Files
omarchy/bin/omarchy-update-keyring
Adolanium 49418942c8 Merge pull request #7807 from Adolanium/keyring-fail-loud
Stop update-keyring from claiming success when key operations fail
2026-09-15 17:50:20 +02:00

32 lines
1.6 KiB
Bash
Executable File

#!/bin/bash
# omarchy:summary=Ensure the Omarchy and Arch keyring packages are installed and populated
# omarchy:requires-sudo=true
# omarchy-update runs this under set -e as a trusted pre-step, so a failed recv
# or a broken keyring has to stop this script here, not surface later as
# signature errors in the middle of the main transaction.
set -euo pipefail
if omarchy-pkg-missing omarchy-keyring || ! sudo pacman-key --list-keys 40DFB630FF42BCFFB047046CF0134EE680CAC571 &>/dev/null; then
sudo pacman-key --recv-keys 40DFB630FF42BCFFB047046CF0134EE680CAC571 --keyserver keys.openpgp.org
sudo pacman-key --lsign-key 40DFB630FF42BCFFB047046CF0134EE680CAC571
# This is generally not a good idea, but this is a special case because we're going to be updating
# the full set of packages in omarchy-update-system-pkgs right after this (and it needs latest keyring)!
sudo pacman -Sy
omarchy-pkg-add omarchy-keyring
sudo pacman-key --list-keys 40DFB630FF42BCFFB047046CF0134EE680CAC571
fi
# Ensure we have the latest archlinux-keyring, maintainer keys might have changed
# Always reinstall, as the keyring can be updated without a package version bump.
echo -e "\e[32m\nUpdate Arch signing keys\e[0m"
sudo pacman -Sy --noconfirm archlinux-keyring >/dev/null 2> >(grep -vE '^warning: archlinux-keyring-[^ ]+ is up to date -- reinstalling$' >&2)
# Say "correct" only once the key verifiably is: before the failure checks
# above, a failed recv or reinstall still ended here with exit 0.
sudo pacman-key --list-keys 40DFB630FF42BCFFB047046CF0134EE680CAC571 >/dev/null
echo "Keys are correct"