Skip to main content

rucc_sysroot/
artifact.rs

1//! What this release pins: one sysroot artifact per target, by URL and by hash.
2//!
3//! Design: `spec/cross-compile/13-distribution.md` section 13.2, which says every downloaded
4//! artifact has a hash pinned in the rucc release, checked before use, with a mismatch being a hard
5//! failure and no flag to get past it. Section 13.8 divides the work in three and the other two are
6//! written: `rucc_driver::fetch` moves the bytes with a program the machine already has, and
7//! `rucc_driver::install` decides whether what arrived is the right tree. This is the third, which
8//! is the statement of what the right one is, and it is the half that makes the other two mean
9//! anything.
10//!
11//! # Why it is here rather than with the two halves that use it
12//!
13//! Because it is read by something that cannot depend on the driver. The distribution manifest of
14//! section 13.5 is generated by a build tool, the same way `docs/TARGETS.md` and `tests/link-lines`
15//! are, and what it says about a target is what this table says plus what [`crate::Wall`] says. A
16//! build tool that pulled in the whole driver to read three strings would be a layer violation
17//! dressed up as convenience. It sits well here for a second reason as well: a pin is a fact about
18//! a sysroot, which is what this crate is for, and the fetch and the install are what a driver does
19//! with one.
20//!
21//! # Why the table is in the binary
22//!
23//! Because a hash that travels with the artifact is not a pin, and a hash in a file beside the
24//! compiler is a hash whoever replaces the artifact can replace too. The release is the authority
25//! for what an artifact of that release is, so the table is compiled into the release, which also
26//! means an upgrade can change a URL without anything on the machine having to be told.
27//!
28//! It is a table rather than a computed URL for the same reason. A name built out of a version and
29//! a tuple looks tidier and quietly says that every target's artifact is at a predictable address
30//! forever, which is a promise about somebody else's file server. A row per target costs three
31//! strings and says only what is true.
32//!
33//! # What is in it
34//!
35//! Fifteen rows, which are the three windows-gnu targets, four musl ones and eight glibc ones. For windows-gnu,
36//! `bin/mingw-headers` in `tamnd/rucc-cross` installs mingw-w64 14.0.0's headers, `bin/mingw-runtime`
37//! builds the runtime, the import libraries and a static winpthreads into the `lib` directory beside
38//! them, `bin/artifact` packs the tree, and the release `sysroots-2026-09-29` is where the files are.
39//! They are built for the UCRT, and the same release has a `-msvcrt` archive of each that nothing
40//! here pins. The archives are 15.2 MiB for x86_64, 14.9 MiB for i686 and 12.6 MiB for aarch64,
41//! installing to 141 MB, 135 MB and 119 MB. The header half is the same in all three, because
42//! mingw-w64 has no per architecture split and [`crate::Sysroot::splits_by_arch`] says so, and the
43//! `lib` half is what differs.
44//!
45//! For musl, `bin/sysroot` builds musl 1.2.5 for x86_64, aarch64, riscv64 and armv7 hard float, and
46//! the release `sysroots-2026-09-23` has the four archives, each about 2 MiB and installing to between
47//! 7 and 13 MB. They hold musl's headers and its static libraries and start files, and not the Linux
48//! uapi headers, which are [`KERNEL_HEADERS`] and fetched once for every Linux target. Both runs that
49//! produced them, on two machines, packed the same bytes.
50//!
51//! For glibc, `bin/glibc-sysroot` puts together the merged header tree of every pinned release from
52//! 2.28 to 2.44 with glibc 2.44's start files and `libc_nonshared.a`, for x86_64, i686, aarch64,
53//! armv7 hard float, riscv64, powerpc64le, s390x and loongarch64, and the release
54//! `sysroots-2026-09-24b` has the eight archives, each under 600 KB. The seven whose ABI has a glibc
55//! older than 2.33 also carry `libc_nonshared_stat.a`, the `stat` family those releases kept in
56//! `libc_nonshared.a`, which [`crate::link::LinkLine::glibc`] adds for a pin before 2.33. There is no `libc.so` in them,
57//! because the driver writes the stubs itself, and one archive serves every release of its target,
58//! which is [`pinned_for_target`]. server2 and server3 built them from separate inputs and packed
59//! the same bytes.
60//!
61//! Every other target is still unpublished, which is a statement about producers rather than about
62//! this table: `--fetch` of one says so by name, and the day a tree for it is published is the day a
63//! row for it is added here. The rows that are here are the first thing `--fetch` has ever had
64//! anything to move, so they are also what the fetch and the install are tested against.
65
66use std::path::{Path, PathBuf};
67
68use rucc_tuple::{Env, Os, TargetTuple};
69
70/// One artifact: the sysroot for one target, as this release pins it.
71///
72/// Or the kernel header tree, which is [`KERNEL_HEADERS`] and the one artifact that is not any
73/// target's.
74#[derive(Debug, Clone, Copy, PartialEq, Eq)]
75pub struct Pinned {
76    /// The target it is the sysroot for, in the spelling that names its directory under the cache,
77    /// or `kernel-headers` for the tree every Linux target shares, which is that tree's directory.
78    pub tuple: &'static str,
79    /// Where to get it. Handed to a downloader as it stands, and nothing here builds it out of
80    /// parts.
81    pub url: &'static str,
82    /// The sha256 of the archive, lowercase hex, which is what the bytes that arrive are held to.
83    pub sha256: &'static str,
84}
85
86impl Pinned {
87    /// The name to write the archive under, which is the last component of the URL.
88    ///
89    /// The URL's own name rather than one built out of the tuple, so that the file on disk is the
90    /// file the server served and a person comparing the two is comparing names as well as bytes.
91    #[must_use]
92    pub fn file_name(&self) -> &'static str {
93        self.url.rsplit('/').next().unwrap_or(self.url)
94    }
95
96    /// Where in the cache the archive is kept.
97    ///
98    /// Under the cache rather than in a temporary directory, because a machine with no downloader is
99    /// told this exact path and a second `--fetch` carries on from the check, which is section 13.8's
100    /// answer for a host that cannot reach the network at all. It is kept after the install for the
101    /// same reason and for one more: a fetch of a target that is already installed then moves
102    /// nothing and says so.
103    ///
104    /// The directory in front of the name is the first twelve characters of the hash, and it is
105    /// there because the name alone does not say which artifact this is. Two releases of a sysroot
106    /// for one target have the same file name, so a cache that kept the name alone would hold last
107    /// release's archive under the name this release wants, and a fetch refuses a file that does not
108    /// match rather than downloading over the top of it. That refusal is right for a file somebody
109    /// placed by hand and wrong for one we put there ourselves, so the fix is to stop the collision
110    /// rather than to soften the check. The hash is what has to change when the bytes change, so it
111    /// is the thing that separates them.
112    #[must_use]
113    pub fn archive_in(&self, cache: &Path) -> PathBuf {
114        cache.join("downloads").join(&self.sha256[..12]).join(self.file_name())
115    }
116}
117
118/// Every artifact this release pins, in tuple order.
119///
120/// A row is three strings and the test below says what they have to be. The order is the tuple's
121/// rather than the order they were published in, so that a row is found by reading down the column
122/// and two releases of this file diff as what changed between them.
123pub const PINNED: &[Pinned] = &[
124    Pinned {
125        tuple: "aarch64-linux-gnu",
126        url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-24b/rucc-sysroot-aarch64-linux-gnu.tar.gz",
127        sha256: "7a3e54260de1a07d00c7b6a1d8c4a3868367885d4aa96351b804a3a4c14e1a3c",
128    },
129    Pinned {
130        tuple: "aarch64-linux-musl",
131        url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-23/rucc-sysroot-aarch64-linux-musl.tar.gz",
132        sha256: "098c24c0c27d264dceaee76141f0933845dcc8a7c3a4b473954987f731fecde5",
133    },
134    Pinned {
135        tuple: "aarch64-windows-gnu",
136        url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-29/rucc-sysroot-aarch64-windows-gnu.tar.gz",
137        sha256: "b304bbbe1a11eaf9b41f9be810c27a3cf4965699872e71e2b703a59941db7aaf",
138    },
139    Pinned {
140        tuple: "armv7-linux-gnueabihf",
141        url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-24b/rucc-sysroot-armv7-linux-gnueabihf.tar.gz",
142        sha256: "f96e369bdbe1013a2d8d162fce9fb83444835098c606f5e200f181db63ab011f",
143    },
144    Pinned {
145        tuple: "armv7-linux-musleabihf",
146        url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-23/rucc-sysroot-armv7-linux-musleabihf.tar.gz",
147        sha256: "645ceef60e0302b260ad804569243c3470f7545f1b135a143f9b7ec8408b6f78",
148    },
149    Pinned {
150        tuple: "i686-linux-gnu",
151        url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-24b/rucc-sysroot-i686-linux-gnu.tar.gz",
152        sha256: "6860bcb60e2079d7ba40f29d8ce6344da202affe0a0f9462d12652bff773d513",
153    },
154    Pinned {
155        tuple: "i686-windows-gnu",
156        url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-29/rucc-sysroot-i686-windows-gnu.tar.gz",
157        sha256: "cea70fbedd27aa9cdc08c335105714747919f09f72b8f33ec5d49c659b3526b1",
158    },
159    Pinned {
160        tuple: "loongarch64-linux-gnu",
161        url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-24b/rucc-sysroot-loongarch64-linux-gnu.tar.gz",
162        sha256: "67e0565d9acc6a768dd2ad6318fab716c34bcbfaeb005398e38d4ca8d7f5c3c2",
163    },
164    Pinned {
165        tuple: "powerpc64le-linux-gnu",
166        url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-24b/rucc-sysroot-powerpc64le-linux-gnu.tar.gz",
167        sha256: "c5262070d3de6f6a91d6df9ee0acf32088d7d03720ce2bb650cae1f865d2ba05",
168    },
169    Pinned {
170        tuple: "riscv64-linux-gnu",
171        url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-24b/rucc-sysroot-riscv64-linux-gnu.tar.gz",
172        sha256: "6157fb51fb66fac4fedfe5233d0a2857bcce346cd8f376c595db558e0470c42f",
173    },
174    Pinned {
175        tuple: "riscv64-linux-musl",
176        url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-23/rucc-sysroot-riscv64-linux-musl.tar.gz",
177        sha256: "00fc00f996d0a9a3de1cabd95840d423de1562ed5345dd5c47f1bf89b30f0b99",
178    },
179    Pinned {
180        tuple: "s390x-linux-gnu",
181        url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-24b/rucc-sysroot-s390x-linux-gnu.tar.gz",
182        sha256: "ac73fa903ef8816f2eebb35d106bcf6aabdc3e5c22e94646af196df8d5615b56",
183    },
184    Pinned {
185        tuple: "x86_64-linux-gnu",
186        url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-24b/rucc-sysroot-x86_64-linux-gnu.tar.gz",
187        sha256: "a951b219c641ee0b17e228adc8e43f36eaa70ee255d3c6f7717ec39c41e8b5b8",
188    },
189    Pinned {
190        tuple: "x86_64-linux-musl",
191        url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-23/rucc-sysroot-x86_64-linux-musl.tar.gz",
192        sha256: "93b42df66c0a7547c3e96cd5512267790df1ca0227a0000ba4f1808eb214c376",
193    },
194    Pinned {
195        tuple: "x86_64-windows-gnu",
196        url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-29/rucc-sysroot-x86_64-windows-gnu.tar.gz",
197        sha256: "9f3919c9bee5447380a9746759439e051087b2364084447d6481fb9425c93758",
198    },
199];
200
201/// The Linux uapi header tree, which every Linux target reads beside its own sysroot.
202///
203/// One archive rather than a part of each Linux sysroot, for the reason [`crate::Kernel`] gives
204/// about the directory: the tree is the same for every Linux row except a small `asm/` per
205/// architecture, so a copy in every sysroot would be the same eleven megabytes once per target.
206/// `bin/kernel-headers` in `tamnd/rucc-cross` produces it and `bin/artifact kernel-headers` packs it,
207/// and `--fetch` of a Linux target installs it after the sysroot when it is not there already.
208pub const KERNEL_HEADERS: Pinned = Pinned {
209    tuple: "kernel-headers",
210    url: "https://github.com/tamnd/rucc-cross/releases/download/sysroots-2026-09-23/rucc-kernel-headers.tar.gz",
211    sha256: "e96934f553df19d6bdbb6804f1b52d079adc4bea10a819d51eda5bc4ec584f2d",
212};
213
214/// The artifact this release pins for `tuple`, if it pins one.
215///
216/// The canonical spelling is what a row is named by, so the caller parses what the user wrote and
217/// asks with the tuple's own text rather than with theirs.
218#[must_use]
219pub fn pinned_for(tuple: &str) -> Option<&'static Pinned> {
220    look(PINNED, tuple)
221}
222
223/// The artifact this release pins for a target, which for a glibc tuple that names a release is the
224/// one for the same tuple without it.
225///
226/// One glibc sysroot serves every release, because the headers in it pick the release with
227/// `__GLIBC_MINOR__` and the libraries a link reads are the stubs the driver writes for the release
228/// asked for. So `x86_64-linux-gnu.2.28` and `x86_64-linux-gnu` fetch the same archive, and it is
229/// installed under the pinned spelling because that is the directory the compiler reads.
230#[must_use]
231pub fn pinned_for_target(target: TargetTuple) -> Option<&'static Pinned> {
232    pinned_for(&target.to_canonical_string())
233        .or_else(|| pinned_for(&glibc_base(target)?.to_canonical_string()))
234}
235
236/// The same glibc target with its release left off, or [`None`] for a target that is not glibc or
237/// names no release.
238///
239/// What [`pinned_for_target`] looks a pinned release up under, and what the install accepts as the
240/// target of an archive fetched for one.
241#[must_use]
242pub fn glibc_base(target: TargetTuple) -> Option<TargetTuple> {
243    if target.os() != Os::Linux || target.env() != Env::Gnu {
244        return None;
245    }
246    target.env_version()?;
247    let mut base = TargetTuple::builder(target.arch(), target.os())
248        .sub_arch(target.sub_arch())
249        .endian(target.endian())
250        .data_model(target.data_model())
251        .env(target.env())
252        .abi(target.abi());
253    if let Some(version) = target.os_version() {
254        base = base.os_version(version);
255    }
256    base.build().ok()
257}
258
259/// Every target this release pins an artifact for, for a message that has to say what there is.
260#[must_use]
261pub fn pinned_targets() -> Vec<&'static str> {
262    PINNED.iter().map(|what| what.tuple).collect()
263}
264
265/// The same lookup over a table that is passed in, so what the lookup does is tested against rows
266/// that are written for it rather than against whatever [`PINNED`] happens to hold this release.
267fn look<'a>(table: &'a [Pinned], tuple: &str) -> Option<&'a Pinned> {
268    table.iter().find(|what| what.tuple == tuple)
269}
270
271#[cfg(test)]
272mod tests {
273    use std::path::PathBuf;
274
275    use super::*;
276
277    #[test]
278    fn a_pinned_glibc_release_shares_the_artifact_of_its_tuple() {
279        let tuple = |spelling: &str| spelling.parse::<TargetTuple>().expect("a tuple");
280        let base = glibc_base(tuple("x86_64-linux-gnu.2.28")).expect("glibc with a release");
281        assert_eq!(base.to_canonical_string(), "x86_64-linux-gnu");
282        let arm = glibc_base(tuple("armv7-linux-gnu.2.31eabihf")).expect("glibc with a release");
283        assert_eq!(arm.to_canonical_string(), "armv7-linux-gnueabihf");
284        // No release, or not glibc, is nothing to fall back to.
285        assert_eq!(glibc_base(tuple("x86_64-linux-gnu")), None);
286        assert_eq!(glibc_base(tuple("x86_64-linux-musl")), None);
287        // And a musl row is still found under its own name.
288        assert_eq!(
289            pinned_for_target(tuple("x86_64-linux-musl")).map(|what| what.tuple),
290            Some("x86_64-linux-musl")
291        );
292    }
293
294    /// A table with rows in it, which is what [`PINNED`] will look like.
295    const TABLE: &[Pinned] = &[
296        Pinned {
297            tuple: "aarch64-linux-musl",
298            url: "https://example.invalid/rucc-sysroot-aarch64-linux-musl.tar.gz",
299            sha256: "1111111111111111111111111111111111111111111111111111111111111111",
300        },
301        Pinned {
302            tuple: "x86_64-linux-musl",
303            url: "https://example.invalid/rucc-sysroot-x86_64-linux-musl.tar.gz",
304            sha256: "2222222222222222222222222222222222222222222222222222222222222222",
305        },
306    ];
307
308    #[test]
309    fn a_target_the_table_names_is_found_and_one_it_does_not_is_not() {
310        let found = look(TABLE, "x86_64-linux-musl").expect("the table has that one");
311        assert_eq!(found.sha256, TABLE[1].sha256);
312        assert_eq!(look(TABLE, "riscv64-linux-gnu"), None);
313    }
314
315    /// A tuple that starts with one the table has is a different target and not a match.
316    #[test]
317    fn a_longer_tuple_is_not_the_row_it_begins_with() {
318        assert_eq!(look(TABLE, "x86_64-linux-musl.1.2.5"), None);
319        assert_eq!(look(TABLE, "x86_64-linux"), None);
320    }
321
322    #[test]
323    fn the_archive_is_named_by_the_url_and_kept_under_the_cache() {
324        let what = TABLE[0];
325        assert_eq!(what.file_name(), "rucc-sysroot-aarch64-linux-musl.tar.gz");
326        assert_eq!(
327            what.archive_in(&PathBuf::from("/tmp/cache")),
328            PathBuf::from(
329                "/tmp/cache/downloads/111111111111/rucc-sysroot-aarch64-linux-musl.tar.gz"
330            )
331        );
332    }
333
334    /// Two releases of the sysroot for one target have the same file name, and the cache has to keep
335    /// them apart, because a fetch refuses a file under the artifact's name that is not the artifact.
336    #[test]
337    fn two_releases_of_one_target_are_not_the_same_path() {
338        let cache = PathBuf::from("/tmp/cache");
339        let old = TABLE[0];
340        let new = Pinned { sha256: TABLE[1].sha256, ..old };
341        assert_eq!(old.file_name(), new.file_name());
342        assert_ne!(old.archive_in(&cache), new.archive_in(&cache));
343    }
344
345    /// What every row of [`PINNED`] has to be.
346    ///
347    /// Left as a test rather than as a comment above the table, because the day somebody adds a row
348    /// is the day the rules stop being obvious, and a pasted hash with a capital letter in it or a
349    /// tuple spelled the way the URL spells it would otherwise be found by a user.
350    #[test]
351    fn every_row_is_a_target_a_url_and_a_hash() {
352        for what in PINNED {
353            let tuple: TargetTuple =
354                what.tuple.parse().unwrap_or_else(|why| panic!("{}: {why}", what.tuple));
355            assert_eq!(
356                tuple.to_canonical_string(),
357                what.tuple,
358                "a row is named by the canonical spelling, because that is what names the \
359                 directory the tree is installed at"
360            );
361            assert!(what.url.starts_with("https://"), "{}: {}", what.tuple, what.url);
362            // A query string or a fragment would make the file name something other than the last
363            // component of the URL, which is the one thing the name is read out of.
364            assert!(!what.url.contains('?') && !what.url.contains('#'), "{}", what.url);
365            assert!(!what.file_name().is_empty(), "{} ends with a separator", what.url);
366            assert_eq!(what.sha256.len(), 64, "{}: {}", what.tuple, what.sha256);
367            assert!(
368                what.sha256.bytes().all(|b| b.is_ascii_digit() || (b'a'..=b'f').contains(&b)),
369                "{}: {} is not lowercase hex, and the check compares text",
370                what.tuple,
371                what.sha256
372            );
373        }
374        let mut sorted: Vec<&str> = pinned_targets();
375        sorted.sort_unstable();
376        sorted.dedup();
377        assert_eq!(sorted, pinned_targets(), "the rows are in tuple order and each target once");
378    }
379
380    /// The kernel tree's row is held to the same rules as a target's, except that its name is the
381    /// directory it is installed at rather than a tuple.
382    #[test]
383    fn the_kernel_tree_is_a_url_and_a_hash_and_no_target_is_called_that() {
384        let what = KERNEL_HEADERS;
385        assert!(what.url.starts_with("https://"), "{}", what.url);
386        assert!(!what.url.contains('?') && !what.url.contains('#'), "{}", what.url);
387        assert_eq!(what.file_name(), "rucc-kernel-headers.tar.gz");
388        assert_eq!(what.sha256.len(), 64, "{}", what.sha256);
389        assert!(
390            what.sha256.bytes().all(|b| b.is_ascii_digit() || (b'a'..=b'f').contains(&b)),
391            "{} is not lowercase hex",
392            what.sha256
393        );
394        assert_eq!(pinned_for(what.tuple), None);
395    }
396}