Skip to content

feat(classifier): recognise pam_u2f / FIDO2 login touches - #9

Draft
Talgarr wants to merge 2 commits into
mainfrom
add-rule-pam-login
Draft

feat(classifier): recognise pam_u2f / FIDO2 login touches#9
Talgarr wants to merge 2 commits into
mainfrom
add-rule-pam-login

Conversation

@Talgarr

@Talgarr Talgarr commented Jun 23, 2026

Copy link
Copy Markdown
Owner

Add an Auth rule matching pam_u2f-backed authentication that fires in-process: sudo, su, login, pkexec/polkit, display-manager workers, and screen lockers (swaylock/hyprlock/i3lock/gtklock). Both full names and their 15-char comm truncations are matched. sshd is excluded so the SSH rule keeps ownership of SSH.

@Talgarr
Talgarr force-pushed the add-rule-pam-login branch from c6f350c to 0034ae4 Compare June 25, 2026 16:29
Talgarr and others added 2 commits June 25, 2026 12:44
Add an Auth rule matching pam_u2f-backed authentication that fires
in-process: sudo, su, login, pkexec/polkit, display-manager workers,
and screen lockers (swaylock/hyprlock/i3lock/gtklock). Both full names
and their 15-char comm truncations are matched. sshd is excluded so the
SSH rule keeps ownership of SSH.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add an e2e check that runs `sudo -v` to exercise pam_u2f and assert the
classifier named the authenticating program (`sudo`). Skips unless pam_u2f
looks configured in /etc/pam.d with a registered key. Register it in the
driver and document it.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@Talgarr
Talgarr force-pushed the add-rule-pam-login branch from 0034ae4 to 21018c8 Compare June 25, 2026 16:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant