Introduce a conditional `trusted=yes` setting for the Raspberry Pi repository in the Dockerfile when `DEBIAN_SUITE=trixie`. This bypasses SHA1 signature rejection by trixie's apt system using Sequoia. Ensure that bookworm maintains full signature verification. Updated documentation to explain the trixie-specific caveat.
69 lines
3.2 KiB
Docker
69 lines
3.2 KiB
Docker
# syntax=docker/dockerfile:1
|
|
#
|
|
# Build the IEC listener kernel module for Raspberry Pi OS (arm64) inside an
|
|
# emulated arm64 container. The module is compiled natively against the same
|
|
# raspberrypi kernel headers the Pi runs, which keeps the module "vermagic" in
|
|
# sync so `insmod` accepts it on the Pi.
|
|
#
|
|
# Requires qemu-binfmt on the host (the build-in-docker.sh wrapper sets this up):
|
|
# docker run --privileged --rm tonistiigi/binfmt --install arm64
|
|
#
|
|
# Kernel version is configurable via build args:
|
|
# --build-arg DEBIAN_SUITE=trixie # Debian/RPi OS suite (see notes)
|
|
# --build-arg HEADERS_PKG=linux-headers-rpi-v8 # 64-bit Pi Zero 2 W (default)
|
|
# --build-arg KERNEL_VERSION=1:6.6.51-1+rpt3 # optional exact pin (see notes)
|
|
#
|
|
# DEBIAN_SUITE must match the kernel you target: each raspberrypi archive suite
|
|
# only carries its own latest kernel (bookworm -> 6.12.x, trixie -> 6.18.x), so
|
|
# pinning a trixie-era KERNEL_VERSION against a bookworm base will fail with
|
|
# "Version ... was not found". Keep this in sync with the Pi's release.
|
|
#
|
|
# Build context is this kernel/ directory.
|
|
ARG DEBIAN_SUITE=bookworm
|
|
FROM --platform=linux/arm64 debian:${DEBIAN_SUITE}
|
|
|
|
# Re-declare after FROM so it is in scope for the RUN below (ARGs before FROM
|
|
# are only visible to the FROM line itself).
|
|
ARG DEBIAN_SUITE=bookworm
|
|
|
|
# The raspberrypi kernel/headers live in the raspberrypi.com archive, not Debian.
|
|
#
|
|
# On trixie, apt verifies signatures with Sequoia (sqv), whose crypto policy
|
|
# rejects SHA1 since 2026-02-01. The raspberrypi archive key's binding
|
|
# self-signature is SHA1, so trixie's apt refuses the repo as "not signed"
|
|
# (bookworm's gpgv doesn't enforce this). We mark the repo trusted=yes *only on
|
|
# trixie* to bypass that check; bookworm keeps full signature verification. The
|
|
# key is still fetched over HTTPS and pinned via signed-by where it is honoured.
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends ca-certificates curl gnupg \
|
|
&& curl -fsSL https://archive.raspberrypi.com/debian/raspberrypi.gpg.key \
|
|
| gpg --dearmor -o /usr/share/keyrings/raspberrypi-archive-keyring.gpg \
|
|
&& opts="signed-by=/usr/share/keyrings/raspberrypi-archive-keyring.gpg" \
|
|
&& if [ "$DEBIAN_SUITE" = "trixie" ]; then opts="$opts trusted=yes"; fi \
|
|
&& echo "deb [$opts] http://archive.raspberrypi.com/debian/ ${DEBIAN_SUITE} main" \
|
|
> /etc/apt/sources.list.d/raspi.list \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# Toolchain + module build dependencies.
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends \
|
|
build-essential bc bison flex libssl-dev libelf-dev kmod make \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# Kernel headers. Override HEADERS_PKG / KERNEL_VERSION to target a specific Pi
|
|
# kernel. Default targets the current 64-bit Raspberry Pi OS Bookworm kernel.
|
|
ARG HEADERS_PKG=linux-headers-rpi-v8
|
|
ARG KERNEL_VERSION=
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends \
|
|
"${HEADERS_PKG}${KERNEL_VERSION:+=${KERNEL_VERSION}}" \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
COPY docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
|
|
RUN chmod +x /usr/local/bin/docker-entrypoint.sh
|
|
|
|
WORKDIR /build
|
|
ENTRYPOINT ["/usr/local/bin/docker-entrypoint.sh"]
|
|
# default: build the module (override with e.g. `clean`)
|
|
CMD []
|