Add pacman --overwrite for transition paths; fix mimeapps/HEY and PAM idempotency

Four corrections to the omarchy-settings transition:

- bin/omarchy-update-system-pkgs: pass --overwrite for the 13 paths
  omarchy-settings now owns. Existing Omarchy installs would otherwise
  fail pacman conflict checks on the upgrade that ships the package
  (the files exist as unowned filesystem entries from the previous
  install scripts). The flags are no-ops once the transition release
  is everyone's baseline; remove then.
- config/mimeapps.list: drop the HEY.desktop mailto mapping. HEY.desktop
  is generated by install/packaging/webapps.sh at install time, not
  shipped under applications/, so it isn't valid for a fresh /etc/skel
  user before the installer runs.
- install/config/mimetypes.sh: add 'xdg-mime default HEY.desktop
  x-scheme-handler/mailto' as a runtime op since the mapping no longer
  lives in mimeapps.list.
- install/config/increase-lockout-limit.sh: delete existing
  pam_faillock.so authsucc lines before re-adding, so re-running the
  installer doesn't duplicate the authsucc entry in
  /etc/pam.d/sddm-autologin.
This commit is contained in:
Ryan Hughes
2026-06-04 18:34:04 -04:00
parent 3636f57f0c
commit 5683750b29
4 changed files with 40 additions and 10 deletions
+23 -1
View File
@@ -6,4 +6,26 @@
set -e
echo -e "\e[32m\nUpdate system packages\e[0m"
sudo pacman -Syyu --noconfirm
# Transition --overwrite: the Omarchy 4 package refactor moves files that
# previous Omarchy installs wrote as unowned files (via install scripts) into
# the omarchy-settings package. Pacman would otherwise refuse to install
# omarchy-settings on the first upgrade because the paths "exist in
# filesystem". Limited to the exact paths the package now owns; remove the
# corresponding --overwrite entry once the transition release is everyone's
# baseline.
sudo pacman -Syyu --noconfirm \
--overwrite '/etc/docker/daemon.json' \
--overwrite '/etc/gnupg/dirmngr.conf' \
--overwrite '/etc/modprobe.d/omarchy-usb-autosuspend.conf' \
--overwrite '/etc/sudoers.d/omarchy-asdcontrol' \
--overwrite '/etc/sudoers.d/omarchy-passwd-tries' \
--overwrite '/etc/sudoers.d/omarchy-tzupdate' \
--overwrite '/etc/sysctl.d/90-omarchy-file-watchers.conf' \
--overwrite '/etc/sysctl.d/99-omarchy-sysctl.conf' \
--overwrite '/etc/systemd/logind.conf.d/10-ignore-power-button.conf' \
--overwrite '/etc/systemd/resolved.conf.d/10-disable-multicast.conf' \
--overwrite '/etc/systemd/resolved.conf.d/20-docker-dns.conf' \
--overwrite '/etc/systemd/system.conf.d/10-faster-shutdown.conf' \
--overwrite '/etc/systemd/system/user@.service.d/10-faster-shutdown.conf' \
--overwrite '/etc/systemd/system/docker.service.d/no-block-boot.conf'
+4 -2
View File
@@ -13,6 +13,10 @@ application/pdf=org.gnome.Evince.desktop
x-scheme-handler/http=chromium.desktop
x-scheme-handler/https=chromium.desktop
# Note: x-scheme-handler/mailto -> HEY.desktop is set at install time by
# install/config/mimetypes.sh because HEY.desktop is generated by
# install/packaging/webapps.sh, not shipped as a /etc/skel file.
video/mp4=mpv.desktop
video/x-msvideo=mpv.desktop
video/x-matroska=mpv.desktop
@@ -29,8 +33,6 @@ video/x-ogm+ogg=mpv.desktop
video/x-theora+ogg=mpv.desktop
application/ogg=mpv.desktop
x-scheme-handler/mailto=HEY.desktop
text/plain=nvim.desktop
text/english=nvim.desktop
text/x-makefile=nvim.desktop
+5 -2
View File
@@ -7,6 +7,9 @@
sudo sed -i 's|^\(auth\s\+required\s\+pam_faillock.so\)\s\+preauth.*$|\1 preauth silent deny=10 unlock_time=120|' "/etc/pam.d/system-auth"
sudo sed -i 's|^\(auth\s\+\[default=die\]\s\+pam_faillock.so\)\s\+authfail.*$|\1 authfail deny=10 unlock_time=120|' "/etc/pam.d/system-auth"
# Ensure lockout limit is reset on restart
sudo sed -i '/pam_faillock\.so preauth/d' /etc/pam.d/sddm-autologin
# Ensure lockout limit is reset on restart.
# Delete BOTH the preauth and authsucc pam_faillock lines before re-adding
# authsucc, so re-running the installer doesn't duplicate the authsucc line.
sudo sed -i '/pam_faillock\.so preauth/d' /etc/pam.d/sddm-autologin
sudo sed -i '/pam_faillock\.so authsucc/d' /etc/pam.d/sddm-autologin
sudo sed -i '/auth.*pam_permit\.so/a auth required pam_faillock.so authsucc' /etc/pam.d/sddm-autologin
+8 -5
View File
@@ -1,7 +1,10 @@
# MIME default mappings now ship as config/mimeapps.list (via /etc/skel for
# new users; existing users keep their own). This script only handles the
# runtime side: refresh applications and set Chromium as the system default
# web browser. (omarchy-install-browser overrides this if the user picks
# something else later.)
# Most MIME default mappings now ship as config/mimeapps.list (via /etc/skel
# for new users; existing users keep their own). This script handles the
# runtime side: refresh applications, set Chromium as the system default web
# browser (omarchy-install-browser overrides if the user picks something
# else later), and wire HEY.desktop as the mailto handler — HEY.desktop is
# generated by install/packaging/webapps.sh at install time so it can't
# live in /etc/skel/.config/mimeapps.list.
omarchy-refresh-applications
xdg-settings set default-web-browser chromium.desktop
xdg-mime default HEY.desktop x-scheme-handler/mailto