- Apr 13, 2019
-
-
Rudolf Polzer authored
Now the colors are only hardcoded in one place, making it easier to override them.
-
- Apr 03, 2019
-
-
Rudolf Polzer authored
Not doing so but running xsecurelock via shell expansion means that the shell will keep holding on to the sleep lock FD, preventing suspend.
-
- Mar 15, 2019
-
-
Rudolf Polzer authored
-
Rudolf Polzer authored
-
Rudolf Polzer authored
-
- Mar 13, 2019
-
-
Rudolf Polzer authored
(cleaner)
-
Rudolf Polzer authored
The easiest way to do that was to execl() a separate binary for the placeholder (thereby closing all close-on-exec file descriptors, even those we don't control, e.g. X11's), also making "ps" more descriptive about what this process is for, and making sure any e.g. internal mutexes by libraries we use are freed. Fixes "systemd does not suspend laptop on closing the lid".
-
- Mar 01, 2019
-
-
Rudolf Polzer authored
Otherwise the sigsuspend() call to wait for SIGCHLD does nothing and just hangs. Also, refactor to prevent this issue from happening in the future.
-
- Feb 28, 2019
-
-
Rudolf Polzer authored
-
Rudolf Polzer authored
$0 didn't contain the full path, so exec failed.
-
Rudolf Polzer authored
Fixes killing saver children twice twice.
-
Rudolf Polzer authored
-
Rudolf Polzer authored
- Always have a separate "dummy process" in each process group to prevent the PGID from getting deallocated when the leader dies. This makes the logic that kills the rest of a process group when the leader dies race-free. - Do the killing the rest of the process group inside WaitPgrp rather than in its callers.
-
Rudolf Polzer authored
-
- Feb 22, 2019
-
-
Rudolf Polzer authored
This signal is now sent from the main program to the saver to reset possible idle timers in the savers, without intending to restart the saver. This is part of the effort to make the auth child protocol more flexible and to properly run auth on top of the saver as a window.
-
Rudolf Polzer authored
That way they will still get waitpid'd on and won't stay zombies.
-
Rudolf Polzer authored
Main changes: - No longer support the case of sigprocmask failing. The new code will in that case have a race that can cause xsecurelock to hang; in the old code a similar (preexisting) race could cause other processes to get killed. - Use only one sigprocmask call to retrieve and set the new mask. - Do the sigprocmask calls outside the loop, not inside (fixes a race that appears to have caused hangs for me; repro: just hold escape).
-
divVerent authored
Use criticial section in WaitPgrp.
-
divVerent authored
Use explicit_bzero for password data.
-
- Jan 26, 2019
-
-
Rudolf Polzer authored
-
Rudolf Polzer authored
This may fix some cases of old screen content appearing after resume from suspend. Cannot reproduce these issues here though.
-
- Jan 20, 2019
-
-
Tobias Stoeckmann authored
The C standard does not guarantee that memset won't be optimized away by a compiler, which means that memset for password data is not safe. Also clear password data in signal handler for SIGTERM, otherwise it could happen that password data is left in memory that way. Signed-off-by:Tobias Stoeckmann <tobias@stoeckmann.org>
-
- Jan 19, 2019
-
-
Tobias Stoeckmann authored
A signal race exists in WaitPgrp that could result in a kill initiated by xsecurelock against a process that does not belong to it. This race can happen if waitpid has been called for a child that has already been terminated and SIGTERM is received before the pid has been reset to 0. In that case SIGTERM will call kill for a pid that has been already released to the operating system and could thus have been assigned to a new process again. To prevent this, the criticial section blocks SIGTERM and also SIGCHLD if WaitPgrp is supposed to block until a child status changes. If the function is supposed to block, sigsuspend() restores SIGCHLD and SIGTERM again and waits until a signal is delivered. These signals are blocked and unblocked for each iteration of the loop. This is required to actually get interrupted/killed by a SIGTERM in non-blocking mode. If no critical section could be installed due to failure in calling sigprocmask the old behaviour is kept. Signed-off-by:Tobias Stoeckmann <tobias@stoeckmann.org>
-
Tobias Stoeckmann authored
Having a conditional loop without breaks or returns is a better foundation to implement a criticial section without duplicating cleanups throughout the code. Signed-off-by:Tobias Stoeckmann <tobias@stoeckmann.org>
-
- Jan 15, 2019
-
-
divVerent authored
Centralized pid handling into WaitPgrp.
-
- Jan 12, 2019
-
-
Tobias Stoeckmann authored
To be able to create a critical section in WaitPgrp to protect against signal races the pid handling has been moved into WaitPgrp. If a child process dies, its pid is set to 0 directly in WaitPgrp which means that a pointer has to be supplied when calling the function. Signed-off-by:Tobias Stoeckmann <tobias@stoeckmann.org>
-
- Jan 10, 2019
-
-
Rudolf Polzer authored
Now disabling do_wakeup only if a key was handled externally.
-
Rudolf Polzer authored
Example: XSECURELOCK_KEY_XF86AudioPause_COMMAND='playerctl --all pause' to control media players using https://github.com/acrisci/playerctl. Fixes #37.
-
- Jan 03, 2019
-
-
Rudolf Polzer authored
-
Rudolf Polzer authored
Sorry for having been inconsistent before.
-
divVerent authored
Show auth in a box on top of the saver
-
Rudolf Polzer authored
-
Rudolf Polzer authored
-
Rudolf Polzer authored
The old variable still works for compatibility if the new one isn't set. Fixes #21.
-
Rudolf Polzer authored
It's then always shown on the screen with the mouse pointer. Also added a macro SHOW_CURSOR_DURING_AUTH to actually show the pointer - this is rather useless at the moment as auth helpers cannot receive mouse events yet anyway. Still a nice proof of concept.
-
Rudolf Polzer authored
Add a feature to show cursor while auth is active (even though nothing actually receives mouse events yet). Not in use yet, though, and there's no way for an auth helper to receive clicks yet anyway.
-
Rudolf Polzer authored
-
Rudolf Polzer authored
This was enabled by Soumya's previous changes. Thanks! I'd now really like to see an alternate auth helper that uses a toolkit in single-window mode (following the monitor the mouse is on)... as otherwise single-window auth is dead now (in fact, this version of auth_x11 would work fine if passed the saver window ID instead). Or maybe just a minor change to auth_x11 to behave as if there's only one monitor all the time, while keeping the dialog on the current one... let's see later.
-
Rudolf Polzer authored
- Auth window is still always on top. - Auth window is now a child of the background window, not of the saver window. - Thus, auth window now overlaps the saver window; thus all overlap protections for that window have been removed. In worst case something may now overlap the saver that we don't want; our protections still kick in if it also overlaps the background window (so there's only an issue if a saver is misbehaving). Now auth helpers can create sibling windows; useful for multi-window auth (be it for showing a windowed prompt on all screens while letting the saver shine through, or be it for showing a "taskbar" at the bottom to allow mouse based actions). This change is compatible to existing auth helpers.
-
Rudolf Polzer authored
We only do this in order to restart the blanking timer; if savers implemented a different protocol for this (e.g. SIGUSR1), this could go.
-