| Summary: | kscreenlocker_greet doesn't allow more unlock attempts if wrong password is entered even once. | ||
|---|---|---|---|
| Product: | [Unmaintained] kscreenlocker | Reporter: | radoslaw.sniezek |
| Component: | general | Assignee: | Plasma Bugs List <plasma-bugs-null> |
| Status: | RESOLVED DOWNSTREAM | ||
| Severity: | major | CC: | kde, nate |
| Priority: | NOR | ||
| Version First Reported In: | git-stable-Plasma/5.27 | ||
| Target Milestone: | --- | ||
| Platform: | NixOS | ||
| OS: | Linux | ||
| Latest Commit: | Version Fixed/Implemented In: | ||
| Sentry Crash Report: | |||
|
Description
radoslaw.sniezek
2024-02-29 15:08:51 UTC
This is a PAM restriction set by your distro, which the screen locker honors. I'd recommend reporting it to the NixOS folks. (In reply to Nate Graham from comment #1) > This is a PAM restriction set by your distro, which the screen locker > honors. I'd recommend reporting it to the NixOS folks. Can you provide a little more details? What is the restriction? The number of unlock attempts? I will take this to nixOs but I need to know a bit more. Shouldn't this restriction be somehow communicated to the user? How am I supposed to know at unlock screen that I will never get another attempt? Currently this feels more broken than intentional. Details can be found at: https://linux.die.net/man/8/pam_faillock Yes it would definitely be nice if this would be communicated better. We need a replacement for PAM that isn't from the 80s and designed for text terminals, which is a bigger task bigger than a bugzilla ticket. How can I verify that this is in fact the RC? I grepped through all of my pam.d files and the faillock is required only on the pam.d/su which I doubt is used here. login, xscreensaver, xlock, vlock, i3lock nor any of sddm* files in pam.d don't mention the failllock. Any other module could be the culprit here? I think this is not related to faillock but to krb5. I disabled the krb5 support on my system, which as a side effect also disables pam/krb5 module, and now the lock screen works as expected. I get the notification of incorrect password right away and after grace period I am able to try again and it unlocks if another attempt is with correct password. I found that there is this bug reported: https://bugs.kde.org/show_bug.cgi?id=481019 but am not sure if that's the same. Anyway, do you guys think that I should open an issue here, agains the locker, or append the above mentioned one, or open an issue against nixos? If the pam/krb5 module is causing this, then it's certainly not KDE's bug. Depending on what angle you're looking at the issue from, it could be considered an issue with the module, the distro's packaging, or the user's configuration. |