fix: crash calling OSR shared texture release() after texture GC'd#50473
Merged
MarshallOfSound merged 1 commit intomainfrom Mar 25, 2026
Merged
Conversation
The weak persistent tracking the OffscreenReleaseHolderMonitor was tied to the texture object, but the release() closure holds a raw pointer to the monitor via its v8::External data. If JS retained texture.release while dropping the texture itself, the monitor would be freed on GC and a later release() call would crash. Track the release function instead of the texture object. Since the texture holds release as a property, this keeps the monitor alive as long as either is reachable.
codebytere
approved these changes
Mar 25, 2026
Member
|
In JS, |
VerteDinde
approved these changes
Mar 25, 2026
|
Release Notes Persisted
|
Contributor
|
I have automatically backported this PR to "39-x-y", please check out #50499 |
This was referenced Mar 25, 2026
Contributor
|
I have automatically backported this PR to "40-x-y", please check out #50500 |
Contributor
|
I have automatically backported this PR to "41-x-y", please check out #50501 |
Contributor
|
I have automatically backported this PR to "42-x-y", please check out #50502 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The weak persistent tracking the
OffscreenReleaseHolderMonitorwas tied to the texture object, but therelease()closure holds a raw pointer to the monitor via itsv8::Externaldata. If JS retainedtexture.releasewhile dropping the texture itself, the monitor would be freed on GC and a laterrelease()call would crash the main process.Track the release function instead of the texture object. Since the texture holds
releaseas a property, this keeps the monitor alive as long as either is reachable, while preserving the existingOSRSharedTextureNotReleasedwarning behavior.Added a regression test that captures
texture.release, forces GC on the texture, then invokes the stale closure.Notes: Fixed a crash when calling an offscreen shared texture's
release()after the texture object was garbage collected.