Files
omarchycn/bin/omarchy-setup-security-fingerprint
T
9b03f15b4f Detect Elan match-on-chip fingerprint readers again (#6578)
* Detect Elan match-on-chip fingerprint readers again

Elan readers report "ELAN:ARM-M4" as their product string, so the
*fingerprint* and *biometric* checks miss them. Elan's 04f3 is also left
out of the vendor list on purpose, because Elan makes touchscreens too.
Both checks fail, so the machine looks like it has no reader.

Add "elan:arm-m4" to the product string check. The comment above the
vendor list already says the excluded vendors should still match there,
so this makes that true. The vendor list and its has_kernel_driver guard
are unchanged, and touchscreens still cannot cause a false positive.

The string is a family name, not one device. libfprint uses it for
04f3:0c9c and 04f3:0ca7 as well as 04f3:0ca8.

Tested on an HP EliteBook X G2i with 04f3:0ca8.

* Point the Elan comment at the vendor list above it

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Configure PAM only after a fingerprint enrolls and verifies

Detection proves a reader is present, not that libfprint can drive it.
Elan MOC sensors outside the elanmoc table pass the gate and then fail
to enroll, which left pam_fprintd in the sudo and polkit stacks with no
print to match.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-09 21:54:01 +02:00

112 lines
4.1 KiB
Bash
Executable File

#!/bin/bash
# omarchy:summary=Set up fingerprint authentication for sudo, polkit, and lock screen
# omarchy:requires-sudo=true
set -e
setup_pam_config() {
# A clamshell gate runs before pam_fprintd in every stack: when the lid is
# shut the reader is unreachable, so it skips fingerprint (success=1) and PAM
# drops straight to the password prompt instead of blocking on the reader
# until it times out. Lid open → fingerprint, then password as the fallback.
#
# pam_exec needs a literal absolute path (no env expansion). Point at the
# fixed /usr/bin path the omarchy package always provides, so the gate keeps
# working across package installs and dev-link — the latter overlays
# $OMARCHY_PATH trees but leaves /usr/bin untouched.
local fprintd_gate="auth [success=1 default=ignore] pam_exec.so quiet /usr/bin/omarchy-hw-laptop-closed"
# Configure sudo
if ! grep -q pam_fprintd.so /etc/pam.d/sudo; then
echo "Configuring sudo for fingerprint authentication..."
sudo sed -i '1i auth sufficient pam_fprintd.so' /etc/pam.d/sudo
fi
if ! grep -q 'omarchy-hw-laptop-closed' /etc/pam.d/sudo; then
echo "Adding clamshell gate to sudo..."
# Insert immediately before pam_fprintd so success=1 skips exactly it.
sudo sed -i "/pam_fprintd\.so/i $fprintd_gate" /etc/pam.d/sudo
fi
# Configure polkit
if [[ -f /etc/pam.d/polkit-1 ]]; then
if ! grep -q 'pam_fprintd.so' /etc/pam.d/polkit-1; then
echo "Configuring polkit for fingerprint authentication..."
sudo sed -i '1i auth sufficient pam_fprintd.so' /etc/pam.d/polkit-1
fi
if ! grep -q 'omarchy-hw-laptop-closed' /etc/pam.d/polkit-1; then
echo "Adding clamshell gate to polkit..."
sudo sed -i "/pam_fprintd\.so/i $fprintd_gate" /etc/pam.d/polkit-1
fi
else
echo "Creating polkit configuration with fingerprint authentication..."
sudo tee /etc/pam.d/polkit-1 >/dev/null <<EOF
$fprintd_gate
auth sufficient pam_fprintd.so
auth required pam_unix.so
account required pam_unix.so
password required pam_unix.so
session required pam_unix.so
EOF
fi
}
setup_lock_fingerprint_pam() {
echo "Configuring lock screen for fingerprint authentication..."
sudo tee /etc/pam.d/omarchy-lock-fingerprint >/dev/null <<'EOF'
#%PAM-1.0
auth required pam_fprintd.so
account include system-local-login
EOF
}
echo -e "\e[32mSetting up fingerprint scanner for authentication.\n\e[0m"
# Bail before installing anything if there's no reader to talk to.
if ! omarchy-hw-fingerprint; then
echo -e "\e[31mNo fingerprint sensor detected.\e[0m"
exit 1
fi
# Install required packages
echo "Installing required packages..."
# libfprint-git provides+conflicts libfprint; pacman -S --noconfirm
# defaults the conflict prompt to N and aborts. Pre-remove it (deps-only,
# so an installed fprintd stays put) so stock libfprint installs cleanly.
if pacman -Q libfprint-git &>/dev/null; then
sudo pacman -Rdd --noconfirm libfprint-git
fi
omarchy-pkg-add libfprint fprintd usbutils
# Enroll first fingerprint
echo -e "\e[32m\nLet's setup your right index finger as the first fingerprint.\e[0m"
echo -e "Keep moving the finger around on sensor until the process completes.\n"
if sudo fprintd-enroll "$USER"; then
echo -e "\e[32m\nFingerprint enrolled successfully!\e[0m"
# Verify
echo -e "\nNow let's verify that it's working correctly.\n"
if fprintd-verify; then
# PAM comes last, once a print is enrolled and verified. Detection only
# proves a reader is there, not that libfprint can drive it — an Elan MOC
# sensor outside the elanmoc table gets this far and then fails to enroll.
# Editing the stacks up front would leave those machines pointing at
# pam_fprintd with nothing to match.
setup_pam_config
setup_lock_fingerprint_pam
echo -e "\e[32m\nPerfect! Fingerprint authentication is now configured.\e[0m"
echo "You can use your fingerprint for sudo, polkit, and lock screen (Super + Ctrl + L)."
else
echo -e "\e[31m\nVerification failed. You may want to try enrolling again.\e[0m"
fi
else
echo -e "\e[31m\nEnrollment failed. Please try again.\e[0m"
exit 1
fi