Files
omarchycn/bin/omarchy-migrate-notify
T
Ryan Hughes 07443f3970 Run notification click actions as argv, not shell strings
The click action of a notification was a free-form shell string run through
`bash -lc`, safe only when every sender shell-quoted every interpolated value
perfectly. One slip is RCE: a hostile yt-dlp video title forged an output
record and injected an mpv option into the click command (mehmetince.net RCE,
partially addressed by #7847).

Add a parameterized transport: omarchy-notification-send gains --exec-arg
(repeatable), encoding a JSON argv into the omarchy-exec-argv hint. The shell
runs it with Quickshell.execDetached(argv) and no shell, so data an attacker
controls is only ever one argument and can never be reparsed as a command. The
shell fails closed on a malformed argv hint.

The legacy free-form --exec string is retained but honored only from Omarchy's
own omarchy-action toasts, and deprecated. Migrate all in-repo callers
(screenshot, screen recording, taildrop receive, migrate-notify, crash-watch,
yt-dlp host) to --exec-arg. Update docs and tests.
2026-08-23 12:00:03 -04:00

61 lines
2.0 KiB
Bash
Executable File

#!/bin/bash
# omarchy:summary=Notify the user when Omarchy has pending migrations
set -euo pipefail
update_in_progress() {
local lock="${XDG_RUNTIME_DIR:-}/omarchy-update.lock"
[[ -n ${XDG_RUNTIME_DIR:-} && -f $lock ]] || return 1
# flock -n only fails here when the lock is held, since the file is ours.
! flock -n "$lock" true 2>/dev/null
}
if update_in_progress; then
exit 0
fi
pending_migrations=$(omarchy-migrate --pending 2>/dev/null) || exit 0
pending_count=$(printf '%s\n' "$pending_migrations" | sed '/^[[:space:]]*$/d' | wc -l)
if (( pending_count == 1 )); then
message="Click to run 1 pending migration."
else
message="Click to run $pending_count pending migrations."
fi
# This runs from omarchy-migrate-notify.service after graphical-session.target,
# but the target can be reached before the shell has claimed
# org.freedesktop.Notifications. Without the wait the toast is sent into the
# void and the user never learns about their pending migrations.
omarchy-notification-wait || true
# That wait is long enough for an update to start underneath us, and the count
# above is already stale by then, so re-check before spending the toast.
if update_in_progress; then
exit 0
fi
# The shell keeps the click command with the toast, so this oneshot can hand the
# invitation over and exit instead of staying activated until it is answered.
omarchy-notification-send -u critical -g  "Pending Omarchy Migrations" "$message" \
--exec-arg omarchy-launch-floating-terminal-with-presentation --exec-arg omarchy-migrate && exit 0
# Reached when the notification could not be handed off, so fall back to telling
# the user in the terminal.
print_pending_migrations() {
echo "Omarchy has pending migrations. Run omarchy-migrate in a terminal to apply them:"
while IFS= read -r migration; do
[[ -n $migration ]] || continue
printf ' %s\n' "$migration"
done <<<"$pending_migrations"
}
if [[ -t 1 ]]; then
print_pending_migrations
else
print_pending_migrations >&2
fi