https://bugs.kde.org/show_bug.cgi?id=525924
Bug ID: 525924
Summary: Large file moves can generate a huge unsplit
KDirNotify.FilesRemoved D-Bus signal and destabilize
the Plasma session
Classification: I don't know
Product: kde
Version First unspecified
Reported In:
Platform: Fedora RPMs
OS: Linux
Status: REPORTED
Severity: normal
Priority: NOR
Component: general
Assignee: [email protected]
Reporter: [email protected]
Target Milestone: ---
Description
I encountered a Plasma desktop failure while using Dolphin on Fedora with KIO
6.30.0.
The immediate D-Bus failure was caused while Dolphin was broadcasting:
org.kde.KDirNotify.FilesRemoved
The signal was being delivered to kded6 when dbus-broker rejected another
accounting charge of:
76,215,631 bytes
At that point the user's D-Bus quota was exhausted and kded6 was disconnected.
Immediately afterward, several KDE session components exited, including Plasma
and the KDE desktop portal. Dolphin remained alive with a broken D-Bus
connection and later crashed.
The structured broker log identifies:
Sender: Dolphin (org.freedesktop.FileManager1, org.kde.dolphin-9757)
Receiver at the failed delivery: kded6
Signal: org.kde.KDirNotify.FilesRemoved
Object path: /
Signature: as (array of strings)
Attempted accounting charge: 76,215,631 bytes
Relevant KIO behavior
Inspection of the KIO 6.30.0 implementation shows that a copy/move job
accumulates successfully moved source URLs and successfully removed
source-directory URLs.
At completion of the move, that accumulated collection is passed to the
file-notification code and emitted as one FilesRemoved notification.
The URL list does not appear to be split into smaller D-Bus messages.
This means that moving a sufficiently large directory tree can potentially
result in a very large FilesRemoved D-Bus broadcast.
Because a broadcast is delivered to multiple subscribers, this can also
multiply the D-Bus accounting cost.
Context
At the time I was migrating large directory trees between two different
filesystems using Dolphin.
One of the moved directory trees currently contains approximately 103,000
files/directories. However, I cannot prove that this specific directory tree
generated the observed 76 MB notification. Reconstructing its current source
URLs produces only approximately 12 MB of serialized data.
Therefore I do not want to claim that this particular move is proven to be the
source of the signal.
What is directly established is:
Dolphin emitted an unusually large FilesRemoved signal.
KIO's move implementation can accumulate a large number of removed URLs and
emit them together.
The message caused very large D-Bus accounting charges.
The user's D-Bus quota was exhausted while the broadcast was being forwarded.
Multiple KDE session components failed immediately afterward.
Expected behavior
Moving a very large file hierarchy should not result in a single unbounded
D-Bus notification capable of exhausting the session bus quota or destabilizing
the desktop.
Large FilesRemoved notifications should probably be chunked/batched, limited,
or represented in some other way that cannot grow proportionally without bound
with the number of moved files.
Actual behavior
A FilesRemoved broadcast generated by Dolphin required approximately 76 MB of
D-Bus accounting per recipient and contributed to exhausting the user-session
D-Bus quota.
This resulted in kded6 being disconnected and coincided with Plasma, portal,
and other KDE session failures.
Additional note
There is a separate dbus-broker quota configuration issue on this machine that
reduced the effective quota and made the incident easier to trigger. I plan to
report that independently.
However, even with a larger quota, allowing a single KIO file-operation
notification to grow to tens of megabytes appears undesirable and potentially
capable of exhausting resources with a sufficiently large file operation.
--
You are receiving this mail because:
You are watching all bug changes.