Merge nucleic/gentle-willow-quail-cjp3 into dev

This commit is contained in:
2026-07-21 04:23:04 -07:00
parent 51f1af7749
commit b0cd84245d
12 changed files with 259 additions and 1 deletions
+17
View File
@@ -0,0 +1,17 @@
Package: naros-identity
Version: @VERSION@
Architecture: @ARCH@
Maintainer: Nucleic <[email protected]>
Section: utils
Priority: optional
Depends: libc6
Description: narOS kernel identity shim (NAROS.md §2.3)
narOS ships no kernel of its own — containers share the host's and the VM tiers
boot an externally-fetched vmlinux — so uname(2) reports a kernel with no narOS
in it, and every consumer that derives an OS string from it (notably the
`OS Version:` line agent harnesses build from os.type()+os.release()) misses the
identity that /etc/os-release carries. This package preloads a small interposer
via /etc/ld.so.preload that appends the narOS release tag to utsname.release,
the way a distro kernel package does. sysname stays "Linux" so build tooling
that switches on it is unaffected; NAROS_UNAME_PASSTHROUGH=1 disables the tag
for callers that resolve /lib/modules/`uname -r`.
+35
View File
@@ -0,0 +1,35 @@
#!/bin/sh
# Register the identity shim in /etc/ld.so.preload (NAROS.md §2.3).
#
# Idempotent, and additive rather than authoritative: the file is rewritten preserving any
# other entries, so this package never owns unrelated preloads. The write goes through a
# temp file + rename because /etc/ld.so.preload is read by the loader on EVERY exec — a
# partially written list would be observed by whatever runs during the write.
set -e
LIB=/usr/lib/naros/libnaros-uname.so
PRELOAD=/etc/ld.so.preload
TMP="$PRELOAD.naros-tmp"
case "$1" in
configure)
# Belt and braces: never point the loader at a library that is not on disk.
if [ ! -f "$LIB" ]; then
echo "naros-identity: $LIB missing, not registering preload" >&2
exit 0
fi
if [ -f "$PRELOAD" ] && grep -qxF "$LIB" "$PRELOAD"; then
exit 0
fi
if [ -f "$PRELOAD" ]; then
cat "$PRELOAD" > "$TMP"
else
: > "$TMP"
fi
echo "$LIB" >> "$TMP"
chmod 0644 "$TMP"
mv "$TMP" "$PRELOAD"
;;
esac
exit 0
+28
View File
@@ -0,0 +1,28 @@
#!/bin/sh
# Deregister the identity shim from /etc/ld.so.preload before its files are removed
# (NAROS.md §2.3), so the loader never names a library that is no longer on disk.
#
# Runs on remove/deconfigure only: on `upgrade` the entry must persist, since the
# replacement .so lands at the same path and the new postinst is a no-op.
set -e
LIB=/usr/lib/naros/libnaros-uname.so
PRELOAD=/etc/ld.so.preload
TMP="$PRELOAD.naros-tmp"
case "$1" in
remove | deconfigure)
[ -f "$PRELOAD" ] || exit 0
# grep exits 1 when nothing survives the filter; that is the empty case, not an error.
grep -vxF "$LIB" "$PRELOAD" > "$TMP" || true
if [ -s "$TMP" ]; then
chmod 0644 "$TMP"
mv "$TMP" "$PRELOAD"
else
# An empty ld.so.preload is legal but pointless — drop the file entirely.
rm -f "$TMP" "$PRELOAD"
fi
;;
esac
exit 0
+25
View File
@@ -0,0 +1,25 @@
# Stage the prebuilt narOS kernel identity shim (os/src/naros-identity, built per-arch
# into dist/bin by that dir's build.sh / the CI binaries job).
#
# /etc/ld.so.preload is written by the postinst rather than shipped in files/: dpkg
# unpacks a package's files in no guaranteed order, so a shipped preload file could land
# before the .so it names and make every binary exec'd for the rest of that transaction —
# including dpkg's own maintainer scripts — emit a loader warning. The postinst runs
# after the whole package is on disk, so the reference is never dangling.
# The /lib/modules alias unit rides along with a static enable symlink (rather than a
# `systemctl enable` in the postinst) so it takes effect inside the mmdebstrap chroot,
# where no systemd is running — the same pattern nucleic-linux-agent uses.
stage() {
local dest="$1" arch="$2"
local lib="$OS_DIR/dist/bin/libnaros-uname-$arch.so"
local unit="$OS_DIR/src/naros-identity/naros-identity-modules.service"
if [ ! -f "$lib" ]; then
echo "prebuilt shim missing: dist/bin/libnaros-uname-$arch.so" > "$dest/.skip-reason"
return 1
fi
install -D -m 0644 "$lib" "$dest/usr/lib/naros/libnaros-uname.so"
install -D -m 0644 "$unit" "$dest/usr/lib/systemd/system/naros-identity-modules.service"
install -d "$dest/etc/systemd/system/sysinit.target.wants"
ln -sf /usr/lib/systemd/system/naros-identity-modules.service \
"$dest/etc/systemd/system/sysinit.target.wants/naros-identity-modules.service"
}
+1 -1
View File
@@ -4,7 +4,7 @@ Architecture: all
Maintainer: Nucleic <[email protected]>
Section: metapackages
Priority: optional
Depends: nash, nash-default-shell, naros-init, naros, ca-certificates, curl, git, openssh-client, iproute2
Depends: nash, nash-default-shell, naros-init, naros, naros-identity, ca-certificates, curl, git, openssh-client, iproute2
Recommends: naros-keyring
Description: narOS base tier (NAROS.md §4)
The minimal narOS surface: nash forced as the default shell, naros-init, the