Skip to content

fix(build): make the Linux packages usable on Ubuntu 22.04 - #725

Merged
manusa merged 5 commits into
mainfrom
issue-721
Sep 22, 2026
Merged

manusa merged 5 commits into
mainfrom
issue-721

Conversation

@manusa

@manusa manusa commented Sep 20, 2026 •

Copy link
Copy Markdown
Owner

Prepares the AppImage for submission to the AppImage catalog
(#721) and fixes what checking it against their checklist turned up.

The spell checker doesn't load on Ubuntu 22.04

nodehun is compiled on the machine that builds the packages, so it links against its
glibc and libstdc++. The Linux release builds on ubuntu-latest, now 24.04, so the
0.0.123 AppImage and tar.gz need GLIBC_2.38 and GLIBCXX_3.4.32, which Ubuntu 22.04
(glibc 2.35, GLIBCXX_3.4.30) does not have. The application still starts, and only
spell checking is gone, because the failure is handled.

  • Both the release job and the Linux Build job now run in a container: ubuntu:22.04.
  • The snap moved to its own job, as snapcraft does not run in docker. publish-snap.yml
    already built it separately.
  • utils/check-glibc.sh fails the build when a native binary in the AppImage needs more
    than Ubuntu 22.04 provides, so this cannot regress unnoticed.

AppStream metainfo

build-config/com.marcnuri.electronim.appdata.xml is installed in usr/share/metainfo,
and build-config/electronim.package.desktop in usr/share/applications alongside it,
because appstreamcli validate-tree (which the catalog's appdir-lint.sh runs) looks
for the launchable there while electron-builder only writes its desktop file to the root
of the AppImage. That entry is a new one with a relative Exec=electronim %U and
Icon=electronim, not the RPM's /opt/electronim one, because the tar.gz ships a
usr/share tree a user can install. Tests keep it in sync with build.linux. The
metainfo keeps the legacy *.appdata.xml name because the catalog only reads listing
data from files named that way. Its description says that ElectronIM is free/libre
software: software centers show the licence name, but nothing else tells users that.

It ships without <screenshots> for now, and that is why this PR does not unblock
the catalog submission on its own: in the catalog's worker.sh the appdata branch wins
over the auto-screenshot branch, so a metainfo file without screenshots means the listing
shows no image at all. #721 tracks adding one, pinned to a commit, before the catalog PR.

Smaller things found while reviewing the above

  • utils/version-from-tag.js stamps the AppStream <releases> at tag time, so software
    centers show a version and a date. The version is only known then.
  • The RPM installs the metainfo in %{_metainfodir}, where Fedora's software center
    scans for it, and no longer carries the stray copies under /opt/electronim/usr. It
    still builds older tags, which Copr builds with the spec on main and which have no
    metainfo: %files takes it from a list %install only writes when the file exists.
  • The release workflow declares permissions: contents: write, which is all the uploads
    need, hands GITHUB_TOKEN to the upload steps only rather than to npm install and the
    install scripts it runs, and checks out without persisting git credentials. Nothing in
    those jobs pushes.
  • One sentence now describes the application in the metainfo, package.json, the snap
    summary, the linux synopsis, the RPM Summary: and the Comment of both desktop
    entries, instead of four different ones.
  • squashfs-root is ignored by git and excluded from build.files, so extracting an
    AppImage in the working tree can't end up inside the next app.asar.
  • docs/Setup.md ran tar xz without -f.

Verification

Built in an ubuntu:22.04 container, the same way the new jobs do, and checked the
resulting AppImage on Ubuntu 22.04:

  • utils/check-glibc.sh: every native binary loads with the versions Ubuntu 22.04
    provides. The same check on the released 0.0.123 AppImage fails and names
    Nodehun.node. It reads only the version needs section, so bundling a library that
    defines newer versions is not mistaken for needing them; it also rejects the
    GLIBC_ABI_DT_RELR requirement that Ubuntu 24.04's default link flags add, and fails
    when a path cannot be listed rather than reporting an empty scan as success.
  • The catalog's appdir-lint.sh: Lint found no fatal issues, and
    desktop-file-validate passes.
  • appstreamcli validate: clean on AppStream 0.15.2 (22.04) and 1.0.2 (24.04).
  • Started offline (--network=none) under Xvfb on 22.04: the settings dialog opens on
    first launch and nothing logs a GLIBC error, where the released AppImage logs
    version `GLIBC_2.38' not found.
  • npm run pretest and npm test (62 suites, 1199 tests) pass.

The snap has the same problem and is worse, since core20 provides only GLIBCXX_3.4.28.
That is tracked separately in #724, to be done on a Linux machine.

Refs #721

nodehun is compiled on the machine that builds the packages and links
against its glibc and libstdc++. The release builds on ubuntu-latest,
now 24.04, so the AppImage and tar.gz of 0.0.123 ship a Nodehun.node
that needs GLIBC_2.38 and GLIBCXX_3.4.32. The spell checker doesn't
load on Ubuntu 22.04, the oldest supported LTS, and the one the
AppImage catalog tests on.

Build the Linux artifacts in an ubuntu:22.04 container, move the snap
to its own job because snapcraft doesn't run in docker, and fail the
build with utils/check-glibc.sh when a native binary needs more than
Ubuntu 22.04 provides.

Ship an AppStream metainfo file too, which the AppImage catalog reads
for the listing. It is installed along the desktop file it launches,
so that appstreamcli validate-tree and the catalog's appdir-lint.sh
both pass.

Refs #721

Signed-off-by: Marc Nuri <marc@marcnuri.com>
A review of #725 found the check passing when it shouldn't. It read
the versions a library defines as versions it needs, missed the
GLIBC_ABI_DT_RELR requirement that Ubuntu 24.04 links in by default,
and reported success when find could not list a path. It now reads
only the version needs section, checks GLIBC, GLIBCXX, CXXABI and GCC
against what Ubuntu 22.04 provides, and takes several paths, so the
release job can check dist and the AppImage runtime without running
the artifact it is about to upload.

The desktop entry installed next to the metainfo is a new one with a
relative Exec and Icon. The RPM entry it reused points into
/opt/electronim, which exists in neither the AppImage nor the tar.gz,
and AppRun puts that directory first in XDG_DATA_DIRS.

Also stamp the AppStream release at tag time, install the metainfo
where Fedora scans for it, limit the release workflow to the
permissions it needs, and describe the application with one sentence
across every package.

Refs #721

Signed-off-by: Marc Nuri <marc@marcnuri.com>
The release job exported GITHUB_TOKEN to every step, so the install
scripts of every npm package ran with a token that can publish
releases. Only the upload steps get it now.

Also assert the spell checker is packed in the release job too, tie
the Ubuntu release check-glibc.sh measures against to the containers
both workflows build in, and stop readelf from flooding the log with
a warning per missing split-debug file of libvulkan.so.1.

Refs #721

Signed-off-by: Marc Nuri <marc@marcnuri.com>
publish-copr.yml builds older tags with the spec on main, and those
tags have no metainfo. %install already skipped installing it, but
%files listed it unconditionally, so rpmbuild failed with "File not
found". %files now reads the metainfo from a list that %install only
writes when the file exists.

Refs #721

Signed-off-by: Marc Nuri <marc@marcnuri.com>
Software centers show the licence name, but nothing tells users the
application is free/libre software, which is what most of them care
about.

Refs #721

Signed-off-by: Marc Nuri <marc@marcnuri.com>
@sonarqubecloud

Copy link
Copy Markdown

@manusa
manusa merged commit 83f7ff8 into main Sep 22, 2026
7 checks passed
@manusa
manusa deleted the issue-721 branch September 22, 2026 03:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant