Skip to content

Refuse to run omarchy-update as root - #13660

Open
AnPod wants to merge 1 commit into
omacom:quattrofrom
AnPod:cursor/fix-update-refuse-root-ef3e
Open

AnPod wants to merge 1 commit into
omacom:quattrofrom
AnPod:cursor/fix-update-refuse-root-ef3e

Conversation

@AnPod

@AnPod AnPod commented Sep 28, 2026

Copy link
Copy Markdown

Summary

Fixes omacom/omarchy#13329: sudo omarchy update made mise / user steps write root-owned state under ~.

Changes

  • Exit early with a clear error when EUID == 0
  • Guard runs before logging/lock so -y cannot skip it

Test plan

  • ./test/shell.d/update-refuse-root-test.sh

An outer sudo made mise/AUR steps write root-owned user state. Privileged
steps already escalate on their own.

Co-authored-by: AnPod <AnPod@users.noreply.github.com>
@jandrusk

jandrusk commented Oct 7, 2026

Copy link
Copy Markdown

Thanks for this. #11479 from @yashranaway fixes the same thing (it rejects root-run updates before any user state changes) and is a couple of weeks older. On 2026-10-03 the maintainers closed #13377, an equivalent fix, in favor of #11479 so the credit stays with the first fix. This one will probably go the same way. If #11479 misses a case you've hit, adding it there would be the best route.

(Small note if it does continue: the test only greps the source for EUID == 0. It never actually runs the script as root, so it would still pass if the guard ended up somewhere unreachable.)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

omarchy-update is annotated omarchy:requires-sudo=true, but running it as root makes the mise step write root-owned files into the user home

4 participants