Add checkout bin to sudoers path

This commit is contained in:
Ryan Hughes
2026-08-11 11:04:50 -04:00
parent 5817feb93f
commit 05bb82b34e
6 changed files with 218 additions and 0 deletions
+43
View File
@@ -14,6 +14,15 @@ fi
prompt_reboot=1
# sudo resolves a bare command name against secure_path, never the caller's
# PATH, so a dev-linked checkout is invisible to `sudo omarchy-*`: a command the
# package does not ship yet fails outright, and one it does ship silently runs
# the packaged copy while every unprivileged call runs the checkout. Prepending
# the checkout's bin keeps root on the code being edited — the same trust the
# link already extends to every system script Omarchy runs out of $OMARCHY_PATH.
sudoers_file="/etc/sudoers.d/omarchy-dev-path"
system_secure_path="/usr/local/sbin:/usr/local/bin:/usr/bin"
if (( $# < 1 || $# > 2 )) || [[ $1 == "-h" || $1 == "--help" ]]; then
cat <<USAGE
Usage: omarchy dev link <path-to-checkout> [--no-reboot]
@@ -28,6 +37,10 @@ themes/, applications/, config/. Files installed at fixed system paths
creation, /usr/share/plymouth) are NOT covered — for those, use
omarchy-dev-pkg-test to build and install the package from the checkout.
Also writes $sudoers_file so sudo resolves omarchy-*
from the checkout instead of the packaged copies. That part takes effect
immediately, no reboot needed.
Use --no-reboot when another command will handle the reboot prompt.
USAGE
exit 0
@@ -51,6 +64,16 @@ omarchy_conf_quote() {
printf '"%s"' "$value"
}
# A double-quoted sudoers string takes a backslash escape for a literal
# backslash or quote, and nothing else — a checkout path with a space in it is
# already covered by the quotes.
sudoers_quote() {
local value="$1"
value=${value//\\/\\\\}
value=${value//\"/\\\"}
printf '"%s"' "$value"
}
target=$(realpath -e "$1" 2>/dev/null) || {
echo "Error: path does not exist: $1" >&2
exit 1
@@ -62,13 +85,33 @@ for required in bin default shell; do
fi
done
# Staged and parsed before anything is installed: a sudoers file sudo refuses to
# read takes every rule after it down with it, including the %wheel grant, and
# the password prompt needed to undo that is on the other side of the breakage.
staged_sudoers=$(mktemp)
trap 'rm -f "$staged_sudoers"' EXIT
{
printf 'Defaults secure_path='
sudoers_quote "$target/bin:$system_secure_path"
printf '\n'
} >"$staged_sudoers"
if ! visudo -cf "$staged_sudoers" >/dev/null; then
echo "Error: refusing to install an invalid $sudoers_file for $target" >&2
exit 1
fi
{
printf 'export OMARCHY_PATH='
omarchy_conf_quote "$target"
printf '\n'
} | sudo tee /etc/omarchy.conf >/dev/null
sudo install -Dm440 -o root -g root "$staged_sudoers" "$sudoers_file"
echo "Pointed Omarchy at $target"
echo "sudo now resolves omarchy-* from $target/bin"
echo
if (( prompt_reboot )) && gum confirm "Reboot now to activate?"; then