Gate sudo fingerprint behind lid state too
Extend the clamshell gate to /etc/pam.d/sudo, not just polkit-1. When the lid is shut the reader is unreachable, so a terminal sudo would block on "Place your finger" until pam_fprintd timed out before letting you type the password. The same pam_exec gate (success=1 skips fingerprint when the lid is closed) now runs ahead of pam_fprintd in the sudo stack as well. setup and removal share one gate definition across sudo and polkit; the migration now gates both stacks on existing installs. Resolves the clamshell case in #856 and supersedes #6003. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
8e549c27d0
commit
cb9485f216
+14
-12
@@ -1,21 +1,23 @@
|
||||
echo "Gate polkit fingerprint auth behind the lid state (password when the lid is shut)"
|
||||
echo "Gate sudo and polkit fingerprint auth behind the lid state (password when the lid is shut)"
|
||||
|
||||
# Existing fingerprint setups have pam_fprintd first in /etc/pam.d/polkit-1 but
|
||||
# no lid gate, so a closed-lid pkexec would block on the unreachable reader for
|
||||
# the full pam_fprintd timeout before offering the password. Insert a pam_exec
|
||||
# gate before pam_fprintd that skips fingerprint while the lid is closed. New
|
||||
# setups already get this from omarchy-setup-security-fingerprint.
|
||||
# Existing fingerprint setups have pam_fprintd first in /etc/pam.d/sudo and
|
||||
# /etc/pam.d/polkit-1 but no lid gate, so a closed-lid sudo or pkexec would
|
||||
# block on the unreachable reader for the full pam_fprintd timeout before
|
||||
# offering the password. Insert a pam_exec gate before pam_fprintd that skips
|
||||
# fingerprint while the lid is closed. New setups already get this from
|
||||
# omarchy-setup-security-fingerprint.
|
||||
#
|
||||
# The gate points at the fixed /usr/bin path the omarchy package always
|
||||
# provides, so it keeps working across package installs and dev-link (which
|
||||
# overlays $OMARCHY_PATH but leaves /usr/bin untouched). pam_exec needs a
|
||||
# literal absolute path — it does not expand env vars.
|
||||
|
||||
polkit_pam="/etc/pam.d/polkit-1"
|
||||
gate="auth [success=1 default=ignore] pam_exec.so quiet /usr/bin/omarchy-hw-laptop-closed"
|
||||
|
||||
if [[ -f $polkit_pam ]] &&
|
||||
grep -q 'pam_fprintd\.so' "$polkit_pam" &&
|
||||
! grep -q 'omarchy-hw-laptop-closed' "$polkit_pam"; then
|
||||
sudo sed -i "/pam_fprintd\.so/i $gate" "$polkit_pam"
|
||||
fi
|
||||
for pam in /etc/pam.d/sudo /etc/pam.d/polkit-1; do
|
||||
if [[ -f $pam ]] &&
|
||||
grep -q 'pam_fprintd\.so' "$pam" &&
|
||||
! grep -q 'omarchy-hw-laptop-closed' "$pam"; then
|
||||
sudo sed -i "/pam_fprintd\.so/i $gate" "$pam"
|
||||
fi
|
||||
done
|
||||
|
||||
Reference in New Issue
Block a user