11#! /bin/bash
22#
3- # The install scripts that grant group memberships must record them in the provisioning
4- # groups file (for first-boot user creation and factory reset) and only call
5- # usermod when the install user actually exists.
6- #
7- # Docker is deliberately excluded: the docker group is root-equivalent, so it is
8- # no longer granted at install time (opt in with omarchy-setup-security-sudoless-docker).
3+ # Privileged groups are never granted by the default install. Docker remains an
4+ # explicit opt-in, and raw input-device access is granted only by the optional
5+ # controller and ydotool installers.
96
107set -euo pipefail
118
@@ -16,13 +13,7 @@ trap 'rm -rf "$TMPDIR"' EXIT
1613
1714export OMARCHY_PROVISIONING_DIR=" $TMPDIR /provisioning"
1815
19- # Stub getent/usermod: the fake system knows only the user "existing".
2016mkdir -p " $TMPDIR /bin"
21- cat > " $TMPDIR /bin/getent" << 'STUB '
22- #!/bin/bash
23- [[ $1 == passwd && $2 == existing ]] && { echo "existing:x:1000:1000::/home/existing:/bin/bash"; exit 0; }
24- exit 2
25- STUB
2617cat > " $TMPDIR /bin/usermod" << STUB
2718#!/bin/bash
2819echo "\$ @" >>"$TMPDIR /usermod.calls"
@@ -44,48 +35,31 @@ cat >"$TMPDIR/bin/sudo" <<STUB
4435echo "\$ @" >>"$TMPDIR /sudo.calls"
4536exec "\$ @"
4637STUB
47- chmod +x " $TMPDIR /bin" /{getent, usermod,groupadd,install,find,sudo}
38+ chmod +x " $TMPDIR /bin" /{usermod,groupadd,install,find,sudo}
4839export PATH=" $TMPDIR /bin:$PATH "
4940export OMARCHY_PATH=" $ROOT "
5041
51- # No install user ( deferred-provisioning install): groups recorded, usermod not called .
42+ # A deferred-provisioning install records neither privileged group .
5243OMARCHY_INSTALL_USER=" " bash -eE " $ROOT /install/config/docker.sh"
53- OMARCHY_INSTALL_USER=" " bash -eE " $ROOT /install/hardware/input-group.sh"
5444OMARCHY_INSTALL_USER=" " bash -eE " $ROOT /install/config/browser-policy.sh"
5545
56- [[ -f $OMARCHY_PROVISIONING_DIR /groups ]] || fail " groups file written without an install user"
57- grep -qxF input " $OMARCHY_PROVISIONING_DIR /groups" || fail " input group recorded"
58- ! grep -qxF omarchy-browser-policy " $OMARCHY_PROVISIONING_DIR /groups" ||
59- fail " browser-policy group must not be recorded"
46+ [[ ! -f $OMARCHY_PROVISIONING_DIR /groups ]] ||
47+ ! grep -Eq ' ^(docker|input)$' " $OMARCHY_PROVISIONING_DIR /groups" ||
48+ fail " default install must not record docker or input groups"
6049[[ ! -f $TMPDIR /usermod.calls ]] || fail " usermod not called without an install user"
6150[[ ! -f $TMPDIR /groupadd.calls ]] || ! grep -F omarchy-browser-policy " $TMPDIR /groupadd.calls" > /dev/null ||
6251 fail " browser-policy group is not created"
6352grep -F -- ' -d -m 0755 -o root -g root /etc/chromium/policies/managed' " $TMPDIR /install.calls" > /dev/null ||
6453 fail " browser-policy directory is created root-owned"
65- pass " deferred provisioning records groups without calling usermod"
66-
67- # The docker group is root-equivalent and must never be granted automatically.
68- ! grep -qxF docker " $OMARCHY_PROVISIONING_DIR /groups" || fail " docker group must not be recorded"
69- pass " docker group is not recorded at install"
54+ pass " deferred provisioning records no privileged groups"
7055
71- # Missing user (defensive): no usermod either.
72- OMARCHY_INSTALL_USER=ghost bash -eE " $ROOT /install/hardware/input-group.sh"
73- OMARCHY_INSTALL_USER=ghost bash -eE " $ROOT /install/config/browser-policy.sh"
74- [[ ! -f $TMPDIR /usermod.calls ]] || fail " usermod not called for a missing user"
75- pass " missing install user defers group grants"
76-
77- # Re-running never duplicates entries.
78- OMARCHY_INSTALL_USER=" " bash -eE " $ROOT /install/hardware/input-group.sh"
79- [[ $( grep -cxF input " $OMARCHY_PROVISIONING_DIR /groups" ) == 1 ]] || fail " input group recorded once"
80- OMARCHY_INSTALL_USER=" " bash -eE " $ROOT /install/config/browser-policy.sh"
81- pass " group recording is idempotent"
82-
83- # Existing user: usermod applies the recorded groups, and docker is never among them.
56+ # The same remains true when an install user already exists.
8457OMARCHY_INSTALL_USER=existing bash -eE " $ROOT /install/config/docker.sh"
85- OMARCHY_INSTALL_USER=existing bash -eE " $ROOT /install/hardware/input-group.sh"
8658OMARCHY_INSTALL_USER=existing bash -eE " $ROOT /install/config/browser-policy.sh"
87- grep -qx -- " -aG input existing" " $TMPDIR /usermod.calls" || fail " usermod grants input to the install user"
88- ! grep -q -- " omarchy-browser-policy" " $TMPDIR /usermod.calls" ||
89- fail " usermod must not grant browser-policy to the install user"
90- ! grep -q -- " docker" " $TMPDIR /usermod.calls" || fail " usermod must not grant docker to the install user"
91- pass " existing install user gets input but never docker or browser-policy"
59+ [[ ! -f $TMPDIR /usermod.calls ]] || fail " default install must not grant privileged groups"
60+ pass " existing install user gets neither docker nor input access"
61+
62+ ! grep -q ' hardware/input-group.sh' " $ROOT /install/hardware/all.sh" ||
63+ fail " hardware setup must not call the removed input-group grant"
64+ [[ ! -e $ROOT /install/hardware/input-group.sh ]] || fail " blanket input-group grant is removed"
65+ pass " hardware setup has no blanket input-group grant"
0 commit comments