Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions sagemaker-serve/src/sagemaker/serve/model_builder_servers.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -751,6 +751,12 @@ def _build_for_smd(self) -> Model:
inference_spec=self.inference_spec,
)

# Propagate secret key to container environment
if self.secret_key:
self.env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = self.secret_key
else:
self.env_vars.pop("SAGEMAKER_SERVE_SECRET_KEY", None)

# Prepare deployment artifacts
if self.mode in LOCAL_MODES:
self._prepare_for_mode()
Expand Down
16 changes: 14 additions & 2 deletions sagemaker-serve/src/sagemaker/serve/model_server/smd/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,10 +13,15 @@
from sagemaker.serve.detector.dependency_manager import capture_dependencies
from sagemaker.serve.validations.check_integrity import (
compute_hash,
generate_secret_key,
)
from sagemaker.core.remote_function.core.serialization import _MetaData
from sagemaker.serve.spec.inference_base import CustomOrchestrator, AsyncCustomOrchestrator

import logging

logger = logging.getLogger(__name__)


def prepare_for_smd(
model_path: str,
Expand All@@ -34,7 +39,9 @@ def prepare_for_smd(
(default is None)

Returns:
( str ) :
str: A generated secret key used to compute the HMAC hash stored in
metadata.json. Callers should propagate this value to the container
environment as SAGEMAKER_SERVE_SECRET_KEY.

"""
model_path = Path(model_path)
Expand DownExpand Up@@ -63,8 +70,13 @@ def prepare_for_smd(

capture_dependencies(dependencies=dependencies, work_dir=code_dir)

secret_key = generate_secret_key()
logger.debug("Generated secret key for SMD artifact integrity check.")

with open(str(code_dir.joinpath("serve.pkl")), "rb") as f:
buffer = f.read()
hash_value = compute_hash(buffer=buffer)
hash_value = compute_hash(buffer=buffer, secret_key=secret_key)
with open(str(code_dir.joinpath("metadata.json")), "wb") as metadata:
metadata.write(_MetaData(hash_value).to_json())

return secret_key
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,4 +55,6 @@ def _upload_smd_artifacts(
"SAGEMAKER_REGION": sagemaker_session.boto_region_name,
"LOCAL_PYTHON": platform.python_version(),
}
if secret_key:
env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = secret_key
return s3_upload_path, env_vars
Original file line numberDiff line numberDiff line change
@@ -1,27 +1,91 @@
"""Validates the integrity of pickled file with SHA-256 hash."""
"""Validates the integrity of pickled file with SHA-256 hash.

Supports two modes:
- Plain SHA-256 (default): Used when no secret key is provided.
- HMAC-SHA256 (keyed): Used when a secret key is provided, for backward
compatibility with older container images that perform HMAC-based checks.
"""

from __future__ import absolute_import
import hmac
import hashlib
import os
import secrets
from pathlib import Path

from sagemaker.core.remote_function.core.serialization import _MetaData

SAGEMAKER_SERVE_SECRET_KEY = "SAGEMAKER_SERVE_SECRET_KEY"


def generate_secret_key(nbytes: int = 32) -> str:
"""Generate a cryptographically secure secret key.

Args:
nbytes: Number of random bytes (the returned hex string will be
twice this length). Defaults to 32 (256-bit key).

Returns:
A hex-encoded random string suitable for use as an HMAC key.
"""
return secrets.token_hex(nbytes)


def compute_hash(buffer: bytes, secret_key: str = None) -> str:
"""Compute hash of the given buffer.

def compute_hash(buffer: bytes) -> str:
"""Compute SHA-256 hash of the given buffer."""
When *secret_key* is provided the hash is an HMAC-SHA256 keyed digest;
otherwise a plain SHA-256 digest is returned.

Args:
buffer: The bytes to hash.
secret_key: Optional HMAC key. When ``None`` (default) a plain
SHA-256 hash is computed.

Returns:
Hex-encoded hash string.
"""
if secret_key:
return hmac.new(secret_key.encode(), msg=buffer, digestmod=hashlib.sha256).hexdigest()
return hashlib.sha256(buffer).hexdigest()


def perform_integrity_check(buffer: bytes, metadata_path: Path):
"""Validates the integrity of bytes by comparing the hash value."""
actual_hash_value = compute_hash(buffer=buffer)
def perform_integrity_check(buffer: bytes, metadata_path: Path, secret_key: str = None):
"""Validates the integrity of bytes by comparing the hash value.

Computes both the plain SHA-256 digest and (when a secret key is
available) the HMAC-SHA256 digest, then checks whether the expected
hash stored in *metadata_path* matches either one. This provides
backward compatibility between SDK versions that write plain hashes
and container images that expect HMAC hashes (or vice-versa).

Args:
buffer: The serialized bytes to verify.
metadata_path: Path to the ``metadata.json`` file containing the
expected hash.
secret_key: Optional HMAC key. When ``None`` the function falls
back to the ``SAGEMAKER_SERVE_SECRET_KEY`` environment variable.
"""
if not Path.exists(metadata_path):
raise ValueError("Path to metadata.json does not exist")

with open(str(metadata_path), "rb") as md:
expected_hash_value = _MetaData.from_json(md.read()).sha256_hash

if not hmac.compare_digest(expected_hash_value, actual_hash_value):
raise ValueError("Integrity check for the serialized function or data failed.")
# Resolve secret key: explicit arg > environment variable > None
effective_secret_key = secret_key or os.environ.get(SAGEMAKER_SERVE_SECRET_KEY)

# Compute candidate digests
plain_hash = hashlib.sha256(buffer).hexdigest()

if hmac.compare_digest(expected_hash_value, plain_hash):
return

if effective_secret_key:
hmac_hash = hmac.new(
effective_secret_key.encode(), msg=buffer, digestmod=hashlib.sha256
).hexdigest()
if hmac.compare_digest(expected_hash_value, hmac_hash):
return

raise ValueError("Integrity check for the serialized function or data failed.")
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions sagemaker-serve/src/sagemaker/serve/model_builder_servers.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -751,6 +751,12 @@ def _build_for_smd(self) -> Model:
inference_spec=self.inference_spec,
)

# Propagate secret key to container environment
if self.secret_key:
self.env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = self.secret_key
else:
self.env_vars.pop("SAGEMAKER_SERVE_SECRET_KEY", None)

# Prepare deployment artifacts
if self.mode in LOCAL_MODES:
self._prepare_for_mode()
Expand Down
16 changes: 14 additions & 2 deletions sagemaker-serve/src/sagemaker/serve/model_server/smd/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,10 +13,15 @@
from sagemaker.serve.detector.dependency_manager import capture_dependencies
from sagemaker.serve.validations.check_integrity import (
compute_hash,
generate_secret_key,
)
from sagemaker.core.remote_function.core.serialization import _MetaData
from sagemaker.serve.spec.inference_base import CustomOrchestrator, AsyncCustomOrchestrator

import logging

logger = logging.getLogger(__name__)


def prepare_for_smd(
model_path: str,
Expand All@@ -34,7 +39,9 @@ def prepare_for_smd(
(default is None)

Returns:
( str ) :
str: A generated secret key used to compute the HMAC hash stored in
metadata.json. Callers should propagate this value to the container
environment as SAGEMAKER_SERVE_SECRET_KEY.

"""
model_path = Path(model_path)
Expand DownExpand Up@@ -63,8 +70,13 @@ def prepare_for_smd(

capture_dependencies(dependencies=dependencies, work_dir=code_dir)

secret_key = generate_secret_key()
logger.debug("Generated secret key for SMD artifact integrity check.")

with open(str(code_dir.joinpath("serve.pkl")), "rb") as f:
buffer = f.read()
hash_value = compute_hash(buffer=buffer)
hash_value = compute_hash(buffer=buffer, secret_key=secret_key)
with open(str(code_dir.joinpath("metadata.json")), "wb") as metadata:
metadata.write(_MetaData(hash_value).to_json())

return secret_key
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,4 +55,6 @@ def _upload_smd_artifacts(
"SAGEMAKER_REGION": sagemaker_session.boto_region_name,
"LOCAL_PYTHON": platform.python_version(),
}
if secret_key:
env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = secret_key
return s3_upload_path, env_vars
Original file line numberDiff line numberDiff line change
@@ -1,27 +1,91 @@
"""Validates the integrity of pickled file with SHA-256 hash."""
"""Validates the integrity of pickled file with SHA-256 hash.

Supports two modes:
- Plain SHA-256 (default): Used when no secret key is provided.
- HMAC-SHA256 (keyed): Used when a secret key is provided, for backward
compatibility with older container images that perform HMAC-based checks.
"""

from __future__ import absolute_import
import hmac
import hashlib
import os
import secrets
from pathlib import Path

from sagemaker.core.remote_function.core.serialization import _MetaData

SAGEMAKER_SERVE_SECRET_KEY = "SAGEMAKER_SERVE_SECRET_KEY"


def generate_secret_key(nbytes: int = 32) -> str:
"""Generate a cryptographically secure secret key.

Args:
nbytes: Number of random bytes (the returned hex string will be
twice this length). Defaults to 32 (256-bit key).

Returns:
A hex-encoded random string suitable for use as an HMAC key.
"""
return secrets.token_hex(nbytes)


def compute_hash(buffer: bytes, secret_key: str = None) -> str:
"""Compute hash of the given buffer.

def compute_hash(buffer: bytes) -> str:
"""Compute SHA-256 hash of the given buffer."""
When *secret_key* is provided the hash is an HMAC-SHA256 keyed digest;
otherwise a plain SHA-256 digest is returned.

Args:
buffer: The bytes to hash.
secret_key: Optional HMAC key. When ``None`` (default) a plain
SHA-256 hash is computed.

Returns:
Hex-encoded hash string.
"""
if secret_key:
return hmac.new(secret_key.encode(), msg=buffer, digestmod=hashlib.sha256).hexdigest()
return hashlib.sha256(buffer).hexdigest()


def perform_integrity_check(buffer: bytes, metadata_path: Path):
"""Validates the integrity of bytes by comparing the hash value."""
actual_hash_value = compute_hash(buffer=buffer)
def perform_integrity_check(buffer: bytes, metadata_path: Path, secret_key: str = None):
"""Validates the integrity of bytes by comparing the hash value.

Computes both the plain SHA-256 digest and (when a secret key is
available) the HMAC-SHA256 digest, then checks whether the expected
hash stored in *metadata_path* matches either one. This provides
backward compatibility between SDK versions that write plain hashes
and container images that expect HMAC hashes (or vice-versa).

Args:
buffer: The serialized bytes to verify.
metadata_path: Path to the ``metadata.json`` file containing the
expected hash.
secret_key: Optional HMAC key. When ``None`` the function falls
back to the ``SAGEMAKER_SERVE_SECRET_KEY`` environment variable.
"""
if not Path.exists(metadata_path):
raise ValueError("Path to metadata.json does not exist")

with open(str(metadata_path), "rb") as md:
expected_hash_value = _MetaData.from_json(md.read()).sha256_hash

if not hmac.compare_digest(expected_hash_value, actual_hash_value):
raise ValueError("Integrity check for the serialized function or data failed.")
# Resolve secret key: explicit arg > environment variable > None
effective_secret_key = secret_key or os.environ.get(SAGEMAKER_SERVE_SECRET_KEY)

# Compute candidate digests
plain_hash = hashlib.sha256(buffer).hexdigest()

if hmac.compare_digest(expected_hash_value, plain_hash):
return

if effective_secret_key:
hmac_hash = hmac.new(
effective_secret_key.encode(), msg=buffer, digestmod=hashlib.sha256
).hexdigest()
if hmac.compare_digest(expected_hash_value, hmac_hash):
return

raise ValueError("Integrity check for the serialized function or data failed.")
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions sagemaker-serve/src/sagemaker/serve/model_builder_servers.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -751,6 +751,12 @@ def _build_for_smd(self) -> Model:
inference_spec=self.inference_spec,
)

# Propagate secret key to container environment
if self.secret_key:
self.env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = self.secret_key
else:
self.env_vars.pop("SAGEMAKER_SERVE_SECRET_KEY", None)

# Prepare deployment artifacts
if self.mode in LOCAL_MODES:
self._prepare_for_mode()
Expand Down
16 changes: 14 additions & 2 deletions sagemaker-serve/src/sagemaker/serve/model_server/smd/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,10 +13,15 @@
from sagemaker.serve.detector.dependency_manager import capture_dependencies
from sagemaker.serve.validations.check_integrity import (
compute_hash,
generate_secret_key,
)
from sagemaker.core.remote_function.core.serialization import _MetaData
from sagemaker.serve.spec.inference_base import CustomOrchestrator, AsyncCustomOrchestrator

import logging

logger = logging.getLogger(__name__)


def prepare_for_smd(
model_path: str,
Expand All@@ -34,7 +39,9 @@ def prepare_for_smd(
(default is None)

Returns:
( str ) :
str: A generated secret key used to compute the HMAC hash stored in
metadata.json. Callers should propagate this value to the container
environment as SAGEMAKER_SERVE_SECRET_KEY.

"""
model_path = Path(model_path)
Expand DownExpand Up@@ -63,8 +70,13 @@ def prepare_for_smd(

capture_dependencies(dependencies=dependencies, work_dir=code_dir)

secret_key = generate_secret_key()
logger.debug("Generated secret key for SMD artifact integrity check.")

with open(str(code_dir.joinpath("serve.pkl")), "rb") as f:
buffer = f.read()
hash_value = compute_hash(buffer=buffer)
hash_value = compute_hash(buffer=buffer, secret_key=secret_key)
with open(str(code_dir.joinpath("metadata.json")), "wb") as metadata:
metadata.write(_MetaData(hash_value).to_json())

return secret_key
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,4 +55,6 @@ def _upload_smd_artifacts(
"SAGEMAKER_REGION": sagemaker_session.boto_region_name,
"LOCAL_PYTHON": platform.python_version(),
}
if secret_key:
env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = secret_key
return s3_upload_path, env_vars
Original file line numberDiff line numberDiff line change
@@ -1,27 +1,91 @@
"""Validates the integrity of pickled file with SHA-256 hash."""
"""Validates the integrity of pickled file with SHA-256 hash.

Supports two modes:
- Plain SHA-256 (default): Used when no secret key is provided.
- HMAC-SHA256 (keyed): Used when a secret key is provided, for backward
compatibility with older container images that perform HMAC-based checks.
"""

from __future__ import absolute_import
import hmac
import hashlib
import os
import secrets
from pathlib import Path

from sagemaker.core.remote_function.core.serialization import _MetaData

SAGEMAKER_SERVE_SECRET_KEY = "SAGEMAKER_SERVE_SECRET_KEY"


def generate_secret_key(nbytes: int = 32) -> str:
"""Generate a cryptographically secure secret key.

Args:
nbytes: Number of random bytes (the returned hex string will be
twice this length). Defaults to 32 (256-bit key).

Returns:
A hex-encoded random string suitable for use as an HMAC key.
"""
return secrets.token_hex(nbytes)


def compute_hash(buffer: bytes, secret_key: str = None) -> str:
"""Compute hash of the given buffer.

def compute_hash(buffer: bytes) -> str:
"""Compute SHA-256 hash of the given buffer."""
When *secret_key* is provided the hash is an HMAC-SHA256 keyed digest;
otherwise a plain SHA-256 digest is returned.

Args:
buffer: The bytes to hash.
secret_key: Optional HMAC key. When ``None`` (default) a plain
SHA-256 hash is computed.

Returns:
Hex-encoded hash string.
"""
if secret_key:
return hmac.new(secret_key.encode(), msg=buffer, digestmod=hashlib.sha256).hexdigest()
return hashlib.sha256(buffer).hexdigest()


def perform_integrity_check(buffer: bytes, metadata_path: Path):
"""Validates the integrity of bytes by comparing the hash value."""
actual_hash_value = compute_hash(buffer=buffer)
def perform_integrity_check(buffer: bytes, metadata_path: Path, secret_key: str = None):
"""Validates the integrity of bytes by comparing the hash value.

Computes both the plain SHA-256 digest and (when a secret key is
available) the HMAC-SHA256 digest, then checks whether the expected
hash stored in *metadata_path* matches either one. This provides
backward compatibility between SDK versions that write plain hashes
and container images that expect HMAC hashes (or vice-versa).

Args:
buffer: The serialized bytes to verify.
metadata_path: Path to the ``metadata.json`` file containing the
expected hash.
secret_key: Optional HMAC key. When ``None`` the function falls
back to the ``SAGEMAKER_SERVE_SECRET_KEY`` environment variable.
"""
if not Path.exists(metadata_path):
raise ValueError("Path to metadata.json does not exist")

with open(str(metadata_path), "rb") as md:
expected_hash_value = _MetaData.from_json(md.read()).sha256_hash

if not hmac.compare_digest(expected_hash_value, actual_hash_value):
raise ValueError("Integrity check for the serialized function or data failed.")
# Resolve secret key: explicit arg > environment variable > None
effective_secret_key = secret_key or os.environ.get(SAGEMAKER_SERVE_SECRET_KEY)

# Compute candidate digests
plain_hash = hashlib.sha256(buffer).hexdigest()

if hmac.compare_digest(expected_hash_value, plain_hash):
return

if effective_secret_key:
hmac_hash = hmac.new(
effective_secret_key.encode(), msg=buffer, digestmod=hashlib.sha256
).hexdigest()
if hmac.compare_digest(expected_hash_value, hmac_hash):
return

raise ValueError("Integrity check for the serialized function or data failed.")
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions sagemaker-serve/src/sagemaker/serve/model_builder_servers.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -751,6 +751,12 @@ def _build_for_smd(self) -> Model:
inference_spec=self.inference_spec,
)

# Propagate secret key to container environment
if self.secret_key:
self.env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = self.secret_key
else:
self.env_vars.pop("SAGEMAKER_SERVE_SECRET_KEY", None)

# Prepare deployment artifacts
if self.mode in LOCAL_MODES:
self._prepare_for_mode()
Expand Down
16 changes: 14 additions & 2 deletions sagemaker-serve/src/sagemaker/serve/model_server/smd/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,10 +13,15 @@
from sagemaker.serve.detector.dependency_manager import capture_dependencies
from sagemaker.serve.validations.check_integrity import (
compute_hash,
generate_secret_key,
)
from sagemaker.core.remote_function.core.serialization import _MetaData
from sagemaker.serve.spec.inference_base import CustomOrchestrator, AsyncCustomOrchestrator

import logging

logger = logging.getLogger(__name__)


def prepare_for_smd(
model_path: str,
Expand All@@ -34,7 +39,9 @@ def prepare_for_smd(
(default is None)

Returns:
( str ) :
str: A generated secret key used to compute the HMAC hash stored in
metadata.json. Callers should propagate this value to the container
environment as SAGEMAKER_SERVE_SECRET_KEY.

"""
model_path = Path(model_path)
Expand DownExpand Up@@ -63,8 +70,13 @@ def prepare_for_smd(

capture_dependencies(dependencies=dependencies, work_dir=code_dir)

secret_key = generate_secret_key()
logger.debug("Generated secret key for SMD artifact integrity check.")

with open(str(code_dir.joinpath("serve.pkl")), "rb") as f:
buffer = f.read()
hash_value = compute_hash(buffer=buffer)
hash_value = compute_hash(buffer=buffer, secret_key=secret_key)
with open(str(code_dir.joinpath("metadata.json")), "wb") as metadata:
metadata.write(_MetaData(hash_value).to_json())

return secret_key
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,4 +55,6 @@ def _upload_smd_artifacts(
"SAGEMAKER_REGION": sagemaker_session.boto_region_name,
"LOCAL_PYTHON": platform.python_version(),
}
if secret_key:
env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = secret_key
return s3_upload_path, env_vars
Original file line numberDiff line numberDiff line change
@@ -1,27 +1,91 @@
"""Validates the integrity of pickled file with SHA-256 hash."""
"""Validates the integrity of pickled file with SHA-256 hash.

Supports two modes:
- Plain SHA-256 (default): Used when no secret key is provided.
- HMAC-SHA256 (keyed): Used when a secret key is provided, for backward
compatibility with older container images that perform HMAC-based checks.
"""

from __future__ import absolute_import
import hmac
import hashlib
import os
import secrets
from pathlib import Path

from sagemaker.core.remote_function.core.serialization import _MetaData

SAGEMAKER_SERVE_SECRET_KEY = "SAGEMAKER_SERVE_SECRET_KEY"


def generate_secret_key(nbytes: int = 32) -> str:
"""Generate a cryptographically secure secret key.

Args:
nbytes: Number of random bytes (the returned hex string will be
twice this length). Defaults to 32 (256-bit key).

Returns:
A hex-encoded random string suitable for use as an HMAC key.
"""
return secrets.token_hex(nbytes)


def compute_hash(buffer: bytes, secret_key: str = None) -> str:
"""Compute hash of the given buffer.

def compute_hash(buffer: bytes) -> str:
"""Compute SHA-256 hash of the given buffer."""
When *secret_key* is provided the hash is an HMAC-SHA256 keyed digest;
otherwise a plain SHA-256 digest is returned.

Args:
buffer: The bytes to hash.
secret_key: Optional HMAC key. When ``None`` (default) a plain
SHA-256 hash is computed.

Returns:
Hex-encoded hash string.
"""
if secret_key:
return hmac.new(secret_key.encode(), msg=buffer, digestmod=hashlib.sha256).hexdigest()
return hashlib.sha256(buffer).hexdigest()


def perform_integrity_check(buffer: bytes, metadata_path: Path):
"""Validates the integrity of bytes by comparing the hash value."""
actual_hash_value = compute_hash(buffer=buffer)
def perform_integrity_check(buffer: bytes, metadata_path: Path, secret_key: str = None):
"""Validates the integrity of bytes by comparing the hash value.

Computes both the plain SHA-256 digest and (when a secret key is
available) the HMAC-SHA256 digest, then checks whether the expected
hash stored in *metadata_path* matches either one. This provides
backward compatibility between SDK versions that write plain hashes
and container images that expect HMAC hashes (or vice-versa).

Args:
buffer: The serialized bytes to verify.
metadata_path: Path to the ``metadata.json`` file containing the
expected hash.
secret_key: Optional HMAC key. When ``None`` the function falls
back to the ``SAGEMAKER_SERVE_SECRET_KEY`` environment variable.
"""
if not Path.exists(metadata_path):
raise ValueError("Path to metadata.json does not exist")

with open(str(metadata_path), "rb") as md:
expected_hash_value = _MetaData.from_json(md.read()).sha256_hash

if not hmac.compare_digest(expected_hash_value, actual_hash_value):
raise ValueError("Integrity check for the serialized function or data failed.")
# Resolve secret key: explicit arg > environment variable > None
effective_secret_key = secret_key or os.environ.get(SAGEMAKER_SERVE_SECRET_KEY)

# Compute candidate digests
plain_hash = hashlib.sha256(buffer).hexdigest()

if hmac.compare_digest(expected_hash_value, plain_hash):
return

if effective_secret_key:
hmac_hash = hmac.new(
effective_secret_key.encode(), msg=buffer, digestmod=hashlib.sha256
).hexdigest()
if hmac.compare_digest(expected_hash_value, hmac_hash):
return

raise ValueError("Integrity check for the serialized function or data failed.")
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions sagemaker-serve/src/sagemaker/serve/model_builder_servers.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -751,6 +751,12 @@ def _build_for_smd(self) -> Model:
inference_spec=self.inference_spec,
)

# Propagate secret key to container environment
if self.secret_key:
self.env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = self.secret_key
else:
self.env_vars.pop("SAGEMAKER_SERVE_SECRET_KEY", None)

# Prepare deployment artifacts
if self.mode in LOCAL_MODES:
self._prepare_for_mode()
Expand Down
16 changes: 14 additions & 2 deletions sagemaker-serve/src/sagemaker/serve/model_server/smd/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,10 +13,15 @@
from sagemaker.serve.detector.dependency_manager import capture_dependencies
from sagemaker.serve.validations.check_integrity import (
compute_hash,
generate_secret_key,
)
from sagemaker.core.remote_function.core.serialization import _MetaData
from sagemaker.serve.spec.inference_base import CustomOrchestrator, AsyncCustomOrchestrator

import logging

logger = logging.getLogger(__name__)


def prepare_for_smd(
model_path: str,
Expand All@@ -34,7 +39,9 @@ def prepare_for_smd(
(default is None)

Returns:
( str ) :
str: A generated secret key used to compute the HMAC hash stored in
metadata.json. Callers should propagate this value to the container
environment as SAGEMAKER_SERVE_SECRET_KEY.

"""
model_path = Path(model_path)
Expand DownExpand Up@@ -63,8 +70,13 @@ def prepare_for_smd(

capture_dependencies(dependencies=dependencies, work_dir=code_dir)

secret_key = generate_secret_key()
logger.debug("Generated secret key for SMD artifact integrity check.")

with open(str(code_dir.joinpath("serve.pkl")), "rb") as f:
buffer = f.read()
hash_value = compute_hash(buffer=buffer)
hash_value = compute_hash(buffer=buffer, secret_key=secret_key)
with open(str(code_dir.joinpath("metadata.json")), "wb") as metadata:
metadata.write(_MetaData(hash_value).to_json())

return secret_key
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,4 +55,6 @@ def _upload_smd_artifacts(
"SAGEMAKER_REGION": sagemaker_session.boto_region_name,
"LOCAL_PYTHON": platform.python_version(),
}
if secret_key:
env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = secret_key
return s3_upload_path, env_vars
Original file line numberDiff line numberDiff line change
@@ -1,27 +1,91 @@
"""Validates the integrity of pickled file with SHA-256 hash."""
"""Validates the integrity of pickled file with SHA-256 hash.

Supports two modes:
- Plain SHA-256 (default): Used when no secret key is provided.
- HMAC-SHA256 (keyed): Used when a secret key is provided, for backward
compatibility with older container images that perform HMAC-based checks.
"""

from __future__ import absolute_import
import hmac
import hashlib
import os
import secrets
from pathlib import Path

from sagemaker.core.remote_function.core.serialization import _MetaData

SAGEMAKER_SERVE_SECRET_KEY = "SAGEMAKER_SERVE_SECRET_KEY"


def generate_secret_key(nbytes: int = 32) -> str:
"""Generate a cryptographically secure secret key.

Args:
nbytes: Number of random bytes (the returned hex string will be
twice this length). Defaults to 32 (256-bit key).

Returns:
A hex-encoded random string suitable for use as an HMAC key.
"""
return secrets.token_hex(nbytes)


def compute_hash(buffer: bytes, secret_key: str = None) -> str:
"""Compute hash of the given buffer.

def compute_hash(buffer: bytes) -> str:
"""Compute SHA-256 hash of the given buffer."""
When *secret_key* is provided the hash is an HMAC-SHA256 keyed digest;
otherwise a plain SHA-256 digest is returned.

Args:
buffer: The bytes to hash.
secret_key: Optional HMAC key. When ``None`` (default) a plain
SHA-256 hash is computed.

Returns:
Hex-encoded hash string.
"""
if secret_key:
return hmac.new(secret_key.encode(), msg=buffer, digestmod=hashlib.sha256).hexdigest()
return hashlib.sha256(buffer).hexdigest()


def perform_integrity_check(buffer: bytes, metadata_path: Path):
"""Validates the integrity of bytes by comparing the hash value."""
actual_hash_value = compute_hash(buffer=buffer)
def perform_integrity_check(buffer: bytes, metadata_path: Path, secret_key: str = None):
"""Validates the integrity of bytes by comparing the hash value.

Computes both the plain SHA-256 digest and (when a secret key is
available) the HMAC-SHA256 digest, then checks whether the expected
hash stored in *metadata_path* matches either one. This provides
backward compatibility between SDK versions that write plain hashes
and container images that expect HMAC hashes (or vice-versa).

Args:
buffer: The serialized bytes to verify.
metadata_path: Path to the ``metadata.json`` file containing the
expected hash.
secret_key: Optional HMAC key. When ``None`` the function falls
back to the ``SAGEMAKER_SERVE_SECRET_KEY`` environment variable.
"""
if not Path.exists(metadata_path):
raise ValueError("Path to metadata.json does not exist")

with open(str(metadata_path), "rb") as md:
expected_hash_value = _MetaData.from_json(md.read()).sha256_hash

if not hmac.compare_digest(expected_hash_value, actual_hash_value):
raise ValueError("Integrity check for the serialized function or data failed.")
# Resolve secret key: explicit arg > environment variable > None
effective_secret_key = secret_key or os.environ.get(SAGEMAKER_SERVE_SECRET_KEY)

# Compute candidate digests
plain_hash = hashlib.sha256(buffer).hexdigest()

if hmac.compare_digest(expected_hash_value, plain_hash):
return

if effective_secret_key:
hmac_hash = hmac.new(
effective_secret_key.encode(), msg=buffer, digestmod=hashlib.sha256
).hexdigest()
if hmac.compare_digest(expected_hash_value, hmac_hash):
return

raise ValueError("Integrity check for the serialized function or data failed.")
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions sagemaker-serve/src/sagemaker/serve/model_builder_servers.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -751,6 +751,12 @@ def _build_for_smd(self) -> Model:
inference_spec=self.inference_spec,
)

# Propagate secret key to container environment
if self.secret_key:
self.env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = self.secret_key
else:
self.env_vars.pop("SAGEMAKER_SERVE_SECRET_KEY", None)

# Prepare deployment artifacts
if self.mode in LOCAL_MODES:
self._prepare_for_mode()
Expand Down
16 changes: 14 additions & 2 deletions sagemaker-serve/src/sagemaker/serve/model_server/smd/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,10 +13,15 @@
from sagemaker.serve.detector.dependency_manager import capture_dependencies
from sagemaker.serve.validations.check_integrity import (
compute_hash,
generate_secret_key,
)
from sagemaker.core.remote_function.core.serialization import _MetaData
from sagemaker.serve.spec.inference_base import CustomOrchestrator, AsyncCustomOrchestrator

import logging

logger = logging.getLogger(__name__)


def prepare_for_smd(
model_path: str,
Expand All@@ -34,7 +39,9 @@ def prepare_for_smd(
(default is None)

Returns:
( str ) :
str: A generated secret key used to compute the HMAC hash stored in
metadata.json. Callers should propagate this value to the container
environment as SAGEMAKER_SERVE_SECRET_KEY.

"""
model_path = Path(model_path)
Expand DownExpand Up@@ -63,8 +70,13 @@ def prepare_for_smd(

capture_dependencies(dependencies=dependencies, work_dir=code_dir)

secret_key = generate_secret_key()
logger.debug("Generated secret key for SMD artifact integrity check.")

with open(str(code_dir.joinpath("serve.pkl")), "rb") as f:
buffer = f.read()
hash_value = compute_hash(buffer=buffer)
hash_value = compute_hash(buffer=buffer, secret_key=secret_key)
with open(str(code_dir.joinpath("metadata.json")), "wb") as metadata:
metadata.write(_MetaData(hash_value).to_json())

return secret_key
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,4 +55,6 @@ def _upload_smd_artifacts(
"SAGEMAKER_REGION": sagemaker_session.boto_region_name,
"LOCAL_PYTHON": platform.python_version(),
}
if secret_key:
env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = secret_key
return s3_upload_path, env_vars
Original file line numberDiff line numberDiff line change
@@ -1,27 +1,91 @@
"""Validates the integrity of pickled file with SHA-256 hash."""
"""Validates the integrity of pickled file with SHA-256 hash.

Supports two modes:
- Plain SHA-256 (default): Used when no secret key is provided.
- HMAC-SHA256 (keyed): Used when a secret key is provided, for backward
compatibility with older container images that perform HMAC-based checks.
"""

from __future__ import absolute_import
import hmac
import hashlib
import os
import secrets
from pathlib import Path

from sagemaker.core.remote_function.core.serialization import _MetaData

SAGEMAKER_SERVE_SECRET_KEY = "SAGEMAKER_SERVE_SECRET_KEY"


def generate_secret_key(nbytes: int = 32) -> str:
"""Generate a cryptographically secure secret key.

Args:
nbytes: Number of random bytes (the returned hex string will be
twice this length). Defaults to 32 (256-bit key).

Returns:
A hex-encoded random string suitable for use as an HMAC key.
"""
return secrets.token_hex(nbytes)


def compute_hash(buffer: bytes, secret_key: str = None) -> str:
"""Compute hash of the given buffer.

def compute_hash(buffer: bytes) -> str:
"""Compute SHA-256 hash of the given buffer."""
When *secret_key* is provided the hash is an HMAC-SHA256 keyed digest;
otherwise a plain SHA-256 digest is returned.

Args:
buffer: The bytes to hash.
secret_key: Optional HMAC key. When ``None`` (default) a plain
SHA-256 hash is computed.

Returns:
Hex-encoded hash string.
"""
if secret_key:
return hmac.new(secret_key.encode(), msg=buffer, digestmod=hashlib.sha256).hexdigest()
return hashlib.sha256(buffer).hexdigest()


def perform_integrity_check(buffer: bytes, metadata_path: Path):
"""Validates the integrity of bytes by comparing the hash value."""
actual_hash_value = compute_hash(buffer=buffer)
def perform_integrity_check(buffer: bytes, metadata_path: Path, secret_key: str = None):
"""Validates the integrity of bytes by comparing the hash value.

Computes both the plain SHA-256 digest and (when a secret key is
available) the HMAC-SHA256 digest, then checks whether the expected
hash stored in *metadata_path* matches either one. This provides
backward compatibility between SDK versions that write plain hashes
and container images that expect HMAC hashes (or vice-versa).

Args:
buffer: The serialized bytes to verify.
metadata_path: Path to the ``metadata.json`` file containing the
expected hash.
secret_key: Optional HMAC key. When ``None`` the function falls
back to the ``SAGEMAKER_SERVE_SECRET_KEY`` environment variable.
"""
if not Path.exists(metadata_path):
raise ValueError("Path to metadata.json does not exist")

with open(str(metadata_path), "rb") as md:
expected_hash_value = _MetaData.from_json(md.read()).sha256_hash

if not hmac.compare_digest(expected_hash_value, actual_hash_value):
raise ValueError("Integrity check for the serialized function or data failed.")
# Resolve secret key: explicit arg > environment variable > None
effective_secret_key = secret_key or os.environ.get(SAGEMAKER_SERVE_SECRET_KEY)

# Compute candidate digests
plain_hash = hashlib.sha256(buffer).hexdigest()

if hmac.compare_digest(expected_hash_value, plain_hash):
return

if effective_secret_key:
hmac_hash = hmac.new(
effective_secret_key.encode(), msg=buffer, digestmod=hashlib.sha256
).hexdigest()
if hmac.compare_digest(expected_hash_value, hmac_hash):
return

raise ValueError("Integrity check for the serialized function or data failed.")
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions sagemaker-serve/src/sagemaker/serve/model_builder_servers.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -751,6 +751,12 @@ def _build_for_smd(self) -> Model:
inference_spec=self.inference_spec,
)

