Files
omarchy/test/shell.d/security-polkit-faillock-test.sh
T
rattatuiandClaude Opus 4.8 8a13eac872 Defer to system-auth in the polkit stack written by fingerprint/FIDO2 setup
The fingerprint and FIDO2 setup commands create /etc/pam.d/polkit-1 from
scratch on Arch, where the polkit package ships its stack in
/usr/lib/pam.d/polkit-1 and /etc/pam.d/polkit-1 does not exist. The
hand-rolled stack listed pam_unix directly instead of including system-auth,
which dropped pam_faillock from the polkit path: polkit prompts had no
brute-force lockout, their failures were not recorded, and they did not count
toward the lockout protecting login and sudo. Defer to system-auth, matching
the vendor file and the sudo stack, keeping the clamshell gate and the
pam_fprintd / pam_u2f sufficient lines in front.

Add a migration to repair installs the old setup already configured, since the
forward fix does not rewrite an existing polkit-1. It acts only on an
Omarchy-created polkit-1 that lacks the system-auth include and carries a
hardware-auth marker, preserves the configured auth lines, backs up the
original, and is idempotent.

Add a test asserting the stack each setup creates defers to system-auth; the
created polkit content was previously untested.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-02 21:41:53 +03:00

33 lines
1.4 KiB
Bash

#!/bin/bash
set -euo pipefail
source "$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)/base-test.sh"
# The fingerprint and FIDO2 setup commands each create /etc/pam.d/polkit-1 from
# scratch when the file does not already exist -- which is the normal case on
# Arch, where the polkit package ships its PAM stack in /usr/lib/pam.d/polkit-1
# and /etc/pam.d/polkit-1 is absent. A hand-rolled stack that lists pam_unix
# directly instead of `include system-auth` silently drops pam_faillock, so
# polkit prompts would have no brute-force lockout and their failures would not
# count toward the shared tally. Assert the created stack defers to system-auth.
for setup in omarchy-setup-security-fingerprint omarchy-setup-security-fido2; do
script="$ROOT/bin/$setup"
# Pull the here-doc body the setup writes to /etc/pam.d/polkit-1.
body=$(sed -n "/tee \/etc\/pam.d\/polkit-1/,/^EOF\$/p" "$script")
[[ -n $body ]] || fail "$setup writes a polkit-1 stack"
for phase in auth account password session; do
grep -qE "^${phase}[[:space:]]+include[[:space:]]+system-auth" <<<"$body" ||
fail "$setup polkit-1 $phase defers to system-auth (keeps faillock)" "$body"
done
! grep -qE "^(account|password|session)[[:space:]]+required[[:space:]]+pam_unix" <<<"$body" ||
fail "$setup polkit-1 does not hand-roll a bare pam_unix stack" "$body"
pass "$setup creates a polkit-1 stack that includes system-auth"
done