problem description
All sources we add to DISTRO_APT_SOURCES are being made available to mmdebstrap to create the minbase system from.
This is a problem because some of those sources provide packages that are mistakenly marked with Priority "required", so all of those get forcibly installed.
Example: Azure/AZNFS-mount#322 which was recently added to microsofts's own source for debian trixie packages, and is not installable at this point, breaking our build. But the issue goes deeper, installing a lot of packages we did not intend to install, or installing them in unintended versions.
Arguably, that's the packages' fault, and they should fix it.
what does the docs say?
But also arguably, the ISAR docs state in https://github.com/ilbers/isar/blob/master/doc/user_manual.md#add-a-new-distro that The first entry of DISTRO_APT_SOURCES is used for bootstrapping (implying that all others are not).
And https://github.com/ilbers/isar/blob/master/doc/technical_overview.md#32-minimal-base-system goes on to state that DISTRO_APT_SOURCES [is] later deployed to the minimal base system to be used by apt itself, implying it's done after the minbase system is constructed (i.e. "later").
Am I interpreting the docs wrong?
If so, should there be a separate way to specify sources only for explicitly installing packages, not during bootstrap?
attempted workaround
We are using hooks to work around this by commenting lines we don't want before minbase is created and un-commenting them afterwards, but this is less than ideal. An official way to do this would be preferred.
versions affected
Our product uses commit cc5a5d9, I cannot test a newer commit easily, sorry. Let me know if this has been addressed already, I did not see any issues that would fit...
Update: Managed to reproduce with latest commit of master (86c761e), same issue.
problem description
All sources we add to DISTRO_APT_SOURCES are being made available to mmdebstrap to create the minbase system from.
This is a problem because some of those sources provide packages that are mistakenly marked with Priority "required", so all of those get forcibly installed.
Example: Azure/AZNFS-mount#322 which was recently added to microsofts's own source for debian trixie packages, and is not installable at this point, breaking our build. But the issue goes deeper, installing a lot of packages we did not intend to install, or installing them in unintended versions.
Arguably, that's the packages' fault, and they should fix it.
what does the docs say?
But also arguably, the ISAR docs state in https://github.com/ilbers/isar/blob/master/doc/user_manual.md#add-a-new-distro that
The first entry of DISTRO_APT_SOURCES is used for bootstrapping(implying that all others are not).And https://github.com/ilbers/isar/blob/master/doc/technical_overview.md#32-minimal-base-system goes on to state that
DISTRO_APT_SOURCES [is] later deployed to the minimal base system to be used by apt itself, implying it's done after the minbase system is constructed (i.e. "later").Am I interpreting the docs wrong?
If so, should there be a separate way to specify sources only for explicitly installing packages, not during bootstrap?
attempted workaround
We are using hooks to work around this by commenting lines we don't want before minbase is created and un-commenting them afterwards, but this is less than ideal. An official way to do this would be preferred.
versions affected
Our product uses commit cc5a5d9,
I cannot test a newer commit easily, sorry. Let me know if this has been addressed already, I did not see any issues that would fit...Update: Managed to reproduce with latest commit of master (86c761e), same issue.