk(startpath):
Expand Down
14 changes: 14 additions & 0 deletions tests/unit/test_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,6 +42,8 @@
resolve_nested_dict_value_from_config,
update_list_of_dicts_with_values_from_config,
volume_size_supported,
PythonVersionError,
check_tarfile_data_filter_attribute,
)
from tests.unit.sagemaker.workflow.helpers import CustomStep
from sagemaker.workflow.parameters import ParameterString, ParameterInteger
Expand DownExpand Up@@ -1748,3 +1750,15 @@ def test_instance_family_from_full_instance_type(self):

for instance_type, family in instance_type_to_family_test_dict.items():
self.assertEqual(family, get_instance_type_family(instance_type))


class TestCheckTarfileDataFilterAttribute(TestCase):
def test_check_tarfile_data_filter_attribute_unhappy_case(self):
with pytest.raises(PythonVersionError):
with patch("tarfile.data_filter", None):
delattr(tarfile, "data_filter")
check_tarfile_data_filter_attribute()

def test_check_tarfile_data_filter_attribute_happy_case(self):
with patch("tarfile.data_filter", "some_value"):
check_tarfile_data_filter_attribute()
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion src/sagemaker/local/image.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -40,6 +40,7 @@
import sagemaker.local.data
import sagemaker.local.utils
import sagemaker.utils
from sagemaker.utils import check_tarfile_data_filter_attribute

CONTAINER_PREFIX = "algo"
STUDIO_HOST_NAME = "sagemaker-local"
Expand DownExpand Up@@ -686,7 +687,8 @@ def _prepare_serving_volumes(self, model_location):
for filename in model_data_source.get_file_list():
if tarfile.is_tarfile(filename):
with tarfile.open(filename) as tar:
tar.extractall(path=model_data_source.get_root_dir())
check_tarfile_data_filter_attribute()
tar.extractall(path=model_data_source.get_root_dir(), filter="data")

volumes.append(_Volume(model_data_source.get_root_dir(), "/opt/ml/model"))

Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/djl_serving/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -20,7 +20,7 @@
from typing import List
from pathlib import Path

from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader
from sagemaker.djl_inference import DJLModel
from sagemaker.djl_inference.model import _read_existing_serving_properties
Expand DownExpand Up@@ -53,7 +53,8 @@ def _extract_js_resource(js_model_dir: str, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=js_model_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=js_model_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path):
Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/tgi/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,7 +19,7 @@
from pathlib import Path

from sagemaker.serve.utils.local_hardware import _check_disk_space, _check_docker_disk_usage
from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader

logger = logging.getLogger(__name__)
Expand All@@ -29,7 +29,8 @@ def _extract_js_resource(js_model_dir: str, code_dir: Path, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=code_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path) -> bool:
Expand Down
29 changes: 27 additions & 2 deletions src/sagemaker/utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -22,6 +22,7 @@
import random
import re
import shutil
import sys
import tarfile
import tempfile
import time
Expand DownExpand Up@@ -591,7 +592,8 @@ def _create_or_update_code_dir(
download_file_from_url(source_directory, local_code_path, sagemaker_session)

with tarfile.open(name=local_code_path, mode="r:gz") as t:
t.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=code_dir, filter="data")

elif source_directory:
if os.path.exists(code_dir):
Expand DownExpand Up@@ -628,7 +630,8 @@ def _extract_model(model_uri, sagemaker_session, tmp):
else:
local_model_path = model_uri.replace("file://", "")
with tarfile.open(name=local_model_path, mode="r:gz") as t:
t.extractall(path=tmp_model_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=tmp_model_dir, filter="data")
return tmp_model_dir


Expand DownExpand Up@@ -1489,3 +1492,25 @@ def format_tags(tags: Tags) -> List[TagsDict]:
return [{"Key": str(k), "Value": str(v)} for k, v in tags.items()]

return tags


class PythonVersionError(Exception):
"""Raise when a secure [/patched] version of Python is not used."""


def check_tarfile_data_filter_attribute():
"""Check if tarfile has data_filter utility.

Tarfile-data_filter utility has guardrails against untrusted de-serialisation.

Raises:
PythonVersionError: if `tarfile.data_filter` is not available.
"""
# The function and it's usages can be deprecated post support of python >= 3.12
if not hasattr(tarfile, "data_filter"):
raise PythonVersionError(
f"Since tarfile extraction is unsafe the operation is prohibited "
f"per PEP-721. Please update your Python [{sys.version}] "
f"to latest patch [refer to https://www.python.org/downloads/] "
f"to consume the security patch"
)
10 changes: 8 additions & 2 deletions src/sagemaker/workflow/_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,7 +32,12 @@
Step,
ConfigurableRetryStep,
)
from sagemaker.utils import _save_model, download_file_from_url, format_tags
from sagemaker.utils import (
_save_model,
download_file_from_url,
format_tags,
check_tarfile_data_filter_attribute,
)
from sagemaker.workflow.retry import RetryPolicy
from sagemaker.workflow.utilities import trim_request_dict

Expand DownExpand Up@@ -257,7 +262,8 @@ def _inject_repack_script_and_launcher(self):
download_file_from_url(self._source_dir, old_targz_path, self.sagemaker_session)

with tarfile.open(name=old_targz_path, mode="r:gz") as t:
t.extractall(path=targz_contents_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=targz_contents_dir, filter="data")

shutil.copy2(fname, os.path.join(targz_contents_dir, REPACK_SCRIPT))
with open(
Expand Down
5 changes: 4 additions & 1 deletion tests/integ/s3_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,6 +19,8 @@
import boto3
from six.moves.urllib.parse import urlparse

from sagemaker.utils import check_tarfile_data_filter_attribute


def assert_s3_files_exist(sagemaker_session, s3_url, files):
parsed_url = urlparse(s3_url)
Expand DownExpand Up@@ -55,4 +57,5 @@ def extract_files_from_s3(s3_url, tmpdir, sagemaker_session):
s3.Bucket(parsed_url.netloc).download_file(parsed_url.path.lstrip("/"), model)

with tarfile.open(model, "r") as tar_file:
tar_file.extractall(tmpdir)
check_tarfile_data_filter_attribute()
tar_file.extractall(tmpdir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -272,4 +272,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir)
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -156,4 +156,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=code_dir)
mock_resource_obj.extractall.assert_called_once_with(path=code_dir, filter="data")
5 changes: 3 additions & 2 deletions tests/unit/test_fw_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -24,7 +24,7 @@
from mock import Mock, patch

from sagemaker import fw_utils
from sagemaker.utils import name_from_image
from sagemaker.utils import name_from_image, check_tarfile_data_filter_attribute
from sagemaker.session_settings import SessionSettings
from sagemaker.instance_group import InstanceGroup

Expand DownExpand Up@@ -424,7 +424,8 @@ def list_tar_files(folder, tar_ball, tmpdir):
startpath = str(tmpdir.ensure(folder, dir=True))

with tarfile.open(name=tar_ball, mode="r:gz") as t:
t.extractall(path=startpath)
check_tarfile_data_filter_attribute()
t.extractall(path=startpath, filter="data")

def walk():
for root, dirs, files in os.walk(startpath):
Expand Down
14 changes: 14 additions & 0 deletions tests/unit/test_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,6 +42,8 @@
resolve_nested_dict_value_from_config,
update_list_of_dicts_with_values_from_config,
volume_size_supported,
PythonVersionError,
check_tarfile_data_filter_attribute,
)
from tests.unit.sagemaker.workflow.helpers import CustomStep
from sagemaker.workflow.parameters import ParameterString, ParameterInteger
Expand DownExpand Up@@ -1748,3 +1750,15 @@ def test_instance_family_from_full_instance_type(self):

for instance_type, family in instance_type_to_family_test_dict.items():
self.assertEqual(family, get_instance_type_family(instance_type))


class TestCheckTarfileDataFilterAttribute(TestCase):
def test_check_tarfile_data_filter_attribute_unhappy_case(self):
with pytest.raises(PythonVersionError):
with patch("tarfile.data_filter", None):
delattr(tarfile, "data_filter")
check_tarfile_data_filter_attribute()

def test_check_tarfile_data_filter_attribute_happy_case(self):
with patch("tarfile.data_filter", "some_value"):
check_tarfile_data_filter_attribute()
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion src/sagemaker/local/image.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -40,6 +40,7 @@
import sagemaker.local.data
import sagemaker.local.utils
import sagemaker.utils
from sagemaker.utils import check_tarfile_data_filter_attribute

CONTAINER_PREFIX = "algo"
STUDIO_HOST_NAME = "sagemaker-local"
Expand DownExpand Up@@ -686,7 +687,8 @@ def _prepare_serving_volumes(self, model_location):
for filename in model_data_source.get_file_list():
if tarfile.is_tarfile(filename):
with tarfile.open(filename) as tar:
tar.extractall(path=model_data_source.get_root_dir())
check_tarfile_data_filter_attribute()
tar.extractall(path=model_data_source.get_root_dir(), filter="data")

volumes.append(_Volume(model_data_source.get_root_dir(), "/opt/ml/model"))

Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/djl_serving/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -20,7 +20,7 @@
from typing import List
from pathlib import Path

from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader
from sagemaker.djl_inference import DJLModel
from sagemaker.djl_inference.model import _read_existing_serving_properties
Expand DownExpand Up@@ -53,7 +53,8 @@ def _extract_js_resource(js_model_dir: str, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=js_model_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=js_model_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path):
Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/tgi/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,7 +19,7 @@
from pathlib import Path

from sagemaker.serve.utils.local_hardware import _check_disk_space, _check_docker_disk_usage
from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader

logger = logging.getLogger(__name__)
Expand All@@ -29,7 +29,8 @@ def _extract_js_resource(js_model_dir: str, code_dir: Path, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=code_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path) -> bool:
Expand Down
29 changes: 27 additions & 2 deletions src/sagemaker/utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -22,6 +22,7 @@
import random
import re
import shutil
import sys
import tarfile
import tempfile
import time
Expand DownExpand Up@@ -591,7 +592,8 @@ def _create_or_update_code_dir(
download_file_from_url(source_directory, local_code_path, sagemaker_session)

with tarfile.open(name=local_code_path, mode="r:gz") as t:
t.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=code_dir, filter="data")

elif source_directory:
if os.path.exists(code_dir):
Expand DownExpand Up@@ -628,7 +630,8 @@ def _extract_model(model_uri, sagemaker_session, tmp):
else:
local_model_path = model_uri.replace("file://", "")
with tarfile.open(name=local_model_path, mode="r:gz") as t:
t.extractall(path=tmp_model_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=tmp_model_dir, filter="data")
return tmp_model_dir


Expand DownExpand Up@@ -1489,3 +1492,25 @@ def format_tags(tags: Tags) -> List[TagsDict]:
return [{"Key": str(k), "Value": str(v)} for k, v in tags.items()]

return tags


class PythonVersionError(Exception):
"""Raise when a secure [/patched] version of Python is not used."""


def check_tarfile_data_filter_attribute():
"""Check if tarfile has data_filter utility.

Tarfile-data_filter utility has guardrails against untrusted de-serialisation.

Raises:
PythonVersionError: if `tarfile.data_filter` is not available.
"""
# The function and it's usages can be deprecated post support of python >= 3.12
if not hasattr(tarfile, "data_filter"):
raise PythonVersionError(
f"Since tarfile extraction is unsafe the operation is prohibited "
f"per PEP-721. Please update your Python [{sys.version}] "
f"to latest patch [refer to https://www.python.org/downloads/] "
f"to consume the security patch"
)
10 changes: 8 additions & 2 deletions src/sagemaker/workflow/_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,7 +32,12 @@
Step,
ConfigurableRetryStep,
)
from sagemaker.utils import _save_model, download_file_from_url, format_tags
from sagemaker.utils import (
_save_model,
download_file_from_url,
format_tags,
check_tarfile_data_filter_attribute,
)
from sagemaker.workflow.retry import RetryPolicy
from sagemaker.workflow.utilities import trim_request_dict

Expand DownExpand Up@@ -257,7 +262,8 @@ def _inject_repack_script_and_launcher(self):
download_file_from_url(self._source_dir, old_targz_path, self.sagemaker_session)

with tarfile.open(name=old_targz_path, mode="r:gz") as t:
t.extractall(path=targz_contents_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=targz_contents_dir, filter="data")

shutil.copy2(fname, os.path.join(targz_contents_dir, REPACK_SCRIPT))
with open(
Expand Down
5 changes: 4 additions & 1 deletion tests/integ/s3_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,6 +19,8 @@
import boto3
from six.moves.urllib.parse import urlparse

from sagemaker.utils import check_tarfile_data_filter_attribute


def assert_s3_files_exist(sagemaker_session, s3_url, files):
parsed_url = urlparse(s3_url)
Expand DownExpand Up@@ -55,4 +57,5 @@ def extract_files_from_s3(s3_url, tmpdir, sagemaker_session):
s3.Bucket(parsed_url.netloc).download_file(parsed_url.path.lstrip("/"), model)

with tarfile.open(model, "r") as tar_file:
tar_file.extractall(tmpdir)
check_tarfile_data_filter_attribute()
tar_file.extractall(tmpdir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -272,4 +272,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir)
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -156,4 +156,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=code_dir)
mock_resource_obj.extractall.assert_called_once_with(path=code_dir, filter="data")
5 changes: 3 additions & 2 deletions tests/unit/test_fw_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -24,7 +24,7 @@
from mock import Mock, patch

from sagemaker import fw_utils
from sagemaker.utils import name_from_image
from sagemaker.utils import name_from_image, check_tarfile_data_filter_attribute
from sagemaker.session_settings import SessionSettings
from sagemaker.instance_group import InstanceGroup

Expand DownExpand Up@@ -424,7 +424,8 @@ def list_tar_files(folder, tar_ball, tmpdir):
startpath = str(tmpdir.ensure(folder, dir=True))

with tarfile.open(name=tar_ball, mode="r:gz") as t:
t.extractall(path=startpath)
check_tarfile_data_filter_attribute()
t.extractall(path=startpath, filter="data")

def walk():
for root, dirs, files in os.walk(startpath):
Expand Down
14 changes: 14 additions & 0 deletions tests/unit/test_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,6 +42,8 @@
resolve_nested_dict_value_from_config,
update_list_of_dicts_with_values_from_config,
volume_size_supported,
PythonVersionError,
check_tarfile_data_filter_attribute,
)
from tests.unit.sagemaker.workflow.helpers import CustomStep
from sagemaker.workflow.parameters import ParameterString, ParameterInteger
Expand DownExpand Up@@ -1748,3 +1750,15 @@ def test_instance_family_from_full_instance_type(self):

for instance_type, family in instance_type_to_family_test_dict.items():
self.assertEqual(family, get_instance_type_family(instance_type))


class TestCheckTarfileDataFilterAttribute(TestCase):
def test_check_tarfile_data_filter_attribute_unhappy_case(self):
with pytest.raises(PythonVersionError):
with patch("tarfile.data_filter", None):
delattr(tarfile, "data_filter")
check_tarfile_data_filter_attribute()

def test_check_tarfile_data_filter_attribute_happy_case(self):
with patch("tarfile.data_filter", "some_value"):
check_tarfile_data_filter_attribute()
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion src/sagemaker/local/image.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -40,6 +40,7 @@
import sagemaker.local.data
import sagemaker.local.utils
import sagemaker.utils
from sagemaker.utils import check_tarfile_data_filter_attribute

CONTAINER_PREFIX = "algo"
STUDIO_HOST_NAME = "sagemaker-local"
Expand DownExpand Up@@ -686,7 +687,8 @@ def _prepare_serving_volumes(self, model_location):
for filename in model_data_source.get_file_list():
if tarfile.is_tarfile(filename):
with tarfile.open(filename) as tar:
tar.extractall(path=model_data_source.get_root_dir())
check_tarfile_data_filter_attribute()
tar.extractall(path=model_data_source.get_root_dir(), filter="data")

volumes.append(_Volume(model_data_source.get_root_dir(), "/opt/ml/model"))

Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/djl_serving/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -20,7 +20,7 @@
from typing import List
from pathlib import Path

from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader
from sagemaker.djl_inference import DJLModel
from sagemaker.djl_inference.model import _read_existing_serving_properties
Expand DownExpand Up@@ -53,7 +53,8 @@ def _extract_js_resource(js_model_dir: str, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=js_model_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=js_model_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path):
Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/tgi/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,7 +19,7 @@
from pathlib import Path

from sagemaker.serve.utils.local_hardware import _check_disk_space, _check_docker_disk_usage
from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader

logger = logging.getLogger(__name__)
Expand All@@ -29,7 +29,8 @@ def _extract_js_resource(js_model_dir: str, code_dir: Path, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=code_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path) -> bool:
Expand Down
29 changes: 27 additions & 2 deletions src/sagemaker/utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -22,6 +22,7 @@
import random
import re
import shutil
import sys
import tarfile
import tempfile
import time
Expand DownExpand Up@@ -591,7 +592,8 @@ def _create_or_update_code_dir(
download_file_from_url(source_directory, local_code_path, sagemaker_session)

with tarfile.open(name=local_code_path, mode="r:gz") as t:
t.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=code_dir, filter="data")

elif source_directory:
if os.path.exists(code_dir):
Expand DownExpand Up@@ -628,7 +630,8 @@ def _extract_model(model_uri, sagemaker_session, tmp):
else:
local_model_path = model_uri.replace("file://", "")
with tarfile.open(name=local_model_path, mode="r:gz") as t:
t.extractall(path=tmp_model_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=tmp_model_dir, filter="data")
return tmp_model_dir


Expand DownExpand Up@@ -1489,3 +1492,25 @@ def format_tags(tags: Tags) -> List[TagsDict]:
return [{"Key": str(k), "Value": str(v)} for k, v in tags.items()]

return tags


class PythonVersionError(Exception):
"""Raise when a secure [/patched] version of Python is not used."""


def check_tarfile_data_filter_attribute():
"""Check if tarfile has data_filter utility.

Tarfile-data_filter utility has guardrails against untrusted de-serialisation.

Raises:
PythonVersionError: if `tarfile.data_filter` is not available.
"""
# The function and it's usages can be deprecated post support of python >= 3.12
if not hasattr(tarfile, "data_filter"):
raise PythonVersionError(
f"Since tarfile extraction is unsafe the operation is prohibited "
f"per PEP-721. Please update your Python [{sys.version}] "
f"to latest patch [refer to https://www.python.org/downloads/] "
f"to consume the security patch"
)
10 changes: 8 additions & 2 deletions src/sagemaker/workflow/_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,7 +32,12 @@
Step,
ConfigurableRetryStep,
)
from sagemaker.utils import _save_model, download_file_from_url, format_tags
from sagemaker.utils import (
_save_model,
download_file_from_url,
format_tags,
check_tarfile_data_filter_attribute,
)
from sagemaker.workflow.retry import RetryPolicy
from sagemaker.workflow.utilities import trim_request_dict

Expand DownExpand Up@@ -257,7 +262,8 @@ def _inject_repack_script_and_launcher(self):
download_file_from_url(self._source_dir, old_targz_path, self.sagemaker_session)

with tarfile.open(name=old_targz_path, mode="r:gz") as t:
t.extractall(path=targz_contents_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=targz_contents_dir, filter="data")

shutil.copy2(fname, os.path.join(targz_contents_dir, REPACK_SCRIPT))
with open(
Expand Down
5 changes: 4 additions & 1 deletion tests/integ/s3_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,6 +19,8 @@
import boto3
from six.moves.urllib.parse import urlparse

from sagemaker.utils import check_tarfile_data_filter_attribute


def assert_s3_files_exist(sagemaker_session, s3_url, files):
parsed_url = urlparse(s3_url)
Expand DownExpand Up@@ -55,4 +57,5 @@ def extract_files_from_s3(s3_url, tmpdir, sagemaker_session):
s3.Bucket(parsed_url.netloc).download_file(parsed_url.path.lstrip("/"), model)

with tarfile.open(model, "r") as tar_file:
tar_file.extractall(tmpdir)
check_tarfile_data_filter_attribute()
tar_file.extractall(tmpdir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -272,4 +272,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir)
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -156,4 +156,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=code_dir)
mock_resource_obj.extractall.assert_called_once_with(path=code_dir, filter="data")
5 changes: 3 additions & 2 deletions tests/unit/test_fw_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -24,7 +24,7 @@
from mock import Mock, patch

from sagemaker import fw_utils
from sagemaker.utils import name_from_image
from sagemaker.utils import name_from_image, check_tarfile_data_filter_attribute
from sagemaker.session_settings import SessionSettings
from sagemaker.instance_group import InstanceGroup

Expand DownExpand Up@@ -424,7 +424,8 @@ def list_tar_files(folder, tar_ball, tmpdir):
startpath = str(tmpdir.ensure(folder, dir=True))

with tarfile.open(name=tar_ball, mode="r:gz") as t:
t.extractall(path=startpath)
check_tarfile_data_filter_attribute()
t.extractall(path=startpath, filter="data")

def walk():
for root, dirs, files in os.walk(startpath):
Expand Down
14 changes: 14 additions & 0 deletions tests/unit/test_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,6 +42,8 @@
resolve_nested_dict_value_from_config,
update_list_of_dicts_with_values_from_config,
volume_size_supported,
PythonVersionError,
check_tarfile_data_filter_attribute,
)
from tests.unit.sagemaker.workflow.helpers import CustomStep
from sagemaker.workflow.parameters import ParameterString, ParameterInteger
Expand DownExpand Up@@ -1748,3 +1750,15 @@ def test_instance_family_from_full_instance_type(self):

for instance_type, family in instance_type_to_family_test_dict.items():
self.assertEqual(family, get_instance_type_family(instance_type))


class TestCheckTarfileDataFilterAttribute(TestCase):
def test_check_tarfile_data_filter_attribute_unhappy_case(self):
with pytest.raises(PythonVersionError):
with patch("tarfile.data_filter", None):
delattr(tarfile, "data_filter")
check_tarfile_data_filter_attribute()

def test_check_tarfile_data_filter_attribute_happy_case(self):
with patch("tarfile.data_filter", "some_value"):
check_tarfile_data_filter_attribute()
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion src/sagemaker/local/image.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -40,6 +40,7 @@
import sagemaker.local.data
import sagemaker.local.utils
import sagemaker.utils
from sagemaker.utils import check_tarfile_data_filter_attribute

CONTAINER_PREFIX = "algo"
STUDIO_HOST_NAME = "sagemaker-local"
Expand DownExpand Up@@ -686,7 +687,8 @@ def _prepare_serving_volumes(self, model_location):
for filename in model_data_source.get_file_list():
if tarfile.is_tarfile(filename):
with tarfile.open(filename) as tar:
tar.extractall(path=model_data_source.get_root_dir())
check_tarfile_data_filter_attribute()
tar.extractall(path=model_data_source.get_root_dir(), filter="data")

volumes.append(_Volume(model_data_source.get_root_dir(), "/opt/ml/model"))

Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/djl_serving/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -20,7 +20,7 @@
from typing import List
from pathlib import Path

from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader
from sagemaker.djl_inference import DJLModel
from sagemaker.djl_inference.model import _read_existing_serving_properties
Expand DownExpand Up@@ -53,7 +53,8 @@ def _extract_js_resource(js_model_dir: str, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=js_model_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=js_model_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path):
Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/tgi/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,7 +19,7 @@
from pathlib import Path

from sagemaker.serve.utils.local_hardware import _check_disk_space, _check_docker_disk_usage
from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader

logger = logging.getLogger(__name__)
Expand All@@ -29,7 +29,8 @@ def _extract_js_resource(js_model_dir: str, code_dir: Path, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=code_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path) -> bool:
Expand Down
29 changes: 27 additions & 2 deletions src/sagemaker/utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -22,6 +22,7 @@
import random
import re
import shutil
import sys
import tarfile
import tempfile
import time
Expand DownExpand Up@@ -591,7 +592,8 @@ def _create_or_update_code_dir(
download_file_from_url(source_directory, local_code_path, sagemaker_session)

with tarfile.open(name=local_code_path, mode="r:gz") as t:
t.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=code_dir, filter="data")

elif source_directory:
if os.path.exists(code_dir):
Expand DownExpand Up@@ -628,7 +630,8 @@ def _extract_model(model_uri, sagemaker_session, tmp):
else:
local_model_path = model_uri.replace("file://", "")
with tarfile.open(name=local_model_path, mode="r:gz") as t:
t.extractall(path=tmp_model_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=tmp_model_dir, filter="data")
return tmp_model_dir


Expand DownExpand Up@@ -1489,3 +1492,25 @@ def format_tags(tags: Tags) -> List[TagsDict]:
return [{"Key": str(k), "Value": str(v)} for k, v in tags.items()]

return tags


class PythonVersionError(Exception):
"""Raise when a secure [/patched] version of Python is not used."""


def check_tarfile_data_filter_attribute():
"""Check if tarfile has data_filter utility.

Tarfile-data_filter utility has guardrails against untrusted de-serialisation.

Raises:
PythonVersionError: if `tarfile.data_filter` is not available.
"""
# The function and it's usages can be deprecated post support of python >= 3.12
if not hasattr(tarfile, "data_filter"):
raise PythonVersionError(
f"Since tarfile extraction is unsafe the operation is prohibited "
f"per PEP-721. Please update your Python [{sys.version}] "
f"to latest patch [refer to https://www.python.org/downloads/] "
f"to consume the security patch"
)
10 changes: 8 additions & 2 deletions src/sagemaker/workflow/_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,7 +32,12 @@
Step,
ConfigurableRetryStep,
)
from sagemaker.utils import _save_model, download_file_from_url, format_tags
from sagemaker.utils import (
_save_model,
download_file_from_url,
format_tags,
check_tarfile_data_filter_attribute,
)
from sagemaker.workflow.retry import RetryPolicy
from sagemaker.workflow.utilities import trim_request_dict

Expand DownExpand Up@@ -257,7 +262,8 @@ def _inject_repack_script_and_launcher(self):
download_file_from_url(self._source_dir, old_targz_path, self.sagemaker_session)

with tarfile.open(name=old_targz_path, mode="r:gz") as t:
t.extractall(path=targz_contents_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=targz_contents_dir, filter="data")

shutil.copy2(fname, os.path.join(targz_contents_dir, REPACK_SCRIPT))
with open(
Expand Down
5 changes: 4 additions & 1 deletion tests/integ/s3_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,6 +19,8 @@
import boto3
from six.moves.urllib.parse import urlparse

from sagemaker.utils import check_tarfile_data_filter_attribute


def assert_s3_files_exist(sagemaker_session, s3_url, files):
parsed_url = urlparse(s3_url)
Expand DownExpand Up@@ -55,4 +57,5 @@ def extract_files_from_s3(s3_url, tmpdir, sagemaker_session):
s3.Bucket(parsed_url.netloc).download_file(parsed_url.path.lstrip("/"), model)

with tarfile.open(model, "r") as tar_file:
tar_file.extractall(tmpdir)
check_tarfile_data_filter_attribute()
tar_file.extractall(tmpdir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -272,4 +272,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir)
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -156,4 +156,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=code_dir)
mock_resource_obj.extractall.assert_called_once_with(path=code_dir, filter="data")
5 changes: 3 additions & 2 deletions tests/unit/test_fw_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -24,7 +24,7 @@
from mock import Mock, patch

from sagemaker import fw_utils
from sagemaker.utils import name_from_image
from sagemaker.utils import name_from_image, check_tarfile_data_filter_attribute
from sagemaker.session_settings import SessionSettings
from sagemaker.instance_group import InstanceGroup

Expand DownExpand Up@@ -424,7 +424,8 @@ def list_tar_files(folder, tar_ball, tmpdir):
startpath = str(tmpdir.ensure(folder, dir=True))

with tarfile.open(name=tar_ball, mode="r:gz") as t:
t.extractall(path=startpath)
check_tarfile_data_filter_attribute()
t.extractall(path=startpath, filter="data")

def walk():
for root, dirs, files in os.walk(startpath):
Expand Down
14 changes: 14 additions & 0 deletions tests/unit/test_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,6 +42,8 @@
resolve_nested_dict_value_from_config,
update_list_of_dicts_with_values_from_config,
volume_size_supported,
PythonVersionError,
check_tarfile_data_filter_attribute,
)
from tests.unit.sagemaker.workflow.helpers import CustomStep
from sagemaker.workflow.parameters import ParameterString, ParameterInteger
Expand DownExpand Up@@ -1748,3 +1750,15 @@ def test_instance_family_from_full_instance_type(self):

for instance_type, family in instance_type_to_family_test_dict.items():
self.assertEqual(family, get_instance_type_family(instance_type))


class TestCheckTarfileDataFilterAttribute(TestCase):
def test_check_tarfile_data_filter_attribute_unhappy_case(self):
with pytest.raises(PythonVersionError):
with patch("tarfile.data_filter", None):
delattr(tarfile, "data_filter")
check_tarfile_data_filter_attribute()

def test_check_tarfile_data_filter_attribute_happy_case(self):
with patch("tarfile.data_filter", "some_value"):
check_tarfile_data_filter_attribute()
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion src/sagemaker/local/image.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -40,6 +40,7 @@
import sagemaker.local.data
import sagemaker.local.utils
import sagemaker.utils
from sagemaker.utils import check_tarfile_data_filter_attribute

CONTAINER_PREFIX = "algo"
STUDIO_HOST_NAME = "sagemaker-local"
Expand DownExpand Up@@ -686,7 +687,8 @@ def _prepare_serving_volumes(self, model_location):
for filename in model_data_source.get_file_list():
if tarfile.is_tarfile(filename):
with tarfile.open(filename) as tar:
tar.extractall(path=model_data_source.get_root_dir())
check_tarfile_data_filter_attribute()
tar.extractall(path=model_data_source.get_root_dir(), filter="data")

volumes.append(_Volume(model_data_source.get_root_dir(), "/opt/ml/model"))

Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/djl_serving/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -20,7 +20,7 @@
from typing import List
from pathlib import Path

from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader
from sagemaker.djl_inference import DJLModel
from sagemaker.djl_inference.model import _read_existing_serving_properties
Expand DownExpand Up@@ -53,7 +53,8 @@ def _extract_js_resource(js_model_dir: str, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=js_model_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=js_model_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path):
Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/tgi/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,7 +19,7 @@
from pathlib import Path

from sagemaker.serve.utils.local_hardware import _check_disk_space, _check_docker_disk_usage
from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader

logger = logging.getLogger(__name__)
Expand All@@ -29,7 +29,8 @@ def _extract_js_resource(js_model_dir: str, code_dir: Path, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=code_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path) -> bool:
Expand Down
29 changes: 27 additions & 2 deletions src/sagemaker/utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -22,6 +22,7 @@
import random
import re
import shutil
import sys
import tarfile
import tempfile
import time
Expand DownExpand Up@@ -591,7 +592,8 @@ def _create_or_update_code_dir(
download_file_from_url(source_directory, local_code_path, sagemaker_session)

with tarfile.open(name=local_code_path, mode="r:gz") as t:
t.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=code_dir, filter="data")

elif source_directory:
if os.path.exists(code_dir):
Expand DownExpand Up@@ -628,7 +630,8 @@ def _extract_model(model_uri, sagemaker_session, tmp):
else:
local_model_path = model_uri.replace("file://", "")
with tarfile.open(name=local_model_path, mode="r:gz") as t:
t.extractall(path=tmp_model_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=tmp_model_dir, filter="data")
return tmp_model_dir


Expand DownExpand Up@@ -1489,3 +1492,25 @@ def format_tags(tags: Tags) -> List[TagsDict]:
return [{"Key": str(k), "Value": str(v)} for k, v in tags.items()]

return tags


class PythonVersionError(Exception):
"""Raise when a secure [/patched] version of Python is not used."""


def check_tarfile_data_filter_attribute():
"""Check if tarfile has data_filter utility.

Tarfile-data_filter utility has guardrails against untrusted de-serialisation.

Raises:
PythonVersionError: if `tarfile.data_filter` is not available.
"""
# The function and it's usages can be deprecated post support of python >= 3.12
if not hasattr(tarfile, "data_filter"):
raise PythonVersionError(
f"Since tarfile extraction is unsafe the operation is prohibited "
f"per PEP-721. Please update your Python [{sys.version}] "
f"to latest patch [refer to https://www.python.org/downloads/] "
f"to consume the security patch"
)
10 changes: 8 additions & 2 deletions src/sagemaker/workflow/_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,7 +32,12 @@
Step,
ConfigurableRetryStep,
)
from sagemaker.utils import _save_model, download_file_from_url, format_tags
from sagemaker.utils import (
_save_model,
download_file_from_url,
format_tags,
check_tarfile_data_filter_attribute,
)
from sagemaker.workflow.retry import RetryPolicy
from sagemaker.workflow.utilities import trim_request_dict

Expand DownExpand Up@@ -257,7 +262,8 @@ def _inject_repack_script_and_launcher(self):
download_file_from_url(self._source_dir, old_targz_path, self.sagemaker_session)

with tarfile.open(name=old_targz_path, mode="r:gz") as t:
t.extractall(path=targz_contents_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=targz_contents_dir, filter="data")

shutil.copy2(fname, os.path.join(targz_contents_dir, REPACK_SCRIPT))
with open(
Expand Down
5 changes: 4 additions & 1 deletion tests/integ/s3_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,6 +19,8 @@
import boto3
from six.moves.urllib.parse import urlparse

from sagemaker.utils import check_tarfile_data_filter_attribute


def assert_s3_files_exist(sagemaker_session, s3_url, files):
parsed_url = urlparse(s3_url)
Expand DownExpand Up@@ -55,4 +57,5 @@ def extract_files_from_s3(s3_url, tmpdir, sagemaker_session):
s3.Bucket(parsed_url.netloc).download_file(parsed_url.path.lstrip("/"), model)

with tarfile.open(model, "r") as tar_file:
tar_file.extractall(tmpdir)
check_tarfile_data_filter_attribute()
tar_file.extractall(tmpdir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -272,4 +272,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir)
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -156,4 +156,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=code_dir)
mock_resource_obj.extractall.assert_called_once_with(path=code_dir, filter="data")
5 changes: 3 additions & 2 deletions tests/unit/test_fw_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -24,7 +24,7 @@
from mock import Mock, patch

from sagemaker import fw_utils
from sagemaker.utils import name_from_image
from sagemaker.utils import name_from_image, check_tarfile_data_filter_attribute
from sagemaker.session_settings import SessionSettings
from sagemaker.instance_group import InstanceGroup

Expand DownExpand Up@@ -424,7 +424,8 @@ def list_tar_files(folder, tar_ball, tmpdir):
startpath = str(tmpdir.ensure(folder, dir=True))

with tarfile.open(name=tar_ball, mode="r:gz") as t:
t.extractall(path=startpath)
check_tarfile_data_filter_attribute()
t.extractall(path=startpath, filter="data")

def walk():
for root, dirs, files in os.walk(startpath):
Expand Down
14 changes: 14 additions & 0 deletions tests/unit/test_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,6 +42,8 @@
resolve_nested_dict_value_from_config,
update_list_of_dicts_with_values_from_config,
volume_size_supported,
PythonVersionError,
check_tarfile_data_filter_attribute,
)
from tests.unit.sagemaker.workflow.helpers import CustomStep
from sagemaker.workflow.parameters import ParameterString, ParameterInteger
Expand DownExpand Up@@ -1748,3 +1750,15 @@ def test_instance_family_from_full_instance_type(self):

for instance_type, family in instance_type_to_family_test_dict.items():
self.assertEqual(family, get_instance_type_family(instance_type))


class TestCheckTarfileDataFilterAttribute(TestCase):
def test_check_tarfile_data_filter_attribute_unhappy_case(self):
with pytest.raises(PythonVersionError):
with patch("tarfile.data_filter", None):
delattr(tarfile, "data_filter")
check_tarfile_data_filter_attribute()

def test_check_tarfile_data_filter_attribute_happy_case(self):
with patch("tarfile.data_filter", "some_value"):
check_tarfile_data_filter_attribute()
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion src/sagemaker/local/image.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -40,6 +40,7 @@
import sagemaker.local.data
import sagemaker.local.utils
import sagemaker.utils
from sagemaker.utils import check_tarfile_data_filter_attribute

CONTAINER_PREFIX = "algo"
STUDIO_HOST_NAME = "sagemaker-local"
Expand DownExpand Up@@ -686,7 +687,8 @@ def _prepare_serving_volumes(self, model_location):
for filename in model_data_source.get_file_list():
if tarfile.is_tarfile(filename):
with tarfile.open(filename) as tar:
tar.extractall(path=model_data_source.get_root_dir())
check_tarfile_data_filter_attribute()
tar.extractall(path=model_data_source.get_root_dir(), filter="data")

volumes.append(_Volume(model_data_source.get_root_dir(), "/opt/ml/model"))

Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/djl_serving/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -20,7 +20,7 @@
from typing import List
from pathlib import Path

from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader
from sagemaker.djl_inference import DJLModel
from sagemaker.djl_inference.model import _read_existing_serving_properties
Expand DownExpand Up@@ -53,7 +53,8 @@ def _extract_js_resource(js_model_dir: str, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=js_model_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=js_model_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path):
Expand Down
5 changes: 3 additions & 2 deletions src/sagemaker/serve/model_server/tgi/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,7 +19,7 @@
from pathlib import Path

from sagemaker.serve.utils.local_hardware import _check_disk_space, _check_docker_disk_usage
from sagemaker.utils import _tmpdir
from sagemaker.utils import _tmpdir, check_tarfile_data_filter_attribute
from sagemaker.s3 import S3Downloader

logger = logging.getLogger(__name__)
Expand All@@ -29,7 +29,8 @@ def _extract_js_resource(js_model_dir: str, code_dir: Path, js_id: str):
"""Uncompress the jumpstart resource"""
tmp_sourcedir = Path(js_model_dir).joinpath(f"infer-prepack-{js_id}.tar.gz")
with tarfile.open(str(tmp_sourcedir)) as resources:
resources.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
resources.extractall(path=code_dir, filter="data")


def _copy_jumpstart_artifacts(model_data: str, js_id: str, code_dir: Path) -> bool:
Expand Down
29 changes: 27 additions & 2 deletions src/sagemaker/utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -22,6 +22,7 @@
import random
import re
import shutil
import sys
import tarfile
import tempfile
import time
Expand DownExpand Up@@ -591,7 +592,8 @@ def _create_or_update_code_dir(
download_file_from_url(source_directory, local_code_path, sagemaker_session)

with tarfile.open(name=local_code_path, mode="r:gz") as t:
t.extractall(path=code_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=code_dir, filter="data")

elif source_directory:
if os.path.exists(code_dir):
Expand DownExpand Up@@ -628,7 +630,8 @@ def _extract_model(model_uri, sagemaker_session, tmp):
else:
local_model_path = model_uri.replace("file://", "")
with tarfile.open(name=local_model_path, mode="r:gz") as t:
t.extractall(path=tmp_model_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=tmp_model_dir, filter="data")
return tmp_model_dir


Expand DownExpand Up@@ -1489,3 +1492,25 @@ def format_tags(tags: Tags) -> List[TagsDict]:
return [{"Key": str(k), "Value": str(v)} for k, v in tags.items()]

return tags


class PythonVersionError(Exception):
"""Raise when a secure [/patched] version of Python is not used."""


def check_tarfile_data_filter_attribute():
"""Check if tarfile has data_filter utility.

