Skip to content

fix(pixel-inference): validate finite float bounds for temperature parameter - #5714

Open
Vishaaallll wants to merge 1 commit into
Osmantic:public-betafrom
Vishaaallll:fix/pixel-inference-temperature-bounds
Open

Vishaaallll wants to merge 1 commit into
Osmantic:public-betafrom
Vishaaallll:fix/pixel-inference-temperature-bounds

Conversation

@Vishaaallll

Copy link
Copy Markdown
Contributor

Why this matters

In ods/extensions/services/pixel-inference/app/main.py, FIELDS accepted temperature in the request payload, but _prepare(payload, grant) omitted range and type validation for the parameter. If a caller supplied non-numeric types, boolean values, non-finite values (NaN, inf), or values outside the standard [0.0, 2.0] sampling range, the invalid value passed unvalidated to the backend inference runtime, causing runtime crashes or undefined sampling distribution behavior.

This surgical fix validates that temperature, when present, is a non-boolean finite float or integer within [0.0, 2.0], raising ShareError(400, 'invalid_temperature') otherwise.

Validation

  • Baseline reproduction: verified that _prepare({"model": "ods/shared", "messages": [{"role": "user", "content": "hi"}], "temperature": -0.5}, grant) passed without error on unpatched code.
  • Post-fix behavior: properly rejects negative, excessive (>2.0), non-finite, and non-numeric temperature values with HTTP 400 invalid_temperature.
  • Telemetry: pixel-inference suite: 2 passed. New-test Ruff, syntax, and diff checks pass; new regression wired into Linux CI.

Overlap check

Searched open/closed PRs on Osmantic/ODS. PR #5616 touched capabilities limits and #5696 touched settings contracts. Neither addresses request-time inference parameter bounds in pixel-inference/app/main.py.

Risk / AI disclosure

AI-assisted investigation, patch, and regression tests. Strictly validates incoming HTTP inference payload parameters against the OpenAI specification. Independent review remains a gate.

Follow-up integration evidence

Composed locally with public-beta at 4fa6ad170 without conflicts. Regression tests pass locally and in Linux CI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant