> The bug description shall be updated to follow the SRU bug template

Done

** Description changed:

- After successful device authentication with authd, GDM sometimes fails
- to display the local-password creation entry. The QR-code/device-
- authentication UI disappears, leaving the user unable to complete login.
+ [ Impact ]
+ 
+ Users logging in through authd's device code flow in GDM may be unable
+ to complete their login. After the user successfully authenticates with
+ the identity provider, authd advances to the local-password challenge.
+ The QR-code/device-authentication UI disappears, but the "Create a local
+ password" entry is not displayed. The user cannot continue and must use
+ the back button to return to the previous stage and retry the login.
+ 
+ The issue is caused by GNOME Shell retaining the previous authd
+ mechanism when authd reports that authentication should advance to the
+ next challenge. The stale mechanism prevents the replacement local-
+ password mechanism from being activated.
+ 
+ The fix is to clear the UI-visible mechanisms when authd advances to the
+ next challenge.
+ 
+ [ Test Plan ]
+ 
+ Use a clean Ubuntu Resolute Desktop VM with authd installed from
+ resolute-updates. Use the existing GDM end-to-end test is available at:
+ 
+ https://github.com/canonical/authd/blob/main/e2e-tests/tests/login_gdm.robot
+ 
+ The test logs in through the GDM greeter using device-code
+ authentication, verifies that the local-password creation prompt is
+ displayed, creates the local password, verifies that the GNOME keyring
+ is unlocked and that the user and home directory were created, logs out,
+ and then logs in again using the new local password.
+ 
+ Run the test ten times with the current Resolute gnome-shell package.
+ With the affected package, the local-password entry is expected to be
+ missing in some runs and the test will fail when the login cannot be
+ completed.
+ 
+ Install the proposed gnome-shell package and repeat exactly the same
+ tests with the same Resolute authd and broker versions. Each run must:
+ 
+ 1. Complete device-code authentication through the GDM greeter.
+ 2. Display the "Create a local password" entry after successful device-code 
authentication.
+ 3. Successfully create the local password and log in.
+ 4. Successfully log out and log in again using the newly created local 
password.
+ 
+ [ Where problems could occur ]
+ 
+ The upload changes only the Ubuntu authd integration in GNOME Shell.
+ When the authd handler receives AuthResult.Next, it clears the
+ previously published authd mechanisms and notifies GDM's
+ ShellUserVerifier that the mechanism list has changed.
+ 
+ If this notification is emitted at the wrong time, GNOME Shell could
+ clear an authd mechanism while an authentication request is still
+ active. This could result in a missing or blank authentication prompt,
+ failure to accept the current credential, or failure to activate the
+ replacement challenge. The problem would be visible during transitions
+ between authd challenges.
+ 
+ The change does not modify the authd protocol, broker authentication, or
+ GNOME Shell's non-authd authentication methods. Possible regressions
+ should therefore appear as failures in authd's GDM flow, such as a
+ missing authentication mode, an unusable password prompt, or an authd
+ login that returns to the greeter. Repeating the complete device-code
+ and local-password flow should detect these regressions.
+ 
+ [ Other Info ]
+ 
+ This bug originally occurred only sporadically because it was often
+ masked by a duplicate auth-mode selection in the authd/GDM interaction.
+ Before authd PR #1623, GDM echoed the auth-mode selection sent by the
+ adapter, and authd treated that echo as a new selection. This resulted
+ in a second SelectAuthenticationMode request and an additional UI-
+ layout/mechanism update. Although the duplicate request could
+ occasionally create a device-code mismatch, the extra update could also
+ refresh GNOME Shell's stale mechanism state and hide this bug.
+ 
+ authd PR #1623 (https://github.com/canonical/authd/pull/1623) fixed the
+ duplicate-selection issue. This removed the accidental mechanism
+ refresh. With #1623 and an unpatched GNOME Shell, the stale mechanism is
+ exposed on almost every login attempt: after authd returns
+ AuthResult.Next, the old authd mechanism remains published and
+ suppresses the local-password mechanism.
  
  Related authd issue: https://github.com/canonical/authd/issues/1424

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2160622

Title:
  Local password entry may not appear after successful device
  authentication

To manage notifications about this bug go to:
https://bugs.launchpad.net/authd/+bug/2160622/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to