3 Commits

Author SHA1 Message Date
s1d3sw1ped_bot 4b2bc70766 PKGBUILD: Point desktop Exec at update shim
Build Arch package / build (push) Successful in 27s
0.30 shipped Exec="/opt/Grok Bot/grok-bot", so the app menu skipped
/usr/bin/grok-bot and never auto-updated. Always rewrite the desktop
Exec to the PATH shim after unpacking the .deb so that cannot regress.
Bump pkgrel to 2; clearer sudo failure hint in the launch shim.
2026-09-02 15:21:20 +00:00
s1d3sw1ped_bot 7fea71c3ec pkgbuild: Fix sha256sums array after 0.35.0 bump
Build Arch package / build (push) Successful in 27s
update.sh replaced only the first sha256sums line and left orphan
hashes, so makepkg could not source PKGBUILD. Rewrite both deb and
launch-shim sums; reset pkgrel to 1 for the first 0.35.0 package.
2026-09-02 14:54:27 +00:00
s1d3sw1ped_bot c8fdd67e83 pkgbuild: Bump grok-bot-bin to 0.35.0 2026-09-02 06:17:46 +00:00
5 changed files with 60 additions and 19 deletions
+5 -5
View File
@@ -1,6 +1,6 @@
pkgbase = grok-bot-bin
pkgdesc = Grok Bot desktop agent (official .deb repackaged)
pkgver = 0.30.0
pkgver = 0.35.0
pkgrel = 2
url = https://cursor.com/download/bot
arch = x86_64
@@ -26,10 +26,10 @@ pkgbase = grok-bot-bin
replaces = sand
options = !strip
options = !debug
source = https://downloads.cursor.com/grokbot/stable/2385d097738b3719cc5ecd9281a107aa106215f1/linux/x64/grok-bot_0.30.0_amd64.deb
source = https://downloads.cursor.com/grokbot/stable/1c5a6ceb364c4dd53f0069f72cc4239220ed471e/linux/x64/grok-bot_0.35.0_amd64.deb
source = grok-bot-launch.sh
noextract = grok-bot_0.30.0_amd64.deb
sha256sums = fb888b2204c8a51c71a9f5f9a2913ac10561f3ef6939c1245ecae4e837d4ada2
sha256sums = 886c8b55eb44d2f7812be50dcc1571907dc2d7e755171e67e916f497634f09eb
noextract = grok-bot_0.35.0_amd64.deb
sha256sums = ed254e819d0f0419a1df9771009363074f65f80d8175d2ee0fc62900087ebd99
sha256sums = 1c5a3599db15816caa839fc9e088ba9798757e44fec89c066ef5f6f3c0972aee
pkgname = grok-bot-bin
+12 -4
View File
@@ -8,8 +8,8 @@
# https://downloads.cursor.com/grokbot/stable/<commit>/linux/x64/grok-bot_<pkgver>_amd64.deb
pkgname=grok-bot-bin
pkgver=0.30.0
_commit=2385d097738b3719cc5ecd9281a107aa106215f1
pkgver=0.35.0
_commit=1c5a6ceb364c4dd53f0069f72cc4239220ed471e
pkgrel=2
pkgdesc="Grok Bot desktop agent (official .deb repackaged)"
arch=('x86_64')
@@ -43,8 +43,8 @@ source=(
)
noextract=("grok-bot_${pkgver}_amd64.deb")
sha256sums=(
'fb888b2204c8a51c71a9f5f9a2913ac10561f3ef6939c1245ecae4e837d4ada2'
'886c8b55eb44d2f7812be50dcc1571907dc2d7e755171e67e916f497634f09eb'
'ed254e819d0f0419a1df9771009363074f65f80d8175d2ee0fc62900087ebd99'
'1c5a3599db15816caa839fc9e088ba9798757e44fec89c066ef5f6f3c0972aee'
)
package() {
@@ -56,6 +56,14 @@ package() {
# Keep provides(sand) on PATH; both names run the same shim.
ln -sf grok-bot "$pkgdir/usr/bin/sand"
# Always point the menu entry at the PATH shim. Upstream .desktop has used
# Exec="/opt/Grok Bot/grok-bot" (0.30) which bypasses auto-update; rewrite
# every build so a future /opt regression cannot ship again.
if [[ -f "$pkgdir/usr/share/applications/grok-bot.desktop" ]]; then
sed -i 's|^Exec=.*|Exec=grok-bot %U|' \
"$pkgdir/usr/share/applications/grok-bot.desktop"
fi
# Path contains a space, so Chromium cannot use the SUID sandbox.
# Arch/CachyOS kernels have user namespaces; keep chrome-sandbox non-setuid.
if [[ -f "$pkgdir/opt/Grok Bot/chrome-sandbox" ]]; then
+1
View File
@@ -58,5 +58,6 @@ Scheduled Gitea Actions will do the same and build a release package.
## Notes
- `/usr/bin/grok-bot` (and `sand`) is a launch shim: unless `GROK_BOT_NO_UPDATE=1`, it checks the latest Gitea release and may `pacman -U` a newer `.pkg.tar.zst` before exec'ing `/opt/Grok Bot/…`. Network/API failures still launch the installed binary.
- If the app menu still launches an old binary without updating, run `/usr/bin/grok-bot` once from a terminal, or `sudo pacman -U` the newer `.pkg.tar.zst` from Releases — the menu must call the PATH shim, not `/opt/Grok Bot/…`.
- Upstream Linux builds still have no in-app updater for the Electron app itself; `scripts/update.sh` bumps the PKGBUILD from Cursor's feed when packaging a new upstream version.
- `chrome-sandbox` is left non-setuid because the install path contains a space; user namespaces cover sandboxing on CachyOS.
+1
View File
@@ -53,6 +53,7 @@ _maybe_update() {
# Prefer passwordless sudo; fall back to interactive sudo. Fail soft either way.
if ! sudo -n pacman -U --noconfirm "$pkg" 2>/dev/null; then
if ! sudo pacman -U --noconfirm "$pkg"; then
echo "grok-bot: need sudo to auto-update; run: sudo pacman -U <pkg> or launch /usr/bin/grok-bot from a terminal" >&2
echo "grok-bot: pacman -U failed; launching installed version" >&2
return 0
fi
+41 -10
View File
@@ -23,20 +23,51 @@ deb_url="https://downloads.cursor.com/grokbot/stable/${commit}/linux/x64/grok-bo
tmp=$(mktemp)
trap 'rm -f "$tmp"' EXIT
curl -fsSL --retry 3 "$deb_url" -o "$tmp"
sha=$(sha256sum "$tmp" | cut -d' ' -f1)
deb_sha=$(sha256sum "$tmp" | cut -d' ' -f1)
shim_sha=$(sha256sum grok-bot-launch.sh | cut -d' ' -f1)
# Reset pkgrel on upstream version bumps.
sed -i \
-e "s/^pkgver=.*/pkgver=${version}/" \
-e "s/^_commit=.*/_commit=${commit}/" \
-e "s/^sha256sums=.*/sha256sums=('${sha}')/" \
-e "s/^pkgrel=.*/pkgrel=1/" \
PKGBUILD
# Refresh .SRCINFO source URL + hashes without requiring makepkg.
sed -i \
-e "s/^\\tpkgver = .*/\\tpkgver = ${version}/" \
-e "s#^\\tsource = https://downloads.cursor.com/grokbot/stable/.*/linux/x64/grok-bot_.*_amd64.deb#\\tsource = https://downloads.cursor.com/grokbot/stable/${commit}/linux/x64/grok-bot_${version}_amd64.deb#" \
-e "s/^\\tnoextract = grok-bot_.*_amd64.deb/\\tnoextract = grok-bot_${version}_amd64.deb/" \
-e "s/^\\tsha256sums = .*/\\tsha256sums = ${sha}/" \
.SRCINFO
python3 - "$deb_sha" "$shim_sha" <<'PY'
import pathlib, re, sys
deb_sha, shim_sha = sys.argv[1], sys.argv[2]
p = pathlib.Path("PKGBUILD")
text = p.read_text()
block = f"sha256sums=(\n '{deb_sha}'\n '{shim_sha}'\n)"
text2, n = re.subn(r"sha256sums=\([^\)]*\)", block, text, count=1, flags=re.S)
if n != 1:
raise SystemExit(f"sha256sums replace failed (n={n})")
p.write_text(text2)
PY
echo "Updated PKGBUILD and .SRCINFO to ${version} sha256=${sha}"
python3 - "$version" "$commit" "$deb_sha" "$shim_sha" <<'PY'
import pathlib, re, sys
version, commit, deb_sha, shim_sha = sys.argv[1:5]
p = pathlib.Path(".SRCINFO")
lines = []
saw_sha = False
for line in p.read_text().splitlines(True):
if line.startswith("\tpkgver ="):
lines.append(f"\tpkgver = {version}\n"); continue
if line.startswith("\tpkgrel ="):
lines.append("\tpkgrel = 1\n"); continue
if line.startswith("\tsource = https://downloads.cursor.com/grokbot/stable/"):
lines.append(f"\tsource = https://downloads.cursor.com/grokbot/stable/{commit}/linux/x64/grok-bot_{version}_amd64.deb\n"); continue
if line.startswith("\tnoextract = grok-bot_"):
lines.append(f"\tnoextract = grok-bot_{version}_amd64.deb\n"); continue
if line.startswith("\tsha256sums ="):
if not saw_sha:
lines.append(f"\tsha256sums = {deb_sha}\n")
lines.append(f"\tsha256sums = {shim_sha}\n")
saw_sha = True
continue
lines.append(line)
p.write_text("".join(lines))
PY
echo "Updated PKGBUILD and .SRCINFO to ${version} deb_sha=${deb_sha} shim_sha=${shim_sha}"