## AC Native OS — Reproducible Build Container (make-clean) ## ## Usage (from repo root): ## docker build -t ac-os-builder -f fedac/native/Dockerfile.builder . ## docker run --rm -v $(pwd)/out:/out ac-os-builder ## ## The source is COPY'd into the image — no bind mounts needed. ## Output: /out/vmlinuz + /out/build.json FROM fedora:43 # ── All packages needed for ac-native + kernel build ── RUN dnf install -y --setopt=install_weak_deps=False \ gcc ccache make cpio lz4 pigz bc perl flex bison diffutils \ elfutils-libelf-devel openssl-devel \ gnu-efi-devel \ curl jq file git tar xz findutils pkgconf-pkg-config zstd xorriso \ openssh-clients ripgrep \ bash \ ca-certificates \ alsa-lib-devel libdrm-devel flite-devel SDL3-devel raylib-devel freetype-devel \ ffmpeg-free-devel \ wpa_supplicant dhcp-client iw \ iwlwifi-mvm-firmware wireless-regdb \ linux-firmware linux-firmware-whence \ intel-gpu-firmware \ realtek-firmware \ alsa-sof-firmware \ busybox mtools dosfstools hfsplus-tools hfsutils gdisk parted \ flashrom \ mesa-libgbm mesa-libgbm-devel \ mesa-libEGL mesa-libEGL-devel \ mesa-libGLES mesa-libGLES-devel \ mesa-dri-drivers \ alsa-lib alsa-firmware alsa-ucm \ openssl nodejs npm dropbear efibootmgr \ sbcl \ && dnf clean all && rm -rf /var/cache/dnf # ── Install Quicklisp + CL dependencies for Lisp build variant ── RUN mkdir -p /cache \ && curl -sfo /tmp/ql.lisp https://beta.quicklisp.org/quicklisp.lisp \ && sbcl --non-interactive \ --load /tmp/ql.lisp \ --eval '(quicklisp-quickstart:install :path "/opt/quicklisp/")' \ --eval '(ql:quickload (list :cffi :bordeaux-threads :alexandria :swank))' \ && rm /tmp/ql.lisp # ── Pre-download QuickJS + Linux kernel source ── # The kernel pre-download is a warm-start optimization: docker-build.sh # prefers the persistent /kernel-build volume and only reads /cache when # that volume is empty. cdn.kernel.org purges EOL series (6.19.9 vanished) # and has outages, so try it with -f (no HTML piped into xz), fall back to # a git.kernel.org tag snapshot, and continue image-building either way — # docker-build.sh downloads loudly at runtime if the source is truly absent. RUN mkdir -p /cache && cd /cache \ && curl -fsL https://bellard.org/quickjs/quickjs-2024-01-13.tar.xz | tar xJ \ && ln -sf quickjs-2024-01-13 quickjs \ && { curl -fsL https://cdn.kernel.org/pub/linux/kernel/v6.x/linux-6.19.9.tar.xz | tar xJ \ || curl -fsL https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/snapshot/linux-6.19.9.tar.gz | tar xz \ || echo "=== WARN: kernel pre-download skipped (mirrors down) ==="; } \ && echo "=== Cached: QuickJS (+ Linux 6.19.9 if mirrors were up) ===" # ── ChromeOS-flavored ALSA UCM (Use Case Manager) configs ── # Upstream alsa-ucm-conf has no entry for sof-rt5682 (Chromebook JSL boards). # Without UCM the DAPM graph stays in whatever default state the topology # sets, which on sof-rt5682+mx98360a leaves the Speakers path disabled even # after `Spk Switch=on`. WeirdTreeThing's fork ships the downstream # ChromeOS UCM files — mirror them into the builder image so # docker-build.sh can copy them into the initramfs at # /usr/share/alsa/ucm2/ (see WeirdTreeThing/chromebook-linux-audio). RUN git clone --depth 1 \ https://github.com/WeirdTreeThing/alsa-ucm-conf-cros \ /opt/alsa-ucm-conf-cros # ── Build cbfstool from coreboot source ── # Fedora doesn't package coreboot utilities and coreboot.org/releases stopped # hosting pre-packaged tarballs, so we sparse-checkout just util/cbfstool # off GitHub (the full repo is 600MB+). The util tree is self-contained and # builds cleanly with gcc + make. Installed to /usr/local/bin so # docker-build.sh's firmware-panel bundling step finds it with `command -v`. RUN git clone --depth 1 --branch 4.22 --filter=blob:none --sparse \ https://github.com/coreboot/coreboot /tmp/coreboot \ && cd /tmp/coreboot \ && git sparse-checkout set util/cbfstool src/commonlib src/vendorcode \ && git submodule update --init --depth 1 3rdparty/vboot \ && cd util/cbfstool \ && make -j"$(nproc)" HOSTCFLAGS="-Wno-error -Wno-calloc-transposed-args -Wno-unterminated-string-initialization" cbfstool \ && install -m 0755 cbfstool /usr/local/bin/cbfstool \ && cd / && rm -rf /tmp/coreboot # ── Install esbuild for KidLisp bundling ── RUN npm install -g esbuild # ── Install Claude Code CLI (native binary) ── RUN curl -fsSL https://claude.ai/install.sh | bash 2>/dev/null \ && CLAUDE_BIN=$(find /root/.local/share/claude/versions -type f 2>/dev/null | sort -V | tail -1) \ && if [ -n "$CLAUDE_BIN" ]; then cp "$CLAUDE_BIN" /usr/local/bin/claude-native && chmod +x /usr/local/bin/claude-native; fi \ || echo "Claude Code install skipped (non-fatal)" # ── Verify tools ── # ── vboot-utils: vbutil_kernel + public devkeys for the Chromebook kernel # partition (docker-build.sh packs vmlinuz.kpart; stock Chromebook firmware # boots it in developer mode via Ctrl+U). ── RUN dnf install -y --setopt=install_weak_deps=False vboot-utils \ && dnf clean all && rm -rf /var/cache/dnf \ && command -v vbutil_kernel \ && { find /usr/share -path '*devkeys/kernel.keyblock' | grep -q . \ || { mkdir -p /usr/share/vboot/devkeys \ && curl -fsSL "https://chromium.googlesource.com/chromiumos/platform/vboot_reference/+archive/HEAD/tests/devkeys.tar.gz" \ | tar -xz -C /usr/share/vboot/devkeys \ && test -f /usr/share/vboot/devkeys/kernel.keyblock; }; } RUN gcc --version | head -1 && busybox --help >/dev/null 2>&1 && esbuild --version && echo "OK" # ── Copy source into image ── COPY . /repo # ── Copy build script ── COPY fedac/native/docker-build.sh /docker-build.sh RUN chmod +x /docker-build.sh ENV AC_SRC=/repo ENTRYPOINT ["/docker-build.sh"] # cache-bust 1774407968