Bug 1488790 - Session unlocked after resuming from hibernate, private data visible, login screen missing
Summary: Session unlocked after resuming from hibernate, private data visible, login s...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: cinnamon-screensaver
Version: 26
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: ---
Assignee: Alternative GTK desktop environments
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-09-06 08:12 UTC by Basic Six
Modified: 2017-11-11 03:06 UTC (History)
4 users (show)

Fixed In Version: cinnamon-screensaver-3.4.3-1.fc25 cinnamon-screensaver-3.4.3-1.fc26 cinnamon-screensaver-3.6.0-2.fc26 cinnamon-screensaver-3.4.3-1.fc27 cinnamon-screensaver-3.6.0-2.fc27
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2017-11-04 21:08:55 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
Cinnamon session unlocked, black rectangle (38.68 KB, image/png)
2017-09-06 08:12 UTC, Basic Six
no flags Details

Description Basic Six 2017-09-06 08:12:26 UTC
Created attachment 1322559 [details]
Cinnamon session unlocked, black rectangle

Description of problem:

This computer was in hibernate mode. After turning it on, it unlocked the session right away and a private email was visible on the screen. I'm setting the severity of this bug report to high because having private data exposed without any password prompt is not just another bug, it's unacceptable.

As can be seen in the attached screenshot, a black rectangle was shown in the top left corner of the screen. It looks like this was the screensaver program which failed to lock the screen and instead just showed this rectangle. It was necessary to switch to another tty, identify the process and kill it to get rid of it.



Version-Release number of selected component (if applicable):

Linux 4.11.11-300.fc26.x86_64
Fedora 26
cinnamon-screensaver 3.4.1



How reproducible:

Not sure how often this happens, but resuming with a different monitor might be a factor.



Steps to Reproduce:
1. Hibernate system (no external monitor or small monitor).
2. Connect laptop to external monitor (or bigger monitor).
3. Resume.



Actual results:

1. Session unlocked, private data exposed for everyone to see.
2. Password prompt / lock screen missing.
3. Black rectangle blocking parts of the screen (process must be killed).



Expected results:

It should work just like hibernating has been working on other operating systems for more than 10 years.

Under no circumstances is it acceptable to have private data exposed without password prompt.



Additional info:

It's probably relevant that this laptop was previously used without external monitor and it's now in a docking station with a bigger monitor, where it was resumed from hibernate mode.

Even though the screenshot might suggest that it's Mate that is used as desktop environment, it's actually Cinnamon. After resuming from hibernate, Cinnamon showed a message that it crashed, that's why it looks that way. However, the fact that Cinnamon crashes sometimes is not part of this bug report. This bug is about the missing password prompt and the fact that simply pressing the power button showed a screen with sensitive data exposed, which is a security risk. This is not how a modern operating system in the 21st century should work.

Comment 1 leigh scott 2017-09-06 12:39:49 UTC
Should be fixed in cinnamon-screensaver-3.4.2-1

Comment 3 Basic Six 2017-09-18 13:11:51 UTC
None of the 5 points on that page mention the black rectangle, so it's not clear if that's really fixed or not.
However, the second point mentions the screen size, which appears to be part of the issue. This is good news.

I am not able to confirm this as fixed though. It hasn't happened in the last few days, but that doesn't mean anything because it doesn't happen every single time. Generally, it seems like there's a new surprise every now and then when a laptop is put into a docking station. This bug is one of them.

If the bug is fixed upstream, you may close this bug.

Comment 4 Fedora Update System 2017-10-12 11:53:10 UTC
cinnamon-screensaver-3.4.3-1.fc26 has been submitted as an update to Fedora 26. https://bodhi.fedoraproject.org/updates/FEDORA-2017-7e466aa2ed

Comment 5 Fedora Update System 2017-10-12 11:53:31 UTC
cinnamon-screensaver-3.4.3-1.el7 has been submitted as an update to Fedora EPEL 7. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-3f44186174

Comment 6 Fedora Update System 2017-10-12 11:53:46 UTC
cinnamon-screensaver-3.4.3-1.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2017-553bf0cce4

Comment 7 Fedora Update System 2017-10-12 11:54:02 UTC
cinnamon-screensaver-3.4.3-1.fc25 has been submitted as an update to Fedora 25. https://bodhi.fedoraproject.org/updates/FEDORA-2017-efdf564c2b

Comment 8 Fedora Update System 2017-10-13 04:20:10 UTC
cinnamon-screensaver-3.4.3-1.el7 has been pushed to the Fedora EPEL 7 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-3f44186174

Comment 9 Fedora Update System 2017-10-13 04:24:20 UTC
cinnamon-screensaver-3.4.3-1.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-7e466aa2ed

Comment 10 Fedora Update System 2017-10-13 04:51:04 UTC
cinnamon-screensaver-3.4.3-1.fc25 has been pushed to the Fedora 25 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-efdf564c2b

Comment 11 Fedora Update System 2017-10-13 06:24:45 UTC
cinnamon-screensaver-3.4.3-1.fc27 has been pushed to the Fedora 27 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-553bf0cce4

Comment 12 Fedora Update System 2017-10-25 22:58:00 UTC
nemo-extensions-3.6.0-1.fc26 nemo-3.6.2-1.fc26 cinnamon-3.6.0-1.fc26 cinnamon-control-center-3.6.0-1.fc26 cinnamon-session-3.6.0-1.fc26 cinnamon-screensaver-3.6.0-2.fc26 muffin-3.6.0-1.fc26 cinnamon-settings-daemon-3.6.0-1.fc26 cinnamon-translations-3.6.0-1.fc26 cinnamon-desktop-3.6.0-1.fc26 xapps-1.0.4-1.fc26 cinnamon-menus-3.6.0-1.fc26 cjs-3.6.0-1.fc26 has been submitted as an update to Fedora 26. https://bodhi.fedoraproject.org/updates/FEDORA-2017-cef381f3ca

Comment 13 Fedora Update System 2017-10-25 22:58:30 UTC
nemo-extensions-3.6.0-1.fc27 nemo-3.6.2-1.fc27 cinnamon-3.6.0-1.fc27 cinnamon-control-center-3.6.0-1.fc27 cinnamon-session-3.6.0-1.fc27 cinnamon-screensaver-3.6.0-2.fc27 muffin-3.6.0-1.fc27 cinnamon-settings-daemon-3.6.0-1.fc27 cinnamon-translations-3.6.0-1.fc27 cinnamon-desktop-3.6.0-1.fc27 xapps-1.0.4-1.fc27 cinnamon-menus-3.6.0-1.fc27 cjs-3.6.0-1.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2017-9a0c3ec5ec

Comment 14 Fedora Update System 2017-10-26 01:34:32 UTC
cinnamon-3.6.0-1.fc26, cinnamon-control-center-3.6.0-1.fc26, cinnamon-desktop-3.6.0-1.fc26, cinnamon-menus-3.6.0-1.fc26, cinnamon-screensaver-3.6.0-2.fc26, cinnamon-session-3.6.0-1.fc26, cinnamon-settings-daemon-3.6.0-1.fc26, cinnamon-translations-3.6.0-1.fc26, cjs-3.6.0-1.fc26, muffin-3.6.0-1.fc26, nemo-3.6.2-1.fc26, nemo-extensions-3.6.0-1.fc26, xapps-1.0.4-1.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-cef381f3ca

Comment 15 Fedora Update System 2017-10-26 20:37:32 UTC
cinnamon-3.6.0-1.fc26 cinnamon-control-center-3.6.0-1.fc26 cinnamon-desktop-3.6.0-1.fc26 cinnamon-menus-3.6.0-1.fc26 cinnamon-screensaver-3.6.0-2.fc26 cinnamon-session-3.6.0-1.fc26 cinnamon-settings-daemon-3.6.0-1.fc26 cinnamon-translations-3.6.0-1.fc26 cjs-3.6.0-1.fc26 muffin-3.6.0-1.fc26 nemo-3.6.2-1.fc26 nemo-extensions-3.6.0-1.fc26 xapps-1.0.4-2.fc26 has been submitted as an update to Fedora 26. https://bodhi.fedoraproject.org/updates/FEDORA-2017-cef381f3ca

Comment 16 Fedora Update System 2017-10-27 15:05:31 UTC
cinnamon-screensaver-3.4.3-1.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.

Comment 17 Fedora Update System 2017-10-27 15:38:35 UTC
cinnamon-3.6.0-1.fc26, cinnamon-control-center-3.6.0-1.fc26, cinnamon-desktop-3.6.0-1.fc26, cinnamon-menus-3.6.0-1.fc26, cinnamon-screensaver-3.6.0-2.fc26, cinnamon-session-3.6.0-1.fc26, cinnamon-settings-daemon-3.6.0-1.fc26, cinnamon-translations-3.6.0-1.fc26, cjs-3.6.0-1.fc26, mintlocale-1.4.4-1.fc26, muffin-3.6.0-1.fc26, nemo-3.6.2-2.fc26, nemo-extensions-3.6.0-1.fc26, xapps-1.0.4-2.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-cef381f3ca

Comment 18 Fedora Update System 2017-10-27 17:05:41 UTC
cinnamon-screensaver-3.4.3-1.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.

Comment 19 Fedora Update System 2017-10-27 18:48:47 UTC
cinnamon-3.6.0-1.fc27, cinnamon-control-center-3.6.0-1.fc27, cinnamon-desktop-3.6.0-1.fc27, cinnamon-menus-3.6.0-1.fc27, cinnamon-screensaver-3.6.0-2.fc27, cinnamon-session-3.6.0-1.fc27, cinnamon-settings-daemon-3.6.0-1.fc27, cinnamon-translations-3.6.0-1.fc27, cjs-3.6.0-1.fc27, mintlocale-1.4.4-1.fc27, muffin-3.6.0-1.fc27, nemo-3.6.2-2.fc27, nemo-extensions-3.6.0-1.fc27, xapps-1.0.4-2.fc27 has been pushed to the Fedora 27 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-9a0c3ec5ec

Comment 20 Fedora Update System 2017-11-04 21:08:55 UTC
cinnamon-3.6.0-1.fc26, cinnamon-control-center-3.6.0-1.fc26, cinnamon-desktop-3.6.0-1.fc26, cinnamon-menus-3.6.0-1.fc26, cinnamon-screensaver-3.6.0-2.fc26, cinnamon-session-3.6.0-1.fc26, cinnamon-settings-daemon-3.6.0-1.fc26, cinnamon-translations-3.6.0-1.fc26, cjs-3.6.0-1.fc26, mintlocale-1.4.4-1.fc26, muffin-3.6.0-1.fc26, nemo-3.6.2-2.fc26, nemo-extensions-3.6.0-1.fc26, xapps-1.0.4-2.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.

Comment 21 Fedora Update System 2017-11-11 02:51:49 UTC
cinnamon-screensaver-3.4.3-1.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.

Comment 22 Fedora Update System 2017-11-11 03:06:12 UTC
cinnamon-3.6.0-1.fc27, cinnamon-control-center-3.6.0-1.fc27, cinnamon-desktop-3.6.0-1.fc27, cinnamon-menus-3.6.0-1.fc27, cinnamon-screensaver-3.6.0-2.fc27, cinnamon-session-3.6.0-1.fc27, cinnamon-settings-daemon-3.6.0-1.fc27, cinnamon-translations-3.6.0-1.fc27, cjs-3.6.0-1.fc27, mintlocale-1.4.4-1.fc27, muffin-3.6.0-1.fc27, nemo-3.6.2-2.fc27, nemo-extensions-3.6.0-1.fc27, xapps-1.0.4-2.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.