Fickle: Firewalled Pickle
People abuse pickle. Especially researchers. Pickle is not secure. Published datasets and ML training weights are often distributed as pickle files (or formats which use pickle files, such as PyTorch checkpoint.ckpt files). Sometimes it is the only format that they are available in.
Examples
Loading basic types is easy:
>>> from fickle import DefaultFirewall
>>> import pickle
>>>
>>> my_picked_data = pickle.dumps({"list": [1, 2, "three", b"four"]})
>>>
>>> firewall = DefaultFirewall()
>>> firewall.loads(my_picked_data)
{'list': [1, 2, 'three', b'four']}
Safely loading PyTorch checkpoint files into numpy arrays is just as easy:
>>> from fickle.ext.pytorch import fake_torch_load_zipped
>>> from zipfile import ZipFile
>>>
>>> zf = ZipFile("/path/to/sd-v1-4.ckpt")
>>> ckpt = fake_torch_load_zipped(zf)
>>> tensor = ckpt["state_dict"]["model.diffusion_model.output_blocks.3.1.norm.weight"]
>>> tensor.array
array([0.39097363, 0.3898967 , 0.35191917, ..., 0.41924757, 0.4031702 ,
0.37156993], dtype=float32)
You can, optionally, even use marshmallow for validation!
Alternatives
| fickle | picklemagic | pikara | |
|---|---|---|---|
Does not rely on pickle._Unpickler? |
✅ | ❌ | ✅ |
Uses pickletools.genops |
yes | no | yes |
| Can load without executing? | ✅ | ✅ | ? |
| Forbid importing arbitrary objects? | ✅ | ✅ | ? |
Forbid calling list.append/set.add/etc? |
✅ | ❌ | ? |
| Forbid calling all methods by default? | ✅ | ❌ | ? |
| Can create dangerous circular structures? | ✅ | ✅ | ? |
| Safe against billion laughs DoS attack? | ? | ? | ? |
| Full support for all pickle opcodes? | ❌ | ✅ | ? |
| Has unit tests? | ✅ | ❌ | ✅ |
| Stable API? | ❌ | ✅ | ✅ |
Metadata
Release files for fickle 0.2.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| fickle-0.2.2.tar.gz | 17.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| fickle-0.2.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 34.4 kB
Release files / fickle-0.2.2.tar.gz
| Download URL | fickle-0.2.2.tar.gz |
|---|---|
| Size | 17.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
9750b8253961009d693c13fd303e5c91d31a210d12ba551b9b5884ec3d61b3de
|
|
BLAKE2b-256 checksum How to use checksums |
602a6d34225e88a56850d3646ab0f24b0cdd3510b46457b5c118797b92f69b59
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.3.0 pkginfo/1.4.2 requests/2.25.1 setuptools/52.0.0 requests-toolbelt/0.9.1 tqdm/4.57.0 CPython/3.9.2
|
Release files / fickle-0.2.2-py3-none-any.whl
| Download URL | fickle-0.2.2-py3-none-any.whl |
|---|---|
| Size | 16.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
df4bb990d93605e10e27b4a923240d081cccb29ef5399a5dda7bf0dc61aff3c9
|
|
BLAKE2b-256 checksum How to use checksums |
ed389e293139e09f0ce0bac6acd58aefea868f4403979938d258b0d160b892a5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.3.0 pkginfo/1.4.2 requests/2.25.1 setuptools/52.0.0 requests-toolbelt/0.9.1 tqdm/4.57.0 CPython/3.9.2
|