fix: prefer registered config over remote code in AutoConfig.from_pretrained#45094
Merged
hmellor merged 9 commits intohuggingface:mainfrom Mar 31, 2026
Merged
Conversation
25ef1a9 to
400e4bb
Compare
6187543 to
06bcb31
Compare
When a class has been explicitly registered via AutoConfig.register() (or other Auto*.register()), it should take precedence over auto_map remote code. Previously, trust_remote_code=True with auto_map entries in config.json would always load remote code, ignoring the registration. This applies the same fix across all Auto classes: AutoConfig, AutoModel, AutoTokenizer, AutoProcessor, AutoFeatureExtractor, AutoImageProcessor, AutoVideoProcessor. This caused issues for downstream libraries (e.g., vLLM) that vendor fixed classes for models with broken remote code — internal calls from AutoTokenizer/AutoProcessor would bypass the registration and load the broken remote class. Fixes: huggingface#45093 Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
06bcb31 to
37100cc
Compare
Member
|
Closing as I believe it is expected behaviour that |
Member
|
Having clarified, my understanding of the intended behaviour of If there is local code present, Transformers should use it in preference to any remote code. |
hmellor
approved these changes
Mar 31, 2026
Member
hmellor
left a comment
There was a problem hiding this comment.
I like this change but will wait for an additional stamp from @ArthurZucker to confirm that this is desired behaviour
…g to transformers) Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com>
Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com>
Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com>
Member
|
The expected behaviour is as follows:
|
Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com>
Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com>
Contributor
|
[For maintainers] Suggested jobs to run (before merge) run-slow: auto |
Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com>
|
The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update. |
sirzechs66
pushed a commit
to sirzechs66/transformers
that referenced
this pull request
Mar 31, 2026
…trained (huggingface#45094) * Prefer registered classes over remote code in Auto*.from_pretrained When a class has been explicitly registered via AutoConfig.register() (or other Auto*.register()), it should take precedence over auto_map remote code. Previously, trust_remote_code=True with auto_map entries in config.json would always load remote code, ignoring the registration. This applies the same fix across all Auto classes: AutoConfig, AutoModel, AutoTokenizer, AutoProcessor, AutoFeatureExtractor, AutoImageProcessor, AutoVideoProcessor. This caused issues for downstream libraries (e.g., vLLM) that vendor fixed classes for models with broken remote code — internal calls from AutoTokenizer/AutoProcessor would bypass the registration and load the broken remote class. Fixes: huggingface#45093 Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * Only ignore remote code if local code is explicit (i.e. doesn't belong to transformers) Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> * update tests Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> * `make style` Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> * fix tokenizer test Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> * Fix tests Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> * Fix explicit registration detection Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> * make style Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> --------- Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: Harry Mellor <19981378+hmellor@users.noreply.github.com>
SangbumChoi
pushed a commit
to SangbumChoi/transformers
that referenced
this pull request
Apr 4, 2026
…trained (huggingface#45094) * Prefer registered classes over remote code in Auto*.from_pretrained When a class has been explicitly registered via AutoConfig.register() (or other Auto*.register()), it should take precedence over auto_map remote code. Previously, trust_remote_code=True with auto_map entries in config.json would always load remote code, ignoring the registration. This applies the same fix across all Auto classes: AutoConfig, AutoModel, AutoTokenizer, AutoProcessor, AutoFeatureExtractor, AutoImageProcessor, AutoVideoProcessor. This caused issues for downstream libraries (e.g., vLLM) that vendor fixed classes for models with broken remote code — internal calls from AutoTokenizer/AutoProcessor would bypass the registration and load the broken remote class. Fixes: huggingface#45093 Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * Only ignore remote code if local code is explicit (i.e. doesn't belong to transformers) Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> * update tests Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> * `make style` Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> * fix tokenizer test Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> * Fix tests Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> * Fix explicit registration detection Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> * make style Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> --------- Signed-off-by: Harry Mellor <19981378+hmellor@users.noreply.github.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: Harry Mellor <19981378+hmellor@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When a config class has been explicitly registered via AutoConfig.register(), it should take precedence over auto_map remote code. Previously,
trust_remote_code=Truewith auto_map.AutoConfig in config.json would always load remote code, ignoring the registration.This caused issues for downstream libraries (e.g., vLLM) that vendor fixed config classes for models with broken remote code — internal calls from AutoTokenizer/AutoProcessor would bypass the registration and load the broken remote class.
What does this PR do?
Fixes: #45093
Code Agent Policy
The Transformers repo is currently being overwhelmed by a large number of PRs and issue comments written by
code agents. We are currently bottlenecked by our ability to review and respond to them. As a result,
we ask that new users do not submit pure code agent PRs at this time.
You may use code agents in drafting or to help you diagnose issues. We'd also ask autonomous "OpenClaw"-like agents
not to open any PRs or issues for the moment.
PRs that appear to be fully agent-written will probably be closed without review, and we may block users who do this
repeatedly or maliciously.
This is a rapidly-evolving situation that's causing significant shockwaves in the open-source community. As a result,
this policy is likely to be updated regularly in the near future. For more information, please read
CONTRIBUTING.md.Before submitting
Pull Request section?
to it if that's the case.
documentation guidelines, and
here are tips on formatting docstrings.
Who can review?
Anyone in the community is free to review the PR once the tests have passed. Feel free to tag
members/contributors who may be interested in your PR.