release: 2026-09-16 - #10134
release: 2026-09-16#10134
Conversation
* fix: keep Jarvis security review label current * chore: simplify security review classifier
* fix: bump rustls to 0.23.45 for RUSTSEC-2026-0285 TLS 1.3 handshake messages were accepted across encryption level boundaries. rustls is transitive here, via segment's rustls-tls feature. Single-package update; no other crate in the lock moved. The shipped binaries still need the rebuild-and-relock round trip from Explorer/Assets/Plugins/RustSegment/README.md: Cargo.lock is a hashed build input, so the committed .dylib/.dll no longer match the lock. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * chore: relock RustSegment native binaries after the rustls bump Cargo.lock is a hashed build input, so bumping rustls to 0.23.45 left the committed .dylib/.dll describing a lock they were not built from. Binaries are from rust-segment-native.yml run 34962852958, which passed Gate A on both runners (byte-identical double build). Gate B failed there by design: the toolchain matched the lock's pin and .native/src was unchanged, so it demanded reproduction of binaries that Cargo.lock had already invalidated. It becomes a real comparison on the next labelled run. Toolchain pins and source_digest are unchanged - same runners, no src edit. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> --------- Co-authored-by: Juan Molteni <juanignaciomolteni@gmail.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: Ani <139157886+anicalbano@users.noreply.github.com>
…uild (#10110) * fix: tolerate transient Unity Cloud API failures after a successful build * fix: restore the build folder confirmation log in download_artifact
* _exit * cleanup
|
Windows and Mac build successful in Unity Cloud! Links reused from the existing
|
🚦 CI StatusWindows and Mac built successfully in Unity Cloud.
Warnings count reduced: 11902 => 11898 Warnings/errors in files changed by this PR (249)…truncated; see the linked run for the full report. All Unity tests passed ✅
Tests time sums the test cases; Job time is the job's wall clock including checkout, licensing and asset import. Slowest tests
Full report: run summary · results + editor logs: editmode · playmode 🏁 Bare-metal benchmark finished — run #35145118714. Full reportPR #10134, run #35145118714 Overall: ✅ no significant changes Builds: Windows change, Windows baseline, macOS change, macOS baseline How to read this table
Apple M1
Intel Core i5
On demand — comment ✅ InWorld suite passed on all 3 legs.
Commit macOS on |
SDK6 scenes are no longer pinned to their LOD representation. Near the player they enter the normal distance-based scene lifecycle and run their original JavaScript through the SDK6 compatibility adapter, which now ships in StreamingAssets instead of being fetched from renderer-artifacts.decentraland.org at runtime. Adapter: decentraland/sdk6-adapter 0.4.3, commit f06e46e415e6e1ef692133eff198aa6bdea3ed4c Build: https://github.com/decentraland/sdk6-adapter/actions/runs/34495065151 SHA-256: 733a108cd8bb667be75d6c76a3fe444f6ddcd481858af8d354dba25a29713b9a * feat: provide ~system/AdaptationLayerHelper for SDK6 UI texture sizing The SDK6 compatibility adapter uses the host-optional ~system/AdaptationLayerHelper.getTextureSize for UiImage sizeInPixels sizing. Texture sources resolve through ISceneData.TryGetMediaUrl, the same path SDK7 texture components use, and the original file is fetched without the KTX variant so the reported size is the source image's. Also clears the nullable compiler warnings in the files this branch touches (LoadSceneDefinitionListSystem, VisualSceneStateResolverShould). * chore: embed sdk6-adapter 5ae8391 The adapter now follows the legacy screen-space UI rules: pointer blocking through the CanvasGroup chain, onClick on pointer down, image source-rect cropping, stack sizing, text truncation and input placeholder, background and submit semantics. It also moves esbuild past GHSA-67mh-4wv8-2f99. Bundle and provenance are the subjects attested by https://github.com/decentraland/sdk6-adapter/actions/runs/34679156027/attempts/1 (sha256 18e63cfc2a6913bbed658bde0bf4ca2af60336be2b4cd07806b00948662f12c9, 1132952 bytes). Bundled dependency licenses are unchanged.
* remove session-id override param & replace device id for a guid * update comment
DafGreco
left a comment
There was a problem hiding this comment.
✔️ PR reviewed and approved by QA on both platforms following instructions playing both happy and un-happy path
Regressions for this ticket had been performed in order to verify that the normal flow is working as expected:
decentraland-bot
left a comment
There was a problem hiding this comment.
Release Review — release: 2026-09-16
Automated release PR merging 15 commits from release/2026-09-16 into main. QA has approved on both platforms.
STEP 1 — Scope
Commits in this release:
fix: os font fallback anr (#10090)— ANR fix in MetricsRegistryfix: far-away scenes broken tick after teleport (#10089)— VisualSceneStateResolver SDK6 path removalfix: keep Jarvis security review label current (#10106)— CI workflowfix: crash when a deleted entity still lists destroyed children (#10067)— ParentingTransformSystem crash fixfeat: guest login (#9888)— Major feature: full guest login flow, account upgrade, identity persistencechore: sync main to dev (#10108)— mergefix: tolerate transient Unity Cloud API failures (#10092)— build script resiliencefix: editor start-position override (#10092)— TeleportStartupOperation simplificationfeat: _exit with 0 code on macOS (#10104)— ExitUtils:_exit(0)replaceskill(SIGKILL)chore: migrate to 'main' protocol (#10060)— protobuf updates, AvatarEmoteMask, comms protocolfix: remove the reflection scan behind web-request debug metrics (#10112)— MetricsRegistry ANR fixfix: reconcile the abgen server already on the port (#10113)— AbgenSidecar port reconciliationfix: stop GPU Instancer blocking the main thread on startup (#10111)— asset changesfeat: run SDK6 scenes through an embedded adapter (#10057)— AdaptationLayerHelper, embedded JS adapterfix: guest session id random per install, no override (#10135)— GuestSessionIdProvider
138 C# files changed, plus assets, prefabs, textures, protocol files, CI scripts.
STEP 2 — Root-cause check
Each fix addresses its root cause:
- #10067 (ParentingTransformSystem): The crash occurred because
OrphanChildrenOfDeletedEntitycalledWorld.Get<TransformComponent>(childEntity)without validating whether the child entity was alive or still actually parented. The fix correctly addsWorld.IsAlivechecks and validatestransformComponent.Parent == entitybefore operating, plus a fallback to scene root when the requested parent is dead. ✅ - #10090/#10112 (MetricsRegistry): Replaced a reflection scan over all loaded assemblies with an explicit type list — addresses the ANR at its source (slow reflection at startup). ✅
- #10089 (VisualSceneStateResolver): Removed the early-return for SDK6 scenes that forced LOD display, now that SDK6 scenes run through the embedded adapter. ✅
- #10104 (ExitUtils): Replaces
kill(pid, SIGKILL)with_exit(0)on macOS — cleaner process termination. ✅ - #10113 (AbgenSidecar): Instead of adopting any server on the port, reconciles version, realm, and status before adopting. ✅
- #10135 (GuestSessionIdProvider): Generates a random GUID per install and persists it, removing any override path. ✅
STEP 3 — Design & integration
Guest login feature (#9888) — the largest change in this release. Design assessment:
- Identity model:
IWeb3Identity.Web3IdentitySourceenum replaced withLoginMethodenum onIWeb3Authenticator. This is a clean refactor — the method is now persisted in the identity JSON and round-tripped correctly, with fallback toLoginMethod.ANYfor legacy cached identities. Test coverage inIdentityMethodPersistenceShouldconfirms round-trip, fallback for absent/unrecognised method. ✅ IAccountLinkAuthenticator: New interface for email linking — implemented byThirdWebAuthenticator, composed intoICompositeWeb3Provider. This earns its abstraction: it is consumed by both theUpgradeGuestAccountPopupControllerand theCompositeWeb3Providerfacade. ✅GuestAccountUpgradedException: Custom exception to signal that a guest wallet has been upgraded with an email. Caught atCompositeWeb3Provider.LoginAsync,TryAutoLoginAsync, andGuestOrSignUpAuthState. The exception propagation is consistent. ✅UpgradeGuestAccountPopupController: New MVC controller for the upgrade popup. CTS lifecycle is correct (SafeRestarton close,SafeCancelAndDisposeon dispose). Analytics events have symmetric subscribe/unsubscribe inUpgradeGuestAccountAnalytics. ✅isGuestpropagation through comms: TheisGuestflag flows fromidentityCache.IsGuest()throughMetaData,CommsHandshakeMetadata,SignedFetchWrap, andSceneRoomMetaDataSource. All call sites updated consistently. ✅- Feature gating: Guest login is behind
FeatureId.GuestLogin(alfa-guest-loginflag). Auto-login clears guest session when the flag is disabled. ✅
SDK6 adapter embedding (#10057):
AdaptationLayerHelperWrapperis a standardJsApiWrapperthat fetches texture dimensions. It validates the URL throughsceneData.TryGetMediaUrlbefore fetching. The texture is created and destroyed within the same flow (try/finally). ✅- The adapter JS is loaded from
StreamingAssetsinstead of a remote URL. A SHA-256 and provenance file are committed alongside. ✅
AbgenSidecar reconciliation (#10113):
- The
ReconcileResidentServerAsyncmethod probes/healthand checks version, realm, and status before adopting. Theadoptedflag prevents killing a server this instance didn't launch. The AB panel is opened to explain why the port is blocked. ✅
STEP 4 — Member audit
ICompositeWeb3Provider.IsThirdWebAccount(renamed fromIsThirdWebOTP): Used byCompositeWeb3Providerinternally (3 call sites) and by external consumers. Rename correctly reflects that it now covers both guest and OTP flows. ✅IWeb3IdentityCache.IsGuest()extension method: Used across 10+ call sites (comms metadata, voice chat, signed fetch, sidebar, passport, communities, chat, donations, places, profile name editor). Single-purpose utility that encapsulates the null-safe check. ✅ProfileBuilder.WithGuestMode(bool): Used byUpgradeGuestAccountPopupController.PromoteProfileAsyncand byProfileFetchingAuthState. Delegates tohasConnectedWeb3 = !isGuest. ✅
STEP 5 — Line-level findings
No P0 or P1 issues found. The code is well-structured, follows project conventions, and each commit has been individually reviewed on dev.
