git.lucas.co / cce-compositor
Wayland compositor (wlroots)
git clone https://git.lucas.co/cce-compositor.git

commiteaffb06e59a3f7d17db50cf563bddbd90d4739b9
parent6370341d9b
authorLucas Galante <lsgalante12@gmail.com>
date2026-10-02 10:36
Refuse restart-compositor while the session is locked

restart-compositor leaves a flag for cce-display-manager, which then
relaunches the session greeter-free. Sent while the screen was locked
(only a process of the user's can send one then), it brought the session
back unlocked. The command now refuses unless the session is Unlocked.

Checked in a shadow: locked, the command errors, the compositor keeps
running, and no flag is written.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

 src/server/window_manager.rs | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/src/server/window_manager.rs b/src/server/window_manager.rs
index c3d612a4..86731588 100644
--- a/src/server/window_manager.rs
+++ b/src/server/window_manager.rs
@@ -5994,6 +5994,13 @@ impl WindowManager {
                 "ok\n".to_string()
             }
             "restart-compositor" => {
+                // Never from a locked session: the display manager relaunches
+                // the session greeter-free, so a restart sent while locked
+                // (only a process of the user's can send one then) came back
+                // unlocked. The user unlocks first.
+                if unsafe { (*self.server).lock_manager.state } != crate::lock_manager::LockState::Unlocked {
+                    return "error: the session is locked; unlock before restarting the compositor\n".to_string();
+                }
                 // Leave the restart flag for cce-display-manager's daemon (it
                 // checks after the session worker exits, verifies the file is
                 // owned by the session user, and relaunches this same session