Merge nucleic/lucid-lunar-wren-wxyw into dev

This commit is contained in:
2026-07-21 01:19:00 -07:00
parent e48c604421
commit ee401ff5b4
16 changed files with 275 additions and 6 deletions
+1
View File
@@ -0,0 +1 @@
20260701T000000Z
+22 -3
View File
@@ -25,8 +25,26 @@ while [ $# -gt 0 ]; do
done
VERSION="$(cat "$OS_DIR/VERSION")"
SNAPSHOT="$(cat "$OS_DIR/SNAPSHOT")"
SUITE="trixie"
# Per-flavor base (NAROS.md §7.4): the VM DESKTOP flavor (N5) builds entirely from a pinned
# Debian FORKY (testing) snapshot for GNOME 50 — trixie ships only GNOME 48 — while every
# other tier, including the HEADLESS VM, stays on the trixie snapshot. One coherent pocket per
# rootfs, no trixie/forky ABI mixing. VARIANT is the os-release identity class
# (base/agent/runner/vm, §2.3); FLAVOR distinguishes the two VM rootfs builds within
# VARIANT=vm (headless vs desktop).
case "$TIER" in
vm-desktop)
SUITE="forky"; VARIANT="vm"; FLAVOR="desktop"
SNAPSHOT="$(cat "$OS_DIR/SNAPSHOT.forky" 2>/dev/null || cat "$OS_DIR/SNAPSHOT")"
;;
vm)
SUITE="trixie"; VARIANT="vm"; FLAVOR="headless"
SNAPSHOT="$(cat "$OS_DIR/SNAPSHOT")"
;;
*)
SUITE="trixie"; VARIANT="$TIER"; FLAVOR=""
SNAPSHOT="$(cat "$OS_DIR/SNAPSHOT")"
;;
esac
MIRROR="https://snapshot.debian.org/archive/debian/${SNAPSHOT}/"
PROFILE="$OS_DIR/mkimage/profiles/$TIER.pkgs"
[ -f "$PROFILE" ] || { echo "no profile for tier '$TIER' ($PROFILE)" >&2; exit 2; }
@@ -89,7 +107,8 @@ mkdir -p "$OUT"
TAR="$OUT/naros-$TIER-$VERSION-$ARCH.tar"
export NAROS_TIER="$TIER" NAROS_VERSION="$VERSION" NAROS_ARCH="$ARCH" \
NAROS_CHANNEL="$CHANNEL" NAROS_SNAPSHOT="$SNAPSHOT" NAROS_SUITE="$SUITE"
NAROS_CHANNEL="$CHANNEL" NAROS_SNAPSHOT="$SNAPSHOT" NAROS_SUITE="$SUITE" \
NAROS_VARIANT="$VARIANT" NAROS_FLAVOR="$FLAVOR"
HOOKS=()
if [ "${#LATE_DEBS[@]}" -gt 0 ]; then
+14 -3
View File
@@ -6,6 +6,15 @@
set -eu
R="$1"
# VARIANT is the os-release identity class (base/agent/runner/vm, §2.3); the build passes it
# separately from NAROS_TIER so the two VM flavors (vm, vm-desktop) both report VARIANT=vm and
# carry the headless/desktop distinction in NAROS_FLAVOR. Fallback to the tier for older callers.
VARIANT="${NAROS_VARIANT:-$NAROS_TIER}"
FLAVOR="${NAROS_FLAVOR:-}"
# naros-init/systemd role: the VM tiers boot as a guest (systemd PID 1, §5); everything else is
# a container surface.
case "$VARIANT" in vm) ROLE="vm" ;; *) ROLE="container" ;; esac
# mmdebstrap writes every build source into the target's sources.list — including the
# CI-local [trusted=yes] copy:// pool, which doesn't exist at runtime and would fail
# every `apt update` in a running container. Keep only the real mirrors (the pinned
@@ -21,8 +30,8 @@ ID_LIKE=debian
VERSION_ID="$NAROS_VERSION"
VERSION="$NAROS_VERSION ($NAROS_CHANNEL)"
VERSION_CODENAME=$NAROS_SUITE
VARIANT="$NAROS_TIER"
VARIANT_ID=$NAROS_TIER
VARIANT="$VARIANT"
VARIANT_ID=$VARIANT
HOME_URL="https://github.com/abkslm/nucleic"
DOCUMENTATION_URL="https://github.com/abkslm/nucleic/blob/main/docs/NAROS.md"
EOF
@@ -30,7 +39,7 @@ EOF
mkdir -p "$R/etc/naros"
echo "$NAROS_CHANNEL" > "$R/etc/naros/channel"
echo "$NAROS_SNAPSHOT" > "$R/etc/naros/snapshot-date"
echo "container" > "$R/etc/naros/role"
echo "$ROLE" > "$R/etc/naros/role"
# Capability manifest (NAROS.md §6.3). Base fields here; toolchain entries are appended
# by the tiers that install them (agent-tier hook, N2). Versions of Nucleic packages are
@@ -43,6 +52,8 @@ cat > "$R/etc/naros/manifest.json" <<EOF
"version": "$NAROS_VERSION",
"channel": "$NAROS_CHANNEL",
"tier": "$NAROS_TIER",
"variant": "$VARIANT",
"flavor": "$FLAVOR",
"arch": "$NAROS_ARCH",
"debian": { "suite": "$NAROS_SUITE", "snapshot": "$NAROS_SNAPSHOT" },
"nash": $nash_ver,
+11
View File
@@ -0,0 +1,11 @@
# dpkg -i in a finish hook, after every Debian + GNOME package is configured (build-rootfs.sh).
# nash-default-shell MUST configure last — its divert flips /bin/sh to nash, and nothing may
# configure under nash mid-build (the reason the whole desktop stack is --include'd first).
# dpkg orders this batch by dependency, so the divert lands before the metas that depend on it,
# and naros-desktop-config (agent user, GDM auto-login, dconf, geometry helper, Firefox policy)
# before the tier meta that pulls it.
nash-default-shell
naros-tier-base
naros-tier-vm
naros-desktop-config
naros-tier-vm-desktop
+12
View File
@@ -0,0 +1,12 @@
# Nucleic packages baked into the naros-vm desktop rootfs, from the local pool. The base
# layer (nash forced + naros identity + hosted-repo trust) plus BOTH guest agents — the vsock
# control-plane agent (exec) and the AT-SPI semantic agent (ax_*). They install via apt
# --include (deps resolved) with no divert trigger; the divert + tier metas configure last
# (vm-desktop.late-pkgs). The GNOME-Shell geometry helper + desktop config ride
# naros-desktop-config (a late meta), not this list.
nash
naros-init
naros
naros-keyring
nucleic-linux-agent
nucleic-a11y-agent
+58
View File
@@ -0,0 +1,58 @@
# naros-vm DESKTOP flavor — Debian package list (NAROS.md §7.4, milestone N5).
#
# Built entirely from a pinned Debian FORKY snapshot (build-rootfs.sh maps vm-desktop→forky)
# because forky ships GNOME 50 / Mutter 50 — the compositor the semantic agent targets —
# while trixie is stuck at GNOME 48. One coherent forky pocket, no trixie/forky ABI mixing.
#
# The GNOME 50 stack is BAKED here at build time (not pulled at firstboot): the whole desktop
# rootfs is one CI-built pocket, so a base build never drags ~1.5 GB from snapshot.debian.org.
# These are apt --include'd (dependencies resolved from forky); the Nucleic layer + tier metas
# configure last (vm-desktop.late-pkgs) so the nash divert stays the final step.
#
# No linux-image — external kernel + its modules ride the two-phase payload (LINUX_VM.md).
# systemd as PID 1 (§5: the VM desktop flavor keeps systemd) + networking/udev/dbus/sudo.
systemd
systemd-sysv
systemd-resolved
udev
dbus
dbus-user-session
sudo
# GNOME 50 Wayland session: shell/Mutter + GDM auto-login, a couple of GTK4 reference apps so
# a fresh screenshot isn't an empty desktop, XWayland for X clients, Mesa for software GL.
gnome-session
gnome-shell
gnome-shell-extension-prefs
gdm3
gnome-console
gnome-text-editor
xwayland
libgl1-mesa-dri
# Accessibility stack — the AT-SPI D-Bus registry the semantic agent consumes, plus the GI
# bindings its Python/host tooling uses, and the settings/dconf plumbing for system defaults.
at-spi2-core
gsettings-desktop-schemas
dconf-cli
python3-gi
gir1.2-atspi-2.0
# Reference browser for computer-use / the semantic agent. Debian ships a real Firefox deb
# (unlike Ubuntu's snap shim), so no Mozilla-apt dance is needed — firefox-esr from forky.
firefox-esr
fonts-dejavu-core
# Modest dev toolchain, mirroring the guest it replaces (agents also exec/build in the VM).
build-essential
git
curl
ca-certificates
openssh-client
iproute2
python3
python3-venv
python3-pip
nodejs
npm
+14
View File
@@ -0,0 +1,14 @@
Package: naros-desktop-config
Version: @VERSION@
Architecture: all
Maintainer: Nucleic <[email protected]>
Section: misc
Priority: optional
Depends: gdm3, dconf-cli, dbus, at-spi2-core, nash
Description: narOS VM desktop configuration (NAROS.md §7.4 N5; LINUX_VM_SEMANTIC_AGENT.md)
The Nucleic desktop policy the old Ubuntu provisioner applied by hand, packaged:
the `agent` auto-login account (uid 501, nash shell, passwordless sudo), GDM
Wayland auto-login, system dconf defaults (AT-SPI on, integer scale = 1, no
idle/lock/blank, GNOME welcome suppressed, the Mutter geometry-helper extension
enabled), the geometry-helper GNOME Shell extension itself, QT_ACCESSIBILITY, and
boot-to-graphical. Installing it turns the naros base into the computer-use guest.
@@ -0,0 +1,32 @@
# System-wide dconf defaults for the naros-vm desktop guest (NAROS.md §7.4 N5). Applied to the
# auto-login agent session without a per-user seed. Ported from the old Ubuntu provisioner's
# dconf block (docs/LINUX_VM_SEMANTIC_AGENT.md Phase 2). `dconf update` (postinst) compiles this.
[org/gnome/desktop/interface]
# Turn the AT-SPI bridge on for GTK/GNOME apps so the semantic agent sees their trees — the
# whole point of the desktop flavor.
toolkit-accessibility=true
# Integer display scale = 1 (no fractional scaling): the invariant that makes the compositor's
# window coordinates equal the virtio-gpu scanout pixels the host captures 1:1, so ax_dump
# frames are directly clickable.
scaling-factor=uint32 1
[org/gnome/mutter]
# Do NOT enable fractional scaling — keep logical == physical pixels.
experimental-features=@as []
[org/gnome/desktop/session]
idle-delay=uint32 0
[org/gnome/desktop/screensaver]
lock-enabled=false
idle-activation-enabled=false
[org/gnome/settings-daemon/plugins/power]
sleep-inactive-ac-type='nothing'
sleep-inactive-battery-type='nothing'
[org/gnome/shell]
welcome-dialog-last-shown-version='99.0'
disable-user-extensions=false
# The Nucleic Mutter geometry helper (focused-window global origin for the AT-SPI agent).
enabled-extensions=['[email protected]']
@@ -0,0 +1,2 @@
user-db:user
system-db:local
@@ -0,0 +1,4 @@
# Qt apps read this to enable their AT-SPI bridge (GTK does so automatically once the a11y bus
# is up). systemd's user session sources /etc/environment.d/*.conf into the graphical session.
# Chromium/Electron still need a per-launch --force-renderer-accessibility (the agent handles it).
QT_ACCESSIBILITY=1
@@ -0,0 +1,3 @@
# narOS agent user (NAROS.md §6.1): frictionless escalation for `apt install` etc.,
# non-interactive. The disposable, NAT-isolated VM is the isolation boundary.
agent ALL=(ALL) NOPASSWD:ALL
+42
View File
@@ -0,0 +1,42 @@
#!/bin/sh
# Realize the naros-vm desktop policy (NAROS.md §7.4 N5). Runs at image-build configure time in
# the mmdebstrap chroot (no running systemd) — every step is offline-safe.
set -e
[ "$1" = "configure" ] || exit 0
# 1. The narOS `agent` user GDM auto-logs into. uid 501 is in lockstep with the sandbox/agent
# tiers (the uid ContainerEngine execs as); login shell is the contract nash path.
if ! id -u agent >/dev/null 2>&1; then
useradd --uid 501 --user-group --create-home --home-dir /home/agent \
--shell /usr/local/bin/nash agent
fi
for g in video input render sudo; do
getent group "$g" >/dev/null 2>&1 && usermod -aG "$g" agent || true
done
passwd -l agent >/dev/null 2>&1 || true # auto-login only, no password
# 2. sudoers drop-in must be 0440 (git can't track that mode).
chmod 0440 /etc/sudoers.d/naros-agent 2>/dev/null || true
# 3. GDM auto-login into the agent's Wayland session, so the host surface sees a live screen.
# (Debian gdm3 reads /etc/gdm3/daemon.conf; we own the desktop policy, so write it whole.)
mkdir -p /etc/gdm3
cat > /etc/gdm3/daemon.conf <<'GDM'
[daemon]
WaylandEnable=true
AutomaticLoginEnable=true
AutomaticLogin=agent
GDM
# 4. Compile the system dconf defaults (AT-SPI on, scale=1, no idle/lock, geometry ext enabled).
dconf update 2>/dev/null || true
# 5. Boot to the graphical session.
systemctl set-default graphical.target >/dev/null 2>&1 || true
# 6. Skip GNOME's first-run tour so the first host screenshot is a usable desktop.
mkdir -p /home/agent/.config
echo yes > /home/agent/.config/gnome-initial-setup-done
chown -R agent:agent /home/agent/.config 2>/dev/null || true
exit 0
+11
View File
@@ -0,0 +1,11 @@
# Stage the Mutter geometry-helper GNOME Shell extension (guest/mutter-geometry-helper) into
# the system extensions dir. It exposes the focused window's true global origin over a private
# D-Bus name for the AT-SPI agent (AT-SPI loses the window origin on Wayland) — enabled via the
# dconf default in files/etc/dconf/db/local.d/00-nucleic. Arch-independent (JS + metadata).
stage() {
local dest="$1"
local ext="$dest/usr/share/gnome-shell/extensions/[email protected]"
local src="$OS_DIR/../guest/mutter-geometry-helper"
install -D -m 0644 "$src/metadata.json" "$ext/metadata.json"
install -D -m 0644 "$src/extension.js" "$ext/extension.js"
}
+15
View File
@@ -0,0 +1,15 @@
Package: naros-tier-vm-desktop
Version: @VERSION@
Architecture: all
Maintainer: Nucleic <[email protected]>
Section: metapackages
Priority: optional
Depends: naros-tier-vm, naros-desktop-config, nucleic-a11y-agent, gnome-session, gnome-shell, gdm3, at-spi2-core, xwayland, firefox-esr
Description: narOS VM guest tier — desktop flavor (GNOME 50, NAROS.md §7.4, milestone N5)
The full computer-use / semantic-agent surface, layered on the headless VM tier
(naros-tier-vm). Ties together the GNOME 50 / Mutter Wayland session (baked from
the pinned Debian forky snapshot), GDM auto-login, the AT-SPI accessibility bus,
the Rust semantic agent (nucleic-a11y-agent), and the Nucleic desktop config
(naros-desktop-config: agent auto-login user, dconf defaults, Mutter geometry
helper, Firefox policy). Built into the naros-vm-desktop rootfs, not apt-installed
at firstboot.
+13
View File
@@ -0,0 +1,13 @@
Package: nucleic-a11y-agent
Version: @VERSION@
Architecture: @ARCH@
Maintainer: Nucleic <[email protected]>
Section: admin
Priority: optional
Depends: at-spi2-core
Description: Nucleic Linux guest AT-SPI semantic agent (NAROS.md §7.4 N5; LINUX_VM_SEMANTIC_AGENT.md)
The Rust (zbus/tokio) accessibility agent — the ax_* semantic control plane over
AF_VSOCK port 2036. A systemd USER service inside the graphical session so it can
reach that session's AT-SPI a11y bus. Baked into the naros-vm desktop flavor
(pulled by naros-tier-vm-desktop); complements the static-C nucleic-linux-agent
(exec, port 2035). Absent → the host falls back to screenshot + pixel actions.
+21
View File
@@ -0,0 +1,21 @@
# Stage the prebuilt Rust AT-SPI semantic agent + its systemd USER unit, with a static
# global-enable symlink so it starts in every graphical session (no `systemctl --global
# enable` needed inside the mmdebstrap chroot). Prefer the CI-built dist/bin binary; fall
# back to the committed guest build (arm64) — the same artifact the pre-narOS base build bakes.
stage() {
local dest="$1" arch="$2"
local bin="$OS_DIR/dist/bin/nucleic-a11y-agent-$arch"
if [ ! -x "$bin" ] && [ "$arch" = arm64 ]; then
bin="$OS_DIR/../guest/nucleic-a11y-agent/build/nucleic-a11y-agent"
fi
local unit="$OS_DIR/../guest/nucleic-a11y-agent/systemd/nucleic-a11y-agent.service"
if [ ! -x "$bin" ]; then
echo "prebuilt binary missing: dist/bin/nucleic-a11y-agent-$arch" > "$dest/.skip-reason"
return 1
fi
install -D -m 0755 "$bin" "$dest/usr/local/bin/nucleic-a11y-agent"
install -D -m 0644 "$unit" "$dest/usr/lib/systemd/user/nucleic-a11y-agent.service"
install -d "$dest/etc/systemd/user/graphical-session.target.wants"
ln -sf /usr/lib/systemd/user/nucleic-a11y-agent.service \
"$dest/etc/systemd/user/graphical-session.target.wants/nucleic-a11y-agent.service"
}