From 5e99006d04b53b18ff3d70bad4a9a1ede940f595 Mon Sep 17 00:00:00 2001 From: cluade-reviewer-andresmgsl Date: Wed, 22 Jul 2026 21:56:26 +0000 Subject: [PATCH] =?UTF-8?q?install-apt:=20address=20review=20=E2=80=94=20l?= =?UTF-8?q?ocale-safe=20parsing,=20metadata=20refresh,=20no=20list=20clobb?= =?UTF-8?q?er,=20README=20order?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Parse apt-cache policy under LC_ALL=C (Candidate: label is localized) - Refresh apt metadata (best effort) and re-check before concluding no suitable nodejs source exists - Refuse to overwrite an existing /etc/apt/sources.list.d/nodesource.list instead of silently replacing a user-managed entry - README: manual path now adds the forge source, then the Node 22 source, then runs apt-get update && install — in that order Verified on fresh debian:13: install, idempotent re-run (NodeSource not re-added), and the refusal branch with a pre-existing user list. Co-Authored-By: Claude Opus 4.8 (1M context) --- README.md | 15 ++++++++++----- scripts/install-apt.sh | 16 ++++++++++++++-- 2 files changed, 24 insertions(+), 7 deletions(-) diff --git a/README.md b/README.md index bfea833..e12a565 100644 --- a/README.md +++ b/README.md @@ -19,7 +19,7 @@ The package is published to the Debian registry of the forge itself. One-time se curl -fsSL https://forgejo.heavyduty.builders/heavy-duty/stoke/raw/branch/main/scripts/install-apt.sh | bash ``` -or manually: +or manually. First add the forge's registry as an apt source: ```bash sudo install -d /etc/apt/keyrings @@ -27,12 +27,9 @@ curl -fsSL https://forgejo.heavyduty.builders/api/packages/heavy-duty/debian/rep | sudo tee /etc/apt/keyrings/forgejo-heavy-duty.asc >/dev/null echo "deb [signed-by=/etc/apt/keyrings/forgejo-heavy-duty.asc] https://forgejo.heavyduty.builders/api/packages/heavy-duty/debian stable main" \ | sudo tee /etc/apt/sources.list.d/forgejo-heavy-duty.list -sudo apt-get update && sudo apt-get install stoke ``` -Upgrades then arrive through regular `apt-get upgrade`. - -The package depends on `nodejs (>= 22.12)`, which the distro archives of Debian 13 (Node 20) and Ubuntu 24.04 (Node 18) cannot satisfy. `install-apt.sh` handles this automatically by adding the [NodeSource](https://deb.nodesource.com) Node 22 repository when no configured apt source offers a new-enough nodejs. If you follow the manual steps instead, make sure such a source is available before `apt-get install stoke`: +The package depends on `nodejs (>= 22.12)`, which the distro archives of Debian 13 (Node 20) and Ubuntu 24.04 (Node 18) cannot satisfy — on those distros, also add a Node 22 source such as [NodeSource](https://deb.nodesource.com): ```bash curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key \ @@ -41,6 +38,14 @@ echo "deb [signed-by=/etc/apt/keyrings/nodesource.asc] https://deb.nodesource.co | sudo tee /etc/apt/sources.list.d/nodesource.list ``` +Then install: + +```bash +sudo apt-get update && sudo apt-get install stoke +``` + +Upgrades then arrive through regular `apt-get upgrade`. `install-apt.sh` performs all of the above, adding the NodeSource repository only when no already-configured apt source offers a new-enough nodejs. + Note: apt releases that verify OpenPGP with `sqv` (Debian 13+, apt >= 2.9) currently reject the signature Forgejo generates for its Debian registry (an upstream signing bug). `install-apt.sh` detects this and falls back to a `[trusted=yes]` source — integrity then relies on HTTPS to the forge. The script prefers the signed source, so setups heal automatically once the forge is fixed. As a fallback, each release also has the `.deb` attached for direct install: `sudo dpkg -i stoke__all.deb`. diff --git a/scripts/install-apt.sh b/scripts/install-apt.sh index 90ceb35..bf13ef5 100755 --- a/scripts/install-apt.sh +++ b/scripts/install-apt.sh @@ -43,16 +43,28 @@ update_only_source() { NODE_MIN="22.12" node_candidate_ok() { local candidate - candidate="$(apt-cache policy nodejs 2>/dev/null | sed -n 's/^ Candidate: //p')" + # LC_ALL=C: the "Candidate:" label is localized. + candidate="$(LC_ALL=C apt-cache policy nodejs 2>/dev/null | sed -n 's/^ Candidate: //p')" [ -n "$candidate" ] && [ "$candidate" != "(none)" ] || return 1 dpkg --compare-versions "${candidate#*:}" ge "$NODE_MIN" } ensure_nodejs_source() { node_candidate_ok && return 0 - echo "No apt source provides nodejs >= $NODE_MIN; adding NodeSource (Node 22) ..." + # The verdict may just be stale package lists — refresh (best effort, a + # transient failure of an unrelated source must not abort) and re-check + # before adding anything. + echo "No apt source seems to provide nodejs >= $NODE_MIN; refreshing apt metadata ..." + $SUDO apt-get update || true + node_candidate_ok && return 0 local ns_keyring="/etc/apt/keyrings/nodesource.asc" local ns_list="/etc/apt/sources.list.d/nodesource.list" + if [ -e "$ns_list" ]; then + echo "error: nodejs >= $NODE_MIN is unavailable and $ns_list already exists;" >&2 + echo "refusing to overwrite it. Point it at a Node >= 22 release and re-run." >&2 + exit 1 + fi + echo "Adding NodeSource (Node 22) ..." curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | $SUDO tee "$ns_keyring" >/dev/null echo "deb [signed-by=$ns_keyring] https://deb.nodesource.com/node_22.x nodistro main" \ | $SUDO tee "$ns_list" >/dev/null