Skip to content

lanzaboote-{tool,uefi-stub}: init at 1.2.0 - #496059

Open
ThinkChaos wants to merge 4 commits into
NixOS:masterfrom
ThinkChaos:lanzaboote-1.0.0
Open

ThinkChaos wants to merge 4 commits into
NixOS:masterfrom
ThinkChaos:lanzaboote-1.0.0

Conversation

@ThinkChaos

Copy link
Copy Markdown
Contributor

Now that we have UEFI platform support via #477645, we can build the Lanzaboote CLI (previously packaged and removed) and UEFI stub (PR'ed but never merged).
I've only included x86_64 support because that's what I've built and tested.

I also applied the changes proposed by #368246

Since these were packaged/proposed, pinging previous maintainers: @blitz @nikstur @RaitoBezarius.
Let me know if you'd like to be added as maintainers.

Supersedes: #353052 (@baloo).

Thank you to everyone who has worked on this before me. I definitely couldn't have gotten UEFI to build without all your work!

Things done

  • Built on platform:
    • x86_64-linux
    • aarch64-linux
    • x86_64-darwin
    • aarch64-darwin
  • Tested, as applicable:
  • Ran nixpkgs-review on this PR. See nixpkgs-review usage.
  • Tested basic functionality of all binary files, usually in ./result/bin/.
  • Nixpkgs Release Notes
    • Package update: when the change is major or breaking.
  • NixOS Release Notes
    • Module addition: when adding a new NixOS module.
    • Module update: when the change is significant.
  • Fits CONTRIBUTING.md, pkgs/README.md, maintainers/README.md and other READMEs.

@RaitoBezarius

Copy link
Copy Markdown
Member

Thanks for the PR, can you add me as a maintainer as well? Thanks.

Comment thread lib/systems/examples.nix
@RaitoBezarius

Copy link
Copy Markdown
Member

Note (this is not a proper review tool so I cannot do the review where it should be): there's a typo in a commit message where lanzaboot-uefi-stub: ... is written, it should be lanzabooteE-uefi-stub: ....

@RaitoBezarius

Copy link
Copy Markdown
Member

During compilation, this is full of warnings like this:

warning: compiler_builtins@0.1.160: Warning: supplying the --target x86_64-unknown-windows-gnu != x86_64-uefi argument to a nix-wrapped compiler may not work correctly - cc-wrapper is currently not designed with multi-target compilers in mind. You may want to use an un-wrapped compiler instead.

Why are they safe to ignore?

@nixpkgs-ci
nixpkgs-ci Bot requested review from Mic92, alyssais, winterqt and zowoq March 4, 2026 02:54
@nixpkgs-ci nixpkgs-ci Bot added 8.has: package (new) This PR adds a new package 10.rebuild-linux: 1-10 This PR causes between 1 and 10 packages to rebuild on Linux. 10.rebuild-darwin: 0 This PR does not cause any packages to rebuild on Darwin. 10.rebuild-linux: 1 This PR causes 1 package to rebuild on Linux. 6.topic: rust General-purpose programming language emphasizing performance, type safety, and concurrency. 8.has: maintainer-list (update) This PR changes `maintainers/maintainer-list.nix` labels Mar 4, 2026
@ThinkChaos

ThinkChaos commented Mar 4, 2026 •

Copy link
Copy Markdown
Contributor Author

During compilation, this is full of warnings like this:

For which derivation do you see those?
For both packages I get clean cargo logs.

Edit: found it /nix/store/3d9y36sfj45mqw3hnd7smqmrdi37lr64-x86_64-unknown-uefi-rustc-1.93.0.drv

@ThinkChaos

ThinkChaos commented Mar 4, 2026 •

Copy link
Copy Markdown
Contributor Author

Why are they safe to ignore?

This is more of an educated guess at this point, but I believe --target x86_64-unknown-windows-gnu is what rustc uses internally to cross compile its compiler builtins when building a UEFI compiler, so it's expected to see it there.
I'll have to dig into it more to be sure, but this issue seems to confirm it: rust-lang/rust#118184

I believe this is where we tell rustc to use the wrapped compiler:

"${setTarget}.cc=${ccForTarget}"

We could potentially change that to the unwrapped version, or conditionally silence the warning via NIX_CC_WRAPPER_SUPPRESS_TARGET_WARNING=1, but I definitely don't understand all the repercussions that would have.

@azahi

azahi commented Mar 5, 2026

Copy link
Copy Markdown
Member

Any plans to add a NixOS module for this? #263713?

@ThinkChaos

ThinkChaos commented Mar 6, 2026 •

Copy link
Copy Markdown
Contributor Author

Any plans to add a NixOS module for this? #263713?

What annoyed me enough to work on this was having crane & rust-overlay in my system closure.
So I don't personally care that much about porting the module over.

@Mic92

Mic92 commented Mar 12, 2026

Copy link
Copy Markdown
Member

Any plans to add a NixOS module for this? #263713?

What annoyed me enough to work on this was having crane & rust-overlay in my system closure. So I don't personally care that much about porting the module over.

In any case having the package would is the harder part the module can be also ported by someone else.

@nixpkgs-ci nixpkgs-ci Bot added the 2.status: merge conflict This PR has merge conflicts with the target branch label May 28, 2026
@nixpkgs-ci nixpkgs-ci Bot added the 2.status: stale https://github.com/NixOS/nixpkgs/blob/master/.github/STALE-BOT.md label Sep 8, 2026

@nixpkgs-ci nixpkgs-ci Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for contributing to the documentation

Make sure you follow the documentation style guide, most notably:

  • Show, don't tell: lead with a minimal working example; explanation follows the code.
  • No meta-commentary: don't write "This section explains how to…", just do it.
  • Imperative mood and active voice: "Run the command", not "The user should run the following command".
  • Present tense: "This creates a folder", not "This will create a folder".
  • Be confident: no hedging with "should", "might", "typically", "usually".
  • Cut filler words: "simply", "just", "easily", "basically"; "to", not "in order to".

For larger changes, like adding or removing whole sections, ask the NixOS documentation team for a review.

@nixpkgs-ci nixpkgs-ci Bot removed 2.status: merge conflict This PR has merge conflicts with the target branch 2.status: stale https://github.com/NixOS/nixpkgs/blob/master/.github/STALE-BOT.md labels Oct 9, 2026
@nixpkgs-ci
nixpkgs-ci Bot requested a review from a team October 9, 2026 16:17
@nixpkgs-ci nixpkgs-ci Bot removed the 10.rebuild-darwin: 0 This PR does not cause any packages to rebuild on Darwin. label Oct 9, 2026
@nixpkgs-ci nixpkgs-ci Bot added 10.rebuild-darwin: 1-10 This PR causes between 1 and 10 packages to rebuild on Darwin. 10.rebuild-darwin: 1 This PR causes 1 package to rebuild on Darwin. 8.has: documentation This PR adds or changes documentation and removed 10.rebuild-linux: 1 This PR causes 1 package to rebuild on Linux. labels Oct 9, 2026
@ThinkChaos ThinkChaos changed the title lanzaboote-{tool,uefi-stub}: init at 1.0.0 lanzaboote-{tool,uefi-stub}: init at 1.2.0 Oct 9, 2026
@ThinkChaos

ThinkChaos commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor Author

I updated the packages to 1.2.0, the latest release ATM.

And after bouncing off it a bunch of times, figured out the only, AFAIK, blocker:

During compilation, this is full of warnings like this:

warning: compiler_builtins@0.1.160: Warning: supplying the --target x86_64-unknown-windows-gnu != x86_64-uefi argument to a nix-wrapped compiler may not work correctly - cc-wrapper is currently not designed with multi-target compilers in mind. You may want to use an un-wrapped compiler instead.

Why are they safe to ignore?

Rust UEFI target predates LLVM's so cc-rs has a workaround that rewrites x86_64-unknown-uefi to x86_64-unknown-windows-gnu when calling clang.
See rust-lang/cc-rs#623 and rust-lang/cc-rs#1264

There's a PR open to fix it in cc-rs but it has been pending for a while: rust-lang/rust#132570
I added a workaround in pkgs/development/compilers/rust/rustc.nix

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

6.topic: rust General-purpose programming language emphasizing performance, type safety, and concurrency. 8.has: documentation This PR adds or changes documentation 8.has: maintainer-list (update) This PR changes `maintainers/maintainer-list.nix` 8.has: package (new) This PR adds a new package 10.rebuild-darwin: 1-10 This PR causes between 1 and 10 packages to rebuild on Darwin. 10.rebuild-darwin: 1 This PR causes 1 package to rebuild on Darwin. 10.rebuild-linux: 1-10 This PR causes between 1 and 10 packages to rebuild on Linux.

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

4 participants