stoke/scripts/install-apt.sh
cluade-reviewer-andresmgsl 5e99006d04 install-apt: address review — locale-safe parsing, metadata refresh, no list clobber, README order
- Parse apt-cache policy under LC_ALL=C (Candidate: label is localized)
- Refresh apt metadata (best effort) and re-check before concluding no
  suitable nodejs source exists
- Refuse to overwrite an existing /etc/apt/sources.list.d/nodesource.list
  instead of silently replacing a user-managed entry
- README: manual path now adds the forge source, then the Node 22 source,
  then runs apt-get update && install — in that order

Verified on fresh debian:13: install, idempotent re-run (NodeSource not
re-added), and the refusal branch with a pre-existing user list.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-22 21:56:26 +00:00

102 lines
4.1 KiB
Bash
Executable file

#!/usr/bin/env bash
#
# One-time setup to install stoke via apt on Debian/Ubuntu.
#
# Adds the heavy-duty Forgejo Debian registry as an APT source (with its
# signing key) and installs the stoke package. Safe to re-run; afterwards
# stoke upgrades through regular `apt-get upgrade`.
#
# Usage:
# ./scripts/install-apt.sh
# FORGE_URL=... OWNER=... ./scripts/install-apt.sh # non-default instance
#
# Run as root or as a user with sudo.
set -euo pipefail
FORGE_URL="${FORGE_URL:-https://forgejo.heavyduty.builders}"
OWNER="${OWNER:-heavy-duty}"
DISTRIBUTION="${DISTRIBUTION:-stable}"
COMPONENT="${COMPONENT:-main}"
KEYRING="/etc/apt/keyrings/forgejo-$OWNER.asc"
LIST="/etc/apt/sources.list.d/forgejo-$OWNER.list"
SUDO=""
if [ "$(id -u)" -ne 0 ]; then
command -v sudo >/dev/null 2>&1 || { echo "error: run as root or install sudo" >&2; exit 1; }
SUDO="sudo"
fi
update_only_source() {
$SUDO apt-get update \
-o Dir::Etc::sourcelist="$1" \
-o Dir::Etc::sourceparts=/dev/null \
-o APT::Get::List-Cleanup=0
}
# stoke needs Node.js >= 22.12 (commander 15), but the distro archives of
# Debian 13 (nodejs 20.x) and Ubuntu 24.04 (nodejs 18.x) cannot satisfy
# that, which would make `apt-get install stoke` fail with an unmet
# dependency. When no configured source offers a new-enough nodejs, add the
# NodeSource repository for Node 22 so the dependency resolves.
NODE_MIN="22.12"
node_candidate_ok() {
local candidate
# LC_ALL=C: the "Candidate:" label is localized.
candidate="$(LC_ALL=C apt-cache policy nodejs 2>/dev/null | sed -n 's/^ Candidate: //p')"
[ -n "$candidate" ] && [ "$candidate" != "(none)" ] || return 1
dpkg --compare-versions "${candidate#*:}" ge "$NODE_MIN"
}
ensure_nodejs_source() {
node_candidate_ok && return 0
# The verdict may just be stale package lists — refresh (best effort, a
# transient failure of an unrelated source must not abort) and re-check
# before adding anything.
echo "No apt source seems to provide nodejs >= $NODE_MIN; refreshing apt metadata ..."
$SUDO apt-get update || true
node_candidate_ok && return 0
local ns_keyring="/etc/apt/keyrings/nodesource.asc"
local ns_list="/etc/apt/sources.list.d/nodesource.list"
if [ -e "$ns_list" ]; then
echo "error: nodejs >= $NODE_MIN is unavailable and $ns_list already exists;" >&2
echo "refusing to overwrite it. Point it at a Node >= 22 release and re-run." >&2
exit 1
fi
echo "Adding NodeSource (Node 22) ..."
curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | $SUDO tee "$ns_keyring" >/dev/null
echo "deb [signed-by=$ns_keyring] https://deb.nodesource.com/node_22.x nodistro main" \
| $SUDO tee "$ns_list" >/dev/null
update_only_source "$ns_list"
node_candidate_ok || { echo "error: still no nodejs >= $NODE_MIN available after adding NodeSource" >&2; exit 1; }
}
echo "Adding APT source for $FORGE_URL/$OWNER ..."
$SUDO install -d -m 0755 /etc/apt/keyrings
curl -fsSL "$FORGE_URL/api/packages/$OWNER/debian/repository.key" | $SUDO tee "$KEYRING" >/dev/null
echo "deb [signed-by=$KEYRING] $FORGE_URL/api/packages/$OWNER/debian $DISTRIBUTION $COMPONENT" \
| $SUDO tee "$LIST" >/dev/null
# Newer apt verifies with sqv (Sequoia), which rejects the signature Forgejo
# currently produces for its Debian registry (malformed Ed25519 MPI encoding
# in the upstream signing library). Try the properly signed source first so
# this heals automatically once the forge is fixed; otherwise fall back to
# [trusted=yes] — package integrity then relies on HTTPS to our own forge.
if ! update_only_source "$LIST"; then
echo
echo "WARNING: signature verification failed (known Forgejo registry issue" >&2
echo "with sqv-based apt). Falling back to [trusted=yes]; transport" >&2
echo "security is provided by HTTPS to $FORGE_URL." >&2
echo
echo "deb [trusted=yes] $FORGE_URL/api/packages/$OWNER/debian $DISTRIBUTION $COMPONENT" \
| $SUDO tee "$LIST" >/dev/null
update_only_source "$LIST"
fi
ensure_nodejs_source
$SUDO apt-get install -y stoke
echo
stoke --version >/dev/null && echo "stoke $(stoke --version) installed. Run: stoke auth login"