unsloth/studio/backend/core/inference/gpu_arbiter.py
Daniel Han 5eef2f4003 Studio: preserve foreign gallery files, force safetensors on remote ControlNets, and close dataset/seed/GPU gaps
Gallery clear/delete now scope to Studio-owned files: image_gallery and
video_gallery skip PNGs / MP4s without a readable recipe (a hand-dropped or
orphan file the listing already hides), so clear() and a guessed-id delete no
longer destroy files the gallery never surfaced.

Remote ControlNets now force use_safetensors: a bare owner/name reaches
from_pretrained without the base trust gate, and the Hub scan fails open when
unavailable, so requiring safetensors closes the pickle deserialization vector.

POSIX uninstall now stops resident sd-server / sd-cli under an owned sd.cpp root
before removing the tree (marker-gated), mirroring the Windows stop-before-delete
scan; a live native server no longer survives unlinking its binary.

Diffusion dataset containment: the training-start read path and the discovery
picker route bare names through the protected resolver, so a symlinked dataset
is rejected / not advertised like the caption/delete routes already do. Uploads
gain the inference decode guard (oversized real images 400 before OOMing the
trainer) and dataset upload/caption/delete/import are blocked with 409 while a
diffusion run is active.

JSONL readers (trainer + routes) tolerate non-object JSON and invalid UTF-8
instead of raising AttributeError / 500.

LoRA family compatibility is enforced in the shared resolver, not only the
picker, so a direct API client cannot apply a mismatched-family adapter.

GPU arbiter gains release_if so the image/video unload idle-check and release
are atomic against a concurrent same-owner load's registration. Native batch
recipes persist the base batch_seed and restore replays from it, so a native
batch_index>0 image no longer advances its seed twice.

FLUX.2-klein selects its sd.cpp text encoder by variant (4B -> Qwen3-4B,
9B -> Qwen3-8B) instead of the single family default.
2026-07-13 10:02:42 +00:00

116 lines
4.7 KiB
Python

# SPDX-License-Identifier: AGPL-3.0-only
# Copyright 2026-present the Unsloth AI Inc. team. All rights reserved. See /studio/LICENSE.AGPL-3.0
"""Single-GPU arbiter for Studio's heavy GPU consumers.
The chat backends, diffusion, and video share one GPU. Before taking it each calls
``acquire_for(owner)``, which evicts the current other owner so two large models never sit in VRAM
at once. The arbiter only sequences ownership (freeing is each backend's teardown); eviction runs
under the lock, so a transfer is atomic vs other acquires.
"""
from __future__ import annotations
import threading
from typing import Any, Callable, Optional
from loggers import get_logger
logger = get_logger(__name__)
CHAT = "chat"
DIFFUSION = "diffusion"
VIDEO = "video"
_lock = threading.Lock()
_owner: Optional[str] = None
def _evict_chat() -> None:
import time
from core.inference import get_inference_backend
from routes.inference import get_llama_cpp_backend
llama = get_llama_cpp_backend()
# is_active (process exists), not is_loaded (exists AND healthy): a chat model still starting
# up holds VRAM but isn't healthy, so is_loaded would skip it and let the load race diffusion.
if llama.is_active:
llama.unload_model()
orchestrator = get_inference_backend()
if orchestrator.active_model_name:
orchestrator.unload_model(orchestrator.active_model_name)
# Kill the subprocess too: its base CUDA context holds VRAM diffusion needs.
orchestrator._shutdown_subprocess(timeout = 5.0)
# The driver reclaims the killed VRAM asynchronously; wait for it to settle before diffusion
# allocates, else a warm chat->diffusion handoff can transiently OOM.
llama._wait_for_vram_settle(since_kill = time.monotonic())
def _evict_diffusion() -> None:
# Unload whichever engine the router has active (diffusers or native sd.cpp), so a
# chat acquire frees the right one.
from core.inference.diffusion_engine_router import get_active_diffusion_engine
get_active_diffusion_engine().unload()
def _evict_video() -> None:
from core.inference.video import get_video_backend
get_video_backend().unload()
# Patchable in tests via monkeypatch.setitem. Ownership is exclusive, so acquire_for's
# evict-the-current-owner generalises to any number of registered owners.
_EVICTORS = {CHAT: _evict_chat, DIFFUSION: _evict_diffusion, VIDEO: _evict_video}
def acquire_for(owner: str, register: Optional[Callable[[], Any]] = None) -> Any:
"""Make ``owner`` the sole GPU owner, evicting the other if it holds it.
``register``, if given, runs under the arbiter lock right after ownership transfers,
and its return value is returned. Registering the in-flight load HERE -- not after
``acquire_for`` returns -- closes the window where a competing acquire could evict this
owner before its load is marked in-flight: eviction would then find nothing to cancel
and both loaders would allocate VRAM at once. ``register`` must be quick (it holds the
lock) and must not re-enter the arbiter. If it raises, ownership stays with ``owner`` --
matching the pre-register behaviour where a failed load left the handoff in place.
"""
global _owner
if owner not in _EVICTORS:
raise ValueError(f"unknown GPU owner: {owner!r}")
with _lock:
if _owner is not None and _owner != owner:
logger.info("gpu_arbiter: evicting %s for %s", _owner, owner)
_EVICTORS[_owner]()
_owner = owner
return register() if register is not None else None
def release(owner: str) -> None:
"""Drop ``owner``'s claim (no-op if it isn't the current owner)."""
global _owner
with _lock:
if _owner == owner:
_owner = None
def release_if(owner: str, predicate: Callable[[], bool]) -> bool:
"""Drop ``owner``'s claim only if it still holds it AND ``predicate()`` is true, atomically.
A slow unload's "nothing resident / no load in flight" check and the ``release`` must not
straddle a concurrent same-owner load: that load's ``acquire_for(register=...)`` re-registers
ownership UNDER this lock, so a plain check-then-``release`` could pass the stale check and then
clear the newer claim (``release`` is owner-guarded but identity-less). Evaluating the predicate
under the lock closes that window -- the load's register runs either fully before or fully after.
``predicate`` must be quick (it holds the lock) and must not re-enter the arbiter. Returns True
iff ownership was dropped."""
global _owner
with _lock:
if _owner != owner or not predicate():
return False
_owner = None
return True
def current_owner() -> Optional[str]:
return _owner