rattatuiandClaude Opus 4.8 8a13eac872 Defer to system-auth in the polkit stack written by fingerprint/FIDO2 setup
The fingerprint and FIDO2 setup commands create /etc/pam.d/polkit-1 from
scratch on Arch, where the polkit package ships its stack in
/usr/lib/pam.d/polkit-1 and /etc/pam.d/polkit-1 does not exist. The
hand-rolled stack listed pam_unix directly instead of including system-auth,
which dropped pam_faillock from the polkit path: polkit prompts had no
brute-force lockout, their failures were not recorded, and they did not count
toward the lockout protecting login and sudo. Defer to system-auth, matching
the vendor file and the sudo stack, keeping the clamshell gate and the
pam_fprintd / pam_u2f sufficient lines in front.

Add a migration to repair installs the old setup already configured, since the
forward fix does not rewrite an existing polkit-1. It acts only on an
Omarchy-created polkit-1 that lacks the system-auth include and carries a
hardware-auth marker, preserves the configured auth lines, backs up the
original, and is idempotent.

Add a test asserting the stack each setup creates defers to system-auth; the
created polkit content was previously untested.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-02 21:41:53 +03:00
2026-08-30 13:26:18 -06:00
2025-10-07 18:17:47 +02:00
2026-05-11 10:39:22 -04:00
2025-06-30 16:42:09 -07:00
2025-07-28 09:32:44 +02:00
2025-07-26 10:02:29 -07:00
2026-05-14 11:34:55 +02:00
S
Description
Omarchy with China region and Chinese language support. Fork of omacom/omarchy.
Readme MIT
452 MiB
0 Stars 1 Watchers 0 Forks