An installer that writes a root-owned file through a heredoc with an unquoted delimiter (<<EOF rather than <<'EOF') has the installing user's shell expand the body first, so a user-controlled value is baked in as a literal. Send that into /etc and root later reads or executes a path the unprivileged user picked: a udev rule carrying $HOME/.local/share/omarchy/bin/... resolves through a symlink that user owns, so replacing the symlink gets their code run as root. Add the static check. A heredoc is flagged when its delimiter is unquoted, its body contains an install-time expansion (escaped \$VAR does not count, since that is left for a root daemon to expand at runtime), and its output reaches /etc, /usr, /opt, /srv, /boot or /var/lib via sudo tee, sudo dd, a redirect, or an install/cp/mv of the generated scratch file. Destinations written as variables are resolved from the file's own assignments. Sites that genuinely need install-time expansion declare it inline: # omarchy:heredoc-expands paths=none -- $servers is a validated IP list paths= is machine-checked against the expansions the scanner finds to be path-shaped, so this cannot become a rubber stamp: adding a $HOME/... to an already-annotated heredoc makes the declaration false and trips the check again. Path expansions anchored under a root-owned prefix, as in "/etc/systemd/system/$unit", are correctly not path-shaped. Annotate the sites the scan reports, each of which expands a scalar: DNS addresses in omarchy-dns, a literal PAM line in omarchy-setup-security-fingerprint, kernel cmdline parameters and usernames in omarchy-upgrade-to-quattro. omarchy-provision-owner expanded a unit name that was already a constant, so its delimiter is now quoted and the name hardcoded; the generated unit file is byte-identical. omarchy-windows-vm declares paths=storage,shared, the only site that interpolates a user-chosen path. Fixtures prove non-vacuity in both directions: the write routes other than a pipe into sudo tee, the shapes that must stay quiet, udev rules and a shutdown unit taken verbatim from this repository's history, and the rubber-stamp case where a paths=none annotation on a baked $HOME path still fails.
85 lines
2.5 KiB
Bash
85 lines
2.5 KiB
Bash
#!/usr/bin/env bash
|
|
|
|
# Install Plymouth package
|
|
echo "Installing Plymouth..."
|
|
yay -S --noconfirm --needed plymouth
|
|
|
|
# Skip if plymouth already exists for some reason
|
|
if ! grep -q "plymouth" /etc/mkinitcpio.conf; then
|
|
# Backup original mkinitcpio.conf just in case
|
|
backup_timestamp=$(date +"%Y%m%d%H%M%S")
|
|
sudo cp /etc/mkinitcpio.conf "/etc/mkinitcpio.conf.bak.${backup_timestamp}"
|
|
|
|
# Add plymouth to HOOKS array. Should be added:
|
|
# - After 'base' and 'udev' (or 'systemd' if using systemd hook)
|
|
# - Before 'encrypt' or 'sd-encrypt' if present
|
|
|
|
# Use sed to add plymouth in-place
|
|
if grep -q "systemd" /etc/mkinitcpio.conf; then
|
|
# Add after systemd
|
|
sudo sed -i '/^HOOKS=/s/systemd/systemd plymouth/' /etc/mkinitcpio.conf
|
|
elif grep -q "udev" /etc/mkinitcpio.conf; then
|
|
# Add after udev
|
|
sudo sed -i '/^HOOKS=/s/udev/udev plymouth/' /etc/mkinitcpio.conf
|
|
else
|
|
# Fallback: add after base
|
|
sudo sed -i '/^HOOKS=/s/base/base plymouth/' /etc/mkinitcpio.conf
|
|
fi
|
|
fi
|
|
|
|
# Regenerate initramfs
|
|
sudo mkinitcpio -P
|
|
|
|
# Add kernel parameters for Plymouth (systemd-boot only)
|
|
if [ -d "/boot/loader/entries" ]; then
|
|
echo "Detected systemd-boot"
|
|
|
|
for entry in /boot/loader/entries/*.conf; do
|
|
if [ -f "$entry" ]; then
|
|
# Skip fallback entries
|
|
if [[ "$(basename "$entry")" == *"fallback"* ]]; then
|
|
echo "Skipped: $(basename "$entry") (fallback entry)"
|
|
continue
|
|
fi
|
|
|
|
# Skip if splash it already present for some reason
|
|
if ! grep -q "splash" "$entry"; then
|
|
sudo sed -i '/^options/ s/$/ splash quiet/' "$entry"
|
|
else
|
|
echo "Skipped: $(basename "$entry") (splash already present)"
|
|
fi
|
|
fi
|
|
done
|
|
else
|
|
echo ""
|
|
echo "systemd-boot not detected. Please manually add these kernel parameters:"
|
|
echo " - splash (to see the graphical splash screen)"
|
|
echo " - quiet (for silent boot)"
|
|
echo ""
|
|
fi
|
|
|
|
# Touch .plymouth-sync-needed to signal rebuild on shutdown / reboot
|
|
touch "$HOME/.config/omarchy/.plymouth-sync-needed"
|
|
|
|
# Create the systemd service
|
|
sudo tee /etc/systemd/system/omarchy-plymouth-shutdown.service >/dev/null <<EOF
|
|
[Unit]
|
|
Description=Sync Plymouth Theme on Shutdown
|
|
DefaultDependencies=yes
|
|
After=network-online.target
|
|
|
|
[Service]
|
|
Type=oneshot
|
|
RemainAfterExit=yes
|
|
ExecStart=/bin/true
|
|
ExecStop=$HOME/.local/share/omarchy/bin/omarchy-plymouth-shutdown-sync
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|
|
EOF
|
|
|
|
# Reload systemd and enable the service
|
|
sudo systemctl daemon-reload
|
|
sudo systemctl enable omarchy-plymouth-shutdown.service
|
|
sudo systemctl start omarchy-plymouth-shutdown.service
|