bee_layer_classify only ever tracked regular files and symlinks (`find ... -type f -o -type l`), so any directory that is empty at build time — like /var/log/nvidia-dcgm, correctly created and chowned by the datacenter-gpu-manager postinst — was silently dropped from every layer's rsync --files-from list and never reached the built ISO. This is why bbc6fb1's78d1b9bfollow-up (seeding a marker file just for that one path) kept the directory alive: it was a targeted workaround for a general gap in the classifier, not a fix of it. Replace that workaround with the general mechanism: classify also walks every directory, computes the subset that is empty all the way down (no file or symlink anywhere in its subtree — a directory that does hold files needs no entry, rsync already recreates it as an implied parent), and assigns each one to a layer via the same dpkg-ownership / injected-rule precedence used for files. Add an injected rule routing /var/log/nvidia-dcgm to 20-nvidia-platform, alongside the DCGM binaries that actually use it, instead of letting it fall through to base by default. bee_layer_build folds each layer's empty-dir list into the same rsync --files-from call; recursion into a directory that is by-construction empty copies nothing extra. Revert the 9000/9999 hook changes from78d1b9bnow that they're redundant, and cover the new path with test-squashfs-layers.sh (ruled, unruled, and nested-empty directories, asserted present in the merged rootfs after a real mksquashfs/unsquashfs round-trip). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
ISO Build
bee ISO is built inside a Debian 12 builder container via iso/builder/build-in-container.sh.
Requirements
- Docker Desktop or another Docker-compatible container runtime
- Privileged containers enabled
- Enough free disk space for builder cache, Debian live-build artifacts, NVIDIA driver cache, and CUDA userspace packages
Build On macOS
From the repository root:
sh iso/builder/build-in-container.sh
The script defaults to linux/amd64 builder containers, so it works on:
- Intel Mac
- Apple Silicon (
M1/M2/M3/M4) via Docker Desktop's Linux VM
You do not need to pass --platform manually for normal ISO builds.
Useful Options
Build with explicit SSH keys baked into the ISO:
sh iso/builder/build-in-container.sh --authorized-keys ~/.ssh/id_ed25519.pub
Force a clean rebuild of the builder image and build caches:
sh iso/builder/build-in-container.sh --clean-build
Use a custom cache directory:
sh iso/builder/build-in-container.sh --cache-dir /path/to/cache
Notes
- The builder image is automatically rebuilt if the local tag exists for the wrong architecture.
- The live ISO boots with Debian
live-boottoram, so the read-only medium is copied into RAM during boot and the runtime no longer depends on the original USB/BMC virtual media staying present. - The NVIDIA variants ship the root filesystem as several semantic SquashFS layers (
live/filesystem-v<ver>-NN-*.squashfs) plus an explicitlive/filesystem.modulethat fixes their OverlayFS order. This bounds the data atoramretry must re-read after a virtual-media drop; it is not a fix for virtual-media instability.amd/nogpukeep a single squashfs. Seebible-local/architecture/squashfs-layers.md. - The builder splits the layers deterministically after the full
lb build, verifies each one, re-merges them into a bootable rootfs, and only then deletes the monolith. The fast path is disabled for a multi-layer medium (it forces a full build). - Target systems require at least 16 GB of installed RAM for the full compressed live medium plus normal runtime overhead. On supported hardware, do not classify a mid-copy failure as low RAM without direct
ENOSPC, OOM, or tmpfs-limit evidence. - The NVIDIA variant installs DCGM 4 packages matched to the CUDA user-mode driver major version. For driver branch
580/ CUDA13.x, the package family isdatacenter-gpu-manager-4-cuda13rather than legacydatacenter-gpu-manager. - Override the container platform only if you know why:
BEE_BUILDER_PLATFORM=linux/amd64 sh iso/builder/build-in-container.sh
- The shipped ISO is still
amd64. - Output ISO artifacts are written under
dist/.