Files
omarchy-pkgs/pkgbuilds/t3code-bin/.omarchy/upstream.sh
T
OmabotandCodex XHigh 7ee0003106 Keep the sandbox up on hardened kernels, and stop deleting what we have not read
Three fixes from a review of the previous commit.

Chromium's sandbox helper ships setuid, the way Arch's own electron and chromium packages ship theirs. Dropping --no-sandbox was right, but it left the app relying on unprivileged user namespaces alone: on linux-hardened, or anywhere else they are denied, Electron falls back to the helper and aborts because it is not root-owned 4755.

The AppImage's usr/ tree is now read before it is removed. Deleting it wholesale is correct for what upstream ships today, and the version bumps arrive unattended, so a release that starts putting something needed in there would have had it dropped on the way past without anyone seeing it. Anything that is not a known icon or a known compatibility library stops the build instead.

The upstream hook checks that the feed still names the asset the PKGBUILD builds. It hashes whatever the feed points at, so a rename — or an arm64 build reaching the Linux feed first — would have pinned that file's checksum to a URL nobody fetches, and the failure would have surfaced a build later as a checksum mismatch.

🤖 Generated by Opus 5 in Claude Code. Reviewed by Codex XHigh.

Co-Authored-By: Codex XHigh <codex@openai.com>
2026-08-19 02:56:22 -07:00

39 lines
1.5 KiB
Bash
Executable File

#!/bin/bash
# T3 Code publishes electron-builder's update feed beside every release, so the
# newest version costs one small request. The feed's checksum is a base64
# SHA-512 and makepkg wants hex SHA-256, so a release that is actually new still
# has to be downloaded once to hash -- hence the version check before the fetch.
set -euo pipefail
FEED_URL="https://github.com/pingdotgg/t3code/releases/latest/download/latest-linux.yml"
RELEASE_URL="https://github.com/pingdotgg/t3code/releases/download"
feed=$(curl -fsSL "$FEED_URL")
version=$(awk '/^version:/ { print $2; exit }' <<<"$feed" | tr -d '"'\''')
asset=$(awk '/^path:/ { print $2; exit }' <<<"$feed" | tr -d '"'\''')
if [[ -z "$version" || -z "$asset" ]]; then
echo "Upstream feed carried no version or asset name" >&2
exit 1
fi
current=$(awk -F= '/^pkgver=/ { print $2; exit }' PKGBUILD)
if [[ -n "$current" ]] && [[ "$(vercmp "$version" "$current")" -le 0 ]]; then
echo '{}'
exit 0
fi
# The PKGBUILD builds one fixed asset name, so a feed naming anything else --
# a rename, or an arm64 build reaching the Linux feed first -- has to stop the
# sync rather than pin that file's checksum to a URL nobody will fetch.
expected="T3-Code-${version}-x86_64.AppImage"
if [[ "$asset" != "$expected" ]]; then
echo "Upstream feed names $asset, but the PKGBUILD builds $expected" >&2
exit 1
fi
sha256=$(curl -fsSL "$RELEASE_URL/v${version}/${asset}" | sha256sum | cut -d' ' -f1)
jq -n --arg pkgver "$version" --arg sha256 "$sha256" \
'{pkgver: $pkgver, sha256sums: {x86_64: [$sha256]}}'