- ds_trace.py: resolve() user-provided save path and use Path.name for filenames
to prevent directory traversal in the local workspace save UI
- rl/finetune UI data_loaders: nosec B614 where paths are already validated
against safe_root via realpath() before use
- Temp paths (/tmp/sample, /tmp/full, /tmp/mock/*, /tmp/predix_loop.pid,
/tmp/autorl_output): nosec B108 — fixed Docker volume mount points or
single-process admin files, not user-writable attack surface
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- B301 (pickle): add nosec B301 to pd.read_pickle calls in Kaggle templates
— files are trusted Kaggle-environment inputs, not user-supplied
- B614 (torch.load): add weights_only=True to all torch.load calls in
model benchmark GT code and gt_code.py
- B104 (binding 0.0.0.0): change run_server and CLI default to 127.0.0.1;
add nosec comment where all-interface binding is required for Docker
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Add _safe_resolve_path() helper function for path validation
- Centralizes path security logic for reuse across codebase
- Comprehensive validation: null bytes, drive letters, absolute paths, path traversal
- Uses relative_to() check to prevent path traversal attacks
- Refactor resolve_model_path() to use the new helper function
Fixes CodeQL alert #10: Uncontrolled data used in path expression
The new helper function makes the security check more explicit,
which helps CodeQL recognize the path validation.
- Translate resolve_model_path() docstring from Chinese to English
- Add detailed security documentation for path validation steps
- Follows project language policy (English-only documentation)
- Translate resolve_model_path() docstring from Chinese to English
- Add detailed security validation steps documentation
- Follows project language policy (all comments in English)
No functional changes - documentation only.
- Add comment explaining torch >=2.8.0 is already safe (CVE fixed in >=2.7.1)
- Dependabot alert #33 is false positive due to missing lockfile
- No version change needed - current specification is already secure
Security Status:
- CVE-2025-2953: Fixed in torch >=2.7.1, current spec >=2.8.0 ✓
- Affects: torch.mkldnn_max_pool2d function
- Impact: Local DoS via improper resource shutdown
- Attack vector: Local (requires local access)
Note: Without a lockfile (pip-tools/uv/poetry), Dependabot cannot determine
the installed version and raises alerts based on the requirement spec alone.
- Document CVE-2025-6638 (ReDoS in MarianTokenizer.remove_language_code)
- Already fixed by transformers>=4.53.0 (patched in 4.53.0)
- Dependabot alert is false positive due to missing lockfile
Fixes Dependabot Alert #41
- Add comment explaining transformers >=4.53.0 is already safe (CVE fixed in >=4.52.1)
- Dependabot alert #37 is false positive due to missing lockfile
- No version change needed - current specification is already secure
Security Status:
- CVE-2025-3777: Fixed in transformers >=4.52.1, current spec >=4.53.0 ✓
- Affects: image_utils.py URL validation via startswith() bypass
- Impact: URL username injection allowing malicious domain redirection
Note: Without a lockfile (pip-tools/uv/poetry), Dependabot cannot determine
the installed version and raises alerts based on the requirement spec alone.
- Add comment explaining transformers >=4.53.0 is already safe (CVE fixed in >=4.50.0)
- Dependabot alert #31 is false positive due to missing lockfile
- No version change needed - current specification is already secure
Security Status:
- CVE-2025-1194: Fixed in transformers >=4.50.0, current spec >=4.53.0 ✓
- Affects: SubWordJapaneseTokenizer in GPT-NeoX-Japanese model
- Impact: ReDoS via crafted input causing exponential regex backtracking
Note: Without a lockfile (pip-tools/uv/poetry), Dependabot cannot determine
the installed version and raises alerts based on the requirement spec alone.
- Upgrade torch from >=2.6.0 to >=2.8.0
- Fixes CVE-2025-3730: DoS in torch.nn.functional.ctc_loss
- Vulnerability in LossCTC.cpp leads to denial of service
- Local attack with low complexity, requires low privileges
- Also fixes CVE-2025-32434 (torch.load RCE)
Fixes Dependabot Alert #34
- Add comment explaining transformers >=4.53.0 is already safe (CVE fixed in >=4.51.0)
- Dependabot alert #35 is false positive due to missing lockfile
- No version change needed - current specification is already secure
Security Status:
- CVE-2025-3263: Fixed in transformers >=4.51.0, current spec >=4.53.0 ✓
- CVE-2024-11393: Fixed in current version ✓
- CVE-2025-3264/3933/2099/6051: Fixed in current version ✓
Note: Without a lockfile (pip-tools/uv/poetry), Dependabot cannot determine
the installed version and raises alerts based on the requirement spec alone.
- Upgrade transformers from >=4.52.1 to >=4.53.0
- Fixes CVE-2025-6051: ReDoS in EnglishNormalizer.normalize_numbers()
- Crafted numeric strings can cause excessive CPU consumption
- Affects text-to-speech and number normalization tasks
Fixes Dependabot Alert #42
- Document CVE-2025-2099 (ReDoS in preprocess_string function)
- Already fixed by transformers>=4.51.0 (patched in 4.50.0)
- Dependabot alert is false positive due to missing lockfile
Fixes Dependabot Alert #32
- Add explicit Werkzeug>=3.1.6 to override webshop's transitive dep (2.2.3)
- Upgrade Flask to >=3.1.0 for Werkzeug 3.x compatibility
- Add installation note: install webshop FIRST, then upgrade Werkzeug/Flask
Security Fixes (Werkzeug 3.1.6):
- CVE-2026-27199: Windows device names in safe_join() (DoS via hanging reads)
- CVE-2025-66221: Windows device names in safe_join() (fixed in 3.1.4)
- CVE-2024-49766: safe_join UNC path bypass on Windows (fixed in 3.0.6)
- CVE-2024-34069: Werkzeug debugger RCE (fixed in 3.0.3+)
Technical Note:
- webshop 0.1.0 depends on Werkzeug==2.2.3 (vulnerable)
- Direct dependency Werkzeug>=3.1.6 overrides transitive dep at install time
- pip installs dependencies in order, last version wins
Fixes Dependabot Alert #7 (GHSA-29vq-49wr-vm6x)
- Update Werkzeug from ==2.3.8 to >=3.1.6
- Update Flask from ==2.2.5 to >=3.0.0
- Fixes GHSA-hgf8-39gv-g3f2 (Windows device names in safe_join)
- Also fixes CVE-2024-34069 and CVE-2024-49767
- Update Werkzeug comment to include resource exhaustion vulnerability
- Version 2.3.8 is latest secure 2.x version (Flask 3.x incompatible with WebShop)
- Document mitigation: max_content_length limits, no debug mode in production
Fixes Dependabot Alert #4 (GHSA-q34m-jh98-gwm2)
- Add comment explaining vLLM >=0.18.0 is already safe (CVE fixed in >=0.14.0)
- Dependabot alert #44 is false positive due to missing lockfile
- Translate all comments to English (project language policy)
- No version change needed - current specification is already secure
Security Status:
- CVE-2026-22807: Fixed in vLLM >=0.14.0, current spec >=0.18.0 ✓
- CVE-2026-22778: Fixed in current version ✓
- CVE-2026-27893: Fixed in current version ✓
Note: Without a lockfile (pip-tools/uv/poetry), Dependabot cannot determine
the installed version and raises alerts based on the requirement spec alone.
- Bump minimum version from 2.0.0 to 2.6.0
- Fixes CVE-2025-32434: RCE vulnerability in torch.load with weights_only=True
- Fixes CVE-2024-31580: Heap buffer overflow (DoS) in vararg_functions.cpp
- Dependabot alerts #40 and #26
- Upgrade Werkzeug from 2.2.3 to 2.3.8 in WebShop requirements
- Translate all comments to English (project language policy)
- Add security note for CVE-2024-34069 (debugger vulnerability)
- Document mitigation: debug mode disabled in production
Security Notes:
- CVE-2024-34069 affects Werkzeug debugger (dev mode only)
- Flask 3.x required for full fix, but incompatible with WebShop
- Mitigation: Benchmark runs locally, never with debug=True in production
- This is the latest secure version compatible with Flask 2.x
Fixes Dependabot Alert #2 (GHSA-2g68-c3qc-8985)
* feat: rdkit for chemcotbench
* update qwen2.5&llama3.1 context
* fix: force failure on validation error and remove try/except in validator
* feat: unified error sample extraction (with test scripts)
* feat: set conda cache with .env
* feat: skip data eval if data pass in last evo
* fix: rm redundant param
* fix ui bug
* refactor: centralize assign_code_list_to_evo in MultiProcessEvolvingStrategy
* feat: add test_params.yaml generation and workspace cleanup improvements for finetune
* refactor: replace get_clear_ws_cmd with clear_workspace and update prompts for hard check criteria
* add bioprobench dataset
* fix: handle commas in training config extraction and refactor prompt includes
* bioprobench description
* add bioprobench readme
* feat: merge lora adapter for blackwell gpu
* feat: support for multi benchmarks in one job
* change dfficult aware content for training
* update difficulty-aware and logging principles
* fix: resolve variable name conflict in FTRunnerEvaluator
* set job id accuracy to minute
* feat(ui): display one selected metric per benchmark
* feat: store sota exp, and fix ws_ckp bug
* fix: truncate data.json in feedback
* fix: opencompass data for conda env
* fix: save only the last model
* feat: set log path and ws path
* fix: set overwrite_cache to avoid lock contention(through injecting params)
* feat: redirect stdout to file in localenv
* add pickle cache to dataset desc
* fix CI
* fix: remove redundant wrapper
* feat: set python_unbuffered
* move redirect stdout to env run
* fix a small bug
* move model folder
* feat(ui): display benchmark baseline
* fix: enrich scenario and benchmark description
* fix: rewrite runner eval to accept easier
* feat: compare with baseline when no SOTA
* update tablebench readme
* fix: switch back to single benchmark (for baseline)
* feat(ui): add ws path in ui
* refactor: update SOTA tracking to use DAG traversal and parent selection
* fix: prioritize local_selection in trace and refactor sibling retrieval logic
* refactor: unify error handling in feedback generation and update workspace injection
* feat: add skip_loop_error_stepname to control error skip step in LoopBase
* fix: set local_selection to NEW_ROOT for experiments without parent
* feat: set different ports for jobs
* feat: set different ports for jobs
* feat: add upper data size limit for LLM fine-tuning and update related prompts
* fix: replace get_truncated_stdout() with stdout for consistent output handling
* refactor: remove data.json from cache and workspace logic, focus on script-based reuse
* fix: rm target_scenario
* feat: add selective cache extraction and custom cache key for data processing
* fix(ui): bug when displaying tablebench
* fix: filter config in dataset_info.json
* feat: add test set, set valid set
* feat(ui): update test score, and set color for final decision
* feat: add test score for baseline and update ui
* fix: use [-100:] as test range
* feat: update data_stats in runner
* feat: wait for opencompass init when run multi jobs
* fix: adjust test&valid split
* feat: force to generate COT(with <think> token), and add answer format in scenarios.json
* feat: improve ui
* fix: unify benchmark volume mounts and set extra_volumes for conda env
* fix(ui): number color
* fix: update GPU memory handling to use total memory in GB and streamline code
* fix: set use_cot_postprocessor
* feat: add env_dict to config classes and merge env vars in Env run
* fix: let coder obey proposal
* fix(ui): direction bug and update chemcot core metirc
* fix: set consistent benchmark mount points and env vars for docker and conda
* fix: addintional target for LoRA
* feat: workspace dir log for benchmark running
* fix: tableInstruct path bug and update benchmark description
* feat: timeout for whole job
* fix: align FinanceIQ import to opencompass
* feat: use llm_judge for FinanceIQ
* feat: switch to turn on <think> or not
* feat: using scripts to redirect stdout, and run in different windows
* feat: sync litellm log
* fix: gpu memory format
* fix: escape special characters in benchmark desc
* fix: set data processing timeout to 1h
* feat: set valid_loss and save_best_model
* fix: inject timeout and stage
* fix: loss history extract logic
* feat: inject output dir
* feat: inject eval batch size
* feat: inject save_total_limit
* feat: update data prompt
* fix: escape shell special characters
* fix: tablebench visualization UI
* fix: move implementation validation to coder, and ignore injected params
* docs: add README for RL-PostTraining evaluation system
* Add AutoRL-Bench evaluation framework for RL post-training
* Add architecture documentation
* docs: update architecture and interface documentation for AutoRL-Bench
* improve doc
* fix
* refactor: YAML配置驱动
* feat: add RL Docker env, workspace test, and update project structure
* feat: 重命名 autorl_bench, 新增 RLWorkspace, 配置 Docker extra_volumes
* Add eval-only AutoRL-Bench pipeline
* sturcture clean
* docs: add autorl_bench README
* feat(rl): Implement RL post-training agent scaffold and example
* refactor: simplify RL scenario classes and update RL CoSTEER integration
* feat(rl): 调通 scaffold,mock 数据跑完 5 步循环
* feat(rl): 接入 LLM 生成代码,支持 model_path 传递
* feat(rl): Docker 执行框架,RLWorkspace.run() + RLPostTrainingRunner
* feat(rl): LLM 生成假设/反馈,完整 loop 跑通
* feat: add RL post-training entry point with configurable options
* refactor: simplify RL proposal and trace classes, update config and docs
* Update rl eval autorl_bench layout
* Update RL workflow and evaluation setup
* Integrate AutoRL-Bench evaluation in RL workflow
* feat(rl): 添加 --base-model/--benchmark CLI 参数,简化 RLTask
* feat(rl): Docker 环境动态选择 + example_agent 完整训练评测流程(无llm)
* fix(rl): 修复 feedback 传递 + 添加 verl 依赖
* refactor: remove unused validate in BenchmarkAdapter and add core utils module
* feat(rl): UI
* Refactor autorl_bench layout and docker entrypoint
* autorl_bench: add aider autoloop tool
* feat(rl): environment docker
* refactor: simplify aider autoloop tooling
* chore: update misc files
* feat(rl): yaml-driven dataset download & auto-download on startup
* feat(rl): yaml-driven dataset download & auto-download on startup
* Refactor RL eval runner and clean up
* Simplify RL eval runner and env
* rl: include litellm in RL docker image
* feat(rl): unified resource path & model repo_id structure
* feat(rl): refactor eval with OpenCompass & add training code template
* feat(rl): refactor eval with OpenCompass & add training code template
* feat(rl): delete test bench
* docs: add benchmark interface notes and TODOs for unified evaluation
* feat(rl): unified benchmark eval interface + shared configs
* feat(rl): 优雅
* feat(rl): prompt prososal+coder improve
* feat(rl): fix eval
* fix(rl): docker
* fix(rl): eval
* v 1.0 tmep
* benchmark v1.0
* benchmark v1.1
* benchmark v1.1: grading日志+代码去重
* benchmark v1.1: grading日志+代码去重
* benchmark v1.1: grading日志+代码去重+task description
* benchmark v1.2: fix
* benchmark v1.3: fix,example-agent ok,rdagent test,openhands develop
* benchmark v1.4: fix,example-agent ok,rdagent ok,openhands develop
* benchmark : add alfworld
* benchmark : update readme
* benchmark : update readme
* benchmark :
* chore: add eval bypass block and mark TODO in grading server
* benchmark
* benchmark
* benchmark
* benchmark
* alfworld
* alfworld
* benchmark
* rdagent
* rdagent
* benchmark
* benchmark:ui
* benchmark:delete docker + log
* 1
* alfworld
* ui
* alfworld
* readme
* alfworld
* parallex
* alfworld
* run
* eval gpu
* alfworld
* alfworld
* fix conda init in start.sh for non-interactive shells
Fallback to common miniconda paths when conda is not in PATH.
Fixes B200 pod startup failure (conda: command not found).
Made-with: Cursor
* simplify start.sh: read TRAINING_PYTHON from .env
No more conda detection logic. Just set TRAINING_PYTHON in .env.
Fallback to conda only if not set.
Made-with: Cursor
* use OPENHANDS_PYTHON from .env to run agent
start.sh now uses OPENHANDS_PYTHON for main.py execution,
since the parent process may be in a different conda env.
Made-with: Cursor
* feat: register OpenCode agent into autorl_bench framework
- Add agents/opencode/ with config.yaml, start.sh, README.md
- Include opencode-rl pipeline code (pipeline/, runner_fsm/, benchmarks/)
- Merge opencode-rl dependencies into autorl_bench requirements.txt
- Remove separate venv requirement, share main environment
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Update opencode agent, benchmarks, and eval configs
- Sync opencode-rl runner_fsm with latest simplifications
- Add smith benchmarks integration
- Update opencompass configs and server with GPU support + error handling
* Update OpenCode agent docs for external opencode-rl integration
- Document external repo architecture (opencode-rl as independent plugin)
- Add setup instructions for cloning and configuring opencode-rl
- Add architecture diagram showing RD-Agent ↔ opencode-rl interaction
- Document OPENCODE_RL_ROOT for custom paths
* feat: add smith benchmark discovery and per-sample evaluator
- Add smith/ module for dynamic benchmark discovery from rl-smith
- Add PerSampleEvaluator for per-sample scoring via vLLM
- Update utils.py to support script-based data download for smith benchmarks
- Update opencode agent config
* enforce RL-only in instructions.md; remove embedded opencode-rl
- instructions.md: prohibit SFT, require RL (GRPO/PPO) for all benchmarks
- remove agents/opencode/opencode-rl/ (runtime uses external OPENCODE_RL_ROOT)
Made-with: Cursor
* comment out OpenCode-only deps in requirements.txt
openai, httpx, python-dotenv, tenacity are for OpenCode agent's
separate environment. Keep peft and pydantic as shared deps.
Made-with: Cursor
* refactor: extract _kill_process_group, narrow exception catches
- run.py: replace 2x nested 3-level try/except with shared
_kill_process_group() using loop + specific exceptions
- server.py: except Exception → except (RuntimeError, ValueError, OSError)
- utils.py: except Exception → except requests.ConnectionError
Made-with: Cursor
* move kill_process_group to core/utils for reuse
Extract from run.py into core/utils.py so other runners
can also use it. Exported via core/__init__.py.
Made-with: Cursor
* add comments to run.py for workspace isolation and signal handling
Made-with: Cursor
* remove OpenCode-only deps from requirements.txt entirely
Made-with: Cursor
* allow SFT in instructions, RL as ultimate goal
Made-with: Cursor
* add workspace isolation rules to instructions.md
Use relative paths, forbid cd outside workspace, ignore symlink targets.
Made-with: Cursor
* update opencode start.sh: use OPENCODE_PYTHON, add PATH for opencode CLI, remove unsupported args
Made-with: Cursor
* opencode start.sh: pass --run-dir to use AutoRL-Bench workspace
Ensures OpenCode-FSM-Runner writes outputs into the workspace prepared
by AutoRL-Bench instead of creating its own runs/ directory.
Made-with: Cursor
* opencode start.sh: prepend training env bin to PATH
Ensures LLM agent bash calls (e.g. python3 -c "from trl import ...")
resolve to the correct training environment, instead of relying on
parent shell conda activation.
Made-with: Cursor
* opencode start.sh: restore --max-retries and --eval-timeout for opencode-rl
Made-with: Cursor
* add humaneval benchmark
* Replace import * cleanup hack with explicit imports in OpenCompass config
- Resolve dataset variable names via importlib before generating config,
so the template uses `from xxx import datasets` instead of `import *`
- Remove the fragile runtime cleanup hack that set leaked modules to None
- Increase OpenCompass timeout from 3600s to 7200s
- Fix score parsing to average across multiple subdatasets
* refine opencompass config file generating
* add humaneval benchmark dependency instructions
human-eval package requires clone from open-compass/human-eval with
a one-line patch to relax assertion for partial evaluation (test split only).
Made-with: Cursor
* fix: sanitize user-provided paths in RL UI (CodeQL)
* fix: resolve user path relative to safe root (CodeQL)
* fix: use Copilot-suggested path sanitization pattern (CodeQL)
* fix: normalize and reject absolute user paths (CodeQL)
* Fix training params, vLLM OOM cleanup, OpenCompass score parsing, and baseline cache logic
* fix: add setuptools<75 to requirements for opencompass pkg_resources dependency
uv venv does not include setuptools by default, causing OpenCompass baseline
evaluation to fail with "No module named 'pkg_resources'".
Made-with: Cursor
* webshop
* feat(autorl_bench): improve smith benchmark integration and evaluator robustness
- Add smith benchmark docs to README: usage examples, discovery mechanism, SMITH_BENCH_DIR
- Improve PerSampleEvaluator: vLLM GPU cleanup, test_range slicing
- Refactor server.py: extract grading server from utils
- Fix OpenCompass score parsing and baseline cache logic
* fix: add smart fallback for OpenCompass dataset variable resolution
When build_dataset_imports_explicit() fails to import an OpenCompass
dataset module (common in grading server subprocess), it now guesses
the correct variable name from the module path convention instead of
falling back to empty names (which causes import * and breaks BBH
due to leaked file handle objects).
* revert: restore opencompass.py to pre-modification state
Revert vLLM pid cleanup, dash-value checks, and metric-based
score parsing added in 31caff2f and bb32e555.
* keep metric-aware score parsing in opencompass; add baseline column to UI
- opencompass.py: retain metric-type filtering (accuracy/score) instead
of naive averaging, avoids polluting scores with pass/timeout counters
- ui.py: add Baseline column to Agent Summary table
Made-with: Cursor
* fix: handle non-string answers in extract_answer to prevent TypeError
arc_agi and other benchmarks can have non-string answer fields (e.g. lists),
which caused a crash in re.search(). Adding str() coercion fixes this.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* update deepsearch qa tasks
* fix: benchmark evaluation reliability (B1-B4)
- B1: auto-detect LoRA adapters and enable vLLM LoRA mode (read base_model from adapter_config.json)
- B2: serialize evaluations with threading.Lock to prevent GPU contention
- B3: cache eval results by model_path to deduplicate concurrent submissions
- B4: propagate error details from OpenCompass to agent (non-numeric scores, load failures)
Made-with: Cursor
* fix(B1): reject LoRA adapter submissions with clear merge instructions
- opencompass.py: detect adapter_config.json and return error with
merge_and_unload() instructions instead of broken vLLM LoRA mode
- instructions.md: add requirement to submit full merged models
- opencompass_template.yaml: remove unused is_lora/lora_path params
Made-with: Cursor
* update chat completion
* update
* update deepsearch
* md
* codex + benchmark update
* codex + benchmark update
* codex + benchmark update
* codex
* codex
* fix: grading server cache key includes mtime to detect model overwrites
Previously cache used only resolved_path, so overwritten models at the
same path returned stale scores. Now cache key = path@max_mtime so
re-evaluation is triggered when model files change.
Made-with: Cursor
* feat: add gemini/claude agent scaffolds, fix codex binary path
- codex/start.sh: use CODEX_BIN env var instead of bare 'codex'
- Add gemini/ and claude/ agent directories with config.yaml and start.sh
Made-with: Cursor
* chore: remove copied human_readable_trace.py from PostTrainBench
Made-with: Cursor
* update evaluation
* benchmark
* Fix log cleanup and OpenHands env
* fix: webshop env pth problem
* benchmark alpacaeval
* style(rl): apply auto-lint fixes
* fix(rl): address CI and CodeQL issues
* fix(rl): make autorl bench imports CI-safe
---------
Co-authored-by: Qizheng Li <jenssenlee@163.com>
Co-authored-by: Young <afe.young@gmail.com>
Co-authored-by: Bowen Xian <xianbowen@outlook.com>
Co-authored-by: chelsea97 <zhuowbrown@gmail.com>
Co-authored-by: Xu Yang <peteryang@vip.qq.com>
Co-authored-by: sakura657 <yctangcse@gmail.com>
Co-authored-by: shatianming5 <tianming.sha@stonybrook.edu>
Co-authored-by: Yeyuqing0913 <shatianming4@gmail.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>