From 55bc67834b3c96871eb1f81b8205627356b40f40 Mon Sep 17 00:00:00 2001 From: Spencer Bull Date: Thu, 3 Sep 2026 22:52:22 -0500 Subject: [PATCH 1/2] perplexity: stop shipping upstream's /lib, fail closed on strays 26.9.1 added /lib/systemd/system/perplexity-local-runtime-setup.service to the deb, and wholesale extraction made the package own /lib -- a symlink owned by filesystem -- so pacman refused every install and upgrade. The unit could never work here anyway: its setup script apt-installs Docker and the NVIDIA Container Toolkit and exits on any distro but Ubuntu, so the Arch equivalents ride optdepends instead. package() now allowlists what leaves the deb: opt/, usr/, and that one known unit path (deleted). Anything else stops the build rather than shipping the next filesystem conflict. Verified in a clean container: the published -1 reproduces the /lib conflict; -2 installs fresh and upgrades from 26.8.4 cleanly. --- pkgbuilds/perplexity/PKGBUILD | 21 ++++++++++++++++++++- 1 file changed, 20 insertions(+), 1 deletion(-) diff --git a/pkgbuilds/perplexity/PKGBUILD b/pkgbuilds/perplexity/PKGBUILD index e7fe1d1..42a496e 100644 --- a/pkgbuilds/perplexity/PKGBUILD +++ b/pkgbuilds/perplexity/PKGBUILD @@ -6,7 +6,7 @@ pkgname=perplexity pkgver=26.9.1+build61614 -pkgrel=1 +pkgrel=2 pkgdesc="Official Perplexity desktop app" arch=('x86_64' 'aarch64') url="https://www.perplexity.ai" @@ -56,6 +56,8 @@ depends=( optdepends=( 'apparmor: confine the app with the bundled user-namespace profile' 'libappindicator-gtk3: tray icon support' + 'docker: containerized local GPU runtime for on-device models' + 'nvidia-container-toolkit: containerized local GPU runtime for on-device models' ) makedepends=('libarchive') @@ -91,6 +93,23 @@ package() { bsdtar -xOf "${deb}" data.tar.xz | bsdtar --no-same-owner -xf - -C "${pkgdir}" + # 26.9.1 started shipping a systemd unit under /lib, and owning /lib -- a + # symlink owned by the filesystem package -- makes pacman refuse the whole + # transaction. The unit is also a no-op here: + # its setup script apt-installs Docker and the NVIDIA Container Toolkit and + # exits on any distro but Ubuntu (install those yourself; see optdepends). + # Delete it, but only it: anything else arriving outside the trees this + # PKGBUILD expects stops the build rather than shipping the next conflict. + local unexpected + unexpected=$(cd "${pkgdir}" && find . \( -type f -o -type l \) | grep -vE \ + '^\./(opt|usr)/|^\./lib/systemd/system/perplexity-local-runtime-setup\.service$' || true) + if [[ -n "${unexpected}" ]]; then + echo "Unexpected files outside opt/ and usr/ in the upstream deb:" >&2 + echo "${unexpected}" >&2 + return 1 + fi + rm -rf "${pkgdir}/lib" + # pacman never runs the deb's postinst, so the /usr/bin entry it would have # symlinked is a launcher here instead, and the menu entry goes through it so # the flags file applies there too. The scheme handler stays upstream's. From 1fa158942a001fcfa6c3e90d11c0802dab4100e7 Mon Sep 17 00:00:00 2001 From: Spencer Bull Date: Fri, 4 Sep 2026 16:16:54 -0500 Subject: [PATCH 2/2] perplexity: make the stray-entry guard type-blind Review caught that the allowlist only listed files and symlinks, so a future deb shipping an empty top-level bin/, sbin/ or lib64/ -- each a filesystem-owned symlink here, the exact conflict class this guard exists to close -- would pass it, as would FIFOs and device nodes. Delete the one known unit, rmdir its emptied parents, and treat any remaining entry outside opt/ and usr/ as unexpected, whatever its type. This also stops silently rm -rf'ing future /lib content: anything new there now fails the build for a human to look at instead. Verified: clean build ships only etc/, opt/ and usr/; an injected empty bin/, a stray lib64/ file, and a FIFO each abort package() with the entry listed. Built via bin/build; installs clean in a fresh container. --- pkgbuilds/perplexity/PKGBUILD | 24 +++++++++++++++--------- 1 file changed, 15 insertions(+), 9 deletions(-) diff --git a/pkgbuilds/perplexity/PKGBUILD b/pkgbuilds/perplexity/PKGBUILD index 42a496e..bbfb058 100644 --- a/pkgbuilds/perplexity/PKGBUILD +++ b/pkgbuilds/perplexity/PKGBUILD @@ -95,20 +95,26 @@ package() { # 26.9.1 started shipping a systemd unit under /lib, and owning /lib -- a # symlink owned by the filesystem package -- makes pacman refuse the whole - # transaction. The unit is also a no-op here: - # its setup script apt-installs Docker and the NVIDIA Container Toolkit and - # exits on any distro but Ubuntu (install those yourself; see optdepends). - # Delete it, but only it: anything else arriving outside the trees this - # PKGBUILD expects stops the build rather than shipping the next conflict. + # transaction. The unit is also a no-op here: its setup script apt-installs + # Docker and the NVIDIA Container Toolkit and exits on any distro but Ubuntu + # (install those yourself; see optdepends). Delete it, and its parents once + # emptied; then anything else left outside opt/ and usr/ -- whatever its + # type, an empty bin/ or lib64/ included, since those are filesystem-owned + # symlinks too -- stops the build rather than shipping the next conflict. + ( + cd "${pkgdir}" + rm -f lib/systemd/system/perplexity-local-runtime-setup.service + rmdir -p lib/systemd/system 2>/dev/null || true + ) + local unexpected - unexpected=$(cd "${pkgdir}" && find . \( -type f -o -type l \) | grep -vE \ - '^\./(opt|usr)/|^\./lib/systemd/system/perplexity-local-runtime-setup\.service$' || true) + unexpected=$(cd "${pkgdir}" && find . -mindepth 1 \ + -path ./opt -prune -o -path ./usr -prune -o -print) if [[ -n "${unexpected}" ]]; then - echo "Unexpected files outside opt/ and usr/ in the upstream deb:" >&2 + echo "Unexpected entries outside opt/ and usr/ in the upstream deb:" >&2 echo "${unexpected}" >&2 return 1 fi - rm -rf "${pkgdir}/lib" # pacman never runs the deb's postinst, so the /usr/bin entry it would have # symlinked is a launcher here instead, and the menu entry goes through it so