The click action of a notification was a free-form shell string run through `bash -lc`, safe only when every sender shell-quoted every interpolated value perfectly. One slip is RCE: a hostile yt-dlp video title forged an output record and injected an mpv option into the click command (mehmetince.net RCE, partially addressed by #7847). Add a parameterized transport: omarchy-notification-send gains --exec-arg (repeatable), encoding a JSON argv into the omarchy-exec-argv hint. The shell runs it with Quickshell.execDetached(argv) and no shell, so data an attacker controls is only ever one argument and can never be reparsed as a command. The shell fails closed on a malformed argv hint. The legacy free-form --exec string is retained but honored only from Omarchy's own omarchy-action toasts, and deprecated. Migrate all in-repo callers (screenshot, screen recording, taildrop receive, migrate-notify, crash-watch, yt-dlp host) to --exec-arg. Update docs and tests.
61 lines
2.0 KiB
Bash
Executable File
61 lines
2.0 KiB
Bash
Executable File
#!/bin/bash
|
|
|
|
# omarchy:summary=Notify the user when Omarchy has pending migrations
|
|
|
|
set -euo pipefail
|
|
|
|
update_in_progress() {
|
|
local lock="${XDG_RUNTIME_DIR:-}/omarchy-update.lock"
|
|
|
|
[[ -n ${XDG_RUNTIME_DIR:-} && -f $lock ]] || return 1
|
|
|
|
# flock -n only fails here when the lock is held, since the file is ours.
|
|
! flock -n "$lock" true 2>/dev/null
|
|
}
|
|
|
|
if update_in_progress; then
|
|
exit 0
|
|
fi
|
|
|
|
pending_migrations=$(omarchy-migrate --pending 2>/dev/null) || exit 0
|
|
pending_count=$(printf '%s\n' "$pending_migrations" | sed '/^[[:space:]]*$/d' | wc -l)
|
|
|
|
if (( pending_count == 1 )); then
|
|
message="Click to run 1 pending migration."
|
|
else
|
|
message="Click to run $pending_count pending migrations."
|
|
fi
|
|
|
|
# This runs from omarchy-migrate-notify.service after graphical-session.target,
|
|
# but the target can be reached before the shell has claimed
|
|
# org.freedesktop.Notifications. Without the wait the toast is sent into the
|
|
# void and the user never learns about their pending migrations.
|
|
omarchy-notification-wait || true
|
|
|
|
# That wait is long enough for an update to start underneath us, and the count
|
|
# above is already stale by then, so re-check before spending the toast.
|
|
if update_in_progress; then
|
|
exit 0
|
|
fi
|
|
|
|
# The shell keeps the click command with the toast, so this oneshot can hand the
|
|
# invitation over and exit instead of staying activated until it is answered.
|
|
omarchy-notification-send -u critical -g "Pending Omarchy Migrations" "$message" \
|
|
--exec-arg omarchy-launch-floating-terminal-with-presentation --exec-arg omarchy-migrate && exit 0
|
|
|
|
# Reached when the notification could not be handed off, so fall back to telling
|
|
# the user in the terminal.
|
|
print_pending_migrations() {
|
|
echo "Omarchy has pending migrations. Run omarchy-migrate in a terminal to apply them:"
|
|
while IFS= read -r migration; do
|
|
[[ -n $migration ]] || continue
|
|
printf ' %s\n' "$migration"
|
|
done <<<"$pending_migrations"
|
|
}
|
|
|
|
if [[ -t 1 ]]; then
|
|
print_pending_migrations
|
|
else
|
|
print_pending_migrations >&2
|
|
fi
|