Public bug reported:

Over the course of about a week, I've experienced repeated segmentation
faults with the *identical* crash signature, affecting five different,
unrelated processes:

- `plasmashell` — SIGSEGV, Thu Sep 24 16:57
- `kscreenlocker_greet` — SIGSEGV, crash loop (4 crashes within under 1 
second), triggered by Meta+L screen lock
- `konsole` — SIGSEGV, Thu Sep 24 18:43
- `gwenview` — SIGSEGV, Fri Sep 25 12:19
- `plasma-discover` — SIGSEGV, Fri Sep 25 13:39 (stacktrace top not fully 
captured, but same time window and signal)

All confirmed crashes share the exact same top-of-stack:
```
?? () from /lib/x86_64-linux-gnu/libfontconfig.so.1
FcCharSetHasChar () from /lib/x86_64-linux-gnu/libfontconfig.so.1
?? () from /lib/x86_64-linux-gnu/libQt5XcbQpa.so.5
QFontEngineMulti::stringToCMap(QChar const*, int, QGlyphLayout*, int*, 
QFlags<QFontEngine::ShaperFlag>) const () from 
/lib/x86_64-linux-gnu/libQt5Gui.so.5
QTextEngine::shapeText(int) const () from /lib/x86_64-linux-gnu/libQt5Gui.so.5
```

Confirmed via `dmesg` kernel traps and a full gdb backtrace for the first 
plasmashell incident:
```
Thread 1 "plasmashell" received signal SIGSEGV, Segmentation fault.
0x000077868c11dd51 in ?? () from /lib/x86_64-linux-gnu/libfontconfig.so.1
#0  0x000077868c11dd51 in ?? () from /lib/x86_64-linux-gnu/libfontconfig.so.1
#1  0x000077868c11e4f7 in FcCharSetHasChar () from 
/lib/x86_64-linux-gnu/libfontconfig.so.1
#2  0x000077868836b900 in ?? () from /lib/x86_64-linux-gnu/libQt5XcbQpa.so.5
#3  0x000077868da2a3c3 in QFontEngineMulti::stringToCMap(...) from 
/lib/x86_64-linux-gnu/libQt5Gui.so.5
#4  0x000077868da4d895 in QTextEngine::shapeText(int) const () from 
/lib/x86_64-linux-gnu/libQt5Gui.so.5
#5  0x000077868da6152f in QTextLine::layout_helper(int) () from 
/lib/x86_64-linux-gnu/libQt5Gui.so.5
#6  ... QQuickText/QQuickLabel layout path ...
```

**Steps to reproduce:**
Not reliably reproducible on demand. Appears timing/race-dependent, and has 
occurred across five different applications, all Qt-based, all during text 
shaping/layout.

**Workaround (temporary):**
```bash
rm -rf ~/.cache/fontconfig
fc-cache -f -v
```
This resolved each individual incident, but the crash recurred days later in a 
different process, suggesting the underlying cache/race condition is not 
permanently fixed by a one-time cache rebuild.

**Mitigation currently in place:**
Added `~/.config/plasma-workspace/env/00-fontconfig-cache.sh` running `fc-cache 
-f` before Plasma session startup, to reduce the race window. Too early to 
confirm long-term effectiveness.

**Suspected root cause:**
Given the recurrence across unrelated processes and the fact that `fc-validate` 
reports no invalid font files, this looks consistent with a read/write race 
condition in fontconfig's mmap'd cache — one process reading the cache while 
another regenerates it, corrupting the in-memory `FcCharSet` structure later 
dereferenced by `FcCharSetHasChar`.

**System information:**
- Distribution: Kubuntu 24.04 LTS (noble)
- fontconfig: 2.15.0-1.1ubuntu2
- libfontconfig1: 2.15.0-1.1ubuntu2
- plasma-workspace: 4:5.27.12-0ubuntu0.1
- Kernel: 7.0.0-34-generic
- No unusual manually-installed fonts; standard Kubuntu font set

** Affects: fontconfig (Ubuntu)
     Importance: Undecided
         Status: New

** Attachment added: "plasmashell-backtrace.txt"
   
https://bugs.launchpad.net/bugs/2168590/+attachment/6002711/+files/plasmashell-backtrace.txt

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168590

Title:
  Recurring SIGSEGV in FcCharSetHasChar (libfontconfig.so.1.12.1)
  crashing multiple unrelated processes (plasmashell,
  kscreenlocker_greet, konsole, gwenview)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/fontconfig/+bug/2168590/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to