Skip to content

Commit 91e525b

Browse files
authored
Fix Debian 7 docker image builds failing due to outdated wget/curl TLS (#1017)
Motivation: Debian 7 (wheezy) is EOL and archive.debian.org has no updated openssl/ca-certificates package for it. The ancient wget/curl in the image can no longer complete a TLS handshake with GitHub or sdkman.io, so downloading CMake, Ninja, Go, the precompiled GCC toolchain, the OpenSSL source tarball, and SDKMAN/the JDK inside the debian:7 stage now fails outright, independent of the existing --no-check-certificate/insecure-ssl workarounds already in place for the (now separate) certificate-validation problem. Modifications: Split Dockerfile.debian into a multi-stage build: a new debian:bookworm-slim downloader stage with a modern curl fetches all HTTPS artifacts (CMake, Ninja, Go, the GCC tarball, the OpenSSL source tarball, SDKMAN, and the JDK), and the debian:7 stage now only COPYs those artifacts in and compiles, without ever making a TLS connection itself. Result: Debian 7 docker images build again.
1 parent 64edccd commit 91e525b

1 file changed

Lines changed: 72 additions & 26 deletions

File tree

‎docker/Dockerfile.debian‎

Lines changed: 72 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,65 @@
11
ARG debian_version=7
2+
ARG openssl_version=3.6.1
3+
ARG openssl_sha256
4+
ARG java_version="8.0.302-zulu"
5+
6+
# ---------------------------------------------------------------------------
7+
# Debian 7 (wheezy) is EOL and archive.debian.org has no updated openssl /
8+
# ca-certificates package for it. The wget/curl shipped there can no longer
9+
# complete a TLS handshake with GitHub, sdkman.io, etc, so every HTTPS
10+
# download needed to build the image is done here, in a modern image, and
11+
# then copied into the debian:7 stage below.
12+
# ---------------------------------------------------------------------------
13+
FROM debian:bookworm-slim AS downloader
14+
ARG openssl_version
15+
ARG openssl_sha256
16+
ARG java_version
17+
ENV CMAKE_VERSION_BASE 3.26
18+
ENV CMAKE_VERSION=$CMAKE_VERSION_BASE.4
19+
ENV NINJA_VERSION 1.7.2
20+
ENV GO_VERSION 1.9.3
21+
ENV GCC_VERSION 4.9.4
22+
ENV JAVA_VERSION $java_version
23+
24+
RUN apt-get -y update && apt-get -y install --no-install-recommends \
25+
ca-certificates \
26+
curl \
27+
unzip \
28+
zip \
29+
&& rm -rf /var/lib/apt/lists/*
30+
31+
WORKDIR /root/download
32+
33+
RUN curl -fsSL -o cmake-$CMAKE_VERSION-linux-x86_64.tar.gz \
34+
https://github.com/Kitware/CMake/releases/download/v$CMAKE_VERSION/cmake-$CMAKE_VERSION-linux-x86_64.tar.gz
35+
36+
RUN curl -fsSL -o ninja-linux.zip \
37+
https://github.com/ninja-build/ninja/releases/download/v$NINJA_VERSION/ninja-linux.zip
38+
39+
RUN curl -fsSL -o go$GO_VERSION.linux-amd64.tar.gz \
40+
http://ftp.belnet.be/mirror/golang/go$GO_VERSION.linux-amd64.tar.gz
41+
42+
RUN curl -fsSL -o gcc-$GCC_VERSION.tar.gz \
43+
https://github.com/netty/netty-tcnative/releases/download/gcc-precompile/gcc-$GCC_VERSION.tar.gz
44+
45+
RUN curl -fsSL -o openssl-$openssl_version.tar.gz \
46+
https://github.com/openssl/openssl/releases/download/openssl-$openssl_version/openssl-$openssl_version.tar.gz && \
47+
echo "$openssl_sha256 openssl-$openssl_version.tar.gz" | sha256sum -c -
48+
49+
# Installed here (not in the debian:7 stage) for the same TLS reason: sdkman's
50+
# own installer and its Java downloads are plain curl/wget under the hood.
51+
RUN curl -s "https://get.sdkman.io" | bash
52+
RUN bash -c "source $HOME/.sdkman/bin/sdkman-init.sh && \
53+
yes | sdk install java $JAVA_VERSION && \
54+
rm -rf $HOME/.sdkman/archives/* && \
55+
rm -rf $HOME/.sdkman/tmp/*"
56+
57+
# ---------------------------------------------------------------------------
258
FROM --platform=linux/amd64 debian:$debian_version
359
# needed to do again after FROM due to docker limitation
460
ARG debian_version
5-
ARG openssl_version=3.6.1
6-
ARG openssl_sha256
61+
ARG openssl_version
762
ENV OPENSSL_VERSION $openssl_version
8-
ENV OPENSSL_SHA256 $openssl_sha256
963
ENV SOURCE_DIR /root/source
1064
ENV CMAKE_VERSION_BASE 3.26
1165
ENV CMAKE_VERSION=$CMAKE_VERSION_BASE.4
@@ -18,7 +72,7 @@ ENV JAVA_VERSION $java_version
1872

1973
# install dependencies
2074
RUN echo "deb http://archive.debian.org/debian/ wheezy contrib main non-free" > /etc/apt/sources.list && \
21-
echo "deb-src http://archive.debian.org/debian/ wheezy contrib main non-free" >> /etc/apt/sources.list && \
75+
echo "deb-src http://archive.debian.org/debian/ wheezy contrib main non-free" >> /etc/apt/sources.list && \
2276
apt-get -y update && apt-get --force-yes -y install \
2377
autoconf \
2478
automake \
@@ -49,20 +103,23 @@ RUN echo "deb http://archive.debian.org/debian/ wheezy contrib main non-free" >
49103
RUN mkdir $SOURCE_DIR
50104
WORKDIR $SOURCE_DIR
51105

52-
RUN wget -q --no-check-certificate https://github.com/Kitware/CMake/releases/download/v$CMAKE_VERSION/cmake-$CMAKE_VERSION-linux-x86_64.tar.gz && tar zxf cmake-$CMAKE_VERSION-linux-x86_64.tar.gz && mv cmake-$CMAKE_VERSION-linux-x86_64 /opt/ && echo 'PATH=/opt/cmake-$CMAKE_VERSION-linux-x86_64/bin:$PATH' >> ~/.bashrc
53-
RUN wget -q --no-check-certificate https://github.com/ninja-build/ninja/releases/download/v$NINJA_VERSION/ninja-linux.zip && unzip ninja-linux.zip && mkdir -p /opt/ninja-$NINJA_VERSION/bin && mv ninja /opt/ninja-$NINJA_VERSION/bin && echo 'PATH=/opt/ninja-$NINJA_VERSION/bin:$PATH' >> ~/.bashrc
106+
COPY --from=downloader /root/download/cmake-$CMAKE_VERSION-linux-x86_64.tar.gz .
107+
RUN tar zxf cmake-$CMAKE_VERSION-linux-x86_64.tar.gz && mv cmake-$CMAKE_VERSION-linux-x86_64 /opt/ && echo 'PATH=/opt/cmake-$CMAKE_VERSION-linux-x86_64/bin:$PATH' >> ~/.bashrc && rm cmake-$CMAKE_VERSION-linux-x86_64.tar.gz
54108

55-
RUN wget -q http://ftp.belnet.be/mirror/golang/go$GO_VERSION.linux-amd64.tar.gz && tar zxf go$GO_VERSION.linux-amd64.tar.gz && mv go /opt/ && echo 'PATH=/opt/go/bin:$PATH' >> ~/.bashrc && echo 'export GOROOT=/opt/go/' >> ~/.bashrc
109+
COPY --from=downloader /root/download/ninja-linux.zip .
110+
RUN unzip ninja-linux.zip && mkdir -p /opt/ninja-$NINJA_VERSION/bin && mv ninja /opt/ninja-$NINJA_VERSION/bin && echo 'PATH=/opt/ninja-$NINJA_VERSION/bin:$PATH' >> ~/.bashrc && rm ninja-linux.zip
56111

57-
RUN wget -q --no-check-certificate https://github.com/netty/netty-tcnative/releases/download/gcc-precompile/gcc-$GCC_VERSION.tar.gz && tar zxf gcc-$GCC_VERSION.tar.gz && mv gcc-$GCC_VERSION /opt/ && echo 'PATH=/opt/gcc-$GCC_VERSION/bin:$PATH' >> ~/.bashrc && echo 'export CC=/opt/gcc-$GCC_VERSION/bin/gcc' >> ~/.bashrc && echo 'export CXX=/opt/gcc-$GCC_VERSION/bin/g++' >> ~/.bashrc
112+
COPY --from=downloader /root/download/go$GO_VERSION.linux-amd64.tar.gz .
113+
RUN tar zxf go$GO_VERSION.linux-amd64.tar.gz && mv go /opt/ && echo 'PATH=/opt/go/bin:$PATH' >> ~/.bashrc && echo 'export GOROOT=/opt/go/' >> ~/.bashrc && rm go$GO_VERSION.linux-amd64.tar.gz
114+
115+
COPY --from=downloader /root/download/gcc-$GCC_VERSION.tar.gz .
116+
RUN tar zxf gcc-$GCC_VERSION.tar.gz && mv gcc-$GCC_VERSION /opt/ && echo 'PATH=/opt/gcc-$GCC_VERSION/bin:$PATH' >> ~/.bashrc && echo 'export CC=/opt/gcc-$GCC_VERSION/bin/gcc' >> ~/.bashrc && echo 'export CXX=/opt/gcc-$GCC_VERSION/bin/g++' >> ~/.bashrc && rm gcc-$GCC_VERSION.tar.gz
58117

59118
# Build OpenSSL 3.x from source using the custom GCC
119+
COPY --from=downloader /root/download/openssl-$openssl_version.tar.gz .
60120
RUN set -x && \
61121
export CC=/opt/gcc-$GCC_VERSION/bin/gcc && \
62-
# --no-check-certificate: Debian 7 ships with outdated CA bundles that can't verify modern GitHub TLS certs
63-
wget --no-check-certificate https://github.com/openssl/openssl/releases/download/openssl-$OPENSSL_VERSION/openssl-$OPENSSL_VERSION.tar.gz && \
64-
echo "$OPENSSL_SHA256 openssl-$OPENSSL_VERSION.tar.gz" | sha256sum -c - && \
65-
tar xvf openssl-$OPENSSL_VERSION.tar.gz && \
122+
tar xf openssl-$OPENSSL_VERSION.tar.gz && \
66123
(cd openssl-$OPENSSL_VERSION && \
67124
# no-asm: the custom GCC on Debian 7 cannot reliably compile OpenSSL's hand-tuned x86_64 assembly
68125
./Configure linux-x86_64 --prefix=/opt/openssl-$OPENSSL_VERSION --libdir=lib shared no-asm no-apps && \
@@ -71,20 +128,9 @@ RUN set -x && \
71128

72129
RUN rm -rf $SOURCE_DIR
73130

74-
# Downloading and installing SDKMAN!
75-
RUN echo '-k' > $HOME/.curlrc
76-
RUN curl -s "https://get.sdkman.io" | bash
77-
RUN rm $HOME/.curlrc
78-
79-
# Don't check the certificates as our curl version is too old.
80-
RUN echo 'sdkman_insecure_ssl=true' >> $HOME/.sdkman/etc/config
81-
82-
# Installing Java removing some unnecessary SDKMAN files
83-
RUN bash -c "source $HOME/.sdkman/bin/sdkman-init.sh && \
84-
yes | sdk install java $JAVA_VERSION && \
85-
rm -rf $HOME/.sdkman/archives/* && \
86-
rm -rf $HOME/.sdkman/tmp/*"
87-
131+
# SDKMAN + the JDK were installed in the downloader stage where curl can
132+
# actually negotiate TLS with get.sdkman.io; just copy the result in here.
133+
COPY --from=downloader /root/.sdkman /root/.sdkman
88134

89135
RUN echo 'export JAVA_HOME="/root/.sdkman/candidates/java/current"' >> ~/.bashrc
90136
RUN echo 'PATH=$JAVA_HOME/bin:$PATH' >> ~/.bashrc

0 commit comments

Comments
 (0)