Auto Add Param To Desktop File

This hook runs as root after a pacman transaction. Never point Exec at a script or package list writable by an ordinary user. Install both under root-owned paths; every ancestor directory must also be protected from user writes.

Save this as ap in your working directory for review, then install it as shown below. It handles simple, unquoted executable names in the first Exec= line only; quoted executable paths and Desktop Actions need a Desktop Entry-aware implementation rather than this small patcher.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
#!/bin/bash
set -euo pipefail
[[ "$EUID" -eq 0 ]] || { printf 'Run through the root-owned pacman hook.\n' >&2; exit 1; }
PARAM="--enable-wayland-ime"
LIST="/etc/desktop-wayland-ime/apps.list"

modify_desktop() {
local file="$1" exec_line command rest
[[ -f "$file" && ! -L "$file" ]] || return 0
exec_line=$(grep -m1 '^Exec=' "$file") || return 0
# Only simple, unquoted executable tokens; skip other grammar safely.
if [[ "$exec_line" =~ ^Exec=([[:alnum:]_./-]+)([[:blank:]].*)?$ ]]; then
command="${BASH_REMATCH[1]}"
rest="${BASH_REMATCH[2]:-}"
else
return 0
fi
[[ " $rest " == *" $PARAM "* ]] && return 0
# Replace only the executable token; leave arguments (including & and |) untouched.
sed -i "0,/^Exec=/s|^Exec=[^[:blank:]]*|& $PARAM|" "$file"
}

while IFS= read -r app || [[ -n "$app" ]]; do
[[ -z "$app" || "$app" == \#* ]] && continue
# Accept desktop basenames only, never paths or traversal.
[[ "$app" =~ ^[[:alnum:]_-][[:alnum:]_.-]*$ ]] || { printf 'Invalid desktop basename.\n' >&2; exit 1; }
modify_desktop "/usr/share/applications/$app.desktop"
done < "$LIST"

Save the package list as apps.list, for example:

1
2
3
cursor-cursor
qq
cherry-studio

Install the reviewed script and list (the working copies are not executed by the hook):

1
2
3
sudo install -d -o root -g root -m 0755 /etc/desktop-wayland-ime
sudo install -o root -g root -m 0755 ap /usr/local/sbin/desktop-wayland-ime
sudo install -o root -g root -m 0644 apps.list /etc/desktop-wayland-ime/apps.list

Create /etc/pacman.d/hooks/desktop-wayland-ime.hook with root:root ownership and mode 0644. Ensure the hook directory and /usr/local/sbin are root-owned and not writable by ordinary users; if those directories are already user-writable, repair that prerequisite before installing anything.

1
2
3
4
5
6
7
8
9
10
[Trigger]
Operation = Install
Operation = Upgrade
Type = Package
Target = *

[Action]
Description = Adding --enable-wayland-ime to selected .desktop files
When = PostTransaction
Exec = /usr/local/sbin/desktop-wayland-ime

The hook modifies selected package-owned files in /usr/share/applications; package upgrades can overwrite them again. A user-level desktop override is an alternative when the setting is only for one account.

Test the parser/idempotence against disposable desktop fixtures before installing, rather than performing a system upgrade only to test a hook. After installation, inspect ownership, mode and the modified Exec= lines during an independently planned package transaction. The earlier personal paru -Syu observation was not rerun for this revised hook; no package upgrade or root execution was performed in this review.