From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 2DCD01FF0E5 for ; Wed, 12 Aug 2026 18:25:46 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 4E4DA214DD; Wed, 12 Aug 2026 18:25:45 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hajdamowicz-info.20251104.gappssmtp.com; s=20251104; t=1786551934; x=1787156734; darn=lists.proxmox.com; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=iMq7Do5RITQnbpN5WA5mSKztKmDsGjDUHvx2UqRxFXk=; b=U2G7KV1se4ZObtjzNkJBEJQIo2lNqXdz8EQYMCQSLzoQrL7KgNyuWm/n7WxKhijQ3q ex26BZUf2aQzk+3YNn7doqbaicTjPLyYY1a4dtvCVGg20fJZWEAZgNmsui0sHBE3taST LgZLP8ye+rJneAiR5FY6DdsbGDxa7nlhiIyU8KMNbXnSfpFcbyzow/Faz2GcMmFDzMzl WWzLU6pvOn5TDIXmOisTrkAXRVkDOEK+dxaGgwGvEIaB6Hj1Qrb/bgZrHl4BkYckGP0L nfEWZHwvvtesSKIo/aMjDtI9akZBU2msCqriomI03ZiY453b0a8iT8CjaeMxDX7VTX6Y bcfA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786551934; x=1787156734; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=iMq7Do5RITQnbpN5WA5mSKztKmDsGjDUHvx2UqRxFXk=; b=j7dR1YpCF3z005NeEg/nkWZ7AIqEJSqoPBl/qrKdlt0eVjEkyNyifYPZxM8OfQZeOx r0S6pt8IbxsJ1ZSTQGV3DLzUGL7NTRCTr6IH9FihFXyxRjvQrE61sShVWPXtXTlwP8Id p8x/hK6QQOeuyYZuxynYti/B+vkTX/TuuZ6/nga4JOU/vfU4V8SlSm4BbNA1oTiDNCdM CtvkOgm5SagHmY8bK84tdtc+HZ9stfw1mzd3S/qNcqVGZswuUz0KbQ/VnSgeKQeMtJtB 9LeTDaMPn3FuoNV3lF4Bp3Mni975qBESddWp9lXQFGghW8cJcwodBegQr1K2u2ONa1Lf fFDQ== X-Gm-Message-State: AOJu0Yx9ZxFJCgsgTC+lmsznvcHsvj5pGkT59ZPgCI7jISe3G5j4vjSU ej1kI4sPciIKvAa9XGoptyQektg1H1vAvLUEvl61CZLf2CL5Y+s3iTy098iZ1gcBnHa+0AN9u5e Ge9Jt8bauJb1v X-Gm-Gg: AR+sD11UhrZTQSAMwe7RLGaXVlqb3LPtdzU78WrlvKYsXpCrU8OyW4p4wTs7IEOIeB+ 9OUl1NF1OtCnBS5rCByo2Su6aFgxe/Sf2XMrNzLY9EKzaA2quycGG3Eq9Wcqzsm1mxpr6GVlw10 MhR8tcAtXEHpcqEhtQTjzRcbQzBSZibkJ5UMOj9ClJakc1At9DrBSS5bLHlBCjG2A1lsV5axQLQ x1GttsV0dd7dWAveAklvJTYcCfc47WTviqNdNG64yJ91mnw/bHk8Whu/H4MFVfa2mO+ndgc5C8z 8dCfBBv7SAxb7iw13YKIlNx8eo5yjVKAOGkzvbH5yWc4PYhFNSA3fs4G0pFKFlFjXEBZjURgn5N kzR92iEBAa9fti8jD99yF+yKgo3OtqADRBA9ObZRCkXugs6fNjQF0/FYwg7nEb1RDr9yKwItku1 1zA05snZjdFhu9f+UyF4hjPHCoC8BiOqoSir7XUGGeLGZXuCi/fU5jWdW4BfG3o2T2xId2VTuMQ iZxreeYK9zD9+XiZOLsRBNrpDJUNCGoGkxflJJT9q5jB1gIFBtDcBulzaz/mEie X-Received: by 2002:a17:907:1c93:b0:c20:d90b:2ccf with SMTP id a640c23a62f3a-c20f2e3d63amr272529966b.7.1786551934247; Wed, 12 Aug 2026 09:25:34 -0700 (PDT) From: Krzysztof Hajdamowicz To: pve-devel@lists.proxmox.com Subject: [PATCH pve-kernel] build: ship Rust artifacts for external modules Date: Wed, 12 Aug 2026 18:25:27 +0200 Message-ID: <20260812162527.98882-1-krzysztof@hajdamowicz.info> X-Mailer: git-send-email 2.55.0 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 0 DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DMARC_PASS -0.1 DMARC pass policy KAM_INFOUSMEBIZ 0.75 Prevalent use of .info|.us|.me|.me.uk|.biz|xyz|id|rocks|life domains in spam/malware RCVD_IN_DNSWL_NONE -0.0001 Sender listed at https://www.dnswl.org/, no trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: UWW6EPFFB6743D4DC4TU5W57MYLSOGLZ X-Message-ID-Hash: UWW6EPFFB6743D4DC4TU5W57MYLSOGLZ X-MailFrom: krzysztof@hajdamowicz.info X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Krzysztof Hajdamowicz X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: External kernel modules containing Rust code cannot currently be built against the Proxmox kernel headers alone. Unlike C modules, Rust modules depend on libraries, metadata and procedural macros generated while building the kernel. In particular, Kbuild needs the matching .rlib, .rmeta and proc-macro .so files from the rust/ output directory. These files are tied not only to the kernel version and configuration, but also to the exact Rust compiler used for the kernel build. They cannot be regenerated reliably by DKMS from the installed headers. This is currently relevant to the out-of-tree bcachefs DKMS work described by the bcachefs maintainer: https://www.patreon.com/bcachefs/posts/in-kernel-rust-162419215 Ship the generated Rust artifacts in a separate, versioned package: proxmox-kernel-${KVNAME}-rust The package installs them under: /usr/src/proxmox-kernel-${KVNAME}-rust/rust The matching headers package exposes this directory as: /usr/src/linux-headers-${KVNAME}/rust using a relative symlink. Keeping the artifacts in a separate package avoids increasing the size of the regular headers package for users who only build C modules. The headers package therefore Recommends the matching Rust package, while the Rust package has an exact dependency on the matching headers package. The exact version relationship is intentional: Rust metadata is not portable between different kernel or compiler builds. The resulting packages were tested on a Debian Trixie builder. The Rust package contained: - 3 .rlib files - 8 .rmeta files - 2 procedural-macro shared objects - no Kbuild .cmd or .o.ur-* temporary files Its compressed package size was approximately 30 MiB and its installed size approximately 155 MiB. Keeping it separate therefore substantially reduces the impact on users who do not need Rust external modules. After installing the generated headers and Rust packages: - an upstream kernel minimal out-of-tree Rust sample module built successfully; - the resulting module had the expected 7.0.14-11-pve vermagic; - bcachefs-tools v1.39.1, built with BCACHEFS_RUST=1, produced a bcachefs.ko containing compiled Rust objects and Rust symbols; - lintian reported no issues for the new package. The modules could not be loaded in the build environment because the LXC container runs the host kernel rather than the newly built kernel. The normal ABI check was also investigated. The kernel configuration expects rustc 1.93.1 built from the source tarball. The available rustup toolchain reported the same version and compiler commit, but was not an identical compiler build. A rebuild with that toolchain resulted in 736 missing and 770 new ABI symbols. All of those differences were Rust symbols; no C ABI symbols differed. This is consistent with Rust crate metadata and symbol hashes depending on the exact compiler build. SKIPABI=1 was used only to finish the local test packages and perform the external-module build tests. This patch does not disable, bypass or otherwise modify abicheck. A package built in the official Proxmox environment with the exact expected compiler should still run the normal ABI check. The result should be verified by an official package build. The ABI result also reinforces why the generated Rust artifacts need to be shipped from the original kernel build instead of being reconstructed later by DKMS. Signed-off-by: Krzysztof Hajdamowicz --- Makefile | 6 ++++-- debian/control.in | 10 ++++++++++ debian/rules | 14 +++++++++++--- 3 files changed, 25 insertions(+), 5 deletions(-) diff --git a/Makefile b/Makefile index f328de3..5625f5d 100644 --- a/Makefile +++ b/Makefile @@ -23,6 +23,7 @@ EXTRAVERSION=-$(KREL)$(KREL_EXTRA)-pve KVNAME=$(KERNEL_VER)$(EXTRAVERSION) PACKAGE=proxmox-kernel-$(KVNAME) HDRPACKAGE=proxmox-headers-$(KVNAME) +RUSTPACKAGE=proxmox-kernel-$(KVNAME)-rust ARCH=$(shell dpkg-architecture -qDEB_HOST_ARCH) @@ -58,12 +59,13 @@ DST_DEB=$(PACKAGE)_$(DEB_VERSION)_$(ARCH).deb SIGNED_TEMPLATE_DEB=$(PACKAGE)-signed-template_$(DEB_VERSION)_$(ARCH).deb META_DEB=proxmox-kernel-$(KERNEL_MAJMIN)_$(DEB_VERSION)_$(ARCH).deb HDR_DEB=$(HDRPACKAGE)_$(DEB_VERSION)_$(ARCH).deb +RUST_DEB=$(RUSTPACKAGE)_$(DEB_VERSION)_$(ARCH).deb META_HDR_DEB=proxmox-headers-$(KERNEL_MAJMIN)_$(DEB_VERSION)_$(ARCH).deb USR_HDR_DEB=proxmox-kernel-libc-dev_$(DEB_VERSION)_$(ARCH).deb LINUX_TOOLS_DEB=linux-tools-$(KERNEL_MAJMIN)_$(DEB_VERSION)_$(ARCH).deb LINUX_TOOLS_DBG_DEB=linux-tools-$(KERNEL_MAJMIN)-dbgsym_$(DEB_VERSION)_$(ARCH).deb -DEBS=$(DST_DEB) $(META_DEB) $(HDR_DEB) $(META_HDR_DEB) $(LINUX_TOOLS_DEB) $(LINUX_TOOLS_DBG_DEB) $(SIGNED_TEMPLATE_DEB) # $(USR_HDR_DEB) +DEBS=$(DST_DEB) $(META_DEB) $(HDR_DEB) $(RUST_DEB) $(META_HDR_DEB) $(LINUX_TOOLS_DEB) $(LINUX_TOOLS_DBG_DEB) $(SIGNED_TEMPLATE_DEB) # $(USR_HDR_DEB) all: deb deb: $(DEBS) @@ -71,7 +73,7 @@ deb: $(DEBS) #lintian $(HDR_DEB) lintian $(LINUX_TOOLS_DEB) -$(META_DEB) $(META_HDR_DEB) $(LINUX_TOOLS_DEB) $(HDR_DEB) $(DST_DEB) &: $(BUILD_DIR).prepared +$(META_DEB) $(META_HDR_DEB) $(LINUX_TOOLS_DEB) $(HDR_DEB) $(RUST_DEB) $(DST_DEB) &: $(BUILD_DIR).prepared cd $(BUILD_DIR); dpkg-buildpackage --jobs=auto -b -uc -us dsc: diff --git a/debian/control.in b/debian/control.in index b7048b6..98a5a60 100644 --- a/debian/control.in +++ b/debian/control.in @@ -57,9 +57,19 @@ Priority: optional Architecture: any Provides: linux-headers-@KVNAME@-@ARCH@, pve-headers-@KVNAME@ Depends: ${misc:Depends}, +Recommends: proxmox-kernel-@KVNAME@-rust (= ${binary:Version}), Description: Proxmox Kernel Headers This package contains the linux kernel headers +Package: proxmox-kernel-@KVNAME@-rust +Section: devel +Priority: optional +Architecture: any +Depends: proxmox-headers-@KVNAME@ (= ${binary:Version}), ${misc:Depends}, ${shlibs:Depends}, +Description: Rust build artifacts for the Proxmox Kernel + This package contains the Rust build artifacts required to compile external + kernel modules written in Rust. + Package: proxmox-kernel-@KVNAME@ Section: admin Priority: optional diff --git a/debian/rules b/debian/rules index 71f9804..56e0248 100755 --- a/debian/rules +++ b/debian/rules @@ -20,6 +20,7 @@ PMX_KERNEL_PKG=proxmox-kernel-$(KVNAME) PMX_KERNEL_SERIES_PKG=proxmox-kernel-$(KERNEL_MAJMIN) PMX_DEBUG_KERNEL_PKG=proxmox-kernel-$(KVNAME)-dbgsym PMX_HEADER_PKG=proxmox-headers-$(KVNAME) +PMX_RUST_PKG=proxmox-kernel-$(KVNAME)-rust PMX_USR_HEADER_PKG=proxmox-kernel-libc-dev PMX_KERNEL_SIGNING_TEMPLATE_PKG=proxmox-kernel-${KVNAME}-signed-template PMX_KERNEL_SIGNED_VERSION := $(shell echo ${DEB_VERSION} | sed -e 's/-/+/') @@ -69,7 +70,7 @@ install: .install_mark .tools_install_mark .headers_install_mark .usr_headers_in binary: install debian/rules fwcheck abicheck - dh_strip -N$(PMX_HEADER_PKG) -N$(PMX_USR_HEADER_PKG) -Xvmlinux -Xvmlinuz + dh_strip -N$(PMX_HEADER_PKG) -N$(PMX_RUST_PKG) -N$(PMX_USR_HEADER_PKG) -Xvmlinux -Xvmlinuz dh_makeshlibs dh_shlibdeps dh_installdeb @@ -179,7 +180,7 @@ endif touch $@ .headers_prepare_mark: .config_mark - rm -rf debian/$(PMX_HEADER_PKG) + rm -rf debian/$(PMX_HEADER_PKG) debian/$(PMX_RUST_PKG) mkdir -p debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME) install -m 0644 $(KERNEL_SRC)/.config debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME) make -C $(KERNEL_SRC_COPY) mrproper @@ -210,9 +211,16 @@ endif mkdir -p $(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG) cp $(KERNEL_SRC)/.config $(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG)/.config $(MAKE) -C $(KERNEL_SRC_COPY) O=$(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG) -j1 syncconfig modules_prepare prepare scripts - cd $(KERNEL_SRC_COPY); cp -a include scripts $(BUILD_DIR)/debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME) find $(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG) -name \*.o.ur-\* -o -name '*.cmd' | xargs rm -f + # External Rust modules need the artifacts generated by the exact kernel build. + mkdir -p debian/$(PMX_RUST_PKG)/usr/src/$(PMX_RUST_PKG) + mv $(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG)/rust debian/$(PMX_RUST_PKG)/usr/src/$(PMX_RUST_PKG)/ + rm -f debian/$(PMX_RUST_PKG)/usr/src/$(PMX_RUST_PKG)/rust/Makefile + install -m 0644 $(KERNEL_SRC_COPY)/rust/Makefile debian/$(PMX_RUST_PKG)/usr/src/$(PMX_RUST_PKG)/rust/Makefile + cd $(KERNEL_SRC_COPY); cp -a include scripts $(BUILD_DIR)/debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME) rsync --ignore-existing -r -v -a $(addprefix $(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG)/,arch include kernel scripts tools) $(BUILD_DIR)/debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)/ + rm -rf debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)/rust + ln -s ../$(PMX_RUST_PKG)/rust debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)/rust rm -rf $(BUILD_DIR)/$(KERNEL_SRC_COPY) touch $@ -- 2.55.0