G3.2+G3.3: classify hang/crash vs audio stall + SEH per-channel plugin crash isolation (mute channel)

This commit is contained in:
2026-08-16 10:23:08 +07:00
parent 30fa98a441
commit 0b8e80fe2c
6 changed files with 186 additions and 8 deletions
+19
View File
@@ -101,3 +101,22 @@ endif()
if(WIN32)
target_link_libraries(gui_probe PRIVATE ${FLUIDSYNTH_LIBRARY} ${SFIZZ_LIBRARY} winmm)
endif()
# G3.3: seh_channel_test — SEH per-channel crash isolation (debug tool, not shipped)
add_executable(seh_channel_test
tests/seh_channel_test.cpp
src/Vst3Instrument.cpp
)
if(VST3_SDK_TARGET)
target_compile_definitions(seh_channel_test PRIVATE HAVE_VST3SDK=1)
target_link_libraries(seh_channel_test PRIVATE ${VST3_SDK_TARGET} sdk_hosting sdk_common)
if(WIN32)
target_sources(seh_channel_test PRIVATE
${CMAKE_CURRENT_SOURCE_DIR}/vst3sdk/public.sdk/source/vst/hosting/module_win32.cpp
${CMAKE_CURRENT_SOURCE_DIR}/vst3sdk/public.sdk/source/common/memorystream.cpp
)
endif()
endif()
if(WIN32)
target_link_libraries(seh_channel_test PRIVATE ${FLUIDSYNTH_LIBRARY} ${SFIZZ_LIBRARY} winmm)
endif()
@@ -119,6 +119,13 @@ public:
// worker thread): real-time code drops MIDI for it. Channel-level flag —
// survives the instance swap (the per-instance flag dies with the object).
bool isReloading(uint32_t channel) const;
// G3.3: mark a channel whose plugin crashed inside processAudioBlock
// (SEH access violation). The channel is muted (real-time dispatch +
// renderAll skip it) until the next assign() — the plugin's state is
// undefined after a fault, so re-processing would fault again.
void markCrashed(uint32_t channel);
bool isCrashed(uint32_t channel) const;
// Editor-open predicate: while any VST editor is attached, channels whose
// plugin DLL path has an open editor count as quiet (same-plugin channels
// too -- the worker pumps the editor's window proc inside the DLL while the
@@ -146,6 +153,8 @@ private:
std::vector<float> scratchL_, scratchR_;
// Channel-level reload flag (see isReloading) — indexed by MIDI channel.
bool reloadingCh_[16] = {};
// G3.3: channel muted after a plugin fault inside processAudioBlock.
bool crashedCh_[16] = {};
// True when the channel's plugin DLL has an attached editor (or its reload
// is in progress): real-time code drops MIDI and skips rendering. Lowercased
// compare inside -- Windows plugin paths are case-insensitive.
+44 -6
View File
@@ -9,6 +9,8 @@
#define FS_SYNTH (static_cast<fluid_synth_t*>(synth))
#define FS_SETTINGS (static_cast<fluid_settings_t*>(settings))
#include <windows.h>
#include <algorithm>
#include <cctype>
#include <cstring>
@@ -206,8 +208,9 @@ bool InstrumentEngineManager::assign(uint32_t channel, InstrumentType type,
types_[channel] = type;
// Fresh instance is by construction not reloading — clear the channel
// flag so real-time MIDI dispatch (which drops reloading channels)
// flows to it again.
// flows to it again. G3.3: a reload also clears the crash-mute.
reloadingCh_[channel] = false;
crashedCh_[channel] = false;
}
if (oldInst) {
isBypassed_.store(true);
@@ -300,11 +303,23 @@ bool InstrumentEngineManager::isReloading(uint32_t channel) const {
return channel < 16 && reloadingCh_[channel];
}
// Quiet = reloading (mid-rebuild) only. G1.4: bo mute-when-editor-open —
// editor co the mo trong luc PLAY, audio loop van process() binh thuong.
void InstrumentEngineManager::markCrashed(uint32_t channel) {
std::lock_guard<std::mutex> lock(mu_);
if (channel < 16) crashedCh_[channel] = true;
}
bool InstrumentEngineManager::isCrashed(uint32_t channel) const {
std::lock_guard<std::mutex> lock(mu_);
return channel < 16 && crashedCh_[channel];
}
// Quiet = reloading (mid-rebuild) OR crashed (G3.3). G1.4: bo
// mute-when-editor-open — editor co the mo trong luc PLAY, audio loop van
// process() binh thuong. G3.3: channel crash -> mute vi trang thai plugin
// khong xac dinh sau fault; xu ly tiep se fault lai.
