Skip to content

fix(pixel-inference): reject boolean value for integer seed parameter - #5943

Open
vaibhavsrv wants to merge 1 commit into
Osmantic:public-betafrom
vaibhavsrv:fix/pixel-inference-seed-type
Open

vaibhavsrv wants to merge 1 commit into
Osmantic:public-betafrom
vaibhavsrv:fix/pixel-inference-seed-type

Conversation

@vaibhavsrv

Copy link
Copy Markdown
Contributor

Why this matters

In ods/extensions/services/pixel-inference/app/main.py, _prepare(payload, grant) lists seed in the allowed FIELDS mapping but does not validate its data type. In Python, bool is a direct subclass of int, so type checks such as isinstance(val, int) evaluate to True for True and False. When a client sends {"seed": true} or a non-integer float/string (e.g. "42"), the unvalidated value passes to the model engine, where boolean flags or floats alter backend pseudo-random number generator seeding unexpectedly or trigger runtime type errors.

This change introduces strict integer validation for seed in _prepare. If present and non-null, it requires type(seed) is int and type(seed) is not bool, raising ShareError(400, 'invalid_seed') for booleans, strings, or floats. Standard integer seeds and omitted/null seeds continue to function cleanly.

Validation

  • Tested baseline reproduction against unpatched code: passing {"seed": True} or {"seed": 42.0} bypassed _prepare without error.
  • Tested post-fix behavior: boolean and non-integer seed values are rejected with HTTP 400 and code invalid_seed; valid integer seeds pass without modification.
  • Telemetry statement: "Pixel-inference suites: 3 passed. New-test Ruff, py_compile, and diff checks pass; new regression wired into Linux CI."

Overlap check

Risk / AI disclosure

AI-assisted defect discovery, implementation, and regression verification. This strengthens request boundary checking for inference random seeds and does not modify running infrastructure, models, or configurations. Independent human review remains a gate.

Follow-up integration evidence

Composed cleanly on top of #5569, #5871, and #5875 at HEAD without conflicts. Production and test diffs passed together; adjacent pixel-agent and pixel-settings checks remain intact.
Backlog composition was local-only (production/test diffs, excluding workflow/Makefile wiring); it is not an upstream merge or independent human approval. Declared live-review gates remain open.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant