Rewrite polkit-1 in place with sed -i so an interrupted migration cannot truncate it

`sudo tee` truncates the live PAM file before writing it, so a migration interrupted in between left /etc/pam.d/polkit-1 empty; the next run then failed the layout check, exited 0, and was marked complete with polkit authentication broken. sed -i writes a temporary file and renames it into place, as the setup commands already do, so the original stays intact until the rewrite is whole and a failed sed needs no restore.

The test's broken-write stub now empties the file instead of discarding the write, so the restore assertion fails if the restore is removed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Codex Medium <noreply@openai.com>
This commit is contained in:
committed 2026-10-02 03:04:07 +02:00
1 parent 21e7975352
commit 60c73865e4
2 files changed
+12 -14

No files matched your search

+3 -5
View File
@@ -61,11 +61,9 @@ if [[ -f $polkit ]] && is_omarchy_vulnerable_stack "$polkit"; then
# Replace only the bare pam_unix lines; keep comments, blank lines, and the
# hardware-auth (gate / pam_fprintd / pam_u2f) lines exactly as they are.
rebuilt=$(sed -E 's/^(auth|account|password|session)([[:space:]]+)required[[:space:]]+pam_unix\.so[[:space:]]*$/\1\2include system-auth/' "$polkit")
if ! printf '%s\n' "$rebuilt" | sudo tee "$polkit" >/dev/null; then
echo "Could not write $polkit; restoring the original." >&2
sudo cp -a "$backup" "$polkit" || true
# sed -i renames a complete file into place, so an interrupted run never leaves polkit-1 truncated.
if ! sudo sed -i -E 's/^(auth|account|password|session)([[:space:]]+)required[[:space:]]+pam_unix\.so[[:space:]]*$/\1\2include system-auth/' "$polkit"; then
echo "Could not rewrite $polkit; leaving it unchanged so the migration retries." >&2
exit 1
fi
@@ -18,20 +18,20 @@ migration="$ROOT/migrations/1788256455.sh"
stub_bin="$test_dir/bin"
mkdir -p "$stub_bin"
# sudo stub: log, optionally refuse (SUDO_ALLOWED=0), and optionally make a
# `tee` write vanish (WRITE_BREAKS=1) so the verification/restore path is
# exercised. Otherwise run the real command so cp/tee act on the temp file.
# sudo stub: log, optionally refuse (SUDO_ALLOWED=0), and optionally make the
# `sed` rewrite empty the file and report success (WRITE_BREAKS=1) so the
# verification/restore path is exercised. Otherwise run the real command so
# cp/sed act on the temp file.
cat >"$stub_bin/sudo" <<'STUB'
#!/bin/bash
printf 'sudo %s\n' "$*" >>"${CALL_LOG:?}"
if [[ ${SUDO_ALLOWED:-1} != 1 ]]; then
if [[ ${SUDO_ALLOWED:-1} != "1" ]]; then
exit 1
elif [[ ${WRITE_BREAKS:-0} == "1" && $1 == "sed" ]]; then
: >"${!#}"
else
exec "$@"
fi
if [[ ${WRITE_BREAKS:-0} == 1 && $1 == tee ]]; then
cat >/dev/null
exit 0
fi
exec "$@"
STUB
chmod +x "$stub_bin"/*