From 27d085a4490a24f580eec6c27de40f5884518f30 Mon Sep 17 00:00:00 2001 From: Nucleic Date: Tue, 21 Jul 2026 02:31:12 -0700 Subject: [PATCH] Merge nucleic/gentle-river-seal-pfoj into dev --- images/agent/Dockerfile | 10 ++++++++++ packages/build-all.sh | 6 ++++++ .../files/etc/apt/sources.list.d/naros.sources | 2 +- 3 files changed, 17 insertions(+), 1 deletion(-) diff --git a/images/agent/Dockerfile b/images/agent/Dockerfile index 46fb594..73cb179 100644 --- a/images/agent/Dockerfile +++ b/images/agent/Dockerfile @@ -55,6 +55,14 @@ COPY pool /tmp/naros-pool # resolves, or apt would pull trixie's older nodejs alongside it. RUN set -eu; \ echo "deb [trusted=yes] copy:///tmp/naros-pool ./" > /etc/apt/sources.list.d/naros-pool.list; \ + # The base bakes naros-keyring's hosted-repo entry (naros.sources) — the runtime + # apt channel. Set it aside for the whole build (here, and under playwright + # --with-deps below) so THIS stage installs only from the local pool + Node source + # above: the freshly built naros-tier-agent must resolve from this run's pool, not a + # same-version deb already published to the hosted channel. It also keeps the image + # build independent of the hosted repo — the same reason the base rootfs smoke test + # scopes sources.list.d away. Restored in the final stage so the image ships it. + mv /etc/apt/sources.list.d/naros.sources /tmp/naros.sources.disabled 2>/dev/null || true; \ mkdir -p -m 755 /etc/apt/keyrings; \ curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key \ -o /etc/apt/keyrings/nodesource.asc; \ @@ -175,6 +183,8 @@ RUN set -eu; \ # toolchain + version, cache paths) so `naros info` / the host probe read one file # instead of probing binary-by-binary. RUN set -eu; \ + # Restore the hosted runtime apt channel set aside at the start of the build. + mv /tmp/naros.sources.disabled /etc/apt/sources.list.d/naros.sources 2>/dev/null || true; \ sed -i -e 's/^VARIANT=.*/VARIANT="agent"/' -e 's/^VARIANT_ID=.*/VARIANT_ID=agent/' /etc/os-release; \ node_v="$(node --version)"; \ python_v="$(python3 -c 'import platform; print(platform.python_version())')"; \ diff --git a/packages/build-all.sh b/packages/build-all.sh index 990e415..97d7a8d 100755 --- a/packages/build-all.sh +++ b/packages/build-all.sh @@ -45,6 +45,12 @@ build_one() { # trap 'rm -rf "$stage"' RETURN [ -d "$d/files" ] && cp -a "$d/files/." "$stage/" + # The runtime apt source's suite must mirror the channel it was published under + # (dists/; NAROS.md §3.2 "Suites mirror channels"), so @CHANNEL@ is templated + # here the same way @VERSION@/@ARCH@ are templated into control. Targeted rather than a + # blanket sed so binary payloads in files/ (e.g. the keyring .gpg) are never rewritten. + [ -f "$stage/etc/apt/sources.list.d/naros.sources" ] && \ + sed -i "s/@CHANNEL@/$CHANNEL/g" "$stage/etc/apt/sources.list.d/naros.sources" if [ -f "$d/stage.sh" ]; then # shellcheck source=/dev/null ( set -euo pipefail; OS_DIR="$OS_DIR" . "$d/stage.sh"; stage "$stage" "$arch" ) || { diff --git a/packages/naros-keyring/files/etc/apt/sources.list.d/naros.sources b/packages/naros-keyring/files/etc/apt/sources.list.d/naros.sources index 16aad90..2feb712 100644 --- a/packages/naros-keyring/files/etc/apt/sources.list.d/naros.sources +++ b/packages/naros-keyring/files/etc/apt/sources.list.d/naros.sources @@ -1,5 +1,5 @@ Types: deb URIs: https://apt.naros.nucleic.blakeslee.xyz -Suites: stable +Suites: @CHANNEL@ Components: main Signed-By: /usr/share/keyrings/naros-archive-keyring.gpg