Skip to content

fix: validate remote model reads with offline request tests - #46

Open
rupayon123 wants to merge 12 commits into
pipe1os:mainfrom
rupayon123:contribution/huggingface-offline-tests-20260909
Open

rupayon123 wants to merge 12 commits into
pipe1os:mainfrom
rupayon123:contribution/huggingface-offline-tests-20260909

Conversation

@rupayon123

@rupayon123 rupayon123 commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Exercise the Hugging Face request layer offline and correct four failures found at that boundary:

  • Reject SafeTensors headers over the same 100 MiB limit as the local reader before issuing another download request.
  • Reject HTTP 200 responses that ignore a requested nonzero byte range, rather than interpreting bytes from the wrong offset.
  • Reject invalid negative seek/read positions and nonpositive stream chunk sizes without corrupting the cursor.
  • Percent-encode file paths so spaces, fragments, query delimiters and literal percent signs remain part of the filename. Preserve directory separators.

Motivation

Addresses #28 with the original request-boundary coverage plus regressions for each reproduced behavior. Existing coverage includes authentication/Range headers, timeouts, bounded reads, error translation, single-file metadata, large-header continuation, 416 fallback, lazy shards and buffered reads/seeks.

Type of change

  • Bug fixes
  • Offline test coverage

Validation

Python 3.11, PYTHONPATH=src pytest -q: 84 passed. New test files pass ruff; git diff --check passes. Each new regression group failed before its fix. Network and token lookup are isolated in tests; no live model weights or credentials are used. The full-response test intentionally rejects unsupported range behavior rather than claiming transparent server compatibility.

Conventional commits include How to test instructions. Prepared with AI assistance. Remote CI is verified separately on the new head.

How to test: python -m pytest -q (73 passed); ruff check tests/test_huggingface.py.
@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: pipe1os/modelinfo-cli/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: f8e0d88e-f7e0-4a13-bc4b-cd17a2916ae0


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codacy-production

codacy-production Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 56 complexity · 0 duplication

Metric Results
Complexity 56
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

How to test: PYTHONPATH=src pytest tests/test_hf_header_limit.py; PYTHONPATH=src pytest
How to test: PYTHONPATH=src pytest tests/test_hf_range_response.py; PYTHONPATH=src pytest
How to test: PYTHONPATH=src pytest tests/test_remote_stream_positions.py; PYTHONPATH=src pytest
How to test: PYTHONPATH=src pytest tests/test_hf_filename_encoding.py; PYTHONPATH=src pytest
@rupayon123 rupayon123 changed the title test: exercise hugging face requests without network access fix: validate remote model reads with offline request tests Sep 14, 2026
@rupayon123

Copy link
Copy Markdown
Contributor Author

Follow-up: 1473e9a876fe898bd09eb19e96423a6d33102190 copies caller-provided headers before adding authentication. Previously, reusing the dictionary after the token was removed still sent the old bearer token. The new offline regression reproduced that behavior before the fix; all 85 local tests pass. The exact head now also passes all nine OS/Python CI jobs and Codacy. This exercises request construction with stubbed transport, not live gated-model access.

@rupayon123

Copy link
Copy Markdown
Contributor Author

September 16 verified update:

Remote header truncation, authoritative shard indexes, cached token paths, zero-length reads and incorrect Content-Range offsets now have regression coverage. The final local suite has 96 passing tests. Responses without Content-Range retain their prior compatibility behavior.

Commits: f2faeb2ef57547f3fecf99c577eb2b8405b0ea18, ff1dd30b1a7e1c085775a3a12330b95e5e2c8342, ed06ed73ae17958c1c96e79ccca9203395f5dcad, 99b28aabf0d156c8fe399cf4f2db3b6596568f1f, 237d1a0a638b79e0eff07596192f245f26d7c356.

Exact current head: 237d1a0a638b79e0eff07596192f245f26d7c356. GitHub checks at this read: Test on ubuntu-latest with Python 3.10: SUCCESS, Test on ubuntu-latest with Python 3.11: SUCCESS, Test on ubuntu-latest with Python 3.12: SUCCESS, Test on macos-latest with Python 3.10: SUCCESS, Test on macos-latest with Python 3.11: SUCCESS, Test on macos-latest with Python 3.12: SUCCESS, Test on windows-latest with Python 3.10: SUCCESS, Test on windows-latest with Python 3.11: SUCCESS, Test on windows-latest with Python 3.12: SUCCESS, Codacy Static Code Analysis: SUCCESS, CodeRabbit: SUCCESS. Local results do not imply maintainer approval.

AI-assisted with OpenAI Codex; changes and validation were inspected before submission.

@rupayon123

Copy link
Copy Markdown
Contributor Author

The latest revision, 5b8459fbbcdc2c26834c23bec7c32f4dcea266bf, rejects valid JSON that is not a SafeTensors header object in both local and remote parsing. This keeps malformed remote shards inside the existing missing-shard error handling instead of crashing later aggregation.

All 109 local tests pass, including regressions for arrays, scalars, and null headers. The exact-head GitHub CI workflow now also passes: https://github.com/pipe1os/modelinfo-cli/actions/runs/35490455375. Prepared with AI assistance.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant