Skip to content

fix: make the CI ISO build work (pacman keyring init + protobuf/cmake/clang) - #3

Merged
debpalash merged 3 commits into
mainfrom
fix/iso-ci-pacman-key
Jun 26, 2026
Merged

debpalash merged 3 commits into
mainfrom
fix/iso-ci-pacman-key

Conversation

@debpalash

Copy link
Copy Markdown
Owner

Third in the chain of ISO-build fixes uncovered after the workspace migration (#1) made the Build IndOS ISO workflow actually run on main.

Problem

With the findmnt fix (#2) letting the build proceed past dependency install, it then failed at the CachyOS keyring step:

==> ERROR: There is no secret key available to sign with.
==> Use 'pacman-key --init' to generate a default secret key.

build-iso.sh runs pacman-key --lsign-key F3B607488DB35A47, which needs a local pacman signing key. A fresh CI container never ran pacman-key --init, so there's none. (Pre-existing — every prior CI ISO build died earlier at the findmnt step, so this was never reached.)

Fix

Run pacman-key --init before --lsign-key. It generates the master key on fresh hosts and is a no-op where the keyring is already initialized (real CachyOS dev machines).

Verification

Dispatched the Build IndOS ISO workflow on this branch: it now gets past dependency install and the keyring step into the main Build ISO phase (pacstrap + cargo + squashfs) — which also exercises the #2 workspace-binary-path fix.

🤖 Generated with Claude Code

debpalash and others added 2 commits June 26, 2026 04:33
After the findmnt fix let the ISO build proceed, it failed at the
CachyOS keyring step: `pacman-key --lsign-key` needs a local signing
key, which a fresh CI container lacks ("no secret key available to sign
with"). Run `pacman-key --init` first; it's a no-op where the keyring is
already initialized. (Pre-existing — masked until the findmnt fix.)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The ISO build compiles the workspace, whose lancedb stack
(lance-encoding) requires `protoc` at build time. build-iso.yml only
installed base-devel, so the cargo build failed ~25 min in with
"Could not find protoc". Add protobuf + cmake + clang — the same
build-tool set the CI rust job already uses. (Pre-existing: lancedb is
pulled via the orchestrator's path dep on indos-context-engine.)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@debpalash debpalash changed the title fix: init pacman keyring before lsign in ISO build fix: make the CI ISO build work (pacman keyring init + protobuf/cmake/clang) Jun 26, 2026
After the protoc fix, the workspace compiled (47 min) but the parallel
indos-shell build failed: build-iso.yml lacked the Wayland/GL libs that
the iced shell needs (build-iso.sh builds shell alongside the workspace
binaries). Add the same Wayland dep set the `gui` job uses.

Also cache ~/.cargo + the workspace/shell target dirs: the uncached
release build of the lancedb/lance/datafusion tree takes ~47 min on a
2-core runner, which made every ISO build impractically slow.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@debpalash
debpalash merged commit a804ca5 into main Jun 26, 2026
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant