Tk Source Code

View Ticket
Login
Ticket UUID: 729f9c80924fb269b08fd9409bbf3a2d73f158a8
Title: send to a dead application returns "target application died" after 2 s instead of "no application named" (send-8.16)
Type: Bug Version: 8.6.18, 9.0.5, 9.1b1
Submitter: serhiy.storchaka Created on: 2026-09-26 08:56:08
Subsystem: 58. [send] Assigned To: jan.nijtmans
Priority: 5 Medium Severity: Minor
Status: Closed Last Modified: 2026-09-27 05:23:44
Resolution: Fixed Closed By: jan.nijtmans
    Closed on: 2026-09-26 23:08:10
Description:

Test send-8.16 fails:

==== send-8.16 Tk_SendCmd procedure, bogusCommWindow FAILED
---- Result was:
1 {target application died}
---- Result should have been (exact matching):
1 {no application named "bogus"}

It failed intermittently before 8.6.16 (1-8 of 10 runs) and fails always since 8.6.16, including the current core-8-6-branch, core-9-0-branch and main. send appends the command to the property of the target's comm window in AppendPropCarefully(). If the target window does not exist, the BadWindow error is handled by AppendErrorProc(), which sets the result "no application named ..." and marks the command as complete. There are two bugs:

  1. Race. If the error is read by Xlib during the XFlush() in TkUnixDoOneXEvent(), no event is queued and the socket is empty, so select() waits until the 2 second timeout and TkUnixDoOneXEvent() returns 0. The wait loop in Tk_SendCmd() does not check pending.gotResponse after a timeout: it calls ValidateName() and overwrites the result with "target application died" (leaking the previous result). If the error arrives a bit later, select() returns, and the test passes.
  2. Since [1602306bfc] (fix for [f52986c698]), Tk_DeleteErrorHandler() sets errorProc to NULL, so the callback of a deleted handler is never called. But the manual (CrtErrHdlr.3) says that it may still be called for errors from requests made before deletion. AppendPropCarefully() deletes the handler right after XChangeProperty(), so the late BadWindow error is now always ignored, and send always waits 2 seconds and returns "target application died".

The manual (CrtErrHdlr.3) still describes the old behavior of Tk_DeleteErrorHandler(), and other code (e.g. extensions, since this is a public API) can depend on it.

User Comments: serhiy.storchaka added on 2026-09-27 05:23:44:

Jan backported it to [dd98a8b50d|core-9-0-branch] (fixed a typo in [6410716225]). Backported to [4468e763f7|core-8-6-branch].


jan.nijtmans added on 2026-09-26 23:08:10:

So, I cannot find anything wrong with this fix (on the contrary!)

Merged to [2957ed0e|trunk] now. Backporting to 9.0 and 8.6 is OK to me (whoever does it)


jan.nijtmans added on 2026-09-26 22:51:58:

> so the fix for this ticket is not merged yet.

Indeed. Fixed the commit text now, pointing to the correct branches, not this one.


serhiy.storchaka added on 2026-09-26 19:05:36:

Right, tkUnixFont.c has no error handler with a callback.

Note that [db7cd2265c], which mentions send-late-x-errors, merged focus-test-xfocus, so the fix for this ticket is not merged yet.


jan.nijtmans added on 2026-09-26 18:41:41:

> How about tkUnixFont.c? Should the same change be done there too?

I guess the answer is NO, I don't see an errorFlag there.


jan.nijtmans added on 2026-09-26 18:38:00:

How about tkUnixFont.c? Should the same change be done there too?


serhiy.storchaka added on 2026-09-26 12:20:30:

Proposed fix in branch send-late-x-errors:

  • Tk_DeleteErrorHandler() again behaves as documented. The crash in [f52986c698] was caused by the font code (since [7f20966df9], workaround for [3767882e06]), which passed the address of a local variable to an error handler; an error reported after the function returned wrote into the stack frame of another function. Now the flag is in thread-specific data.
  • AppendPropCarefully() calls XSync() before deleting the error handler for synchronous sends, and the wait loop in Tk_SendCmd() no longer overwrites a response set while waiting.
  • failsOnCILinux and failsOnXQuartz are removed from send-8.16. failsOnCILinux is also removed from send-8.15: it passes on all versions and platforms I tried, so it was probably added by mistake.