Backport of the reboot flag (PR #8080, merged to quattro as 1565919c) onto the
v4-0-1 release branch, on top of the #8056 backport it follows.
Group membership is fixed at login, so removing (or adding) the docker group
does not take effect in the running session. The existing-user migration and the
Setup > Security toggles now call omarchy-state set reboot-required, so
omarchy-update-restart prompts for the reboot that actually applies the change
and the bar shows it pending. A plain log out and back in still works.
The migration test now exercises the real removal command and omarchy-state
rather than a stub, asserting the reboot flag is set on removal and left alone
when the user is already out of the group.
Clean cherry-pick on top of the #8056 backport: all three files are
byte-identical to quattro, so merging v4-0-1 into quattro resolves without a
conflict. omarchy-state and omarchy-update-restart are unchanged on this branch
and read the same ~/.local/state/omarchy/reboot-required marker. test/shell
passes: 186 files.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018DEMYa9UWtroz93DhMTtcV
75 lines
3.3 KiB
Bash
75 lines
3.3 KiB
Bash
#!/bin/bash
|
|
#
|
|
# The docker-group opt-in migration must remove an existing install's user from
|
|
# the root-equivalent docker group (only when they are in it), flag a reboot so
|
|
# the group change actually takes effect (group membership is fixed at login),
|
|
# refresh the stale Docker launcher entry, and stay idempotent on reruns.
|
|
#
|
|
# The real omarchy-remove-security-sudoless-docker and omarchy-state run here
|
|
# (from the repo bin); only the privileged/system calls are stubbed, so the whole
|
|
# chain — including the reboot flag — is exercised.
|
|
|
|
set -euo pipefail
|
|
|
|
source "$(dirname "${BASH_SOURCE[0]}")/base-test.sh"
|
|
|
|
migration="$ROOT/migrations/1787580187.sh"
|
|
test_dir=$(mktemp -d)
|
|
trap 'rm -rf "$test_dir"' EXIT
|
|
|
|
home="$test_dir/home"
|
|
omarchy_path="$test_dir/omarchy"
|
|
stub_bin="$test_dir/bin"
|
|
mkdir -p "$home/.local/share/applications" "$omarchy_path/applications" "$stub_bin"
|
|
|
|
printf 'NEW-LAUNCHER\n' >"$omarchy_path/applications/Docker.desktop"
|
|
printf 'OLD-LAUNCHER\n' >"$home/.local/share/applications/Docker.desktop"
|
|
|
|
# id reports a controllable group set; sudo just drops the prefix; gpasswd
|
|
# records its call instead of touching the real system.
|
|
cat >"$stub_bin/id" <<'STUB'
|
|
#!/bin/bash
|
|
printf '%s\n' "${STUB_GROUPS:-wheel input}"
|
|
STUB
|
|
cat >"$stub_bin/sudo" <<'STUB'
|
|
#!/bin/bash
|
|
exec "$@"
|
|
STUB
|
|
cat >"$stub_bin/gpasswd" <<'STUB'
|
|
#!/bin/bash
|
|
echo "$@" >>"${GPASSWD_CALLS:?}"
|
|
STUB
|
|
chmod +x "$stub_bin/id" "$stub_bin/sudo" "$stub_bin/gpasswd"
|
|
|
|
reboot_flag="$home/.local/state/omarchy/reboot-required"
|
|
gpasswd_calls="$test_dir/gpasswd-calls"
|
|
launcher="$home/.local/share/applications/Docker.desktop"
|
|
|
|
run_migration() {
|
|
rm -f "$gpasswd_calls" "$reboot_flag"
|
|
HOME="$home" OMARCHY_PATH="$omarchy_path" USER="tester" STUB_GROUPS="$1" \
|
|
GPASSWD_CALLS="$gpasswd_calls" PATH="$stub_bin:$ROOT/bin:$PATH" \
|
|
bash -euo pipefail "$migration" >/dev/null 2>&1
|
|
}
|
|
|
|
# In the docker group: user removed, reboot flagged, launcher refreshed.
|
|
run_migration "wheel input docker" || fail "migration runs when the user is in the docker group"
|
|
grep -q -- "-d tester docker" "$gpasswd_calls" || fail "migration removes the user from the docker group"
|
|
[[ -f $reboot_flag ]] || fail "migration flags a reboot so the group change takes effect"
|
|
[[ $(cat "$launcher") == "NEW-LAUNCHER" ]] || fail "migration refreshes the stale Docker launcher entry"
|
|
pass "migration removes the group, flags a reboot, and refreshes the launcher"
|
|
|
|
# Not in the docker group (fresh install, or already migrated): nothing changes.
|
|
printf 'OLD-LAUNCHER\n' >"$launcher"
|
|
run_migration "wheel input" || fail "migration runs when the user is not in the docker group"
|
|
[[ ! -f $gpasswd_calls ]] || fail "migration must not touch the group when the user is not in it"
|
|
[[ ! -f $reboot_flag ]] || fail "migration must not flag a reboot when nothing changed"
|
|
[[ $(cat "$launcher") == "NEW-LAUNCHER" ]] || fail "migration still refreshes the launcher when the group is already absent"
|
|
pass "migration is a no-op on the group and reboot when already out"
|
|
|
|
# No launcher entry present: the refresh is skipped without error.
|
|
rm -f "$launcher"
|
|
run_migration "wheel input" || fail "migration tolerates a missing launcher entry"
|
|
[[ ! -e $launcher ]] || fail "migration does not create a launcher entry that was not there"
|
|
pass "migration skips the launcher refresh when no entry exists"
|