Shrink fast-shutdown, gpg, increase-file-watchers, increase-lockout-limit to runtime-only ops
Each script's static-file write moves to omarchy-settings. The scripts keep only the runtime side: reload systemd, restart dirmngr, sysctl --system, or (for lockout-limit) the PAM seds that have to stay scripted because /etc/pam.d/system-auth and /etc/pam.d/sddm-autologin are upstream-owned and need targeted line edits rather than a full-file override. faillock.conf's deny=10 (formerly inside increase-sudo-tries.sh sed) now rides through the etc-overrides dance in omarchy-settings.
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
sudo mkdir -p /etc/systemd/system.conf.d
|
||||
sudo cp "$OMARCHY_PATH/default/systemd/faster-shutdown.conf" /etc/systemd/system.conf.d/10-faster-shutdown.conf
|
||||
sudo mkdir -p /etc/systemd/system/user@.service.d
|
||||
sudo cp "$OMARCHY_PATH/default/systemd/user@.service.d/faster-shutdown.conf" /etc/systemd/system/user@.service.d/faster-shutdown.conf
|
||||
# The two faster-shutdown drop-ins
|
||||
# (etc/systemd/system.conf.d/10-faster-shutdown.conf,
|
||||
# etc/systemd/system/user@.service.d/10-faster-shutdown.conf)
|
||||
# ship via omarchy-settings. Reload systemd so the new drop-ins take effect.
|
||||
sudo systemctl daemon-reload
|
||||
|
||||
@@ -1,6 +1,4 @@
|
||||
# Setup GPG configuration with multiple keyservers for better reliability
|
||||
sudo mkdir -p /etc/gnupg
|
||||
sudo cp ~/.local/share/omarchy/default/gpg/dirmngr.conf /etc/gnupg/
|
||||
sudo chmod 644 /etc/gnupg/dirmngr.conf
|
||||
# etc/gnupg/dirmngr.conf ships via omarchy-settings. Restart dirmngr so it
|
||||
# picks up the new keyserver list and timeout.
|
||||
sudo gpgconf --kill dirmngr || true
|
||||
sudo gpgconf --launch dirmngr || true
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# Increase inotify file watchers for VS Code, webpack, and other dev tools (default 8192 is too low)
|
||||
echo "fs.inotify.max_user_watches=524288" | sudo tee /etc/sysctl.d/90-omarchy-file-watchers.conf >/dev/null
|
||||
# etc/sysctl.d/90-omarchy-file-watchers.conf ships via omarchy-settings.
|
||||
# Apply the new sysctl values immediately.
|
||||
sudo sysctl --system >/dev/null 2>&1
|
||||
|
||||
@@ -1,3 +1,8 @@
|
||||
# The faillock.conf side ships via the omarchy-settings etc-overrides
|
||||
# (deny = 10). The two PAM file edits below remain a script because
|
||||
# /etc/pam.d/system-auth and /etc/pam.d/sddm-autologin are upstream-owned
|
||||
# and the changes are insertions, not full-file overrides.
|
||||
|
||||
# Increase lockout limit to 10 and decrease timeout to 2 minutes
|
||||
sudo sed -i 's|^\(auth\s\+required\s\+pam_faillock.so\)\s\+preauth.*$|\1 preauth silent deny=10 unlock_time=120|' "/etc/pam.d/system-auth"
|
||||
sudo sed -i 's|^\(auth\s\+\[default=die\]\s\+pam_faillock.so\)\s\+authfail.*$|\1 authfail deny=10 unlock_time=120|' "/etc/pam.d/system-auth"
|
||||
|
||||
Reference in New Issue
Block a user