Close three paths from an unprivileged session to root
Apply the Omabot patch on Quattro, verify effective SSH hardening, prevent stored provisioning state from restoring the blanket input-group grant, and stop Omarchy from shipping asdcontrol authorization that belongs to the package. Co-authored-by: David Heinemeier Hansson <david@hey.com>
This commit is contained in:
co-authored by
David Heinemeier Hansson
parent
943d2fcbe9
commit
df819a6f98
@@ -4,7 +4,6 @@ run_logged "$OMARCHY_INSTALL/hardware/dell-xps-touchpad-haptics.sh"
|
||||
run_logged "$OMARCHY_INSTALL/hardware/surface.sh"
|
||||
|
||||
run_logged "$OMARCHY_INSTALL/hardware/network.sh"
|
||||
run_logged "$OMARCHY_INSTALL/hardware/input-group.sh"
|
||||
run_logged "$OMARCHY_INSTALL/hardware/set-wireless-regdom.sh"
|
||||
run_logged "$OMARCHY_INSTALL/hardware/fix-fkeys.sh"
|
||||
run_logged "$OMARCHY_INSTALL/hardware/fix-synaptic-touchpad.sh"
|
||||
|
||||
@@ -1,11 +0,0 @@
|
||||
# Give this user privileged input access for dictation tools + xbox controllers to work.
|
||||
# Recorded for provisioning first-boot user creation and factory reset, granted directly
|
||||
# when the install user already exists (deferred-provisioning installs create the user at
|
||||
# first boot instead).
|
||||
provisioning_dir="${OMARCHY_PROVISIONING_DIR:-/var/lib/omarchy/provisioning}"
|
||||
mkdir -p "$provisioning_dir"
|
||||
grep -qxF input "$provisioning_dir/groups" 2>/dev/null || echo input >>"$provisioning_dir/groups"
|
||||
|
||||
if [[ -n ${OMARCHY_INSTALL_USER:-} ]] && getent passwd "$OMARCHY_INSTALL_USER" >/dev/null; then
|
||||
usermod -aG input "$OMARCHY_INSTALL_USER"
|
||||
fi
|
||||
Reference in New Issue
Block a user