Repository navigation
Expand file tree
/
Copy pathDockerfile
More file actions
92 lines (84 loc) · 4.54 KB
/
Copy pathDockerfile
File metadata and controls
92 lines (84 loc) · 4.54 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
# ============================================================================
# semantic-diff dev container
# ----------------------------------------------------------------------------
# WHAT THIS PROVIDES
# A Linux/x86_64 (or arm64) build environment for semantic-diff, which links
# against rustc internals (rustc_private: rustc_middle, rustc_data_structures,
# StableHasher) and runs as a custom rustc codegen-backend shim. The HOST is
# darwin/arm64 with only stable Rust 1.91 and CANNOT build this project, so
# this container is MANDATORY for every build, every test, and the M0 gate.
#
# It pins:
# - a nightly rustc by exact date (StableHasher output and rustc_private
# APIs drift across nightlies; the fingerprint is only stable on a frozen
# toolchain — this date is load-bearing). See rust-toolchain.toml, which
# must match PINNED_NIGHTLY below.
# - the rustc-dev + rust-src components (compiler internals + std sources),
# added via `rustup component add`. RUSTC_BOOTSTRAP=1 is set in the env so
# the stable-channel binary will accept the unstable rustc_private feature
# and -Z flags (e.g. -Z mir-opt-level=0).
#
# The pinned nightly below (2026-04-03) is the same one cuda-oxide ships
# against, verified to carry rustc-dev + rust-src and the codegen-backend /
# collect_and_partition_mono_items / type_id_hash APIs this project reuses.
# rustowl pins nightly-2026-01-16 for the same StableHasher pipeline; both are
# compatible reference points. Bump deliberately, never incidentally: any
# nightly change requires a full fingerprint re-baseline (see docs/spec.md
# "re-baseline protocol").
#
# CAPABILITIES / PRIVILEGES
# NONE. semantic-diff does not trace syscalls, touch the kernel, or need
# /dev access. No --privileged and no --cap-add are required. Run plainly:
# docker build -t semantic-diff-dev .
# docker run --rm -it -v "$PWD":/work -w /work semantic-diff-dev bash
# (For the M0 double-build the script uses `git worktree`, so bind-mount the
# repo read-write as above; no extra host access is needed.)
#
# DO NOT build this image as part of doc/harness scaffolding — it is for the
# M1+ implementation phase.
# ============================================================================
FROM debian:bookworm-slim
# Pinned nightly — MUST match rust-toolchain.toml. Load-bearing; bumping it
# invalidates every committed fingerprint (.sdiff/*.idx) and forces re-baseline.
ARG PINNED_NIGHTLY=nightly-2026-04-03
ENV PINNED_NIGHTLY=${PINNED_NIGHTLY}
# Required so the toolchain accepts rustc_private + unstable -Z flags.
ENV RUSTC_BOOTSTRAP=1
ENV RUSTUP_HOME=/usr/local/rustup \
CARGO_HOME=/usr/local/cargo \
PATH=/usr/local/cargo/bin:$PATH
# Build tooling. NOT version-pinned, deliberately: the only pin load-bearing for
# fingerprint determinism is the Rust nightly below. libssl/curl/git/gcc never
# enter the MIR fingerprint — we hash pre-optimization MIR inside rustc, before
# LLVM codegen and linking, so the system C/SSL layer has zero influence on
# StableHasher output. Exact apt-version pins (build-essential=12.9, libssl-dev=
# 3.0.16-1~deb12u1, ...) only rot: Debian drops superseded patch versions from
# the mirror, breaking the build for no reproducibility gain. The honest pin is
# the toolchain; pinning the system layer here would be theater. (Repro of the
# system layer, if ever needed, belongs on snapshot.debian.org, not inline pins.)
RUN apt-get update && \
apt-get install -y --no-install-recommends \
build-essential \
ca-certificates \
curl \
git \
pkg-config \
libssl-dev \
&& rm -rf /var/lib/apt/lists/*
# Install rustup, then the pinned nightly with the compiler-internals components.
# rustc-dev -> the rustc_private crates (rustc_middle, rustc_data_structures, ...)
# rust-src -> std sources, needed to monomorphize/inspect std MIR
# llvm-tools -> for delegating real codegen to LLVM from the backend shim
RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs \
| sh -s -- -y --default-toolchain none --profile minimal && \
rustup toolchain install "${PINNED_NIGHTLY}" \
--profile minimal \
-c rustc-dev -c rust-src -c llvm-tools && \
rustup default "${PINNED_NIGHTLY}" && \
rustc --version && \
rustc --print sysroot
WORKDIR /work
# Sanity at build time: confirm the internals component is actually present.
RUN ls "$(rustc --print sysroot)/lib/rustlib/src/rust" >/dev/null \
&& echo "rust-src + rustc-dev present for ${PINNED_NIGHTLY}"
CMD ["/bin/bash"]