Conversation
added 2 commits
August 26, 2026 20:19
Two minimal, backward-compatible source changes that let gt4sd-core run under torch 2.6.0 (the runtime linchpin blocking ~22 Dependabot alerts, incl. the CRITICAL torch.load RCE, CVE-2025-32434). Verified against a torch-2.6 env; both changes are no-ops on torch 1.12. - torchdrug/unpatch.py: torch 2.x renamed the base LR scheduler _LRScheduler -> LRScheduler (the private name survives only as a deprecated subclass). Use the public base for the subclass assertions and mirror the revert onto both names so torchdrug un-patching keeps working on torch 1.x and 2.x. - frameworks/torch: add install_torch_load_compat(), a centralized shim that restores the pre-2.6 torch.load default (weights_only=False) only when the caller did not pass weights_only. GT4SD and several deps (pytorch_lightning, guacamol_baselines, reinvent_models) load full, trusted checkpoints; a centralized shim reaches those internal call sites, unlike per-site edits. No-op on torch < 2.6. - __init__.py: install the shim at import time, before any checkpoint loads. Spike result (torch 2.6.0 + torchvision 0.21.0 + PyG cp310 pt26 cpu wheels + fast_transformers rebuild): 395 passed / 5 failed / 61 skipped. All 5 failures are a torch-2.x uint8-mask masked_fill_ regression inside the upstream `moses` package (moses/vae/model.py, moses/aae/model.py), reached via guacamol_baselines -- not gt4sd-core source. Lint clean (black + flake8) and all 6 CLI entry points OK under torch 2.6.
|
Thank you for your pull request and welcome to our community. We could not parse the GitHub identity of the following contributors: Karl Wehden.
|
|
Thank you for your pull request and welcome to our community. We could not parse the GitHub identity of the following contributors: Karl Wehden.
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
GitHub Actions request
@drugilsberg: please add or advise on a dedicated Torch 2.x GitHub
Actions job. The existing workflow creates the Torch 1.12 environment, so it
cannot reproduce the validated Torch 2.6 result remotely.
Local validation with the published testing-fork pins: