Make --exec take the command as rest-of-line words

Replace --exec-arg with an ergonomic --exec that consumes the rest of the line
as the click command. The caller's shell tokenizes the words into discrete
arguments before the tool sees them, and the shell runs them as positional
parameters (never a re-parsed string), so safety is identical to the argv form
while the call sites read naturally: `--exec omarchy toggle something`.

Crucially the tool never splits a string itself — a single quoted whole-command
argument is rejected and points at the unquoted form, because whitespace-
splitting a string hands argument boundaries to whoever controls its content
(the injection we are avoiding). --exec must come last; migrate every caller.
This commit is contained in:
Ryan Hughes
2026-08-23 14:26:25 -04:00
parent eb988b42e6
commit bf2013e6f3
21 changed files with 148 additions and 113 deletions
+5 -4
View File
@@ -32,16 +32,17 @@ announce() {
# likely to be delivered is the one most worth reporting.
omarchy-notification-wait || return 1
# --exec-arg rather than a libnotify action: the shell runs clicks from its own
# --exec rather than a libnotify action: the shell runs clicks from its own
# hint and never emits ActionInvoked. Keeps the default "omarchy-action" app
# name, the only one shouldBypassDnd() lets through. Crash details ride as
# literal argv, so a hostile process name can't be reparsed as a command.
# discrete argv words, so a hostile process name can't be reparsed as a
# command. --exec consumes the rest of the line, so it comes last.
omarchy-notification-send \
--urgency critical \
--glyph "$CRASH_GLYPH" \
--exec-arg omarchy-agent-crash --exec-arg "$pid" --exec-arg "$comm" --exec-arg "$exe" --exec-arg "$signal" \
"Process crashed: $comm" \
"Click to diagnose with AI"
"Click to diagnose with AI" \
--exec omarchy-agent-crash "$pid" "$comm" "$exe" "$signal"
}
# -n 0 so a restart does not re-announce crashes already dealt with.