A pass over the install scripts, dev-tools commands, and Hyprland Lua files that I had stuffed with explain-everything preambles. Most of those rationales (which files ship where, why hyprctl setenv doesn't suffice, etc.) belong in commit messages or PR descriptions, not in code people have to read forever. Kept the few comments that document genuinely non-obvious behaviour: the keybind-env reason for hl.env in envs.lua, why the runtime PAM seds stay scripted in increase-lockout-limit, the chroot/--now distinction in chroot.sh, and the dev-pkg-test split-install reason.
10 lines
749 B
Bash
10 lines
749 B
Bash
# /etc/pam.d/{system-auth,sddm-autologin} are upstream-owned and the changes
|
|
# are insertions, not full-file overrides, so they stay scripted.
|
|
sudo sed -i 's|^\(auth\s\+required\s\+pam_faillock.so\)\s\+preauth.*$|\1 preauth silent deny=10 unlock_time=120|' "/etc/pam.d/system-auth"
|
|
sudo sed -i 's|^\(auth\s\+\[default=die\]\s\+pam_faillock.so\)\s\+authfail.*$|\1 authfail deny=10 unlock_time=120|' "/etc/pam.d/system-auth"
|
|
|
|
# Drop both lines before re-adding authsucc so reruns don't duplicate it.
|
|
sudo sed -i '/pam_faillock\.so preauth/d' /etc/pam.d/sddm-autologin
|
|
sudo sed -i '/pam_faillock\.so authsucc/d' /etc/pam.d/sddm-autologin
|
|
sudo sed -i '/auth.*pam_permit\.so/a auth required pam_faillock.so authsucc' /etc/pam.d/sddm-autologin
|