Defer to system-auth in the polkit stack written by fingerprint/FIDO2 setup

The fingerprint and FIDO2 setup commands create /etc/pam.d/polkit-1 from
scratch on Arch, where the polkit package ships its stack in
/usr/lib/pam.d/polkit-1 and /etc/pam.d/polkit-1 does not exist. The
hand-rolled stack listed pam_unix directly instead of including system-auth,
which dropped pam_faillock from the polkit path: polkit prompts had no
brute-force lockout, their failures were not recorded, and they did not count
toward the lockout protecting login and sudo. Defer to system-auth, matching
the vendor file and the sudo stack, keeping the clamshell gate and the
pam_fprintd / pam_u2f sufficient lines in front.

Add a migration to repair installs the old setup already configured, since the
forward fix does not rewrite an existing polkit-1. It acts only on an
Omarchy-created polkit-1 that lacks the system-auth include and carries a
hardware-auth marker, preserves the configured auth lines, backs up the
original, and is idempotent.

Add a test asserting the stack each setup creates defers to system-auth; the
created polkit content was previously untested.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
rattatuiandClaude Opus 4.8 committed 2026-09-02 21:41:53 +03:00
1 parent 4d017913d0
commit 8a13eac872
4 files changed
+92 -8

No files matched your search

+4 -4
View File
@@ -31,11 +31,11 @@ setup_pam_config() {
echo "Creating polkit configuration with FIDO2 authentication..."
sudo tee /etc/pam.d/polkit-1 >/dev/null <<'EOF'
auth sufficient pam_u2f.so cue authfile=/etc/fido2/fido2
auth required pam_unix.so
auth include system-auth
account required pam_unix.so
password required pam_unix.so
session required pam_unix.so
account include system-auth
password include system-auth
session include system-auth
EOF
fi
}
+4 -4
View File
@@ -47,11 +47,11 @@ setup_pam_config() {
sudo tee /etc/pam.d/polkit-1 >/dev/null <<EOF
$fprintd_gate
auth sufficient pam_fprintd.so
auth required pam_unix.so
auth include system-auth
account required pam_unix.so
password required pam_unix.so
session required pam_unix.so
account include system-auth
password include system-auth
session include system-auth
EOF
fi
}
+52
View File
@@ -0,0 +1,52 @@
echo "Restore polkit brute-force protection on machines that enabled fingerprint or FIDO2 auth"
polkit=/etc/pam.d/polkit-1
# When fingerprint or FIDO2 auth was set up while /etc/pam.d/polkit-1 did not yet
# exist -- the normal case on Arch, where the polkit package ships its stack in
# /usr/lib/pam.d/polkit-1 -- the setup commands hand-rolled an /etc/pam.d/polkit-1
# that lists pam_unix directly instead of `include system-auth`. That override
# dropped pam_faillock, so polkit prompts had no brute-force lockout and their
# failures never counted toward the shared tally. The setup commands now defer to
# system-auth; this repairs the files the old ones already wrote.
#
# In scope only when the file exists, no package owns it (Omarchy wrote it), it
# does not already defer to system-auth, and it carries an Omarchy hardware-auth
# marker (the clamshell gate, pam_fprintd, or the FIDO2 authfile). That pins the
# repair to the exact stack the setup commands produced and leaves an
# administrator's own polkit-1 untouched. Idempotent by construction: once
# system-auth is included, this run and every other user's run no-op.
if [[ -f $polkit ]] &&
! pacman -Qo "$polkit" &>/dev/null &&
! grep -qE '^auth[[:space:]]+include[[:space:]]+system-auth' "$polkit" &&
grep -qE 'omarchy-hw-laptop-closed|pam_fprintd\.so|authfile=/etc/fido2/fido2' "$polkit"; then
echo "Rewriting $polkit to defer to system-auth (restores pam_faillock lockout)..."
# Keep the configured hardware-auth auth lines verbatim (the clamshell gate and
# the pam_fprintd / pam_u2f 'sufficient' lines); only the bare pam_unix stack is
# replaced with the system-auth includes the vendor file and the sudo stack use.
hw_auth=$(grep -E '^auth' "$polkit" | grep -vE 'pam_unix\.so')
rebuilt=$(
[[ -n $hw_auth ]] && printf '%s\n' "$hw_auth"
printf 'auth include system-auth\n'
printf 'account include system-auth\n'
printf 'password include system-auth\n'
printf 'session include system-auth\n'
)
backup="$polkit.omarchy-bak.$(date +%s)"
if sudo cp -a "$polkit" "$backup"; then
printf '%s\n' "$rebuilt" | sudo tee "$polkit" >/dev/null
if grep -qE '^auth[[:space:]]+include[[:space:]]+system-auth' "$polkit"; then
echo "Restored polkit brute-force protection. Previous file saved at $backup."
else
echo "polkit repair could not be verified; restoring the original file." >&2
sudo cp -a "$backup" "$polkit"
fi
else
echo "Administrator privileges are required to repair $polkit. Run omarchy-migrate again from a terminal." >&2
fi
fi
@@ -0,0 +1,32 @@
#!/bin/bash
set -euo pipefail
source "$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)/base-test.sh"
# The fingerprint and FIDO2 setup commands each create /etc/pam.d/polkit-1 from
# scratch when the file does not already exist -- which is the normal case on
# Arch, where the polkit package ships its PAM stack in /usr/lib/pam.d/polkit-1
# and /etc/pam.d/polkit-1 is absent. A hand-rolled stack that lists pam_unix
# directly instead of `include system-auth` silently drops pam_faillock, so
# polkit prompts would have no brute-force lockout and their failures would not
# count toward the shared tally. Assert the created stack defers to system-auth.
for setup in omarchy-setup-security-fingerprint omarchy-setup-security-fido2; do
script="$ROOT/bin/$setup"
# Pull the here-doc body the setup writes to /etc/pam.d/polkit-1.
body=$(sed -n "/tee \/etc\/pam.d\/polkit-1/,/^EOF\$/p" "$script")
[[ -n $body ]] || fail "$setup writes a polkit-1 stack"
for phase in auth account password session; do
grep -qE "^${phase}[[:space:]]+include[[:space:]]+system-auth" <<<"$body" ||
fail "$setup polkit-1 $phase defers to system-auth (keeps faillock)" "$body"
done
! grep -qE "^(account|password|session)[[:space:]]+required[[:space:]]+pam_unix" <<<"$body" ||
fail "$setup polkit-1 does not hand-roll a bare pam_unix stack" "$body"
pass "$setup creates a polkit-1 stack that includes system-auth"
done