Files
arthur-os/bin/omarchy-update-pacman-guard

65 lines
1.3 KiB
Bash
Executable File

#!/bin/bash
# omarchy:summary=Prevent direct pacman system upgrades from bypassing omarchy update.
# omarchy:hidden=true
set -euo pipefail
if [[ ${OMARCHY_UPDATE_PACMAN:-} == "1" || ${OMARCHY_ALLOW_DIRECT_PACMAN:-} == "1" ]]; then
exit 0
fi
pacman_args=()
if [[ -n ${OMARCHY_PACMAN_CMDLINE:-} ]]; then
read -r -a pacman_args <<<"$OMARCHY_PACMAN_CMDLINE"
elif [[ -r /proc/$PPID/cmdline ]]; then
mapfile -d '' -t pacman_args <"/proc/$PPID/cmdline" || true
fi
is_system_upgrade=0
has_sync=0
has_sysupgrade=0
for arg in "${pacman_args[@]}"; do
case "$arg" in
--sync)
has_sync=1
;;
--sysupgrade)
has_sysupgrade=1
;;
--*)
;;
-*)
[[ $arg == *S* ]] && has_sync=1
[[ $arg == *u* ]] && has_sysupgrade=1
;;
esac
done
if (( has_sync && has_sysupgrade )); then
is_system_upgrade=1
fi
(( is_system_upgrade )) || exit 0
cat >&2 <<'MESSAGE'
Woah partner...
This looks like a direct pacman system upgrade. Omarchy updates should normally
run through:
omarchy update
That path handles the update transcript, snapshot, keyrings, package upgrade,
migrations, post-update hooks, shell update state, and restart checks together.
If you really meant to bypass Omarchy for this transaction, rerun pacman with:
sudo env OMARCHY_ALLOW_DIRECT_PACMAN=1 pacman -Syu
MESSAGE
exit 1