Files
omarchy-pkgs/pkgbuilds/grok-bot/grok-bot.install
T

42 lines
1.6 KiB
Plaintext

# Electron's renderer sandbox needs unprivileged user namespaces, or else a
# setuid-root chrome-sandbox. Upstream omarchy-pkgs probes for user namespaces
# inside package() and sets 4755 when they are missing. That is wrong twice
# for this repo: the build runs in a CI container where the probe fails, so
# every user would get the setuid helper; and the helper lives under
# "/opt/Grok Bot/", and Electron cannot exec a setuid chrome-sandbox from a
# path with a space (electron/electron#44414), so 4755 would not even work.
#
# The package therefore always ships chrome-sandbox as 0755. This hook only
# tells the user what to do on a host that lacks unprivileged user namespaces.
# The probe drops to nobody first: pacman runs hooks as root, and root can
# unshare a user namespace even where unprivileged users cannot.
_userns_available() {
[[ -L /proc/self/ns/user ]] || return 1
if (( EUID == 0 )) && command -v setpriv >/dev/null; then
setpriv --reuid=65534 --regid=65534 --clear-groups -- unshare --user true 2>/dev/null
else
# Already unprivileged (or no setpriv): the direct probe is the real answer.
unshare --user true 2>/dev/null
fi
}
_advise() {
_userns_available && return 0
cat <<'MSG'
==> Unprivileged user namespaces are unavailable on this kernel, so Grok Bot's
renderer sandbox cannot start. A setuid chrome-sandbox is not an option
here: Electron cannot exec it from "/opt/Grok Bot/" (electron#44414).
To run without the sandbox, add this line to ~/.config/grok-bot-flags.conf:
--no-sandbox
MSG
}
post_install() {
_advise
}
post_upgrade() {
_advise
}