Merge nucleic/gentle-river-seal-pfoj into dev
This commit is contained in:
@@ -55,6 +55,14 @@ COPY pool /tmp/naros-pool
|
|||||||
# resolves, or apt would pull trixie's older nodejs alongside it.
|
# resolves, or apt would pull trixie's older nodejs alongside it.
|
||||||
RUN set -eu; \
|
RUN set -eu; \
|
||||||
echo "deb [trusted=yes] copy:///tmp/naros-pool ./" > /etc/apt/sources.list.d/naros-pool.list; \
|
echo "deb [trusted=yes] copy:///tmp/naros-pool ./" > /etc/apt/sources.list.d/naros-pool.list; \
|
||||||
|
# The base bakes naros-keyring's hosted-repo entry (naros.sources) — the runtime
|
||||||
|
# apt channel. Set it aside for the whole build (here, and under playwright
|
||||||
|
# --with-deps below) so THIS stage installs only from the local pool + Node source
|
||||||
|
# above: the freshly built naros-tier-agent must resolve from this run's pool, not a
|
||||||
|
# same-version deb already published to the hosted channel. It also keeps the image
|
||||||
|
# build independent of the hosted repo — the same reason the base rootfs smoke test
|
||||||
|
# scopes sources.list.d away. Restored in the final stage so the image ships it.
|
||||||
|
mv /etc/apt/sources.list.d/naros.sources /tmp/naros.sources.disabled 2>/dev/null || true; \
|
||||||
mkdir -p -m 755 /etc/apt/keyrings; \
|
mkdir -p -m 755 /etc/apt/keyrings; \
|
||||||
curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key \
|
curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key \
|
||||||
-o /etc/apt/keyrings/nodesource.asc; \
|
-o /etc/apt/keyrings/nodesource.asc; \
|
||||||
@@ -175,6 +183,8 @@ RUN set -eu; \
|
|||||||
# toolchain + version, cache paths) so `naros info` / the host probe read one file
|
# toolchain + version, cache paths) so `naros info` / the host probe read one file
|
||||||
# instead of probing binary-by-binary.
|
# instead of probing binary-by-binary.
|
||||||
RUN set -eu; \
|
RUN set -eu; \
|
||||||
|
# Restore the hosted runtime apt channel set aside at the start of the build.
|
||||||
|
mv /tmp/naros.sources.disabled /etc/apt/sources.list.d/naros.sources 2>/dev/null || true; \
|
||||||
sed -i -e 's/^VARIANT=.*/VARIANT="agent"/' -e 's/^VARIANT_ID=.*/VARIANT_ID=agent/' /etc/os-release; \
|
sed -i -e 's/^VARIANT=.*/VARIANT="agent"/' -e 's/^VARIANT_ID=.*/VARIANT_ID=agent/' /etc/os-release; \
|
||||||
node_v="$(node --version)"; \
|
node_v="$(node --version)"; \
|
||||||
python_v="$(python3 -c 'import platform; print(platform.python_version())')"; \
|
python_v="$(python3 -c 'import platform; print(platform.python_version())')"; \
|
||||||
|
|||||||
@@ -45,6 +45,12 @@ build_one() { # <pkgdir> <arch>
|
|||||||
trap 'rm -rf "$stage"' RETURN
|
trap 'rm -rf "$stage"' RETURN
|
||||||
|
|
||||||
[ -d "$d/files" ] && cp -a "$d/files/." "$stage/"
|
[ -d "$d/files" ] && cp -a "$d/files/." "$stage/"
|
||||||
|
# The runtime apt source's suite must mirror the channel it was published under
|
||||||
|
# (dists/<channel>; NAROS.md §3.2 "Suites mirror channels"), so @CHANNEL@ is templated
|
||||||
|
# here the same way @VERSION@/@ARCH@ are templated into control. Targeted rather than a
|
||||||
|
# blanket sed so binary payloads in files/ (e.g. the keyring .gpg) are never rewritten.
|
||||||
|
[ -f "$stage/etc/apt/sources.list.d/naros.sources" ] && \
|
||||||
|
sed -i "s/@CHANNEL@/$CHANNEL/g" "$stage/etc/apt/sources.list.d/naros.sources"
|
||||||
if [ -f "$d/stage.sh" ]; then
|
if [ -f "$d/stage.sh" ]; then
|
||||||
# shellcheck source=/dev/null
|
# shellcheck source=/dev/null
|
||||||
( set -euo pipefail; OS_DIR="$OS_DIR" . "$d/stage.sh"; stage "$stage" "$arch" ) || {
|
( set -euo pipefail; OS_DIR="$OS_DIR" . "$d/stage.sh"; stage "$stage" "$arch" ) || {
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
Types: deb
|
Types: deb
|
||||||
URIs: https://apt.naros.nucleic.blakeslee.xyz
|
URIs: https://apt.naros.nucleic.blakeslee.xyz
|
||||||
Suites: stable
|
Suites: @CHANNEL@
|
||||||
Components: main
|
Components: main
|
||||||
Signed-By: /usr/share/keyrings/naros-archive-keyring.gpg
|
Signed-By: /usr/share/keyrings/naros-archive-keyring.gpg
|
||||||
|
|||||||
Reference in New Issue
Block a user