The protected entrypoints revoked the sudo timestamp before installing their cleanup traps, so a signal or failure during that first sudo -k exited without the cleanup path. Install the traps first. The shell restart probed the notification bus name with busctl's default 25 second timeout, so an unresponsive user bus could stall the restart by that much per probe. Bound each probe to one second. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
51 lines
2.1 KiB
Bash
Executable File
51 lines
2.1 KiB
Bash
Executable File
#!/bin/bash -p
|
|
|
|
# omarchy:summary=Overwrite the package configuration for /etc/pacman with the Omarchy default of using its dedicated mirrors and repositories, then update all packages.
|
|
# omarchy:requires-sudo=true
|
|
|
|
if [[ $- != *p* ]]; then
|
|
echo "Refusing an unsafe Bash startup." >&2
|
|
exit 126
|
|
fi
|
|
|
|
security_entrypoint=$(/usr/bin/readlink -e -- "${BASH_SOURCE[0]}") || exit 126
|
|
source "${security_entrypoint%/*}/omarchy-security-functions" || exit 126
|
|
omarchy_security_require_privileged_bash_startup || exit 126
|
|
set -e
|
|
omarchy_security_sanitize_bash_environment "$0" "$@"
|
|
omarchy_security_require_source_root "$0"
|
|
# Channel switching calls this behind its own sanitized PATH and hands the
|
|
# caller's original path over the same way the updater receives it.
|
|
user_path=${OMARCHY_UPDATE_USER_PATH:-$PATH}
|
|
unset OMARCHY_UPDATE_USER_PATH
|
|
# Traps first, so a signal or failure during the entry revocation still
|
|
# exits through the cleanup path.
|
|
omarchy_security_install_sudo_cleanup_traps
|
|
omarchy_security_revoke_sudo_timestamp || exit 1
|
|
omarchy_security_enable_no_update_sudo
|
|
|
|
channel="${1:-stable}"
|
|
if [[ $channel != "stable" && $channel != "rc" && $channel != "edge" ]]; then
|
|
echo "Invalid channel: $channel" >&2
|
|
exit 2
|
|
fi
|
|
|
|
sudo cp -f /etc/pacman.conf /etc/pacman.conf.bak
|
|
sudo cp -f /etc/pacman.d/mirrorlist /etc/pacman.d/mirrorlist.bak
|
|
echo "Setting channel to $channel"
|
|
sudo cp -f "$OMARCHY_PATH/default/pacman/pacman-$channel.conf" /etc/pacman.conf
|
|
sudo cp -f "$OMARCHY_PATH/default/pacman/mirrorlist-$channel" /etc/pacman.d/mirrorlist
|
|
|
|
# Allow user customization of /etc/pacman.conf before the upgrade runs, so
|
|
# custom repositories and IgnorePkg entries shape the downgrade-capable
|
|
# transaction below. The hook is user code: it runs cold behind the no-update
|
|
# wrapper, and the timestamp is revoked again afterwards so any authorization
|
|
# the hook obtained for itself cannot carry into the transaction.
|
|
omarchy_security_revoke_sudo_timestamp
|
|
PATH="$OMARCHY_PATH/default/omarchy/sudo-no-update:$user_path" \
|
|
"$OMARCHY_PATH/bin/omarchy-hook" pre-refresh-pacman
|
|
omarchy_security_revoke_sudo_timestamp
|
|
|
|
# Reset all package DBs and then update
|
|
omarchy-update-pacman -Syyuu --noconfirm
|