Files
omarchy/test/acceptance.d/system-test.sh
T
OmarchybotandClaude Opus 5 c0b593b349 Don't put the user in the docker group; make it opt-in (backport of #8056)
Backport of the docker group removal (PR #8056, merged to quattro as b5ded31e)
onto the v4-0-1 release branch.

The docker group is root-equivalent: anything in it can docker run -v /:/host
and rewrite the host as root with no password. On a single-user box that is not
an escalation -- the owner is already a wheel user -- but it hands any code
running as the user, a rogue plugin or a poisoned dependency, a silent,
headless, passwordless path to root that sudo's password prompt would otherwise
gate.

Stop granting the group by default. The daemon still runs, the Docker TUI and
the Windows VM reach it through a polkit prompt, and the plain docker CLI runs
under sudo. Sudoless Docker becomes a warned opt-in under Setup > Security, and
no automatic path re-grants it: install and first-boot provisioning never record
or apply the group, and the Quattro upgrade no longer adds it. A migration takes
existing installs out of the group, reusing omarchy-remove-security-sudoless-
docker so the change and its notice have one source of truth.

The Windows VM keeps needing the root daemon for a privileged container, so it
runs without the group without becoming a new way in: the compose moves to a
root-owned directory written only by an elevated, input-validated writer, volume
paths are rebuilt from $HOME on migration rather than trusted from the
user-writable legacy file, the privileged sub-action is checked against an
allowlist before dispatch, pkexec elevates a verified root-owned command path,
mount sources are refused when they are or resolve through a symlink, and the
guest password moves to a private 0600 per-user file instead of a
world-readable compose. Existing installs auto-migrate the VM without a
redownload.

Two files had diverged from quattro and were resolved by hand:

bin/omarchy-windows-vm -- v4-0-1 still carries the "Starting Windows VM" toast
that #7585 dropped on quattro, and the new start path has no user-side status
check to hang it on: after this change the user cannot inspect the container
without privilege, which is the whole point. Took quattro's version. #7585's
reason holds here too -- the shell shows its own "Launching Windows…" OSD until
the RDP window appears (shell/services/AppLibrary.qml) -- and the failure
notification stays. The file is now byte-identical to quattro.

manual/28-windows-vm.md -- took the new paragraph on the root-owned compose,
without the neighbouring OEM-key paragraph, which documents omarchy windows key,
a command quattro has and this branch does not.

test/shell passes here: 186 files, including the three this adds.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018DEMYa9UWtroz93DhMTtcV
2026-08-24 19:54:01 +02:00

117 lines
4.7 KiB
Bash

#!/bin/bash
set -euo pipefail
source "$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)/base-test.sh"
status=0
verify_core_packages() {
local package
local -a missing=()
while IFS= read -r package; do
[[ -z $package || $package == \#* ]] && continue
pacman -Q "$package" >/dev/null 2>&1 || missing+=("$package")
done <"$OMARCHY_PATH/install/omarchy-base.packages"
(( ${#missing[@]} == 0 )) || fail "all Omarchy core packages are installed" "missing packages: ${missing[*]}"
pass "all Omarchy core packages are installed (${#missing[@]} missing)"
}
verify_defaults() {
[[ $(omarchy-default-browser) == "chromium" ]] || fail "Chromium is the default browser"
pass "Chromium is the default browser"
[[ $(omarchy-default-terminal) == "foot" ]] || fail "Foot is the default terminal"
pass "Foot is the default terminal"
[[ $(omarchy-default-editor) == "nvim" ]] || fail "Neovim is the default editor"
pass "Neovim is the default editor"
[[ $(omarchy-theme-current) != "Unknown" ]] || fail "a current theme is configured"
pass "a current theme is configured"
[[ $(omarchy-theme-bg-current) != "Unknown" ]] || fail "a current background is configured"
pass "a current background is configured"
[[ -n $(omarchy-font-current) ]] || fail "a monospace font is configured"
pass "a monospace font is configured"
[[ $(xdg-mime query default x-scheme-handler/http) == "chromium.desktop" ]] || fail "HTTP MIME handling uses Chromium"
[[ $(xdg-mime query default inode/directory) == "org.gnome.Nautilus.desktop" ]] || fail "directory MIME handling uses Nautilus"
pass "desktop MIME handlers are configured"
}
verify_services() {
local unit
for unit in \
avahi-daemon.service cups.service cups-browsed.service docker.socket \
NetworkManager.service power-profiles-daemon.service sddm.service \
systemd-resolved.service ufw.service; do
systemctl is-enabled --quiet "$unit" || fail "core system services are enabled" "$unit is not enabled"
done
pass "core system services are enabled"
for unit in NetworkManager.service systemd-resolved.service ufw.service; do
systemctl is-active --quiet "$unit" || fail "critical system services are running" "$unit is not active"
done
pass "critical system services are running"
systemctl --user is-active --quiet pipewire.service pipewire-pulse.service wireplumber.service ||
fail "user audio services are running"
pass "user audio services are running"
}
verify_runtime_tools() {
# Docker access is intentionally NOT granted to the desktop user: the docker
# group is root-equivalent, so a rogue process running as the user could
# otherwise `docker run -v /:/host` its way to passwordless root. The daemon is
# still enabled (docker.socket, checked in verify_services) and reached through
# a polkit/sudo prompt; opting into sudoless Docker is a separate, warned step.
command -v docker >/dev/null 2>&1 || fail "Docker CLI is installed"
! id -nG | grep -qw docker || fail "desktop user must not be in the docker group"
# The group name being absent is not sufficient — a world-writable socket or an
# ACL would still hand the user the root daemon. Prove it is actually
# unreachable without elevation.
if timeout 10 docker info >/dev/null 2>&1; then
fail "desktop user must not reach the Docker daemon without elevation"
fi
pass "Docker is installed but unreachable by the desktop user without elevation"
nvim --headless '+qa' >/dev/null 2>&1 || fail "Neovim starts headlessly"
pass "Neovim starts headlessly"
timeout 10 fastfetch --pipe false >/dev/null 2>&1 || fail "Fastfetch can read system information"
pass "Fastfetch can read system information"
git --version >/dev/null || fail "Git is installed and runnable"
tmux -V >/dev/null || fail "Tmux is installed and runnable"
mise --version >/dev/null || fail "Mise is installed and runnable"
pass "core terminal tools are runnable"
}
verify_user_setup() {
local directory
for directory in DESKTOP DOCUMENTS DOWNLOAD PICTURES; do
[[ -d $(xdg-user-dir "$directory") ]] || fail "XDG user directories exist" "$directory is missing"
done
pass "XDG user directories exist"
[[ -e $HOME/.local/state/omarchy/current/theme ]] || fail "current theme state exists"
[[ -e $HOME/.local/state/omarchy/current/background ]] || fail "current background state exists"
[[ -s $HOME/.config/omarchy/shell.json ]] || fail "shell configuration exists"
jq empty "$HOME/.config/omarchy/shell.json" || fail "shell configuration is valid JSON"
pass "Omarchy user state and shell configuration exist"
}
for check in verify_core_packages verify_defaults verify_services verify_runtime_tools verify_user_setup; do
if ! ("$check"); then
status=1
fi
done
exit $status