canonical / canonical/authd

Entra password e2e test sometimes times out waiting for MFA code prompt

Open
#1,902 0 comments 0 reactions 0 assignees View on GitHub
e2e-tests
Dominant language
Go
Stars
308
Forks
41
Avg merge
2d 4h
Merged PRs (30d)
58

Description

I've seen the `Test polkit authentication as authd user via pkexec using Entra ID password and MFA after initial GDM login` test case fail with `ValueError: Timed out looking for 'Enter your MFA code' after '30' seconds`. The video shows that the Entra password was entered and the GDM spinner spinning until the timeout occurs.

Observed in:
* https://authd-e2e-test-logs.adrian-dombeck.workers.dev/push-34370596846/run-34370596846-1/resolute-authd-msentraid/log.html#s1-s27-t2
* https://authd-e2e-test-logs.adrian-dombeck.workers.dev/push-34096489851/run-34096489851-1/resolute-authd-msentraid/log.html#s1-s27-t2

Image

Excerpt from the logs:

```
Sep 09 16:39:15 ubuntu gdm-session-wor[3728]: adapter.isAuthenticatedRequested{*authd.IARequest_AuthenticationData_Secret{Secret:"***********"}}
Sep 09 16:39:15 ubuntu gdm-session-wor[3728]: adapter.isAuthenticatedRequestedSend{adapter.isAuthenticatedRequested{*authd.IARequest_AuthenticationData_Secret{Secret:"***********"}}}
Sep 09 16:39:15 ubuntu gdm-session-wor[3728]: Authentication request for session "2102147668-4d669187-ddd0-4e2a-9f77-b59f204ca534": &authd.IARequest_AuthenticationData_Secret{Secret:"PwV5tDLXxbLQu6QZ+B5SlNwrsrf8RRCCrOwlktF2nBuzIbEcvWp5PXMA1BUZ2wSDc/LHVu9YkR9WoENabC9YXWcvkZVGU/I6yZAMCX+w0QWRy0OF+1X73w1jv9gN1Q9GLDWEpUVhl8ZddTrvSuM9i0Hkmop9lOA6HRjhk/WP+eQhuAGwUWBnOKHzGJRcIb3SmJdwMTWJr/jPuij2TNAWMjJVpeT6MgbJSYMH+V9112b6ItPhCBUuIDq18sn+4Cl37JWsGVIB/glzwMNwgqMWsJGNqcr+i1omtdWtRxOXswHDRR2ZzT1y+Pq/Ndpw6cuf6RKbB7YwpcH8IeJbviqwag=="}
Sep 09 16:39:15 ubuntu authd-msentraid[3623]: Handling IsAuthenticated call for session 4d669187-ddd0-4e2a-9f77-b59f204ca534
Sep 09 16:39:15 ubuntu authd-msentraid[3623]: No cached auth info for user "e2e-test@ubudev1.onmicrosoft.com" (first login or unreadable token): could not read token: open /var/snap/authd-msentraid/x1/login.microsoftonline.com_03c73201-ef9e-4182-ae04-0adb51f4a0b6_v2.0/e2e-test@ubudev1.onmicrosoft.com/token.json: no such file or directory
Sep 09 16:39:15 ubuntu authd-msentraid[3623]: Initiating MFA flow for user "e2e-test@ubudev1.onmicrosoft.com" (withDeviceScope=true)
Sep 09 16:39:15 ubuntu kernel: audit: type=1400 audit(1788971955.670:205): apparmor="DENIED" operation="open" class="file" profile="snap.authd-msentraid.authd-msentraid" name="/sys/fs/cgroup/system.slice/snap.authd-msentraid.authd-msentraid.service/cpu.max" pid=3623 comm="authd-msentraid" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
Sep 09 16:39:15 ubuntu kernel: audit: type=1400 audit(1788971955.670:206): apparmor="DENIED" operation="open" class="file" profile="snap.authd-msentraid.authd-msentraid" name="/sys/fs/cgroup/system.slice/cpu.max" pid=3623 comm="authd-msentraid" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
Sep 09 16:39:15 ubuntu authd-msentraid.authd-msentraid[3623]: 2026-09-09T16:39:15.672893Z DEBUG himmelblau::auth: request_auth_config_internal() client_id=29d9ed98-a469-4536-ade2-f981bc1d605e redirect_uri=ms-aadj-redir://auth/drs scope=openid profile resource=https://enrollment.manage.microsoft.com/ caller_app_redirect_uri=companyportal://com.microsoft.CompanyPortal
Sep 09 16:39:19 ubuntu authd-msentraid.authd-msentraid[3623]: 2026-09-09T16:39:19.446855Z DEBUG himmelblau::auth: Credential type: pref_credential=1, has_password=true, has_fido=None, has_remote_ngc=None, has_access_pass=None, is_passkey_support_enabled=Some(true)
Sep 09 16:39:19 ubuntu authd-msentraid.authd-msentraid[3623]: 2026-09-09T16:39:19.446909Z DEBUG himmelblau::auth: passwordless_security_key: skipped (not enabled in config)
Sep 09 16:39:19 ubuntu authd-msentraid.authd-msentraid[3623]: 2026-09-09T16:39:19.446918Z DEBUG himmelblau::auth: passwordless_qr_bluetooth: skipped (not enabled in config)
Sep 09 16:39:19 ubuntu authd-msentraid.authd-msentraid[3623]: 2026-09-09T16:39:19.446925Z DEBUG himmelblau::auth: passwordless_tap triggered via fallthrough
Sep 09 16:39:19 ubuntu authd-msentraid.authd-msentraid[3623]: 2026-09-09T16:39:19.446931Z DEBUG himmelblau::auth: passwordless_tap: skipped (has_access_pass=false)
Sep 09 16:39:19 ubuntu authd-msentraid.authd-msentraid[3623]: 2026-09-09T16:39:19.446936Z DEBUG himmelblau::auth: passwordless_fido triggered via fallthrough
Sep 09 16:39:19 ubuntu authd-msentraid.authd-msentraid[3623]: 2026-09-09T16:39:19.446943Z DEBUG himmelblau::auth: passwordless_remote_ngc triggered via fallthrough
Sep 09 16:39:19 ubuntu authd-msentraid.authd-msentraid[3623]: 2026-09-09T16:39:19.446949Z DEBUG himmelblau::auth: passwordless_remote_ngc: skipped (remote_ngc_params absent)
Sep 09 16:39:19 ubuntu authd-msentraid.authd-msentraid[3623]: 2026-09-09T16:39:19.621832Z DEBUG himmelblau::auth: MFA methods available: [ArrUserProofs { auth_method_id: "PhoneAppOTP", is_default: true, display: "" }]
Sep 09 16:39:23 ubuntu authd-msentraid[3623]: IsAuthenticated result (session 4d669187-ddd0-4e2a-9f77-b59f204ca534): next, {}
Sep 09 16:39:23 ubuntu authd[1068]: 2102147668-4d669187-ddd0-4e2a-9f77-b59f204ca534: Authentication result: next
Sep 09 16:39:23 ubuntu authd-msentraid[3623]: Getting authentication modes for session 4d669187-ddd0-4e2a-9f77-b59f204ca534
Sep 09 16:39:23 ubuntu authd-msentraid[3623]: Got authentication modes for session 4d669187-ddd0-4e2a-9f77-b59f204ca534: [map[id:entra_mfa_code label:Enter your MFA code]]
Sep 09 16:39:23 ubuntu gdm-session-wor[3728]: adapter.authModesReceived{authModes:[]*authd.GAMResponse_AuthenticationMode{(*authd.GAMResponse_AuthenticationMode)(0x1039be2b8230)}}
Sep 09 16:39:23 ubuntu gnome-shell[1527]: authd: Access response: next
Sep 09 16:39:23 ubuntu authd-msentraid[3623]: Selecting authentication mode entra_mfa_code for session 4d669187-ddd0-4e2a-9f77-b59f204ca534
Sep 09 16:39:23 ubuntu authd-msentraid[3623]: Selected authentication mode entra_mfa_code for session 4d669187-ddd0-4e2a-9f77-b59f204ca534: map[entry:chars label:Enter your MFA code type:form]
Sep 09 16:39:23 ubuntu gdm-session-wor[3728]: adapter.UILayoutReceived{&authd.UILayout{state:impl.MessageState{NoUnkeyedLiterals:pragma.NoUnkeyedLiterals{}, DoNotCompare:pragma.DoNotCompare{}, DoNotCopy:pragma.DoNotCopy{}, atomicMessageInfo:(*impl.MessageInfo)(nil)}, Type:"form", Label:(*string)(0x1039be298680), Button:(*string)(0x1039be298690), Wait:(*string)(0x1039be2986a0), Entry:(*string)(0x1039be2986b0), Content:(*string)(0x1039be2986c0), Code:(*string)(0x1039be2986d0), RendersQrcode:(*bool)(nil), unknownFields:[]uint8(nil), sizeCache:0}}
```

Contributor guide

Open the contributing guide

Research direction

Start with the `Test polkit authentication as authd user via pkexec using Entra ID password and MFA after initial GDM login` end-to-end test and compare the two linked failure logs. Trace the flow from password submission through the `entra_mfa_code` authentication mode, then run the test repeatedly; done means the MFA prompt appears reliably without the 30-second timeout.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
authentication, testing
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.