This is the Norwegian Digitalisation Agency's (Digdir) fork of libkrunfw, a library that bundles a Linux kernel so that libkrun can map it directly into a guest. It tracks superradcompany/libkrunfw, the libkrunfw fork that upstream Microsandbox builds from. See the upstream repository for the original documentation, including build instructions for every variant.
| Branch | Role |
|---|---|
main-digdir |
Default branch. The Digdir patch queue on top of the upstream commit that the Microsandbox release we build on pins. |
krunfw |
Mirror of upstream krunfw. Updated by fast-forward only and never contains Digdir changes. |
main-digdir is rebuilt onto a new upstream base when we move to a new Microsandbox release, so its history is
rewritten. Released firmware is identified by immutable tags (see RELEASE.md).
The fork stays as close to upstream as possible. We add a change only where it is clearly needed, because every change has to be carried forward on each synchronization with upstream, and a small patch queue keeps the fork easy to maintain.
Digdir's changes are the commits on main-digdir after the upstream base, such as guest kernel configuration for
Kubernetes networking inside a sandbox and CI for the kernels we ship. The commits describe each change.
We ship only the x86_64 and aarch64 kernels, and the same kernel bundle is linked into the Linux, macOS and Windows libraries.
The build is unchanged from upstream. On Linux with the kernel build toolchain, Python 3 and pyelftools:
make kernel.c # the kernel bundle consumed by the Microsandbox runtime release
make # the shared library for the hostThis repository publishes no releases of its own. The Digdir Microsandbox runtime release builds the kernel bundle
from the vendor/libkrunfw submodule and publishes the resulting libraries. See RELEASE.md.
Report problems with the Digdir changes or builds as issues in this repository. Problems that also exist upstream belong upstream, and changes that are useful beyond Digdir should be contributed there; a later upstream release then lets us drop the corresponding patch. RELEASE.md describes how changes to the patch queue are made.
Report security vulnerabilities as described in Digdir's security policy, not in public issues or pull requests.
The upstream licensing is unchanged and applies to the Digdir modifications as well:
- Linux kernel: GPL-2.0-only (LICENSE-GPL-2.0-only)
- Files in the
patchesdirectory: GPL-2.0-only - Library code, including automatically generated code: LGPL-2.1-only (LICENSE-LGPL-2.1-only)
The library bundles a Linux kernel but does not execute any code from it, acting as a mere storage format, so it is not a derivative work of the Linux kernel. Binary distributions of this library must be accompanied by the source code of the bundled Linux kernel and of the library itself. Programs linking against the library are not required to be licensed under GPL-2.0-only or LGPL-2.1-only.