[Model] Handle trust_remote_code for transformers backend#32194
Merged
Isotr0py merged 1 commit intovllm-project:mainfrom Jan 13, 2026
Merged
[Model] Handle trust_remote_code for transformers backend#32194Isotr0py merged 1 commit intovllm-project:mainfrom
trust_remote_code for transformers backend#32194Isotr0py merged 1 commit intovllm-project:mainfrom
Conversation
Signed-off-by: DarkLight1337 <tlleungac@connect.ust.hk>
Contributor
There was a problem hiding this comment.
Code Review
The pull request correctly propagates the trust_remote_code argument to the try_get_class_from_dynamic_module function. However, there is a critical issue in vllm/transformers_utils/dynamic_module.py where resolve_trust_remote_code is explicitly called with hardcoded has_local_code=False and has_remote_code=True. This bypasses the internal logic of transformers.dynamic_module_utils.get_class_from_dynamic_module, which already handles these parameters correctly. This redundancy can lead to incorrect security assessments, especially when loading models from local paths, and should be addressed.
Isotr0py
approved these changes
Jan 13, 2026
TomerBN-Nvidia
pushed a commit
to TomerBN-Nvidia/vllm
that referenced
this pull request
Jan 13, 2026
…ject#32194) Signed-off-by: DarkLight1337 <tlleungac@connect.ust.hk> Signed-off-by: Tomer Natan <tbarnatan@computelab-frontend-8.nvidia.com>
sammysun0711
pushed a commit
to sammysun0711/vllm
that referenced
this pull request
Jan 16, 2026
…ject#32194) Signed-off-by: DarkLight1337 <tlleungac@connect.ust.hk>
akh64bit
pushed a commit
to akh64bit/vllm
that referenced
this pull request
Jan 16, 2026
…ject#32194) Signed-off-by: DarkLight1337 <tlleungac@connect.ust.hk>
dsuhinin
pushed a commit
to dsuhinin/vllm
that referenced
this pull request
Jan 21, 2026
…ject#32194) Signed-off-by: DarkLight1337 <tlleungac@connect.ust.hk> Signed-off-by: dsuhinin <suhinin.dmitriy@gmail.com>
npanpaliya
pushed a commit
to odh-on-pz/vllm-cpu
that referenced
this pull request
Feb 16, 2026
…ject/vllm#32194) Signed-off-by: DarkLight1337 <tlleungac@connect.ust.hk>
npanpaliya
pushed a commit
to odh-on-pz/vllm-cpu
that referenced
this pull request
Feb 16, 2026
- [Misc] Implement `TokenizerLike.convert_tokens_to_ids` (vllm-project/vllm#31796) [INFERENG-4151](https://issues.redhat.com/browse/INFERENG-4151) - [Bug] Revert torch warning fix (vllm-project/vllm#31585) [INFERENG-4152](https://issues.redhat.com/browse/INFERENG-4152) - [Bug] Fix AttributeError: `ColumnParallelLinear` object has no attribute `weight_scale_inv` (vllm-project/vllm#30823) [INFERENG-4153](https://issues.redhat.com/browse/INFERENG-4153) - Avoid `opencv-python-headless==4.13.0.90`, it's broken. See opencv/opencv-python#1183 - [Bugfix] Handle mistral tokenizer in get_hf_processor (vllm-project/vllm#31817) [INFERENG-4151](https://issues.redhat.com/browse/INFERENG-4151) - [Bugfix] Fix Whisper/encoder-decoder GPU memory leak vllm-project/vllm#32789 - [Model] Handle `trust_remote_code` for transformers backend (vllm-project/vllm#32194) (fixes GHSA-2pc9-4j83-qjmr) - [Bugfix] CUDA: fix segfault by bumping numba to `numba==0.63.1` ([AIPCC-9384](https://issues.redhat.com/browse/AIPCC-9384)) - [Bugfix] pin `mistral_common==1.8.5` to avoid crash with Voxtral ([INFERENG-4154](https://issues.redhat.com/browse/INFERENG-4154)) - [Bugfix] fix tokenizer loading for mistral models (vllm-project/vllm#33175) [INFERENG-4151](https://issues.redhat.com/browse/INFERENG-4151)
ItzDEXX
pushed a commit
to ItzDEXX/vllm
that referenced
this pull request
Feb 19, 2026
…ject#32194) Signed-off-by: DarkLight1337 <tlleungac@connect.ust.hk>
Shafi-Hussain
pushed a commit
to odh-on-pz/vllm-cpu
that referenced
this pull request
Mar 17, 2026
…ject/vllm#32194) Signed-off-by: DarkLight1337 <tlleungac@connect.ust.hk>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Add
trust_remote_codeargument totry_get_class_from_dynamic_moduleand handle it accordingly.Test Plan
Test Result
Essential Elements of an Effective PR Description Checklist
supported_models.mdandexamplesfor a new model.