login greeter
git clone https://git.lucas.co/cce-display-manager.git
cce-gnome-keyring-start: keep TPM warnings out of the unsealed password
The unseal was captured with 2>&1, so any warning tpm2-tools or the TSS
printed on stderr during a successful unseal was prepended to the
password. The unlock then failed and the login keyring stayed locked. It
fails closed, but for no reason. stderr now goes to a temp file and is
printed only when every attempt fails.
Checked by hash only: the old and new forms unseal the same password,
and today's run printed no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
scripts/cce-gnome-keyring-start | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/scripts/cce-gnome-keyring-start b/scripts/cce-gnome-keyring-start
index 3a37047..4891a6d 100755
--- a/scripts/cce-gnome-keyring-start
+++ b/scripts/cce-gnome-keyring-start
@@ -29,13 +29,18 @@ TMP=$(mktemp -d); trap 'rm -rf "$TMP"' EXIT INT TERM
# The TPM serializes, so a request racing another user of it fails
# transiently. Retry the whole unseal, primary key included.
+#
+# stderr goes to a file, never into PW: tpm2-tools and the TSS print warnings
+# on stderr even when the unseal succeeds, and with `2>&1` (until 2026-10-02)
+# any such line was prepended to the password, the unlock failed and the
+# keyring stayed locked.
n=0
until PW=$( { tpm2_createprimary -Q -C o -g sha256 -G ecc -c "$TMP/primary.ctx" \
&& tpm2_load -Q -C "$TMP/primary.ctx" -u "$PUB" -r "$PRIV" -c "$TMP/seal.ctx" \
- && tpm2_unseal -c "$TMP/seal.ctx"; } 2>&1 ); do
+ && tpm2_unseal -c "$TMP/seal.ctx"; } 2>"$TMP/err" ); do
n=$((n + 1))
if [ "$n" -ge 5 ]; then
- echo "TPM unseal failed after $n attempts: $PW" >&2
+ echo "TPM unseal failed after $n attempts: $(cat "$TMP/err")" >&2
exit 1
fi
sleep 1