Skip to content

[Bug]: clients can crash the openai server with invalid regex #17313

Closed
@g-eoj

Description

@g-eoj

Your current environment

root@3bea15cf4c9f:/# uv run --with vllm python collect_env.py
INFO 04-28 15:38:49 [__init__.py:239] Automatically detected platform cuda.
Collecting environment information...
/usr/local/lib/python3.11/dist-packages/_distutils_hack/__init__.py:31: UserWarning: Setuptools is replacing distutils. Support for replacing an already imported distutils is deprecated. In the future, this condition will fail. Register concerns at https://github.com/pypa/setuptools/issues/new?template=distutils-deprecation.yml
  warnings.warn(
PyTorch version: 2.6.0+cu124
Is debug build: False
CUDA used to build PyTorch: 12.4
ROCM used to build PyTorch: N/A

OS: Ubuntu 22.04.5 LTS (x86_64)
GCC version: (Ubuntu 11.4.0-1ubuntu1~22.04) 11.4.0
Clang version: Could not collect
CMake version: Could not collect
Libc version: glibc-2.35

Python version: 3.11.10 (main, Sep  7 2024, 18:35:41) [GCC 11.4.0] (64-bit runtime)
Python platform: Linux-6.8.0-52-generic-x86_64-with-glibc2.35
Is CUDA available: True
CUDA runtime version: 12.4.131
CUDA_MODULE_LOADING set to: LAZY
GPU models and configuration: 
GPU 0: NVIDIA A100-SXM4-80GB
GPU 1: NVIDIA A100-SXM4-80GB

Nvidia driver version: 550.127.05
cuDNN version: Could not collect
HIP runtime version: N/A
MIOpen runtime version: N/A
Is XNNPACK available: True

CPU:
Architecture:                         x86_64
CPU op-mode(s):                       32-bit, 64-bit
Address sizes:                        48 bits physical, 48 bits virtual
Byte Order:                           Little Endian
CPU(s):                               256
On-line CPU(s) list:                  0-255
Vendor ID:                            AuthenticAMD
Model name:                           AMD EPYC 7763 64-Core Processor
CPU family:                           25
Model:                                1
Thread(s) per core:                   2
Core(s) per socket:                   64
Socket(s):                            2
Stepping:                             1
Frequency boost:                      enabled
CPU max MHz:                          3529.0520
CPU min MHz:                          1500.0000
BogoMIPS:                             4899.64
Flags:                                fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush mmx fxsr sse sse2 ht syscall nx mmxext fxsr_opt pdpe1gb rdtscp lm constant_tsc rep_good nopl nonstop_tsc cpuid extd_apicid aperfmperf rapl pni pclmulqdq monitor ssse3 fma cx16 pcid sse4_1 sse4_2 x2apic movbe popcnt aes xsave avx f16c rdrand lahf_lm cmp_legacy svm extapic cr8_legacy abm sse4a misalignsse 3dnowprefetch osvw ibs skinit wdt tce topoext perfctr_core perfctr_nb bpext perfctr_llc mwaitx cpb cat_l3 cdp_l3 hw_pstate ssbd mba ibrs ibpb stibp vmmcall fsgsbase bmi1 avx2 smep bmi2 erms invpcid cqm rdt_a rdseed adx smap clflushopt clwb sha_ni xsaveopt xsavec xgetbv1 xsaves cqm_llc cqm_occup_llc cqm_mbm_total cqm_mbm_local user_shstk clzero irperf xsaveerptr rdpru wbnoinvd amd_ppin brs arat npt lbrv svm_lock nrip_save tsc_scale vmcb_clean flushbyasid decodeassists pausefilter pfthreshold v_vmsave_vmload vgif v_spec_ctrl umip pku ospke vaes vpclmulqdq rdpid overflow_recov succor smca fsrm debug_swap
Virtualization:                       AMD-V
L1d cache:                            4 MiB (128 instances)
L1i cache:                            4 MiB (128 instances)
L2 cache:                             64 MiB (128 instances)
L3 cache:                             512 MiB (16 instances)
NUMA node(s):                         2
NUMA node0 CPU(s):                    0-63,128-191
NUMA node1 CPU(s):                    64-127,192-255
Vulnerability Gather data sampling:   Not affected
Vulnerability Itlb multihit:          Not affected
Vulnerability L1tf:                   Not affected
Vulnerability Mds:                    Not affected
Vulnerability Meltdown:               Not affected
Vulnerability Mmio stale data:        Not affected
Vulnerability Reg file data sampling: Not affected
Vulnerability Retbleed:               Not affected
Vulnerability Spec rstack overflow:   Mitigation; Safe RET
Vulnerability Spec store bypass:      Mitigation; Speculative Store Bypass disabled via prctl
Vulnerability Spectre v1:             Mitigation; usercopy/swapgs barriers and __user pointer sanitization
Vulnerability Spectre v2:             Mitigation; Retpolines; IBPB conditional; IBRS_FW; STIBP always-on; RSB filling; PBRSB-eIBRS Not affected; BHI Not affected
Vulnerability Srbds:                  Not affected
Vulnerability Tsx async abort:        Not affected

Versions of relevant libraries:
[pip3] numpy==2.2.5
[pip3] nvidia-cublas-cu12==12.4.5.8
[pip3] nvidia-cuda-cupti-cu12==12.4.127
[pip3] nvidia-cuda-nvrtc-cu12==12.4.127
[pip3] nvidia-cuda-runtime-cu12==12.4.127
[pip3] nvidia-cudnn-cu12==9.1.0.70
[pip3] nvidia-cufft-cu12==11.2.1.3
[pip3] nvidia-curand-cu12==10.3.5.147
[pip3] nvidia-cusolver-cu12==11.6.1.9
[pip3] nvidia-cusparse-cu12==12.3.1.170
[pip3] nvidia-cusparselt-cu12==0.6.2
[pip3] nvidia-nccl-cu12==2.21.5
[pip3] nvidia-nvjitlink-cu12==12.4.127
[pip3] nvidia-nvtx-cu12==12.4.127
[pip3] pyzmq==26.4.0
[pip3] torch==2.6.0
[pip3] torchaudio==2.6.0
[pip3] torchvision==0.21.0
[pip3] transformers==4.51.3
[pip3] triton==3.2.0
[conda] Could not collect
ROCM Version: Could not collect
Neuron SDK Version: N/A
vLLM Version: 0.8.4
vLLM Build Flags:
CUDA Archs: Not Set; ROCm: Disabled; Neuron: Disabled
GPU Topology:
	GPU0	GPU1	NIC0	NIC1	NIC2	NIC3	CPU Affinity	NUMA Affinity	GPU NUMA ID
GPU0	X 	NV12	NODE	NODE	SYS	SYS	0-63,128-191	0		N/A
GPU1	NV12	X 	SYS	SYS	NODE	NODE	64-127,192-255	1		N/A
NIC0	NODE	SYS	X 	PIX	SYS	SYS				
NIC1	NODE	SYS	PIX	X 	SYS	SYS				
NIC2	SYS	NODE	SYS	SYS	X 	PIX				
NIC3	SYS	NODE	SYS	SYS	PIX	X 				

Legend:

  X    = Self
  SYS  = Connection traversing PCIe as well as the SMP interconnect between NUMA nodes (e.g., QPI/UPI)
  NODE = Connection traversing PCIe as well as the interconnect between PCIe Host Bridges within a NUMA node
  PHB  = Connection traversing PCIe as well as a PCIe Host Bridge (typically the CPU)
  PXB  = Connection traversing multiple PCIe bridges (without traversing the PCIe Host Bridge)
  PIX  = Connection traversing at most a single PCIe bridge
  NV#  = Connection traversing a bonded set of # NVLinks

NIC Legend:

  NIC0: mlx5_0
  NIC1: mlx5_1
  NIC2: mlx5_2
  NIC3: mlx5_3

CUDA_VERSION=12.4.1
LD_LIBRARY_PATH=/usr/local/nvidia/lib:/usr/local/nvidia/lib64
NCCL_VERSION=2.21.5-1
NVIDIA_DRIVER_CAPABILITIES=compute,utility
NVIDIA_PRODUCT_NAME=CUDA
NVIDIA_REQUIRE_CUDA=cuda>=12.4 brand=tesla,driver>=470,driver<471 brand=unknown,driver>=470,driver<471 brand=nvidia,driver>=470,driver<471 brand=nvidiartx,driver>=470,driver<471 brand=geforce,driver>=470,driver<471 brand=geforcertx,driver>=470,driver<471 brand=quadro,driver>=470,driver<471 brand=quadrortx,driver>=470,driver<471 brand=titan,driver>=470,driver<471 brand=titanrtx,driver>=470,driver<471 brand=tesla,driver>=525,driver<526 brand=unknown,driver>=525,driver<526 brand=nvidia,driver>=525,driver<526 brand=nvidiartx,driver>=525,driver<526 brand=geforce,driver>=525,driver<526 brand=geforcertx,driver>=525,driver<526 brand=quadro,driver>=525,driver<526 brand=quadrortx,driver>=525,driver<526 brand=titan,driver>=525,driver<526 brand=titanrtx,driver>=525,driver<526 brand=tesla,driver>=535,driver<536 brand=unknown,driver>=535,driver<536 brand=nvidia,driver>=535,driver<536 brand=nvidiartx,driver>=535,driver<536 brand=geforce,driver>=535,driver<536 brand=geforcertx,driver>=535,driver<536 brand=quadro,driver>=535,driver<536 brand=quadrortx,driver>=535,driver<536 brand=titan,driver>=535,driver<536 brand=titanrtx,driver>=535,driver<536
NVIDIA_VISIBLE_DEVICES=all
NCCL_CUMEM_ENABLE=0
PYTORCH_NVML_BASED_CUDA_CHECK=1
TORCHINDUCTOR_COMPILE_THREADS=1
CUDA_MODULE_LOADING=LAZY

🐛 Describe the bug

If a client connects to the openai server and uses extra_body={"guided_regex": as described here:
https://docs.vllm.ai/en/v0.8.4_a/features/structured_outputs.html#online-serving-openai-api

Then they can crash the server with invalid regex:

ERROR 04-28 15:36:55 [core.py:387] EngineCore hit an exception: Traceback (most recent call last):
ERROR 04-28 15:36:55 [core.py:387]   File "/root/.cache/uv/archive-v0/kYowyHpQY8CQtup1TNFhp/lib/python3.11/site-packages/vllm/v1/engine/core.py", line 380, in run_engine_core
ERROR 04-28 15:36:55 [core.py:387]     engine_core.run_busy_loop()
ERROR 04-28 15:36:55 [core.py:387]   File "/root/.cache/uv/archive-v0/kYowyHpQY8CQtup1TNFhp/lib/python3.11/site-packages/vllm/v1/engine/core.py", line 402, in run_busy_loop
ERROR 04-28 15:36:55 [core.py:387]     self._process_engine_step()
ERROR 04-28 15:36:55 [core.py:387]   File "/root/.cache/uv/archive-v0/kYowyHpQY8CQtup1TNFhp/lib/python3.11/site-packages/vllm/v1/engine/core.py", line 431, in _process_engine_step
ERROR 04-28 15:36:55 [core.py:387]     outputs = self.step_fn()
ERROR 04-28 15:36:55 [core.py:387]               ^^^^^^^^^^^^^^
ERROR 04-28 15:36:55 [core.py:387]   File "/root/.cache/uv/archive-v0/kYowyHpQY8CQtup1TNFhp/lib/python3.11/site-packages/vllm/v1/engine/core.py", line 206, in step
ERROR 04-28 15:36:55 [core.py:387]     scheduler_output = self.scheduler.schedule()
ERROR 04-28 15:36:55 [core.py:387]                        ^^^^^^^^^^^^^^^^^^^^^^^^^
ERROR 04-28 15:36:55 [core.py:387]   File "/root/.cache/uv/archive-v0/kYowyHpQY8CQtup1TNFhp/lib/python3.11/site-packages/vllm/v1/core/sched/scheduler.py", line 286, in schedule
ERROR 04-28 15:36:55 [core.py:387]     if structured_output_req and structured_output_req.grammar:
ERROR 04-28 15:36:55 [core.py:387]                                  ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
ERROR 04-28 15:36:55 [core.py:387]   File "/root/.cache/uv/archive-v0/kYowyHpQY8CQtup1TNFhp/lib/python3.11/site-packages/vllm/v1/structured_output/request.py", line 43, in grammar
ERROR 04-28 15:36:55 [core.py:387]     completed = self._check_grammar_completion()
ERROR 04-28 15:36:55 [core.py:387]                 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
ERROR 04-28 15:36:55 [core.py:387]   File "/root/.cache/uv/archive-v0/kYowyHpQY8CQtup1TNFhp/lib/python3.11/site-packages/vllm/v1/structured_output/request.py", line 31, in _check_grammar_completion
ERROR 04-28 15:36:55 [core.py:387]     self._grammar = self._grammar.result(timeout=0.0001)
ERROR 04-28 15:36:55 [core.py:387]                     ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
ERROR 04-28 15:36:55 [core.py:387]   File "/usr/lib/python3.11/concurrent/futures/_base.py", line 449, in result
ERROR 04-28 15:36:55 [core.py:387]     return self.__get_result()
ERROR 04-28 15:36:55 [core.py:387]            ^^^^^^^^^^^^^^^^^^^
ERROR 04-28 15:36:55 [core.py:387]   File "/usr/lib/python3.11/concurrent/futures/_base.py", line 401, in __get_result
ERROR 04-28 15:36:55 [core.py:387]     raise self._exception
ERROR 04-28 15:36:55 [core.py:387]   File "/usr/lib/python3.11/concurrent/futures/thread.py", line 58, in run
ERROR 04-28 15:36:55 [core.py:387]     result = self.fn(*self.args, **self.kwargs)
ERROR 04-28 15:36:55 [core.py:387]              ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
ERROR 04-28 15:36:55 [core.py:387]   File "/root/.cache/uv/archive-v0/kYowyHpQY8CQtup1TNFhp/lib/python3.11/site-packages/vllm/v1/structured_output/__init__.py", line 77, in _async_create_grammar
ERROR 04-28 15:36:55 [core.py:387]     return self.backend.compile_grammar(request_type, grammar_spec)
ERROR 04-28 15:36:55 [core.py:387]            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
ERROR 04-28 15:36:55 [core.py:387]   File "/root/.cache/uv/archive-v0/kYowyHpQY8CQtup1TNFhp/lib/python3.11/site-packages/vllm/v1/structured_output/backend_xgrammar.py", line 99, in compile_grammar
ERROR 04-28 15:36:55 [core.py:387]     ctx = self.compiler.compile_regex(grammar_spec)
ERROR 04-28 15:36:55 [core.py:387]           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
ERROR 04-28 15:36:55 [core.py:387]   File "/root/.cache/uv/archive-v0/kYowyHpQY8CQtup1TNFhp/lib/python3.11/site-packages/xgrammar/compiler.py", line 150, in compile_regex
ERROR 04-28 15:36:55 [core.py:387]     return CompiledGrammar._create_from_handle(self._handle.compile_regex(regex))
ERROR 04-28 15:36:55 [core.py:387]                                                ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
ERROR 04-28 15:36:55 [core.py:387] RuntimeError: [15:36:55] /project/cpp/regex_converter.cc:73: Regex parsing error at position 106: Invalid repetition count.
ERROR 04-28 15:36:55 [core.py:387] 
ERROR 04-28 15:36:55 [core.py:387] 
CRITICAL 04-28 15:36:55 [core_client.py:359] Got fatal signal from worker processes, shutting down. See stack trace above for root cause issue.

Maybe not a bug but I think the server should be resistant to unexpected user inputs.

Before submitting a new issue...

  • Make sure you already searched for relevant issues, and asked the chatbot living at the bottom right corner of the documentation page, which can answer lots of frequently asked questions.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingsecuritySecurity related issues and PRs

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions