rattatuiandClaude Opus 4.8 21e7975352 Harden the polkit migration: exact-layout match, retry on failure, and tests
Address review feedback on the polkit faillock migration:

- Match only the exact stack the setup commands wrote and replace just the bare
  pam_unix lines, preserving comments and the hardware-auth lines. An
  administrator-authored polkit-1 carrying any other directive is left
  untouched, rather than rebuilt from scratch.

- Also repair the markerless post-removal layout: both remove commands strip
  their own marker lines but leave the bare pam_unix stack behind, so keying on
  a hardware-auth marker skipped those machines permanently.

- Exit non-zero when the backup cannot be created or the rewrite cannot be
  verified (after restoring). omarchy-migrate runs under set -e and records a
  migration complete unconditionally after it returns, so a failed repair must
  fail loudly to be retried instead of silently marked done.

- Add test/shell.d/security-polkit-migration-test.sh covering the fingerprint,
  FIDO2, combined, and markerless layouts, comment preservation, idempotence, an
  untouched administrator stack, and the refused-sudo and unverifiable-write
  failure paths.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-03 09:18:18 +03:00
2026-08-30 13:26:18 -06:00
2025-10-07 18:17:47 +02:00
2026-05-11 10:39:22 -04:00
2025-06-30 16:42:09 -07:00
2025-07-28 09:32:44 +02:00
2025-07-26 10:02:29 -07:00
2026-05-14 11:34:55 +02:00
S
Description
Omarchy with China region and Chinese language support. Fork of omacom/omarchy.
Readme MIT
452 MiB
0 Stars 1 Watchers 0 Forks