Login screen reuses last written password after user selection

Bug #1777956 reported by Marco Trevisan (Treviño)
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gnome-shell (Ubuntu)
Fix Released
Medium
Marco Trevisan (Treviño)
Bionic
Fix Released
Undecided
Unassigned

Bug Description

[ Impact ]

Login could be delayed while a loging with a wrong password could be retried.

See the screencast https://gitlab.gnome.org/GNOME/gnome-shell/uploads/9e74e74b81ef4d986a77b728e010af37/out.webm

See upstream issue https://gitlab.gnome.org/GNOME/gnome-shell/issues/311

1. Try to login up to `allowed-failures` defined with a positive value and
   using wrong password
2. Continue writing a password as soon as the interface is sensitive again
3. The interface will go back to user selection
4. Select your user and gdm will try to start the authentication

[ Test case ]

1. Try to login using a wrong password (assuming `allowed-failures` setting is default)
2. Continue writing a password as soon as the interface is sensitive again
3. The interface will go back to user selection
4. Select your user again
5. The password field is active and you can properly write the password with no wait

[ Regression potential ]

Login questions which might have been already requested on more complex pam configurations could not be properly handled (requesting answers again).

Login/Unlock retries could not be handled properly.

description: updated
description: updated
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package gnome-shell - 3.28.2-0ubuntu1

---------------
gnome-shell (3.28.2-0ubuntu1) cosmic; urgency=medium

  [ Olivier Tilloy ]
  * New upstream release
    - fixes valid password rejection at login screen (LP: #1765261)
  * Drop patches applied upstream:
    - debian/patches/polkitAgent-Guard-against-repeated-close-calls.patch
    - debian/patches/popupMenu-Fix-wrong-call-to-clutter_actor_add_child.patch
    - debian/patches/workspaceThumbnail-initialize-porthole-based-on-workArea.patch
    - debian/patches/workspaceThumbnail-only-update-_porthole-if-the-overview-.patch
    - debian/patches/workspaceThumbnail-rebuild-thumbnails-if-workareas-size-c.patch

  [ Andrea Azzarone ]
  * debian/patches/ubuntu_lock_on_suspend.patch: inhibit suspend until the
    screen is locked also in the case where automatic screen lock is disabled
    and screen lock on suspend is enabled (LP: #1768786)

  [ Marco Trevisan (Treviño) ]
  * Cherry pick upstream patches:
    - debian/patches/st-label-Unset-clutter-text-instance-on-disposal.patch (LP: #1714989)
  * debian/patches/st-texture-cache-Don-t-add-NULL-textures-to-cache.patch:
    - Cherry pick updated version from upstream, splitted in:
    + debian/patches/st-texture-cache-Don-t-add-NULL-textures-to-cache.patch
    + debian/patches/st-texture-cache-Save-cairo-surfaces-to-a-different-map.patch
  * debian/patches/authPrompt-Do-not-enable-sensitivity-if-retries-are-disal.patch
    debian/patches/authPrompt-Unset-preemptiveAnswer-on-reset.patch
    debian/patches/gdm-util-Always-allow-to-retry-login-in-unlock-mode.patch:
    - GDM gnome-shell greeter fix to fix unneeded login attempts (LP: #1777956)
  * debian/patches/series:
    - reorder to apply upstream cherry-picks before the others

  [ Daniel van Vugt ]
  * debian/patches/magnifier.js-Fix-zoom-juddering.patch:
    - magnifier.js: Fix zoom juddering (LP: #1691675)

 -- Marco Trevisan (Treviño) <email address hidden> Thu, 21 Jun 2018 01:59:11 +0200

Changed in gnome-shell (Ubuntu):
status: In Progress → Fix Released
description: updated
Revision history for this message
Brian Murray (brian-murray) wrote : Please test proposed package

Hello Marco, or anyone else affected,

Accepted gnome-shell into bionic-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/gnome-shell/3.28.2-0ubuntu0.18.04.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-bionic to verification-done-bionic. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-bionic. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

Changed in gnome-shell (Ubuntu Bionic):
status: New → Fix Committed
tags: added: verification-needed verification-needed-bionic
Revision history for this message
Sebastien Bacher (seb128) wrote :

the password prompt behaves correctly in 3.28.2-0ubuntu0.18.04.1

tags: added: verification-done verification-done-bionic
removed: verification-needed verification-needed-bionic
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package gnome-shell - 3.28.2-0ubuntu0.18.04.1

---------------
gnome-shell (3.28.2-0ubuntu0.18.04.1) bionic; urgency=medium

  [ Olivier Tilloy ]
  * New upstream release (LP: #1775145)
    - fixes valid password rejection at login screen (LP: #1765261)
  * Drop patches applied upstream:
    - debian/patches/polkitAgent-Guard-against-repeated-close-calls.patch
    - debian/patches/popupMenu-Fix-wrong-call-to-clutter_actor_add_child.patch
    - debian/patches/workspaceThumbnail-initialize-porthole-based-on-workArea.patch
    - debian/patches/workspaceThumbnail-only-update-_porthole-if-the-overview-.patch
    - debian/patches/workspaceThumbnail-rebuild-thumbnails-if-workareas-size-c.patch

  [ Andrea Azzarone ]
  * debian/patches/ubuntu_lock_on_suspend.patch: inhibit suspend until the
    screen is locked also in the case where automatic screen lock is disabled
    and screen lock on suspend is enabled (LP: #1768786)

  [ Marco Trevisan (Treviño) ]
  * Cherry pick upstream patches:
    - debian/patches/st-label-Unset-clutter-text-instance-on-disposal.patch (LP: #1714989)
  * debian/patches/st-texture-cache-Don-t-add-NULL-textures-to-cache.patch:
    - Cherry pick updated version from upstream, splitted in:
    + debian/patches/st-texture-cache-Don-t-add-NULL-textures-to-cache.patch
    + debian/patches/st-texture-cache-Save-cairo-surfaces-to-a-different-map.patch
  * debian/patches/authPrompt-Do-not-enable-sensitivity-if-retries-are-disal.patch
    debian/patches/authPrompt-Unset-preemptiveAnswer-on-reset.patch
    debian/patches/gdm-util-Always-allow-to-retry-login-in-unlock-mode.patch:
    - GDM gnome-shell greeter fix to fix unneeded login attempts (LP: #1777956)
  * debian/patches/series:
    - reorder to apply upstream cherry-picks before the others

  [ Daniel van Vugt ]
  * debian/patches/magnifier.js-Fix-zoom-juddering.patch:
    - magnifier.js: Fix zoom juddering (LP: #1691675)

 -- Marco Trevisan <email address hidden> Tue, 21 Jun 2018 01:45:42 +0200

Changed in gnome-shell (Ubuntu Bionic):
status: Fix Committed → Fix Released
Revision history for this message
Steve Langasek (vorlon) wrote : Update Released

The verification of the Stable Release Update for gnome-shell has completed successfully and the package has now been released to -updates. Subsequently, the Ubuntu Stable Release Updates Team is being unsubscribed and will not receive messages about this bug report. In the event that you encounter a regression using the package from -updates please report a new bug using ubuntu-bug and tag the bug report regression-update so we can easily find any regressions.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.