From ddde19bf425347304d22c53d99d59d6d70775a0a Mon Sep 17 00:00:00 2001 From: Nucleic Date: Sat, 18 Jul 2026 21:19:16 -0700 Subject: [PATCH] Merge nucleic/clever-quartz-marten-uqnx into dev --- packages/naros-tier-agent/control | 6 ++- tests/parity-allowlist.txt | 76 ++++++++++++++++++++++++++++++- tests/parity-sweep.sh | 8 ++-- 3 files changed, 83 insertions(+), 7 deletions(-) diff --git a/packages/naros-tier-agent/control b/packages/naros-tier-agent/control index a8fce0c..3bbe5c0 100644 --- a/packages/naros-tier-agent/control +++ b/packages/naros-tier-agent/control @@ -4,7 +4,11 @@ Architecture: all Maintainer: Nucleic Section: metapackages Priority: optional -Depends: naros-tier-base, nucleic-bridge, build-essential, pkg-config, python3, python3-pip, python3-venv, sudo, gh, ripgrep, fd-find, jq, yq, sqlite3, htop, tree, zip, unzip, zstd, xz-utils, moreutils, rsync, less, procps, file, bsdextrautils +Depends: naros-tier-base, nucleic-bridge, build-essential, pkg-config, + python3, python3-pip, python3-venv, sudo, gh, ripgrep, fd-find, jq, yq, + sqlite3, htop, tree, zip, unzip, zstd, xz-utils, moreutils, rsync, less, + procps, file, bsdextrautils, e2fsprogs, util-linux-extra, mount, login, + gpgv Description: narOS agent tier — apt-resolvable half (NAROS.md §4, §6) The dev toolchain and modern CLI kit that come from Debian, plus the control bridge. The non-apt half of the agent tier — Node (NodeSource), rustup, Go, diff --git a/tests/parity-allowlist.txt b/tests/parity-allowlist.txt index 2ce3fd4..eb8bf57 100644 --- a/tests/parity-allowlist.txt +++ b/tests/parity-allowlist.txt @@ -4,10 +4,82 @@ # node:22 image plumbing, not a tool agents use. docker-entrypoint.sh +policy-rc.d # The node:22 image ships node under /usr/local with npx/corepack symlinked there; # NodeSource's deb provides the same commands at /usr/bin — same names, so only # image-internal helper names should ever land here, not node/npm/npx/corepack. -# bookworm→trixie package renames/drops surface here as they are DISCOVERED and -# understood in CI — do not pre-seed guesses. +# Removed Debian transition/deprecation helpers. narOS is natively merged-/usr and +# uses signed-by keyrings instead of apt-key. +apt-key +dpkg-fsys-usrunmess + +# Version-pinned Bookworm compiler names. Trixie's build-essential provides the +# current GCC suite and the same unversioned commands. +cpp-12 +g++-12 +gcc-12 +gcc-ar-12 +gcc-nm-12 +gcc-ranlib-12 +gcov-12 +gcov-dump-12 +gcov-tool-12 +lto-dump-12 +x86_64-linux-gnu-cpp-12 +x86_64-linux-gnu-g++-12 +x86_64-linux-gnu-gcc-12 +x86_64-linux-gnu-gcc-ar-12 +x86_64-linux-gnu-gcc-nm-12 +x86_64-linux-gnu-gcc-ranlib-12 +x86_64-linux-gnu-gcov-12 +x86_64-linux-gnu-gcov-dump-12 +x86_64-linux-gnu-gcov-tool-12 +x86_64-linux-gnu-lto-dump-12 + +# Version-pinned Bookworm Python 3.11 and Perl 5.36 names. Trixie's python3, +# pip3, pydoc3, pygettext3, perl and cpan commands remain available. +cpan5.36-x86_64-linux-gnu +pdb3.11 +perl5.36-x86_64-linux-gnu +perl5.36.0 +pip3.11 +pydoc3.11 +pygettext3.11 +python3.11 + +# GNU gold is deprecated, while these target-prefixed gprofng aliases and dwp +# are no longer emitted by Trixie's binutils. Current ld, gprofng and gp-* tools +# remain available. +dwp +gold +ld.gold +x86_64-linux-gnu-dwp +x86_64-linux-gnu-gold +x86_64-linux-gnu-gp-archive +x86_64-linux-gnu-gp-collect-app +x86_64-linux-gnu-gp-display-html +x86_64-linux-gnu-gp-display-src +x86_64-linux-gnu-gp-display-text +x86_64-linux-gnu-gprofng +x86_64-linux-gnu-ld.gold + +# Commands removed from Trixie's util-linux/shadow packages. Block-device, +# filesystem, mount and login capabilities that still have Trixie packages are +# installed explicitly by naros-tier-agent; these obsolete interfaces are not. +addpart +cpgr +cppw +delpart +faillog +groupmems +last +lastb +lastlog +mesg +utmpdump + +# Historical compatibility aliases; the canonical commands remain available. +md5sum.textutils +slogin diff --git a/tests/parity-sweep.sh b/tests/parity-sweep.sh index b06341c..1fdfaee 100755 --- a/tests/parity-sweep.sh +++ b/tests/parity-sweep.sh @@ -65,10 +65,6 @@ allow_filter "$tmp/removed.all" > "$tmp/unexplained" || true echo "PATH: $(wc -l < "$tmp/ref.path") reference, $(wc -l < "$tmp/cand.path") candidate," \ "$(wc -l < "$tmp/removed.path") removed, $added_path added" echo "npm globals removed: $(wc -l < "$tmp/removed.npm")" -if [ -s "$tmp/removed.all" ]; then - echo "--- removed (before allowlist) ---" - cat "$tmp/removed.all" -fi if [ -s "$tmp/unexplained" ]; then echo "PARITY FAILURE — present in $REF, missing from $CAND, not allowlisted:" >&2 @@ -76,4 +72,8 @@ if [ -s "$tmp/unexplained" ]; then echo "(fix the image, or add to $ALLOW with a comment explaining the removal)" >&2 exit 1 fi +if [ -s "$tmp/removed.all" ]; then + echo "--- deliberate removals (allowlisted) ---" + cat "$tmp/removed.all" +fi echo "parity OK"