# Propagate secret key to container environment
if self.secret_key:
self.env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = self.secret_key
else:
self.env_vars.pop("SAGEMAKER_SERVE_SECRET_KEY", None)

# Prepare deployment artifacts
if self.mode in LOCAL_MODES:
self._prepare_for_mode()
Expand Down
16 changes: 14 additions & 2 deletions sagemaker-serve/src/sagemaker/serve/model_server/smd/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,10 +13,15 @@
from sagemaker.serve.detector.dependency_manager import capture_dependencies
from sagemaker.serve.validations.check_integrity import (
compute_hash,
generate_secret_key,
)
from sagemaker.core.remote_function.core.serialization import _MetaData
from sagemaker.serve.spec.inference_base import CustomOrchestrator, AsyncCustomOrchestrator

import logging

logger = logging.getLogger(__name__)


def prepare_for_smd(
model_path: str,
Expand All@@ -34,7 +39,9 @@ def prepare_for_smd(
(default is None)

Returns:
( str ) :
str: A generated secret key used to compute the HMAC hash stored in
metadata.json. Callers should propagate this value to the container
environment as SAGEMAKER_SERVE_SECRET_KEY.

"""
model_path = Path(model_path)
Expand DownExpand Up@@ -63,8 +70,13 @@ def prepare_for_smd(

capture_dependencies(dependencies=dependencies, work_dir=code_dir)

secret_key = generate_secret_key()
logger.debug("Generated secret key for SMD artifact integrity check.")

with open(str(code_dir.joinpath("serve.pkl")), "rb") as f:
buffer = f.read()
hash_value = compute_hash(buffer=buffer)
hash_value = compute_hash(buffer=buffer, secret_key=secret_key)
with open(str(code_dir.joinpath("metadata.json")), "wb") as metadata:
metadata.write(_MetaData(hash_value).to_json())

return secret_key
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,4 +55,6 @@ def _upload_smd_artifacts(
"SAGEMAKER_REGION": sagemaker_session.boto_region_name,
"LOCAL_PYTHON": platform.python_version(),
}
if secret_key:
env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = secret_key
return s3_upload_path, env_vars
Original file line numberDiff line numberDiff line change
@@ -1,27 +1,91 @@
"""Validates the integrity of pickled file with SHA-256 hash."""
"""Validates the integrity of pickled file with SHA-256 hash.

Supports two modes:
- Plain SHA-256 (default): Used when no secret key is provided.
- HMAC-SHA256 (keyed): Used when a secret key is provided, for backward
compatibility with older container images that perform HMAC-based checks.
"""

from __future__ import absolute_import
import hmac
import hashlib
import os
import secrets
from pathlib import Path

from sagemaker.core.remote_function.core.serialization import _MetaData

SAGEMAKER_SERVE_SECRET_KEY = "SAGEMAKER_SERVE_SECRET_KEY"


def generate_secret_key(nbytes: int = 32) -> str:
"""Generate a cryptographically secure secret key.

Args:
nbytes: Number of random bytes (the returned hex string will be
twice this length). Defaults to 32 (256-bit key).

Returns:
A hex-encoded random string suitable for use as an HMAC key.
"""
return secrets.token_hex(nbytes)


def compute_hash(buffer: bytes, secret_key: str = None) -> str:
"""Compute hash of the given buffer.

def compute_hash(buffer: bytes) -> str:
"""Compute SHA-256 hash of the given buffer."""
When *secret_key* is provided the hash is an HMAC-SHA256 keyed digest;
otherwise a plain SHA-256 digest is returned.

Args:
buffer: The bytes to hash.
secret_key: Optional HMAC key. When ``None`` (default) a plain
SHA-256 hash is computed.

Returns:
Hex-encoded hash string.
"""
if secret_key:
return hmac.new(secret_key.encode(), msg=buffer, digestmod=hashlib.sha256).hexdigest()
return hashlib.sha256(buffer).hexdigest()


def perform_integrity_check(buffer: bytes, metadata_path: Path):
"""Validates the integrity of bytes by comparing the hash value."""
actual_hash_value = compute_hash(buffer=buffer)
def perform_integrity_check(buffer: bytes, metadata_path: Path, secret_key: str = None):
"""Validates the integrity of bytes by comparing the hash value.

Computes both the plain SHA-256 digest and (when a secret key is
available) the HMAC-SHA256 digest, then checks whether the expected
hash stored in *metadata_path* matches either one. This provides
backward compatibility between SDK versions that write plain hashes
and container images that expect HMAC hashes (or vice-versa).

Args:
buffer: The serialized bytes to verify.
metadata_path: Path to the ``metadata.json`` file containing the
expected hash.
secret_key: Optional HMAC key. When ``None`` the function falls
back to the ``SAGEMAKER_SERVE_SECRET_KEY`` environment variable.
"""
if not Path.exists(metadata_path):
raise ValueError("Path to metadata.json does not exist")

with open(str(metadata_path), "rb") as md:
expected_hash_value = _MetaData.from_json(md.read()).sha256_hash

if not hmac.compare_digest(expected_hash_value, actual_hash_value):
raise ValueError("Integrity check for the serialized function or data failed.")
# Resolve secret key: explicit arg > environment variable > None
effective_secret_key = secret_key or os.environ.get(SAGEMAKER_SERVE_SECRET_KEY)

# Compute candidate digests
plain_hash = hashlib.sha256(buffer).hexdigest()

if hmac.compare_digest(expected_hash_value, plain_hash):
return

if effective_secret_key:
hmac_hash = hmac.new(
effective_secret_key.encode(), msg=buffer, digestmod=hashlib.sha256
).hexdigest()
if hmac.compare_digest(expected_hash_value, hmac_hash):
return

raise ValueError("Integrity check for the serialized function or data failed.")
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions sagemaker-serve/src/sagemaker/serve/model_builder_servers.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -751,6 +751,12 @@ def _build_for_smd(self) -> Model:
inference_spec=self.inference_spec,
)

# Propagate secret key to container environment
if self.secret_key:
self.env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = self.secret_key
else:
self.env_vars.pop("SAGEMAKER_SERVE_SECRET_KEY", None)

# Prepare deployment artifacts
if self.mode in LOCAL_MODES:
self._prepare_for_mode()
Expand Down
16 changes: 14 additions & 2 deletions sagemaker-serve/src/sagemaker/serve/model_server/smd/prepare.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,10 +13,15 @@
from sagemaker.serve.detector.dependency_manager import capture_dependencies
from sagemaker.serve.validations.check_integrity import (
compute_hash,
generate_secret_key,
)
from sagemaker.core.remote_function.core.serialization import _MetaData
from sagemaker.serve.spec.inference_base import CustomOrchestrator, AsyncCustomOrchestrator

import logging

logger = logging.getLogger(__name__)


def prepare_for_smd(
model_path: str,
Expand All@@ -34,7 +39,9 @@ def prepare_for_smd(
(default is None)

Returns:
( str ) :
str: A generated secret key used to compute the HMAC hash stored in
metadata.json. Callers should propagate this value to the container
environment as SAGEMAKER_SERVE_SECRET_KEY.

"""
model_path = Path(model_path)
Expand DownExpand Up@@ -63,8 +70,13 @@ def prepare_for_smd(

capture_dependencies(dependencies=dependencies, work_dir=code_dir)

secret_key = generate_secret_key()
logger.debug("Generated secret key for SMD artifact integrity check.")

with open(str(code_dir.joinpath("serve.pkl")), "rb") as f:
buffer = f.read()
hash_value = compute_hash(buffer=buffer)
hash_value = compute_hash(buffer=buffer, secret_key=secret_key)
with open(str(code_dir.joinpath("metadata.json")), "wb") as metadata:
metadata.write(_MetaData(hash_value).to_json())

return secret_key
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,4 +55,6 @@ def _upload_smd_artifacts(
"SAGEMAKER_REGION": sagemaker_session.boto_region_name,
"LOCAL_PYTHON": platform.python_version(),
}
if secret_key:
env_vars["SAGEMAKER_SERVE_SECRET_KEY"] = secret_key
return s3_upload_path, env_vars
Original file line numberDiff line numberDiff line change
@@ -1,27 +1,91 @@
"""Validates the integrity of pickled file with SHA-256 hash."""
"""Validates the integrity of pickled file with SHA-256 hash.

Supports two modes:
- Plain SHA-256 (default): Used when no secret key is provided.
- HMAC-SHA256 (keyed): Used when a secret key is provided, for backward
compatibility with older container images that perform HMAC-based checks.
"""

from __future__ import absolute_import
import hmac
import hashlib
import os
import secrets
from pathlib import Path

from sagemaker.core.remote_function.core.serialization import _MetaData

SAGEMAKER_SERVE_SECRET_KEY = "SAGEMAKER_SERVE_SECRET_KEY"


def generate_secret_key(nbytes: int = 32) -> str:
"""Generate a cryptographically secure secret key.

Args:
nbytes: Number of random bytes (the returned hex string will be
twice this length). Defaults to 32 (256-bit key).

Returns:
A hex-encoded random string suitable for use as an HMAC key.
"""
return secrets.token_hex(nbytes)


def compute_hash(buffer: bytes, secret_key: str = None) -> str:
"""Compute hash of the given buffer.

def compute_hash(buffer: bytes) -> str:
"""Compute SHA-256 hash of the given buffer."""
When *secret_key* is provided the hash is an HMAC-SHA256 keyed digest;
otherwise a plain SHA-256 digest is returned.

Args:
buffer: The bytes to hash.
secret_key: Optional HMAC key. When ``None`` (default) a plain
SHA-256 hash is computed.

Returns:
Hex-encoded hash string.
"""
if secret_key:
return hmac.new(secret_key.encode(), msg=buffer, digestmod=hashlib.sha256).hexdigest()
return hashlib.sha256(buffer).hexdigest()


def perform_integrity_check(buffer: bytes, metadata_path: Path):
"""Validates the integrity of bytes by comparing the hash value."""
actual_hash_value = compute_hash(buffer=buffer)
def perform_integrity_check(buffer: bytes, metadata_path: Path, secret_key: str = None):
"""Validates the integrity of bytes by comparing the hash value.

Computes both the plain SHA-256 digest and (when a secret key is
available) the HMAC-SHA256 digest, then checks whether the expected
hash stored in *metadata_path* matches either one. This provides
backward compatibility between SDK versions that write plain hashes
and container images that expect HMAC hashes (or vice-versa).

Args:
buffer: The serialized bytes to verify.
metadata_path: Path to the ``metadata.json`` file containing the
expected hash.
secret_key: Optional HMAC key. When ``None`` the function falls
back to the ``SAGEMAKER_SERVE_SECRET_KEY`` environment variable.
"""
if not Path.exists(metadata_path):
raise ValueError("Path to metadata.json does not exist")

with open(str(metadata_path), "rb") as md:
expected_hash_value = _MetaData.from_json(md.read()).sha256_hash

if not hmac.compare_digest(expected_hash_value, actual_hash_value):
raise ValueError("Integrity check for the serialized function or data failed.")
# Resolve secret key: explicit arg > environment variable > None
effective_secret_key = secret_key or os.environ.get(SAGEMAKER_SERVE_SECRET_KEY)

# Compute candidate digests
plain_hash = hashlib.sha256(buffer).hexdigest()

if hmac.compare_digest(expected_hash_value, plain_hash):
return

if effective_secret_key:
hmac_hash = hmac.new(
effective_secret_key.encode(), msg=buffer, digestmod=hashlib.sha256
).hexdigest()
if hmac.compare_digest(expected_hash_value, hmac_hash):
return

raise ValueError("Integrity check for the serialized function or data failed.")
Loading