Skip to content

test: cover local binary parser success and failure paths - #45

Open
rupayon123 wants to merge 7 commits into
pipe1os:mainfrom
rupayon123:contribution/binary-parser-tests-20260909
Open

rupayon123 wants to merge 7 commits into
pipe1os:mainfrom
rupayon123:contribution/binary-parser-tests-20260909

Conversation

@rupayon123

Copy link
Copy Markdown
Contributor

Summary

Adds 12 generated-fixture tests for local SafeTensors and PyTorch headers: valid metadata, truncated and oversized headers, malformed JSON, deduplicated and missing shards, invalid ZIPs, missing/truncated pickle metadata, and the restricted unpickler's rejection of an unapproved builtin.

Motivation & Context

Addresses #29 without downloading model weights, committing binary fixtures, or adding a PyTorch dependency. The existing fixture-based checks remain intact.

Type of Change

  • Test coverage (no production behavior changes)

How Has This Been Tested?

Python 3.11: python -m pytest -q — 76 passed, up from 64 on the unchanged base. ruff check tests/test_binary_parsers.py and git diff --check pass.

The PyTorch success fixture covers metadata dictionaries inside an archive, not a real torch-generated tensor checkpoint; actual storage reconstruction remains additional coverage work.

Checklist

  • Conventional commit with a How to test body.
  • New tests and existing suite pass locally.
  • No runtime dependencies or production code changes.

Prepared with AI assistance; the submitted tests were executed locally.

How to test: python -m pytest -q (76 passed on Python 3.11).
@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: b6a3fa60-0296-43b0-8a3c-3d085d80d62b


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codacy-production

codacy-production Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Not up to standards ⛔

🔴 Issues 1 critical

Alerts:
⚠ 1 issue (≤ 0 issues of at least minor severity)

Results:
1 new issue

Category Results
Security 1 critical

View in Codacy

🟢 Metrics 31 complexity · 0 duplication

Metric Results
Complexity 31
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@rupayon123

Copy link
Copy Markdown
Contributor Author

I checked the two Codacy annotations on this PR. Both point to pickle.dumps(...) in generated test fixtures, not to an unrestricted pickle.load/loads call. One serializes a fixed OrderedDict; the other serializes the harmless builtin len specifically to verify that the production RestrictedUnpickler rejects an unapproved global.

No downloaded or user-supplied pickle is executed by these tests. All nine Python/OS CI test jobs passed. I have left the restricted-unpickler regression intact rather than suppressing the security check; the two annotations need maintainer review as test-fixture false positives.

@rupayon123

Copy link
Copy Markdown
Contributor Author

Additional fixes pushed to this branch:

  • 9f3375d: Parse supported PyTorch storage references.
  • 314757b: Reject truncated GGUF headers and handle partial stream reads.
  • 75fc7d5: Honor shard index assignments and reject missing indexed tensors.

All 98 local tests pass. Regressions cover safe PyTorch storage references, truncated GGUF fields/partial reads, and authoritative shard-index assignments. PyTorch compatibility is fixture-based; no live torch-generated checkpoint was loaded.

Prepared with AI assistance. Changes are submitted for review; this is not a claim of maintainer approval.

@rupayon123

Copy link
Copy Markdown
Contributor Author

September 16 verified update:

The checkpoint wrapper and additional PyTorch storage-type regressions are now covered. The final local suite has 105 passing tests. These use controlled metadata/pickle fixtures, not a production PyTorch checkpoint.

Commits: 4eb16eb27c919025563e8d3bb4508fbc928d711e, 3ab619eac8dc1f6c007be1473f69fd937eea7cb8.

Exact current head: 3ab619eac8dc1f6c007be1473f69fd937eea7cb8. GitHub checks at this read: Test on ubuntu-latest with Python 3.10: SUCCESS, Test on ubuntu-latest with Python 3.11: SUCCESS, Test on ubuntu-latest with Python 3.12: SUCCESS, Test on macos-latest with Python 3.10: SUCCESS, Test on macos-latest with Python 3.11: SUCCESS, Test on macos-latest with Python 3.12: SUCCESS, Test on windows-latest with Python 3.10: SUCCESS, Test on windows-latest with Python 3.11: SUCCESS, Test on windows-latest with Python 3.12: SUCCESS, Codacy Static Code Analysis: ACTION_REQUIRED, CodeRabbit: SUCCESS. Local results do not imply maintainer approval.

AI-assisted with OpenAI Codex; changes and validation were inspected before submission.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant