From 7fa32bb98c829be6ec12e4f55a997c7f5ca88634 Mon Sep 17 00:00:00 2001 From: Omarchybot Date: Mon, 24 Aug 2026 15:49:17 +0200 Subject: [PATCH] Remove the sudo lockout reset command (backport of #8046) Backport of the omarchy-sudo-reset removal (PR #8046, merged to quattro as d99d4fc6) onto the v4-0-1 release branch, so 4.0.1 stops shipping the command. Nothing in the repository called omarchy-sudo-reset, and its one line interpolated an environment-supplied $USER into a string handed to a root shell: su -c "faillock --reset --user $USER". $USER is an environment variable rather than a kernel-supplied identity, so whatever set it before the command ran chose the rest of what root's shell executed. That is not a way past PAM on its own -- su still has to authenticate -- but the installer sets root's password to the user's own, so the prompt this raises is one the user answers by habit. It bought little for that. Omarchy sets deny=10 unlock_time=120 in /etc/pam.d/system-auth and in the lock screen's PAM stack, so a lockout takes ten wrong passwords to reach and clears itself two minutes later, and manual/45-troubleshooting.md documents the root-TTY reset for anyone who would rather not wait. That reset is unaffected by this change. The sudo group keeps keepalive and passwordless, so GROUP_DESCRIPTIONS[sudo] is unchanged and omarchy sudo reset falls through to the router's unknown-command path. No migration is needed: bin/omarchy-* ships as files in the omarchy package, so an upgrade drops what the package no longer contains. Clean cherry-pick: the file was byte-identical to quattro's pre-image and nothing else on this branch referenced it, so merging v4-0-1 into quattro resolves without a conflict. test/shell and test/cli pass here. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_018DEMYa9UWtroz93DhMTtcV --- bin/omarchy-sudo-reset | 5 ----- 1 file changed, 5 deletions(-) delete mode 100755 bin/omarchy-sudo-reset diff --git a/bin/omarchy-sudo-reset b/bin/omarchy-sudo-reset deleted file mode 100755 index 56d91a8d..00000000 --- a/bin/omarchy-sudo-reset +++ /dev/null @@ -1,5 +0,0 @@ -#!/bin/bash - -# omarchy:summary=Reset the sudo lockout/faillock for the current user. - -su -c "faillock --reset --user $USER"