fix(assets): guard Material/Texture event callbacks against teardown/…#170
Merged
star-e merged 1 commit intoJul 6, 2026
Merged
Conversation
…GC crash Material::PassesUpdated and the SimpleTexture/TextureBase update events can be emitted from update()/copy()/doDestroy() while the script engine is being cleaned up or a GC is running. In those windows findFirst() may still return an se::Object whose V8 persistent points at a freed object, so calling into it crashes in ObjectWrap::handle() (Local<Object>::New on a dangling handle). Resolve the live JS wrapper from the native emitter at emit time instead of capturing s.thisObject(), and bail out when the engine is invalid, in cleanup, or garbage collecting.
bofeng-song
force-pushed
the
fix/material-event-callback-teardown-crash
branch
from
June 26, 2026 07:59
58d3772 to
2b3b94a
Compare
Code Size Check Report
Interface Check ReportThis pull request does not change any public interfaces ! |
Contributor
|
@cocos-robot run-test-cases-custom |
Contributor
|
@cocos-robot run test cases |
Contributor
|
@cocos-robot run test cases |
Contributor
|
@cocos-robot run test cases |
1 similar comment
Contributor
|
@cocos-robot run test cases |
|
@bofeng-song, Please check the result of
Task Details
|
|
@bofeng-song, Please check the result of
Task Details |
|
@bofeng-song ❗ There was an error during the execution of the tasks. Please check the logs for more details. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
GC crash
Material::PassesUpdated and the SimpleTexture/TextureBase update events can be emitted from update()/copy()/doDestroy() while the script engine is being cleaned up or a GC is running. In those windows findFirst() may still return an se::Object whose V8 persistent points at a freed object, so calling into it crashes in ObjectWrap::handle() (Local::New on a dangling handle).
Resolve the live JS wrapper from the native emitter at emit time instead of capturing s.thisObject(), and bail out when the engine is invalid, in cleanup, or garbage collecting.
Re: #
https://forum.cocos.org/t/topic/172523/23
Changelog
Continuous Integration
This pull request:
Compatibility Check
This pull request:
Reproduce
Attach rt-passes-repro.ts to any node in the scene and run it to reproduce the crash.
rt-passes-repro.zip