# SPDX-FileCopyrightText: 2026 Stan Grams # # SPDX-License-Identifier: GPL-2.0-or-later # trx-rs SDK / build image. # # Single source of truth for the build environment. Used two ways: # * CI — as the job container for the lint/test jobs (Docker executor). # * Dev — run locally or via .devcontainer for a reproducible toolchain. # # Pinning the Rust version here (and in rust-toolchain.toml) means CI and every # developer share the exact same rustc/clippy, so "works locally, fails in CI" # cannot happen. FROM docker.io/library/debian:bookworm-slim # Keep in sync with rust-toolchain.toml. ARG RUST_VERSION=1.97.1 ARG NODE_MAJOR=20 ENV DEBIAN_FRONTEND=noninteractive \ RUSTUP_HOME=/usr/local/rustup \ CARGO_HOME=/usr/local/cargo \ PATH=/usr/local/cargo/bin:/usr/local/bin:/usr/bin:/bin # Build dependencies (mirror README's manual instructions). RUN apt-get update && apt-get install -y --no-install-recommends \ ca-certificates curl git \ build-essential pkg-config cmake clang libclang-dev \ libopus-dev libasound2-dev libsoapysdr-dev chromium \ && rm -rf /var/lib/apt/lists/* # Node.js — JS-based actions (actions/checkout, actions/cache) run *inside* # the job container under the Docker executor, so node must be present. RUN curl -fsSL https://deb.nodesource.com/setup_${NODE_MAJOR}.x | bash - \ && apt-get install -y --no-install-recommends nodejs \ && rm -rf /var/lib/apt/lists/* # Pinned Rust toolchain, installed world-readable so any UID the runner or a # devcontainer uses can invoke cargo. RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs \ | sh -s -- -y --no-modify-path \ --default-toolchain "${RUST_VERSION}" --profile minimal \ --component rustfmt --component clippy \ && chmod -R a+rwX "$RUSTUP_HOME" "$CARGO_HOME" # sccache — shared compilation cache. Enabled at build time via # RUSTC_WRAPPER (see the CI workflow and .devcontainer), not repo-wide, so # non-SDK builds are unaffected. musl build is static and runs anywhere. # # The release asset is per-architecture, so resolve it from `uname -m` rather # than hardcoding one triple: everything else in this image is arch-agnostic, # and a pinned x86_64 URL is what forces an amd64 build (and Rosetta or qemu) # on an arm64 host. `uname -m` reflects the build platform under plain # docker/podman build as well as buildx, unlike the BuildKit-only TARGETARCH. ARG SCCACHE_VERSION=0.8.2 RUN set -eux; \ case "$(uname -m)" in \ x86_64) sccache_arch=x86_64 ;; \ aarch64|arm64) sccache_arch=aarch64 ;; \ *) echo "unsupported architecture for sccache: $(uname -m)" >&2; exit 1 ;; \ esac; \ sccache_dist="sccache-v${SCCACHE_VERSION}-${sccache_arch}-unknown-linux-musl"; \ curl -fsSL "https://github.com/mozilla/sccache/releases/download/v${SCCACHE_VERSION}/${sccache_dist}.tar.gz" \ | tar -xz -C /tmp; \ install -m755 "/tmp/${sccache_dist}/sccache" /usr/local/bin/sccache; \ rm -rf /tmp/sccache-* WORKDIR /work