Skip to content

fix(appimage): AppRun runnable by every user, not just root - #18

Merged
packetThrower merged 2 commits into
mainfrom
fix/appimage-apprun-mode
Sep 29, 2026
Merged

packetThrower merged 2 commits into
mainfrom
fix/appimage-apprun-mode

Conversation

@packetThrower

Copy link
Copy Markdown
Owner

Summary

The AppImage's AppRun is -rwxr--r-- (0744), and every file in the image is stored as root-owned. For any user but root it's read-only. The AppImage runtime's FUSE mount tolerates that. A kernel squashfs mount enforces it, and firejail, the AppImage catalog's test harness, uses one. It refuses to start the app with AppRun: Permission denied, the same failure Zorite hit on AppImage/appimage.github.io#7154.

  • Cause: it comes from cargo-packager's AppImage build. The released v0.7.0 x86_64 AppImage has AppRun at 0744. usr/bin/* is correctly 0755.
  • Fix: a new step right after cargo packager extracts the AppImage, sets AppRun to 0755, fails the build if any executable is left owner-only, and re-packs it with appimagetool in place, under the same file name. With neither -u nor -g, appimagetool embeds no update information.

Zorite's equivalent: packetThrower/zorite#112.

Test plan

  • Inspected the released v0.7.0 x86_64 AppImage: AppRun is 0744 and root-owned
  • The guard flags a 0744 AppRun and passes once it's 0755 (tested on a mock AppDir)
  • actionlint clean
  • Next release build: the step passes, and the published AppImage's AppRun is 0755

🤖 Generated with Claude Code

packetThrower and others added 2 commits September 29, 2026 10:02
cargo-packager builds the AppImage with AppRun at 0744, and the image
stores every file as root-owned, so for any other user AppRun is
read-only. The AppImage runtime's FUSE mount tolerates that, but a kernel
squashfs mount enforces it: firejail, which the AppImage catalog tests
with, refuses to start the app ("AppRun: Permission denied") — the same
failure Zorite hit on AppImage/appimage.github.io#7154.

Re-pack after cargo-packager with AppRun 0755 (appimagetool, no update
information embedded), and fail the build if any executable is left
owner-only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Rust 1.98's new chunks_exact_to_as_chunks lint fails clippy -D warnings
on every branch: seven UTF-16 / u16 decoders used chunks_exact(2).
as_chunks::<2>() yields [u8; 2] arrays and drops a trailing odd byte just
as chunks_exact does, so decoding is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@packetThrower
packetThrower merged commit 77f56b6 into main Sep 29, 2026
6 checks passed
@packetThrower
packetThrower deleted the fix/appimage-apprun-mode branch September 29, 2026 17:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant