Skip to content

WindowClone: always pass create_child_func to bind_model - #2935

Closed
lenemter wants to merge 1 commit into
mainfrom
lenemter/try-fix-crash
Closed

lenemter wants to merge 1 commit into
mainfrom
lenemter/try-fix-crash

Conversation

@lenemter

Copy link
Copy Markdown
Member

Fixes #2934

I assume due to some race condition mutter tries to call null as a function even after we call bind_model (null, ...). I reproduced the crash and ClutterActor *child = priv->create_child_func (item, priv->create_child_data);
is where the crash occurs and this branch fixed the crash for me.

static void
clutter_actor_child_model__items_changed (GListModel *model,
                                          guint       position,
                                          guint       removed,
                                          guint       added,
                                          gpointer    user_data)
{
  ClutterActor *parent = user_data;
  ClutterActorPrivate *priv = parent->priv;
  guint i;

  while (removed--)
    {
      ClutterActor *child = clutter_actor_get_child_at_index (parent, position);
      clutter_actor_destroy (child);
    }

  for (i = 0; i < added; i++)
    {
      GObject *item = g_list_model_get_item (model, position + i);
      ClutterActor *child = priv->create_child_func (item, priv->create_child_data);

      /* The actor returned by the function can have a floating reference,
       * if the implementation is in pure C, or have a full reference, usually
       * the case for language bindings. To avoid leaking references, we
       * try to assume ownership of the instance, and release the reference
       * at the end unconditionally, leaving the only reference to the actor
       * itself.
       */
      if (g_object_is_floating (child))
        g_object_ref_sink (child);

      clutter_actor_insert_child_at_index (parent, child, position + i);

      g_object_unref (child);
      g_object_unref (item);
    }
}

@lenemter
lenemter requested a review from a team September 22, 2026 13:39
@utf-4096

Copy link
Copy Markdown

This doesn’t seem to resolve the crash for me, same backtrace. I added some warning ()s around bind_model and I don't see any logs in journalctl, so I’m not sure this code path is being reached.

@lenemter lenemter closed this Oct 3, 2026
@lenemter
lenemter deleted the lenemter/try-fix-crash branch October 3, 2026 14:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Receiving a dialog/popup in an inactive workspace causes a crash

2 participants