Skip to content

fix(content): fail closed on image inference watchdog timeout, dedupe in-flight inference - #124

Merged
govza merged 6 commits into
masterfrom
fix/image-watchdog-fail-closed
Sep 13, 2026
Merged

govza merged 6 commits into
masterfrom
fix/image-watchdog-fail-closed

Conversation

@govza

@govza govza commented Sep 13, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Start the image inference watchdog when the task leaves the queue (not on enqueue) and fail closed (keep blurred) on timeout instead of revealing the image
  • Background: join in-flight inference for the same src instead of enqueueing duplicate tasks
  • Firefox: resolve image source from the reflected src while currentSrc still reports the old value
  • Skip inference for placeholder-resolution images

Test plan

  • pnpm test:unit
  • pnpm lint
  • Manual: images that time out stay blurred; duplicate <img> with same src trigger one inference; Firefox lazy-load src swap resolves correctly

https://claude.ai/code/session_01L7JHWoqQg8W4ExvRhfbj6g

… queue, fail closed on timeout

On Firefox mobile the single-lane WASM queue takes well over 20 s to reach
below-fold Google Images, so the send-time watchdog expired while tasks were
still queued and finalized them as skipped, revealing a whole band unmasked.
The background now broadcasts a 'started' result when a task is dequeued; the
content watchdog arms from that moment. Exhausted timeouts keep the blur so the
late prediction still applies; only explicit inference errors fail open.

Claude-Session: https://claude.ai/code/session_01L7JHWoqQg8W4ExvRhfbj6g
…g duplicates per src

Content retries, repeated <img> copies and sibling tabs used to enqueue one
task each for the same hostname+src; the verdict is broadcast by src anyway.
Duplicates now join the existing task (raising its queued priority when the
newcomer is visible), so retries no longer inflate the backlog.

Claude-Session: https://claude.ai/code/session_01L7JHWoqQg8W4ExvRhfbj6g
…ox still reports the old currentSrc

Firefox keeps currentSrc on the previous request until the new image's size
is known, so a src swap looked like a no-op re-stamp in handleSrcChange. On
Google Images the 10 px placeholder's safe verdict therefore stayed on the
element and the full thumbnail rendered unmasked. Reads now go through
resolveImageSource (reflected src unless srcset/picture select candidates),
and every processed image re-checks its source on load.

Claude-Session: https://claude.ai/code/session_01L7JHWoqQg8W4ExvRhfbj6g
Google Images decodes a 10 px thumbnail before the real one; those
placeholders were most of the inference backlog on mobile while carrying
nothing to detect. Finalize them as skipped once decoded; the src swap to
the real thumbnail re-enters processing.

Claude-Session: https://claude.ai/code/session_01L7JHWoqQg8W4ExvRhfbj6g
Drop the added comments, fold the four light/shadow DOM src loops into
collectMatchingImages, brand the in-flight image key, keep priority on the
task itself, track queued ids so raisePriority never swallows errors, and
re-broadcast started to duplicates that join a running task. Placeholder
skip now requires both sides tiny and never exceeds the host's min size.
Add tests for the queue-wait guard, started arming, fail-open on errors,
placeholder skip, in-flight joining and priority raising (happy-dom added
as the DOM test environment).

Claude-Session: https://claude.ai/code/session_01RvK31wdZERD2K4EmaytRTE
… crashing GeckoView

Firefox Nightly 158 (Bug 1977695) enables homepage-as-new-tab by default. On
geckodriver's session delete Fenix then opens a fresh homepage tab while Gecko is
already quitting, hitting MOZ_RELEASE_ASSERT(domWindow) in GeckoViewSupport::Open.
The crash kills the Marionette reply, wdio's endSession throws, and the whole spec
file is reported failed even though every scenario passed.

Turn the feature off after launch by broadcasting a local Nimbus rollout to
QANimbusToolingReceiver; seeding fenix_preferences.xml earlier does not survive the
pm clear geckodriver runs while creating the session.

Claude-Session: https://claude.ai/code/session_01JXYmCiDLk3QEbAwCTS5wS5
@govza
govza merged commit eba00a7 into master Sep 13, 2026
4 checks passed
@govza
govza deleted the fix/image-watchdog-fail-closed branch September 13, 2026 19:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant