Merge nucleic/gentle-river-seal-pfoj into dev

This commit is contained in:
2026-07-21 02:31:12 -07:00
parent c66662aa80
commit 27d085a449
3 changed files with 17 additions and 1 deletions
+10
View File
@@ -55,6 +55,14 @@ COPY pool /tmp/naros-pool
# resolves, or apt would pull trixie's older nodejs alongside it.
RUN set -eu; \
echo "deb [trusted=yes] copy:///tmp/naros-pool ./" > /etc/apt/sources.list.d/naros-pool.list; \
# The base bakes naros-keyring's hosted-repo entry (naros.sources) — the runtime
# apt channel. Set it aside for the whole build (here, and under playwright
# --with-deps below) so THIS stage installs only from the local pool + Node source
# above: the freshly built naros-tier-agent must resolve from this run's pool, not a
# same-version deb already published to the hosted channel. It also keeps the image
# build independent of the hosted repo — the same reason the base rootfs smoke test
# scopes sources.list.d away. Restored in the final stage so the image ships it.
mv /etc/apt/sources.list.d/naros.sources /tmp/naros.sources.disabled 2>/dev/null || true; \
mkdir -p -m 755 /etc/apt/keyrings; \
curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key \
-o /etc/apt/keyrings/nodesource.asc; \
@@ -175,6 +183,8 @@ RUN set -eu; \
# toolchain + version, cache paths) so `naros info` / the host probe read one file
# instead of probing binary-by-binary.
RUN set -eu; \
# Restore the hosted runtime apt channel set aside at the start of the build.
mv /tmp/naros.sources.disabled /etc/apt/sources.list.d/naros.sources 2>/dev/null || true; \
sed -i -e 's/^VARIANT=.*/VARIANT="agent"/' -e 's/^VARIANT_ID=.*/VARIANT_ID=agent/' /etc/os-release; \
node_v="$(node --version)"; \
python_v="$(python3 -c 'import platform; print(platform.python_version())')"; \