Merge nucleic/zesty-dewy-ferret-tlmk into dev

This commit is contained in:
2026-07-21 19:14:46 -07:00
parent fd7ed7dcf7
commit a0f73f317f
3 changed files with 38 additions and 9 deletions
+10 -3
View File
@@ -1,9 +1,16 @@
# Base Nucleic layer baked into the naros-vm rootfs so nash is the forced shell and the
# hosted apt repo is trusted from the very first boot. The vsock agent (nucleic-linux-agent)
# and the rest of the tier arrive at firstboot via `apt install naros-tier-vm` (NAROS.md
# §7.4), so they are intentionally NOT baked here — this mirrors the base tier's layer.
# hosted apt repo is trusted from the very first boot — plus the vsock control-plane agent.
#
# The agent is baked (from this same local pool, i.e. the same deb published to the hosted
# repo) because it is the host's ONLY way to reach the guest: it used to be overlaid by the
# Mac-host bootstrap from a separate GHCR artifact, but that second source could drift from
# the deb and silently win. With the overlay collapsed, apt is the single source of truth —
# and a soft-failing firstboot `apt install` is too weak a guarantee for the control plane.
# The REST of the tier (sudo, dbus, the tier meta) still arrives at firstboot via
# `apt install naros-tier-vm` (NAROS.md §7.4), which finds this dependency already satisfied.
nash
naros-init
naros
naros-identity
naros-keyring
nucleic-linux-agent
+22 -1
View File
@@ -17,12 +17,13 @@ set -euo pipefail
PKG_DIR="$(cd "$(dirname "$0")" && pwd)"
OS_DIR="$(cd "$PKG_DIR/.." && pwd)"
ARCHES="arm64,amd64" CHANNEL="${NAROS_CHANNEL:-edge}" ONLY=""
ARCHES="arm64,amd64" CHANNEL="${NAROS_CHANNEL:-edge}" ONLY="" REQUIRE=""
while [ $# -gt 0 ]; do
case "$1" in
--arch) ARCHES="$2"; shift 2 ;;
--channel) CHANNEL="$2"; shift 2 ;;
--only) ONLY="$2"; shift 2 ;;
--require) REQUIRE="$2"; shift 2 ;;
*) echo "unknown arg: $1" >&2; exit 2 ;;
esac
done
@@ -82,3 +83,23 @@ for d in "$PKG_DIR"/*/; do
build_one "$d" all
fi
done
# A missing prebuilt binary only WARNS above, so that metadata-only iteration works without a Rust
# toolchain. That leniency is wrong for the packages a guest cannot boot without: nucleic-a11y-agent
# was cross-built for arm64 only, so its amd64 deb skipped silently and simply never appeared in the
# published repo — a gap nothing failed on. --require turns the skip into an error for a named set.
if [ -n "$REQUIRE" ]; then
missing=""
IFS=, read -ra RR <<< "$REQUIRE"
IFS=, read -ra AA <<< "$ARCHES"
for name in "${RR[@]}"; do
ver="$(pkg_version "$PKG_DIR/$name")"
for a in "${AA[@]}"; do
[ -f "$POOL/${name}_${ver}_$a.deb" ] || missing="$missing ${name}_${ver}_$a.deb"
done
done
if [ -n "$missing" ]; then
echo "FATAL: required package(s) did not build (see the SKIP lines above):$missing" >&2
exit 1
fi
fi
+6 -5
View File
@@ -1,13 +1,14 @@
# Stage the prebuilt Rust AT-SPI semantic agent + its systemd USER unit, with a static
# global-enable symlink so it starts in every graphical session (no `systemctl --global
# enable` needed inside the mmdebstrap chroot). Prefer the CI-built dist/bin binary; fall
# back to the committed guest build (arm64) — the same artifact the pre-narOS base build bakes.
# enable` needed inside the mmdebstrap chroot).
#
# dist/bin is the ONLY source. There used to be an arm64-only fallback to a committed
# guest/nucleic-a11y-agent/build/ binary, which papered over the fact that CI built this
# crate natively on arm64 and never for amd64 — so the amd64 deb silently skipped staging
# and never reached the repo. naros.yml now cross-builds both arches (musl via zigbuild).
stage() {
local dest="$1" arch="$2"
local bin="$OS_DIR/dist/bin/nucleic-a11y-agent-$arch"
if [ ! -x "$bin" ] && [ "$arch" = arm64 ]; then
bin="$OS_DIR/../guest/nucleic-a11y-agent/build/nucleic-a11y-agent"
fi
local unit="$OS_DIR/../guest/nucleic-a11y-agent/systemd/nucleic-a11y-agent.service"
if [ ! -x "$bin" ]; then
echo "prebuilt binary missing: dist/bin/nucleic-a11y-agent-$arch" > "$dest/.skip-reason"