Public bug reported:
Occasionally, after entering the password at the lightdm greeter, the desktop
background
appears but the session does not start for exactly 90 seconds. The delay ends
when systemd
SIGKILLs the greeter's session scope after its stop timeout expires.
Root cause, confirmed by capturing the stuck process during the hang:
signal_cb() in src/session-child.c calls exit() directly from a signal
handler:
static void
signal_cb (int signum)
{
if (child_pid > 0)
kill (child_pid, signum);
else
exit (EXIT_SUCCESS);
}
exit() is not async-signal-safe. When logind stops the greeter session it sends
SIGTERM. If
that signal is delivered while the main thread is inside malloc() -- holding
the glibc
main_arena lock -- then exit() runs the ELF destructors, libgnutls/libtasn1
call free(), and
free() blocks forever on that same non-recursive lock. The process can then
only be killed
with SIGKILL, so systemd waits out DefaultTimeoutStopSec (90 s) before the user
session can
take the VT.
Backtrace of the deadlocked session-child (PID 2614, uid 126, sole member of
session-c1.scope), taken 63 s into the stop:
#1 __GI___lll_lock_wait_private (futex=0x7459c4404ac0 <main_arena>)
#2 _int_free (av=0x7459c4404ac0 <main_arena>) at ./malloc/malloc.c:4644
#3 __GI___libc_free () at ./malloc/malloc.c:3398
#4 libtasn1.so.6
#5 libgnutls.so.30
#6 _dl_call_fini () at ./elf/dl-call_fini.c:43
#7 _dl_fini () at ./elf/dl-fini.c:114
#8 __run_exit_handlers (run_dtors=true) at ./stdlib/exit.c:108
#9 __GI_exit () at ./stdlib/exit.c:138
#10 signal_cb (in /usr/sbin/lightdm)
#11 <signal handler called>
#12 malloc_consolidate (av=0x7459c4404ac0 <main_arena>) at
./malloc/malloc.c:4878
#13 _int_malloc (av=0x7459c4404ac0 <main_arena>, bytes=1324)
#14 __GI___libc_malloc (bytes=1324)
#15 g_file_get_contents ()
Frames #13/#12 take the lock at 0x7459c4404ac0 <main_arena>; frames #2/#1 wait
on the same
address on the same thread. /proc/2614/status confirms it is inside the handler:
SigCgt has bit 15 (SIGTERM) set and SigBlk shows SIGTERM currently blocked;
state is S,
wchan futex_do_wait, unchanged across snapshots 5 s apart.
Journal:
10:25:32 Stopping session-c1.scope - Session c1 of User lightdm...
10:27:02 session-c1.scope: Stopping timed out. Killing.
10:27:02 session-c1.scope: Killing process 2614 (lightdm) with signal
SIGKILL.
10:27:02 Started session-c2.scope - Session c2 of User mgk25
Fix: use _exit(EXIT_SUCCESS) instead of exit(EXIT_SUCCESS). _exit() is
async-signal-safe and
skips precisely the atexit handlers and ELF destructors that must not run from
a signal
handler. One-line change; the kill() path is unaffected.
The code is identical in current upstream main, so this is not fixed in any
later release.
Reported upstream at https://github.com/ubuntu/lightdm/issues/484
Workaround, for anyone hitting this before an SRU:
/etc/systemd/system/session-.scope.d/10-stop-timeout.conf
[Scope]
TimeoutStopSec=5s
This bounds the hang to a few seconds instead of 90.
ProblemType: Bug
DistroRelease: Ubuntu 24.04
Package: lightdm 1.30.0-0ubuntu14
ProcVersionSignature: Ubuntu 7.0.0-31.31~24.04.1-generic 7.0.14
Uname: Linux 7.0.0-31-generic x86_64
ApportVersion: 2.28.3-0ubuntu0.1
Architecture: amd64
CasperMD5CheckResult: pass
CurrentDesktop: XFCE
Date: Thu Sep 24 10:41:19 2026
InstallationDate: Installed on 2024-06-13 (833 days ago)
InstallationMedia: Ubuntu 24.04 LTS "Noble Numbat" - Release amd64 (20240424)
SourcePackage: lightdm
UpgradeStatus: No upgrade log present (probably fresh install)
** Affects: lightdm (Ubuntu)
Importance: Undecided
Status: New
** Tags: amd64 apport-bug noble
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168421
Title:
lightdm session-child calls exit() from its SIGTERM handler,
deadlocking in malloc: 90 s login delay
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lightdm/+bug/2168421/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs