The shell suites pin the bullseye floor image to a dated tag, and the two PowerShell orchestrators still ask for the floating one, so the two suites build and test a different floor.
scripts/suite-lib.sh:192 defines CLD_FLOOR_IMAGE=debian:bullseye-20241111-slim and the comment above it calls that "THE ONE SPELLING of the bullseye floor image for both suites". scripts/run-evidence.sh:66 and scripts/run-appimage.sh:91 use it.
experiments/run.ps1:111 and experiments/appimage.ps1:211 still hardcode debian:bullseye-slim, and their headers at run.ps1:11 and appimage.ps1:10 describe the floating tag too.
The pin is not cosmetic. Per scripts/build.sh:34-44 and docs/building.md, the floating tag carries libc6 2.31-13+deb11u14 from the bullseye-security suite, while archive.debian.org (where the stage rewrites apt to) tops out at deb11u11; libc6-dev must version-match libc6 exactly, so the install fails with "held broken packages". That is the failure the dated tag was chosen to remove, and the PowerShell path still walks into it.
Fix: use debian:bullseye-20241111-slim in both PowerShell files and their headers, and note there that the tag must move with scripts/suite-lib.sh.
The shell suites pin the bullseye floor image to a dated tag, and the two PowerShell orchestrators still ask for the floating one, so the two suites build and test a different floor.
scripts/suite-lib.sh:192definesCLD_FLOOR_IMAGE=debian:bullseye-20241111-slimand the comment above it calls that "THE ONE SPELLING of the bullseye floor image for both suites".scripts/run-evidence.sh:66andscripts/run-appimage.sh:91use it.experiments/run.ps1:111andexperiments/appimage.ps1:211still hardcodedebian:bullseye-slim, and their headers atrun.ps1:11andappimage.ps1:10describe the floating tag too.The pin is not cosmetic. Per
scripts/build.sh:34-44anddocs/building.md, the floating tag carries libc62.31-13+deb11u14from the bullseye-security suite, whilearchive.debian.org(where the stage rewrites apt to) tops out atdeb11u11;libc6-devmust version-match libc6 exactly, so the install fails with "held broken packages". That is the failure the dated tag was chosen to remove, and the PowerShell path still walks into it.Fix: use
debian:bullseye-20241111-slimin both PowerShell files and their headers, and note there that the tag must move withscripts/suite-lib.sh.