Wayland compositor (wlroots)
git clone https://git.lucas.co/cce-compositor.git
Refuse restart-compositor while the session is locked
restart-compositor leaves a flag for cce-display-manager, which then
relaunches the session greeter-free. Sent while the screen was locked
(only a process of the user's can send one then), it brought the session
back unlocked. The command now refuses unless the session is Unlocked.
Checked in a shadow: locked, the command errors, the compositor keeps
running, and no flag is written.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
src/server/window_manager.rs | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/src/server/window_manager.rs b/src/server/window_manager.rs
index c3d612a4..86731588 100644
--- a/src/server/window_manager.rs
+++ b/src/server/window_manager.rs
@@ -5994,6 +5994,13 @@ impl WindowManager {
"ok\n".to_string()
}
"restart-compositor" => {
+ // Never from a locked session: the display manager relaunches
+ // the session greeter-free, so a restart sent while locked
+ // (only a process of the user's can send one then) came back
+ // unlocked. The user unlocks first.
+ if unsafe { (*self.server).lock_manager.state } != crate::lock_manager::LockState::Unlocked {
+ return "error: the session is locked; unlock before restarting the compositor\n".to_string();
+ }
// Leave the restart flag for cce-display-manager's daemon (it
// checks after the session worker exits, verifies the file is
// owned by the session user, and relaunches this same session