Skip to content

fix: reject export previews after shared GPU device loss - #2400

Merged
richiemcilroy merged 4 commits into
mainfrom
fix/export-preview-gpu-loss
Oct 7, 2026
Merged

richiemcilroy merged 4 commits into
mainfrom
fix/export-preview-gpu-loss

Conversation

@richiemcilroy

@richiemcilroy richiemcilroy commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

After the shared graphics device is lost, fast export previews keep creating renderer layers on that same device. Each retry can panic again because both the shared cache and the editor retain the failed resource generation.

Track loss when the shared device is created and reject previews before decoding and again before renderer allocation. After the existing bounded retries, show the restart-Cap error and clear the stale preview/estimate. Keep the original loss diagnostics, normal GPU validation, and existing panic boundary. Devices, textures, and pipelines stay together; this does not attempt automatic recovery.

Verification on macOS arm64 with Rust 1.88.0:

  • Four CPU-only wgpu Noop regression tests pass inside the desktop crate: repeated unguarded panics, guarded loss through cloned handles with retained resources, independent-device health, and preserved shader validation.
  • A separate probe using the existing YUV pipeline constructor reproduced nine caught failures after synthetic destruction; the guard returned nine errors without panicking.
  • Desktop source check, strict desktop Clippy across all targets, TypeScript check, scoped Biome, Rust formatting, and three existing export-estimate tests pass.
  • Local Rust checks use a compile-only Tauri configuration omitting unbuilt bundled executables and packaging framework metadata. They do not verify packaging.
  • Adds the Noop regression tests to the existing macOS, Windows, and Linux desktop CI matrix.

The original device-loss cause is unknown. Synthetic destruction is not a Windows driver fault, hardware rendering test, or complete preview IPC test. Loss during rendering can still reach the existing panic boundary. Fallback devices created after shared initialization failure are outside this guard. Windows hardware loss, the complete preview IPC flow, and packaged-app behavior remain unverified.

CI on the current head, after merging main, passes on Windows x64, macOS arm64 and Linux x64: Clippy, Build Desktop (including the four GPU-loss regression tests and the GPUI suite), Typecheck, formatting, lint, CodeQL and Socket. Rust cache and the Tauri plugin-version check are skipped by their existing conditions. The earlier Windows Clippy dead-code warning and the GPUI every_embedded_icon_is_referenced failure were baseline issues that main has since fixed.

Not yet verified by hand: a real GPU device loss in the native application.

RetriggerConfidence Score: 5/5

The PR appears safe to merge; this re-review found no new actionable issue.

Summary

The PR tracks loss of the shared GPU device, rejects export previews before decoding and renderer allocation, clears stale preview state after retries, and adds regression tests to desktop CI.

Reviews (3) · Last reviewed commit: "ci: run the device-loss test after the G..."

@richiemcilroy

Copy link
Copy Markdown
Member Author

hey @greptileai, please re-review the PR

@richiemcilroy
richiemcilroy marked this pull request as ready for review October 5, 2026 14:16
@richiemcilroy

Copy link
Copy Markdown
Member Author

hey @greptileai, please re-review the PR

@richiemcilroy
richiemcilroy merged commit 367af08 into main Oct 7, 2026
28 checks passed

This branch was successfully deployed

1 active deployment
Preview — c96708a4 Deployed Oct 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant