Commit Graph
805 Commits
Author SHA1 Message Date
Afonso Oliveira 6af052fcc3 Bind update inhibitor cleanup to owned process identity
Keep inhibitor state in validated private directories and verify the recorded owner, PID, start time and launch token before signaling. Authenticate the held command before detaching and drop it back to the invoking user.

Serialize launch and cancellation, identify the child before publishing its state, and preserve caller-owned idle choices. Cover cross-account fallback state, process identity, cancellation, retry, and update-lock handling with isolated regressions.
2026-09-21 16:09:04 +01:00
Afonso Oliveira 56ca654dc8 Merge quattro into update security foundation 2026-09-21 14:14:59 +01:00
David Heinemeier Hansson 599a6a665b Report skipped checks separately in shell tests 2026-09-21 11:49:32 +02:00
David Heinemeier Hansson 961ec7f39f Merge pull request #12748 from omacom/simplify/network-qr-test-environment
Fall back to connected Wi-Fi when QR route lookup fails
2026-09-21 11:37:46 +02:00
David Heinemeier Hansson 07fc39c8be Merge pull request #12747 from omacom/simplify/pacman-test-environment
Isolate pacman tests from inherited LC_ALL
2026-09-21 11:37:20 +02:00
David Heinemeier Hansson 5c2be2e653 Fix Wi-Fi QR fallback after failed route lookup 2026-09-21 10:54:38 +02:00
David Heinemeier Hansson 6f9f31ecea Isolate pacman tests from inherited LC_ALL 2026-09-21 10:50:25 +02:00
David Heinemeier Hansson 86bf7ebc71 Isolate About tests from inherited NO_COLOR 2026-09-21 10:50:25 +02:00
David Heinemeier Hansson 5b22f50be3 Stub route discovery in network QR tests 2026-09-21 10:50:25 +02:00
David Heinemeier Hansson ef81d37a87 Merge pull request #12745 from omacom/simplify/locate-test-history
Remove obsolete repository scan from locate test
2026-09-21 10:46:36 +02:00
David Heinemeier Hansson 273c340dfa Remove obsolete repository scan from locate test 2026-09-21 10:40:17 +02:00
David Heinemeier Hansson faffb8ee4d Remove stale migration filename assertion 2026-09-21 10:40:17 +02:00
David Heinemeier Hansson 1aa1423eac Retire the shipped Copy URL migration test 2026-09-21 10:10:02 +02:00
Ryan Hughes 39d1cb956d Merge quattro into use-omasnap-for-screenshots 2026-09-21 02:19:10 -04:00
Ryan Hughes c0ba99670d Clean up legacy screenshot tools in Omasnap migration 2026-09-21 02:14:54 -04:00
David Heinemeier Hansson ab18321bb5 Merge pull request #12429 from omacom/owe-video-backgrounds
Replace the shell's desktop video path with OWE
2026-09-21 03:55:16 +02:00
David Heinemeier Hansson 0d5232ed7b Fix Elsewhen migration for dev checkouts 2026-09-21 03:38:10 +02:00
David Heinemeier Hansson b423f4993d Complete OWE service setup and lock feed fallback 2026-09-20 20:36:19 -05:00
Ryan Hughes 45748a2812 Remove obsolete Elsewhen plugin symlink 2026-09-20 14:25:34 -04:00
Ryan Hughes e265934bb1 Use Omasnap for screenshots 2026-09-20 13:18:36 -04:00
Spencer Bull 16cc7d7a9d Leave the shell restart to the update flow
Restarting immediately after the plugin rescan races Quickshell IPC handler creation and can crash the exiting shell. The normal update flow already restarts after migrations. Let this migration finish through live enablement and placement without adding timing workarounds.
2026-09-19 00:06:29 -05:00
Spencer Bull 9e3ff71f48 Simplify Elsewhen installation and bar migration
Link the package into the existing plugin directory and let bar put handle enablement, clock-relative placement, and the missing-clock fallback. Preserve user checkouts and existing placements, and seed the same link for new users. This removes the Atreyu packaged-discovery prerequisite and the checkout cleanup and JSON rewrite machinery.
2026-09-19 00:01:29 -05:00
Bjarne Oeverli eff410f91e Draw the lock screen video from the OWE lock feed
The shell drops its own player: BackgroundMedia is image-only, and the
lock loads Owe.LockFeedSurface through a Loader, so a system without the
module shows no lock video instead of losing the whole lock screen. The
feed pauses per output when the panel blanks or power saver turns on.

The lock view keeps its still effect path and darkens the feed for
legibility. QtMultimedia and the shell video pause policy are gone, and
the base package list requires owe and owe-lockfeed instead.
2026-09-18 22:49:47 +02:00
Bjarne Oeverli 831626daea Note that OWE plays the desktop video audio 2026-09-18 21:02:01 +02:00
Bjarne Oeverli dbebc458db Replace the desktop video path with OWE
The desktop background no longer plays videos. OWE owns video
backgrounds, and the shell layer stays empty behind one. The shell keeps
stills, which OWE hands back to it.

Remove the desktop video pause plumbing that only existed to stop an
unseen player: the lock, idle, and battery service lookups, the
per-output fullscreen check, the first-screen audio opt-in, and the audio
output in BackgroundVideo. The lock screen keeps its own silent playback.

Update the background tests, the manual, and the package note.
2026-09-18 18:46:17 +02:00
Bjarne Oeverli d01ef2d5d0 Let OWE own video backgrounds while it runs
The background plugin now watches for the OWE daemon socket. While OWE is
running, the desktop yields video playback to it and the shell keeps
stills. The lock screen keeps its own playback.

This lets Omarchy cooperate with OWE without OWE editing shell.json, so
the engine can ship as a package.

Add a package-list note that owe-wallpaper-engine must be added once it is
packaged.
2026-09-18 18:23:21 +02:00
Spencer BullandCodex XHigh e8a8236a22 Preserve local Elsewhen work and fallback bar layouts
Retire only checkouts whose refs and reflogs are reachable from recorded origin history, and preserve ignored files. Leave configs without an explicit supported bar layout untouched so migration does not replace the shell fallback with an almost empty bar.

Co-Authored-By: Codex XHigh <noreply@openai.com>
2026-09-17 22:11:46 -05:00
Spencer Bull 49286d0e66 Place Elsewhen immediately before the center clock 2026-09-17 21:41:39 -05:00
Spencer Bull 531c3e890f Install Elsewhen, the world clock plugin, by default
Elsewhen (omacom.elsewhen) arrives as the elsewhen package under
/usr/share/omarchy/plugins, the packaged root the shell scans between its
bundled plugins and the user's. It opens the right section of the default
bar, just before the tray, and a migration installs the package, writes the
widget into a customized shell.json in the same spot, and retires a pristine
pre-package clone of the upstream repo that the package now shadows.
2026-09-17 21:41:01 -05:00
Afonso Oliveira 689771bdc1 Merge branch 'fix/9457-e-20260917' into fix/9469-c-20260917 2026-09-17 20:48:14 +01:00
Afonso OliveiraandClaude Fable 5.1 c8407ee73f Cover completion failures in the package scriptlet contract
pacman continues a transaction after a failed scriptlet. Model that in
the shared package-scriptlet contract: a failed pre_upgrade followed by
post_upgrade must keep the removal blocker while a rule remains, a
clean retry recovers, a stranded blocker with a live rule is cleaned by
the next completed installation, a fresh install that cannot remove a
leftover rule leaves publication refused, and the sweep does not depend
on inherited glob state.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-17 20:41:45 +01:00
Afonso OliveiraandClaude Fable 5.1 b34b117fd0 Recover the session lock before waiting for notifications
Restarting the shell waited for the notification bus name to reappear
before it would re-acquire a lock whose client had died. A slow or
failed notification plugin then left the user stranded behind
Hyprland's failsafe even though the lock service worked.

Wait for the shell's core IPC, re-secure the lock immediately, and only
then wait for a previously running notification service, reporting it
separately if it never returns. Cover the never-returning case: the lock
comes back and the restart still reports the missing service.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-17 17:02:43 +01:00
Afonso OliveiraandClaude Fable 5.1 13a4306a8e Run the refresh hook before its transaction and keep the inhibitor through user work
Three review findings on the update-hook boundary:

The pre-refresh-pacman hook had been moved after the refresh transaction
and, during a channel switch, deferred to the very end. That defeated the
hook's purpose: custom repositories and IgnorePkg entries were not in
place when the downgrade-capable -Syyuu ran. Run the hook where it used
to run, after the package config is re-synced and before the transaction,
but cold: revoke the timestamp, run it behind the no-update wrapper with
the caller's original PATH, and revoke again before continuing. Every
later privileged command authenticates with --no-update, so a detached
child left by the hook has no reusable timestamp to wait for. Channel
switching hands the caller's PATH to the refresh the same way the updater
receives it, and no longer defers or re-runs the hook.

Stay Awake was released before AUR builds, hooks and mise, so the machine
could sleep during the longest part of an update. Releasing the inhibitor
needs no privilege because the held command already dropped to the user,
so stop it after mise and before the reboot prompt, as before.

A packaged channel destination cannot be inspected before its package is
installed, and a transaction can replace the running tree with a release
that predates the command-scoped wrapper; from then on a bare sudo would
resolve to /usr/bin/sudo and publish a timestamp, and the destination's
own updater authenticates the same way. The switch used to abort only
after the packages had changed, with generic rerun advice. Now it checks
for the wrapper after each transaction before any further privileged
step, completes what it safely can, and stops cold with instructions to
run that release's update from a fresh session instead of launching it.

Boundary tests pin the hook between the config copies and the transaction
with a cold timestamp on both sides, the older-destination stop with its
guidance and no launched updater, the new inhibitor position, and the
post-update hook staying unreached on failures and signals. Docs, the
manual and the sample hook describe the restored timing.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-17 11:11:08 +01:00
Afonso OliveiraandClaude Fable 5.1 99ddf35138 Merge the current passwordless sudo expiry head
Bring in the legacy-grant classifier fix and the reserved-prefix
quarantine from #9457 so this branch no longer carries a stale copy of
that command.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-17 10:44:30 +01:00
Afonso OliveiraandClaude Fable 5.1 ea617b9126 Quarantine unrecognized policy under the generated sudoers prefix
Matching a legacy grant by its filename and rule relationship is not a
complete fingerprint: the legacy writer took the filename from $USER but
produced the rule with echo, and under BASH_ENV with xpg_echo a name such
as ali\0143e yields an alice rule in a mismatched file. Preserving that
as administrator policy let the migration certify success with an
unrestricted grant still live until the next boot.

The prefix is reserved anyway: boot cleanup and the package hook remove
everything under it. Move any file the classifier does not recognize
into a fresh root-only directory under /var/lib/omarchy/sudoers-quarantine/
as `policy`, with the original name stored beside it, so nothing there
stays live, the administrator keeps the content, and a legacy filename
already close to NAME_MAX still fits. An untrusted quarantine directory
keeps the migration pending. Cover the mismatched and maximum-length
legacy files in the unit cleanup and through the real migration runner.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 23:32:17 +01:00
Afonso OliveiraandClaude Fable 5.1 3eb3142313 Recognize legacy sudo grants for any account name
The legacy command wrote the caller's unvalidated name into both the
sudoers filename and the rule. Cleanup applied the current lower-case
account pattern to that suffix, so an exact legacy grant for an account
such as Alice was classified as administrator policy, left active, and
the machine-wide migration marker was written anyway.

Match a legacy grant by its exact filename and rule relationship instead
of the account policy, and cover it in the lifecycle suite through both
the unit cleanup and the real migration runner.

The account pattern itself stays lower-case: sudoers reads an upper-case
word such as ALICE as a User_Alias reference, and ALL as every user, so
such names must never reach the generated rule. Pin that with a test.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 23:01:13 +01:00
Afonso OliveiraandClaude Fable 5.1 4bd593f4ed Merge quattro and route refreshes through omarchy-update-pacman
Upstream now runs every Omarchy-owned pacman transaction through the
hidden omarchy-update-pacman helper so a mid-transaction systemd reexec
cannot kill it. Keep the deferred pre-refresh-pacman hook and the
command-scoped sudo wrapper, and call the helper from the refresh and
channel commands; the wrapper still applies to the helper's own sudo.

The sudo boundary fixture copies the helper into its root and runs a
systemd-run stand-in that execs the wrapped pacman step in place.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 21:54:06 +01:00
Erik Melton 9c5482c58d Merge pull request #8170 from Adolanium/hook-state-name-guard
Refuse hook and state names that are paths
2026-09-16 18:09:20 +02:00
Erik Melton f6ce7c554f Merge pull request #10379 from AksharP5/fix/factory-reset-password-hashes
Erase old password hashes during factory reset
2026-09-16 18:07:22 +02:00
David Heinemeier Hansson 2fbac0c8e8 Merge pull request #11934 from omacom/claude-browser-extension
Set up browser integration when choosing Claude
2026-09-15 12:41:39 -04:00
David Heinemeier Hansson 677e69d4f1 Make Claude browser extension installation best effort 2026-09-15 12:40:25 -04:00
David Heinemeier Hansson 8fa9f4d03e Leave Claude browser integration settings unchanged 2026-09-15 12:38:00 -04:00
Erik Melton a73bcbfc0a Remove unsafe project bin PATH injection (#11336)
* Remove unsafe project bin PATH injection

* Cover customized unsafe Mise paths

* Revoke legacy Mise Work trust

* Harden legacy Mise trust cleanup

* Preserve ignored Mise Work configs

* Scope Mise path cleanup to env

* Accept paranoid Mise ignore marker

Reported-by: infosec-us-team
2026-09-15 18:02:17 +02:00
b44fb74780 [Security] Keep screen-recording state out of world-writable /tmp (#8374)
* Keep screen-recording state out of world-writable /tmp

* Compare the /tmp name across the run instead of requiring it absent

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Fall back to the state directory when there is no runtime dir

* Let the /tmp snapshot come back empty

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Resolve the region file the same way in the resizer

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Protect recording fallback state and document its path

---------

Co-authored-by: Omabot <omabot@omarchy.org>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-15 17:53:37 +02:00
Adolanium 49418942c8 Merge pull request #7807 from Adolanium/keyring-fail-loud
Stop update-keyring from claiming success when key operations fail
2026-09-15 17:50:20 +02:00
David Heinemeier Hansson 45e32c8c2d Set up browser integration when choosing Claude 2026-09-15 08:10:58 -04:00
Ryan Hughes 24417bf191 Treat matching kernel headers as a base system guarantee 2026-09-15 00:46:30 -04:00
Ryan Hughes 662051ecde Install matching kernel headers for every DKMS setup 2026-09-15 00:06:17 -04:00
Ryan Hughes 08a875852e Leave fresh-install kernel selection to the ISO 2026-09-14 16:46:45 -04:00
Ryan Hughes ff85faf8dd Make linux-omarchy the default kernel except on T2 Macs 2026-09-14 16:32:09 -04:00