diff --git a/README.md b/README.md index 41b82bf..80d9ba6 100644 --- a/README.md +++ b/README.md @@ -44,6 +44,19 @@ For macOS: xcode-select --install ``` +`cargo-hyperlight` 0.1.14 searches `PATH` for `llvm-ar`; otherwise it may find +Apple's incompatible archiver. Add a provisioned compatible LLVM installation +to `PATH`, or add the active Rust toolchain's LLVM directory: + +```bash + export PATH="$(rustc --print sysroot)/lib/rustlib/$(rustc -vV | sed -n 's/^host: //p')/bin:$PATH" +``` + +```powershell + $hostTriple = (rustc -vV | Select-String '^host: ').Line.Substring(6) + $env:Path = "$(rustc --print sysroot)\lib\rustlib\$hostTriple\bin;$env:Path" +``` + In addition on Linux and macOS you will need to install the bare-metal target matching your architecture, which `cargo-hyperlight` derives the guest target from: diff --git a/src/hyperlight-js/build.rs b/src/hyperlight-js/build.rs index 6efa73f..81845ff 100644 --- a/src/hyperlight-js/build.rs +++ b/src/hyperlight-js/build.rs @@ -45,7 +45,6 @@ fn main() { kvm: { all(feature = "kvm", target_os = "linux") }, mshv3: { all(feature = "mshv3", target_os = "linux") }, hvf: { all(feature = "hvf", target_os = "macos") }, - whp: { target_os = "windows" }, // hyperlight-host only implements crash dumps and the gdb debug stub on // x86_64, so mirror its aliases — otherwise enabling either feature on // aarch64 (e.g. macOS) would expose a wrapper around a method that does diff --git a/src/hyperlight-js/src/sandbox/monitor/cpu_time/macos.rs b/src/hyperlight-js/src/sandbox/monitor/cpu_time/macos.rs index 872aa5e..d56b9b0 100644 --- a/src/hyperlight-js/src/sandbox/monitor/cpu_time/macos.rs +++ b/src/hyperlight-js/src/sandbox/monitor/cpu_time/macos.rs @@ -36,6 +36,8 @@ pub(crate) struct ThreadCpuHandle { impl ThreadCpuHandle { pub(crate) fn for_current_thread() -> Option { + // SAFETY: Returns a new send right owned by this handle. Mach port names + // are task-wide, so the monitor thread may use the right to inspect this thread. let thread_port = unsafe { mach_thread_self() }; if thread_port == MACH_PORT_NULL { tracing::warn!("[CPU_TIME] mach_thread_self() returned a null port"); @@ -49,9 +51,14 @@ impl ThreadCpuHandle { } pub(crate) fn elapsed(&self) -> Option { + // SAFETY: thread_basic_info contains only integer C fields, for which all-zero + // bit patterns are valid; thread_info initializes the requested fields below. let mut info: libc::thread_basic_info = unsafe { std::mem::zeroed() }; let mut count = libc::THREAD_BASIC_INFO_COUNT; + // SAFETY: info is the structure required by THREAD_BASIC_INFO and count is its + // size in natural_t units. The task-wide send right remains valid until Drop, + // and Mach permits querying the represented thread from the monitor thread. let result = unsafe { libc::thread_info( self.thread_port, @@ -90,6 +97,8 @@ impl ThreadCpuHandle { impl Drop for ThreadCpuHandle { fn drop(&mut self) { if self.thread_port != MACH_PORT_NULL { + // SAFETY: Self exclusively owns the send right returned by mach_thread_self. + // ThreadCpuHandle is not Clone, and Drop consumes that right exactly once. unsafe { mach_port_deallocate(mach_task_self_, self.thread_port) }; } }