Termux removed libffi 3.5.2 from its rolling package pool. The pinned URL
returns 404 and stops runtime-library staging. Pin the available 3.8.0
archive with its downloaded SHA-256, which matches the package index.
Name the package, version and URL when a download fails. Flush staging
progress so piped build logs preserve the failure order. Update the
bionic Python tests to follow the current supplier and binary layout.
Verified all 83 library/license archives and 265 staged shared libraries.
The complete staging step and its verified cache hit both returned 0.
The pinned Python ctypes extension finds its required libffi symbols.
Focused tests: 19 passed, 2 skipped. Bionic execution remains a CI gate.
The clean non-root install passed native imports but ffmpeg needed libvulkan.so. Bundle Termux's real generic loader and exercise media conversion in the bare runtime. Restore doctor imports, pm-venv recognition, and current diagnostics seams.
Stage npm, ffmpeg and its bionic runtime libraries, and static ARM ripgrep. Bind caches to actual build inputs. Generate entrypoints from the project manifest and verify real CLI/TUI startup and media conversion offline. Keep versions unchanged. Windows service work remains out of scope.
Assemble the sealed hermes-agent aarch64 .deb: deps-only venv built
AT its on-device path (per-subdir mounts, staged uv, no app wheel --
Hermes is not pip-installable by design), trampolines that resolve their
symlink chain and export the payload linker path (runtime libs derived
from the suppliers' own Depends metadata), the prebuilt TUI bundle, and
the code-scoped .install_method stamp (restoring the 'apt' lane this
distribution needs). Validation runs in the BARE pinned base -- real
extraction, real postinst, C-extension imports, bundled node, TUI syntax
check, and the steward-refusal contract. A derived builder image
(toolchain pre-baked at uid 1000, content-addressed off the lock digest)
keeps cache-miss runs fast.