Review caught that the allowlist only listed files and symlinks, so a
future deb shipping an empty top-level bin/, sbin/ or lib64/ -- each a
filesystem-owned symlink here, the exact conflict class this guard
exists to close -- would pass it, as would FIFOs and device nodes.
Delete the one known unit, rmdir its emptied parents, and treat any
remaining entry outside opt/ and usr/ as unexpected, whatever its type.
This also stops silently rm -rf'ing future /lib content: anything new
there now fails the build for a human to look at instead.
Verified: clean build ships only etc/, opt/ and usr/; an injected empty
bin/, a stray lib64/ file, and a FIFO each abort package() with the
entry listed. Built via bin/build; installs clean in a fresh container.
26.9.1 added /lib/systemd/system/perplexity-local-runtime-setup.service
to the deb, and wholesale extraction made the package own /lib -- a
symlink owned by filesystem -- so pacman refused every install and
upgrade. The unit could never work here anyway: its setup script
apt-installs Docker and the NVIDIA Container Toolkit and exits on any
distro but Ubuntu, so the Arch equivalents ride optdepends instead.
package() now allowlists what leaves the deb: opt/, usr/, and that one
known unit path (deleted). Anything else stops the build rather than
shipping the next filesystem conflict.
Verified in a clean container: the published -1 reproduces the /lib
conflict; -2 installs fresh and upgrades from 26.8.4 cleanly.
Tracks Perplexity's own Debian repository, the feed the app updates
itself from, via .omarchy/upstream.sh -- same shape as
openai-codex-desktop. pkgver carries the build number from the pool
filename because the index's Version field drops it and upstream
rebuilds under the same marketing version; the pool wants the '+'
percent-encoded. The launcher replaces the postinst symlink pacman
never creates and defaults Chromium to Wayland.