Tarfile-data_filter utility has guardrails against untrusted de-serialisation.

Raises:
PythonVersionError: if `tarfile.data_filter` is not available.
"""
# The function and it's usages can be deprecated post support of python >= 3.12
if not hasattr(tarfile, "data_filter"):
raise PythonVersionError(
f"Since tarfile extraction is unsafe the operation is prohibited "
f"per PEP-721. Please update your Python [{sys.version}] "
f"to latest patch [refer to https://www.python.org/downloads/] "
f"to consume the security patch"
)
10 changes: 8 additions & 2 deletions src/sagemaker/workflow/_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,7 +32,12 @@
Step,
ConfigurableRetryStep,
)
from sagemaker.utils import _save_model, download_file_from_url, format_tags
from sagemaker.utils import (
_save_model,
download_file_from_url,
format_tags,
check_tarfile_data_filter_attribute,
)
from sagemaker.workflow.retry import RetryPolicy
from sagemaker.workflow.utilities import trim_request_dict

Expand DownExpand Up@@ -257,7 +262,8 @@ def _inject_repack_script_and_launcher(self):
download_file_from_url(self._source_dir, old_targz_path, self.sagemaker_session)

with tarfile.open(name=old_targz_path, mode="r:gz") as t:
t.extractall(path=targz_contents_dir)
check_tarfile_data_filter_attribute()
t.extractall(path=targz_contents_dir, filter="data")

shutil.copy2(fname, os.path.join(targz_contents_dir, REPACK_SCRIPT))
with open(
Expand Down
5 changes: 4 additions & 1 deletion tests/integ/s3_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -19,6 +19,8 @@
import boto3
from six.moves.urllib.parse import urlparse

from sagemaker.utils import check_tarfile_data_filter_attribute


def assert_s3_files_exist(sagemaker_session, s3_url, files):
parsed_url = urlparse(s3_url)
Expand DownExpand Up@@ -55,4 +57,5 @@ def extract_files_from_s3(s3_url, tmpdir, sagemaker_session):
s3.Bucket(parsed_url.netloc).download_file(parsed_url.path.lstrip("/"), model)

with tarfile.open(model, "r") as tar_file:
tar_file.extractall(tmpdir)
check_tarfile_data_filter_attribute()
tar_file.extractall(tmpdir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -272,4 +272,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir)
mock_resource_obj.extractall.assert_called_once_with(path=js_model_dir, filter="data")
Original file line numberDiff line numberDiff line change
Expand Up@@ -156,4 +156,4 @@ def test_extract_js_resources_success(self, mock_tarfile, mock_path):

mock_path.assert_called_once_with(js_model_dir)
mock_path_obj.joinpath.assert_called_once_with(f"infer-prepack-{MOCK_JUMPSTART_ID}.tar.gz")
mock_resource_obj.extractall.assert_called_once_with(path=code_dir)
mock_resource_obj.extractall.assert_called_once_with(path=code_dir, filter="data")
5 changes: 3 additions & 2 deletions tests/unit/test_fw_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -24,7 +24,7 @@
from mock import Mock, patch

from sagemaker import fw_utils
from sagemaker.utils import name_from_image
from sagemaker.utils import name_from_image, check_tarfile_data_filter_attribute
from sagemaker.session_settings import SessionSettings
from sagemaker.instance_group import InstanceGroup

Expand DownExpand Up@@ -424,7 +424,8 @@ def list_tar_files(folder, tar_ball, tmpdir):
startpath = str(tmpdir.ensure(folder, dir=True))

with tarfile.open(name=tar_ball, mode="r:gz") as t:
t.extractall(path=startpath)
check_tarfile_data_filter_attribute()
t.extractall(path=startpath, filter="data")

def walk():
for root, dirs, files in os.walk(startpath):
Expand Down
14 changes: 14 additions & 0 deletions tests/unit/test_utils.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,6 +42,8 @@
resolve_nested_dict_value_from_config,
update_list_of_dicts_with_values_from_config,
volume_size_supported,
PythonVersionError,
check_tarfile_data_filter_attribute,
)
from tests.unit.sagemaker.workflow.helpers import CustomStep
from sagemaker.workflow.parameters import ParameterString, ParameterInteger
Expand DownExpand Up@@ -1748,3 +1750,15 @@ def test_instance_family_from_full_instance_type(self):

for instance_type, family in instance_type_to_family_test_dict.items():
self.assertEqual(family, get_instance_type_family(instance_type))


class TestCheckTarfileDataFilterAttribute(TestCase):
def test_check_tarfile_data_filter_attribute_unhappy_case(self):
with pytest.raises(PythonVersionError):
with patch("tarfile.data_filter", None):
delattr(tarfile, "data_filter")
check_tarfile_data_filter_attribute()

def test_check_tarfile_data_filter_attribute_happy_case(self):
with patch("tarfile.data_filter", "some_value"):
check_tarfile_data_filter_attribute()