Repository navigation
🚨 fix(ggml-cuda): backport the block_reduce shared-memory race fix (llama.cpp #26385) - #837
Merged
Merged
Conversation
…p #26385) block_reduce has each warp write its partial result to shared memory, syncs once and reads the partials back, with no barrier after the read. When a kernel reduces twice through one buffer, a warp that is ahead can write its second partial while another warp still reads the first. soft_max_f32 reduces the row maximum and then the sum of exponentials that way, so a slow warp can take a partial sum for the maximum and its part of the row comes out wrong. group_norm_f32 and the cooperative single-row softmax also reduce twice through one buffer. It showed with LFM2-Audio: two sessions in one process sometimes gave different bytes for the same request, while each alone was bit-exact. Their kernels share the GPU, the warps of a block drift apart, and the encoder's attention softmax runs over rows of more than 32 positions, which take several warps. compute-sanitizer racecheck reports the WAR hazards in soft_max_f32 on main with a single session too. This is upstream's fix, from ggml-org/llama.cpp#26385: soft_max_f32 syncs between its two reductions when the block has more than one warp, group_norm_f32 and the cooperative softmax give their second reduction a buffer of its own, and block_reduce states that callers must not reuse the buffer until every read is done. The upstream diff applies unchanged; only line offsets and the vendored files' CRLF line endings differ. No other block_reduce caller in ggml-cuda reduces twice through one buffer. Checked on an A10 with CUDA 12.8, against main: - racecheck on the LFM2-Audio encoder over a 99-position question: 484704 errors in soft_max_f32 on main, none here. Over a single-turn S2S request cut at 60 tokens, every kernel checked: 1303436 errors on main, none here - test-backend-ops SOFT_MAX, GROUP_NORM, NORM, RMS_NORM, L2_NORM, SUM_ROWS and MEAN pass on both. Under racecheck's timing main fails 83 of 212 SOFT_MAX cases, the cooperative ones included, and both GROUP_NORM cases; this commit passes them all with no hazard - one session per process, EN and JP: ASR offline, TTS and S2S offline and streamed (36 requests): all 82 output files byte-identical to main, in two runs each - under memcheck's timing, main differs in 9 of 9 encoder repeats and in 5 of 5 single-turn S2S requests; this commit in none - two C API sessions in one process, running multi-turn S2S from a branch not yet merged: with this commit 0 of 159 turns differ from each session alone; without any fix 1 of 162 did, too rare on an idle machine to show the fix by itself
Owner
|
@ykhrustalev This may take a little longer. For ggml changes, I need to understand the problem, check the solution, and run regression tests. Sometimes there could be a simpler solution with low regression risk (e.g., #542) |
This was referenced Oct 8, 2026
Owner
|
@ykhrustalev Thanks, PR merged! No observable performance impact in my tests. I was initially concerned about flash attention, but it bypasses the modified standalone softmax kernel because softmax is fused into the attention kernel. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport of ggml-org/llama.cpp#26385, which fixes a shared-memory race in ggml-cuda kernels that call
block_reducetwice.Problem
block_reducewrites each warp's partial to shared memory, syncs once and reads the partials back, with no barrier after the read. A kernel that reduces twice through one buffer lets a warp that is ahead overwrite partials another warp is still readingsoft_max_f32reduces the row maximum and then the sum that way, so a slow warp can take a partial sum for the maximum.group_norm_f32and the cooperative single-row softmax do the samelfm2_audio: two sessions in one process sometimes gave different bytes for the same request, while each alone was bit-exact. The encoder's attention softmax has rows over 32 positions, which take several warps. compute-sanitizer racecheck reports the hazards on main with one session toolfm2_audio: on the CUDA backend, and in the HIP build of the same sources, any model with a softmax row over 32 or a group norm over groups of 1024 or more elements is exposedWhat this PR changes
soft_max_f32syncs between its two reductions when the block has more than one warp;group_norm_f32gives its second reduction its own 32 floats; the cooperative softmax gets separate buffers for its maximum and its sum;block_reducegains a comment stating the contractblock_reducecallers (norm, rms_norm, the channel RMS norm, l2_norm, sum_rows and mean) reduce once per kernel, and convrot-linear's own reduction ends with a barrier, so none needs a changeTesting
A10, CUDA 12.8, main (75d0294) against this branch (the HIP build, which compiles the same sources, was not built or run):
soft_max_f32; here none. A single-turn S2S request cut at 60 tokens, every kernel checked: main 1303436 errors; here nonetest-backend-ops, built from the vendored source against the same ggml (the project does not build it): SOFT_MAX, GROUP_NORM, NORM, RMS_NORM, L2_NORM, SUM_ROWS and MEAN pass on both. Under racecheck's timing main fails 83 of 212 SOFT_MAX cases (the three cooperative ones among them) and both GROUP_NORM cases; this branch passes all, with no hazardlfm2_audio_cuda_testamong them, pass on both