Merge nucleic/gentle-willow-quail-cjp3 into dev
This commit is contained in:
@@ -0,0 +1,17 @@
|
||||
Package: naros-identity
|
||||
Version: @VERSION@
|
||||
Architecture: @ARCH@
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: utils
|
||||
Priority: optional
|
||||
Depends: libc6
|
||||
Description: narOS kernel identity shim (NAROS.md §2.3)
|
||||
narOS ships no kernel of its own — containers share the host's and the VM tiers
|
||||
boot an externally-fetched vmlinux — so uname(2) reports a kernel with no narOS
|
||||
in it, and every consumer that derives an OS string from it (notably the
|
||||
`OS Version:` line agent harnesses build from os.type()+os.release()) misses the
|
||||
identity that /etc/os-release carries. This package preloads a small interposer
|
||||
via /etc/ld.so.preload that appends the narOS release tag to utsname.release,
|
||||
the way a distro kernel package does. sysname stays "Linux" so build tooling
|
||||
that switches on it is unaffected; NAROS_UNAME_PASSTHROUGH=1 disables the tag
|
||||
for callers that resolve /lib/modules/`uname -r`.
|
||||
@@ -0,0 +1,35 @@
|
||||
#!/bin/sh
|
||||
# Register the identity shim in /etc/ld.so.preload (NAROS.md §2.3).
|
||||
#
|
||||
# Idempotent, and additive rather than authoritative: the file is rewritten preserving any
|
||||
# other entries, so this package never owns unrelated preloads. The write goes through a
|
||||
# temp file + rename because /etc/ld.so.preload is read by the loader on EVERY exec — a
|
||||
# partially written list would be observed by whatever runs during the write.
|
||||
set -e
|
||||
|
||||
LIB=/usr/lib/naros/libnaros-uname.so
|
||||
PRELOAD=/etc/ld.so.preload
|
||||
TMP="$PRELOAD.naros-tmp"
|
||||
|
||||
case "$1" in
|
||||
configure)
|
||||
# Belt and braces: never point the loader at a library that is not on disk.
|
||||
if [ ! -f "$LIB" ]; then
|
||||
echo "naros-identity: $LIB missing, not registering preload" >&2
|
||||
exit 0
|
||||
fi
|
||||
if [ -f "$PRELOAD" ] && grep -qxF "$LIB" "$PRELOAD"; then
|
||||
exit 0
|
||||
fi
|
||||
if [ -f "$PRELOAD" ]; then
|
||||
cat "$PRELOAD" > "$TMP"
|
||||
else
|
||||
: > "$TMP"
|
||||
fi
|
||||
echo "$LIB" >> "$TMP"
|
||||
chmod 0644 "$TMP"
|
||||
mv "$TMP" "$PRELOAD"
|
||||
;;
|
||||
esac
|
||||
|
||||
exit 0
|
||||
@@ -0,0 +1,28 @@
|
||||
#!/bin/sh
|
||||
# Deregister the identity shim from /etc/ld.so.preload before its files are removed
|
||||
# (NAROS.md §2.3), so the loader never names a library that is no longer on disk.
|
||||
#
|
||||
# Runs on remove/deconfigure only: on `upgrade` the entry must persist, since the
|
||||
# replacement .so lands at the same path and the new postinst is a no-op.
|
||||
set -e
|
||||
|
||||
LIB=/usr/lib/naros/libnaros-uname.so
|
||||
PRELOAD=/etc/ld.so.preload
|
||||
TMP="$PRELOAD.naros-tmp"
|
||||
|
||||
case "$1" in
|
||||
remove | deconfigure)
|
||||
[ -f "$PRELOAD" ] || exit 0
|
||||
# grep exits 1 when nothing survives the filter; that is the empty case, not an error.
|
||||
grep -vxF "$LIB" "$PRELOAD" > "$TMP" || true
|
||||
if [ -s "$TMP" ]; then
|
||||
chmod 0644 "$TMP"
|
||||
mv "$TMP" "$PRELOAD"
|
||||
else
|
||||
# An empty ld.so.preload is legal but pointless — drop the file entirely.
|
||||
rm -f "$TMP" "$PRELOAD"
|
||||
fi
|
||||
;;
|
||||
esac
|
||||
|
||||
exit 0
|
||||
@@ -0,0 +1,25 @@
|
||||
# Stage the prebuilt narOS kernel identity shim (os/src/naros-identity, built per-arch
|
||||
# into dist/bin by that dir's build.sh / the CI binaries job).
|
||||
#
|
||||
# /etc/ld.so.preload is written by the postinst rather than shipped in files/: dpkg
|
||||
# unpacks a package's files in no guaranteed order, so a shipped preload file could land
|
||||
# before the .so it names and make every binary exec'd for the rest of that transaction —
|
||||
# including dpkg's own maintainer scripts — emit a loader warning. The postinst runs
|
||||
# after the whole package is on disk, so the reference is never dangling.
|
||||
# The /lib/modules alias unit rides along with a static enable symlink (rather than a
|
||||
# `systemctl enable` in the postinst) so it takes effect inside the mmdebstrap chroot,
|
||||
# where no systemd is running — the same pattern nucleic-linux-agent uses.
|
||||
stage() {
|
||||
local dest="$1" arch="$2"
|
||||
local lib="$OS_DIR/dist/bin/libnaros-uname-$arch.so"
|
||||
local unit="$OS_DIR/src/naros-identity/naros-identity-modules.service"
|
||||
if [ ! -f "$lib" ]; then
|
||||
echo "prebuilt shim missing: dist/bin/libnaros-uname-$arch.so" > "$dest/.skip-reason"
|
||||
return 1
|
||||
fi
|
||||
install -D -m 0644 "$lib" "$dest/usr/lib/naros/libnaros-uname.so"
|
||||
install -D -m 0644 "$unit" "$dest/usr/lib/systemd/system/naros-identity-modules.service"
|
||||
install -d "$dest/etc/systemd/system/sysinit.target.wants"
|
||||
ln -sf /usr/lib/systemd/system/naros-identity-modules.service \
|
||||
"$dest/etc/systemd/system/sysinit.target.wants/naros-identity-modules.service"
|
||||
}
|
||||
@@ -4,7 +4,7 @@ Architecture: all
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: metapackages
|
||||
Priority: optional
|
||||
Depends: nash, nash-default-shell, naros-init, naros, ca-certificates, curl, git, openssh-client, iproute2
|
||||
Depends: nash, nash-default-shell, naros-init, naros, naros-identity, ca-certificates, curl, git, openssh-client, iproute2
|
||||
Recommends: naros-keyring
|
||||
Description: narOS base tier (NAROS.md §4)
|
||||
The minimal narOS surface: nash forced as the default shell, naros-init, the
|
||||
|
||||
Reference in New Issue
Block a user