mirror of
https://github.com/yusufipk/dikte.git
synced 2026-09-11 10:56:10 +00:00
Ship a managed Vulkan whisper-server for Linux x64
This commit is contained in:
@@ -221,6 +221,7 @@ class InstallProgram(Local):
|
||||
|
||||
def install(self, *names, archive=None):
|
||||
self.patch_attr(ggml, "_arch", lambda: "x64")
|
||||
self.patch_attr(ggml, "_has_vulkan", lambda: False)
|
||||
blob = self.archive if archive is None else archive
|
||||
with serving(self.release(*names, archive=blob), blob) as calls:
|
||||
path = ggml.install_program(ggml.WHISPER)
|
||||
@@ -238,6 +239,105 @@ class InstallProgram(Local):
|
||||
"whisper-bin-ubuntu-x64.tar.gz")
|
||||
self.assertTrue(urls[1].endswith("whisper-bin-ubuntu-x64.tar.gz"))
|
||||
|
||||
def test_linux_x64_with_vulkan_takes_diktes_accelerated_build(self):
|
||||
self.patch_attr(ggml, "_arch", lambda: "x64")
|
||||
self.patch_attr(ggml, "_has_vulkan", lambda: True)
|
||||
listing = self.release("whisper-bin-ubuntu-vulkan-x64.tar.gz")
|
||||
listing["tag_name"] = "whisper.cpp-v1.9.3"
|
||||
managed_sha = hashlib.sha256(self.archive).hexdigest()
|
||||
with mock.patch.object(ggml, "MANAGED_WHISPER_SHA256", managed_sha,
|
||||
create=True):
|
||||
with fake_urlopen(listing, body(self.archive)) as calls:
|
||||
path = ggml.install_program(ggml.WHISPER)
|
||||
urls = [call.full_url for call in calls]
|
||||
self.assertIn(
|
||||
"/repos/yusufipk/dikte/releases/tags/whisper.cpp-v1.9.3",
|
||||
urls[0],
|
||||
)
|
||||
self.assertTrue(urls[1].endswith(
|
||||
"whisper-bin-ubuntu-vulkan-x64.tar.gz"))
|
||||
self.assertTrue(os.path.isfile(path))
|
||||
self.assertEqual("v1.9.3", ggml.installed_version(ggml.WHISPER))
|
||||
|
||||
def test_an_explicit_whisper_version_still_comes_from_upstream(self):
|
||||
self.patch_attr(ggml, "_arch", lambda: "x64")
|
||||
self.patch_attr(ggml, "_has_vulkan", lambda: True)
|
||||
listing = self.release("whisper-bin-ubuntu-x64.tar.gz")
|
||||
with fake_urlopen(listing, body(self.archive)) as calls:
|
||||
ggml.install_program(ggml.WHISPER, tag="v1.9.1")
|
||||
self.assertIn(
|
||||
"/repos/ggml-org/whisper.cpp/releases/tags/v1.9.1",
|
||||
calls[0].full_url,
|
||||
)
|
||||
|
||||
def test_linux_arm64_keeps_using_the_upstream_cpu_build(self):
|
||||
self.patch_attr(ggml, "_arch", lambda: "arm64")
|
||||
self.patch_attr(ggml.platform, "machine", lambda: "aarch64")
|
||||
self.patch_attr(ggml, "_has_vulkan", lambda: True)
|
||||
listing = self.release("whisper-bin-ubuntu-arm64.tar.gz")
|
||||
with fake_urlopen(listing, body(self.archive)) as calls:
|
||||
ggml.install_program(ggml.WHISPER)
|
||||
self.assertIn(
|
||||
"/repos/ggml-org/whisper.cpp/releases/latest",
|
||||
calls[0].full_url,
|
||||
)
|
||||
|
||||
def test_linux_non_x86_does_not_try_the_managed_x64_build(self):
|
||||
self.patch_attr(ggml, "_has_vulkan", lambda: True)
|
||||
listing = self.release("whisper-bin-ubuntu-arm64.tar.gz")
|
||||
with mock.patch("platform.machine", return_value="ppc64le"):
|
||||
with fake_urlopen(listing, listing) as calls:
|
||||
with self.assertRaises(ggml.LocalError):
|
||||
ggml.install_program(ggml.WHISPER)
|
||||
self.assertIn(
|
||||
"/repos/ggml-org/whisper.cpp/releases/latest",
|
||||
calls[0].full_url,
|
||||
)
|
||||
|
||||
def test_a_missing_managed_build_falls_back_to_upstream_cpu(self):
|
||||
self.patch_attr(ggml, "_arch", lambda: "x64")
|
||||
self.patch_attr(ggml, "_has_vulkan", lambda: True)
|
||||
managed = self.release("Dikte-1.1.0-x86_64.AppImage")
|
||||
managed["tag_name"] = "whisper.cpp-v1.9.3"
|
||||
upstream = self.release("whisper-bin-ubuntu-x64.tar.gz")
|
||||
with fake_urlopen(managed, upstream, body(self.archive)) as calls:
|
||||
path = ggml.install_program(ggml.WHISPER)
|
||||
urls = [call.full_url for call in calls]
|
||||
self.assertIn(
|
||||
"/repos/yusufipk/dikte/releases/tags/whisper.cpp-v1.9.3",
|
||||
urls[0],
|
||||
)
|
||||
self.assertIn("/repos/ggml-org/whisper.cpp/releases/latest", urls[1])
|
||||
self.assertTrue(urls[2].endswith("whisper-bin-ubuntu-x64.tar.gz"))
|
||||
self.assertTrue(os.path.isfile(path))
|
||||
|
||||
def test_a_managed_build_with_an_unreviewed_digest_falls_back(self):
|
||||
self.patch_attr(ggml, "_has_vulkan", lambda: True)
|
||||
managed = self.release("whisper-bin-ubuntu-vulkan-x64.tar.gz")
|
||||
managed["assets"][0]["digest"] = "sha256:" + "0" * 64
|
||||
upstream = self.release("whisper-bin-ubuntu-x64.tar.gz")
|
||||
with fake_urlopen(managed, upstream, body(self.archive)) as calls:
|
||||
try:
|
||||
path = ggml.install_program(ggml.WHISPER)
|
||||
except ggml.LocalError as exc:
|
||||
self.fail(f"unreviewed digest did not fall back: {exc}")
|
||||
urls = [call.full_url for call in calls]
|
||||
self.assertEqual(3, len(urls))
|
||||
self.assertTrue(urls[2].endswith("whisper-bin-ubuntu-x64.tar.gz"))
|
||||
self.assertTrue(os.path.isfile(path))
|
||||
|
||||
def test_an_unavailable_managed_release_falls_back_to_upstream_cpu(self):
|
||||
self.patch_attr(ggml, "_arch", lambda: "x64")
|
||||
self.patch_attr(ggml, "_has_vulkan", lambda: True)
|
||||
upstream = self.release("whisper-bin-ubuntu-x64.tar.gz")
|
||||
with fake_urlopen(http_error(404), upstream,
|
||||
body(self.archive)) as calls:
|
||||
path = ggml.install_program(ggml.WHISPER)
|
||||
self.assertEqual(3, len(calls))
|
||||
self.assertTrue(calls[2].full_url.endswith(
|
||||
"whisper-bin-ubuntu-x64.tar.gz"))
|
||||
self.assertTrue(os.path.isfile(path))
|
||||
|
||||
def test_a_release_with_nothing_for_this_machine_says_so(self):
|
||||
self.patch_attr(ggml, "_arch", lambda: "x64")
|
||||
with fake_urlopen(self.release("whisper-bin-Win32.zip")):
|
||||
@@ -399,6 +499,18 @@ class InstallProgram(Local):
|
||||
with self.assertRaises(ggml.LocalError):
|
||||
self.install("whisper-bin-ubuntu-x64.tar.gz", archive=buf.getvalue())
|
||||
|
||||
def test_python_without_safe_tar_filters_refuses_the_archive(self):
|
||||
archive = self.path("bundle.tar.gz")
|
||||
archive.write_bytes(self.archive)
|
||||
destination = self.path("unpacked")
|
||||
destination.mkdir()
|
||||
with mock.patch.object(tarfile.TarFile, "extractall",
|
||||
side_effect=[TypeError("no filter"), None]) as extract:
|
||||
with self.assertRaises(ggml.LocalError) as caught:
|
||||
ggml._extract(archive, destination)
|
||||
self.assertEqual(1, extract.call_count)
|
||||
self.assertIn("safely", str(caught.exception))
|
||||
|
||||
def test_everything_is_asked_for_over_tls(self):
|
||||
for url in (hub.GITHUB_API, hub.HF_API, hub.HF_FILES):
|
||||
with self.subTest(url=url):
|
||||
|
||||
@@ -0,0 +1,180 @@
|
||||
"""The release build that makes Linux Vulkan a one-click install."""
|
||||
|
||||
import hashlib
|
||||
import io
|
||||
import json
|
||||
import os
|
||||
import pathlib
|
||||
import shutil
|
||||
import subprocess
|
||||
import sys
|
||||
import tarfile
|
||||
import tempfile
|
||||
import unittest
|
||||
|
||||
from dikte import ggml
|
||||
|
||||
|
||||
ROOT = pathlib.Path(__file__).parents[1]
|
||||
PACKAGING = ROOT / "packaging" / "whisper-vulkan"
|
||||
WORKFLOW = ROOT / ".github" / "workflows" / "whisper-vulkan.yml"
|
||||
|
||||
|
||||
class WhisperVulkanPackaging(unittest.TestCase):
|
||||
@unittest.skipUnless(shutil.which("bash"), "bash is unavailable")
|
||||
def test_the_release_scripts_parse_as_shell(self):
|
||||
for name in ("build-package.sh", "validate-package.sh",
|
||||
"smoke-runtime.sh"):
|
||||
script = PACKAGING / name
|
||||
checked = subprocess.run(
|
||||
["bash", "-n", script], capture_output=True, text=True,
|
||||
)
|
||||
self.assertEqual("", checked.stderr)
|
||||
self.assertEqual(0, checked.returncode)
|
||||
|
||||
def test_the_workflow_builds_validates_smokes_and_publishes(self):
|
||||
workflow = WORKFLOW.read_text(encoding="utf-8")
|
||||
for step in ("Build deterministic archive",
|
||||
"Verify reviewed archive digest",
|
||||
"Validate archive and ELF contract",
|
||||
"CPU fallback smoke test (no Vulkan loader)",
|
||||
"Vulkan plugin-load smoke test (Mesa llvmpipe)",
|
||||
"Publish dependency release"):
|
||||
self.assertIn(step, workflow)
|
||||
self.assertNotRegex(workflow, r"uses: [^\n]+@v\d+(?:\s|$)")
|
||||
|
||||
def test_publish_is_safe_for_dikte_and_limited_to_reviewed_master(self):
|
||||
workflow = WORKFLOW.read_text(encoding="utf-8")
|
||||
self.assertGreaterEqual(workflow.count("persist-credentials: false"), 2)
|
||||
self.assertIn("github.ref == 'refs/heads/master'", workflow)
|
||||
self.assertIn("--prerelease", workflow)
|
||||
self.assertIn("--latest=false", workflow)
|
||||
self.assertIn("--verify-tag", workflow)
|
||||
self.assertIn("refusing to replace existing tag", workflow)
|
||||
self.assertIn("^[0-9]+\\.[0-9]+\\.[0-9]+$", workflow)
|
||||
self.assertIn("^[0-9a-f]{40}$", workflow)
|
||||
publish_script = workflow.split(" - name: Publish dependency release", 1)[1]
|
||||
publish_script = publish_script.split(" run: |", 1)[1]
|
||||
self.assertNotIn("${{ inputs.", publish_script)
|
||||
|
||||
def test_bundle_ci_runs_when_its_installer_or_contract_changes(self):
|
||||
workflow = WORKFLOW.read_text(encoding="utf-8")
|
||||
for path in ("dikte/ggml.py", "tests/test_packaging.py",
|
||||
"README.md", "README.tr.md"):
|
||||
self.assertIn(f"- {path}", workflow)
|
||||
|
||||
def test_the_validator_checks_tar_links_before_extraction(self):
|
||||
validator = (PACKAGING / "validate-package.sh").read_text(
|
||||
encoding="utf-8")
|
||||
for check in ("member.issym()", "member.islnk()", "member.isdev()"):
|
||||
self.assertIn(check, validator)
|
||||
|
||||
@unittest.skipUnless(sys.platform == "linux" and shutil.which("bash"),
|
||||
"Linux packaging test is unavailable")
|
||||
def test_the_validator_rejects_an_escaping_symlink(self):
|
||||
asset = "whisper-bin-ubuntu-vulkan-x64"
|
||||
with tempfile.TemporaryDirectory() as temporary:
|
||||
output = pathlib.Path(temporary)
|
||||
archive = output / f"{asset}.tar.gz"
|
||||
with tarfile.open(archive, "w:gz") as bundle:
|
||||
link = tarfile.TarInfo(f"{asset}/whisper-server")
|
||||
link.type = tarfile.SYMTYPE
|
||||
link.linkname = "/etc/passwd"
|
||||
bundle.addfile(link, io.BytesIO())
|
||||
digest = hashlib.sha256(archive.read_bytes()).hexdigest()
|
||||
(output / f"{asset}.tar.gz.sha256").write_text(
|
||||
f"{digest} {asset}.tar.gz\n", encoding="utf-8",
|
||||
)
|
||||
checked = subprocess.run(
|
||||
["bash", PACKAGING / "validate-package.sh"],
|
||||
env=os.environ | {"OUT_DIR": str(output)},
|
||||
capture_output=True, text=True,
|
||||
)
|
||||
self.assertNotEqual(0, checked.returncode)
|
||||
self.assertIn("unsafe symlink", checked.stderr)
|
||||
|
||||
def test_the_validator_checks_elf_architecture_dependencies_and_paths(self):
|
||||
validator = (PACKAGING / "validate-package.sh").read_text(
|
||||
encoding="utf-8")
|
||||
for check in ("Advanced Micro Devices X86-64", "unexpected DT_NEEDED",
|
||||
"path.read_bytes()"):
|
||||
self.assertIn(check, validator)
|
||||
|
||||
def test_the_builder_and_its_downloads_are_pinned(self):
|
||||
dockerfile = (PACKAGING / "Dockerfile.build").read_text(
|
||||
encoding="utf-8")
|
||||
self.assertRegex(dockerfile, r"FROM ubuntu@sha256:[0-9a-f]{64}")
|
||||
self.assertIn("CMAKE_SHA256=", dockerfile)
|
||||
self.assertIn("libvulkan-dev=", dockerfile)
|
||||
self.assertIn("shaderc=", dockerfile)
|
||||
key = (PACKAGING / "lunarg-signing-key-pub.asc").read_bytes()
|
||||
self.assertEqual(
|
||||
"aa1c3c29673140e77f0d6a9aaeed5d9b5621e305ead51c59fae4458bbb4df92b",
|
||||
hashlib.sha256(key).hexdigest(),
|
||||
)
|
||||
|
||||
def test_the_bundle_has_portable_dynamic_backends(self):
|
||||
script = (PACKAGING / "build-package.sh").read_text(
|
||||
encoding="utf-8")
|
||||
for flag in ("GGML_BACKEND_DL=ON", "GGML_CPU_ALL_VARIANTS=ON",
|
||||
"GGML_NATIVE=OFF", "GGML_OPENMP=OFF",
|
||||
"GGML_VULKAN=ON"):
|
||||
self.assertIn(flag, script)
|
||||
self.assertIn("libggml-cpu*.so", script)
|
||||
self.assertIn("libggml-vulkan.so", script)
|
||||
|
||||
def test_the_dependency_release_matches_the_installer(self):
|
||||
workflow = WORKFLOW.read_text(encoding="utf-8")
|
||||
script = (PACKAGING / "build-package.sh").read_text(
|
||||
encoding="utf-8")
|
||||
self.assertEqual("whisper.cpp-v1.9.3",
|
||||
ggml.MANAGED_WHISPER_RELEASE)
|
||||
self.assertEqual("v1.9.3", ggml.MANAGED_WHISPER_VERSION)
|
||||
self.assertIn("RELEASE_TAG: whisper.cpp-v${{ inputs.whisper_version }}",
|
||||
workflow)
|
||||
self.assertIn("WHISPER_VERSION:=1.9.3", script)
|
||||
commit = "371b5a7561823ab2bb32142d2751e35e7534727b"
|
||||
self.assertIn(f"WHISPER_COMMIT:={commit}", script)
|
||||
self.assertIn(commit, workflow)
|
||||
self.assertIn(ggml.MANAGED_WHISPER_VULKAN, workflow)
|
||||
self.assertIn(ggml.MANAGED_WHISPER_SHA256, workflow)
|
||||
|
||||
def test_the_bundle_carries_metadata_and_all_required_licenses(self):
|
||||
script = (PACKAGING / "build-package.sh").read_text(
|
||||
encoding="utf-8")
|
||||
for name in ("BUILD-INFO.json", "SHA256SUMS", ".cdx.json"):
|
||||
self.assertIn(name, script)
|
||||
for name in ("cpp-httplib-MIT.txt", "nlohmann-json-MIT.txt"):
|
||||
self.assertTrue((PACKAGING / "licenses" / name).is_file())
|
||||
|
||||
def _make_test_sbom(self):
|
||||
with tempfile.TemporaryDirectory() as temporary:
|
||||
root = pathlib.Path(temporary)
|
||||
(root / "whisper-server").write_bytes(b"elf")
|
||||
sbom = root / "whisper-bin-ubuntu-vulkan-x64.cdx.json"
|
||||
environment = os.environ | {
|
||||
"ROOT": str(root),
|
||||
"VERSION": "1.9.3",
|
||||
"COMMIT": "371b5a7561823ab2bb32142d2751e35e7534727b",
|
||||
"EPOCH": "1787219223",
|
||||
}
|
||||
with sbom.open("w", encoding="utf-8") as output:
|
||||
subprocess.run(
|
||||
[sys.executable, PACKAGING / "make-sbom.py"],
|
||||
env=environment, stdout=output, check=True,
|
||||
)
|
||||
return json.loads(sbom.read_text(encoding="utf-8")), sbom.name
|
||||
|
||||
def test_the_sbom_does_not_record_the_file_being_written(self):
|
||||
document, sbom_name = self._make_test_sbom()
|
||||
names = {component["name"] for component in document["components"]}
|
||||
self.assertNotIn(sbom_name, names)
|
||||
|
||||
def test_the_sbom_lists_ggml(self):
|
||||
document, _ = self._make_test_sbom()
|
||||
names = {component["name"] for component in document["components"]}
|
||||
self.assertIn("ggml", names)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
Reference in New Issue
Block a user