Match only active include lines when deciding polkit-1 is already fixed

The layout check skips comments, but the already-fixed check matched `include system-auth` anywhere on a line, so a comment such as `# auth include system-auth` made the migration skip a stack that still listed bare pam_unix, and it was marked complete with the lockout still missing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
OmarchybotandClaude Opus 5.5 committed 2026-10-02 03:12:21 +02:00
1 parent 60c73865e4
commit d95c68f9fb
2 files changed
+7 -1

No files matched your search

+1 -1
View File
@@ -29,7 +29,7 @@ is_omarchy_vulnerable_stack() {
local phase
# Already fixed, or partially converted: leave it alone (also makes reruns no-op).
if grep -qE '(auth|account|password|session)[[:space:]]+include[[:space:]]+system-auth' "$file"; then
if grep -qE '^(auth|account|password|session)[[:space:]]+include[[:space:]]+system-auth' "$file"; then
return 1
fi
@@ -148,6 +148,12 @@ assert_repaired comment
grep -qxF '# managed by omarchy' <<<"$(result comment)" || fail "comments are preserved through the rewrite"
pass "migration repairs a commented stack and preserves the comment"
run_migration commented-include "# auth include system-auth
$fingerprint_stack"
(( migrate_rc == 0 )) || fail "a stack with a commented-out include migrates cleanly"
assert_repaired commented-include
pass "migration repairs a stack whose only include is commented out"
run_migration fixed "$fixed_stack"
[[ "$(result fixed)" == "$(printf '%s' "$fixed_stack")" ]] || fail "an already-fixed stack is left byte-for-byte unchanged"
! grep -q '^sudo ' "$test_dir/fixed.calls" || fail "an already-fixed stack triggers no privileged writes"