#!/bin/bash # omarchy:summary=Apply the current theme color to Chromium, Chrome, Edge, and Brave # omarchy:hidden=true source "$OMARCHY_PATH/install/helpers/browser-policy.sh" CHROMIUM_THEME=$HOME/.local/state/omarchy/current/theme/chromium.theme THEME_HEX_COLOR=$BROWSER_POLICY_DEFAULT_COLOR if [[ -f $CHROMIUM_THEME ]]; then THEME_HEX_COLOR=$(browser_policy_theme_hex "$(<$CHROMIUM_THEME)") fi # Tests override this with a temporary directory list; production uses the # fixed trust-root set from browser-policy.sh. POLICY_DIRS=("${BROWSER_POLICY_MANAGED_DIRS[@]}") if [[ -n ${OMARCHY_BROWSER_POLICY_DIRS:-} ]]; then POLICY_DIRS=() while IFS= read -r dir; do POLICY_DIRS+=("$dir") done <<< "$OMARCHY_BROWSER_POLICY_DIRS" fi # A managed color.json is already correct only when it is a regular, root-owned # file with mode 0644 containing exactly the canonical JSON for the requested # color. file_is_canonical() { local file=$1 [[ -f $file && ! -L $file ]] || return 1 [[ $(<"$file") == "$expected_json" ]] || return 1 [[ $(stat -c '%U:%G %a' "$file") == "root:root 644" ]] } # Skip the privileged policy write and browser refreshes entirely when every # existing managed color.json is already canonical. The writer only touches # directories that exist, so a browser installed since then has no color.json # yet and takes the write. expected_json='{"BrowserThemeColor": "'$THEME_HEX_COLOR'", "BrowserColorScheme": "device"}' saw_any=false all_unchanged=true for dir in "${POLICY_DIRS[@]}"; do [[ -d $dir && ! -L $dir ]] || continue saw_any=true if ! file_is_canonical "$dir/color.json"; then all_unchanged=false break fi done $saw_any && $all_unchanged && exit 0 failed=0 # A script's background job reads /dev/null unless told otherwise, which would # turn the writer's terminal sudo prompt into a pkexec dialog. Keep stdin. omarchy-theme-set-browser-policy "${THEME_HEX_COLOR#\#}" <&0 & policy_pid=$! # While the policy writes, find the running browsers with one process table # read. A pgrep per browser rescans /proc each time, ~40ms apiece. declare -A running_names=() running_args="" while read -r name args; do running_names[$name]=1 running_args+="$args"$'\n' done < <(ps -eo comm=,args=) # Chrome installs as either binary name, so take whichever exists. chrome=google-chrome-stable omarchy-cmd-present "$chrome" || chrome=google-chrome browsers_to_refresh=() for browser in chromium:chromium "chrome:$chrome" msedge:microsoft-edge-stable brave:brave; do [[ -n ${running_names[${browser%%:*}]:-} ]] && omarchy-cmd-present "${browser#*:}" && browsers_to_refresh+=("${browser#*:}") done # Match on the binary path: the running process is named plain "brave", and a # bare brave-origin pattern would also match the installer's own terminal. [[ $running_args == *"/opt/brave-origin-bin/"* ]] && omarchy-cmd-present brave-origin && browsers_to_refresh+=(brave-origin) wait "$policy_pid" || failed=1 # Refresh each running browser in parallel, so one slow launch doesn't # serialize the rest. refresh_pids=() for command in "${browsers_to_refresh[@]}"; do "$command" --refresh-platform-policy --no-startup-window &>/dev/null & refresh_pids+=("$!") done for pid in "${refresh_pids[@]}"; do wait "$pid" done exit "$failed"