The root-run package hook changed ownership of paths below a user-controlled home directory. A config symlink could redirect chown to an arbitrary root-owned file during installation or upgrade. Run the config writer as the target desktop user and remove the privileged ownership changes. This also prevents the missing-config path from writing through a user-controlled pathname as root. Add regression coverage and bump the package release. Reported-by: piratemoo (Esther) <22439214+piratemoo@users.noreply.github.com> Link: https://github.com/piratemoo/Arbitrary-File-Ownership-Change-via-Symlink-LPE
dell-xps-touchpad-haptics
This package installs the Dell XPS Synaptics haptic touchpad daemon, its systemd service, and a small CLI for switching between Omarchy's preset haptic levels.
What it installs:
/usr/bin/dell-xps-touchpad-haptics/usr/bin/dell-xps-touchpad-haptics-daemon/usr/lib/systemd/system/dell-xps-touchpad-haptics.service/usr/lib/udev/rules.d/99-dell-xps-touchpad-haptics.rules
What the pacman install hook does:
- picks a desktop user and writes
/etc/dell-xps-touchpad-haptics.env - creates
~/.config/omarchy/dell-haptic.confif needed - enables the service and restarts it when a running systemd manager is available
Usage:
dell-xps-touchpad-haptics get
dell-xps-touchpad-haptics set low
dell-xps-touchpad-haptics set mid
dell-xps-touchpad-haptics set high
Preset levels:
low=10mid=50high=100
Debugging:
- level changes are logged by the service when it notices the config change and attempts HID gain readback
- set
DELL_XPS_TOUCHPAD_HAPTICS_DEBUG=1in/etc/dell-xps-touchpad-haptics.envto log each press and release report tojournalctl -u dell-xps-touchpad-haptics.service