Skip to content

fix(pixel-inference): reject negative or out-of-range temperature in prepare - #5940

Open
vaibhavsrv wants to merge 1 commit into
Osmantic:public-betafrom
vaibhavsrv:fix/pixel-inference-temperature-bounds
Open

vaibhavsrv wants to merge 1 commit into
Osmantic:public-betafrom
vaibhavsrv:fix/pixel-inference-temperature-bounds

Conversation

@vaibhavsrv

Copy link
Copy Markdown
Contributor

Why this matters

In ods/extensions/services/pixel-inference/app/main.py, _prepare(payload, grant) checks inference request fields against the allowed FIELDS set and enforces message formatting, but does not validate the type or numerical bounds of temperature. When a client passes a negative temperature, a value exceeding the model runtime cap (> 2.0), or a non-numeric/boolean value (such as true or a string), the unvalidated value passes through to downstream inference runtimes, triggering unhandled backend exceptions, process abortion, or HTTP 500 crashes.

This change adds a surgical validation block to _prepare before computing the token limit. It verifies that temperature is an int or float (excluding bool) within the canonical [0.0, 2.0] range, raising ShareError(400, 'invalid_temperature') otherwise. Existing valid temperatures, default behavior, and model parameter fallbacks remain completely unchanged.

Validation

  • Tested baseline reproduction against unpatched main.py: passing {"temperature": -1.0}, {"temperature": 2.5}, or {"temperature": True} bypassed validation and was forwarded without rejection.
  • Tested post-fix behavior: negative, out-of-range, and boolean/string temperatures are rejected with HTTP 400 and code invalid_temperature; valid values in [0.0, 2.0] succeed identically.
  • Telemetry statement: "Pixel-inference suites: 4 passed. New-test Ruff, py_compile, and diff checks pass; new regression wired into Linux CI."

Overlap check

Risk / AI disclosure

AI-assisted investigation, implementation, and unit regression. This strengthens an inference parameter contract check and does not modify running infrastructure, model files, or container configurations. Independent human review and platform qualification remain gates.

Follow-up integration evidence

Composed cleanly on top of #5569, #5871, and #5875 at HEAD without conflicts. Production and test diffs passed together; adjacent pixel-agent and pixel-settings checks remain intact.
Backlog composition was local-only (production/test diffs, excluding workflow/Makefile wiring); it is not an upstream merge or independent human approval. Declared live-review gates remain open.

@vaibhavsrv
vaibhavsrv force-pushed the fix/pixel-inference-temperature-bounds branch from 4f33371 to ceec0ab Compare September 22, 2026 03:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant