From 65e07dda32be68b2b24cf8f22dca6e9cbeed548c Mon Sep 17 00:00:00 2001 From: Ben Hillis Date: Fri, 14 Aug 2026 20:11:39 +0000 Subject: [PATCH 1/2] openvmm: add new package OpenVMM is a modular, cross-platform virtual machine monitor written in Rust. This package ships the OpenVMM host binary, which runs virtual machines on Linux via KVM or the Microsoft Hypervisor. Source0 is the archive GitHub generates for the openvmm-v tag. Upstream publishes a single release asset, openvmm--vendor.tar.gz, containing the vendored crate sources and the cargo_config source replacement written by cargo vendor, so the package builds offline. The package requires rust >= 1.95, which Azure Linux 3.0 does not ship yet, so it does not build until the distribution toolchain advances. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md | 2 +- LICENSES-AND-NOTICES/SPECS/data/licenses.json | 1 + SPECS/openvmm/openvmm.signatures.json | 6 ++ SPECS/openvmm/openvmm.spec | 75 +++++++++++++++++++ cgmanifest.json | 10 +++ 5 files changed, 93 insertions(+), 1 deletion(-) create mode 100644 SPECS/openvmm/openvmm.signatures.json create mode 100644 SPECS/openvmm/openvmm.spec diff --git a/LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md b/LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md index 00165b945c9..e1e6037ec0b 100644 --- a/LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md +++ b/LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md @@ -9,7 +9,7 @@ The Azure Linux SPEC files originated from a variety of sources with varying lic | Fedora (Copyright Remi Collet) | [CC-BY-SA 4.0](https://creativecommons.org/licenses/by-sa/4.0/legalcode) | libmemcached-awesome
librabbitmq | | Fedora (ISC) | [ISC License](https://github.com/sarugaku/resolvelib/blob/main/LICENSE) | python-requests-gssapi
python-resolvelib | | Magnus Edenhill Open Source | [Magnus Edenhill Open Source BSD License](https://github.com/jemalloc/jemalloc/blob/dev/COPYING) | librdkafka | -| Microsoft | [Microsoft MIT License](/LICENSES-AND-NOTICES/LICENSE.md) | application-gateway-kubernetes-ingress
asc
azcopy
azl-otel-collector
azure-iot-sdk-c
azure-nvme-utils
azure-storage-cpp
azurelinux-image-tools
azurelinux-release
azurelinux-repos
azurelinux-rpm-macros
azurelinux-sysinfo
bazel
bmon
bpftrace
ccache
cert-manager
cf-cli
check-restart
clamav
cloud-hypervisor
cloud-provider-kubevirt
cmake-fedora
containerd2
coredns
dasel
dcos-cli
debugedit
dejavu-fonts
distroless-packages
docker-buildx
docker-cli
docker-compose
doxygen
dtc
edk2-hvloader-signed
elixir
espeak-ng
espeakup
flannel
fluent-bit
freefont
gflags
gh
go-md2man
grpc
grub2-efi-binary-signed
GSL
gtk-update-icon-cache
intel-pf-bb-config
ivykis
jsonbuilder
jx
kata-containers-cc
kata-packages-uvm
keda
keras
kernel-64k-signed
kernel-hwe-signed
kernel-mshv-signed
kernel-signed
kernel-uki
kernel-uki-signed
kpatch
kube-vip-cloud-provider
kubernetes
libacvp
libconfini
libconfuse
libgdiplus
libimobiledevice-glue
libmaxminddb
libmetalink
libsafec
libuv
libxml++
lld
lsb-release
ltp
lttng-consume
mm-common
moby-containerd-cc
moby-engine
msgpack
ncompress
networkd-dispatcher
nlohmann-json
nmap
ntopng
opentelemetry-cpp
packer
pcaudiolib
pcre2
perl-Test-Warnings
perl-Text-Template
pigz
prebuilt-ca-certificates
prebuilt-ca-certificates-base
prometheus-adapter
python-cachetools
python-cherrypy
python-cstruct
python-execnet
python-google-pasta
python-libclang
python-libevdev
python-logutils
python-ml-dtypes
python-namex
python-nocasedict
python-omegaconf
python-opt-einsum
python-optree
python-pecan
python-pip
python-pyrpm
python-remoto
python-repoze-lru
python-routes
python-rsa
python-setuptools
python-sphinxcontrib-websupport
python-tensorboard
python-tensorboard-plugin-wit
python-yamlloader
R
rabbitmq-server
rocksdb
rubygem-addressable
rubygem-asciidoctor
rubygem-bindata
rubygem-concurrent-ruby
rubygem-connection_pool
rubygem-cool.io
rubygem-deep_merge
rubygem-digest-crc
rubygem-elastic-transport
rubygem-elasticsearch
rubygem-elasticsearch-api
rubygem-eventmachine
rubygem-excon
rubygem-faraday
rubygem-faraday-em_http
rubygem-faraday-em_synchrony
rubygem-faraday-excon
rubygem-faraday-httpclient
rubygem-faraday-multipart
rubygem-faraday-net_http
rubygem-faraday-net_http_persistent
rubygem-faraday-rack
rubygem-faraday-retry
rubygem-ffi
rubygem-fiber-local
rubygem-hirb
rubygem-hocon
rubygem-hoe
rubygem-http_parser
rubygem-httpclient
rubygem-io-event
rubygem-jmespath
rubygem-ltsv
rubygem-mini_portile2
rubygem-minitest
rubygem-mocha
rubygem-msgpack
rubygem-multi_json
rubygem-multipart-post
rubygem-net-http-persistent
rubygem-nio4r
rubygem-nokogiri
rubygem-oj
rubygem-parallel
rubygem-power_assert
rubygem-prometheus-client
rubygem-protocol-hpack
rubygem-protocol-http
rubygem-protocol-http1
rubygem-protocol-http2
rubygem-public_suffix
rubygem-puppet-resource_api
rubygem-rdiscount
rubygem-rdkafka
rubygem-rexml
rubygem-ruby-kafka
rubygem-ruby-progressbar
rubygem-rubyzip
rubygem-semantic_puppet
rubygem-serverengine
rubygem-sigdump
rubygem-strptime
rubygem-systemd-journal
rubygem-test-unit
rubygem-thor
rubygem-timers
rubygem-tzinfo
rubygem-tzinfo-data
rubygem-webhdfs
rubygem-webrick
rubygem-yajl-ruby
rubygem-zip-zip
runc
sdbus-cpp
sgx-backwards-compatibility
shim
skopeo
span-lite
sriov-network-device-plugin
SymCrypt
SymCrypt-OpenSSL
systemd-boot-signed
tardev-snapshotter
tensorflow
tinyxml2
toml11
tracelogging
trident
umoci
usrsctp
vala
valkey
vnstat
walinuxagent-acl-config
zstd | +| Microsoft | [Microsoft MIT License](/LICENSES-AND-NOTICES/LICENSE.md) | application-gateway-kubernetes-ingress
asc
azcopy
azl-otel-collector
azure-iot-sdk-c
azure-nvme-utils
azure-storage-cpp
azurelinux-image-tools
azurelinux-release
azurelinux-repos
azurelinux-rpm-macros
azurelinux-sysinfo
bazel
bmon
bpftrace
ccache
cert-manager
cf-cli
check-restart
clamav
cloud-hypervisor
cloud-provider-kubevirt
cmake-fedora
containerd2
coredns
dasel
dcos-cli
debugedit
dejavu-fonts
distroless-packages
docker-buildx
docker-cli
docker-compose
doxygen
dtc
edk2-hvloader-signed
elixir
espeak-ng
espeakup
flannel
fluent-bit
freefont
gflags
gh
go-md2man
grpc
grub2-efi-binary-signed
GSL
gtk-update-icon-cache
intel-pf-bb-config
ivykis
jsonbuilder
jx
kata-containers-cc
kata-packages-uvm
keda
keras
kernel-64k-signed
kernel-hwe-signed
kernel-mshv-signed
kernel-signed
kernel-uki
kernel-uki-signed
kpatch
kube-vip-cloud-provider
kubernetes
libacvp
libconfini
libconfuse
libgdiplus
libimobiledevice-glue
libmaxminddb
libmetalink
libsafec
libuv
libxml++
lld
lsb-release
ltp
lttng-consume
mm-common
moby-containerd-cc
moby-engine
msgpack
ncompress
networkd-dispatcher
nlohmann-json
nmap
ntopng
opentelemetry-cpp
openvmm
packer
pcaudiolib
pcre2
perl-Test-Warnings
perl-Text-Template
pigz
prebuilt-ca-certificates
prebuilt-ca-certificates-base
prometheus-adapter
python-cachetools
python-cherrypy
python-cstruct
python-execnet
python-google-pasta
python-libclang
python-libevdev
python-logutils
python-ml-dtypes
python-namex
python-nocasedict
python-omegaconf
python-opt-einsum
python-optree
python-pecan
python-pip
python-pyrpm
python-remoto
python-repoze-lru
python-routes
python-rsa
python-setuptools
python-sphinxcontrib-websupport
python-tensorboard
python-tensorboard-plugin-wit
python-yamlloader
R
rabbitmq-server
rocksdb
rubygem-addressable
rubygem-asciidoctor
rubygem-bindata
rubygem-concurrent-ruby
rubygem-connection_pool
rubygem-cool.io
rubygem-deep_merge
rubygem-digest-crc
rubygem-elastic-transport
rubygem-elasticsearch
rubygem-elasticsearch-api
rubygem-eventmachine
rubygem-excon
rubygem-faraday
rubygem-faraday-em_http
rubygem-faraday-em_synchrony
rubygem-faraday-excon
rubygem-faraday-httpclient
rubygem-faraday-multipart
rubygem-faraday-net_http
rubygem-faraday-net_http_persistent
rubygem-faraday-rack
rubygem-faraday-retry
rubygem-ffi
rubygem-fiber-local
rubygem-hirb
rubygem-hocon
rubygem-hoe
rubygem-http_parser
rubygem-httpclient
rubygem-io-event
rubygem-jmespath
rubygem-ltsv
rubygem-mini_portile2
rubygem-minitest
rubygem-mocha
rubygem-msgpack
rubygem-multi_json
rubygem-multipart-post
rubygem-net-http-persistent
rubygem-nio4r
rubygem-nokogiri
rubygem-oj
rubygem-parallel
rubygem-power_assert
rubygem-prometheus-client
rubygem-protocol-hpack
rubygem-protocol-http
rubygem-protocol-http1
rubygem-protocol-http2
rubygem-public_suffix
rubygem-puppet-resource_api
rubygem-rdiscount
rubygem-rdkafka
rubygem-rexml
rubygem-ruby-kafka
rubygem-ruby-progressbar
rubygem-rubyzip
rubygem-semantic_puppet
rubygem-serverengine
rubygem-sigdump
rubygem-strptime
rubygem-systemd-journal
rubygem-test-unit
rubygem-thor
rubygem-timers
rubygem-tzinfo
rubygem-tzinfo-data
rubygem-webhdfs
rubygem-webrick
rubygem-yajl-ruby
rubygem-zip-zip
runc
sdbus-cpp
sgx-backwards-compatibility
shim
skopeo
span-lite
sriov-network-device-plugin
SymCrypt
SymCrypt-OpenSSL
systemd-boot-signed
tardev-snapshotter
tensorflow
tinyxml2
toml11
tracelogging
trident
umoci
usrsctp
vala
valkey
vnstat
walinuxagent-acl-config
zstd | | Netplan source | [GPLv3](https://github.com/canonical/netplan/blob/main/COPYING) | netplan | | Numad source | [LGPLv2 License](https://www.gnu.org/licenses/old-licenses/lgpl-2.1.txt) | numad | | NVIDIA | [ASL 2.0 License and spec specific licenses](http://www.apache.org/licenses/LICENSE-2.0) | ibarr
ibdump
ibsim
iser
iser-hwe
iser-hwe-signed
iser-signed
isert
isert-hwe
isert-hwe-signed
isert-signed
libnvidia-container
libvma
mft_kernel
mft_kernel-hwe
mft_kernel-hwe-signed
mft_kernel-signed
mlnx-ethtool
mlnx-iproute2
mlnx-nfsrdma
mlnx-nfsrdma-hwe
mlnx-nfsrdma-hwe-signed
mlnx-nfsrdma-signed
mlnx-ofa_kernel
mlnx-ofa_kernel-hwe
mlnx-ofa_kernel-hwe-modules-signed
mlnx-ofa_kernel-modules-signed
mlnx-tools
mlx-bootctl
mlx-steering-dump
multiperf
nvidia-container-toolkit
ofed-docs
ofed-scripts
perftest
rshim
sockperf
srp
srp-hwe
srp-hwe-signed
srp-signed
xpmem
xpmem-hwe
xpmem-hwe-modules-signed
xpmem-modules-signed | diff --git a/LICENSES-AND-NOTICES/SPECS/data/licenses.json b/LICENSES-AND-NOTICES/SPECS/data/licenses.json index 4e89ffd5cd9..e38a00876c8 100644 --- a/LICENSES-AND-NOTICES/SPECS/data/licenses.json +++ b/LICENSES-AND-NOTICES/SPECS/data/licenses.json @@ -2345,6 +2345,7 @@ "nmap", "ntopng", "opentelemetry-cpp", + "openvmm", "packer", "pcaudiolib", "pcre2", diff --git a/SPECS/openvmm/openvmm.signatures.json b/SPECS/openvmm/openvmm.signatures.json new file mode 100644 index 00000000000..63cb8f32f6e --- /dev/null +++ b/SPECS/openvmm/openvmm.signatures.json @@ -0,0 +1,6 @@ +{ + "Signatures": { + "openvmm-0.1.0-vendor.tar.gz": "d21252583e230fff402945332afe4ffa6ee2bd4a96e6ef446a29fe5f93d25fb2", + "openvmm-0.1.0.tar.gz": "ad476f399c3c02309239638614107174166b75f85cc6cdd11122d418cd6caef5" + } +} diff --git a/SPECS/openvmm/openvmm.spec b/SPECS/openvmm/openvmm.spec new file mode 100644 index 00000000000..f9a2b46d6ce --- /dev/null +++ b/SPECS/openvmm/openvmm.spec @@ -0,0 +1,75 @@ +Vendor: Microsoft Corporation +Distribution: Azure Linux +Name: openvmm +Version: 0.1.0 +Release: 1%{?dist} +Summary: Modular, cross-platform virtual machine monitor +Group: Applications/System +License: MIT +URL: https://github.com/microsoft/openvmm +# Upstream tags releases as "openvmm-v". The generated archive unpacks +# into "openvmm-openvmm-v". +Source0: https://github.com/microsoft/openvmm/archive/refs/tags/openvmm-v%{version}.tar.gz#/%{name}-%{version}.tar.gz +# Note: the %%{name}-%%{version}-vendor.tar.gz file is published by upstream and +# contains the vendored sources in vendor/ plus the source replacement config +# 'cargo_config' written by cargo vendor. +Source1: https://github.com/microsoft/openvmm/releases/download/openvmm-v%{version}/%{name}-%{version}-vendor.tar.gz + +# Upstream validates the distribution build for x86_64 only. +ExclusiveArch: x86_64 + +# Cargo enforces the workspace's rust-version. +BuildRequires: rust >= 1.95.0 +BuildRequires: cargo >= 1.95.0 +BuildRequires: binutils +BuildRequires: gcc +BuildRequires: glibc-devel +BuildRequires: kernel-headers +BuildRequires: openssl-devel +BuildRequires: pkgconf-pkg-config +BuildRequires: protobuf +# protoc resolves the well-known .proto imports from /usr/include. +BuildRequires: protobuf-devel + +%description +OpenVMM is a modular, cross-platform, general-purpose virtual machine monitor +written in Rust. This package provides the OpenVMM host binary, which runs +virtual machines on Linux via KVM or Microsoft Hypervisor. + +%global rust_target x86_64-unknown-linux-gnu + +# The release profile does not emit debug info. +%global debug_package %{nil} + +%prep +%autosetup -n %{name}-openvmm-v%{version} -N +tar -xf %{SOURCE1} +%autopatch -p1 +# Append the source replacement, keeping the rustflags upstream ships. +printf '\n' >> .cargo/config.toml +cat cargo_config >> .cargo/config.toml + +%build +# Override the PROTOC path set for repository development builds. +export PROTOC="$(command -v protoc)" +# Link against the distribution OpenSSL. +export OPENSSL_NO_VENDOR=1 + +cargo build --release --locked --offline -p openvmm --target %{rust_target} + +%install +install -D -p -m 0755 target/%{rust_target}/release/openvmm %{buildroot}%{_bindir}/openvmm + +%check +# The upstream test suite expects virtualization unavailable to the build. +./target/%{rust_target}/release/openvmm --version + +%files +%license LICENSE +%doc README.md +%{_bindir}/openvmm + +%changelog +* Thu Aug 13 2026 Ben Hillis - 0.1.0-1 +- Original version for Azure Linux +- License verified diff --git a/cgmanifest.json b/cgmanifest.json index c70d34be9f6..2da4faca41d 100644 --- a/cgmanifest.json +++ b/cgmanifest.json @@ -15788,6 +15788,16 @@ } } }, + { + "component": { + "type": "other", + "other": { + "name": "openvmm", + "version": "0.1.0", + "downloadUrl": "https://github.com/microsoft/openvmm/archive/refs/tags/openvmm-v0.1.0.tar.gz" + } + } + }, { "component": { "type": "other", From 1e14dc2a80c9cb1ee906336bd791e50e1708e422 Mon Sep 17 00:00:00 2001 From: Ben Hillis Date: Fri, 21 Aug 2026 22:09:51 +0000 Subject: [PATCH 2/2] openvmm: run unit tests in %check and let RPM split debuginfo The release profile sets debug = true, so suppressing debug_package left the symbols out of any package. Drop the override so RPM produces the debuginfo package. Run the unit tests for the pure-logic crates in the binary's dependency closure. 1053 tests, no virtualization required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 50ad1e94-a714-4445-bf61-acec0dec4d22 --- SPECS/openvmm/openvmm.spec | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/SPECS/openvmm/openvmm.spec b/SPECS/openvmm/openvmm.spec index f9a2b46d6ce..0363402609f 100644 --- a/SPECS/openvmm/openvmm.spec +++ b/SPECS/openvmm/openvmm.spec @@ -38,8 +38,10 @@ virtual machines on Linux via KVM or Microsoft Hypervisor. %global rust_target x86_64-unknown-linux-gnu -# The release profile does not emit debug info. -%global debug_package %{nil} +# Unit tests for the pure-logic crates in the openvmm binary's dependency +# closure. The rest of the test suite drives a live VM, which needs +# virtualization the build environment does not have. +%global test_crates -p acpi -p consomme -p crypto -p loader -p mesh_protobuf -p openvmm_core -p openvmm_entry -p pal -p pci_core -p vhdx -p vm_topology -p vmcore -p vmm_core %prep %autosetup -n %{name}-openvmm-v%{version} -N @@ -61,7 +63,7 @@ cargo build --release --locked --offline -p openvmm --target %{rust_target} install -D -p -m 0755 target/%{rust_target}/release/openvmm %{buildroot}%{_bindir}/openvmm %check -# The upstream test suite expects virtualization unavailable to the build. +cargo test --release --locked --offline --lib --target %{rust_target} %{test_crates} ./target/%{rust_target}/release/openvmm --version %files