Repository navigation
Make mx.compile cache erasing thread safe - #4248
Conversation
|
A question rather than a correction, since you may have scoped this out already.
An erase reaching the tracing thread while it is inside The same thing re-entrant on one thread, when a traced body drops another wrapper over the same callable: Repro for the second, no threads needed: constexpr std::uintptr_t outer_id = 0xf11d;
std::function<std::vector<array>(const std::vector<array>&)> fun =
[&](const std::vector<array>& inputs) {
detail::compile_erase(detail::compiler_cache(), outer_id);
return std::vector<array>{inputs[0] + array(1.0f)};
};
auto compiled = detail::compile(fun, outer_id);
eval(compiled({array(3.0f)}));The re-entrant one predates this PR and reproduces on main. The cross-thread one only becomes reachable once erases reach the tracing thread's cache. Holding the |
|
Technically it won't happen in python bindings because it is guaranteed that a function won't be destructed until nothing is using it, i.e. erasing won't happen while compiling the same function. But it might make sense not giving users a foot gun when it is not hard to do. |
|
The CI failures are a teardown crash introduced by this branch. Three lines reproduce it, no import mlx.core as mx
f = mx.compile(lambda x: x + 1)
mx.eval(f(mx.array([1.0])))Linux, CPU-only build: exit 139 on The symbolized stack for thread 1 is further down that same log, addresses trimmed:
An early return fixes it here, repro 0/3 and 835 tests OK: ~ThreadCleanup() {
if (!Py_IsInitialized()) {
return;
}
nb::gil_scoped_acquire gil;
mx::detail::compile_clear_cache(cache);
}That covers the after-finalization case only, it does not change what a thread exiting during |
9e92a55 to
f7811bd
Compare
…xit (#303) mlx 0.32.1 (ml-explore/mlx#4248) removed the GIL-safe pre-finalization hooks that cleared the thread_local compile cache, so the mtplx-model-owner thread exiting cleanly during Py_Finalize runs mlx's TLS destructor into _Py_Dealloc on a dead interpreter — the SIGSEGV and the Py_FatalError/SIGTRAP crash reports in #303 are one bug. Upstream closed ml-explore/mlx#4327/#4347 WONTFIX: `mx.clear_streams()` at thread end is the permanent contract; there is no release to bump to (0.32.2 on mlx main carries the same behavior), so this mitigation is permanent, not a stopgap. Two layers: - `_release_mlx_thread_state()` runs on the owner thread as its last mlx action (getattr-guarded — mlx builds without clear_streams no-op), and is atexit-registered for the main thread as insurance. - `shutdown(park=True)` (used only by the server lifespan teardown) parks the drained owner thread on a never-set Event instead of letting it pthread_exit — TSD destructors run only on thread exit, never for threads reaped by process exit, so parking holds even if a future mlx adds more Python-holding thread_locals. Daemon-ness alone never protected this thread: it was told to exit cleanly, and the clean exit IS the crash. No os._exit anywhere — in-process atexit work (smart-fan restore, telemetry) keeps running, exit codes are preserved, and the startup-failure path (openai.py:2093) keeps the joining default. Why now: a benchmark harness that restarts the server per cell rolls this dice on every teardown, and a crashed teardown skips shutdown work and can corrupt the next cell's warm-restore numbers. Prior art: mlx-vlm and sous shipped the same clear_streams contract within a day of the mlx release; neither pinned. Separate findings escalated from this investigation (not fixed here): production has NO shutdown-time SSD cold-tier flush at all (flush_cold_tier's only caller is the admin quiesce endpoint), and smart-fan's signal hooks never install from the worker thread (atexit only). Both need their own issues. Tests: test_model_scheduler.py 10 passed (park keeps the thread alive and rejects new work; clear_streams called once; missing/raising mlx swallowed; existing join-default tests unchanged).
* Return tuple in meshgrid (ml-explore#4229) * Add endpoint parameter to linspace (ml-explore#4184) Co-authored-by: Cheng <git@zcbenz.com> * Fix vmap of partition/argpartition dropping the kth argument (ml-explore#4116) * Fix nan_to_num replacing inf with 0 for float16 and bfloat16 (ml-explore#4222) Co-authored-by: codeAnqiang-ma <273298913+codeAnqiang-ma@users.noreply.github.com> Co-authored-by: Cheng <git@zcbenz.com> * Fix einsum not broadcasting batch dimensions in batched tensordot (ml-explore#4125) Co-authored-by: Cheng <git@zcbenz.com> * Dequantize in float32 (ml-explore#4241) * chore: Reject complex in erf and erfinv (ml-explore#4243) * Fix cpu compilation failure of abs with uint (ml-explore#4240) Co-authored-by: Cheng <git@zcbenz.com> * Fix quantize matrix multiplication floor issue (ml-explore#4251) * Only use MPI backend for world size > 1 (ml-explore#4210) * chore: Reject complex in expm1, sigmoid and arctan2 (ml-explore#4257) * Decompose small kernel-depth 3D convs into 2D convs (ml-explore#3785) Co-authored-by: katlun-lgtm <264247399+katlun-lgtm@users.noreply.github.com> Co-authored-by: Cheng <git@zcbenz.com> * Fix Metal sort of a view with a negative stride (ml-explore#4252) * Mirror the depth axis in the decomposed 3D conv when flipped (ml-explore#4277) * Fix Metal row reductions on negative-stride views (ml-explore#4267) Co-authored-by: Fu Xiaonan <214359569+FU-max-boop@users.noreply.github.com> * [CUDA] Fix custom kernel cache collision for same name, different source (ml-explore#4273) Co-authored-by: Cheng <git@zcbenz.com> * Fix ops rejecting integers larger than INT32_MAX (ml-explore#4255) Co-authored-by: Feli <feli@hnu.edu.cn> Co-authored-by: Cheng <git@zcbenz.com> * Fix var/std for complex numbers (ml-explore#4260) * Fix int32 overflow in conv padded input and pad shapes (ml-explore#4258) Co-authored-by: Cheng <git@zcbenz.com> * chore: Reject complex in remainder (ml-explore#4270) * chore: Compare the macOS SDK version as a version when gating JACCL (ml-explore#4286) * Clamp ring socket transfers so a payload of 2 GiB or more can be sent (ml-explore#4281) Co-authored-by: Cheng <git@zcbenz.com> * chore: Use normalize_axis_index in split/unstack/partition/topk (ml-explore#4288) * Remove grouped output in CI (ml-explore#4195) * [CUDA] Fix finding cuda 13 headers in JIT compilation (ml-explore#3995) * Refactor wheel building script (ml-explore#3818) * Make mx.compile cache erasing thread safe (ml-explore#4248) Co-authored-by: yentur <mr.yentur@gmail.com> * Add builds for free-threaded python (ml-explore#3812) * Fix int32 overflow in concatenate/repeat/kron (ml-explore#4303) * python: Widen list elements that do not fit in int32 to int64 (ml-explore#4305) * Propagate CPU errors to events (ml-explore#3742) Co-authored-by: Alessio Pollero <alessio.pollero@gmail.com> * Fix mx.arange dtype inference overflow regression (ml-explore#4324) * Add workflow to update pull request limit bypass list (ml-explore#4320) * Support head dimension 72 in Metal full attention (ml-explore#4330) * Patch bump to 0.32.2 (ml-explore#4333) * Preserve subnormal float values when casting to bool (ml-explore#4224) * python: Support assigning through a bare Ellipsis index (ml-explore#4314) * Fix divmod truncating the quotient for floats (ml-explore#4108) Co-authored-by: Cheng <git@zcbenz.com> * Add force_fused option to scaled_dot_product_attention (ml-explore#4185) * chore: Reject negative eps in the normalization layers (ml-explore#4312) * Bound GGUF metadata string/array values against the file mapping (ml-explore#4212) Co-authored-by: x14ngch3n <x14ngch3n@users.noreply.github.com> Co-authored-by: Cheng <git@zcbenz.com> * Read each K/V byte once in gqa-8 decode attention (ml-explore#4077) * Fix fft vmap and jvp for transforms over a subset of axes (ml-explore#4138) * Fix median dropping NaN (ml-explore#4146) * Fix the CPU scan over a size one axis with a padded stride (ml-explore#4139) Co-authored-by: Cheng <git@zcbenz.com> * chore: Validate the optimizer betas at construction (ml-explore#4310) Co-authored-by: Cheng <git@zcbenz.com> * `RMSNormVJP` backward writes a full `{n_rows, D}` `gw_temp` intermediate (ml-explore#4293) * [Bug]: add default none value to axis parameter of the take_along_axis (ml-explore#4357) Co-authored-by: Anastasiia Filippova <a_filippova@apple.com> * Add a fused full-attention path for head_dim 256 on NAX devices (ml-explore#3842) Co-authored-by: Cheng <git@zcbenz.com> * Update nanobind to 2.15.0 (ml-explore#4337) * Skip unnecessary simdgroup computations for quantised MOE matmuls on NAX (ml-explore#4352) * Add AI usage policy (ml-explore#4331) Co-authored-by: Jake Bowhay <60778417+j-bowhay@users.noreply.github.com> * Raise cpu stream errors from synchronize (ml-explore#4338) Co-authored-by: Cheng <git@zcbenz.com> * chore: Validate eps in Adam at construction (ml-explore#4361) Co-authored-by: Anastasiia Filippova <a_filippova@apple.com> * Bound winograd conv2d working set by tiling the batch (ml-explore#4102) Co-authored-by: Cheng <git@zcbenz.com> * Use a 32-row block in qmm_t_nax when one block covers all of M (ml-explore#4171) * chore: Deduplicate fftshift and ifftshift (ml-explore#4318) * Fix Log and Equal is_equivalent ignoring primitive state (ml-explore#4266) Co-authored-by: Cheng <git@zcbenz.com> * Stabilize reduced-precision InstanceNorm (ml-explore#4230) * chore: Normalize negative axes in sort and argsort (ml-explore#4332) * Clean up main thread compile cache before python interpreter shuts down (ml-explore#4373) * chore: Check malformed jaccl hostfile that miss rdma in pairs (ml-explore#4284) Co-authored-by: Cheng <git@zcbenz.com> * Round mxfp8 block scales up to avoid saturation (ml-explore#4353) Co-authored-by: Daniel Hiltgen <daniel.hiltgen@ollama.com> Co-authored-by: Cheng <git@zcbenz.com> * Add support for the __array_namespace_info__ (ml-explore#4334) * Stop a failed CUDA graph commit from poisoning the encoder (ml-explore#4356) Co-authored-by: Cheng <git@zcbenz.com> * Fix quantized kernels in JIT build (ml-explore#4372) Co-authored-by: Cheng <git@zcbenz.com> * Avoid zero work in stride-2 ConvTranspose3d (ml-explore#4343) * [CUDA] Ce fused kernel (ml-explore#3947) * Fix cpu exclusive scan for complex numbers (ml-explore#4272) Co-authored-by: Cheng <git@zcbenz.com> * Support Relocatable CUDA DLLs on Windows (ml-explore#4382) * Use cast_to for fused AsType in compiled Metal kernels (ml-explore#4351) Co-authored-by: katlun-lgtm <katlun@windyviews.com> Co-authored-by: Cheng <zcbenz@gmail.com> * python: Declare DLPackCompatible protocol members as methods (ml-explore#4384) * Fix quantizing sliced arrays (ml-explore#4381) * Fix einsum dropping a trailing empty subscript (ml-explore#4299) Co-authored-by: Cheng <git@zcbenz.com> * Add script to run python tests (ml-explore#4393) * Hold GIL in AttachedData destructor (ml-explore#4391) * Bound Metal buffer COUNT, not just bytes, in MetalAllocator The Metal allocator throws `[metal::malloc] Resource limit (N) exceeded` when num_resources_ (the live+cached Metal buffer COUNT) reaches resource_limit_ (the iogpu.rsrc_limit sysctl, default ~499000). Freed buffers are recycled into a size-keyed cache whose only trim is by BYTES (release_cached_buffers takes a bytes-to-free target, max_pool_size_ ~= physical RAM). Under churn with many distinct buffer shapes (varied prompt lengths, growing KV caches, multiple co-resident models) the cache fills with entries never reused at that exact size, so the COUNT climbs to the limit while byte usage stays modest and the byte trim never fires — the process crashes mid-inference on a machine with most of its RAM free. malloc() now also reclaims by count: when num_resources_ crosses a 90% high-water mark of resource_limit_, it clears the (pure-reuse) buffer cache so the count drops back to the live working set. Clearing the cache only costs re-allocation, never correctness, so the count limit becomes unreachable by any request mix or batching method while the existing byte limits keep total memory bounded. Adds get_num_resources()/get_resource_limit() to the public memory API (metal + no_gpu + cuda backends) so the count and its ceiling are observable from callers. Adds an MLX_RESOURCE_LIMIT env override that can only LOWER the ceiling (clamped to the OS limit, strictly validated) to exercise the trim deterministically and as an operator safety valve. * perf(mlx): opt-in Gemma 4 expert-QMM tile kernel with parallel descriptor builder (#4) * perf(mlx): add opt-in Gemma 4 expert-QMM tile kernel with parallel descriptor builder Adds a distinctly-named expert QMM implementation for the Gemma 4 26B-A4B MoE production shapes, gated by MLX_GATHER_QMM_EXPERT_SLICES: - qmm_t_expert_impl: BM32 expert tile body (BM16 fallback rows) taking a private/by-value row count; the shared qmm_t_impl constant-address ABI and all ordinary gathered/batched/dense QMM routes are unchanged. - build_gemma4_sorted_expert_tiles_bm32: one 128-thread threadgroup replaces the reference design's single-GPU-thread serial builder; parallel expert-range binary search, Hillis-Steele scan, and strided upper-bound descriptor emission. - Selector runs after the NAX-first route and requires affine BF16 transposed inputs, 4-bit gs=64 weights, 128 experts, assignment counts of exactly 4096/8192/16384, and the exact gate/up or down rank-3 shapes; every miss keeps the legacy route. NAX engagement is non-engagement, never bypassed. - device.{h,cpp}: one-shot request resolution, nonthrowing dual-symbol AOT probe/prewarm, relaxed-atomic diagnostics (requested, aotAvailable, naxAvailable, hits, per-class fallbacks). - gpu_tests: exact-shape arithmetic parity, fallback, and counter invariant probes. Retention standing (2026-08-09 production matrix): opt-in experiment. Standalone profile dropped (prefill -10.2% vs bracket); paired weighted-unsort+R1 profile retained-final (prefill +1.8%, TTFT -7.5%, decode +3.3%, arrival E2E +12.0%). NOTE: this source post-dates the benchmarked binaries/metallib (post-measurement kernel-body edit); rebuild and re-verify before any performance claim. * fix(mlx): fail-safe sortedness check in gemma expert tile builder; counter/atomic hygiene Review-wave fixes for the R1 expert-QMM path: - N1 (sortedness trust): build_gemma4_sorted_expert_tiles_bm32 now verifies each thread's post-binary-search segment boundary against the generalized invariant indices[start - 1] < lid <= indices[start] (edge threads check their single neighbor), votes per simdgroup via simd_or, folds the votes through threadgroup memory, and on any violation retracts count[0] to 0 (tile kernel then early-returns) and records the violation in count[1]; the buffer ABI is unchanged (count index 1 was previously unused). try_gemma4_expert_qmm allocates the second count element, drains the encoder after the builder, and re-routes a retracted call to the order-agnostic legacy path instead of dispatching the tile kernel (zero count is unambiguous: the selector's assignment gate guarantees M is 4096/8192/16384). - N2 (route-condition duplication): the sorted-RHS gate literal that appeared (negated) in the diagnostics record and in the dispatch decision is now the shared static constexpr predicate takes_sorted_rhs_route, so future tuning of the 16/4 thresholds cannot desynchronize counter vs route. - N3 (per-call bias normalization): gather_qmm_rhs no longer spends ensure_row_contiguous