已合并
Docs:add OAT & LICENSE & SECURITY rules #16
wangzitao创建于 3月16日
Docs:add OAT & LICENSE & SECURITY rules #16
已合并
共 5 个文件变更+248-78
| @@ -0,0 +1,38 @@ | |||
| 1 | +CANN Open Software License Agreement Version 2.0 | ||
| 2 | + | ||
| 3 | +This CANN Open Software License Agreement Version 2.0 (hereinafter referred to as this "Agreement") is a legal agreement between you and Huawei, and it governs your use, modification, or distribution of CANN Open Software (hereinafter referred to as "Software"). Please read this Agreement carefully. | ||
| 4 | + | ||
| 5 | +If you are entering into this Agreement on behalf of a company or other legal entity, you represent that you have the legal authority to bind that entity to this Agreement, in which case "you" will mean the entity you represent. | ||
| 6 | + | ||
| 7 | +BY DOWNLOADING, INSTALLING, OR USING THE SOFTWARE, YOU AGREE YOU HAVE FULLY UNDERSTOOD AND ACCEPTED THE TERMS CONTAINED HEREIN. IF YOU DO NOT AGREE TO ANY OF THE TERMS OF THIS AGREEMENT, OR IF YOU DO NOT QUALIFY FOR AGREEING TO THIS AGREEMENT, YOU ARE NOT AUTHORIZED TO AND SHALL NOT DOWNLOAD, INSTALL, OR MAKE ANY USE OF THE SOFTWARE. | ||
| 8 | + | ||
| 9 | +1. Definition | ||
| 10 | + | ||
| 11 | +1.1 Software means the APIs, source code files, binaries, and related documents of Compute Architecture for Neural Networks("CANN") that are licensable by Huawei, and provided and licensed under this Agreement. | ||
| 12 | + | ||
| 13 | +1.2 Huawei AI Processors mean AI chipsets (i) branded with "Ascend", "Kirin"," Yueying" or other brands owned or controlled by Huawei; or (ii) manufactured (including have manufactured), supplied (including have supplied) or designed (including have designed) by Huawei. | ||
| 14 | + | ||
| 15 | +2. Grant of Intellectual Property Rights | ||
| 16 | +2.1 Subject to the terms and conditions of this Agreement, including your full compliance thereof, Huawei hereby grants you a limited, worldwide, royalty-free, non-transferable, non-sublicensable, and revocable license for you to (i) download, use, modify, integrate, and distribute the Software or its derivative works for the purpose of developing software solely for use in systems with Huawei AI Processors and/or Software, and (ii) distribute any software developed based upon Software and/or its derivative works solely for use in systems with Huawei AI Processors and/or Software. | ||
| 17 | + | ||
| 18 | +3. Restrictions | ||
| 19 | +3.1 You are not authorized to, and shall not use, modify, or distribute this Software or its derivative works for any other purposes than those expressly permitted by this Agreement. You shall not make any use of the Software or its derivative works to develop or distribute any software for use in systems with processors other than Huawei AI Processors. All rights not expressly granted herein are expressly reserved by Huawei. | ||
| 20 | + | ||
| 21 | +3.2 You are not authorized to, and shall not remove, obscure, or alter any copyright or other notices in this Software or any part of it. | ||
| 22 | + | ||
| 23 | +3.3 Distribution Restrictions | ||
| 24 | +You may distribute the Software or its derivative works in any medium, whether in source or executable forms, for the purpose stipulated in Section 2; provided that you provide recipients with a copy of this Agreement, and retain all notices in the Software. | ||
| 25 | + | ||
| 26 | +4. Disclaimer of Warranty and Limitation of Liability | ||
| 27 | +THE SOFTWARE IS PROVIDED WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED. IN NO EVENT SHALL HUAWEI OR ANY OTHER COPYRIGHT HOLDER BE LIABLE TO YOU FOR ANY DAMAGES, INCLUDING, BUT NOT LIMITED TO ANY DIRECT, OR INDIRECT, SPECIAL OR CONSEQUENTIAL DAMAGES ARISING FROM YOUR USE OR INABILITY TO USE THE SOFTWARE, IN WHOLE OR IN PART, NO MATTER HOW IT IS CAUSED OR THE LEGAL THEORY IT IS BASED ON, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. | ||
| 28 | + | ||
| 29 | +5. Termination | ||
| 30 | +5.1 This Agreement will continue to apply until terminated by either you or Huawei as described below: | ||
| 31 | +a.You may terminate this Agreement by ceasing your use of the Software; | ||
| 32 | +b. Huawei may at any time, terminate this Agreement if: (i) you fail to comply with any term of this Agreement; or (ii) you directly or indirectly initiate any legal proceeding against any individual or entity by alleging that the Software or any part of it infringes your intellectual property rights. | ||
| 33 | +5.2 By termination, all the rights granted to you under this Agreement are terminated, and you shall cease to use and delete this Software or any derivative works immediately. All rights granted to you under this Agreement shall hereby be void ab initio in the event of termination in accordance with Section 5.1. b above. Huawei reserves the right to pursue any and all legal remedies available to enforce the terms and conditions of this Agreement or to protect Huawei’s intellectual property rights for such breach or violation. All provisions shall survive the termination of this Agreement except for Section 2 and Section 3.3. | ||
| 34 | + | ||
| 35 | +6. MISCELLANEOUS | ||
| 36 | +If the application of any provision of this Agreement to any particular facts or circumstances is held to be invalid or unenforceable by a court of competent jurisdiction, then (a) the validity and enforceability of such provision as applied to any other particular facts or circumstances and the validity of other provisions of this Agreement shall not in any way be affected or impaired thereby and (b) such provision shall be enforced to the maximum extent possible so as to affect the intent of the you and Huawei and reformed without further action by you and Huawei to the extent necessary to make such provision valid and enforceable. | ||
| 37 | + | ||
| 38 | +END OF THE TERMS AND CONDITIONS | ||
| @@ -0,0 +1,72 @@ | |||
| 1 | + | ||
| 2 | +<!-- Copyright (c) 2026 Huawei Technologies Co., Ltd. | ||
| 3 | + This program is free software, you can redistribute it and/or modify it under the terms and conditions of | ||
| 4 | + CANN Open Software License Agreement Version 2.0 (the "License"). | ||
| 5 | + Please refer to the License for details. You may not use this file except in compliance with the License. | ||
| 6 | + THIS SOFTWARE IS PROVIDED ON AN "AS IS" BASIS, WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, | ||
| 7 | + INCLUDING BUT NOT LIMITED TO NON-INFRINGEMENT, MERCHANTABILITY, OR FITNESS FOR A PARTICULAR PURPOSE. | ||
| 8 | + See LICENSE in the root of the software repository for the full text of the License. | ||
| 9 | +--> | ||
| 10 | + | ||
| 11 | +<configuration> | ||
| 12 | + <oatconfig> | ||
| 13 | + <licensefile></licensefile> | ||
| 14 | + <policylist> | ||
| 15 | + <policy name="projectPolicy" desc=""> | ||
| 16 | + <!--policyitem type="compatibility" name="GPL-2.0+" path="abc/.*" desc="Process that runs independently, invoked by the X process."/--> | ||
| 17 | + <policyitem type="license" name="cann License" path=".*" desc="Dynamically linked by module X"/> | ||
| 18 | + <!--policyitem type="copyright" name="xxx" path="abc/.*" rule="may" group="defaultGroup" filefilter="copyrightPolicyFilter" desc="Developed by X Company"/--> | ||
| 19 | + </policy> | ||
| 20 | + </policylist> | ||
| 21 | + <filefilterlist> | ||
| 22 | + <filefilter name="defaultFilter" desc="Files not to check"> | ||
| 23 | + <!--filteritem type="filename" name="*.uvwxyz" desc="Describe the reason for filtering scan results"/--> | ||
| 24 | + <!--filteritem type="filepath" name="abcdefg/.*.uvwxyz" desc="Describe the reason for filtering scan results"/--> | ||
| 25 | + <!--filteritem type="filepath" name="projectroot/[a-zA-Z0-9]{20,}.sh" desc="Temp files"/--> | ||
| 26 | + </filefilter> | ||
| 27 | + <filefilter name="defaultPolicyFilter" desc="Filters for compatibility,license header policies"> | ||
| 28 | + <!--filteritem type="filename" name="*.uvwxyz" desc="Describe the reason for filtering scan results"/--> | ||
| 29 | + <!--filteritem type="filepath" name="abcdefg/.*.uvwxyz" desc="Describe the reason for filtering scan results"/--> | ||
| 30 | + <!--filteritem type="filepath" name="projectroot/[a-zA-Z0-9]{20,}.sh" desc="Temp files"/--> | ||
| 31 | + </filefilter> | ||
| 32 | + <filefilter name="copyrightPolicyFilter" desc="Filters for copyright header policies"> | ||
| 33 | + <!--filteritem type="filename" name="*.uvwxyz" desc="Describe the reason for filtering scan results"/--> | ||
| 34 | + <!--filteritem type="filepath" name="abcdefg/.*.uvwxyz" desc="Describe the reason for filtering scan results"/--> | ||
| 35 | + <!--filteritem type="filepath" name="projectroot/[a-zA-Z0-9]{20,}.sh" desc="Temp files"/--> | ||
| 36 | + </filefilter> | ||
| 37 | + <filefilter name="licenseFileNamePolicyFilter" desc="Filters for LICENSE file policies"> | ||
| 38 | + <!--filteritem type="filename" name="*.uvwxyz" desc="Describe the reason for filtering scan results"/--> | ||
| 39 | + <!--filteritem type="filepath" name="abcdefg/.*.uvwxyz" desc="Describe the reason for filtering scan results"/--> | ||
| 40 | + <!--filteritem type="filepath" name="projectroot/[a-zA-Z0-9]{20,}.sh" desc="Temp files"/--> | ||
| 41 | + </filefilter> | ||
| 42 | + <filefilter name="readmeFileNamePolicyFilter" desc="Filters for README file policies"> | ||
| 43 | + <!--filteritem type="filename" name="*.uvwxyz" desc="Describe the reason for filtering scan results"/--> | ||
| 44 | + <!--filteritem type="filepath" name="abcdefg/.*.uvwxyz" desc="Describe the reason for filtering scan results"/--> | ||
| 45 | + <!--filteritem type="filepath" name="projectroot/[a-zA-Z0-9]{20,}.sh" desc="Temp files"/--> | ||
| 46 | + </filefilter> | ||
| 47 | + <filefilter name="readmeOpenSourcefileNamePolicyFilter" desc="Filters for README.OpenSource file policies"> | ||
| 48 | + <!--filteritem type="filename" name="*.uvwxyz" desc="Describe the reason for filtering scan results"/--> | ||
| 49 | + <!--filteritem type="filepath" name="abcdefg/.*.uvwxyz" desc="Describe the reason for filtering scan results"/--> | ||
| 50 | + <!--filteritem type="filepath" name="projectroot/[a-zA-Z0-9]{20,}.sh" desc="Temp files"/--> | ||
| 51 | + </filefilter> | ||
| 52 | + <filefilter name="binaryFileTypePolicyFilter" desc="Filters for binary file policies"> | ||
| 53 | + <!--filteritem type="filename" name="*.uvwxyz" desc="Describe the reason for filtering scan results"/--> | ||
| 54 | + <!--filteritem type="filepath" name="abcdefg/.*.uvwxyz" desc="Describe the reason for filtering scan results"/--> | ||
| 55 | + <!--filteritem type="filepath" name="projectroot/[a-zA-Z0-9]{20,}.sh" desc="Temp files"/--> | ||
| 56 | + </filefilter> | ||
| 57 | + | ||
| 58 | + </filefilterlist> | ||
| 59 | + <licensematcherlist> | ||
| 60 | + <licensematcher name="cann License" desc="If the scanning result is InvalidLicense, you can define matching rules here. Note that quotation marks must be escaped."> | ||
| 61 | + <licensetext name=" | ||
| 62 | + This program is free software, you can redistribute it and/or modify it under the terms and conditions of | ||
| 63 | + CANN Open Software License Agreement Version 2.0 (the "License"). | ||
| 64 | + Please refer to the License for details. You may not use this file except in compliance with the License. | ||
| 65 | + THIS SOFTWARE IS PROVIDED ON AN "AS IS" BASIS, WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, | ||
| 66 | + INCLUDING BUT NOT LIMITED TO NON-INFRINGEMENT, MERCHANTABILITY, OR FITNESS FOR A PARTICULAR PURPOSE. | ||
| 67 | + See LICENSE in the root of the software repository for the full text of the License. | ||
| 68 | + " desc=""/> | ||
| 69 | + </licensematcher> | ||
| 70 | + </licensematcherlist> | ||
| 71 | + </oatconfig> | ||
| 72 | +</configuration> | ||
| @@ -0,0 +1,60 @@ | |||
| 1 | +# 安全声明 | ||
| 2 | + | ||
| 3 | +## 运行用户建议 | ||
| 4 | + | ||
| 5 | +基于安全性角度考虑,不建议使用root等管理员类型账户执行任何命令,遵循权限最小化原则。 | ||
| 6 | + | ||
| 7 | +## 文件权限控制 | ||
| 8 | + | ||
| 9 | +- 建议用户在主机(包括宿主机)及容器中设置运行系统umask值为0027及以上,保障新增文件夹默认最高权限为750,新增文件默认最高权限为640。 | ||
| 10 | +- 建议用户对个人隐私数据、商业资产、源文件和算子开发过程中保存的各类文件等敏感内容做好权限控制等安全措施。例如涉及本项目安装目录权限管控、输入公共数据文件权限管控,设定的权限建议参考[A-文件(夹)各场景权限管控推荐最大值](#A-文件(夹)各场景权限管控推荐最大值)。 | ||
| 11 | +- 算子运行时可能会缓存算子编译文件,存储在运行目录下的`kernel_meta_*`文件夹内,加快后续算子的调用速度,用户可根据需要自行对生成后的相关文件进行权限控制。 | ||
| 12 | +- 用户安装和使用过程需要做好权限控制,建议参考[A-文件(夹)各场景权限管控推荐最大值](#A-文件(夹)各场景权限管控推荐最大值)文件权限参考进行设置。 | ||
| 13 | + | ||
| 14 | +## 构建安全声明 | ||
| 15 | + | ||
| 16 | +在源码编译安装本项目时,需要您自行编译,编译过程中会生成一些中间文件,建议您在编译完成后,对中间文件做好权限控制,以保证文件安全。 | ||
| 17 | + | ||
| 18 | +## 运行安全声明 | ||
| 19 | + | ||
| 20 | +- 建议用户结合运行环境资源状况编写对应算子调用脚本。若算子调用脚本与资源状况不匹配,如生成输入数据或标杆计算结果使用空间超出内存容量限制、脚本在本地保存数据超过磁盘空间大小等情况,可能会引发错误并导致进程意外退出。 | ||
| 21 | +- 算子在运行异常时会退出进程并打印报错信息,建议根据报错提示定位具体错误原因,包括设定算子同步执行、查看日志文件等方式。 | ||
| 22 | +- 算子通过[PyTorch](https://gitee.com/ascend/pytorch)方式调用时,可能会因为版本不匹配导致运行错误,具体请参考[PyTorch安全声明](https://gitee.com/ascend/pytorch#%E5%AE%89%E5%85%A8%E5%A3%B0%E6%98%8E)。 | ||
| 23 | + | ||
| 24 | +## 公网地址声明 | ||
| 25 | +本项目代码中包含的公网地址声明如下所示: | ||
| 26 | + | ||
| 27 | +| 类型 | 开源代码地址 | 文件名 | 公网IP地址/公网URL地址/域名/邮箱地址/压缩文件地址 | 用途说明 | | ||
| 28 | +| :------------: |:------------------------------------------------------------------------------------------:|:----------------------------------------------------------| :---------------------------------------------------------- |:-----------------------------------------| | ||
| 29 | +| 依赖 | 不涉及 | cmake/third_party/makeself-fetch.cmake | https://gitcode.com/cann-src-third-party/makeself/releases/download/release-2.5.0-patch1.0/makeself-release-2.5.0-patch1.tar.gz | 从gitcode下载makeself源码,作用编译依赖 | | ||
| 30 | +| 依赖 | 不涉及 | cmake/third_party/json.cmake | https://gitcode.com/cann-src-third-party/json/releases/download/v3.11.3/include.zip | 从gitcode下载json源码,作用编译依赖 | | ||
| 31 | +| 依赖 | 不涉及 | cmake/third_party/gtest.cmake | https://gitcode.com/cann-src-third-party/googletest/releases/download/v1.14.0/googletest-1.14.0.tar.gz | 从gitcode下载googletest源码,作用编译依赖 | | ||
| 32 | +| 依赖 | 不涉及 | cmake/third_party/eigen.cmake | https://gitcode.com/cann-src-third-party/eigen/releases/download/3.4.0/eigen-3.4.0.tar.gz | 从gitcode下载eigen源码,作用编译依赖 | | ||
| 33 | +--- | ||
| 34 | + | ||
| 35 | +## 漏洞机制说明 | ||
| 36 | +[漏洞管理](https://gitcode.com/cann/community/blob/master/security/security.md) | ||
| 37 | + | ||
| 38 | +## 附录 | ||
| 39 | + | ||
| 40 | +### A-文件(夹)各场景权限管控推荐最大值 | ||
| 41 | + | ||
| 42 | +| 类型 | Linux权限参考最大值 | | ||
| 43 | +| -------------- | --------------- | | ||
| 44 | +| 用户主目录 | 750(rwxr-x---) | | ||
| 45 | +| 程序文件(含脚本文件、库文件等) | 550(r-xr-x---) | | ||
| 46 | +| 程序文件目录 | 550(r-xr-x---) | | ||
| 47 | +| 配置文件 | 640(rw-r-----) | | ||
| 48 | +| 配置文件目录 | 750(rwxr-x---) | | ||
| 49 | +| 日志文件(记录完毕或者已经归档) | 440(r--r-----) | | ||
| 50 | +| 日志文件(正在记录) | 640(rw-r-----) | | ||
| 51 | +| 日志文件目录 | 750(rwxr-x---) | | ||
| 52 | +| Debug文件 | 640(rw-r-----) | | ||
| 53 | +| Debug文件目录 | 750(rwxr-x---) | | ||
| 54 | +| 临时文件目录 | 750(rwxr-x---) | | ||
| 55 | +| 维护升级文件目录 | 770(rwxrwx---) | | ||
| 56 | +| 业务数据文件 | 640(rw-r-----) | | ||
| 57 | +| 业务数据文件目录 | 750(rwxr-x---) | | ||
| 58 | +| 密钥组件、私钥、证书、密文文件目录 | 700(rwx-----) | | ||
| 59 | +| 密钥组件、私钥、证书、加密密文 | 600(rw-------) | | ||
| 60 | +| 加解密接口、加解密脚本 | 500(r-x------) | | ||
| @@ -1,52 +1,25 @@ | |||
| 1 | # 环境部署 | 1 | # 环境部署 |
| 2 | -请您在学习QuickStart或各类教程操作之前,请先参考下面步骤完成基础环境搭建。 | ||
| 3 | 2 | ||
| 4 | -注意本文提到的编译态和运行态场景含义如下,请按需安装: | 3 | +您在学习QuickStart或各类教程操作之前,请先参考下面步骤完成基础环境搭建,确保已安装NPU驱动、固件和CANN软件(`Ascend-cann-toolkit`和`Ascend-cann-ops`)等。 |
| 5 | - | ||
| 6 | -- 编译态:针对仅编译不运行本项目的场景,只需安装前置依赖和CANN toolkit包。 | ||
| 7 | -- 运行态:针对运行本项目的场景(编译运行或纯运行),除了安装前置依赖和CANN toolkit包,还需安装驱动与固件、CANN ops包。 | ||
| 8 | - | ||
| 9 | -## 前提条件 | ||
| 10 | - | ||
| 11 | -编译本项目前,请确保编译环境的基础库依赖、NPU驱动和固件已安装。 | ||
| 12 | - | ||
| 13 | -1. **安装依赖** | ||
| 14 | - | ||
| 15 | - - python >= 3.7.0(建议版本 <= 3.10) | ||
| 16 | - - gcc >= 7.3.0 | ||
| 17 | - - cmake >= 3.16.0 | ||
| 18 | - - pigz(可选,安装后可提升打包速度,建议版本 >= 2.4) | ||
| 19 | - - dos2unix | ||
| 20 | - - gawk | ||
| 21 | - - patch | ||
| 22 | - - make | ||
| 23 | - | ||
| 24 | - 上述依赖包请注意版本号,也可通过项目根目录install\_deps.sh一键安装,命令如下,若遇到不支持系统,请参考该文件自行适配。 | ||
| 25 | - ```bash | ||
| 26 | - bash install_deps.sh | ||
| 27 | - ``` | ||
| 28 | - | ||
| 29 | -2. **安装驱动与固件**(运行态依赖) | ||
| 30 | - | ||
| 31 | - 运行算子时必须安装驱动与固件,若仅编译算子,可跳过本操作。 | ||
| 32 | - | ||
| 33 | - 单击[下载链接](https://www.hiascend.com/hardware/firmware-drivers/community),根据实际产品型号和环境架构,获取对应的`Ascend-hdk-<chip_type>-npu-driver_<version>_linux-<arch>.run`、`Ascend-hdk-<chip_type>-npu-firmware_<version>.run`包。 | ||
| 34 | - | ||
| 35 | - 安装指导详见《[CANN 软件安装指南](https://www.hiascend.com/document/redirect/CannCommunityInstSoftware)》。 | ||
| 36 | 4 | ||
| 37 | ## 环境准备 | 5 | ## 环境准备 |
| 38 | 6 | ||
| 39 | -本项目提供了多种CANN包(`Ascend-cann-toolkit`和`Ascend-cann-ops`)安装方式,请按需选择。 | 7 | +本项目提供多种搭建昇腾环境的方式,请按需选择。 |
| 40 | 8 | ||
| 41 | -| CANN安装方式 | 说明 |使用场景| | 9 | +> **说明**:本文提到的编译态和运行态含义如下,请根据实际情况选择。 |
| 42 | -| :--- | :--- | :--- | | 10 | +> |
| 43 | -| WebIDE | 一站式开发平台,提供了在线直接运行的昇腾环境。当前可提供单机算力,**默认安装最新商发版CANN软件包**(目前是CANN 8.5.0)。 | 适用于没有昇腾设备的开发者。| | 11 | +> - 编译态:针对仅编译本项目不运行的场景,只需安装前置依赖和CANN toolkit包。 |
| 44 | -| Docker | Docker镜像是一种高效部署方式,目前仅适用于Atlas A2系列产品,OS仅支持Ubuntu操作系统。**默认安装最新商发版CANN软件包**(目前是CANN 8.5.0) |适用有昇腾设备,需要快速搭建环境的开发者。| | 12 | +> - 运行态:针对运行本项目的场景(编译运行或纯运行),除了安装前置依赖和CANN toolkit包,还需安装驱动与固件、CANN ops包。 |
| 45 | -| 手动安装 | - |适用有昇腾设备,想体验手动安装CANN包或体验最新master分支能力的开发者。| | 13 | + |
| 14 | +| 安装方式 | 使用说明 | 使用场景 | | ||
| 15 | +| ----- | ------ | ------ | | ||
| 16 | +| WebIDE | 一站式开发平台,提供在线直接运行的昇腾环境,无需手动安装。<br>当前可提供单机算力,**默认安装最新商发版CANN软件包**(目前是CANN 8.5.0)。 | 适用于没有昇腾设备的开发者。| | ||
| 17 | +| Docker | Docker镜像是一种高效部署方式,已预集成CANN包和必备依赖。<br>当前仅适用于Atlas A2系列产品,OS仅支持Ubuntu操作系统。**默认安装最新商发版CANN软件包**(目前是CANN 8.5.0) |适用有昇腾设备,需要快速搭建环境的开发者。| | ||
| 18 | +| 手动安装 | - |适用有昇腾设备,想体验手动安装CANN包或体验最新master分支能力的开发者。| | ||
| 46 | 19 | ||
| 47 | ### 方式1:WebIDE环境 | 20 | ### 方式1:WebIDE环境 |
| 48 | 21 | ||
| 49 | -对于无昇腾设备的开发者,可直接使用WebIDE开发平台,即“**算子一站式开发平台**”,该平台为您提供在线可直接运行的昇腾环境,环境中已安装必备的软件包,无需手动安装。更多关于开发平台的介绍请参考[LINK](https://gitcode.com/org/cann/discussions/54)。 | 22 | +对于无昇腾设备的开发者,可直接使用WebIDE开发平台,即“**算子一站式开发平台**”,该平台为您提供在线可直接运行的昇腾环境,环境中已安装必备的驱动固件、软件包和依赖,无需手动安装。更多关于开发平台的介绍请参考[LINK](https://gitcode.com/org/cann/discussions/54)。 |
| 50 | 23 | ||
| 51 | 1. 进入开源项目,单击“`云开发`”按钮,使用已认证过的华为云账号登录。若未注册或认证,请根据页面提示进行注册和认证。 | 24 | 1. 进入开源项目,单击“`云开发`”按钮,使用已认证过的华为云账号登录。若未注册或认证,请根据页面提示进行注册和认证。 |
| 52 | 25 | ||
| @@ -63,7 +36,11 @@ | |||
| 63 | 36 | ||
| 64 | > **说明**:镜像文件比较大,下载需要一定时间,请您耐心等待。 | 37 | > **说明**:镜像文件比较大,下载需要一定时间,请您耐心等待。 |
| 65 | 38 | ||
| 66 | -1.**下载镜像** | 39 | +1.**安装驱动与固件(运行态依赖)** |
| 40 | + | ||
| 41 | +宿主机上昇腾驱动与固件的下载和安装操作请参考《[CANN软件安装指南](https://www.hiascend.com/document/redirect/CannCommunityInstWizard)》中“准备软件包”和“安装NPU驱动和固件”章节。驱动与固件是运行态依赖,若仅编译算子,可以不安装。 | ||
| 42 | + | ||
| 43 | +2.**下载镜像** | ||
| 67 | 44 | ||
| 68 | - 步骤1:以root用户登录宿主机。确保宿主机已安装Docker引擎(版本1.11.2及以上)。 | 45 | - 步骤1:以root用户登录宿主机。确保宿主机已安装Docker引擎(版本1.11.2及以上)。 |
| 69 | - 步骤2:从[昇腾镜像仓库](https://www.hiascend.com/developer/ascendhub/detail/17da20d1c2b6493cb38765adeba85884)拉取已预集成CANN软件包及`ops-blas`所需依赖的镜像。命令如下,根据实际架构选择: | 46 | - 步骤2:从[昇腾镜像仓库](https://www.hiascend.com/developer/ascendhub/detail/17da20d1c2b6493cb38765adeba85884)拉取已预集成CANN软件包及`ops-blas`所需依赖的镜像。命令如下,根据实际架构选择: |
| @@ -75,7 +52,7 @@ | |||
| 75 | docker pull --platform=amd64 swr.cn-south-1.myhuaweicloud.com/ascendhub/cann:8.5.0-910b-ubuntu22.04-py3.10-ops | 52 | docker pull --platform=amd64 swr.cn-south-1.myhuaweicloud.com/ascendhub/cann:8.5.0-910b-ubuntu22.04-py3.10-ops |
| 76 | ``` | 53 | ``` |
| 77 | 54 | ||
| 78 | -2.**运行Docker** | 55 | +3.**运行Docker** |
| 79 | 拉取镜像后,需要以特定参数启动容器,以便容器内能访问宿主的昇腾设备。 | 56 | 拉取镜像后,需要以特定参数启动容器,以便容器内能访问宿主的昇腾设备。 |
| 80 | 57 | ||
| 81 | ```bash | 58 | ```bash |
| @@ -97,46 +74,76 @@ docker run --name cann_container --device /dev/davinci0 --device /dev/davinci_ma | |||
| 97 | | `swr.cn-south-1.myhuaweicloud.com/ascendhub/cann:8.5.0-910b-ubuntu22.04-py3.10-ops` | 指定要运行的Docker镜像。 |请确保此镜像名和标签(tag)与你通过`docker pull`拉取的镜像完全一致。 | | 74 | | `swr.cn-south-1.myhuaweicloud.com/ascendhub/cann:8.5.0-910b-ubuntu22.04-py3.10-ops` | 指定要运行的Docker镜像。 |请确保此镜像名和标签(tag)与你通过`docker pull`拉取的镜像完全一致。 | |
| 98 | | `bash` | 容器启动后立即执行的命令。 | - | | 75 | | `bash` | 容器启动后立即执行的命令。 | - | |
| 99 | 76 | ||
| 100 | -### 方式3:手动安装CANN | 77 | +### 方式3:手动安装 |
| 101 | 78 | ||
| 102 | -对于有昇腾设备的开发者,若您想手动安装CANN包,请根据下述描述,选择对应的安装指导。 | 79 | +对于有昇腾设备的开发者,若您想手动搭建昇腾环境,请参考下述步骤。 |
| 103 | 80 | ||
| 104 | -**场景1:已发布版本** | 81 | +#### 前置依赖 |
| 105 | 82 | ||
| 106 | -若您想体验**官网正式发布的CANN包**能力,请访问[CANN官网下载中心](https://www.hiascend.com/cann/download),根据产品和环境架构选择对应版本的软件包(仅支持CANN 8.5.0及后续版本)进行安装。 | 83 | +请先确保编译环境的基础库依赖已安装,注意满足版本号要求。 |
| 107 | 84 | ||
| 85 | +- python >= 3.7.0(建议版本 <= 3.10) | ||
| 86 | +- gcc >= 7.3.0 | ||
| 87 | +- cmake >= 3.16.0 | ||
| 88 | +- pigz(可选,安装后可提升打包速度,建议版本 >= 2.4) | ||
| 89 | +- dos2unix | ||
| 90 | +- gawk | ||
| 91 | +- make | ||
| 92 | +- patch | ||
| 93 | +- googletest(仅执行UT时依赖,建议版本 [release-1.11.0](https://github.com/google/googletest/releases/tag/release-1.11.0)) | ||
| 108 | 94 | ||
| 109 | -**场景2:master版本** | 95 | +上述依赖可通过项目根目录install\_deps.sh一键安装,命令如下,若遇到不支持系统,请参考该文件自行适配。 |
| 110 | 96 | ||
| 111 | -若您想体验**master分支最新能力**,请单击[下载链接](https://ascend.devcloud.huaweicloud.com/artifactory/cann-run-mirror/software/master/),根据产品和环境架构选择对应版本的软件包,关键安装命令如下,更多安装指导参考《[CANN软件安装指南](https://www.hiascend.com/document/redirect/CannCommunityInstWizard)》。 | 97 | +```bash |
| 98 | +bash install_deps.sh | ||
| 99 | +``` | ||
| 112 | 100 | ||
| 113 | -1. 安装CANN toolkit包。 | 101 | +安装完上述依赖后,可通过项目根目录requirements.txt继续安装python三方库依赖,命令如下。 |
| 114 | 102 | ||
| 115 | - ```bash | 103 | +```bash |
| 116 | - # 确保安装包具有可执行权限 | 104 | +pip3 install -r requirements.txt |
| 117 | - chmod +x Ascend-cann-toolkit_${cann_version}_linux-${arch}.run | 105 | +``` |
| 118 | - # 安装命令 | ||
| 119 | - ./Ascend-cann-toolkit_${cann_version}_linux-${arch}.run --install --install-path=${install_path} | ||
| 120 | - ``` | ||
| 121 | - - \$\{cann\_version\}:表示CANN包版本号。 | ||
| 122 | - - \$\{arch\}:表示CPU架构,如aarch64、x86_64。 | ||
| 123 | - - \$\{install\_path\}:表示指定安装路径,默认安装在`/usr/local/Ascend`目录。 | ||
| 124 | 106 | ||
| 125 | -2. 安装CANN ops包(运行态依赖)。 | 107 | +#### 软件安装 |
| 126 | 108 | ||
| 127 | - ops包是运行态依赖,若仅编译算子,可以不安装此包。 | 109 | +1. **安装驱动与固件(运行态依赖)** |
| 128 | 110 | ||
| 129 | - ```bash | 111 | + 昇腾驱动与固件的下载和安装操作请参考《[CANN软件安装指南](https://www.hiascend.com/document/redirect/CannCommunityInstWizard)》中“准备软件包”和“安装NPU驱动和固件”章节。驱动与固件是运行态依赖,若仅编译算子,可以不安装。 |
| 130 | - # 确保安装包具有可执行权限 | ||
| 131 | - chmod +x Ascend-cann-${soc_name}-ops_${cann_version}_linux-${arch}.run | ||
| 132 | - # 安装命令 | ||
| 133 | - ./Ascend-cann-${soc_name}-ops_${cann_version}_linux-${arch}.run --install --install-path=${install_path} | ||
| 134 | - ``` | ||
| 135 | 112 | ||
| 136 | - - \$\{cann\_version\}:表示CANN包版本号。 | 113 | +2. **安装CANN包** |
| 137 | - - \$\{arch\}:表示CPU架构,如aarch64、x86_64。 | 114 | + |
| 138 | - - \$\{soc\_name\}:表示NPU型号名称。 | 115 | + - **场景1:已发布版本** |
| 139 | - - \$\{install\_path\}:表示指定安装路径,ops包需与toolkit包安装在相同路径,root用户默认安装在`/usr/local/Ascend`目录。 | 116 | + |
| 117 | + 若您想体验官网正式发布的CANN包能力,请访问[CANN官网下载中心](https://www.hiascend.com/cann/download),根据产品和环境架构选择对应版本的软件包(仅支持CANN 8.5.0及后续版本)进行安装。 | ||
| 118 | + | ||
| 119 | + - **场景2:master版本** | ||
| 120 | + | ||
| 121 | + 若您想体验master分支最新能力,请单击[下载链接](https://ascend.devcloud.huaweicloud.com/artifactory/cann-run-mirror/software/master/),根据产品和环境架构选择对应版本的软件包,关键安装命令如下,更多安装指导参考《[CANN软件安装指南](https://www.hiascend.com/document/redirect/CannCommunityInstWizard)》。 | ||
| 122 | + | ||
| 123 | + 1. **安装CANN toolkit包** | ||
| 124 | + | ||
| 125 | + ```bash | ||
| 126 | + # 确保安装包具有可执行权限 | ||
| 127 | + chmod +x Ascend-cann-toolkit_${cann_version}_linux-${arch}.run | ||
| 128 | + # 安装命令 | ||
| 129 | + ./Ascend-cann-toolkit_${cann_version}_linux-${arch}.run --install --install-path=${install_path} | ||
| 130 | + ``` | ||
| 131 | + | ||
| 132 | + 2. **安装CANN ops包(运行态依赖)** | ||
| 133 | + | ||
| 134 | + ops包是运行态依赖,若仅编译算子,可不安装此包。 | ||
| 135 | + | ||
| 136 | + ```bash | ||
| 137 | + # 确保安装包具有可执行权限 | ||
| 138 | + chmod +x Ascend-cann-${soc_name}-ops_${cann_version}_linux-${arch}.run | ||
| 139 | + # 安装命令 | ||
| 140 | + ./Ascend-cann-${soc_name}-ops_${cann_version}_linux-${arch}.run --install --install-path=${install_path} | ||
| 141 | + ``` | ||
| 142 | + | ||
| 143 | + - \$\{cann\_version\}:表示CANN包版本号。 | ||
| 144 | + - \$\{arch\}:表示CPU架构,如aarch64、x86_64。 | ||
| 145 | + - \$\{soc\_name\}:表示NPU型号名称。 | ||
| 146 | + - \$\{install\_path\}:表示指定安装路径,ops包需与toolkit包安装在相同路径,root用户默认安装在`/usr/local/Ascend`目录。 | ||
| 140 | 147 | ||
| 141 | ## 环境验证 | 148 | ## 环境验证 |
| 142 | 149 | ||
| @@ -176,13 +183,6 @@ git clone -b ${tag_version} https://gitcode.com/cann/ops-blas.git | |||
| 176 | 183 | ||
| 177 | 对于WebIDE或Docker环境,已默认提供最新商发版本的项目源码,如需获取其他版本的源码,也需通过上述命令下载源码。 | 184 | 对于WebIDE或Docker环境,已默认提供最新商发版本的项目源码,如需获取其他版本的源码,也需通过上述命令下载源码。 |
| 178 | 185 | ||
| 179 | -对于手动安装CANN场景,安装CANN包和下载源码后,还需额外安装python基础库依赖。 | ||
| 180 | - | ||
| 181 | -```bash | ||
| 182 | -# 安装根目录requirements.txt依赖 | ||
| 183 | -cd ops-blas | ||
| 184 | -pip3 install -r requirements.txt | ||
| 185 | -``` | ||
| 186 | > [!NOTE] 注意 | 186 | > [!NOTE] 注意 |
| 187 | > | 187 | > |
| 188 | > - gitcode平台在使用HTTPS协议的时候要配置并使用个人访问令牌代替登录密码进行克隆,推送等操作。 | 188 | > - gitcode平台在使用HTTPS协议的时候要配置并使用个人访问令牌代替登录密码进行克隆,推送等操作。 |
| @@ -159,7 +159,7 @@ typedef enum aclblasLtMatmulDescAttribute { | |||
| 159 | ACLBLASLT_MATMUL_DESC_EPILOGUE_AUX_LD = 11, /**<The leading dimension of the epilogue auxiliary buffer pointer in the device memory. Data type: ``int64_t``. */ | 159 | ACLBLASLT_MATMUL_DESC_EPILOGUE_AUX_LD = 11, /**<The leading dimension of the epilogue auxiliary buffer pointer in the device memory. Data type: ``int64_t``. */ |
| 160 | ACLBLASLT_MATMUL_DESC_EPILOGUE_AUX_BATCH_STRIDE = 12, /**<The batch stride of the epilogue auxiliary buffer pointer in the device memory. Data type: ``int64_t``. */ | 160 | ACLBLASLT_MATMUL_DESC_EPILOGUE_AUX_BATCH_STRIDE = 12, /**<The batch stride of the epilogue auxiliary buffer pointer in the device memory. Data type: ``int64_t``. */ |
| 161 | ACLBLASLT_MATMUL_DESC_POINTER_MODE = 13, /**<Specifies that alpha and beta are passed by reference, whether they are scalars on the host or on the device, or device vectors. Default value is: ``ACLBLASLT_POINTER_MODE_HOST`` (on the host). Data type: ``int32_t`` based on ``aclblasLtPointerMode_t``. */ | 161 | ACLBLASLT_MATMUL_DESC_POINTER_MODE = 13, /**<Specifies that alpha and beta are passed by reference, whether they are scalars on the host or on the device, or device vectors. Default value is: ``ACLBLASLT_POINTER_MODE_HOST`` (on the host). Data type: ``int32_t`` based on ``aclblasLtPointerMode_t``. */ |
| 162 | - ACLBLASLT_MATMUL_DESC_AMAX_D_POINTER = 14, /**<Device pointer to the memory location that on completion will be set to the maximum of the absolute values in the output matrix. Data type: ``void*`` / ``const void*``. */ | 162 | + ACLBLASLT_MATMUL_DESC_AMAX_D_POINTER = 14, /**<Device pointer to the memory that on completion will be set to the maximum of the absolute values in the output matrix. Data type: ``void*`` / ``const void*``. */ |
| 163 | ACLBLASLT_MATMUL_DESC_EPILOGUE_AUX_DATA_TYPE = 22, /**<Type of the auxiliary vector in the device memory. Default value is: ``ACLBLASLT_DATATYPE_INVALID`` (using D matrix type). Data type: ``int32_t`` based on ``aclDataType``. */ | 163 | ACLBLASLT_MATMUL_DESC_EPILOGUE_AUX_DATA_TYPE = 22, /**<Type of the auxiliary vector in the device memory. Default value is: ``ACLBLASLT_DATATYPE_INVALID`` (using D matrix type). Data type: ``int32_t`` based on ``aclDataType``. */ |
| 164 | ACLBLASLT_MATMUL_DESC_A_SCALE_MODE = 31, /**<Scaling mode that defines how the matrix scaling factor for matrix A is interpreted. See ``aclblasLtMatmulMatrixScale_t``. */ | 164 | ACLBLASLT_MATMUL_DESC_A_SCALE_MODE = 31, /**<Scaling mode that defines how the matrix scaling factor for matrix A is interpreted. See ``aclblasLtMatmulMatrixScale_t``. */ |
| 165 | ACLBLASLT_MATMUL_DESC_B_SCALE_MODE = 32, /**<Scaling mode that defines how the matrix scaling factor for matrix B is interpreted. See ``aclblasLtMatmulMatrixScale_t``. */ | 165 | ACLBLASLT_MATMUL_DESC_B_SCALE_MODE = 32, /**<Scaling mode that defines how the matrix scaling factor for matrix B is interpreted. See ``aclblasLtMatmulMatrixScale_t``. */ |