Skip to content

Commit f5cb588

Browse files
CI: build boringssl-static and the FIPS profile on Debian 13, verify both jars on Alpine
Motivation: CI built boringssl-static only on the two release images and never built the FIPS profile at all, so #997 could add the musl check to that profile without the matching link changes and nothing failed until a downstream build did (#1008). Modifications: - docker/Dockerfile.debian13 + docker-compose.debian-13.yaml: `build` (default profile) and `build-fips`. The image carries the build environment from certificate #5244's security policy, the module the FIPS profile pins: clang 17.0.6 and ninja 1.12.1 from the Debian archive, go 1.22.3 and cmake 3.29.3 downloaded at those versions. No JDK 8 in trixie: the build runs on JDK 21 with the pom's --release 8. - ci-pr.yml / ci-build.yml: legs debian13-x86_64 and debian13-x86_64-fips, and two bare-Alpine musl-verify legs on their jars. The FIPS one is the leg with no substitute: the module's integrity check and self-tests run in an ELF constructor at dlopen, so only a real load proves the post-link patchelf left it intact. - docker/README.md, docs/musl-compatibility.md. Result: A change to the FIPS profile, or to the release profiles that is not ported to it, fails on the PR. Not a release image: the artifacts have a glibc 2.34 floor.
1 parent 8000517 commit f5cb588

6 files changed

Lines changed: 202 additions & 0 deletions

File tree

‎.github/workflows/ci-build.yml‎

Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,16 @@ jobs:
4040
- setup: al2023-x86_64-aws_lc
4141
docker-compose-run: "-f docker/docker-compose.al2023.yaml run build"
4242
docker-bake-args: "-f docker-compose.al2023.yaml"
43+
# boringssl-static on a current toolchain, and the only CI leg that builds the FIPS
44+
# profile (it needs clang-17; see docker/Dockerfile.debian13). Neither is a release
45+
# artifact. Before these legs the FIPS profile had no CI at all, so a change to the
46+
# release profiles that was not ported to it went unnoticed until a downstream build.
47+
- setup: debian13-x86_64
48+
docker-compose-run: "-f docker/docker-compose.debian-13.yaml run build"
49+
docker-bake-args: "-f docker-compose.debian-13.yaml"
50+
- setup: debian13-x86_64-fips
51+
docker-compose-run: "-f docker/docker-compose.debian-13.yaml run build-fips"
52+
docker-bake-args: "-f docker-compose.debian-13.yaml"
4353

4454
name: ${{ matrix.setup }}
4555
steps:
@@ -205,6 +215,28 @@ jobs:
205215
drop-elftools: "0"
206216
build-service: runtime-setup
207217
run-service: verify
218+
# The Debian 13-built jars: the FIPS artifact is the one that matters (its power-on
219+
# self-test and integrity check run inside an ELF constructor at dlopen, so only a
220+
# real load proves the patchelf'd library is still intact), and the default-profile
221+
# one shows what a modern-gcc build looks like on musl. bare x86_64 only: aarch64
222+
# would need an arm64 FIPS build leg, and the gcompat/nolibgcc variants add nothing
223+
# the CentOS 6 legs do not already establish.
224+
- setup: alpine-x86_64-fips
225+
os: ubuntu-24.04
226+
jars: build-debian13-x86_64-fips-jars
227+
variant: bare
228+
extra-pkgs: ""
229+
drop-elftools: "1"
230+
build-service: runtime-setup
231+
run-service: verify
232+
- setup: alpine-x86_64-debian13
233+
os: ubuntu-24.04
234+
jars: build-debian13-x86_64-jars
235+
variant: bare
236+
extra-pkgs: ""
237+
drop-elftools: "1"
238+
build-service: runtime-setup
239+
run-service: verify
208240
- setup: glibc-control-x86_64
209241
os: ubuntu-24.04
210242
jars: build-centos6-x86_64-jars

‎.github/workflows/ci-pr.yml‎

Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,16 @@ jobs:
3838
- setup: al2023-x86_64-aws_lc
3939
docker-compose-run: "-f docker/docker-compose.al2023.yaml run build"
4040
docker-bake-args: "-f docker-compose.al2023.yaml"
41+
# boringssl-static on a current toolchain, and the only CI leg that builds the FIPS
42+
# profile (it needs clang-17; see docker/Dockerfile.debian13). Neither is a release
43+
# artifact. Before these legs the FIPS profile had no CI at all, so a change to the
44+
# release profiles that was not ported to it went unnoticed until a downstream build.
45+
- setup: debian13-x86_64
46+
docker-compose-run: "-f docker/docker-compose.debian-13.yaml run build"
47+
docker-bake-args: "-f docker-compose.debian-13.yaml"
48+
- setup: debian13-x86_64-fips
49+
docker-compose-run: "-f docker/docker-compose.debian-13.yaml run build-fips"
50+
docker-bake-args: "-f docker-compose.debian-13.yaml"
4151

4252
name: ${{ matrix.setup }}
4353
steps:
@@ -267,6 +277,28 @@ jobs:
267277
drop-elftools: "0"
268278
build-service: runtime-setup
269279
run-service: verify
280+
# The Debian 13-built jars: the FIPS artifact is the one that matters (its power-on
281+
# self-test and integrity check run inside an ELF constructor at dlopen, so only a
282+
# real load proves the patchelf'd library is still intact), and the default-profile
283+
# one shows what a modern-gcc build looks like on musl. bare x86_64 only: aarch64
284+
# would need an arm64 FIPS build leg, and the gcompat/nolibgcc variants add nothing
285+
# the CentOS 6 legs do not already establish.
286+
- setup: alpine-x86_64-fips
287+
os: ubuntu-24.04
288+
jars: build-pr-debian13-x86_64-fips-jars
289+
variant: bare
290+
extra-pkgs: ""
291+
drop-elftools: "1"
292+
build-service: runtime-setup
293+
run-service: verify
294+
- setup: alpine-x86_64-debian13
295+
os: ubuntu-24.04
296+
jars: build-pr-debian13-x86_64-jars
297+
variant: bare
298+
extra-pkgs: ""
299+
drop-elftools: "1"
300+
build-service: runtime-setup
301+
run-service: verify
270302
# Control: anything failing on Alpine must pass here, or the check is at fault rather
271303
# than the artifact.
272304
- setup: glibc-control-x86_64

‎docker/Dockerfile.debian13‎

Lines changed: 72 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,72 @@
1+
ARG debian_version=13
2+
FROM debian:$debian_version
3+
# needed to do again after FROM due to docker limitation
4+
ARG debian_version
5+
ARG go_version=1.22.3
6+
ARG cmake_version=3.29.3
7+
ENV GO_VERSION $go_version
8+
ENV CMAKE_VERSION $cmake_version
9+
ENV DEBIAN_FRONTEND noninteractive
10+
11+
# A modern glibc builder for boringssl-static, and the only in-tree image that can build the
12+
# fips-boringssl-static profile. That profile pins the BoringCrypto module that holds
13+
# certificate #5244, and this image carries the build environment its security policy names:
14+
# clang 17.0.6, go 1.22.3, ninja 1.12.1, cmake 3.29.3
15+
# Debian 13 packages clang-17 at exactly 17.0.6 and ninja at exactly 1.12.1. Its cmake (3.31)
16+
# and Go (1.24) are newer than the policy's, so those two come from cmake.org and go.dev at the
17+
# policy's versions instead. patchelf 0.18 has --remove-needed; APR's buildconf wants the
18+
# `libtool` script, which is in libtool-bin.
19+
#
20+
# No JDK 8 in trixie: the build runs on JDK 21. The pom compiles with --release 8, so the
21+
# class files are still Java 8.
22+
#
23+
# Not pinned to linux/amd64 like the older images, so it can also be built natively on an
24+
# arm64 host for a quick local run. CI builds it on amd64 runners.
25+
#
26+
# Unlike the CentOS 6 image this is NOT a release builder: its artifact has a glibc 2.41 floor.
27+
# It exists to give the boringssl-static and FIPS builds CI coverage on a current toolchain.
28+
RUN apt-get update && apt-get install -y --no-install-recommends \
29+
autoconf \
30+
automake \
31+
bzip2 \
32+
ca-certificates \
33+
clang-17 \
34+
curl \
35+
g++ \
36+
gcc \
37+
git \
38+
gnupg \
39+
libapr1-dev \
40+
libtool \
41+
libtool-bin \
42+
make \
43+
ninja-build \
44+
openjdk-21-jdk-headless \
45+
patch \
46+
patchelf \
47+
perl \
48+
pkg-config \
49+
tar \
50+
unzip \
51+
wget \
52+
xz-utils \
53+
zip \
54+
&& rm -rf /var/lib/apt/lists/*
55+
56+
# dpkg's amd64/arm64 spelling matches go.dev's; cmake.org spells the arch x86_64/aarch64.
57+
RUN ARCH=$(dpkg --print-architecture) && case $ARCH in amd64) CM=x86_64;; arm64) CM=aarch64;; esac \
58+
&& wget -q https://go.dev/dl/go$GO_VERSION.linux-$ARCH.tar.gz \
59+
&& tar -C /opt -xzf go$GO_VERSION.linux-$ARCH.tar.gz && rm go$GO_VERSION.linux-$ARCH.tar.gz \
60+
&& wget -q https://github.com/Kitware/CMake/releases/download/v$CMAKE_VERSION/cmake-$CMAKE_VERSION-linux-$CM.tar.gz \
61+
&& tar -C /opt -xzf cmake-$CMAKE_VERSION-linux-$CM.tar.gz && rm cmake-$CMAKE_VERSION-linux-$CM.tar.gz \
62+
&& ln -s /opt/cmake-$CMAKE_VERSION-linux-$CM /opt/cmake \
63+
&& ln -s /usr/lib/jvm/java-21-openjdk-$ARCH /usr/lib/jvm/java-21
64+
# The compose services run `bash -cl`, and Debian's /etc/profile resets PATH for login shells,
65+
# so ENV PATH alone is not enough: root's ~/.profile sources ~/.bashrc, which restores it.
66+
ENV PATH /opt/go/bin:/opt/cmake/bin:$PATH
67+
RUN echo 'export PATH=/opt/go/bin:/opt/cmake/bin:$PATH' >> ~/.bashrc
68+
ENV JAVA_HOME /usr/lib/jvm/java-21
69+
RUN go version && clang-17 --version | head -1 && ninja --version && cmake --version | head -1
70+
71+
# /code is a bind mount owned by the host user; newer git refuses to touch it otherwise.
72+
RUN git config --global --add safe.directory '*'

‎docker/README.md‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,20 @@ docker compose -f docker/docker-compose.opensuse.yaml -f docker/docker-compose.o
3939
docker compose -f docker/docker-compose.centos-7.yaml run cross-compile-aarch64-build
4040
```
4141

42+
## Debian 13 with java 21: boringssl-static on a current toolchain, and the FIPS profile
43+
44+
Not a release builder (glibc 2.41 floor). It is the one image that can build the
45+
`fips-boringssl-static` profile, and it carries the build environment named by the security
46+
policy of the certificate that profile pins (#5244): clang 17.0.6 and ninja 1.12.1 from the
47+
archive, go 1.22.3 and cmake 3.29.3 downloaded at those versions. Both services stop at
48+
`package`, which is where the musl compatibility check runs. Not pinned to amd64, so on an
49+
arm64 host it builds natively.
50+
51+
```
52+
docker compose -f docker/docker-compose.debian-13.yaml run build
53+
docker compose -f docker/docker-compose.debian-13.yaml run build-fips
54+
```
55+
4256
etc, etc
4357

4458

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
version: "3"
2+
3+
# Debian 13 builder. Two things run here that no other image covers, see Dockerfile.debian13:
4+
# build boringssl-static (default profile) on a current gcc, so the Linux native
5+
# build is exercised somewhere other than the CentOS 6 release image
6+
# build-fips the fips-boringssl-static profile, which needs clang-17
7+
# Both stop at `package`, which is where the native-jar musl check runs.
8+
9+
services:
10+
11+
runtime-setup:
12+
image: netty-tcnative-debian:13
13+
build:
14+
context: ../
15+
dockerfile: docker/Dockerfile.debian13
16+
args:
17+
debian_version: "13"
18+
19+
common: &common
20+
image: netty-tcnative-debian:13
21+
depends_on: [runtime-setup]
22+
environment:
23+
- MAVEN_OPTS
24+
volumes:
25+
- ~/.m2/repository:/root/.m2/repository
26+
- ..:/code:delegated
27+
working_dir: /code
28+
29+
build:
30+
<<: *common
31+
command: /bin/bash -cl "./mvnw -am -pl boringssl-static clean package"
32+
33+
build-fips:
34+
<<: *common
35+
command: /bin/bash -cl "./mvnw -Pfips-boringssl-static -am -pl boringssl-static clean package"
36+
37+
shell:
38+
<<: *common
39+
volumes:
40+
- ~/.m2/repository:/root/.m2/repository
41+
- ~/.gitconfig:/root/.gitconfig:delegated
42+
- ~/.gitignore:/root/.gitignore:delegated
43+
- ..:/code:delegated
44+
entrypoint: /bin/bash

‎docs/musl-compatibility.md‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -224,6 +224,14 @@ The check must go further than loading. Minimum bar, in order of strength:
224224

225225
Only (3) would catch a library that loads but whose crypto is broken.
226226

227+
In CI this is the `musl-verify` job. It runs against the CentOS 6 and CentOS 7 release jars on
228+
several Alpine variants, and, bare x86_64 only, against the two Debian 13 jars: the
229+
default-profile one and the **FIPS** one (`debian13-x86_64-fips`, see `docker/Dockerfile.debian13`).
230+
The FIPS leg is the one with no substitute: its power-on self-test and integrity check run in an
231+
ELF constructor during `dlopen`, so only a real load shows that the post-link `patchelf` left the
232+
module intact. Before that leg existed the FIPS profile was built by nobody but downstream users,
233+
and a change made to the release profiles and not ported to it surfaced only there.
234+
227235
Two TLS 1.3 behaviours will make a naive handshake test report false failures:
228236
- the client reaches `NOT_HANDSHAKING` while the server still sits in `NEED_UNWRAP` waiting
229237
for optional post-handshake traffic — treat an idle `NEED_UNWRAP` as settled;

0 commit comments

Comments
 (0)