Address review feedback on the polkit faillock migration:
- Match only the exact stack the setup commands wrote and replace just the bare
pam_unix lines, preserving comments and the hardware-auth lines. An
administrator-authored polkit-1 carrying any other directive is left
untouched, rather than rebuilt from scratch.
- Also repair the markerless post-removal layout: both remove commands strip
their own marker lines but leave the bare pam_unix stack behind, so keying on
a hardware-auth marker skipped those machines permanently.
- Exit non-zero when the backup cannot be created or the rewrite cannot be
verified (after restoring). omarchy-migrate runs under set -e and records a
migration complete unconditionally after it returns, so a failed repair must
fail loudly to be retried instead of silently marked done.
- Add test/shell.d/security-polkit-migration-test.sh covering the fingerprint,
FIDO2, combined, and markerless layouts, comment preservation, idempotence, an
untouched administrator stack, and the refused-sudo and unverifiable-write
failure paths.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>