firebase / firebase/firebase-unity-sdk

Firebase Unity SDK – Native crash in Realtime Database (uS WebSocket thread)

Open
#1,391 1 comment 1 reaction 0 assignees View on GitHub
api: database
Dominant language
C#
Stars
320
Forks
60
Avg merge
11h 15m
Merged PRs (30d)
11

Description

# Firebase Unity SDK – Native crash in Realtime Database (uS WebSocket thread)

## Summary

Unity Editor crashes with a **native crash** in `FirebaseCppApp-13_7_0.dll` (Windows) when using Firebase Realtime Database with multiple `ValueChanged` and `ChildAdded`/`ChildRemoved` listeners. The crash occurs on a **worker thread** in the uS (µWebSockets) layer, not in C#.

## Environment

- **Unity**: 6000.3.0f1 (Unity 6)
- **Firebase Unity SDK**: 13.7.0 (Realtime Database)
- **Platform**: Windows 10 (64-bit), Unity Editor
- **Scripting**: .NET / Mono

## Crash details

- **Module**: `FirebaseCppApp-13_7_0.dll`
- **Thread**: Worker thread (stack shows `BaseThreadInitThunk` / `RtlUserThreadStart`)
- **Native stack** (representative frames):
- `uS::TLS::Context::operator bool`
- `uS::Node::...`
- `uS::Socket::write`
- `uS::Socket::freeMessage`

So the failure is in the C++ WebSocket/TLS code, not in managed code.

## Reproduction

1. Open a Unity project with Firebase Realtime Database (SDK 13.7.0).
2. Load a games list from the database and build UI for each game.
3. For each game, attach:
- `DatabaseReference.ValueChanged`
- `DatabaseReference.ChildAdded` (e.g. on a `/Players` child ref)
- `DatabaseReference.ChildRemoved`
4. Trigger a “refresh” that:
- Removes all listeners,
- Fetches a new snapshot (`GetValueAsync` / equivalent),
- Rebuilds the UI,
- Re-attaches the same listeners for each game (either in one frame or over a few frames).
5. The crash can occur during or shortly after re-attaching many listeners, or when many `ValueChanged` callbacks are processed. It is intermittent but reproducible under load.

## Mitigations tried (C# side)

- Coalescing UI rebuilds to at most one per frame.
- Not attaching listeners while a “refresh” is in progress.
- Deferring listener attachment by one frame after the UI rebuild.
- Staggering listener attachment (e.g. 5 games per frame).
- Delaying the single coalesced UI rebuild by one frame.
- In Editor only: adding an extra 2.5 s delay after the UI rebuild before starting listener attachment.

These reduce frequency but do not eliminate the crash; the failure remains in native code.

## Request

Please check whether this uS WebSocket/TLS path is subject to known race conditions or use-after-free when many listeners are added/removed or when many callbacks are delivered, and whether a fix or workaround is available or planned for the Unity SDK.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.