Christian Werner de2fb56a59
All checks were successful
Build kernel module / build (1:6.12.93-1+rpt1, bookworm) (pull_request) Successful in 8m4s
Build kernel module / build (1:6.18.34-1+rpt1, trixie) (pull_request) Successful in 5m25s
Build kernel module / release (pull_request) Has been skipped
feat(kernel): Add trixie SHA1 signature workaround to Dockerfile
Introduce a conditional `trusted=yes` setting for the Raspberry Pi
repository in the Dockerfile when `DEBIAN_SUITE=trixie`. This bypasses
SHA1 signature rejection by trixie's apt system using Sequoia. Ensure
that bookworm maintains full signature verification. Updated
documentation to explain the trixie-specific caveat.
2026-06-19 21:03:18 +02:00

69 lines
3.2 KiB
Docker

# syntax=docker/dockerfile:1
#
# Build the IEC listener kernel module for Raspberry Pi OS (arm64) inside an
# emulated arm64 container. The module is compiled natively against the same
# raspberrypi kernel headers the Pi runs, which keeps the module "vermagic" in
# sync so `insmod` accepts it on the Pi.
#
# Requires qemu-binfmt on the host (the build-in-docker.sh wrapper sets this up):
# docker run --privileged --rm tonistiigi/binfmt --install arm64
#
# Kernel version is configurable via build args:
# --build-arg DEBIAN_SUITE=trixie # Debian/RPi OS suite (see notes)
# --build-arg HEADERS_PKG=linux-headers-rpi-v8 # 64-bit Pi Zero 2 W (default)
# --build-arg KERNEL_VERSION=1:6.6.51-1+rpt3 # optional exact pin (see notes)
#
# DEBIAN_SUITE must match the kernel you target: each raspberrypi archive suite
# only carries its own latest kernel (bookworm -> 6.12.x, trixie -> 6.18.x), so
# pinning a trixie-era KERNEL_VERSION against a bookworm base will fail with
# "Version ... was not found". Keep this in sync with the Pi's release.
#
# Build context is this kernel/ directory.
ARG DEBIAN_SUITE=bookworm
FROM --platform=linux/arm64 debian:${DEBIAN_SUITE}
# Re-declare after FROM so it is in scope for the RUN below (ARGs before FROM
# are only visible to the FROM line itself).
ARG DEBIAN_SUITE=bookworm
# The raspberrypi kernel/headers live in the raspberrypi.com archive, not Debian.
#
# On trixie, apt verifies signatures with Sequoia (sqv), whose crypto policy
# rejects SHA1 since 2026-02-01. The raspberrypi archive key's binding
# self-signature is SHA1, so trixie's apt refuses the repo as "not signed"
# (bookworm's gpgv doesn't enforce this). We mark the repo trusted=yes *only on
# trixie* to bypass that check; bookworm keeps full signature verification. The
# key is still fetched over HTTPS and pinned via signed-by where it is honoured.
RUN apt-get update \
&& apt-get install -y --no-install-recommends ca-certificates curl gnupg \
&& curl -fsSL https://archive.raspberrypi.com/debian/raspberrypi.gpg.key \
| gpg --dearmor -o /usr/share/keyrings/raspberrypi-archive-keyring.gpg \
&& opts="signed-by=/usr/share/keyrings/raspberrypi-archive-keyring.gpg" \
&& if [ "$DEBIAN_SUITE" = "trixie" ]; then opts="$opts trusted=yes"; fi \
&& echo "deb [$opts] http://archive.raspberrypi.com/debian/ ${DEBIAN_SUITE} main" \
> /etc/apt/sources.list.d/raspi.list \
&& rm -rf /var/lib/apt/lists/*
# Toolchain + module build dependencies.
RUN apt-get update \
&& apt-get install -y --no-install-recommends \
build-essential bc bison flex libssl-dev libelf-dev kmod make \
&& rm -rf /var/lib/apt/lists/*
# Kernel headers. Override HEADERS_PKG / KERNEL_VERSION to target a specific Pi
# kernel. Default targets the current 64-bit Raspberry Pi OS Bookworm kernel.
ARG HEADERS_PKG=linux-headers-rpi-v8
ARG KERNEL_VERSION=
RUN apt-get update \
&& apt-get install -y --no-install-recommends \
"${HEADERS_PKG}${KERNEL_VERSION:+=${KERNEL_VERSION}}" \
&& rm -rf /var/lib/apt/lists/*
COPY docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
RUN chmod +x /usr/local/bin/docker-entrypoint.sh
WORKDIR /build
ENTRYPOINT ["/usr/local/bin/docker-entrypoint.sh"]
# default: build the module (override with e.g. `clean`)
CMD []