Repository navigation
Expand file tree
/
Copy pathDockerfile
More file actions
185 lines (164 loc) · 9.71 KB
/
Copy pathDockerfile
File metadata and controls
185 lines (164 loc) · 9.71 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
# SPDX-License-Identifier: AGPL-3.0-or-later
# Commercial license available
# © Concepts 1996–2026 Miroslav Šotek. All rights reserved.
# © Code 2020–2026 Miroslav Šotek. All rights reserved.
# ORCID: 0009-0009-3560-0851
# Contact: www.anulum.li | protoscience@anulum.li
# SCPN Quantum Control — Container reproduction image
# PURPOSE: reproduction / CI test image — NOT a production runtime.
# This image exists to run the test suite in a clean, pinned container
# (its default CMD is pytest, and .github/workflows/docker.yml builds it
# and runs the tests inside — it is never pushed to a registry). It
# therefore deliberately ships tests/, docs/, paper/, notebooks/, data/,
# and CI fixtures. The final image installs a compiled scpn_quantum_engine
# wheel produced in a separate, digest-pinned builder stage so native custody
# and parity tests exercise real extension behaviour. The pinned Rust toolchain
# and cached WASM dependencies also support actual build-tool acceptance tests.
# Do NOT slim this into a runtime image — slimming would defeat its only
# job (reproducing the full test run). For a production deployment, install
# the published wheel (`pip install scpn-quantum-control`) into your own
# base image instead of reusing this one.
FROM ghcr.io/pyo3/maturin:v1.10.2@sha256:4ac83047776d1facc6c7073d9b0dc03e349cac2ff8540499e82be3990ef26258 AS native-builder
WORKDIR /build
COPY scpn_quantum_engine/ scpn_quantum_engine/
RUN maturin build \
--release \
--locked \
--manifest-path scpn_quantum_engine/Cargo.toml \
--features extension-module \
--interpreter python3.12 \
--out /wheels
FROM rust:1.99.0-slim-bookworm@sha256:2c3a22f0a5533ea2dd5a16627bc841228151faa2d4de2644ac9987e4a2f1f2fa AS wasm-builder
WORKDIR /build/studio_wasm_kernel
COPY rust-toolchain.toml /build/rust-toolchain.toml
COPY scpn_quantum_engine/studio_wasm_kernel/ ./
RUN rustup component add rustfmt clippy \
&& rustup target add wasm32-unknown-unknown \
&& cargo build --release --locked --target wasm32-unknown-unknown
FROM python:3.12-slim@sha256:3d5ed973e45820f5ba5e46bd065bd88b3a504ff0724d85980dcd05eab361fcf4
LABEL org.opencontainers.image.title="scpn-quantum-control"
LABEL org.opencontainers.image.description="NISQ quantum simulation of coupled Kuramoto oscillator networks"
LABEL org.opencontainers.image.source="https://github.com/anulum/scpn-quantum-control"
LABEL org.opencontainers.image.licenses="AGPL-3.0-or-later"
RUN useradd --create-home sqc
WORKDIR /app
RUN apt-get update \
&& apt-get install -y --no-install-recommends git gcc libc6-dev \
&& rm -rf /var/lib/apt/lists/*
COPY --from=wasm-builder /usr/local/rustup /opt/rustup
COPY --from=wasm-builder /usr/local/cargo /home/sqc/.cargo
ENV RUSTUP_HOME=/opt/rustup
ENV CARGO_HOME=/home/sqc/.cargo
ENV PATH=/home/sqc/.cargo/bin:$PATH
RUN chown -R sqc:sqc /home/sqc/.cargo
COPY .pre-commit-config.yaml pyproject.toml mkdocs.yml requirements.txt requirements-dev.txt README.md LICENSE ROADMAP.md ./
# The changelog, public-claim, and rendered-docs-header guards read these
# root documents.
COPY CHANGELOG.md VALIDATION.md RESULTS_SUMMARY.md CAPABILITIES_AND_USECASES.md REUSE.toml ./
COPY ARCHITECTURE.md CONTRIBUTING.md DEPRECATIONS.md CONTRIBUTORS.md GOVERNANCE.md NOTICE.md SUPPORT.md ./
COPY requirements-ci-cross-platform-smoke.txt requirements-ci-py311-linux.txt requirements-ci-py312-linux.txt requirements-ci-py313-linux.txt requirements-ci-studio-platform.txt ./
# Workflow audits inspect the browser lock without installing Chromium here.
COPY requirements-ci-studio-browser.txt ./
# Supply-chain contract tests validate the human-reviewed inputs that generate
# the minimal-install and Quimb hash closures.
COPY requirements-ci-minimal-install-py312-linux.in requirements-ci-quimb-py312-linux.in ./
COPY requirements-ci-minimal-install-py312-linux.txt requirements-ci-quimb-py312-linux.txt ./
# Optional-runtime contract tests inspect these locks without installing the
# heavyweight runtimes in the reproduction image.
COPY requirements-ci-jax-py312-linux.txt requirements-ci-torch-cpu-py312-linux.txt ./
# Reproduction audits inspect these workflow inputs without installing them.
COPY requirements-ci-julia-tier.txt requirements-integration-sc-neurocore.txt requirements-publish.txt rust-toolchain.toml ./
# The workflow environment audit reads the lock of every tool a job installs;
# the shell-lint, licence-lint and mutation tools are not installed here.
COPY requirements-ci-shell-lint.txt requirements-ci-licence-lint.txt requirements-ci-mutation.txt ./
COPY src/ src/
COPY experimental_workers/ experimental_workers/
COPY oscillatools/src/ oscillatools/src/
# The standalone-package decision and real wheel tests require the complete
# Hatchling metadata pair, including the README declared by its pyproject.
COPY oscillatools/pyproject.toml oscillatools/pyproject.toml
COPY oscillatools/README.md oscillatools/README.md
# The Kuramoto convention matrix names the sibling's own tests; without them
# the generated convention page drifts. The image runs only `tests/`.
COPY oscillatools/tests/ oscillatools/tests/
# The archive-metadata test checks both Zenodo records against the Zenodo
# relation-type vocabulary.
COPY .zenodo.json ./
COPY oscillatools/.zenodo.json oscillatools/.zenodo.json
# Cross-language documentation contract tests inspect the pinned TypeDoc
# command and version without installing the Studio frontend in this image.
COPY studio-web/package.json studio-web/package.json
# The shared contract ownership check requires every declared consumer of a
# contract to exist as a file: the TypeScript contract modules, the program
# compiler pair and the WebAssembly kernel crate. The original kernel inputs
# also support the build-tool acceptance tests.
COPY studio-web/src/shared/contracts/ studio-web/src/shared/contracts/
COPY studio-web/src/features/programs/programCompiler.ts studio-web/src/features/programs/programCompiler.test.ts studio-web/src/features/programs/
COPY scpn_quantum_engine/studio_wasm_kernel/ scpn_quantum_engine/studio_wasm_kernel/
ENV PYTHONPATH=/app/src:/app/oscillatools/src:/app
ENV XDG_CACHE_HOME=/home/sqc/.cache
ENV XDG_CONFIG_HOME=/home/sqc/.config
ENV MPLCONFIGDIR=/home/sqc/.config/matplotlib
# Amazon Braket imports its default simulator during adapter collection; Numba
# cache locators can fail in copied container layers, so Docker CI disables JIT.
ENV NUMBA_DISABLE_JIT=1
RUN pip install --no-cache-dir --require-hashes -r requirements-ci-py312-linux.txt \
&& pip install --no-cache-dir --no-deps --require-hashes -r requirements-ci-studio-platform.txt
COPY --from=native-builder /wheels/ dist/
RUN pip install --no-cache-dir --no-deps dist/*.whl \
&& python -c "import scpn_quantum_engine as engine; assert hasattr(engine, 'MlDsaSigningKey')"
# Tests that record the installed distribution version need the package's
# metadata, as the hosted test jobs provide it. The sources under /app/src
# remain the imported copy.
RUN pip install --no-cache-dir --no-deps -e . \
&& python -c "from importlib.metadata import version; version('scpn-quantum-control')"
COPY tests/ tests/
COPY tools/ tools/
COPY .github/workflows/ .github/workflows/
COPY .github/dependabot.yml .github/dependabot.yml
# The static Rust-inventory, dependency-evidence, and kernel-execution audits
# read the engine crate manifest, its locked dependency graph, and every
# in-tree pyo3-featured member crate the bounded program-AD replay extraction
# introduced. Ship those inputs alongside the primary crate.
COPY scpn_quantum_engine/Cargo.toml scpn_quantum_engine/Cargo.toml
COPY scpn_quantum_engine/Cargo.lock scpn_quantum_engine/Cargo.lock
COPY scpn_quantum_engine/src/ scpn_quantum_engine/src/
COPY scpn_quantum_engine/benches/ scpn_quantum_engine/benches/
COPY scpn_quantum_engine/program_ad_replay/src/ scpn_quantum_engine/program_ad_replay/src/
COPY scpn_quantum_engine/program_ad_replay/Cargo.toml scpn_quantum_engine/program_ad_replay/Cargo.toml
COPY scpn_quantum_engine/tests/ scpn_quantum_engine/tests/
COPY scpn_quantum_engine/fuzz/ scpn_quantum_engine/fuzz/
COPY docs/ docs/
COPY paper/ paper/
COPY examples/ examples/
COPY notebooks/ notebooks/
COPY results/ results/
# `data/` holds curated hardware-result JSONs that
# `tests/test_phase1_dla_parity_reproduces.py` asserts against; the
# reproducer ERRORs out without the fixture. `scripts/` holds the
# analysis module the reproducer imports.
COPY data/ data/
COPY figures/ figures/
COPY scripts/ scripts/
# `benchmarks/` holds the committed regression baselines + threshold policies
# that the tier-benchmark and native-speedup gate guards read live-tree
# (tests/test_tier_benchmark_regression_gate.py fails closed without them).
COPY benchmarks/ benchmarks/
# Git-backed repository-policy audits need an index, but the host .git tree,
# history, remotes, objects, and credentials are deliberately excluded from the
# build context. Apply the repository ignore contract, then create a
# credential-free synthetic Git index over the curated tracked files copied
# above. Ignored fixtures remain readable without becoming policy inputs.
COPY Dockerfile Dockerfile
COPY .gitignore .gitignore
RUN git init -q \
&& git add -A \
&& chown -R sqc:sqc /app
RUN mkdir -p /home/sqc/.cache/pytest /home/sqc/.config/matplotlib \
&& chown -R sqc:sqc /home/sqc/.cache /home/sqc/.config
USER sqc
HEALTHCHECK --interval=60s --timeout=10s --start-period=10s --retries=3 \
CMD python -c "import scpn_quantum_control; print('OK')"
# Skip slow, hardware, private-corpus, and machine-dependent performance tests by default.
# Exhaustive public imports run in the required CPU framework CI profile.
CMD ["pytest", "tests/", "-v", "--tb=short", "-o", "cache_dir=/home/sqc/.cache/pytest", "-m", "not slow and not hardware and not internal_corpus and not performance and not framework_imports"]