feat(desktop,server,web): app icons, completion notifications, single-user mode, bundled penguin CLI (#226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,69 @@
|
||||
#!/bin/bash
|
||||
# Deb post-install (electron-builder deb.afterInstall). Overriding the option REPLACES
|
||||
# electron-builder's default template, so this file is that default (app-builder-lib
|
||||
# templates/linux/after-install.tpl, v26.15.3) verbatim, plus the marked PenguinHarness
|
||||
# section exposing the bundled `penguin` CLI launcher on PATH. The dollar-brace forms
|
||||
# are electron-builder template macros (executable, sanitizedProductName); any other
|
||||
# all-letter dollar-brace token fails the build, so shell variables stay brace-less.
|
||||
|
||||
if type update-alternatives >/dev/null 2>&1; then
|
||||
# Remove previous link if it doesn't use update-alternatives
|
||||
if [ -L '/usr/bin/${executable}' -a -e '/usr/bin/${executable}' -a "`readlink '/usr/bin/${executable}'`" != '/etc/alternatives/${executable}' ]; then
|
||||
rm -f '/usr/bin/${executable}'
|
||||
fi
|
||||
update-alternatives --install '/usr/bin/${executable}' '${executable}' '/opt/${sanitizedProductName}/${executable}' 100 || ln -sf '/opt/${sanitizedProductName}/${executable}' '/usr/bin/${executable}'
|
||||
else
|
||||
ln -sf '/opt/${sanitizedProductName}/${executable}' '/usr/bin/${executable}'
|
||||
fi
|
||||
|
||||
# PenguinHarness: expose the bundled penguin CLI launcher on PATH. Never clobber a real
|
||||
# file of that name; replacing a (possibly stale) symlink keeps re-installs idempotent.
|
||||
if [ ! -e '/usr/bin/penguin' ] || [ -L '/usr/bin/penguin' ]; then
|
||||
ln -sf '/opt/${sanitizedProductName}/resources/app/bin/penguin' '/usr/bin/penguin'
|
||||
fi
|
||||
|
||||
# Check if user namespaces are supported by the kernel and working with a quick test:
|
||||
if ! { [[ -L /proc/self/ns/user ]] && unshare --user true; }; then
|
||||
# Use SUID chrome-sandbox only on systems without user namespaces:
|
||||
chmod 4755 '/opt/${sanitizedProductName}/chrome-sandbox' || true
|
||||
else
|
||||
chmod 0755 '/opt/${sanitizedProductName}/chrome-sandbox' || true
|
||||
fi
|
||||
|
||||
if hash update-mime-database 2>/dev/null; then
|
||||
update-mime-database /usr/share/mime || true
|
||||
fi
|
||||
|
||||
if hash update-desktop-database 2>/dev/null; then
|
||||
update-desktop-database /usr/share/applications || true
|
||||
fi
|
||||
|
||||
# Install apparmor profile. (Ubuntu 24+)
|
||||
# First check if the version of AppArmor running on the device supports our profile.
|
||||
# This is in order to keep backwards compatibility with Ubuntu 22.04 which does not support abi/4.0.
|
||||
# In that case, we just skip installing the profile since the app runs fine without it on 22.04.
|
||||
#
|
||||
# Those apparmor_parser flags are akin to performing a dry run of loading a profile.
|
||||
# https://wiki.debian.org/AppArmor/HowToUse#Dumping_profiles
|
||||
#
|
||||
# Unfortunately, at the moment AppArmor doesn't have a good story for backwards compatibility.
|
||||
# https://askubuntu.com/questions/1517272/writing-a-backwards-compatible-apparmor-profile
|
||||
if apparmor_status --enabled > /dev/null 2>&1; then
|
||||
APPARMOR_PROFILE_SOURCE='/opt/${sanitizedProductName}/resources/apparmor-profile'
|
||||
APPARMOR_PROFILE_TARGET='/etc/apparmor.d/${executable}'
|
||||
if apparmor_parser --skip-kernel-load --debug "$APPARMOR_PROFILE_SOURCE" > /dev/null 2>&1; then
|
||||
cp -f "$APPARMOR_PROFILE_SOURCE" "$APPARMOR_PROFILE_TARGET"
|
||||
|
||||
# Updating the current AppArmor profile is not possible and probably not meaningful in a chroot'ed environment.
|
||||
# Use cases are for example environments where images for clients are maintained.
|
||||
# There, AppArmor might correctly be installed, but live updating makes no sense.
|
||||
if ! { [ -x '/usr/bin/ischroot' ] && /usr/bin/ischroot; } && hash apparmor_parser 2>/dev/null; then
|
||||
# Extra flags taken from dh_apparmor:
|
||||
# > By using '-W -T' we ensure that any abstraction updates are also pulled in.
|
||||
# https://wiki.debian.org/AppArmor/Contribute/FirstTimeProfileImport
|
||||
apparmor_parser --replace --write-cache --skip-read-cache "$APPARMOR_PROFILE_TARGET"
|
||||
fi
|
||||
else
|
||||
echo "Skipping the installation of the AppArmor profile as this version of AppArmor does not seem to support the bundled profile"
|
||||
fi
|
||||
fi
|
||||
@@ -0,0 +1,36 @@
|
||||
#!/bin/bash
|
||||
# Deb post-remove (electron-builder deb.afterRemove). Overriding the option REPLACES
|
||||
# electron-builder's default template, so this file is that default (app-builder-lib
|
||||
# templates/linux/after-remove.tpl, v26.15.3) verbatim, plus the marked PenguinHarness
|
||||
# section removing the `penguin` CLI launcher link installed by after-install.tpl.
|
||||
|
||||
# Delete the link to the binary
|
||||
# update-alternatives --remove <name> <path>: 'path' must be the registered alternative binary,
|
||||
# not the generic symlink — see https://man7.org/linux/man-pages/man1/update-alternatives.1.html
|
||||
if type update-alternatives >/dev/null 2>&1; then
|
||||
update-alternatives --remove '${executable}' '/opt/${sanitizedProductName}/${executable}'
|
||||
else
|
||||
rm -f '/usr/bin/${executable}'
|
||||
fi
|
||||
|
||||
# PenguinHarness: remove the penguin CLI launcher link, but only if it is ours.
|
||||
if [ -L '/usr/bin/penguin' ] && [ "`readlink '/usr/bin/penguin'`" = '/opt/${sanitizedProductName}/resources/app/bin/penguin' ]; then
|
||||
rm -f '/usr/bin/penguin'
|
||||
fi
|
||||
|
||||
APPARMOR_PROFILE_DEST='/etc/apparmor.d/${executable}'
|
||||
|
||||
# Remove and unload apparmor profile.
|
||||
if [ -f "$APPARMOR_PROFILE_DEST" ]; then
|
||||
# Unload the profile from the running kernel before deleting the file so the
|
||||
# policy is not left enforced until the next reboot. Mirror the chroot guard
|
||||
# used in the after-install script — live AppArmor operations are not
|
||||
# meaningful inside a chroot.
|
||||
# https://wiki.debian.org/AppArmor/HowToUse
|
||||
if apparmor_status --enabled > /dev/null 2>&1; then
|
||||
if ! { [ -x '/usr/bin/ischroot' ] && /usr/bin/ischroot; } && hash apparmor_parser 2>/dev/null; then
|
||||
apparmor_parser --remove "$APPARMOR_PROFILE_DEST" || true
|
||||
fi
|
||||
fi
|
||||
rm -f "$APPARMOR_PROFILE_DEST"
|
||||
fi
|
||||
Reference in New Issue
Block a user