By name, the sudo call resolved through secure_path, which puts /usr/local/bin ahead of /usr/bin and falls back to the caller's PATH where no secure_path is set, so an install could run a different helper than the pinned path did. $OMARCHY_PATH/bin is the package's symlink into /usr/bin on an install and the checkout under a dev link, so neither PATH nor secure_path takes part. Co-Authored-By: Codex XHigh <noreply@openai.com>
10 lines
413 B
Bash
10 lines
413 B
Bash
echo "Remove legacy temporary passwordless sudo grants"
|
|
|
|
# Migration queues are per-user; the privileged repair is once per machine.
|
|
# The helper beside this migration: the package's /usr/bin copy on an install,
|
|
# and under a dev link the checkout's, which may be newer than the package.
|
|
helper="$OMARCHY_PATH/bin/omarchy-sudo-passwordless"
|
|
if ! "$helper" __migration-complete; then
|
|
sudo "$helper" __migrate
|
|
fi
|