3a7f2234a6
The desktop launcher demanded a root-owned 4755 chrome-sandbox on every Linux host and shelled out to sudo to configure it. Launched from the .desktop entry there is no TTY, so sudo fails silently and `hermes desktop` exits without a window — and every update rebuilds the helper user-owned, re-breaking the app (#88032, #51327). The update hand-off's relaunch gate blocked on the same condition, so post-update auto-relaunch never fired either (#58593). On hosts where unprivileged user namespaces work, Chromium uses its namespace sandbox and never consults the setuid helper. Probe the actual capability with `unshare --user --map-root-user true` (fails closed) and skip the sudo path when the probe succeeds; hosts with userns disabled or AppArmor-restricted (Ubuntu 23.10+) keep the existing setuid-helper and --no-sandbox fallback behavior unchanged. Sandboxing stays fully enabled in both cases. Fixes #88032 Fixes #51327 Fixes #58593 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>