#!/bin/bash # omarchy:hidden=true # omarchy:summary=Provide internal helpers for command-scoped sudo authentication if [[ ${BASH_SOURCE[0]} == "$0" ]]; then echo "omarchy-security-functions is an internal function library." >&2 exit 64 fi omarchy_security_require_privileged_bash_startup() { [[ $- == *p* ]] || return 1 /usr/bin/env -i /usr/bin/bash -p -c ' mapfile -d "" -t argv <"/proc/$1/cmdline" || exit 1 executable=$(/usr/bin/readlink -e -- "/proc/$1/exe") || exit 1 [[ $executable == "/usr/bin/bash" && ( ${argv[0]:-} == "/bin/bash" || ${argv[0]:-} == "/usr/bin/bash" ) && ${argv[1]:-} == "-p" ]] ' omarchy-bash-startup "$$" } omarchy_security_sanitize_bash_environment() { local script=$1 shift local entry name environment_fd environment_pid local -a unsets=() # Read the raw environment: privileged Bash ignores exported functions, but # leaves their records for ordinary child interpreters to import later. exec {environment_fd}< <(/usr/bin/env -0) environment_pid=$! while IFS= read -r -d '' entry <&"$environment_fd"; do name=${entry%%=*} case "$name" in BASH_ENV|ENV|SHELLOPTS|BASHOPTS|PS4|CDPATH|GLOBIGNORE|BASH_FUNC_*%%) unsets+=(-u "$name") ;; esac done exec {environment_fd}<&- wait "$environment_pid" || return 1 if (( ${#unsets[@]} > 0 )); then exec /usr/bin/env "${unsets[@]}" /usr/bin/bash -p -- "$script" "$@" fi } omarchy_security_sudo_supports_no_update() { local help help=$(LC_ALL=C /usr/bin/sudo -h 2>&1) || return 1 /usr/bin/grep -Eq '^usage: sudo .*\[[^]]*N[^]]*\]' <<< "$help" } omarchy_security_revoke_sudo_timestamp() { /usr/bin/sudo -k } omarchy_security_exit_with_revoked_sudo() { local status=$1 trap - EXIT HUP INT TERM if ! omarchy_security_revoke_sudo_timestamp; then echo "Could not invalidate cached sudo authorization." >&2 (( status != 0 )) || status=1 fi exit "$status" } omarchy_security_install_signal_exit_traps() { trap 'exit 129' HUP trap 'exit 130' INT trap 'exit 143' TERM } omarchy_security_install_sudo_cleanup_traps() { trap 'omarchy_security_exit_with_revoked_sudo "$?"' EXIT omarchy_security_install_signal_exit_traps } omarchy_security_enable_no_update_sudo() { local wrapper_dir="$OMARCHY_PATH/default/omarchy/sudo-no-update" if ! omarchy_security_sudo_supports_no_update; then echo "This sudo does not support --no-update; refusing mixed-trust work." >&2 return 1 fi if [[ ! -f $wrapper_dir/sudo || ! -x $wrapper_dir/sudo ]]; then echo "The command-scoped sudo wrapper is missing." >&2 return 1 fi PATH="$wrapper_dir:$OMARCHY_PATH/bin:/usr/bin:/usr/sbin:/bin:/sbin" OMARCHY_SUDO_NO_UPDATE=1 export PATH OMARCHY_SUDO_NO_UPDATE }