Thanks. I added the SRU template to the bug description.

** Description changed:

+ [ Impact ]
+ 
+ mate-notification-daemon crashes (SIGSEGV) in two cases:
+ - a client calls CloseNotification with ID 0
+ - a client calls Notify while more than 20 notifications are open
+ 
+ In both cases the handler sends a D-Bus error reply and then returns FALSE.
+ The generated skeleton then sends a second error reply on the same
+ GDBusMethodInvocation, so the invocation is unreferenced two times.
+ 
+ Users of the MATE desktop see "The application Popup Notifications has closed
+ unexpectedly", frequently at login, when update-notifier starts the daemon.
+ The notification that caused the crash is lost.
+ 
+ The fix is upstream commit 7ed5496 (in 1.29.0). The two handlers return TRUE
+ after the error reply.
+ 
+ [ Test Plan ]
+ 
+ 1. In a MATE session, run:
+      gdbus call --session --dest org.freedesktop.Notifications \
+        --object-path /org/freedesktop/Notifications \
+        --method org.freedesktop.Notifications.CloseNotification 0
+    Expected: the call returns the error "0 is not a valid notification ID".
+    Then run:
+      gdbus call --session --dest org.freedesktop.Notifications \
+        --object-path /org/freedesktop/Notifications \
+        --method org.freedesktop.Notifications.GetServerInformation
+    Expected: the call returns the server information. "journalctl -k" shows
+    no segfault of mate-notificati.
+    Without the fix, the daemon segfaults in
+    g_type_check_instance_is_fundamentally_a after the first call.
+ 
+ 2. Run:
+      for i in $(seq 22); do notify-send -t 30000 "test $i"; done
+    Expected: the daemon continues to run, and the journal shows no
+    "g_object_unref: assertion 'G_IS_OBJECT (object)' failed" message.
+    Without the fix, the result of this step is not constant: the critical
+    message, a crash, or no visible effect. Step 1 is the reliable
+    reproducer.
+ 
+ 3. Regression check: run notify-send "hello". Expected: the notification
+    shows, and it closes when it expires or when you click its close button.
+ 
+ [ Where problems could occur ]
+ 
+ The change affects only the return value of two D-Bus method handlers, on
+ their error paths. With TRUE, the GDBus skeleton treats the call as handled
+ and does not send a second reply. The success paths do not change.
+ 
+ A regression would show as a client that does not get an error reply for
+ CloseNotification(0), or for Notify above the limit. Such a client would wait
+ until its D-Bus call times out. Step 1 of the test plan makes sure that the
+ error reply arrives.
+ 
+ [ Other Info ]
+ 
+ The patch is a cherry-pick of the upstream commit, with only line offsets
+ changed. Debian has the same bug in 1.26.1-1 (trixie, forky, sid).
+ 
+ The same patch is in stonking, version 1.26.1-1ubuntu1 (Fix Released on
+ 2026-09-30). Stonking is the only release newer than resolute.
+ 
+ [ Original Description ]
+ 
  Package: mate-notification-daemon → Launchpad, Ubuntu 26.04 LTS
  
  Title: mate-notification-daemon segfaults in libgobject at session start
  (glib 2.88 regression)
  
  Tags: segfault, glib-2.88, apport-bug, desktop-MATE, regression-2.86 (if
  2.86 worked)
  
  Link this upstream: GNOME/GLib!789 "GObject 2.87.1/2.88.0 use-after-free
  in g_object_notify_queue"
  
  Bug description:
  mate-notification-daemon (1.26.1-1build6) crashes with a segfault on every 
desktop-session start and whenever notifications are shown. It is triggered at 
login by update-notifier activating D-Bus org.freedesktop.Notifications, and 
reproducible manually:
  for i in $(seq 1 60); do notify-send "x" "y"; done   # → daemon segfaults
  
  Stacktrace (reproduced under gdb):
  Signal SIGSEGV at g_type_check_instance_is_fundamentally_a 
[libgobject-2.0.so.0.8800.0]
  #0 g_type_check_instance_is_fundamentally_a ... libgobject-2.0.so.0
  #1 g_object_unref ... libgobject-2.0.so.0     ← unref of freed instance
  #6 g_main_loop_run   libgobject-2.0.so.0
  #7 gtk_main          libgtk-3.so.0
  #8 main              [mate-notification-daemon]
  
  syslog:
  kernel: mate-notificati[114779]: segfault at 650e4413881e ip 00007d5f3b6f1301 
sp ... error 4 in libgobject-2.0.so.0.8800.0[3e301...]
  
  Root cause: GLib 2.88.0 (a major/newer release) changed g_object_notify
  to queue notifications asynchronously. mate-notification-daemon 1.26.x
  holds a weak reference to a GObject (monitor/GdkMonitor) and calls
  g_object_unref without a strong reference; when the weak ref fires
  during a notification shift (notify_stack_shift_notifications), the
  instance is already freed → invalid GTypeInstance →
  g_type_check_instance_is_fundamentally_a dereferences freed memory →
  SIGSEGV. (Confirmed: assertion g_object_unref: assertion 'G_IS_OBJECT
  (object)' failed is logged immediately before each crash.) This was
  masked on older GLib but exposed by 2.88.0.
  
  Affected / verified: glib 2.88.0-1 (libgobject-2.0.so.0.8800.0); mate-
  notification-daemon 1.26.1-1build6; Ubuntu 26.04 LTS.
  
  What I checked: -proposed (universe/main/restricted/multiverse) has no
  newer version; only 1.26.1-1build6 exists in resolute/universe. So this
  is not fixed by Ubuntu yet.
  
  Fix for Ubuntu maintainers: SRU mate-notification-daemon 1.28.x
  (upstream). The MATE 1.26.x branch is EOL; 1.28.x fixes this and other
  GLib 2.88 issues.
  
  Workaround (for users): sudo apt install xfce4-notifyd and set it as the
  notification daemon (mate-notification-properties → Custom →
  xfce4-notifyd-config), or remove ~/.config/autostart/update-
  notifier.desktop (avoids the boot-time trigger only).
  
  ProblemType: Bug
  DistroRelease: Ubuntu 26.04
  Package: mate-notification-daemon 1.26.1-1build6
  ProcVersionSignature: Ubuntu 7.0.0-31.31-generic 7.0.14
  Uname: Linux 7.0.0-31-generic x86_64
  ApportVersion: 2.34.1-0ubuntu0.1
  Architecture: amd64
  CasperMD5CheckResult: pass
  CurrentDesktop: MATE
  Date: Sat Aug 29 18:49:42 2026
  InstallationDate: Installed on 2026-06-28 (62 days ago)
  InstallationMedia: Ubuntu 26.04 "Resolute Raccoon" - Release amd64 
(20260423.1)
  ProcEnviron:
   LANG=en_US.UTF-8
   PATH=(custom, no user)
   SHELL=/bin/bash
   TERM=xterm-256color
   XDG_RUNTIME_DIR=<set>
  SourcePackage: mate-notification-daemon
  UpgradeStatus: No upgrade log present (probably fresh install)

** Changed in: mate-notification-daemon (Ubuntu Resolute)
       Status: Incomplete => In Progress

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2165836

Title:
  mate-notification-daemon segfaults in libgobject at session start
  (glib 2.88 regression)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/mate-notification-daemon/+bug/2165836/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to