rucc_sysroot/layout.rs
1//! The directory layout of one target's sysroot, and the cache key that names it.
2//!
3//! Design: `spec/cross-compile/08-sysroots.md` sections 8.2 and 8.3.
4//!
5//! # Why the directories are split the way they are
6//!
7//! Section 8.3 is about a multiplication. Headers are naively `arch x os x libc x libc-version`
8//! trees, which for glibc alone is eight architectures times six versions and several hundred
9//! megabytes, and `spec/cross-compile/13-distribution.md` has a size budget that number destroys.
10//!
11//! The fix is two splits that turn the product into a sum. The per version differences go inside
12//! the files as `#if __GLIBC_MINOR__ >= n`, so one tree serves every version. The per architecture
13//! differences stay in directories, because they are whole files rather than lines, but only for
14//! the small part of a libc that has any: `bits/` and a handful of others. Everything else is one
15//! copy.
16//!
17//! That is why a sysroot here has two include directories rather than one. [`Sysroot::arch_include`]
18//! holds the files that differ by architecture and is searched first, and
19//! [`Sysroot::generic_include`] holds the copy that every architecture shares.
20//!
21//! A Linux target searches four directories and not two, because the kernel's headers are a second
22//! pair with the same split and a different owner. They are [`Kernel`], their root is the cache
23//! rather than a sysroot, and the order is the libc's two and then the kernel's two, which is the
24//! order `zig cc -E -v` prints for a glibc target. `linux/` and `asm/` are nine megabytes of files
25//! that are the same for every target, so one tree is shared and only `asm/` is copied per
26//! architecture.
27//!
28//! # Why the root is a function of the tuple
29//!
30//! `spec/cross-compile/02-the-goal.md` claim 5 asks for byte identical output from different hosts.
31//! A sysroot that lands in a directory named after the host, or after the day it was built, or
32//! after a hash of an absolute path, breaks that before anything is compiled. So the root is the
33//! cache directory the caller chose plus the canonical spelling of the tuple, and nothing else.
34//!
35//! The canonical spelling is the key rather than a hash of it because it is already unique, it is
36//! already a legal directory name, and a cache a person can read is a cache a person can debug. It
37//! carries the whole ten field model, so `x86_64-linux-gnu` and `x86_64-linux-gnu.2.28` are
38//! different directories, which is the point of `env_version` being in the tuple at all.
39
40use std::fmt;
41use std::path::{Path, PathBuf};
42
43use rucc_tuple::{Arch, DataModel, Endian, Env, Os, TargetTuple, Version};
44
45/// One target's sysroot: where its headers are, where its link inputs are, and where the record
46/// of what they are is.
47///
48/// Constructed rather than discovered. Nothing here checks that any of these directories exists,
49/// because the caller that is about to produce a sysroot needs the same answer as the caller that
50/// is about to read one, and a constructor that failed for an absent directory would give the
51/// first one nothing to create.
52#[derive(Debug, Clone, PartialEq, Eq)]
53pub struct Sysroot {
54 target: TargetTuple,
55 root: PathBuf,
56}
57
58impl Sysroot {
59 /// The sysroot for this target inside this cache directory.
60 ///
61 /// The path is `<cache>/sysroots/<canonical tuple>`. Two hosts running this with the same
62 /// cache directory and the same target get the same path, which is what makes the tuple a
63 /// cache key and is the reason `spec/cross-compile/03-target-model.md` section 3.2 admits a
64 /// field only when it changes how a call is made or a struct is laid out.
65 #[must_use]
66 pub fn in_cache(cache: &Path, target: TargetTuple) -> Self {
67 let root = cache.join("sysroots").join(target.to_canonical_string());
68 Sysroot { target, root }
69 }
70
71 /// A sysroot rooted at a directory the user named, with `--sysroot` or `-isysroot`.
72 ///
73 /// The layout below the root is the same, so a user who assembled a tree the way we lay one
74 /// out is served by every other method here. A user who did not is served by
75 /// [`Options::sysroot`](crate::Options::sysroot), which replaces step 3 of section 8.5
76 /// wholesale rather than assuming a shape.
77 #[must_use]
78 pub fn at(root: PathBuf, target: TargetTuple) -> Self {
79 Sysroot { target, root }
80 }
81
82 /// The target this sysroot is for.
83 #[must_use]
84 pub const fn target(&self) -> TargetTuple {
85 self.target
86 }
87
88 /// The directory everything else here is under.
89 #[must_use]
90 pub fn root(&self) -> &Path {
91 &self.root
92 }
93
94 /// The cache key, which is the canonical spelling of the tuple.
95 ///
96 /// The whole tuple and not a summary of it. A key that dropped `env_version` would serve a
97 /// sysroot built against glibc 2.28 to a target that pinned 2.34, and the failure would be a
98 /// missing symbol at link time on one machine and not on another.
99 #[must_use]
100 pub fn cache_key(&self) -> String {
101 self.target.to_canonical_string()
102 }
103
104 /// The headers that differ by architecture, which are searched before the generic ones.
105 ///
106 /// Section 8.3's second split. For musl this is `bits/`, which is a few dozen small files
107 /// against a few hundred shared ones, so the copy per architecture is cheap and the
108 /// alternative of one whole tree per architecture is not.
109 #[must_use]
110 pub fn arch_include(&self) -> PathBuf {
111 self.root.join("include").join(self.header_arch())
112 }
113
114 /// The headers every architecture shares, which is almost all of them.
115 #[must_use]
116 pub fn generic_include(&self) -> PathBuf {
117 self.root.join("include").join("generic")
118 }
119
120 /// The libc's include directories, in search order, most specific first.
121 ///
122 /// Two rather than four. A Linux target also needs the kernel's own headers, which are
123 /// [`Kernel`] and are not under this root, because they are the same files for every target
124 /// that shares an architecture and carrying a copy of them per tuple is nine megabytes times
125 /// the size of the table.
126 #[must_use]
127 pub fn includes(&self) -> Vec<PathBuf> {
128 vec![self.arch_include(), self.generic_include()]
129 }
130
131 /// The link inputs: the start files, the libc archive or its generated stubs, and the
132 /// compiler's own runtime for this target.
133 #[must_use]
134 pub fn lib(&self) -> PathBuf {
135 self.root.join("lib")
136 }
137
138 /// The manifest naming every input with its source, its hash and its licence.
139 ///
140 /// A file rather than a directory, and at the top rather than beside the libraries, because
141 /// the thing a person does with it is read it first.
142 #[must_use]
143 pub fn manifest_path(&self) -> PathBuf {
144 self.root.join("manifest")
145 }
146
147 /// The name the target's libc gives to its per architecture header directory.
148 ///
149 /// Not the architecture component of the canonical tuple, which carries a baseline the headers
150 /// do not care about: `armv7a-linux-musleabihf` and `armv5te-linux-musleabi` read the same
151 /// `arm` directory, because a header does not know which instructions the chip has. 32-bit x86
152 /// is `i386` in musl's source tree whatever the tuple spells it.
153 ///
154 /// # Why the libc is part of the answer
155 ///
156 /// The two libcs do not split their headers at the same place, and the name has to follow the
157 /// libc rather than a scheme of ours, because the producer installs what the libc's own build
158 /// system installs and the compiler has to look where that put it.
159 ///
160 /// musl splits per architecture and per ABI, which is what `arch/` in its source tree is, so
161 /// `x86_64`, `i386` and `x32` are three directories. glibc splits per architecture family and
162 /// handles the rest inside the files: one `x86` directory serves i386, x86-64 and x32, and 22
163 /// of the 31 files in its `bits/` branch on `__x86_64__`, `__ILP32__` or `__WORDSIZE` to do it,
164 /// starting with `bits/wordsize.h`. Checked against Zig 0.16, which ships twelve glibc
165 /// directories named after families and seventeen musl directories named after architectures.
166 ///
167 /// # The rule this is here to enforce
168 ///
169 /// An ILP32 ABI on a 64-bit architecture cannot read the LP64 headers. Every type that carries
170 /// a pointer or a `long` is a different size, and `x86_64-linux-gnux32` is the row that proves
171 /// it. For musl that is a separate directory, which is what the suffix below is. For glibc it
172 /// is a branch inside glibc's own files, so the directory is shared and the thing that checks
173 /// it is section 8.4's structural equivalence corpus rather than a path.
174 #[must_use]
175 pub fn header_arch(&self) -> &'static str {
176 if self.target.env() == Env::Gnu {
177 return self.header_family();
178 }
179 let narrow = self.target.data_model() == DataModel::Ilp32On64;
180 match (self.target.arch(), narrow) {
181 // x32 is what everyone calls it, including musl and glibc, so it does not get the
182 // suffix the rule below would give it.
183 (Arch::X86_64, true) => "x32",
184 (Arch::X86_64, false) => "x86_64",
185 (Arch::X86, _) => "i386",
186 (Arch::Aarch64 | Arch::Arm64Ec, true) => "aarch64_ilp32",
187 (Arch::Aarch64 | Arch::Arm64Ec, false) => "aarch64",
188 (Arch::Arm, _) => "arm",
189 (Arch::Riscv64, true) => "riscv64_ilp32",
190 (Arch::Riscv64, false) => "riscv64",
191 (Arch::Riscv32, _) => "riscv32",
192 (Arch::S390x, true) => "s390x_ilp32",
193 (Arch::S390x, false) => "s390x",
194 (Arch::PowerPc64, true) => "powerpc64_ilp32",
195 (Arch::PowerPc64, false) => "powerpc64",
196 (Arch::LoongArch64, true) => "loongarch64_ilp32",
197 (Arch::LoongArch64, false) => "loongarch64",
198 (Arch::Wasm32, _) => "wasm32",
199 }
200 }
201
202 /// The architecture family, which is how glibc names its per architecture header directory.
203 ///
204 /// The data model is not in it, on purpose, for the reason [`Sysroot::header_arch`] gives: the
205 /// family's files carry the branch themselves. `s390x` and `loongarch` are spelled the way
206 /// glibc's own `sysdeps` tree spells them, which is not the same shortening for both.
207 ///
208 /// # Why powerpc is the only family whose byte order is in the name
209 ///
210 /// The byte order is in the name exactly where the installed text depends on it, and that is one
211 /// family. Measured on glibc 2.44, by installing a family's headers twice with
212 /// `make install-headers` and diffing the two installs. `aarch64_be-linux-gnu` against
213 /// `aarch64-linux-gnu` is 474 files each and an empty diff, so one directory serves both orders.
214 /// `powerpc64-linux-gnu` against `powerpc64le-linux-gnu` is 474 files each and one file that
215 /// differs, `bits/long-double.h`, because little endian powerpc can redirect `long double` to
216 /// the float128 ABI and big endian powerpc cannot, so one install defines
217 /// `__LDOUBLE_REDIRECTS_TO_FLOAT128_ABI` as `(__LDBL_MANT_DIG__ == 113)` and the other defines
218 /// it as `0`. One directory for both orders would hand half of the powerpc rows a macro that is
219 /// wrong about their own ABI.
220 ///
221 /// The word size is not in the name, for powerpc either. The third run of the same experiment,
222 /// `powerpc-linux-gnu` against `powerpc64-linux-gnu` with the order held fixed, is 474 files
223 /// each and an empty diff, which is the x86 answer again: `bits/wordsize.h` is two files in
224 /// glibc's `sysdeps` tree for powerpc and they are byte identical, and both of them branch on
225 /// `__powerpc64__`. So the name is the family and the order and nothing else, which is why it is
226 /// `powerpc` and `powerpcle` rather than a spelling per width.
227 ///
228 /// `bits/endianness.h` is not the reason, which is worth saying because it reads like the
229 /// obvious one and tamnd/rucc#940 was written around it. glibc's copies of that file for arm,
230 /// aarch64 and powerpc branch on `__BIG_ENDIAN__` and `_BIG_ENDIAN` inside the file, the same
231 /// way `bits/wordsize.h` branches on `__x86_64__`, so both orders install the same text into it.
232 /// musl 1.2.5 does the same in `bits/alltypes.h` and `bits/signal.h` and ships no per order
233 /// directory under `arch/` at all, which is why [`Sysroot::header_arch`]'s musl names carry no
234 /// order either.
235 fn header_family(&self) -> &'static str {
236 match (self.target.arch(), self.target.endian()) {
237 (Arch::X86_64 | Arch::X86, _) => "x86",
238 // Arm64EC is a Windows ABI and never has glibc headers. It answers with the family it
239 // belongs to rather than with a word that is not a directory anywhere.
240 (Arch::Aarch64 | Arch::Arm64Ec, _) => "aarch64",
241 (Arch::Arm, _) => "arm",
242 (Arch::Riscv64 | Arch::Riscv32, _) => "riscv",
243 (Arch::S390x, _) => "s390x",
244 // `powerpc` is the big endian directory because that is the name glibc's own `sysdeps`
245 // tree uses and big endian is what the bare spelling means everywhere in this tuple
246 // model. `powerpcle` is the GNU spelling of the other one.
247 (Arch::PowerPc64, Endian::Big) => "powerpc",
248 (Arch::PowerPc64, Endian::Little) => "powerpcle",
249 (Arch::LoongArch64, _) => "loongarch",
250 // There is no glibc for wasm. The arm of the match exists because the type is closed
251 // and a wildcard here would quietly name a directory for a future architecture.
252 (Arch::Wasm32, _) => "wasm32",
253 }
254 }
255}
256
257/// The kernel's own headers, which are not the libc's and are shared by every target that can read
258/// them.
259///
260/// `linux/` and `asm/` are the system call interface rather than the C library, and a sysroot
261/// without them does not compile 31 of glibc's installed headers or 3 of musl's, `sys/quota.h` and
262/// `net/ethernet.h` among them. So they are part of what section 8.2 calls a sysroot even though no
263/// libc produced them.
264///
265/// # Why they are not under [`Sysroot`]
266///
267/// One tree serves every libc and every architecture except `asm/`, which is per architecture and
268/// small. Copying the shared part into each tuple's sysroot would be nine megabytes times the
269/// number of Linux rows in the table, for files that are identical in every copy. So the root is
270/// the cache directory rather than a sysroot, and a sysroot that was produced with it records the
271/// version in its manifest, which is [`crate::Manifest::kernel`] and the `kernel` line of the
272/// format. The tree carries its own record as well, headed `rucc kernel headers manifest 1`, because
273/// one tree serves every target and a sysroot manifest names one. Nothing checks the two against
274/// each other: a sysroot can be produced beside one tree and read beside another, and the manifest
275/// makes that visible rather than preventing it.
276///
277/// # Why the version is not in the path
278///
279/// The driver has to be able to compute this path before it reads anything, and a version in the
280/// path would mean asking the cache what it has before being able to ask where it is. It is the
281/// same decision [`Sysroot::in_cache`] makes about the libc version, where the tuple carries the
282/// version only because `env_version` is part of the target's identity, and the same gap: a cache
283/// populated by one release and read by the next gets whatever is there.
284/// `spec/cross-compile/13-distribution.md` section 13.2 owns that, because the answer is the
285/// content hash in the cache layout and it belongs to both.
286#[derive(Debug, Clone, PartialEq, Eq)]
287pub struct Kernel {
288 arch: &'static str,
289 root: PathBuf,
290}
291
292impl Kernel {
293 /// The kernel headers in this cache directory for this target, when the target has any.
294 ///
295 /// [`None`] for everything that is not Linux with a libc we produce a tree for. Windows, the
296 /// BSDs and Darwin have their own system headers and no `linux/` at all, freestanding has no
297 /// system call interface by definition, and Android is Linux but bionic carries its own
298 /// scrubbed copy of the uapi headers, which is a different tree from this one and not a subset
299 /// of it.
300 #[must_use]
301 pub fn for_target(cache: &Path, target: TargetTuple) -> Option<Kernel> {
302 if target.os() != Os::Linux || !matches!(target.env(), Env::Gnu | Env::Musl) {
303 return None;
304 }
305 let arch = kernel_arch(target.arch())?;
306 Some(Kernel { arch, root: cache.join("kernel-headers") })
307 }
308
309 /// The directory both of these are under.
310 #[must_use]
311 pub fn root(&self) -> &Path {
312 &self.root
313 }
314
315 /// `asm/`, which is the part of the interface that is per architecture.
316 ///
317 /// Named after the kernel's own architecture directory and not after ours or the libc's, which
318 /// is a third spelling of the same machine and the reason this is a method rather than a format
319 /// string at the call site.
320 #[must_use]
321 pub fn arch_include(&self) -> PathBuf {
322 self.root.join(self.arch)
323 }
324
325 /// `linux/`, `asm-generic/` and the rest, which are the same files for every architecture.
326 #[must_use]
327 pub fn generic_include(&self) -> PathBuf {
328 self.root.join("generic")
329 }
330
331 /// Both directories, in search order, most specific first.
332 #[must_use]
333 pub fn includes(&self) -> Vec<PathBuf> {
334 vec![self.arch_include(), self.generic_include()]
335 }
336
337 /// The kernel's name for this architecture.
338 #[must_use]
339 pub const fn arch(&self) -> &'static str {
340 self.arch
341 }
342}
343
344/// What `make headers_install ARCH=` takes, which is a third naming of the machine.
345///
346/// `arm64` rather than `aarch64` and `s390` rather than `s390x`, because those are the directories
347/// under `arch/` in the kernel's source tree, and the 31-bit s390 port leaving did not rename the
348/// one that stayed. One directory serves both widths of x86, of riscv and of powerpc, the same way
349/// glibc's family does and for the same reason: the uapi headers branch on the compiler's macros.
350///
351/// [`None`] for an architecture the kernel does not have, which is wasm.
352const fn kernel_arch(arch: Arch) -> Option<&'static str> {
353 match arch {
354 Arch::X86_64 | Arch::X86 => Some("x86"),
355 Arch::Aarch64 | Arch::Arm64Ec => Some("arm64"),
356 Arch::Arm => Some("arm"),
357 Arch::Riscv64 | Arch::Riscv32 => Some("riscv"),
358 Arch::S390x => Some("s390"),
359 Arch::PowerPc64 => Some("powerpc"),
360 Arch::LoongArch64 => Some("loongarch"),
361 Arch::Wasm32 => None,
362 }
363}
364
365/// Whether we can produce a sysroot for this target without the user fetching anything.
366///
367/// Section 8.2's table has seven rows and two of them are legal walls rather than engineering.
368/// The macOS SDK is restricted by the Xcode licence to Apple-branded hardware and the Windows SDK
369/// is not redistributable, so for those two the answer is a path the user supplies under their own
370/// licence, and `spec/cross-compile/13-distribution.md` owns the mechanism.
371///
372/// This returns false for those two and true for everything else, including freestanding, which
373/// needs nine compiler headers and no link inputs at all.
374#[must_use]
375pub fn can_be_bundled(target: TargetTuple) -> bool {
376 !matches!(target.os(), Os::MacOs | Os::IOs) && target.env() != Env::Msvc
377}
378
379/// The glibc our bundled header tree is derived from.
380///
381/// A fact about the tree and not a choice. `sysroots/manifest` in `tamnd/rucc-cross` pins the glibc
382/// source by version and hash, the tree is produced from that source, and this is that version. It
383/// moves when the pin moves and the two are checked against each other by the producer.
384pub const BUNDLED_GLIBC: Version = Version::new(2, 44);
385
386/// The `__GLIBC_MINOR__` a target gets when it is compiled against the bundled glibc tree.
387///
388/// Design: `spec/cross-compile/08-sysroots.md` section 8.3.
389///
390/// One tree serves every glibc release, with the differences written inside the files as
391/// `#if __GLIBC_MINOR__ >= n`, so the release is the part of it the target supplies. That is Zig's
392/// patch to the same tree and the same macro, which is where the spelling comes from: `features.h`
393/// keeps `__GLIBC__` at 2 and leaves the minor to the compiler, and `__GLIBC_PREREQ` reads both.
394///
395/// [`None`] for anything that is not glibc, because there is no such macro on musl or mingw and
396/// defining one would have every probe for it answer yes on a libc that does not have it.
397///
398/// The version is the one the tuple asked for, which is the point of `env_version` being in the
399/// tuple, and [`BUNDLED_GLIBC`] when it asked for nothing. Asking for an older release is how a
400/// program is kept off symbols and declarations the target's libc does not have, and it is honest
401/// only as far as the text goes: the declarations are guarded by the macro and the structure
402/// layouts in the same files are one release's. Issue #926's last box is where that is finished and
403/// it is the same direction as the compat symbol gap of #920, too permissive rather than wrong
404/// about what it does say.
405///
406/// # Errors
407///
408/// A release newer than the tree, which is the one direction that cannot be approximated. Every
409/// `__GLIBC_PREREQ` in the program would answer yes and the declarations behind them would not be
410/// there, so the failure would be a missing declaration at best and a missing symbol at link time
411/// at worst. Both versions are in the error, because the two things a person can do about it are
412/// pin a release the tree has and name a sysroot that has the one they asked for, and neither is a
413/// choice they can make without being told which release the tree is.
414pub fn bundled_glibc_minor(target: TargetTuple) -> Result<Option<u32>, GlibcSkew> {
415 if target.os() != Os::Linux || target.env() != Env::Gnu {
416 return Ok(None);
417 }
418 let Some(asked) = target.env_version() else {
419 return Ok(Some(BUNDLED_GLIBC.minor_part().unwrap_or(0)));
420 };
421 // A glibc version is two components and a tuple will hold one or three, so a request this
422 // cannot read as a glibc release is a request for the tree's own version rather than an error:
423 // `gnu.2` is somebody naming the libc and not pinning it.
424 let Some(minor) = asked.minor_part() else {
425 return Ok(Some(BUNDLED_GLIBC.minor_part().unwrap_or(0)));
426 };
427 if asked.major_part() != BUNDLED_GLIBC.major_part()
428 || minor > BUNDLED_GLIBC.minor_part().unwrap_or(0)
429 {
430 return Err(GlibcSkew { asked, tree: BUNDLED_GLIBC });
431 }
432 Ok(Some(minor))
433}
434
435/// A glibc release the bundled tree cannot serve, and the release the tree is.
436///
437/// A type rather than a pair, because the two versions read the same way round in the message as
438/// they do here and a caller that swapped them would produce a diagnostic exactly as wrong as it is
439/// convincing.
440#[derive(Debug, Clone, Copy, PartialEq, Eq)]
441pub struct GlibcSkew {
442 /// What the target asked for.
443 pub asked: Version,
444 /// What the bundled tree is, which is [`BUNDLED_GLIBC`].
445 pub tree: Version,
446}
447
448impl fmt::Display for GlibcSkew {
449 fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
450 write!(
451 f,
452 "the target asked for glibc {}, and the bundled headers are glibc {}",
453 self.asked, self.tree
454 )
455 }
456}
457
458impl std::error::Error for GlibcSkew {}