fix(appimage): AppRun runnable by every user, not just root - #18
Merged
Merged
Conversation
cargo-packager builds the AppImage with AppRun at 0744, and the image
stores every file as root-owned, so for any other user AppRun is
read-only. The AppImage runtime's FUSE mount tolerates that, but a kernel
squashfs mount enforces it: firejail, which the AppImage catalog tests
with, refuses to start the app ("AppRun: Permission denied") — the same
failure Zorite hit on AppImage/appimage.github.io#7154.
Re-pack after cargo-packager with AppRun 0755 (appimagetool, no update
information embedded), and fail the build if any executable is left
owner-only.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Rust 1.98's new chunks_exact_to_as_chunks lint fails clippy -D warnings on every branch: seven UTF-16 / u16 decoders used chunks_exact(2). as_chunks::<2>() yields [u8; 2] arrays and drops a trailing odd byte just as chunks_exact does, so decoding is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The AppImage's
AppRunis-rwxr--r--(0744), and every file in the image is stored as root-owned. For any user but root it's read-only. The AppImage runtime's FUSE mount tolerates that. A kernel squashfs mount enforces it, and firejail, the AppImage catalog's test harness, uses one. It refuses to start the app withAppRun: Permission denied, the same failure Zorite hit on AppImage/appimage.github.io#7154.AppRunat 0744.usr/bin/*is correctly 0755.cargo packagerextracts the AppImage, setsAppRunto 0755, fails the build if any executable is left owner-only, and re-packs it with appimagetool in place, under the same file name. With neither-unor-g, appimagetool embeds no update information.Zorite's equivalent: packetThrower/zorite#112.
Test plan
AppRunis 0744 and root-ownedAppRunand passes once it's 0755 (tested on a mock AppDir)actionlintcleanAppRunis 0755🤖 Generated with Claude Code