Skip to content

Android Emulator host SIGSEGV in gfxstream GL fence wait path (EmulatedEglFenceSync / tcmalloc) #191

Description

@XiaoTong6666

Environment

  • Emulator 37.1.11.0 (build 15917651)
  • Debian sid, KDE Wayland, Linux 7.2-amd64
  • Pixel_9a, x86_64, 6144 MB RAM
  • android-CinnamonBun/google_apis_ps16k/x86_64
  • GPU: auto

Launch command:

qemu-system-x86_64 @Pixel_9a -show-kernel -no-snapshot-load -writable-system

Crash

September 10, 2026, 17:47:15 UTC+8.

SIGSEGV / SEGV_MAPERR

tcmalloc::SLL_Next
tcmalloc::SLL_PopRange
tcmalloc::ThreadCache::FreeList::PopRange
tcmalloc::ThreadCache::ReleaseToCentralCache
tcmalloc::ThreadCache::ListTooLong
cfree
gfxstream::host::gl::EmulatedEglFenceSync::wait
...
gfxstream::host::SyncThread::doSyncThreadCmd

There also appears to be a fence lifetime race in the current source. FrameBuffer queues a raw fence pointer. The worker's registry lookup doesn't retain a reference, while wait() calls incRef() only afterward. A concurrent destroy could release the last reference between those two operations.

Not sure if this caused the crash. No reliable reproducer yet.

I have the original Apport report and core dump (~2 GB), available for further debugging. I haven't uploaded the raw dump publicly because it contains process memory.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions