Red Hat Bugzilla – Bug 807369
RFE: Clear screen including scroll-back buffer after locking session
Last modified: 2016-04-06 06:05:17 EDT
Created attachment 573106 [details] Implement console erase There was a discussion (bug #681600) how to disable access to text printed before locking session while session is locked to prevent from leaking sensitive data. Attached patch implements optional console erase by adding -e or --erase option to vlock command. In addition, the scroll-back buffer is erased if underlying kernel supports it. The support exist in Linux since 3.0 and has been back-ported into RHEL-6 kernel too. Making this feature default can be subject of further discussion.
This request was not resolved in time for the current release. Red Hat invites you to ask your support representative to propose this request, if still desired, for consideration in the next release of Red Hat Enterprise Linux.
This request was erroneously removed from consideration in Red Hat Enterprise Linux 6.4, which is currently under development. This request will be evaluated for inclusion in Red Hat Enterprise Linux 6.4.
I spotted a typo: --- a/help.c +++ b/help.c @@ -26,6 +26,8 @@ void print_help(int exitcode) { " switch to other virtual consoles.\n" "-a or --all: lock all virtual consoles by preventing other users\n" " from switching virtual consoles.\n" + "-e or --erase: erase current virtual console content\n" + " from switching virtual consoles.\n" "-v or --version: Print the version number of vlock and exit.\n" "-h or --help: Print this help message and exit.\n" ); The second line should not be added. Something like this: --- a/help.c +++ b/help.c @@ -26,6 +26,7 @@ void print_help(int exitcode) { " switch to other virtual consoles.\n" "-a or --all: lock all virtual consoles by preventing other users\n" " from switching virtual consoles.\n" + "-e or --erase: erase current virtual console content\n" "-v or --version: Print the version number of vlock and exit.\n" "-h or --help: Print this help message and exit.\n" );
Applied to f18 (=RHEL7) and f19. I have doubts we will see a special RHEL6.x errata for vlock. Maybe we can close this report.
This request was evaluated by Red Hat Product Management for inclusion in the current release of Red Hat Enterprise Linux. Because the affected component is not scheduled to be updated in the current release, Red Hat is unable to address this request at this time. Red Hat invites you to ask your support representative to propose this request, if appropriate, in the next release of Red Hat Enterprise Linux.