cinnamon-session aborts on g_variant_unref(NULL) when an Electron client (Obsidian) crashes mid-DBus dispatch — kicks user to LightDM greeter
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 48/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- c
- Lĩnh vực
- desktop-dev
Hướng nghiên cứu
Bắt đầu trong các đường dẫn của cinnamon-session-binary xử lý tín hiệu name-lost của tên org.gnome.SessionManager và đường dẫn đóng của end-session-dialog; issue không cung cấp tệp nguồn hoặc vị trí kiểm thử. Tái hiện hoặc theo dõi một máy khách DBus đã đăng ký nhưng bị kết thúc không sạch trong khi theo dõi journalctl. Hoàn tất khi lỗi của máy khách được ghi nhật ký hoặc được xử lý như có thể khôi phục, và phiên Cinnamon vẫn hoạt động mà không bị hủy do các lỗi critical của GLib.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Body (paste into "Add a description")
Summary
When an Electron-based DBus client (Obsidian 1.12.7, bundled Chromium) crashes
with an int3 trap inside dbus_connection_dispatch, cinnamon-session-binary
itself aborts on g_variant_unref: assertion 'value != NULL' failed and the
entire user session is torn down — LightDM returns to the greeter and every
X-session child process (terminals, multiplexers, editors, IDEs) is killed.
The session manager should log the misbehaving client and continue, not abort.
Reproduced 4 times in 1 hour on 2026-05-10 (13:05, 13:08, 13:24, 13:57)
plus once on 2026-05-08 with the identical signature.
Environment
| Distro | Linux Mint 22.2 (Zara) |
| Session | X11 / X-Cinnamon |
cinnamon-session |
6.4.0+xia |
cinnamon |
6.4.8+xia |
| Display manager | LightDM |
| Kernel | 6.8.0-110-generic |
| GPU | AMD Radeon RX 7900 XT (amdgpu) |
| Triggering app | Obsidian 1.12.7 (Electron / Chromium) |
Crash signature (journalctl, one occurrence)
May 10 13:57:38 kernel: traps: ThreadPoolSingl[1497465] trap int3 ip:5af2bf41433e
sp:7c4423df8440 error:0 in obsidian[5af2badd7000+923e000]
May 10 13:57:38 cinnamon-session-binary: CRITICAL: Unable to start session:
Lost name on bus: org.gnome.SessionManager
May 10 13:57:38 cinnamon-session-binary: GLib-CRITICAL: g_variant_unref:
assertion 'value != NULL' failed
May 10 13:57:38 cinnamon-session-binary: CRITICAL: Unable to close Cinnamon's
end session dialog: The connection is closed
May 10 13:57:38 cinnamon-session-binary: GLib-GObject-CRITICAL: g_object_unref:
assertion 'G_IS_OBJECT (object)' failed
May 10 13:57:38 lightdm: pam_unix(lightdm:session): session closed for user
May 10 13:57:38 systemd-logind: Session c8 logged out. Waiting for processes to exit.
May 10 13:57:39 systemd-coredump: Process 1497452 (obsidian) of user 1000 dumped core.
May 10 13:57:39 lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm
May 10 13:57:39 systemd-logind: New session c9 of user lightdm.
The Obsidian coredump confirms the crashing thread was inside DBus dispatch
when it hit the int3:
Stack trace of thread 1497465 (ThreadPoolSingl):
#0..#3 (obsidian internal)
#4 dbus_connection_dispatch (libdbus-1.so.3 + 0x181b9)
#5..#13 (obsidian internal)
#14 start_thread (libc.so.6 + 0x9caa4)
Expected behaviour
A single misbehaving DBus client crashing should not be able to take down
cinnamon-session and end the user session. The g_variant_unref(NULL) is a
defensive bug inside cinnamon-session: somewhere in the
Lost name on bus / end-session-dialog cleanup path, a GVariant* is unref'd
without a null check after the client connection is already closed.
Actual behaviour
cinnamon-session aborts → systemd-logind closes the session → LightDM greeter →
all running work in the X session is lost (terminal multiplexers, editors,
running builds, unsaved buffers).
Reproduction
The triggering Obsidian/Chromium crash itself is rare and not deterministic.
However, the cinnamon-session vulnerability should be reproducible synthetically
by killing any DBus-registered session client uncleanly mid-method-call —
for example kill -SEGV <pid> of a session-registered client during an
EndSessionResponse exchange, or while the session manager is processing
org.gnome.SessionManager name loss.
Suggested fix
Audit the Lost name on bus / end-session-dialog cleanup paths in
cinnamon-session for unchecked g_variant_* and g_object_* calls. Add
g_return_if_fail (value != NULL) guards. Treat connection is closed as a
recoverable warning, not a fatal session-ending event.
Relevant search points (likely candidates):
- whatever handles the
name-lostsignal onorg.gnome.SessionManager - the dialog-close path that emits
Unable to close Cinnamon's end session dialog
Workaround currently applied locally (not a fix)
Launch Obsidian with --disable-gpu --disable-gpu-compositing --disable-software-rasterizer. This eliminates the Chromium GPU-process path
that trips the int3 — i.e. it removes the trigger but does not address the
cinnamon-session fragility. Any other Electron app crashing mid-DBus will
reproduce the same kickout.
- Ngôn ngữ chính
- C
- Star
- 30
- Fork
- 41
- Merge trung bình
- 22 ngày 3 giờ
- Pull request đã merge (30 ngày)
- 1
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của linuxmint/cinnamon-session
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
linuxmint/cinnamon-session#218 ·
-
bug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
linuxmint/cinnamon-session#217 ·
-
Intermittent reboot/poweroff failure from active Cinnamon X11 session; logout-first reboot succeedsĐang mởbug
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 30/100
linuxmint/cinnamon-session#216 · 3 bình luận ·
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 15/100
linuxmint/cinnamon-session#200 ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 38/100
linuxmint/cinnamon-session#196 · 1 bình luận ·
Tất cả issue của linuxmint/cinnamon-session
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
microsoft/ebpf-for-windows#5604 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Update OPENEXR_IMATH_TAGĐang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 84/100
AcademySoftwareFoundation/openexr#2683 ·
Maintainer thường phản hồi trong vòng 1 ngày