ckerr

#54520: fix: detach interned string cache before isolate disposal

Merged
Created: Sep 28, 2026, 12:38:11 PM
Merged: Sep 28, 2026, 2:52:47 PM
3 comments
Target: main

Summary

The interned-string cache clears its strings in OnBeforeDispose() but retains its isolate pointer until OnDisposed(), after IsolateHolder has already freed the isolate.

Detach the cache in OnBeforeDispose() instead, clearing its cached strings and isolate references while the isolate and PerIsolateData are still alive. This avoids a dangling raw_ptr during isolate teardown while preserving per-isolate caching behavior.

Add a subprocess regression that populates the cache through nativeImage.getSize() and checks that the application exits cleanly.

With raw_ptr checks enabled, the focused test reported the following diagnostic (unrelated stack frames omitted):

[DanglingPtr](1/3) A raw_ptr/raw_ref is dangling.

[DanglingPtr](2/3) First, the memory was freed at:

Stack trace:
...
#2 0x5f596f73d86b base::allocator::(anonymous namespace)::DanglingRawPtrDetected() [../../base/allocator/partition_alloc_support.cc:468:11]
#3 0x5f596f814387 partition_alloc::PartitionRoot::FreeInUnknownRoot<>() [../../base/allocator/partition_allocator/src/partition_alloc/in_slot_metadata.h:443:5]
#4 0x5f5972aeb5dd gin::IsolateHolder::~IsolateHolder() [../../gin/isolate_holder.cc:156:13]
#5 0x5f596793150d electron::JavascriptEnvironment::~JavascriptEnvironment() [../../third_party/libc++/src/include/__memory/unique_ptr.h:74:5]
#6 0x5f5967902a21 electron::ElectronBrowserMainParts::PostMainMessageLoopRun() [../../third_party/libc++/src/include/__memory/unique_ptr.h:74:5]
...

[DanglingPtr](3/3) Later, the dangling raw_ptr was released at:

Stack trace:
...
#2 0x5f596f73d95d base::allocator::(anonymous namespace)::DanglingRawPtrReleased<>() [../../base/allocator/partition_alloc_support.cc:630:21]
#3 0x5f596f7867c2 base::internal::RawPtrBackupRefImpl<>::ReleaseInternal() [../../base/allocator/partition_allocator/src/partition_alloc/in_slot_metadata.h:240:7]
#4 0x5f5967a2115e gin_helper::(anonymous namespace)::InternedStringCache::Detach() [../../base/allocator/partition_allocator/src/partition_alloc/pointers/raw_ptr_backup_ref_impl.h:194:7]
#5 0x5f5972aed98d gin::PerIsolateData::NotifyDisposed() [../../gin/per_isolate_data.cc:109:14]
#6 0x5f5972aeb5e6 gin::IsolateHolder::~IsolateHolder() [../../gin/isolate_holder.cc:157:18]
...

Validation

  • Confirmed the dangling-pointer error before applying the fix, then rebuilt Electron and confirmed the same focused test passed without that error after the fix, with raw_ptr checks enabled in both runs: does not crash on exit after getting its size in spec/api-native-image.spec.ts.
  • Both nativeImage.createEmpty() tests passed without raw_ptr diagnostics, including the subprocess shutdown regression.
  • git diff --check passed.
  • Targeted C++/JavaScript lint and formatting checks passed for the changed files.
  • Independent code review reported no findings.

Raw_ptr checks were enabled only for local validation; this PR does not change the raw_ptr build flags.

Notes: Fixed a potential crash during application shutdown.

Backports

45-x-y
Merged
PR Number
#54526
Merged At
Sep 28, 2026, 5:23:01 PM
Released In
Not yet
Release Date
Not yet

Semver Impact

Major
Breaking changes
Minor
New features
Patch
Bug fixes
None
Docs, tests, etc.

Semantic Versioning helps users understand the impact of updates:

  • Major (X.y.z): Breaking changes that may require code modifications
  • Minor (x.Y.z): New features that maintain backward compatibility
  • Patch (x.y.Z): Bug fixes that don't change the API
  • None: Changes that don't affect using facing parts of Electron