Skip to content

Rework external_deps for Saigo and CMake-based NaCl rebuild - #1986

Open
illwieckz wants to merge 66 commits into
masterfrom
illwieckz/deps
Open

illwieckz wants to merge 66 commits into
masterfrom
illwieckz/deps

Conversation

@illwieckz

@illwieckz illwieckz commented Jun 26, 2026 •

Copy link
Copy Markdown
Member

This introduces a big change: the NaCl loader and bootstrap executables are now suffixed with their architecture, like the IRT: nacl_loader-amd64, nacl_helper_bootstrap-amd4.

To avoid name collision, the armhf loader wrapper for running armhf on arm64 is now named nacl_helper_bootstrap-ldarmhf, it chainloads what is now nacl_helper_bootstrap-armhf.

This change genericizes what already existed for loading the amd64 loader on windows-amd64 when running the i686 engine, except now that's all the loaders that have a suffix, not just the non-native one.

This makes things very easy to manage, for example the external_deps script just loops over all the different nexe architecture an engine architecture can support and builds the nacl_loader for it. This already works for the windows-i686 deps build: it builds both the i686 and amd64 loaders using MinGW.

This same mechanism would be usable in the future to build for the linux-arm64 deps both the armhf loader and the amd64 loader (purposed to be running on box64 when armhf support isn't there in hardware).

With that loader suffix thing I deeply rewrote the NaCl startup code in VirtualMachine.cpp, which is then already shaped for the ability to chose between armhf or amd64 on box64 at run time. The integration of box64 (CMake code, etc.) isn't there, but the VirtualMachine.cpp code is ready. That rework is deep and deduplicate and refactor intensively the binary name construction and the command construction.

I started adding the macos-arm64-default deps configuration. For now not everything works, but it already successfully builds the amd64 loader.

The IRT was previously fetched as part of the naclsdk, which is not removed yet, so the IRT is still shipped the old way at this point.

For Saigo it uses the recent release I packaged:

For the NaCl loader it uses my illwieckz/staging branch that contains all my unmerged code:

@illwieckz

illwieckz commented Jun 26, 2026 •

Copy link
Copy Markdown
Member Author

The CI fails because I haven't uploaded preview external_deps archives yet (it's too early).

@illwieckz

illwieckz commented Jun 26, 2026 •

Copy link
Copy Markdown
Member Author

Building the NaCl loader with MinGW requires JWasm:

I wonder if we can extend the script to build specific host tools.

I actually suspect that some macOS tools are meant to be built for the host as well (nasm, pkg-config…), and that we were lucky to be able to reuse the ones built for the target because we weren't cross-compiling…

@illwieckz

illwieckz commented Jun 26, 2026 •

Copy link
Copy Markdown
Member Author

I'm very proud of this:

build_naclruntime() {
	local nacl_arch_list=()

	case "${PLATFORM}" in
	windows-amd64-*)
		nacl_arch_list+=('amd64')
		;;
	windows-i686-*)
		nacl_arch_list+=('i686')
		nacl_arch_list+=('amd64')
		;;
	linux-amd64-*)
		nacl_arch_list+=('amd64')
		;;
	linux-i686-*)
		nacl_arch_list+=('i686')
		;;
	linux-arm64-*)
		nacl_arch_list+=('armhf')
		;;
	linux-armhf-*)
		nacl_arch_list+=('armhf')
		;;
	macos-amd64-*)
		nacl_arch_list+=('amd64')
		;;
	macos-arm64-*)
		nacl_arch_list+=('amd64')
		;;
	*)
		log ERROR 'Unsupported platform for naclruntime'
		;;
	esac

	local dir_name="DaemonEngine-native_client-${NACLRUNTIME_REVISION:0:7}"
	local archive_name="native_client-${NACLRUNTIME_REVISION}.zip"

	download_extract naclruntime "${archive_name}" \
		"{$NACLRUNTIME_BASEURL}/${NACLRUNTIME_REVISION}"

	"${download_only}" && return

	cd "${dir_name}"

	for nacl_arch in "${nacl_arch_list[@]}"
	do
		(
			setup_platform "${PLATFORM_SYSTEM}-${nacl_arch}-${PLATFORM_COMPILER}"
			cmake_build
		)

		case "${PLATFORM}" in
		linux-*)
			mv "${PREFIX}/bin/nacl_helper_bootstrap" "${PREFIX}/nacl_helper_bootstrap-${nacl_arch}"
			;;
		esac

		mv "${PREFIX}/bin/sel_ldr${EXE_EXT}" "${PREFIX}/nacl_loader-${nacl_arch}${EXE_EXT}"
	done

@illwieckz

illwieckz commented Jun 26, 2026 •

Copy link
Copy Markdown
Member Author

I actually suspect that some macOS tools are meant to be built for the host as well (nasm, pkg-config…), and that we were lucky to be able to reuse the ones built for the target because we weren't cross-compiling…

Yes, pkg-config is a host tool required to build opusfile on macOS. There is already some specific code (but specific to pkg-config) to build it for the host, but we still install it in the packaged prefix.

So we better refactor this and reuse the mechanism for JWasm.

@illwieckz
illwieckz force-pushed the illwieckz/deps branch 6 times, most recently from eb0893d to 6d2955a Compare June 26, 2026 06:46
@illwieckz
illwieckz force-pushed the illwieckz/deps branch 2 times, most recently from bd56fb3 to 7179f26 Compare June 26, 2026 07:50
@illwieckz

illwieckz commented Jun 26, 2026 •

Copy link
Copy Markdown
Member Author

So we better refactor this and reuse the mechanism for JWasm.

Now done.

Those “packages“:

  • native-pkgconfig (macOS)
  • native-nasm (macOS)
  • native-jwasm (MinGW)

Are now guaranteed to be compiled the native way and stored in their own native prefix that is not packaged.
It also means that those tools are not executed from the prefix that is to be packaged.

The building of the NaCl client is now working out of the box with MinGW. Well, at least on Ubuntu 24.04 Noble. On Debian 13 Trixie I get some “-Wincompatible-pointer-types” errors, to be fixed in Native Client upstream. The build tooling is fine.

@illwieckz
illwieckz force-pushed the illwieckz/deps branch 2 times, most recently from 8db6365 to c456a3f Compare June 26, 2026 08:00
@illwieckz

Copy link
Copy Markdown
Member Author

Something annoying is that both the NASM build we download (2.16.03) and the latest stable one (3.01 from October 2025) provide a macOS fat binary of i386 and amd64, no arm64… So we can compile macOS deps for both amd64 and arm64 from amd64, but we can only build arm64 deps from arm64.

That's not a big deal because I build on amd64, but that is annoying.

@illwieckz
illwieckz force-pushed the illwieckz/deps branch 2 times, most recently from 4f241c0 to b00fbd9 Compare July 7, 2026 19:01
illwieckz added 2 commits July 8, 2026 14:22
…s to the NaCl subinvocation

It's used by Unvanquished to pass CBSE_PYTHON_PATH.

Also delete DAEMON_CBSE_PYTHON_PATH (already moved to the game as CBSE_PYTHON_PATH).
@illwieckz
illwieckz force-pushed the illwieckz/deps branch 2 times, most recently from feb9da6 to 56b8708 Compare July 10, 2026 09:31
@illwieckz
illwieckz force-pushed the illwieckz/deps branch 2 times, most recently from 78d544b to cb12ca8 Compare July 14, 2026 09:06
Set up the chdir and environment variable in posix_spawn.
Fixes #1336.

Co-authored-by: Thomas Debesse <dev@illwieckz.net>
slipher and others added 6 commits September 7, 2026 01:53
Remove cvars controlling whether the Linux bootstrap loader is used.
Never use bootstrap with the amd64 loader.
Always use bootstrap with 32-bit loaders.
Remove amd64 bootstrap usage from deps.

Closes #1327.

Co-authored-by: Thomas Debesse <dev@illwieckz.net>
When creating a NaCl (or native exe) VM on Windows, block
evironment variables from being passed through to the 
subprocess as is done on *nix. Probably we do this since
there are NACL* variables that can disable secure sandboxing.

inheritEnvironment is always false on Windows, but I implemented
the true case anyway since it's less code than having the Q_UNUSED
and asserting it's false.
Check the Linux sysctl vm.mmap_min_addr only when using the NaCl
bootstrap (rather than always when using NaCl). Or equivalently, check
it only with 32-bit NaCl runtimes. The bootstrap fails to start when the
value is too high to due low fixed address mappings. On ARM at least,
sel_ldr proper would also fail with a too-high min address since that
disturbs the address space layout. On 64-bit there is neither the
bootstrap nor 0-based address space layout so it always works.

Co-authored-by: Thomas Debesse <dev@illwieckz.net>
Co-authored-by: Thomas Debesse <dev@illwieckz.net>
@illwieckz
illwieckz force-pushed the illwieckz/deps branch 3 times, most recently from 783665a to 5590945 Compare October 5, 2026 03:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants