Skip to content

Commit 2eff547

Browse files
authored
Merge branch 'main' into tp-cp-compose
2 parents 12058ee + a12c38a commit 2eff547

108 files changed

Lines changed: 6341 additions & 1129 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.ai/skills/diffusers-cli/run.md‎

Lines changed: 15 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -108,7 +108,7 @@ Each entry calls `pipeline.load_lora_weights(<lora_id>, adapter_name=<name>)`. A
108108
- `--cpu-offload {model, group}` — `model` uses `enable_model_cpu_offload`, `group` uses
109109
`enable_group_offload(offload_type="leaf_level", use_stream=True)`. Use `group` to fit a 9B+ model on a single
110110
A100. Onload target device comes from `--device-map` (must be a plain device string in this case).
111-
- `--attention-backend {default, flash_hub, flash_varlen_hub, flash_4_hub, sage_hub}` — hub-hosted kernels,
111+
- `--attention-backend {default, flash_hub, flash_varlen_hub, flash_4_hub, sage_hub, sage_blackwell_hub}` — hub-hosted kernels,
112112
auto-downloaded on first use. Failures (kernel not available, CUDA arch mismatch, network) raise a clear
113113
`SystemExit` listing the alternatives instead of silently reverting to the default. Only supported on
114114
transformer-based pipelines; UNet pipelines get a `logger.warning` and the flag is ignored.
@@ -151,8 +151,8 @@ user also explicitly asked for a local target via `--output`.
151151
## Remote execution (`--remote`)
152152

153153
Add `--remote` to run the same call inside a [Hugging Face Sandbox](https://huggingface.co/docs/huggingface_hub/en/guides/sandbox)
154-
— an isolated cloud VM (built on HF Jobs) the CLI drives over HTTP: it uploads inputs, installs deps, runs
155-
the pipeline, downloads outputs, then terminates the sandbox.
154+
— an isolated cloud VM (built on HF Jobs) the CLI drives over HTTP: it uploads inputs, runs the pipeline,
155+
downloads outputs, then terminates the sandbox.
156156

157157
```bash
158158
diffusers-cli run \
@@ -167,12 +167,14 @@ What happens:
167167

168168
1. Your HF token is picked up (from `--token` or your login) and forwarded into the sandbox as `HF_TOKEN`.
169169
2. `--pipeline-kwargs` are parsed locally so JSON errors fail fast (no wasted sandbox time).
170-
3. A dedicated sandbox is created on `--flavor` from a pytorch image
171-
(`pytorch/pytorch:2.10.0-cuda12.8-cudnn9-runtime` by default) that already has torch + CUDA. Any local
172-
file paths in `--pipeline-kwargs` are uploaded into the sandbox under `/tmp/diffusers-cli/inputs/<run_id>/`
173-
via native file transfer (no bucket), and the JSON paths are rewritten to point at them.
174-
4. The small Python deps (`diffusers`, `accelerate`, `transformers`, `safetensors`, `sentencepiece`, `ftfy`)
175-
are installed with `uv pip install --system`. Output (install + run) streams live to your terminal.
170+
3. A dedicated sandbox is created on `--flavor` from `diffusers/diffusers-cli-cuda:latest` by default — a
171+
prebuilt image (`docker/diffusers-cli-cuda/` in this repo, rebuilt nightly) that already ships torch,
172+
CUDA, `diffusers`, and the rest of the CLI's deps. Any local file paths in `--pipeline-kwargs` are
173+
uploaded into the sandbox under `/tmp/diffusers-cli/inputs/<run_id>/` via native file transfer (no
174+
bucket), and the JSON paths are rewritten to point at them.
175+
4. No dependency install runs on the default image — that step is skipped unless you passed `--dependencies`
176+
(only the extras are installed then) or pointed `--image` somewhere else (the full set is installed).
177+
Output streams live to your terminal.
176178
5. The sandbox CLI writes outputs to `/tmp/diffusers-cli/outputs/`; the CLI downloads every artifact back into
177179
the local target (see [`--push-to`](#-push-to) for when the download is skipped).
178180
6. The sandbox is terminated (unless `--keep-alive`/`--sandbox-id`), and the wallclock `run_seconds` for the
@@ -182,12 +184,13 @@ Flags:
182184

183185
- `--flavor <name>` — sandbox hardware (e.g. `a10g-small`, `a100-large`, `4xa100-large`).
184186
- `--timeout <duration>` — max wallclock for the run command inside the sandbox (e.g. `30m`, `2h`). Defaults to `10m`.
185-
- `--dependencies <pkg>` — extra pip deps (repeatable). Appends to the defaults.
187+
- `--dependencies <pkg>` — extra pip deps (repeatable), installed on top of whatever the image ships.
186188
- `--namespace <name>` — create the sandbox under a different account.
187189
- `--push-to <bucket>` — see [`--push-to`](#-push-to) above. The upload runs inside the sandbox; an explicit
188190
value with no `--output` makes the bucket the sole destination and skips the local download.
189-
- `--image <ref>` — override the sandbox image. Must ship torch + CUDA; the CLI installs the small Python
190-
deps on top via `uv pip install --system`. Useful for pinning a specific torch or bundling extra system libs.
191+
- `--image <ref>` — override the sandbox image. Must ship torch + CUDA; the CLI then installs the small
192+
Python deps on top via `uv pip install --system` on every cold sandbox, which the default image avoids.
193+
Useful for pinning a specific torch or bundling extra system libs.
191194
- `--volume <bucket-id>[:<mount-path>]` — mount an HF storage bucket into the sandbox as a read-write directory.
192195
Repeatable. Default mount is `/mnt/buckets/<bucket-id>`. Reference mounted files from `--pipeline-kwargs`
193196
like any other local path — no upload happens, the container reads straight from the FUSE mount. Applied

‎.github/workflows/benchmark.yml‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,8 +5,6 @@ on:
55
schedule:
66
- cron: "30 1 1,15 * *" # every 2 weeks on the 1st and the 15th of every month at 1:30 AM
77

8-
permissions:
9-
contents: read
108

119
env:
1210
DIFFUSERS_IS_CI: yes
@@ -16,8 +14,12 @@ env:
1614
MKL_NUM_THREADS: 8
1715
BASE_PATH: benchmark_outputs
1816

17+
permissions: {}
18+
1919
jobs:
2020
torch_models_cuda_benchmark_tests:
21+
permissions:
22+
contents: read
2123
env:
2224
SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL_BENCHMARK }}
2325
name: Torch Core Models CUDA Benchmarking Tests

‎.github/workflows/bot_pytest.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -75,7 +75,7 @@ jobs:
7575
shell: bash
7676
steps:
7777
- name: Checkout PR head
78-
uses: actions/checkout@v6
78+
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
7979
with:
8080
# Works for forks too — no fork credentials needed.
8181
ref: refs/pull/${{ github.event.issue.number }}/head
@@ -116,7 +116,7 @@ jobs:
116116
117117
- name: Test suite reports artifacts
118118
if: ${{ always() }}
119-
uses: actions/upload-artifact@v6
119+
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
120120
with:
121121
name: bot_gpu_test_reports
122122
path: reports

‎.github/workflows/bot_review.yml‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,8 +27,11 @@ on:
2727
SERGE_INSTALLATION_ID:
2828
required: true
2929

30+
permissions: {}
31+
3032
jobs:
3133
relay:
34+
permissions: {}
3235
name: Relay to Serge
3336
concurrency:
3437
group: diffusers-bot-review-${{ github.event.issue.number || github.event.pull_request.number }}

‎.github/workflows/build_docker_images.yml‎

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ jobs:
3131
pull-requests: read
3232
steps:
3333
- name: Set up Docker Buildx
34-
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
34+
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
3535

3636
- name: Check out code
3737
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
@@ -54,6 +54,7 @@ jobs:
5454
diffusers-pytorch-xformers-cuda
5555
diffusers-pytorch-minimum-cuda
5656
diffusers-doc-builder
57+
diffusers-cli-cuda
5758
)
5859
5960
declare -A IMAGES_TO_BUILD=()
@@ -102,19 +103,20 @@ jobs:
102103
- diffusers-pytorch-xformers-cuda
103104
- diffusers-pytorch-minimum-cuda
104105
- diffusers-doc-builder
106+
- diffusers-cli-cuda
105107

106108
steps:
107109
- name: Checkout repository
108110
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
109111
- name: Set up Docker Buildx
110-
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
112+
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
111113
- name: Login to Docker Hub
112-
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3
114+
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
113115
with:
114116
username: ${{ env.REGISTRY }}
115117
password: ${{ secrets.DOCKERHUB_TOKEN }}
116118
- name: Build and push
117-
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
119+
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6.19.2
118120
with:
119121
no-cache: true
120122
context: ./docker/${{ matrix.image-name }}

‎.github/workflows/build_pr_documentation.yml‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,8 @@ permissions:
1616

1717
jobs:
1818
check-links:
19+
permissions:
20+
contents: read
1921
runs-on: ubuntu-latest
2022

2123
steps:

‎.github/workflows/claude_review.yml‎

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -6,13 +6,15 @@ on:
66
pull_request_review_comment:
77
types: [created]
88

9-
permissions:
10-
contents: write
11-
pull-requests: write
12-
issues: read
9+
10+
permissions: {}
1311

1412
jobs:
1513
claude-review:
14+
permissions:
15+
contents: write
16+
issues: read
17+
pull-requests: write
1618
if: |
1719
(
1820
github.event_name == 'issue_comment' &&

‎.github/workflows/issue_labeler.yml‎

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,12 +4,14 @@ on:
44
issues:
55
types: [opened]
66

7-
permissions:
8-
contents: read
9-
issues: write
7+
8+
permissions: {}
109

1110
jobs:
1211
label:
12+
permissions:
13+
contents: read
14+
issues: write
1315
runs-on: ubuntu-latest
1416
steps:
1517
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

‎.github/workflows/mirror_community_pipeline.yml‎

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -20,11 +20,13 @@ on:
2020
required: true
2121
default: 'main'
2222

23-
permissions:
24-
contents: read
23+
24+
permissions: {}
2525

2626
jobs:
2727
mirror_community_pipeline:
28+
permissions:
29+
contents: read
2830
env:
2931
SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL_COMMUNITY_MIRROR }}
3032
runs-on: ubuntu-22.04
@@ -69,13 +71,13 @@ jobs:
6971
run: |
7072
echo "CHECKOUT_REF: ${{ env.CHECKOUT_REF }}"
7173
echo "PATH_IN_REPO: ${{ env.PATH_IN_REPO }}"
72-
- uses: actions/checkout@v6
74+
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
7375
with:
7476
ref: ${{ env.CHECKOUT_REF }}
7577

7678
# Setup + install dependencies
7779
- name: Set up Python
78-
uses: actions/setup-python@v6
80+
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
7981
with:
8082
python-version: "3.10"
8183
- name: Install dependencies

‎.github/workflows/nightly_tests.yml‎

Lines changed: 20 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,8 +5,6 @@ on:
55
schedule:
66
- cron: "0 0 * * *" # every day at midnight
77

8-
permissions:
9-
contents: read
108

119
env:
1210
DIFFUSERS_IS_CI: yes
@@ -25,8 +23,12 @@ env:
2523
# (torchvision::nms). The pinned set is (re)written into the override file per job below.
2624
UV_OVERRIDE: /tmp/uv-overrides.txt
2725

26+
permissions: {}
27+
2828
jobs:
2929
setup_torch_cuda_pipeline_matrix:
30+
permissions:
31+
contents: read
3032
name: Setup Torch Pipelines CUDA Slow Tests Matrix
3133
runs-on:
3234
group: aws-general-8-plus
@@ -58,6 +60,8 @@ jobs:
5860
path: reports
5961

6062
run_nightly_tests_for_torch_pipelines:
63+
permissions:
64+
contents: read
6165
name: Nightly Torch Pipelines CUDA Tests
6266
needs: setup_torch_cuda_pipeline_matrix
6367
strategy:
@@ -110,6 +114,8 @@ jobs:
110114
path: reports
111115

112116
run_nightly_tests_for_other_torch_modules:
117+
permissions:
118+
contents: read
113119
name: Nightly Torch CUDA Tests
114120
runs-on:
115121
group: aws-g4dn-2xlarge
@@ -180,6 +186,8 @@ jobs:
180186
path: reports
181187

182188
run_torch_compile_tests:
189+
permissions:
190+
contents: read
183191
name: PyTorch Compile CUDA tests
184192

185193
runs-on:
@@ -223,6 +231,8 @@ jobs:
223231
path: reports
224232

225233
run_big_gpu_torch_tests:
234+
permissions:
235+
contents: read
226236
name: Torch tests on big GPU
227237
strategy:
228238
fail-fast: false
@@ -275,6 +285,8 @@ jobs:
275285
path: reports
276286

277287
torch_minimum_version_cuda_tests:
288+
permissions:
289+
contents: read
278290
name: Torch Minimum Version CUDA Tests
279291
runs-on:
280292
group: aws-g4dn-2xlarge
@@ -332,6 +344,8 @@ jobs:
332344
path: reports
333345

334346
run_nightly_quantization_tests:
347+
permissions:
348+
contents: read
335349
name: Torch quantization nightly tests
336350
strategy:
337351
fail-fast: false
@@ -402,6 +416,8 @@ jobs:
402416
path: reports
403417

404418
run_nightly_pipeline_level_quantization_tests:
419+
permissions:
420+
contents: read
405421
name: Torch quantization nightly tests
406422
strategy:
407423
fail-fast: false
@@ -453,6 +469,8 @@ jobs:
453469
path: reports
454470

455471
generate_consolidated_report:
472+
permissions:
473+
contents: read
456474
name: Generate Consolidated Test Report
457475
needs: [
458476
run_nightly_tests_for_torch_pipelines,

0 commit comments

Comments
 (0)