From 1fa158942a001fcfa6c3e90d11c0802dab4100e7 Mon Sep 17 00:00:00 2001 From: Spencer Bull Date: Fri, 4 Sep 2026 16:16:54 -0500 Subject: [PATCH] perplexity: make the stray-entry guard type-blind Review caught that the allowlist only listed files and symlinks, so a future deb shipping an empty top-level bin/, sbin/ or lib64/ -- each a filesystem-owned symlink here, the exact conflict class this guard exists to close -- would pass it, as would FIFOs and device nodes. Delete the one known unit, rmdir its emptied parents, and treat any remaining entry outside opt/ and usr/ as unexpected, whatever its type. This also stops silently rm -rf'ing future /lib content: anything new there now fails the build for a human to look at instead. Verified: clean build ships only etc/, opt/ and usr/; an injected empty bin/, a stray lib64/ file, and a FIFO each abort package() with the entry listed. Built via bin/build; installs clean in a fresh container. --- pkgbuilds/perplexity/PKGBUILD | 24 +++++++++++++++--------- 1 file changed, 15 insertions(+), 9 deletions(-) diff --git a/pkgbuilds/perplexity/PKGBUILD b/pkgbuilds/perplexity/PKGBUILD index 42a496e..bbfb058 100644 --- a/pkgbuilds/perplexity/PKGBUILD +++ b/pkgbuilds/perplexity/PKGBUILD @@ -95,20 +95,26 @@ package() { # 26.9.1 started shipping a systemd unit under /lib, and owning /lib -- a # symlink owned by the filesystem package -- makes pacman refuse the whole - # transaction. The unit is also a no-op here: - # its setup script apt-installs Docker and the NVIDIA Container Toolkit and - # exits on any distro but Ubuntu (install those yourself; see optdepends). - # Delete it, but only it: anything else arriving outside the trees this - # PKGBUILD expects stops the build rather than shipping the next conflict. + # transaction. The unit is also a no-op here: its setup script apt-installs + # Docker and the NVIDIA Container Toolkit and exits on any distro but Ubuntu + # (install those yourself; see optdepends). Delete it, and its parents once + # emptied; then anything else left outside opt/ and usr/ -- whatever its + # type, an empty bin/ or lib64/ included, since those are filesystem-owned + # symlinks too -- stops the build rather than shipping the next conflict. + ( + cd "${pkgdir}" + rm -f lib/systemd/system/perplexity-local-runtime-setup.service + rmdir -p lib/systemd/system 2>/dev/null || true + ) + local unexpected - unexpected=$(cd "${pkgdir}" && find . \( -type f -o -type l \) | grep -vE \ - '^\./(opt|usr)/|^\./lib/systemd/system/perplexity-local-runtime-setup\.service$' || true) + unexpected=$(cd "${pkgdir}" && find . -mindepth 1 \ + -path ./opt -prune -o -path ./usr -prune -o -print) if [[ -n "${unexpected}" ]]; then - echo "Unexpected files outside opt/ and usr/ in the upstream deb:" >&2 + echo "Unexpected entries outside opt/ and usr/ in the upstream deb:" >&2 echo "${unexpected}" >&2 return 1 fi - rm -rf "${pkgdir}/lib" # pacman never runs the deb's postinst, so the /usr/bin entry it would have # symlinked is a launcher here instead, and the menu entry goes through it so