Skip to content

Native package test segfaults on all RIDs on current main #77

Description

@wieslawsoltes

Problem

The required native runtime package gate crashed on every packaged RID after the collapsed single-select popup was added. A packaged Code OSS 1.137.0 host reproduced the same crash on its first pointer input.

Baseline run: https://github.com/SceneTech/WebScene/actions/runs/34683830568

  • Windows x64: native engine test crashed after 2.19 seconds.
  • Linux x64: native engine test crashed after 12.85 seconds.
  • macOS arm64: native engine test crashed after 4.02 seconds.
  • The previous package revision before select-popup merge 19e3c1e passed.

Confirmed root causes

The symbolicated Code OSS macOS crash is EXC_BAD_ACCESS / KERN_INVALID_ADDRESS 0x0 in v8_dom_runtime::dispatch_input. Select-popup pointer dispatch called active_select_popup(), which queried through v8::Isolate::GetCurrentContext(), before the input owner's v8::Context::Scope had been entered.

After fixing context entry, the focused package test exposed three semantic failures:

  1. Collapsed-select layout deliberately suppressed authored option boxes and returned immediately, also skipping the private shadow popup.
  2. The popup is a native top-layer control but relied on ordinary document stacking, allowing overlapping authored content to take its pointer.
  3. Internal popup code assigned attributes["style"] directly. That changed serialized markup without updating WebScene's parsed inline declaration state, so fixed positioning, row minimum heights, padding, and display:none were absent from layout and hit testing.

The earlier media sampler warning was unrelated.

Fix

Draft PR #76, consolidated commit 41cf43cc34355f9511df94631f49baa87ff8818f:

  1. Enters the input owner's V8 context before select-popup lookup or dispatch.
  2. Keeps authored collapsed-select options suppressed while laying out the private shadow popup.
  3. Resolves the active native popup subtree before the ordinary document hit.
  4. Routes private popup styles through the native CSS parse/store/apply path.
  5. Adds webscene_native_select_popup_context, covering open, pointer selection, close/hit-test removal, reopen/outside dismissal, keyboard commit, disabled options, and Escape.
  6. Waits for synthetic clicks to be consumed so asynchronous input cannot race the assertion.

Acceptance status

  • Focused popup CTest: passed on packaged Windows x64, Linux x64, and macOS arm64.
  • Full native engine suite: passed without a crash on all three RIDs.
  • Required 150-document/514-subtest web-platform subset: passed.
  • Complete hosted CI, cross-RID evidence, release package verification, and all RID consumer installs: passed.
  • Remaining integration acceptance: rebuild the AppScene SDK with this revision and pass the packaged Code OSS editor create/type/render/undo smoke.

Activity

  1. wieslawsoltes commented on Sep 15, 2026

    @wieslawsoltes
    CollaboratorAuthor

    The packaged Code OSS reproduction provided the missing symbolication and confirms the fault:

    • EXC_BAD_ACCESS / KERN_INVALID_ADDRESS 0x0
    • worker stack enters v8_dom_runtime::dispatch_input
    • the faulting instruction dereferences the result of v8::Isolate::GetCurrentContext()
    • the caller immediately queries select elements through active_select_popup()

    Select-popup pointer dispatch was added before v8::Context::Scope context_scope(local_context), so the first native pointer event queried the active realm while no V8 context was entered. This also explains why the regression begins at merge 19e3c1e; the previous packaged run at 173b870 passes the native engine suite.

    Fix pushed to draft PR #76 at 1ede3086a40a1d5ad5bf433cddea56eac7de8a37: move popup dispatch inside the input-owner context and add webscene_native_select_popup_context as a focused packaged-runtime CTest. Fresh Windows/Linux/macOS package CI is now the qualification gate.

  2. wieslawsoltes commented on Sep 15, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Correction to the earlier force-pushed revision: the consolidated fix is now acc0b76. The first post-crash Linux package run also caught the unconditional stacking-hit rejection described in the updated issue body; the focused test now covers both context entry and popup-row hit testing.

  3. wieslawsoltes commented on Sep 15, 2026

    @wieslawsoltes
    CollaboratorAuthor

    The final diagnosis replaces the earlier stacking-helper hypothesis: the popup shadow subtree was never laid out because collapsed-select layout returned after suppressing authored options. Commit b4cc777 continues layout only for the private shadow popup and gives that active popup top-layer hit priority. Fresh packaged Windows/Linux/macOS CI is running.

  4. wieslawsoltes commented on Sep 15, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Final consolidated validation is green at 41cf43cc34355f9511df94631f49baa87ff8818f.

    The hosted build matrix, NativeAOT/native contracts, packaged Linux x64/macOS arm64/Windows x64 runtime jobs, cross-RID evidence, release-package verification, and all three installed-package consumer jobs passed. The timing-dependent interop stress failure found during qualification was fixed and documented in #78 without reducing its 12,800-operation workload or bounded queue.

    A fresh read-only run of the retained Code OSS DMG still opens the native AppScene window, starts the real bundled Node server, and then crashes in v8_dom_runtime::dispatch_input. That package is intentionally still pinned to AppScene/WebScene preview.3, so it is baseline confirmation rather than validation of this branch. Acceptance remains rebuilding the SDK from this revision and passing the packaged editor create/type/render/undo smoke.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions