Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 304657 - <kde-base/krunner-4.4.0-r1: lock module race condition
Summary: <kde-base/krunner-4.4.0-r1: lock module race condition
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://www.kde.org/info/security/advi...
Whiteboard: ~4 [noglsa]
Keywords:
: 308077 (view as bug list)
Depends on:
Blocks:
 
Reported: 2010-02-12 01:56 UTC by Marc Schiffbauer
Modified: 2010-09-18 12:36 UTC (History)
6 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marc Schiffbauer gentoo-dev 2010-02-12 01:56:38 UTC
the screensaver lock can be broken easily



Reproducible: Always

Steps to Reproduce:
* use kde 4.4
* lock the screen
* press key so the password prompt opens
* hold down the return key
Actual Results:  
Screensaver exits

Expected Results:  
Screensaver should stay alive
Comment 1 Ai Locke Shinseiko (Wizzleby) 2010-02-12 02:20:47 UTC
(In reply to comment #0)
I can reproduce this as well,
in my case holding enter does nothing, but after the second attempt of hitting enter at the screen lock password prompt with no password entered, it let me in.
Comment 2 John J. Aylward 2010-02-12 02:28:12 UTC
on AMD64 and I can't get the screensaver to come on at all. I can open the preferences and test it, and also if I use KDM auto-login and lock screen it'll lock that first time with the screen saver active. However, if I disable auto-login or try to lock the screen at all (using the menu options or the hot-key) nothing happens. I can't seem to find a log message indicating what went wrong either.
Comment 3 Dan Coats 2010-02-12 03:20:35 UTC
(In reply to comment #2)
> on AMD64 and I can't get the screensaver to come on at all. I can open the
> preferences and test it, and also if I use KDM auto-login and lock screen it'll
> lock that first time with the screen saver active. However, if I disable
> auto-login or try to lock the screen at all (using the menu options or the
> hot-key) nothing happens. I can't seem to find a log message indicating what
> went wrong either.
> 

This bug is not about screensaver/Kscreensaver. This bug is about an upstream issue with kscreenlocker. The upstream bug is filed at https://bugs.kde.org/show_bug.cgi?id=226449
Comment 4 Vincent Le Ligeour 2010-02-12 16:46:03 UTC
(In reply to comment #3)
> (In reply to comment #2)
> > on AMD64 and I can't get the screensaver to come on at all. I can open the
> > preferences and test it, and also if I use KDM auto-login and lock screen it'll
> > lock that first time with the screen saver active. However, if I disable
> > auto-login or try to lock the screen at all (using the menu options or the
> > hot-key) nothing happens. I can't seem to find a log message indicating what
> > went wrong either.
> > 
> 
> This bug is not about screensaver/Kscreensaver. This bug is about an upstream
> issue with kscreenlocker. The upstream bug is filed at
> https://bugs.kde.org/show_bug.cgi?id=226449
> 

I experience the bug reported in comment #2 and I'm not sure it is the same as the comment #1 that is exactly what was reported on kde bugtracker
Comment 5 Ai Locke Shinseiko (Wizzleby) 2010-02-12 18:39:09 UTC
kde bug 226449 is listed as a dupe of kde bug 217882

kde bug 217882 is now closed as: resolved, fixed.


https://bugs.kde.org/show_bug.cgi?id=217882
at comment 16, the link is given to the fixed revision.

http://websvn.kde.org/?view=rev&revision=1089213
Comment 6 John J. Aylward 2010-02-13 15:27:17 UTC
(In reply to comment #4)
> (In reply to comment #3)
> > (In reply to comment #2)
> > > on AMD64 and I can't get the screensaver to come on at all. I can open the
> > > preferences and test it, and also if I use KDM auto-login and lock screen it'll
> > > lock that first time with the screen saver active. However, if I disable
> > > auto-login or try to lock the screen at all (using the menu options or the
> > > hot-key) nothing happens. I can't seem to find a log message indicating what
> > > went wrong either.
> > > 
> > 
> > This bug is not about screensaver/Kscreensaver. This bug is about an upstream
> > issue with kscreenlocker. The upstream bug is filed at
> > https://bugs.kde.org/show_bug.cgi?id=226449
> > 
> 
> I experience the bug reported in comment #2 and I'm not sure it is the same as
> the comment #1 that is exactly what was reported on kde bugtracker
> 

I found a workaround for the issue I'm seeing is to disable the semantic-desktop use flag. After recompiling the items with the flag disabled the screensaver works now.
Comment 7 Tobias Heinlein (RETIRED) gentoo-dev 2010-02-17 17:30:36 UTC
Thanks for the report, everyone.

KDE team: Looking at the patch in CVS, I assume krunner-4.4.0-r1 already has the fix. Thanks! 

Since 4.4.0 is the only version affected and has never been stable, this bug is resolved.

If I missed something, please reopen.
Comment 8 Stefan Behte (RETIRED) gentoo-dev Security 2010-03-06 16:52:00 UTC
*** Bug 308077 has been marked as a duplicate of this bug. ***