on biases before classification reads the raw tensor's fields; normalization runs only inside the winning-route branch (hit semantics unchanged; the legacy block keeps its own normalization point and ordering). - N4 (armed_ data race): Gemma4ExpertQMMCounters::armed_ is now std::atomic<bool> with relaxed loads/stores in armed(), snapshot(), snapshot_and_disarm() (read-then-write order preserved) and clear_and_arm(); the class remains non-copyable, now enforced. * fix(mlx): make the R1 sortedness fail-safe sound; proper retract attribution F1: the per-expert boundary vote was a partial detector -- an inversion inside a segment used by no other expert's boundary could escape, so "re-route on any violation" overclaimed. build_gemma4_sorted_expert_tiles_bm32 now also runs a strided adjacent-pair scan: thread lid checks indices[i-1] <= indices[i] for i = lid+1; i < M; i += 128, covering every adjacent pair in [1, M) exactly once (1..128 iterations at the reachable M in {4096,8192,16384}). Adjacent-pair monotonicity is transitive, so a clean scan is a sound and complete sortedness oracle; it folds into the same simd_or/threadgroup vote and the same retract (count[0]=0, count[1]=1). The boundary checks stay as cheap, precise diagnostics. F2: retracts were write-only in count[1] and surfaced as fallback_metallib_unavailable -- misattribution in the only observable surface. A dedicated fallback_sortedness_retracted counter now rides the GemmA4 route counters and the C diagnostics ABI (sizeof 80 -> 88, new uint64 at offset 80; existing offsets unchanged). try_gemma4_expert_qmm returns the route class: count[0]==0 with count[1]==1 records fallback_sortedness_retracted, any other unusable build keeps fallback_metallib_unavailable, then re-routes to the legacy path as before. F4: new doctest drives the full armed() -> clear_and_arm() -> snapshot_and_disarm() cycle and the attempts == hits + fallbacks invariant including the new class; the route-table and counter-invariant tests now cover fallback_sortedness_retracted. Verified: cmake tests 262/262 + 3550 assertions pass; metal -Wall -Wextra -fno-fast-math compile of kernels/quantized.metal is warning-free. * perf(metal): E=256 expert-tile route + trust + gpu::eval UAF fix — darkbloom-base mirror (#7) * perf(metal): instantiate E=256 expert-tile route for Qwen 3.5/3.6 MoE prefill (mirror of Cmlx/mlx 58fab46) * fix(metal): use-after-free in gpu::eval for primitives that synchronize mid-eval (mirror) * perf(metal): trust mode skips retract readback (mirror) * fix(compile): preserve all-cache binding cleanup --------- Co-authored-by: JasonHonKL <148705846+JasonHonKL@users.noreply.github.com> Co-authored-by: AK <144495202+AKnassa@users.noreply.github.com> Co-authored-by: Cheng <git@zcbenz.com> Co-authored-by: Adityaj0 <93090622+Adityaj0@users.noreply.github.com> Co-authored-by: anchor <codeanqiang@gmail.com> Co-authored-by: codeAnqiang-ma <273298913+codeAnqiang-ma@users.noreply.github.com> Co-authored-by: Rohan Gautam <rohan1gautam@gmail.com> Co-authored-by: Ayaan Gazali <ayaangazali.work@gmail.com> Co-authored-by: Erwin Zhang <59893706+erwinzhang7@users.noreply.github.com> Co-authored-by: katlun-lgtm <katlun@gmail.com> Co-authored-by: katlun-lgtm <264247399+katlun-lgtm@users.noreply.github.com> Co-authored-by: robertomeroni <150194833+robertomeroni@users.noreply.github.com> Co-authored-by: Fu Xiaonan <ht3fudatou@163.com> Co-authored-by: Fu Xiaonan <214359569+FU-max-boop@users.noreply.github.com> Co-authored-by: Hao Xu <hxu44@apple.com> Co-authored-by: Feli <89400571+FeliGame@users.noreply.github.com> Co-authored-by: Feli <feli@hnu.edu.cn> Co-authored-by: Eyüp Can Akman <eyupcanakman@gmail.com> Co-authored-by: Cheng <zcbenz@gmail.com> Co-authored-by: yentur <mr.yentur@gmail.com> Co-authored-by: Alessio Pollero <alessio.pollero@gmail.com> Co-authored-by: Zhiqi Zhang <zhiqizhangg@gmail.com> Co-authored-by: Daniel Hiltgen <dhiltgen@users.noreply.github.com> Co-authored-by: Tanish Jain <recklurker@gmail.com> Co-authored-by: hojin12312 <hojin12312@gmail.com> Co-authored-by: Xiang Chen <46052474+x14ngch3n@users.noreply.github.com> Co-authored-by: x14ngch3n <x14ngch3n@users.noreply.github.com> Co-authored-by: Duhyeon, Kim <49020301+dudududukim@users.noreply.github.com> Co-authored-by: rohith <kapellirohith@gmail.com> Co-authored-by: Ishaan Samantray <devteam.aegis@gmail.com> Co-authored-by: Aaishwarya Mishra <aaishwarymishra@gmail.com> Co-authored-by: Anastasiia Filippova <a_filippova@apple.com> Co-authored-by: Yanzhao Wang <19340816+wyanzhao@users.noreply.github.com> Co-authored-by: XXXXRT666 <157766680+XXXXRT666@users.noreply.github.com> Co-authored-by: Jake Bowhay <60778417+j-bowhay@users.noreply.github.com> Co-authored-by: vraj patel <87225460+vraj00222@users.noreply.github.com> Co-authored-by: Gusanidas <33495733+Gusanidas@users.noreply.github.com> Co-authored-by: Dwijen Patel <dwijen@gmail.com> Co-authored-by: Vladimir Iglovikov <ternaus@users.noreply.github.com> Co-authored-by: Brian C. <94733710+deBrian07@users.noreply.github.com> Co-authored-by: Daniel Hiltgen <daniel.hiltgen@ollama.com> Co-authored-by: YH Yan <strayberry0w0@gmail.com> Co-authored-by: katlun-lgtm <katlun@windyviews.com> Co-authored-by: anupsv <6407789+anupsv@users.noreply.github.com> Co-authored-by: Gajesh Naik <26431906+Gajesh2007@users.noreply.github.com> Co-authored-by: David Tai <davidtai@Davids-MBP.lan>
…xit (#303) mlx 0.32.1 (ml-explore/mlx#4248) removed the GIL-safe pre-finalization hooks that cleared the thread_local compile cache, so the mtplx-model-owner thread exiting cleanly during Py_Finalize runs mlx's TLS destructor into _Py_Dealloc on a dead interpreter — the SIGSEGV and the Py_FatalError/SIGTRAP crash reports in #303 are one bug. Upstream closed ml-explore/mlx#4327/#4347 WONTFIX: `mx.clear_streams()` at thread end is the permanent contract; there is no release to bump to (0.32.2 on mlx main carries the same behavior), so this mitigation is permanent, not a stopgap. Two layers: - `_release_mlx_thread_state()` runs on the owner thread as its last mlx action (getattr-guarded — mlx builds without clear_streams no-op), and is atexit-registered for the main thread as insurance. - `shutdown(park=True)` (used only by the server lifespan teardown) parks the drained owner thread on a never-set Event instead of letting it pthread_exit — TSD destructors run only on thread exit, never for threads reaped by process exit, so parking holds even if a future mlx adds more Python-holding thread_locals. Daemon-ness alone never protected this thread: it was told to exit cleanly, and the clean exit IS the crash. No os._exit anywhere — in-process atexit work (smart-fan restore, telemetry) keeps running, exit codes are preserved, and the startup-failure path (openai.py:2093) keeps the joining default. Why now: a benchmark harness that restarts the server per cell rolls this dice on every teardown, and a crashed teardown skips shutdown work and can corrupt the next cell's warm-restore numbers. Prior art: mlx-vlm and sous shipped the same clear_streams contract within a day of the mlx release; neither pinned. Separate findings escalated from this investigation (not fixed here): production has NO shutdown-time SSD cold-tier flush at all (flush_cold_tier's only caller is the admin quiesce endpoint), and smart-fan's signal hooks never install from the worker thread (atexit only). Both need their own issues. Tests: test_model_scheduler.py 10 passed (park keeps the thread alive and rejects new work; clear_streams called once; missing/raising mlx swallowed; existing join-default tests unchanged).
…xit (#303) mlx 0.32.1 (ml-explore/mlx#4248) removed the GIL-safe pre-finalization hooks that cleared the thread_local compile cache, so the mtplx-model-owner thread exiting cleanly during Py_Finalize runs mlx's TLS destructor into _Py_Dealloc on a dead interpreter — the SIGSEGV and the Py_FatalError/SIGTRAP crash reports in #303 are one bug. Upstream closed ml-explore/mlx#4327/#4347 WONTFIX: `mx.clear_streams()` at thread end is the permanent contract; there is no release to bump to (0.32.2 on mlx main carries the same behavior), so this mitigation is permanent, not a stopgap. Two layers: - `_release_mlx_thread_state()` runs on the owner thread as its last mlx action (getattr-guarded — mlx builds without clear_streams no-op), and is atexit-registered for the main thread as insurance. - `shutdown(park=True)` (used only by the server lifespan teardown) parks the drained owner thread on a never-set Event instead of letting it pthread_exit — TSD destructors run only on thread exit, never for threads reaped by process exit, so parking holds even if a future mlx adds more Python-holding thread_locals. Daemon-ness alone never protected this thread: it was told to exit cleanly, and the clean exit IS the crash. No os._exit anywhere — in-process atexit work (smart-fan restore, telemetry) keeps running, exit codes are preserved, and the startup-failure path (openai.py:2093) keeps the joining default. Why now: a benchmark harness that restarts the server per cell rolls this dice on every teardown, and a crashed teardown skips shutdown work and can corrupt the next cell's warm-restore numbers. Prior art: mlx-vlm and sous shipped the same clear_streams contract within a day of the mlx release; neither pinned. Separate findings escalated from this investigation (not fixed here): production has NO shutdown-time SSD cold-tier flush at all (flush_cold_tier's only caller is the admin quiesce endpoint), and smart-fan's signal hooks never install from the worker thread (atexit only). Both need their own issues. Tests: test_model_scheduler.py 10 passed (park keeps the thread alive and rejects new work; clear_streams called once; missing/raising mlx swallowed; existing join-default tests unchanged).
…not abort at shutdown (Phosphene #76) mlx no longer registers its own exit-time cleanup (ml-explore/mlx#4248); teardown then ran during static destruction after the interpreter was gone and aborted with PyThreadState_Get / SIGABRT — after the MP4 was fully written, so the panel marked a successful render as failed. Register mx.clear_streams at exit, guarded for older mlx. Diagnosed and verified by @PhantombrainM on a Mac Studio M4 Max, mlx 0.32.1.
…not abort at shutdown (Phosphene #76) mlx no longer registers its own exit-time cleanup (ml-explore/mlx#4248); teardown then ran during static destruction after the interpreter was gone and aborted with PyThreadState_Get / SIGABRT — after the MP4 was fully written, so the panel marked a successful render as failed. Register mx.clear_streams at exit, guarded for older mlx. Diagnosed and verified by @PhantombrainM on a Mac Studio M4 Max, mlx 0.32.1.
Close #3940.
Compiled python function would erase the cache automatically on destruction, but the destruction can happen on any thread so it could happen that a cache entry gets deleted on a different thread from creation.
This PR enforces the erasing to happen on the original cache rather than the cache in the current thread, and makes
CompilerCachethread safe to the race condition above. The test is from #4096.The code is not strictly thread safe to avoid unnecessary overheads based on following assumptions: