From a0f73f317f5ed69dc7b347e8ceeec7f1c08baf96 Mon Sep 17 00:00:00 2001 From: Nucleic Date: Tue, 21 Jul 2026 19:14:46 -0700 Subject: [PATCH] Merge nucleic/zesty-dewy-ferret-tlmk into dev --- mkimage/profiles/vm.naros-pkgs | 13 ++++++++++--- packages/build-all.sh | 23 ++++++++++++++++++++++- packages/nucleic-a11y-agent/stage.sh | 11 ++++++----- 3 files changed, 38 insertions(+), 9 deletions(-) diff --git a/mkimage/profiles/vm.naros-pkgs b/mkimage/profiles/vm.naros-pkgs index d05e357..250e8ee 100644 --- a/mkimage/profiles/vm.naros-pkgs +++ b/mkimage/profiles/vm.naros-pkgs @@ -1,9 +1,16 @@ # Base Nucleic layer baked into the naros-vm rootfs so nash is the forced shell and the -# hosted apt repo is trusted from the very first boot. The vsock agent (nucleic-linux-agent) -# and the rest of the tier arrive at firstboot via `apt install naros-tier-vm` (NAROS.md -# §7.4), so they are intentionally NOT baked here — this mirrors the base tier's layer. +# hosted apt repo is trusted from the very first boot — plus the vsock control-plane agent. +# +# The agent is baked (from this same local pool, i.e. the same deb published to the hosted +# repo) because it is the host's ONLY way to reach the guest: it used to be overlaid by the +# Mac-host bootstrap from a separate GHCR artifact, but that second source could drift from +# the deb and silently win. With the overlay collapsed, apt is the single source of truth — +# and a soft-failing firstboot `apt install` is too weak a guarantee for the control plane. +# The REST of the tier (sudo, dbus, the tier meta) still arrives at firstboot via +# `apt install naros-tier-vm` (NAROS.md §7.4), which finds this dependency already satisfied. nash naros-init naros naros-identity naros-keyring +nucleic-linux-agent diff --git a/packages/build-all.sh b/packages/build-all.sh index 97d7a8d..ff2eaef 100755 --- a/packages/build-all.sh +++ b/packages/build-all.sh @@ -17,12 +17,13 @@ set -euo pipefail PKG_DIR="$(cd "$(dirname "$0")" && pwd)" OS_DIR="$(cd "$PKG_DIR/.." && pwd)" -ARCHES="arm64,amd64" CHANNEL="${NAROS_CHANNEL:-edge}" ONLY="" +ARCHES="arm64,amd64" CHANNEL="${NAROS_CHANNEL:-edge}" ONLY="" REQUIRE="" while [ $# -gt 0 ]; do case "$1" in --arch) ARCHES="$2"; shift 2 ;; --channel) CHANNEL="$2"; shift 2 ;; --only) ONLY="$2"; shift 2 ;; + --require) REQUIRE="$2"; shift 2 ;; *) echo "unknown arg: $1" >&2; exit 2 ;; esac done @@ -82,3 +83,23 @@ for d in "$PKG_DIR"/*/; do build_one "$d" all fi done + +# A missing prebuilt binary only WARNS above, so that metadata-only iteration works without a Rust +# toolchain. That leniency is wrong for the packages a guest cannot boot without: nucleic-a11y-agent +# was cross-built for arm64 only, so its amd64 deb skipped silently and simply never appeared in the +# published repo — a gap nothing failed on. --require turns the skip into an error for a named set. +if [ -n "$REQUIRE" ]; then + missing="" + IFS=, read -ra RR <<< "$REQUIRE" + IFS=, read -ra AA <<< "$ARCHES" + for name in "${RR[@]}"; do + ver="$(pkg_version "$PKG_DIR/$name")" + for a in "${AA[@]}"; do + [ -f "$POOL/${name}_${ver}_$a.deb" ] || missing="$missing ${name}_${ver}_$a.deb" + done + done + if [ -n "$missing" ]; then + echo "FATAL: required package(s) did not build (see the SKIP lines above):$missing" >&2 + exit 1 + fi +fi diff --git a/packages/nucleic-a11y-agent/stage.sh b/packages/nucleic-a11y-agent/stage.sh index 4c522c3..3b7da9e 100644 --- a/packages/nucleic-a11y-agent/stage.sh +++ b/packages/nucleic-a11y-agent/stage.sh @@ -1,13 +1,14 @@ # Stage the prebuilt Rust AT-SPI semantic agent + its systemd USER unit, with a static # global-enable symlink so it starts in every graphical session (no `systemctl --global -# enable` needed inside the mmdebstrap chroot). Prefer the CI-built dist/bin binary; fall -# back to the committed guest build (arm64) — the same artifact the pre-narOS base build bakes. +# enable` needed inside the mmdebstrap chroot). +# +# dist/bin is the ONLY source. There used to be an arm64-only fallback to a committed +# guest/nucleic-a11y-agent/build/ binary, which papered over the fact that CI built this +# crate natively on arm64 and never for amd64 — so the amd64 deb silently skipped staging +# and never reached the repo. naros.yml now cross-builds both arches (musl via zigbuild). stage() { local dest="$1" arch="$2" local bin="$OS_DIR/dist/bin/nucleic-a11y-agent-$arch" - if [ ! -x "$bin" ] && [ "$arch" = arm64 ]; then - bin="$OS_DIR/../guest/nucleic-a11y-agent/build/nucleic-a11y-agent" - fi local unit="$OS_DIR/../guest/nucleic-a11y-agent/systemd/nucleic-a11y-agent.service" if [ ! -x "$bin" ]; then echo "prebuilt binary missing: dist/bin/nucleic-a11y-agent-$arch" > "$dest/.skip-reason"