2017-05-11 22:15:10 +01:00
|
|
|
FROM debian:jessie-slim as builder
|
2017-05-10 21:55:40 +01:00
|
|
|
|
2017-05-11 22:15:10 +01:00
|
|
|
ARG ARCH=x86_64
|
|
|
|
ARG DEBIAN_FRONTEND=noninteractive
|
2017-05-10 21:55:40 +01:00
|
|
|
|
2017-08-02 22:02:14 +01:00
|
|
|
ARG GLIBC_VER=2.26
|
|
|
|
ARG BUSYB_VER=1.27.1
|
2017-05-12 01:30:49 +01:00
|
|
|
ARG SU_EXEC_VER=v0.2
|
2017-08-02 22:02:14 +01:00
|
|
|
ARG TINI_VER=v0.15.0
|
2017-05-12 01:30:49 +01:00
|
|
|
|
2017-05-22 17:06:05 +01:00
|
|
|
ARG PREFIX=/output
|
|
|
|
WORKDIR $PREFIX
|
2017-05-11 10:36:22 +01:00
|
|
|
|
2017-05-11 23:37:11 +01:00
|
|
|
#Set up our dependencies, configure the output filesystem a bit
|
2017-05-11 22:15:10 +01:00
|
|
|
RUN apt-get update -qy && \
|
2017-05-12 11:50:24 +01:00
|
|
|
apt-get install -qy curl build-essential gawk linux-libc-dev && \
|
2017-05-22 17:05:55 +01:00
|
|
|
mkdir -p bin dev etc home lib proc root sbin tmp usr/bin usr/sbin usr/lib var && \
|
2017-05-22 17:27:07 +01:00
|
|
|
# This is probably only relevant on 64bit systems?
|
2017-05-22 17:05:55 +01:00
|
|
|
ln -sv lib lib64
|
2017-05-11 23:37:11 +01:00
|
|
|
|
2017-05-12 01:30:49 +01:00
|
|
|
# Pull busybox and some other utilities
|
2017-08-02 22:28:58 +01:00
|
|
|
RUN curl -L https://busybox.net/downloads/binaries/${BUSYB_VER}-defconfig-multiarch/busybox-${ARCH} > bin/busybox && \
|
2017-05-12 13:43:42 +01:00
|
|
|
curl -L https://github.com/javabean/su-exec/releases/download/${SU_EXEC_VER}/su-exec.amd64 > sbin/su-exec && \
|
2017-05-12 14:07:18 +01:00
|
|
|
curl -L https://github.com/krallin/tini/releases/download/${TINI_VER}/tini-amd64 > sbin/tini && \
|
2017-05-12 14:08:17 +01:00
|
|
|
chmod +x bin/busybox sbin/su-exec sbin/tini && \
|
2017-05-22 17:27:07 +01:00
|
|
|
# "Install" busybox, creating symlinks to all binaries it provides
|
2017-08-02 22:28:58 +01:00
|
|
|
bin/busybox --list-full | xargs -i ln -s /bin/busybox "${PREFIX}/{}"
|
2017-05-12 00:34:57 +01:00
|
|
|
|
2017-05-10 21:55:40 +01:00
|
|
|
WORKDIR /tmp
|
|
|
|
|
2017-05-12 11:50:24 +01:00
|
|
|
ARG CFLAGS="-Os -pipe -fstack-protector-strong"
|
|
|
|
ARG LDFLAGS="-Wl,-O1,--sort-common -Wl,-s"
|
|
|
|
|
|
|
|
# Download and build glibc from source
|
2017-08-02 22:28:58 +01:00
|
|
|
RUN curl -L https://ftp.gnu.org/gnu/glibc/glibc-${GLIBC_VER}.tar.xz | tar xJ && \
|
2017-05-12 11:50:24 +01:00
|
|
|
mkdir -p glibc-build && cd glibc-build && \
|
|
|
|
\
|
|
|
|
echo "slibdir=/lib" >> configparms && \
|
|
|
|
echo "rtlddir=/lib" >> configparms && \
|
|
|
|
echo "sbindir=/bin" >> configparms && \
|
|
|
|
echo "rootsbindir=/bin" >> configparms && \
|
|
|
|
\
|
2017-05-22 17:27:07 +01:00
|
|
|
# Fix debian lib path weirdness
|
2017-08-02 22:30:15 +01:00
|
|
|
rm -rf /usr/include/${ARCH}-linux-gnu/c++ && \
|
|
|
|
ln -s /usr/include/${ARCH}-linux-gnu/* /usr/include && \
|
2017-05-22 17:27:07 +01:00
|
|
|
\
|
2017-08-02 22:28:58 +01:00
|
|
|
../glibc-${GLIBC_VER}/configure \
|
2017-05-12 11:50:24 +01:00
|
|
|
--prefix="$(pwd)/root" \
|
|
|
|
--libdir="$(pwd)/root/lib" \
|
|
|
|
--libexecdir=/lib \
|
|
|
|
--with-headers=/usr/include \
|
|
|
|
--enable-add-ons \
|
|
|
|
--enable-obsolete-rpc \
|
|
|
|
--enable-kernel=3.10.0 \
|
|
|
|
--enable-bind-now \
|
|
|
|
--disable-profile \
|
|
|
|
--enable-stackguard-randomization \
|
|
|
|
--enable-stack-protector=strong \
|
|
|
|
--enable-lock-elision \
|
|
|
|
--enable-multi-arch \
|
|
|
|
--disable-werror && \
|
|
|
|
make && make install_root=$(pwd)/out install
|
|
|
|
|
|
|
|
# Copy glibc libs & generate ld cache
|
2017-08-02 22:28:58 +01:00
|
|
|
RUN cp -d glibc-build/out/lib/*.so "${PREFIX}/lib" && \
|
|
|
|
echo '/usr/lib' > "${PREFIX}/etc/ld.so.conf" && \
|
|
|
|
ldconfig -r "${PREFIX}"
|
2017-05-12 11:50:24 +01:00
|
|
|
|
2017-05-22 18:09:32 +01:00
|
|
|
WORKDIR $PREFIX
|
|
|
|
|
|
|
|
# Add root user and group
|
|
|
|
RUN echo 'root:x:0:0:root:/root:/bin/sh'\\n\
|
|
|
|
'nobody:x:65534:65534:nobody:/:/sbin/nologin' \
|
|
|
|
> etc/passwd && \
|
|
|
|
echo 'root:::0:::::\nnobody:!::0:::::' \
|
|
|
|
> etc/shadow && \
|
|
|
|
echo 'root:x:0:root\nnogroup:x:65533\nnobody:x:65544' \
|
|
|
|
> etc/group
|
|
|
|
|
2017-05-11 22:15:10 +01:00
|
|
|
# =============
|
|
|
|
|
|
|
|
FROM scratch
|
2017-05-10 21:55:40 +01:00
|
|
|
WORKDIR /
|
2017-05-12 00:34:57 +01:00
|
|
|
COPY --from=builder /output/ /
|
2017-05-11 22:15:10 +01:00
|
|
|
CMD ["sh"]
|