fix(test-guest): pin HVF runtime dependencies (#2924)

Signed-off-by: Evan Lezar <elezar@nvidia.com>
This commit is contained in:
Evan Lezar
2026-08-25 14:01:29 +00:00
committed by GitHub
parent 455883905a
commit e2ca9cb890
4 changed files with 41 additions and 5 deletions
Generated
+17
View File
@@ -34,10 +34,27 @@
"type": "github"
}
},
"nixpkgs-test-guest": {
"locked": {
"lastModified": 1785318670,
"narHash": "sha256-dN6Ou5x/+23FZLEpYP3IffO+NyJFzUlGumt1uu3MMaY=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "0954f7ee2f6bb3dc7d4e3d0d8bcb8fd4bde4cfc5",
"type": "github"
},
"original": {
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "0954f7ee2f6bb3dc7d4e3d0d8bcb8fd4bde4cfc5",
"type": "github"
}
},
"root": {
"inputs": {
"flake-utils": "flake-utils",
"nixpkgs": "nixpkgs",
"nixpkgs-test-guest": "nixpkgs-test-guest",
"rust-overlay": "rust-overlay",
"treefmt-nix": "treefmt-nix"
}
+10 -1
View File
@@ -14,6 +14,9 @@
inputs = {
flake-utils.url = "github:numtide/flake-utils";
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
# Keep the QEMU and OVMF runtime used by Apple Silicon test guests on a
# known-good release. Development shells and cross toolchains use nixpkgs.
nixpkgs-test-guest.url = "github:NixOS/nixpkgs/0954f7ee2f6bb3dc7d4e3d0d8bcb8fd4bde4cfc5";
rust-overlay = {
url = "github:oxalica/rust-overlay";
inputs.nixpkgs.follows = "nixpkgs";
@@ -29,6 +32,7 @@
{
flake-utils,
nixpkgs,
nixpkgs-test-guest,
treefmt-nix,
rust-overlay,
...
@@ -40,6 +44,7 @@
inherit system;
overlays = [ (import rust-overlay) ];
};
testGuestPkgs = import nixpkgs-test-guest { inherit system; };
commonDevShellPackages = with pkgs; [
# Assemble Debian artifacts on macOS and Linux.
dpkg
@@ -56,7 +61,11 @@
rustToolchain = pkgs.rust-bin.fromRustupToolchainFile ./rust-toolchain.toml;
z3-static = pkgs.callPackage ./nix/pkgs/z3-static.nix { };
aws-lc-static = pkgs.callPackage ./nix/pkgs/aws-lc-static.nix { };
testGuest = import ./nix/test-guest { inherit pkgs; };
testGuest = import ./nix/test-guest {
inherit pkgs;
qemuPkgs = testGuestPkgs;
firmwarePkgs = testGuestPkgs;
};
in
{
apps.test-guest = testGuest.app;
+6
View File
@@ -16,6 +16,12 @@ This prototype uses Nix, QEMU, and Ansible to boot and configure disposable Linu
The first run downloads the selected cloud image and VM runtime. Nix reuses those immutable inputs on later runs, while each guest starts from a fresh writable overlay.
On Apple Silicon, test guests deliberately take QEMU 11.0.2 and its matching OVMF
firmware from a separately pinned Nixpkgs revision. All other guest-runtime tools,
development dependencies, and cross-toolchain dependencies continue to use the main
current Nixpkgs input. This avoids a QEMU 11.1 HVF guest boot regression. Update
this pair only after validating an ARM64 Ubuntu guest boot with HVF.
## Directory structure
```text
+8 -4
View File
@@ -3,13 +3,17 @@
# PROTOTYPE: Composable distro VMs for installing and exercising artifacts.
{ pkgs }:
{
pkgs,
qemuPkgs ? pkgs,
firmwarePkgs ? pkgs,
}:
let
isAarch64 = pkgs.stdenv.hostPlatform.isAarch64;
isDarwin = pkgs.stdenv.hostPlatform.isDarwin;
architecture = if isAarch64 then "aarch64" else "x86_64";
qemu = pkgs.qemu.override { hostCpuOnly = true; };
qemu = qemuPkgs.qemu.override { hostCpuOnly = true; };
qemuBinary =
if isAarch64 then "${qemu}/bin/qemu-system-aarch64" else "${qemu}/bin/qemu-system-x86_64";
@@ -75,8 +79,8 @@ let
export OPENSHELL_TEST_GUEST_RUNNER=${./run.sh}
export TEST_GUEST_BASH=${pkgs.bash}/bin/bash
export TEST_GUEST_QEMU=${qemuBinary}
export TEST_GUEST_FIRMWARE_CODE=${pkgs.OVMF.firmware}
export TEST_GUEST_FIRMWARE_VARS=${pkgs.OVMF.variables}
export TEST_GUEST_FIRMWARE_CODE=${firmwarePkgs.OVMF.firmware}
export TEST_GUEST_FIRMWARE_VARS=${firmwarePkgs.OVMF.variables}
export TEST_GUEST_MACHINE=${if isAarch64 then "virt" else "q35"}
export TEST_GUEST_ACCELERATOR=${if isDarwin then "hvf" else "kvm"}
export TEST_GUEST_ARCHITECTURE=${architecture}