Conversation
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
This was referenced Oct 1, 2026
ananthsub
force-pushed
the
ananthsub/partial-ckpt-indirect-prompt-injection
branch
from
October 1, 2026 21:53
95c3b23 to
d88d2c2
Compare
This was referenced Oct 1, 2026
ananthsub
force-pushed
the
ananthsub/partial-ckpt-indirect-prompt-injection
branch
from
October 1, 2026 22:05
d88d2c2 to
e297cd8
Compare
ananthsub
force-pushed
the
ananthsub/partial-ckpt-e2e
branch
from
October 1, 2026 22:05
207f588 to
afee845
Compare
ananthsub
force-pushed
the
ananthsub/partial-ckpt-e2e
branch
from
October 2, 2026 13:22
afee845 to
6a3c667
Compare
ananthsub
force-pushed
the
ananthsub/partial-ckpt-indirect-prompt-injection
branch
from
October 2, 2026 13:22
e297cd8 to
3bd2b9c
Compare
ananthsub
force-pushed
the
ananthsub/partial-ckpt-e2e
branch
from
October 2, 2026 19:43
6a3c667 to
f3ade85
Compare
ananthsub
force-pushed
the
ananthsub/partial-ckpt-indirect-prompt-injection
branch
from
October 2, 2026 19:43
3bd2b9c to
2304606
Compare
The indirect prompt injection resources server keeps a mutable environment per cookie session, so it now declares checkpoint_mode "exported" and implements the three session hooks: export each live session's environment, restore a batch only after every state validates, and drop a retired session. Verification keeps the default "wait" mode because it deletes the session. Export leaves out a session the server already dropped, such as one whose verification raised, so a later commit does not fail on it. The environment is copied through JSON, which keeps its key order: tool outputs serialize the environment as stored, so a restored session answers byte for byte as the original would. Ported from #3548 onto the v2 checkpoint hooks. The execution identity map, header identity lookups, mutation receipts, revisions, and the verify identity check are not carried: the v2 participant keys sessions by cookie session ID and relies on ordering instead of receipts. Signed-off-by: Ananth Subramaniam <ansubramania@nvidia.com>
ananthsub
force-pushed
the
ananthsub/partial-ckpt-e2e
branch
from
October 2, 2026 21:17
f3ade85 to
ca27fd2
Compare
ananthsub
force-pushed
the
ananthsub/partial-ckpt-indirect-prompt-injection
branch
from
October 2, 2026 21:17
2304606 to
41588ad
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed and why
The indirect prompt injection resources server keeps a mutable environment for each session: tool calls update patient charts, send messages, and so on. Before this change it was restart-only by default, so every live session blocked a checkpoint until its rollout was retired and restarted from its input. Now a rollout interrupted by a crash can continue from its last checkpoint.
checkpoint_mode = "exported"and implements the three session hooks, keyed by the cookie session ID:export_session_statesreturns each live session's environment as anIPICheckpointState;restore_session_statesvalidates every state first, then installs them all, so an invalid state installs nothing;retire_session_statedrops the session.checkpoint_verifystays at the defaultwait, because/verifydeletes the session's environment and cannot be replayed./verifydrops the session in itsfinallyblock even when verification raises, and the participant only stops tracking a session on a successful/verify. Without this, the next commit after a failed verification would fail.How it works
Where this PR sits in the overall flow
The highlighted part is what this PR adds.
flowchart LR C["Controller<br/>NeMo RL, or rollout collection"] CO["Coordination<br/>prepare, commit, restore, resume, retire"] K["Control plane on every server<br/>phases, fencing, lease, storage"] subgraph G["One participant per Gym server"] E["Environment server<br/>episode steps"] M["Policy model<br/>held responses, generation cuts"] A["Agent<br/>sessions parked at boundaries"] R["Resources server<br/>session state"] end W["Inference worker<br/>stages cut prefixes"] D[("Checkpoint directory<br/>records, then manifest")] C --> CO --> K K --> E & M & A & R M --> W G --> D classDef this fill:#fde68a,stroke:#b45309,stroke-width:2px,color:#1f2937 class R thisOne checkpoint, a crash, and the restore, end to end:
This PR
Each session's environment, saved at a checkpoint. It is copied through JSON, which keeps its key order, so a restored session answers byte for byte as the original would.
Where this sits in the stack
This PR builds on the partial-rollout checkpointing stack: #3882 (core) through #3889 (end-to-end suite), plus #3893 (rollout collection). It is one of five PRs that port the environments the old stack checkpointed onto the new hooks. Each one is based on #3889 and can be reviewed on its own, except Blackjack, which builds on the Gymnasium fix:
ananthsub/partial-ckpt-workplace-assistant): feat(checkpoint): checkpoint Workplace Assistant sessionsananthsub/partial-ckpt-gymnasium): fix(gymnasium): build Gymnasium servers on the shared resources server setupananthsub/partial-ckpt-blackjack): feat(checkpoint): export Blackjack game state for partial-rollout checkpoints (on the Gymnasium PR)ananthsub/partial-ckpt-indirect-prompt-injection): feat(checkpoint): export indirect prompt injection session state (this PR)ananthsub/partial-ckpt-proof-refinement): feat(checkpoint): continue proof refinement agent turns from their boundariesRelationship to the old stack
This supersedes #3548, which added the same recovery on the old (v1) checkpoint stack. Ported from #3548 onto the v2 checkpoint hooks.
Carried over:
Not carried, because the v2 stack removes the mechanisms they served:
execution_to_sessionmap and the identity lookups from rollout headers, since v2 keys resources state by the cookie session ID;/verify;Issue
No separate issue. This is part of the partial-rollout checkpointing work, as the port of draft #3548.
Validation
pytest -q resources_servers/indirect_prompt_injection/tests: 282 passed, including 16 new tests intest_checkpoint.py. They drive the server through its real/ng-control/v1/checkpoint/*routes over ASGI:/verify. Tool outputs and the verify reply match an uncheckpointed run exactly. After verification, the restored server and its participant hold no session;stale_attemptwhile another session keeps working;pytest -q tests/unit_tests/test_checkpoint_*.py(withRAY_TMPDIR=/tmp): 115 passed.ruff checkandruff formaton the server: clean.pre-commit run --fileson the changed files: passed.Rollout evidence
Pending. No model rollout has been run yet. A smoke run should start the indirect prompt injection environment with checkpointing on, take a checkpoint mid-episode, restart the resources server from that checkpoint, and confirm the rollouts continue and their rewards match uncheckpointed runs. End-to-end use also needs the agent lane.
Compatibility
schema_version: 1, the environment as a JSON object) is new and does not read checkpoints written by feat(checkpoint): add indirect prompt injection state recovery #3548.