mirror of
https://github.com/mudler/LocalAI.git
synced 2026-07-31 10:28:43 -04:00
The "Bump Backend dependencies" workflow has failed every night for the last two weeks. #11012 fixed one cause (repos renamed under localai-org); what is left is rate limiting. bump_deps.sh fans out to ~25 parallel matrix jobs that each query api.github.com anonymously. Anonymous calls are capped at 60/hour per source IP and GitHub-hosted runners egress through shared NAT addresses, so a random handful of jobs draw HTTP 403 and die at curl exit 22 with an empty response. Last night that hit ggml-org/whisper.cpp and mudler/depth-anything.cpp -- both public and resolvable, nothing wrong with either pin. Route every bump script through a shared gh_curl helper that sends GITHUB_TOKEN when present (1000/hour instead of 60) and retries transient failures, including the 403s that plain --retry ignores. The helper suppresses xtrace around the call so the Authorization header cannot land in a public job log. bump_docs.sh had a sharper version of the same bug: it piped an unchecked response into `jq -r .tag_name`, so a throttled request resolved to the string "null" and would have been published as the docs version. It now refuses to write anything it cannot resolve to a tag. Verified locally by running all four scripts end to end against their real upstreams: correct SHAs/tags written, exit 0; a nonexistent repo now fails with a named diagnostic instead of a bare exit 22 and leaves the pinned file untouched; the token is absent from the xtrace output; and the scripts still work unauthenticated. Assisted-by: Claude:opus-4.8 [Claude Code] Co-authored-by: localai-org-maint-bot <306269227+localai-org-maint-bot@users.noreply.github.com>
59 lines
2.6 KiB
Bash
Executable File
59 lines
2.6 KiB
Bash
Executable File
#!/bin/bash
|
|
# Bump the single vllm-metal pin (VLLM_METAL_VERSION) in the vLLM backend's
|
|
# darwin (Apple Silicon) install path. The macOS/Metal build
|
|
# (backend/python/vllm/install.sh, Darwin branch) installs vllm-metal, which is
|
|
# version-locked to a specific vLLM source release. install.sh derives that vLLM
|
|
# version at build time from vllm-metal's own installer (`vllm_v=`) at the pinned
|
|
# tag, so there is only ONE value to bump here -- mirroring bump_vllm_wheel.sh,
|
|
# which bumps the Linux cu130 wheel pin.
|
|
#
|
|
# This deliberately tracks vllm-project/vllm-metal, NOT vllm-project/vllm: the
|
|
# darwin build can only use the exact vLLM version vllm-metal supports, so it may
|
|
# lag the Linux pin (requirements-cublas13-after.txt) until vllm-metal catches up.
|
|
set -xe
|
|
|
|
source "$(dirname "${BASH_SOURCE[0]}")/gh_curl.sh"
|
|
|
|
REPO=$1 # vllm-project/vllm-metal
|
|
FILE=$2 # backend/python/vllm/install.sh
|
|
VAR=$3 # VLLM_METAL_VERSION (used for the workflow's output file names)
|
|
|
|
if [ -z "$FILE" ] || [ -z "$REPO" ] || [ -z "$VAR" ]; then
|
|
echo "usage: $0 <repo> <install-file> <var-name>" >&2
|
|
exit 1
|
|
fi
|
|
|
|
# vllm-metal ships frequent dev releases, all flagged as non-prerelease, so
|
|
# /releases/latest returns the newest one (with its cp312 wheel asset).
|
|
LATEST_TAG=$(gh_curl -H "Accept: application/vnd.github+json" \
|
|
"https://api.github.com/repos/$REPO/releases/latest" \
|
|
| python3 -c "import json,sys; print(json.load(sys.stdin)['tag_name'])")
|
|
|
|
# The coupled vLLM source version lives in vllm-metal's installer at that tag.
|
|
NEW_VLLM_VERSION=$(gh_curl \
|
|
"https://raw.githubusercontent.com/$REPO/$LATEST_TAG/install.sh" \
|
|
| grep -oE 'vllm_v="[0-9]+\.[0-9]+\.[0-9]+"' | head -1 | cut -d'"' -f2)
|
|
|
|
if [ -z "$LATEST_TAG" ] || [ -z "$NEW_VLLM_VERSION" ]; then
|
|
echo "Could not resolve vllm-metal tag ($LATEST_TAG) or its vllm_v ($NEW_VLLM_VERSION)." >&2
|
|
exit 1
|
|
fi
|
|
|
|
set +e
|
|
CURRENT_TAG=$(grep -oE 'VLLM_METAL_VERSION="[^"]*"' "$FILE" | head -1 | cut -d'"' -f2)
|
|
set -e
|
|
|
|
# Rewrite the single pin. install.sh derives VLLM_VERSION from this tag at build
|
|
# time, so there is nothing else to touch. peter-evans/create-pull-request opens
|
|
# no PR on a clean tree, so a no-op rewrite (already current) is safe.
|
|
sed -i "$FILE" \
|
|
-e "s|VLLM_METAL_VERSION=\"[^\"]*\"|VLLM_METAL_VERSION=\"$LATEST_TAG\"|"
|
|
|
|
if [ -z "$CURRENT_TAG" ]; then
|
|
echo "Could not find VLLM_METAL_VERSION=\"...\" in $FILE." >&2
|
|
exit 0
|
|
fi
|
|
|
|
echo "vllm-metal ${CURRENT_TAG} -> ${LATEST_TAG} (builds vLLM ${NEW_VLLM_VERSION}): https://github.com/$REPO/releases/tag/${LATEST_TAG}" >> "${VAR}_message.txt"
|
|
echo "${LATEST_TAG}" >> "${VAR}_commit.txt"
|