Merge pull request #13350 from omacom/fix/sudo-passwordless-migration-path
Run the passwordless sudo helper from $OMARCHY_PATH in its migration
This commit is contained in:
2 files changed
+10
-5
No files matched your search
@@ -1,6 +1,9 @@
|
||||
echo "Remove legacy temporary passwordless sudo grants"
|
||||
|
||||
# Migration queues are per-user; the privileged repair is once per machine.
|
||||
if ! /usr/bin/omarchy-sudo-passwordless __migration-complete; then
|
||||
sudo /usr/bin/omarchy-sudo-passwordless __migrate
|
||||
# The helper beside this migration: the package's /usr/bin copy on an install,
|
||||
# and under a dev link the checkout's, which may be newer than the package.
|
||||
helper="$OMARCHY_PATH/bin/omarchy-sudo-passwordless"
|
||||
if ! "$helper" __migration-complete; then
|
||||
sudo "$helper" __migrate
|
||||
fi
|
||||
@@ -44,9 +44,11 @@ pass "legacy cleanup removes generated rules for any account and quarantines eve
|
||||
|
||||
# Run the actual migration queue for separate temporary homes. Sudo only calls
|
||||
# the mapped helper and can be refused without requesting host authorization.
|
||||
mkdir -p "$test_tmp/source/migrations"
|
||||
sed "s|/usr/bin/omarchy-sudo-passwordless|$test_tmp/omarchy-sudo-passwordless|g" \
|
||||
"$ROOT/migrations/1788163635.sh" >"$test_tmp/source/migrations/1788163635.sh"
|
||||
# The migration reaches the helper through $OMARCHY_PATH, as the package's bin
|
||||
# links and a dev checkout provide it, so the mapped copy stands in there.
|
||||
mkdir -p "$test_tmp/source/migrations" "$test_tmp/source/bin"
|
||||
cp "$ROOT/migrations/1788163635.sh" "$test_tmp/source/migrations/"
|
||||
ln -s "$test_tmp/omarchy-sudo-passwordless" "$test_tmp/source/bin/omarchy-sudo-passwordless"
|
||||
printf 'echo "later migration ran"\n' >"$test_tmp/source/migrations/1788163636.sh"
|
||||
run_migrations() {
|
||||
TEST_MIGRATION=1 OMARCHY_PATH="$test_tmp/source" OMARCHY_MIGRATION_STATE="$test_tmp/$1" \
|
||||
|
||||
Reference in new issue
Block a user