CI / Check (pull_request) Successful in 5m26s
CI / Detect Changes (pull_request) Has been skipped
CI / Deploy Agent (pull_request) Has been skipped
CI / Deploy Dashboard (pull_request) Has been skipped
CI / Deploy Docs (pull_request) Has been skipped
CI / Deploy MCP (pull_request) Has been skipped
nix-portable fell back to proot in the deployment (user namespaces are blocked by the container's default seccomp/apparmor profile, and orca can't relax it), and proot corrupts the nix build's file-permission syscalls — every firmware build failed at `cp: setting permissions … No such file or directory` and fell back to the analysis-only SBOM. Ship a real nix instead and disable its build sandbox (`sandbox = false`): a plain gcc/make firmware build needs no user namespace, so it runs under the locked-down profile with no proot at all. The store ships as a compressed bootstrap tarball (built in a throwaway `nixos/nix` stage) and is seeded onto /nix at first start by docker/agent-entrypoint.sh, so a persistent /nix volume survives redeploys. Seeding and the whole path are best-effort — a broken nix just falls back to analysis-only, never breaking a scan. No agent code change: NixBackend::detect() already prefers the system `nix`. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
20 lines
810 B
Bash
20 lines
810 B
Bash
#!/usr/bin/env bash
|
|
# Seed the nix store on first start, then run the agent.
|
|
#
|
|
# The firmware-SBOM pipeline drives a real `nix` build (tramiton NixBackend).
|
|
# The image ships the store as a bootstrap tarball rather than baking /nix, so a
|
|
# persistent /nix volume (mounted empty on first deploy) gets populated once and
|
|
# then survives redeploys. Seeding is best-effort: if it fails, the agent still
|
|
# starts and firmware SBOMs fall back to analysis-only.
|
|
if [ ! -e /nix/store ]; then
|
|
echo "agent-entrypoint: seeding /nix store from image bootstrap..."
|
|
mkdir -p /nix
|
|
if tar -C / -xzf /opt/nix-bootstrap.tar.gz; then
|
|
echo "agent-entrypoint: /nix store seeded."
|
|
else
|
|
echo "agent-entrypoint: WARN nix seed failed; firmware SBOM will use analysis-only fallback."
|
|
fi
|
|
fi
|
|
|
|
exec compliance-agent "$@"
|