aslein1413's picture
Upload folder using huggingface_hub
0187f98 verified
Raw
History Blame Contribute Delete
688 Bytes
# Load an untrusted torch.package archive the normal way. No safe flag exists here.
# The archive interns its own module whose top-level code runs when the pickled
# object's class is resolved -> /tmp/MARKER_importtime.txt appears on load.
import os, torch
from torch.package import PackageImporter
m = "evil_importtime.pt"
print("marker before:", os.path.exists("/tmp/MARKER_importtime.txt"))
imp = PackageImporter(m)
obj = imp.load_pickle("data", "obj.pkl") # standard consumer API
print("loaded:", type(obj))
print("marker after :", os.path.exists("/tmp/MARKER_importtime.txt"))
if os.path.exists("/tmp/MARKER_importtime.txt"):
print(open("/tmp/MARKER_importtime.txt").read())