Files
omarchy/migrations
rattatuiandClaude Opus 4.8 8a13eac872 Defer to system-auth in the polkit stack written by fingerprint/FIDO2 setup
The fingerprint and FIDO2 setup commands create /etc/pam.d/polkit-1 from
scratch on Arch, where the polkit package ships its stack in
/usr/lib/pam.d/polkit-1 and /etc/pam.d/polkit-1 does not exist. The
hand-rolled stack listed pam_unix directly instead of including system-auth,
which dropped pam_faillock from the polkit path: polkit prompts had no
brute-force lockout, their failures were not recorded, and they did not count
toward the lockout protecting login and sudo. Defer to system-auth, matching
the vendor file and the sudo stack, keeping the clamshell gate and the
pam_fprintd / pam_u2f sufficient lines in front.

Add a migration to repair installs the old setup already configured, since the
forward fix does not rewrite an existing polkit-1. It acts only on an
Omarchy-created polkit-1 that lacks the system-auth include and carries a
hardware-auth marker, preserves the configured auth lines, backs up the
original, and is idempotent.

Add a test asserting the stack each setup creates defers to system-auth; the
created polkit content was previously untested.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-02 21:41:53 +03:00
..
2026-06-12 13:49:46 -04:00
2026-06-12 13:49:46 -04:00
2026-06-12 13:49:46 -04:00
2026-06-12 13:49:46 -04:00
2026-06-12 13:49:46 -04:00
2026-06-12 13:49:46 -04:00
2026-06-29 08:51:15 -05:00
2026-06-20 15:44:37 -04:00
2026-06-21 02:25:42 -04:00
2026-06-21 12:31:06 +02:00
2026-07-19 09:59:13 -07:00
2026-07-24 19:49:13 -07:00
2026-07-28 21:07:50 -04:00
2026-07-29 12:27:38 -07:00
2026-08-01 21:56:51 -05:00
2026-08-01 19:32:32 -07:00
2026-08-11 13:56:09 +02:00