Repository navigation
build: make megatron_core wheel byte-reproducible - #25
Merged
Merged
Conversation
The daily-cron wheel megatron_core-0.19.0+4045637 has a churning sha256 (e908877f -> 2bf28206 -> 7a6132f0) even though it is always built from the same upstream commit. This breaks downstream `pip install --require-hashes`. Two non-determinism sources are fixed: 1. scripts/dependence/build.sh (megatron_build): the `python -m build` run had no SOURCE_DATE_EPOCH, so every rebuild stamped the current wall-clock time into every regenerated zip member (the compiled .so and *.dist-info/RECORD). Pin SOURCE_DATE_EPOCH to the source commit time and export deterministic compile/link flags (-ffile-prefix-map, -frandom-seed, -g0, -Wl,--build-id=none) so the whole wheel is stable for a given commit. 2. setup.py: the helpers_cpp Pybind11Extension only used -O3 -Wall -std=c++17, so the compiled .so could vary (build-id / embedded paths) when built directly. Add matching deterministic extra_compile_args plus extra_link_args=[-Wl,--build-id=none, -Wl,-s]. Verified: building the wheel twice with a full clean in between now yields an identical sha256 (089434eb...), whereas without the fix the two builds differ.
morirun
reviewed
Sep 19, 2026
morirun
left a comment
There was a problem hiding this comment.
初看(Draft,head 286b64e)
方向对:把 SOURCE_DATE_EPOCH 与确定性 C/C++/链接参数钉住,正好对上下游 --require-hashes 被 nightly 重打包打穿的问题(和 PaddleFleet 侧对齐 CI 的现象一致)。双次干净构建同 sha256 的验证也写清楚了。
小点
-
setup.py的-ffile-prefix-map=.=.
走build.sh时主要靠导出的CFLAGS/CXXFLAGS(已用${megatron_dir}=.),这条直接编译路径上的 map 基本是空操作,绝对构建路径仍可能进.so。若希望「不经过 build.sh 也稳定」,可改成与build.sh同类的真实前缀映射,或在注释里写明「直接setup.py构建不保证与 nightly 同 digest」。 -
-Wl,--build-id=none/-Wl,-s
GNU ld 场景合理;若以后同脚本在 macOS/非 GNU 链接器上编 helpers,这些 flag 可能告警或无效。当前若只发linux_x86_64wheel,可以接受,建议在 PR 里写死目标平台假设。 -
后续制品策略(PR Note 已提到)
可复现构建能稳住 digest;若 BOS 仍覆盖同一 URL,下游长期仍脆弱。不可变对象键是更好的下一刀,本 PR 不必一起做。
不代推、不代合;Draft 阶段仅作核对。
zrr1999
marked this pull request as ready for review
September 19, 2026 14:20
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The daily-cron wheel
megatron_core-0.19.0+<commit>published topaddle-github-action.bj.bcebos.com/whl/has a churning sha256 even though it is built from the same commit (observede908877f → 2bf28206 → 7a6132f0). Because the artifact URL is fixed and overwritten by every nightly rebuild, any downstream consumer that pins it withpip install --require-hashesbreaks intermittently. This took down PaddleFleet's GLM-5.2 accuracy-alignment CI (the referencesetup_reference.shaborted on a megatron_core hash mismatch before training).Root cause (non-reproducible build)
scripts/dependence/build.sh(megatron_build) runspython -m build --wheelwith noSOURCE_DATE_EPOCH, so every rebuild stamps the current wall-clock time into every regenerated zip member (the compiled.soand*.dist-info/RECORD) → different bytes → different sha256.setup.pybuilds themegatron.core.datasets.helpers_cppPybind11Extension with only-O3 -Wall -std=c++17— no deterministic compile/link flags, so the.socan vary (random ELF build-id, embedded build paths).Fix
build.sh: pinSOURCE_DATE_EPOCHto the source commit time (with a fixed fallback for tarball builds) and export deterministicCFLAGS/CXXFLAGS/LDFLAGS(-ffile-prefix-map,-frandom-seed,-g0,-Wl,--build-id=none).setup.py: add matchingextra_compile_args+extra_link_args=[-Wl,--build-id=none, -Wl,-s]so the.sois deterministic even when built directly.Verification
Built the wheel twice with a full clean in between:
089434eb…(MATCH ✅)f8b260e1…vs6a7bdf95…(DIFFER)Note
Reproducibility holds for a fixed toolchain (g++/GNU-ld/Python ABI,
cp312 linux_x86_64). A CI base-image compiler bump will legitimately move the digest once. Downstream consumers should still prefer immutable, uniquely-named artifacts; a complementary follow-up is to publish per-build immutable object keys rather than overwriting the fixed URL.