Match only active include lines when deciding polkit-1 is already fixed
The layout check skips comments, but the already-fixed check matched `include system-auth` anywhere on a line, so a comment such as `# auth include system-auth` made the migration skip a stack that still listed bare pam_unix, and it was marked complete with the lockout still missing. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
60c73865e4
commit
d95c68f9fb
2 files changed
+7
-1
No files matched your search
@@ -29,7 +29,7 @@ is_omarchy_vulnerable_stack() {
|
||||
local phase
|
||||
|
||||
# Already fixed, or partially converted: leave it alone (also makes reruns no-op).
|
||||
if grep -qE '(auth|account|password|session)[[:space:]]+include[[:space:]]+system-auth' "$file"; then
|
||||
if grep -qE '^(auth|account|password|session)[[:space:]]+include[[:space:]]+system-auth' "$file"; then
|
||||
return 1
|
||||
fi
|
||||
|
||||
|
||||
@@ -148,6 +148,12 @@ assert_repaired comment
|
||||
grep -qxF '# managed by omarchy' <<<"$(result comment)" || fail "comments are preserved through the rewrite"
|
||||
pass "migration repairs a commented stack and preserves the comment"
|
||||
|
||||
run_migration commented-include "# auth include system-auth
|
||||
$fingerprint_stack"
|
||||
(( migrate_rc == 0 )) || fail "a stack with a commented-out include migrates cleanly"
|
||||
assert_repaired commented-include
|
||||
pass "migration repairs a stack whose only include is commented out"
|
||||
|
||||
run_migration fixed "$fixed_stack"
|
||||
[[ "$(result fixed)" == "$(printf '%s' "$fixed_stack")" ]] || fail "an already-fixed stack is left byte-for-byte unchanged"
|
||||
! grep -q '^sudo ' "$test_dir/fixed.calls" || fail "an already-fixed stack triggers no privileged writes"
|
||||
|
||||
Reference in new issue
Block a user