diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 4d11351..8c8ab46 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -505,6 +505,41 @@ jobs: - name: Build .deb + .AppImage run: cargo packager --release -f deb -f appimage + # cargo-packager ships AppRun as 0744, and the AppImage stores every + # file as root-owned, so for anyone but root AppRun is read-only. The + # AppImage runtime's FUSE mount tolerates that; a kernel squashfs mount + # doesn't — firejail (the AppImage catalog's test harness) refuses to + # start it ("AppRun: Permission denied"). Re-pack with AppRun 0755, and + # fail the build if any executable is left owner-only. appimagetool + # only publishes a `continuous` tag, so there's no version to pin; with + # neither -u nor -g it embeds no update information. + - name: Make AppRun executable for every user + run: | + set -e + APPIMAGE=$(find "target/release" -maxdepth 1 -name '*.AppImage' | head -1) + if [ -z "$APPIMAGE" ]; then + echo "::error::no .AppImage produced by cargo-packager" + exit 1 + fi + ARCH="${{ matrix.rpm_arch }}" + + curl -fsSL -o appimagetool \ + "https://github.com/AppImage/appimagetool/releases/download/continuous/appimagetool-${ARCH}.AppImage" + chmod +x appimagetool + TOOL="$PWD/appimagetool" + + cd "$(dirname "$APPIMAGE")" + NAME=$(basename "$APPIMAGE") + rm -rf squashfs-root + "./$NAME" --appimage-extract >/dev/null + chmod 0755 squashfs-root/AppRun + if find squashfs-root -type f -perm -u=x ! -perm -o=x | grep .; then + echo "::error::executables above aren't runnable by other users" + exit 1 + fi + ARCH="$ARCH" "$TOOL" squashfs-root "$NAME" + rm -rf squashfs-root + # cargo-packager 0.11 doesn't expose .deb postinst hooks, so # we patch the freshly-built .deb to inject one that reloads # udev rules + retriggers attached tty/usb devices. Matches diff --git a/Cargo.lock b/Cargo.lock index bbda9bc..77d969f 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1757,7 +1757,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "39cab71617ae0d63f51a36d69f866391735b51691dbda63cf6f96d042b63efeb" dependencies = [ "libc", - "windows-sys 0.52.0", + "windows-sys 0.59.0", ] [[package]] @@ -5214,7 +5214,7 @@ dependencies = [ "once_cell", "socket2", "tracing", - "windows-sys 0.52.0", + "windows-sys 0.59.0", ] [[package]] @@ -5737,7 +5737,7 @@ dependencies = [ "errno", "libc", "linux-raw-sys 0.4.15", - "windows-sys 0.52.0", + "windows-sys 0.59.0", ] [[package]] @@ -5750,7 +5750,7 @@ dependencies = [ "errno", "libc", "linux-raw-sys 0.12.1", - "windows-sys 0.52.0", + "windows-sys 0.59.0", ] [[package]] @@ -5766,9 +5766,9 @@ dependencies = [ [[package]] name = "rustls" -version = "0.23.40" +version = "0.23.45" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "ef86cd5876211988985292b91c96a8f2d298df24e75989a43a3c73f2d4d8168b" +checksum = "0d41d731c7d2f962d1ccc364cec258de3c0e93b38c2fb3ba97ac74513048d634" dependencies = [ "log", "once_cell", @@ -5812,9 +5812,9 @@ dependencies = [ [[package]] name = "rustls-webpki" -version = "0.103.13" +version = "0.103.15" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "61c429a8649f110dddef65e2a5ad240f747e85f7758a6bccc7e5777bd33f756e" +checksum = "f3c3cf1d8b1e7d4927e2d154c3fcb02979afb9939629c62cd9048d4f07b60ac2" dependencies = [ "ring", "rustls-pki-types", @@ -6697,10 +6697,10 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "32497e9a4c7b38532efcdebeef879707aa9f794296a4f0244f6f69e9bc8574bd" dependencies = [ "fastrand", - "getrandom 0.3.4", + "getrandom 0.4.2", "once_cell", "rustix 1.1.4", - "windows-sys 0.52.0", + "windows-sys 0.59.0", ] [[package]] @@ -7985,7 +7985,7 @@ version = "0.1.11" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "c2a7b1c03c876122aa43f3020e6c3c3ee5c05081c9a00739faf7503aeba10d22" dependencies = [ - "windows-sys 0.52.0", + "windows-sys 0.59.0", ] [[package]]