Repository navigation
Gentoo: prepare phase-aware feature packaging - #1564
Merged
ilysenko merged 1 commit intoOct 7, 2026
Merged
Conversation
ilysenko
marked this pull request as ready for review
October 7, 2026 11:21
ilysenko
approved these changes
Oct 7, 2026
ilysenko
left a comment
Owner
There was a problem hiding this comment.
Reviewed the complete shared packaging and Gentoo foundation diff, including two independent reviews. No blocking regressions found; all 22 current-head checks pass. Phase separation, permission preservation, signed-stable verification and update-builder closure are consistent. Full Portage lifecycle validation remains a documented limitation; no repository feature is declared Gentoo-supported yet.
5 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Prepare the Gentoo feature-packaging foundation on top of current
main. This follows the merged local-ebuild implementation in #1553, but does not declare any repository feature supported yet. The supported repository feature selection therefore remains empty, andPACKAGE_WITH_UPDATER=0continues to leave native updates to Portage.gentoo.supportedauditing and enabled-only dependency plans, separating regular-userbootstrapprerequisites from EAPI 8BDEPEND,DEPEND,RDEPEND, andIDEPEND.bootstrapatoms into dependency installation before helper/app/package builds. These tools do not become runtime dependencies or enter the world set, and feature keyword/license/USE policy is not automatically relaxed.ebuild, includingpackageDependencies.ebuildas an RDEPEND-only declaration. Gentoo package resources stay belowusr/oretc/; staging hooks run with the builder's privileges, never as Portagepkg_*hooks.unpack.This is groundwork for feature-by-feature follow-ups, not a claim that all Linux features work on Gentoo. It's based and tested on an OpenRC Gentoo installation; thus
systemd-related feature are not in this PR's scope.The existing signed-source verification, transactional repository deployment, bundled CLI default, and package identity are unchanged.
Validation
EAPI 8atom parsing, refusal cases, phase isolation, user-space package hooks, resource modes, and the archive-to-image path underumask 022.bash tests/scripts_smoke.sh: passed; the broad smoke subset reports 99 passed / 2 intentionally skipped signed-bundle tests, in addition to the Gentoo tests.app.asar,ChatGPT, and bundledcodexbyte-for-byte with the accepted build. No host package merge or GUI replacement was performed.nix flake check --no-build --all-systems: passed evaluation for x86_64-linux and aarch64-linux. This is evaluation, not a claim that the full Nix builds or VM tests ran locally.git diff --check: passed.Local environment limitations
./scripts/ci-local.sh allcannot start here because neither Docker nor Podman is installed.The previously reported all-feature run on local Node 26.10.0 had 18 failures against unchanged upstream
main: 17 Watchbound resource-copy failures plus one reaper fixture inheriting the live Wayland session. The reaper fixture passes with session variables cleared.The Watchbound failures are now confirmed to be a real build-time Node API compatibility defect in the community feature's resource installer. It reserves the package directory with
mkdir, then copies to that already-existing directory withforce: false, errorOnExist: true. Node 26.10.0 now rejects that directory as documented by Node #64124. Enabling the feature while creating its resources enters this production path; the failure uses the build host's system Node.The focused fix is tracked separately in PR #1565, an independent sibling based directly on
main. Its feature suite passes 126 tests on both Node 24.19.0 and 26.10.0, and a Watchbound-only build from signed stable 26.1002.52244 / amd64 succeeds with packaged inventories and hashes verified. This Gentoo foundation PR does not contain or depend on that fix, and the supported repository feature selection remains empty. The diagnosis does not establish a defect in the Gentoo ebuild, the official GUI's runtime, or the Watchbound native engine.Upstream CI uses Node 24 for this PR's source tests and supplies the package/build matrix.
The historical stable-only dependency audit is not rerun. Native Gentoo systemd and ARM64 runtime environments have not been tested.
Review gate and draft status
The complete
origin/main..HEADdiff was independently reviewed withgpt-6.1-solat maximum reasoning effort. Initial review found two directory-permission blockers; both were fixed with recursive permission and archive-to-image regression tests. The complete revised diff was reviewed again, and the final result reports no actionable regressions / no remaining blockers relative to61b1663164e3f141ba1a307cc61a1d4e3c8fb276.The review model ran read-only checks; the full filesystem-writing packaging tests and official-payload builds listed above were run separately in the writable local validation environment.
Opening as Draft to run upstream PR CI; not requesting maintainer re-review or merge yet.