From 935891e36bf265a3c65906694badc1e66cfc091d Mon Sep 17 00:00:00 2001 From: chris-010 <10660568+chris-010@users.noreply.github.com> Date: Sun, 9 Aug 2026 06:34:15 +0200 Subject: [PATCH] fix(greeter): do not cancel the session on a non-fatal PAM error message greetd delivers PAM_ERROR_MSG as an auth message of type Error, and ipc.rs turned that into Message::Error, which cancels the greetd session. But such a message describes the current attempt, not the end of the conversation: pam_fprintd reports "Failed to match fingerprint" this way and then retries until max-tries is reached. The consequence at the login screen is that a single failed fingerprint press ends the conversation. The greeter reconnects and immediately creates a new session, whose PAM worker calls fprintd's Claim 14 ms later while the previous worker still holds it, so the claim is denied and no fingerprint prompt ever appears again. The previous worker only exits when it next tries to talk to the greeter, which can be arbitrarily far in the future, so delaying the new session does not help either. Per the greetd protocol every auth message has to be acknowledged with PostAuthMessageResponse, and for a non-interactive one the response is None, which is what the Info arm already does. Route the Error message to its own Message::AuthError that shows the text and acknowledges it. Message::Error and the Response::Error path stay as they are, so a failed authentication still cancels the session. Drafted with AI assistance (Claude Code); the change and the measurements behind it were reviewed and tested by me on real hardware. Signed-off-by: chris-010 <10660568+chris-010@users.noreply.github.com> --- src/greeter.rs | 10 ++++++++++ src/greeter/ipc.rs | 3 ++- 2 files changed, 12 insertions(+), 1 deletion(-) diff --git a/src/greeter.rs b/src/greeter.rs index 6431496..4a6063f 100644 --- a/src/greeter.rs +++ b/src/greeter.rs @@ -363,6 +363,9 @@ pub enum Message { Common(common::Message), OutputEvent(OutputEvent, WlOutput), Auth(Option), + /// Non-fatal error message from PAM (`PAM_ERROR_MSG`), reported by greetd as an auth + /// message of type `Error`. Unlike [`Message::Error`] the conversation stays alive. + AuthError(String), ConfigUpdateUser, DialogCancel, DialogConfirm, @@ -1493,6 +1496,13 @@ impl cosmic::Application for App { self.authenticating = true; self.send_request(Request::PostAuthMessageResponse { response }); } + Message::AuthError(error) => { + // The conversation continues, so acknowledge like any other + // non-interactive auth message rather than cancelling the session. + self.common.error_opt = Some(error); + self.authenticating = false; + self.send_request(Request::PostAuthMessageResponse { response: None }); + } Message::Login => { self.common.prompt_opt = None; self.common.error_opt = None; diff --git a/src/greeter/ipc.rs b/src/greeter/ipc.rs index d3f1e45..4e92afe 100644 --- a/src/greeter/ipc.rs +++ b/src/greeter/ipc.rs @@ -115,7 +115,8 @@ pub fn subscription() -> Subscription { .await; } greetd_ipc::AuthMessageType::Error => { - _ = sender.send(Message::Error(auth_message)).await; + // PAM_ERROR_MSG: a failed attempt, not a dead session. + _ = sender.send(Message::AuthError(auth_message)).await; } }, greetd_ipc::Response::Error {