Files
omarchy/migrations
rattatuiandClaude Opus 4.8 21e7975352 Harden the polkit migration: exact-layout match, retry on failure, and tests
Address review feedback on the polkit faillock migration:

- Match only the exact stack the setup commands wrote and replace just the bare
  pam_unix lines, preserving comments and the hardware-auth lines. An
  administrator-authored polkit-1 carrying any other directive is left
  untouched, rather than rebuilt from scratch.

- Also repair the markerless post-removal layout: both remove commands strip
  their own marker lines but leave the bare pam_unix stack behind, so keying on
  a hardware-auth marker skipped those machines permanently.

- Exit non-zero when the backup cannot be created or the rewrite cannot be
  verified (after restoring). omarchy-migrate runs under set -e and records a
  migration complete unconditionally after it returns, so a failed repair must
  fail loudly to be retried instead of silently marked done.

- Add test/shell.d/security-polkit-migration-test.sh covering the fingerprint,
  FIDO2, combined, and markerless layouts, comment preservation, idempotence, an
  untouched administrator stack, and the refused-sudo and unverifiable-write
  failure paths.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-03 09:18:18 +03:00
..
2026-06-12 13:49:46 -04:00
2026-06-12 13:49:46 -04:00
2026-06-12 13:49:46 -04:00
2026-06-12 13:49:46 -04:00
2026-06-12 13:49:46 -04:00
2026-06-12 13:49:46 -04:00
2026-06-29 08:51:15 -05:00
2026-06-20 15:44:37 -04:00
2026-06-21 02:25:42 -04:00
2026-06-21 12:31:06 +02:00
2026-07-19 09:59:13 -07:00
2026-07-24 19:49:13 -07:00
2026-07-28 21:07:50 -04:00
2026-07-29 12:27:38 -07:00
2026-08-01 21:56:51 -05:00
2026-08-01 19:32:32 -07:00
2026-08-11 13:56:09 +02:00