42 lines
1.6 KiB
Plaintext
42 lines
1.6 KiB
Plaintext
# Electron's renderer sandbox needs unprivileged user namespaces, or else a
|
|
# setuid-root chrome-sandbox. Upstream omarchy-pkgs probes for user namespaces
|
|
# inside package() and sets 4755 when they are missing. That is wrong twice
|
|
# for this repo: the build runs in a CI container where the probe fails, so
|
|
# every user would get the setuid helper; and the helper lives under
|
|
# "/opt/Grok Bot/", and Electron cannot exec a setuid chrome-sandbox from a
|
|
# path with a space (electron/electron#44414), so 4755 would not even work.
|
|
#
|
|
# The package therefore always ships chrome-sandbox as 0755. This hook only
|
|
# tells the user what to do on a host that lacks unprivileged user namespaces.
|
|
# The probe drops to nobody first: pacman runs hooks as root, and root can
|
|
# unshare a user namespace even where unprivileged users cannot.
|
|
_userns_available() {
|
|
[[ -L /proc/self/ns/user ]] || return 1
|
|
if (( EUID == 0 )) && command -v setpriv >/dev/null; then
|
|
setpriv --reuid=65534 --regid=65534 --clear-groups -- unshare --user true 2>/dev/null
|
|
else
|
|
# Already unprivileged (or no setpriv): the direct probe is the real answer.
|
|
unshare --user true 2>/dev/null
|
|
fi
|
|
}
|
|
|
|
_advise() {
|
|
_userns_available && return 0
|
|
cat <<'MSG'
|
|
==> Unprivileged user namespaces are unavailable on this kernel, so Grok Bot's
|
|
renderer sandbox cannot start. A setuid chrome-sandbox is not an option
|
|
here: Electron cannot exec it from "/opt/Grok Bot/" (electron#44414).
|
|
To run without the sandbox, add this line to ~/.config/grok-bot-flags.conf:
|
|
|
|
--no-sandbox
|
|
MSG
|
|
}
|
|
|
|
post_install() {
|
|
_advise
|
|
}
|
|
|
|
post_upgrade() {
|
|
_advise
|
|
}
|