diff --git a/mkimage/profiles/vm.late-pkgs b/mkimage/profiles/vm.late-pkgs new file mode 100644 index 0000000..3387e72 --- /dev/null +++ b/mkimage/profiles/vm.late-pkgs @@ -0,0 +1,9 @@ +# Installed via dpkg -i in a finish hook, after every Debian package is configured +# (build-rootfs.sh). nash-default-shell MUST be last-stage: its divert flips /bin/sh to +# nash, and anything configured after the flip runs under nash — so the divert is the +# image's final configure step (mirrors the base tier). +# +# naros-tier-vm is deliberately NOT here: it is apt-installed at firstboot from the hosted +# repo (NAROS.md §7.4), which is what shrinks the provisioning script to the meta + glue. +nash-default-shell +naros-tier-base diff --git a/mkimage/profiles/vm.naros-pkgs b/mkimage/profiles/vm.naros-pkgs new file mode 100644 index 0000000..dde1ea9 --- /dev/null +++ b/mkimage/profiles/vm.naros-pkgs @@ -0,0 +1,8 @@ +# Base Nucleic layer baked into the naros-vm rootfs so nash is the forced shell and the +# hosted apt repo is trusted from the very first boot. The vsock agent (nucleic-linux-agent) +# and the rest of the tier arrive at firstboot via `apt install naros-tier-vm` (NAROS.md +# §7.4), so they are intentionally NOT baked here — this mirrors the base tier's layer. +nash +naros-init +naros +naros-keyring diff --git a/mkimage/profiles/vm.pkgs b/mkimage/profiles/vm.pkgs new file mode 100644 index 0000000..bf9b500 --- /dev/null +++ b/mkimage/profiles/vm.pkgs @@ -0,0 +1,22 @@ +# naros-vm headless tier — bootable base + systemd (NAROS.md §7.4, milestone N4). +# +# The VM boots the naros base userspace with **systemd as PID 1** (§5: the VM flavor keeps +# systemd). This list is deliberately just the bootable minimum: the base utility set plus +# systemd/udev. Everything Nucleic-specific beyond the base layer — the vsock agent, the +# `agent` sudoers, and (N5) the GNOME 50 desktop stack — arrives at FIRSTBOOT via +# `apt install naros-tier-vm` (§7.4), NOT baked here. +# +# No linux-image: the VM boots an externally-sourced kernel + initrd whose matching modules +# ride the two-phase payload (LINUX_VM.md; the kernel/initrd flow is a narOS non-goal to +# change). A Debian kernel here would drag a whole second linux-image. +ca-certificates +curl +git +openssh-client +iproute2 +# systemd as PID 1 + the networking/udev a bootable guest needs to reach the hosted apt +# repo at firstboot. dbus/sudo are pulled in by naros-tier-vm, not baked. +systemd +systemd-sysv +systemd-resolved +udev diff --git a/packages/naros-tier-vm/control b/packages/naros-tier-vm/control index 84a8cf0..1104103 100644 --- a/packages/naros-tier-vm/control +++ b/packages/naros-tier-vm/control @@ -4,9 +4,10 @@ Architecture: all Maintainer: Nucleic Section: metapackages Priority: optional -Depends: naros-tier-base, systemd, dbus, sudo +Depends: naros-tier-base, nucleic-linux-agent, systemd, dbus, sudo Description: narOS VM guest tier — headless scope (NAROS.md §4, §7.4, milestone N4) - The bootable-guest surface. Headless scope for now: systemd (the VM flavor - keeps it as PID 1), dbus, sudo. nucleic-linux-agent packaging, the firstboot - provisioning glue, and the GNOME 50 desktop stack (naros-desktop, N5) land in - later milestones and will extend this meta. + The bootable-guest surface, apt-installed at firstboot onto the naros base + rootfs the two-phase build boots (§7.4). Headless scope: systemd (the VM flavor + keeps it as PID 1), dbus, sudo, and the vsock control-plane agent + (nucleic-linux-agent) so linux_vm_exec works with no provisioner hand-install. + The GNOME 50 desktop stack (naros-desktop, N5) lands later and extends this meta. diff --git a/packages/nucleic-linux-agent/control b/packages/nucleic-linux-agent/control new file mode 100644 index 0000000..3f39312 --- /dev/null +++ b/packages/nucleic-linux-agent/control @@ -0,0 +1,13 @@ +Package: nucleic-linux-agent +Version: @VERSION@ +Architecture: @ARCH@ +Maintainer: Nucleic +Section: admin +Priority: optional +Description: Nucleic Linux guest vsock control-plane agent (NAROS.md §3.1, §7.4) + The dependency-free static-C agent that answers the host over AF_VSOCK + (NDJSON, port 2035): ping + the streaming exec sub-protocol linux_vm_exec + speaks. Pulled in by naros-tier-vm (apt-installed at firstboot) so a booted + guest is reachable with no hand-install; started by its systemd unit as root in the + disposable, NAT-isolated guest. Computer-use (screen capture + HID) is entirely + host-side over virtio-gpu/USB, so this agent is needed only for exec. diff --git a/packages/nucleic-linux-agent/postinst b/packages/nucleic-linux-agent/postinst new file mode 100644 index 0000000..e3a08d2 --- /dev/null +++ b/packages/nucleic-linux-agent/postinst @@ -0,0 +1,10 @@ +#!/bin/sh +# The enable symlink ships in the package (honored on next boot), so image builds need no +# action here. On a LIVE system (the §7.3 apt-install conversion path), pick the unit up and +# start it now. Guarded on a running systemd so it is a no-op inside the mmdebstrap chroot. +set -e +if [ "$1" = "configure" ] && [ -d /run/systemd/system ]; then + systemctl daemon-reload || true + systemctl enable --now nucleic-linux-agent.service || true +fi +exit 0 diff --git a/packages/nucleic-linux-agent/stage.sh b/packages/nucleic-linux-agent/stage.sh new file mode 100644 index 0000000..c03d45e --- /dev/null +++ b/packages/nucleic-linux-agent/stage.sh @@ -0,0 +1,21 @@ +# Stage the prebuilt static nucleic-linux-agent binary (the guest vsock control-plane +# agent, built per-arch from guest/nucleic-linux-agent/src/agent.c) plus its systemd unit +# and a static enable symlink. The unit is the single source in guest/…/systemd — staged +# here so the deb and the pre-narOS Ubuntu payload path can never drift. +# +# The enable symlink is shipped statically (not via `systemctl enable` in a postinst) so it +# takes effect inside the mmdebstrap chroot, where no systemd is running (NAROS.md §4). +stage() { + local dest="$1" arch="$2" + local bin="$OS_DIR/dist/bin/nucleic-linux-agent-$arch" + local unit="$OS_DIR/../guest/nucleic-linux-agent/systemd/nucleic-linux-agent.service" + if [ ! -x "$bin" ]; then + echo "prebuilt binary missing: $bin" > "$dest/.skip-reason" + return 1 + fi + install -D -m 0755 "$bin" "$dest/usr/local/bin/nucleic-linux-agent" + install -D -m 0644 "$unit" "$dest/usr/lib/systemd/system/nucleic-linux-agent.service" + install -d "$dest/etc/systemd/system/multi-user.target.wants" + ln -sf /usr/lib/systemd/system/nucleic-linux-agent.service \ + "$dest/etc/systemd/system/multi-user.target.wants/nucleic-linux-agent.service" +}