From 2ffae36a182bbbb1758cc8e8f3568e33eb73567e Mon Sep 17 00:00:00 2001 From: Spencer Bull Date: Sat, 26 Sep 2026 14:38:53 -0500 Subject: [PATCH 1/2] Resolve the passwordless sudo helper by name in its migration Pinning /usr/bin ran the packaged helper even where the migration came from somewhere else. Under a dev link the migration is read from the checkout while /usr/bin still holds the last installed package, and a package predating __migrate prints its usage and fails the update. By name, the unprivileged call goes through PATH and the sudo call through secure_path, which is how other migrations reach their helpers and which lands on /usr/bin on an install. Co-Authored-By: Codex XHigh --- migrations/1788163635.sh | 6 ++++-- test/shell.d/passwordless-grant-lifecycle-test.sh | 6 ++++-- 2 files changed, 8 insertions(+), 4 deletions(-) diff --git a/migrations/1788163635.sh b/migrations/1788163635.sh index 7ce941a5..26712800 100644 --- a/migrations/1788163635.sh +++ b/migrations/1788163635.sh @@ -1,6 +1,8 @@ echo "Remove legacy temporary passwordless sudo grants" # Migration queues are per-user; the privileged repair is once per machine. -if ! /usr/bin/omarchy-sudo-passwordless __migration-complete; then - sudo /usr/bin/omarchy-sudo-passwordless __migrate +# By name: secure_path resolves /usr/bin on an install and the checkout under a +# dev link, where the installed package may predate __migrate. +if ! omarchy-sudo-passwordless __migration-complete; then + sudo omarchy-sudo-passwordless __migrate fi diff --git a/test/shell.d/passwordless-grant-lifecycle-test.sh b/test/shell.d/passwordless-grant-lifecycle-test.sh index 2eee2dea..aba77e96 100644 --- a/test/shell.d/passwordless-grant-lifecycle-test.sh +++ b/test/shell.d/passwordless-grant-lifecycle-test.sh @@ -44,9 +44,11 @@ pass "legacy cleanup removes generated rules for any account and quarantines eve # Run the actual migration queue for separate temporary homes. Sudo only calls # the mapped helper and can be refused without requesting host authorization. +# The migration names the helper rather than a path, so both of its calls reach +# the mapped copy through PATH, as they reach a dev checkout's through the link. mkdir -p "$test_tmp/source/migrations" -sed "s|/usr/bin/omarchy-sudo-passwordless|$test_tmp/omarchy-sudo-passwordless|g" \ - "$ROOT/migrations/1788163635.sh" >"$test_tmp/source/migrations/1788163635.sh" +cp "$ROOT/migrations/1788163635.sh" "$test_tmp/source/migrations/" +ln -s ../omarchy-sudo-passwordless "$test_tmp/bin/omarchy-sudo-passwordless" printf 'echo "later migration ran"\n' >"$test_tmp/source/migrations/1788163636.sh" run_migrations() { TEST_MIGRATION=1 OMARCHY_PATH="$test_tmp/source" OMARCHY_MIGRATION_STATE="$test_tmp/$1" \ From 92ef7e940717ab69d45b435dbd0e78e346a6375f Mon Sep 17 00:00:00 2001 From: Spencer Bull Date: Sat, 26 Sep 2026 14:49:34 -0500 Subject: [PATCH 2/2] Reach the migration's helper through $OMARCHY_PATH rather than by name By name, the sudo call resolved through secure_path, which puts /usr/local/bin ahead of /usr/bin and falls back to the caller's PATH where no secure_path is set, so an install could run a different helper than the pinned path did. $OMARCHY_PATH/bin is the package's symlink into /usr/bin on an install and the checkout under a dev link, so neither PATH nor secure_path takes part. Co-Authored-By: Codex XHigh --- migrations/1788163635.sh | 9 +++++---- test/shell.d/passwordless-grant-lifecycle-test.sh | 8 ++++---- 2 files changed, 9 insertions(+), 8 deletions(-) diff --git a/migrations/1788163635.sh b/migrations/1788163635.sh index 26712800..f0925b40 100644 --- a/migrations/1788163635.sh +++ b/migrations/1788163635.sh @@ -1,8 +1,9 @@ echo "Remove legacy temporary passwordless sudo grants" # Migration queues are per-user; the privileged repair is once per machine. -# By name: secure_path resolves /usr/bin on an install and the checkout under a -# dev link, where the installed package may predate __migrate. -if ! omarchy-sudo-passwordless __migration-complete; then - sudo omarchy-sudo-passwordless __migrate +# The helper beside this migration: the package's /usr/bin copy on an install, +# and under a dev link the checkout's, which may be newer than the package. +helper="$OMARCHY_PATH/bin/omarchy-sudo-passwordless" +if ! "$helper" __migration-complete; then + sudo "$helper" __migrate fi diff --git a/test/shell.d/passwordless-grant-lifecycle-test.sh b/test/shell.d/passwordless-grant-lifecycle-test.sh index aba77e96..ec0af64c 100644 --- a/test/shell.d/passwordless-grant-lifecycle-test.sh +++ b/test/shell.d/passwordless-grant-lifecycle-test.sh @@ -44,11 +44,11 @@ pass "legacy cleanup removes generated rules for any account and quarantines eve # Run the actual migration queue for separate temporary homes. Sudo only calls # the mapped helper and can be refused without requesting host authorization. -# The migration names the helper rather than a path, so both of its calls reach -# the mapped copy through PATH, as they reach a dev checkout's through the link. -mkdir -p "$test_tmp/source/migrations" +# The migration reaches the helper through $OMARCHY_PATH, as the package's bin +# links and a dev checkout provide it, so the mapped copy stands in there. +mkdir -p "$test_tmp/source/migrations" "$test_tmp/source/bin" cp "$ROOT/migrations/1788163635.sh" "$test_tmp/source/migrations/" -ln -s ../omarchy-sudo-passwordless "$test_tmp/bin/omarchy-sudo-passwordless" +ln -s "$test_tmp/omarchy-sudo-passwordless" "$test_tmp/source/bin/omarchy-sudo-passwordless" printf 'echo "later migration ran"\n' >"$test_tmp/source/migrations/1788163636.sh" run_migrations() { TEST_MIGRATION=1 OMARCHY_PATH="$test_tmp/source" OMARCHY_MIGRATION_STATE="$test_tmp/$1" \