Bug#1141964: ITP: libkrunfw -- Dynamic library bundling the guest payload consumed by libkrun

Ben Westover <[email protected]> Sun, 12 Jul 2026 17:08:27 -0400
Newsgroups gmane.linux.debian.devel.general
Message-ID <45606e22-9046-4d66-8aac-fd8dbcfc1841__21435.3236997098$1783890701$gmane$org@debian.org>
Package: wnpp
X-Debbugs-Cc: [email protected]
Owner: Ben Westover <[email protected]>
Severity: wishlist

* Package name    : libkrunfw
   Version         : 5.5.0
   Upstream Contact: Sergio Lopez <[email protected]>
* URL             : https://github.com/libkrun/libkrunfw
* License         : LGPL-2.1
   Programming Lang: C
   Description     : Library bundling guest payload consumed by libkrun

libkrunfw is a library bundling a Linux kernel in a dynamic library in a 
way that can be easily consumed by libkrun.

By having the kernel bundled in a dynamic library, libkrun can leave to 
the linker the work of mapping the sections into the process, and then 
directly inject those mappings into the guest without any kind of 
additional work nor processing.

I am packaging this because it is a dependency of libkrun. Because it's 
an encapsulation of a Linux kernel, there will be a kernel tarball in 
the package source. I cannot just depend on linux-source, because this 
library builds against a very specific kernel version and patchset.

This is the upstream explanation of the licensing situation it causes:

 > This library bundles a Linux kernel but does not execute any code from
 > it, acting as a mere storage format. As a consequence, this library
 > does not constitute a derivative work of the Linux kernel.
 > Thus, the following licenses apply:
 > * Linux kernel: GPL-2.0-only
 > * Files contained in the patches directory: GPL-2.0-only
 > * Library code, including automatically-generated code: LGPL-2.1-only
 > Therefore, distributions of this library in binary form are required
 > to be accompanied by the source code of the Linux kernel bundled in
 > the binary along with the code of the library itself, but other
 > programs linking against this library are not required to be licensed
 > under the GPL-2.0-only nor the LGPL-2.1-only licenses.

I do not plan to maintain this in a team unless one expresses interest.

Regards
--
Ben Westover
OpenPGP_signature.asc (application/pgp-signature, 840 B)
-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEEOGnacqRhdU6eNmtFwxHF9U6JtpgFAmpUAkwFAwAAAAAACgkQwxHF9U6JtpgM
ohAAmoKsrQCYtrxwrrGKufcXcLEevoZvnvcI+SF9M5rh9cXGaw8XGPqnANmV/B7cYKml/F3ujVJp
rWXsxRhLPPrVRriS7E6FAyRIPsUrnvJVZqzdu7upmFcg6uqFX48RiTALpVVjUk80H0T3s6AJQ7Fs
ndrs9vXI6iORd5KUvPsoQLjPOHTUWm6L6M+cNSncesTdhuPl2UQ22xhVy8eS1ZAgX67b+ZYQiGyV
v91UGQUh88Vxf+ay9jQmKNkbovvloR6LWEzCa4fgWDXrglNsNgwLHijh5fNCZlFaHHtt5HEomeNw
0rSuu3iV7OcjbXuX29diTZsnXZAF6ZDuayYFFD1BEGkODRhjTYDLp0FCqkesxd6jYHcbFQFUri5k
fb5NXqUXXbeJFaGKm2OKZJOgWznfO3DKqd2we2TG3cRkCkH2iF65n2jmz7HO62vNs4tU1LtTEf7r
5lA85SkTxndD22MmSQXhwSuveEH2oMzRhghzZKJPOIPm2Y98gvq4XHpwIbxTJt3e/ljKbSKdJ8dU
GUIKpfkMUSVC8DSvLF4V+r1q/HVStKiNN+41HCzPPF3avG13/hgyfL50qFzRr8tpwd4akbyoO6Fu
sNfoCnBLGP49g7R98iK/gWGKUmWVVWhQeGNdv8bYuCrt4l91XAwGC2Cm2tophF3fk5xUaVZKA2tC
5Hg=
=3mwG
-----END PGP SIGNATURE-----