From 2a47ad775bf9c600bdaae87650326e69bc76a96c Mon Sep 17 00:00:00 2001 From: Marcelo Alcantara Date: Thu, 24 Sep 2026 16:05:38 +1000 Subject: [PATCH] Drop setuid from chrome-sandbox and keep Obsidian's tests in its package Chromium sandboxes through unprivileged user namespaces on Arch-family kernels, so the setuid-root helper is unnecessary. The watcher tests now run from check() as checksummed package sources, leaving tests/ and the shared Tests workflow untouched. --- .github/workflows/test.yml | 1 - pkgbuilds/obsidian/.omarchy/upstream.sh | 2 +- pkgbuilds/obsidian/PKGBUILD | 15 ++++++++++++--- pkgbuilds/obsidian/README.md | 4 ++-- .../obsidian/test-upstream.py | 2 +- pkgbuilds/obsidian/{.omarchy => }/upstream.py | 0 6 files changed, 16 insertions(+), 8 deletions(-) rename tests/obsidian-upstream.py => pkgbuilds/obsidian/test-upstream.py (95%) rename pkgbuilds/obsidian/{.omarchy => }/upstream.py (100%) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 8754f27..29d18b0 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -50,7 +50,6 @@ jobs: pacman -Syu --noconfirm git jq python libarchive python tests/oma-service-removal.py python tests/upstream-watch.py - python tests/obsidian-upstream.py ./bin/sync-upstream self-test ./bin/sync-rebuilds --self-test ./bin/omarchy-pkgs self-test diff --git a/pkgbuilds/obsidian/.omarchy/upstream.sh b/pkgbuilds/obsidian/.omarchy/upstream.sh index c422cec..e2b9028 100644 --- a/pkgbuilds/obsidian/.omarchy/upstream.sh +++ b/pkgbuilds/obsidian/.omarchy/upstream.sh @@ -1,3 +1,3 @@ #!/bin/bash set -euo pipefail -python3 "$(dirname "$0")/upstream.py" +python3 "$(dirname "$0")/../upstream.py" diff --git a/pkgbuilds/obsidian/PKGBUILD b/pkgbuilds/obsidian/PKGBUILD index 00e8060..25a0ea5 100644 --- a/pkgbuilds/obsidian/PKGBUILD +++ b/pkgbuilds/obsidian/PKGBUILD @@ -41,13 +41,20 @@ depends=( provides=('obsidian') conflicts=('obsidian-appimage' 'obsidian-bin') options=('!debug' '!strip') -source=('obsidian.desktop') +checkdepends=('python') +source=('obsidian.desktop' 'upstream.py' 'test-upstream.py') source_aarch64=( "obsidian-${pkgver}-arm64.tar.gz::https://github.com/obsidianmd/obsidian-releases/releases/download/v${pkgver}/obsidian-${pkgver}-arm64.tar.gz" ) -sha256sums=('42ecb332c900a01b2a6db0a70b4cc8c0553e863aee72894b23ed20a6289b131c') +sha256sums=('42ecb332c900a01b2a6db0a70b4cc8c0553e863aee72894b23ed20a6289b131c' + 'd2933bdc97d9ba55986d710114512e0eb105e1cc549cef4aa7416cb333e0a9b8' + '7213e4e691c53e184b0f037478ac6758fe44adad7a984fc1daef7fd17c31d5d8') sha256sums_aarch64=('98aac34d1f132a35cf506fc3fa196d595dcdeefdebd44b0cc5faaa7a1a210de2') +check() { + python test-upstream.py +} + package() { local source_dir="$srcdir/obsidian-${pkgver}-arm64" local install_dir="$pkgdir/opt/obsidian" @@ -78,7 +85,9 @@ package() { "$install_dir/chrome_crashpad_handler" \ "$install_dir/obsidian" \ "$install_dir/obsidian-cli" - chmod 4755 "$install_dir/chrome-sandbox" + # Chromium sandboxes through unprivileged user namespaces, which Arch-family + # kernels allow; a setuid-root helper is not needed. + chmod 755 "$install_dir/chrome-sandbox" install -d "$pkgdir/usr/bin" ln -s /opt/obsidian/obsidian "$pkgdir/usr/bin/obsidian" diff --git a/pkgbuilds/obsidian/README.md b/pkgbuilds/obsidian/README.md index 4d12c27..ca6564e 100644 --- a/pkgbuilds/obsidian/README.md +++ b/pkgbuilds/obsidian/README.md @@ -2,9 +2,9 @@ This is the canonical `obsidian` package, extracted from omacom/omarchy-pkgs #240 at `dcef132b2df11bb762e233ea8c6af3110f079b67`. It repackages the official ARM64 desktop tarball and preserves the original contributor attribution and Electron/Chromium license files. -The package owns the installed application bundle and Electron runtime. Obsidian's user-controlled in-app updater may separately update application code; no updater-disabling patch is applied. See https://obsidian.md/help/updates. +The package owns the installed application bundle and Electron runtime. `chrome-sandbox` is installed without setuid: Chromium's sandbox uses unprivileged user namespaces, which Arch-family kernels allow. A system that disables them must re-enable them rather than launch Obsidian with `--no-sandbox`. Obsidian's user-controlled in-app updater may separately update application code; no updater-disabling patch is applied. See https://obsidian.md/help/updates. -The package-local upstream hook selects stable desktop releases containing the exact ARM64 tarball, ignoring mobile-only tags. Missing SHA256 metadata on the selected desktop release fails rather than silently selecting an older installer. Run `python tests/obsidian-upstream.py` for offline tests. Upstream's scheduled sync opens or updates its normal review PR; maintainers need GitHub PR notifications enabled and should monitor failed sync runs too. +The package-local upstream hook selects stable desktop releases containing the exact ARM64 tarball, ignoring mobile-only tags. Missing SHA256 metadata on the selected desktop release fails rather than silently selecting an older installer. The offline tests in `test-upstream.py` run in the package's `check()`; run them directly with `python pkgbuilds/obsidian/test-upstream.py`. Upstream's scheduled sync opens or updates its normal review PR; maintainers need GitHub PR notifications enabled and should monitor failed sync runs too. This package conflicts with `obsidian-appimage` and `obsidian-bin`. It does not automatically remove them or migrate users. Adoption in Omarchy Mac requires a separate change to the existing ARM preinstall/removal mappings. Do not modify vaults or user configuration as part of the package transaction. diff --git a/tests/obsidian-upstream.py b/pkgbuilds/obsidian/test-upstream.py similarity index 95% rename from tests/obsidian-upstream.py rename to pkgbuilds/obsidian/test-upstream.py index 2638b34..762d68e 100644 --- a/tests/obsidian-upstream.py +++ b/pkgbuilds/obsidian/test-upstream.py @@ -3,7 +3,7 @@ import importlib.util from pathlib import Path import unittest -path = Path(__file__).resolve().parents[1] / 'pkgbuilds/obsidian/.omarchy/upstream.py' +path = Path(__file__).with_name('upstream.py') spec = importlib.util.spec_from_file_location('obsidian_upstream', path) module = importlib.util.module_from_spec(spec) spec.loader.exec_module(module) diff --git a/pkgbuilds/obsidian/.omarchy/upstream.py b/pkgbuilds/obsidian/upstream.py similarity index 100% rename from pkgbuilds/obsidian/.omarchy/upstream.py rename to pkgbuilds/obsidian/upstream.py