Give each fragment density map its own memory block

On the Steam Frame the game crashed in Turnip while Dawn recorded an eye
render pass, reading an unmapped address. Turnip reads a density map through
a host mapping of its memory taken at bind time, and the maps were
sub-allocated from blocks that Dawn's buffer upload fast path maps and
unmaps. A dedicated allocation is never mapped or unmapped by Dawn.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019HBRGKTE1GnN2ah8gcZKr3
This commit is contained in:
Claude committed 2026-10-04 15:15:08 +00:00
1 parent 6e526fa6b9
commit 2a72421926
1 file changed
+6 -2
+6 -2
View File
@@ -93,8 +93,12 @@ MaybeError AuroraFdmUpload(Device* device, uint32_t width, uint32_t height, cons
VkMemoryRequirements requirements;
device->fn.GetImageMemoryRequirements(device->GetVkDevice(), map.image, &requirements);
DAWN_TRY_ASSIGN(map.memory,
device->GetResourceMemoryAllocator()->Allocate(requirements, MemoryKind::DeviceLocal));
// A memory block of its own. Turnip reads a map through a host mapping of its memory, taken
// when the image is bound, and Dawn's buffer uploads map and unmap the shared blocks they
// sub-allocate from (Buffer::MapMemoryAndPerformOperation). An unmap there pulled the mapping
// from under a map sharing the block, and the next render pass read freed memory.
DAWN_TRY_ASSIGN(map.memory, device->GetResourceMemoryAllocator()->Allocate(
requirements, MemoryKind::DeviceLocal, /*forceDisableSubAllocation=*/true));
DAWN_TRY(CheckVkSuccess(device->fn.BindImageMemory(device->GetVkDevice(), map.image,
ToBackend(map.memory.GetResourceHeap())->GetMemory(),
map.memory.GetOffset()),