我拒绝让 SPICE 消亡。
I refuse to let SPICE die

原始链接: https://github.com/nefarius/vd_agent/

本仓库提供了一个由社区维护的 Red Hat SPICE Windows Guest Agent 分支。它旨在为现代 Windows 环境(特别是运行在 Linux QEMU/KVM 上的 Windows 11 虚拟机)提供持续支持。 **主要特性:** * **无缝集成:** 支持客户端鼠标模式(无需捕获指针)、动态桌面调整大小、剪贴板共享(文本/图像)及文件传输。 * **稳定性修复:** 包含针对多 GPU 环境的关键鼠标修复,防止在使用 GPU 直通时出现指针丢失问题。 * **基础设施:** 项目使用 MSYS2 UCRT64 构建 MSI 安装程序,并以 GitHub Actions 作为官方持续集成(CI)平台。 * **安全性:** 通过 SignRelay 实现全自动化、安全的签名流程,确保所有发布版本均包含有效的 Authenticode 签名和 SHA-256 校验和。 该代理采用 GPL-2.0-or-later 许可证,在保持与历史 SPICE 部署完全兼容的同时,为当前的客户机操作系统提供了可靠的解决方案。开发和构建说明(包括子模块管理和部署工作流)已记录在案,适用于本地 MSYS2 开发及自动化发布周期。

Hacker News 最新 | 过往 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 我拒绝让 SPICE 消亡 (github.com/nefarius) 13 点,由 Nefarius 发布于 2 小时前 | 隐藏 | 过往 | 收藏 | 2 条评论 帮助 franga2000 6 分钟前 | 下一条 [–] 我真的不明白红帽为什么要终止 SPICE。它是唯一能让开源虚拟化(如 Proxmox)上的虚拟机使用体验接近 VMware 的方案。VNC 真的是你能用到的最差的远程桌面协议了,延迟高、画质差、集成度低。 回复 c0l0 6 分钟前 | 上一条 [–] 作为一个非频繁使用 SPICE(通过 Proxmox PVE)的用户,我希望 QEMU 能直接在 Hypervisor 层支持 Sunlight/Moonlight 流媒体。随着 Venus、VirtIO GPU 以及英特尔对 SR-IOV 的支持逐渐成熟,这将成为 VDI 类基础设施的杀手级应用。 回复 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请 YC | 联系 搜索:
相关文章

原文

Community-maintained Windows guest agent for SPICE. This repository is a public mirror of the abandoned freedesktop.org spice/win32/vd_agent project. Canonical downloads live on GitHub Releases.

The agent provides:

  • Client mouse mode without grabbing the pointer
  • Desktop resolution matching the client
  • Clipboard sharing (text and images)
  • File transfer into the guest
  • A Windows service (spice-agent) that starts vdagent.exe in each session

Red Hat no longer maintains upstream SPICE. This fork keeps the Windows agent building and shipping for current guests, especially Windows 11 VMs on Linux.

The tree already includes the multi-GPU mouse fix from d7405ee (vdagent/desktop_layout.cpp): when a real GPU is passed through alongside the SPICE display device, the agent no longer loses mouse movement.

The agent is GPL-2.0-or-later. See COPYING and the copyright headers in each source file. Original copyright remains with Red Hat, Inc. and other upstream authors. This fork does not claim the Red Hat or SPICE trademarks.

Pinned build-time submodules (do not bump casually):

Submodule URLs use HTTPS. MSI upgrades keep the historical WiX UpgradeCode (7eb9b146-db04-42d7-a8ba-71fc8ced7eed). Related products are removed after InstallValidate, before the install transaction begins, so the shared components are recopied instead of being deleted by the old package's uninstall. Because wixl does not read the PE version resource, the File table gets RC_FILEVERSION explicitly; keep it identical to the four fields in VS_VERSION_INFO. The x64 installer still only ships vdagent.exe and vdservice.exe into C:\Program Files\SPICE agent\bin.

git clone --recursive https://github.com/nefarius/vd_agent.git
cd vd_agent

If you already cloned without submodules:

git submodule update --init --recursive

The freedesktop GitLab remote is preserved as upstream after the mirror was created. Fetch it with:

Local build (MSYS2 UCRT64)

The Autotools + MinGW-w64 UCRT64 path is the supported way to produce the installer. CMake + MSVC remains available for local development but does not build an MSI.

  • MSYS2
  • An UCRT64 shell (C:\msys64\ucrt64.exe, or MSYSTEM=UCRT64)

From the UCRT64 shell, in the repository root:

bash msys2/install.sh
autoreconf -i
bash msys2/build.sh builducrt64
bash msys2/package.sh builducrt64

install.sh pulls autotools, autoconf-archive, the UCRT64 toolchain, msitools (wixl), and ImageMagick (tests). PNG clipboard conversion uses the Windows Imaging Component that ships with Windows Vista and later.

build.sh configures, compiles vdagent.exe / vdservice.exe, and runs test-png, test-log, and test-shell. package.sh then invokes make msi and writes:

builducrt64/spice-vdagent-x64-<version>.msi

Version strings come from git describe via build-aux/git-version-gen. Release tags must look like v0.11.0 (minor bumps) so Programs and Features shows the tag exactly. Untagged builds add the commit count since the last tag (for example v0.11.0 plus 83 commits becomes 0.11.0.83-<hash>). Configure fails if that count plus --with-buildid reaches 256, because that would collide with the next micro version.

To sign a local build, sign the two executables before package.sh, then sign the MSI.

git submodule update --init --recursive
cmake -S . -B build64 -A x64
cmake --build build64 --config Release
cmake --build build64 --config Release --target check

GitHub Actions (.github/workflows/build.yml) builds the x64 UCRT64 MSI on windows-2022.

Event Signing Publish
Pull request / master push Skipped Workflow artifact vdagent-win-x64 only
Tag v* Required Signed MSI + SHA-256, artifact mirror, GitHub Release

Signing uses SignRelay so the certificate never lands on the runner. The flow matches DsHidMini:

  1. Build and test unsigned binaries
  2. On a v* tag, sign vdagent.exe and vdservice.exe in place
  3. Package the MSI from those binaries
  4. Sign the MSI
  5. Verify Authenticode (Get-AuthenticodeSignature Status = Valid)
  6. Write <msi>.sha256
  7. Upload vdagent-win-x64 and, on tags, notify AppVeyorArtifactsReceiver
  8. Attach the MSI and checksum to the GitHub Release

The SignRelay composite action is pinned to commit 39ccbe0cef16a383237130380a5aef8db040d5d0. The CLI needs .NET 10 on the runner (actions/setup-dotnet with 10.0.x).

Create these on nefarius/vd_agent (Settings → Secrets and variables):

Name Kind Purpose
SIGN_RELAY_SERVER Variable Relay base URL, for example https://signrelay.api.nefarius.systems/
SIGN_RELAY_CI_TOKEN Secret CI bearer token (SignRelay__CiToken on the server)
WEBHOOK_URL Secret AppVeyorArtifactsReceiver webhook

Copy SIGN_RELAY_CI_TOKEN and WEBHOOK_URL from an already-working repo such as DsHidMini. SIGN_RELAY_SERVER is already set as a repository variable. Do not commit secret values.

The Windows SignRelay agent holds the code-signing certificate. Configure subject/thumbprint and timestamp there, not in this repository.

  1. Update CHANGELOG.md

  2. Tag an annotated release and push it:

    git tag -a v0.11.0 -m "vdagent-win 0.11.0"
    git push origin v0.11.0
  3. Confirm the Build workflow:

    • unsigned path is not used
    • both executables and the MSI verify as Valid
    • artifacts receiver accepted the webhook
    • the GitHub Release contains the MSI and .sha256
  4. Install the MSI in a Windows 11 SPICE guest and run the checklist below

If a tagged build fails after signing started, fix the tree and move the tag forward (or use a new minor version). Do not reuse a published MSI name with different bytes.

To recover a failed release: delete the GitHub Release draft if any, push a new tag, and keep the previous published tag immutable if users may have downloaded it.

appveyor.yml is kept only for historical parity with the last upstream UCRT64 MSI layout. GitHub Actions is the authoritative CI. Remove AppVeyor once a signed Actions MSI has been smoke-tested.

Use a Windows 11 guest on Linux (QEMU/KVM + SPICE), with the QXL or qxl-wddm-dod display device.

  1. Clean install — run spice-vdagent-x64-*.msi as Administrator
  2. Servicespice-agent is Running / Automatic; vdagent.exe is present in the user session
  3. SPICE connection — reconnect virt-viewer / spicy; agent channel is up
  4. Clipboard — text and a bitmap both ways
  5. File transfer — drop a file from the client; it lands on the desktop
  6. Dynamic resolution — resize the client window; the guest desktop follows when the WDDM QXL driver is in use
  7. Multi-GPU / passthrough mouse — add a real GPU for passthrough, keep the SPICE display, confirm the pointer keeps moving (the d7405ee fix)
  8. Upgrade — install over a previous Spice agent MSI; service comes back
  9. Uninstall — remove the product; spice-agent is gone

Optional CMake / Fedora notes

联系我们 contact @ memedata.com