Bug 424854 - Some keyboard events can bypass lock screen
Summary: Some keyboard events can bypass lock screen
Status: RESOLVED WORKSFORME
Alias: None
Product: kscreenlocker
Classification: Plasma
Component: general (show other bugs)
Version: unspecified
Platform: Manjaro Linux
: NOR normal
Target Milestone: ---
Assignee: Plasma Bugs List
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-07-31 10:21 UTC by Giorgi Gzirishvili
Modified: 2021-07-21 04:33 UTC (History)
2 users (show)

See Also:
Latest Commit:
Version Fixed In:
Sentry Crash Report:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Giorgi Gzirishvili 2020-07-31 10:21:46 UTC
I just discovered that in Plasma 5.19, hitting Meta key while you're on the lock screen triggers the Application Launcher behind the scene; after that, you can unlock to confirm the result. Fortunately, it doesn't accept input while locked, and I found no such issues regarding other keyboard events. Still, it *might* turn out to be somewhat serious.


STEPS TO REPRODUCE
1. Lock the screen.
2. Hit <kbd>Meta</kbd>.
3. Unlock the screen.
4. Observe the open launcher.

OBSERVED RESULT
A wild launcher appears!

EXPECTED RESULT
It shouldn't.

SOFTWARE/OS VERSIONS
- OS: Manjaro 20.0.3 (Lysia)
- Architecture: x86-64
- Kernel: Linux kernel 5.7.9 (5.7.9-1-MANJARO)
- Desktop: KDE Plasma 5.19.3
  - KDE Frameworks 5.72.0
  - Qt 5.15.0
- Windowing system: XCB (X.Org 1.20.8)

ADDITIONAL INFORMATION
N/A
Comment 1 Nate Graham 2021-06-21 22:36:56 UTC
Cannot reproduce with Plasma 5.22. Can you?
Comment 2 Bug Janitor Service 2021-07-06 04:34:01 UTC
Dear Bug Submitter,

This bug has been in NEEDSINFO status with no change for at least
15 days. Please provide the requested information as soon as
possible and set the bug status as REPORTED. Due to regular bug
tracker maintenance, if the bug is still in NEEDSINFO status with
no change in 30 days the bug will be closed as RESOLVED > WORKSFORME
due to lack of needed information.

For more information about our bug triaging procedures please read the
wiki located here:
https://community.kde.org/Guidelines_and_HOWTOs/Bug_triaging

If you have already provided the requested information, please
mark the bug as REPORTED so that the KDE team knows that the bug is
ready to be confirmed.

Thank you for helping us make KDE software even better for everyone!
Comment 3 Bug Janitor Service 2021-07-21 04:33:42 UTC
This bug has been in NEEDSINFO status with no change for at least
30 days. The bug is now closed as RESOLVED > WORKSFORME
due to lack of needed information.

For more information about our bug triaging procedures please read the
wiki located here:
https://community.kde.org/Guidelines_and_HOWTOs/Bug_triaging

Thank you for helping us make KDE software even better for everyone!