Repository navigation
Native package test segfaults on all RIDs on current main #77
Description
Activity
The packaged Code OSS reproduction provided the missing symbolication and confirms the fault:
EXC_BAD_ACCESS / KERN_INVALID_ADDRESS 0x0- worker stack enters
v8_dom_runtime::dispatch_input - the faulting instruction dereferences the result of
v8::Isolate::GetCurrentContext() - the caller immediately queries
selectelements throughactive_select_popup()
Select-popup pointer dispatch was added before
v8::Context::Scope context_scope(local_context), so the first native pointer event queried the active realm while no V8 context was entered. This also explains why the regression begins at merge19e3c1e; the previous packaged run at173b870passes the native engine suite.Fix pushed to draft PR #76 at
1ede3086a40a1d5ad5bf433cddea56eac7de8a37: move popup dispatch inside the input-owner context and addwebscene_native_select_popup_contextas a focused packaged-runtime CTest. Fresh Windows/Linux/macOS package CI is now the qualification gate.Correction to the earlier force-pushed revision: the consolidated fix is now acc0b76. The first post-crash Linux package run also caught the unconditional stacking-hit rejection described in the updated issue body; the focused test now covers both context entry and popup-row hit testing.
The final diagnosis replaces the earlier stacking-helper hypothesis: the popup shadow subtree was never laid out because collapsed-select layout returned after suppressing authored options. Commit b4cc777 continues layout only for the private shadow popup and gives that active popup top-layer hit priority. Fresh packaged Windows/Linux/macOS CI is running.
Final consolidated validation is green at
41cf43cc34355f9511df94631f49baa87ff8818f.The hosted build matrix, NativeAOT/native contracts, packaged Linux x64/macOS arm64/Windows x64 runtime jobs, cross-RID evidence, release-package verification, and all three installed-package consumer jobs passed. The timing-dependent interop stress failure found during qualification was fixed and documented in #78 without reducing its 12,800-operation workload or bounded queue.
A fresh read-only run of the retained Code OSS DMG still opens the native AppScene window, starts the real bundled Node server, and then crashes in
v8_dom_runtime::dispatch_input. That package is intentionally still pinned to AppScene/WebScene preview.3, so it is baseline confirmation rather than validation of this branch. Acceptance remains rebuilding the SDK from this revision and passing the packaged editor create/type/render/undo smoke.
Problem
The required native runtime package gate crashed on every packaged RID after the collapsed single-select popup was added. A packaged Code OSS 1.137.0 host reproduced the same crash on its first pointer input.
Baseline run: https://github.com/SceneTech/WebScene/actions/runs/34683830568
19e3c1epassed.Confirmed root causes
The symbolicated Code OSS macOS crash is
EXC_BAD_ACCESS / KERN_INVALID_ADDRESS 0x0inv8_dom_runtime::dispatch_input. Select-popup pointer dispatch calledactive_select_popup(), which queried throughv8::Isolate::GetCurrentContext(), before the input owner'sv8::Context::Scopehad been entered.After fixing context entry, the focused package test exposed three semantic failures:
optionboxes and returned immediately, also skipping the private shadow popup.attributes["style"]directly. That changed serialized markup without updating WebScene's parsed inline declaration state, so fixed positioning, row minimum heights, padding, anddisplay:nonewere absent from layout and hit testing.The earlier media sampler warning was unrelated.
Fix
Draft PR #76, consolidated commit
41cf43cc34355f9511df94631f49baa87ff8818f:webscene_native_select_popup_context, covering open, pointer selection, close/hit-test removal, reopen/outside dismissal, keyboard commit, disabled options, and Escape.Acceptance status