From a2254648adc5c7d33706cf9ffed77ddb71333476 Mon Sep 17 00:00:00 2001 From: archipelago Date: Fri, 7 Aug 2026 15:55:18 -0400 Subject: [PATCH] fix(iso): force IPv4 for every package retrieval in the build This box (and its containers) blackhole IPv6: deb.debian.org answers AAAA first, wget tries v6 until debootstrap's per-package timeout, and the installer-env stage died twice today with 'Couldn't download packages'. Probed in a debian:trixie container: v4 OK, v6 hangs. inet4_only for wget (covers debootstrap) + Acquire::ForceIPv4 for every apt-get, including the chroot and the rootfs Dockerfile stages. Co-Authored-By: Claude --- .../_archived/build-auto-installer-iso.sh | 25 +++++++++++++------ 1 file changed, 17 insertions(+), 8 deletions(-) diff --git a/image-recipe/_archived/build-auto-installer-iso.sh b/image-recipe/_archived/build-auto-installer-iso.sh index 7d3b7a49..453979f4 100755 --- a/image-recipe/_archived/build-auto-installer-iso.sh +++ b/image-recipe/_archived/build-auto-installer-iso.sh @@ -304,7 +304,7 @@ ENV DEBIAN_FRONTEND=noninteractive # - libnftnl-dev, libmnl-dev, clang, libclang-dev: rustables → # bindgen (the gateway feature enables rustables for nftables # integration). bindgen panics without libclang.so. -RUN apt-get update && apt-get install -y --no-install-recommends \ +RUN apt-get -o Acquire::ForceIPv4=true update && apt-get -o Acquire::ForceIPv4=true install -y --no-install-recommends \ git ca-certificates build-essential pkg-config dpkg-dev \ libdbus-1-dev libssl-dev \ clang libclang-dev libnftnl-dev libmnl-dev \ @@ -343,7 +343,7 @@ RUN echo "deb http://deb.debian.org/debian trixie main non-free-firmware" > /etc rm -f /etc/apt/sources.list.d/debian.sources # Install all packages we need including nginx, podman, tor, and openssl (for self-signed certs) -RUN apt-get update && apt-get -y full-upgrade && apt-get install -y --no-install-recommends \ +RUN apt-get -o Acquire::ForceIPv4=true update && apt-get -o Acquire::ForceIPv4=true -y full-upgrade && apt-get -o Acquire::ForceIPv4=true install -y --no-install-recommends \ DOCKERFILE_HEAD # The ONLY build-time interpolation in the entire Dockerfile: the kernel and @@ -438,7 +438,7 @@ RUN find /usr/share/doc -depth -type f ! -name copyright -delete 2>/dev/null || # Install Tailscale from official repo RUN curl -fsSL https://pkgs.tailscale.com/stable/debian/trixie.noarmor.gpg | tee /usr/share/keyrings/tailscale-archive-keyring.gpg >/dev/null && \ curl -fsSL https://pkgs.tailscale.com/stable/debian/trixie.tailscale-keyring.list | tee /etc/apt/sources.list.d/tailscale.list && \ - apt-get update && apt-get -y full-upgrade && apt-get install -y --no-install-recommends tailscale && \ + apt-get -o Acquire::ForceIPv4=true update && apt-get -o Acquire::ForceIPv4=true -y full-upgrade && apt-get -o Acquire::ForceIPv4=true install -y --no-install-recommends tailscale && \ apt-get clean && rm -rf /var/lib/apt/lists/* # Install FIPS mesh daemon from the .deb built in stage 1. apt-get install @@ -834,8 +834,15 @@ _INSTALLER_ENV_SCRIPT="$WORK_DIR/_installer-env.sh" cat > "$_INSTALLER_ENV_SCRIPT" <<'INSTALLER_ENV_EOF' set -e -apt-get update -qq -apt-get install -y -qq debootstrap squashfs-tools initramfs-tools dosfstools mtools \ +# This build host (and its containers) blackhole IPv6: deb.debian.org +# answers AAAA first, wget tries v6 with long timeouts, and debootstrap's +# per-package fetch fails ("Couldn't download packages", repro'd twice on +# 2026-08-07). Force v4 for every retrieval tool this script drives. +echo 'inet4_only = on' >> /etc/wgetrc +APT_V4='-o Acquire::ForceIPv4=true' + +apt-get $APT_V4 update -qq +apt-get $APT_V4 install -y -qq debootstrap squashfs-tools initramfs-tools dosfstools mtools \ grub-efi-amd64-bin grub-pc-bin grub-common isolinux syslinux-common echo " [container] Running debootstrap --variant=minbase..." @@ -860,9 +867,11 @@ cp /etc/resolv.conf /installer/etc/resolv.conf 2>/dev/null || true mount --bind /proc /installer/proc mount --bind /sys /installer/sys mount --bind /dev /installer/dev -chroot /installer apt-get update -qq -chroot /installer apt-get -y -qq full-upgrade -chroot /installer apt-get install -y --no-install-recommends live-boot live-boot-initramfs-tools +# Same v6-blackhole discipline inside the chroot (its apt reads the +# chroot's own config, not the container's). +chroot /installer apt-get -o Acquire::ForceIPv4=true update -qq +chroot /installer apt-get -o Acquire::ForceIPv4=true -y -qq full-upgrade +chroot /installer apt-get -o Acquire::ForceIPv4=true install -y --no-install-recommends live-boot live-boot-initramfs-tools chroot /installer apt-get clean umount /installer/dev 2>/dev/null || true umount /installer/sys 2>/dev/null || true