Repository navigation
V4.1 runtime image distribution by config digest (spark_v41_runtime_image_distribute) - #12353
Merged
Merged
Conversation
…mage_distribute
The fleet's one image transport (save, scp through the executor, load) was GLM-only and named
by tag. It now takes a VllmImageDistributionSubject { tag, config digest } and supplied targets:
the source must hold the digest under the tag before a byte moves; a target already holding it
is a Noop (settled before any save); a different image under the tag refuses rather than having
the tag moved; an unread daemon refuses; the image Size is stated against every filesystem a
copy lands on (source /tmp, executor /tmp, target /tmp and data root) before the save; and the
target's inspect Id must read back as the digest.
The V4.1 entry names the arm A image by its production receipt (run 36207135528, srv8,
sha256:ea39410e...), deriving the canonical tag from the observed source tree through the build's
own key fold. Both hosts are admitted by admit_host_held_by_subject (Group A) and claimed.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…docker info, not defaulted (review 71552) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
Wet control passed. fleet-converge run 36252411337 dispatched Review 71552: both findings fixed in the new head.
Checked locally on the new head: typecheck, the fleet-converge YAML regenerates with no change, and 11 claims pass. Note: the wet run above executed the previous head. On the new head a repeat run would be a Noop on srv5, which already holds the digest. — sent from merry-eagle-768 |
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 27, 2026
…nly the reads they rebind The unrelated-diff control (#12353) reached 13147 witnesses, the same order as #12361's replay. Two defects, both measured on srv1: - the flat bare channel admitted dotted field accesses (cfg.root, whose empty candidate set says nothing about top-level root) and ambiguous bare names; the global-bare lookup resolves only a BARE name to a UNIQUE declarer, so the execution walk now admits exactly that (fan-out ran through test-local helpers named root/subject/observed/standing). - an import-region edit seeded every declaration in its file (684 seeds from an 11-file diff); import_rebound_declarations now seeds only the reads whose import binding changed between the two indexes. Receipt gains the binding kind and one BodyReachSeed line per seed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
A fleet-converge mode,
spark_v41_runtime_image_distribute, moves the produced V4.1 runtime image from the host its production receipt names (srv8, run 36207135528) to the selected Group A Spark. The image is identified by its config digestsha256:ea39410ed01d396caad86339d877c1adb181a983baadffd22c722069109ea664, never by tag alone.How: one transport, generalized rather than duplicated
The fleet has no registry.
gunbc.spark.vllm_runtime_image_build distribute_vllm_image(save → scp through the executor → load) was the only image transport, but it worked only for GLM and named images by tag. It now takes aVllmImageDistributionSubject { tag, config }and a list of supplied targets:docker image inspect.Idunder the tag must equal the digest. A different image under the tag refuses ("the tag is not the identity").Size(newextdeps.docker.cli docker_image_inspect_size_from_stdout), checked on:/tmp(1×);/tmp(1×);/tmpand/var/lib/docker(2× each). Filesystem identity is not read, so this is an upper bound; it is exact when both are on one filesystem, which is what the Sparks have..Idmust equal the digest, or it refuses with a type and location.The GLM entry now goes through
with_spark_build_host, the same credential setup the build uses. Its digest still comes from the source's readback because no GLM production receipt has been recorded; this is stated in a comment as a declared frontier.The V4.1 receipt row
v41_arm_a_produced_imagerecords only what run 36207135528 established:d2d649e6…, worktree diff79ee4347…);The tag is derived from the tree through the candidate recipe and the build's own key fold. A claim checks that it re-derives the printed
gunbc-vllm-dsv41-gb10:d73e307009a5d716. Control: changing one hex digit of the worktree digest turns that claim red.Admission
targetis the destination.admit_host_held_by_subject(PairServingUnitOn { FabricGroupA }), the same check the build uses.claim_host_effect_livewith a 2h term. The step timeout is derived from that term.Evidence
gunbc runtypecheck and regeneration offleet-converge.ymlfrom the model.🤖 Generated with Claude Code