Files
omarchy/test/shell.d/theme-set-browser-test.sh
T
fd961e5300 Speed up the theme switch's browser refresh (#13038)
* Speed up theme switch by backgrounding preload and parallelizing browser refresh

`omarchy theme set` was blocking on `omarchy-theme-switcher --preload` (~1.1s)
and serially refreshing every Chromium-family browser (~1.0-1.5s), making a
picked theme feel slow even though the shell recolored instantly.

- Background `omarchy-theme-switcher --preload` like the background cache
- In `omarchy-theme-set-browser`, skip the privileged policy write and browser
  refreshes when every existing `color.json` already has the requested color
- Refresh only running browsers, and run those refreshes in parallel

Fixes #12627.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* Harden the unchanged-color shortcut in omarchy-theme-set-browser

Review feedback identified that the original shortcut could vacuously skip
when no managed policy directories existed, and that it accepted a color.json
whose ownership or contents the privileged writer would have rewritten.

- Only skip when at least one managed directory exists and every existing
  color.json is a regular, root-owned 0644 file containing the canonical JSON
- Add OMARCHY_BROWSER_POLICY_DIRS as a test-only override so the setter's
  unchanged-color check does not depend on the host's real /etc policy files
- Update browser-policy-sudoers-test.sh to use that override, and make
  theme-set-browser-test.sh behavioral rather than grep-only

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* Find running browsers with one process scan during the policy write

Each browser check ran its own pgrep, and every pgrep rescans /proc,
~40ms apiece. Read the process table once with ps while the policy
writer runs, keeping its stdin so a terminal sudo prompt stays in the
terminal, then refresh the running browsers in parallel.

Chrome's fallback to plain google-chrome never ran: the refresh helper
returned success for a missing browser, so the || branch was dead. Pick
whichever Chrome binary exists up front instead.

The unchanged-color shortcut keeps its root:root 0644 check without the
fallback for hosts lacking stat -c, which Omarchy never runs on. Its
tests stub stat, ps and command discovery, so they neither depend on
nor touch the host's browsers.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-27 16:24:04 +02:00

131 lines
4.9 KiB
Bash
Executable File

#!/bin/bash
set -euo pipefail
source "$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)/base-test.sh"
TMPDIR=$(mktemp -d)
TMP_BIN="$TMPDIR/bin"
CALL_LOG="$TMPDIR/calls.txt"
trap 'rm -rf "$TMPDIR"' EXIT
mkdir -p "$TMP_BIN"
# No browser is running unless a case says so, so the policy cases never
# refresh a real browser on the host.
cat > "$TMP_BIN/ps" <<'FAKE'
#!/bin/bash
exit 0
FAKE
chmod +x "$TMP_BIN/ps"
# Stub the privileged writer so we can observe whether the setter calls it.
cat > "$TMP_BIN/omarchy-theme-set-browser-policy" <<'FAKE'
#!/bin/bash
printf '%s\n' "$*" >> "${CALL_LOG:?}"
exit 0
FAKE
chmod +x "$TMP_BIN/omarchy-theme-set-browser-policy"
# A policy directory that already carries the target color, so the setter can
# skip everything.
policy_tmp="$TMPDIR/policies"
mkdir -p "$policy_tmp"
printf '{"BrowserThemeColor": "#1c2027", "BrowserColorScheme": "device"}\n' > "$policy_tmp/color.json"
# A test cannot make a root-owned file, so stat reports the owner the writer
# leaves behind, or a user-owned one.
stat_bin="$TMPDIR/stat-bin"
mkdir -p "$stat_bin"
cat >"$stat_bin/stat" <<'FAKE'
#!/bin/bash
printf '%s\n' "${STAT_OWNER:?}"
FAKE
chmod +x "$stat_bin/stat"
# No theme file -> fallback color #1c2027, which matches the fixture.
HOME="$TMPDIR" PATH="$stat_bin:$TMP_BIN:$ROOT/bin:$PATH" OMARCHY_PATH="$ROOT" STAT_OWNER="root:root 644" \
OMARCHY_BROWSER_POLICY_DIRS="$policy_tmp" CALL_LOG="$CALL_LOG" \
bash "$ROOT/bin/omarchy-theme-set-browser" >/dev/null
if [[ -e $CALL_LOG ]]; then
fail "setter skipped the privileged write when color.json already matches"
fi
pass "setter skips the privileged write when color.json already matches"
# The same color in a file the writer did not leave behind is not trusted.
HOME="$TMPDIR" PATH="$stat_bin:$TMP_BIN:$ROOT/bin:$PATH" OMARCHY_PATH="$ROOT" STAT_OWNER="user:user 666" \
OMARCHY_BROWSER_POLICY_DIRS="$policy_tmp" CALL_LOG="$CALL_LOG" \
bash "$ROOT/bin/omarchy-theme-set-browser" >/dev/null
if [[ ! -e $CALL_LOG ]]; then
fail "setter rewrites a matching color.json that is not root-owned 0644"
fi
pass "setter rewrites a matching color.json that is not root-owned 0644"
# Now point it at a policy dir whose color.json does not match.
rm -f "$CALL_LOG"
printf '{"BrowserThemeColor": "#ff0000"}\n' > "$policy_tmp/color.json"
HOME="$TMPDIR" PATH="$TMP_BIN:$ROOT/bin:$PATH" OMARCHY_PATH="$ROOT" \
OMARCHY_BROWSER_POLICY_DIRS="$policy_tmp" CALL_LOG="$CALL_LOG" \
bash "$ROOT/bin/omarchy-theme-set-browser" >/dev/null
if [[ ! -e $CALL_LOG ]]; then
fail "setter invoked the privileged writer when color.json mismatched"
fi
pass "setter invokes the privileged writer when color.json mismatches"
# No managed policy dirs at all must not vacuously skip the writer.
rm -f "$CALL_LOG"
HOME="$TMPDIR" PATH="$TMP_BIN:$ROOT/bin:$PATH" OMARCHY_PATH="$ROOT" \
OMARCHY_BROWSER_POLICY_DIRS="$TMPDIR/nonexistent" CALL_LOG="$CALL_LOG" \
bash "$ROOT/bin/omarchy-theme-set-browser" >/dev/null
if [[ ! -e $CALL_LOG ]]; then
fail "setter invoked the privileged writer when no managed dirs exist"
fi
pass "setter invokes the privileged writer when no managed dirs exist"
# Refreshes go to exactly the running browsers. ps is stubbed with a process
# table; each browser command logs its refresh.
browser_bin="$TMPDIR/browser-bin"
mkdir -p "$browser_bin"
cat >"$browser_bin/ps" <<'FAKE'
#!/bin/bash
printf '%s\n' \
'chromium /usr/lib/chromium/chromium --type=renderer' \
'chrome /opt/google/chrome/chrome' \
'brave /opt/brave-origin-bin/brave --profile' \
'bash bash -c pgrep -f brave'
FAKE
for command in chromium google-chrome microsoft-edge-stable brave brave-origin; do
printf '#!/bin/bash\nprintf "%%s\\n" "%s" >>"$REFRESH_LOG"\n' "$command" >"$browser_bin/$command"
done
# Only the stubs count as installed, so a real browser on the host, such as
# google-chrome-stable, is neither preferred nor launched.
cat >"$browser_bin/omarchy-cmd-present" <<'FAKE'
#!/bin/bash
[[ -x ${BROWSER_BIN:?}/$1 ]]
FAKE
chmod +x "$browser_bin"/*
printf '{"BrowserThemeColor": "#ff0000"}\n' >"$policy_tmp/color.json"
refresh_log="$TMPDIR/refreshes"
HOME="$TMPDIR" PATH="$browser_bin:$TMP_BIN:$ROOT/bin:$PATH" OMARCHY_PATH="$ROOT" \
OMARCHY_BROWSER_POLICY_DIRS="$policy_tmp" CALL_LOG="$CALL_LOG" REFRESH_LOG="$refresh_log" BROWSER_BIN="$browser_bin" \
bash "$ROOT/bin/omarchy-theme-set-browser" >/dev/null
refreshed=$(sort "$refresh_log" | tr '\n' ' ')
# Chrome running as plain google-chrome is refreshed through that name; Edge is
# installed but not running; brave-origin matches on its binary path, and the
# running "brave" process refreshes plain brave too.
[[ $refreshed == "brave brave-origin chromium google-chrome " ]] ||
fail "setter refreshes exactly the running browsers (got: $refreshed)"
pass "setter refreshes exactly the running browsers"
grep -q '<&0 &$' "$ROOT/bin/omarchy-theme-set-browser" ||
fail "setter keeps stdin for the backgrounded policy writer"
pass "setter keeps stdin for the backgrounded policy writer"