# SPDX-FileCopyrightText: 2026 Stan Grams <sjg@haxx.space>
#
# SPDX-License-Identifier: GPL-2.0-or-later

# trx-rs SDK / build image.
#
# Single source of truth for the build environment. Used two ways:
#   * CI  — as the job container for the lint/test jobs (Docker executor).
#   * Dev — run locally or via .devcontainer for a reproducible toolchain.
#
# Pinning the Rust version here (and in rust-toolchain.toml) means CI and every
# developer share the exact same rustc/clippy, so "works locally, fails in CI"
# cannot happen.
FROM docker.io/library/debian:bookworm-slim

# Keep in sync with rust-toolchain.toml.
ARG RUST_VERSION=1.97.1
ARG NODE_MAJOR=20

ENV DEBIAN_FRONTEND=noninteractive \
    RUSTUP_HOME=/usr/local/rustup \
    CARGO_HOME=/usr/local/cargo \
    PATH=/usr/local/cargo/bin:/usr/local/bin:/usr/bin:/bin

# Build dependencies (mirror README's manual instructions).
RUN apt-get update && apt-get install -y --no-install-recommends \
        ca-certificates curl git \
        build-essential pkg-config cmake clang libclang-dev \
        libopus-dev libasound2-dev libsoapysdr-dev chromium \
    && rm -rf /var/lib/apt/lists/*

# Node.js — JS-based actions (actions/checkout, actions/cache) run *inside*
# the job container under the Docker executor, so node must be present.
RUN curl -fsSL https://deb.nodesource.com/setup_${NODE_MAJOR}.x | bash - \
    && apt-get install -y --no-install-recommends nodejs \
    && rm -rf /var/lib/apt/lists/*

# Pinned Rust toolchain, installed world-readable so any UID the runner or a
# devcontainer uses can invoke cargo.
RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs \
      | sh -s -- -y --no-modify-path \
        --default-toolchain "${RUST_VERSION}" --profile minimal \
        --component rustfmt --component clippy \
    && chmod -R a+rwX "$RUSTUP_HOME" "$CARGO_HOME"

# sccache — shared compilation cache. Enabled at build time via
# RUSTC_WRAPPER (see the CI workflow and .devcontainer), not repo-wide, so
# non-SDK builds are unaffected. musl build is static and runs anywhere.
#
# The release asset is per-architecture, so resolve it from `uname -m` rather
# than hardcoding one triple: everything else in this image is arch-agnostic,
# and a pinned x86_64 URL is what forces an amd64 build (and Rosetta or qemu)
# on an arm64 host. `uname -m` reflects the build platform under plain
# docker/podman build as well as buildx, unlike the BuildKit-only TARGETARCH.
ARG SCCACHE_VERSION=0.8.2
RUN set -eux; \
    case "$(uname -m)" in \
      x86_64)  sccache_arch=x86_64 ;; \
      aarch64|arm64) sccache_arch=aarch64 ;; \
      *) echo "unsupported architecture for sccache: $(uname -m)" >&2; exit 1 ;; \
    esac; \
    sccache_dist="sccache-v${SCCACHE_VERSION}-${sccache_arch}-unknown-linux-musl"; \
    curl -fsSL "https://github.com/mozilla/sccache/releases/download/v${SCCACHE_VERSION}/${sccache_dist}.tar.gz" \
      | tar -xz -C /tmp; \
    install -m755 "/tmp/${sccache_dist}/sccache" /usr/local/bin/sccache; \
    rm -rf /tmp/sccache-*

WORKDIR /work
