Public bug reported: [ Impact ]
Qt 6.10 apps crash with SIGSEGV in FcCharSetHasChar() when a fontconfig fallback pattern has no charset. QFontEngineMultiFontConfig::shouldLoadFontEngineForCharacter() ignores the result of FcPatternGetCharSet() and passes the uninitialized FcCharSet pointer to FcCharSetHasChar() (0xfefefefefefefefe in this build, which fills uninitialized locals with 0xFE). Charset-less patterns come from fontconfig caches written by a fontconfig built with the fontations backend: Google Chrome 154 bundles one and links its cache for the system fontconfig (https://gitlab.freedesktop.org/fontconfig/fontconfig/-/work_items/565), and the Kubuntu 26.04.1 image shipped such a cache for fonts-katex. These placeholders then win fc-match for any family, and plasmashell, krunner, konsole, systemsettings and other Qt apps crash on their first glyph fallback. See bug 2168311 (Plasma does not start) and bug 2168420. Qt fixed this upstream in qtbase commit 80ddc8dee6a05cd619085e29fc21ff92c4b877a8 "Fix crash when fontconfig fallback pattern has no charset" (merged 2026-08-12). It has "Pick-to: 6.12 6.11 6.8", which leaves out 6.10, so 26.04 LTS (6.10.2+dfsg-7) keeps the crash. The patch changes 5 lines in src/gui/text/unix/qfontenginemultifontconfig.cpp: - FcCharSet *charSet; - FcPatternGetCharSet(matchPattern, FC_CHARSET, 0, &charSet); - charSetHasChar = FcCharSetHasChar(charSet, ucs4); + FcCharSet *charSet = nullptr; + if (FcPatternGetCharSet(matchPattern, FC_CHARSET, 0, &charSet) == FcResultMatch + && charSet != nullptr) { + charSetHasChar = FcCharSetHasChar(charSet, ucs4); + } [ Test Plan ] 1. Make a charset-less pattern win matching: install fonts-katex (default on Kubuntu) and start Google Chrome 154 once, or copy its ~/.cache/fontconfig/<md5>-le64.cache-12 files as <md5>-le64.cache-9. 2. Check that `fc-match monospace` returns a KaTeX .woff file. 3. Run the PyQt6 reproducer from fontconfig#565 with QT_QPA_PLATFORM=offscreen (a QTextLayout with CJK and emoji text), or print U+FFFD in Konsole. Without the fix: SIGSEGV in FcCharSetHasChar(). With the fix: the text is laid out, no crash. [ Where problems could occur ] Only the fontconfig charset check in QFontEngineMultiFontConfig changes. When a fallback pattern has no charset, Qt now keeps its existing optimistic default (load the font engine), as it already does when there is no match pattern, and the font engine decides glyph coverage. A regression would show up as a different fallback font being loaded for some characters. [ Other Info ] Backtrace (plasmashell 15:46 and konsole 19:53 on 2026-09-24, same stack): #0 ?? () libfontconfig.so.1 +0xc4fc #1 FcCharSetHasChar () libfontconfig.so.1 #2 QFontEngineMultiFontConfig::shouldLoadFontEngineForCharacter(int, unsigned int) const #3 QFontEngineMulti::stringToCMap(...) #4 QTextEngine::shapeText(int) const From the konsole core: charset pointer 0xfefefefefefefefe, ucs4 U+FFFD, and the cached fallback pattern held only family="DejaVu Sans Mono" (copied from the request), file=/usr/share/fonts/truetype/katex/KaTeX_AMS-Regular.woff and fontwrapper=WOFF. Versions: libqt6gui6 6.10.2+dfsg-7, fontconfig 2.17.1-3ubuntu1, plasma- workspace 4:6.6.6-0ubuntu0.1, konsole 4:25.12.3-0ubuntu1. (Found with the help of an AI assistant, Claude; the cores, backtraces and tests are from my machine.) ** Affects: qt6-base (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2168504 Title: Qt apps crash in FcCharSetHasChar() on glyph fallback when the fallback pattern has no charset; please backport qtbase 80ddc8dee6a0 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/qt6-base/+bug/2168504/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
