Merge nucleic/clever-quartz-marten-uqnx into dev

This commit is contained in:
2026-07-18 21:19:16 -07:00
parent f40e456924
commit ddde19bf42
3 changed files with 83 additions and 7 deletions
+5 -1
View File
@@ -4,7 +4,11 @@ Architecture: all
Maintainer: Nucleic <[email protected]> Maintainer: Nucleic <[email protected]>
Section: metapackages Section: metapackages
Priority: optional Priority: optional
Depends: naros-tier-base, nucleic-bridge, build-essential, pkg-config, python3, python3-pip, python3-venv, sudo, gh, ripgrep, fd-find, jq, yq, sqlite3, htop, tree, zip, unzip, zstd, xz-utils, moreutils, rsync, less, procps, file, bsdextrautils Depends: naros-tier-base, nucleic-bridge, build-essential, pkg-config,
python3, python3-pip, python3-venv, sudo, gh, ripgrep, fd-find, jq, yq,
sqlite3, htop, tree, zip, unzip, zstd, xz-utils, moreutils, rsync, less,
procps, file, bsdextrautils, e2fsprogs, util-linux-extra, mount, login,
gpgv
Description: narOS agent tier — apt-resolvable half (NAROS.md §4, §6) Description: narOS agent tier — apt-resolvable half (NAROS.md §4, §6)
The dev toolchain and modern CLI kit that come from Debian, plus the control The dev toolchain and modern CLI kit that come from Debian, plus the control
bridge. The non-apt half of the agent tier — Node (NodeSource), rustup, Go, bridge. The non-apt half of the agent tier — Node (NodeSource), rustup, Go,
+74 -2
View File
@@ -4,10 +4,82 @@
# node:22 image plumbing, not a tool agents use. # node:22 image plumbing, not a tool agents use.
docker-entrypoint.sh docker-entrypoint.sh
policy-rc.d
# The node:22 image ships node under /usr/local with npx/corepack symlinked there; # The node:22 image ships node under /usr/local with npx/corepack symlinked there;
# NodeSource's deb provides the same commands at /usr/bin — same names, so only # NodeSource's deb provides the same commands at /usr/bin — same names, so only
# image-internal helper names should ever land here, not node/npm/npx/corepack. # image-internal helper names should ever land here, not node/npm/npx/corepack.
# bookworm→trixie package renames/drops surface here as they are DISCOVERED and # Removed Debian transition/deprecation helpers. narOS is natively merged-/usr and
# understood in CI — do not pre-seed guesses. # uses signed-by keyrings instead of apt-key.
apt-key
dpkg-fsys-usrunmess
# Version-pinned Bookworm compiler names. Trixie's build-essential provides the
# current GCC suite and the same unversioned commands.
cpp-12
g++-12
gcc-12
gcc-ar-12
gcc-nm-12
gcc-ranlib-12
gcov-12
gcov-dump-12
gcov-tool-12
lto-dump-12
x86_64-linux-gnu-cpp-12
x86_64-linux-gnu-g++-12
x86_64-linux-gnu-gcc-12
x86_64-linux-gnu-gcc-ar-12
x86_64-linux-gnu-gcc-nm-12
x86_64-linux-gnu-gcc-ranlib-12
x86_64-linux-gnu-gcov-12
x86_64-linux-gnu-gcov-dump-12
x86_64-linux-gnu-gcov-tool-12
x86_64-linux-gnu-lto-dump-12
# Version-pinned Bookworm Python 3.11 and Perl 5.36 names. Trixie's python3,
# pip3, pydoc3, pygettext3, perl and cpan commands remain available.
cpan5.36-x86_64-linux-gnu
pdb3.11
perl5.36-x86_64-linux-gnu
perl5.36.0
pip3.11
pydoc3.11
pygettext3.11
python3.11
# GNU gold is deprecated, while these target-prefixed gprofng aliases and dwp
# are no longer emitted by Trixie's binutils. Current ld, gprofng and gp-* tools
# remain available.
dwp
gold
ld.gold
x86_64-linux-gnu-dwp
x86_64-linux-gnu-gold
x86_64-linux-gnu-gp-archive
x86_64-linux-gnu-gp-collect-app
x86_64-linux-gnu-gp-display-html
x86_64-linux-gnu-gp-display-src
x86_64-linux-gnu-gp-display-text
x86_64-linux-gnu-gprofng
x86_64-linux-gnu-ld.gold
# Commands removed from Trixie's util-linux/shadow packages. Block-device,
# filesystem, mount and login capabilities that still have Trixie packages are
# installed explicitly by naros-tier-agent; these obsolete interfaces are not.
addpart
cpgr
cppw
delpart
faillog
groupmems
last
lastb
lastlog
mesg
utmpdump
# Historical compatibility aliases; the canonical commands remain available.
md5sum.textutils
slogin
+4 -4
View File
@@ -65,10 +65,6 @@ allow_filter "$tmp/removed.all" > "$tmp/unexplained" || true
echo "PATH: $(wc -l < "$tmp/ref.path") reference, $(wc -l < "$tmp/cand.path") candidate," \ echo "PATH: $(wc -l < "$tmp/ref.path") reference, $(wc -l < "$tmp/cand.path") candidate," \
"$(wc -l < "$tmp/removed.path") removed, $added_path added" "$(wc -l < "$tmp/removed.path") removed, $added_path added"
echo "npm globals removed: $(wc -l < "$tmp/removed.npm")" echo "npm globals removed: $(wc -l < "$tmp/removed.npm")"
if [ -s "$tmp/removed.all" ]; then
echo "--- removed (before allowlist) ---"
cat "$tmp/removed.all"
fi
if [ -s "$tmp/unexplained" ]; then if [ -s "$tmp/unexplained" ]; then
echo "PARITY FAILURE — present in $REF, missing from $CAND, not allowlisted:" >&2 echo "PARITY FAILURE — present in $REF, missing from $CAND, not allowlisted:" >&2
@@ -76,4 +72,8 @@ if [ -s "$tmp/unexplained" ]; then
echo "(fix the image, or add to $ALLOW with a comment explaining the removal)" >&2 echo "(fix the image, or add to $ALLOW with a comment explaining the removal)" >&2
exit 1 exit 1
fi fi
if [ -s "$tmp/removed.all" ]; then
echo "--- deliberate removals (allowlisted) ---"
cat "$tmp/removed.all"
fi
echo "parity OK" echo "parity OK"