fix: name SCARD_W_SECURITY_VIOLATION and point at the polkit rule

Seen on the first Arch field test: pcscd up, but polkit denied the
user, and the CLI only printed the raw 0x8010006A.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-09-20 22:05:01 +02:00
commit b655392893
2 changed files with 22 additions and 3 deletions

View file

@ -171,9 +171,21 @@ changes travel encrypted).
| `card already looks provisioned` | it has SDM on or non-zero key versions; wipe first (`--force` only if you know k0 is zero) |
| `this is not an NTAG 424 DNA` | wrong tag; Bolt Cards need NTAG 424 DNA |
If the user cannot access the reader (permission errors from pcscd), Arch's
pcsclite uses polkit: the session must be a local active login, or add a rule
for `org.debian.pcsc-lite.access_pcsc` / `access_card`.
| `SCARD_W_SECURITY_VIOLATION` (0x8010006A) | polkit refused your user access to pcscd. Arch's pcsclite only auto-allows local *active* logins, so SSH sessions and some Wayland setups are denied. Grant it explicitly (below) |
```sh
sudo tee /etc/polkit-1/rules.d/50-pcscd.rules >/dev/null <<'EOF'
polkit.addRule(function(action, subject) {
if ((action.id == "org.debian.pcsc-lite.access_pcsc" ||
action.id == "org.debian.pcsc-lite.access_card") &&
subject.isInGroup("wheel")) {
return polkit.Result.YES;
}
});
EOF
```
Takes effect immediately, no restart.
## Nix / NixOS