Defer to system-auth in the polkit stack written by fingerprint/FIDO2 setup
The fingerprint and FIDO2 setup commands create /etc/pam.d/polkit-1 from scratch on Arch, where the polkit package ships its stack in /usr/lib/pam.d/polkit-1 and /etc/pam.d/polkit-1 does not exist. The hand-rolled stack listed pam_unix directly instead of including system-auth, which dropped pam_faillock from the polkit path: polkit prompts had no brute-force lockout, their failures were not recorded, and they did not count toward the lockout protecting login and sudo. Defer to system-auth, matching the vendor file and the sudo stack, keeping the clamshell gate and the pam_fprintd / pam_u2f sufficient lines in front. Add a migration to repair installs the old setup already configured, since the forward fix does not rewrite an existing polkit-1. It acts only on an Omarchy-created polkit-1 that lacks the system-auth include and carries a hardware-auth marker, preserves the configured auth lines, backs up the original, and is idempotent. Add a test asserting the stack each setup creates defers to system-auth; the created polkit content was previously untested. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
4d017913d0
commit
8a13eac872
4 files changed
+92
-8
No files matched your search
@@ -31,11 +31,11 @@ setup_pam_config() {
|
||||
echo "Creating polkit configuration with FIDO2 authentication..."
|
||||
sudo tee /etc/pam.d/polkit-1 >/dev/null <<'EOF'
|
||||
auth sufficient pam_u2f.so cue authfile=/etc/fido2/fido2
|
||||
auth required pam_unix.so
|
||||
auth include system-auth
|
||||
|
||||
account required pam_unix.so
|
||||
password required pam_unix.so
|
||||
session required pam_unix.so
|
||||
account include system-auth
|
||||
password include system-auth
|
||||
session include system-auth
|
||||
EOF
|
||||
fi
|
||||
}
|
||||
|
||||
@@ -47,11 +47,11 @@ setup_pam_config() {
|
||||
sudo tee /etc/pam.d/polkit-1 >/dev/null <<EOF
|
||||
$fprintd_gate
|
||||
auth sufficient pam_fprintd.so
|
||||
auth required pam_unix.so
|
||||
auth include system-auth
|
||||
|
||||
account required pam_unix.so
|
||||
password required pam_unix.so
|
||||
session required pam_unix.so
|
||||
account include system-auth
|
||||
password include system-auth
|
||||
session include system-auth
|
||||
EOF
|
||||
fi
|
||||
}
|
||||
|
||||
@@ -0,0 +1,52 @@
|
||||
echo "Restore polkit brute-force protection on machines that enabled fingerprint or FIDO2 auth"
|
||||
|
||||
polkit=/etc/pam.d/polkit-1
|
||||
|
||||
# When fingerprint or FIDO2 auth was set up while /etc/pam.d/polkit-1 did not yet
|
||||
# exist -- the normal case on Arch, where the polkit package ships its stack in
|
||||
# /usr/lib/pam.d/polkit-1 -- the setup commands hand-rolled an /etc/pam.d/polkit-1
|
||||
# that lists pam_unix directly instead of `include system-auth`. That override
|
||||
# dropped pam_faillock, so polkit prompts had no brute-force lockout and their
|
||||
# failures never counted toward the shared tally. The setup commands now defer to
|
||||
# system-auth; this repairs the files the old ones already wrote.
|
||||
#
|
||||
# In scope only when the file exists, no package owns it (Omarchy wrote it), it
|
||||
# does not already defer to system-auth, and it carries an Omarchy hardware-auth
|
||||
# marker (the clamshell gate, pam_fprintd, or the FIDO2 authfile). That pins the
|
||||
# repair to the exact stack the setup commands produced and leaves an
|
||||
# administrator's own polkit-1 untouched. Idempotent by construction: once
|
||||
# system-auth is included, this run and every other user's run no-op.
|
||||
if [[ -f $polkit ]] &&
|
||||
! pacman -Qo "$polkit" &>/dev/null &&
|
||||
! grep -qE '^auth[[:space:]]+include[[:space:]]+system-auth' "$polkit" &&
|
||||
grep -qE 'omarchy-hw-laptop-closed|pam_fprintd\.so|authfile=/etc/fido2/fido2' "$polkit"; then
|
||||
|
||||
echo "Rewriting $polkit to defer to system-auth (restores pam_faillock lockout)..."
|
||||
|
||||
# Keep the configured hardware-auth auth lines verbatim (the clamshell gate and
|
||||
# the pam_fprintd / pam_u2f 'sufficient' lines); only the bare pam_unix stack is
|
||||
# replaced with the system-auth includes the vendor file and the sudo stack use.
|
||||
hw_auth=$(grep -E '^auth' "$polkit" | grep -vE 'pam_unix\.so')
|
||||
|
||||
rebuilt=$(
|
||||
[[ -n $hw_auth ]] && printf '%s\n' "$hw_auth"
|
||||
printf 'auth include system-auth\n'
|
||||
printf 'account include system-auth\n'
|
||||
printf 'password include system-auth\n'
|
||||
printf 'session include system-auth\n'
|
||||
)
|
||||
|
||||
backup="$polkit.omarchy-bak.$(date +%s)"
|
||||
if sudo cp -a "$polkit" "$backup"; then
|
||||
printf '%s\n' "$rebuilt" | sudo tee "$polkit" >/dev/null
|
||||
|
||||
if grep -qE '^auth[[:space:]]+include[[:space:]]+system-auth' "$polkit"; then
|
||||
echo "Restored polkit brute-force protection. Previous file saved at $backup."
|
||||
else
|
||||
echo "polkit repair could not be verified; restoring the original file." >&2
|
||||
sudo cp -a "$backup" "$polkit"
|
||||
fi
|
||||
else
|
||||
echo "Administrator privileges are required to repair $polkit. Run omarchy-migrate again from a terminal." >&2
|
||||
fi
|
||||
fi
|
||||
@@ -0,0 +1,32 @@
|
||||
#!/bin/bash
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
source "$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)/base-test.sh"
|
||||
|
||||
# The fingerprint and FIDO2 setup commands each create /etc/pam.d/polkit-1 from
|
||||
# scratch when the file does not already exist -- which is the normal case on
|
||||
# Arch, where the polkit package ships its PAM stack in /usr/lib/pam.d/polkit-1
|
||||
# and /etc/pam.d/polkit-1 is absent. A hand-rolled stack that lists pam_unix
|
||||
# directly instead of `include system-auth` silently drops pam_faillock, so
|
||||
# polkit prompts would have no brute-force lockout and their failures would not
|
||||
# count toward the shared tally. Assert the created stack defers to system-auth.
|
||||
|
||||
for setup in omarchy-setup-security-fingerprint omarchy-setup-security-fido2; do
|
||||
script="$ROOT/bin/$setup"
|
||||
|
||||
# Pull the here-doc body the setup writes to /etc/pam.d/polkit-1.
|
||||
body=$(sed -n "/tee \/etc\/pam.d\/polkit-1/,/^EOF\$/p" "$script")
|
||||
|
||||
[[ -n $body ]] || fail "$setup writes a polkit-1 stack"
|
||||
|
||||
for phase in auth account password session; do
|
||||
grep -qE "^${phase}[[:space:]]+include[[:space:]]+system-auth" <<<"$body" ||
|
||||
fail "$setup polkit-1 $phase defers to system-auth (keeps faillock)" "$body"
|
||||
done
|
||||
|
||||
! grep -qE "^(account|password|session)[[:space:]]+required[[:space:]]+pam_unix" <<<"$body" ||
|
||||
fail "$setup polkit-1 does not hand-roll a bare pam_unix stack" "$body"
|
||||
|
||||
pass "$setup creates a polkit-1 stack that includes system-auth"
|
||||
done
|
||||
Reference in new issue
Block a user