fix: name SCARD_W_SECURITY_VIOLATION and point at the polkit rule

Seen on the first Arch field test: pcscd up, but polkit denied the
user, and the CLI only printed the raw 0x8010006A.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-09-20 22:05:01 +02:00
commit b655392893
2 changed files with 22 additions and 3 deletions

View file

@ -171,9 +171,21 @@ changes travel encrypted).
| `card already looks provisioned` | it has SDM on or non-zero key versions; wipe first (`--force` only if you know k0 is zero) | | `card already looks provisioned` | it has SDM on or non-zero key versions; wipe first (`--force` only if you know k0 is zero) |
| `this is not an NTAG 424 DNA` | wrong tag; Bolt Cards need NTAG 424 DNA | | `this is not an NTAG 424 DNA` | wrong tag; Bolt Cards need NTAG 424 DNA |
If the user cannot access the reader (permission errors from pcscd), Arch's | `SCARD_W_SECURITY_VIOLATION` (0x8010006A) | polkit refused your user access to pcscd. Arch's pcsclite only auto-allows local *active* logins, so SSH sessions and some Wayland setups are denied. Grant it explicitly (below) |
pcsclite uses polkit: the session must be a local active login, or add a rule
for `org.debian.pcsc-lite.access_pcsc` / `access_card`. ```sh
sudo tee /etc/polkit-1/rules.d/50-pcscd.rules >/dev/null <<'EOF'
polkit.addRule(function(action, subject) {
if ((action.id == "org.debian.pcsc-lite.access_pcsc" ||
action.id == "org.debian.pcsc-lite.access_card") &&
subject.isInGroup("wheel")) {
return polkit.Result.YES;
}
});
EOF
```
Takes effect immediately, no restart.
## Nix / NixOS ## Nix / NixOS

View file

@ -51,6 +51,7 @@ SCARD_E_COMM_DATA_LOST = 0x8010002F
SCARD_W_UNRESPONSIVE_CARD = 0x80100066 SCARD_W_UNRESPONSIVE_CARD = 0x80100066
SCARD_W_UNPOWERED_CARD = 0x80100067 SCARD_W_UNPOWERED_CARD = 0x80100067
SCARD_W_REMOVED_CARD = 0x80100069 SCARD_W_REMOVED_CARD = 0x80100069
SCARD_W_SECURITY_VIOLATION = 0x8010006A
ERROR_NAMES = { ERROR_NAMES = {
SCARD_E_INVALID_HANDLE: "SCARD_E_INVALID_HANDLE", SCARD_E_INVALID_HANDLE: "SCARD_E_INVALID_HANDLE",
@ -69,6 +70,7 @@ ERROR_NAMES = {
SCARD_W_UNRESPONSIVE_CARD: "SCARD_W_UNRESPONSIVE_CARD", SCARD_W_UNRESPONSIVE_CARD: "SCARD_W_UNRESPONSIVE_CARD",
SCARD_W_UNPOWERED_CARD: "SCARD_W_UNPOWERED_CARD", SCARD_W_UNPOWERED_CARD: "SCARD_W_UNPOWERED_CARD",
SCARD_W_REMOVED_CARD: "SCARD_W_REMOVED_CARD", SCARD_W_REMOVED_CARD: "SCARD_W_REMOVED_CARD",
SCARD_W_SECURITY_VIOLATION: "SCARD_W_SECURITY_VIOLATION",
} }
HINTS = { HINTS = {
@ -80,6 +82,11 @@ HINTS = {
), ),
SCARD_E_SHARING_VIOLATION: ("another program holds the reader (pcsc_scan, another writer instance?)"), SCARD_E_SHARING_VIOLATION: ("another program holds the reader (pcsc_scan, another writer instance?)"),
SCARD_E_READER_UNAVAILABLE: "the reader was unplugged", SCARD_E_READER_UNAVAILABLE: "the reader was unplugged",
SCARD_W_SECURITY_VIOLATION: (
"polkit denied this user access to pcscd (happens over SSH or when the desktop "
"session is not active in logind). Add a rule, see README > Troubleshooting, "
"or run once with sudo to confirm the reader works."
),
} }
# Card temporarily absent / not ready: keep polling. # Card temporarily absent / not ready: keep polling.