Skip to content

Commit 4f2904b

Browse files
committed
Merge branch 'master' into fix-docs-backfill-workflow
2 parents c2be1e5 + 283d709 commit 4f2904b

19 files changed

Lines changed: 1073 additions & 5 deletions

‎.github/workflows/coverity.yml‎

Lines changed: 138 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,138 @@
1+
name: Coverity Scan
2+
3+
on:
4+
schedule:
5+
- cron: "0 1 * * 1"
6+
workflow_dispatch:
7+
8+
permissions:
9+
contents: read
10+
11+
concurrency:
12+
group: coverity-${{ github.ref }}
13+
cancel-in-progress: true
14+
15+
env:
16+
COVERITY_PROJECT: IntelPython/dpctl
17+
ONEAPI_ROOT: /opt/intel/oneapi
18+
19+
jobs:
20+
coverity-scan:
21+
if: github.repository == 'IntelPython/dpctl'
22+
runs-on: ubuntu-latest
23+
timeout-minutes: 150
24+
25+
steps:
26+
- name: Checkout repo
27+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
28+
with:
29+
# versioneer needs the tags to compute the package version
30+
fetch-depth: 0
31+
32+
- name: Add Intel repository
33+
run: |
34+
wget -qO- https://apt.repos.intel.com/intel-gpg-keys/GPG-PUB-KEY-INTEL-SW-PRODUCTS.PUB \
35+
| gpg --dearmor | sudo tee /usr/share/keyrings/oneapi-archive-keyring.gpg > /dev/null
36+
echo "deb [signed-by=/usr/share/keyrings/oneapi-archive-keyring.gpg] https://apt.repos.intel.com/oneapi all main" \
37+
| sudo tee /etc/apt/sources.list.d/oneAPI.list
38+
sudo apt update
39+
40+
- name: Install latest Intel OneAPI
41+
run: |
42+
sudo apt install intel-oneapi-compiler-dpcpp-cpp
43+
sudo apt install intel-oneapi-tbb
44+
sudo apt install intel-oneapi-umf
45+
sudo apt install hwloc
46+
47+
- name: Install CMake and Ninja
48+
run: |
49+
sudo apt-get install ninja-build
50+
51+
- name: Setup Python
52+
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
53+
with:
54+
python-version: '3.12'
55+
architecture: x64
56+
57+
- name: Install dpctl dependencies
58+
run: |
59+
pip install numpy cython setuptools"<80" scikit-build cmake ninja versioneer[toml]==0.29
60+
61+
- name: Report compiler version
62+
run: |
63+
source "${ONEAPI_ROOT}/setvars.sh"
64+
icpx --version
65+
66+
- name: Download Coverity Build Tool
67+
timeout-minutes: 15
68+
env:
69+
COVERITY_SCAN_TOKEN: ${{ secrets.COVERITY_SCAN_TOKEN }}
70+
run: |
71+
curl --location --no-progress-meter --fail-with-body \
72+
--retry 5 --retry-connrefused --retry-delay 5 \
73+
--data-urlencode "token=${COVERITY_SCAN_TOKEN}" \
74+
--data-urlencode "project=${COVERITY_PROJECT}" \
75+
--output cov-analysis.tar.gz \
76+
https://scan.coverity.com/download/linux64
77+
mkdir -p cov-analysis
78+
tar -xzf cov-analysis.tar.gz --strip 1 -C cov-analysis
79+
echo "${PWD}/cov-analysis/bin" >> "$GITHUB_PATH"
80+
81+
- name: Configure Coverity for the DPC++ compiler
82+
env:
83+
# icx/icpx are not in Coverity's list of known compilers, so the
84+
# clang-based templates below have to be accepted explicitly
85+
COVERITY_UNSUPPORTED: 1
86+
run: |
87+
source "${ONEAPI_ROOT}/setvars.sh"
88+
# Cython-generated sources and the pybind11 extensions go through
89+
# icpx, the sysroot/driver probing bits still use gcc
90+
cov-configure --gcc
91+
cov-configure --template --comptype clangcc --compiler icx
92+
cov-configure --template --comptype clangcxx --compiler icpx
93+
94+
- name: Build under cov-build
95+
timeout-minutes: 90
96+
env:
97+
COVERITY_UNSUPPORTED: 1
98+
run: |
99+
set -o pipefail
100+
source "${ONEAPI_ROOT}/setvars.sh"
101+
rm -rf _skbuild
102+
# --skip-editable: the in-place build_ext already compiled everything
103+
# Coverity needs to see, a pip install would only repeat it
104+
cov-build --dir cov-int \
105+
python scripts/build_locally.py --oneapi --skip-editable --verbose \
106+
2>&1 | tee cov-build.log
107+
if ! grep -qE "Emitted [1-9][0-9]* .*compilation unit" cov-build.log; then
108+
echo "::error::Coverity captured 0 compilation units — the C++ build did not run under cov-build."
109+
exit 1
110+
fi
111+
112+
- name: Upload Coverity build log
113+
if: always()
114+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
115+
with:
116+
name: coverity-build-log
117+
path: |
118+
cov-build.log
119+
cov-int/build-log.txt
120+
retention-days: 7
121+
if-no-files-found: warn
122+
123+
- name: Submit results to Coverity Scan
124+
timeout-minutes: 15
125+
env:
126+
COVERITY_SCAN_TOKEN: ${{ secrets.COVERITY_SCAN_TOKEN }}
127+
COVERITY_SCAN_EMAIL: ${{ secrets.COVERITY_SCAN_EMAIL }}
128+
run: |
129+
tar -czf cov-int.tgz cov-int
130+
curl --no-progress-meter --fail-with-body \
131+
--retry 5 --retry-connrefused --retry-delay 5 \
132+
--form token="${COVERITY_SCAN_TOKEN}" \
133+
--form email="${COVERITY_SCAN_EMAIL}" \
134+
--form file=@cov-int.tgz \
135+
--form version="${GITHUB_SHA}" \
136+
--form description="GitHub Actions ${GITHUB_REF_NAME} (run ${GITHUB_RUN_ID})" \
137+
--form project="${COVERITY_PROJECT}" \
138+
https://scan.coverity.com/builds

‎.github/workflows/openssf-scorecard.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -70,6 +70,6 @@ jobs:
7070

7171
# Upload the results to GitHub's code scanning dashboard.
7272
- name: "Upload to code-scanning"
73-
uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
73+
uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
7474
with:
7575
sarif_file: results.sarif

‎.github/workflows/zizmor.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ jobs:
2929
persist-credentials: false
3030

3131
- name: Run zizmor
32-
uses: zizmorcore/zizmor-action@70fb788f84895a7701f5643d103d587e460b5c99 # v0.6.3
32+
uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4
3333
with:
3434
# Low/informational template-injection notes come from internally-defined
3535
# values (no external input), so they are reported as annotations but do not gate CI

‎.pre-commit-config.yaml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -74,7 +74,7 @@ repos:
7474
hooks:
7575
- id: flake8
7676
- repo: https://github.com/pre-commit/mirrors-clang-format
77-
rev: v23.1.0
77+
rev: v23.1.1
7878
hooks:
7979
- id: clang-format
8080
args: ["-i"]

‎CHANGELOG.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
3333

3434
### Maintenance
3535
* Updated pybind11 version used by `dpctl` and examples [gh-2357](https://github.com/IntelPython/dpctl/pull/2357)
36+
* Added a weekly `Coverity Scan` workflow that builds `dpctl` with the DPC++ compiler under `cov-build` and submits the results to Coverity Scan
3637

3738
## [0.22.1] - Apr. 24, 2026
3839

‎README.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
[![Coverage Status](https://coveralls.io/repos/github/IntelPython/dpctl/badge.svg?branch=master)](https://coveralls.io/github/IntelPython/dpctl?branch=master)
55
![Generate Documentation](https://github.com/IntelPython/dpctl/actions/workflows/generate-docs.yml/badge.svg?branch=master)
66
[![Join the chat at https://matrix.to/#/#Data-Parallel-Python_community:gitter.im](https://badges.gitter.im/Join%20Chat.svg)](https://app.gitter.im/#/room/#Data-Parallel-Python_community:gitter.im)
7+
[![Coverity Scan Build Status](https://scan.coverity.com/projects/intelpython-dpctl/badge.svg)](https://scan.coverity.com/projects/intelpython-dpctl)
78
[![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/IntelPython/dpctl/badge)](https://securityscorecards.dev/viewer/?uri=github.com/IntelPython/dpctl)
89

910
<img align="left" src="https://spec.oneapi.io/oneapi-logo-white-scaled.jpg" alt="oneAPI logo" width="75"/>

‎benchmarks/README.md‎

Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
# dpctl ASV Benchmarks
2+
3+
Runtime-overhead benchmarks for [dpctl](https://github.com/IntelPython/dpctl)
4+
using [ASV](https://asv.readthedocs.io/en/stable/): object construction,
5+
queue caching, USM allocation, device enumeration, kernel bundle
6+
compilation, data movement, kernel submission. No compute throughput.
7+
8+
## Coverage
9+
10+
| File | API |
11+
|------|-----|
12+
| `bench_construct.py` | `SyclDevice`/`SyclContext`/`SyclQueue`/`SyclPlatform` construction, device/queue attribute reads |
13+
| `bench_queue_cache.py` | `get_device_cached_queue` for each key kind, vs. an uncached baseline |
14+
| `bench_usm.py` | `MemoryUSM{Device,Host,Shared}` alloc/free, aligned alloc, first touch, USM pointer queries |
15+
| `bench_enumerate.py` | `get_devices`, `get_num_devices`, `get_platforms`, `select_*_device`, `has_*_devices`, `select_device_with_aspects` |
16+
| `bench_compile.py` | Kernel bundles from SPIR-V / OpenCL C source / SYCL source, kernel lookup, availability probes |
17+
| `bench_copy.py` | `SyclQueue.memcpy`/`memcpy_async`/`fill`/`memset`, `_Memory.copy_to_host`/`copy_from_host`/`copy_from_device` |
18+
| `bench_submit.py` | `submit`, `submit_async`, batched submission, `submit_barrier`, idle `wait` |
19+
20+
## Device axis
21+
22+
Benchmarks parameterize over the `cpu`/`gpu` filter selectors and skip when a
23+
selector has no matching device, so the same benchmark names run on any
24+
node. Sizes over 25% of a device's `global_mem_size` skip the same way.
25+
26+
## Compilation caching
27+
28+
`benchmarks/__init__.py` disables the persistent JIT cache
29+
(`SYCL_CACHE_PERSISTENT=0`). `time_bundle_from_source_cold` mints a unique
30+
kernel name per call to defeat the in-memory cache too; `_warm` reuses one
31+
name to measure the cache-hit path.
32+
33+
`create_kernel_bundle_from_source` runs on the OpenCL backend only.
34+
`create_kernel_bundle_from_sycl_source` needs a device where
35+
`can_compile("sycl")` is true.
36+
37+
## Running
38+
39+
```bash
40+
pip install ".[benchmark]"
41+
cd benchmarks && asv machine --yes && asv run --python=same --quick HEAD^!
42+
```
43+
44+
One module: `asv run --python=same --quick --bench bench_compile HEAD^!`
45+
46+
Compare commits: `asv continuous --python=same HEAD~1 HEAD`
47+
48+
View results: `asv publish && asv preview`

‎benchmarks/asv.conf.json‎

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
{
2+
"version": 1,
3+
"project": "dpctl",
4+
"project_url": "https://github.com/IntelPython/dpctl",
5+
"show_commit_url": "https://github.com/IntelPython/dpctl/commit/",
6+
"repo": "..",
7+
"branches": [
8+
"master",
9+
"dev-milestone"
10+
],
11+
"environment_type": "conda",
12+
"conda_channels": [
13+
"https://software.repos.intel.com/python/conda/",
14+
"conda-forge"
15+
],
16+
"benchmark_dir": "benchmarks",
17+
"env_dir": ".asv/env",
18+
"results_dir": ".asv/results",
19+
"html_dir": ".asv/html",
20+
"build_cache_size": 2,
21+
"default_benchmark_timeout": 900,
22+
"regressions_thresholds": {
23+
".*": 0.2
24+
}
25+
}

‎benchmarks/benchmarks/__init__.py‎

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
# Data Parallel Control (dpctl)
2+
#
3+
# Copyright 2026 Intel Corporation
4+
#
5+
# Licensed under the Apache License, Version 2.0 (the "License");
6+
# you may not use this file except in compliance with the License.
7+
# You may obtain a copy of the License at
8+
#
9+
# http://www.apache.org/licenses/LICENSE-2.0
10+
#
11+
# Unless required by applicable law or agreed to in writing, software
12+
# distributed under the License is distributed on an "AS IS" BASIS,
13+
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14+
# See the License for the specific language governing permissions and
15+
# limitations under the License.
16+
17+
"""ASV benchmarks for dpctl."""
18+
19+
import os
20+
21+
# Disable the persistent JIT cache before dpctl is imported, so cold-compile
22+
# benchmarks in bench_compile.py measure a real compile, not a cache hit.
23+
os.environ.setdefault("SYCL_CACHE_PERSISTENT", "0")

0 commit comments

Comments
 (0)