Merge nucleic/lucid-lunar-wren-wxyw into dev
This commit is contained in:
+22
-3
@@ -25,8 +25,26 @@ while [ $# -gt 0 ]; do
|
||||
done
|
||||
|
||||
VERSION="$(cat "$OS_DIR/VERSION")"
|
||||
SNAPSHOT="$(cat "$OS_DIR/SNAPSHOT")"
|
||||
SUITE="trixie"
|
||||
# Per-flavor base (NAROS.md §7.4): the VM DESKTOP flavor (N5) builds entirely from a pinned
|
||||
# Debian FORKY (testing) snapshot for GNOME 50 — trixie ships only GNOME 48 — while every
|
||||
# other tier, including the HEADLESS VM, stays on the trixie snapshot. One coherent pocket per
|
||||
# rootfs, no trixie/forky ABI mixing. VARIANT is the os-release identity class
|
||||
# (base/agent/runner/vm, §2.3); FLAVOR distinguishes the two VM rootfs builds within
|
||||
# VARIANT=vm (headless vs desktop).
|
||||
case "$TIER" in
|
||||
vm-desktop)
|
||||
SUITE="forky"; VARIANT="vm"; FLAVOR="desktop"
|
||||
SNAPSHOT="$(cat "$OS_DIR/SNAPSHOT.forky" 2>/dev/null || cat "$OS_DIR/SNAPSHOT")"
|
||||
;;
|
||||
vm)
|
||||
SUITE="trixie"; VARIANT="vm"; FLAVOR="headless"
|
||||
SNAPSHOT="$(cat "$OS_DIR/SNAPSHOT")"
|
||||
;;
|
||||
*)
|
||||
SUITE="trixie"; VARIANT="$TIER"; FLAVOR=""
|
||||
SNAPSHOT="$(cat "$OS_DIR/SNAPSHOT")"
|
||||
;;
|
||||
esac
|
||||
MIRROR="https://snapshot.debian.org/archive/debian/${SNAPSHOT}/"
|
||||
PROFILE="$OS_DIR/mkimage/profiles/$TIER.pkgs"
|
||||
[ -f "$PROFILE" ] || { echo "no profile for tier '$TIER' ($PROFILE)" >&2; exit 2; }
|
||||
@@ -89,7 +107,8 @@ mkdir -p "$OUT"
|
||||
TAR="$OUT/naros-$TIER-$VERSION-$ARCH.tar"
|
||||
|
||||
export NAROS_TIER="$TIER" NAROS_VERSION="$VERSION" NAROS_ARCH="$ARCH" \
|
||||
NAROS_CHANNEL="$CHANNEL" NAROS_SNAPSHOT="$SNAPSHOT" NAROS_SUITE="$SUITE"
|
||||
NAROS_CHANNEL="$CHANNEL" NAROS_SNAPSHOT="$SNAPSHOT" NAROS_SUITE="$SUITE" \
|
||||
NAROS_VARIANT="$VARIANT" NAROS_FLAVOR="$FLAVOR"
|
||||
|
||||
HOOKS=()
|
||||
if [ "${#LATE_DEBS[@]}" -gt 0 ]; then
|
||||
|
||||
@@ -6,6 +6,15 @@
|
||||
set -eu
|
||||
R="$1"
|
||||
|
||||
# VARIANT is the os-release identity class (base/agent/runner/vm, §2.3); the build passes it
|
||||
# separately from NAROS_TIER so the two VM flavors (vm, vm-desktop) both report VARIANT=vm and
|
||||
# carry the headless/desktop distinction in NAROS_FLAVOR. Fallback to the tier for older callers.
|
||||
VARIANT="${NAROS_VARIANT:-$NAROS_TIER}"
|
||||
FLAVOR="${NAROS_FLAVOR:-}"
|
||||
# naros-init/systemd role: the VM tiers boot as a guest (systemd PID 1, §5); everything else is
|
||||
# a container surface.
|
||||
case "$VARIANT" in vm) ROLE="vm" ;; *) ROLE="container" ;; esac
|
||||
|
||||
# mmdebstrap writes every build source into the target's sources.list — including the
|
||||
# CI-local [trusted=yes] copy:// pool, which doesn't exist at runtime and would fail
|
||||
# every `apt update` in a running container. Keep only the real mirrors (the pinned
|
||||
@@ -21,8 +30,8 @@ ID_LIKE=debian
|
||||
VERSION_ID="$NAROS_VERSION"
|
||||
VERSION="$NAROS_VERSION ($NAROS_CHANNEL)"
|
||||
VERSION_CODENAME=$NAROS_SUITE
|
||||
VARIANT="$NAROS_TIER"
|
||||
VARIANT_ID=$NAROS_TIER
|
||||
VARIANT="$VARIANT"
|
||||
VARIANT_ID=$VARIANT
|
||||
HOME_URL="https://github.com/abkslm/nucleic"
|
||||
DOCUMENTATION_URL="https://github.com/abkslm/nucleic/blob/main/docs/NAROS.md"
|
||||
EOF
|
||||
@@ -30,7 +39,7 @@ EOF
|
||||
mkdir -p "$R/etc/naros"
|
||||
echo "$NAROS_CHANNEL" > "$R/etc/naros/channel"
|
||||
echo "$NAROS_SNAPSHOT" > "$R/etc/naros/snapshot-date"
|
||||
echo "container" > "$R/etc/naros/role"
|
||||
echo "$ROLE" > "$R/etc/naros/role"
|
||||
|
||||
# Capability manifest (NAROS.md §6.3). Base fields here; toolchain entries are appended
|
||||
# by the tiers that install them (agent-tier hook, N2). Versions of Nucleic packages are
|
||||
@@ -43,6 +52,8 @@ cat > "$R/etc/naros/manifest.json" <<EOF
|
||||
"version": "$NAROS_VERSION",
|
||||
"channel": "$NAROS_CHANNEL",
|
||||
"tier": "$NAROS_TIER",
|
||||
"variant": "$VARIANT",
|
||||
"flavor": "$FLAVOR",
|
||||
"arch": "$NAROS_ARCH",
|
||||
"debian": { "suite": "$NAROS_SUITE", "snapshot": "$NAROS_SNAPSHOT" },
|
||||
"nash": $nash_ver,
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
# dpkg -i in a finish hook, after every Debian + GNOME package is configured (build-rootfs.sh).
|
||||
# nash-default-shell MUST configure last — its divert flips /bin/sh to nash, and nothing may
|
||||
# configure under nash mid-build (the reason the whole desktop stack is --include'd first).
|
||||
# dpkg orders this batch by dependency, so the divert lands before the metas that depend on it,
|
||||
# and naros-desktop-config (agent user, GDM auto-login, dconf, geometry helper, Firefox policy)
|
||||
# before the tier meta that pulls it.
|
||||
nash-default-shell
|
||||
naros-tier-base
|
||||
naros-tier-vm
|
||||
naros-desktop-config
|
||||
naros-tier-vm-desktop
|
||||
@@ -0,0 +1,12 @@
|
||||
# Nucleic packages baked into the naros-vm desktop rootfs, from the local pool. The base
|
||||
# layer (nash forced + naros identity + hosted-repo trust) plus BOTH guest agents — the vsock
|
||||
# control-plane agent (exec) and the AT-SPI semantic agent (ax_*). They install via apt
|
||||
# --include (deps resolved) with no divert trigger; the divert + tier metas configure last
|
||||
# (vm-desktop.late-pkgs). The GNOME-Shell geometry helper + desktop config ride
|
||||
# naros-desktop-config (a late meta), not this list.
|
||||
nash
|
||||
naros-init
|
||||
naros
|
||||
naros-keyring
|
||||
nucleic-linux-agent
|
||||
nucleic-a11y-agent
|
||||
@@ -0,0 +1,58 @@
|
||||
# naros-vm DESKTOP flavor — Debian package list (NAROS.md §7.4, milestone N5).
|
||||
#
|
||||
# Built entirely from a pinned Debian FORKY snapshot (build-rootfs.sh maps vm-desktop→forky)
|
||||
# because forky ships GNOME 50 / Mutter 50 — the compositor the semantic agent targets —
|
||||
# while trixie is stuck at GNOME 48. One coherent forky pocket, no trixie/forky ABI mixing.
|
||||
#
|
||||
# The GNOME 50 stack is BAKED here at build time (not pulled at firstboot): the whole desktop
|
||||
# rootfs is one CI-built pocket, so a base build never drags ~1.5 GB from snapshot.debian.org.
|
||||
# These are apt --include'd (dependencies resolved from forky); the Nucleic layer + tier metas
|
||||
# configure last (vm-desktop.late-pkgs) so the nash divert stays the final step.
|
||||
#
|
||||
# No linux-image — external kernel + its modules ride the two-phase payload (LINUX_VM.md).
|
||||
|
||||
# systemd as PID 1 (§5: the VM desktop flavor keeps systemd) + networking/udev/dbus/sudo.
|
||||
systemd
|
||||
systemd-sysv
|
||||
systemd-resolved
|
||||
udev
|
||||
dbus
|
||||
dbus-user-session
|
||||
sudo
|
||||
|
||||
# GNOME 50 Wayland session: shell/Mutter + GDM auto-login, a couple of GTK4 reference apps so
|
||||
# a fresh screenshot isn't an empty desktop, XWayland for X clients, Mesa for software GL.
|
||||
gnome-session
|
||||
gnome-shell
|
||||
gnome-shell-extension-prefs
|
||||
gdm3
|
||||
gnome-console
|
||||
gnome-text-editor
|
||||
xwayland
|
||||
libgl1-mesa-dri
|
||||
|
||||
# Accessibility stack — the AT-SPI D-Bus registry the semantic agent consumes, plus the GI
|
||||
# bindings its Python/host tooling uses, and the settings/dconf plumbing for system defaults.
|
||||
at-spi2-core
|
||||
gsettings-desktop-schemas
|
||||
dconf-cli
|
||||
python3-gi
|
||||
gir1.2-atspi-2.0
|
||||
|
||||
# Reference browser for computer-use / the semantic agent. Debian ships a real Firefox deb
|
||||
# (unlike Ubuntu's snap shim), so no Mozilla-apt dance is needed — firefox-esr from forky.
|
||||
firefox-esr
|
||||
fonts-dejavu-core
|
||||
|
||||
# Modest dev toolchain, mirroring the guest it replaces (agents also exec/build in the VM).
|
||||
build-essential
|
||||
git
|
||||
curl
|
||||
ca-certificates
|
||||
openssh-client
|
||||
iproute2
|
||||
python3
|
||||
python3-venv
|
||||
python3-pip
|
||||
nodejs
|
||||
npm
|
||||
Reference in New Issue
Block a user