Skip to content

[Security] Document StatelessProcessGroup security concerns #17591

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

russellb
Copy link
Member

@russellb russellb commented May 2, 2025

A recent PR, #15988, improved StatelessProcessGroup to ensure the
torch.distributed TCPStore uses the specified IP address unless of
binding to all interfaces. Upon closer inspection, this is quite
important, as the way vllm is using this TCPStore includes pickled data,
so malicious access to the TCPStore would allow remote code execution on
a vllm host.

Update some places throughout the code base to reflect the importance of
specifying a secured IP addres for use with this interface.

Finally, fix a couple places in tests to explicitly use localhost
instead of the IP we find that's (probably) the one used for the host's
default route. Otherwise, a host running these tests is briefly
vulnerable on the IP address chosen.

Signed-off-by: Russell Bryant [email protected]

@russellb russellb requested a review from youkaichao as a code owner May 2, 2025 14:55
Copy link

github-actions bot commented May 2, 2025

👋 Hi! Thank you for contributing to the vLLM project.

💬 Join our developer Slack at https://slack.vllm.ai to discuss your PR in #pr-reviews, coordinate on features in #feat- channels, or join special interest groups in #sig- channels.

Just a reminder: PRs would not trigger full CI run by default. Instead, it would only run fastcheck CI which starts running only a small and essential subset of CI tests to quickly catch errors. You can run other CI tests on top of those by going to your fastcheck build on Buildkite UI (linked in the PR checks section) and unblock them. If you do not have permission to unblock, ping simon-mo or khluu to add you in our Buildkite org.

Once the PR is approved and ready to go, your PR reviewer(s) can run CI to test the changes comprehensively before merging.

To run CI, PR reviewers can either: Add ready label to the PR or enable auto-merge.

🚀

@mergify mergify bot added the documentation Improvements or additions to documentation label May 2, 2025
@russellb russellb requested a review from njhill May 2, 2025 14:57
@russellb russellb force-pushed the statelessprocessgroup-security branch from f320c43 to 3e3ac95 Compare May 2, 2025 16:49
@simon-mo simon-mo added the ready ONLY add when PR is ready to merge/full CI is needed label May 12, 2025
@simon-mo simon-mo enabled auto-merge (squash) May 12, 2025 18:26
A recent PR, vllm-project#15988, improved StatelessProcessGroup to ensure the
torch.distributed TCPStore uses the specified IP address unless of
binding to all interfaces. Upon closer inspection, this is quite
important, as the way vllm is using this TCPStore includes pickled data,
so malicious access to the TCPStore would allow remote code execution on
a vllm host.

Update some places throughout the code base to reflect the importance of
specifying a secured IP addres for use with this interface.

Finally, fix a couple places in tests to explicitly use localhost
instead of the IP we find that's (probably) the one used for the host's
default route. Otherwise, a host running these tests is briefly
vulnerable on the IP address chosen.

Signed-off-by: Russell Bryant <[email protected]>
@russellb russellb force-pushed the statelessprocessgroup-security branch from 3e3ac95 to ba86dd6 Compare May 13, 2025 12:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation ready ONLY add when PR is ready to merge/full CI is needed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants