https://bugs.kde.org/show_bug.cgi?id=525924

            Bug ID: 525924
           Summary: Large file moves can generate a huge unsplit
                    KDirNotify.FilesRemoved D-Bus signal and destabilize
                    the Plasma session
    Classification: I don't know
           Product: kde
      Version First unspecified
       Reported In:
          Platform: Fedora RPMs
                OS: Linux
            Status: REPORTED
          Severity: normal
          Priority: NOR
         Component: general
          Assignee: [email protected]
          Reporter: [email protected]
  Target Milestone: ---

Description

I encountered a Plasma desktop failure while using Dolphin on Fedora with KIO
6.30.0.

The immediate D-Bus failure was caused while Dolphin was broadcasting:

org.kde.KDirNotify.FilesRemoved

The signal was being delivered to kded6 when dbus-broker rejected another
accounting charge of:

76,215,631 bytes

At that point the user's D-Bus quota was exhausted and kded6 was disconnected.
Immediately afterward, several KDE session components exited, including Plasma
and the KDE desktop portal. Dolphin remained alive with a broken D-Bus
connection and later crashed.

The structured broker log identifies:

Sender: Dolphin (org.freedesktop.FileManager1, org.kde.dolphin-9757)
Receiver at the failed delivery: kded6
Signal: org.kde.KDirNotify.FilesRemoved
Object path: /
Signature: as (array of strings)
Attempted accounting charge: 76,215,631 bytes
Relevant KIO behavior

Inspection of the KIO 6.30.0 implementation shows that a copy/move job
accumulates successfully moved source URLs and successfully removed
source-directory URLs.

At completion of the move, that accumulated collection is passed to the
file-notification code and emitted as one FilesRemoved notification.

The URL list does not appear to be split into smaller D-Bus messages.

This means that moving a sufficiently large directory tree can potentially
result in a very large FilesRemoved D-Bus broadcast.

Because a broadcast is delivered to multiple subscribers, this can also
multiply the D-Bus accounting cost.

Context

At the time I was migrating large directory trees between two different
filesystems using Dolphin.

One of the moved directory trees currently contains approximately 103,000
files/directories. However, I cannot prove that this specific directory tree
generated the observed 76 MB notification. Reconstructing its current source
URLs produces only approximately 12 MB of serialized data.

Therefore I do not want to claim that this particular move is proven to be the
source of the signal.

What is directly established is:

Dolphin emitted an unusually large FilesRemoved signal.
KIO's move implementation can accumulate a large number of removed URLs and
emit them together.
The message caused very large D-Bus accounting charges.
The user's D-Bus quota was exhausted while the broadcast was being forwarded.
Multiple KDE session components failed immediately afterward.
Expected behavior

Moving a very large file hierarchy should not result in a single unbounded
D-Bus notification capable of exhausting the session bus quota or destabilizing
the desktop.

Large FilesRemoved notifications should probably be chunked/batched, limited,
or represented in some other way that cannot grow proportionally without bound
with the number of moved files.

Actual behavior

A FilesRemoved broadcast generated by Dolphin required approximately 76 MB of
D-Bus accounting per recipient and contributed to exhausting the user-session
D-Bus quota.

This resulted in kded6 being disconnected and coincided with Plasma, portal,
and other KDE session failures.

Additional note

There is a separate dbus-broker quota configuration issue on this machine that
reduced the effective quota and made the incident easier to trigger. I plan to
report that independently.

However, even with a larger quota, allowing a single KIO file-operation
notification to grow to tens of megabytes appears undesirable and potentially
capable of exhausting resources with a sufficiently large file operation.

-- 
You are receiving this mail because:
You are watching all bug changes.

Reply via email to