Skip to content

Stop update stay-awake from hanging on sudo -v - #12900

Closed
Chessing234 wants to merge 1 commit into
omacom:quattrofrom
Chessing234:fix/9066-update-stay-awake-sudo-n
Closed

Chessing234 wants to merge 1 commit into
omacom:quattrofrom
Chessing234:fix/9066-update-stay-awake-sudo-n

Conversation

@Chessing234

Copy link
Copy Markdown
Contributor

Summary

  • omarchy-update-stay-awake no longer gates on bare sudo -v, which hangs under passwordless NOPASSWD (verifypw=all) and under omarchy-update's logging PTY (Fixes #9066).
  • Probe with sudo -n true; use sudo when that works, pkexec when attended without a ticket, and skip privileged inhibit when OMARCHY_UPDATE_UNATTENDED=1.

Test plan

  • bash test/shell.d/update-stay-awake-sudo-test.sh
  • omarchy sudo passwordless then omarchy update -y completes without a password hang
  • Interactive update without a cached sudo ticket still gets a polkit prompt for the inhibitor

Made with Cursor

Bare sudo -v hangs under passwordless NOPASSWD (verifypw=all) and under
omarchy-update's logging PTY; fall back to pkexec only when attended.
@llstrk

llstrk commented Sep 22, 2026

Copy link
Copy Markdown

Verified: At 2e95ec73, no production defect was confirmed in the reviewed scope. The helper replaces foreground sudo -v with a noninteractive probe and selects the intended inhibitor launch in mocked tests, both with and without a PTY:

sudo -n true Update mode Observed launch
succeeds either sudo systemd-inhibit
fails attended pkexec systemd-inhibit
fails unattended unprivileged systemd-inhibit

The new sudo regression test passes on head and fails against the unfixed baseline. The unattended fallback still attempts inhibition as the user; it does not skip the command entirely.

Optional test improvement: Add an early sudo stub in test/shell.d/update-lock-test.sh and test/shell.d/update-disk-space-test.sh, before their first update invocation. The new probe can reach sudo outside their existing stub set. A simulated passwordless sudo that resets environment/PATH makes the lock test fail at “update starts its sleep inhibitor”; the disk-space test can pass despite reaching that external command. A local stub that strips an initial -n before exec "$@" keeps both the probe and inhibitor within the tests' stub set. Both tests passed with that correction and zero calls to the external sudo sentinel. This is a test-isolation issue, not a demonstrated production update failure.


Review information

Test scope: Pinned source inspection, targeted shell tests, baseline controls, and mocked authorization/backend routing. Real sudo authentication, polkit dialogs, privileged inhibitor cleanup and sleep prevention were not validated.

Community review: Independent automated community review, unaffiliated with the Omarchy team, intended to help prepare PRs for their review.

Automated AI review: Astra initial inspection, independent Opus 5 and Astra technical reviews, followed by synthesis and verification against targeted evidence.

@Chessing234

Copy link
Copy Markdown
Contributor Author

folding into #12109 — sudo -n stay-awake probe is on the /tmp staging fold now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants