Repository navigation
Windows: hard exit after shutdown, a hung renderer ends only its tile, pipe_probe serves its own pages - #58
Merged
Conversation
…, pipe_probe serves its own pages cef_host: - A shutdown request (kOpShutdown, the pipe closing, a crash-loop host exit) arms a watchdog that ends the process 6 s later if the message loop hasn't quit, and 30 s after it has (a stuck CefShutdown), with the macOS log line. Its thread starts with the process, since starting one takes the loader lock a wedged thread may hold. - The liveness ping is answered by the renderer's main thread (a process message), not the page; a page can't answer under the ping's id. Plugin: - A renderer that leaves the liveness ping unanswered ends only its tile (processGone crashed), not the host, as on macOS. - A replaced GPU process isn't watched: unlike macOS, Windows tiles keep painting after Chromium relaunches it (checked in CI). Tests: - pipe_probe serves its pages on 127.0.0.1, prints each host's output, and checks that a host whose UI thread is suspended at kOpShutdown exits on its own about 6 s later with the watchdog's line. - The smoke test hangs one tile's renderer on a shared host (only it goes, and a page that breaks evals beside it stays) and replaces a host's GPU process with chrome://gpucrash (its tiles keep painting). - policy_test covers the watchdog's wait. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
wenkaifan0720
force-pushed
the
fix/windows-parity-gaps
branch
from
September 24, 2026 14:12
5e6521d to
67b1958
Compare
wenkaifan0720
marked this pull request as ready for review
September 24, 2026 14:12
Collaborator
Author
|
windows-build on 67b1958 (run 36011088679): 6 of 6 attempts green (the first run plus 5 reruns).
That is 12 of 12 pipe_probe runs, 12 of 12 hung-renderer cases (the tile beside it that breaks evals was never taken for hung), 12 of 12 GPU-replacement cases, and 36 of 36 crash-loop rounds. On every run, the plugin log's only liveness line was the one for the hung tile: 🤖 Generated with Claude Code |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes the three Windows parity gaps left after #57.
1. Hard exit after shutdown (as macOS
ArmHardExit/ExtendHardExitForTeardown)A shutdown request (
kOpShutdown, the pipe closing, the crash-loop host exit) arms a watchdog incef_hostthat ends the process if it is still running 6 s later, or 30 s after its message loop has quit (a stuckCefShutdown). It logs[cef_host] still running after shutdown (<why>); exiting nowto stderr and exits with code 0, the same as macOS.Two Windows-specific choices:
TerminateProcess, notexit().exit()runs DLL detach code, which can block on a lock the wedged thread holds.The timings and the wait loop (it re-reads the deadline after every sleep, so the teardown extension is kept) are in
cef_host_policy.h, covered bypolicy_test.cc.2. A hung renderer ends only its tile (as macOS since #49)
ReportBrowserGone(session, "crashed"), the same path askOpCreateFailedandkOpBrowserGone. That one session getsprocessGone('crashed')and is disposed; the host and its other tiles carry on. Before, the plugin killed the host.window.cefQueryorJSONisn't taken for hung, and a page's owneval:reply under the ping's id is refused.chrome://gpucrashthe tiles keep presenting at about 60 fps, and new tiles on the host paint. So Windows doesn't watch for it, and the smoke test now checks that the tiles survive. Nothing else escalates a hang to the host, same as macOS. When the hung tile is the host's last, disposing it shuts the host down, as any dispose does.3. pipe_probe serves its own pages
pipe_proberuns a small HTTP server on 127.0.0.1 for its two pages, instead of example.com and iana.org. A slow CI network once held the host inCefShutdownfor over 20 s. It now also:kOpShutdown. That host has to exit on its own about 6 s later, with code 0 and the watchdog's line. On CI it exits 6.03 s afterkOpShutdown.Smoke test
The smoke test gains two cases, and each runs in both compositing modes:
processGone('crashed'), about 32 s after the hang.chrome://gpucrashreplaces the host's GPU process (checked by pid).processGone.The README ("What works" notes), PROTOCOL.md, both CHANGELOGs (under a new "## Unreleased") and the plugin comments are updated. I haven't merged it. The windows-build pass count is in a comment below.
🤖 Generated with Claude Code