Build the custom vminit image locally via make vminit-image; drop the CI workflow
The GitHub-hosted macos runners can't build the host framework (needs the macOS 26+ Virtualization SDK), so publish the custom vminit guest image from a local macOS 26/27 machine instead. Adds root-Makefile targets: - vminit-image-prep : one-time swiftly + musl static SDK install - vminit-image : build cctl + cross-build vminitd, package the image - vminit-image-push : push to GHCR (REGISTRY_* env creds) Forces WARNINGS_AS_ERRORS=false (Xcode Swift 6.4 rejects -warnings-as-errors alongside SwiftPM's -suppress-warnings). Removes .github/workflows/vminit-image.yml and repoints vminitReference + PATCHES.md docs at the Makefile. Co-Authored-By: Claude Opus 4.8 <[email protected]>
This commit is contained in:
+13
-8
@@ -36,9 +36,10 @@ in-tree means the patch can't be lost to a dependency re-resolve.
|
|||||||
stdout is never read (the "no output, just a spinner" symptom in Nucleic Control containers).
|
stdout is never read (the "no output, just a spinner" symptom in Nucleic Control containers).
|
||||||
Behavior is unchanged; it only surfaces the failing stream. Marked `[Nucleic vendored patch]`
|
Behavior is unchanged; it only surfaces the failing stream. Marked `[Nucleic vendored patch]`
|
||||||
(the `import os`, the `nucleicIOLog` static, and the per-stream check in `setupIO`). All three are
|
(the `import os`, the `nucleicIOLog` static, and the per-stream check in `setupIO`). All three are
|
||||||
wrapped in `#if canImport(os)` — the swiftly toolchain used by `.github/workflows/vminit-image.yml`
|
wrapped in `#if canImport(os)` — non-Xcode toolchains (e.g. a swiftly Swift used to cross-build the
|
||||||
resolves Foundation/Virtualization but not the `os` overlay, so the diagnostic degrades to a no-op
|
host framework) resolve Foundation/Virtualization but not the `os` overlay, so the diagnostic
|
||||||
there instead of failing the build; Xcode (local) builds keep it.
|
degrades to a no-op there instead of failing the build; Xcode (the local `make vminit-image` path)
|
||||||
|
builds keep it.
|
||||||
|
|
||||||
4. **Trimmed for footprint (no behavior change).** `Tests/`, `docs/`, `examples/`, and `images/`
|
4. **Trimmed for footprint (no behavior change).** `Tests/`, `docs/`, `examples/`, and `images/`
|
||||||
were dropped, and the corresponding `.testTarget(...)` entries removed from `Package.swift`. The
|
were dropped, and the corresponding `.testTarget(...)` entries removed from `Package.swift`. The
|
||||||
@@ -79,9 +80,13 @@ in-tree means the patch can't be lost to a dependency re-resolve.
|
|||||||
Patches #1–#7 are host-side (the `Containerization` library), shipped by a normal `swift build`.
|
Patches #1–#7 are host-side (the `Containerization` library), shipped by a normal `swift build`.
|
||||||
Patches #8+ live in `vminitd/` (the guest agent), which rides in the initfs OCI image. They are INERT
|
Patches #8+ live in `vminitd/` (the guest agent), which rides in the initfs OCI image. They are INERT
|
||||||
until that image is rebuilt from this source and published, and `ContainerEngine.vminitReference`
|
until that image is rebuilt from this source and published, and `ContainerEngine.vminitReference`
|
||||||
points at it. That is now automated: **`.github/workflows/vminit-image.yml`** builds vminitd from this
|
points at it. Build it with **`make vminit-image`** (root Makefile) — it builds cctl + the guest
|
||||||
vendored tree and pushes `ghcr.io/abkslm/vminit:<tag>`; `vminitReference` is pinned to that custom
|
vminitd/vmexec from this vendored tree and packages `ghcr.io/abkslm/vminit:<tag>` into the local cctl
|
||||||
image. Bump the `-nucleicN` tag suffix and re-run the workflow whenever a guest patch changes.
|
store; `make vminit-image-push` (with GHCR creds in the environment) publishes it, and `vminitReference`
|
||||||
|
is pinned to that custom image. First time on a machine, run `make vminit-image-prep` once (installs
|
||||||
|
the swiftly toolchain + musl SDK the guest cross-build needs). Bump the `-nucleicN` tag suffix and
|
||||||
|
rebuild whenever a guest patch changes. Built locally, not in CI: the host framework needs the macOS
|
||||||
|
26+ Virtualization SDK that GitHub-hosted runners lack.
|
||||||
|
|
||||||
8. **`vminitd/Sources/VminitdCore/ManagedProcess.swift` — offload the blocking start off the event loop.**
|
8. **`vminitd/Sources/VminitdCore/ManagedProcess.swift` — offload the blocking start off the event loop.**
|
||||||
`ManagedProcess.start()` did synchronous, potentially slow pipe reads (waiting for `vmexec` to
|
`ManagedProcess.start()` did synchronous, potentially slow pipe reads (waiting for `vmexec` to
|
||||||
@@ -124,7 +129,7 @@ image. Bump the `-nucleicN` tag suffix and re-run the workflow whenever a guest
|
|||||||
stdio-or-abort guard in `start()`), patch #7 (the bounded `deleteProcess` timeout in
|
stdio-or-abort guard in `start()`), patch #7 (the bounded `deleteProcess` timeout in
|
||||||
`Vminitd.swift`), and patch #8 (the `ManagedProcess.start` event-loop offload in `vminitd/`). Grep
|
`Vminitd.swift`), and patch #8 (the `ManagedProcess.start` event-loop offload in `vminitd/`). Grep
|
||||||
for `[Nucleic vendored patch]` to find every site. Patch #9 (per-exec cgroups) is design-only so
|
for `[Nucleic vendored patch]` to find every site. Patch #9 (per-exec cgroups) is design-only so
|
||||||
far — see its entry. After re-applying any `vminitd/` patch, re-run `.github/workflows/vminit-image.yml`
|
far — see its entry. After re-applying any `vminitd/` patch, rebuild + publish the custom init image
|
||||||
to rebuild + publish the custom init image, and bump `ContainerEngine.vminitReference`.
|
with `make vminit-image` + `make vminit-image-push`, and bump `ContainerEngine.vminitReference`.
|
||||||
5. Update the commit hash above and in the root `Package.swift` comment.
|
5. Update the commit hash above and in the root `Package.swift` comment.
|
||||||
6. `swift build` and run the balloon tests.
|
6. `swift build` and run the balloon tests.
|
||||||
|
|||||||
Reference in New Issue
Block a user