diff --git a/.github/workflows/nix.yml b/.github/workflows/nix.yml new file mode 100644 index 0000000..9e6d0f7 --- /dev/null +++ b/.github/workflows/nix.yml @@ -0,0 +1,37 @@ +name: nix + +# Build the PVH fork's libkrun through the Nix flake and push the result to +# the `bsdkrun` Cachix cache, so consumers (bsdkrun's flake depends on this +# one on Linux) get substituted binaries instead of rebuilding the fork. + +on: + push: + branches: ["feat/pvh-boot"] + workflow_dispatch: {} + +permissions: + contents: read + +jobs: + build: + name: nix ยท ${{ matrix.arch }} + strategy: + fail-fast: false + matrix: + include: + - arch: x86_64-linux + runner: ubuntu-latest + - arch: aarch64-linux + runner: ubuntu-24.04-arm + runs-on: ${{ matrix.runner }} + steps: + - uses: actions/checkout@v4 + - uses: DeterminateSystems/nix-installer-action@v16 + - name: Setup Cachix + uses: cachix/cachix-action@v17 + with: + name: bsdkrun + authToken: "${{ secrets.CACHIX_AUTH_TOKEN }}" + + - name: nix build + run: nix build -L .#libkrun diff --git a/flake.lock b/flake.lock new file mode 100644 index 0000000..afea44d --- /dev/null +++ b/flake.lock @@ -0,0 +1,27 @@ +{ + "nodes": { + "nixpkgs": { + "locked": { + "lastModified": 1785571196, + "narHash": "sha256-KoTsyMQqnXQZq8deCEnu4QkyldkwH/bpMMhUcfMdGIw=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "148bab9c1c3c53136ecb44a6ea356a0ed5b39b06", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "root": { + "inputs": { + "nixpkgs": "nixpkgs" + } + } + }, + "root": "root", + "version": 7 +} diff --git a/flake.nix b/flake.nix new file mode 100644 index 0000000..ce9fbdd --- /dev/null +++ b/flake.nix @@ -0,0 +1,54 @@ +{ + description = "libkrun with x86_64 PVH direct boot (feat/pvh-boot fork) โ€” boots NetBSD/FreeBSD amd64 microVMs"; + + inputs = { + nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; + }; + + outputs = { self, nixpkgs }: + let + # libkrun on macOS is a different beast (Hypervisor.framework + EFI, no + # libkrunfw, not in nixpkgs) โ€” this flake covers the Linux/KVM side, which + # is what the PVH fork is for. + systems = [ "x86_64-linux" "aarch64-linux" ]; + forAllSystems = f: + nixpkgs.lib.genAttrs systems + (system: f (import nixpkgs { inherit system; })); + in + { + packages = forAllSystems (pkgs: rec { + # Reuse nixpkgs' libkrun recipe (cargoSetupHook + bindgenHook, libkrunfw, + # glibc.static for the init blob, the --no-as-needed libkrunfw RUSTFLAGS, + # dev-output split) with this fork as the source. importCargoLock reads + # our own Cargo.lock, so there is no vendor hash to keep in sync. + libkrun = pkgs.libkrun.overrideAttrs (old: { + pname = "libkrun-pvh"; + version = "1.19.4-pvh"; + src = self; + cargoDeps = pkgs.rustPlatform.importCargoLock { + lockFile = ./Cargo.lock; + }; + # blk + net are what bsdkrun's BSD guests ride on (virtio-blk root, + # virtio-net via gvproxy). Duplicate flags are harmless if nixpkgs' + # recipe already sets them. + makeFlags = (old.makeFlags or [ ]) ++ [ "BLK=1" "NET=1" ]; + }); + default = libkrun; + }); + + # `nix develop` โ€” everything `make BLK=1 NET=1` needs (cargo, rustc, + # bindgen/libclang, pkg-config, libkrunfw, static glibc), inherited from + # the package itself so the two can't drift apart. + devShells = forAllSystems (pkgs: { + default = pkgs.mkShell { + inputsFrom = [ self.packages.${pkgs.stdenv.hostPlatform.system}.libkrun ]; + packages = with pkgs; [ + rustfmt + clippy + rust-analyzer + patchelf + ]; + }; + }); + }; +}