Channel-correct Docker images: keyring from own channel; repo-add uses edge
The builder stage never declared ARG MIRROR, so the keyring [omarchy] repo pointed at the channel-less legacy pkgs.omarchy.org/$arch path — it works only because a stale copy of the old layout still answers there, and it would miss a keyring rotation. Each image now pulls omarchy-keyring from its own channel (edge/rc/stable), matching the base mirror it already selects. update-repo and remove-package switch to the edge x86_64 image: repo-add and repo-remove compile nothing, and using the channel image would deadlock bootstrap-rc — the rc image can only build once the rc channel it pulls the keyring from exists remotely.
This commit is contained in:
+3
-2
@@ -89,7 +89,8 @@ if [[ ! $REPLY =~ ^[Yy]$ ]]; then
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
# Build/update the Docker image (always use x86_64 for removal - it's architecture independent)
|
# Build/update the Docker image (always use x86_64 for removal - it's architecture independent)
|
||||||
build_docker_image "$BUILD_DIR" "x86_64" "$MIRROR"
|
# repo-remove is mirror-independent — always use the edge x86_64 image
|
||||||
|
build_docker_image "$BUILD_DIR" "x86_64" "edge"
|
||||||
|
|
||||||
acquire_release_lock || exit 1
|
acquire_release_lock || exit 1
|
||||||
|
|
||||||
@@ -104,7 +105,7 @@ docker run --rm --platform linux/amd64 \
|
|||||||
-e MIRROR="$MIRROR" \
|
-e MIRROR="$MIRROR" \
|
||||||
-v "$REPO_ROOT:/pkgs.omarchy.org" \
|
-v "$REPO_ROOT:/pkgs.omarchy.org" \
|
||||||
-v "$BUILD_DIR:/build:ro" \
|
-v "$BUILD_DIR:/build:ro" \
|
||||||
omarchy-pkg-builder:latest-x86_64-$MIRROR /build/remove-package.sh "$PACKAGE_NAME"
|
omarchy-pkg-builder:latest-x86_64-edge /build/remove-package.sh "$PACKAGE_NAME"
|
||||||
|
|
||||||
RESULT=$?
|
RESULT=$?
|
||||||
|
|
||||||
|
|||||||
+5
-4
@@ -28,16 +28,17 @@ update_database() {
|
|||||||
# Make output directory writable for container
|
# Make output directory writable for container
|
||||||
make_dir_writable "$REPO_DIR"
|
make_dir_writable "$REPO_DIR"
|
||||||
|
|
||||||
# Build Docker image (always use x86_64 for repo update - it's architecture independent)
|
# repo-add is architecture- and mirror-independent, so always use the edge
|
||||||
build_docker_image "$BUILD_DIR" "x86_64" "$MIRROR"
|
# x86_64 image. This also lets bootstrap-rc build the rc database before the
|
||||||
|
# rc channel exists remotely (an rc image can only build after it does).
|
||||||
|
build_docker_image "$BUILD_DIR" "x86_64" "edge"
|
||||||
|
|
||||||
# Run repo-add in Docker container (always use x86_64 image)
|
|
||||||
docker run --rm --platform linux/amd64 \
|
docker run --rm --platform linux/amd64 \
|
||||||
-e ARCH="$ARCH" \
|
-e ARCH="$ARCH" \
|
||||||
-e MIRROR="$MIRROR" \
|
-e MIRROR="$MIRROR" \
|
||||||
-v "$REPO_ROOT:/output" \
|
-v "$REPO_ROOT:/output" \
|
||||||
-v "$BUILD_DIR:/build:ro" \
|
-v "$BUILD_DIR:/build:ro" \
|
||||||
omarchy-pkg-builder:latest-x86_64-$MIRROR /build/update-repo.sh
|
omarchy-pkg-builder:latest-x86_64-edge /build/update-repo.sh
|
||||||
}
|
}
|
||||||
|
|
||||||
# Main execution
|
# Main execution
|
||||||
|
|||||||
+5
-2
@@ -106,10 +106,13 @@ RUN ln -sf /usr/lib/os-release /etc/os-release && \
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
# Setup Omarchy keyring manually before adding repo (avoids keyserver trust issues)
|
# Setup Omarchy keyring manually before adding repo (avoids keyserver trust issues)
|
||||||
# Note: Repository is removed at the end since build scripts add it dynamically
|
# Note: Repository is removed at the end since build scripts add it dynamically.
|
||||||
|
# The keyring comes from this image's own channel (the bare /$arch path is a
|
||||||
|
# stale legacy layout); %s keeps pacman's $arch literal while MIRROR expands.
|
||||||
|
ARG MIRROR=edge
|
||||||
RUN pacman-key --recv-keys 40DFB630FF42BCFFB047046CF0134EE680CAC571 --keyserver keys.openpgp.org && \
|
RUN pacman-key --recv-keys 40DFB630FF42BCFFB047046CF0134EE680CAC571 --keyserver keys.openpgp.org && \
|
||||||
pacman-key --lsign-key 40DFB630FF42BCFFB047046CF0134EE680CAC571 && \
|
pacman-key --lsign-key 40DFB630FF42BCFFB047046CF0134EE680CAC571 && \
|
||||||
printf '\n[omarchy]\nSigLevel = Optional\nServer = https://pkgs.omarchy.org/$arch\n' >> /etc/pacman.conf && \
|
printf '\n[omarchy]\nSigLevel = Optional\nServer = https://pkgs.omarchy.org/%s/$arch\n' "${MIRROR}" >> /etc/pacman.conf && \
|
||||||
pacman -Sy --noconfirm && \
|
pacman -Sy --noconfirm && \
|
||||||
pacman -S --noconfirm omarchy-keyring && \
|
pacman -S --noconfirm omarchy-keyring && \
|
||||||
pacman-key --populate omarchy && \
|
pacman-key --populate omarchy && \
|
||||||
|
|||||||
Reference in New Issue
Block a user