From d783f46f5d41c61f17f8c79c2415490e96321da7 Mon Sep 17 00:00:00 2001 From: Scott Jones Date: Mon, 14 Sep 2026 21:55:22 -0400 Subject: [PATCH] Build Grok Bot 0.47.0 for aarch64 and fix packaged desktop integration --- pkgbuilds/grok-bot/PKGBUILD | 56 ++++++++++++++++------------- pkgbuilds/grok-bot/grok-bot.desktop | 2 +- pkgbuilds/grok-bot/grok-bot.install | 41 +++++++++++++++++++++ 3 files changed, 73 insertions(+), 26 deletions(-) create mode 100644 pkgbuilds/grok-bot/grok-bot.install diff --git a/pkgbuilds/grok-bot/PKGBUILD b/pkgbuilds/grok-bot/PKGBUILD index 1109333..bcc5797 100644 --- a/pkgbuilds/grok-bot/PKGBUILD +++ b/pkgbuilds/grok-bot/PKGBUILD @@ -2,14 +2,15 @@ # Contributor: Omarchy pkgname=grok-bot -pkgver=0.29.0 +pkgver=0.47.0 pkgrel=1 -_commit=f0e5bfcee649ea84c0c61369cf896cd146d72136 +_commit=c1e7d7a46549956d25f53e9c0b9f59666e03aa3a pkgdesc='Grok Bot desktop agent' -arch=('x86_64') +arch=('x86_64' 'aarch64') url='https://x.ai/bot' license=('custom') depends=( + 'alsa-lib' 'at-spi2-core' 'gtk3' 'hicolor-icon-theme' @@ -25,32 +26,36 @@ optdepends=('libappindicator-gtk3: tray support') provides=('sand') conflicts=('sand') options=('!strip' '!debug') +install=grok-bot.install + +_deb_x86_64="grok-bot_${pkgver}_amd64.deb" +_deb_aarch64="grok-bot_${pkgver}_arm64.deb" source=( - "${pkgname}_${pkgver}.deb::https://downloads.cursor.com/grokbot/stable/${_commit}/linux/x64/Grok_Bot_${pkgver}.deb" 'grok-bot.sh' 'grok-bot.desktop' ) -sha256sums=('d223b5830282aef11d5c46d8f4d1edd239bf992e336405cbd288d4476b9233d4' - '6dfa6c305941afa6cbaefbeaae06d05ab5a88f31630005d25a819a160c20c7a3' - '856056c9ca63dda5d01158ce8fb6a9a7cbb3f67c13a92b573cd196d3e50f26e7') -noextract=("${pkgname}_${pkgver}.deb") +source_x86_64=( + "${_deb_x86_64}::https://downloads.cursor.com/grokbot/stable/${_commit}/linux/x64/${_deb_x86_64}" +) +source_aarch64=( + "${_deb_aarch64}::https://downloads.cursor.com/grokbot/stable/${_commit}/linux/arm64/${_deb_aarch64}" +) +sha256sums=('6dfa6c305941afa6cbaefbeaae06d05ab5a88f31630005d25a819a160c20c7a3' + '3e2a2461ea58d17ac1777616be9ba660f7cb9ceefa9292016e36c55758bf78dd') +sha256sums_x86_64=('11ca0f51a535b97af51a352adf9c0f9ecd2e1b0430a69ae9451b688a7a065808') +sha256sums_aarch64=('836f8d19d3826c6573c31ac45c7a9b797abc73381ae0d2b1e7a8dae5410e7e46') +noextract=("${_deb_x86_64}" "${_deb_aarch64}") package() { - bsdtar -xOf "${srcdir}/${pkgname}_${pkgver}.deb" data.tar.xz | + local deb_var="_deb_${CARCH}" + local deb="${!deb_var}" + + bsdtar -xOf "${srcdir}/${deb}" data.tar.xz | bsdtar -x -C "${pkgdir}" -f - rm -rf "${pkgdir}/usr/share/doc" \ - "${pkgdir}/usr/share/applications/sand.desktop" - - local icon1024="${pkgdir}/usr/share/icons/hicolor/1024x1024/apps" - if [[ -f "${icon1024}/sand.png" && ! -f "${icon1024}/grok-bot.png" ]]; then - install -Dm644 "${icon1024}/sand.png" "${icon1024}/grok-bot.png" - fi - rm -f "${icon1024}/sand.png" - if [[ -f "${icon1024}/grok-bot.png" ]]; then - install -Dm644 "${icon1024}/grok-bot.png" \ - "${pkgdir}/usr/share/icons/hicolor/512x512/apps/grok-bot.png" - fi + "${pkgdir}/usr/share/applications/sand.desktop" \ + "${pkgdir}/usr/share/applications/grok-bot.desktop" # Always install our Wayland wrapper; do not keep any /usr/bin from the .deb. rm -f "${pkgdir}/usr/bin/grok-bot" "${pkgdir}/usr/bin/sand" @@ -64,9 +69,10 @@ package() { install -Dm644 "${pkgdir}/opt/Grok Bot/LICENSES.chromium.html" \ "${pkgdir}/usr/share/licenses/${pkgname}/LICENSES.chromium.html" - if ! { [[ -L /proc/self/ns/user ]] && unshare --user true; }; then - chmod 4755 "${pkgdir}/opt/Grok Bot/chrome-sandbox" - else - chmod 0755 "${pkgdir}/opt/Grok Bot/chrome-sandbox" - fi + # Ship chrome-sandbox without setuid. Upstream's build-time userns probe + # would measure the CI container, not the user's machine, and a setuid + # helper could not exec from "/opt/Grok Bot/" anyway (electron#44414). + # grok-bot.install tells users on kernels without unprivileged user + # namespaces how to run without the sandbox. + chmod 0755 "${pkgdir}/opt/Grok Bot/chrome-sandbox" } diff --git a/pkgbuilds/grok-bot/grok-bot.desktop b/pkgbuilds/grok-bot/grok-bot.desktop index 992c36c..ddda47a 100644 --- a/pkgbuilds/grok-bot/grok-bot.desktop +++ b/pkgbuilds/grok-bot/grok-bot.desktop @@ -8,6 +8,6 @@ Terminal=false Type=Application Categories=Development; MimeType=x-scheme-handler/grokbot;x-scheme-handler/sand; -StartupWMClass=Grok Bot +StartupWMClass=grok-bot StartupNotify=true Keywords=Grok;AI;Agent; diff --git a/pkgbuilds/grok-bot/grok-bot.install b/pkgbuilds/grok-bot/grok-bot.install new file mode 100644 index 0000000..11a7683 --- /dev/null +++ b/pkgbuilds/grok-bot/grok-bot.install @@ -0,0 +1,41 @@ +# Electron's renderer sandbox needs unprivileged user namespaces, or else a +# setuid-root chrome-sandbox. Upstream omarchy-pkgs probes for user namespaces +# inside package() and sets 4755 when they are missing. That is wrong twice +# for this repo: the build runs in a CI container where the probe fails, so +# every user would get the setuid helper; and the helper lives under +# "/opt/Grok Bot/", and Electron cannot exec a setuid chrome-sandbox from a +# path with a space (electron/electron#44414), so 4755 would not even work. +# +# The package therefore always ships chrome-sandbox as 0755. This hook only +# tells the user what to do on a host that lacks unprivileged user namespaces. +# The probe drops to nobody first: pacman runs hooks as root, and root can +# unshare a user namespace even where unprivileged users cannot. +_userns_available() { + [[ -L /proc/self/ns/user ]] || return 1 + if (( EUID == 0 )) && command -v setpriv >/dev/null; then + setpriv --reuid=65534 --regid=65534 --clear-groups -- unshare --user true 2>/dev/null + else + # Already unprivileged (or no setpriv): the direct probe is the real answer. + unshare --user true 2>/dev/null + fi +} + +_advise() { + _userns_available && return 0 + cat <<'MSG' +==> Unprivileged user namespaces are unavailable on this kernel, so Grok Bot's + renderer sandbox cannot start. A setuid chrome-sandbox is not an option + here: Electron cannot exec it from "/opt/Grok Bot/" (electron#44414). + To run without the sandbox, add this line to ~/.config/grok-bot-flags.conf: + + --no-sandbox +MSG +} + +post_install() { + _advise +} + +post_upgrade() { + _advise +}