Skip to content

fix: delay authentication creation after system wake - #82

Merged
deepin-bot[bot] merged 1 commit into
linuxdeepin:masterfrom
52cyb:master
Sep 1, 2026
Merged

deepin-bot[bot] merged 1 commit into
linuxdeepin:masterfrom
52cyb:master

Conversation

@52cyb

@52cyb 52cyb commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor
  1. Add a dedicated m_wakeUpAuthTimer (300ms single-shot) to postpone authentication creation after system wake-up
  2. Replace direct createAuthentication() calls in system wake and active change flows with timer-triggered execution
  3. Stop timer appropriately during sleep, invisible, or inactive states to prevent unnecessary authentication
  4. Fix potential race condition where authentication creation during screen wake could be interrupted by system events

Log: Fix potential lock screen flash or authentication failure after system wake-up

Influence:

  1. Test system wake-up from sleep and verify lock screen appears normally without flashing
  2. Test rapid wake-sleep-wake cycles to ensure authentication state is consistent
  3. Test when lock screen is invisible during wake-up to verify no authentication is created
  4. Test switching user accounts after wake-up to verify authentication creation is correct
  5. Test system suspend/resume multiple times to check stability
  6. Verify no authentication is triggered when system enters sleep or becomes inactive

fix: 延迟系统唤醒后的认证创建

  1. 添加专用的 m_wakeUpAuthTimer(300ms 单次触发)来延迟系统唤醒后的认 证创建
  2. 将系统唤醒和活动状态变化流程中的直接 createAuthentication() 调用替 换为定时器触发执行
  3. 在休眠、不可见或不活动状态时适当停止定时器,避免不必要的认证
  4. 修复屏幕唤醒期间认证创建可能被系统事件打断的竞态条件问题

Log: 修复系统唤醒后可能出现的锁屏闪烁或认证失败问题

Influence:

  1. 测试系统从休眠唤醒后锁屏是否正常显示,无闪烁现象
  2. 测试快速唤醒-休眠-唤醒循环,验证认证状态一致性
  3. 测试唤醒时锁屏不可见的情况,验证不会创建认证
  4. 测试唤醒后切换用户账户,验证认证创建正确性
  5. 多次测试系统挂起/恢复,检查稳定性
  6. 验证系统进入休眠或不活动状态时不会触发认证

PMS: BUG-373405

Summary by Sourcery

Delay post-wake authentication creation to stabilize lock-screen behavior during system power and session state transitions.

Bug Fixes:

  • Prevent authentication failures and lock-screen flashing after system wake-up by delaying authentication creation and cancelling it when the session is sleeping, inactive, or invisible.

Enhancements:

  • Coordinate authentication creation across wake-up and activity-state transitions to avoid race conditions with system events.

1. Add a dedicated `m_wakeUpAuthTimer` (300ms single-shot) to postpone
authentication creation after system wake-up
2. Replace direct `createAuthentication()` calls in system wake and
active change flows with timer-triggered execution
3. Stop timer appropriately during sleep, invisible, or inactive states
to prevent unnecessary authentication
4. Fix potential race condition where authentication creation during
screen wake could be interrupted by system events

Log: Fix potential lock screen flash or authentication failure after
system wake-up

Influence:
1. Test system wake-up from sleep and verify lock screen appears
normally without flashing
2. Test rapid wake-sleep-wake cycles to ensure authentication state
is consistent
3. Test when lock screen is invisible during wake-up to verify no
authentication is created
4. Test switching user accounts after wake-up to verify authentication
creation is correct
5. Test system suspend/resume multiple times to check stability
6. Verify no authentication is triggered when system enters sleep or
becomes inactive

fix: 延迟系统唤醒后的认证创建

1. 添加专用的 `m_wakeUpAuthTimer`(300ms 单次触发)来延迟系统唤醒后的认
证创建
2. 将系统唤醒和活动状态变化流程中的直接 `createAuthentication()` 调用替
换为定时器触发执行
3. 在休眠、不可见或不活动状态时适当停止定时器,避免不必要的认证
4. 修复屏幕唤醒期间认证创建可能被系统事件打断的竞态条件问题

Log: 修复系统唤醒后可能出现的锁屏闪烁或认证失败问题

Influence:
1. 测试系统从休眠唤醒后锁屏是否正常显示,无闪烁现象
2. 测试快速唤醒-休眠-唤醒循环,验证认证状态一致性
3. 测试唤醒时锁屏不可见的情况,验证不会创建认证
4. 测试唤醒后切换用户账户,验证认证创建正确性
5. 多次测试系统挂起/恢复,检查稳定性
6. 验证系统进入休眠或不活动状态时不会触发认证

PMS: BUG-373405
@sourcery-ai

sourcery-ai Bot commented Sep 1, 2026

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Introduces a 300 ms single-shot delay for authentication creation during system wake and active-state changes, while cancelling pending work in sleep, invisible, and inactive paths to reduce wake-up races, lock-screen flashing, and authentication failures.

Sequence diagram for delayed wake-up authentication

sequenceDiagram
    participant System
    participant LockWorker
    participant WakeUpAuthTimer
    participant Authentication

    System->>LockWorker: activeChanged(active)
    alt active and visible
        LockWorker->>WakeUpAuthTimer: start()
        WakeUpAuthTimer-->>LockWorker: timeout after 300 ms
        LockWorker->>Authentication: createAuthentication(name)
    else inactive or invisible
        LockWorker->>WakeUpAuthTimer: stop()
        LockWorker->>Authentication: endAuthentication(account, AT_All)
        LockWorker->>Authentication: destroyAuthentication(account)
    end

    System->>LockWorker: systemStateChanged(isSleep)
    alt entering sleep
        LockWorker->>WakeUpAuthTimer: stop()
    else waking with active session
        LockWorker->>WakeUpAuthTimer: start()
        WakeUpAuthTimer-->>LockWorker: timeout after 300 ms
        LockWorker->>Authentication: createAuthentication(name)
    end
Loading

File-Level Changes

Change Details Files
Defers authentication creation after wake and active-state transitions through a cancellable single-shot timer.
  • Adds a parented, single-shot 300 ms wake-up authentication timer.
  • Schedules authentication instead of creating it immediately when the session becomes active and visible.
  • Stops pending authentication when sleep, invisibility, or inactive-state paths are entered.
  • Creates authentication from the timer callback using the current user at execution time.
src/dde-lock/lockworker.cpp
src/dde-lock/lockworker.h

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 1 issue

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="src/dde-lock/lockworker.cpp" line_range="223" />
<code_context>

         if (active && m_model->visible()) {
-            createAuthentication(m_model->currentUser()->name());
+            m_wakeUpAuthTimer->start();
         } else {
+            m_wakeUpAuthTimer->stop();
</code_context>
<issue_to_address>
**issue (broader_impact):** The wake-up timer is started when the session is locked without checking that the lock screen is visible, and its timeout unconditionally calls `createAuthentication()`. If the lock screen becomes or remains invisible during the 300 ms delay, authentication is still created and `createAuthentication()` sets the session locked, causing unnecessary authentication and potentially reproducing the lock-screen flash this change is intended to prevent.

**Triggers:** When the system resumes while the session is locked but the lock screen is invisible, or when visibility changes to false before the timer expires.

**Suggested fix:** Stop the timer from the `visibleChanged(false)` path and re-check visibility, session activity, and the current lock state in the timeout callback before creating authentication.
</issue_to_address>

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

Comment thread src/dde-lock/lockworker.cpp
@deepin-ci-robot

Copy link
Copy Markdown

deepin pr auto review

🤖 AI 代码审查报告

总体评分: 95 分 (通过阈值: 70分)

Pass


📊 总体评价

项目 结果
审查结论 代码审查通过
评分详情 代码变更通过添加 m_wakeUpAuthTimer 定时器延迟系统唤醒后的认证创建,有效修复了系统唤醒后锁屏闪烁或认证失败的竞态条件问题(BUG-373405)。代码逻辑清晰,无安全漏洞,仅有少量代码质量改进建议。

🔍 详细分析

1. 语法逻辑 ✅

评价: 优秀 ✅ 通过

潜在问题:

  1. src/dde-lock/lockworker.cpp:62 - 定时器 lambda 中调用 m_model->currentUser()->name(),如果定时器触发时 currentUser() 返回 nullptr,将导致空指针解引用。定时器延迟执行的特性增加了状态变化的风险窗口,建议在 lambda 中增加 nullptr 检查

建议: 在 lambda 中增加 nullptr 检查:if (m_model && m_model->currentUser()) { createAuthentication(m_model->currentUser()->name()); }


2. 代码质量 ✅

评价: 优秀 ✅ 通过

潜在问题:

  1. src/dde-lock/lockworker.cpp:60 - m_wakeUpAuthTimer 的 300ms 间隔未添加注释说明选择此值的原因,建议添加注释说明设计依据
  2. src/dde-lock/lockworker.cpp:59 - 新增的 m_wakeUpAuthTimer 定时器缺少功能注释,在构造函数中添加简短注释说明定时器用途有助于代码可维护性

建议: 添加注释说明 300ms 延迟的设计依据和定时器用途,便于后续维护


3. 代码性能 ✅

评价: 优秀 ✅ 通过

潜在问题:

  1. src/dde-lock/lockworker.cpp:60 - 300ms 作为魔法数字硬编码在代码中,建议定义为命名常量以提高可维护性

建议: 定义命名常量:static constexpr int kWakeUpAuthDelayMs = 300;


4. 代码安全 🔒

评价: 优秀 ✅ 通过

🔐 发现 0 个安全漏洞

安全漏洞详情:
✅ 未发现安全漏洞

建议: 无需安全加固,代码变更不涉及安全风险


💡 改进建议代码示例

// 在定时器 lambda 中增加 nullptr 检查
connect(m_wakeUpAuthTimer, &QTimer::timeout, this, [this](){
    if (m_model && m_model->currentUser()) {
        createAuthentication(m_model->currentUser()->name());
    }
});

// 定义命名常量替代魔法数字
static constexpr int kWakeUpAuthDelayMs = 300;
m_wakeUpAuthTimer->setInterval(kWakeUpAuthDelayMs);

本报告由 AI 代码审查工具自动生成

@deepin-ci-robot

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: 52cyb, yixinshark

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@52cyb

52cyb commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

/forcemerge

@deepin-bot

deepin-bot Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

This pr force merged! (status: unstable)

@deepin-bot
deepin-bot Bot merged commit 3e57e2f into linuxdeepin:master Sep 1, 2026
13 of 15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants