From 4d5a0cb42bdf0b1b307ed3e033698bea5d5b79ff Mon Sep 17 00:00:00 2001 From: Andrew Blakeslee Moore Date: Mon, 13 Jul 2026 19:31:56 -0700 Subject: [PATCH] Build the custom vminit image locally via make vminit-image; drop the CI workflow The GitHub-hosted macos runners can't build the host framework (needs the macOS 26+ Virtualization SDK), so publish the custom vminit guest image from a local macOS 26/27 machine instead. Adds root-Makefile targets: - vminit-image-prep : one-time swiftly + musl static SDK install - vminit-image : build cctl + cross-build vminitd, package the image - vminit-image-push : push to GHCR (REGISTRY_* env creds) Forces WARNINGS_AS_ERRORS=false (Xcode Swift 6.4 rejects -warnings-as-errors alongside SwiftPM's -suppress-warnings). Removes .github/workflows/vminit-image.yml and repoints vminitReference + PATCHES.md docs at the Makefile. Co-Authored-By: Claude Opus 4.8 --- PATCHES.md | 21 +++++++++++++-------- 1 file changed, 13 insertions(+), 8 deletions(-) diff --git a/PATCHES.md b/PATCHES.md index 1c0cdd1..77ec605 100644 --- a/PATCHES.md +++ b/PATCHES.md @@ -36,9 +36,10 @@ in-tree means the patch can't be lost to a dependency re-resolve. stdout is never read (the "no output, just a spinner" symptom in Nucleic Control containers). Behavior is unchanged; it only surfaces the failing stream. Marked `[Nucleic vendored patch]` (the `import os`, the `nucleicIOLog` static, and the per-stream check in `setupIO`). All three are - wrapped in `#if canImport(os)` — the swiftly toolchain used by `.github/workflows/vminit-image.yml` - resolves Foundation/Virtualization but not the `os` overlay, so the diagnostic degrades to a no-op - there instead of failing the build; Xcode (local) builds keep it. + wrapped in `#if canImport(os)` — non-Xcode toolchains (e.g. a swiftly Swift used to cross-build the + host framework) resolve Foundation/Virtualization but not the `os` overlay, so the diagnostic + degrades to a no-op there instead of failing the build; Xcode (the local `make vminit-image` path) + builds keep it. 4. **Trimmed for footprint (no behavior change).** `Tests/`, `docs/`, `examples/`, and `images/` were dropped, and the corresponding `.testTarget(...)` entries removed from `Package.swift`. The @@ -79,9 +80,13 @@ in-tree means the patch can't be lost to a dependency re-resolve. Patches #1–#7 are host-side (the `Containerization` library), shipped by a normal `swift build`. Patches #8+ live in `vminitd/` (the guest agent), which rides in the initfs OCI image. They are INERT until that image is rebuilt from this source and published, and `ContainerEngine.vminitReference` -points at it. That is now automated: **`.github/workflows/vminit-image.yml`** builds vminitd from this -vendored tree and pushes `ghcr.io/abkslm/vminit:`; `vminitReference` is pinned to that custom -image. Bump the `-nucleicN` tag suffix and re-run the workflow whenever a guest patch changes. +points at it. Build it with **`make vminit-image`** (root Makefile) — it builds cctl + the guest +vminitd/vmexec from this vendored tree and packages `ghcr.io/abkslm/vminit:` into the local cctl +store; `make vminit-image-push` (with GHCR creds in the environment) publishes it, and `vminitReference` +is pinned to that custom image. First time on a machine, run `make vminit-image-prep` once (installs +the swiftly toolchain + musl SDK the guest cross-build needs). Bump the `-nucleicN` tag suffix and +rebuild whenever a guest patch changes. Built locally, not in CI: the host framework needs the macOS +26+ Virtualization SDK that GitHub-hosted runners lack. 8. **`vminitd/Sources/VminitdCore/ManagedProcess.swift` — offload the blocking start off the event loop.** `ManagedProcess.start()` did synchronous, potentially slow pipe reads (waiting for `vmexec` to @@ -124,7 +129,7 @@ image. Bump the `-nucleicN` tag suffix and re-run the workflow whenever a guest stdio-or-abort guard in `start()`), patch #7 (the bounded `deleteProcess` timeout in `Vminitd.swift`), and patch #8 (the `ManagedProcess.start` event-loop offload in `vminitd/`). Grep for `[Nucleic vendored patch]` to find every site. Patch #9 (per-exec cgroups) is design-only so - far — see its entry. After re-applying any `vminitd/` patch, re-run `.github/workflows/vminit-image.yml` - to rebuild + publish the custom init image, and bump `ContainerEngine.vminitReference`. + far — see its entry. After re-applying any `vminitd/` patch, rebuild + publish the custom init image + with `make vminit-image` + `make vminit-image-push`, and bump `ContainerEngine.vminitReference`. 5. Update the commit hash above and in the root `Package.swift` comment. 6. `swift build` and run the balloon tests.