Repository navigation
feat: minidump scope - #1340
Open
timfish wants to merge 3 commits into
Open
feat: minidump scope#1340timfish wants to merge 3 commits into
timfish wants to merge 3 commits into
Conversation
…t hub Behind the thread-registry feature. Each thread registers a slot on first use of its hub, SwitchGuard keeps the slot pointing at the hub current on that thread, and the slot is removed when the thread exits. Hub::for_os_thread looks a hub up by the id current_os_thread_id returns, which is the id a crash handler sees for the crashing thread.
Nothing is sent to the crash reporter until the crash. The on_crash hook in minidumper-child names the crashing OS thread; a parked helper thread serializes the scope of the hub current on that thread (inline on macOS, where other threads are suspended) and the handler sends it before the dump request. The reporter merges it with the fatal event. This replaces the manual set_user/set_tag/set_extra/add_breadcrumb mirror, which cost one message per scope write. Depends on the on_crash hook from the feat/on-crash-hook branch of minidumper-child via a crates-io patch until it is released.
|
👋 Thanks for sending this our way! Before a maintainer reviews the code, we ask community contributors to align with us on the approach first — it keeps your time pointed at changes we can land. The easiest way is to open or find a GitHub issue and discuss the approach with a maintainer there, then link that issue from this PR. If the issue is already assigned to someone else, please check in with them (or with us) before continuing — otherwise two people may end up working on the same task. See our contributing guidelines for the full picture. |
timfish
marked this pull request as ready for review
October 5, 2026 08:27
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The minidump crash event now carries the scope of the thread that crashed, including hubs bound with
Hub::run, so a server with one hub per request reports the request that crashed.Nothing is sent to the crash reporter until the crash. The new
on_crashhook inminidumper-childnames the crashing OS thread, a parked helper thread serializes that thread's scope withScope::apply_to_event, and the handler sends it before the dump request. The reporter merges it with the fatal event. This replaces the manualset_user/set_tag/set_extra/add_breadcrumb, which cost one message per scope write.sentry-coregains athread-registryfeature:Hub::for_os_threadandcurrent_os_thread_idmap OS thread ids to the hub current on each thread, kept up to date bySwitchGuard. Zero cost with the feature off.Linux and Windows: signal safety
The handler runs on the crashing thread (signal handler / exception handler), which may hold the allocator, registry or scope lock. So the handler only does signal-safe work: it sets atomics,
unparks the helper (futex / keyed event, no allocation), polls an atomicdoneflag with 1 ms sleeps, then reads the result withtry_lock(which cannot block, because the helper unlocks before it setsdone) and writes it to the socket.Everything else runs on the
sentry-minidump-scopehelper thread: registry lookup, scope clone, event processors, JSON. It starts at init, because spawning a thread in the handler would allocate. If the crashed thread holds a lock the helper needs, the helper blocks, the handler's wait hitsscope_timeout(default 2s) and the minidump event goes out without scope. The worst case is a missing scope, never a missing minidump.macOS: inline, no helper
crash-handleruses a Mach exception port on macOS. The callback runs on a dedicated handler thread, not the crashing thread, andSIGABRTtakes the same path. It is not signal context, so the scope work runs inline. A helper would not work, because the handler suspends every other thread before it calls the callback, and that includes the helper.scope_timeouthas no effect here.Limit: if a suspended thread or the crashed thread held the allocator, registry or scope lock, the inline work blocks on it with no timeout and no dump is requested. I have not seen this in testing.
Details
gettid/tidon Linux,GetCurrentThreadId/thread_idon Windows, and the Mach port name (pthread_mach_thread_np/thread) on macOS. Threads that never used Sentry fall back to the main hub.Eventin 16 KiB chunks plus an end message, because the reporter reads one message per call. Bad or missing JSON gives an empty event. Attachments on the scope are not carried.Tested on Linux and macOS so far. I wont be back with my Windows machine for a week!