Channel-correct Docker images: keyring from own channel; repo-add uses edge
The builder stage never declared ARG MIRROR, so the keyring [omarchy] repo pointed at the channel-less legacy pkgs.omarchy.org/$arch path — it works only because a stale copy of the old layout still answers there, and it would miss a keyring rotation. Each image now pulls omarchy-keyring from its own channel (edge/rc/stable), matching the base mirror it already selects. update-repo and remove-package switch to the edge x86_64 image: repo-add and repo-remove compile nothing, and using the channel image would deadlock bootstrap-rc — the rc image can only build once the rc channel it pulls the keyring from exists remotely.
This commit is contained in:
+3
-2
@@ -89,7 +89,8 @@ if [[ ! $REPLY =~ ^[Yy]$ ]]; then
|
||||
fi
|
||||
|
||||
# Build/update the Docker image (always use x86_64 for removal - it's architecture independent)
|
||||
build_docker_image "$BUILD_DIR" "x86_64" "$MIRROR"
|
||||
# repo-remove is mirror-independent — always use the edge x86_64 image
|
||||
build_docker_image "$BUILD_DIR" "x86_64" "edge"
|
||||
|
||||
acquire_release_lock || exit 1
|
||||
|
||||
@@ -104,7 +105,7 @@ docker run --rm --platform linux/amd64 \
|
||||
-e MIRROR="$MIRROR" \
|
||||
-v "$REPO_ROOT:/pkgs.omarchy.org" \
|
||||
-v "$BUILD_DIR:/build:ro" \
|
||||
omarchy-pkg-builder:latest-x86_64-$MIRROR /build/remove-package.sh "$PACKAGE_NAME"
|
||||
omarchy-pkg-builder:latest-x86_64-edge /build/remove-package.sh "$PACKAGE_NAME"
|
||||
|
||||
RESULT=$?
|
||||
|
||||
|
||||
+5
-4
@@ -28,16 +28,17 @@ update_database() {
|
||||
# Make output directory writable for container
|
||||
make_dir_writable "$REPO_DIR"
|
||||
|
||||
# Build Docker image (always use x86_64 for repo update - it's architecture independent)
|
||||
build_docker_image "$BUILD_DIR" "x86_64" "$MIRROR"
|
||||
# repo-add is architecture- and mirror-independent, so always use the edge
|
||||
# x86_64 image. This also lets bootstrap-rc build the rc database before the
|
||||
# rc channel exists remotely (an rc image can only build after it does).
|
||||
build_docker_image "$BUILD_DIR" "x86_64" "edge"
|
||||
|
||||
# Run repo-add in Docker container (always use x86_64 image)
|
||||
docker run --rm --platform linux/amd64 \
|
||||
-e ARCH="$ARCH" \
|
||||
-e MIRROR="$MIRROR" \
|
||||
-v "$REPO_ROOT:/output" \
|
||||
-v "$BUILD_DIR:/build:ro" \
|
||||
omarchy-pkg-builder:latest-x86_64-$MIRROR /build/update-repo.sh
|
||||
omarchy-pkg-builder:latest-x86_64-edge /build/update-repo.sh
|
||||
}
|
||||
|
||||
# Main execution
|
||||
|
||||
+5
-2
@@ -106,10 +106,13 @@ RUN ln -sf /usr/lib/os-release /etc/os-release && \
|
||||
fi
|
||||
|
||||
# Setup Omarchy keyring manually before adding repo (avoids keyserver trust issues)
|
||||
# Note: Repository is removed at the end since build scripts add it dynamically
|
||||
# Note: Repository is removed at the end since build scripts add it dynamically.
|
||||
# The keyring comes from this image's own channel (the bare /$arch path is a
|
||||
# stale legacy layout); %s keeps pacman's $arch literal while MIRROR expands.
|
||||
ARG MIRROR=edge
|
||||
RUN pacman-key --recv-keys 40DFB630FF42BCFFB047046CF0134EE680CAC571 --keyserver keys.openpgp.org && \
|
||||
pacman-key --lsign-key 40DFB630FF42BCFFB047046CF0134EE680CAC571 && \
|
||||
printf '\n[omarchy]\nSigLevel = Optional\nServer = https://pkgs.omarchy.org/$arch\n' >> /etc/pacman.conf && \
|
||||
printf '\n[omarchy]\nSigLevel = Optional\nServer = https://pkgs.omarchy.org/%s/$arch\n' "${MIRROR}" >> /etc/pacman.conf && \
|
||||
pacman -Sy --noconfirm && \
|
||||
pacman -S --noconfirm omarchy-keyring && \
|
||||
pacman-key --populate omarchy && \
|
||||
|
||||
Reference in New Issue
Block a user