Repository navigation
fix(docker): run the oneAPI release image on Debian 13 with the pinned Intel GPU runtime - #1629
Merged
Merged
Conversation
lusoris
force-pushed
the
fix/release-oneapi-image-runtime
branch
from
September 29, 2026 14:36
c9f2e7b to
a74842e
Compare
lusoris
force-pushed
the
fix/release-oneapi-image-runtime
branch
from
September 29, 2026 14:47
a74842e to
9675aa6
Compare
6 of 12 tasks
lusoris
force-pushed
the
fix/release-oneapi-image-runtime
branch
from
September 29, 2026 16:52
9675aa6 to
b9cc797
Compare
…d Intel GPU runtime The published oneAPI image crashed every `vmaf --backend sycl` run on an Arc B580 (exit 139 right after device selection). The cause is the Intel GPU compute runtime (NEO 25.18) that Intel's oneapi-runtime:2025.3.1 image carries: swapping only that runtime for NEO 26.35 in the unchanged image fixes the crash, and swapping only the Level Zero loader does not. The image now follows the design build-config.env already recorded (ADR-1368). Builder and final stage start from the release track's debian:13-slim. scripts/ci/install-intel-oneapi.sh installs Intel's oneAPI 2026.1 compiler or SYCL runtime plus UMF at apt build 2026.1.1-325, with the repository key pinned by fingerprint. install-intel-ocloc.sh gains `--components build|runtime`, which adds the NEO GPU runtime at INTEL_NEO_VERSION (the package set the dev container uses) and the Level Zero loader at LEVEL_ZERO_VERSION, checked against GitHub's asset digests. The base-image gate now requires ONEAPI_BUILDER and ONEAPI_RUNTIME to equal RELEASE_BUILDER_BASE, and its distro exemption list is empty. The image is published as `-oneapi2026`. The `-oneapi2025` tag and the `final-oneapi2025` stage stay as aliases of the same image. In the rebuilt image the B580 and a UHD 770 match `--backend cpu` within the parity gate for the default model, psnr_hvs and ssimulacra2 on the Netflix pair and BBB 4K. The image shrinks from 5.86 GB to 2.39 GB. Closes T-RELEASE-ONEAPI-IMAGE-B580-SIGSEGV-2026-09-29. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
lusoris
force-pushed
the
fix/release-oneapi-image-runtime
branch
from
September 30, 2026 08:23
b9cc797 to
d645609
Compare
The rebase onto #1626 kept master's open copy of T-RELEASE-ONEAPI-IMAGE-B580-SIGSEGV-2026-09-29 next to this branch's closing row. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Sep 30, 2026
#1629 moved three sys.exit calls in dev/scripts/fetch-intel-neo.py, so their HISS-07 fingerprints changed line. Recorded again from master's baseline with praetor 25451d8: still 185 -> 431, the same 246 engine findings; f41e74d still re-records 185 on this tree. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Sep 30, 2026
#1629 moved three sys.exit calls in dev/scripts/fetch-intel-neo.py, so their HISS-07 fingerprints changed line. Recorded again from master's baseline with praetor 25451d8: still 185 -> 431, the same 246 engine findings; f41e74d still re-records 185 on this tree. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Sep 30, 2026
) * perf(sycl): read the shared frame in psnr, psnr_hvs and motion_v2 The SYCL psnr_hvs, psnr and motion_v2 twins now read the planes the SYCL state uploads once per frame instead of converting and uploading their own copies. Scores are bit-identical to the previous twins on an Arc B580 and a UHD 770. - Opt-in shared Cb/Cr planes in common.cpp (vmaf_sycl_shared_chroma_init / _upload, vmaf_sycl_get_shared_plane): the first chroma-reading twin of a frame packs the chroma into pinned staging and uploads it with one DMA per plane; later twins reuse it. Luma-only runs never allocate chroma. - vmaf_sycl_queue_after_upload() gives twins on their own queue the input barriers the combined graph gets; a device-side slot fence orders each upload after the last readers of the slot it overwrites. - psnr_hvs: no host float conversion or private upload; two work-items per 8x8 block, one dispatch for all planes, per-block float expressions unchanged. 9- and 11-bit input now scores the raw sample like the CPU. - motion_v2: runs the ADR-1371 pipeline on the shared luma and keeps the frame through its cur_copy; no host copy or private upload. - psnr: chroma from the shared planes; one atomic per work-group. At 3840x2160, psnr_hvs drops from 17.1 to 7.6 ms per frame on the B580 and from 124 to 60 on the UHD 770, where psnr drops from 25.3 to 12.3. ADR-1369, Research-1369. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs: regenerate generated docs after rebasing onto master Merge the RC2/RC3 disposition rows three-way by bug id: master (#1626) had two RC3 rows from an earlier keep-both resolution, and this branch adds three RC2 and six RC3 ids. Drop the open oneAPI B580 row #1629 closed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
12 of 19 tasks
lusoris
added a commit
that referenced
this pull request
Sep 30, 2026
The docs/state.md resolver let master's side of each conflict hunk win and added only the bug ids master lacked. Mid-rebase "ours" is master plus the branch commits already replayed, so on 2026-09-30 it kept master's Open copy of bugs a branch had closed (#1627, #1629) and an earlier commit's text of a row a later commit rewrote (#1625). Disposition rows conflicted on nearly every rebase, and keep-both left master with two RC3 rows. The resolver now reads the three index stages git keeps for the conflicted path and merges them three-way (ADR-1383): - rows and move tombstones are keyed by bug id, in the shapes check-state-md-rows.sh recognises; a row's state is its text plus its section, so a move, an edit, a close or a deletion on one side carries over - disposition rows are keyed by their bold label; their id lists merge as sets and repeated labels are folded into one row - every other line merges three-way by line; lines both sides added are kept, a line both sides added identically is kept once, and overlapping deletions are not a conflict - a row both sides changed differently stops the tool with exit 1 and nothing written; --take NAME=ours|theirs settles it explicitly It writes LF bytes, runs the row gate on its result and exits 3 when the gate rejects it or an id sits in two disposition rows. The test suite now builds throwaway repositories and drives real git rebase conflicts through the tool. CI never ran the old test; it now runs in the state.md row hygiene step of the Rules workflow and under the git fixture isolation suite. Research-1383 replays the rebase conflicts of the PRs merged since 2026-09-20 through both resolvers. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Sep 30, 2026
#1629 moved three sys.exit calls in dev/scripts/fetch-intel-neo.py, so their HISS-07 fingerprints changed line. Recorded again from master's baseline with praetor 25451d8: still 185 -> 431, the same 246 engine findings; f41e74d still re-records 185 on this tree. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Sep 30, 2026
The docs/state.md resolver let master's side of each conflict hunk win and added only the bug ids master lacked. Mid-rebase "ours" is master plus the branch commits already replayed, so on 2026-09-30 it kept master's Open copy of bugs a branch had closed (#1627, #1629) and an earlier commit's text of a row a later commit rewrote (#1625). Disposition rows conflicted on nearly every rebase, and keep-both left master with two RC3 rows. The resolver now reads the three index stages git keeps for the conflicted path and merges them three-way (ADR-1383): - rows and move tombstones are keyed by bug id, in the shapes check-state-md-rows.sh recognises; a row's state is its text plus its section, so a move, an edit, a close or a deletion on one side carries over - disposition rows are keyed by their bold label; their id lists merge as sets and repeated labels are folded into one row - every other line merges three-way by line; lines both sides added are kept, a line both sides added identically is kept once, and overlapping deletions are not a conflict - a row both sides changed differently stops the tool with exit 1 and nothing written; --take NAME=ours|theirs settles it explicitly It writes LF bytes, runs the row gate on its result and exits 3 when the gate rejects it or an id sits in two disposition rows. The test suite now builds throwaway repositories and drives real git rebase conflicts through the tool. CI never ran the old test; it now runs in the state.md row hygiene step of the Rules workflow and under the git fixture isolation suite. Research-1383 replays the rebase conflicts of the PRs merged since 2026-09-20 through both resolvers. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Sep 30, 2026
…1638) * fix(dev): resolve docs/state.md rebase conflicts three-way by bug id The docs/state.md resolver let master's side of each conflict hunk win and added only the bug ids master lacked. Mid-rebase "ours" is master plus the branch commits already replayed, so on 2026-09-30 it kept master's Open copy of bugs a branch had closed (#1627, #1629) and an earlier commit's text of a row a later commit rewrote (#1625). Disposition rows conflicted on nearly every rebase, and keep-both left master with two RC3 rows. The resolver now reads the three index stages git keeps for the conflicted path and merges them three-way (ADR-1383): - rows and move tombstones are keyed by bug id, in the shapes check-state-md-rows.sh recognises; a row's state is its text plus its section, so a move, an edit, a close or a deletion on one side carries over - disposition rows are keyed by their bold label; their id lists merge as sets and repeated labels are folded into one row - every other line merges three-way by line; lines both sides added are kept, a line both sides added identically is kept once, and overlapping deletions are not a conflict - a row both sides changed differently stops the tool with exit 1 and nothing written; --take NAME=ours|theirs settles it explicitly It writes LF bytes, runs the row gate on its result and exits 3 when the gate rejects it or an id sits in two disposition rows. The test suite now builds throwaway repositories and drives real git rebase conflicts through the tool. CI never ran the old test; it now runs in the state.md row hygiene step of the Rules workflow and under the git fixture isolation suite. Research-1383 replays the rebase conflicts of the PRs merged since 2026-09-20 through both resolvers. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(research): record the final state.md replay numbers The last replay ran after the overlapping-deletion fix; the older window now has no refusals left from that defect and no conflict markers. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(state): fold the duplicate RC3 disposition row and drop a stale _Updated line Keep-both resolutions left two "RC3 performance and backend acceleration" rows under "## First-release phase classification" and both versions of union of their ids, exactly as the resolver folds repeated labels; every id in the union is an open row. The first version of #1625's _Updated line is dropped: the branch had already replaced it before its final rebase. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(ci): make check-state-md-rows.sh work with Debian 12's mawk mawk 1.3.4 20200120, the awk of Debian 12, reads regex intervals such as {0,2} and {4} literally. The gate's id pattern then matched no row, so it reported "OK (0 id-bearing rows ...)" for every file and never ran its duplicate-id or tombstone checks. The same mawk strips only one asterisk with \*?\*?, so the optional bold is now spelled (\*\*|\*)? and the verification date without intervals. CI's Ubuntu runner has a newer mawk and was not affected; the self-test now passes on both. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(state): say what the rebase left of the ledger cleanup rebase this branch only drops the stale _Updated line; the _Updated entry now says so. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs: regenerate generated docs after rebasing onto master Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs: regenerate generated docs after rebasing onto master Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Sep 30, 2026
#1629 moved three sys.exit calls in dev/scripts/fetch-intel-neo.py, so their HISS-07 fingerprints changed line. Recorded again from master's baseline with praetor 25451d8: still 185 -> 431, the same 246 engine findings; f41e74d still re-records 185 on this tree.
This was referenced Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The published oneAPI image crashed every
vmaf --backend syclrun on an Arc B580 (exit 139 right after device selection); a UHD 770 worked. The cause is the Intel GPU compute runtime (NEO 25.18) that Intel'soneapi-runtime:2025.3.1image carries. In the unchanged image, swapping only that runtime for NEO 26.35 stops the crash, and swapping only the Level Zero loader does not.This PR moves the image to the design
build-config.envalready described (ADR-1368):debian:13-slim, like the CPU image.scripts/ci/install-intel-oneapi.sh. The repository key is pinned by fingerprint.INTEL_NEO_VERSION(the package set the dev container installs) and the Level Zero loader atLEVEL_ZERO_VERSIONcome from the existingscripts/ci/install-intel-ocloc.sh, which gains--components build|runtime. The fetcher checks the loader against GitHub's asset digests.-oneapi2026. The-oneapi2025tag and thefinal-oneapi2025stage stay as aliases of the same image (HISS-14).ONEAPI_BUILDERandONEAPI_RUNTIMEto equalRELEASE_BUILDER_BASE, and its distro exemption list is empty.It also fixes a second break found on the way: on current
masterthe 2025.3.2 builder no longer links the unit tests.libsycl-devicelib-host.aneeds libm after--as-neededhas dropped it. The 2026.1.1 compiler links them.Closes
T-RELEASE-ONEAPI-IMAGE-B580-SIGSEGV-2026-09-29.Type
fix— bug fixbuild/ci— tooling / infraChecklist
make format && make lintis green locally. The repository's pre-commit framework passes on this diff in a Linux container (every hook, REUSE included), plus hadolint 2.14.0, shellcheck 0.11.0, shfmt 3.13.1 and actionlint.praetorctlgovernance was not available on this host; CI runs it.python3 scripts/ci/run_meson_test.py -- -C build. Not run separately; the image builder compiles and links every unit test with the 2026.1.1 compiler. The changed Python and shell contracts pass (fetcher 21 tests, base-image single-source 77, dev-container secret 31, CUDA installer 18, image runtime and publish source-binding contracts)./cross-backend-diffand the worst ULP is ≤ 2. No kernel code changed. The image's SYCL scores were compared with its CPU backend under the parity-gate tolerances (table below)..c/.cpp/.cu/.h/.hpp, it has the appropriate license header (seeCONTRIBUTING.md). None added; the new shell script carries the EUPL-1.2 header.!orBREAKING CHANGE:and the migration path is documented below. Not breaking: both old names keep working.docs/adr/_index_fragments/<NNNN-slug>.mdand the slug is appended todocs/adr/_index_fragments/_order.txt.Bug-status hygiene (ADR-0165)
docs/state.mdupdated in this PR:T-RELEASE-ONEAPI-IMAGE-B580-SIGSEGV-2026-09-29moved to "Recently closed", with the evidence and a copy-paste check for a native Linux host.Netflix golden-data gate (ADR-0024)
assertAlmostEqual(...)score in the Netflix golden Python tests.Cross-backend numerical results
--backend syclin the rebuilt image against--backend cpuin the same image. Windows 11 host, Docker Desktop WSL 2 backend,/dev/dxg. Every GPU run heldflock /f/gpu.lock. Tolerances are the parity gate's (FEATURE_TOLERANCE,metric_delta,area_tolerance_factor; the VMAF score at places=4), checked per frame and per metric. Each JSON'sfeature_backendsconfirms the SYCL twin ran.Image built at this branch's head (
final-oneapi2026, AOT image check: 30 fat binaries, 19 targets).vmaf)integer_motion21.2e-5 (5e-5)vmaf)integer_motion21.2e-5 (5e-5)--feature psnr_hvspsnr_hvs_y8.3e-5 (5e-4)--feature psnr_hvspsnr_hvs_y8.3e-5 (5e-4)--feature ssimulacra2--feature ssimulacra2vmaf)integer_motion25e-6 (5e-5)vmaf)integer_motion25e-6 (5e-5)--feature psnr_hvspsnr_hvs_y8.43e-4 (3.34e-3, area-scaled)--feature psnr_hvspsnr_hvs_y8.43e-4 (3.34e-3, area-scaled)--feature ssimulacra2--feature ssimulacra2Root-cause probe
The same 2025-built binary (
final-oneapi2025at2d9d5b069) in every row, with packages swapped. Default model, Netflix pair, 2 frames.Image size
final-oneapi2025, probe at2d9d5b069)final-oneapi2026)docker save+ gzip -6Deep-dive deliverables (ADR-0108)
docs/research/2128-oneapi-release-image-runtime.md: the probe, Intel's apt repository layout and pins, the key, the rebuilt image and its scores.## Alternatives considered: overlay NEO on the 2025 images, Intel's 2026 images, Debian 13 with pinned packages (chosen), Debian's Level Zero loader, a second NEO installer, switchingdev/Containerfilenow, and four tag-naming options.AGENTS.mdinvariant note —docker/AGENTS.md(oneAPI bases and the image's load-bearing steps) anddev/AGENTS.md(the shared installer and fetcher).changelog.d/fixed/release-oneapi-image-runtime.mdandchangelog.d/changed/release-oneapi-image-tag.md.docs/rebase-notes.md, "ADR-1368 — oneAPI release image on Debian 13 with pinned Intel packages".Reproducer
On a Linux host with an Intel GPU:
On Windows with Docker Desktop, pass
--device /dev/dxg -v /usr/lib/wsl:/usr/lib/wsl:roinstead of/dev/dri, and append:/usr/lib/wsl/libto the image'sLD_LIBRARY_PATH(seedocs/development/docker-production.md).Known follow-ups
/dev/dxgand the host driver's/usr/lib/wsl/lib, which is not thei915/xerender-node path. The state row carries the copy-paste check for the maintainer's RTX 4090 + Arc A380 box.dev/Containerfilekeeps its own NEO and Level Zero steps. They install the same package set through the same fetcher, but theirRUNs are bound to the BuildKit-secret contract (ADR-1271) andcheck-workflow-versions.py, so moving them onto the installer is a separate change.install-intel-oneapi.shand--components buildcould replace both.install-intel-ocloc.sh.node-sycl(unpublished) builds libvmaf without SYCL, so the runtime it copies is unused. Unchanged here; the target builds with the new runtime stage.🤖 Generated with Claude Code