Three fixes from a review of the previous commit. Chromium's sandbox helper ships setuid, the way Arch's own electron and chromium packages ship theirs. Dropping --no-sandbox was right, but it left the app relying on unprivileged user namespaces alone: on linux-hardened, or anywhere else they are denied, Electron falls back to the helper and aborts because it is not root-owned 4755. The AppImage's usr/ tree is now read before it is removed. Deleting it wholesale is correct for what upstream ships today, and the version bumps arrive unattended, so a release that starts putting something needed in there would have had it dropped on the way past without anyone seeing it. Anything that is not a known icon or a known compatibility library stops the build instead. The upstream hook checks that the feed still names the asset the PKGBUILD builds. It hashes whatever the feed points at, so a rename — or an arm64 build reaching the Linux feed first — would have pinned that file's checksum to a URL nobody fetches, and the failure would have surfaced a build later as a checksum mismatch. 🤖 Generated by Opus 5 in Claude Code. Reviewed by Codex XHigh. Co-Authored-By: Codex XHigh <codex@openai.com>
39 lines
1.5 KiB
Bash
Executable File
39 lines
1.5 KiB
Bash
Executable File
#!/bin/bash
|
|
# T3 Code publishes electron-builder's update feed beside every release, so the
|
|
# newest version costs one small request. The feed's checksum is a base64
|
|
# SHA-512 and makepkg wants hex SHA-256, so a release that is actually new still
|
|
# has to be downloaded once to hash -- hence the version check before the fetch.
|
|
set -euo pipefail
|
|
|
|
FEED_URL="https://github.com/pingdotgg/t3code/releases/latest/download/latest-linux.yml"
|
|
RELEASE_URL="https://github.com/pingdotgg/t3code/releases/download"
|
|
|
|
feed=$(curl -fsSL "$FEED_URL")
|
|
version=$(awk '/^version:/ { print $2; exit }' <<<"$feed" | tr -d '"'\''')
|
|
asset=$(awk '/^path:/ { print $2; exit }' <<<"$feed" | tr -d '"'\''')
|
|
|
|
if [[ -z "$version" || -z "$asset" ]]; then
|
|
echo "Upstream feed carried no version or asset name" >&2
|
|
exit 1
|
|
fi
|
|
|
|
current=$(awk -F= '/^pkgver=/ { print $2; exit }' PKGBUILD)
|
|
if [[ -n "$current" ]] && [[ "$(vercmp "$version" "$current")" -le 0 ]]; then
|
|
echo '{}'
|
|
exit 0
|
|
fi
|
|
|
|
# The PKGBUILD builds one fixed asset name, so a feed naming anything else --
|
|
# a rename, or an arm64 build reaching the Linux feed first -- has to stop the
|
|
# sync rather than pin that file's checksum to a URL nobody will fetch.
|
|
expected="T3-Code-${version}-x86_64.AppImage"
|
|
if [[ "$asset" != "$expected" ]]; then
|
|
echo "Upstream feed names $asset, but the PKGBUILD builds $expected" >&2
|
|
exit 1
|
|
fi
|
|
|
|
sha256=$(curl -fsSL "$RELEASE_URL/v${version}/${asset}" | sha256sum | cut -d' ' -f1)
|
|
|
|
jq -n --arg pkgver "$version" --arg sha256 "$sha256" \
|
|
'{pkgver: $pkgver, sha256sums: {x86_64: [$sha256]}}'
|