Resume after hibernate on KDE 4.1 reveals an unlocked session

Bug #253772 reported by madhusudansingh
276
This bug affects 2 people
Affects Status Importance Assigned to Milestone
KDE Base
Fix Released
Medium
kdebase-workspace (Ubuntu)
Fix Released
Medium
Unassigned
Nominated for Intrepid by Aldo "xoen" Giambelluca

Bug Description

This problem is non-existent (the last time I checked) on KDE 3.5.9. It appears to be a KDE 4.1 related glitch.

What I expected to happen ?

When I resume after hibernate, I am usually presented with a locked screensaver, which allows me to resume my KDE session when I supply a password. This was the behavior on KDE 3.5.9.

What happened instead ?

I am presented with an unlocked session ready to go. This appears to be graphics card independent - tested it on both an ATI X1300 card as well as an Intel 915 card. Can try with an Nvidia card if requested.

$ lsb_release -rd
Description: Ubuntu 8.04.1
Release: 8.04

$ apt-cache policy kubuntu-kde4-desktop
kubuntu-kde4-desktop:
  Installed: 0.14-0ubuntu1~hardy1~ppa1
  Candidate: 0.14-0ubuntu1~hardy1~ppa1
  Version table:
 *** 0.14-0ubuntu1~hardy1~ppa1 0
        500 http://ppa.launchpad.net hardy/main Packages
        100 /var/lib/dpkg/status
     0.14 0
        500 http://us.archive.ubuntu.com hardy/universe Packages

$ apt-cache policy acpi-support
acpi-support:
  Installed: 0.109
  Candidate: 0.109
  Version table:
 *** 0.109 0
        500 http://us.archive.ubuntu.com hardy/main Packages
        100 /var/lib/dpkg/status

Tags: cft-2.6.27
Revision history for this message
Leann Ogasawara (leannogasawara) wrote :

The Ubuntu Kernel Team is planning to move to the 2.6.27 kernel for the upcoming Intrepid Ibex 8.10 release. As a result, the kernel team would appreciate it if you could please test this newer 2.6.27 Ubuntu kernel. There are one of two ways you should be able to test:

1) If you are comfortable installing packages on your own, the linux-image-2.6.27-* package is currently available for you to install and test.

--or--

2) The upcoming Alpha5 for Intrepid Ibex 8.10 will contain this newer 2.6.27 Ubuntu kernel. Alpha5 is set to be released Thursday Sept 4. Please watch http://www.ubuntu.com/testing for Alpha5 to be announced. You should then be able to test via a LiveCD.

Please let us know immediately if this newer 2.6.27 kernel resolves the bug reported here or if the issue remains. More importantly, please open a new bug report for each new bug/regression introduced by the 2.6.27 kernel and tag the bug report with 'linux-2.6.27'. Also, please specifically note if the issue does or does not appear in the 2.6.26 kernel. Thanks again, we really appreicate your help and feedback.

Revision history for this message
Neil Munro (neilmunro-deactivatedaccount) wrote :

The Intrepid Ibex 8.10 Beta release was most recently announced - http://www.ubuntu.com/testing/intrepid/beta . It contains the 2.6.27 Ubuntu kernel. It would be great if you could test and verify if this is still an issue. The status is being set to Incomplete until we receive further feedback. Thanks.

Changed in linux:
status: New → Incomplete
Revision history for this message
Aldo "xoen" Giambelluca (xoen) wrote :

Same problem here, I use kubuntu 8.04 (Intrepid Ibex), 64 bit edition.

Resume from hibernation give me the session without have to insert the password!

Changed in linux:
status: Incomplete → Confirmed
Revision history for this message
markor (markoresko) wrote :

I am using Xubuntu 8.04.1 i386 on my Asus eeepc 701 mini-laptop.
When I go from Hibernation, the system is UNLOCKED to anyone who
get a hand to my computer.

So because of this Ubuntu behavior, All my data could be stolen
even if I use truecrypt , because session is Unlocked every time
you resume from hibernation..
So I consider this "Unloced from hibernation" truely a security risk.

Revision history for this message
markor (markoresko) wrote :

Just to mention, I am using Xfce, so it is Ubuntu-related, not just Kde-related problem..

Revision history for this message
Leann Ogasawara (leannogasawara) wrote :

I know this sounds silly, but you don't have autologin enabled do you?

Revision history for this message
markor (markoresko) wrote :

No I don`t have autologin enabled. I have password for account, password for another acount, root password set, and grub password set. I even set psceen saver to lock the screen after very short time.
So, I am not shure why it is unlocked after hibernate.
Maybe hibernate procedure should lock computer before going to hibernation?

Revision history for this message
tavasti (tavasti) wrote :

I have same problem. Running Kubuntu 8.10.

- If I hibernate from K-menu, screen is unlocked
- If I hibernate from 'Guidance Power Manager' applet, screen is locked (according setting in Guidance Power Manager)
- On dialog appearing with ctrl-alt-del hibernate is not even available

Revision history for this message
Kurt Huwig (k-huwig) wrote :

Same for me. Using the Guidance Power Manager applet, the screen is locked upon resume. Using the default KDE way, the session is unlocked upon resume, which means that everyone can read my mail etc.

Revision history for this message
Kurt Huwig (k-huwig) wrote :

As the 'Guidance Power Manager' applet only works if you have a battery, I installed "kpowersave" which does also allow suspend to RAM. If I set the screen locking to "auto" or "KScreensaver" then the session returns unlocked. If I set it to "xlock" (and the package 'xlockmore' is installed), then upon resume the session is locked with xlock. So this is some kind of workaround.

Revision history for this message
tavasti (tavasti) wrote :

Same problem is found in Xubuntu. When hibernating or suspending from Xubuntu 8.10, session comes back unlocked.

Kees Cook (kees)
Changed in linux:
importance: Undecided → Medium
Revision history for this message
markor (markoresko) wrote :

Since is is doing the same in Xubuntu/Xfce, as reported, maybe bug is not Kde-related but on some more basic lever?

Revision history for this message
Jonathan Thomas (echidnaman) wrote :

Fixed in KDE 4.2 with powerdevil.

Changed in kdebase:
status: Confirmed → Fix Released
Changed in kdebase:
status: Unknown → Fix Released
Revision history for this message
Aldo "xoen" Giambelluca (xoen) wrote :

I'm using Kubuntu 8.10 with backports enabled, I have KDE 4.2, I've tried, the problem still exists for me (I've configured things in System Settings > Power Managment for ask what to do on power button press).

Does this bug exist in jaunty?

Revision history for this message
Aldo "xoen" Giambelluca (xoen) wrote :

The problem is still present in Kubuntu 8.10 (updated) with backports enabled.

Changed in kdebase-workspace:
status: Fix Released → Confirmed
Revision history for this message
Aldo "xoen" Giambelluca (xoen) wrote :

This is fixed now, The problem is fixed in Kubuntu 8.10 with backports enabled.

Changed in kdebase-workspace:
status: Confirmed → Fix Released
Changed in kdebase:
importance: Unknown → Medium
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.