diff --git a/Dockerfile b/Dockerfile index 17b47e5..9b80218 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,9 +1,36 @@ # syntax=docker/dockerfile:1 +FROM node:12-buster as wwwstage + +ARG KASMWEB_RELEASE="master" + +RUN \ + echo "**** build clientside ****" && \ + export QT_QPA_PLATFORM=offscreen && \ + export QT_QPA_FONTDIR=/usr/share/fonts && \ + mkdir /src && \ + cd /src && \ + wget https://github.com/kasmtech/noVNC/tarball/${KASMWEB_RELEASE} -O - \ + | tar --strip-components=1 -xz && \ + npm install && \ + npm run-script build + +RUN \ + echo "**** organize output ****" && \ + mkdir /build-out && \ + cd /src && \ + rm -rf node_modules/ && \ + cp -R ./* /build-out/ && \ + cd /build-out && \ + rm *.md && \ + rm AUTHORS && \ + cp index.html vnc.html + FROM ghcr.io/linuxserver/baseimage-fedora:37 as buildstage -ARG KASMVNC_RELEASE="1.0.1" -ARG KASMWEB_RELEASE="develop" +ARG KASMVNC_RELEASE="master" + +COPY --from=wwwstage /build-out /www RUN \ echo "**** install build deps ****" && \ @@ -35,6 +62,7 @@ RUN \ libxshmfence-devel \ libXtst-devel \ mesa-libEGL-devel \ + mesa-libgbm-devel \ mesa-libGL-devel \ meson \ nettle-devel \ @@ -60,7 +88,7 @@ RUN \ echo "**** build kasmvnc ****" && \ git clone https://github.com/kasmtech/KasmVNC.git src && \ cd /src && \ - git checkout -f release/${KASMVNC_release} && \ + git checkout -f ${KASMVNC_release} && \ sed -i \ -e '/find_package(FLTK/s@^@#@' \ -e '/add_subdirectory(tests/s@^@#@' \ @@ -72,14 +100,14 @@ RUN \ . && \ make -j4 && \ echo "**** build xorg ****" && \ - XORG_VER="1.20.7" && \ + XORG_VER="1.20.14" && \ XORG_PATCH=$(echo "$XORG_VER" | grep -Po '^\d.\d+' | sed 's#\.##') && \ wget --no-check-certificate \ - -O /tmp/xorg-server-${XORG_VER}.tar.bz2 \ - "https://www.x.org/archive/individual/xserver/xorg-server-${XORG_VER}.tar.bz2" && \ + -O /tmp/xorg-server-${XORG_VER}.tar.gz \ + "https://www.x.org/archive/individual/xserver/xorg-server-${XORG_VER}.tar.gz" && \ tar --strip-components=1 \ -C unix/xserver \ - -xf /tmp/xorg-server-${XORG_VER}.tar.bz2 && \ + -xf /tmp/xorg-server-${XORG_VER}.tar.gz && \ cd unix/xserver && \ patch -Np1 -i ../xserver${XORG_PATCH}.patch && \ patch -s -p0 < ../CVE-2022-2320-v1.20.patch && \ @@ -106,7 +134,7 @@ RUN \ --disable-dri2 \ --enable-glx \ --disable-xwayland \ - --disable-dri3 && \ + --enable-dri3 && \ find . -name "Makefile" -exec sed -i 's/-Werror=array-bounds//g' {} \; && \ make -j4 && \ echo "**** generate final output ****" && \ @@ -123,8 +151,7 @@ RUN \ ln -s /usr/lib64/dri dri && \ cd /src && \ mkdir -p builder/www && \ - curl -s https://kasm-ci.s3.amazonaws.com/kasmweb-${KASMWEB_RELEASE}.tar.gz \ - | tar xzf - -C builder/www && \ + cp -ax /www/* builder/www/ && \ cp builder/www/index.html builder/www/vnc.html && \ make servertarball && \ mkdir /build-out && \ @@ -205,7 +232,9 @@ RUN \ libstdc++ \ libwebp \ libXfont2 \ + libxshmfence \ mesa-dri-drivers \ + mesa-libgbm \ mesa-libGL \ nginx \ nodejs \ @@ -232,6 +261,8 @@ RUN \ xorg-x11-drv-amdgpu \ xorg-x11-drv-ati \ xorg-x11-drv-intel \ + xorg-x11-drv-nouveau \ + xorg-x11-drv-qxl \ xterm && \ echo "**** filesystem setup ****" && \ ln -s /usr/local/share/kasmvnc /usr/share/kasmvnc && \ diff --git a/Dockerfile.aarch64 b/Dockerfile.aarch64 index 7eddd9c..e0789ee 100644 --- a/Dockerfile.aarch64 +++ b/Dockerfile.aarch64 @@ -1,9 +1,41 @@ # syntax=docker/dockerfile:1 +FROM node:12-buster as wwwstage + +ARG KASMWEB_RELEASE="master" + +RUN \ + echo "**** install build deps ****" && \ + apt-get update && \ + apt-get install -y phantomjs + +RUN \ + echo "**** build clientside ****" && \ + export QT_QPA_PLATFORM=offscreen && \ + export QT_QPA_FONTDIR=/usr/share/fonts && \ + mkdir /src && \ + cd /src && \ + wget https://github.com/kasmtech/noVNC/tarball/${KASMWEB_RELEASE} -O - \ + | tar --strip-components=1 -xz && \ + npm install && \ + npm run-script build + +RUN \ + echo "**** organize output ****" && \ + mkdir /build-out && \ + cd /src && \ + rm -rf node_modules/ && \ + cp -R ./* /build-out/ && \ + cd /build-out && \ + rm *.md && \ + rm AUTHORS && \ + cp index.html vnc.html + FROM ghcr.io/linuxserver/baseimage-fedora:arm64v8-37 as buildstage -ARG KASMVNC_RELEASE="1.0.1" -ARG KASMWEB_RELEASE="develop" +ARG KASMVNC_RELEASE="master" + +COPY --from=wwwstage /build-out /www RUN \ echo "**** install build deps ****" && \ @@ -35,6 +67,7 @@ RUN \ libxshmfence-devel \ libXtst-devel \ mesa-libEGL-devel \ + mesa-libgbm-devel \ mesa-libGL-devel \ meson \ nettle-devel \ @@ -60,7 +93,7 @@ RUN \ echo "**** build kasmvnc ****" && \ git clone https://github.com/kasmtech/KasmVNC.git src && \ cd /src && \ - git checkout -f release/${KASMVNC_release} && \ + git checkout -f ${KASMVNC_release} && \ sed -i \ -e '/find_package(FLTK/s@^@#@' \ -e '/add_subdirectory(tests/s@^@#@' \ @@ -72,14 +105,14 @@ RUN \ . && \ make -j4 && \ echo "**** build xorg ****" && \ - XORG_VER="1.20.7" && \ + XORG_VER="1.20.14" && \ XORG_PATCH=$(echo "$XORG_VER" | grep -Po '^\d.\d+' | sed 's#\.##') && \ wget --no-check-certificate \ - -O /tmp/xorg-server-${XORG_VER}.tar.bz2 \ - "https://www.x.org/archive/individual/xserver/xorg-server-${XORG_VER}.tar.bz2" && \ + -O /tmp/xorg-server-${XORG_VER}.tar.gz \ + "https://www.x.org/archive/individual/xserver/xorg-server-${XORG_VER}.tar.gz" && \ tar --strip-components=1 \ -C unix/xserver \ - -xf /tmp/xorg-server-${XORG_VER}.tar.bz2 && \ + -xf /tmp/xorg-server-${XORG_VER}.tar.gz && \ cd unix/xserver && \ patch -Np1 -i ../xserver${XORG_PATCH}.patch && \ patch -s -p0 < ../CVE-2022-2320-v1.20.patch && \ @@ -106,7 +139,7 @@ RUN \ --disable-dri2 \ --enable-glx \ --disable-xwayland \ - --disable-dri3 && \ + --enable-dri3 && \ find . -name "Makefile" -exec sed -i 's/-Werror=array-bounds//g' {} \; && \ make -j4 && \ echo "**** generate final output ****" && \ @@ -123,8 +156,7 @@ RUN \ ln -s /usr/lib64/dri dri && \ cd /src && \ mkdir -p builder/www && \ - curl -s https://kasm-ci.s3.amazonaws.com/kasmweb-${KASMWEB_RELEASE}.tar.gz \ - | tar xzf - -C builder/www && \ + cp -ax /www/* builder/www/ && \ cp builder/www/index.html builder/www/vnc.html && \ make servertarball && \ mkdir /build-out && \ @@ -146,8 +178,9 @@ RUN \ make \ nodejs \ pulseaudio-libs-devel \ - python3 + python3 + RUN \ echo "**** grab source ****" && \ mkdir -p /kclient && \ @@ -204,7 +237,9 @@ RUN \ libstdc++ \ libwebp \ libXfont2 \ + libxshmfence \ mesa-dri-drivers \ + mesa-libgbm \ mesa-libGL \ nginx \ nodejs \ @@ -230,6 +265,8 @@ RUN \ xkeyboard-config \ xorg-x11-drv-amdgpu \ xorg-x11-drv-ati \ + xorg-x11-drv-nouveau \ + xorg-x11-drv-qxl \ xterm && \ echo "**** filesystem setup ****" && \ ln -s /usr/local/share/kasmvnc /usr/share/kasmvnc && \ diff --git a/root/etc/nginx/conf.d/default.conf b/root/defaults/default.conf similarity index 96% rename from root/etc/nginx/conf.d/default.conf rename to root/defaults/default.conf index 32e6762..2dfebc4 100644 --- a/root/etc/nginx/conf.d/default.conf +++ b/root/defaults/default.conf @@ -1,4 +1,6 @@ server { + #auth_basic "Login"; + #auth_basic_user_file /etc/nginx/.htpasswd; listen 3000 default_server; listen [::]:3000 default_server; location / { @@ -47,6 +49,8 @@ server { } server { + #auth_basic "Login"; + #auth_basic_user_file /etc/nginx/.htpasswd; listen 3001 ssl; listen [::]:3001 ssl; ssl_certificate /config/ssl/cert.pem; diff --git a/root/etc/s6-overlay/s6-rc.d/init-kasmvnc-config/dependencies.d/init-keygen b/root/etc/s6-overlay/s6-rc.d/init-kasmvnc-config/dependencies.d/init-nginx similarity index 100% rename from root/etc/s6-overlay/s6-rc.d/init-kasmvnc-config/dependencies.d/init-keygen rename to root/etc/s6-overlay/s6-rc.d/init-kasmvnc-config/dependencies.d/init-nginx diff --git a/root/etc/s6-overlay/s6-rc.d/init-keygen/run b/root/etc/s6-overlay/s6-rc.d/init-keygen/run deleted file mode 100755 index c645f22..0000000 --- a/root/etc/s6-overlay/s6-rc.d/init-keygen/run +++ /dev/null @@ -1,12 +0,0 @@ -#!/usr/bin/with-contenv bash - -if [ ! -f "/config/ssl/cert.pem" ]; then - mkdir -p /config/ssl - openssl req -new -x509 \ - -days 3650 -nodes \ - -out /config/ssl/cert.pem \ - -keyout /config/ssl/cert.key \ - -subj "/C=US/ST=CA/L=Carlsbad/O=Linuxserver.io/OU=LSIO Server/CN=*" - chmod 600 /config/ssl/cert.key - chown -R abc:abc /config/ssl -fi diff --git a/root/etc/s6-overlay/s6-rc.d/init-keygen/up b/root/etc/s6-overlay/s6-rc.d/init-keygen/up deleted file mode 100644 index cacd3ec..0000000 --- a/root/etc/s6-overlay/s6-rc.d/init-keygen/up +++ /dev/null @@ -1 +0,0 @@ -/etc/s6-overlay/s6-rc.d/init-keygen/run diff --git a/root/etc/s6-overlay/s6-rc.d/init-keygen/dependencies.d/init-os-end b/root/etc/s6-overlay/s6-rc.d/init-nginx/dependencies.d/init-os-end similarity index 100% rename from root/etc/s6-overlay/s6-rc.d/init-keygen/dependencies.d/init-os-end rename to root/etc/s6-overlay/s6-rc.d/init-nginx/dependencies.d/init-os-end diff --git a/root/etc/s6-overlay/s6-rc.d/init-nginx/run b/root/etc/s6-overlay/s6-rc.d/init-nginx/run new file mode 100755 index 0000000..035bae8 --- /dev/null +++ b/root/etc/s6-overlay/s6-rc.d/init-nginx/run @@ -0,0 +1,30 @@ +#!/usr/bin/with-contenv bash + +# nginx Path +NGINX_CONFIG=/etc/nginx/conf.d/default.conf + +# user passed env vars +CPORT="${CUSTOM_PORT:-3000}" +CHPORT="${CUSTOM_HTTPS_PORT:-3001}" +CUSER="${CUSTOM_USER:-abc}" + +# create self signed cert +if [ ! -f "/config/ssl/cert.pem" ]; then + mkdir -p /config/ssl + openssl req -new -x509 \ + -days 3650 -nodes \ + -out /config/ssl/cert.pem \ + -keyout /config/ssl/cert.key \ + -subj "/C=US/ST=CA/L=Carlsbad/O=Linuxserver.io/OU=LSIO Server/CN=*" + chmod 600 /config/ssl/cert.key + chown -R abc:abc /config/ssl +fi + +# modify nginx config +cp /defaults/default.conf ${NGINX_CONFIG} +sed -i "s/3000/$CPORT/g" ${NGINX_CONFIG} +sed -i "s/3001/$CHPORT/g" ${NGINX_CONFIG} +if [ ! -z ${PASSWORD+x} ]; then + printf "${CUSER}:$(openssl passwd -apr1 ${PASSWORD})\n" > /etc/nginx/.htpasswd + sed -i 's/#//g' ${NGINX_CONFIG} +fi diff --git a/root/etc/s6-overlay/s6-rc.d/init-keygen/type b/root/etc/s6-overlay/s6-rc.d/init-nginx/type similarity index 100% rename from root/etc/s6-overlay/s6-rc.d/init-keygen/type rename to root/etc/s6-overlay/s6-rc.d/init-nginx/type diff --git a/root/etc/s6-overlay/s6-rc.d/init-nginx/up b/root/etc/s6-overlay/s6-rc.d/init-nginx/up new file mode 100644 index 0000000..b3b5b49 --- /dev/null +++ b/root/etc/s6-overlay/s6-rc.d/init-nginx/up @@ -0,0 +1 @@ +/etc/s6-overlay/s6-rc.d/init-nginx/run diff --git a/root/etc/s6-overlay/s6-rc.d/svc-kasmvnc/run b/root/etc/s6-overlay/s6-rc.d/svc-kasmvnc/run index c18e901..245820d 100755 --- a/root/etc/s6-overlay/s6-rc.d/svc-kasmvnc/run +++ b/root/etc/s6-overlay/s6-rc.d/svc-kasmvnc/run @@ -1,7 +1,17 @@ #!/usr/bin/with-contenv bash +# Pass gpu flags if mounted +if [ -e /dev/dri/renderD* ]; then + HW3D="-hw3d" +fi +if [ -z ${DRINODE+x} ]; then + DRINODE="/dev/dri/renderD128" +fi + s6-setuidgid abc \ /usr/local/bin/Xvnc $DISPLAY \ + ${HW3D} \ + -drinode ${DRINODE} \ -disableBasicAuth \ -SecurityTypes None \ -AlwaysShared \ diff --git a/root/etc/s6-overlay/s6-rc.d/user/contents.d/init-keygen b/root/etc/s6-overlay/s6-rc.d/user/contents.d/init-nginx similarity index 100% rename from root/etc/s6-overlay/s6-rc.d/user/contents.d/init-keygen rename to root/etc/s6-overlay/s6-rc.d/user/contents.d/init-nginx