diff --git a/image-recipe/_archived/build-auto-installer-iso.sh b/image-recipe/_archived/build-auto-installer-iso.sh index 85e5b593..fdf425f7 100755 --- a/image-recipe/_archived/build-auto-installer-iso.sh +++ b/image-recipe/_archived/build-auto-installer-iso.sh @@ -1183,39 +1183,13 @@ BACKENDFILE fi fi -# Extract NostrVPN binary from container image (native system service, not a container app) -# NOTE: The container image must be built against Debian 13's GLIBC (2.40). -# If built against a newer GLIBC, the binary will fail at runtime. -# Rebuild with: FROM debian:13 AS builder -echo " Extracting NostrVPN binary..." -_NVPN_IMG="${NOSTR_VPN_IMAGE:-146.59.87.168:3000/lfg2025/nostr-vpn:v0.3.7}" -NVPN_IMAGE_ID="$($CONTAINER_CMD images -q "$_NVPN_IMG" 2>/dev/null)" -if [ -z "$NVPN_IMAGE_ID" ]; then - $CONTAINER_CMD pull "$_NVPN_IMG" 2>/dev/null || true -fi -NVPN_CONTAINER=$($CONTAINER_CMD create "$_NVPN_IMG" 2>/dev/null) || true -if [ -n "$NVPN_CONTAINER" ]; then - $CONTAINER_CMD cp "$NVPN_CONTAINER:/usr/local/bin/nvpn" "$ARCH_DIR/bin/nvpn" 2>/dev/null && \ - chmod +x "$ARCH_DIR/bin/nvpn" && \ - echo " ✅ NostrVPN binary extracted ($(du -h "$ARCH_DIR/bin/nvpn" | cut -f1))" - $CONTAINER_CMD rm "$NVPN_CONTAINER" 2>/dev/null || true - # Check GLIBC compatibility — Debian 13 (Trixie) has GLIBC 2.40 - if [ -f "$ARCH_DIR/bin/nvpn" ]; then - NVPN_GLIBC=$(objdump -T "$ARCH_DIR/bin/nvpn" 2>/dev/null | grep -oP 'GLIBC_\K[0-9.]+' | sort -V | tail -1) - if [ -n "$NVPN_GLIBC" ]; then - # Compare: if required GLIBC > 2.40, warn - if printf '%s\n' "2.40" "$NVPN_GLIBC" | sort -V | tail -1 | grep -qv "^2\.40$"; then - echo " ⚠ WARNING: nvpn binary requires GLIBC $NVPN_GLIBC but Debian 13 has 2.40" - echo " ⚠ The nvpn daemon will fail at runtime. Rebuild the container against Debian 13." - echo " ⚠ VPN invite/status will still work via Rust backend config.toml fallback." - else - echo " ✅ nvpn GLIBC compatibility OK (requires $NVPN_GLIBC, target has 2.40)" - fi - fi - fi -else - echo " ⚠ NostrVPN image not available — nvpn binary will be missing" -fi +# NostrVPN (the native `nvpn` mesh-VPN daemon) has been removed from the +# product — the active VPN path is WireGuard/Tailscale (see core vpn.rs). Its +# service is already masked below (ln -sf /dev/null nostr-vpn.service) and the +# binary is never spawned at runtime, so we no longer extract it. The +# nostr-vpn image was deleted from the registry, which is why hard-requiring +# it here bricked the build. Intentionally left out; do not re-add without +# restoring the daemon. # Extract nostr-rs-relay binary from container image (native system service for VPN signaling) echo " Extracting nostr-rs-relay binary..." @@ -1233,11 +1207,11 @@ else echo " ⚠ nostr-rs-relay image not available — relay binary will be missing" fi -# A missing nvpn/nostr-rs-relay used to be a warning, and the resulting ISO -# shipped units that crash-looped (or silently lacked VPN signaling) on every -# install. Refuse to produce that ISO unless explicitly overridden. +# A missing nostr-rs-relay used to be a warning, and the resulting ISO shipped +# an enabled nostr-relay unit that crash-looped on every install. Refuse to +# produce that ISO unless explicitly overridden. (nvpn is intentionally no +# longer required — NostrVPN was removed; see the note above.) MISSING_VPN_BINARIES="" -[ -f "$ARCH_DIR/bin/nvpn" ] || MISSING_VPN_BINARIES="$MISSING_VPN_BINARIES nvpn" [ -f "$ARCH_DIR/bin/nostr-rs-relay" ] || MISSING_VPN_BINARIES="$MISSING_VPN_BINARIES nostr-rs-relay" if [ -n "$MISSING_VPN_BINARIES" ]; then if [ "${ALLOW_MISSING_VPN_BINARIES:-0}" = "1" ]; then