- strategy_orchestrator.py: remove unreachable dead 'if not factor_values' after early return
- strategy_orchestrator.py: eliminate duplicate OHLVC load in evaluate_strategy
- env.py: escape single-quotes in Docker entry to prevent shell injection (CWE-78)
- env.py: replace mutable default args with None pattern in DockerEnv subclasses
- factor_runner.py: move pandarallel.initialize() from import-time to lazy init
- quant.py: guard against empty orch_factors, move strategy_name before try block
- quant_proposal.py: fix __init__ return type Tuple[dict,bool] -> None
- strategy_orchestrator.py: remove dead rdagent_logger import shadowed by getLogger
- factor.py: replace unusual 'not x is None' with idiomatic 'x is not None'
- workflow/loop.py: withdraw_loop(0) raises RuntimeError instead of looking for folder -1
- workflow/tracking.py: replace crash-prone AssertionError with logger.warning + skip
- factor_from_report.py: fix misleading comment about loop_n/step_n dual use
- Path injection (B614): centralized safe_resolve_path in core/utils.py,
refactored 6 UI modules to use it with safe_root validation
- B701: added explicit autoescape=select_autoescape() to Jinja2
Environment() calls in 3 files
- B101: replaced assert statements with proper if/raise patterns in
12+ files (partial)
- B112: added logger.warning() to bare except:continue blocks in
5 files
Converted conda commands in _update_bin_path, _sync_conda_cache_with_real_envs,
_prepare_conda_env, and FTCondaEnv.prepare() to list args. Replaced pipe-based
grep with pure Python parsing. LocalEnv.Popen retains shell=True with nosec
since entry is an internal command string set by LocalEnvConf, not user input.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- factor.py: check_output([python_bin, path]) instead of shell string
- env.py QlibCondaEnv: all four conda commands use list args
Shell=True with a constructed string allows shell injection if
python_bin or path contain shell metacharacters.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Two bugs that together caused an infinite SKIP loop after LoopResumeError:
1. loop.py _run_step: set step_forward=False in the `else: raise` branch so that
when LoopResumeError propagates from _propose (LLMUnavailableError), step_idx
stays at 0. Previously it advanced to 1, leaving loops permanently stuck with
missing direct_exp_gen result on next resume.
2. base.py _create_chat_completion_auto_continue: when finish_reason=="length"
triggers a continuation retry, merge into the previous assistant message instead
of appending a second consecutive one. llama-server returns 400 on two consecutive
assistant messages, which caused LLMUnavailableError -> LoopResumeError cascade.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Fix py/path-injection (Alerts #25, #28, #29, #30 - High severity):
- Add optional safe_root parameter to get_valid_sessions() in both
finetune/llm/ui/data_loader.py and rl/ui/data_loader.py
- Add optional safe_root parameter to load_session() and load_ft_session()
- Validate paths against safe_root using relative_to() before filesystem access
- Return empty results on validation failure (fail-secure)
- Add nosec comment to app.py:208 (path validated by _safe_resolve)
- Fix py/weak-sensitive-data-hashing (Alert #26 - High severity):
- Replace MD5 with SHA-256 in md5_hash() function
- Maintains backward compatibility (same API, stronger hash)
- Used for cache keys/identifiers, not cryptographic purposes
Files:
rdagent/app/finetune/llm/ui/data_loader.py
rdagent/app/rl/ui/data_loader.py
rdagent/app/rl/ui/app.py
rdagent/utils/__init__.py
* update rdagent cmd
* fix log error message
* use multiProcessing.Process instead of subprocess.Popen
* add traces to gitignore
* add user interactor in RDLoop (finance scenarios)
* add interactor (feedback, hypothesis) for quant scens
* fix the test_end in qlib conf
* add features init config, general instruction to qlib scenarios
* set base features for based exp
* fix bug when combine factors
* move traces folder to git_ignore_folder
* fix bug in features init
* fix quant interact bug
* fix logger warning error
* bug fixes
* modify rdagent logger, now it can set file output
* adjust cli functions and fix logger bug
* fix server port transport problem
* update server_ui in cli
* add web code
* fix CI problem
* black fix
* update web ui README
* update README
* update readme
* refine prompt
* small update
* fix a small bug
* remove debug config after execution
* fix: only remove <think> at start
* feat: support creating dataset & multi-eval frame (#1302)
* feat: add iterative evolve and evaluation support with partial chain stop
* feat: add FTDataEvaluator and support multiple implement functions in finetune
* feat: data implement for pre-proposal and proposal and add datasets (#1303)
* feat:(1) support for multi layer dataset extraction (2) add category.json for dataset in datasets/
* fix: fix bug for generate category.json
* feat: add get_dataset_folder_desc
* init data proposal and merge qzli/ft
* update data proposal prompts and add max_position_embeddings and resolve confilcts
* remove sample counts in data proposal
* turn data and train to unified hypo_gen
* refine prompts
* remove category.json and add it to dataset_info
* fix jinja problem and proposal done
* lint
* add ai-generated description and raw readme into dataset_info.json
* update prompt for description
* add datasets
* initial fix for proposal of data
* final version for data proposal
* lint
* feat: add stats in dataset_info, and enable data coder (#1306)
* refactor(dataset): add stats into dataset_info.json, and remove dataset from gitignore_folder
* feat: enable data coder and run data process
* feat: Merge data coder (#1307)
* feat: implement finetune data coding, evaluation, and config improvements
* fix: deepspeed config path
* fix: dataset info columns
---------
Co-authored-by: Young <afe.young@gmail.com>
* replace str length with token_limit
* add readme to dataset_info and remove useless blank lines in scenario description
* feat: dataset prepare
* fix: extract prams script name
* feat: add loss&predictions samples to feedback
* remove duplicate envs and and add llm_api_preferences and enhance reasoning token limits
* feat: network for ft_env
* fix: remove gpt-4o, which has low quota
* feat: a simple ui
* feat: merge data and train task type (#1309)
* feat: filter redundant prams of lf
* fix: ui bug caused by removing task_type
* fix: force agent to use high concurrency, and remove redundant prompt
* feat: extract info from llama factory log, and check data exists before download
* fix: add compatibility rules
* feat: llm evaluator for data coder
* feat: openai package in ft docker, and refine prompt
* feat: refine ft ui, add more info
* feat: add raw logs
* refine data coder prompt(for feedback debug)
* feat: select dataset in scen init
* fix: ui for docker log seperately
* feat: sync log through blob
* improve ui, and add llm feedback in Runner&Exp2FB (#1312)
* fix: ui bug to visualize docker log, and lint
* feat: unified docker log for ft env, and some refactor
* fix bugs and improve ui
* feat: save log of evaluator(single feedback)
* feat: add evaluator, set cleanup docker log
* feat: call llm in RunnerEvaluator and Feedback
* fix: extract structured error message in RunnerEvaluator
* feat: feedback improve, and fix some bugs
* feat: feedback improve when runner fails
* small update
* feat(UI): add running info and benchmark metric in loop expander
* feat(UI): add render markdown toggle
* feat: refine prompts and add error type in exp2fb
* feat: add filterd params reason, set default benchmark timeout to infinite, and refine train loss express
* recover dataset deepscaler
* feat: set timeout in .env
* refactor: unifiied ft_env timeout
* feat: debug mode for data coder
* feat: deliver data_stats after generate debug_data
* feat: use gpt-5.1 as judge model, set judge_retry, and refine debug mode prompt
* refine prompt
* refactor: llama factory manager logic, and refine data processing prompt
* feat(DockerEnv): support GPU selection via CUDA_VISIBLE_DEVICES
* feat: set api concurrency via .env
* fix: ft env timeout bug
* feat: enable CondaEnv run
* fix: can't update bin path in first run, and path bug in lf manager
* feat(ui): set log path through .env
* refactor(ui): wrap_lines, remove css
* feat(coder): retry when parse code-block fail
* fix: refine single-fb in ui, and fix path bug(not allow proposal to decide path)
* fix: opencompass CondaEnv torch compatible with vllm
* fix: refine error text in coding
* feat: deepspeed config for CondaEnv
* feat: memory estimator
* fix: deepspeed package for condaenv
* fix: use `client.chat.completions.create()` only
* feat: flash attention for condaenv
* feat: strong and weak models interface
* fix: condaenv package dependency
* use multi round conversation in llm finetune proposal
* refine prompt for data processing
* enable evolving in data coder
* maximize output token size
* fix: refine ui
* fix: optional packages for llama factory
* fix: torch denpendency for b200
* fix: opencompass dependency
* update cot prompts
* skip the sub implement
* skip conda preparation if env exists
* update chemcot datasets
* fix: unify docker to use litellm
* update readme and instructions
* fix: set CUDA_VISIBLE_DEVICES for CondaEnv
* feat: add panorama dataset, refactor dataset interface
* feat: calculate token using tiktoken, and ndarray bug
* fix: download subtasks of chemcotdataset seperately
* feat: customized prepare func for datasets
* feat: update new benchmarks
* add datasets package
* docs: readme for llm finetune
* feat: download raw data directly, with post-process function
* feat: analyze raw dataset
* suppress litellm debug info
* feat(ui): summary page
* feat: run multi-jobs
* feat: improve ui
* feat: add path and checkout options to LLM finetune loop entrypoint
* feat: add FinanceIQ_ppl benchmark with auto-download and dataset desc rendering
* refactor: remove unused imports and dead code, fix session folder logging
* feat: enable tablebench and tableInstruct dataset
* refine dataset readme, and coder prompt
* refine proposal and coder prompt
* fix: ui path (default log path)
* feat: add automatic LoRA model merging for benchmarking with vLLM
* refactor: reorganize finetune benchmark and merge modules under benchmark dir
* refactor: modularize benchmark config and error extraction for finetune scenario
* fix: update benchmark import paths and disable env cache for device info
* refactor docke&conda env and fix import bugs
* modify init python file
* feat: add FinanceIQ dataset split utility and integrate with pipeline
* feat: set weak and strong model by env, distribute workload across models
* feat: sample dataset and rm params for tensorboard, wandb
* update script to run jobs
* refine proposal prompt, remove specific dataset name
* fix(ui): auto switch log folder
* fix: estimate the processed full data after sample
* feat: filter raw data more aggressively, and lower data_eval standard
* feat: sync workspace to blob
* feat: rdkit for chemcotbench
* update qwen2.5&llama3.1 context
* fix: force failure on validation error and remove try/except in validator
* feat: unified error sample extraction (with test scripts)
* feat: set conda cache with .env
* feat: skip data eval if data pass in last evo
* fix: rm redundant param
* fix ui bug
* refactor: centralize assign_code_list_to_evo in MultiProcessEvolvingStrategy
* feat: add test_params.yaml generation and workspace cleanup improvements for finetune
* refactor: replace get_clear_ws_cmd with clear_workspace and update prompts for hard check criteria
* add bioprobench dataset
* fix: handle commas in training config extraction and refactor prompt includes
* bioprobench description
* add bioprobench readme
* feat: merge lora adapter for blackwell gpu
* feat: support for multi benchmarks in one job
* change dfficult aware content for training
* update difficulty-aware and logging principles
* fix: resolve variable name conflict in FTRunnerEvaluator
* set job id accuracy to minute
* feat(ui): display one selected metric per benchmark
* feat: store sota exp, and fix ws_ckp bug
* fix: truncate data.json in feedback
* fix: opencompass data for conda env
* fix: save only the last model
* feat: set log path and ws path
* fix: set overwrite_cache to avoid lock contention(through injecting params)
* feat: redirect stdout to file in localenv
* add pickle cache to dataset desc
* fix CI
* fix: remove redundant wrapper
* feat: set python_unbuffered
* move redirect stdout to env run
* fix a small bug
* move model folder
* feat(ui): display benchmark baseline
* fix: enrich scenario and benchmark description
* fix: rewrite runner eval to accept easier
* feat: compare with baseline when no SOTA
* update tablebench readme
* fix: switch back to single benchmark (for baseline)
* feat(ui): add ws path in ui
* refactor: update SOTA tracking to use DAG traversal and parent selection
* fix: prioritize local_selection in trace and refactor sibling retrieval logic
* refactor: unify error handling in feedback generation and update workspace injection
* feat: add skip_loop_error_stepname to control error skip step in LoopBase
* fix: set local_selection to NEW_ROOT for experiments without parent
* feat: set different ports for jobs
* feat: set different ports for jobs
* feat: add upper data size limit for LLM fine-tuning and update related prompts
* fix: replace get_truncated_stdout() with stdout for consistent output handling
* refactor: remove data.json from cache and workspace logic, focus on script-based reuse
* fix: rm target_scenario
* feat: add selective cache extraction and custom cache key for data processing
* fix(ui): bug when displaying tablebench
* fix: filter config in dataset_info.json
* feat: add test set, set valid set
* feat(ui): update test score, and set color for final decision
* feat: add test score for baseline and update ui
* fix: use [-100:] as test range
* feat: update data_stats in runner
* feat: wait for opencompass init when run multi jobs
* fix: adjust test&valid split
* feat: force to generate COT(with <think> token), and add answer format in scenarios.json
* feat: improve ui
* fix: unify benchmark volume mounts and set extra_volumes for conda env
* fix(ui): number color
* fix: update GPU memory handling to use total memory in GB and streamline code
* fix: set use_cot_postprocessor
* feat: add env_dict to config classes and merge env vars in Env run
* fix: let coder obey proposal
* fix(ui): direction bug and update chemcot core metirc
* fix: set consistent benchmark mount points and env vars for docker and conda
* fix: addintional target for LoRA
* feat: workspace dir log for benchmark running
* fix: tableInstruct path bug and update benchmark description
* feat: timeout for whole job
* fix: align FinanceIQ import to opencompass
* feat: use llm_judge for FinanceIQ
* feat: switch to turn on <think> or not
* feat: using scripts to redirect stdout, and run in different windows
* feat: sync litellm log
* fix: gpu memory format
* fix: escape special characters in benchmark desc
* fix: set data processing timeout to 1h
* feat: set valid_loss and save_best_model
* fix: inject timeout and stage
* fix: loss history extract logic
* feat: inject output dir
* feat: inject eval batch size
* feat: inject save_total_limit
* feat: update data prompt
* fix: escape shell special characters
* fix: tablebench visualization UI
* fix: move implementation validation to coder, and ignore injected params
* feat: README for FinanceIQ dataset
* fix: bioprobench desc error
* fix: remove task alignment when coder eval
* fix: FinanceIQ now extracts last capital as answer
* fix: stdout contains binary data
* feat: recover estimate full output and set eval setting automatically
* fix(ui): precision for summary table
* fix(ui): import error
* feat: try to use lora
* fix(api): fix litellm bug for code block
* fix: refine prompts to give agent more decision space
* chore(ci): fix mypy typing issues
* chore(ci): format code with black
* chore(ci): fix ruff lint violations
* chore(ci): sort imports with isort
* chore(ci): format code with black
* test: temporarily skip extract_parameters imports due to numpy pin
* fix: compatibility issues for qlib scenarios on finetune branch
* fix(fin_factor): skip to fb for coder error
* fix(loop): default skip to feedback step on skip_loop_error
When skip_loop_error exception happens and skip_loop_error_stepname is not
explicitly set, default to jumping to 'feedback' step if it exists,
otherwise fall back to the last step (record).
This prevents KeyError when record step tries to access feedback data that
doesn't exist because we skipped the feedback phase.
Also removed redundant skip_loop_error_stepname from finetune loop since
it's now the default behavior.
* add 'skip to record' to DS scenario like other scenarios
* fix 2 scenarios bug about rd_loop class
* fix: lint(mypy, ruff, black) error
* fix: mypy lint error
* fix data science scenario bug
---------
Co-authored-by: Xu Yang <peteryang@vip.qq.com>
Co-authored-by: Qizheng Li <jenssenlee@163.com>
Co-authored-by: you-n-g <you-n-g@users.noreply.github.com>
Co-authored-by: amstrongzyf <201840057@smail.nju.edu.cn>
Co-authored-by: Young <afe.young@gmail.com>
Co-authored-by: amstrongzyf <amstrongzyf@126.com>
Co-authored-by: chelsea97 <zhuowbrown@gmail.com>
Co-authored-by: SunsetWolf <Lv.Linlang@hotmail.com>
* fix: prevent calendar index overflow when signal data ends early
* fix: make test_end optional to resolve Qlib backtest calendar misalignment
* fix: enhance GPU information output in get_gpu_info function
* fix: improve GPU information output in get_gpu_info function for better clarity
---------
Co-authored-by: Xu Yang <peteryang@vip.qq.com>
* refactor: use get_truncated_stdout for consistent stdout handling across modules
* lint
* feat: add dump_stdout_type to DSRunnerCoSTEERSettings and use in eval
* fix: avoid circular import by moving DSRunnerEvaluator import inside method
* fix: update fallback criterion
* fix: ensure evo_fb is initialized and used correctly in fallback logic
* refactor: rename use_new_evo to should_use_new_evo for clarity
* feat: add option to enable hyperparameter tuning only in first eval loop
* fix: use total_seconds() for accurate time calculations in evolution and tracking
* change refine prompt for full code
* fix: fix the logic of running
* refine prompt
* fix some bugs
* fix
* add two guidelines
* refactor the code
* make costeer evaluator more logical
* refine eval prompt
* make costeer eval prompt markdown
* update code diff prompt
* correct pipeline
* feat: add apply_patch utility and update ret.py with patch functionality (#1071)
* restore to the right version
* fix the docstring
* fix extract_output fcn
* add inplace parameter to apply patch
* remove enable_runner_iteration and make the eval prompt same as main
* refine runner eval prompt based on main
* Update rdagent/scenarios/data_science/dev/runner/prompts.yaml
* add wait_retry
* refactor: move enable_runner_code_diff to DSRunnerCoSTEERSettings as diff_mode
* reformat and remove enable_runner_code_diff
---------
Co-authored-by: yuanteli <1957922024@qq.com>
Co-authored-by: Xu <v-xuminrui@microsoft.com>
Co-authored-by: Jensen Lee <91518020+Jensen246@users.noreply.github.com>
Co-authored-by: you-n-g <you-n-g@users.noreply.github.com>
Co-authored-by: Qizheng Li <jenssenlee@163.com>
* Align scenario descriptions and include debug timeout
- Updated config.py to support debug timeout configuration
- Synchronized prompts in exp_gen and scen modules
- Refactored proposal.py for consistency with new scenario descriptions
- Improved __init__.py for better scenario management
* remove running time in stdout
---------
Co-authored-by: Xu Yang <xuyang1@microsoft.com>
* check sample submission & add package constraint
* add trace.log into clear
* change default
* simplify
* clear CI workspace before running
* move to CI
* use sudo to clean workspace
* move prepare out of global var
---------
Co-authored-by: Xu Yang <xuyang1@microsoft.com>
* init commit
* remove the 5-fold spec from prompts
* refine the hyperparameter specification
* do not sample data
* a small spelling issue
* refine prompt to avoid submission cheating
* do not sample data
* simplify code
* refine the coder evaluator prompt
* refine wording
* remove runtime from proposal
* refine wording
* refine prompt
* add gpu info in runtime_info.py
* modify the spec
* add router and add refinement exp gen
* fix prompt bug
* use rule-based logic for router
* complete the prompt
* fix circular import bug
* fix bug
* make refine_decision optional
* update pipeline prompts: (1) add scenary: in an iterative cooding loop and use sample datasets (2)add some generation tops in coding (3)add evaluation guidelines in evaluation (4)polish the json schema and description
* fix a small bug
* fix a small bug
* rdagent/scenarios/data_science/loop.py back to the original version
* refactor: replace _get_exp_gen with default_exp_gen for exp generation
* import
* refactor: make the __init__ back to main
* fix small bugs
* fix bugs for proposal_version
* move refine into runner
* check early stop
* EDA improvement & coder classes number
* fix CI
* slightly refine the prompt
* remove rule_base_eval and remove useless prompt
---------
Co-authored-by: Xu <v-xuminrui@microsoft.com>
Co-authored-by: TPLin22 <tplin2@163.com>
Co-authored-by: amstrongzyf <amstrongzyf@126.com>
Co-authored-by: Xu Yang <peteryang@vip.qq.com>
Co-authored-by: Xu Yang <xuyang1@microsoft.com>
Co-authored-by: Young <afe.young@gmail.com>
* docs: document extra_volumes dict format in DockerConf
* feat: accept dict values in extra_volumes to specify bind and mode
* fix: skip invalid PDF reports to prevent infinite loop
* from break to raise self.LoopTerminationError
* format with black
---------
Co-authored-by: Young <afe.young@gmail.com>
* start to work on multi-trace + async
* init ver of async-multi-tarce, to test
* add eng-ver log
* complete version of async+ mul-trace
* debug
* fix bug on DS_RD_SETTING.get()
* update
* fix bug + simplif the usage of async in multi-trace
* fix mini bug of arg_name
* Move local_selection into class Experiment & clean the code