Include .rpmsave files in password check #23
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Hi there 👋
recently I noticed that
yk-authwas no longer working properly on my installation. Login was possible with any password and a touch on the yubikey. After investigating this issue, I noticed that my configured login password in/etc/qubes/yk-key/yk-login-pass-hashed.hexwas renamed toyk-login-pass-hashed.hex.rpmsave. Since this file does not get recognized byyk-auth, login without password (but key) was possible.It seems the RPM instruction
%config(noreplace)has an edge case here in case of files being renamed / removed. I could not find any reference to this behavior, but it seems that in such cases, the old configuration file gets moved with an.rpmsavesuffix. At least, this is the only explanation that I can think of in my case.Since my case proofs that something like this can happen, and the impact of loosing the strength of 2 factor authentication, I think it is worth to include the
.rpmsavefile into the password check. This is what this MR tries to achieve.