Lock screen not really functioning - Gnome Shell extensions visible and active even in lock screen

Bug #1875038 reported by florin
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gnome-shell (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

Lock screen should block access to computer until the screen is unlocked. But, although it was fixed either in extensions, or the lock screen itself in Ubuntu 19.10, it is now present again. I can remove shortcuts from Dash to Dock bar, I can run whatever app is there. In my view, this is a security flaw that in some cases can lead to jokes (removing) or even crashing the computer if really multiple windows of some app are started. And who knows what kind of apps are there.
I did report it in the past, I also reported the bug in Gnome Bugzilla and the extension bug reporting app - they were bouncing from one to the other. At some point the bug disappeared. I think Ubuntu should fix this until something bad happens. See the attachment.

ProblemType: Bug
DistroRelease: Ubuntu 20.04
Package: gnome-shell 3.36.1-5ubuntu1
ProcVersionSignature: Ubuntu 5.4.0-26.30-generic 5.4.30
Uname: Linux 5.4.0-26-generic x86_64
NonfreeKernelModules: nvidia_modeset nvidia
ApportVersion: 2.20.11-0ubuntu27
Architecture: amd64
CasperMD5CheckResult: skip
CurrentDesktop: ubuntu:GNOME
Date: Sat Apr 25 17:52:58 2020
DisplayManager: gdm3
InstallationDate: Installed on 2020-04-24 (1 days ago)
InstallationMedia: Ubuntu 20.04 LTS "Focal Fossa" - Release amd64 (20200423)
RelatedPackageVersions: mutter-common 3.36.1-3ubuntu3
SourcePackage: gnome-shell
UpgradeStatus: No upgrade log present (probably fresh install)

Revision history for this message
florin (florin-arjocu) wrote :
information type: Private Security → Public Security
Revision history for this message
Daniel van Vugt (vanvugt) wrote :

Thanks for the bug report.

You appear to be using 'dash-to-dock' which is not part of Ubuntu so we can't support that here.

Please instead report the bug to the developers of your extension at: https://github.com/micheleg/dash-to-dock/issues

Changed in gnome-shell (Ubuntu):
status: New → Invalid
Revision history for this message
florin (florin-arjocu) wrote :

I know, but does that matter? Lock screen should be over every piece of soft, "locking" the access to computer unless you insert the password.

Revision history for this message
Daniel van Vugt (vanvugt) wrote :

In theory you're right. In practice, gnome-shell gives extensions free rein to do whatever they want, including painting over whatever they like. gnome-shell can't enforce anything.

It just sounds like a bug in the extensions so you need a newer version of the extension that properly supports gnome-shell 3.36.

Revision history for this message
florin (florin-arjocu) wrote :

I have had this discussion with Gnome Shell developers when I first saw the bug, some versions behind, they see it as a feature, not as a bug. It is like fighting the wind over there. In the real world, where people expect computers and OS's to do what they say they do, a lock screen is supposed to lock access. Whatever else is running behind, access should be restricted, otherwise, it is worthless as a secure OS and lock screen. I know this should be on Gnome Shell developers, but as Ubuntu joined the boat using it, it becomes a problem for Ubuntu, too. I am tired of posting bugs on Gnome bugzilla because it is difficult, close to impossible to fight them (a lost fight was there to add back file sorting by extension in search, for instance).

Revision history for this message
Daniel van Vugt (vanvugt) wrote :

I know getting bugs fixed or even recognised as bugs can be very time consuming and frustrating.

In the case of gnome-shell extensions we only have the choice between:

  * Allow extensions, and allow them to do anything including breaking the shell; or

  * Disallow extensions.

A more restricted middleground for extensions does not exist and is unlikely to ever exist because it would be such a large long term change.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.