diff --git a/packages/arch/openhuman-bin/PKGBUILD b/packages/arch/openhuman-bin/PKGBUILD index b2bed31895..79faa29a48 100644 --- a/packages/arch/openhuman-bin/PKGBUILD +++ b/packages/arch/openhuman-bin/PKGBUILD @@ -1,7 +1,8 @@ # Maintainer: OpenHuman +# Contributed-by: Luu Khoa Hoc pkgname=openhuman-bin -pkgver=0.54.0 +pkgver=0.63.7 pkgrel=1 pkgdesc='Personal AI desktop assistant for communities' arch=('x86_64') @@ -15,21 +16,58 @@ optdepends=( provides=('openhuman') conflicts=('openhuman') options=('!strip') +makedepends=('python') source=( "OpenHuman_${pkgver}_amd64.AppImage::https://github.com/tinyhumansai/openhuman/releases/download/v${pkgver}/OpenHuman_${pkgver}_amd64.AppImage" 'openhuman' 'openhuman.desktop' 'openhuman.svg' ) +# AppImage checksum is verified at build time against the upstream-published +# digest (prepare()), so it is intentionally SKIP here. The three local files +# are static and pinned. sha256sums=( - '2f76bc5b6f3a0e6cf2765f414a82b26903337720d190b4f9b26a5d7e2508abab' + 'SKIP' 'dbd46b85be9d551363b44ec19613a5fb5df4a08f5b618cb38ffe8891a0f31eeb' 'e357a666334449273047c02740a3e3fa34c58ff00304af8b3ec1a080a9574e99' '7892979a084a5e2bbc73c32fe0f447918aa9b458c50bf0bb856469c837e6401c' ) +# Auto-resolve the latest stable release tag from GitHub. +pkgver() { + curl -fsSL "https://api.github.com/repos/tinyhumansai/openhuman/releases/latest" \ + | python3 -c "import json,sys; print(json.load(sys.stdin)['tag_name'].lstrip('v'))" +} + prepare() { cd "${srcdir}" + + # Verify the downloaded AppImage against the digest published by upstream + # for this exact version (sha256: in the release asset metadata). + local expected + expected=$(curl -fsSL "https://api.github.com/repos/tinyhumansai/openhuman/releases/tags/v${pkgver}" \ + | python3 -c " +import json, sys, re +d = json.load(sys.stdin) +for a in d.get('assets'): + if re.search(r'amd64\.AppImage$', a.get('name', '')): + print((a.get('digest') or '').replace('sha256:', '')) + break +") + local actual + actual=$(sha256sum "OpenHuman_${pkgver}_amd64.AppImage" | cut -d' ' -f1) + if [ -z "${expected}" ]; then + echo "ERROR: Could not retrieve upstream digest for v${pkgver}." >&2 + echo " Cannot verify AppImage integrity; refusing to install unverified binary." >&2 + exit 1 + fi + if [ "${expected}" != "${actual}" ]; then + echo "ERROR: AppImage sha256 mismatch for v${pkgver}" >&2 + echo " expected: ${expected}" >&2 + echo " actual: ${actual}" >&2 + exit 1 + fi + rm -rf squashfs-root chmod +x "OpenHuman_${pkgver}_amd64.AppImage" "./OpenHuman_${pkgver}_amd64.AppImage" --appimage-extract >/dev/null