From 98df07df93df1cb091c95451f7162dca1a2ae2dd Mon Sep 17 00:00:00 2001 From: Ganga Ram Date: Wed, 30 Sep 2026 19:13:38 +0400 Subject: [PATCH] fix: cancel session on interactive auth failure - Completes PAM transactions on failed passwords while preserving non-interactive sessions for retries. Signed-off-by: Ganga Ram --- src/greeter.rs | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/src/greeter.rs b/src/greeter.rs index c19ba9d..852e219 100644 --- a/src/greeter.rs +++ b/src/greeter.rs @@ -1556,11 +1556,16 @@ impl cosmic::Application for App { self.send_request(Request::PostAuthMessageResponse { response }); } Message::AuthError(error) => { - // The conversation continues, so acknowledge like any other - // non-interactive auth message rather than cancelling the session. self.common.error_opt = Some(error); - self.authenticating = false; - self.send_request(Request::PostAuthMessageResponse { response: None }); + if self.authenticating { + // Cancel failed password session so pam_faillock records the attempt. + self.authenticating = false; + self.send_request(Request::CancelSession); + } else { + // The conversation continues, so acknowledge like any other + // non-interactive auth message rather than cancelling the session. + self.send_request(Request::PostAuthMessageResponse { response: None }); + } } Message::Login => { self.common.prompt_opt = None;