Show fingerprint reader status in authentication dialogs - #11952
tonibergholm wants to merge 1 commit into
Conversation
Automated AI review
Verified: PAM text now reaches both the lock view and the polkit fingerprint card. The lock wake fires at most once per lock. The new Lock shows "Preparing fingerprint reader…" on every retry, indefinitely when pam_fprintd fails early
pam_fprintd (fprintd 1.94.5) returns without sending any message when it cannot claim the device, cannot reach fprintd, or On a working reader the same clear causes a brief flash. After the 30 s "Verification timed out", or after "Failed to match fingerprint" on the third mismatch, the next attempt shows "Preparing fingerprint reader…" again before the placement prompt (for example "Place your right index finger on the fingerprint reader"). Separately, if Impact: with a busy, wedged or unreachable reader (the situation several open PRs, such as #7158, #11918 and #12544, deal with), the base shows only the icon. The head now tells the user to wait for a reader that is not coming. On a working reader, "Preparing" after a timeout or the third mismatch suggests the reader is reinitialising. Suggested change: show the fallback only until the first PAM message of a lock cycle (a flag reset in Polkit status can describe the wrong module or a previous attemptQuickshell (v0.3.1) never clears
When a registered key is attached and pam_u2f prompts, the box correctly shows "Please touch the FIDO authenticator.", though the card still shows a fingerprint glyph. The base shows only the glyph in that state, so this part is an improvement. Impact: short periods of wrong text, not a failed authentication. Suggested change: use a neutral fallback (not reader-specific), or show it only when pam_fprintd is the first auth module. With a neutral fallback in place, the displayed message can also be cleared when a new attempt starts, without reintroducing reader-specific text. Open PR #13217 also reads Verified: fprintd enrolment checkfprintd 1.94.5
Optional test improvement: the new test runs the real handler and reset bodies, and fails on the base. These diagnostic mutations still pass it:
Asserting those lines would cover the lifecycle and binding the PR describes. Related open PRs:
Review informationTest scope: Source review of the head, the base and a local merge with the current AI process: Opus 5.5 Medium coordination and synthesis, Opus 5.5 Xhigh technical review and final fact check, GPT 6 Sol Xhigh search for related issues, Opus 5.5 Medium editorial check. Opt out: To stop receiving these reviews, reply to this comment saying so. |
|
I implemented a similar solution in #7158 |
Summary
Fingerprint authentication currently shows an icon without the PAM reader status, leaving users without guidance while the sensor initializes or asks for another scan. Display PAM messages below the lock password field and the polkit fingerprint card, with a preparing-reader fallback before a message arrives.
The lock wakes once for the first informational PAM message per lock cycle; retry messages do not repeatedly wake an unattended display. Clear the message when resetting authentication and starting another attempt. Require an enrolled fingerprint entry in fprintd-list output rather than matching any occurrence of “finger”.
Integration context
This upstreams the UI integration from t2touch, which exposes Apple T2 Touch ID through the standard fprintd interface. Its installer applies these three QML changes to Omarchy. The machine owner confirms that T2 fingerprint authentication works on this machine with the existing local integration. This is user-confirmed hardware success, not a completed test of every authentication path on the final PR branch.
Validation
Passed focused suites: lock-fingerprint-message, lock-blank-fingerprint, polkit, system-lock, lock-password-overflow, and lock-fingerprint-indicator. The last two ran with compositor access.
git diff --checkpassed.Inspected the running desktop's lock preview with the original local patch: the preparing-reader text fits below the password field. The PR preserves that layout and adds message-reset cleanup and regression coverage.
The four t2touch UI installer unit tests also pass. A read-only transform check confirms that the current installer rejects the upstreamed source before writing, so rerunning it will safely skip this UI patch rather than apply it twice.
Draft checks remaining