From e2ca9cb890ee11c8e18f194a32c76bdb345b6224 Mon Sep 17 00:00:00 2001 From: Evan Lezar Date: Tue, 25 Aug 2026 14:01:29 +0000 Subject: [PATCH] fix(test-guest): pin HVF runtime dependencies (#2924) Signed-off-by: Evan Lezar --- flake.lock | 17 +++++++++++++++++ flake.nix | 11 ++++++++++- nix/test-guest/README.md | 6 ++++++ nix/test-guest/default.nix | 12 ++++++++---- 4 files changed, 41 insertions(+), 5 deletions(-) diff --git a/flake.lock b/flake.lock index 746d9b48a..b5861792a 100644 --- a/flake.lock +++ b/flake.lock @@ -34,10 +34,27 @@ "type": "github" } }, + "nixpkgs-test-guest": { + "locked": { + "lastModified": 1785318670, + "narHash": "sha256-dN6Ou5x/+23FZLEpYP3IffO+NyJFzUlGumt1uu3MMaY=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "0954f7ee2f6bb3dc7d4e3d0d8bcb8fd4bde4cfc5", + "type": "github" + }, + "original": { + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "0954f7ee2f6bb3dc7d4e3d0d8bcb8fd4bde4cfc5", + "type": "github" + } + }, "root": { "inputs": { "flake-utils": "flake-utils", "nixpkgs": "nixpkgs", + "nixpkgs-test-guest": "nixpkgs-test-guest", "rust-overlay": "rust-overlay", "treefmt-nix": "treefmt-nix" } diff --git a/flake.nix b/flake.nix index aaa8bc75c..9491ebeae 100644 --- a/flake.nix +++ b/flake.nix @@ -14,6 +14,9 @@ inputs = { flake-utils.url = "github:numtide/flake-utils"; nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; + # Keep the QEMU and OVMF runtime used by Apple Silicon test guests on a + # known-good release. Development shells and cross toolchains use nixpkgs. + nixpkgs-test-guest.url = "github:NixOS/nixpkgs/0954f7ee2f6bb3dc7d4e3d0d8bcb8fd4bde4cfc5"; rust-overlay = { url = "github:oxalica/rust-overlay"; inputs.nixpkgs.follows = "nixpkgs"; @@ -29,6 +32,7 @@ { flake-utils, nixpkgs, + nixpkgs-test-guest, treefmt-nix, rust-overlay, ... @@ -40,6 +44,7 @@ inherit system; overlays = [ (import rust-overlay) ]; }; + testGuestPkgs = import nixpkgs-test-guest { inherit system; }; commonDevShellPackages = with pkgs; [ # Assemble Debian artifacts on macOS and Linux. dpkg @@ -56,7 +61,11 @@ rustToolchain = pkgs.rust-bin.fromRustupToolchainFile ./rust-toolchain.toml; z3-static = pkgs.callPackage ./nix/pkgs/z3-static.nix { }; aws-lc-static = pkgs.callPackage ./nix/pkgs/aws-lc-static.nix { }; - testGuest = import ./nix/test-guest { inherit pkgs; }; + testGuest = import ./nix/test-guest { + inherit pkgs; + qemuPkgs = testGuestPkgs; + firmwarePkgs = testGuestPkgs; + }; in { apps.test-guest = testGuest.app; diff --git a/nix/test-guest/README.md b/nix/test-guest/README.md index ae2845205..ca62f893e 100644 --- a/nix/test-guest/README.md +++ b/nix/test-guest/README.md @@ -16,6 +16,12 @@ This prototype uses Nix, QEMU, and Ansible to boot and configure disposable Linu The first run downloads the selected cloud image and VM runtime. Nix reuses those immutable inputs on later runs, while each guest starts from a fresh writable overlay. +On Apple Silicon, test guests deliberately take QEMU 11.0.2 and its matching OVMF +firmware from a separately pinned Nixpkgs revision. All other guest-runtime tools, +development dependencies, and cross-toolchain dependencies continue to use the main +current Nixpkgs input. This avoids a QEMU 11.1 HVF guest boot regression. Update +this pair only after validating an ARM64 Ubuntu guest boot with HVF. + ## Directory structure ```text diff --git a/nix/test-guest/default.nix b/nix/test-guest/default.nix index 2cfc77227..72937cfec 100644 --- a/nix/test-guest/default.nix +++ b/nix/test-guest/default.nix @@ -3,13 +3,17 @@ # PROTOTYPE: Composable distro VMs for installing and exercising artifacts. -{ pkgs }: +{ + pkgs, + qemuPkgs ? pkgs, + firmwarePkgs ? pkgs, +}: let isAarch64 = pkgs.stdenv.hostPlatform.isAarch64; isDarwin = pkgs.stdenv.hostPlatform.isDarwin; architecture = if isAarch64 then "aarch64" else "x86_64"; - qemu = pkgs.qemu.override { hostCpuOnly = true; }; + qemu = qemuPkgs.qemu.override { hostCpuOnly = true; }; qemuBinary = if isAarch64 then "${qemu}/bin/qemu-system-aarch64" else "${qemu}/bin/qemu-system-x86_64"; @@ -75,8 +79,8 @@ let export OPENSHELL_TEST_GUEST_RUNNER=${./run.sh} export TEST_GUEST_BASH=${pkgs.bash}/bin/bash export TEST_GUEST_QEMU=${qemuBinary} - export TEST_GUEST_FIRMWARE_CODE=${pkgs.OVMF.firmware} - export TEST_GUEST_FIRMWARE_VARS=${pkgs.OVMF.variables} + export TEST_GUEST_FIRMWARE_CODE=${firmwarePkgs.OVMF.firmware} + export TEST_GUEST_FIRMWARE_VARS=${firmwarePkgs.OVMF.variables} export TEST_GUEST_MACHINE=${if isAarch64 then "virt" else "q35"} export TEST_GUEST_ACCELERATOR=${if isDarwin then "hvf" else "kvm"} export TEST_GUEST_ARCHITECTURE=${architecture}