Reach the migration's helper through $OMARCHY_PATH rather than by name
By name, the sudo call resolved through secure_path, which puts /usr/local/bin ahead of /usr/bin and falls back to the caller's PATH where no secure_path is set, so an install could run a different helper than the pinned path did. $OMARCHY_PATH/bin is the package's symlink into /usr/bin on an install and the checkout under a dev link, so neither PATH nor secure_path takes part. Co-Authored-By: Codex XHigh <noreply@openai.com>
This commit is contained in:
1 parent
2ffae36a18
commit
92ef7e9407
2 files changed
+9
-8
No files matched your search
@@ -44,11 +44,11 @@ pass "legacy cleanup removes generated rules for any account and quarantines eve
|
||||
|
||||
# Run the actual migration queue for separate temporary homes. Sudo only calls
|
||||
# the mapped helper and can be refused without requesting host authorization.
|
||||
# The migration names the helper rather than a path, so both of its calls reach
|
||||
# the mapped copy through PATH, as they reach a dev checkout's through the link.
|
||||
mkdir -p "$test_tmp/source/migrations"
|
||||
# The migration reaches the helper through $OMARCHY_PATH, as the package's bin
|
||||
# links and a dev checkout provide it, so the mapped copy stands in there.
|
||||
mkdir -p "$test_tmp/source/migrations" "$test_tmp/source/bin"
|
||||
cp "$ROOT/migrations/1788163635.sh" "$test_tmp/source/migrations/"
|
||||
ln -s ../omarchy-sudo-passwordless "$test_tmp/bin/omarchy-sudo-passwordless"
|
||||
ln -s "$test_tmp/omarchy-sudo-passwordless" "$test_tmp/source/bin/omarchy-sudo-passwordless"
|
||||
printf 'echo "later migration ran"\n' >"$test_tmp/source/migrations/1788163636.sh"
|
||||
run_migrations() {
|
||||
TEST_MIGRATION=1 OMARCHY_PATH="$test_tmp/source" OMARCHY_MIGRATION_STATE="$test_tmp/$1" \
|
||||
|
||||
Reference in new issue
Block a user