Skip to content

screenshot: forward GetDeviceQueue2 to driver instead of GetDeviceQueue - #42

Merged
olehkuznetsov merged 1 commit into
android-graphics:mainfrom
jimblacklercorp:fix-screenshot-getdevicequeue2
Oct 8, 2026
Merged

olehkuznetsov merged 1 commit into
android-graphics:mainfrom
jimblacklercorp:fix-screenshot-getdevicequeue2

Conversation

@jimblacklercorp

Copy link
Copy Markdown

screenshot::GetDeviceQueue2 previously stripped VkDeviceQueueInfo2::flags and pNext by forwarding to screenshot::GetDeviceQueue. When an application or ANGLE creates queues with non-zero flags (such as VK_DEVICE_QUEUE_CREATE_PROTECTED_BIT), vkGetDeviceQueue fails to match the queue in the ICD and writes VK_NULL_HANDLE into *pQueue, causing a null-pointer dereference in Android's libvulkan.so (vulkan::driver::GetDeviceQueue) and polluting the layer's queue set with VK_NULL_HANDLE.

Forward GetDeviceQueue2 directly to pDisp->GetDeviceQueue2 and guard queue registration against VK_NULL_HANDLE in both GetDeviceQueue and GetDeviceQueue2.

BUG=571072981

screenshot::GetDeviceQueue2 previously stripped VkDeviceQueueInfo2::flags and pNext by forwarding to screenshot::GetDeviceQueue. When an application or ANGLE creates queues with non-zero flags (such as VK_DEVICE_QUEUE_CREATE_PROTECTED_BIT), vkGetDeviceQueue fails to match the queue in the ICD and writes VK_NULL_HANDLE into *pQueue, causing a null-pointer dereference in Android's libvulkan.so (vulkan::driver::GetDeviceQueue) and polluting the layer's queue set with VK_NULL_HANDLE.

Forward GetDeviceQueue2 directly to pDisp->GetDeviceQueue2 and guard queue registration against VK_NULL_HANDLE in both GetDeviceQueue and GetDeviceQueue2.

BUG=571072981
@jimblacklercorp
jimblacklercorp requested review from m--koma and olehkuznetsov and removed request for m--koma October 7, 2026 15:48
@olehkuznetsov
olehkuznetsov merged commit 3891315 into android-graphics:main Oct 8, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants