From 9ce0b6f39eb74318b0534d9f76edb2d040052db9 Mon Sep 17 00:00:00 2001 From: Daniel Han Date: Wed, 1 Jul 2026 06:34:51 +0000 Subject: [PATCH 1/9] Pin llm-compressor auto-install to a vetted version range install_llm_compressor() auto-installs llm-compressor on first use of an FP8/FP4 compressed export when it is not already present. The install command used the bare package name, so pip resolved to whatever the configured index served; a compromised, dependency-confused, or inflated-version ("999.0.0") release could then run under the Unsloth process at install and import time. Bound the automatic install to a vetted range (_LLM_COMPRESSOR_SPEC = "llmcompressor>=0.8.0,<0.13"), which the oneshot / QuantizationModifier API this uses supports, so pip can no longer jump to an arbitrary future or inflated version. An already-installed newer llm-compressor is still used as-is (the import short-circuits), so this only constrains the auto-install, never a user's own install. Add UNSLOTH_DISABLE_LLM_COMPRESSOR_AUTOINSTALL=1 to forbid the automatic install entirely and require a manual, vetted install, for locked-down or air-gapped environments. Update the manual-install hints to the pinned spec. Add tests/saving/test_llm_compressor_install_pin.py: static (ast) guards that the spec stays a bounded pin, that the install command never passes an unpinned llmcompressor literal, and that the opt-out env gate is evaluated before any install runs. --- .../saving/test_llm_compressor_install_pin.py | 88 +++++++++++++++++++ unsloth/save.py | 42 +++++++-- 2 files changed, 122 insertions(+), 8 deletions(-) create mode 100644 tests/saving/test_llm_compressor_install_pin.py diff --git a/tests/saving/test_llm_compressor_install_pin.py b/tests/saving/test_llm_compressor_install_pin.py new file mode 100644 index 0000000000..2e2aafa498 --- /dev/null +++ b/tests/saving/test_llm_compressor_install_pin.py @@ -0,0 +1,88 @@ +"""Guard that the automatic first-use install of llm-compressor stays version-pinned. + +``install_llm_compressor()`` auto-installs llm-compressor when a user requests an FP8/FP4 +compressed export and it is not already present. A bare ``pip install llmcompressor`` would resolve +to whatever the configured package index serves, so a compromised, dependency-confused, or +inflated-version ("999.0.0") release could run under the Unsloth process at install/import time. + +These are static checks (no import, no network, no GPU), mirroring test_save_shell_injection.py: +they keep the install command bounded to a vetted range and keep the opt-out env gate in place so +locked-down environments can forbid the automatic install entirely. +""" + +from __future__ import annotations + +import ast +from pathlib import Path + +SAVE_PY = Path(__file__).resolve().parents[2] / "unsloth" / "save.py" + +_ENV_FLAG = "UNSLOTH_DISABLE_LLM_COMPRESSOR_AUTOINSTALL" + + +def _module() -> ast.Module: + return ast.parse(SAVE_PY.read_text(encoding = "utf-8"), filename = str(SAVE_PY)) + + +def _get_function(name: str) -> ast.FunctionDef: + for node in ast.walk(_module()): + if isinstance(node, ast.FunctionDef) and node.name == name: + return node + raise AssertionError(f"Function {name} not found in save.py") + + +def _spec_value(): + for node in ast.walk(_module()): + if isinstance(node, ast.Assign) and isinstance(node.value, ast.Constant): + if any(isinstance(t, ast.Name) and t.id == "_LLM_COMPRESSOR_SPEC" for t in node.targets): + return node.value.value + return None + + +def _first_lineno(fn: ast.AST, predicate) -> int | None: + lines = [n.lineno for n in ast.walk(fn) if predicate(n) and hasattr(n, "lineno")] + return min(lines) if lines else None + + +def test_spec_is_a_bounded_pin() -> None: + spec = _spec_value() + assert spec is not None, "_LLM_COMPRESSOR_SPEC must be defined at module scope" + assert "llmcompressor" in spec, f"spec must name llmcompressor, got {spec!r}" + # A lower and an upper bound: pip cannot jump to an arbitrary (e.g. inflated) future release. + assert ">=" in spec and "<" in spec, f"spec must have lower and upper bounds, got {spec!r}" + + +def test_install_command_uses_pinned_spec_not_bare_name() -> None: + fn = _get_function("install_llm_compressor") + # No argv list may pass the bare, unpinned package literal "llmcompressor". + for node in ast.walk(fn): + if isinstance(node, ast.List): + for elt in node.elts: + if isinstance(elt, ast.Constant) and elt.value == "llmcompressor": + raise AssertionError( + "install command must not pass an unpinned 'llmcompressor' literal; " + "use the bounded _LLM_COMPRESSOR_SPEC" + ) + names = {n.id for n in ast.walk(fn) if isinstance(n, ast.Name)} + assert "_LLM_COMPRESSOR_SPEC" in names, "install command must reference _LLM_COMPRESSOR_SPEC" + + +def test_optout_env_gate_precedes_subprocess_install() -> None: + fn = _get_function("install_llm_compressor") + env_line = _first_lineno(fn, lambda n: isinstance(n, ast.Constant) and n.value == _ENV_FLAG) + assert env_line is not None, f"{_ENV_FLAG} opt-out must be checked in install_llm_compressor" + + def _is_check_call(n: ast.AST) -> bool: + return ( + isinstance(n, ast.Call) + and isinstance(n.func, ast.Attribute) + and n.func.attr == "check_call" + and isinstance(n.func.value, ast.Name) + and n.func.value.id == "subprocess" + ) + + install_line = _first_lineno(fn, _is_check_call) + assert install_line is not None, "expected a subprocess.check_call install in the function" + assert env_line < install_line, ( + "the auto-install opt-out must be evaluated before any package install runs" + ) diff --git a/unsloth/save.py b/unsloth/save.py index 76bc6aa733..36eba890d7 100644 --- a/unsloth/save.py +++ b/unsloth/save.py @@ -1363,11 +1363,24 @@ def install_python_non_blocking(packages = []): return run_installer +# Version-pin the automatic first-use install of llm-compressor. Without a bound, +# `pip install llmcompressor` resolves to whatever the configured index offers, so a compromised, +# dependency-confused, or inflated-version ("999.0.0") release could be pulled and executed under +# the Unsloth process at install/import time. The oneshot / QuantizationModifier API this uses is +# stable across the 0.8-0.12 line; bump the ceiling deliberately after testing a newer series +# rather than tracking latest automatically. An already-installed newer llm-compressor is used +# as-is (the import below short-circuits), so this bound only constrains what gets auto-installed, +# never what the user installed themselves. +_LLM_COMPRESSOR_SPEC = "llmcompressor>=0.8.0,<0.13" + + def install_llm_compressor(): """Import llm-compressor, installing it on first use for FP8/FP4 export. - Pins the current torch + transformers so pip does not upgrade them (a plain install pulls - transformers>=5 and breaks Unsloth). Returns (oneshot, QuantizationModifier). + Installs a version-pinned llm-compressor (``_LLM_COMPRESSOR_SPEC``) and pins the current torch + + transformers so pip does not upgrade them (a plain install pulls transformers>=5 and breaks + Unsloth). Set ``UNSLOTH_DISABLE_LLM_COMPRESSOR_AUTOINSTALL=1`` to forbid the automatic install + and require a manual, vetted install instead. Returns (oneshot, QuantizationModifier). """ try: from llmcompressor import oneshot @@ -1376,9 +1389,22 @@ def install_llm_compressor(): except Exception: pass + # Opt-out for locked-down / air-gapped setups: never reach out to a package index + # automatically; require the user to install the pinned spec themselves. + if os.environ.get("UNSLOTH_DISABLE_LLM_COMPRESSOR_AUTOINSTALL", "0").lower() not in ( + "0", "", "false", "no", + ): + raise RuntimeError( + "Unsloth: llm-compressor is required for FP8/FP4 compressed export but is not " + "installed, and automatic installation is disabled via " + "UNSLOTH_DISABLE_LLM_COMPRESSOR_AUTOINSTALL. Install it manually with:\n" + f" uv pip install --python {sys.executable} '{_LLM_COMPRESSOR_SPEC}'\n" + "(pin torch and transformers to your current versions to avoid upgrading them)." + ) + print( "Unsloth: Installing llm-compressor for FP8/FP4 export " - "(pinning your torch + transformers so they are not upgraded). " + f"({_LLM_COMPRESSOR_SPEC}; pinning your torch + transformers so they are not upgraded). " "This can take a few minutes..." ) import importlib @@ -1401,13 +1427,13 @@ def install_llm_compressor(): import importlib.util if importlib.util.find_spec("pip") is not None: - cmd = [sys.executable, "-m", "pip", "install", "llmcompressor"] + cmd = [sys.executable, "-m", "pip", "install", _LLM_COMPRESSOR_SPEC] elif shutil.which("uv") is not None: - cmd = ["uv", "pip", "install", "--python", sys.executable, "llmcompressor"] + cmd = ["uv", "pip", "install", "--python", sys.executable, _LLM_COMPRESSOR_SPEC] else: raise RuntimeError( "Unsloth: cannot install llm-compressor because this environment has neither pip nor " - f"uv. Install it manually with:\n uv pip install --python {sys.executable} llmcompressor\n" + f"uv. Install it manually with:\n uv pip install --python {sys.executable} '{_LLM_COMPRESSOR_SPEC}'\n" "(pin torch and transformers to your current versions to avoid upgrading them)." ) cpath = None @@ -1421,8 +1447,8 @@ def install_llm_compressor(): except subprocess.CalledProcessError as e: raise RuntimeError( "Unsloth: Failed to install llm-compressor. Install it manually with:\n" - f" uv pip install --python {sys.executable} llmcompressor\n" - f"or, if pip is available:\n {sys.executable} -m pip install llmcompressor\n" + f" uv pip install --python {sys.executable} '{_LLM_COMPRESSOR_SPEC}'\n" + f"or, if pip is available:\n {sys.executable} -m pip install '{_LLM_COMPRESSOR_SPEC}'\n" "(pin torch and transformers to your current versions to avoid upgrading them).\n" f"Underlying error: {e}" ) From 0a28144f964e945a202b34ea2e743b3b97bac1a9 Mon Sep 17 00:00:00 2001 From: "pre-commit-ci[bot]" <66853113+pre-commit-ci[bot]@users.noreply.github.com> Date: Wed, 1 Jul 2026 06:35:36 +0000 Subject: [PATCH 2/9] [pre-commit.ci] auto fixes from pre-commit.com hooks for more information, see https://pre-commit.ci --- tests/saving/test_llm_compressor_install_pin.py | 10 ++++++---- unsloth/save.py | 5 ++++- 2 files changed, 10 insertions(+), 5 deletions(-) diff --git a/tests/saving/test_llm_compressor_install_pin.py b/tests/saving/test_llm_compressor_install_pin.py index 2e2aafa498..fc3f30fee0 100644 --- a/tests/saving/test_llm_compressor_install_pin.py +++ b/tests/saving/test_llm_compressor_install_pin.py @@ -34,7 +34,9 @@ def _get_function(name: str) -> ast.FunctionDef: def _spec_value(): for node in ast.walk(_module()): if isinstance(node, ast.Assign) and isinstance(node.value, ast.Constant): - if any(isinstance(t, ast.Name) and t.id == "_LLM_COMPRESSOR_SPEC" for t in node.targets): + if any( + isinstance(t, ast.Name) and t.id == "_LLM_COMPRESSOR_SPEC" for t in node.targets + ): return node.value.value return None @@ -83,6 +85,6 @@ def test_optout_env_gate_precedes_subprocess_install() -> None: install_line = _first_lineno(fn, _is_check_call) assert install_line is not None, "expected a subprocess.check_call install in the function" - assert env_line < install_line, ( - "the auto-install opt-out must be evaluated before any package install runs" - ) + assert ( + env_line < install_line + ), "the auto-install opt-out must be evaluated before any package install runs" diff --git a/unsloth/save.py b/unsloth/save.py index 36eba890d7..f00407b742 100644 --- a/unsloth/save.py +++ b/unsloth/save.py @@ -1392,7 +1392,10 @@ def install_llm_compressor(): # Opt-out for locked-down / air-gapped setups: never reach out to a package index # automatically; require the user to install the pinned spec themselves. if os.environ.get("UNSLOTH_DISABLE_LLM_COMPRESSOR_AUTOINSTALL", "0").lower() not in ( - "0", "", "false", "no", + "0", + "", + "false", + "no", ): raise RuntimeError( "Unsloth: llm-compressor is required for FP8/FP4 compressed export but is not " From 7d91e51ac97a0c0983a546eab68a058c4001395f Mon Sep 17 00:00:00 2001 From: Daniel Han Date: Wed, 1 Jul 2026 07:41:44 +0000 Subject: [PATCH 3/9] Loosen llm-compressor auto-install ceiling to <1.0 so new models still export The earlier <0.13 ceiling was too tight: brand-new architectures (for example Qwen3_5ForConditionalGeneration / qwen3_5, gemma-4 MoE) can require a newer llm-compressor, and _unsloth_save_compressed_tensors already fails with "requires a newer llm-compressor" when a scheme is unavailable. Capping the auto-install at 0.12 would block getting that newer release and break compressed export for new models. Widen to llmcompressor>=0.8.0,<1.0. pip still auto-installs the latest 0.x (where new-architecture support lands), while the <1.0 ceiling continues to block a jump to an inflated-version ("999.0.0") or 1.0+ dependency-confusion release. An already-installed newer llm-compressor is still used as-is (the import short-circuits), and UNSLOTH_DISABLE_LLM_COMPRESSOR_AUTOINSTALL still forbids the automatic install entirely for locked-down environments. --- unsloth/save.py | 21 ++++++++++++--------- 1 file changed, 12 insertions(+), 9 deletions(-) diff --git a/unsloth/save.py b/unsloth/save.py index f00407b742..4355d77f6d 100644 --- a/unsloth/save.py +++ b/unsloth/save.py @@ -1363,15 +1363,18 @@ def install_python_non_blocking(packages = []): return run_installer -# Version-pin the automatic first-use install of llm-compressor. Without a bound, -# `pip install llmcompressor` resolves to whatever the configured index offers, so a compromised, -# dependency-confused, or inflated-version ("999.0.0") release could be pulled and executed under -# the Unsloth process at install/import time. The oneshot / QuantizationModifier API this uses is -# stable across the 0.8-0.12 line; bump the ceiling deliberately after testing a newer series -# rather than tracking latest automatically. An already-installed newer llm-compressor is used -# as-is (the import below short-circuits), so this bound only constrains what gets auto-installed, -# never what the user installed themselves. -_LLM_COMPRESSOR_SPEC = "llmcompressor>=0.8.0,<0.13" +# Bound the automatic first-use install of llm-compressor to its current 0.x series. Without any +# bound, `pip install llmcompressor` resolves to whatever the configured index offers, so a +# compromised, dependency-confused, or inflated-version ("999.0.0") release could be pulled and +# executed under the Unsloth process at install/import time; the "<1.0" ceiling blocks that jump. +# The floor keeps the oneshot / QuantizationModifier API this uses. Crucially the range still lets +# pip pick up new 0.x releases, which is where support for brand-new architectures lands (the gate +# below can require a newer llm-compressor for newer schemes/models) -- an exact pin would break +# exporting new models. Bump the ceiling deliberately when llm-compressor reaches 1.0 so a new +# major is vetted before it is auto-installed. An already-installed newer llm-compressor is used +# as-is (the import below short-circuits), so this only constrains the auto-install, never what +# the user installed themselves. +_LLM_COMPRESSOR_SPEC = "llmcompressor>=0.8.0,<1.0" def install_llm_compressor(): From fe5eee6a363591831253a4a079f56ff4b96f1913 Mon Sep 17 00:00:00 2001 From: Daniel Han Date: Wed, 1 Jul 2026 08:57:32 +0000 Subject: [PATCH 4/9] Lower llm-compressor floor to 0.6.0 so supported old torch still resolves The >=0.8.0 floor conflicts with the torch this install pins in its constraints file. Unsloth supports torch>=2.4, but llm-compressor 0.7.0+ require torch>=2.7 (0.10+ need >=2.9, 0.12+ need >=2.10). On a supported torch 2.4-2.6 box pip then has no candidate in [0.8.0, 1.0) and FP8/FP4 export fails before quantization. Lower the floor to 0.6.0 (its metadata only needs torch>=1.7), which never conflicts with any supported torch. pip still prefers the newest compatible release, so modern torch continues to get the latest 0.x (0.12.0). The <1.0 ceiling that blocks an inflated-version supply-chain jump is unchanged. Add a regression test asserting the floor stays <= 0.6.0. --- .../saving/test_llm_compressor_install_pin.py | 20 +++++++++++++++++ unsloth/save.py | 22 ++++++++++++------- 2 files changed, 34 insertions(+), 8 deletions(-) diff --git a/tests/saving/test_llm_compressor_install_pin.py b/tests/saving/test_llm_compressor_install_pin.py index fc3f30fee0..89fdf52f84 100644 --- a/tests/saving/test_llm_compressor_install_pin.py +++ b/tests/saving/test_llm_compressor_install_pin.py @@ -54,6 +54,26 @@ def test_spec_is_a_bounded_pin() -> None: assert ">=" in spec and "<" in spec, f"spec must have lower and upper bounds, got {spec!r}" +def test_floor_stays_compatible_with_supported_torch() -> None: + """The floor must not require a torch newer than the oldest torch Unsloth supports (>=2.4). + + llm-compressor 0.7.0+ require torch>=2.7 (0.10+ >=2.9, 0.12+ >=2.10); only <=0.6.x allows + torch<2.7. Since install_llm_compressor() pins the current torch in the constraints file, a + floor above 0.6.0 leaves pip with no candidate on a supported torch 2.4-2.6 box and breaks + FP8/FP4 export. Keep the floor at or below 0.6.0. + """ + from packaging.requirements import Requirement + from packaging.version import Version + + req = Requirement(_spec_value()) + lowers = [Version(s.version) for s in req.specifier if s.operator in (">=", "==", "~=")] + assert lowers, "spec must declare a lower bound" + assert max(lowers) <= Version("0.6.0"), ( + f"floor {max(lowers)} requires a torch newer than Unsloth's minimum (2.4); " + "llm-compressor >0.6.0 needs torch>=2.7. Keep the floor <= 0.6.0." + ) + + def test_install_command_uses_pinned_spec_not_bare_name() -> None: fn = _get_function("install_llm_compressor") # No argv list may pass the bare, unpinned package literal "llmcompressor". diff --git a/unsloth/save.py b/unsloth/save.py index 4355d77f6d..b9a7cb1dfc 100644 --- a/unsloth/save.py +++ b/unsloth/save.py @@ -1367,14 +1367,20 @@ def install_python_non_blocking(packages = []): # bound, `pip install llmcompressor` resolves to whatever the configured index offers, so a # compromised, dependency-confused, or inflated-version ("999.0.0") release could be pulled and # executed under the Unsloth process at install/import time; the "<1.0" ceiling blocks that jump. -# The floor keeps the oneshot / QuantizationModifier API this uses. Crucially the range still lets -# pip pick up new 0.x releases, which is where support for brand-new architectures lands (the gate -# below can require a newer llm-compressor for newer schemes/models) -- an exact pin would break -# exporting new models. Bump the ceiling deliberately when llm-compressor reaches 1.0 so a new -# major is vetted before it is auto-installed. An already-installed newer llm-compressor is used -# as-is (the import below short-circuits), so this only constrains the auto-install, never what -# the user installed themselves. -_LLM_COMPRESSOR_SPEC = "llmcompressor>=0.8.0,<1.0" +# The range still lets pip pick up new 0.x releases, which is where support for brand-new +# architectures lands (the gate below can require a newer llm-compressor for newer schemes/models) +# -- an exact pin would break exporting new models. Bump the ceiling deliberately when +# llm-compressor reaches 1.0 so a new major is vetted before it is auto-installed. +# +# The floor is 0.6.0 (its metadata only needs torch>=1.7) so it never conflicts with the torch this +# install pins in the constraints file below: Unsloth supports torch>=2.4, but llm-compressor +# 0.7.0+ require torch>=2.7 (0.10+ need >=2.9, 0.12+ need >=2.10). A higher floor would leave pip +# with no candidate on a supported torch 2.4-2.6 box and break FP8/FP4 export before quantization. +# pip still prefers the newest compatible release, so modern torch gets the latest 0.x anyway. +# +# An already-installed newer llm-compressor is used as-is (the import below short-circuits), so this +# only constrains the auto-install, never what the user installed themselves. +_LLM_COMPRESSOR_SPEC = "llmcompressor>=0.6.0,<1.0" def install_llm_compressor(): From b86d9ff8217270098bef7b817bf26e3f38d50769 Mon Sep 17 00:00:00 2001 From: Daniel Han Date: Wed, 1 Jul 2026 09:39:45 +0000 Subject: [PATCH 5/9] Cap llm-compressor auto-install ceiling to a vetted minor (<0.13) A bare <1.0 ceiling still admits any 0.x, so an inflated "0.999.0" served by a compromised or misconfigured index would win pip's highest-version selection -- the same dependency-confusion this pin is meant to block. Cap the ceiling to the current vetted minor (<0.13) so that jump is blocked; bump it deliberately, after vetting, when a newer llm-compressor is needed (e.g. for a brand-new architecture scheme). Current new models are unaffected: 0.12.0 is < 0.13 and supports them. The 0.6.0 floor (torch>=1.7 compatible) is unchanged, so resolution still works across Unsloth's whole supported torch range (2.4 -> 0.6.0 ... 2.12 -> 0.12.0). Add a regression test asserting the ceiling admits the current vetted release but blocks an inflated 0.x and the next major. --- .../saving/test_llm_compressor_install_pin.py | 16 ++++++++++++++ unsloth/save.py | 21 ++++++++++--------- 2 files changed, 27 insertions(+), 10 deletions(-) diff --git a/tests/saving/test_llm_compressor_install_pin.py b/tests/saving/test_llm_compressor_install_pin.py index 89fdf52f84..10e1c93fe0 100644 --- a/tests/saving/test_llm_compressor_install_pin.py +++ b/tests/saving/test_llm_compressor_install_pin.py @@ -54,6 +54,22 @@ def test_spec_is_a_bounded_pin() -> None: assert ">=" in spec and "<" in spec, f"spec must have lower and upper bounds, got {spec!r}" +def test_ceiling_blocks_inflated_versions() -> None: + """The ceiling must cap to a vetted minor, not just <1.0. + + A bare <1.0 still admits any 0.x, so an inflated 0.999.0 served by a compromised/misconfigured + index would win pip's highest-version selection -- the exact dependency-confusion this pin is + meant to block. Assert the current-latest vetted release resolves while an inflated 0.x and the + next major do not. + """ + from packaging.requirements import Requirement + + spec = Requirement(_spec_value()).specifier + assert spec.contains("0.12.0"), "the current vetted release must resolve" + assert not spec.contains("0.999.0"), "an inflated 0.x must be blocked (cap to a vetted minor)" + assert not spec.contains("1.0.0"), "a new major must not be auto-installed" + + def test_floor_stays_compatible_with_supported_torch() -> None: """The floor must not require a torch newer than the oldest torch Unsloth supports (>=2.4). diff --git a/unsloth/save.py b/unsloth/save.py index b9a7cb1dfc..a4982cb169 100644 --- a/unsloth/save.py +++ b/unsloth/save.py @@ -1363,24 +1363,25 @@ def install_python_non_blocking(packages = []): return run_installer -# Bound the automatic first-use install of llm-compressor to its current 0.x series. Without any -# bound, `pip install llmcompressor` resolves to whatever the configured index offers, so a -# compromised, dependency-confused, or inflated-version ("999.0.0") release could be pulled and -# executed under the Unsloth process at install/import time; the "<1.0" ceiling blocks that jump. -# The range still lets pip pick up new 0.x releases, which is where support for brand-new -# architectures lands (the gate below can require a newer llm-compressor for newer schemes/models) -# -- an exact pin would break exporting new models. Bump the ceiling deliberately when -# llm-compressor reaches 1.0 so a new major is vetted before it is auto-installed. +# Bound the automatic first-use install of llm-compressor to a vetted window. Without a bound, +# `pip install llmcompressor` resolves to whatever the configured index offers, so a compromised, +# dependency-confused, or inflated-version release could be pulled and executed under the Unsloth +# process at install/import time. The ceiling must cap to a vetted minor, NOT just "<1.0": every 0.x +# version satisfies "<1.0", so an inflated "0.999.0" on a malicious/misconfigured index would still +# win pip's highest-version selection. "<0.13" caps to the current 0.12 series and blocks that jump. +# Bump this ceiling deliberately (after vetting) when a newer llm-compressor is needed -- e.g. for a +# brand-new architecture whose scheme the installed build does not yet support. Current new models +# still resolve: 0.12.0 is < 0.13 and supports them. # # The floor is 0.6.0 (its metadata only needs torch>=1.7) so it never conflicts with the torch this # install pins in the constraints file below: Unsloth supports torch>=2.4, but llm-compressor # 0.7.0+ require torch>=2.7 (0.10+ need >=2.9, 0.12+ need >=2.10). A higher floor would leave pip # with no candidate on a supported torch 2.4-2.6 box and break FP8/FP4 export before quantization. -# pip still prefers the newest compatible release, so modern torch gets the latest 0.x anyway. +# pip still prefers the newest compatible release, so modern torch gets the latest vetted 0.x anyway. # # An already-installed newer llm-compressor is used as-is (the import below short-circuits), so this # only constrains the auto-install, never what the user installed themselves. -_LLM_COMPRESSOR_SPEC = "llmcompressor>=0.6.0,<1.0" +_LLM_COMPRESSOR_SPEC = "llmcompressor>=0.6.0,<0.13" def install_llm_compressor(): From 413e5f844db663214302d939ddc7aaed69426dd4 Mon Sep 17 00:00:00 2001 From: Daniel Han Date: Wed, 1 Jul 2026 09:47:49 +0000 Subject: [PATCH 6/9] Trim comments in the llm-compressor pin (comment-only, no code change) --- .../saving/test_llm_compressor_install_pin.py | 30 +++--------------- unsloth/save.py | 31 +++++-------------- 2 files changed, 12 insertions(+), 49 deletions(-) diff --git a/tests/saving/test_llm_compressor_install_pin.py b/tests/saving/test_llm_compressor_install_pin.py index 10e1c93fe0..b8b92b1f7e 100644 --- a/tests/saving/test_llm_compressor_install_pin.py +++ b/tests/saving/test_llm_compressor_install_pin.py @@ -1,14 +1,6 @@ -"""Guard that the automatic first-use install of llm-compressor stays version-pinned. - -``install_llm_compressor()`` auto-installs llm-compressor when a user requests an FP8/FP4 -compressed export and it is not already present. A bare ``pip install llmcompressor`` would resolve -to whatever the configured package index serves, so a compromised, dependency-confused, or -inflated-version ("999.0.0") release could run under the Unsloth process at install/import time. - -These are static checks (no import, no network, no GPU), mirroring test_save_shell_injection.py: -they keep the install command bounded to a vetted range and keep the opt-out env gate in place so -locked-down environments can forbid the automatic install entirely. -""" +"""Static guards (no import/network/GPU, like test_save_shell_injection.py) that +install_llm_compressor()'s first-use auto-install of llm-compressor stays version-pinned to a vetted +range and keeps its opt-out env gate, so a compromised/inflated release can't be auto-pulled.""" from __future__ import annotations @@ -55,13 +47,7 @@ def test_spec_is_a_bounded_pin() -> None: def test_ceiling_blocks_inflated_versions() -> None: - """The ceiling must cap to a vetted minor, not just <1.0. - - A bare <1.0 still admits any 0.x, so an inflated 0.999.0 served by a compromised/misconfigured - index would win pip's highest-version selection -- the exact dependency-confusion this pin is - meant to block. Assert the current-latest vetted release resolves while an inflated 0.x and the - next major do not. - """ + """Cap to a vetted minor: a bare <1.0 admits any 0.x, so an inflated 0.999.0 could win pip.""" from packaging.requirements import Requirement spec = Requirement(_spec_value()).specifier @@ -71,13 +57,7 @@ def test_ceiling_blocks_inflated_versions() -> None: def test_floor_stays_compatible_with_supported_torch() -> None: - """The floor must not require a torch newer than the oldest torch Unsloth supports (>=2.4). - - llm-compressor 0.7.0+ require torch>=2.7 (0.10+ >=2.9, 0.12+ >=2.10); only <=0.6.x allows - torch<2.7. Since install_llm_compressor() pins the current torch in the constraints file, a - floor above 0.6.0 leaves pip with no candidate on a supported torch 2.4-2.6 box and breaks - FP8/FP4 export. Keep the floor at or below 0.6.0. - """ + """Floor must stay <=0.6.0: 0.7+ need torch>=2.7, but the pinned torch can be as old as 2.4.""" from packaging.requirements import Requirement from packaging.version import Version diff --git a/unsloth/save.py b/unsloth/save.py index a4982cb169..74f50e640b 100644 --- a/unsloth/save.py +++ b/unsloth/save.py @@ -1363,34 +1363,18 @@ def install_python_non_blocking(packages = []): return run_installer -# Bound the automatic first-use install of llm-compressor to a vetted window. Without a bound, -# `pip install llmcompressor` resolves to whatever the configured index offers, so a compromised, -# dependency-confused, or inflated-version release could be pulled and executed under the Unsloth -# process at install/import time. The ceiling must cap to a vetted minor, NOT just "<1.0": every 0.x -# version satisfies "<1.0", so an inflated "0.999.0" on a malicious/misconfigured index would still -# win pip's highest-version selection. "<0.13" caps to the current 0.12 series and blocks that jump. -# Bump this ceiling deliberately (after vetting) when a newer llm-compressor is needed -- e.g. for a -# brand-new architecture whose scheme the installed build does not yet support. Current new models -# still resolve: 0.12.0 is < 0.13 and supports them. -# -# The floor is 0.6.0 (its metadata only needs torch>=1.7) so it never conflicts with the torch this -# install pins in the constraints file below: Unsloth supports torch>=2.4, but llm-compressor -# 0.7.0+ require torch>=2.7 (0.10+ need >=2.9, 0.12+ need >=2.10). A higher floor would leave pip -# with no candidate on a supported torch 2.4-2.6 box and break FP8/FP4 export before quantization. -# pip still prefers the newest compatible release, so modern torch gets the latest vetted 0.x anyway. -# -# An already-installed newer llm-compressor is used as-is (the import below short-circuits), so this -# only constrains the auto-install, never what the user installed themselves. +# Bound the first-use auto-install so a compromised / inflated ("0.999.0") release can't be pulled: +# cap to the current vetted minor (bump <0.13 deliberately after vetting a newer one). Floor 0.6.0 +# keeps torch>=2.4 boxes resolvable (llm-compressor 0.7+ need torch>=2.7; torch is pinned below). _LLM_COMPRESSOR_SPEC = "llmcompressor>=0.6.0,<0.13" def install_llm_compressor(): """Import llm-compressor, installing it on first use for FP8/FP4 export. - Installs a version-pinned llm-compressor (``_LLM_COMPRESSOR_SPEC``) and pins the current torch - + transformers so pip does not upgrade them (a plain install pulls transformers>=5 and breaks - Unsloth). Set ``UNSLOTH_DISABLE_LLM_COMPRESSOR_AUTOINSTALL=1`` to forbid the automatic install - and require a manual, vetted install instead. Returns (oneshot, QuantizationModifier). + Installs a version-pinned llm-compressor, pinning the current torch + transformers so pip does + not upgrade them. Set UNSLOTH_DISABLE_LLM_COMPRESSOR_AUTOINSTALL=1 to forbid the auto-install. + Returns (oneshot, QuantizationModifier). """ try: from llmcompressor import oneshot @@ -1399,8 +1383,7 @@ def install_llm_compressor(): except Exception: pass - # Opt-out for locked-down / air-gapped setups: never reach out to a package index - # automatically; require the user to install the pinned spec themselves. + # Opt-out for locked-down / air-gapped setups: forbid the auto-install, require a manual one. if os.environ.get("UNSLOTH_DISABLE_LLM_COMPRESSOR_AUTOINSTALL", "0").lower() not in ( "0", "", From 1f4bed5b350de7e9b831c659024f92d36e52bd67 Mon Sep 17 00:00:00 2001 From: Daniel Han Date: Wed, 1 Jul 2026 10:28:58 +0000 Subject: [PATCH 7/9] Cap llm-compressor auto-install to the exact vetted patch (<=0.12.0) --- tests/saving/test_llm_compressor_install_pin.py | 6 ++++-- unsloth/save.py | 8 ++++---- 2 files changed, 8 insertions(+), 6 deletions(-) diff --git a/tests/saving/test_llm_compressor_install_pin.py b/tests/saving/test_llm_compressor_install_pin.py index b8b92b1f7e..f222f0d222 100644 --- a/tests/saving/test_llm_compressor_install_pin.py +++ b/tests/saving/test_llm_compressor_install_pin.py @@ -47,13 +47,15 @@ def test_spec_is_a_bounded_pin() -> None: def test_ceiling_blocks_inflated_versions() -> None: - """Cap to a vetted minor: a bare <1.0 admits any 0.x, so an inflated 0.999.0 could win pip.""" + """Cap to the exact vetted patch: block an inflated 0.x, a new major, and any higher in-range patch.""" from packaging.requirements import Requirement spec = Requirement(_spec_value()).specifier assert spec.contains("0.12.0"), "the current vetted release must resolve" - assert not spec.contains("0.999.0"), "an inflated 0.x must be blocked (cap to a vetted minor)" + assert not spec.contains("0.999.0"), "an inflated 0.x must be blocked" assert not spec.contains("1.0.0"), "a new major must not be auto-installed" + assert not spec.contains("0.12.1"), "a higher in-range patch must be blocked (cap to the vetted patch)" + assert not spec.contains("0.12.999"), "a crafted higher in-range patch (e.g. on a mirror) must be blocked" def test_floor_stays_compatible_with_supported_torch() -> None: diff --git a/unsloth/save.py b/unsloth/save.py index 74f50e640b..226ca5fed8 100644 --- a/unsloth/save.py +++ b/unsloth/save.py @@ -1363,10 +1363,10 @@ def install_python_non_blocking(packages = []): return run_installer -# Bound the first-use auto-install so a compromised / inflated ("0.999.0") release can't be pulled: -# cap to the current vetted minor (bump <0.13 deliberately after vetting a newer one). Floor 0.6.0 -# keeps torch>=2.4 boxes resolvable (llm-compressor 0.7+ need torch>=2.7; torch is pinned below). -_LLM_COMPRESSOR_SPEC = "llmcompressor>=0.6.0,<0.13" +# Bound the first-use auto-install so no unvetted release is pulled: not an inflated "0.999.0", nor +# a crafted higher in-range patch like "0.12.999" from a mirror. Cap to the exact vetted patch and +# bump deliberately. Floor 0.6.0 keeps torch>=2.4 resolvable (0.7+ need torch>=2.7; torch pinned below). +_LLM_COMPRESSOR_SPEC = "llmcompressor>=0.6.0,<=0.12.0" def install_llm_compressor(): From 4dfcdeb156698a2c6ef0a9a5267d863596a793ce Mon Sep 17 00:00:00 2001 From: "pre-commit-ci[bot]" <66853113+pre-commit-ci[bot]@users.noreply.github.com> Date: Wed, 1 Jul 2026 10:29:39 +0000 Subject: [PATCH 8/9] [pre-commit.ci] auto fixes from pre-commit.com hooks for more information, see https://pre-commit.ci --- tests/saving/test_llm_compressor_install_pin.py | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/tests/saving/test_llm_compressor_install_pin.py b/tests/saving/test_llm_compressor_install_pin.py index f222f0d222..c2ddfb14e2 100644 --- a/tests/saving/test_llm_compressor_install_pin.py +++ b/tests/saving/test_llm_compressor_install_pin.py @@ -54,8 +54,12 @@ def test_ceiling_blocks_inflated_versions() -> None: assert spec.contains("0.12.0"), "the current vetted release must resolve" assert not spec.contains("0.999.0"), "an inflated 0.x must be blocked" assert not spec.contains("1.0.0"), "a new major must not be auto-installed" - assert not spec.contains("0.12.1"), "a higher in-range patch must be blocked (cap to the vetted patch)" - assert not spec.contains("0.12.999"), "a crafted higher in-range patch (e.g. on a mirror) must be blocked" + assert not spec.contains( + "0.12.1" + ), "a higher in-range patch must be blocked (cap to the vetted patch)" + assert not spec.contains( + "0.12.999" + ), "a crafted higher in-range patch (e.g. on a mirror) must be blocked" def test_floor_stays_compatible_with_supported_torch() -> None: From 2aad8cbe5ec17cc31568f8fea1f33b2367af4a05 Mon Sep 17 00:00:00 2001 From: Daniel Han Date: Thu, 2 Jul 2026 09:03:02 +0000 Subject: [PATCH 9/9] Do not reinstall llm-compressor when it is already installed The FP8/FP4 compressed export calls install_llm_compressor() in the export worker process to ensure the dependency is present. That in-process import can fail even when llm-compressor is installed, because Unsloth's transformers patches interfere in this process (the actual quantization runs in a separate clean subprocess that re-imports it fine). On that spurious failure the code fell through to a pip install of the version-capped, torch/transformers-pinned spec, which made pip re-resolve the whole graph and backtrack over every llm-compressor release, eventually trying to build numpy<2 from source and failing the export with a confusing pip error. Guard the install on importlib.metadata: when a llm-compressor distribution is already present, return instead of reinstalling. Reinstalling cannot fix an in-process import error, and the isolated quantization subprocess imports it cleanly. A genuinely absent install still triggers the auto-install as before. --- unsloth/save.py | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/unsloth/save.py b/unsloth/save.py index 226ca5fed8..2692f5595c 100644 --- a/unsloth/save.py +++ b/unsloth/save.py @@ -1383,6 +1383,23 @@ def install_llm_compressor(): except Exception: pass + # Already installed but not importable in THIS process? Do not reinstall. The in-process import + # can fail under Unsloth's transformers patches (the compressed export quantizes in an isolated + # subprocess that re-imports cleanly), and reinstalling the version-capped, torch/transformers- + # pinned spec makes pip re-resolve and backtrack destructively (it drags in numpy<2 built from + # source and the export fails). Only fall through to a pip install when it is genuinely absent. + try: + from importlib.metadata import version as _iv, PackageNotFoundError as _PNF + try: + _iv("llmcompressor") + # Present; the compressed-export subprocess performs the real import. The caller only + # uses this to trigger the install and fail fast, so returning None here is safe. + return None, None + except _PNF: + pass + except Exception: + pass + # Opt-out for locked-down / air-gapped setups: forbid the auto-install, require a manual one. if os.environ.get("UNSLOTH_DISABLE_LLM_COMPRESSOR_AUTOINSTALL", "0").lower() not in ( "0",