From 75669dcc4f060733f0fcf3b6de574b8f4630d4a1 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Thu, 3 Sep 2026 11:25:45 +0200 Subject: chore(client): build against the latest Electron, and stop defining the package twice MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Chromium CVEs are fixed in Electron releases, and a client built against an old one ships those holes to every user. That is a certain harm; a build that breaks on a new Electron is a repairable one. build-client.sh now bumps to the latest on every build, prints the comparison, and lets the build fail if it cannot cope — the failure is the signal to fix, not a reason to stay behind. It writes package.json and the lockfile on purpose: the new pin is meant to be committed. A registry it cannot reach is a warning, not a failure. Exercised by pinning back to 42.9.2 and building: "==> Electron 42.9.2 -> 44.1.1", exit 0, electron=44.1.1 in the packaged output. Note npm audit would have said nothing about any of this — Chromium CVEs fixed in Electron do not reliably reach the npm advisory database. Separately, package.json declared linux.target [deb, rpm] with its own deb/rpm depends, so `npm run dist` built a second package under the same name. The two had drifted: /opt/MeshBay/meshbay-client against /opt/meshbay-client/meshbay, and Depends: python3-meshbay-common naming none of the Electron runtime libraries the real DEBIAN/control lists — it would have installed cleanly and then refused to start. Nothing in the tree referenced `npm run dist`, which is why the drift was free to happen. That config is gone, "dist" delegates to build-client.sh, and test_desktop_shell.py refuses its return. `--dir` was re-run with no linux block at all: exit 0, same binary build-client.sh consumes. It needs appId, productName and files, nothing else. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01AbwJDbNTkiRUh7HTWEoyss --- packaging/build/build-client.sh | 43 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 43 insertions(+) (limited to 'packaging/build') diff --git a/packaging/build/build-client.sh b/packaging/build/build-client.sh index d42000a..7bac10c 100755 --- a/packaging/build/build-client.sh +++ b/packaging/build/build-client.sh @@ -46,6 +46,49 @@ mkdir -p "$ROOT" # --- Build the Electron app ----------------------------------------------- cd "$CLIENT" +# --- Electron: always build against the latest release -------------------- +# +# Chromium CVEs are fixed in Electron releases, and a client built against an +# old one ships those holes to every user. That is a certain harm; a build that +# breaks on a new Electron is a repairable one. So this bumps to the latest on +# every build and lets the build fail if it cannot cope — the failure is the +# signal to fix, not a reason to stay behind. +# +# It writes package.json and package-lock.json, so the build leaves the repo +# dirty on purpose: the new pin is meant to be committed. `npm audit` will not +# tell you any of this — Chromium CVEs fixed in Electron do not reliably reach +# the npm advisory database, which is why this check exists at all. +echo " checking for a newer Electron" +PINNED=$(node -p "require('./package-lock.json').packages['node_modules/electron'].version" 2>/dev/null || echo "unknown") +LATEST=$(npm view electron version 2>/dev/null || echo "") + +if [ -z "$LATEST" ]; then + echo " !! could not reach the npm registry — building against the pinned Electron $PINNED" >&2 +elif [ "$LATEST" = "$PINNED" ]; then + echo " Electron $PINNED is the latest" +else + echo "" + echo " ==> Electron $PINNED -> $LATEST" + echo "" + npm install --save-dev --ignore-scripts "electron@$LATEST" 2>&1 | tail -2 + # allowScripts pins an exact version; leave it matching so npm does not + # start refusing a script a future Electron reintroduces. + node -e " + const fs = require('node:fs'); + const p = JSON.parse(fs.readFileSync('package.json', 'utf8')); + if (p.allowScripts) { + for (const k of Object.keys(p.allowScripts)) { + if (k.startsWith('electron@')) { + delete p.allowScripts[k]; + p.allowScripts['electron@$LATEST'] = true; + } + } + fs.writeFileSync('package.json', JSON.stringify(p, null, 2) + '\n'); + } + " + echo " package.json and package-lock.json updated — commit them" +fi + echo " npm ci" npm ci --ignore-scripts 2>&1 | tail -3 -- cgit v1.2.3