The fingerprint and FIDO2 setup commands create /etc/pam.d/polkit-1 from scratch on Arch, where the polkit package ships its stack in /usr/lib/pam.d/polkit-1 and /etc/pam.d/polkit-1 does not exist. The hand-rolled stack listed pam_unix directly instead of including system-auth, which dropped pam_faillock from the polkit path: polkit prompts had no brute-force lockout, their failures were not recorded, and they did not count toward the lockout protecting login and sudo. Defer to system-auth, matching the vendor file and the sudo stack, keeping the clamshell gate and the pam_fprintd / pam_u2f sufficient lines in front. Add a migration to repair installs the old setup already configured, since the forward fix does not rewrite an existing polkit-1. It acts only on an Omarchy-created polkit-1 that lacks the system-auth include and carries a hardware-auth marker, preserves the configured auth lines, backs up the original, and is idempotent. Add a test asserting the stack each setup creates defers to system-auth; the created polkit content was previously untested. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
33 lines
1.4 KiB
Bash
33 lines
1.4 KiB
Bash
#!/bin/bash
|
|
|
|
set -euo pipefail
|
|
|
|
source "$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)/base-test.sh"
|
|
|
|
# The fingerprint and FIDO2 setup commands each create /etc/pam.d/polkit-1 from
|
|
# scratch when the file does not already exist -- which is the normal case on
|
|
# Arch, where the polkit package ships its PAM stack in /usr/lib/pam.d/polkit-1
|
|
# and /etc/pam.d/polkit-1 is absent. A hand-rolled stack that lists pam_unix
|
|
# directly instead of `include system-auth` silently drops pam_faillock, so
|
|
# polkit prompts would have no brute-force lockout and their failures would not
|
|
# count toward the shared tally. Assert the created stack defers to system-auth.
|
|
|
|
for setup in omarchy-setup-security-fingerprint omarchy-setup-security-fido2; do
|
|
script="$ROOT/bin/$setup"
|
|
|
|
# Pull the here-doc body the setup writes to /etc/pam.d/polkit-1.
|
|
body=$(sed -n "/tee \/etc\/pam.d\/polkit-1/,/^EOF\$/p" "$script")
|
|
|
|
[[ -n $body ]] || fail "$setup writes a polkit-1 stack"
|
|
|
|
for phase in auth account password session; do
|
|
grep -qE "^${phase}[[:space:]]+include[[:space:]]+system-auth" <<<"$body" ||
|
|
fail "$setup polkit-1 $phase defers to system-auth (keeps faillock)" "$body"
|
|
done
|
|
|
|
! grep -qE "^(account|password|session)[[:space:]]+required[[:space:]]+pam_unix" <<<"$body" ||
|
|
fail "$setup polkit-1 does not hand-roll a bare pam_unix stack" "$body"
|
|
|
|
pass "$setup creates a polkit-1 stack that includes system-auth"
|
|
done
|