Add checkout bin to sudoers path

This commit is contained in:
Ryan Hughes
2026-08-11 11:04:50 -04:00
parent 5817feb93f
commit 05bb82b34e
6 changed files with 218 additions and 0 deletions
+43
View File
@@ -14,6 +14,15 @@ fi
prompt_reboot=1
# sudo resolves a bare command name against secure_path, never the caller's
# PATH, so a dev-linked checkout is invisible to `sudo omarchy-*`: a command the
# package does not ship yet fails outright, and one it does ship silently runs
# the packaged copy while every unprivileged call runs the checkout. Prepending
# the checkout's bin keeps root on the code being edited — the same trust the
# link already extends to every system script Omarchy runs out of $OMARCHY_PATH.
sudoers_file="/etc/sudoers.d/omarchy-dev-path"
system_secure_path="/usr/local/sbin:/usr/local/bin:/usr/bin"
if (( $# < 1 || $# > 2 )) || [[ $1 == "-h" || $1 == "--help" ]]; then
cat <<USAGE
Usage: omarchy dev link <path-to-checkout> [--no-reboot]
@@ -28,6 +37,10 @@ themes/, applications/, config/. Files installed at fixed system paths
creation, /usr/share/plymouth) are NOT covered — for those, use
omarchy-dev-pkg-test to build and install the package from the checkout.
Also writes $sudoers_file so sudo resolves omarchy-*
from the checkout instead of the packaged copies. That part takes effect
immediately, no reboot needed.
Use --no-reboot when another command will handle the reboot prompt.
USAGE
exit 0
@@ -51,6 +64,16 @@ omarchy_conf_quote() {
printf '"%s"' "$value"
}
# A double-quoted sudoers string takes a backslash escape for a literal
# backslash or quote, and nothing else — a checkout path with a space in it is
# already covered by the quotes.
sudoers_quote() {
local value="$1"
value=${value//\\/\\\\}
value=${value//\"/\\\"}
printf '"%s"' "$value"
}
target=$(realpath -e "$1" 2>/dev/null) || {
echo "Error: path does not exist: $1" >&2
exit 1
@@ -62,13 +85,33 @@ for required in bin default shell; do
fi
done
# Staged and parsed before anything is installed: a sudoers file sudo refuses to
# read takes every rule after it down with it, including the %wheel grant, and
# the password prompt needed to undo that is on the other side of the breakage.
staged_sudoers=$(mktemp)
trap 'rm -f "$staged_sudoers"' EXIT
{
printf 'Defaults secure_path='
sudoers_quote "$target/bin:$system_secure_path"
printf '\n'
} >"$staged_sudoers"
if ! visudo -cf "$staged_sudoers" >/dev/null; then
echo "Error: refusing to install an invalid $sudoers_file for $target" >&2
exit 1
fi
{
printf 'export OMARCHY_PATH='
omarchy_conf_quote "$target"
printf '\n'
} | sudo tee /etc/omarchy.conf >/dev/null
sudo install -Dm440 -o root -g root "$staged_sudoers" "$sudoers_file"
echo "Pointed Omarchy at $target"
echo "sudo now resolves omarchy-* from $target/bin"
echo
if (( prompt_reboot )) && gum confirm "Reboot now to activate?"; then
+22
View File
@@ -6,6 +6,7 @@
set -euo pipefail
default_target="/usr/share/omarchy"
sudoers_file="/etc/sudoers.d/omarchy-dev-path"
configured="$default_target"
conf_present=0
linked=0
@@ -23,9 +24,30 @@ if [[ -f /etc/omarchy.conf ]]; then
fi
fi
# /etc/sudoers.d is root-only, so report what sudo resolves rather than reading
# the drop-in — and say so plainly instead of guessing when there is no cached
# credential to ask with. A missing entry here is what makes `sudo omarchy-*`
# run the packaged copy of a command the checkout has changed.
sudo_bin_dir() {
local resolved
if ! sudo -n true 2>/dev/null; then
echo "unknown (needs sudo)"
return
fi
resolved=$(sudo -n bash -c 'type -P omarchy-dev-status' 2>/dev/null) || {
echo "not on sudo's PATH"
return
}
dirname "$resolved"
}
if (( linked )); then
echo "dev-link: configured"
echo " /etc/omarchy.conf -> OMARCHY_PATH=$configured"
echo " sudo resolves omarchy-* from: $(sudo_bin_dir)"
echo " status: reboot required before all session layers use this checkout"
else
echo "dev-link: inactive"
+10
View File
@@ -13,6 +13,8 @@ fi
prompt_reboot=1
sudoers_file="/etc/sudoers.d/omarchy-dev-path"
if (( $# > 1 )); then
echo "Usage: omarchy dev unlink [--no-reboot]" >&2
exit 1
@@ -32,6 +34,9 @@ Writes /etc/omarchy.conf so OMARCHY_PATH resolves to /usr/share/omarchy
after reboot. This intentionally does not rewrite the running Hyprland,
systemd, shell, or app-launcher environment; reboot to make every layer agree.
Removes $sudoers_file, the drop-in that pointed sudo
at the checkout, so sudo goes back to the packaged omarchy-* immediately.
Use --no-reboot when another command will handle the reboot prompt.
USAGE
exit 0
@@ -46,6 +51,11 @@ default_target="/usr/share/omarchy"
printf 'export OMARCHY_PATH="%s"\n' "$default_target" | sudo tee /etc/omarchy.conf >/dev/null
# omarchy-dev-link prepended the checkout to sudo's secure_path. Drop it in the
# same step that drops the checkout, or sudo keeps running a tree nothing else
# points at — and keeps trusting a user-writable directory for root's commands.
sudo rm -f "$sudoers_file"
echo "Pointed Omarchy at $default_target"
echo