mirror of
https://github.com/ever-co/ever-gauzy.git
synced 2026-10-02 10:05:00 +08:00
On arm64 electron-builder has no template snap, so it builds without one:
snapcraft pulls stage-packages and, in host (destructive) mode, runs a bare
`apt-get update`. As the unprivileged runner user that fails:
E: Could not open lock file /var/lib/apt/lists/lock - open (13: Permission denied)
Failed to refresh package list: failed to run apt update.
amd64 never hits this because it uses the template snap and runs no apt,
which is why "snap worked before" held only for amd64.
Add a PATH shim in every release-linux-arm64 job that runs ONLY snapcraft
as root, then chowns what it wrote back to the runner user. Every other
target (deb/rpm/AppImage/flatpak/tar.gz) is untouched.
Proven on ubuntu-24.04-arm with an electron@38.2.2 / electron-builder@26.0.3
harness using the apps' exact snap config (base core22):
without the shim: 12/12 jobs fail at "pull app" (runs 35896229973,
35902920526, 35903381014, 35904503217)
with the shim: 2/2 jobs produce the .snap, owned by runner (run 35905018543)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>