Skip to content

Fix Docker image builds and multiprocessing scratch space - #489

Open
jjacobson95 wants to merge 3 commits into
mpnst-treated-experimentsfrom
docker-build-fixes
Open

jjacobson95 wants to merge 3 commits into
mpnst-treated-experimentsfrom
docker-build-fixes

Conversation

@jjacobson95

Copy link
Copy Markdown
Collaborator

Pipeline Hardening/Debugging PR # 11

Fix Docker image builds and multiprocessing scratch space

Fixes a multiprocessing crash that hit the drug-descriptor and curve-fitting steps inside the containers, plus several Docker build reliability issues. Must merge after the phosphosites and cnf PRs, because docker-compose.yml references those new services.

Fix the multiprocessing crash (all 15 images)

  • The build bind-mounts the host's local/ directory at /tmp inside each container. Python 3.14 changed the default multiprocessing start method to "forkserver", which opens a Unix-domain socket under the temp directory (that is, under the /tmp bind mount). Docker's macOS file sharing does not support the required socket operation there, so every worker process crashed with OSError: [Errno 22]. This broke build_drug_desc.py and fit_curve.py on 2026-09-03, each at the end of a multi-hour step, and it was deterministic so retries didn't help.
  • The fix creates a container-local scratch directory (/opt/mp_tmp) and points TMPDIR at it, keeping multiprocessing scratch files off the bind mount. Regular /tmp/<name> output paths (how build outputs are written) are unaffected, so nothing else changes. Applied consistently to all 15 dataset/utility images (beataml, bladder, broad_sanger_exp, broad_sanger_omics, colorectal, cptac, genes, hcmi, liver, mpnst, mpnstpdx, novartis, pancreatic, sarcoma, upload).

R image reliability (broad_sanger, mpnst)

  • Removed an apt-get upgrade from the broad_sanger images: it pulled in a newer OpenSSL that replaced the base image's R and broke the R ABI, and it turned out to be unnecessary because the package list installs cleanly without it.
  • Pinned the mpnst image to r-base:4.4.1 to match every other R image in the build and to get a compatible libssl3t64, so libssl-dev installs cleanly.

Compose wiring

  • Added phosphosites and cnf services to docker-compose.yml so the two new images build alongside the rest.

Scope: 16 files. Base: mpnst-treated-experiments. Must merge after the phosphosites and cnf PRs.

Also fixes three orchestration bugs found in the v19 full build, and
redacts credentials from the build log.

Every process_* function awaited only the PREVIOUS future before submitting
the next, so the LAST dataset's exception was never retrieved -- and an
unretrieved exception in a ThreadPoolExecutor is discarded, not raised. In
--high_mem mode nothing was awaited at all. In v19 that let `hcmi omics`
fail all three attempts while the build logged "All omics files completed",
then published and validated a release with hcmi transcriptomics,
copy_number and mutations missing entirely. Every future is now collected
and retrieved through _await_all(), so no dataset failure can be dropped.

The resulting `validate failed` printed only "None": stderr is passed
through to sys.stderr, so subprocess never captures it and res.stderr is
always None. Report the exit code and point at the container output.

Finally, docker command lines were logged verbatim, and credentials are
passed as `-e NAME=value`, so build logs contained the live
SYNAPSE_AUTH_TOKEN in cleartext. Added _redact() and gitignored the build
logs and PID files.
@jjacobson95 jjacobson95 modified the milestones: 2.3 new build, 2.4 new build Sep 22, 2026
Harden build orchestration and set the default dataset list
args:
HTTPS_PROXY: ${HTTPS_PROXY}
platform: linux/amd64
image: phosphosites:latest

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

remove this to avoid building at this time.

dockerfile: coderbuild/docker/Dockerfile.cnf
args:
HTTPS_PROXY: ${HTTPS_PROXY}
platform: linux/amd64

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

remove this as well

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants