Public bug reported:

[ Impact ]

On Wayland sessions, dropping something onto a GTK3 application
occasionally makes mutter disconnect that application with a Wayland
protocol error. The destination exits immediately and unsaved state is
lost.

The most visible victim is gnome-terminal: gnome-terminal-server is one
process for all windows and tabs, so a single unlucky drop closes every
terminal and kills everything running in them.

This is upstream mutter issue #4710, "Sometimes DnD destination
application exits due to 'premature finish request'", fixed by a one-
line change:

  https://gitlab.gnome.org/GNOME/mutter/-/issues/4710
  https://gitlab.gnome.org/GNOME/mutter/-/merge_requests/5009
  main:     6d192fde90f0598335fe51229da5fb73b0bf255c
            "wayland/data-offer: Don't skip initial identical action updates"
  gnome-49: ce70447369 (backport of the same change)

--- a/src/wayland/meta-wayland-data-offer.c
+++ b/src/wayland/meta-wayland-data-offer.c
@@ meta_wayland_data_offer_update_action (MetaWaylandDataOffer *offer)
   current_action = meta_wayland_data_source_get_current_action (source);
   action = data_offer_choose_action (offer);
 
-  if (current_action == action)
+  if (offer->action_sent && current_action == action)
     return;

Affected, checked against the "applied" source branches:
  noble     46.2-1ubuntu0.24.04.16 (updates) and 46.2-1ubuntu0.24.04.18 
(proposed)
  questing  49.0-2ubuntu5.3
Not affected:
  resolute  50.1-0ubuntu2.x and later already contain the fix.

The file is unmodified by Ubuntu patches in noble, so the upstream
change applies as is.

What happens: a data source outlives the data offers created for it. If
a previous offer (for example the one given to the drag source's own
window) sets the source's action, and the new destination then selects
the same action, mutter returns early from
meta_wayland_data_offer_update_action() without sending
wl_data_offer.action and without setting offer->action_sent. When the
destination later calls wl_data_offer.finish, data_offer_finish() sees
!offer->action_sent and posts WL_DATA_OFFER_ERROR_INVALID_FINISH
("premature finish request"), which is fatal for the client.

On my system (Ubuntu 24.04.5, GNOME on Wayland) this happened 13 times
between 2026-08-20 and 2026-10-01, always with this pair of journal
lines:

  gnome-shell[3671]: WL: error in client communication (pid 3215327)
  gnome-terminal-[3215327]: Error reading events from display: Invalid argument
  systemd[1912]: gnome-terminal-server.service: Main process exited, 
code=exited, status=1/FAILURE

10 of the 13 came 1–3 seconds after a screenshot was opened in eog and
dragged from there into a terminal. About 1000 such drags happened in
the same period, so the natural hit rate is around 1%.

The client-side message differs from the upstream report ("Broken
pipe"). With libwayland 1.22 and GTK 3.24.41, GTK destroys the
wl_data_offer right after sending finish, so the wl_display.error event
refers to an object the client no longer knows and
wl_display_read_events() fails with EINVAL. libwayland's own message
about it is logged by GTK at debug level only, which is why nothing more
specific appears in the journal.

[ Test Plan ]

The natural race is rare, so the attached dnd-repro.py forces the
ordering with two sleeps. It needs python3-gi and GTK 3, both installed
by default on Ubuntu Desktop, and a Wayland session.

1. Log in to a "Ubuntu" (Wayland) session.
2. Run: ./dnd-repro.py
   Two small windows open: "dnd-repro: source" and "dnd-repro: victim". Place 
them side by side.
3. Press on the text in the source window and drag straight into the victim 
window (within 2 seconds).
4. Keep the button held over the victim window until its label says DROP NOW 
(about 5 seconds), then release. Both windows are frozen while the button is 
held; that is intended.

The dragged data uses a private mime type, so other windows the pointer
crosses cannot accept it and do not influence the result.

Unpatched mutter: the victim window disappears. The script prints

  victim exit status: 1
  wl_data_offer.action events received by victim: 0 (values: none)
  wl_data_offer.finish requests sent by victim:   1
  log: Gdk-DEBUG: unknown object (4278190082), message error(ous)
  log: Gdk-Message: Error reading events from display: Invalid argument
  RESULT: REPRODUCED (victim was disconnected by the compositor)

and `journalctl -b | grep "error in client communication"` shows a new
line for the victim's pid.

Patched mutter: the victim window stays open and shows "drop completed,
bug not triggered". The script, after the victim window is closed,
prints at least one wl_data_offer.action event and

  RESULT: not reproduced (drop completed normally)

5. Control run, any mutter: ./dnd-repro.py --control (no sleeps). The drop must 
complete normally. This confirms the test windows themselves are valid drag 
sources and destinations.
6. Regression check with real applications on the patched mutter: drag a file 
from Files into gnome-terminal (the path is pasted), drag a file between two 
Files windows with and without Shift held (copy and move), drag selected text 
between two gedit or Text Editor windows, and drag a link from Firefox into a 
terminal.

[ Where problems could occur ]

The change only affects the Wayland drag-and-drop action negotiation in
mutter. After it, mutter sends wl_data_offer.action at least once for
every offer, including when the chosen action equals the source's
current action. The protocol already allows this event at any time and
well-behaved clients handle repeated values.

A regression would show up as wrong drag-and-drop behaviour in Wayland
sessions: a wrong copy/move/ask result, a wrong drag cursor, or a client
that mishandles an action event it did not receive before. X11 sessions
do not use this code. Drags that involve XWayland clients go through the
same data offer code on the Wayland side and should be included in
testing.

[ Other Info ]

Ubuntu 24.04.5 LTS, kernel 6.8.0-142-generic, session type wayland
libmutter-14-0      46.2-1ubuntu0.24.04.16
gnome-shell         46.0-0ubuntu6~24.04.15
gnome-terminal      3.52.0-1ubuntu2
libgtk-3-0t64       3.24.41-4ubuntu1.3
libwayland-client0  1.22.0-2.1build1
libwayland-server0  1.22.0-2.1build1
eog                 45.3-1ubuntu2

No core dump is produced: the client leaves through _exit(1) in GDK's
Wayland event source, not through a signal.

End of the victim's WAYLAND_DEBUG log from the attached reproducer run
on noble (run-165532-victim.log). The victim asks for "copy" on every
motion, never receives wl_data_offer.action for this offer, and is
disconnected right after finish:

  [3308946.782]  -> [email protected]_actions(7, 1)
  [3308946.784]  -> [email protected](250377, 
"application/x-dnd-repro")
  [3308955.203] [email protected]()
  [3308955.221] [email protected]()
  [3308955.458]  -> [email protected](250378, 
"application/x-dnd-repro")
  [3308955.471]  -> [email protected]("application/x-dnd-repro", 
fd 17)
  [3308955.523]  -> [email protected]_actions(7, 1)
  drop received: b'dnd-repro payload'
  [3308959.722]  -> [email protected]_actions(7, 1)
  [3308959.725]  -> [email protected]()
  [3308959.726]  -> [email protected]()
  Gdk-DEBUG: unknown object (4278190082), message error(ous)
  Gdk-Message: Error reading events from display: Invalid argument

Journal line for the same run (the victim's pid is 576163):

  Oct 01 16:55:37 gnome-shell[3671]: WL: error in client communication
(pid 576163)

The control run (./dnd-repro.py --control) on the same unpatched system
completed the drop normally and the victim received
wl_data_offer.action(1).

ProblemType: Bug
DistroRelease: Ubuntu 24.04
Package: mutter (not installed)
ProcVersionSignature: Ubuntu 6.8.0-142.142-generic 6.8.12
Uname: Linux 6.8.0-142-generic x86_64
NonfreeKernelModules: nvidia_modeset nvidia
ApportVersion: 2.28.3-0ubuntu0.1
Architecture: amd64
CasperMD5CheckResult: pass
CurrentDesktop: ubuntu:GNOME
Date: Thu Oct  1 17:05:11 2026
InstallationDate: Installed on 2022-09-18 (1474 days ago)
InstallationMedia: Ubuntu 22.04.1 LTS "Jammy Jellyfish" - Release amd64 
(20220809.1)
SourcePackage: mutter
UpgradeStatus: Upgraded to noble on 2024-09-11 (750 days ago)

** Affects: mutter
     Importance: Unknown
         Status: Unknown

** Affects: mutter (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: amd64 apport-bug noble wayland-session

** Attachment added: "dnd-repro.py"
   
https://bugs.launchpad.net/bugs/2169158/+attachment/6004275/+files/dnd-repro.py

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169158

Title:
  Drag-and-drop destination (e.g. all gnome-terminal windows) is killed
  with protocol error "premature finish request" — please backport
  upstream fix (mutter#4710)

To manage notifications about this bug go to:
https://bugs.launchpad.net/mutter/+bug/2169158/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to