Both buster and bullseye now switch unconditionally to archive.debian.org
(no probing). bullseye-security lines are commented out because
archive.debian.org does not carry bullseye-security yet (404), avoiding
apt update errors. _probe_url and all probe/revert logic removed (~60
lines). Docs updated accordingly.
Remove the two 'DEBUG: __debhelper_ver / __coreutils_ver' printouts; the
version guards and their comparison branches already make the flow
self-explanatory.
The redundant non-curl -L call was removed (-L covers both cases). The
python3 urllib fallback (~25 lines) guarded against containers lacking
both wget and curl, which never occurs in the supported Debian/Ubuntu
build images, so it was dropped. Behavior verified with sandboxed
runs: bullseye probe-success keeps official sources, probe-fail
switches main to archive and reverts security to deb.debian.org.
buster is fully archived (main/updates/backports and security under
buster/updates all on archive.debian.org), so keep the unconditional
switch but drop its duplicated .list/.sources loops. Extract shared
_switch_to_archive() and _add_backports() helpers used by both buster
and bullseye, merge the bullseye security-revert loops, and remove the
redundant EOL_CODENAMES scan and dead warning branch. Behavior
unchanged; verified via sandboxed runs for buster, bullseye (probe
ok + probe fail) and non-EOL bookworm.
- docker/setup-buildx-action v3->v4, docker/login-action v3->v4,
docker/build-push-action v5->v7 to eliminate Node.js 20 deprecated
warnings (Node 24 runtime, requires runner >=2.327.1)
actions/checkout@v5, upload-artifact@v7, download-artifact@v7,
ncipollo/release-action@v1 already node24 -> keep
- install_deps.sh: fix bullseye EOL handling that caused
'archive.debian.org/debian-security bullseye-security 404' in
Build and Push Dependency Images (continously failing since 82d0f3f):
robust _probe_url (wget->curl->python3 fallback, both Release/InRelease),
keep official source when reachable, and when falling back to archive
verify archive security exists else revert security to deb.debian.org
(keeps bullseye/main on archive, security on official until archive ready)
- pullsrc.sh fetches debhelper/libdebhelper-perl 14.3 (pinned DEBHELPER_SIDPKG
in version.env, empty = auto-detect latest sid) into gitignored builddep/
- install_deps.sh installs builddep/*.deb and adds compat sed hacks for sid
debhelper >= 13.27: rewrite Dh_Lib.pm bucket 'cp --update=none' to '-n' on
coreutils < 9.3 (buster/bionic/bookworm), downgrade use v5.28 pragmas in
Dh_Lib.pm/dh_assistant for perl < 5.28, handle ${tmpdir} brace form in the
non-merged-usr hack; drop the dead sid-apt-source _DEBIAN_DEBHELPER
- Dockerfile.deps: BuildKit bind mounts instead of COPY (nothing in layers)
- CI deps-image build runs ./pullsrc.sh debhelper first to populate context
- merge APT_MIRROR and EOL archive switching into install_deps.sh
fix_apt_sources() (buster unconditional, bullseye probed via
Release/InRelease with fallback to archive.debian.org)
- make DEBMIRROR follow APT_MIRROR in version.env (nounset-safe)
- remove switch_archive_sources.sh (no remaining callers)
- simplify docker/Dockerfile.deps to single RUN and update CI to use
install_deps.sh --fix-apt-only
- update docs (AGENTS.md/README.md) to reflect new flow
Building against libfido2-dev from backports (e.g. Debian 10 buster,
libfido2 1.5.0-2~bpo10+1) produces a libfido2-1 (>= 1.5.0) runtime
dependency that a stock target system (libfido2 0.4.0) cannot satisfy,
making the package uninstallable. Gate the install on the package being
available from the default archive instead of only in backports.
compile.sh:
- drop libcrypt-dev build-dep when absent (crypt.h in libc6-dev)
- strip runit integration when dh-runit constraint is unsatisfiable
(avoids uninstallable runit-helper >= 2.17 dep)
- rewrite sysusers named-GID syntax for systemd < 244 (237 cannot
parse 'u sshd -:nogroup', sshd privsep user was never created)
- install systemd units to /lib on non-merged-usr distros
(deb-systemd-helper 1.51 only searches /lib/systemd/system)
install_deps.sh:
- install ca-certificates (fixes GitHub TLS verification in pullsrc)
- install libcrypt-dev when available in the archive
- pull dwz from <codename>-backports when too old for debhelper 13.14
- patch debhelper 13.14 for Perl 5.26 (list-context state, dh_missing)
- lower init-system-helpers dep versions and drop
--skip-systemd-native from invoke-rc.d calls on old distros
- keep dh_installsystemd unit path at /lib on non-merged-usr
CI: add ubuntu:bionic to both workflow matrices