mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-06 22:17:51 +00:00
|
Some checks are pending
CI / Focused test guidance (report-only) (push) Waiting to run
CI / Python syntax (compileall) (push) Waiting to run
CI / JS syntax (node --check) (push) Waiting to run
CI / Python tests (pytest) (push) Waiting to run
CodeQL / Analyze (actions) (push) Waiting to run
CodeQL / Analyze (javascript-typescript) (push) Waiting to run
CodeQL / Analyze (python) (push) Waiting to run
ci / docker publish / build (amd64) (push) Waiting to run
ci / docker publish / build (arm64) (push) Waiting to run
ci / docker publish / merge manifest + tag (push) Blocked by required conditions
scripts/mlx_image_server.py resolved the model per request (`req.model or _args.model`) on both /v1/images/generations and /v1/images/edits, so the caller chose which model was served. `_is_hidream()` is a substring test and `_snapshot_path()` accepts either a local directory or a Hugging Face repo id, so a caller-supplied string selected the HiDream branch and then supplied the directory it runs `scripts/hidream_o1/generate_hidream_o1_mlx.py` from, under sys.executable. The server has no auth, and the Cookbook binds it to 0.0.0.0 whenever it is serving to a remote host, so one POST executed attacker code on the serving host. Both paths now use `_args.model`. The request field is still accepted for OpenAI wire compatibility and ignored, matching scripts/diffusion_server.py, and Odysseus already sends the served model's own id, so this is a no-op for legitimate callers. /v1/images/harmonize already pinned. Regression tests cover both endpoints, the local-directory and Hugging-Face-repo halves, and that a server actually launched with a HiDream model still serves it. Three of the four fail on the unfixed code. |
||
|---|---|---|
| .. | ||
| _completion | ||
| _lib | ||
| demo_email | ||
| add_hwfit_models.py | ||
| agent_migration_manifest.py | ||
| backfill_model_release_dates.py | ||
| check-docker-amd-gpu.sh | ||
| check-docker-gpu.sh | ||
| claim_ownerless.py | ||
| diffusion_server.py | ||
| encode_previews.sh | ||
| fix_paths.py | ||
| hf_download.py | ||
| import_from_vllm_recipes.py | ||
| index_documents.py | ||
| migrate_faiss_to_chroma.py | ||
| migrate_searxng_settings.py | ||
| mlx_image_server.py | ||
| odysseus | ||
| odysseus-backup | ||
| odysseus-calendar | ||
| odysseus-contacts | ||
| odysseus-cookbook | ||
| odysseus-docs | ||
| odysseus-gallery | ||
| odysseus-logs | ||
| odysseus-mail | ||
| odysseus-mcp | ||
| odysseus-memory | ||
| odysseus-notes | ||
| odysseus-personal | ||
| odysseus-preset | ||
| odysseus-research | ||
| odysseus-sessions | ||
| odysseus-signature | ||
| odysseus-skills | ||
| odysseus-tasks | ||
| odysseus-theme | ||
| odysseus-webhook | ||
| pr_blocker_audit.py | ||
| update_database.py | ||