refactor: purge CHandle from module internals (M14 R5)

Module-internal object references are Rust types now (values, Arc,
Mutex); CHandle remains only at the oakengine C-ABI boundary:

- oakundo: the global stack holds UndoStack/UndoCommand values
  directly (stack token is the static's address)
- oaktimeline: marker/workarea boxes carry Arc<Mutex<T>>; commands
  share the same allocation through Arc clones (readers in oakengine
  stubs and the app's graphops updated to lock)
- oaktask/oakstorage: sessions, write-through bindings and the
  database backend pass ProjectArc; the Session drops its manual
  release bookkeeping; nodeutil keeps the CHandle<->Arc boundary
  conversion (release_project restored for the app)
- oakcodec: handle.rs deleted outright (no facade entry needed it);
  texture/block placeholders are unit structs
- oakrender: copier's project handle is an identity u64; alive-count
  machinery removed; handle.rs is make_owned/get/get_mut only
- oakplugin: the instance registry is gone (its unregister key never
  matched, leaking weak entries); handle.rs is the RefBox boundary type
- oaknode/oakcommon: only dead guard/borrow helpers removed; external
  payload handles (texture/processor) documented as the boundary

Flake hunts landed along the way: the audio recording test serializes
on the shared manager lock with a normalized state; the autocacher
cancel test uses a slow producer so cancellation is deterministic.
This commit is contained in:
2026-08-17 16:40:15 +08:00
parent ede03d0bfe
commit b36cbd6b6f
53 changed files with 1260 additions and 2369 deletions
+6 -60
View File
@@ -19,6 +19,12 @@
//! than shared — each module DLL must run its own addref/release code (the
//! function pointers in a handle always point into the DLL that created the
//! object).
//!
//! M14 R5: only the parts the oakengine facade needs remain (owned
//! box/addref/release plus typed `get`/`get_mut` views — the facade boxes
//! its task payloads through [`make_owned`] and reads them back with
//! `get`/`get_mut`). The borrowed-handle and panic-guard helpers had no
//! in-crate callers and were removed.
use std::sync::atomic::AtomicU32;
@@ -65,23 +71,6 @@ unsafe extern "C" fn owned_release<T: 'static>(ctx: *mut std::ffi::c_void) {
}
}
/// Release function for borrowed handles: destroys only the box, never the
/// pointee.
///
/// CPP-PARITY: src/task/c_api/taskhandle.h (wrap_borrowed)
unsafe extern "C" fn borrowed_release<T: 'static>(ctx: *mut std::ffi::c_void) {
if ctx.is_null() {
return;
}
let b = ctx as *const RefBox<*mut T>;
let last = unsafe { (*b).refs.fetch_sub(1, std::sync::atomic::Ordering::SeqCst) };
if last == 1 {
unsafe {
drop(Box::from_raw(ctx as *mut RefBox<*mut T>));
}
}
}
/// Owned handle with count 1; empty on allocation failure.
pub fn make_owned<T: Send + 'static>(value: T) -> CHandle {
let b = Box::new(RefBox {
@@ -96,27 +85,6 @@ pub fn make_owned<T: Send + 'static>(value: T) -> CHandle {
}
}
/// Borrowed handle for an object owned elsewhere (release frees only the
/// box).
///
/// # Safety
/// Caller guarantees `ptr` outlives every derived handle.
pub unsafe fn make_borrowed<T: Send + 'static>(ptr: *mut T) -> CHandle {
if ptr.is_null() {
return CHandle::null();
}
let b = Box::new(RefBox {
refs: AtomicU32::new(1),
value: ptr,
});
CHandle {
ctx: Box::into_raw(b) as *mut std::ffi::c_void,
addref: Some(owned_addref::<*mut T>),
release: Some(borrowed_release::<T>),
abi_version: OAKTASK_ABI_VERSION,
}
}
/// Typed view into a handle; `None` for empty handles.
///
/// # Safety
@@ -139,25 +107,3 @@ pub unsafe fn get_mut<T: 'static>(h: &CHandle) -> Option<&mut T> {
}
unsafe { Some(&mut (*(h.ctx as *mut RefBox<T>)).value) }
}
/// Panic-catching FFI wrapper for i32-returning exports.
pub fn guard<F: FnOnce() -> crate::error::Result<()>>(f: F) -> i32 {
match std::panic::catch_unwind(std::panic::AssertUnwindSafe(f)) {
Ok(Ok(())) => crate::error::OAKTASK_OK,
Ok(Err(e)) => e.code(),
Err(_) => crate::error::OAKTASK_E_FAILED,
}
}
/// Panic-catching FFI wrapper for handle-returning exports.
pub fn guard_handle<F: FnOnce() -> crate::error::Result<CHandle>>(f: F) -> CHandle {
match std::panic::catch_unwind(std::panic::AssertUnwindSafe(f)) {
Ok(Ok(h)) => h,
Ok(Err(_)) | Err(_) => CHandle::null(),
}
}
/// Panic-catching FFI wrapper for void exports.
pub fn guard_void<F: FnOnce()>(f: F) {
let _ = std::panic::catch_unwind(std::panic::AssertUnwindSafe(f));
}
-9
View File
@@ -33,7 +33,6 @@
use std::sync::Mutex;
use crate::error::{Error, Result};
use crate::handle::{make_borrowed, CHandle};
use crate::task::Task;
/// Process-wide singleton manager. C++ is a lazy singleton; the Rust side
@@ -186,14 +185,6 @@ impl TaskManager {
self.tasks.len()
}
/// Borrowed handle to the task at `index`; `Err(Error::NotFound)` if out
/// of range.
pub fn get_task_at(&self, index: usize) -> Result<CHandle> {
let task = self.tasks.get(index).ok_or(Error::NotFound)?;
let ptr = task.task() as *const Task as usize as *mut Task;
Ok(unsafe { make_borrowed::<Task>(ptr) })
}
/// Raw pointer to the task at `index` (stable while the manager owns
/// it). Used by `oaktask_manager_at` to build a borrowed task handle.
pub fn task_ptr_at(&self, index: usize) -> Result<*mut Task> {