Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 35 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -505,6 +505,41 @@ jobs:
- name: Build .deb + .AppImage
run: cargo packager --release -f deb -f appimage

# cargo-packager ships AppRun as 0744, and the AppImage stores every
# file as root-owned, so for anyone but root AppRun is read-only. The
# AppImage runtime's FUSE mount tolerates that; a kernel squashfs mount
# doesn't — firejail (the AppImage catalog's test harness) refuses to
# start it ("AppRun: Permission denied"). Re-pack with AppRun 0755, and
# fail the build if any executable is left owner-only. appimagetool
# only publishes a `continuous` tag, so there's no version to pin; with
# neither -u nor -g it embeds no update information.
- name: Make AppRun executable for every user
run: |
set -e
APPIMAGE=$(find "target/release" -maxdepth 1 -name '*.AppImage' | head -1)
if [ -z "$APPIMAGE" ]; then
echo "::error::no .AppImage produced by cargo-packager"
exit 1
fi
ARCH="${{ matrix.rpm_arch }}"

curl -fsSL -o appimagetool \
"https://github.com/AppImage/appimagetool/releases/download/continuous/appimagetool-${ARCH}.AppImage"
chmod +x appimagetool
TOOL="$PWD/appimagetool"

cd "$(dirname "$APPIMAGE")"
NAME=$(basename "$APPIMAGE")
rm -rf squashfs-root
"./$NAME" --appimage-extract >/dev/null
chmod 0755 squashfs-root/AppRun
if find squashfs-root -type f -perm -u=x ! -perm -o=x | grep .; then
echo "::error::executables above aren't runnable by other users"
exit 1
fi
ARCH="$ARCH" "$TOOL" squashfs-root "$NAME"
rm -rf squashfs-root

# cargo-packager 0.11 doesn't expose .deb postinst hooks, so
# we patch the freshly-built .deb to inject one that reloads
# udev rules + retriggers attached tty/usb devices. Matches
Expand Down
22 changes: 11 additions & 11 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading