Nucleic: Build Script Error Investigation

This commit is contained in:
2026-07-18 20:49:08 -07:00
parent 86582c2c68
commit 21258870d1
+10 -5
View File
@@ -13,8 +13,9 @@
# Build via build.sh (assembles the context: this directory + the dist/pool apt pool). # Build via build.sh (assembles the context: this directory + the dist/pool apt pool).
# NOTE: every RUN here executes under nash — /bin/sh is already diverted in naros-base. # NOTE: every RUN here executes under nash — /bin/sh is already diverted in naros-base.
# That is deliberate dogfood (this build is part of nash's M3 validation surface); nash's # That is deliberate dogfood (this build is part of nash's M3 validation surface); nash's
# parse-failure fallback re-execs the preserved /usr/bin/bash.real, so a nash regression # `-c` parse-failure fallback re-execs the preserved /usr/bin/bash.real, so a nash
# degrades loudly in CI rather than silently corrupting the image. # regression degrades loudly in CI rather than silently corrupting the image. Scripts
# piped on stdin do not cross that fallback and must choose their interpreter explicitly.
ARG BASE=naros-base:build ARG BASE=naros-base:build
FROM ${BASE} FROM ${BASE}
@@ -72,7 +73,10 @@ RUN set -eu; \
# Everything world-readable so the non-root agent uses them in place (§6.1: no /root # Everything world-readable so the non-root agent uses them in place (§6.1: no /root
# permission hacks — system paths or /opt by convention). # permission hacks — system paths or /opt by convention).
RUN set -eu; \ RUN set -eu; \
curl -fsSL https://sh.rustup.rs | sh -s -- -y --profile minimal \ # nash's parse fallback applies to `-c`, not scripts supplied on stdin.
# Upstream installers are outside the dogfood surface, so run them with the
# preserved Debian bash instead of feeding them to the diverted sh/bash.
curl -fsSL https://sh.rustup.rs | /usr/bin/bash.real -s -- -y --profile minimal \
--default-toolchain stable --no-modify-path; \ --default-toolchain stable --no-modify-path; \
"$CARGO_HOME/bin/rustc" --version; \ "$CARGO_HOME/bin/rustc" --version; \
case "$TARGETARCH" in \ case "$TARGETARCH" in \
@@ -133,8 +137,9 @@ RUN npm install -g @anthropic-ai/claude-code@latest \
# xAI Grok Build via its official installer, relocated from the 0700 /root to a # xAI Grok Build via its official installer, relocated from the 0700 /root to a
# world-traversable /opt and relinked onto PATH (same dance as nucleic-sandbox v4+ — # world-traversable /opt and relinked onto PATH (same dance as nucleic-sandbox v4+ —
# narOS keeps agent-reachable installs out of /root by convention). # narOS keeps agent-reachable installs out of /root by convention). As with rustup, the
RUN curl -fsSL https://x.ai/cli/install.sh | bash \ # stdin-fed upstream script needs the preserved real bash rather than diverted `bash`.
RUN curl -fsSL https://x.ai/cli/install.sh | /usr/bin/bash.real \
&& rm -f /usr/local/bin/grok /usr/local/bin/agent \ && rm -f /usr/local/bin/grok /usr/local/bin/agent \
&& mv /root/.grok /opt/grok \ && mv /root/.grok /opt/grok \
&& chmod -R a+rX /opt/grok \ && chmod -R a+rX /opt/grok \