From 60c73865e4732eb8717fae8f960d2c786e8f387d Mon Sep 17 00:00:00 2001 From: Omarchybot <317366263+omarchybot@users.noreply.github.com> Date: Fri, 2 Oct 2026 03:04:07 +0200 Subject: [PATCH] Rewrite polkit-1 in place with sed -i so an interrupted migration cannot truncate it `sudo tee` truncates the live PAM file before writing it, so a migration interrupted in between left /etc/pam.d/polkit-1 empty; the next run then failed the layout check, exited 0, and was marked complete with polkit authentication broken. sed -i writes a temporary file and renames it into place, as the setup commands already do, so the original stays intact until the rewrite is whole and a failed sed needs no restore. The test's broken-write stub now empties the file instead of discarding the write, so the restore assertion fails if the restore is removed. Co-Authored-By: Claude Opus 5.5 Co-Authored-By: Codex Medium --- migrations/1788256455.sh | 8 +++----- test/shell.d/security-polkit-migration-test.sh | 18 +++++++++--------- 2 files changed, 12 insertions(+), 14 deletions(-) diff --git a/migrations/1788256455.sh b/migrations/1788256455.sh index e133604e..d4a8d355 100644 --- a/migrations/1788256455.sh +++ b/migrations/1788256455.sh @@ -61,11 +61,9 @@ if [[ -f $polkit ]] && is_omarchy_vulnerable_stack "$polkit"; then # Replace only the bare pam_unix lines; keep comments, blank lines, and the # hardware-auth (gate / pam_fprintd / pam_u2f) lines exactly as they are. - rebuilt=$(sed -E 's/^(auth|account|password|session)([[:space:]]+)required[[:space:]]+pam_unix\.so[[:space:]]*$/\1\2include system-auth/' "$polkit") - - if ! printf '%s\n' "$rebuilt" | sudo tee "$polkit" >/dev/null; then - echo "Could not write $polkit; restoring the original." >&2 - sudo cp -a "$backup" "$polkit" || true + # sed -i renames a complete file into place, so an interrupted run never leaves polkit-1 truncated. + if ! sudo sed -i -E 's/^(auth|account|password|session)([[:space:]]+)required[[:space:]]+pam_unix\.so[[:space:]]*$/\1\2include system-auth/' "$polkit"; then + echo "Could not rewrite $polkit; leaving it unchanged so the migration retries." >&2 exit 1 fi diff --git a/test/shell.d/security-polkit-migration-test.sh b/test/shell.d/security-polkit-migration-test.sh index b00e4681..42481e7d 100644 --- a/test/shell.d/security-polkit-migration-test.sh +++ b/test/shell.d/security-polkit-migration-test.sh @@ -18,20 +18,20 @@ migration="$ROOT/migrations/1788256455.sh" stub_bin="$test_dir/bin" mkdir -p "$stub_bin" -# sudo stub: log, optionally refuse (SUDO_ALLOWED=0), and optionally make a -# `tee` write vanish (WRITE_BREAKS=1) so the verification/restore path is -# exercised. Otherwise run the real command so cp/tee act on the temp file. +# sudo stub: log, optionally refuse (SUDO_ALLOWED=0), and optionally make the +# `sed` rewrite empty the file and report success (WRITE_BREAKS=1) so the +# verification/restore path is exercised. Otherwise run the real command so +# cp/sed act on the temp file. cat >"$stub_bin/sudo" <<'STUB' #!/bin/bash printf 'sudo %s\n' "$*" >>"${CALL_LOG:?}" -if [[ ${SUDO_ALLOWED:-1} != 1 ]]; then +if [[ ${SUDO_ALLOWED:-1} != "1" ]]; then exit 1 +elif [[ ${WRITE_BREAKS:-0} == "1" && $1 == "sed" ]]; then + : >"${!#}" +else + exec "$@" fi -if [[ ${WRITE_BREAKS:-0} == 1 && $1 == tee ]]; then - cat >/dev/null - exit 0 -fi -exec "$@" STUB chmod +x "$stub_bin"/*