[From nobody Thu Sep 17 19:43:11 2026
Received: (at submit) by bugs.debian.org; 16 Sep 2026 19:46:37 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-14.1 required=4.0 tests=BAYES_00,
 BODY_INCLUDES_PACKAGE,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,
 DKIM_VALID_EF,FORGED_GMAIL_RCVD,FOURLA,FREEMAIL_FROM,HAS_PACKAGE,
 SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 57; hammy, 150; neutral, 313; spammy,
 0. spammytokens: hammytokens:0.000-+--XDebbugsCc,
 0.000-+--X-Debbugs-Cc, 0.000-+--H*u:Evolution, 0.000-+--forky,
 0.000-+--journalctl
Return-path: &lt;mariodebian@gmail.com&gt;
Received: from mail-wr2-x28.google.com ([2a00:1450:4864:30::28]:32893)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_128_GCM:128)
 (Exim 4.96) (envelope-from &lt;mariodebian@gmail.com&gt;)
 id 1x6vaW-00D1w3-2w for submit@bugs.debian.org;
 Wed, 16 Sep 2026 19:46:36 +0000
Received: by mail-wr2-x28.google.com with SMTP id
 ffacd0b85a97d-485b1d2874aso90900f8f.1
 for &lt;submit@bugs.debian.org&gt;; Wed, 16 Sep 2026 12:46:36 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=gmail.com; s=20251104; t=1789587994; x=1790192794; darn=bugs.debian.org;
 h=mime-version:user-agent:content-transfer-encoding:content-type:date
 :to:from:subject:message-id:from:to:cc:subject:date:message-id
 :reply-to:content-type;
 bh=klyhsX5EKGwHMFpCdfbgmPNQ68wPzlZ2WonfpCgZiKU=;
 b=iz1QMQG85LxIsTcdm4ksBiVzMKLzxx4ak6R1n6EIHvj4PlHfC7C838+M1XG4bcwdnX
 dGgx+zodQm2GQJr3hUMvknBG7/lC79pbnV9AywMNB+y3VyDJsWe1OrC3aZJcccG99QE2
 EB92GwJR9L03Nr5jfHHYA3TK6hLq52+UfRGg1uBV/2qlUrssKeBU0+gNNeKE3gqGRzZ9
 JyV7Dx7KUr22sCrnjOC7eCvEBhs+MHKr7rRR7z5XyjLJQ6HZ4hTCkBoyYOA1sruEFrVr
 8akRZSgsblI4VhrQFH9N0/e/H2ohVUUZw21z+rI/SmTygJ8CGfremPvrTlpD9QzF7dNi
 Knnw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20260707; t=1789587994; x=1790192794;
 h=mime-version:user-agent:content-transfer-encoding:content-type:date
 :to:from:subject:message-id:x-gm-gg:x-gm-message-state:from:to:cc
 :subject:date:message-id:reply-to:content-type;
 bh=klyhsX5EKGwHMFpCdfbgmPNQ68wPzlZ2WonfpCgZiKU=;
 b=ld41r+UJ/+uacNHC4KAlCUyL4vpzHKLDpcamEivyRK+DlZI/0Cc8fGY16+TD458TNZ
 gZfTFheSwVYbUsVG5J8nEqb4G34uHV2cS4mMhVVkGmNpOE04Y5eeM5+MXN/j4xY5aDSJ
 OT+FW4SQTPQw4ieMiwdb10GcEQh2xAJHJvLxWKQERumXYMNzW7XO1qhcnW1d2wd06NKo
 FB7bqW2aGBz7gIPs16+cH/4a1KpWtUek3AWDOUPD1MOfS31QkP8FmwwkcJV0cmF31ptt
 rg3EC5rXs3/+eg6n1Q9+IwKuU2OrVzWmdfIQJaTnd5vpssLA45YCwF/sMWEpHb0EYn6Q
 RHtQ==
X-Gm-Message-State: AFuF++kA+lTK+2FrPuxl8/ck2ZAdzaHsiWfJQIjFkZEoblOZtMGSjbxo
 f3Cx0Jcw0E1lAyIU5zzehyx5AFLx6BWSD/4zXms5N1CeZr78s+E+eCsPn022GA==
X-Gm-Gg: AYBFou0pBV9fweYMtfeQLjCCpMFDr063yqpKYGUMtZBi+w5dxUyfOjSnLzsAbHgGmxe
 rHZUtO4277VYNhXrbRs0913NRRXjdC4PqBD0sieZkHAGjR5LeQgGGApG6SEkFIlA8PKVwLZhstE
 iQg5gb0SYeZoDJ8IREmq7O0YepyfVajeGPMbV8Ez90sp62xNFXdRGCDl6RTcCuyqO1skn8Qb6+z
 fCSyFYwH3EFEidd4xM+ZM/rzNlj2FRttp4BJKmsbY0Tya3xSwgYDExjRtFaW2L1ZAqW9K2z35L9
 tqNMb5A9HygR97Z74EgMJ3We4DllhWpozUnIx7fqC4VvGj6g5MhcOyslJ3HCrYtVRcoaEt4nv5O
 tEbAGSbWPvCPeTj9Foedv1cja9q2nZSEA8cpo6RB1vUJemzgyf0lax5ZCpZr19FMoR63ls8Lk8V
 /BxQGMbFcseQPJNfVz+/EOPFdxvjHpLTJ7UFDeDgziC74n011oAKfLe8vuOEH6dT0ooXlVyaBLI
 f6CtKui9vbAqRkkzu/lAVe5loK3k0o81rtXPsZUE00=
X-Received: by 2002:a5d:5888:0:b0:487:c5e:4572 with SMTP id
 ffacd0b85a97d-4870cf03182mr9707899f8f.11.1789587993996; 
 Wed, 16 Sep 2026 12:46:33 -0700 (PDT)
Received: from [192.168.1.11] (78.red-83-53-98.dynamicip.rima-tde.net.
 [83.53.98.78]) by smtp.gmail.com with ESMTPSA id
 ffacd0b85a97d-4870bf43511sm8795018f8f.33.2026.09.16.12.46.33
 for &lt;submit@bugs.debian.org&gt;
 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
 Wed, 16 Sep 2026 12:46:33 -0700 (PDT)
Message-ID: &lt;72414213a50b402a5aad887b2790f67cc9ad14bc.camel@gmail.com&gt;
Subject: gnome-keyring: gnome-keyring-daemon segfaults in libgck-1 after
 50.0-1 -&gt; 51.0-1 upgrade
From: &quot;mariodebian@gmail.com&quot; &lt;mariodebian@gmail.com&gt;
To: submit@bugs.debian.org
Date: Wed, 16 Sep 2026 21:46:32 +0200
Content-Type: text/plain; charset=&quot;UTF-8&quot;
Content-Transfer-Encoding: quoted-printable
User-Agent: Evolution 3.56.2-10+b1 
MIME-Version: 1.0
Delivered-To: submit@bugs.debian.org

Package: gnome-keyring
Version: 51.0-1
Severity: important
X-Debbugs-Cc:

Dear Maintainer,

After the upgrade from gnome-keyring 50.0-1 to 51.0-1 (together with
gcr4/libgck-2-2/libgcr-4-4 4.4.0.1-8+b2 -&gt; 4.4.1-2 on the same day),
gnome-keyring-daemon started segfaulting repeatedly whenever a client
tries to unlock or write to the &quot;login&quot; collection (e.g. GNOME Online
Accounts saving an OAuth2 token, or a GUI password prompt completing).

This makes the secrets service effectively unusable: every application
that stores or retrieves a secret (Evolution's IMAP/SMTP passwords,
GNOME Online Accounts tokens, the SSH agent component) has to re-ask
for credentials every session, because gnome-keyring-daemon dies and
restarts with an empty/locked state in the middle of the operation.

Downgrading gnome-keyring, gnome-keyring-pkcs11 and libpam-gnome-
keyring
back to 50.0-1 (from snapshot.debian.org) immediately fixed the
problem; the daemon has been stable for hours since the downgrade,
with the exact same ~/.local/share/keyrings contents and the exact
same SSH keys in ~/.ssh.

Steps to reproduce
-------------------
1. Have a &quot;login&quot; keyring that gnome-keyring-daemon manages (default
   setup, PAM auto-unlock via pam_gnome_keyring).
2. Trigger a secret prompt/unlock, e.g.:
   - Open Evolution and let it ask for the IMAP/SMTP password, or
   - Add/refresh a Google account in GNOME Online Accounts (OAuth2
     token needs to be stored), or
   - Simply restart gnome-keyring-daemon and unlock the keyring via
     the gcr-prompter dialog.
3. gnome-keyring-daemon crashes with SIGSEGV a few seconds after the
   secret exchange with gcr-prompter completes.
4. systemd restarts the (systemd --user) service, which comes back
   with the collection locked again, so every stored secret has to be
   re-entered.

Observed crash (journalctl --user -u gnome-keyring-daemon.service)
--------------------------------------------------------------------
sep 16 20:46:07 host gcr-prompter[60485]: Gcr: completed password
prompt for callback :1.165@/org/gnome/keyring/Prompt/p3
sep 16 20:46:07 host gcr-prompter[60485]: Gcr: calling the PromptDone
method on /org/gnome/keyring/Prompt/p3@:1.165, and ignoring reply
sep 16 20:46:07 host systemd[1476]: gnome-keyring-daemon.service: Main
process exited, code=3Dkilled, status=3D11/SEGV
sep 16 20:46:07 host kernel: gnome-keyring-d[55426]: segfault at
f00dface ip 00007fa0a06e7482 sp 00007ffd1da93770 error 4 in libgck-
1.so.0.0.0[1d482,7fa0a06d4000+1d000] likely on CPU 0 (core 0, socket 0)
sep 16 20:46:07 host kernel: Code: 18 00 00 00 00 48 85 ff 0f 84 9a 00
00 00 48 89 fb 48 89 f5 49 89 d4 49 89 cd e8 d9 d6 fe ff 48 89 c6 48 8b
03 48 85 c0 74 05 &lt;48&gt; 39 30 74 0c 48 89 df e8 d1 d7 fe ff 85 c0 74 6d
48 85 ed 0f 84

The fault address (0xf00dface) looks like a memory-poisoning pattern,
suggesting a use-after-free/double-free rather than a plain NULL
pointer bug.

The same boot also shows repeated warnings just before some of the
earlier crashes, which may be related to the same underlying state
corruption:

  gnome-keyring-daemon[NNNN]: asked to register item
    /org/freedesktop/secrets/collection/login/N, but it's already
registered
  gnome-keyring-daemon[NNNN]: Gck: gck_session_find_objects: assertion
    'GCK_IS_SESSION (self)' failed
  gnome-keyring-daemon[NNNN]: GLib-GObject: g_object_unref: assertion
    'G_IS_OBJECT (object)' failed

Note: libgck-1-0 itself stayed at 3.41.2-6+b1 across the whole
timeframe (it did not get upgraded on 2026-09-15), so the regression
looks like it's in gnome-keyring's own use of libgck's PKCS#11/GObject
API rather than in libgck-1-0 itself.

Workaround
----------
Downgrade and hold at 50.0-1:

  sudo dpkg -i gnome-keyring_50.0-1_amd64.deb \
               gnome-keyring-pkcs11_50.0-1_amd64.deb \
               libpam-gnome-keyring_50.0-1_amd64.deb
  sudo apt-mark hold gnome-keyring gnome-keyring-pkcs11 libpam-gnome-
keyring

(.debs pulled from snapshot.debian.org,
archive/debian/20260317T150720Z/)

I don't have a symbolized backtrace (no gnome-keyring-dbgsym/systemd-
coredump
installed at the time), only the kernel oops line above. Happy to
install dbgsym packages and reproduce with 51.0-1 again to get a
proper `bt full` under gdb if that's useful =E2=80=94 let me know.

-- System Information:
Debian Release: forky/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64

Kernel: Linux 7.1.13+deb14-amd64 (SMP w/ PREEMPT_DYNAMIC)
Locale: LANG=3Des_ES.UTF-8, LC_CTYPE=3Des_ES.UTF-8 (charmap=3DUTF-8),
LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash, /bin/bash linked to
/usr/bin/bash
Init: systemd (via /run/systemd/system)

Versions of packages gnome-keyring depends on:
ii  dbus                    1.16.2-5+b1
ii  libgcrypt20             1.12.3-2
ii  libglib2.0-0t64         2.90.0-1
ii  libp11-kit0             0.26.5-1
ii  libgck-1-0              3.41.2-6+b1
ii  gcr4                    4.4.1-2
ii  libgck-2-2              4.4.1-2
ii  libgcr-4-4              4.4.1-2

-- no debconf information
]