// Called with mu_ held by the real-time dispatch.
bool InstrumentEngineManager::channelQuiet(uint32_t ch) const {
if (ch >= 16 || reloadingCh_[ch]) return true;
if (ch >= 16 || reloadingCh_[ch] || crashedCh_[ch]) return true;
return false;
}
@@ -362,6 +377,20 @@ void InstrumentEngineManager::allNotesOff() {
}
}
// G3.3: SEH cannot live inside a function that needs C++ unwinding (C2712),
// so per-channel process() runs in this helper. A plugin access violation
// (0xC0000005) is caught here — the channel is muted instead of killing the
// whole bridge process. /EHa (set in CMakeLists) allows mixing with the
// outer C++ try/catch net in main.cpp.
static bool SafeProcessChannel(INativeInstrument* inst, float* outL, float* outR, uint32_t n) {
__try {
inst->processAudioBlock(outL, outR, n);
return true;
} __except (EXCEPTION_EXECUTE_HANDLER) {
return false;
}
}
void InstrumentEngineManager::renderAll(float* outputL, float* outputR, uint32_t numSamples) {
if (isBypassed_.load()) {
std::memset(outputL, 0, numSamples * sizeof(float));
@@ -377,10 +406,19 @@ void InstrumentEngineManager::renderAll(float* outputL, float* outputR, uint32_t
scratchR_.resize(numSamples);
}
for (auto& [ch, inst] : channels_) {
if (channelQuiet(ch)) continue; // editor open on this plugin DLL: do not process
if (channelQuiet(ch)) continue; // editor open / crashed: do not process
std::memset(scratchL_.data(), 0, numSamples * sizeof(float));
std::memset(scratchR_.data(), 0, numSamples * sizeof(float));
inst->processAudioBlock(scratchL_.data(), scratchR_.data(), numSamples);
if (!SafeProcessChannel(inst.get(), scratchL_.data(), scratchR_.data(), numSamples)) {
// G3.3: plugin fault — mute this channel only, keep the bridge up.
if (!crashedCh_[ch]) {
crashedCh_[ch] = true;
std::cerr << "[NativeBridge] G3.3: channel " << ch
<< " plugin crashed in processAudioBlock (SEH) — muted until reload"
<< std::endl;
}
continue;
}
for (uint32_t i = 0; i < numSamples; ++i) {
outputL[i] += scratchL_[i];
outputR[i] += scratchR_[i];
+80
View File
@@ -0,0 +1,80 @@
// native_bridge/tests/seh_channel_test.cpp
// G3.3: SEH per-channel crash isolation. A plugin whose processAudioBlock
// faults (access violation) must be caught by SafeProcessChannel -> renderAll
// mutes the channel instead of taking down the whole bridge process.
// Assert-based, no framework. Includes the engine .cpp (like shm_selfcheck).
#include "../include/NativeInstrumentEngine.h"
#include "../src/NativeInstrumentEngine.cpp"
#include <cassert>
#include <cstdio>
#include <cstring>
class CrashingStub : public INativeInstrument {
public:
bool init(double, uint32_t) override { return true; }
void selectProgram(uint32_t, uint32_t, uint32_t) override {}
void noteOn(uint32_t, uint32_t, float, uint32_t) override {}
void noteOff(uint32_t, uint32_t, uint32_t) override {}
void controlChange(uint32_t, uint32_t, uint32_t) override {}
void programChange(uint32_t, uint32_t) override {}
void pitchBend(uint32_t, uint32_t) override {}
bool openGUI(void*) override { return false; }
void closeGUI() override {}
void processAudioBlock(float*, float*, uint32_t) override {
volatile int* p = nullptr;
*p = 42; // deliberate access violation
}
};
class OkStub : public INativeInstrument {
public:
bool init(double, uint32_t) override { return true; }
void selectProgram(uint32_t, uint32_t, uint32_t) override {}
void noteOn(uint32_t, uint32_t, float, uint32_t) override {}
void noteOff(uint32_t, uint32_t, uint32_t) override {}
void controlChange(uint32_t, uint32_t, uint32_t) override {}
void programChange(uint32_t, uint32_t) override {}
void pitchBend(uint32_t, uint32_t) override {}
bool openGUI(void*) override { return false; }
void closeGUI() override {}
void processAudioBlock(float* outL, float* outR, uint32_t n) override {
for (uint32_t i = 0; i < n; ++i) { outL[i] = 1.0f; outR[i] = 2.0f; }
}
};
int main() {
// 1. Faulting plugin: SEH catches the AV, process survives, returns false.
{
float L[64] = {}, R[64] = {};
CrashingStub stub;
bool ok = SafeProcessChannel(&stub, L, R, 64);
assert(!ok);
// Block left untouched (renderAll continues without this channel).
bool allZero = true;
for (float f : L) if (f != 0.0f) allZero = false;
assert(allZero);
}
// 2. Healthy plugin passes through unchanged.
{
float L[64] = {}, R[64] = {};
OkStub stub;
bool ok = SafeProcessChannel(&stub, L, R, 64);
assert(ok);
assert(L[0] == 1.0f && R[0] == 2.0f);
}
// 3. Manager crash-mute flags: set, read, and renderAll skips a crashed
// channel (no exception escapes into the audio loop).
{
InstrumentEngineManager mgr;
assert(!mgr.isCrashed(3));
mgr.markCrashed(3);
assert(mgr.isCrashed(3));
assert(!mgr.isCrashed(4)); // other channels unaffected
float L[64] = {}, R[64] = {};
mgr.renderAll(L, R, 64); // crashed + unassigned: no-op, no crash
assert(L[0] == 0.0f);
}
std::printf("SEH_CHANNEL_TEST PASS\n");
return 0;
}