Merge nucleic/olive-ember-seal-q7vk into dev
This commit is contained in:
Executable
+78
@@ -0,0 +1,78 @@
|
||||
#!/usr/bin/env bash
|
||||
# Build every narOS package into dist/pool/ with plain dpkg-deb (NAROS.md §3.1).
|
||||
#
|
||||
# Deliberately not debhelper: these are binary payloads, scripts, and meta-packages —
|
||||
# a uniform stage-and-pack loop keeps the whole layer readable and buildable anywhere
|
||||
# dpkg-deb exists (this container, CI). Graduating a package to dpkg-buildpackage later
|
||||
# is a per-package decision, not a build-system change.
|
||||
#
|
||||
# build-all.sh [--arch arm64,amd64] [--channel edge|stable] [--only pkg1,pkg2]
|
||||
#
|
||||
# Per package dir: control (template: @VERSION@ @ARCH@), optional files/ (copied
|
||||
# verbatim), optional stage.sh (sourced; must define stage <destdir> <arch>), optional
|
||||
# postinst/prerm/preinst/postrm. Arch-any packages build once per requested arch and
|
||||
# typically stage a prebuilt binary from dist/bin/<name>-<arch>; missing binaries skip
|
||||
# the package with a warning so metadata-only iteration needs no Rust toolchain.
|
||||
set -euo pipefail
|
||||
|
||||
PKG_DIR="$(cd "$(dirname "$0")" && pwd)"
|
||||
OS_DIR="$(cd "$PKG_DIR/.." && pwd)"
|
||||
ARCHES="arm64,amd64" CHANNEL="${NAROS_CHANNEL:-edge}" ONLY=""
|
||||
while [ $# -gt 0 ]; do
|
||||
case "$1" in
|
||||
--arch) ARCHES="$2"; shift 2 ;;
|
||||
--channel) CHANNEL="$2"; shift 2 ;;
|
||||
--only) ONLY="$2"; shift 2 ;;
|
||||
*) echo "unknown arg: $1" >&2; exit 2 ;;
|
||||
esac
|
||||
done
|
||||
|
||||
OS_VERSION="$(cat "$OS_DIR/VERSION")"
|
||||
POOL="$OS_DIR/dist/pool"
|
||||
mkdir -p "$POOL"
|
||||
|
||||
pkg_version() { # package semver + channel tag, e.g. 0.1.0+edge26.07
|
||||
local d="$1" base
|
||||
base="$( [ -f "$d/VERSION" ] && cat "$d/VERSION" || echo 0.1.0 )"
|
||||
echo "${base}+${CHANNEL}${OS_VERSION}"
|
||||
}
|
||||
|
||||
build_one() { # <pkgdir> <arch>
|
||||
local d="$1" arch="$2" name ver stage out
|
||||
name="$(basename "$d")"
|
||||
ver="$(pkg_version "$d")"
|
||||
stage="$(mktemp -d)"
|
||||
trap 'rm -rf "$stage"' RETURN
|
||||
|
||||
[ -d "$d/files" ] && cp -a "$d/files/." "$stage/"
|
||||
if [ -f "$d/stage.sh" ]; then
|
||||
# shellcheck source=/dev/null
|
||||
( set -euo pipefail; OS_DIR="$OS_DIR" . "$d/stage.sh"; stage "$stage" "$arch" ) || {
|
||||
echo "SKIP $name/$arch: $(cat "$stage/.skip-reason" 2>/dev/null || echo staging failed)" >&2
|
||||
return 0
|
||||
}
|
||||
fi
|
||||
|
||||
mkdir -p "$stage/DEBIAN"
|
||||
sed -e "s/@VERSION@/$ver/" -e "s/@ARCH@/$arch/" "$d/control" > "$stage/DEBIAN/control"
|
||||
local s
|
||||
for s in preinst postinst prerm postrm; do
|
||||
[ -f "$d/$s" ] && install -m 0755 "$d/$s" "$stage/DEBIAN/$s"
|
||||
done
|
||||
|
||||
out="$POOL/${name}_${ver}_$(grep -Po '^Architecture: \K.*' "$stage/DEBIAN/control").deb"
|
||||
dpkg-deb --root-owner-group -Zxz --build "$stage" "$out" > /dev/null
|
||||
echo "built ${out#"$OS_DIR/"}"
|
||||
}
|
||||
|
||||
for d in "$PKG_DIR"/*/; do
|
||||
name="$(basename "$d")"
|
||||
[ -f "$d/control" ] || continue
|
||||
if [ -n "$ONLY" ] && ! echo ",$ONLY," | grep -q ",$name,"; then continue; fi
|
||||
if grep -q '^Architecture: @ARCH@' "$d/control"; then
|
||||
IFS=, read -ra AA <<< "$ARCHES"
|
||||
for a in "${AA[@]}"; do build_one "$d" "$a"; done
|
||||
else
|
||||
build_one "$d" all
|
||||
fi
|
||||
done
|
||||
@@ -0,0 +1,12 @@
|
||||
Package: naros-init
|
||||
Version: @VERSION@
|
||||
Architecture: @ARCH@
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: admin
|
||||
Priority: optional
|
||||
Description: narOS PID-1 supervisor for container surfaces (NAROS.md §5)
|
||||
Small static init: reaps zombies, forwards signals, optionally supervises the
|
||||
in-container control bridge (NAROS_BRIDGE=1) and/or a primary command
|
||||
(everything after --), and otherwise acts as the keepalive that replaces
|
||||
ContainerEngine's sleep loop. Role-driven via /etc/naros/role or NAROS_ROLE.
|
||||
In the VM desktop flavor systemd stays PID 1 and naros-init runs as a unit.
|
||||
@@ -0,0 +1,9 @@
|
||||
# Stage the prebuilt static naros-init binary (built by CI from shell/naros-init).
|
||||
stage() {
|
||||
local dest="$1" arch="$2" bin="$OS_DIR/dist/bin/naros-init-$arch"
|
||||
if [ ! -x "$bin" ]; then
|
||||
echo "prebuilt binary missing: $bin" > "$dest/.skip-reason"
|
||||
return 1
|
||||
fi
|
||||
install -D -m 0755 "$bin" "$dest/usr/sbin/naros-init"
|
||||
}
|
||||
@@ -0,0 +1,11 @@
|
||||
Package: naros-keyring
|
||||
Version: @VERSION@
|
||||
Architecture: all
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: misc
|
||||
Priority: optional
|
||||
Description: narOS apt archive keyring and source entry (NAROS.md §3.2)
|
||||
The narOS apt repository's signing public key
|
||||
(/usr/share/keyrings/naros-archive-keyring.gpg) plus the deb822 source entry
|
||||
for apt.naros.dev pinned to that key. Installing this on any Debian-family
|
||||
system enables `apt install naros-tier-agent` conversion (NAROS.md §7.3).
|
||||
@@ -0,0 +1,5 @@
|
||||
Types: deb
|
||||
URIs: https://apt.naros.dev
|
||||
Suites: stable
|
||||
Components: main
|
||||
Signed-By: /usr/share/keyrings/naros-archive-keyring.gpg
|
||||
@@ -0,0 +1,10 @@
|
||||
# The public key is materialized by CI from the NAROS_APT_PUBLIC_KEY secret (or by an
|
||||
# operator into os/repo/keys/). No key in the tree, no keyring package — skip cleanly.
|
||||
stage() {
|
||||
local dest="$1" key="$OS_DIR/repo/keys/naros-archive-keyring.gpg"
|
||||
if [ ! -f "$key" ]; then
|
||||
echo "public key missing: $key (CI materializes it from secrets)" > "$dest/.skip-reason"
|
||||
return 1
|
||||
fi
|
||||
install -D -m 0644 "$key" "$dest/usr/share/keyrings/naros-archive-keyring.gpg"
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
Package: naros-tier-agent
|
||||
Version: @VERSION@
|
||||
Architecture: all
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: metapackages
|
||||
Priority: optional
|
||||
Depends: naros-tier-base, nucleic-bridge, build-essential, pkg-config, python3, python3-pip, python3-venv, ripgrep, fd-find, jq, sqlite3, htop, tree, zip, unzip, zstd, xz-utils, moreutils, rsync, less, procps, file, bsdextrautils
|
||||
Description: narOS agent tier — apt-resolvable half (NAROS.md §4, §6)
|
||||
The dev toolchain and modern CLI kit that come from Debian, plus the control
|
||||
bridge. The non-apt half of the agent tier — Node (NodeSource), rustup, Go,
|
||||
mise, warm caches, agent CLIs, Playwright — is layered by the naros-agent
|
||||
image build (milestone N2); this meta is what `apt install` can deliver into
|
||||
any Debian-family container (NAROS.md §7.3 conversion path).
|
||||
@@ -0,0 +1,12 @@
|
||||
Package: naros-tier-base
|
||||
Version: @VERSION@
|
||||
Architecture: all
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: metapackages
|
||||
Priority: optional
|
||||
Depends: nash, nash-default-shell, naros-init, naros, ca-certificates, curl, git, openssh-client, iproute2
|
||||
Recommends: naros-keyring
|
||||
Description: narOS base tier (NAROS.md §4)
|
||||
The minimal narOS surface: nash forced as the default shell, naros-init, the
|
||||
naros CLI, and the small always-wanted utility set. Installing this meta on a
|
||||
stock Debian-family system converts it to a naros-base-equivalent environment.
|
||||
@@ -0,0 +1,12 @@
|
||||
Package: naros-tier-runner
|
||||
Version: @VERSION@
|
||||
Architecture: all
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: metapackages
|
||||
Priority: optional
|
||||
Depends: naros-tier-agent
|
||||
Description: narOS runner tier (NAROS.md §4)
|
||||
The Covalence runner surface: everything in the agent tier. nucleicd itself is
|
||||
a direct image COPY (versioned with the app, not a deb — NAROS.md §3.1), so
|
||||
this meta currently only anchors the tier for introspection and future
|
||||
runner-only dependencies.
|
||||
@@ -0,0 +1,12 @@
|
||||
Package: naros-tier-vm
|
||||
Version: @VERSION@
|
||||
Architecture: all
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: metapackages
|
||||
Priority: optional
|
||||
Depends: naros-tier-base, systemd, dbus, sudo
|
||||
Description: narOS VM guest tier — headless scope (NAROS.md §4, §7.4, milestone N4)
|
||||
The bootable-guest surface. Headless scope for now: systemd (the VM flavor
|
||||
keeps it as PID 1), dbus, sudo. nucleic-linux-agent packaging, the firstboot
|
||||
provisioning glue, and the GNOME 50 desktop stack (naros-desktop, N5) land in
|
||||
later milestones and will extend this meta.
|
||||
@@ -0,0 +1,12 @@
|
||||
Package: naros
|
||||
Version: @VERSION@
|
||||
Architecture: all
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: utils
|
||||
Priority: optional
|
||||
Description: narOS introspection CLI (NAROS.md §6.3)
|
||||
`naros info [--json]` prints the capability manifest (/etc/naros/manifest.json:
|
||||
tier, version, channel, snapshot, toolchains, caches); `naros version` prints
|
||||
the release. Lets agents and the host ask "what can this box do" instead of
|
||||
probing binary-by-binary. v1 is a POSIX sh script; a compiled multi-call
|
||||
binary shared with naros-init can replace it without interface change.
|
||||
Executable
+24
@@ -0,0 +1,24 @@
|
||||
#!/bin/sh
|
||||
# narOS introspection CLI (NAROS.md §6.3). Reads /etc/naros + /etc/os-release only.
|
||||
set -eu
|
||||
MANIFEST=/etc/naros/manifest.json
|
||||
|
||||
case "${1:-info}" in
|
||||
version)
|
||||
. /etc/os-release
|
||||
echo "narOS ${VERSION_ID:-unknown} (${VARIANT:-?}/$(cat /etc/naros/channel 2>/dev/null || echo '?'))"
|
||||
;;
|
||||
info)
|
||||
if [ "${2:-}" = "--json" ]; then
|
||||
cat "$MANIFEST"
|
||||
elif command -v jq > /dev/null 2>&1; then
|
||||
jq . "$MANIFEST"
|
||||
else
|
||||
cat "$MANIFEST"
|
||||
fi
|
||||
;;
|
||||
*)
|
||||
echo "usage: naros [info [--json] | version]" >&2
|
||||
exit 2
|
||||
;;
|
||||
esac
|
||||
@@ -0,0 +1,14 @@
|
||||
Package: nash-default-shell
|
||||
Version: @VERSION@
|
||||
Architecture: all
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: shells
|
||||
Priority: optional
|
||||
Depends: nash
|
||||
Description: force nash as the system default shell (NASH.md §7.1)
|
||||
The maintainer-script form of the locked divert block: /bin/bash and /bin/dash
|
||||
are dpkg-diverted to /usr/bin/{bash,dash}.real and /bin/{bash,dash,sh} point at
|
||||
nash, so shebangs and tools that hardcode sh/bash land in nash. Real shells
|
||||
stay reachable at the .real paths — nash's parse-failure fallback depends on
|
||||
them. Removing this package cleanly restores stock shells. dpkg-divert keeps
|
||||
apt upgrades of bash/dash from clobbering the links.
|
||||
@@ -0,0 +1,4 @@
|
||||
# narOS shell environment (nash-default-shell). NUCLEIC_REAL_BASH is nash's
|
||||
# parse-failure fallback + NUCLEIC_NASH_DISABLE target (NASH.md §4.1).
|
||||
export NUCLEIC_REAL_BASH=/usr/bin/bash.real
|
||||
[ -n "${SHELL:-}" ] || export SHELL=/usr/local/bin/nash
|
||||
@@ -0,0 +1,10 @@
|
||||
#!/bin/sh
|
||||
# NASH.md §7.1, verbatim semantics (merged-usr symlink handling verified in nash M0).
|
||||
set -e
|
||||
if [ "$1" = "configure" ]; then
|
||||
dpkg-divert --package nash-default-shell --divert /usr/bin/bash.real --rename --add /bin/bash
|
||||
dpkg-divert --package nash-default-shell --divert /usr/bin/dash.real --rename --add /bin/dash
|
||||
ln -sf /usr/local/bin/nash /bin/bash
|
||||
ln -sf /usr/local/bin/nash /bin/dash
|
||||
ln -sf /usr/local/bin/nash /bin/sh
|
||||
fi
|
||||
@@ -0,0 +1,9 @@
|
||||
#!/bin/sh
|
||||
# Clean revert: drop the nash links, un-divert the real shells, restore sh -> dash.
|
||||
set -e
|
||||
if [ "$1" = "remove" ]; then
|
||||
rm -f /bin/bash /bin/dash
|
||||
dpkg-divert --package nash-default-shell --rename --remove /bin/bash
|
||||
dpkg-divert --package nash-default-shell --rename --remove /bin/dash
|
||||
ln -sf dash /usr/bin/sh
|
||||
fi
|
||||
@@ -0,0 +1,12 @@
|
||||
Package: nash
|
||||
Version: @VERSION@
|
||||
Architecture: @ARCH@
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: shells
|
||||
Priority: optional
|
||||
Description: Nucleic agent shell (brush fork)
|
||||
Bourne/bash-compatible shell whose job is to make every shell action an agent
|
||||
takes observable by construction (docs/NASH.md). Static musl binary; installs
|
||||
as /usr/bin/nash with the locked /usr/local/bin/nash path provided as a
|
||||
symlink. This package does NOT change the default shell — that is
|
||||
nash-default-shell's job.
|
||||
@@ -0,0 +1,9 @@
|
||||
#!/bin/sh
|
||||
# The locked contract (NASH.md §2, §7) addresses nash at /usr/local/bin/nash on every
|
||||
# surface (probe, exec argv, $SHELL). The real file lives at /usr/bin/nash per policy;
|
||||
# this symlink satisfies the contract path.
|
||||
set -e
|
||||
if [ "$1" = "configure" ]; then
|
||||
mkdir -p /usr/local/bin
|
||||
ln -sf /usr/bin/nash /usr/local/bin/nash
|
||||
fi
|
||||
@@ -0,0 +1,5 @@
|
||||
#!/bin/sh
|
||||
set -e
|
||||
if [ "$1" = "remove" ]; then
|
||||
[ -L /usr/local/bin/nash ] && rm -f /usr/local/bin/nash || true
|
||||
fi
|
||||
@@ -0,0 +1,9 @@
|
||||
# Stage the prebuilt static nash binary (built by CI from shell/, target musl).
|
||||
stage() {
|
||||
local dest="$1" arch="$2" bin="$OS_DIR/dist/bin/nash-$arch"
|
||||
if [ ! -x "$bin" ]; then
|
||||
echo "prebuilt binary missing: $bin" > "$dest/.skip-reason"
|
||||
return 1
|
||||
fi
|
||||
install -D -m 0755 "$bin" "$dest/usr/bin/nash"
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
Package: nucleic-bridge
|
||||
Version: @VERSION@
|
||||
Architecture: all
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: net
|
||||
Priority: optional
|
||||
Depends: nodejs
|
||||
Description: in-container control bridge (docs/VSOCK_CONTROL_PLANE.md)
|
||||
Loopback TCP to the vsock-relayed host control socket, so the agent and the
|
||||
interceptor shims reach the host approval server with no IP listener.
|
||||
Launched by naros-init (or the container's root init) only when Nucleic
|
||||
relays a control socket in.
|
||||
@@ -0,0 +1,6 @@
|
||||
# The bridge source of truth stays beside the sandbox image context; the deb packages it.
|
||||
stage() {
|
||||
local dest="$1"
|
||||
install -D -m 0644 "$OS_DIR/../containers/nucleic-sandbox/control-bridge.js" \
|
||||
"$dest/opt/nucleic/control-bridge.js"
|
||||
}
|
||||
Reference in New Issue
Block a user