Install verification¶
Generated by scripts/gen_install_verification.py. Do not edit by hand —
regenerate.
Measured: 2026-08-26
Method: apt-get install -y --no-install-recommends, one package per
fresh container, inside the target's own image.
apt-cache policy proves an archive offers a package. A capability-matrix row
claims more than that: it claims the package installs on that target. The last
round's inventories rested entirely on the weaker check and said so. This closes
the gap for DragonOS Tier 1 and for the four upstream .deb artifacts that
SCOPE.md admits to Tier 1 alongside apt.
Three outcomes, because the harness is degraded. This account has no subordinate UID ranges, so a rootless container cannot run a postinst that chowns to a system user. That is a fact about the harness, not about any package, and conflating the two would be exactly the error D-018 exists to prevent — an earlier version of this probe reported 21 false failures by doing precisely that.
The classification is therefore structural rather than a string match on error text: if dpkg has a version recorded, dependency resolution and unpack succeeded, whatever happened afterwards.
Result 1 — the apt claims hold¶
31 of 34 DragonOS Tier 1 packages resolve and install on
Debian 13. The 3 that do not are exactly the
three apt-cache policy already reported absent. No package that policy
said was available failed to resolve.
| Outcome | Count | What it means |
|---|---|---|
OK |
25 | Resolved, unpacked and configured. |
UNPACKED |
6 | Resolved and unpacked; configuration blocked by the harness, not the package. See the caveat below. |
UNRESOLVED |
3 | Not in the archive. This is a fact about Debian 13. |
Not in Debian 13¶
| Package | Reported |
|---|---|
kismet |
E: Unable to locate package kismet |
sdrpp |
E: Unable to locate package sdrpp |
sdrangel |
E: Unable to locate package sdrangel |
Consistent with dragonos-tier1-inventory.md: all three are apt on Kali,
and sdrpp is apt on Parrot too.
Resolved but not configured¶
direwolf, gpredict, gpsd, cubicsdr, gnuradio, gr-gsm
Every one of these pulls dbus or systemd, whose maintainer scripts set ownership
and ACLs the container cannot map. direwolf is representative: its postinst
creates a system user and runs chown direwolf:direwolf /var/lib/direwolf,
which returns EINVAL.
Dependency resolution — the thing being measured — succeeded for all of them. Whether they configure cleanly is untested here and needs either CI or a machine with subuid ranges. It is not evidence of a problem.
Result 2 — three of four upstream .deb artifacts do not install¶
SCOPE.md defines Tier 1 as "apt-installable or upstream .deb". The
second half was never tested. dragonos-tier1-inventory.md flagged the risk —
"a .deb built for an older release is not guaranteed to satisfy on a newer
one" — and recommended an install test before any manifest claimed support.
Here is that test. The risk was real.
| Artifact | Built for | Debian 13 | Ubuntu 26.04 |
|---|---|---|---|
satdump-ubuntu2404 |
Ubuntu 24.04 | ❌ unmet deps | ❌ unmet deps |
sdrpp-bookworm |
Debian 12 | ❌ unmet deps | ❌ unmet deps |
sdrpp-sid |
Debian unstable | ✅ installs | ✅ installs |
sdrangel-ubuntu2604 |
Ubuntu 26.04 | ❌ unmet deps | ✅ resolves |
ais-catcher-bookworm |
Debian 12 | ✅ installs | ✅ resolves |
Why each one failed¶
| Artifact | Target | Unmet |
|---|---|---|
satdump-ubuntu2404 |
debian-13 | Depends: libhdf5-hl-100t64 but it is |
sdrpp-bookworm |
debian-13 | Depends: libvolk2-dev but it is |
sdrangel-ubuntu2604 |
debian-13 | Depends: libavcodec62 (>= 7:8.0.1) but it is ;Depends: libavformat62 (>= 7:8.0.1) but it is |
satdump-ubuntu2404 |
ubuntu-26.04 | Depends: libfftw3-bin but it is ;Depends: libvolk-bin but it is |
sdrpp-bookworm |
ubuntu-26.04 | Depends: libfftw3-dev but it is ;Depends: libglfw3-dev but it is |
SatDump's published .deb installs on neither target. The only Linux
artifact its release ships targets Ubuntu 24.04, and on Debian 13 it wants
libhdf5-hl-100t64 while on Ubuntu 26.04 it wants libvolk-bin and
libfftw3-bin versions that are not there. SatDump is still Tier 1 — but by
apt, not by .deb. satdump 1.2.2-1 is in Debian 13 and installed cleanly in
the package probe above.
SDR++ works, but only through the artifact nobody would pick. The
debian_bookworm build fails on both targets, wanting libvolk2-dev — the old
SONAME, which is exactly the package-name correction the DragonOS inventory had
to make. The debian_sid build installs cleanly on both Debian 13 and
Ubuntu 26.04. Choosing the right artifact here is not obvious and is not
documented upstream.
SDR++ has no pinnable release. Its assets hang off a rolling nightly tag,
so the download URL never changes and the artifact behind it does. There is no
version to pin and no checksum published. That is the pin/hash sub-project
SCOPE.md names, in its sharpest form so far: even a diligent packager cannot
pin this.
SDRangel resolves only on the base it was built for. Its Ubuntu 26.04 .deb
resolves on Ubuntu 26.04 and fails on Debian 13, wanting
libavcodec62 (>= 7:8.0.1) — Ubuntu's ffmpeg, not Debian 13's. Upstream
publishes a per-release matrix, which is the right thing to do; the manifest has
to select from it per target rather than carry one URL.
AIS-Catcher is the only genuinely portable one. Its Debian 12 build resolves on both Debian 13 and Ubuntu 26.04.
Corrections this forces¶
docs/reference/dragonos-tier1-inventory.mdlists four units as Tier 1 "by upstream.deb". Measured, only two reach a target through their.deb— SDR++ (via thesidartifact) and AIS-Catcher. SatDump is Tier 1 by apt instead, and SDRangel is Tier 1 only on Ubuntu 26.04.- A manifest cannot carry one
.debURL per package.sdrppandsdrangelboth need per-target artifact selection, which the existingSelectoralready expresses — but it means the four.debunits need four install blocks, not one. SCOPE.md's Tier 1 definition needs a word. "Upstream.deb" should read "upstream.debthat resolves on the target". As written it admits artifacts that do not install, which is the opposite of what a tier meant to be cheap and stable is for.
What is still not tested¶
Said plainly, because the point of this document is that untested claims are not claims:
- Configuration is untested for anything touching dbus or systemd. Six
packages and two
.debartifacts areUNPACKED, meaning resolved and unpacked only. Fixing this needssudo usermod --add-subuids 100000-165535 --add-subgids 100000-165535 <user>andpodman system migrate, or CI. - Nothing was run. Installing is not launching. No binary was executed, no GUI opened, no SDR attached.
- Only Debian 13 was probed for packages. Ubuntu 26.04, Kali, Parrot and
Mint have
apt-cache policydata but no install test. - The
.debmatrix covers two bases, not all five targets. - No checksums are pinned yet. The probe records the SHA-256 of each artifact it downloaded, which is a starting point for the pin database and not the same as a published upstream checksum — none of the four publishes one.