Skip to content

vllm.snapshot.manifest

Classes:

Functions:

ReadyMarker

Bases: BaseModel

Ready marker the child writes; unknown keys are ignored.

Source code in vllm/snapshot/manifest.py
class ReadyMarker(BaseModel):
    """Ready marker the child writes; unknown keys are ignored."""

    token_ids: tuple[StrictInt, ...]
    text: StrictStr
    sampled_token_logprob: StrictFloat | StrictInt

ReleaseMarker

Bases: BaseModel

Release marker the controller writes; unknown keys are ignored.

Source code in vllm/snapshot/manifest.py
class ReleaseMarker(BaseModel):
    """Release marker the controller writes; unknown keys are ignored."""

    release: Literal[True]
    host: StrictStr | None = None
    port: Annotated[StrictInt, Field(ge=1, le=65535)]

    @field_validator("release", mode="before")
    @classmethod
    def _require_json_true(cls, value: Any) -> Any:
        # A literal accepts 1 as True; the barrier requires JSON true itself.
        if value is not True:
            raise ValueError("release must be JSON true")
        return value

SnapshotCompatibilityError

Bases: RuntimeError

The snapshot identity does not match the requested runtime.

Source code in vllm/snapshot/manifest.py
class SnapshotCompatibilityError(RuntimeError):
    """The snapshot identity does not match the requested runtime."""

SnapshotSecurityError

Bases: RuntimeError

The snapshot artifact does not meet the private-path contract.

Source code in vllm/snapshot/manifest.py
class SnapshotSecurityError(RuntimeError):
    """The snapshot artifact does not meet the private-path contract."""

read_manifest(path)

Read a snapshot published by atomically installing its manifest.

Source code in vllm/snapshot/manifest.py
def read_manifest(path: Path) -> SnapshotManifest:
    """Read a snapshot published by atomically installing its manifest."""
    path = Path(path)
    validate_artifact_root(path, creating=False)
    manifest_path = path / "manifest.json"
    if manifest_path.is_symlink():
        raise SnapshotSecurityError(f"manifest is a symlink: {manifest_path}")
    flags = os.O_RDONLY | getattr(os, "O_NOFOLLOW", 0)
    try:
        file_descriptor = os.open(manifest_path, flags)
    except FileNotFoundError as error:
        raise SnapshotSecurityError(
            f"manifest does not exist: {manifest_path}"
        ) from error
    try:
        with os.fdopen(file_descriptor, encoding="utf-8") as manifest_file:
            payload = manifest_file.read()
    except UnicodeDecodeError as error:
        raise SnapshotCompatibilityError("invalid snapshot manifest: JSON") from error
    try:
        return SnapshotManifest.model_validate_json(payload, strict=True)
    except ValidationError as error:
        raise SnapshotCompatibilityError(
            f"invalid snapshot manifest: {_validation_path(error)}"
        ) from error

validate_artifact_root(path, *, creating)

Validate that an artifact path cannot be replaced by another user.

Source code in vllm/snapshot/manifest.py
def validate_artifact_root(path: Path, *, creating: bool) -> None:
    """Validate that an artifact path cannot be replaced by another user."""
    path = Path(os.path.abspath(path))
    if path.is_symlink():
        raise SnapshotSecurityError(f"snapshot path is a symlink: {path}")
    if not creating and not path.exists():
        raise SnapshotSecurityError(f"snapshot path does not exist: {path}")

    effective_uid = os.geteuid()
    for component in _existing_path_chain(path):
        component_stat = component.lstat()
        if stat.S_ISLNK(component_stat.st_mode):
            raise SnapshotSecurityError(
                f"snapshot path contains a symlink: {component}"
            )
        if component_stat.st_uid not in (0, effective_uid):
            raise SnapshotSecurityError(
                f"snapshot path has an untrusted owner: {component}"
            )
        if component_stat.st_mode & (
            stat.S_IWGRP | stat.S_IWOTH
        ) and not _is_trusted_sticky_directory(component_stat):
            raise SnapshotSecurityError(
                f"snapshot path has a group- or world-writable ancestor: {component}"
            )

    if path.exists():
        path_stat = path.lstat()
        if not stat.S_ISDIR(path_stat.st_mode):
            raise SnapshotSecurityError(f"snapshot path is not a directory: {path}")
        if path_stat.st_uid != effective_uid:
            raise SnapshotSecurityError(
                f"snapshot directory is not owned by the current user: {path}"
            )
        if stat.S_IMODE(path_stat.st_mode) & 0o077:
            raise SnapshotSecurityError(
                f"snapshot directory must have mode 0700: {path}"
            )

validate_identity(expected, actual)

Require an exact match for every field that can affect compatibility.

Source code in vllm/snapshot/manifest.py
def validate_identity(
    expected: SnapshotRuntimeIdentity, actual: SnapshotRuntimeIdentity
) -> None:
    """Require an exact match for every field that can affect compatibility."""
    # ``expected`` may be a manifest, so compare the identity fields only.
    fields = set(SnapshotRuntimeIdentity.model_fields)
    expected_values = expected.model_dump(include=fields)
    actual_values = actual.model_dump(include=fields)
    differing = [
        name
        for name in SnapshotRuntimeIdentity.model_fields
        if expected_values[name] != actual_values[name]
    ]
    if differing:
        raise SnapshotCompatibilityError(f"snapshot mismatch: {', '.join(differing)}")

write_manifest_atomic(path, manifest)

Write a new private manifest and make its directory entry durable.

Source code in vllm/snapshot/manifest.py
def write_manifest_atomic(path: Path, manifest: SnapshotManifest) -> None:
    """Write a new private manifest and make its directory entry durable."""
    path = Path(path)
    validate_artifact_root(path, creating=False)
    destination = path / "manifest.json"
    try:
        _write_json_atomic(destination, manifest.model_dump(mode="json"))
    except FileExistsError as error:
        raise SnapshotSecurityError(
            f"manifest already exists: {destination}"
        ) from error