From d95c68f9fbd1d05bad37dfaba5cd62bfdf72833d Mon Sep 17 00:00:00 2001 From: Omarchybot <317366263+omarchybot@users.noreply.github.com> Date: Fri, 2 Oct 2026 03:12:21 +0200 Subject: [PATCH] Match only active include lines when deciding polkit-1 is already fixed The layout check skips comments, but the already-fixed check matched `include system-auth` anywhere on a line, so a comment such as `# auth include system-auth` made the migration skip a stack that still listed bare pam_unix, and it was marked complete with the lockout still missing. Co-Authored-By: Claude Opus 5.5 --- migrations/1788256455.sh | 2 +- test/shell.d/security-polkit-migration-test.sh | 6 ++++++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/migrations/1788256455.sh b/migrations/1788256455.sh index d4a8d355..38022bc3 100644 --- a/migrations/1788256455.sh +++ b/migrations/1788256455.sh @@ -29,7 +29,7 @@ is_omarchy_vulnerable_stack() { local phase # Already fixed, or partially converted: leave it alone (also makes reruns no-op). - if grep -qE '(auth|account|password|session)[[:space:]]+include[[:space:]]+system-auth' "$file"; then + if grep -qE '^(auth|account|password|session)[[:space:]]+include[[:space:]]+system-auth' "$file"; then return 1 fi diff --git a/test/shell.d/security-polkit-migration-test.sh b/test/shell.d/security-polkit-migration-test.sh index 42481e7d..d9b14fa1 100644 --- a/test/shell.d/security-polkit-migration-test.sh +++ b/test/shell.d/security-polkit-migration-test.sh @@ -148,6 +148,12 @@ assert_repaired comment grep -qxF '# managed by omarchy' <<<"$(result comment)" || fail "comments are preserved through the rewrite" pass "migration repairs a commented stack and preserves the comment" +run_migration commented-include "# auth include system-auth +$fingerprint_stack" +(( migrate_rc == 0 )) || fail "a stack with a commented-out include migrates cleanly" +assert_repaired commented-include +pass "migration repairs a stack whose only include is commented out" + run_migration fixed "$fixed_stack" [[ "$(result fixed)" == "$(printf '%s' "$fixed_stack")" ]] || fail "an already-fixed stack is left byte-for-byte unchanged" ! grep -q '^sudo ' "$test_dir/fixed.calls" || fail "an already-fixed stack triggers no privileged writes"