mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-11 04:30:53 +08:00
* feat(isolation): add RFC 0012 backend contract Signed-off-by: Drew Newberry <385+drew@users.noreply.github.com> * refactor(isolation): name the interface crate explicitly Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): expose trusted host gateway Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs(agents): inventory the MXC driver Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): add mediated DNS transport Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): tighten interface error and digest contracts Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs(isolation): remove unrelated driver inventory Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): define capability-free launch contract Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): seal confirmed boundary state Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): validate confirmation for external backend implementations Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): clarify mediated DNS identity Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(isolation): generalize loopback connector Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(isolation): unify typed network mediation Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): bind launches to sandbox sessions Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(mxc): initialize extended sandbox status Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): add boundary protocol and Linux primitives Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): harden signals and separate process status from transport Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): validate remote confirmation through public contract Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): validate wire state and propagate snapshot failures Signed-off-by: Drew Newberry <anewberry@nvidia.com> * test(isolation): import owned agent specification explicitly Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs(isolation): describe mediated DNS channel Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): bound mediation attach without nested retries Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(isolation): generalize loopback protocol Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): add transport-neutral session authentication Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(isolation): separate sandbox backend protocol Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): harden runtime boundary controls Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): add terminal boundary operation Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): split supervisor and sandbox runtimes Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): harden boundary isolation and lifecycle ownership Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): reject private root redirects and adopt typed errors Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): preserve accept thread ownership on musl Signed-off-by: Drew Newberry <anewberry@nvidia.com> * test(sandbox): isolate credential probes from filtered threads Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): return retained exec exit status to independent waiters Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): bound network mediation and preserve socket authorization Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): bound control admission and retire stale mediation Signed-off-by: Drew Newberry <anewberry@nvidia.com> * ci(e2e): select migrated drivers per stack layer Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(sandbox): implement loopback connector Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(isolation): authenticate the Sandbox Protocol Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(supervisor): rotate launch-scoped authentication Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(sandbox): consume dedicated backend crate Signed-off-by: Drew Newberry <anewberry@nvidia.com> * test(sandbox): align topology session fixture Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): align projected bootstrap bundle Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(auth): validate refreshed credentials before rotation Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): fail closed across supervisor disconnects Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): repair rebased sandbox CI Signed-off-by: Drew Newberry <anewberry@nvidia.com> * build(runtime): publish separate sandbox and supervisor images Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(config): configure the sandbox runtime image Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(ci): validate sandbox binary linkage Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(isolation): use backend and runtime terminology Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(sandbox): use a scratch runtime image Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(ci): refresh schema and dependency policy Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): bind reconnects to supervisor process Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs: align runtime split operational guidance Signed-off-by: Drew Newberry <anewberry@nvidia.com> * chore(security): document Kubernetes runtime RBAC Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): enforce runtime lifecycle invariants Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(compute): identify sandbox start generations Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(server): restore sandbox launch sessions Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): support authenticated runtime replacement Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(auth): bind sandbox session successors Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(auth): retry pending sandbox successors Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(vm): run the supervisor outside the guest workload Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(vm): use sandbox backend protocol Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): repair rebase integration Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): use unified build toolchain Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(vm): use sandbox runtime terminology Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(vm): own guest network bootstrap Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): expose guest init version Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): select native supervisor artifacts Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): guard guest init Linux symbols Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): scope Linux test imports Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): avoid guest interface casts Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): reconcile admitted sandbox identity Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): share resolved sandbox identity Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): surface host supervisor failures Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): include guest logs on supervisor exit Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): rotate and clean runtime generations Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): make sandbox starts generation-aware Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): rotate restored sandbox sessions Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(vm): keep shared paths in the base layer Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): bind sandbox session lineage Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(docker): isolate workloads behind the host supervisor Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(docker): rotate launch-scoped authentication Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(docker): use sandbox backend protocol Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(docker): use host networking for supervisor Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): preserve host gateway alias resolution Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(docker): use separate sandbox and supervisor images Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): restore startup validation after rebase Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(docker): name the sandbox runtime directly Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): narrow supervisor CA runtime storage Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): close companion isolation gaps Signed-off-by: Drew Newberry <anewberry@nvidia.com> * test(docker): align mediated network expectations Signed-off-by: Drew Newberry <anewberry@nvidia.com> * test(docker): exercise mediated network paths Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): attach supervisor to managed network Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): defer supervisor recovery until gateway is ready Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): make sandbox starts generation-aware Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): rotate restored sandbox sessions Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): preserve workloads during session rotation Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(docker): remove unrelated configuration RFC changes Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): bind sandbox session lineage Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(kubernetes): add proxy-pod isolation topology Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(kubernetes): use sandbox backend protocol Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): use stable sandbox service authority Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(kubernetes): split sandbox and supervisor images Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): adapt proxy pods to current runtime APIs Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(kubernetes): describe the single runtime placement Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(kubernetes): simplify sandbox orchestration Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): validate deployment prerequisites Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): update Trivy Helm profile inventory Signed-off-by: Drew Newberry <anewberry@nvidia.com> * test(kubernetes): update Trivy scan inventory count Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): reuse preloaded runtime images in e2e Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): type and clean runtime resources Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): make sandbox restarts recoverable Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): rotate restored sandbox sessions Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): preserve supervisor egress Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): bind sandbox session lineage Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(podman): adopt isolated sandbox and supervisor containers Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): stage bootstrap archives at named volume destinations Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(podman): rotate launch-scoped authentication Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(podman): use sandbox backend protocol Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(podman): use host networking for supervisor Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(podman): split sandbox and supervisor images Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): repair rebase integration Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(podman): name the sandbox runtime directly Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): provision supervisor CA runtime storage Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): address isolation review findings Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): inspect Debian supervisor provenance Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): use libpod-compatible tmpfs options Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): bind verified sandbox runtime binary Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): provide external driver data directory Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): start sandbox before joining user namespace Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): separate supervisor user namespace Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): make sandbox starts generation-aware Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): rotate restored sandbox sessions Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): bind sandbox session lineage Signed-off-by: Drew Newberry <anewberry@nvidia.com> * perf(isolation): add TCP and DNS benchmark harnesses Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(perf): align benchmark timing and supported protocols Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(perf): report TCP benchmark metrics accurately Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(perf): cancel failed worker startup Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(docker): build matching local supervisor image Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): make local sandbox smoke test runnable Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): wire local sandbox runtime image Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(kubernetes): narrow sandbox service RBAC Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(ci): validate split runtime artifacts Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): harden runtime session handling Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(supervisor): add standalone network proxy role Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs(rfc): remove implementation companion notes Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(vm): standardize runtime release name Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(vm): pin renamed runtime artifacts Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(auth): persist sandbox runtime identity Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(runtime): restore branch validation Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(isolation): reconcile main after rebase Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(network): close unframed HTTP 1.0 responses Signed-off-by: Drew Newberry <anewberry@nvidia.com> * chore(isolation): preserve upstream OCSF updates Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(security): close credential and TLS replay paths Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(auth): make sandbox refresh retries idempotent Signed-off-by: Drew Newberry <anewberry@nvidia.com> --------- Signed-off-by: Drew Newberry <385+drew@users.noreply.github.com> Signed-off-by: Drew Newberry <anewberry@nvidia.com>
300 lines
10 KiB
Bash
Executable File
300 lines
10 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
# Gather VM runtime artifacts from local sources and compress for embedding.
|
|
#
|
|
# This script collects libkrun, libkrunfw, and the guest OCI unpacker
|
|
# from local sources or pinned releases and compresses them with zstd for
|
|
# embedding into the openshell-driver-vm binary.
|
|
#
|
|
# Usage:
|
|
# ./compress-vm-runtime.sh
|
|
#
|
|
# Environment:
|
|
# OPENSHELL_VM_RUNTIME_COMPRESSED_DIR - Output directory (default: target/vm-runtime-compressed)
|
|
# VM_RUNTIME_TARBALL - Path to a pre-built vm-runtime-*.tar.zst tarball.
|
|
# When set, the script extracts and re-compresses
|
|
# artifacts from this tarball instead of looking for
|
|
# local builds. Used by CI and download-kernel-runtime.sh.
|
|
#
|
|
# The script sets OPENSHELL_VM_RUNTIME_COMPRESSED_DIR for use by build.rs.
|
|
|
|
set -euo pipefail
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
source "${SCRIPT_DIR}/_lib.sh"
|
|
ROOT="$(vm_lib_root)"
|
|
|
|
# Source pins for runtime tool versions.
|
|
source "${ROOT}/crates/openshell-driver-vm/runtime/pins.env" 2>/dev/null || true
|
|
UMOCI_VERSION="${UMOCI_VERSION:-v0.6.0}"
|
|
|
|
# ── macOS dylib portability helpers ─────────────────────────────────────
|
|
|
|
# Make a dylib portable by rewriting paths to use @loader_path
|
|
make_dylib_portable() {
|
|
local dylib="$1"
|
|
local dylib_name
|
|
dylib_name="$(basename "$dylib")"
|
|
|
|
# Rewrite install name
|
|
install_name_tool -id "@loader_path/${dylib_name}" "$dylib" 2>/dev/null || true
|
|
|
|
# Rewrite libkrunfw reference if present
|
|
local krunfw_path
|
|
krunfw_path=$(otool -L "$dylib" 2>/dev/null | grep libkrunfw | awk '{print $1}' || true)
|
|
if [ -n "$krunfw_path" ] && [[ "$krunfw_path" != @* ]]; then
|
|
install_name_tool -change "$krunfw_path" "@loader_path/libkrunfw.dylib" "$dylib"
|
|
fi
|
|
|
|
# Re-codesign
|
|
codesign -f -s - "$dylib" 2>/dev/null || true
|
|
}
|
|
|
|
WORK_DIR="${ROOT}/target/vm-runtime"
|
|
OUTPUT_DIR="${OPENSHELL_VM_RUNTIME_COMPRESSED_DIR:-${ROOT}/target/vm-runtime-compressed}"
|
|
|
|
mkdir -p "$OUTPUT_DIR"
|
|
|
|
download_umoci_for_guest() {
|
|
local output="$1"
|
|
local guest_arch="$2"
|
|
download_umoci_binary "$output" "${UMOCI_VERSION}" "$guest_arch"
|
|
}
|
|
|
|
# ── Fast path: compressed artifacts already present (e.g. from vm:setup) ──
|
|
|
|
_check_compressed_artifacts() {
|
|
local dir="$1"
|
|
local platform
|
|
platform="$(uname -s)-$(uname -m)"
|
|
case "$platform" in
|
|
Darwin-arm64)
|
|
for f in libkrun.dylib.zst libkrunfw.5.dylib.zst umoci.zst; do
|
|
[ -f "${dir}/${f}" ] || return 1
|
|
done
|
|
;;
|
|
Linux-*)
|
|
for f in libkrun.so.zst libkrunfw.so.5.zst umoci.zst; do
|
|
[ -f "${dir}/${f}" ] || return 1
|
|
done
|
|
;;
|
|
*) return 1 ;;
|
|
esac
|
|
return 0
|
|
}
|
|
|
|
if [ -z "${VM_RUNTIME_TARBALL:-}" ] && _check_compressed_artifacts "$OUTPUT_DIR"; then
|
|
echo "==> Compressed artifacts already present in ${OUTPUT_DIR} — skipping compression."
|
|
ls -lah "$OUTPUT_DIR"
|
|
|
|
# Decompress artifacts into WORK_DIR for local inspection.
|
|
echo ""
|
|
echo "==> Decompressing artifacts into ${WORK_DIR} for runtime bundle..."
|
|
rm -rf "$WORK_DIR"
|
|
mkdir -p "$WORK_DIR"
|
|
for f in "${OUTPUT_DIR}"/*.zst; do
|
|
[ -f "$f" ] || continue
|
|
[ -s "$f" ] || continue
|
|
name="$(basename "${f%.zst}")"
|
|
[[ "$name" == rootfs*.tar ]] && continue
|
|
zstd -d "$f" -o "${WORK_DIR}/${name}" -f -q
|
|
chmod 0755 "${WORK_DIR}/${name}"
|
|
done
|
|
echo " Decompressed files:"
|
|
ls -lah "$WORK_DIR"
|
|
|
|
echo ""
|
|
echo "Next step: mise run vm:supervisor && cargo build -p openshell-driver-vm"
|
|
exit 0
|
|
fi
|
|
|
|
rm -rf "$WORK_DIR"
|
|
mkdir -p "$WORK_DIR"
|
|
|
|
# ── Fast path: pre-built tarball from CI or download-kernel-runtime.sh ──
|
|
|
|
if [ -n "${VM_RUNTIME_TARBALL:-}" ]; then
|
|
echo "==> Using pre-built runtime tarball: ${VM_RUNTIME_TARBALL}"
|
|
|
|
if [ ! -f "${VM_RUNTIME_TARBALL}" ]; then
|
|
echo "Error: VM_RUNTIME_TARBALL not found: ${VM_RUNTIME_TARBALL}" >&2
|
|
exit 1
|
|
fi
|
|
|
|
# Extract tarball contents
|
|
zstd -d "${VM_RUNTIME_TARBALL}" --stdout | tar -xf - -C "$WORK_DIR"
|
|
|
|
VM_RUNTIME_PLATFORM="${VM_RUNTIME_PLATFORM:-}"
|
|
if [ -z "$VM_RUNTIME_PLATFORM" ]; then
|
|
case "$(basename "$VM_RUNTIME_TARBALL")" in
|
|
vm-runtime-darwin-aarch64.tar.zst) VM_RUNTIME_PLATFORM="darwin-aarch64" ;;
|
|
vm-runtime-linux-aarch64.tar.zst) VM_RUNTIME_PLATFORM="linux-aarch64" ;;
|
|
vm-runtime-linux-x86_64.tar.zst) VM_RUNTIME_PLATFORM="linux-x86_64" ;;
|
|
esac
|
|
fi
|
|
if [ ! -f "${WORK_DIR}/umoci" ]; then
|
|
if [ -z "$VM_RUNTIME_PLATFORM" ]; then
|
|
echo "Error: VM_RUNTIME_TARBALL has no umoci and platform could not be inferred." >&2
|
|
echo " Set VM_RUNTIME_PLATFORM to linux-aarch64, linux-x86_64, or darwin-aarch64." >&2
|
|
exit 1
|
|
fi
|
|
ensure_umoci_for_platform "$WORK_DIR" "$VM_RUNTIME_PLATFORM" "$UMOCI_VERSION"
|
|
fi
|
|
|
|
echo " Extracted files:"
|
|
ls -lah "$WORK_DIR"
|
|
|
|
echo ""
|
|
compress_dir "$WORK_DIR" "$OUTPUT_DIR"
|
|
|
|
# Check for rootfs tarball (built separately)
|
|
ROOTFS_TARBALL="${OUTPUT_DIR}/rootfs.tar.zst"
|
|
if [ -f "$ROOTFS_TARBALL" ]; then
|
|
echo " rootfs.tar.zst: $(du -h "$ROOTFS_TARBALL" | cut -f1) (pre-built)"
|
|
else
|
|
echo ""
|
|
echo "Note: rootfs.tar.zst not found."
|
|
echo " openshell-driver-vm does not embed a standalone rootfs."
|
|
fi
|
|
|
|
echo ""
|
|
echo "==> Compressed artifacts in ${OUTPUT_DIR}:"
|
|
ls -lah "$OUTPUT_DIR"
|
|
TOTAL=$(du -sh "$OUTPUT_DIR" | cut -f1)
|
|
echo ""
|
|
echo "==> Total compressed size: ${TOTAL}"
|
|
echo ""
|
|
echo "Next step: mise run vm:supervisor && cargo build -p openshell-driver-vm"
|
|
exit 0
|
|
fi
|
|
|
|
echo "==> Detecting platform..."
|
|
|
|
case "$(uname -s)-$(uname -m)" in
|
|
Darwin-arm64)
|
|
PLATFORM="darwin-aarch64"
|
|
echo " Platform: macOS ARM64"
|
|
|
|
# Source priority for libkrun:
|
|
# 1. Custom build from build-libkrun-macos.sh (portable, no GPU deps)
|
|
# 2. Custom runtime with custom libkrunfw
|
|
LIBKRUN_BUILD_DIR="${ROOT}/target/libkrun-build"
|
|
CUSTOM_DIR="${ROOT}/target/custom-runtime"
|
|
BREW_PREFIX="$(brew --prefix 2>/dev/null || echo /opt/homebrew)"
|
|
|
|
if [ -f "${LIBKRUN_BUILD_DIR}/libkrun.dylib" ]; then
|
|
echo " Using portable libkrun from ${LIBKRUN_BUILD_DIR}"
|
|
cp "${LIBKRUN_BUILD_DIR}/libkrun.dylib" "$WORK_DIR/"
|
|
cp "${LIBKRUN_BUILD_DIR}/libkrunfw.dylib" "$WORK_DIR/"
|
|
|
|
# Verify portability
|
|
if otool -L "${LIBKRUN_BUILD_DIR}/libkrun.dylib" | grep -q "/opt/homebrew"; then
|
|
echo " Warning: libkrun has hardcoded Homebrew paths - may not be portable"
|
|
else
|
|
echo " ✓ libkrun is portable (no hardcoded paths)"
|
|
fi
|
|
elif [ -f "${CUSTOM_DIR}/provenance.json" ]; then
|
|
echo " Using custom runtime from ${CUSTOM_DIR}"
|
|
|
|
# libkrun from Homebrew (needs path rewriting for portability)
|
|
if [ -f "${CUSTOM_DIR}/libkrun.dylib" ]; then
|
|
cp "${CUSTOM_DIR}/libkrun.dylib" "$WORK_DIR/"
|
|
else
|
|
cp "${BREW_PREFIX}/lib/libkrun.dylib" "$WORK_DIR/"
|
|
make_dylib_portable "$WORK_DIR/libkrun.dylib"
|
|
fi
|
|
|
|
# libkrunfw from custom build
|
|
cp "${CUSTOM_DIR}/libkrunfw.dylib" "$WORK_DIR/"
|
|
else
|
|
echo "Error: No portable libkrun build found." >&2
|
|
echo " Run: FROM_SOURCE=1 mise run vm:setup" >&2
|
|
exit 1
|
|
fi
|
|
|
|
# Normalize libkrunfw naming - ensure both names exist for build.rs
|
|
# build.rs expects libkrunfw.5.dylib.zst; some builds produce libkrunfw.dylib
|
|
if [ ! -f "$WORK_DIR/libkrunfw.dylib" ] && [ -f "$WORK_DIR/libkrunfw.5.dylib" ]; then
|
|
cp "$WORK_DIR/libkrunfw.5.dylib" "$WORK_DIR/libkrunfw.dylib"
|
|
fi
|
|
if [ ! -f "$WORK_DIR/libkrunfw.5.dylib" ] && [ -f "$WORK_DIR/libkrunfw.dylib" ]; then
|
|
cp "$WORK_DIR/libkrunfw.dylib" "$WORK_DIR/libkrunfw.5.dylib"
|
|
fi
|
|
|
|
download_umoci_for_guest "$WORK_DIR/umoci" "arm64"
|
|
;;
|
|
|
|
Linux-*)
|
|
ARCH="$(uname -m)"
|
|
case "$ARCH" in
|
|
aarch64|x86_64) ;;
|
|
*)
|
|
echo "Error: Unsupported Linux architecture: ${ARCH}" >&2
|
|
exit 1
|
|
;;
|
|
esac
|
|
PLATFORM="linux-${ARCH}"
|
|
echo " Platform: Linux ${ARCH}"
|
|
|
|
BUILD_DIR="${ROOT}/target/libkrun-build"
|
|
if [ ! -f "${BUILD_DIR}/libkrun.so" ]; then
|
|
echo "Error: libkrun not found. Run: FROM_SOURCE=1 mise run vm:setup" >&2
|
|
exit 1
|
|
fi
|
|
|
|
cp "${BUILD_DIR}/libkrun.so" "$WORK_DIR/"
|
|
|
|
# Copy libkrunfw - find the versioned .so file
|
|
for krunfw in "${BUILD_DIR}"/libkrunfw.so*; do
|
|
[ -f "$krunfw" ] || continue
|
|
cp "$krunfw" "$WORK_DIR/"
|
|
done
|
|
|
|
# Ensure the soname symlink (libkrunfw.so.5) exists alongside the fully
|
|
# versioned file (libkrunfw.so.5.x.y). libloading loads by soname.
|
|
if [ ! -f "$WORK_DIR/libkrunfw.so.5" ]; then
|
|
versioned=$(ls "$WORK_DIR"/libkrunfw.so.5.* 2>/dev/null | head -n1)
|
|
if [ -n "$versioned" ]; then
|
|
cp "$versioned" "$WORK_DIR/libkrunfw.so.5"
|
|
fi
|
|
fi
|
|
|
|
download_umoci_for_guest "$WORK_DIR/umoci" "$ARCH"
|
|
;;
|
|
|
|
*)
|
|
echo "Error: Unsupported platform: $(uname -s)-$(uname -m)" >&2
|
|
echo "Supported platforms: Darwin-arm64, Linux-aarch64, Linux-x86_64" >&2
|
|
exit 1
|
|
;;
|
|
esac
|
|
|
|
echo ""
|
|
echo "==> Collected artifacts:"
|
|
ls -lah "$WORK_DIR"
|
|
|
|
echo ""
|
|
compress_dir "$WORK_DIR" "$OUTPUT_DIR"
|
|
|
|
# Check for rootfs tarball (built separately by build-rootfs-tarball.sh)
|
|
ROOTFS_TARBALL="${OUTPUT_DIR}/rootfs.tar.zst"
|
|
if [ -f "$ROOTFS_TARBALL" ]; then
|
|
echo " rootfs.tar.zst: $(du -h "$ROOTFS_TARBALL" | cut -f1) (pre-built)"
|
|
else
|
|
echo ""
|
|
echo "Note: rootfs.tar.zst not found."
|
|
echo " openshell-driver-vm does not embed a standalone rootfs."
|
|
fi
|
|
|
|
echo ""
|
|
echo "==> Compressed artifacts in ${OUTPUT_DIR}:"
|
|
ls -lah "$OUTPUT_DIR"
|
|
|
|
TOTAL=$(du -sh "$OUTPUT_DIR" | cut -f1)
|
|
echo ""
|
|
echo "==> Total compressed size: ${TOTAL}"
|
|
echo ""
|
|
echo "Next step: mise run vm:supervisor && cargo build -p openshell-driver-vm"
|