findings(E-10..E-22): fix the defects a code review found in the E-1..E-9 work

A review of the group-E fixes found 13 further defects; ten were introduced by
those fixes, two pre-existed and were merely relocated, one is deferred.

Services / transport
  E-10  retireWorker synthesized no bg/exit frame, so sharedspice's s_bgRunning
        mirror stayed latched true after a mid-run worker death: Run stayed
        disabled and the promised fresh-worker restart was unreachable for the
        whole session. Retirement now dispatches a synthetic controlled-exit
        straight to the installed handler (never through dispatchEvt — a
        fabricated frame must not touch the credit ledger). Driving the repro
        exposed two further defects, both fixed here: a replacement worker
        trapped on pre-init engine reads, and the rerun's cm_input_path/circ hit
        that uninitialized engine before KiCad's validate() re-init (the native
        flow assumes a crashed engine survives in-process — true for the dll,
        false for a dead worker). Reads now answer their empty shapes pre-init,
        writes lazy-init, and init is idempotent per worker engine.
  E-19  dispatchEvt acked only AFTER handler(evt) returned, and the sharedspice
        client deliberately rethrows non-trap errors — so each throw leaked one
        unit of the 64-frame credit window until the stream died with a
        misattributed "transport exceeded". The ack moves to a finally in both
        service copies; the throw still propagates (the trap machinery needs it).
  E-20  the oversize-line path promises to transfer the accepted prefix, but
        with the window full that flush only DEFERS, and stopEventStream wiped
        the deferred queue — losing the diagnostics that explain the failure.
        The terminal notice now carries them as pendingEvents; both hosts
        deliver them in order, unacked (the fatal frame is outside the credit
        protocol).
  E-21  the 30s prefetch deadline discarded every model already collected and
        reported nothing. A caller-owned progress sink ships the partials and
        the omission reaches the export report. (Awaiting the aborted collection
        was rejected: an in-flight source fetch is not abortable — E-4's
        original disease.) Plus a serving-candidate memo, so a .wrl ref served
        by its .step fallback stops re-probing the miss on every export.

Scheduler
  E-14  _terminalizeNativeTrap classified by message substring, so any plain JS
        error QUOTING 'Aborted(' or 'out of bounds' permanently bricked a
        healthy instance. Now structural only: instanceof RuntimeError plus a
        duck-typed name check (verified in this build's glue that abort() throws
        a genuine RuntimeError both pre- and post-runtime-init). Module.onAbort
        now latches the gate — the authoritative notification, previously
        ignored.
  E-15  the shim half: _pumpResume gates on terminal (catching wakes already
        queued at latch time) and resolveWait refuses on terminal WITHOUT
        consuming the entry, so a frame stays visibly parked rather than
        resuming inside a trapped module.
  E-16  the E-5 handler read the realm-global scheduler at dispatch instead of
        its installing module's; also frees the per-line buffer on the non-trap
        rethrow path.
  E-11  get_vec trusted the worker's res.length over the transferred arrays.
        Observed death shape: a 4 GiB std::vector threw an unhandled
        std::length_error that exited the editor's main loop. Now clamped, with
        the buffers freed on every failure path.

Guardrails (replacing two deferred refactors: e2e→production-code injection and
collapsing the four copies of the worker-lifecycle machinery)
  E-18  the source contract asserted comment-string counts — rewording failed
        CI while moving a guard outside its #ifdef passed. It now parses the
        #ifdef regions and asserts on code.
        service-stub-parity.ts pins what the four lifecycle copies must share:
        credit-window equality parsed from source, the finally-ack, boot
        deadlines, terminal-notice consumption. The transport numbers are now
        single-sourced from the worker.
        CI actually runs the gates: the web/standalone vitest suites (which had
        NEVER run in CI), the reducer, the source contract and the parity tool —
        with a NON_PLAYWRIGHT_GATES check so deleting a step re-fails the lint.
  E-22  the e2e occ stub's 60s boot watchdog, deleted in a66e109, is restored in
        the ngspice-stub shape with a wedgeNextBoot() repro hook.

Every behavioral fix has red-then-green evidence (the reds were captured first).
E-17 (a stale RUNNING cross-stamping the next run's generation under E-6's
transport deferral) is DEFERRED with its analysis recorded — a real fix needs
run identity on the bg frames.

Test hygiene: the dwell lint now requires the mandated ": <why>" and all 47 bare
markers carry their reason; three export-report dwells became modal-lease polls;
exact-ledger assertions became relative deltas; the dead data-wx-dom-id branch,
an unused fault hook and unused receipt plumbing are gone; abort scans, wx
dialog drivers, the sim harness and the vitest FakeWorker are each one copy now.

Bumps kicad and wxwidgets to their findings-group-e tips.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Istvan Matejcsok 2026-08-27 12:27:12 +02:00
commit c421d724b0
48 changed files with 2071 additions and 694 deletions

View file

@ -120,14 +120,26 @@ EM_JS( void, js_ngspice_get_vec_start,
return 0;
HEAP32[( aMeta >> 2 ) + 1] = res.vtype | 0;
HEAP32[( aMeta >> 2 ) + 2] = res.flags | 0;
HEAP32[( aMeta >> 2 ) + 3] = res.length | 0;
if( res.real && res.real.length ) {
const p = _malloc( res.real.length * 8 );
// E-11: v_length must describe what was actually TRANSFERRED,
// never the worker's self-reported count — a corrupted worker
// answering a huge length with small arrays otherwise drives the
// native consumer through a multi-gigabyte copy (observed dying
// as an unhandled std::length_error that exits the main loop).
// Interleaved re,im doubles: 2 per complex element.
let length = Math.max( 0, res.length | 0 );
const nReal = ( res.real && res.real.length ) | 0;
const nComp = ( res.comp && res.comp.length ) | 0;
if( nReal ) length = Math.min( length, nReal );
if( nComp ) length = Math.min( length, nComp >> 1 );
if( !nReal && !nComp ) length = 0;
HEAP32[( aMeta >> 2 ) + 3] = length;
if( nReal ) {
const p = _malloc( nReal * 8 );
HEAPF64.set( res.real, p >> 3 );
HEAPU32[aReal >> 2] = p;
}
if( res.comp && res.comp.length ) {
const p = _malloc( res.comp.length * 8 );
if( nComp ) {
const p = _malloc( nComp * 8 );
HEAPF64.set( res.comp, p >> 3 );
HEAPU32[aComp >> 2] = p;
}
@ -159,13 +171,19 @@ extern "C" int wxWasmYieldUntil( int aToken );
// handler, and a superseded handler disarms itself.
EM_JS( void, js_ngspice_install_events, (), {
const installingModule = Module;
// E-16: capture the installing module's SCHEDULER too — the liveness gate
// and trap latch below must describe the exact instance this handler
// drives, not whatever scheduler the realm holds at dispatch time (under
// same-realm module replacement the realm-global would belong to the
// successor).
const installingScheduler = globalThis.__wxScheduler;
const installed = globalThis.__ngspiceOnEvent;
if( installed && installed.__pcbjamNgspiceOwnerModule === installingModule )
return;
const handler = ( evt ) => {
if( globalThis.__ngspiceOnEvent !== handler )
return; // superseded install — never drive a retired module
const sched = globalThis.__wxScheduler;
const sched = installingScheduler;
if( !sched || !sched.canTouchNative || !sched.canTouchNative() ) {
// E-8/M-2: a dead or terminal instance takes no native entry; the
// drop is loud, never silent.
@ -173,6 +191,11 @@ EM_JS( void, js_ngspice_install_events, (), {
+ 'dead/terminal module' );
return;
}
// E-16: a plain-JS throw between the malloc and the native entry
// leaks the line buffer — track it so the non-trap rethrow path can
// free it (never free on the trap path: freeing re-enters a trapped
// module).
let pendingText = 0;
const call = ( kind, text, a, b ) => {
let p = 0;
if( text != null ) {
@ -185,7 +208,9 @@ EM_JS( void, js_ngspice_install_events, (), {
p = _malloc( n );
stringToUTF8( text, p, n );
}
pendingText = p;
installingModule._pcbjam_ngspice_event( kind, p, a | 0, b | 0 );
pendingText = 0; // the native entry freed it
};
try {
if( evt.kind === 'char' || evt.kind === 'stat' ) {
@ -201,8 +226,11 @@ EM_JS( void, js_ngspice_install_events, (), {
// A trap on this fresh entry poisons the instance: latch the
// terminal gate so no later completion re-enters it.
if( !sched._terminalizeNativeTrap
|| !sched._terminalizeNativeTrap( 'ngspice event entry', e ) )
|| !sched._terminalizeNativeTrap( 'ngspice event entry', e ) ) {
if( pendingText )
_free( pendingText );
throw e;
}
}
};
handler.__pcbjamNgspiceOwnerModule = installingModule;
@ -428,6 +456,33 @@ extern "C" EMSCRIPTEN_KEEPALIVE void pcbjam_ngspice_reset_callbacks( void* aUser
s_user = nullptr;
}
// E-7: the browser harness's final-refresh receipt — called by
// SIMULATOR_FRAME::onSimFinished after every final native refresh (one
// ifdef'd line there; the JS-side knowledge lives HERE, in the stub layer).
// Optional test evidence, no mainline behavior.
// clang-format off
EM_JS( void, js_ngspice_sim_run_applied, ( uint32_t aGeneration ), {
const hook = globalThis.__pcbjamNgspiceFinalRefreshApplied;
if( typeof hook === 'function' )
{
try
{
hook( aGeneration >>> 0 );
}
catch( error )
{
console.error( '[ngspice] final-refresh hook failed', error );
}
}
} );
// clang-format on
extern "C" EMSCRIPTEN_KEEPALIVE void pcbjam_sim_run_applied( uint32_t aGeneration )
{
js_ngspice_sim_run_applied( aGeneration );
}
// -------------------------------------------------------------------------
// The sharedspice API surface NGSPICE::init_dll binds to
// -------------------------------------------------------------------------
@ -506,11 +561,17 @@ pvector_info pcbjam_ngGet_Vec_Info( char* aVecName )
js_ngspice_get_vec_start( token, aVecName ? aVecName : "", meta, &real, &comp, &vname );
if( wxWasmYieldUntil( token ) != 0 )
return nullptr;
if( !meta[0] )
// E-11: a plain-JS throw mid-prepare (after some mallocs landed) resolves
// the inertResult without adopting the buffers into the arena — free
// whatever was written on EVERY failure path (free(nullptr) is a no-op,
// so this covers all partial orderings).
if( wxWasmYieldUntil( token ) != 0 || !meta[0] )
{
std::free( vname );
std::free( real );
std::free( comp );
return nullptr;
}
s_name = vname;
s_real = real;