Categories checked clean:
- R1 (perf-alloc): No allocations introduced in hot paths. MetricsRegistry change explicitly removes a per-startup reflection scan. ✅
- R2 (LINQ): No LINQ added in systems or hot paths. ✅
- R4 (ECS lifecycle): ParentingTransformSystem changes are correct ECS query patterns with proper
World.IsAliveandTryGetRefchecks. ✅ - R5 (entity by-ref): No structural changes over by-ref entities. The
RemoveFromParentparameter change toin TransformComponentis read-only. ✅ - R6 (acquire/release symmetry):
UpgradeGuestAccountPopupController—linkCtsisSafeRestarted on close andSafeCancelAndDisposed on Dispose.UpgradeGuestAccountAnalyticshas symmetric subscribe/unsubscribe. ✅ - R7 (nullability): Identity method fallback to
LoginMethod.ANYfor legacy data is correct. No null-forgiving operators added without justification. ✅ - R8 (root cause): All fixes address root causes (see Step 2). ✅
- R9 (logging): All logging uses
ReportHubwith explicitReportCategory. ✅ - R10 (catch-scope):
ThirdWebLoginService.TryAutoLoginAsyncusescatch (Exception e) when (e is not GuestAccountUpgradedException)— correct filtering. ✅ - R11 (async/cancellation): CancellationTokens are threaded through all new async paths.
ThrowIfCancellationRequestedused in awaited flows (acceptable per CLAUDE.md §9).linkCtslifecycle inUpgradeGuestAccountPopupControlleris correct. ✅ - R12 (abstraction justification):
IAccountLinkAuthenticatorhas two consumers (UpgradeGuestAccountPopupController,CompositeWeb3Provider). ✅ - R13 (reuse):
GuestSessionIdProviderreusesDCLPlayerPrefsandDCLPrefKeys.BuildIdentityAsyncextracts the common identity construction previously duplicated between login flows. ✅ - R18 (magic numbers):
SceneFacade.FROZEN_INTERVAL_MS = -1is properly named. ✅ - R20 (idiom cluster): No
Concurrent*collections. String comparisons useStringComparison.OrdinalIgnoreCaseinContainsMessage. ✅ - R22 (tests):
IdentityMethodPersistenceShould(5 test cases),SceneFacadeShould(2 new tests for 0-FPS freeze/resume),TeleportStartupOperationShould(2 new tests),AvatarRandomizerShould,AdaptationLayerHelperWrapperShould,ParentingTransformSystemShould,MetricsRegistryShould— comprehensive coverage. ✅ - R23 (AI comments): No AI-style narration comments detected. ✅
- R24 (scope): Each commit is well-scoped to its stated purpose. ✅
STEP 6 — Complexity
COMPLEX — touches auth/identity infrastructure, ECS transform systems, comms metadata, scene runtime module registration, analytics, feature flags, and multiple plugin/container wiring points.
STEP 7 — QA
QA_REQUIRED: YES — runtime code is modified across authentication, scene loading, parenting, voice chat, and comms.
QA has already approved on both platforms (DafGreco).
STEP 8 — Warnings
No warnings. Main.unity is not in the changed files.
Merge gates
- R25 (open threads): 0 open review threads. QA approved. ✅
- R26 (QA sign-off): QA approved by DafGreco on both Windows and Mac. The PR carries the
auto-prlabel. ✅
CI Status
- ✅ Build (Windows + macOS): PASS
- ✅ Lint: PASS
- ✅ Test (editmode + playmode): PASS
- ✅ InWorld suite: PASS
- ✅ Rust checks: PASS
⚠️ request-security-review: FAIL (workflow infrastructure — does not indicate a code issue)- ⏳
Claude Review: Pending (this review)
REVIEW_RESULT: PASS ✅
COMPLEXITY: COMPLEX
COMPLEXITY_REASON: Touches auth/identity (guest login, account linking, identity persistence), ECS parenting, comms metadata, scene runtime (SDK6 adapter), analytics, and plugin wiring across 138 C# files.
QA_REQUIRED: YES
Reviewed by Jarvis 🤖 · Requested by Ani Albano (<@U05FQD5JWH2>) via Slack
🚀 Automated release PR