2222
2323distributable :
2424 url : git+https://github.com/tianocore/edk2
25- ref : edk2-stable {{version.raw }}
25+ ref : $ {{version.tag }}
2626
2727versions :
2828 github : tianocore/edk2/tags
@@ -31,26 +31,25 @@ versions:
3131
3232build :
3333 dependencies :
34- git-scm.org : ' * '
34+ git-scm.org : " * "
3535 python.org : ~3.11
36- nasm.us : ' *'
37- freedesktop.org/pkg-config : ' *'
36+ nasm.us : " *"
3837 # iasl (ACPI compiler) — EDK II compiles `.asl` ACPI tables to `.aml`
3938 # for several modules (RamDiskDxe's NFIT, etc.). It is not in qemu's
4039 # toolchain, so without this the X64 build dies with
4140 # `iasl: command not found` (exit 127) on every platform.
42- acpica.org : ' * '
41+ acpica.org : " * "
4342 linux :
44- gnu.org/gcc : ' * '
43+ gnu.org/gcc : " * "
4544 # BaseTools' GenFv #includes <uuid/uuid.h> and links -luuid; on
4645 # Linux that comes from util-linux's libuuid (on darwin it's in the
4746 # SDK). Without it the BaseTools build fails:
4847 # `GenFvInternalLib.c: fatal error: uuid/uuid.h: No such file`.
49- github.com/util-linux/util-linux : ' * '
48+ github.com/util-linux/util-linux : " * "
5049 darwin :
5150 # CLANGPDB toolchain emits PE/COFF directly via lld-link, avoiding
5251 # the macOS-only `mtoc` that XCODE5 requires.
53- llvm.org : ' * '
52+ llvm.org : 19
5453 env :
5554 darwin :
5655 # EDK II's CLANGPDB toolchain calls clang/lld-link as
@@ -60,173 +59,91 @@ build:
6059 # non-existent /usr/bin/lld-link → `lld-link: No such file`. Using
6160 # the dep prefix (not `which clang`) avoids resolving to that shim.
6261 CLANG_BIN : " {{deps.llvm.org.prefix}}/bin/"
62+ TC : CLANGPDB
63+ linux :
64+ TC : GCC
65+ x86-64 :
66+ NATIVE_FW : " {{prefix}}/share/qemu/edk2-x86_64-code.fd"
67+ HOST_ARCH : X64
68+ aarch64 :
69+ NATIVE_FW : " {{prefix}}/share/qemu/edk2-aarch64-code.fd"
70+ HOST_ARCH : AARCH64
71+ WORKSPACE : " $SRCROOT"
72+ EDK_TOOLS_PATH : " $SRCROOT/BaseTools"
73+ CONF_PATH : " $SRCROOT/Conf"
6374 script :
64- - run : |
65- set -e
66-
67- # Brewkit checks out git+ sources to ${PKGX_PANTRY_PATH}/srcs/...
68- # and rsyncs once into ${SRCROOT}. After a manual `rm -rf builds`
69- # the re-stage may skip the copy (only rsyncs `props/`), leaving
70- # cwd empty. Repopulate from srcs/ if needed.
71- SRC_DIR="${PKGX_PANTRY_PATH}/srcs/$(basename "$SRCROOT")"
72- if [ ! -d ./BaseTools ] && [ -d "$SRC_DIR/BaseTools" ]; then
73- echo "edk2: repopulating build dir from $SRC_DIR"
74- cp -a "$SRC_DIR/." ./
75- fi
76-
77- # EDK II pulls a pinned OpenSSL via submodule (CryptoPkg) and a
78- # handful of others (BrotliCustomDecompressLib, MipiSysTLib, …).
79- # We need them for SecureBoot-capable OVMF builds.
80- git submodule update --init --recursive --depth 1
81-
82- # BaseTools — the C helpers (GenFv, GenFw, …) used by the build.
83- #
84- # Built SERIALLY on purpose. The VfrCompile sub-makefile has a
85- # missing dependency between the `dlg`-generated VfrLexer.cpp and
86- # its own compile step; under `make -j` the compiler races the
87- # generator and reads a half-written file, failing with
88- # `VfrLexer.cpp: error: expected expression`. With many cores
89- # (CI runners) the race is near-deterministic, which is why every
90- # platform's build was red. Serial BaseTools is quick (~1-2 min)
91- # and the EDK II `build` below is still fully parallel via `-n`.
92- make -C BaseTools
93-
94- # edksetup.sh is bash-only and expects to be sourced from $PWD.
95- export WORKSPACE="$PWD"
96- export EDK_TOOLS_PATH="$PWD/BaseTools"
97- export CONF_PATH="$PWD/Conf"
98- . ./edksetup.sh BaseTools
99-
100- # EDK II's toolchain tag is platform-specific:
101- # GCC → Linux gcc/clang, ld.bfd or ld.lld. (Modern EDK II
102- # dropped the old GCC5/GCC49/... family tags in favour
103- # of a single GCC; edk2-stable202605's tools_def only
104- # ships *_GCC_*, so GCC5 errors `[GCC5] not defined`.)
105- # CLANGPDB → cross-platform clang + lld-link → PE/COFF directly
106- # (used on Darwin to skip the macOS-only mtoc hop)
107- case "$(uname -s)" in
108- Darwin) TC=CLANGPDB ;;
109- *) TC=GCC ;;
110- esac
111- echo "edk2: using toolchain tag $TC (CLANG_BIN=${CLANG_BIN:-unset})"
112-
113- # Recent clang (>=20) tightens -Wcast-function-type-mismatch, which
114- # trips OpenSSL's pem_password_cb casts in CryptoPkg/BaseCryptLib.
115- # EDK II compiles with -Werror, so soften that one warning. We
116- # also relax a couple of other newer-clang diagnostics that
117- # surface in third-party submodules (OpenSSL, MipiSysT).
118- if [ -f Conf/tools_def.txt ]; then
119- EXTRA="-Wno-error=cast-function-type-mismatch -Wno-error=incompatible-function-pointer-types -Wno-error=unused-but-set-variable -Wno-error=deprecated-declarations"
120- # Append EXTRA to every CC_FLAGS line for the active toolchain.
121- sed -i.bak -E \
122- "s@^([[:space:]]*(DEBUG|RELEASE|NOOPT)_${TC}_[A-Z0-9]+_CC_FLAGS[[:space:]]*=.*)\$@\\1 ${EXTRA}@" \
123- Conf/tools_def.txt
124- # Count patched lines in two steps — a `$(grep …"(…)"…)` nested
125- # inside an `echo "…"` tripped a parse error (`unexpected token
126- # (`) on the darwin runner's shell. `grep -c` returns 1 when it
127- # matches nothing, so guard with `|| true` under `set -e`.
128- patched=$(grep -cE "^[[:space:]]*(DEBUG|RELEASE|NOOPT)_${TC}_[A-Z0-9]+_CC_FLAGS.*cast-function-type-mismatch" Conf/tools_def.txt || true)
129- echo "edk2: patched ${patched} ${TC} CC_FLAGS lines"
130-
131- # CryptoPkg overrides CC_FLAGS in its DSC, so the tools_def
132- # patch isn't enough — patch the source file directly to
133- # silence the two pem_password_cb casts that newer clang
134- # rejects with -Wcast-function-type-mismatch.
135- CRYPT_PEM="CryptoPkg/Library/BaseCryptLib/Pem/CryptPem.c"
136- if [ -f "$CRYPT_PEM" ] && ! grep -q "clang diagnostic.*cast-function-type-mismatch" "$CRYPT_PEM"; then
137- {
138- printf '%s\n' '#if defined(__clang__)'
139- printf '%s\n' '#pragma clang diagnostic push'
140- printf '%s\n' '#pragma clang diagnostic ignored "-Wcast-function-type-mismatch"'
141- printf '%s\n' '#endif'
142- cat "$CRYPT_PEM"
143- printf '%s\n' '#if defined(__clang__)'
144- printf '%s\n' '#pragma clang diagnostic pop'
145- printf '%s\n' '#endif'
146- } > "$CRYPT_PEM.new"
147- mv "$CRYPT_PEM.new" "$CRYPT_PEM"
148- echo "edk2: patched $CRYPT_PEM for -Wcast-function-type-mismatch"
149- fi
150- fi
75+ # EDK II pulls a pinned OpenSSL via submodule (CryptoPkg) and a
76+ # handful of others (BrotliCustomDecompressLib, MipiSysTLib, …).
77+ # We need them for SecureBoot-capable OVMF builds.
78+ - git submodule update --init --recursive --depth 1
15179
152- mkdir -p "{{prefix}}/share/qemu"
153-
154- # Build both QEMU firmware targets. The host-native arch always
155- # builds; the foreign arch needs a cross-compiler. clang (darwin
156- # CLANGPDB) cross-compiles freely, so darwin bottles carry both
157- # blobs. GCC on Linux only targets its own arch — the X64 OvmfPkg
158- # build feeds x86-only flags (-m64, -mno-red-zone, -mno-sse, …) to
159- # gcc, which a native aarch64 gcc rejects (and vice-versa). So each
160- # target is best-effort; we require the host-native blob at the end.
161- HOST_ARCH="$(uname -m)"
162-
163- # ── X64 (amd64) → edk2-x86_64-code.fd / edk2-i386-vars.fd ──
164- if build -a X64 -t "$TC" -b RELEASE \
165- -p OvmfPkg/OvmfPkgX64.dsc \
166- -D SECURE_BOOT_ENABLE=TRUE \
167- -D TPM2_ENABLE=TRUE \
168- -D NETWORK_IP6_ENABLE=TRUE \
169- -D NETWORK_HTTP_BOOT_ENABLE=TRUE \
170- -n {{ hw.concurrency }}; then
171- OUT_X64="Build/OvmfX64/RELEASE_${TC}/FV"
172- install -m 0644 "$OUT_X64/OVMF_CODE.fd" "{{prefix}}/share/qemu/edk2-x86_64-code.fd"
173- install -m 0644 "$OUT_X64/OVMF_VARS.fd" "{{prefix}}/share/qemu/edk2-i386-vars.fd"
174- # Combined CODE+VARS image (qemu `-bios` style).
175- if [ -f "$OUT_X64/OVMF.fd" ]; then
176- install -m 0644 "$OUT_X64/OVMF.fd" "{{prefix}}/share/qemu/edk2-x86_64.fd"
177- fi
178- else
179- echo "edk2: X64 build failed — expected when cross-compiling from a non-x86_64 host with GCC; continuing"
180- fi
181-
182- # ── AARCH64 (arm64) → edk2-aarch64-code.fd / edk2-arm-vars.fd ──
183- # ArmVirtQemu emits QEMU_EFI.fd + QEMU_VARS.fd.
184- if build -a AARCH64 -t "$TC" -b RELEASE \
185- -p ArmVirtPkg/ArmVirtQemu.dsc \
186- -D NETWORK_HTTP_BOOT_ENABLE=TRUE \
187- -n {{ hw.concurrency }}; then
188- # ArmVirtQemu.dsc names its output dir `ArmVirtQemu-AArch64`
189- # (mixed case, from the DSC, not the -a flag). Hardcoding
190- # `AARCH64` worked on darwin's case-insensitive FS but `install`
191- # couldn't find it on case-sensitive Linux — glob it instead.
192- OUT_AARCH64=$(ls -d Build/ArmVirtQemu-*/RELEASE_${TC}/FV 2>/dev/null | head -1)
193- install -m 0644 "$OUT_AARCH64/QEMU_EFI.fd" "{{prefix}}/share/qemu/edk2-aarch64-code.fd"
194- install -m 0644 "$OUT_AARCH64/QEMU_VARS.fd" "{{prefix}}/share/qemu/edk2-arm-vars.fd"
195- else
196- echo "edk2: AARCH64 build failed — expected when cross-compiling from a non-arm64 host with GCC; continuing"
197- fi
198-
199- # A bottle with no firmware for its own host arch is a hard fail.
200- case "$HOST_ARCH" in
201- x86_64) NATIVE_FW="{{prefix}}/share/qemu/edk2-x86_64-code.fd" ;;
202- arm64|aarch64) NATIVE_FW="{{prefix}}/share/qemu/edk2-aarch64-code.fd" ;;
203- *) NATIVE_FW="" ;;
80+ # BaseTools — the C helpers (GenFv, GenFw, …) used by the build.
81+ #
82+ # Built SERIALLY on purpose. The VfrCompile sub-makefile has a
83+ # missing dependency between the `dlg`-generated VfrLexer.cpp and
84+ # its own compile step; under `make -j` the compiler races the
85+ # generator and reads a half-written file, failing with
86+ # `VfrLexer.cpp: error: expected expression`. With many cores
87+ # (CI runners) the race is near-deterministic, which is why every
88+ # platform's build was red. Serial BaseTools is quick (~1-2 min)
89+ # and the EDK II `build` below is still fully parallel via `-n`.
90+ - make -C BaseTools
91+
92+ # edksetup.sh is bash-only and expects to be sourced from $PWD.
93+
94+ - . ./edksetup.sh BaseTools
95+
96+ # ── X64 (amd64) → edk2-x86_64-code.fd / edk2-i386-vars.fd ──
97+ - if test "{{hw.platform}}+{{hw.arch}}" != "linux+aarch64"; then
98+ - build -a X64 -t "$TC" -b RELEASE
99+ -p OvmfPkg/OvmfPkgX64.dsc
100+ -D SECURE_BOOT_ENABLE=TRUE
101+ -D TPM2_ENABLE=TRUE
102+ -D NETWORK_IP6_ENABLE=TRUE
103+ -D NETWORK_HTTP_BOOT_ENABLE=TRUE
104+ -n {{ hw.concurrency }}
105+
106+ - find Build/OvmfX64 -name OVMF_CODE.fd -exec install -Dm0664 {} {{prefix}}/share/qemu/edk2-x86_64-code.fd \;
107+ - find Build/OvmfX64 -name OVMF_VARS.fd -exec install -Dm0664 {} {{prefix}}/share/qemu/edk2-i386-vars.fd \;
108+ # install if found
109+ - find Build/OvmfX64 -name OVMF.fd -exec install -Dm0664 {} {{prefix}}/share/qemu/edk2-x86_64.fd \; || true
110+
111+ - fi # !linux/aarch64
112+
113+ # ── AARCH64 (arm64) → edk2-aarch64-code.fd / edk2-arm-vars.fd ──
114+ # ArmVirtQemu emits QEMU_EFI.fd + QEMU_VARS.fd.
115+ - if test "{{hw.platform}}+{{hw.arch}}" != "linux+x86-64"; then
116+
117+ - build -a AARCH64 -t "$TC" -b RELEASE
118+ -p ArmVirtPkg/ArmVirtQemu.dsc
119+ -D NETWORK_HTTP_BOOT_ENABLE=TRUE
120+ -n {{ hw.concurrency }}
121+ # ArmVirtQemu.dsc names its output dir `ArmVirtQemu-AArch64`
122+ # (mixed case, from the DSC, not the -a flag). Hardcoding
123+ # `AARCH64` worked on darwin's case-insensitive FS but `install`
124+ # couldn't find it on case-sensitive Linux — glob it instead.
125+ - find Build/ArmVirtQemu* -name QEMU_EFI.fd -exec install -Dm0664 {} {{prefix}}/share/qemu/edk2-aarch64-code.fd \;
126+ - find Build/ArmVirtQemu* -name QEMU_VARS.fd -exec install -Dm0664 {} {{prefix}}/share/qemu/edk2-arm-vars.fd \;
127+
128+ - fi # !linux/x86-64
129+
130+ # Thin shim so pkgx has at least one `bin/*` entry to advertise
131+ # and so downstream tooling can discover the blob directory
132+ # without sourcing env vars.
133+ - run : install -Dm755 $PROP {{prefix}}/bin/edk2-firmware-path
134+ prop : |
135+ #!/bin/sh
136+ # Print the absolute path to an EDK II firmware blob.
137+ # Usage: edk2-firmware-path [x86_64-code|i386-vars|aarch64-code|arm-vars|dir]
138+ dir="$(cd "$(dirname "$0")/../share/qemu" && pwd)"
139+ case "${1:-dir}" in
140+ dir) echo "$dir" ;;
141+ x86_64-code|amd64-code) echo "$dir/edk2-x86_64-code.fd" ;;
142+ i386-vars|amd64-vars) echo "$dir/edk2-i386-vars.fd" ;;
143+ aarch64-code|arm64-code) echo "$dir/edk2-aarch64-code.fd" ;;
144+ arm-vars|arm64-vars) echo "$dir/edk2-arm-vars.fd" ;;
145+ *) echo "unknown firmware key: $1" >&2; exit 2 ;;
204146 esac
205- if [ -n "$NATIVE_FW" ] && [ ! -s "$NATIVE_FW" ]; then
206- echo "edk2: FATAL — host-native firmware $NATIVE_FW was not produced" >&2
207- exit 1
208- fi
209-
210- # Thin shim so pkgx has at least one `bin/*` entry to advertise
211- # and so downstream tooling can discover the blob directory
212- # without sourcing env vars.
213- mkdir -p "{{prefix}}/bin"
214- shim="{{prefix}}/bin/edk2-firmware-path"
215- {
216- printf '%s\n' '#!/bin/sh'
217- printf '%s\n' '# Print the absolute path to an EDK II firmware blob.'
218- printf '%s\n' '# Usage: edk2-firmware-path [x86_64-code|i386-vars|aarch64-code|arm-vars|dir]'
219- printf '%s\n' 'dir="$(cd "$(dirname "$0")/../share/qemu" && pwd)"'
220- printf '%s\n' 'case "${1:-dir}" in'
221- printf '%s\n' ' dir) echo "$dir" ;;'
222- printf '%s\n' ' x86_64-code|amd64-code) echo "$dir/edk2-x86_64-code.fd" ;;'
223- printf '%s\n' ' i386-vars|amd64-vars) echo "$dir/edk2-i386-vars.fd" ;;'
224- printf '%s\n' ' aarch64-code|arm64-code) echo "$dir/edk2-aarch64-code.fd" ;;'
225- printf '%s\n' ' arm-vars|arm64-vars) echo "$dir/edk2-arm-vars.fd" ;;'
226- printf '%s\n' ' *) echo "unknown firmware key: $1" >&2; exit 2 ;;'
227- printf '%s\n' 'esac'
228- } > "$shim"
229- chmod +x "$shim"
230147
231148provides :
232149 - bin/edk2-firmware-path
@@ -242,11 +159,11 @@ runtime:
242159
243160test :
244161 dependencies :
245- qemu.org : ' * '
162+ qemu.org : " * "
246163 # `timeout` is GNU coreutils — present on Linux runners but NOT on
247164 # macOS, where the test would otherwise die with `timeout: command
248165 # not found`.
249- gnu.org/coreutils : ' * '
166+ gnu.org/coreutils : " * "
250167 script :
251168 # Boot whichever firmware blobs this bottle shipped, each under its
252169 # matching qemu, and confirm UEFI reaches the Boot Manager (BdsDxe)
@@ -258,36 +175,28 @@ test:
258175 # on our pipe. Do NOT add `-nographic`: it also grabs stdio for the
259176 # monitor and qemu aborts ("cannot use stdio by multiple character
260177 # devices").
261- - |
262- Q="{{prefix}}/share/qemu"
263- tested=0
264- booted() { grep -q -E "(TianoCore|EDK II|UEFI Interactive Shell|BdsDxe)" "$1"; }
265-
266- # x86_64 firmware (x86_64 hosts + all darwin)
267- if [ -s "$Q/edk2-x86_64-code.fd" ]; then
268- cp "$Q/edk2-i386-vars.fd" vars-x64.fd
269- timeout 90 qemu-system-x86_64 \
270- -machine q35,accel=tcg -m 256 \
271- -drive if=pflash,format=raw,readonly=on,file="$Q/edk2-x86_64-code.fd" \
272- -drive if=pflash,format=raw,file=vars-x64.fd \
273- -display none -no-reboot -serial stdio > boot-x64.log 2>&1 || true
274- if booted boot-x64.log; then echo "x86_64 firmware reached BdsDxe"; tested=1
275- else echo "x86_64 boot FAILED"; cat boot-x64.log; exit 1; fi
276- fi
277-
278- # aarch64 firmware (arm64 hosts + all darwin). ArmVirt pflash images
279- # must be 64MiB, so pad the copies.
280- if [ -s "$Q/edk2-aarch64-code.fd" ]; then
281- cp "$Q/edk2-aarch64-code.fd" code-a64.fd
282- cp "$Q/edk2-arm-vars.fd" vars-a64.fd
283- truncate -s 64m code-a64.fd vars-a64.fd
284- timeout 90 qemu-system-aarch64 \
285- -machine virt -cpu cortex-a57 -m 256 \
286- -drive if=pflash,format=raw,readonly=on,file=code-a64.fd \
287- -drive if=pflash,format=raw,file=vars-a64.fd \
288- -display none -no-reboot -serial stdio > boot-a64.log 2>&1 || true
289- if booted boot-a64.log; then echo "aarch64 firmware reached BdsDxe"; tested=1
290- else echo "aarch64 boot FAILED"; cat boot-a64.log; exit 1; fi
291- fi
292178
293- [ "$tested" = 1 ] || { echo "no firmware blob was present to test"; exit 1; }
179+ - test "$(edk2-firmware-path dir)" = "{{prefix}}/share/qemu"
180+
181+ # x86_64 firmware (x86_64 hosts + all darwin)
182+ - if test "{{hw.platform}}+{{hw.arch}}" != "linux+aarch64"; then
183+ - ( timeout 90 qemu-system-x86_64 -machine q35,accel=tcg -m 256
184+ -drive if=pflash,format=raw,readonly=on,file="$(edk2-firmware-path x86_64-code)"
185+ -drive if=pflash,format=raw,file="$(edk2-firmware-path i386-vars)"
186+ -display none -no-reboot -serial stdio 2>&1 | tee boot-x64.log ) || true
187+ - grep -E "(TianoCore|EDK II|UEFI Interactive Shell|BdsDxe)" boot-x64.log
188+ - fi
189+
190+ # aarch64 firmware (arm64 hosts + all darwin). ArmVirt pflash images
191+ # must be 64MiB, so pad the copies.
192+ - if test "{{hw.platform}}+{{hw.arch}}" != "linux+x86-64"; then
193+ - cp "$(edk2-firmware-path aarch64-code)" code-a64.fd
194+ - cp "$(edk2-firmware-path arm-vars)" vars-a64.fd
195+ - truncate -s 64m code-a64.fd vars-a64.fd
196+ - ( timeout 90 qemu-system-aarch64
197+ -machine virt -cpu cortex-a57 -m 256
198+ -drive if=pflash,format=raw,readonly=on,file=code-a64.fd
199+ -drive if=pflash,format=raw,file=vars-a64.fd
200+ -display none -no-reboot -serial stdio 2>&1 | tee boot-a64.log ) || true
201+ - grep -E "(TianoCore|EDK II|UEFI Interactive Shell|BdsDxe)" boot-a64.log
202+ - fi
0 commit comments