* Fix DoS via malicious HDF5 dataset metadata in KerasFileEditor (#21880)
* Fix DoS via malicious HDF5 dataset metadata in KerasFileEditor
* Refactor: move MAX_BYTES constant outside loop per review feedback
* Fix: harden HDF5 dataset metadata validation in KerasFileEditor
* Do not allow external links in HDF5 files. (#22057)
Keras never uses this feature.
- verify that we get H5 Groups when expected, otherwise, merely by doing `[key]` we may be loading an external Dataset.
- verify that the H5 Datasets are not external links and fail if they are.
- remove unused methods `items` and `values` in `H5IOStore` and `ShardedH5IOStore`. They are not used, the implementation of `MutableMapping` was incomplete anyway and these methods we return unverified Datasets.
- fixed logic related to `failed_saveables` in `load_state`.
- preserve the order of keys in the implementation of `ShardedH5IOStore.keys()`.
* Set mutable to True by default in nnx_metadata (#22074)
* Disallow TFSMLayer deserialization in safe_mode to prevent external SavedModel execution (#22035)
* Implement safe mode checks in TFSMLayer
Added safe mode checks for loading TFSMLayer from external SavedModels.
* Update keras/src/export/tfsm_layer.py
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
* Align logic with __init__ method for robust checks
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
* Fix indentation and formatting in tfsm_layer.py
* Add setup method to enable unsafe deserialization
Enable unsafe deserialization for TFSM Layer tests.
* Update TFSMLayer initialization in tests
* Fix import for TFSMLayer in tfsm_layer_test.py
* Remove safe_mode check from TFSMLayer.__init__()
The safe_mode check should only be in from_config(), not __init__().
Direct instantiation (TFSMLayer(filepath=...)) is a legitimate use case
where the user explicitly creates the layer. The security concern is
only during deserialization of untrusted .keras files, which goes
through from_config().
This allows attackers to create malicious .keras files while still
blocking victims from loading them with safe_mode=True.
* Implement tests for TFSMLayer safe mode functionality
Add comprehensive tests for TFSMLayer safe_mode behavior:
- test_safe_mode_direct_instantiation_allowed: Verifies direct
TFSMLayer instantiation works as expected
- test_safe_mode_from_config_blocked: Verifies from_config() raises
ValueError when safe_mode=True
- test_safe_mode_from_config_allowed_when_disabled: Verifies
from_config() works with safe_mode=False
- test_safe_mode_model_loading_blocked: Tests the full attack scenario
where loading a .keras file with safe_mode=True is blocked
* Clarify test docstrings in tfsm_layer_test.py
Updated test docstrings for clarity on instantiation and loading behavior.
* Invoke model with random input in tfsm_layer tests
Added model invocation with random input to tests for TFSMLayer.
* Set safe_mode default to True in from_config method
* Update tfsm_layer_test.py
* Update tfsm_layer_test.py
* Update tfsm_layer_test.py to original
* New test case tfsm_layer_test.py
* Update Comments tfsm_layer.py
* Update tfsm_layer_test.py
* Update tfsm_layer.py
* Update tfsm_layer.py to remove ruff errors
* Update tfsm_layer.py
* Update tfsm_layer_test.py
* Update tfsm_layer.py
* Update tfsm_layer.py
* Update tfsm_layer_test.py
* Update tfsm_layer.py format fix
Changes in format
* Update tfsm_layer.py
* Update tfsm_layer_test.py
* Update tfsm_layer.py
* Update tfsm_layer_test.py
* Fixes unnecessary changes tfsm_layer.py
* Added new test case tfsm_layer_test.py
* Set `safe_mode=None` in `from_config`, which fixes the unit tests.
Also re-added empty lines.
* Remove unneeded `custom_objects` in unit tests.
---------
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Fabien Hertschuh <1091026+hertschuh@users.noreply.github.com>
* patch release 3.12.2 changes
---------
Co-authored-by: sarvesh patil <103917093+HyperPS@users.noreply.github.com>
Co-authored-by: hertschuh <1091026+hertschuh@users.noreply.github.com>
Co-authored-by: Divyashree Sreepathihalli <divyashreepathihalli@gmail.com>
Co-authored-by: Manan Patel <70314133+0xManan@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>