https://bugs.kde.org/show_bug.cgi?id=526223

            Bug ID: 526223
           Summary: PAM auto-unlock of "kdewallet" fails when "Use One
                    Wallet" is disabled and a second wallet exists
    Classification: Frameworks and Libraries
           Product: frameworks-kwallet
      Version First 6.30.0
       Reported In:
          Platform: Debian testing
                OS: Linux
            Status: REPORTED
          Severity: normal
          Priority: NOR
         Component: general
          Assignee: [email protected]
          Reporter: [email protected]
                CC: [email protected]
  Target Milestone: ---

DESCRIPTION
With two wallets configured (`kdewallet` and a second wallet, e.g.
`localwallet`, with a different password) and `Use One Wallet=false` in
`kwalletrc`, automatic unlocking of `kdewallet` via PAM at login does not
happen, even though `kdewallet`'s password is identical to the user's login
password (the condition required for auto-unlock). After login, `kdewallet` is
still locked and a password prompt is shown.

Setting Use `One Wallet=true` makes automatic unlock work correctly.

STEPS TO REPRODUCE
1. Create a default wallet named `kdewallet` with the same password as the user
account.
2. Create a second wallet (e.g. `localwallet`) with a different password.
3. Set `Use One Wallet=false` in `~/.config/kwalletrc`.
4. Log out and log back in.

OBSERVED RESULT
`kdewallet` remains locked:
```
$ qdbus6 org.kde.kwalletd6 /modules/kwalletd6 org.kde.KWallet.isOpen kdewallet
false
$ busctl --user get-property org.freedesktop.secrets
/org/freedesktop/secrets/collection/kdewallet org.freedesktop.Secret.Collection
Locked
b true
```

while PAM has correctly passed the unlock key (`PAM_KWALLET5_LOGIN` is set,
`ksecretd --pam-login` is running, no obvious errors in the user-visible logs):
```
$ systemctl --user show-environment | grep -i kwallet
PAM_KWALLET5_LOGIN=/run/user/1000/kwallet5.socket
$ ps -eo pid,cmd | grep ksecretd
2200 /usr/bin/ksecretd --pam-login 17 18
```

Setting `Use One Wallet=true` in `kwalletrc` and repeating the logout/login
cycle makes `kdewallet` unlock correctly.

The following warning also appears in the log on every boot regardless of the
bug described above, and is likely unrelated:
```
pam_kwallet_init[...]: socat[...] W address is opened in read-write mode but
only supports read-only
```

EXPECTED RESULT
`kdewallet` should unlock automatically at login, as it does when only one
wallet is configured.


SOFTWARE/OS VERSIONS
Operating System: Debian GNU/Linux forky/sid
KDE Plasma Version: 6.7.4
KDE Frameworks Version: 6.30.0
Qt Version: 6.10.2

ADDITIONAL INFORMATION
- `ReadAlias default` on `org.freedesktop.secrets` correctly points to
`/org/freedesktop/secrets/collection/kdewallet`.
- Found a community report with similar symptoms (socat warning, `isOpen` false
after boot), without a resolution:
https://discuss.cachyos.org/t/kwallet-doesnt-automatically-unlock/15723
- Maybe related historical bug (different mechanism, about wallet naming):
https://bugs.kde.org/show_bug.cgi?id=361860

-- 
You are receiving this mail because:
You are watching all bug changes.

Reply via email to