build: add musl support - #70
Open
KnorpelSenf wants to merge 1 commit into
Open
Conversation
This uses unsafe Rust to create zero'ed structs first, and then explicitly set the known options. As a result, the hidden padding fields are untouched so we can compile with musl.
Open
kvinwang
added a commit
to Dstack-TEE/dstack
that referenced
this pull request
Jul 27, 2026
The gateway CVM app image is built for x86_64-unknown-linux-musl, and ktls 6.0.2 does not compile for it: error[E0063]: missing field `__pad1` in initializer of `cmsghdr` error: cannot construct `msghdr` with struct literal syntax due to private fields The crate builds both structs with struct literal syntax. That is fine on glibc, where they have exactly the members it names, but musl declares msg_iovlen and msg_controllen as int/socklen_t followed by explicit padding, and libc models that with private __pad1/__pad2 members a literal cannot name. So this is a permanent property of musl's ABI rather than a libc regression, and 6.0.2 is the latest published release -- there is no version to bump to. rustls/ktls#70 fixes it by building both from std::mem::zeroed() field by field. It has been open since 2026-05-04. Rather than point the dependency at the contributor's fork -- a moving, non-crates.io source for the crate that installs session keys into the kernel, in a build that otherwise pins everything down to package versions and image digests -- the 6.0.2 release is vendored with only that patch applied. Each hunk is marked, dev-dependencies are dropped, and vendor/README.md records the provenance and the condition for deleting it again. ktls was the only thing blocking the musl build (confirmed with --keep-going). Verified by running both binaries against the same backend: a 100 MiB transfer through the terminate path checksums correctly, kTLS actually engages (ktls_offloaded=2, ktls_offload_failed=0) and TlsDecryptError stays at 0 for the glibc and the static musl build alike. The patched code is on the close_notify path, so compiling was not the interesting half.
7 tasks
kvinwang
added a commit
to Dstack-TEE/dstack
that referenced
this pull request
Jul 27, 2026
The gateway CVM app image is built for x86_64-unknown-linux-musl, and ktls 6.0.2 does not compile for it: error[E0063]: missing field `__pad1` in initializer of `cmsghdr` error: cannot construct `msghdr` with struct literal syntax due to private fields The crate builds both structs with struct literal syntax. That is fine on glibc, where they have exactly the members it names, but musl declares msg_iovlen and msg_controllen as int/socklen_t followed by explicit padding, and libc models that with private __pad1/__pad2 members a literal cannot name. So this is a permanent property of musl's ABI rather than a libc regression, and 6.0.2 is the latest published release -- there is no version to bump to. rustls/ktls#70 fixes it by building both from std::mem::zeroed() field by field. It has been open since 2026-05-04. Rather than point the dependency at the contributor's fork -- a moving, non-crates.io source for the crate that installs session keys into the kernel, in a build that otherwise pins everything down to package versions and image digests -- the 6.0.2 release is vendored with only that patch applied. Each hunk is marked, dev-dependencies are dropped, and vendor/README.md records the provenance and the condition for deleting it again. ktls was the only thing blocking the musl build (confirmed with --keep-going). Verified by running both binaries against the same backend: a 100 MiB transfer through the terminate path checksums correctly, kTLS actually engages (ktls_offloaded=2, ktls_offload_failed=0) and TlsDecryptError stays at 0 for the glibc and the static musl build alike. The patched code is on the close_notify path, so compiling was not the interesting half.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This uses unsafe Rust to create zero'ed structs first, and then explicitly set the known fields. As a result, the hidden padding fields are filled with zeros, too, so we can compile with musl.
Please note that I haven't spent too much time on ktls-related things yet, so please tell me if I am making a stupid mistake right now. The changes make perfect sense to me and align with the kernel manpages as far as I can tell, but you never know.
The repro docker script from #69 passes on this branch:
Closes #69.