[Android][Fabric] "Unable to remove a view from a view that is not a ViewGroup" still crashes with fixDifferentiatorParentTagForUnflattenCase enabled (0.86.2)
还没有人认领这个 Issue。
- 主要语言
- C++
- 星标
- 127k
- 派生
- 25.3k
- 平均合并
- 1 天 23 小时
- 30 天内合并 PR
- 4
描述
Description
We are still seeing the fatal Android Fabric crash
java.lang.IllegalStateException: Unable to remove a view from a view that is not a ViewGroup. ParentTag: 1902 - Tag: 1900 - Index: 0
in production with fixDifferentiatorParentTagForUnflattenCase enabled, on stock React Native 0.86.2 (new architecture, bridgeless, Hermes).
After #56542 ("Fix parentTagForUpdate in unflatten-unflatten branch") we backported the fix by force-enabling the flag at startup:
// Application.onCreate, after loadReactNative(this)
ReactNativeFeatureFlags.dangerouslyForceOverride(
object : ReactNativeNewArchitectureFeatureFlagsDefaults() {
override fun fixDifferentiatorParentTagForUnflattenCase(): Boolean = true
}
)
We verified the override is effective (the dangerouslyForceOverride return value confirms the flag had not been read before the override, and the override happens in Application.onCreate before any surface is mounted). The crash volume dropped after enabling the flag, but the crash recurred in a build that provably contains it — so at least one more differ reparenting path can still emit a Remove mutation against a wrong parent tag (a tag whose ViewState holds a null or non-ViewGroup view, i.e. a non-container or a never-materialized/non-layoutable node).
Occurrence details from the crash session (Crashlytics):
- Device: Samsung SM-S938W (Galaxy S25 Ultra), Android 16
- The crashing tags (1900/1902) are mid-session views, not first-render views
- Timeline: the session had two device orientation changes (portrait → landscape → portrait), then a large state-driven re-render (a BLE device connected and the dashboard swapped several conditional subtrees), and the crash fired ~7 s after that re-render began
- The same differ family also produces the sibling hard throw
"Cannot remove child at index X from parent ViewGroup"reported elsewhere (e.g. software-mansion/react-native-screens#2491)
Stack (top frames):
Fatal Exception: java.lang.IllegalStateException: Unable to remove a view from a view that is not a ViewGroup. ParentTag: 1902 - Tag: 1900 - Index: 0
at com.facebook.react.fabric.mounting.SurfaceMountingManager.removeViewAt(SurfaceMountingManager.kt:444)
at com.facebook.react.fabric.mounting.mountitems.IntBufferBatchMountItem.execute(IntBufferBatchMountItem.kt:125)
at com.facebook.react.fabric.mounting.MountItemDispatcher.executeOrEnqueue(MountItemDispatcher.kt:379)
at com.facebook.react.fabric.mounting.MountItemDispatcher.dispatchMountItems$lambda$7$lambda$6(MountItemDispatcher.kt:269)
at com.facebook.react.internal.tracing.PerformanceTracer.trace(PerformanceTracer.kt:46)
at com.facebook.react.fabric.mounting.MountItemDispatcher.dispatchMountItems(MountItemDispatcher.kt:250)
at com.facebook.react.fabric.mounting.MountItemDispatcher.tryDispatchMountItems(MountItemDispatcher.kt:94)
at com.facebook.react.fabric.FabricUIManager$DispatchUIFrameCallback.doFrameGuarded(FabricUIManager.java:1624)
at com.facebook.react.uimanager.GuardedFrameCallback.doFrame(GuardedFrameCallback.kt:42)
at com.facebook.react.modules.core.ReactChoreographer.frameCallback$lambda$1(ReactChoreographer.java:58)
at android.view.Choreographer$CallbackRecord.run(Choreographer.java:1899)
...
We could not reproduce locally (hundreds of scripted navigations/re-renders on the same screens stay clean); the reparenting race appears to need production timing. We're reporting because the flag from #56542 finished rollout and is default-true on main, so this evidences that the unflatten wrong-parent-tag family is not fully closed.
Workaround we ship meanwhile (in case it helps other affected apps): a build-time ASM transform that wraps SurfaceMountingManager.removeViewAt in try/catch (IllegalStateException) → log non-fatal → skip the remove. This matches the method's existing soft-fail handling of its other inconsistency cases, and addViewAt already self-heals a child that is still attached elsewhere. Not proposing that upstream — the differ emitting the wrong parent tag is the actual bug.
Happy to provide more Crashlytics context (thread dumps, breadcrumb timeline) on request.
Steps to reproduce
No deterministic repro. Observed pattern: device rotation (two orientation changes) followed by a large conditional re-render that flattens/unflattens nested views; crash fires during a subsequent mount batch.
React Native Version
0.86.2
Affected Platforms
Runtime - Android
Areas
Fabric - The New Renderer
Output of npx @react-native-community/cli info
React Native: 0.86.2 (new architecture, bridgeless)
React: 19.2.8
Expo: 57.0.4
Hermes: bundled
OS observed crashing: Android 16 (Samsung SM-S938W)
compileSdk/targetSdk: 36, minSdk: 24
AGP: 8.12.0, Gradle: 9.3.1
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
首先阅读 SurfaceMountingManager.kt 中的 removeViewAt,并通过 IntBufferBatchMountItem.kt 和 MountItemDispatcher.kt 跟踪 Remove batch。将其行为与 #56542 中的 fix 进行比较,并调查所描述的 orientation 和 conditional re-render 顺序;完成的标准是识别并覆盖仍会发出无效 parent tag 的路径,而不依赖仅在 production 中发生的 crash。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- android, kotlin, react-native
- 领域
- mobile
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 活跃
- 描述清晰度
- 需要澄清
- 新手友好度
- 35/100