Android Emulator host SIGSEGV in gfxstream GL fence wait path (EmulatedEglFenceSync / tcmalloc)
Maintainers usually reply within 2 days
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 48/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- cpp
- Domain
- computer-graphics
Research direction
Start with host/frame_buffer.cpp, host/sync_thread.cpp, host/gl/emulated_egl_fence_sync.cpp, and host/render_control.cpp to trace fence ownership from queueing through wait and destruction. Use the reported stack trace and, if available, the Apport report or core dump to determine whether the lifetime race explains the SIGSEGV. Done means the cause is established and the fence lifetime behavior is corrected and validated.
Written by the indexing model from the issue text.
Description
Environment
- Emulator 37.1.11.0 (build 15917651)
- Debian sid, KDE Wayland, Linux 7.2-amd64
Pixel_9a, x86_64, 6144 MB RAMandroid-CinnamonBun/google_apis_ps16k/x86_64- GPU:
auto
Launch command:
qemu-system-x86_64 @Pixel_9a -show-kernel -no-snapshot-load -writable-system
Crash
September 10, 2026, 17:47:15 UTC+8.
SIGSEGV / SEGV_MAPERR
tcmalloc::SLL_Next
tcmalloc::SLL_PopRange
tcmalloc::ThreadCache::FreeList::PopRange
tcmalloc::ThreadCache::ReleaseToCentralCache
tcmalloc::ThreadCache::ListTooLong
cfree
gfxstream::host::gl::EmulatedEglFenceSync::wait
...
gfxstream::host::SyncThread::doSyncThreadCmd
There also appears to be a fence lifetime race in the current source. FrameBuffer queues a raw fence pointer. The worker's registry lookup doesn't retain a reference, while wait() calls incRef() only afterward. A concurrent destroy could release the last reference between those two operations.
Not sure if this caused the crash. No reliable reproducer yet.
I have the original Apport report and core dump (~2 GB), available for further debugging. I haven't uploaded the raw dump publicly because it contains process memory.
- Dominant language
- C++
- Stars
- 57
- Forks
- 38
- Avg merge
- 3d 6h
- Merged PRs (30d)
- 6
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from google/gfxstream
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
google/gfxstream#192 · 1 comment ·
Maintainers usually reply within 2 days
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
Maintainers usually reply within 2 days
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
google/gfxstream#183 · 5 comments ·
Maintainers usually reply within 2 days
-
request to periodically make versioned tagged releasesMay be free again @gurchetansingh claimed this 58 days ago, and no pull request is open. Open
google/gfxstream#166 · 1 comment · 1 assignee ·
Maintainers usually reply within 2 days
-
duplicate
Difficulty 4/5 3-5 days Newbie friendliness 35/100
google/gfxstream#106 · 3 comments ·
Maintainers usually reply within 2 days
All issues in google/gfxstream
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
cp-algorithms/cp-algorithms#1715 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Icinga/icinga2#11058 · 1 comment ·
Maintainers usually reply within 1 day
-
status:needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
PX4/PX4-Autopilot#28924 ·
Maintainers usually reply within 1 day
-
component: split-view platform: windows
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
zen-browser/desktop#15616 · 1 reaction ·
Maintainers usually reply within 1 day