Gate sudo fingerprint behind lid state too

Extend the clamshell gate to /etc/pam.d/sudo, not just polkit-1. When the
lid is shut the reader is unreachable, so a terminal sudo would block on
"Place your finger" until pam_fprintd timed out before letting you type the
password. The same pam_exec gate (success=1 skips fingerprint when the lid
is closed) now runs ahead of pam_fprintd in the sudo stack as well.

setup and removal share one gate definition across sudo and polkit; the
migration now gates both stacks on existing installs.

Resolves the clamshell case in #856 and supersedes #6003.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
David Heinemeier Hansson
2026-07-23 15:29:22 -07:00
co-authored by Claude Opus 4.8
parent 8e549c27d0
commit cb9485f216
3 changed files with 36 additions and 29 deletions
+14 -12
View File
@@ -1,21 +1,23 @@
echo "Gate polkit fingerprint auth behind the lid state (password when the lid is shut)"
echo "Gate sudo and polkit fingerprint auth behind the lid state (password when the lid is shut)"
# Existing fingerprint setups have pam_fprintd first in /etc/pam.d/polkit-1 but
# no lid gate, so a closed-lid pkexec would block on the unreachable reader for
# the full pam_fprintd timeout before offering the password. Insert a pam_exec
# gate before pam_fprintd that skips fingerprint while the lid is closed. New
# setups already get this from omarchy-setup-security-fingerprint.
# Existing fingerprint setups have pam_fprintd first in /etc/pam.d/sudo and
# /etc/pam.d/polkit-1 but no lid gate, so a closed-lid sudo or pkexec would
# block on the unreachable reader for the full pam_fprintd timeout before
# offering the password. Insert a pam_exec gate before pam_fprintd that skips
# fingerprint while the lid is closed. New setups already get this from
# omarchy-setup-security-fingerprint.
#
# The gate points at the fixed /usr/bin path the omarchy package always
# provides, so it keeps working across package installs and dev-link (which
# overlays $OMARCHY_PATH but leaves /usr/bin untouched). pam_exec needs a
# literal absolute path — it does not expand env vars.
polkit_pam="/etc/pam.d/polkit-1"
gate="auth [success=1 default=ignore] pam_exec.so quiet /usr/bin/omarchy-hw-laptop-closed"
if [[ -f $polkit_pam ]] &&
grep -q 'pam_fprintd\.so' "$polkit_pam" &&
! grep -q 'omarchy-hw-laptop-closed' "$polkit_pam"; then
sudo sed -i "/pam_fprintd\.so/i $gate" "$polkit_pam"
fi
for pam in /etc/pam.d/sudo /etc/pam.d/polkit-1; do
if [[ -f $pam ]] &&
grep -q 'pam_fprintd\.so' "$pam" &&
! grep -q 'omarchy-hw-laptop-closed' "$pam"; then
sudo sed -i "/pam_fprintd\.so/i $gate" "$pam"
fi
done