Skip to content

fix: pin the simulator library list instead of fetching it per request - #182

Merged
jcschaff merged 2 commits into
mainfrom
fix/pin-simulator-registry
Sep 23, 2026
Merged

jcschaff merged 2 commits into
mainfrom
fix/pin-simulator-registry

Conversation

@jcschaff

Copy link
Copy Markdown
Contributor

Part of the open follow-up on publishing simulator images, and a first small step toward strategy decision 2 (identity is an image digest).

The problem

handlers.run_simulation built each run's container definition from pbest's _default_registry_deps(). That function does an httpx.get on every request, fetching registry.json from the dev branch of biosimulations/registry. The md5 of the resulting definition is the SimulatorVersion identity, and it is also the tag the service looks for in ghcr.io/biosimulations/registry_env. Three consequences:

  • Any commit to that file upstream silently changed the identity. The next run then rebuilt the entire 1.3 GB image, and any image published under the old tag stopped matching.
  • Simulation submission depended on GitHub being reachable, with no timeout set.
  • Nothing in this repo recorded which library versions a given identity meant.

The change

  • compose_api/simulation/simulator_registry.json is a copy of that file at f8b0132, the last commit to touch it (2026-04-30). The contents are identical; pre-commit's JSON formatter changed only the whitespace.
  • compose_api/simulation/simulator_registry.py parses it exactly as pbest parses the fetched copy. It records the source commit and how to take an upstream change.
  • The handler and the test fixtures use registry_dependencies() in place of _default_registry_deps().
  • CLAUDE.md notes that editing this file changes the simulator identity.

The identity is unchanged: c7e984d31f441805315590a4c53e7f9f both before and after, checked by generating the definition both ways. No rebuild is triggered.

Tests

  • New tests/simulation/test_simulator_registry.py:
    • checks the pinned file parses into the three pypi libraries and one conda library, all with versions;
    • makes httpx.get raise, and checks the definition and its hash are still produced and stable.
  • tests/simulation/test_simulation.py passes against the new source.
  • make check is clean.

What this does not do

  • It does not publish an image. registry_env still holds only 7a327410… (2026-05-01); the current identity is c7e984d3…. Publishing it is now worthwhile, because the tag will stay stable until someone changes it here on purpose.
  • It does not make identity reproducible. The md5 still describes the recipe, not the built image; decision 2 addresses that.

🤖 Generated with Claude Code

jcschaff and others added 2 commits September 22, 2026 23:46
run_simulation fetched registry.json from the dev branch of
biosimulations/registry on every request, so the simulator identity (the
md5 of the generated definition) depended on a network call and on
whatever that branch held at the time. Copy the file at f8b0132 into
compose_api/simulation/ and parse it locally. The identity is unchanged
(c7e984d3), and it now changes only in a reviewed commit here.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@jcschaff
jcschaff merged commit 5dfa9bb into main Sep 23, 2026
6 checks passed
@jcschaff
jcschaff deleted the fix/pin-simulator-registry branch September 23, 2026 12:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant