Skip to content

Design: environments and containers on Torch - #28

Merged
renmengye merged 2 commits into
mainfrom
docs/environments
Aug 6, 2026
Merged

renmengye merged 2 commits into
mainfrom
docs/environments

Conversation

@renmengye

Copy link
Copy Markdown
Member

Per Mengye's Singularity question + the Torch docs (Apptainer is the only supported runtime): containers where they pay — per-target Apptainer images declared in each contract (experiments; reproducibility + --nv GPU path), host uv venv for the tick (it drives host Slurm; containerizing it is friction without benefit), and Apptainer --no-home as the named OS-sandboxing step for agent sessions (closes the threat model's residual same-user filesystem risk).

🤖 Generated with Claude Code

renmengye and others added 2 commits August 6, 2026 10:49
… experiments, contained sessions as hardening path

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Aug 6, 2026 •

Copy link
Copy Markdown

Advisory review — not an approval. Automated findings from autoresearch; a human code owner still owns this PR. Reply to any finding you disagree with, or add the opt-out label to silence future runs on this PR.

  • Reproducibility claim contradicts the pinning mechanism actually specified (medium confidence, docs/design/architecture.md:372)
    The table asserts a pinned image makes the contract's determinism promise stronger via "same digest at claim time and at CI re-verification", but the mechanism specified two paragraphs later is an absolute path to a mutable .sif file on the shared filesystem, with digest pinning deferred ("pin by content digest once images churn"). An absolute path gives no digest identity: the file can be rebuilt/overwritten between claim time and re-verification, so the stated verification property does not hold as designed. Either the claim should be softened or the environment block should carry a digest field from the start.
  • docker://... pull option conflicts with the stated no-Docker/pinning constraints (medium confidence, docs/design/architecture.md:378)
    The example comment allows docker://... to pull while the same section states the design pins images on the shared filesystem by absolute path for reproducibility. A docker:// reference resolved at experiment launch (a) requires outbound network from the compute node at run time, (b) resolves a mutable tag rather than a fixed artifact, and (c) writes into an Apptainer cache under HOME — all of which undercut the determinism argument in the row above. Worth stating explicitly whether pull-at-launch is permitted, and if so with a required digest tag.
  • Unconditional --nv for every containerized experiment, including CPU-only targets (low confidence, docs/design/architecture.md:381)
    The launcher is specified to wrap the benchmark command in apptainer exec --nv &lt;image&gt; ... whenever the block is present. The phase 5 pilot target is explicitly CPU-only, and --nv on a host without NVIDIA driver libraries produces a warning (and, depending on Apptainer version/config, can fail), plus it injects host driver libraries that undermine the "same image everywhere" reproducibility goal. The flag should be conditional on the target/partition requesting a GPU rather than always applied.
  • --no-home --bind &lt;workspace&gt; hardening claim is stronger than the mechanism supports, and tension with per-run HOME resume (low confidence, docs/design/architecture.md:374)
    Two points: (1) Apptainer by default still mounts the current working directory and /tmp, and the workspace bind may sit under a shared state root, so "a contained session cannot read same-user absolute paths (key files, other runs)" only holds if cwd/tmp mounts are also suppressed and the bind is scoped below the run directory — worth spelling out the exact flag set. (2) Phase 3 relies on a redirected per-run HOME for Claude Code credentials and resume_session_id state; --no-home disables home mounting, so the design should state that the redirected HOME lives inside the bound workspace and is exported inside the container, otherwise resume and env-key auth break.

Docs-only change; no code paths to verify. The cluster-docs URL, Torch's Apptainer configuration (e.g., whether cwd/tmp auto-mounts are enabled and whether compute nodes have outbound network for docker:// pulls), and the actual contract schema/launcher code are not in the provided context, so the container-behavior findings are design-consistency observations rather than verified defects.

@renmengye
renmengye merged commit b52eedf into main Aug 6, 2026
6 checks passed
@renmengye
renmengye deleted the docs/environments branch August 6, 2026 14:51
This was referenced Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant