Repository navigation
Build the FIPS profile in CI, and make it build again #1009
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
fredericgermain
wants to merge
4
commits into
netty:main
Choose a base branch
from
fredericgermain:dev-images-patchelf
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
4 commits
Select commit
Hold shift + click to select a range
6ef800a
Install patchelf in the Arch and openSUSE dev images
fredericgermain 10883d9
FIPS profile: build BoringSSL's newest FIPS branch from git, pinned
fredericgermain e30baa6
Keep the artifact loadable on musl when built with a current toolchain
fredericgermain e5ce588
CI: build boringssl-static and the FIPS profile on Debian 13, verify …
fredericgermain File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -23,6 +23,7 @@ RUN pacman -Sy --noconfirm --needed \ | |
| lsb-release \ | ||
| make \ | ||
| ninja \ | ||
| patchelf \ | ||
| perl \ | ||
| tar \ | ||
| unzip \ | ||
|
|
||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,82 @@ | ||
| # Everything in this image is pinned: the base by digest, the Debian archive by a | ||
| # snapshot.debian.org timestamp, clang by version, Go by version and checksum. To refresh it, | ||
| # bump the four values below together and rebuild. | ||
| ARG debian_image=debian:13.7@sha256:9cc080028c43b27d2074d63a5f9caf7166d731494965616c1a6d2827a004585c | ||
| FROM $debian_image | ||
| ARG debian_snapshot=20260915T000000Z | ||
| ARG clang_version=19 | ||
| ARG go_version=1.27.1 | ||
| ARG go_sha256_amd64=63d339f0da5ab53635a56f2490a7984dfe12dfcff22ad749f63edaf590168445 | ||
| ARG go_sha256_arm64=3450b45a3f9ee8568792736a5c5e70a1f2e9b36c35a8f74958c03e51d7d92bec | ||
| ENV DEBIAN_FRONTEND noninteractive | ||
|
|
||
| # A modern glibc builder for boringssl-static, and the only in-tree image that can build the | ||
| # fips-boringssl-static profile, which compiles BoringSSL with clang. Google's FIPS.md asks for | ||
| # recent stable Clang, Go, Ninja and CMake: clang, ninja and cmake are Debian 13's own. Go is | ||
| # not: BoringSSL's go.mod floor (1.25.8 on the pinned fips-20260721) is ahead of trixie's 1.24, | ||
| # so it comes from go.dev, checksum-verified. patchelf 0.18 has --remove-needed; APR's | ||
| # buildconf wants the `libtool` script, which is in libtool-bin. | ||
| # | ||
| # No JDK 8 in trixie: the build runs on JDK 21. The pom compiles with --release 8, so the | ||
| # class files are still Java 8. | ||
| # | ||
| # Not pinned to linux/amd64 like the older images, so it can also be built natively on an | ||
| # arm64 host for a quick local run. CI builds it on amd64 runners. | ||
| # | ||
| # Unlike the CentOS 6 image this is NOT a release builder: its artifact needs a newer glibc than | ||
| # the release ones. It exists to give the boringssl-static and FIPS builds CI coverage on a | ||
| # current toolchain. | ||
|
|
||
| # Freeze the archive. snapshot.debian.org serves the archive as it was at that instant, so the | ||
| # same package versions install no matter when the image is built; Valid-Until has long passed | ||
| # by then, hence check-valid-until=no. | ||
| RUN rm -f /etc/apt/sources.list.d/debian.sources \ | ||
| && echo "deb [check-valid-until=no] http://snapshot.debian.org/archive/debian/$debian_snapshot trixie main" > /etc/apt/sources.list \ | ||
| && echo "deb [check-valid-until=no] http://snapshot.debian.org/archive/debian/$debian_snapshot trixie-updates main" >> /etc/apt/sources.list \ | ||
| && echo "deb [check-valid-until=no] http://snapshot.debian.org/archive/debian-security/$debian_snapshot trixie-security main" >> /etc/apt/sources.list | ||
|
|
||
| RUN apt-get update && apt-get install -y --no-install-recommends \ | ||
| autoconf \ | ||
| automake \ | ||
| bzip2 \ | ||
| ca-certificates \ | ||
| clang-$clang_version \ | ||
| cmake \ | ||
| curl \ | ||
| g++ \ | ||
| gcc \ | ||
| git \ | ||
| gnupg \ | ||
| libapr1-dev \ | ||
| libtool \ | ||
| libtool-bin \ | ||
| make \ | ||
| ninja-build \ | ||
| openjdk-21-jdk-headless \ | ||
| patch \ | ||
| patchelf \ | ||
| perl \ | ||
| pkg-config \ | ||
| tar \ | ||
| unzip \ | ||
| wget \ | ||
| xz-utils \ | ||
| zip \ | ||
| && rm -rf /var/lib/apt/lists/* \ | ||
| && ln -s clang-$clang_version /usr/bin/clang && ln -s clang++-$clang_version /usr/bin/clang++ | ||
|
|
||
| # dpkg's amd64/arm64 spelling matches go.dev's and the JVM directory name. | ||
| RUN ARCH=$(dpkg --print-architecture) \ | ||
| && case $ARCH in amd64) GO_SHA256=$go_sha256_amd64;; arm64) GO_SHA256=$go_sha256_arm64;; esac \ | ||
| && wget -q https://go.dev/dl/go$go_version.linux-$ARCH.tar.gz \ | ||
| && echo "$GO_SHA256 go$go_version.linux-$ARCH.tar.gz" | sha256sum -c - \ | ||
| && tar -C /opt -xzf go$go_version.linux-$ARCH.tar.gz && rm go$go_version.linux-$ARCH.tar.gz \ | ||
| && ln -s /opt/go/bin/go /usr/local/bin/go && ln -s /opt/go/bin/gofmt /usr/local/bin/gofmt \ | ||
| && ln -s /usr/lib/jvm/java-21-openjdk-$ARCH /usr/lib/jvm/java-21 \ | ||
| && go version && clang --version && ninja --version && cmake --version | ||
| ENV JAVA_HOME /usr/lib/jvm/java-21 | ||
| # Use exactly the pinned Go; never let it fetch another toolchain. | ||
| ENV GOTOOLCHAIN local | ||
|
|
||
| # /code is a bind mount owned by the host user; newer git refuses to touch it otherwise. | ||
| RUN git config --global --add safe.directory '*' |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,46 @@ | ||
| version: "3" | ||
|
|
||
| # Debian 13 builder. Two things run here that no other image covers, see Dockerfile.debian13: | ||
| # build boringssl-static (default profile) on a current gcc, so the Linux native | ||
| # build is exercised somewhere other than the CentOS 6 release image | ||
| # build-fips the fips-boringssl-static profile, which needs clang | ||
| # Both stop at `package`, which is where the native-jar musl check runs. | ||
|
|
||
| services: | ||
|
|
||
| runtime-setup: | ||
| image: netty-tcnative-debian:13 | ||
| build: | ||
| context: ../ | ||
| dockerfile: docker/Dockerfile.debian13 | ||
| cache_from: | ||
| - type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:debian13 | ||
| cache_to: | ||
| - type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:debian13,mode=max,ignore-error=true | ||
|
|
||
| common: &common | ||
| image: netty-tcnative-debian:13 | ||
| depends_on: [runtime-setup] | ||
| environment: | ||
| - MAVEN_OPTS | ||
| volumes: | ||
| - ~/.m2/repository:/root/.m2/repository | ||
| - ..:/code:delegated | ||
| working_dir: /code | ||
|
|
||
| build: | ||
| <<: *common | ||
| command: /bin/bash -cl "./mvnw -am -pl boringssl-static clean package" | ||
|
|
||
| build-fips: | ||
| <<: *common | ||
| command: /bin/bash -cl "./mvnw -Pfips-boringssl-static -am -pl boringssl-static clean package" | ||
|
|
||
| shell: | ||
| <<: *common | ||
| volumes: | ||
| - ~/.m2/repository:/root/.m2/repository | ||
| - ~/.gitconfig:/root/.gitconfig:delegated | ||
| - ~/.gitignore:/root/.gitignore:delegated | ||
| - ..:/code:delegated | ||
| entrypoint: /bin/bash |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It's the tar bundle that's actually FIPS validated, isn't it? I'm not sure we can just jump to the latest commit on the boringssl fips branch.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
From https://boringssl.googlesource.com/boringssl/+/refs/heads/main/crypto/fipsmodule/FIPS.md
The last validated module is 2024-08-05 (fips-20240805), certificate (#5244, issued April 2026)
It was updated already to fips-20251031 previously in netty-tcnative. I believe this had more to do to get newer API and avoid compilation problem. So the current version is not fips validated.
FIPS.md recommand to use main directly.
Also to be noted,
https://commondatastorage.googleapis.com/chromium-boringssl-fipsis not working anymore, we need to fetch git commits directly on the upstream repo.