Commit Graph
23 Commits
Author SHA1 Message Date
Afonso OliveiraandClaude Fable 5.1 43b91163f6 Install cleanup traps before the entry revocation and bound the bus probe
The protected entrypoints revoked the sudo timestamp before installing
their cleanup traps, so a signal or failure during that first sudo -k
exited without the cleanup path. Install the traps first.

The shell restart probed the notification bus name with busctl's
default 25 second timeout, so an unresponsive user bus could stall the
restart by that much per probe. Bound each probe to one second.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-17 20:33:59 +01:00
Afonso OliveiraandClaude Fable 5.1 13a4306a8e Run the refresh hook before its transaction and keep the inhibitor through user work
Three review findings on the update-hook boundary:

The pre-refresh-pacman hook had been moved after the refresh transaction
and, during a channel switch, deferred to the very end. That defeated the
hook's purpose: custom repositories and IgnorePkg entries were not in
place when the downgrade-capable -Syyuu ran. Run the hook where it used
to run, after the package config is re-synced and before the transaction,
but cold: revoke the timestamp, run it behind the no-update wrapper with
the caller's original PATH, and revoke again before continuing. Every
later privileged command authenticates with --no-update, so a detached
child left by the hook has no reusable timestamp to wait for. Channel
switching hands the caller's PATH to the refresh the same way the updater
receives it, and no longer defers or re-runs the hook.

Stay Awake was released before AUR builds, hooks and mise, so the machine
could sleep during the longest part of an update. Releasing the inhibitor
needs no privilege because the held command already dropped to the user,
so stop it after mise and before the reboot prompt, as before.

A packaged channel destination cannot be inspected before its package is
installed, and a transaction can replace the running tree with a release
that predates the command-scoped wrapper; from then on a bare sudo would
resolve to /usr/bin/sudo and publish a timestamp, and the destination's
own updater authenticates the same way. The switch used to abort only
after the packages had changed, with generic rerun advice. Now it checks
for the wrapper after each transaction before any further privileged
step, completes what it safely can, and stops cold with instructions to
run that release's update from a fresh session instead of launching it.

Boundary tests pin the hook between the config copies and the transaction
with a cold timestamp on both sides, the older-destination stop with its
guidance and no launched updater, the new inhibitor position, and the
post-update hook staying unreached on failures and signals. Docs, the
manual and the sample hook describe the restored timing.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-17 11:11:08 +01:00
Afonso OliveiraandClaude Fable 5.1 4bd593f4ed Merge quattro and route refreshes through omarchy-update-pacman
Upstream now runs every Omarchy-owned pacman transaction through the
hidden omarchy-update-pacman helper so a mid-transaction systemd reexec
cannot kill it. Keep the deferred pre-refresh-pacman hook and the
command-scoped sudo wrapper, and call the helper from the refresh and
channel commands; the wrapper still applies to the helper's own sudo.

The sudo boundary fixture copies the helper into its root and runs a
systemd-run stand-in that execs the wrapped pacman step in place.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 21:54:06 +01:00
David Heinemeier HanssonandClaude Fable 5 f5194e3ff5 Shield Omarchy pacman transactions from desktop session teardown
Upgrading systemd runs its post_upgrade scriptlet mid-transaction, which
reexecs both the system manager and every user manager. When pacman runs
inside a user-session scope (the floating update terminal), that reexec
can SIGKILL it and abandon the transaction halfway, with packages
upgraded but none of the post-transaction hooks run.

Route every Omarchy-owned system mutation through a new hidden
omarchy-update-pacman helper that registers the transaction as a PID 1
scope via systemd-run, keeping it out of the user manager's cgroups.
System scopes survive the system manager's own reexec, and as a bonus the
transaction now also survives its terminal window closing. On unbooted
systems (the installer chroot) the helper runs pacman directly.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-13 10:21:38 +02:00
Afonso Oliveira 5bc41b2585 Resolve security libraries beside canonical entrypoints 2026-09-07 17:31:54 +01:00
Afonso Oliveira f37c73fa20 Bind protected update commands to their source root 2026-09-07 17:27:04 +01:00
Afonso Oliveira 35b318ed09 Complete command-scoped authentication across update phases 2026-09-06 22:26:06 +01:00
Afonso Oliveira 1136a715c0 OM-SEC-14: Run update hooks without reusable sudo authority 2026-08-31 21:32:42 +01:00
Ryan Hughes 0804962619 Improve update and migration flow 2026-06-04 18:38:25 -04:00
Ty SmithandClaude Opus 4.7 c4dbf12920 Add pre-refresh-pacman.d hooks for custom repository support (#5681)
Fires after the channel template is copied to /etc/pacman.conf and before
`pacman -Syyuu` runs, letting users layer custom Pacman repositories or
IgnorePkg directives onto the freshly-written config so they're respected
by the upgrade. Useful for users running on overlay distros (CachyOS,
Chaotic-AUR, internal company repos) where a wipe-and-reinstall would
otherwise pull vanilla Arch versions.

Ships with `pre-refresh-pacman.d/add-custom-repo.sample` showing the
pattern.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-11 10:19:12 +02:00
Ryan HughesandDavid Heinemeier Hansson d2a4cc0c4d Add omarchy CLI (#5477)
* Add omarchy CLI

* Remove outdated or internal

* Add bash completions for command

* Add omarchy command documentation

* Add missing docs

* Correct to what's now right

* Fix tests

---------

Co-authored-by: David Heinemeier Hansson <david@hey.com>
2026-05-01 17:40:22 +02:00
David Heinemeier Hansson 7514ae7dcf Use consistent bash5 style for conditionals and quoting 2026-02-21 10:18:47 +01:00
David Heinemeier Hansson da0122c85a Allow proper downgrades of packages 2026-02-19 15:35:15 +01:00
David Heinemeier Hansson ab4694e3f5 Introduce rc channel 2026-01-31 21:49:07 +01:00
David Heinemeier Hansson 6cbca7825b Excess CR 2026-01-07 20:51:40 +01:00
David Heinemeier Hansson 2855712158 Ensure mirror and pkgs channels are always kept in sync as stable or edge 2026-01-07 19:45:00 +01:00
David Heinemeier Hansson ca40676657 Add documentation to Omarchy commands 2026-01-05 10:17:32 +01:00
David Heinemeier Hansson c97995b9ea Can just do it in one go 2025-11-28 05:03:04 -08:00
David Heinemeier Hansson 6a181adf0d Reset all package DBs when changing channel 2025-11-28 13:03:55 +01:00
David Heinemeier Hansson c86614039e Take backups of existing pacman.conf + mirrorlist before refreshing
Closes #3479
2025-11-22 11:05:45 +01:00
David Heinemeier Hansson 88a1141301 Simplify mirror/pkgs to just channel 2025-11-22 10:50:23 +01:00
David Heinemeier Hansson f6cd5e076d Simplify switching between edge and stable channels 2025-11-22 10:41:30 +01:00
David Heinemeier Hansson 2bdf3fd450 Do all the upgrade work in that initial migration for old installations 2025-11-21 19:02:19 +01:00