Repository navigation
Automatic crash processing: initialise the Cycles cache path once, safely - #7
Open
andylebihan wants to merge 1 commit into
Open
andylebihan wants to merge 1 commit into
andylebihan wants to merge 1 commit into
Conversation
path_cache_get lazily assigned a file-static string and then read it, with no synchronisation. The Metal shader cache runs two compile threads that both reach it, so one thread could be copying the string while the other replaced it, and the copy was left holding a freed buffer. Freeing that buffer again in path_join aborted the process. A function-local static is initialised once, under the guarantee the language already provides, and is then never written again. Fixes RH-84838 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes RH-84838 — 57 reports, all macOS, Rhino 8.12 through 8.19, all on a Metal shader-compile thread.
What happens
path_cache_getlazily fills in a file-static string and then reads it:Nothing synchronises that.
ShaderCachestartsmax_mtlcompiler_threads(2) compile threads, both runMetalKernelPipeline::compile(), and both reachpath_cache_getthrough theuse_binary_archiveblock inkernel.mm. So two threads can find the string empty at the same time and both assign it —string::operator=frees the existing buffer and installs a new one — while the other is reading it intopath_join.path_jointakes the global by const reference and copies from it. If the buffer it is reading was freed and replaced by the other thread, the copy is left pointing at freed memory, and theappendthat follows reallocates and frees that stale pointer. That is the reported stack, exactly:RhCore::operator deletein that stack is a red herring — on macOS opennurbs' globaloperator deleteis a plainfree. The abort is the allocator refusing a pointer it did not hand out, which is what a freed-and-replaced string buffer looks like.This also explains why it could not be reproduced by hand: it needs two kernels to compile at once with the cache path still unset, which is a narrow window on the first raytrace of a session.
The fix
A function-local
static const string, initialised once. Thread-safe initialisation of function-local statics is guaranteed by the language, and the string is never written again afterwards, so concurrent readers are safe.Notes
path_getandpath_user_gethave the same lazy-assignment shape oncached_path/cached_user_path. They are left alone:path_init()normally sets both at startup before any worker thread exists, so their lazy branch is a fallback rather than the common path. Worth tidying, but not on this change.🤖 Generated with Claude Code