-
Notifications
You must be signed in to change notification settings - Fork 21
Expand file tree
/
Copy pathflake.nix
More file actions
193 lines (182 loc) · 7.08 KB
/
Copy pathflake.nix
File metadata and controls
193 lines (182 loc) · 7.08 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
# Copyright lowRISC contributors.
# Licensed under the Apache License, Version 2.0, see LICENSE for details.
# SPDX-License-Identifier: Apache-2.0
{
description = "CHERI-Mocha is a secure enclave reference design and is part of the COSMIC project.";
inputs = {
lowrisc-nix.url = "github:lowRISC/lowrisc-nix";
nixpkgs.follows = "lowrisc-nix/nixpkgs";
flake-utils.follows = "lowrisc-nix/flake-utils";
uv2nix = {
url = "github:pyproject-nix/uv2nix";
inputs.pyproject-nix.follows = "pyproject-nix";
inputs.nixpkgs.follows = "nixpkgs";
};
pyproject-nix = {
url = "github:pyproject-nix/pyproject.nix";
inputs.nixpkgs.follows = "nixpkgs";
};
pyproject-build-systems = {
url = "github:pyproject-nix/build-system-pkgs";
inputs.nixpkgs.follows = "nixpkgs";
inputs.pyproject-nix.follows = "pyproject-nix";
inputs.uv2nix.follows = "uv2nix";
};
ftditool = {
url = "github:lowRISC/ftditool?ref=v0.5.1";
inputs.nixpkgs.follows = "nixpkgs";
};
};
nixConfig = {
extra-substituters = ["https://nix-cache.lowrisc.org/public/"];
extra-trusted-public-keys = ["nix-cache.lowrisc.org-public-1:O6JLD0yXzaJDPiQW1meVu32JIDViuaPtGDfjlOopU7o="];
};
outputs = {
nixpkgs,
flake-utils,
lowrisc-nix,
...
} @ inputs: let
system_outputs = system: let
pkgs = import nixpkgs {inherit system;};
lrPkgs = lowrisc-nix.outputs.packages.${system};
workspace = inputs.uv2nix.lib.workspace.loadWorkspace {workspaceRoot = ./.;};
overlay = workspace.mkPyprojectOverlay {
sourcePreference = "wheel";
};
pythonSet =
(pkgs.callPackage inputs.pyproject-nix.build.packages {
python = pkgs.python312;
}).overrideScope
(
pkgs.lib.composeManyExtensions [
inputs.pyproject-build-systems.overlays.default
overlay
(lowrisc-nix.lib.pyprojectOverrides {inherit pkgs;})
]
);
pythonEnv = pythonSet.mkVirtualEnv "python-env" workspace.deps.default;
fpga = import nix/fpga.nix {
inherit
pkgs
pythonEnv
;
llvm = lrPkgs.llvm_cheri;
ftditool = ftditool-cli;
};
ftditool-cli = inputs.ftditool.packages.${system}.default;
cheri-toolchain = pkgs.callPackage ./nix/cheri_toolchain.nix {inherit (lrPkgs) llvm_cheri;};
in rec {
formatter = pkgs.alejandra;
devShells = rec {
default = baremetal;
# CHERI baremetal + EDA development shell, built on lowrisc-nix's generic
# mkEdaShell. Commercial EDA tools (Xcelium, Jasper, Vivado) are declared
# via tool_data.json and resolved at runtime from the JSON file named by
# $LOWRISC_EDA_CONFIG; without that config the shell still works and just
# warns. Open-source tools listed in tool_data.json (Verilator, FuseSoC)
# are absent from that config and are simply skipped — they are still
# provided as Nix packages below. Enter with `nix develop`; it execs a
# hermetic FHS sandbox, so it is not direnv-loadable.
baremetal = lowrisc-nix.lib.mkEdaShell {
inherit pkgs;
name = "baremetal";
tools = builtins.fromJSON (builtins.readFile ./tool_data.json);
extraDeps =
(with pkgs; [
bc
bison
cmake
cpio
flex
gnumake
picocom
gtkwave
openfpgaloader
ftditool-cli
openocd
gdb
expect
uv
pythonEnv
verible
srecord
d2
dtc
autoconf
automake
bmake
byacc
libarchive
libarchive.dev
libelf
libtool
pkg-config
zlib
zlib.dev
])
++ (with lrPkgs; [
verilator_5_040
llvm_cheri
]);
# Project env, appended after the EDA setup (mkEdaShell has no `env`
# attr — buildFHSEnv takes a bash profile fragment instead).
profile = ''
# Prevent uv from managing Python downloads; force the nixpkgs interpreter.
export UV_PYTHON_DOWNLOADS=never
export UV_PYTHON=${pythonSet.python.interpreter}
export SYSROOT_PURECAP=${cheri-toolchain.linux-headers-purecap}/usr/include
export COMPILER_RT_PURECAP=${cheri-toolchain.compiler-rt-builtins-purecap}/lib
export LIBC_PURECAP_INCLUDE=${cheri-toolchain.muslc-linux-riscv64-purecap}/include
export LIBC_PURECAP_LIB=${cheri-toolchain.muslc-linux-riscv64-purecap}/lib
# The debugger the debug tests drive. Commercial EDA trees ship
# their own gdb and mkEdaShell puts their paths first, so a bare
# `gdb` in this shell can be a vendor build that cannot even load
# (Xcelium's wants libmpfr.so.4). Name ours instead of relying on
# $PATH order; util/gdb_response.exp reads this.
export GDB=${pkgs.gdb}/bin/gdb
export HOSTCC=${pkgs.llvmPackages_21.clang}/bin/clang
export HOSTCXX=${pkgs.llvmPackages_21.clang}/bin/clang++
export HOSTLD=${pkgs.llvmPackages_21.lld}/bin/ld.lld
'';
};
};
apps = {
# Non-interactive entry point into the baremetal shell, for running a
# one-off command in it: `nix run .#baremetal -- <cmd> <args>`.
# mkEdaShell's shellHook execs the FHS sandbox with no argv, so
# `nix develop -c CMD` never reaches CMD: the dispatcher sees no
# arguments and drops into an interactive $SHELL instead. The app
# payload forwards argv through to `exec "$@"` inside the sandbox.
baremetal = devShells.baremetal.app;
# CI job runner, and what the workflows call. `nix run .#ci -- <job>`
# runs ci/run.py inside the same baremetal shell, so a CI job and a
# local run of it are the same command in the same environment:
# nix run .#ci -- verilator-test
# The workflows invoke this from an ordinary `run:` step rather than
# through `defaults.run.shell`, which keeps the Actions runner's own
# child a plain bash it can track.
ci = {
type = "app";
program = "${pkgs.writeShellScript "mocha-ci" ''
repo="$(${pkgs.git}/bin/git rev-parse --show-toplevel 2>/dev/null || pwd)"
exec ${devShells.baremetal.app.program} "$repo/ci/run.py" "$@"
''}";
};
bitstream-build = flake-utils.lib.mkApp {
drv = fpga.bitstream-build;
};
bitstream-hash = flake-utils.lib.mkApp {
drv = fpga.bitstream-hash;
};
bitstream-load = flake-utils.lib.mkApp {
drv = fpga.bitstream-load;
};
fpga-runner = flake-utils.lib.mkApp {
drv = fpga.fpga-runner;
};
};
};
in
flake-utils.lib.eachDefaultSystem system_outputs;
}