diff --git a/migrations/1788256455.sh b/migrations/1788256455.sh index d4a8d355..38022bc3 100644 --- a/migrations/1788256455.sh +++ b/migrations/1788256455.sh @@ -29,7 +29,7 @@ is_omarchy_vulnerable_stack() { local phase # Already fixed, or partially converted: leave it alone (also makes reruns no-op). - if grep -qE '(auth|account|password|session)[[:space:]]+include[[:space:]]+system-auth' "$file"; then + if grep -qE '^(auth|account|password|session)[[:space:]]+include[[:space:]]+system-auth' "$file"; then return 1 fi diff --git a/test/shell.d/security-polkit-migration-test.sh b/test/shell.d/security-polkit-migration-test.sh index 42481e7d..d9b14fa1 100644 --- a/test/shell.d/security-polkit-migration-test.sh +++ b/test/shell.d/security-polkit-migration-test.sh @@ -148,6 +148,12 @@ assert_repaired comment grep -qxF '# managed by omarchy' <<<"$(result comment)" || fail "comments are preserved through the rewrite" pass "migration repairs a commented stack and preserves the comment" +run_migration commented-include "# auth include system-auth +$fingerprint_stack" +(( migrate_rc == 0 )) || fail "a stack with a commented-out include migrates cleanly" +assert_repaired commented-include +pass "migration repairs a stack whose only include is commented out" + run_migration fixed "$fixed_stack" [[ "$(result fixed)" == "$(printf '%s' "$fixed_stack")" ]] || fail "an already-fixed stack is left byte-for-byte unchanged" ! grep -q '^sudo ' "$test_dir/fixed.calls" || fail "an already-fixed stack triggers no privileged writes"