Complete command-scoped authentication across update phases

This commit is contained in:
Afonso Oliveira committed 2026-09-06 22:26:06 +01:00
1 parent 7f9a401bb1
commit 35b318ed09
16 files changed
+583 -1643

No files matched your search

+1 -1
View File
@@ -28,7 +28,7 @@ Three documentation trees, split by genre and audience:
- Prefer `(( ))` over numeric operators inside `[[ ]]` (e.g., `(( count < 50 ))`, not `[[ $count -lt 50 ]]`)
- Prefer a full `if`/`else` conditional for simple two-path control flow; don't rely on `exec` or `exit` in one branch to make following statements unreachable
- For strings/paths with spaces, quote them instead of escaping spaces with `\ ` (e.g., `"$APP_DIR/Disk Usage.desktop"`, not `$APP_DIR/Disk\ Usage.desktop`)
- Shebangs must use `#!/bin/bash` consistently (never `#!/usr/bin/env bash`)
- Shebangs must use `#!/bin/bash` consistently (never `#!/usr/bin/env bash`). A security entrypoint may use `#!/bin/bash -p` when it must suppress inherited startup code before its first command; document the boundary and test rejection of ordinary Bash with a decoy `-p` argument.
- Scripts under `install/` and `migrations/` may be sourced and intentionally omit shebangs
# Command Naming
+4 -1
View File
@@ -83,7 +83,7 @@ if [[ -n $dev_checkout ]]; then
omarchy-state set reboot-required
fi
omarchy-refresh-pacman "$pacman_channel"
omarchy-refresh-pacman "$pacman_channel" defer-hook
# --ask 4 accepts omarchy <-> omarchy-dev replacement prompts without file overwrites.
sudo env OMARCHY_UPDATE_PACMAN=1 pacman -S --needed --noconfirm --ask 4 "${packages[@]}"
@@ -97,3 +97,6 @@ if [[ -z $dev_checkout ]]; then
fi
omarchy-update -y
# No channel-owned privileged work follows the historical refresh hook.
omarchy-refresh-pacman "$pacman_channel" run-deferred
+31 -230
View File
@@ -4,242 +4,43 @@
# omarchy:requires-sudo=true
if [[ $- != *p* ]]; then
echo "Refusing an unsafe Bash startup for pacman refresh." >&2
echo "Refusing an unsafe Bash startup." >&2
exit 126
fi
require_privileged_bash_startup() {
[[ $- == *p* ]] || return 1
/usr/bin/env -i /usr/bin/bash -p -c '
[[ $1 =~ ^[1-9][0-9]*$ ]] || exit 1
mapfile -d "" -t argv <"/proc/$1/cmdline" || exit 1
executable=$(/usr/bin/readlink -e -- "/proc/$1/exe") || exit 1
[[ $executable == /usr/bin/bash ]]
[[ ${argv[0]:-} == /bin/bash || ${argv[0]:-} == /usr/bin/bash ]]
[[ ${argv[1]:-} == -p ]]
' omarchy-bash-startup "$$"
}
if ! require_privileged_bash_startup; then
echo "Refusing an unsafe Bash startup for pacman refresh." >&2
exit 126
fi
unset -f require_privileged_bash_startup
source "${BASH_SOURCE[0]%/*}/omarchy-security-functions" || exit 126
omarchy_security_require_privileged_bash_startup || exit 126
set -e
omarchy_security_sanitize_bash_environment "$0" "$@"
user_path=$PATH
omarchy_security_revoke_sudo_timestamp || exit 1
omarchy_security_install_sudo_cleanup_traps
omarchy_security_enable_no_update_sudo
sanitize_bash_startup_environment() {
local environment_entry environment_name
local needs_reexec=0
local -a environment_unsets=(-u BASH_ENV -u ENV)
[[ -z ${BASH_ENV+x} && -z ${ENV+x} ]] || needs_reexec=1
while IFS= read -r -d '' environment_entry; do
environment_name="${environment_entry%%=*}"
if [[ $environment_name == BASH_FUNC_*%% ]]; then
environment_unsets+=(-u "$environment_name")
needs_reexec=1
fi
done < <(/usr/bin/env -0)
if (( needs_reexec )); then
exec /usr/bin/env "${environment_unsets[@]}" /usr/bin/bash -p "$0" "$@"
fi
}
sanitize_bash_startup_environment "$@"
unset -f sanitize_bash_startup_environment
usage() {
echo "Usage: omarchy-refresh-pacman [stable|rc|edge]" >&2
}
# Composite commands can postpone the legacy user hook until their own final
# privilege boundary. The two internal modes are deliberately paired: a caller
# that defers must invoke --run-deferred-hook exactly once after all of its
# sudo-capable work has finished.
channel=stable
hook_mode=normal
case "$#:$1:${2:-}" in
0::)
;;
1:stable: | 1:rc: | 1:edge:)
channel="$1"
;;
1:--run-deferred-hook:)
hook_mode=run-deferred
;;
2:stable:--defer-hook | 2:rc:--defer-hook | 2:edge:--defer-hook)
channel="$1"
hook_mode=defer
;;
*)
usage
exit 2
;;
esac
trusted_directory_chain() {
local current="$1" allow_current_user="$2" canonical owner mode current_uid
current_uid=$(/usr/bin/id -u) || return 1
while :; do
[[ -d $current && ! -L $current ]] || return 1
canonical=$(/usr/bin/realpath -e -- "$current") || return 1
[[ $canonical == "$current" ]] || return 1
[[ $current == / ]] && break
read -r owner mode < <(/usr/bin/stat -Lc '%u %a' -- "$current") || return 1
if [[ $owner != 0 ]] && ! { [[ $allow_current_user == "true" && $owner == "$current_uid" ]]; }; then
return 1
fi
(( (8#$mode & 0022) == 0 )) || return 1
current=${current%/*}
[[ -n $current ]] || current=/
done
}
trusted_omarchy_source_root() {
local config=/etc/omarchy.conf default_root=/usr/share/omarchy configured_root="" canonical=""
local owner="" mode="" links="" size="" line="" encoded="" decoded="" character=""
local index=0 escaped=0 lines=()
if [[ ! -e $config && ! -L $config ]]; then
configured_root="$default_root"
else
[[ -f $config && ! -L $config ]] || return 1
canonical=$(/usr/bin/realpath -e -- "$config") || return 1
[[ $canonical == "$config" ]] || return 1
read -r owner mode links size < <(/usr/bin/stat -Lc '%u %a %h %s' -- "$config") || return 1
[[ $owner == "0" && $links == "1" ]] || return 1
(( (8#$mode & 0022) == 0 && size > 0 && size <= 4096 )) || return 1
trusted_directory_chain /etc false || return 1
mapfile -t lines <"$config" || return 1
(( ${#lines[@]} == 1 )) || return 1
line="${lines[0]}"
[[ $line == 'export OMARCHY_PATH="'*'"' ]] || return 1
encoded="${line#'export OMARCHY_PATH="'}"
encoded="${encoded%'"'}"
for (( index = 0; index < ${#encoded}; index++ )); do
character="${encoded:index:1}"
if (( escaped )); then
case "$character" in
'\' | '"' | '$' | '`') decoded+="$character" ;;
*) return 1 ;;
esac
escaped=0
elif [[ $character == '\' ]]; then
escaped=1
elif [[ $character == '"' ]]; then
return 1
else
decoded+="$character"
fi
done
(( escaped == 0 )) || return 1
configured_root="$decoded"
fi
[[ -d $configured_root && ! -L $configured_root ]] || return 1
canonical=$(/usr/bin/realpath -e -- "$configured_root") || return 1
[[ $canonical == "$configured_root" ]] || return 1
if [[ $configured_root == "$default_root" ]]; then
trusted_directory_chain "$configured_root" false || return 1
else
trusted_directory_chain "$configured_root" true || return 1
fi
printf '%s\n' "$configured_root"
}
trusted_omarchy_source_file() {
local relative="$1" source="$OMARCHY_PATH/$1" canonical owner mode links directory current_uid
current_uid=$(/usr/bin/id -u) || return 1
[[ $relative != /* && $relative != ../* && $relative != */../* && $relative != */.. ]] || return 1
[[ -f $source && ! -L $source ]] || return 1
canonical=$(/usr/bin/realpath -e -- "$source") || return 1
[[ $canonical == "$source" && $canonical == "$OMARCHY_PATH/"* ]] || return 1
read -r owner mode links < <(/usr/bin/stat -Lc '%u %a %h' -- "$source") || return 1
[[ $links == 1 ]] && (( (8#$mode & 0022) == 0 )) || return 1
if [[ $OMARCHY_PATH == /usr/share/omarchy ]]; then
[[ $owner == 0 ]] || return 1
else
[[ $owner == 0 || $owner == "$current_uid" ]] || return 1
fi
directory=${source%/*}
while [[ $directory == "$OMARCHY_PATH" || $directory == "$OMARCHY_PATH/"* ]]; do
[[ -d $directory && ! -L $directory ]] || return 1
canonical=$(/usr/bin/realpath -e -- "$directory") || return 1
[[ $canonical == "$directory" ]] || return 1
read -r owner mode < <(/usr/bin/stat -Lc '%u %a' -- "$directory") || return 1
(( (8#$mode & 0022) == 0 )) || return 1
if [[ $OMARCHY_PATH == /usr/share/omarchy ]]; then
[[ $owner == 0 ]] || return 1
else
[[ $owner == 0 || $owner == "$current_uid" ]] || return 1
fi
[[ $directory == "$OMARCHY_PATH" ]] && break
directory=${directory%/*}
done
printf '%s\n' "$source"
}
if ! OMARCHY_PATH=$(trusted_omarchy_source_root); then
echo "Refusing to refresh pacman from an untrusted Omarchy source root." >&2
exit 1
channel="${1:-stable}"
hook_mode="${2:-normal}"
if [[ $channel != "stable" && $channel != "rc" && $channel != "edge" ]]; then
echo "Invalid channel: $channel" >&2
exit 2
fi
export OMARCHY_PATH
user_path="${PATH:-/usr/bin:/bin}"
PATH="$OMARCHY_PATH/bin:/usr/bin:/usr/sbin:/bin:/sbin"
export PATH
as_root() {
if ((EUID == 0)); then
"$@"
elif [[ ${OMARCHY_SUDO_NO_UPDATE:-0} == 1 ]]; then
/usr/bin/sudo -N -- "$@"
else
/usr/bin/sudo -- "$@"
fi
}
cleanup_sudo_credentials() {
/usr/bin/sudo -k || true
}
trap cleanup_sudo_credentials EXIT
if [[ $hook_mode == "run-deferred" ]]; then
/usr/bin/sudo -k || exit 1
PATH="$user_path" "$OMARCHY_PATH/bin/omarchy-hook" pre-refresh-pacman
exit
if [[ $hook_mode != "normal" && $hook_mode != "defer-hook" && $hook_mode != "run-deferred" ]]; then
echo "Invalid refresh hook mode: $hook_mode" >&2
exit 2
fi
pacman_source=$(trusted_omarchy_source_file "default/pacman/pacman-$channel.conf") || {
echo "Refusing an untrusted pacman configuration source." >&2
exit 1
}
mirror_source=$(trusted_omarchy_source_file "default/pacman/mirrorlist-$channel") || {
echo "Refusing an untrusted pacman mirror source." >&2
exit 1
}
as_root /usr/bin/cp -f -- /etc/pacman.conf /etc/pacman.conf.bak
as_root /usr/bin/cp -f -- /etc/pacman.d/mirrorlist /etc/pacman.d/mirrorlist.bak
echo "Setting channel to $channel"
echo
# The unprivileged shell opens the authorized source. Root consumes only the
# inherited descriptor, never a caller-writable development-checkout pathname.
as_root /usr/bin/install -T -o root -g root -m 0644 /dev/stdin /etc/pacman.conf <"$pacman_source"
as_root /usr/bin/install -T -o root -g root -m 0644 /dev/stdin /etc/pacman.d/mirrorlist <"$mirror_source"
# Reset all package DBs and then update.
as_root /usr/bin/env OMARCHY_UPDATE_PACMAN=1 /usr/bin/pacman -Syyuu --noconfirm
# This legacy hook used to run before pacman. Executable user code cannot
# safely precede a later sudo authentication: a child can wait for the new
# timestamp even if the parent invalidates around the hook. Keep the hook, but
# run it only after every privileged refresh step and with a cold credential.
if [[ $hook_mode == "normal" ]]; then
/usr/bin/sudo -k || exit 1
PATH="$user_path" "$OMARCHY_PATH/bin/omarchy-hook" pre-refresh-pacman
if [[ $hook_mode != "run-deferred" ]]; then
sudo cp -f /etc/pacman.conf /etc/pacman.conf.bak
sudo cp -f /etc/pacman.d/mirrorlist /etc/pacman.d/mirrorlist.bak
echo "Setting channel to $channel"
sudo cp -f "$OMARCHY_PATH/default/pacman/pacman-$channel.conf" /etc/pacman.conf
sudo cp -f "$OMARCHY_PATH/default/pacman/mirrorlist-$channel" /etc/pacman.d/mirrorlist
sudo env OMARCHY_UPDATE_PACMAN=1 pacman -Syyuu --noconfirm
fi
# Keep the historical hook name, but finish every privileged refresh operation
# before running user code. Callers with later root work can defer the hook.
if [[ $hook_mode != "defer-hook" ]]; then
omarchy_security_revoke_sudo_timestamp
PATH="$OMARCHY_PATH/default/omarchy/sudo-no-update:$user_path" \
"$OMARCHY_PATH/bin/omarchy-hook" pre-refresh-pacman
fi
+91
View File
@@ -0,0 +1,91 @@
#!/bin/bash
# omarchy:hidden=true
# omarchy:summary=Provide internal helpers for command-scoped sudo authentication
if [[ ${BASH_SOURCE[0]} == "$0" ]]; then
echo "omarchy-security-functions is an internal function library." >&2
exit 64
fi
omarchy_security_require_privileged_bash_startup() {
[[ $- == *p* ]] || return 1
/usr/bin/env -i /usr/bin/bash -p -c '
mapfile -d "" -t argv <"/proc/$1/cmdline" || exit 1
executable=$(/usr/bin/readlink -e -- "/proc/$1/exe") || exit 1
[[ $executable == "/usr/bin/bash" &&
( ${argv[0]:-} == "/bin/bash" || ${argv[0]:-} == "/usr/bin/bash" ) &&
${argv[1]:-} == "-p" ]]
' omarchy-bash-startup "$$"
}
omarchy_security_sanitize_bash_environment() {
local script=$1
shift
local entry name environment_fd environment_pid
local -a unsets=()
# Read the raw environment: privileged Bash ignores exported functions, but
# leaves their records for ordinary child interpreters to import later.
exec {environment_fd}< <(/usr/bin/env -0)
environment_pid=$!
while IFS= read -r -d '' entry <&"$environment_fd"; do
name=${entry%%=*}
case "$name" in
BASH_ENV|ENV|SHELLOPTS|BASHOPTS|PS4|CDPATH|GLOBIGNORE|BASH_FUNC_*%%)
unsets+=(-u "$name")
;;
esac
done
exec {environment_fd}<&-
wait "$environment_pid" || return 1
if (( ${#unsets[@]} > 0 )); then
exec /usr/bin/env "${unsets[@]}" /usr/bin/bash -p -- "$script" "$@"
fi
}
omarchy_security_sudo_supports_no_update() {
local help
help=$(LC_ALL=C /usr/bin/sudo -h 2>&1) || return 1
/usr/bin/grep -Eq '^usage: sudo .*\[[^]]*N[^]]*\]' <<< "$help"
}
omarchy_security_revoke_sudo_timestamp() {
/usr/bin/sudo -k
}
omarchy_security_exit_with_revoked_sudo() {
local status=$1
trap - EXIT HUP INT TERM
if ! omarchy_security_revoke_sudo_timestamp; then
echo "Could not invalidate cached sudo authorization." >&2
(( status != 0 )) || status=1
fi
exit "$status"
}
omarchy_security_install_signal_exit_traps() {
trap 'exit 129' HUP
trap 'exit 130' INT
trap 'exit 143' TERM
}
omarchy_security_install_sudo_cleanup_traps() {
trap 'omarchy_security_exit_with_revoked_sudo "$?"' EXIT
omarchy_security_install_signal_exit_traps
}
omarchy_security_enable_no_update_sudo() {
local wrapper_dir="$OMARCHY_PATH/default/omarchy/sudo-no-update"
if ! omarchy_security_sudo_supports_no_update; then
echo "This sudo does not support --no-update; refusing mixed-trust work." >&2
return 1
fi
if [[ ! -f $wrapper_dir/sudo || ! -x $wrapper_dir/sudo ]]; then
echo "The command-scoped sudo wrapper is missing." >&2
return 1
fi
PATH="$wrapper_dir:$OMARCHY_PATH/bin:/usr/bin:/usr/sbin:/bin:/sbin"
OMARCHY_SUDO_NO_UPDATE=1
export PATH OMARCHY_SUDO_NO_UPDATE
}
+21 -206
View File
@@ -6,210 +6,27 @@
# omarchy:requires-sudo=true
if [[ $- != *p* ]]; then
echo "Refusing an unsafe Bash startup for the Omarchy update." >&2
echo "Refusing an unsafe Bash startup." >&2
exit 126
fi
require_privileged_bash_startup() {
[[ $- == *p* ]] || return 1
/usr/bin/env -i /usr/bin/bash -p -c '
[[ $1 =~ ^[1-9][0-9]*$ ]] || exit 1
mapfile -d "" -t argv <"/proc/$1/cmdline" || exit 1
executable=$(/usr/bin/readlink -e -- "/proc/$1/exe") || exit 1
[[ $executable == /usr/bin/bash ]]
[[ ${argv[0]:-} == /bin/bash || ${argv[0]:-} == /usr/bin/bash ]]
[[ ${argv[1]:-} == -p ]]
' omarchy-bash-startup "$$"
}
if ! require_privileged_bash_startup; then
echo "Refusing an unsafe Bash startup for the Omarchy update." >&2
exit 126
fi
unset -f require_privileged_bash_startup
source "${BASH_SOURCE[0]%/*}/omarchy-security-functions" || exit 126
omarchy_security_require_privileged_bash_startup || exit 126
set -e
omarchy_security_sanitize_bash_environment "$0" "$@"
user_path=$PATH
omarchy_security_revoke_sudo_timestamp || exit 1
omarchy_security_install_sudo_cleanup_traps
omarchy_security_enable_no_update_sudo
# Privileged mode prevents BASH_ENV and exported functions from running before
# this boundary. Re-exec once without their raw environment records so ordinary
# Bash helpers cannot import them again and bypass the trusted command paths.
sanitize_bash_startup_environment() {
local environment_entry environment_name
local needs_reexec=0
local -a environment_unsets=(-u BASH_ENV -u ENV)
[[ -z ${BASH_ENV+x} && -z ${ENV+x} ]] || needs_reexec=1
while IFS= read -r -d '' environment_entry; do
environment_name="${environment_entry%%=*}"
if [[ $environment_name == BASH_FUNC_*%% ]]; then
environment_unsets+=(-u "$environment_name")
needs_reexec=1
fi
done < <(/usr/bin/env -0)
if (( needs_reexec )); then
exec /usr/bin/env "${environment_unsets[@]}" /usr/bin/bash -p "$0" "$@"
fi
}
sanitize_bash_startup_environment "$@"
unset -f sanitize_bash_startup_environment
trusted_directory_chain() {
local current="$1" allow_current_user="$2" canonical owner mode current_uid
current_uid=$(/usr/bin/id -u) || return 1
while :; do
[[ -d $current && ! -L $current ]] || return 1
canonical=$(/usr/bin/realpath -e -- "$current") || return 1
[[ $canonical == "$current" ]] || return 1
[[ $current == / ]] && break
read -r owner mode < <(/usr/bin/stat -Lc '%u %a' -- "$current") || return 1
if [[ $owner != 0 ]] && ! { [[ $allow_current_user == "true" && $owner == "$current_uid" ]]; }; then
return 1
fi
(( (8#$mode & 0022) == 0 )) || return 1
current=${current%/*}
[[ -n $current ]] || current=/
done
}
trusted_omarchy_source_root() {
local config=/etc/omarchy.conf
local default_root=/usr/share/omarchy
local configured_root=""
local canonical=""
local owner=""
local mode=""
local links=""
local size=""
local line=""
local encoded=""
local decoded=""
local character=""
local index=0
local escaped=0
local lines=()
if [[ ! -e $config && ! -L $config ]]; then
configured_root="$default_root"
else
[[ -f $config && ! -L $config ]] || return 1
canonical=$(/usr/bin/realpath -e -- "$config") || return 1
[[ $canonical == "$config" ]] || return 1
read -r owner mode links size < <(/usr/bin/stat -Lc '%u %a %h %s' -- "$config") || return 1
[[ $owner == "0" && $links == "1" ]] || return 1
(( (8#$mode & 0022) == 0 && size > 0 && size <= 4096 )) || return 1
trusted_directory_chain /etc false || return 1
mapfile -t lines <"$config" || return 1
(( ${#lines[@]} == 1 )) || return 1
line="${lines[0]}"
[[ $line == 'export OMARCHY_PATH="'*'"' ]] || return 1
encoded="${line#'export OMARCHY_PATH="'}"
encoded="${encoded%'"'}"
for (( index = 0; index < ${#encoded}; index++ )); do
character="${encoded:index:1}"
if (( escaped )); then
case "$character" in
'\' | '"' | '$' | '`') decoded+="$character" ;;
*) return 1 ;;
esac
escaped=0
elif [[ $character == '\' ]]; then
escaped=1
elif [[ $character == '"' ]]; then
return 1
else
decoded+="$character"
fi
done
(( escaped == 0 )) || return 1
configured_root="$decoded"
fi
[[ -d $configured_root && ! -L $configured_root ]] || return 1
canonical=$(/usr/bin/realpath -e -- "$configured_root") || return 1
[[ $canonical == "$configured_root" ]] || return 1
if [[ $configured_root == "$default_root" ]]; then
trusted_directory_chain "$configured_root" false || return 1
else
trusted_directory_chain "$configured_root" true || return 1
fi
printf '%s\n' "$configured_root"
}
sudo_supports_no_update() {
LC_ALL=C /usr/bin/sudo -h 2>&1 | /usr/bin/grep -Eq '^usage: sudo .*\[[^]]*N[^]]*\]'
}
validate_non_reusable_sudo() {
local wrapper_dir="$OMARCHY_PATH/default/omarchy/sudo-no-update"
local wrapper="$wrapper_dir/sudo" canonical="" current="" owner="" mode=""
sudo_supports_no_update || {
echo "This sudo does not support --no-update; refusing to run a mixed-trust update." >&2
return 1
}
[[ -f $wrapper && -x $wrapper && ! -L $wrapper ]] || {
echo "Trusted no-update sudo wrapper is missing; refusing to run a mixed-trust update." >&2
return 1
}
canonical=$(/usr/bin/realpath -e -- "$wrapper") || return 1
[[ $canonical == "$wrapper" ]] || return 1
if [[ $OMARCHY_PATH == "/usr/share/omarchy" ]]; then
current="$wrapper"
while :; do
[[ ! -L $current ]] || return 1
read -r owner mode < <(/usr/bin/stat -Lc '%u %a' -- "$current") || return 1
[[ $owner == "0" ]] || return 1
(( (8#$mode & 0022) == 0 )) || return 1
[[ $current == "$OMARCHY_PATH" ]] && break
current=${current%/*}
done
fi
}
enable_non_reusable_sudo() {
local wrapper_dir="$OMARCHY_PATH/default/omarchy/sudo-no-update"
validate_non_reusable_sudo
PATH="$wrapper_dir:$PATH"
export PATH
}
if ! OMARCHY_PATH=$(trusted_omarchy_source_root); then
echo "Refusing to update from an untrusted Omarchy source root." >&2
exit 1
fi
export OMARCHY_PATH
user_path="${PATH:-/usr/bin:/bin}"
PATH="$OMARCHY_PATH/bin:/usr/bin:/usr/sbin:/bin:/sbin"
export PATH
update_stay_awake_stopped=0
# Verify and enable the security primitive before any update-owned privileged
# work. Every authorization in this workflow is command-scoped (`sudo -N`): it
# may prompt for the command being run, but it never publishes a reusable
# timestamp to a dev hook, migration tool, AUR build, or detached child.
validate_non_reusable_sudo || exit 1
if [[ ${OMARCHY_SUDO_NO_UPDATE:-0} == 1 ]]; then
enable_non_reusable_sudo
fi
/usr/bin/sudo -k || exit 1
enable_non_reusable_sudo
export OMARCHY_SUDO_NO_UPDATE=1
cleanup_update() {
local status=$?
trap - EXIT
trap - EXIT HUP INT TERM
if (( update_stay_awake_stopped == 0 )); then
omarchy-update-stay-awake stop || true
omarchy-update-stay-awake stop || status=1
fi
/usr/bin/sudo -k || true
exit "$status"
omarchy_security_exit_with_revoked_sudo "$status"
}
if [[ -z ${OMARCHY_UPDATE_LOGGED:-} ]]; then
@@ -223,6 +40,7 @@ fi
trap 'echo ""; echo -e "\033[0;31mSomething went wrong during the update!\n\nPlease review the output above carefully, correct the error, and retry the update.\n\nIf you need assistance, get help from the community at https://omarchy.org/discord\033[0m"' ERR
trap cleanup_update EXIT
omarchy_security_install_signal_exit_traps
omarchy-update-requires-free-space
@@ -243,9 +61,7 @@ if [[ ${1:-} == "-y" ]] || omarchy-update-confirm; then
omarchy-update-stay-awake start
# A dev link explicitly authorizes its checkout through root-owned system
# configuration (including sudo's secure_path), so preserve the established
# pull-before-packages/migrations ordering for that trusted mode.
# Preserve the established development-checkout update ordering.
omarchy-update-dev
omarchy-update-keyring
@@ -258,7 +74,7 @@ if [[ ${1:-} == "-y" ]] || omarchy-update-confirm; then
# tooling with privileged repairs. The no-update sudo wrapper has covered the
# whole update, so neither the package transaction nor a later repair can
# publish a timestamp to a detached migration child.
/usr/bin/sudo -k
omarchy_security_revoke_sudo_timestamp
omarchy-migrate
omarchy-update-orphan-pkgs
@@ -275,19 +91,18 @@ if [[ ${1:-} == "-y" ]] || omarchy-update-confirm; then
omarchy-update-stay-awake stop
update_stay_awake_stopped=1
# AUR installation can refresh sudo after running package build code. No
# privileged update stage may follow it: user-controlled code can outlive
# its parent and wait for a later timestamp even if we invalidate in between.
# AUR package installation must also use the no-update wrapper. Finish
# update-owned system work before build code, hooks, or mise can run.
omarchy-update-aur-pkgs
/usr/bin/sudo -k
omarchy_security_revoke_sudo_timestamp
# Hooks and mise execute user-controlled code. Give each a cold credential
# boundary and run mise last so it cannot wait for a legitimate hook sudo.
# Only the unprivileged reboot prompt follows them.
PATH="$user_path" "$OMARCHY_PATH/bin/omarchy-hook" post-update
/usr/bin/sudo -k
PATH="$user_path" "$OMARCHY_PATH/bin/omarchy-update-mise"
/usr/bin/sudo -k
PATH="$OMARCHY_PATH/default/omarchy/sudo-no-update:$user_path" "$OMARCHY_PATH/bin/omarchy-hook" post-update
omarchy_security_revoke_sudo_timestamp
PATH="$OMARCHY_PATH/default/omarchy/sudo-no-update:$user_path" "$OMARCHY_PATH/bin/omarchy-update-mise"
omarchy_security_revoke_sudo_timestamp
"$OMARCHY_PATH/bin/omarchy-update-restart" --reboot-only
fi
+8 -1
View File
@@ -2,10 +2,17 @@
# omarchy:summary=Update AUR packages if any are installed
sudo_options=()
if [[ ${OMARCHY_SUDO_NO_UPDATE:-0} == "1" ]]; then
sudo_wrapper="$OMARCHY_PATH/default/omarchy/sudo-no-update/sudo"
[[ -x $sudo_wrapper ]] || exit 1
sudo_options=(--sudo "$sudo_wrapper" --nosudoloop)
fi
if pacman -Qem >/dev/null; then
if omarchy-pkg-aur-accessible; then
echo -e "\e[32m\nUpdate AUR packages\e[0m"
yay -Sua --noconfirm --cleanafter --ignore gcc14,gcc14-libs
yay "${sudo_options[@]}" -Sua --noconfirm --cleanafter --ignore gcc14,gcc14-libs || exit 1
echo
else
echo -e "\e[31m\nAUR is unavailable (so skipping updates)\e[0m"
+51 -36
View File
@@ -1,51 +1,66 @@
#!/bin/bash
# omarchy:summary=Prompt for required reboot or service restarts after updates
# omarchy:args=[--services-only|--reboot-only]
mode="${1:-all}"
case "$mode" in
all|--services-only|--reboot-only) ;;
*) echo "Unknown restart phase: $mode" >&2; exit 2 ;;
esac
echo
confirm_reboot() {
gum confirm "$1" && { omarchy-system-reboot; exit 0; }
if [[ ${OMARCHY_UPDATE_UNATTENDED:-0} == "1" ]]; then
echo "$1 Run omarchy-system-reboot when ready."
elif gum confirm "$1"; then
omarchy-system-reboot
exit 0
fi
}
running_kernel=$(uname -r)
kernel_updated=true
if [[ $mode != "--services-only" ]]; then
running_kernel=$(uname -r)
kernel_updated=true
for kernel in /usr/lib/modules/*/vmlinuz; do
if [[ -f $kernel ]] && pacman -Qo "$kernel" &>/dev/null; then
installed_kernel=$(basename "$(dirname "$kernel")")
for kernel in /usr/lib/modules/*/vmlinuz; do
if [[ -f $kernel ]] && pacman -Qo "$kernel" &>/dev/null; then
installed_kernel=$(basename "$(dirname "$kernel")")
if [[ $installed_kernel == $running_kernel ]]; then
kernel_updated=false
break
if [[ $installed_kernel == $running_kernel ]]; then
kernel_updated=false
break
fi
fi
fi
done
done
if [[ $kernel_updated == "true" ]]; then
confirm_reboot "Linux kernel has been updated. Reboot?"
elif [[ -f $HOME/.local/state/omarchy/reboot-required ]]; then
confirm_reboot "Updates require reboot. Ready?"
if [[ $kernel_updated == "true" ]]; then
confirm_reboot "Linux kernel has been updated. Reboot?"
elif [[ -f $HOME/.local/state/omarchy/reboot-required ]]; then
confirm_reboot "Updates require reboot. Ready?"
fi
running_hyprland=$(readlink /proc/$(pgrep -x Hyprland)/exe 2>/dev/null)
if [[ $running_hyprland == *"(deleted)"* ]]; then
confirm_reboot "Hyprland has been updated. Reboot?"
fi
fi
running_hyprland=$(readlink /proc/$(pgrep -x Hyprland)/exe 2>/dev/null)
if [[ $running_hyprland == *"(deleted)"* ]]; then
confirm_reboot "Hyprland has been updated. Reboot?"
if [[ $mode != "--reboot-only" ]]; then
for file in "$HOME"/.local/state/omarchy/restart-*-required; do
if [[ -f $file ]]; then
filename=$(basename "$file")
service=$(echo "$filename" | sed 's/restart-\(.*\)-required/\1/')
echo "Restarting $service"
omarchy-state clear "$filename"
omarchy-restart-"$service"
fi
done
# Updates routinely replace the shell's QML, and a stale process can lazy-load
# new files into old code. A restart failure (locked session, ssh, TTY) only
# prints its reason: the next update or login gets a fresh shell anyway.
echo -e "\e[32m\nRestarting shell\e[0m"
echo "All plugins have been reloaded"
omarchy-restart-shell || true
fi
for file in "$HOME"/.local/state/omarchy/restart-*-required; do
if [[ -f $file ]]; then
filename=$(basename "$file")
service=$(echo "$filename" | sed 's/restart-\(.*\)-required/\1/')
echo "Restarting $service"
omarchy-state clear "$filename"
omarchy-restart-"$service"
fi
done
# Updates routinely replace the shell's QML, and a stale process can lazy-load
# new files into old code. A restart failure (locked session, ssh, TTY) only
# prints its reason: the next update or login gets a fresh shell anyway.
echo -e "\e[32m\nRestarting shell\e[0m"
echo "All plugins have been reloaded"
omarchy-restart-shell || true
+41 -32
View File
@@ -81,46 +81,55 @@ stop() {
}
start() {
local inhibit_pid=""
local inhibit_start_time=""
local inhibit_runner=()
local idle_owner="$$:$RANDOM:$RANDOM"
stop
mkdir -p "$state_dir"
if omarchy-cmd-present systemd-inhibit; then
if (( EUID != 0 )); then
if [[ -t 0 ]]; then
sudo -v
inhibit_runner=(sudo)
else
inhibit_runner=(pkexec)
fi
fi
# sudo authenticates in the foreground, then backgrounds the inhibitor.
# The held command drops back to this user before publishing its PID, so stop
# can release the inhibitor without another privileged operation or ticket.
local hold_command=(
/usr/bin/systemd-inhibit --what=sleep:idle --who=omarchy-update
--why="Omarchy update in progress" --mode=block
/usr/bin/setpriv --reuid "$UID" --regid "$(id -g)" --clear-groups
/usr/bin/bash -p -c '
read -r process_stat <"/proc/$$/stat"
process_stat=${process_stat##*) }
read -r -a fields <<< "$process_stat"
printf "%s %s\n" "$$" "${fields[19]}" >"$1"
exec /usr/bin/sleep infinity
' omarchy-update-inhibitor "$inhibit_pid_file"
)
if [[ -n ${OMARCHY_UPDATE_LOCK_FD:-} ]]; then
"${inhibit_runner[@]}" systemd-inhibit \
--what=sleep:idle \
--who=omarchy-update \
--why="Omarchy update in progress" \
--mode=block \
sleep infinity >/dev/null 2>&1 {OMARCHY_UPDATE_LOCK_FD}>&- &
else
"${inhibit_runner[@]}" systemd-inhibit \
--what=sleep:idle \
--who=omarchy-update \
--why="Omarchy update in progress" \
--mode=block \
sleep infinity >/dev/null 2>&1 &
fi
inhibit_pid=$!
inhibit_start_time=$(process_start_time "$inhibit_pid" 2>/dev/null || true)
if [[ -n $inhibit_start_time ]]; then
printf '%s %s\n' "$inhibit_pid" "$inhibit_start_time" >"$inhibit_pid_file"
fi
if (( EUID == 0 )); then
( [[ -z ${OMARCHY_UPDATE_LOCK_FD:-} ]] || exec {OMARCHY_UPDATE_LOCK_FD}>&-
exec "${hold_command[@]}" ) &
elif [[ -t 0 ]]; then
sudo -N -b -- "${hold_command[@]}"
else
( [[ -z ${OMARCHY_UPDATE_LOCK_FD:-} ]] || exec {OMARCHY_UPDATE_LOCK_FD}>&-
exec pkexec "${hold_command[@]}" ) &
fi
# For graphical authentication the launcher may wait for a password. Wait for
# either the user-owned held command to become ready or the launcher to fail.
local launcher_pid=${!:-}
local readiness_attempts=0
while [[ ! -s $inhibit_pid_file ]]; do
if [[ -n $launcher_pid ]] && ! kill -0 "$launcher_pid" 2>/dev/null; then
wait "$launcher_pid" || return 1
echo "The update sleep inhibitor did not start." >&2
return 1
fi
readiness_attempts=$((readiness_attempts + 1))
if [[ -t 0 ]] && (( EUID != 0 && readiness_attempts >= 100 )); then
echo "The update sleep inhibitor did not become ready." >&2
return 1
fi
sleep 0.05
done
if [[ ! -f $stay_awake_state ]]; then
printf '%s\n' "$idle_owner" >"$idle_owner_file"
mkdir -p "$(dirname "$stay_awake_state")"
+11 -19
View File
@@ -1,27 +1,19 @@
#!/bin/bash -p
# Internal update/migration sudo boundary. Authentication may authorize this
# command, but -N prevents it from publishing a timestamp that detached user
# code can silently reuse.
# Preserve sudo options while preventing authentication from refreshing the
# credential cache. Timestamp maintenance and informational modes stand alone.
if [[ $- != *p* ]]; then
echo "Refusing an unsafe Bash startup for the sudo boundary." >&2
exit 126
fi
source "${BASH_SOURCE[0]%/*}/../../../bin/omarchy-security-functions" || exit 126
omarchy_security_require_privileged_bash_startup || exit 126
require_privileged_bash_startup() {
[[ $- == *p* ]] || return 1
/usr/bin/env -i /usr/bin/bash -p -c '
[[ $1 =~ ^[1-9][0-9]*$ ]] || exit 1
mapfile -d "" -t argv <"/proc/$1/cmdline" || exit 1
executable=$(/usr/bin/readlink -e -- "/proc/$1/exe") || exit 1
[[ $executable == /usr/bin/bash ]]
[[ ${argv[0]:-} == /bin/bash || ${argv[0]:-} == /usr/bin/bash ]]
[[ ${argv[1]:-} == -p ]]
' omarchy-bash-startup "$$"
}
if ! require_privileged_bash_startup; then
echo "Refusing an unsafe Bash startup for the sudo boundary." >&2
exit 126
if (( $# == 1 )); then
case "$1" in
-k|--reset-timestamp|-K|--remove-timestamp|-h|--help|-V|--version)
exec /usr/bin/sudo "$@"
;;
esac
fi
exec /usr/bin/sudo -N -- "$@"
exec /usr/bin/sudo -N "$@"
+7 -11
View File
@@ -26,7 +26,7 @@ The design goal is:
| `~/.local/state/omarchy/current/` | user | Generated active theme, selected theme name, and current background symlink. |
| `~/.local/state/omarchy/migrations/` | user | Per-user migration markers. |
| `~/.local/state/omarchy/reboot-required` | user | Optional reboot marker checked by `omarchy-update-restart`. |
| `~/.local/state/omarchy/restart-*-required` | user | Optional allowlisted service/app restart markers checked by `omarchy-update-restart`. Marker names select fixed commands from the system-authorized Omarchy tree; they are not resolved through caller `PATH`. The shell needs no marker: it is restarted unconditionally after every update. |
| `~/.local/state/omarchy/restart-*-required` | user | Optional service/app restart markers checked by `omarchy-update-restart`. The shell needs no marker: it is restarted unconditionally after every update. |
## Migration layout
@@ -56,12 +56,7 @@ privileged work should invoke the appropriate helper or privilege prompt.
Migrations must be idempotent; if one user already applied a machine-wide repair,
the migration should no-op for other users.
The runner derives the migration source from root-owned `/etc/omarchy.conf`,
starts from a cold sudo timestamp, and routes migration sudo calls through
`sudo --no-update`. Historical migrations are strictly ordered and can mix
user-controlled tools or theme hooks with later privileged repairs; no-update
authentication lets those repairs run without publishing a credential a
detached earlier process could reuse.
When invoked by the update, migrations inherit its cold credential state and no-update sudo wrapper. The standalone migration runner has its own security changes in the migration-boundary PR; this update change does not establish that standalone boundary. Historical migrations remain strictly ordered.
For watchers and diagnostics, `omarchy-migrate --pending` prints pending
migration names and exits `0` when any are pending. When no migrations are
@@ -149,9 +144,9 @@ omarchy-update
Important behavior:
- `omarchy update` derives its source tree from root-owned `/etc/omarchy.conf`, or the root-owned `/usr/share/omarchy` default when that file is absent. It does not trust inherited `OMARCHY_PATH` or caller `PATH` for the privileged phase.
- `omarchy update` uses the session’s `OMARCHY_PATH` and a fixed command search path for its system phases. User PATH is restored behind the sudo wrapper for hooks and mise.
- Mixed-trust update entrypoints start Bash in privileged mode, discard `BASH_ENV`, `ENV`, and exported-function records before launching helpers, and reject an ordinary `bash path/to/command` invocation. Run them as executables (normally through the `omarchy` CLI); `/usr/bin/bash -p path/to/command` is the explicit interpreter form. This keeps shell startup injection from replacing the no-update sudo boundary.
- In dev-link mode, the root-owned configuration is the explicit authorization for the user-writable checkout. `omarchy update` fast-forwards that authorized checkout from its configured upstream before changing system packages or running migrations.
- In dev-link mode, `omarchy update` fast-forwards the active checkout from its configured upstream before changing system packages or running migrations.
- Migrations remain in chronological order even though historical entries mix user-controlled code with later privileged repairs. Before entering that mixed-trust tail, Omarchy invalidates its timestamp and forces every later sudo call—including AUR's configurable sudo command—to use `--no-update`; prompts authorize one command without publishing a reusable timestamp. Yay's credential loop is disabled for the update.
- User-controlled post-update hooks and mise tools run only after every sudo-capable update stage. Omarchy invalidates its sudo timestamp before each boundary and on every exit; detached children therefore have no later reusable update authorization to wait for.
- `-y` exports `OMARCHY_UPDATE_UNATTENDED=1` — a promise not to ask anything.
@@ -292,7 +287,8 @@ scripts.
| `omarchy-update-confirm` | Gum confirmation copy for `omarchy update`. | **Question.** Could be inlined into `omarchy-update`; separate file only helps keep copy isolated. |
| `omarchy-update-dev` | Fast-forwards the active dev-linked checkout from its configured upstream; no-ops for package-backed installs. | **Keep.** Runs before package updates so a checkout conflict stops the update before system mutation. |
| `omarchy-update-keyring` | Ensures Omarchy keyring and Arch keyring are current before the main transaction. | **Keep, but review.** It uses targeted `pacman -Sy` for keyring bootstrapping; acceptable for this special case but should remain tightly scoped. |
| `omarchy-update-system-pkgs` | Runs the ordinary guarded `pacman -Syu --noconfirm`. Package-vs-package conflicts may be retried interactively with `pacman -Su`; filesystem conflicts fail closed without moving, restoring, quarantining, or broadly overwriting live paths. The production Quattro transition performs the sole explicit settings-package takeover with `--overwrite='*'`; all later production and developer package transactions obey Pacman's ownership checks. | **Keep.** Small leaf command with no generic privileged conflict handler. |
| `omarchy-update-system-pkgs` | Runs `sudo env OMARCHY_UPDATE_PACMAN=1 pacman -Syu --noconfirm` with `--overwrite '/usr/share/omarchy/*'`, capturing stderr to a report file; on failure it execs `omarchy-update-system-pkgs-when-conflicted`. | **Keep for now.** Small leaf command, clear/testable. |
| `omarchy-update-system-pkgs-when-conflicted` | Hidden conflict handler: quarantines unowned conflicting files under `/var/lib/omarchy/replaced`, retries the upgrade once, restores files the upgrade didn't claim, and hands package-vs-package conflicts to an interactive pacman run (never under `-y`). | **Keep internal/hidden.** Keeps conflict recovery out of the happy path. |
| `omarchy-update-pkg-prune` | Trims the pacman cache to two versions per package (`paccache -rk2`) before the snapshot, keeping the offline downgrade path while capping snapshot growth. | **Keep internal/hidden.** |
| `omarchy-update-requires-free-space` | Aborts the update below a 10 GiB free-space threshold on `/`; silently skipped when free space cannot be determined; `OMARCHY_UPDATE_FORCE=1` bypasses. | **Keep internal/hidden.** |
| `omarchy-migrate` | Public migration command. Waits for pacman, then runs all pending migrations for the current user. Supports `--pending`. | **Keep.** This replaces the discarded `omarchy-update-user-finalize` name and no longer needs `--force`. |
@@ -304,7 +300,7 @@ scripts.
| `omarchy-update-mise` | Runs `MISE_MINIMUM_RELEASE_AGE=0 mise up` for mise-managed tools — the override of mise's release-age cooldown is the point. | **Keep.** Mise-managed tools are intentionally part of the blessed update path. |
| `omarchy-update-orphan-pkgs` | Lists orphans and prompts before removal; noninteractive mode never removes. | **Keep for now.** Safe because it is prompt-only. |
| `omarchy-update-analyze-logs` | Scans `/tmp/omarchy-update.log` for known failure patterns, currently initramfs generation. | **Keep/expand.** Useful safety net; should grow only for high-signal checks. |
| `omarchy-update-restart` | Restarts allowlisted components selected by `restart-*-required` markers, always restarts the shell, and prompts for reboot after kernel/Hyprland updates. Internal phase flags let the update finish sudo-capable restarts before user hooks and defer only the unprivileged reboot prompt. | **Keep.** Important final step; may eventually include service-restart checks. |
| `omarchy-update-restart` | Restarts components selected by `restart-*-required` markers, always restarts the shell, and prompts for reboot after kernel/Hyprland updates. Internal phase flags let the update finish sudo-capable restarts before user hooks and defer only the unprivileged reboot prompt. | **Keep.** Important final step; may eventually include service-restart checks. |
| `omarchy-update-firmware` | Manual firmware update command using fwupd. Not part of the normal update pipeline. | **Keep separate.** Firmware is not a routine system update step. |
| `omarchy-update-time` | Restarts `systemd-timesyncd`. | **Question.** Not really an update command. Consider renaming/moving under system/time maintenance. |
+8 -6
View File
@@ -105,7 +105,7 @@ assert_log_line() {
}
run_channel stable
assert_log_line $'refresh\tstable' "stable refreshes the stable pacman channel"
assert_log_line $'refresh\tstable\tdefer-hook' "stable refreshes the stable pacman channel"
assert_log_line $'sudo\tenv\tOMARCHY_UPDATE_PACMAN=1\tpacman\t-S\t--needed\t--noconfirm\t--ask\t4\tomarchy\tomarchy-settings' "stable installs stable Omarchy packages"
assert_log_line $'unlink\t--no-reboot' "stable restores the package-backed Omarchy path without an early reboot prompt"
assert_log_line $'update\t-y\tOMARCHY_PATH=/usr/share/omarchy' "stable runs the normal update pipeline from the package-backed path"
@@ -115,13 +115,13 @@ fi
pass "stable does not require reboot when already package-backed"
run_channel rc
assert_log_line $'refresh\trc' "rc refreshes the rc pacman channel"
assert_log_line $'refresh\trc\tdefer-hook' "rc refreshes the rc pacman channel"
assert_log_line $'sudo\tenv\tOMARCHY_UPDATE_PACMAN=1\tpacman\t-S\t--needed\t--noconfirm\t--ask\t4\tomarchy\tomarchy-settings' "rc installs rc Omarchy packages"
assert_log_line $'unlink\t--no-reboot' "rc restores the package-backed Omarchy path without an early reboot prompt"
assert_log_line $'update\t-y\tOMARCHY_PATH=/usr/share/omarchy' "rc runs the normal update pipeline from the package-backed path"
OMARCHY_TEST_PATH="$ROOT" run_channel edge
assert_log_line $'refresh\tedge' "edge refreshes the edge pacman channel"
assert_log_line $'refresh\tedge\tdefer-hook' "edge refreshes the edge pacman channel"
assert_log_line $'sudo\tenv\tOMARCHY_UPDATE_PACMAN=1\tpacman\t-S\t--needed\t--noconfirm\t--ask\t4\tomarchy-dev\tomarchy-settings-dev' "edge installs development Omarchy packages"
assert_log_line $'unlink\t--no-reboot' "edge unlinks dev without an early reboot prompt"
assert_log_line $'state\tset\treboot-required' "edge marks reboot required when leaving dev"
@@ -137,7 +137,7 @@ if run_channel dev >"$test_tmp/occupied.out" 2>"$test_tmp/occupied.err"; then
fi
grep -q "already exists and is not a git checkout" "$test_tmp/occupied.err" || fail "dev explains occupied checkout paths" "$(cat "$test_tmp/occupied.err")"
if grep -Fx $'refresh\tedge' "$log_file" >/dev/null; then
if grep -Fx $'refresh\tedge\tdefer-hook' "$log_file" >/dev/null; then
fail "dev validates checkout path before changing packages" "$(cat "$log_file")"
fi
pass "dev refuses occupied non-checkout paths before package changes"
@@ -145,15 +145,17 @@ pass "dev refuses occupied non-checkout paths before package changes"
rmdir "$checkout"
run_channel dev
assert_log_line $'gum\tconfirm\t--default=false\tSwitch to dev channel?' "dev asks for confirmation"
assert_log_line $'refresh\tedge' "dev refreshes the edge pacman channel"
assert_log_line $'refresh\tedge\tdefer-hook' "dev refreshes the edge pacman channel"
assert_log_line $'sudo\tenv\tOMARCHY_UPDATE_PACMAN=1\tpacman\t-S\t--needed\t--noconfirm\t--ask\t4\tomarchy-dev\tomarchy-settings-dev' "dev installs development Omarchy packages"
assert_log_line $'git\tclone\thttps://github.com/basecamp/omarchy.git\t'"$checkout" "dev clones the source checkout to ~/omarchy"
assert_log_line $'link\t'"$checkout"$'\t--no-reboot' "dev links ~/omarchy without an early reboot prompt"
assert_log_line $'state\tset\treboot-required' "dev defers the reboot prompt to the update pipeline"
assert_log_line $'update\t-y\tOMARCHY_PATH='"$checkout" "dev runs the normal update pipeline from the source checkout"
[[ $(grep -E '^(git|link|state|refresh|sudo|update)' "$log_file") == $'git\tclone\thttps://github.com/basecamp/omarchy.git\t'"$checkout"$'\nlink\t'"$checkout"$'\t--no-reboot\nstate\tset\treboot-required\nrefresh\tedge\nsudo\tenv\tOMARCHY_UPDATE_PACMAN=1\tpacman\t-S\t--needed\t--noconfirm\t--ask\t4\tomarchy-dev\tomarchy-settings-dev\nupdate\t-y\tOMARCHY_PATH='"$checkout" ]] ||
[[ $(grep -E '^(git|link|state|refresh|sudo|update)' "$log_file" | sed '/run-deferred/d') == $'git\tclone\thttps://github.com/basecamp/omarchy.git\t'"$checkout"$'\nlink\t'"$checkout"$'\t--no-reboot\nstate\tset\treboot-required\nrefresh\tedge\tdefer-hook\nsudo\tenv\tOMARCHY_UPDATE_PACMAN=1\tpacman\t-S\t--needed\t--noconfirm\t--ask\t4\tomarchy-dev\tomarchy-settings-dev\nupdate\t-y\tOMARCHY_PATH='"$checkout" ]] ||
fail "dev activates the checkout before changing or updating packages" "$(cat "$log_file")"
pass "dev activates the checkout before changing or updating packages"
[[ $(tail -1 "$log_file") == $'refresh\tedge\trun-deferred' ]] || fail "channel refresh hook must run after the complete update"
pass "channel changes defer the refresh hook until all update work finishes"
OMARCHY_TEST_PATH="$checkout" run_channel stable
assert_log_line $'unlink\t--no-reboot' "switching from dev to stable unlinks without an early reboot prompt"
+124
View File
@@ -0,0 +1,124 @@
#!/bin/bash
# Test the real orchestration with fixed privileged paths redirected to harmless
# stand-ins. No host sudo, package transaction, namespace root, or exploit runs.
boundary_tmp=$(mktemp -d)
trap 'rm -rf "$boundary_tmp"' EXIT
export SUDO_TEST_ROOT="$boundary_tmp/omarchy"
export SUDO_TEST_LOG="$boundary_tmp/events"
export SUDO_TEST_CACHE="$boundary_tmp/cache"
export OMARCHY_PATH="$SUDO_TEST_ROOT"
export SUDO_TEST_HOME="$boundary_tmp/home"
mkdir -p "$SUDO_TEST_HOME"
mkdir -p "$SUDO_TEST_ROOT/bin" "$SUDO_TEST_ROOT/mock" "$SUDO_TEST_ROOT/default/omarchy/sudo-no-update"
: >"$SUDO_TEST_LOG"
copy_boundary_file() {
python3 - "$ROOT" "$SUDO_TEST_ROOT" "$1" <<'PY'
import sys
from pathlib import Path
source, target, name = map(Path,sys.argv[1:])
p=target/name
p.parent.mkdir(parents=True,exist_ok=True)
s=(source/name).read_text().replace('$HOME', '$SUDO_TEST_HOME')
for command in ['sudo','pacman','omarchy-pkg-missing','systemd-inhibit','setpriv','snapper']:
s=s.replace('/usr/bin/'+command, str(target/'mock'/command))
s=s.replace('PATH=/usr/bin:/usr/sbin:/bin:/sbin', 'PATH="'+str(target/'bin')+':/usr/bin:/usr/sbin:/bin:/sbin"')
p.write_text(s)
p.chmod((source/name).stat().st_mode & 0o777)
PY
}
copy_boundary_file bin/omarchy-security-functions
copy_boundary_file default/omarchy/sudo-no-update/sudo
cat >"$SUDO_TEST_ROOT/mock/sudo" <<'STUB'
#!/bin/bash
set -euo pipefail
printf 'sudo' >>"$SUDO_TEST_LOG"
printf ' %q' "$@" >>"$SUDO_TEST_LOG"
printf '\n' >>"$SUDO_TEST_LOG"
if [[ ${1:-} == "-h" ]]; then
if [[ ${SUDO_TEST_UNSUPPORTED:-0} == "1" ]]; then
echo 'usage: sudo [-ABbEHknPS] command'
else
echo 'usage: sudo [-ABbEHkNnPS] command'
fi
exit 0
fi
if [[ ${1:-} == "-k" || ${1:-} == "-K" ]]; then
[[ ${SUDO_TEST_REVOKE_FAIL:-0} != "1" ]] || exit 1
rm -f "$SUDO_TEST_CACHE"
exit 0
fi
if [[ ${1:-} == "-N" ]]; then
shift
else
touch "$SUDO_TEST_CACHE"
fi
[[ ${SUDO_TEST_SUDO_FAIL:-0} != "1" ]] || exit 1
background=0
while (( $# )); do
case "$1" in
-N|-n) shift ;;
-b) background=1; shift ;;
-v) exit 0 ;;
-u|--user) shift 2 ;;
--) shift; break ;;
*) break ;;
esac
done
(( $# )) || exit 0
if (( background )); then
"$@" &
else
"$@"
fi
STUB
chmod +x "$SUDO_TEST_ROOT/mock/sudo"
cat >"$SUDO_TEST_ROOT/bin/test-step" <<'STUB'
#!/bin/bash
set -euo pipefail
step=${0##*/}
printf 'step:%s %s\n' "$step" "$*" >>"$SUDO_TEST_LOG"
if [[ $step == "omarchy-hook" || $step == "omarchy-update-mise" ]]; then
[[ ! -e $SUDO_TEST_CACHE ]] || exit 91
fi
if [[ ${SUDO_TEST_FAIL_STEP:-} == "$step" ]]; then
# Model a misbehaving child leaving state behind, then failing. Cleanup must
# still revoke it. This never invokes real sudo or exercises a privilege flaw.
touch "$SUDO_TEST_CACHE"
exit 17
fi
if [[ ${SUDO_TEST_SIGNAL_STEP:-} == "$step" ]]; then
touch "$SUDO_TEST_CACHE"
kill -TERM "$PPID"
exit 0
fi
case "$step" in
omarchy-update-system-pkgs|omarchy-update-keyring|omarchy-snapshot)
sudo /usr/bin/true
;;
pacman) exit 0 ;;
yay)
[[ $* == *"--sudo $OMARCHY_PATH/default/omarchy/sudo-no-update/sudo"* ]] || exit 92
[[ $* == *"--nosudoloop"* ]] || exit 93
;;
esac
STUB
chmod +x "$SUDO_TEST_ROOT/bin/test-step"
for step in omarchy-update-lock omarchy-update-requires-free-space omarchy-update-confirm omarchy-update-pkg-prune omarchy-snapshot omarchy-update-stay-awake omarchy-update-dev omarchy-update-keyring omarchy-update-system-pkgs omarchy-migrate omarchy-hook omarchy-update-aur-pkgs omarchy-update-mise omarchy-update-orphan-pkgs omarchy-update-analyze-logs omarchy-update-status omarchy-update-restart omarchy-pkg-aur-accessible omarchy-notification-dismiss pacman cp yay; do
ln -s test-step "$SUDO_TEST_ROOT/bin/$step"
done
ln -s ../bin/test-step "$SUDO_TEST_ROOT/mock/pacman"
reset_boundary() {
: >"$SUDO_TEST_LOG"
rm -f "$SUDO_TEST_CACHE"
unset SUDO_TEST_FAIL_STEP SUDO_TEST_SIGNAL_STEP SUDO_TEST_SUDO_FAIL SUDO_TEST_REVOKE_FAIL SUDO_TEST_UNSUPPORTED
}
assert_boundary_cold() {
[[ ! -e $SUDO_TEST_CACHE ]] || fail "$1 left cached authorization"
[[ $(tail -1 "$SUDO_TEST_LOG") == "sudo -k" ]] || fail "$1 did not revoke at exit" "$(<"$SUDO_TEST_LOG")"
}
+95 -1018
View File
File diff suppressed because it is too large. Load diff
+44 -27
View File
@@ -4,16 +4,31 @@ set -euo pipefail
source "$(dirname "$0")/base-test.sh"
test_tmp=$(mktemp -d)
trap 'rm -rf "$test_tmp"' EXIT
stub_bin="$test_tmp/bin"
test_home="$test_tmp/home"
source "$SHELL_TEST_DIR/fixtures/sudo-boundary-test.sh"
test_tmp="$boundary_tmp"
stub_bin="$SUDO_TEST_ROOT/bin"
test_home="$SUDO_TEST_HOME"
runtime_dir="$test_tmp/runtime"
mkdir -p "$stub_bin" "$test_home" "$runtime_dir"
mkdir -p "$runtime_dir"
for command in omarchy-update omarchy-update-lock omarchy-update-stay-awake; do
rm -f "$SUDO_TEST_ROOT/bin/$command"
copy_boundary_file "bin/$command"
done
cat >"$SUDO_TEST_ROOT/mock/setpriv" <<'STUB'
#!/bin/bash
while [[ ${1:-} == --* ]]; do
case "$1" in
--reuid|--regid) shift 2 ;;
--clear-groups) shift ;;
*) exit 90 ;;
esac
done
exec "$@"
STUB
chmod +x "$SUDO_TEST_ROOT/mock/setpriv"
run_with_lock_env() {
HOME="$test_home" \
SUDO_TEST_HOME="$test_home" \
XDG_RUNTIME_DIR="$runtime_dir" \
XDG_STATE_HOME="$test_tmp/state" \
PATH="$stub_bin:$ROOT/bin:$PATH" \
@@ -24,6 +39,7 @@ write_stub() {
local name="$1"
local body="$2"
rm -f "$stub_bin/$name"
cat >"$stub_bin/$name" <<SH
#!/bin/bash
$body
@@ -51,13 +67,15 @@ for command in \
done
write_stub omarchy-update-available 'exit 1'
write_stub pkexec 'exec "$@"'
write_stub systemd-inhibit 'while [[ $1 == --* ]]; do shift; done; exec "$@"'
ln -s ../bin/systemd-inhibit "$SUDO_TEST_ROOT/mock/systemd-inhibit"
# omarchy-update should hold the lock before snapshotting, so a second update
# cannot even enter its pre-update snapshot.
update_snapshot_marker="$test_tmp/update-snapshot-started"
write_stub omarchy-snapshot 'echo started >"$TEST_MARKER"; sleep 2; exit 0'
OMARCHY_UPDATE_LOGGED=1 TEST_MARKER="$update_snapshot_marker" run_with_lock_env "$ROOT/bin/omarchy-update" -y >"$test_tmp/update-first.out" 2>&1 &
OMARCHY_UPDATE_LOGGED=1 TEST_MARKER="$update_snapshot_marker" run_with_lock_env "$SUDO_TEST_ROOT/bin/omarchy-update" -y >"$test_tmp/update-first.out" 2>&1 &
update_pid=$!
for _ in {1..50}; do
@@ -67,7 +85,7 @@ done
[[ -f $update_snapshot_marker ]] || fail "first omarchy-update reached snapshot under lock"
set +e
OMARCHY_UPDATE_LOGGED=1 TEST_MARKER="$test_tmp/update-second-snapshot-started" run_with_lock_env "$ROOT/bin/omarchy-update" -y >"$test_tmp/update-second.out" 2>&1
OMARCHY_UPDATE_LOGGED=1 TEST_MARKER="$test_tmp/update-second-snapshot-started" run_with_lock_env "$SUDO_TEST_ROOT/bin/omarchy-update" -y >"$test_tmp/update-second.out" 2>&1
update_second_status=$?
set -e
@@ -85,11 +103,11 @@ pass "omarchy-update prevents overlapping top-level updates"
inhibit_pid_file="$test_tmp/inhibit-pid"
keyring_marker="$test_tmp/keyring-started"
write_stub omarchy-snapshot 'exit 0'
write_stub systemd-inhibit 'echo "$$" >"$INHIBIT_PID_FILE"; exec sleep 30'
write_stub systemd-inhibit '[[ -z ${INHIBIT_PID_FILE:-} ]] || echo "$$" >"$INHIBIT_PID_FILE"; while [[ $1 == --* ]]; do shift; done; exec "$@"'
write_stub omarchy-update-keyring 'echo started >"$TEST_MARKER"; sleep 3; exit 0'
OMARCHY_UPDATE_LOGGED=1 TEST_MARKER="$keyring_marker" INHIBIT_PID_FILE="$inhibit_pid_file" \
run_with_lock_env "$ROOT/bin/omarchy-update" -y >"$test_tmp/update-inhibit.out" 2>&1 &
run_with_lock_env "$SUDO_TEST_ROOT/bin/omarchy-update" -y >"$test_tmp/update-inhibit.out" 2>&1 &
inhibit_update_pid=$!
for _ in {1..100}; do
@@ -123,11 +141,10 @@ if (( EUID != 0 )); then
terminal_inhibit_pid_file="$test_tmp/terminal-inhibit-pid"
write_stub sudo '
printf "%s\n" "$*" >>"$SUDO_LOG"
if [[ $1 == "-v" ]]; then
exit 0
fi
exec "$@"'
write_stub pkexec 'touch "$PKEXEC_MARKER"; exec "$@"'
[[ $1 == "-N" && $2 == "-b" && $3 == "--" ]] || exit 90
shift 3
"$@" &'
write_stub pkexec '[[ -z ${PKEXEC_MARKER:-} ]] || touch "$PKEXEC_MARKER"; exec "$@"'
# start leaves the inhibitor running on purpose, but script tears the pty down
# the moment its command returns, which SIGHUPs that inhibitor before it can
@@ -137,7 +154,7 @@ exec "$@"'
#!/bin/bash
omarchy-update-stay-awake start
for _ in {1..200}; do
grep -q '^systemd-inhibit ' "$SUDO_LOG" && break
grep -q -- '^-N -b -- ' "$SUDO_LOG" && break
sleep 0.05
done
SH
@@ -146,10 +163,10 @@ SH
SUDO_LOG="$sudo_log" PKEXEC_MARKER="$pkexec_marker" INHIBIT_PID_FILE="$terminal_inhibit_pid_file" \
run_with_lock_env script -qefc "$terminal_driver" /dev/null >/dev/null
grep -qx -- '-v' "$sudo_log" || fail "terminal sleep inhibition validates sudo in the foreground"
grep -q '^systemd-inhibit ' "$sudo_log" || fail "terminal sleep inhibition runs through sudo"
grep -q -- '^-N -b -- ' "$sudo_log" || fail "terminal inhibition authenticates its background command without a reusable timestamp"
grep -q -- '^-N -b -- ' "$sudo_log" || fail "terminal sleep inhibition runs through sudo"
[[ ! -e $pkexec_marker ]] || fail "terminal sleep inhibition does not use pkexec"
run_with_lock_env "$ROOT/bin/omarchy-update-stay-awake" stop
run_with_lock_env "$SUDO_TEST_ROOT/bin/omarchy-update-stay-awake" stop
pass "terminal updates use sudo instead of Polkit for sleep inhibition"
fi
@@ -158,7 +175,7 @@ fi
write_stub omarchy-snapshot 'exit 0'
write_stub omarchy-update-keyring 'exit 0'
write_stub omarchy-toggle-idle '
state_file="$HOME/.local/state/omarchy/indicators/stay-awake"
state_file="$SUDO_TEST_HOME/.local/state/omarchy/indicators/stay-awake"
case "$1" in
stay-awake)
mkdir -p "$(dirname "$state_file")"
@@ -169,20 +186,20 @@ case "$1" in
;;
esac'
write_stub omarchy-update-restart '
state_file="$HOME/.local/state/omarchy/indicators/stay-awake"
if [[ ${EXPECT_STAY_AWAKE:-0} == "1" ]]; then
state_file="$SUDO_TEST_HOME/.local/state/omarchy/indicators/stay-awake"
if [[ ${1:-} == "--services-only" || ${EXPECT_STAY_AWAKE:-0} == "1" ]]; then
[[ -f $state_file ]]
else
[[ ! -f $state_file ]]
fi'
rm -f "$test_home/.local/state/omarchy/indicators/stay-awake"
OMARCHY_UPDATE_LOGGED=1 run_with_lock_env "$ROOT/bin/omarchy-update" -y
OMARCHY_UPDATE_LOGGED=1 run_with_lock_env "$SUDO_TEST_ROOT/bin/omarchy-update" -y
[[ ! -f $test_home/.local/state/omarchy/indicators/stay-awake ]] || fail "update clears its Stay Awake state before restart handling"
mkdir -p "$test_home/.local/state/omarchy/indicators"
touch "$test_home/.local/state/omarchy/indicators/stay-awake"
OMARCHY_UPDATE_LOGGED=1 EXPECT_STAY_AWAKE=1 run_with_lock_env "$ROOT/bin/omarchy-update" -y
OMARCHY_UPDATE_LOGGED=1 EXPECT_STAY_AWAKE=1 run_with_lock_env "$SUDO_TEST_ROOT/bin/omarchy-update" -y
[[ -f $test_home/.local/state/omarchy/indicators/stay-awake ]] || fail "update preserves pre-existing Stay Awake state"
pass "omarchy-update restores only its own Stay Awake state before restart handling"
@@ -194,7 +211,7 @@ mkdir -p "$stay_awake_helper_state" "$(dirname "$stay_awake_state")"
printf '%s\n' "old-update-owner" >"$stay_awake_helper_state/idle-owner"
printf '%s\n' "user-choice" >"$stay_awake_state"
run_with_lock_env "$ROOT/bin/omarchy-update-stay-awake" stop
run_with_lock_env "$SUDO_TEST_ROOT/bin/omarchy-update-stay-awake" stop
[[ $(<"$stay_awake_state") == "user-choice" ]] ||
fail "stale update ownership does not remove a newer Stay Awake choice"
pass "stale update ownership preserves a newer Stay Awake choice"
@@ -206,7 +223,7 @@ unrelated_start_time=$(awk '{ print $22 }' "/proc/$unrelated_pid/stat")
mkdir -p "$stay_awake_helper_state"
printf '%s %s\n' "$unrelated_pid" "$((unrelated_start_time + 1))" >"$stay_awake_helper_state/inhibit-pid"
run_with_lock_env "$ROOT/bin/omarchy-update-stay-awake" stop
run_with_lock_env "$SUDO_TEST_ROOT/bin/omarchy-update-stay-awake" stop
kill -0 "$unrelated_pid" 2>/dev/null ||
fail "stale inhibitor state does not terminate a reused PID"
kill "$unrelated_pid"
+39
View File
@@ -0,0 +1,39 @@
#!/bin/bash
set -euo pipefail
source "$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)/base-test.sh"
source "$SHELL_TEST_DIR/fixtures/sudo-boundary-test.sh"
rm "$SUDO_TEST_ROOT/bin/omarchy-update-restart"
copy_boundary_file bin/omarchy-update-restart
for step in omarchy-state omarchy-restart-sshd omarchy-restart-shell omarchy-system-reboot; do
ln -s test-step "$SUDO_TEST_ROOT/bin/$step"
done
cat >"$SUDO_TEST_ROOT/bin/gum" <<'STUB'
#!/bin/bash
printf 'prompt:%s\n' "$*" >>"$SUDO_TEST_LOG"
exit 1
STUB
chmod +x "$SUDO_TEST_ROOT/bin/gum"
mkdir -p "$SUDO_TEST_HOME/.local/state/omarchy"
touch "$SUDO_TEST_HOME/.local/state/omarchy/reboot-required" "$SUDO_TEST_HOME/.local/state/omarchy/restart-sshd-required"
for mode in --services-only --reboot-only; do
reset_boundary
PATH="$SUDO_TEST_ROOT/bin:$PATH" "$SUDO_TEST_ROOT/bin/omarchy-update-restart" "$mode" >"$boundary_tmp/output" 2>&1
if [[ $mode == "--services-only" ]]; then
grep -q '^step:omarchy-restart-sshd ' "$SUDO_TEST_LOG" || fail "service phase did not restart a marked service"
grep -q '^step:omarchy-restart-shell ' "$SUDO_TEST_LOG" || fail "service phase did not restart the shell"
if grep -q '^prompt:' "$SUDO_TEST_LOG"; then fail "service phase offered a reboot before update cleanup"; fi
else
grep -q '^prompt:' "$SUDO_TEST_LOG" || fail "reboot phase did not offer the required reboot"
if grep -q '^step:omarchy-restart-' "$SUDO_TEST_LOG"; then fail "reboot phase performed later service work"; fi
fi
pass "restart $mode performs only its selected phase"
done
reset_boundary
OMARCHY_UPDATE_UNATTENDED=1 PATH="$SUDO_TEST_ROOT/bin:$PATH" "$SUDO_TEST_ROOT/bin/omarchy-update-restart" --reboot-only >"$boundary_tmp/output" 2>&1
if grep -Eq "^(prompt:|step:omarchy-restart-|step:omarchy-system-reboot)" "$SUDO_TEST_LOG"; then
fail "unattended reboot phase prompted or performed service work"
fi
pass "unattended reboot phase reports a required reboot without prompting"
+7 -55
View File
@@ -2,60 +2,11 @@
set -euo pipefail
source "$(dirname "$0")/base-test.sh"
if [[ -z ${OMARCHY_UPDATE_SEQUENCE_NS:-} ]]; then
outer_uid=$(id -u)
outer_gid=$(id -g)
subuid=$(awk -F: -v user="$(id -un)" '$1 == user { print $2; exit }' /etc/subuid)
subgid=$(awk -F: -v group="$(id -gn)" '$1 == group { print $2; exit }' /etc/subgid)
if [[ -z $subuid || -z $subgid ]]; then
pass "no subordinate uid/gid range; skipping authorized update-sequence test"
exit 0
fi
exec unshare --user --mount \
--map-users "0:$outer_uid:1" --map-users "1:$subuid:65536" \
--map-groups "0:$outer_gid:1" --map-groups "1:$subgid:65536" \
env OMARCHY_UPDATE_SEQUENCE_NS=setup bash "$0"
elif [[ $OMARCHY_UPDATE_SEQUENCE_NS == setup ]]; then
mount -t tmpfs -o mode=0755 tmpfs /run
namespace_tmp=$(mktemp -d -p /run omarchy-update-sequence.XXXXXXXX)
chmod 0755 "$namespace_tmp"
mkdir -p "$namespace_tmp/default/omarchy/sudo-no-update"
cp "$ROOT/default/omarchy/sudo-no-update/sudo" "$namespace_tmp/default/omarchy/sudo-no-update/sudo"
chmod 0755 "$namespace_tmp/default/omarchy/sudo-no-update/sudo"
cat >"$namespace_tmp/fixed-sudo" <<'STUB'
#!/bin/bash
if [[ ${1:-} == "-h" ]]; then
echo 'usage: sudo [-ABbEHkNnPS] command'
fi
exit 0
STUB
chmod 0755 "$namespace_tmp/fixed-sudo"
mount --bind "$namespace_tmp/fixed-sudo" /usr/bin/sudo
mount -t tmpfs -o mode=0755 tmpfs /etc
printf 'export OMARCHY_PATH="%s"\n' "$namespace_tmp" >/etc/omarchy.conf
chmod 0644 /etc/omarchy.conf
chown -R 1000:1000 "$namespace_tmp"
set +e
setpriv --reuid 1000 --regid 1000 --clear-groups \
env OMARCHY_UPDATE_SEQUENCE_NS=run OMARCHY_AUTHORIZED_TEST_ROOT="$namespace_tmp" bash "$0"
status=$?
set -e
umount /usr/bin/sudo
umount /etc
rm -rf "$namespace_tmp"
umount /run
exit "$status"
fi
test_tmp="$OMARCHY_AUTHORIZED_TEST_ROOT"
trap 'rm -rf "$test_tmp"/*' EXIT
stub_bin="$test_tmp/bin"
mkdir -p "$stub_bin"
source "$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)/base-test.sh"
source "$SHELL_TEST_DIR/fixtures/sudo-boundary-test.sh"
copy_boundary_file bin/omarchy-update
test_tmp="$boundary_tmp"
stub_bin="$SUDO_TEST_ROOT/bin"
# Every step omarchy-update runs, recorded in order with the unattended flag it
# was handed. One of them can be told to fail.
@@ -80,6 +31,7 @@ steps=(
)
for step in "${steps[@]}"; do
rm -f "$stub_bin/$step"
cat >"$stub_bin/$step" <<'STUB'
#!/bin/bash
printf '%s unattended=%s\n' "${0##*/}" "${OMARCHY_UPDATE_UNATTENDED:-}" >>"$STEP_LOG"
@@ -96,7 +48,7 @@ run_update() {
FAILING_STEP="${FAILING_STEP:-}" \
OMARCHY_UPDATE_LOGGED=1 \
PATH="$stub_bin:$PATH" \
"$ROOT/bin/omarchy-update" "$@" >"$test_tmp/out" 2>"$test_tmp/err"
"$SUDO_TEST_ROOT/bin/omarchy-update" "$@" >"$test_tmp/out" 2>"$test_tmp/err"
}
steps_run() {