Skip to content

fix(server): reject invalid HTTP generation inputs - #1421

Draft
JiaxinD wants to merge 2 commits into
NVIDIA:mainfrom
JiaxinD:fix/server-finite-sampling
Draft

JiaxinD wants to merge 2 commits into
NVIDIA:mainfrom
JiaxinD:fix/server-finite-sampling

Conversation

@JiaxinD

@JiaxinD JiaxinD commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Background

HTTP generation requests can pass invalid inputs into later processing: temperature: 1e400 becomes infinity during JSON decoding, while a prompt containing an escaped lone Unicode surrogate raises UnicodeEncodeError during UTF-8 length calculation. Both should receive HTTP 400 before worker acquisition. Found while reviewing the server request path; no originating issue.

Exit Criteria

Both completion routes reject nonfinite temperatures and surrogate text before acquiring a worker. Subsequent requests with zero temperature and valid Unicode, including emoji, remain valid.

Implementation

Set allow_inf_nan=False on the shared temperature field. Add an inherited string-field validator to StrictRequest that verifies UTF-8 encodability and emits a constant validation message, covering completion prompts, chat content and nested text parts. Saturated fake-registry regressions detect unintended worker acquisition. No native protocol, ABI, bundle or dependency changes.

Change categories

  • Public API

Validation

Commands and Results

With PYTHONPATH=apps/server/python;core/builder;. on Windows:

  • python -m pytest apps/server/python/tests/test_app.py -k nonfinite -q -p no:cacheprovider: before the temperature fix, all six new cases failed (429 instead of 400).
  • The surrogate regression was reproduced before the fix with fail-fast enabled: the first completion prompt case raised UnicodeEncodeError during UTF-8 length calculation. The eight added cases cover high/low surrogates in completion prompts, chat user/system content and nested text parts.
  • python -m pytest apps/server/python/tests -q -p no:cacheprovider: after both fixes, 24 passed.
  • ruff check apps/server/python/trtmc_server/schemas.py apps/server/python/tests/test_app.py: passed.
  • With PYTHONPATH=core/builder;apps/benchmark;.: python -m tools.model_ci validate and python tools/test_impact.py --validate: passed.
  • git diff --check: passed. Independent read-only review found no actionable findings.

Hardware, Environment, and Revisions

CPU-only Windows, Python 3.13.2, FastAPI 0.139.0, Pydantic 2.12.5. Tested source committed as 128fd03, based on upstream 613bbf0. No model weights or datasets involved.

Not Run / Remaining Gaps

No native worker process, TensorRT engine, GPU inference or throughput test was run. HTTP tests use the existing fake registry/session; they prove boundary rejection and subsequent valid-request routing, not hardware behavior.

Contributor Self-Review

  • I have completed a self-review of this change.

Notes For Future Readers

This HTTP-boundary fix is independent of #1417, which handles numeric overflow in direct native JSONL input. Native validation remains necessary for direct callers. Review-ready within scope; Draft remains solely because the repository's three non-draft slots are occupied.

Risk level

  • Low

Invalid inputs are rejected earlier. Finite temperatures, defaults and valid Unicode retain their behavior. The shared validator also covers string fields such as model and role. No artifact rebuild is needed beyond deploying the server Python change.

Signed-off-by: JiaxinD <djx2048@gmail.com>
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Comment @coderabbitai help to get the list of available commands.

Signed-off-by: JiaxinD <djx2048@gmail.com>
@JiaxinD JiaxinD changed the title fix(server): reject nonfinite HTTP temperature fix(server): reject invalid HTTP generation inputs Sep 26, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant