Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 27 additions & 14 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -277,24 +277,37 @@ jobs:
# (Vulkan backend dropped).

# ── ROCm / HIP (Linux) ───────────────────────────────────────────
- name: Install ROCm / HIP runtime (Linux)
# ROCm 10.0.0 has no apt channel. Since ROCm 7.14 AMD builds and
# releases through "TheRock"; repo.radeon.com/rocm/apt/ tops out at
# 7.2.4 (its own `latest` resolves there, and apt/7.14 and apt/10.0.0
# both 404), the manylinux channel stops at rocm-rel-7.2.4, and the
# TheRock wheel index carries only 7.14.0 alphas. The official
# container image is the only stable, digest-pinnable ROCm 10.0.0
# artifact -- see ADR-1225.
#
# `docker pull` is not viable here: the image is 8.2 GB compressed /
# 29 GB extracted and this leg already carries the CUDA toolkit and
# oneAPI on the same runner. `install-rocm-from-image.sh` instead
# streams each layer blob from the registry straight into tar,
# extracting only /opt/rocm and skipping the math libraries libvmaf
# never links, so peak disk is the ~5.5 GB result rather than the
# 29 GB image.
#
# Cost: ~8 GB download + ~3-5 min wall-clock per HIP-lane run,
# comparable to the apt install it replaces.
- name: Install ROCm / HIP toolchain (Linux)
if: matrix.hip && startsWith(matrix.os, 'ubuntu')
env:
ROCM_VERSION: "7.2.4"
ROCM_IMAGE: "rocm/dev-ubuntu-24.04@sha256:a90cf047f615abe70fbef83c64def0a2d549ef37a39c8ea545430aba4981b374"
run: |
sudo apt-get update
sudo -E apt-get -yq install wget gnupg lsb-release
sudo install -d -m 0755 /etc/apt/keyrings
wget -qO- https://repo.radeon.com/rocm/rocm.gpg.key \
| gpg --dearmor \
| sudo tee /etc/apt/keyrings/rocm.gpg > /dev/null
UBUNTU_CODENAME="$(lsb_release -cs)"
echo "deb [arch=amd64 signed-by=/etc/apt/keyrings/rocm.gpg] https://repo.radeon.com/rocm/apt/${ROCM_VERSION} ${UBUNTU_CODENAME} main" \
| sudo tee /etc/apt/sources.list.d/rocm.list
printf 'Package: *\nPin: release o=repo.radeon.com\nPin-Priority: 600\n' \
| sudo tee /etc/apt/preferences.d/rocm-pin-600
sudo apt-get update
sudo -E apt-get -yq install --no-install-recommends rocm-hip-runtime-dev
sudo -E apt-get -yq install --no-install-recommends jq
./scripts/ci/install-rocm-from-image.sh \
--image "$ROCM_IMAGE" --dest /opt/rocm
# Surface the ROCm tooling on PATH / pkg-config / ld so meson's
# `dependency('hip-lang')` and the link of `amdhip64` resolve
# without per-step exports.
echo "ROCM_PATH=/opt/rocm" | sudo tee -a "$GITHUB_ENV"
echo "/opt/rocm/bin" | sudo tee -a "$GITHUB_PATH"
echo "/opt/rocm/lib" | sudo tee /etc/ld.so.conf.d/rocm.conf
echo "PKG_CONFIG_PATH=/opt/rocm/lib/pkgconfig:${PKG_CONFIG_PATH:-}" \
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/docker-publish-operator-node.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@
# ghcr.io/vmafx/vmafx-node:latest (same)
#
# Post-push steps: cosign keyless sign + syft SBOM (CycloneDX JSON) via cosign attest.
# GPU node variants (-cuda13, -rocm7, -sycl) are deferred to a follow-on PR.
# GPU node variants (-cuda13, -rocm10, -sycl) are deferred to a follow-on PR.
#
# ADR-0815: operator-node-distroless-dockerfiles
# ADR-0698: distroless base-image policy
Expand Down
34 changes: 17 additions & 17 deletions .github/workflows/docker-publish-production.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
# ghcr.io/vmafx/vmafx:<tag> (cpu, amd64+arm64)
# ghcr.io/vmafx/vmafx:latest (same)
# ghcr.io/vmafx/vmafx:<tag>-cuda13 (amd64 only — CUDA not portable to arm64)
# ghcr.io/vmafx/vmafx:<tag>-rocm7 (amd64 only)
# ghcr.io/vmafx/vmafx:<tag>-rocm10 (amd64 only)
# ghcr.io/vmafx/vmafx:<tag>-oneapi2025 (amd64 only)
#

Expand Down Expand Up @@ -371,10 +371,10 @@ jobs:
retention-days: 90

# -----------------------------------------------------------------------
# GPU variant: ROCm 7 (amd64 only)
# GPU variant: ROCm 10 (amd64 only)
# -----------------------------------------------------------------------
build-rocm7:
name: Publish ROCm 7 image
build-rocm10:
name: Publish ROCm 10 image
needs: validate-release
runs-on: ubuntu-latest
timeout-minutes: 90
Expand Down Expand Up @@ -411,15 +411,15 @@ jobs:
with:
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
tags: |
type=raw,value=${{ env.PUBLISH_TAG }}-rocm7
type=raw,value=${{ env.PUBLISH_TAG }}-rocm10

- name: Build and push
id: push
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
file: docker/Dockerfile.production-gpu
target: final-rocm7
target: final-rocm10
platforms: linux/amd64
push: true
tags: ${{ steps.meta.outputs.tags }}
Expand Down Expand Up @@ -452,17 +452,17 @@ jobs:
syft \
"${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}@${{ steps.push.outputs.digest }}" \
--output cyclonedx-json \
--file sbom-rocm7.cdx.json
--file sbom-rocm10.cdx.json
cosign attest --yes \
--predicate sbom-rocm7.cdx.json \
--predicate sbom-rocm10.cdx.json \
--type cyclonedx \
"${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}@${{ steps.push.outputs.digest }}"

- name: Upload SBOM as workflow artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: sbom-rocm7
path: sbom-rocm7.cdx.json
name: sbom-rocm10
path: sbom-rocm10.cdx.json
retention-days: 90

# -----------------------------------------------------------------------
Expand Down Expand Up @@ -567,7 +567,7 @@ jobs:
name: Smoke-test GPU images
needs:
- build-cuda13
- build-rocm7
- build-rocm10
- build-oneapi2025
runs-on: ubuntu-latest
timeout-minutes: 20
Expand All @@ -592,7 +592,7 @@ jobs:
run: |
for digest in \
"${{ needs.build-cuda13.outputs.digest }}" \
"${{ needs.build-rocm7.outputs.digest }}" \
"${{ needs.build-rocm10.outputs.digest }}" \
"${{ needs.build-oneapi2025.outputs.digest }}"; do
cosign verify \
--certificate-identity \
Expand All @@ -605,7 +605,7 @@ jobs:
run: |
for digest in \
"${{ needs.build-cuda13.outputs.digest }}" \
"${{ needs.build-rocm7.outputs.digest }}" \
"${{ needs.build-rocm10.outputs.digest }}" \
"${{ needs.build-oneapi2025.outputs.digest }}"; do
image="${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}@${digest}"
docker pull "${image}"
Expand Down Expand Up @@ -794,7 +794,7 @@ jobs:
- build-cpu
- smoke-test
- build-cuda13
- build-rocm7
- build-rocm10
- build-oneapi2025
- smoke-gpu
- build-server
Expand Down Expand Up @@ -824,13 +824,13 @@ jobs:
# could fail on every publish without anyone noticing. That is how
# docker/Dockerfile.production-gpu kept a CUDA 12.0 pin, an
# intel/oneapi-basekit:2026.0 reference to an image that does not
# exist, and a ROCm 6.4 runtime against a 7.2.4 build toolchain.
# exist, and a ROCm 6.4 runtime against a 10.0.0 build toolchain.
# They gate now.
fail=0
for job in build-cuda13 build-rocm7 build-oneapi2025 build-server; do
for job in build-cuda13 build-rocm10 build-oneapi2025 build-server; do
case "$job" in
build-cuda13) r="${{ needs.build-cuda13.result }}" ;;
build-rocm7) r="${{ needs.build-rocm7.result }}" ;;
build-rocm10) r="${{ needs.build-rocm10.result }}" ;;
build-oneapi2025) r="${{ needs.build-oneapi2025.result }}" ;;
build-server) r="${{ needs.build-server.result }}" ;;
esac
Expand Down
63 changes: 30 additions & 33 deletions .github/workflows/libvmaf-build-matrix.yml
Original file line number Diff line number Diff line change
Expand Up @@ -442,44 +442,41 @@ jobs:
sudo apt-get update
sudo -E apt-get -yq install ccache ninja-build nasm gcc g++

# ---------- ROCm / HIP runtime (T7-10b) ----------
# Installs `rocm-hip-runtime-dev` from the official AMD apt repo
# at `repo.radeon.com/rocm/apt/<ver>`. ROCm 7.2.3 matches the
# version under test on the maintainer's local box; the apt URL
# carries the version path component, so bumping ROCm here is a
# one-line change. The ROCm install uses `lsb_release -cs` to
# detect the codename dynamically (plucky for ubuntu-26.04).
# Pin priority 600
# keeps Ubuntu base packages preferred where versions overlap so
# the HIP install doesn't drag in a parallel toolchain.
# ---------- ROCm / HIP toolchain (T7-10b) ----------
# ROCm 10.0.0 has no apt channel. Since ROCm 7.14 AMD builds and
# releases through "TheRock"; repo.radeon.com/rocm/apt/ tops out at
# 7.2.4 (its own `latest` resolves there, and apt/7.14 and apt/10.0.0
# both 404), the manylinux channel stops at rocm-rel-7.2.4, and the
# TheRock wheel index carries only 7.14.0 alphas. The official
# container image is the only stable, digest-pinnable ROCm 10.0.0
# artifact -- see ADR-1225.
#
# Cost: ~200 MB download + ~3-5 min wall-clock per HIP-lane run.
# Acceptable because HIP is opt-in (`-Denable_hip=true`) and the
# lane runs only when its matrix row is selected.
- name: Install ROCm / HIP runtime
# `docker pull` is not viable here: the image is 8.2 GB compressed /
# 29 GB extracted and this leg already carries the CUDA toolkit and
# oneAPI on the same runner. `install-rocm-from-image.sh` instead
# streams each layer blob from the registry straight into tar,
# extracting only /opt/rocm and skipping the math libraries libvmaf
# never links, so peak disk is the ~5.5 GB result rather than the
# 29 GB image.
#
# Cost: ~8 GB download + ~3-5 min wall-clock per HIP-lane run,
# comparable to the apt install it replaces.
- name: Install ROCm / HIP toolchain
if: ${{ (matrix.hip) && steps.impact.outputs.c_core == 'true' }}
env:
ROCM_VERSION: "7.2.3"
ROCM_IMAGE: "rocm/dev-ubuntu-24.04@sha256:a90cf047f615abe70fbef83c64def0a2d549ef37a39c8ea545430aba4981b374"
run: |
sudo apt-get update
sudo -E apt-get -yq install ccache ninja-build nasm libomp-dev \
pkg-config gcc g++ wget gnupg lsb-release
sudo install -d -m 0755 /etc/apt/keyrings
wget -qO- https://repo.radeon.com/rocm/rocm.gpg.key \
| gpg --dearmor \
| sudo tee /etc/apt/keyrings/rocm.gpg > /dev/null
UBUNTU_CODENAME="$(lsb_release -cs)"
echo "deb [arch=amd64 signed-by=/etc/apt/keyrings/rocm.gpg] https://repo.radeon.com/rocm/apt/${ROCM_VERSION} ${UBUNTU_CODENAME} main" \
| sudo tee /etc/apt/sources.list.d/rocm.list
printf 'Package: *\nPin: release o=repo.radeon.com\nPin-Priority: 600\n' \
| sudo tee /etc/apt/preferences.d/rocm-pin-600
sudo apt-get update
sudo -E apt-get -yq install --no-install-recommends rocm-hip-runtime-dev
# Surface the ROCm tooling on PATH / pkg-config / ld so
# meson's `dependency('hip-lang')` and the link of
# `amdhip64` resolve without per-step exports.
echo "/opt/rocm/bin" | sudo tee -a "$GITHUB_PATH"
echo "/opt/rocm/lib" | sudo tee /etc/ld.so.conf.d/rocm.conf
sudo -E apt-get -yq install --no-install-recommends \
ccache ninja-build nasm libomp-dev pkg-config gcc g++ jq
./scripts/ci/install-rocm-from-image.sh \
--image "$ROCM_IMAGE" --dest /opt/rocm
# Surface the ROCm tooling on PATH / pkg-config / ld so meson's
# `dependency('hip-lang')` and the link of `amdhip64` resolve
# without per-step exports.
echo "ROCM_PATH=/opt/rocm" | sudo tee -a "$GITHUB_ENV"
echo "/opt/rocm/bin" | sudo tee -a "$GITHUB_PATH"
echo "/opt/rocm/lib" | sudo tee /etc/ld.so.conf.d/rocm.conf
echo "PKG_CONFIG_PATH=/opt/rocm/lib/pkgconfig:${PKG_CONFIG_PATH:-}" \
| sudo tee -a "$GITHUB_ENV"
sudo ldconfig
Expand Down
11 changes: 7 additions & 4 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -440,10 +440,13 @@ linked AGENTS.md before resolving conflicts.
([ADR-0435](docs/adr/0435-local-dev-mcp-container.md)):
`dev/Containerfile` pins `cuda-toolkit-13-3`, the unversioned
`intel-basekit` meta-package (Intel does not publish a
`intel-basekit-2025.3` apt package), and `ROCM_VER=7.2.4` apt
repos. If SDK versions are bumped (routine security
maintenance), update the version pins and the apt repo URL paths in
`dev/Containerfile` before merging.
`intel-basekit-2025.3` apt package), and the digest-pinned
`rocm/dev-ubuntu-24.04:10.0.0-full` image in the `rocm-src` stage
(ADR-1225 — ROCm has no apt channel past 7.2.4). If SDK versions are
bumped (routine security maintenance), update the version pins and the
apt repo URL paths in `dev/Containerfile` before merging; a ROCm bump
additionally means re-validating the `rocm-src` prune list against its
hipcc smoke check.
`dev/scripts/smoke-probe-loop.sh` assumes the golden pair lives at
`${VMAF_TESTDATA_PATH}/ref_576x324_48f.yuv` / `dis_576x324_48f.yuv`
— do not rename these files. The probe JSON schema fields (`ts`,
Expand Down
33 changes: 33 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -10739,6 +10739,39 @@ core internal headers (`framesync.h`, `thread_pool.h`, `picture_pool.h`,
(62-run `--precision max` output matrix, 21 396 metric values). (ADR-1141)


- **ROCm 10.0.0 across every HIP consumer, installed from digest-pinned
container images** (ADR-1225). AMD froze the `repo.radeon.com/rocm/apt/`
channel at 7.2.4 when ROCm moved to the "TheRock" build/release system at
7.14 — `apt/7.14` and `apt/10.0.0` both 404, the manylinux channel stops at
`rocm-rel-7.2.4`, and the TheRock wheel index carries only 7.14.0 alphas —
so the fork now takes ROCm from `rocm/dev-ubuntu-24.04:10.0.0-full`
(digest-pinned) instead. `dev/Containerfile`,
`docker/Dockerfile.production-gpu` and `docker/Dockerfile.node` copy a
pruned `/opt/rocm` out of that image; the two CI HIP lanes use the new
`scripts/ci/install-rocm-from-image.sh`, which streams the image's
`/opt/rocm` out of the registry (peak disk ~5.5 GB rather than the 29 GB a
`docker pull` would need on a runner that already carries CUDA and oneAPI).
Verified on AMD `gfx1036` under Linux 7.2.3: HIP tests 19 Ok / 0 Fail and
an end-to-end HIP score of `45.315104`, bit-identical to the CPU reference.
- **`HSA_OVERRIDE_GFX_VERSION=10.3.0` removed from
`dev/docker-compose.yml`.** ROCm 10 supports `gfx1036` natively, so the
alias onto `gfx1030` that ROCm 6.x/7.x needed is now actively wrong — it
would map the agent to `gfx1030` while meson compiles `gfx1036` code
objects for the arch `rocm_agent_enumerator` reports.
- **`node-rocm` image ships the complete HIP runtime closure.** ROCm 10's
`libamdhip64.so` links `librocprofiler-register`, `librocm_kpack`,
`libamd_comgr` and the bundled `libLLVM` / `libclang-cpp` plus a
`rocm_sysdeps` bundle; the previous flat copy of `libamdhip64.so*` +
`libhsa-runtime64.so*` would have produced an image whose every HIP binary
died at load. The stage now copies the verified 397 MB closure with its
`$ORIGIN`-relative directory layout intact.
- **The README ROCm badge follows the image pin.** It scraped
`ARG ROCM_VER=` out of `dev/Containerfile`, which ADR-1225 removes; it now
reads the version out of the digest-pinned
`rocm/dev-ubuntu-24.04:<version>-full` reference in the same file, so it
keeps reporting a live value instead of going blank.


- **CI workflow display names are short again** (ADR-1227). GitHub's
`badge.svg` endpoint paints the workflow `name:` into the badge, so names
like `Tests & Quality Gates — Netflix Golden / Sanitizers / Tiny AI /
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@
[![C23](https://img.shields.io/badge/C-C23-00599C?logo=c&logoColor=white)](core/meson.build)
[![C++23](https://img.shields.io/badge/C%2B%2B-C%2B%2B23-00599C?logo=cplusplus&logoColor=white)](core/meson.build)
[![CUDA](https://img.shields.io/badge/dynamic/regex?url=https%3A%2F%2Fraw.githubusercontent.com%2FVMAFx%2Fvmafx%2Fmaster%2FDockerfile&search=nvidia%2Fcuda%3A%28%5Cd%2B%5C.%5Cd%2B%5C.%5Cd%2B%29&replace=%241&label=CUDA&color=76B900&logo=nvidia&logoColor=white)](Dockerfile)
[![ROCm](https://img.shields.io/badge/dynamic/regex?url=https%3A%2F%2Fraw.githubusercontent.com%2FVMAFx%2Fvmafx%2Fmaster%2Fdev%2FContainerfile&search=ARG%20ROCM_VER%3D%28%5Cd%2B%5C.%5Cd%2B%28%5C.%5Cd%2B%29%3F%29&replace=%241&label=ROCm&color=ED1C24&logo=amd&logoColor=white)](dev/Containerfile)
[![ROCm](https://img.shields.io/badge/dynamic/regex?url=https%3A%2F%2Fraw.githubusercontent.com%2FVMAFx%2Fvmafx%2Fmaster%2Fdev%2FContainerfile&search=rocm%2Fdev-ubuntu-24%5C.04%3A%28%5Cd%2B%5C.%5Cd%2B%5C.%5Cd%2B%29-full&replace=%241&label=ROCm&color=ED1C24&logo=amd&logoColor=white)](dev/Containerfile)

<!-- Hardware capability badges -->
[![GPU: CUDA · SYCL · HIP · Metal](https://img.shields.io/badge/GPU-CUDA%20%C2%B7%20SYCL%20%C2%B7%20HIP%20%C2%B7%20Metal-76B900?logo=nvidia&logoColor=white)](docs/backends/)
Expand Down
31 changes: 31 additions & 0 deletions changelog.d/changed/1225-rocm-10-therock-migration.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
- **ROCm 10.0.0 across every HIP consumer, installed from digest-pinned
container images** (ADR-1225). AMD froze the `repo.radeon.com/rocm/apt/`
channel at 7.2.4 when ROCm moved to the "TheRock" build/release system at
7.14 — `apt/7.14` and `apt/10.0.0` both 404, the manylinux channel stops at
`rocm-rel-7.2.4`, and the TheRock wheel index carries only 7.14.0 alphas —
so the fork now takes ROCm from `rocm/dev-ubuntu-24.04:10.0.0-full`
(digest-pinned) instead. `dev/Containerfile`,
`docker/Dockerfile.production-gpu` and `docker/Dockerfile.node` copy a
pruned `/opt/rocm` out of that image; the two CI HIP lanes use the new
`scripts/ci/install-rocm-from-image.sh`, which streams the image's
`/opt/rocm` out of the registry (peak disk ~5.5 GB rather than the 29 GB a
`docker pull` would need on a runner that already carries CUDA and oneAPI).
Verified on AMD `gfx1036` under Linux 7.2.3: HIP tests 19 Ok / 0 Fail and
an end-to-end HIP score of `45.315104`, bit-identical to the CPU reference.
- **`HSA_OVERRIDE_GFX_VERSION=10.3.0` removed from
`dev/docker-compose.yml`.** ROCm 10 supports `gfx1036` natively, so the
alias onto `gfx1030` that ROCm 6.x/7.x needed is now actively wrong — it
would map the agent to `gfx1030` while meson compiles `gfx1036` code
objects for the arch `rocm_agent_enumerator` reports.
- **`node-rocm` image ships the complete HIP runtime closure.** ROCm 10's
`libamdhip64.so` links `librocprofiler-register`, `librocm_kpack`,
`libamd_comgr` and the bundled `libLLVM` / `libclang-cpp` plus a
`rocm_sysdeps` bundle; the previous flat copy of `libamdhip64.so*` +
`libhsa-runtime64.so*` would have produced an image whose every HIP binary
died at load. The stage now copies the verified 397 MB closure with its
`$ORIGIN`-relative directory layout intact.
- **The README ROCm badge follows the image pin.** It scraped
`ARG ROCM_VER=` out of `dev/Containerfile`, which ADR-1225 removes; it now
reads the version out of the digest-pinned
`rocm/dev-ubuntu-24.04:<version>-full` reference in the same file, so it
keeps reporting a live value instead of going blank.
Loading
Loading