Add: attach registered device Buffer sources at L2 submission - #2482
Conversation
Separate source wrapping from consumer attachment. Buffer.wrap records a caller-owned address in a live context; Worker.submit validates and pins that registration before materialization through the existing argument and import path. Tensor views retain the same canonical Buffer identity. Fence source close with accepted uses, reject stale descriptors and context tokens, and keep unproven native uses retained after errors. Worker free and copy do not manage these external allocations. Cover context, provenance, overlap, failure and concurrent close paths, and exercise the producer/consumer path with externally owned storage.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (6)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe change adds ChangesBorrowed Device Sources
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~60 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant PythonCaller
participant Worker
participant Buffer
participant DeviceBufferSource
participant L2RunLane
PythonCaller->>Worker: Request device_location
Worker-->>PythonCaller: Return BufferLocation
PythonCaller->>Buffer: Wrap address with Buffer.wrap
Buffer->>DeviceBufferSource: Register source range
PythonCaller->>Worker: Submit Tensor containing Buffer
Worker->>DeviceBufferSource: Validate and reserve source
Worker->>L2RunLane: Submit native run
L2RunLane-->>Worker: Report successful completion
Worker->>DeviceBufferSource: Release source use at finalization
Merge Risk: ⚪ Minimal · up to This change adds an opt-in API for registering externally owned device memory for direct L2 submissions. The supplied context shows no concrete failure introduced by the change. Existing behavior is unchanged for callers that do not use the new API. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Borrowed device memory is useful, but it moves an important safety guarantee to the caller: the library cannot establish that a supplied address belongs to the caller or remains allocated. Submission lifecycle controls reduce the risk of premature release through this API. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
Warning Some tools did not complete. Review the errors below. 🔧 Ruff (0.16.6)python/simpler/worker.py�[1;31mruff failed�[0m python/simpler/buffer.py�[1;31mruff failed�[0m tests/ut/py/test_worker/test_l2_argument_binding.py�[1;31mruff failed�[0m
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. I’m a rabbit with a buffer to wrap, Comment |
Summary
Caller-owned device storage can enter the direct L2 Buffer/Tensor/TaskArgs path without a Worker-specific buffer constructor:
Wrapping creates a source registration. Submission installs a private consumer snapshot and reserves the source before materialization. The Buffer identity and descriptor stay unchanged; existing geometry, grant, transfer, exact-worker and import checks remain active. Close and acquisition share the source lock, so a cached attachment cannot revive a released source. Rewrapping an idle address creates a new identity. Live source overlap is refused; overlap with an owned allocation is refused on attachment.
The current context provider is
Worker.device_locationon an initialized direct L2 Program Worker. The token identifies that process and Worker incarnation, not merely a device ordinal. Foreign Workers, forked processes and closed contexts are refused. This deliberately does not attach an externally owned RTS context or add a cross-Worker/Remote grant. Those consumers need their own context provider and authorization path; this PR does not mark U1b or kernel eager complete.Lifetime and limits
Follow-up to #2480, related to #2460. Replaces the proposed
worker.borrow_device_buffersurface in draft #2475; it does not include the independent native fix already merged as #2478. No native ABI changes or planning documents are included.Validation
task_20260929_022352_171443715530, device 8). A5 onboard was not run locally. The later context-error guard is covered by unit tests; no new hardware success-path behavior was added after this run.The cached-close test fails before the reservation validates already-attached source identities under its lock. The fork test times out before the process check is moved ahead of mutex acquisition.
a938898b: complete Python unit suite 2833 passed, 65 skipped after rebuilding the editable package at that commit.