Skip to content

Same unconfined predictions/<item_id> path pattern remains in four benchmark rollouts #306

Description

@WODE25500

Follow-up from #264 (now merged). That PR validated the SpreadsheetBench task identifier and confined its persistent output directory. The same unconfined pattern remains in four other benchmark rollouts:

  • skillopt/envs/docvqa/rollout.py:173 and :232
  • skillopt/envs/livemathematicianbench/rollout.py:144
  • skillopt/envs/searchqa/rollout.py:204
  • skillopt/envs/officeqa/rollout.py:530

Each is os.path.join(out_root, "predictions", item_id), where item_id comes straight from the dataset item — no validation of the identifier and no containment check on the destination. An id such as ../../x therefore derives a destination outside out_root and processing continues into the model / code-execution path. skillopt/envs/spreadsheetbench/rollout.py now has _is_safe_task_id() and _confined_task_out_dir(), which could be lifted into a shared helper.

Two caveats are why this is filed rather than sent as a direct port:

  1. A charset validator is not sufficient for livemathematicianbench. Its ids are colon-shaped (202602:12), so all 177 ids across the shipped splits would be rejected by the SpreadsheetBench rule. Those runs need confinement by construction (map an id to a safe directory name) rather than validate-and-reject. Separately, an id containing : cannot be a Windows directory name at all, so those runs are already broken on Windows for an unrelated reason.

  2. Renaming the directory is not free. Readers look the task up by its raw id — skillopt/optimizer/slow_update.py:113 reads predictions/<task_id>/conversation.json — so any id-to-dirname mapping has to be applied on the read side too.

docvqa (63180), searchqa (hex) and officeqa (UID0003) use ids that are already safe shapes, so for those three the SpreadsheetBench approach can be applied as-is.

Filed separately because it is outside #264's reviewed scope.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions