Merge nucleic/clever-quartz-marten-uqnx into dev
This commit is contained in:
+10
-5
@@ -13,8 +13,9 @@
|
|||||||
# Build via build.sh (assembles the context: this directory + the dist/pool apt pool).
|
# Build via build.sh (assembles the context: this directory + the dist/pool apt pool).
|
||||||
# NOTE: every RUN here executes under nash — /bin/sh is already diverted in naros-base.
|
# NOTE: every RUN here executes under nash — /bin/sh is already diverted in naros-base.
|
||||||
# That is deliberate dogfood (this build is part of nash's M3 validation surface); nash's
|
# That is deliberate dogfood (this build is part of nash's M3 validation surface); nash's
|
||||||
# parse-failure fallback re-execs the preserved /usr/bin/bash.real, so a nash regression
|
# `-c` parse-failure fallback re-execs the preserved /usr/bin/bash.real, so a nash
|
||||||
# degrades loudly in CI rather than silently corrupting the image.
|
# regression degrades loudly in CI rather than silently corrupting the image. Scripts
|
||||||
|
# piped on stdin do not cross that fallback and must choose their interpreter explicitly.
|
||||||
ARG BASE=naros-base:build
|
ARG BASE=naros-base:build
|
||||||
FROM ${BASE}
|
FROM ${BASE}
|
||||||
|
|
||||||
@@ -72,7 +73,10 @@ RUN set -eu; \
|
|||||||
# Everything world-readable so the non-root agent uses them in place (§6.1: no /root
|
# Everything world-readable so the non-root agent uses them in place (§6.1: no /root
|
||||||
# permission hacks — system paths or /opt by convention).
|
# permission hacks — system paths or /opt by convention).
|
||||||
RUN set -eu; \
|
RUN set -eu; \
|
||||||
curl -fsSL https://sh.rustup.rs | sh -s -- -y --profile minimal \
|
# nash's parse fallback applies to `-c`, not scripts supplied on stdin.
|
||||||
|
# Upstream installers are outside the dogfood surface, so run them with the
|
||||||
|
# preserved Debian bash instead of feeding them to the diverted sh/bash.
|
||||||
|
curl -fsSL https://sh.rustup.rs | /usr/bin/bash.real -s -- -y --profile minimal \
|
||||||
--default-toolchain stable --no-modify-path; \
|
--default-toolchain stable --no-modify-path; \
|
||||||
"$CARGO_HOME/bin/rustc" --version; \
|
"$CARGO_HOME/bin/rustc" --version; \
|
||||||
case "$TARGETARCH" in \
|
case "$TARGETARCH" in \
|
||||||
@@ -133,8 +137,9 @@ RUN npm install -g @anthropic-ai/claude-code@latest \
|
|||||||
|
|
||||||
# xAI Grok Build via its official installer, relocated from the 0700 /root to a
|
# xAI Grok Build via its official installer, relocated from the 0700 /root to a
|
||||||
# world-traversable /opt and relinked onto PATH (same dance as nucleic-sandbox v4+ —
|
# world-traversable /opt and relinked onto PATH (same dance as nucleic-sandbox v4+ —
|
||||||
# narOS keeps agent-reachable installs out of /root by convention).
|
# narOS keeps agent-reachable installs out of /root by convention). As with rustup, the
|
||||||
RUN curl -fsSL https://x.ai/cli/install.sh | bash \
|
# stdin-fed upstream script needs the preserved real bash rather than diverted `bash`.
|
||||||
|
RUN curl -fsSL https://x.ai/cli/install.sh | /usr/bin/bash.real \
|
||||||
&& rm -f /usr/local/bin/grok /usr/local/bin/agent \
|
&& rm -f /usr/local/bin/grok /usr/local/bin/agent \
|
||||||
&& mv /root/.grok /opt/grok \
|
&& mv /root/.grok /opt/grok \
|
||||||
&& chmod -R a+rX /opt/grok \
|
&& chmod -R a+rX /opt/grok \
|
||||||
|
|||||||
Reference in New Issue
Block a user