From cb9485f216dac912c204bffa0b4ee08f89eea64d Mon Sep 17 00:00:00 2001 From: David Heinemeier Hansson Date: Thu, 23 Jul 2026 15:23:26 -0700 Subject: [PATCH] Gate sudo fingerprint behind lid state too Extend the clamshell gate to /etc/pam.d/sudo, not just polkit-1. When the lid is shut the reader is unreachable, so a terminal sudo would block on "Place your finger" until pam_fprintd timed out before letting you type the password. The same pam_exec gate (success=1 skips fingerprint when the lid is closed) now runs ahead of pam_fprintd in the sudo stack as well. setup and removal share one gate definition across sudo and polkit; the migration now gates both stacks on existing installs. Resolves the clamshell case in #856 and supersedes #6003. Co-Authored-By: Claude Opus 4.8 (1M context) --- bin/omarchy-remove-security-fingerprint | 6 ++--- bin/omarchy-setup-security-fingerprint | 33 ++++++++++++++----------- migrations/1784818437.sh | 26 ++++++++++--------- 3 files changed, 36 insertions(+), 29 deletions(-) diff --git a/bin/omarchy-remove-security-fingerprint b/bin/omarchy-remove-security-fingerprint index 9bff3782..c5355a7b 100755 --- a/bin/omarchy-remove-security-fingerprint +++ b/bin/omarchy-remove-security-fingerprint @@ -7,10 +7,10 @@ set -e remove_pam_config() { - # Remove from sudo - if grep -q pam_fprintd.so /etc/pam.d/sudo; then + # Remove from sudo (both the fingerprint module and its clamshell gate) + if grep -Eq 'pam_fprintd\.so|omarchy-hw-laptop-closed' /etc/pam.d/sudo; then echo "Removing fingerprint authentication from sudo..." - sudo sed -i '/pam_fprintd\.so/d' /etc/pam.d/sudo + sudo sed -i -e '/pam_fprintd\.so/d' -e '/omarchy-hw-laptop-closed/d' /etc/pam.d/sudo fi # Remove from polkit (both the fingerprint module and its clamshell gate) diff --git a/bin/omarchy-setup-security-fingerprint b/bin/omarchy-setup-security-fingerprint index d02558dc..07bf5e10 100755 --- a/bin/omarchy-setup-security-fingerprint +++ b/bin/omarchy-setup-security-fingerprint @@ -7,23 +7,29 @@ set -e setup_pam_config() { - # Configure sudo - if ! grep -q pam_fprintd.so /etc/pam.d/sudo; then - echo "Configuring sudo for fingerprint authentication..." - sudo sed -i '1i auth sufficient pam_fprintd.so' /etc/pam.d/sudo - fi - - # Configure polkit. A clamshell gate runs before pam_fprintd: when the lid - # is shut the reader is unreachable, so it skips fingerprint (success=1) and - # PAM drops straight to the password prompt. Lid open → fingerprint, then - # password as the fallback. + # A clamshell gate runs before pam_fprintd in every stack: when the lid is + # shut the reader is unreachable, so it skips fingerprint (success=1) and PAM + # drops straight to the password prompt instead of blocking on the reader + # until it times out. Lid open → fingerprint, then password as the fallback. # # pam_exec needs a literal absolute path (no env expansion). Point at the # fixed /usr/bin path the omarchy package always provides, so the gate keeps # working across package installs and dev-link — the latter overlays # $OMARCHY_PATH trees but leaves /usr/bin untouched. - local polkit_gate="auth [success=1 default=ignore] pam_exec.so quiet /usr/bin/omarchy-hw-laptop-closed" + local fprintd_gate="auth [success=1 default=ignore] pam_exec.so quiet /usr/bin/omarchy-hw-laptop-closed" + # Configure sudo + if ! grep -q pam_fprintd.so /etc/pam.d/sudo; then + echo "Configuring sudo for fingerprint authentication..." + sudo sed -i '1i auth sufficient pam_fprintd.so' /etc/pam.d/sudo + fi + if ! grep -q 'omarchy-hw-laptop-closed' /etc/pam.d/sudo; then + echo "Adding clamshell gate to sudo..." + # Insert immediately before pam_fprintd so success=1 skips exactly it. + sudo sed -i "/pam_fprintd\.so/i $fprintd_gate" /etc/pam.d/sudo + fi + + # Configure polkit if [[ -f /etc/pam.d/polkit-1 ]]; then if ! grep -q 'pam_fprintd.so' /etc/pam.d/polkit-1; then echo "Configuring polkit for fingerprint authentication..." @@ -31,13 +37,12 @@ setup_pam_config() { fi if ! grep -q 'omarchy-hw-laptop-closed' /etc/pam.d/polkit-1; then echo "Adding clamshell gate to polkit..." - # Insert immediately before pam_fprintd so success=1 skips exactly it. - sudo sed -i "/pam_fprintd\.so/i $polkit_gate" /etc/pam.d/polkit-1 + sudo sed -i "/pam_fprintd\.so/i $fprintd_gate" /etc/pam.d/polkit-1 fi else echo "Creating polkit configuration with fingerprint authentication..." sudo tee /etc/pam.d/polkit-1 >/dev/null <