fix(greeter): do not cancel the session on a non-fatal PAM error message

greetd delivers PAM_ERROR_MSG as an auth message of type Error, and ipc.rs
turned that into Message::Error, which cancels the greetd session. But such a
message describes the current attempt, not the end of the conversation:
pam_fprintd reports "Failed to match fingerprint" this way and then retries
until max-tries is reached.

The consequence at the login screen is that a single failed fingerprint press
ends the conversation. The greeter reconnects and immediately creates a new
session, whose PAM worker calls fprintd's Claim 14 ms later while the previous
worker still holds it, so the claim is denied and no fingerprint prompt ever
appears again. The previous worker only exits when it next tries to talk to the
greeter, which can be arbitrarily far in the future, so delaying the new session
does not help either.

Per the greetd protocol every auth message has to be acknowledged with
PostAuthMessageResponse, and for a non-interactive one the response is None,
which is what the Info arm already does. Route the Error message to its own
Message::AuthError that shows the text and acknowledges it. Message::Error and
the Response::Error path stay as they are, so a failed authentication still
cancels the session.

Drafted with AI assistance (Claude Code); the change and the measurements behind
it were reviewed and tested by me on real hardware.

Signed-off-by: chris-010 <10660568+chris-010@users.noreply.github.com>
This commit is contained in:
chris-010 2026-08-09 06:34:15 +02:00 • committed by Michael Murphy
parent a133abe686
commit 935891e36b
2 changed files with 12 additions and 1 deletions

View file

@ -363,6 +363,9 @@ pub enum Message {
Common(common::Message),
OutputEvent(OutputEvent, WlOutput),
Auth(Option<String>),
/// Non-fatal error message from PAM (`PAM_ERROR_MSG`), reported by greetd as an auth
/// message of type `Error`. Unlike [`Message::Error`] the conversation stays alive.
AuthError(String),
ConfigUpdateUser,
DialogCancel,
DialogConfirm,
@ -1493,6 +1496,13 @@ impl cosmic::Application for App {
self.authenticating = true;
self.send_request(Request::PostAuthMessageResponse { response });
}
Message::AuthError(error) => {
// The conversation continues, so acknowledge like any other
// non-interactive auth message rather than cancelling the session.
self.common.error_opt = Some(error);
self.authenticating = false;
self.send_request(Request::PostAuthMessageResponse { response: None });
}
Message::Login => {
self.common.prompt_opt = None;
self.common.error_opt = None;

View file

@ -115,7 +115,8 @@ pub fn subscription() -> Subscription<Message> {
.await;
}
greetd_ipc::AuthMessageType::Error => {
_ = sender.send(Message::Error(auth_message)).await;
// PAM_ERROR_MSG: a failed attempt, not a dead session.
_ = sender.send(Message::AuthError(auth_message)).await;
}
},
greetd_ipc::Response::Error {