Conversation
This was referenced Sep 30, 2026
… patch [skip ci] Reproduce the subscriber churn SIGSEGV using separate processes and compare pinned gz-transport 15.1.0 builds with identical flags. Serialize nonblocking socket polling and wait on OS notification descriptors outside the node mutex. Preserve every failure and first core; verify the loaded library and real deliveries. This commit does not install the candidate into release Dockerfiles or claim final-image acceptance. Explicit manual diagnostics do not enable publication.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Current status — both validation tags published; registry re-pull passed
PR #5 remains OPEN and unmerged; auto-merge is disabled.
mainis stille05a9fb7. General main/release publication stays disabled (POSIM_PUBLISH_IMAGES=false); nolatest, main or release tag was written. The already-testedabad9d70images were published without rebuilding.validation-pr5-abad9d70-arm64-rdpvalidation-pr5-abad9d70-amd64Repository: ioeslab/posim. Both installed inventories passed. Independent audits of actual observations and raw child-process logs found no startup/shutdown failure in these post-publication checks. These 14+1 trials per architecture are additional to, not replacements for, the earlier native 77+5 acceptance trials.
Immutable published references:
ioeslab/posim@sha256:72179187c96a801184a15ab9cdaf3ca9714d3717ce04e97cd2ec60f34d83edb8.ioeslab/posim@sha256:9783525a2a18ecc2e275e9af43e82ccab6202bb99b63790ffd165d8885fa9784.Publication history is retained: ARM64's first upload timed out. The second upload completed, but the original post-push checker incorrectly compared Docker containerd's index ID with a configuration digest. Tooling commit
584953b5distinguishes these identities and passed 12 guard tests. The final ARM64 run verified the exact index/platform/config chain, reused the identical published tag without overwriting it, pulled it anonymously and completed the fresh-container checks. No application code or acceptance thresholds changed, and no failed runtime trial was discarded. AMD64's successful attempt-1 evidence is retained separately from that workflow's historical ARM64 failures.docker pullmay reuse cached layers; this is digest-verified public retrieval followed by fresh-container execution, not a cold-download claim. GUI/RDP, joystick, CUDA/WGPU sonar and all-world coverage remain outside the scope. Earlier non-publication statements below describe their historical checkpoints.Historical initial status: publication blocked — debugging runtime shutdown
POSIM_PUBLISH_IMAGES=false. This PR is not merged and no image from it has been published. A green diagnostic workflow means evidence was collected, not release acceptance.Native image evidence
c3a4498dbaselinec3a4498dbaselinea74aa354a74aa354bd5ec83cbd5ec83cOriginal artifacts and all failed trials are retained. The earlier baseline summaries (13/14 and 10/14) missed child aborts hidden by a successful wrapper exit; they are not acceptance results.
Native runs: ARM64 bd5, AMD64 bd5, incomplete, ARM64 a74, AMD64 a74.
Implemented build/runtime fixes
Historical candidate:
6253abad— ARM64 passed; AMD64 release was blockedGDB run captured MAVROS SIGSEGV in a DDS event thread while the main thread unloaded RMW libraries at exit. Router I/O and DDS threads were still alive. Code and a native-image reproducer identified the Router → endpoint → Router strong-reference cycle.
Controlled before/after diagnostic: the empty Router control released; ROS-only and ROS+UDP endpoints leaked before the local weak-parent patch. All three released after the patch. BlueROV and BlueROV Heavy then each passed five execution/payload/connection/shutdown trials (10/10) in the disposable patched container. This is diagnostic evidence, not final-image acceptance. The patch is now integrated into the Docker builds with its checksum and ownership probe.
Fresh-container Gazebo backtrace showed shutdown joining a background Fuel download. Jetty had already advertised the world and advanced its clock before creating the scene entities. The four launch entries now default to Jetty's
--wait-for-assets(explicitwait_for_assets:=falseopts back into asynchronous startup). The bimanual check requires the realgrabbapoleentity and spherical-coordinate service output. This mitigates ready-scene shutdown racing cold downloads; it does not fix interruption during a download or guarantee network availability.Earlier clock-only world observations did not establish asset readiness. The new checks are stricter, so old and new pass counts should not be treated as identical acceptance criteria.
Final raw-log audit of the native candidate:
rexrov_waves-r3crashed on shutdown in Gazebo Transport'sRunReceptionTask/zmq_poll/ libzmq. The parent exit of zero and wrapper SIGINT do not override the logged segmentation fault. The later controlled transport investigation is documented below.38ada73cadds transparent version probing, bounded library-specific symbol retrieval, a preflight version comparison, fail-fast handling for startup failure, and three wrapper regression tests. Corrected diagnostic completed 20/20 instrumented trials with normal inferior exit, but did not reproduce SIGSEGV. It used one diagnostic container and does not override the fresh-container production failure; native evidence remains 77/77 and 76/77. Redundant image builds triggered by diagnostic pushes were cancelled.Post-diagnostic symbolization of the original failure used the exact captured ZeroMQ library (build ID
ac4eff7609d3a2693528173b6ad0df03a09bdb09, Ubuntuzeromq3 4.3.5-1build3) and matching Ubuntu DDEB symbols. The frame chain iszmq_poll -> socket_base_t::getsockopt -> xsub_t::xhas_in -> xsub_t::match; the top address maps to inlinedtrie_t::check,trie.cpp:219. Load bias was inferred from the unique page-aligned mapping compatible with thezmq_pollsymbol range; this is not a newly captured full GDB stack. At that stage, concurrent subscription-trie access was a code-inspection hypothesis; the controlled follow-up below now reproduces it. The original final-image failure remains valid evidence. The publication opt-in is still disabled.Image IDs: ARM64
sha256:b3452540588705bd021cf6dd89c80a7fd6f8557da249ea20226f1db0724e9011; AMD64sha256:528f01785189660ae7c011980bed2fc2d1ac3732401de186dc6c718406cbc369. Native source head is6253abad; PR merge-test checkout and image revision label are1727fa79c1356f01135edf945370f04fe857b865.Local classifier/readiness, diagnostic-wrapper, churn and linkage unit tests: 22/22. Full GitHub lint for the new candidate passed. All historical failures and diagnostic artifacts remain available; nothing has been relabeled as a pass.
Transport poll-race follow-up (2026-09-30)
A two-process payload probe repeatedly removes the last subscriber on active topics. Both variants use the same pinned gz-transport 15.1.0 source, compiler settings and probe; only the poll-serialization patch differs. The driver records real anchor/churn deliveries, child exit codes, timeouts and the loaded library hash. No failed trial is retried or discarded.
trie_t::check -> xsub_t::match -> xsub_t::xhas_in -> socket_base_t::getsockopt -> zmq_poll -> RunReceptionTask, the same function chain implicated in the original AMD64 failure.174bab1e: unpatched 5/5 SIGSEGV, patched 5/5 passed. Every passing patched trial delivered actual messages and terminated normally. These are diagnostic probe trials, not Gazebo Quickstart trials.The patch serializes zero-timeout socket polling with subscription updates, while blocking only on OS notification descriptors outside the mutex. It rechecks socket events on each loop for ZeroMQ's edge-triggered
ZMQ_FDsemantics. Candidate Docker builds use a pinned separate ROS vendor overlay, not replacement files in/opt/ros. The overlay preserves the installed public build configuration, including Zenoh disabled, and records source/patch/library hashes. Image inventory checks the actual Gazebo/probe linkage and repeats five payload-churn trials using only the installed setup chain.The ROS-vendor-configured local ARM64 overlay also passed its five build-probe trials and five installed-inventory probe trials. Its public configuration matched the installed ROS vendor byte-for-byte, and both Gazebo and the probe resolved the patched library. These are additional local checks, not native final-image acceptance.
Historical final-image audit of
0fbb707b: camera startup blocked acceptanceFresh ARM64 and AMD64 image builds completed. Downloaded artifacts were independently checked against all launch commands, result records, actual observations and raw child-process logs.
sha256:2ad24f7e264b2bdfdefd62a2cbbf4d7dfacbab0c0ab46c68f0352a0ae9731584.sha256:b058652ea2ac64e4e36ce5a5466670ad3f02e181587956d638a195fbbda7431f.camera-r5: the world control service appeared, but the camera entity, advancing simulation and ROS image payload were not observed within their original budgets./world/camera_world/createremained unavailable until shutdown began. Parent exit zero and normal shutdown do not override this startup failure. The original acceptance record does not contain a server stack; the separate same-image diagnostic below captured the cold-start wait.55d11e37ce0a8ee041e58e8943ba9df013ab49f1, whose parents are maine05a9fb7and candidate0fbb707b. This is GitHub's test checkout, not a PR merge; main has not been changed.Diagnostic-only commit
c60bef43adds a fresh-container camera readiness probe. It preserves the original startup budget and captures server stacks after a readiness failure, with verbose startup logs and Fuel cache inventory. Native AMD64 diagnostic completed and stopped on the first fresh-container readiness failure. At the unchanged entity-readiness deadline, GDB captured the server waiting onFuelClient::DownloadModel -> Rest::Request -> libcurl/pollwhile loading an SDF material. The server main thread was waiting for construction to finish. Verbose logs show a nested Sunken Vase resource download before scene initialization resumed about 155 seconds after launch. Real camera images arrived later, and shutdown was normal. This establishes an external Fuel-download wait in the reproduced failure, not a transport shutdown crash. It does not identify the remote server/network cause or prove the uninstrumented acceptance failure had an identical stack.The diagnostic preserved the failed readiness verdict despite the later image payload. No acceptance timeout was raised, no failed run was replaced, and no application-level cold-asset fix has yet been applied. A deterministic asset-preparation/cache solution must be validated on rebuilt images before publication. These instrumented observations cannot replace the failed acceptance trial.
PR #5 remains open/unmerged.
POSIM_PUBLISH_IMAGES=false; no candidate image was published. All earlier failures and the new camera failure are retained.Validated build-time Fuel assets candidate
abad9d70(2026-09-30)The reproduced camera wait involves Sunken Vase Distorted's version-3 Sunken Vase material dependency, in addition to the version-4 top-level model. The candidate now prepares the Fuel dependency closure used by the 14 Quickstarts during image build: 12 version-pinned model assets, all 105 prepared files hashed, nested SDF HTTP references checked, and original author/license metadata retained. No geometry, texture or simulation parameter is edited. Native installations are unchanged.
The image exports a shared Fuel cache and its locked provenance under
/opt/posim_fuel. Inventory verifies the installed lock against the validation source and checks the files without downloading. CI retains the original 77 connected trials and adds five separate fresh-container camera trials with--network none, requiring actual ROS image payloads and normal shutdown. Startup budgets are unchanged; offline runs do not replace connected failures.Local preflight: 33 Python unit tests passed; the production downloader fetched the critical version-3 dependency into isolated staging and verified the full lock; an older local ARM64 development image with the prepared cache produced a 320×240 BGR image and terminated normally with networking disabled. This is development evidence, not acceptance of the new native images. Both native image matrices have now completed and their downloaded artifacts passed an independent raw-observation/child-log audit:
All offline records retain Docker's
NetworkMode=none, an exited container with code zero, actual camera payload dimensions/byte count/hash, advancing simulation, entity readiness, and raw shutdown logs. No child crash was logged in either connected matrix or the additional offline trials. Both inventories verified all 105 cached files against lock SHA-2569776a35839f1797769f7ba3a80dfe046366493889838d8e78cd40c16c9ab31fa. These results apply to the declared test scope, not every feature/world or zero failure probability.sha256:72179187c96a801184a15ab9cdaf3ca9714d3717ce04e97cd2ec60f34d83edb8.sha256:72d00bb8e32725bd8e4fe91b8f21de770d4e4f4753f93d596bce4cc97d018cc5.32eedbacf781a0fd1e517481571e76bfaab73c51, GitHub's synthetic test checkout with parents maine05a9fb7and candidateabad9d70. This is not an actual PR merge.No PR merge or Docker Hub publication was performed. PR #5 is OPEN with auto-merge disabled; main remains
e05a9fb7d25ec21399f897e9bddfcabc4493b703, andPOSIM_PUBLISH_IMAGES=false. Publication and a registry re-pull/Quickstart check remain pending.Acceptance and scope
The full native test is installed inventory + 14 distinct headless paths + 63 additional repetitions (77 runtime trials). It requires actual payloads, advancing simulation, model readiness, MAVROS connected state for both BlueROVs, and clean child-process shutdown. A parent launch exit of zero never overrides a child crash. PRs never publish; main/version-tag publication also requires the opt-in variable and success on the exact image ID being pushed.
GUI/RDP, joystick, CUDA/WGPU sonar execution, physical fidelity, and all 18 world files are outside this matrix. Do not infer zero failure probability from any finite passing sample.