Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .github/workflows/ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ jobs:
toolchain: ${{ env.RUST_STABLE }}
- uses: Swatinem/rust-cache@v2
- name: build(Arm64/hvp)
run: cargo build --no-default-features --features hvp --verbose
run: cargo build --verbose

fmt:
name: Fmt
Expand Down Expand Up @@ -113,7 +113,7 @@ jobs:
override: true
- uses: Swatinem/rust-cache@v2
- name: clippy
run: cargo clippy --all-targets --no-default-features --features hvp
run: cargo clippy --all-targets

udeps-x86_64_kvm:
name: Udeps(x86_64/Kvm)
Expand Down Expand Up @@ -164,7 +164,7 @@ jobs:
with:
tool: cargo-udeps
- name: udeps
run: cargo udeps --all-targets --no-default-features --features hvp
run: cargo udeps --all-targets

test:
name: Test
Expand Down
1 change: 0 additions & 1 deletion Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 0 additions & 5 deletions crates/vm-cli/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,3 @@ vm-bootloader.workspace = true
vm-core.workspace = true
vm-device.workspace = true
vm-vmm.workspace = true

[features]
default = ["kvm"]
kvm = ["vm-core/kvm", "vm-vmm/kvm"]
hvp = ["vm-core/hvp", "vm-vmm/hvp"]
4 changes: 2 additions & 2 deletions crates/vm-cli/src/main.rs
Original file line number Diff line number Diff line change
Expand Up @@ -19,10 +19,10 @@ mod term;

fn build_hypervisor() -> anyhow::Result<Box<dyn Hypervisor>> {
cfg_select! {
all(target_arch = "aarch64", feature = "hvp") => {
target_os = "macos" => {
Ok(Box::new(vm_core::virtualization::hvp::AppleHypervisor))
}
feature = "kvm" => {
target_os = "linux" => {
Ok(Box::new(vm_core::virtualization::kvm::KvmHypervisor::new()?))
}
Comment on lines +22 to 27

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '\n== Files ==\n'
git ls-files crates/vm-cli/src/main.rs crates/vm-core/Cargo.toml crates/vm-core/src/virtualization.rs crates/vm-core/src/virtualization/* 2>/dev/null || true

printf '\n== main.rs outline ==\n'
ast-grep outline crates/vm-cli/src/main.rs --view expanded || true

printf '\n== Cargo.toml outline ==\n'
ast-grep outline crates/vm-core/Cargo.toml --view expanded || true

printf '\n== Search for AppleHypervisor and target_arch gates ==\n'
rg -n 'AppleHypervisor|target_arch|aarch64|x86_64-apple-darwin|target_os = "macos"|cfg_select!' crates/vm-core crates/vm-cli -S

Repository: junyu0312/rust-vm

Length of output: 50374


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '\n== main.rs around the relevant lines ==\n'
sed -n '1,120p' crates/vm-cli/src/main.rs

printf '\n== vm-core Cargo.toml around dependency/configuration lines ==\n'
sed -n '1,220p' crates/vm-core/Cargo.toml

printf '\n== virtualization.rs relevant slice ==\n'
sed -n '1,240p' crates/vm-core/src/virtualization.rs

Repository: junyu0312/rust-vm

Length of output: 3356


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '\n== Determine whether AppleHypervisor is gated by arch in code or docs ==\n'
rg -n 'AppleHypervisor|Hypervisor.framework|aarch64|arm64|Intel Macs|x86_64' -S .

Repository: junyu0312/rust-vm

Length of output: 50374


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Narrow, read-only inspection for the exact branches and cfgs.
printf '\n== crates/vm-cli/src/main.rs ==\n'
nl -ba crates/vm-cli/src/main.rs | sed -n '1,120p'

printf '\n== crates/vm-core/Cargo.toml ==\n'
nl -ba crates/vm-core/Cargo.toml | sed -n '1,220p'

printf '\n== crates/vm-core/src/virtualization.rs ==\n'
nl -ba crates/vm-core/src/virtualization.rs | sed -n '1,260p'

Repository: junyu0312/rust-vm

Length of output: 228


🌐 Web query:

Hypervisor.framework Intel Macs supported Apple Silicon only macOS Hypervisor.framework availability

💡 Result:

The Hypervisor.framework is available and supported on both Intel-based Macs and Apple Silicon Macs [1][2][3]. It is not restricted to Apple Silicon [1][3]. On Intel-based Mac computers, the framework requires a processor that supports the Intel VT-x feature set, including Extended Page Tables (EPT) and Unrestricted Mode [1][4][5]. These requirements generally align with Intel processors from the Westmere generation (released in 2010) or newer [4][6]. Developers can verify if a specific Intel-based Mac supports the framework by checking if the command sysctl kern.hv_support returns 1 [4][5][7]. On Apple Silicon Macs, the Hypervisor.framework is fully supported to build virtualization solutions [8][9]. Furthermore, starting with macOS 15.0, Apple added support for nested virtualization on Apple Silicon through the framework, enabling a hypervisor to run inside another virtual machine [10]. For high-level tasks, Apple also provides the Virtualization.framework, which is available on both Intel and Apple Silicon architectures and provides a higher-level API for running virtual machines [3].

Citations:


🏁 Script executed:

#!/bin/bash
set -euo pipefail

sed -n '1,220p' crates/vm-core/src/virtualization/hvp.rs
printf '\n==\n'
sed -n '1,220p' crates/vm-core/src/virtualization/hvp/vm.rs
printf '\n==\n'
sed -n '1,260p' crates/vm-core/src/virtualization/hvp/vcpu.rs

Repository: junyu0312/rust-vm

Length of output: 16904


Gate the macOS hypervisor path on target_arch = "aarch64". AppleHypervisor pulls in crate::arch::aarch64::*, so x86_64-apple-darwin will hit this branch and fail to compile.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@crates/vm-cli/src/main.rs` around lines 22 - 27, The macOS branch in the
hypervisor selection logic needs to be limited to Apple Silicon builds because
`AppleHypervisor` depends on `crate::arch::aarch64::*` and will not compile on
x86_64 macOS. Update the platform gating in the `select_hypervisor` path so the
`vm_core::virtualization::hvp::AppleHypervisor` arm only matches when both
`target_os = "macos"` and `target_arch = "aarch64"` are true, and ensure the
other hypervisor arms remain unchanged.

_ => panic!(),
Expand Down
16 changes: 7 additions & 9 deletions crates/vm-core/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -5,13 +5,9 @@ edition = "2024"

[dependencies]
acpi_tables = { workspace = true }
applevisor = { workspace = true, optional = true }
applevisor-sys = { workspace = true, optional = true }
async-trait = { workspace = true }
bitflags = { workspace = true }
gdbstub_arch = { workspace = true }
kvm-bindings = { workspace = true, optional = true }
kvm-ioctls = { workspace = true, optional = true }
serde = { workspace = true }
serde_json = { workspace = true }
static_assertions = { workspace = true }
Expand All @@ -25,16 +21,18 @@ vm-utils = { workspace = true }
[target.'cfg(target_arch = "aarch64")'.dependencies]
anyhow = { workspace = true }
futures = { workspace = true }
vm-aarch64 = { workspace = true }
strum = { workspace = true, optional = true }
strum_macros = { workspace = true }
vm-aarch64 = { workspace = true }

[target.'cfg(target_arch = "x86_64")'.dependencies]
vm-firmware = { workspace = true }

[target.'cfg(target_os = "linux")'.dependencies]
kvm-bindings = { workspace = true }
kvm-ioctls = { workspace = true }
vmm-sys-util = { workspace = true }

[features]
kvm = ["kvm-bindings", "kvm-ioctls"]
hvp = ["applevisor", "applevisor-sys", "strum"]
[target.'cfg(target_os = "macos")'.dependencies]
applevisor = { workspace = true }
applevisor-sys = { workspace = true }
strum = { workspace = true }
Comment on lines 24 to +38

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '== Cargo.toml ==\n'
sed -n '1,220p' crates/vm-core/Cargo.toml

printf '\n== virtualization.rs outline ==\n'
ast-grep outline crates/vm-core/src/virtualization.rs --view expanded || true

printf '\n== main.rs outline ==\n'
ast-grep outline crates/vm-cli/src/main.rs --view expanded || true

printf '\n== Search for applevisor / hvp / aarch64 gates ==\n'
rg -n --hidden --glob '!target' --glob '!**/node_modules/**' \
  'applevisor|applevisor-sys|hv_vm_config_set_el2_enabled|target_arch\s*=\s*"aarch64"|cfg_select!|feature\s*=\s*"hvp"|hvp' \
  crates/vm-core crates/vm-cli

Repository: junyu0312/rust-vm

Length of output: 14450


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '== crates/vm-core/src/virtualization.rs (relevant slice) ==\n'
sed -n '1,260p' crates/vm-core/src/virtualization.rs

printf '\n== crates/vm-core/src/virtualization/hvp.rs (relevant slice) ==\n'
sed -n '1,260p' crates/vm-core/src/virtualization/hvp.rs

printf '\n== crates/vm-cli/src/main.rs (relevant slice) ==\n'
sed -n '1,260p' crates/vm-cli/src/main.rs

Repository: junyu0312/rust-vm

Length of output: 3528


🌐 Web query:

applevisor crate supported architectures macOS x86_64 aarch64 Hypervisor.framework

💡 Result:

The applevisor Rust crate provides safe bindings specifically for the Apple Silicon (aarch64) Hypervisor.framework [1][2]. According to its documentation and metadata, the crate is designed for and explicitly focuses on support for aarch64 (Apple Silicon) architectures [1][2]. It does not support x86_64 architectures because it acts as a wrapper for the Apple Silicon-specific Hypervisor.framework APIs [1][3]. Key points regarding its architecture support: - Primary Architecture: aarch64 (Apple Silicon) [1][2]. - Platform Limitation: The crate is intended for macOS on Apple Silicon [1][2]. - API Focus: It provides bindings to the Hypervisor.framework as it exists on Apple Silicon [1][3]. Consequently, it is incompatible with x86_64 macOS environments [1][2]. Developers using this crate must ensure their project is targeting the appropriate Apple Silicon hardware and that their binary has been granted the necessary com.apple.security.hypervisor entitlement to interact with the framework [3].

Citations:


Gate the macOS virtualization deps by target_arch = "aarch64". applevisor/applevisor-sys are Apple Silicon-only, but hvp is still compiled for every macOS target, so x86_64-apple-darwin will pull in the ARM-only path and fail the build. strum can move with the same gate since it’s only used there.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@crates/vm-core/Cargo.toml` around lines 24 - 38, The macOS virtualization
dependencies are currently enabled for every macOS build, which pulls in Apple
Silicon-only crates on x86_64. Update the dependency gate in Cargo.toml so the
applevisor, applevisor-sys, and strum entries are only included when both
target_os is macos and target_arch is aarch64, and keep the existing
vm-core/vm-aarch64 related paths aligned with that architecture-specific gating.

4 changes: 2 additions & 2 deletions crates/vm-core/src/virtualization.rs
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
#[cfg(feature = "hvp")]
#[cfg(target_os = "macos")]
pub mod hvp;

#[cfg(feature = "kvm")]
#[cfg(target_os = "linux")]
pub mod kvm;

pub mod hypervisor;
Expand Down
2 changes: 1 addition & 1 deletion crates/vm-core/src/virtualization/hypervisor/error.rs
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ pub enum HypervisorError {
#[error("Failed to create vm: {0}")]
CreateVm(String),

#[cfg(feature = "kvm")]
#[cfg(target_os = "linux")]
#[error("Kvm error: {0}")]
Kvm(#[from] kvm_ioctls::Error),
}
4 changes: 2 additions & 2 deletions crates/vm-core/src/virtualization/vcpu/error.rs
Original file line number Diff line number Diff line change
Expand Up @@ -10,11 +10,11 @@ pub enum VcpuError {
#[error("Vcpu command channel disconnected")]
VcpuCommandDisconnected,

#[cfg(feature = "hvp")]
#[cfg(target_os = "macos")]
#[error("{0}")]
ApplevisorError(#[from] applevisor::error::HypervisorError),

#[cfg(feature = "kvm")]
#[cfg(target_os = "linux")]
#[error("{0}")]
KvmError(#[from] kvm_ioctls::Error),

Expand Down
4 changes: 2 additions & 2 deletions crates/vm-core/src/virtualization/vm/error.rs
Original file line number Diff line number Diff line change
Expand Up @@ -24,11 +24,11 @@ pub enum VmError {
#[error("Failed to create memory region")]
MemoryRegionOverlap,

#[cfg(feature = "hvp")]
#[cfg(target_os = "macos")]
#[error("Applevisor error: {0}")]
ApplevisorError(#[from] applevisor::error::HypervisorError),

#[cfg(feature = "kvm")]
#[cfg(target_os = "linux")]
#[error("Kvm error: {0}")]
Kvm(#[from] kvm_ioctls::Error),

Expand Down
7 changes: 0 additions & 7 deletions crates/vm-vmm/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -29,12 +29,5 @@ vm-utils = { workspace = true }
vm-virtio = { workspace = true }
winnow = { workspace = true }

[target.'cfg(target_arch = "aarch64")'.dependencies]
strum = { workspace = true, optional = true }

[target.'cfg(target_os = "linux")'.dependencies]
vm-vfio = { workspace = true }

[features]
kvm = []
hvp = ["strum"]
2 changes: 1 addition & 1 deletion scripts/run_hvp.sh
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ set -x

rm -f /tmp/vm.sock

cargo build --release --no-default-features --features hvp
cargo build --release
codesign --force --sign - \
--entitlements entitlements.plist \
target/release/vm-cli
Expand Down
Loading