Repository navigation
Expand file tree
/
Copy pathflake.nix
More file actions
131 lines (124 loc) · 5.03 KB
/
Copy pathflake.nix
File metadata and controls
131 lines (124 loc) · 5.03 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
#
# flake.nix — xtcp2
#
# Thin orchestrator. Every concern lives under ./nix/ and is wired up here.
# See ./nix/default.nix for the per-system aggregator.
# Monitor "run all": nix build path:.#test-linkmonitor -L
# Runs tests, race, vet, lint, formatting, replay, fuzzing and doc checks.
# See ./nix/README.md for individual targets, logs and Nix policy checks.
#
# Quick references:
# nix develop # dev shell
# nix build .#xtcp2 # main binary
# nix build .#xtcp2-all # every cmd/* binary
# nix build .#oci-xtcp2 # OCI image (load via `./result | docker load`)
# nix run .#regen-protos # `buf generate` (needs network)
# nix flake check # all registered checks, including monitor suite
# nix build path:.#test-linkmonitor -L # focused monitor gates; includes untracked files
# nix run .#microvm-x86_64-lifecycle # boot xtcp2 in a VM, run 3-check self-test
# nix run .#microvm-x86_64-discovery-bench # ns-discovery A/B (dir vs /proc scan)
# nix run .#microvm-x86_64-goip-parity # ip vs goip netlink comparison (needs /dev/kvm)
#
# Capturing netlink fixtures — use the microVM, not the host:
# nix run .#microvm-x86_64-netlink-dump-capture
# THE SANCTIONED CAPTURE PATH. Boots a root guest, drives it over serial
# with tcl/expect, captures in a clean namespace with no side traffic,
# and writes pkg/xtcpnl/testdata/. Needs /dev/kvm; does NOT need host
# root, so it is runnable unattended. Pass --out DIR to write somewhere
# else, which is worth doing first: it rewrites EVERY fixture it
# captures, not only a newly added one, and committed line-number
# citations point into those files.
# nix run .#capture-netlink-fixtures
# The same corpus on the HOST. Needs host root (sudo, interactively) and
# captures in the host's namespace, where other processes' netlink
# traffic is mixed in. Diagnostic fallback only — prefer the microVM.
#
# Overriding the giouring source (local fork):
# nix develop --override-input giouring path:/home/das/Downloads/giouring
#
{
description = "xtcp2 — TCP socket introspection via netlink";
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
flake-utils.url = "github:numtide/flake-utils";
microvm = {
url = "github:astro/microvm.nix";
inputs.nixpkgs.follows = "nixpkgs";
};
# Local fork of iceber/iouring-go. Pin rev — overridable via
# `--override-input giouring path:/path/to/local`.
giouring = {
url = "github:randomizedcoder/giouring/9e96b7216bf07ce3c97281092444e85311f7b2e4";
flake = false;
};
# xdp2 provides `proto-audit`, the netlink layout oracle. It normalises the
# kernel UAPI headers and 15 other sources to one IR indexed by wire bit
# offset, which is what lets it find a field xtcp2's Go structs are
# *missing* rather than merely mis-reading one they have. Consumed by
# nix/checks/proto-audit-netlink.nix; see docs/netlink/coverage-status.md.
#
# Deliberately NOT `inputs.nixpkgs.follows = "nixpkgs"`. proto-audit is a
# Rust build over a large pinned source set (a kernel tarball, DPDK, nDPI,
# suricata, tshark, a scapy python) and is built against the nixpkgs it was
# tested with. Following xtcp2's nixpkgs would trade one duplicated nixpkgs
# evaluation for a build that may simply not work.
#
# Override to a local checkout when iterating on the oracle itself:
# nix build .#proto-audit-netlink --override-input xdp2 path:/home/das/Downloads/xdp2
xdp2.url = "github:randomizedcoder/xdp2/16aa76764c8ab18897de6af13cac37c2fa89bb37";
};
nixConfig = {
extra-substituters = [ "https://microvm.cachix.org" ];
extra-trusted-public-keys = [
"microvm.cachix.org-1:oXnBc6hRE3eX5rSYdRyMYXnfzcCxC7yKPTbZXALsqys="
];
};
outputs =
{
self,
nixpkgs,
flake-utils,
microvm,
giouring,
xdp2,
}:
flake-utils.lib.eachSystem [ "x86_64-linux" ] (
system:
let
pkgs = import nixpkgs {
inherit system;
# MinIO ships in nixpkgs marked insecure (upstream cadence vs.
# nixpkgs vulnerability tracking). The Vector flavor of the
# microvm uses it as a local test fixture, never exposed beyond
# the VM. Pin the exact version we accept so accidental nixpkgs
# bumps fail loudly instead of silently sliding to a new CVE.
config.permittedInsecurePackages = [
"minio-2025-10-15T17-29-55Z"
];
};
inherit (nixpkgs) lib;
aggregator = import ./nix {
inherit
pkgs
lib
microvm
nixpkgs
giouring
xdp2
;
src = ./.;
};
in
{
inherit (aggregator)
packages
devShells
checks
apps
;
}
)
// {
overlays.default = import ./nix/overlays.nix { inherit self; };
};
}