pub fn run_guarded_thread(what: &str, f: impl FnOnce())Expand description
Run a shell-spawned render-thread body, catching any panic so the thread
exits cleanly instead of unwinding out of the thread closure — following
the same catch_unwind + AssertUnwindSafe + error-log convention as
guard, but for a whole-thread closure rather than an FFI entry point.
A dev-build render-thread panic logs here and returns, which runs the
closure’s owned RenderReceiver’s Drop — the receiver-liveness drain
(see render_split’s RenderReceiver) that fires any orphaned Ack’s
safety net, so a UI/main thread blocked on a Pause/SurfaceDestroyed
barrier unblocks rather than deadlocking. This is a diagnosability aid,
not the correctness anchor: correctness rests on the receiver-liveness drain,
which fires on any thread exit (clean early return, hang teardown, or
this caught panic).
No-op under the release panic = "abort" profile (root Cargo.toml):
there catch_unwind never catches — a panic aborts the whole process before
unwinding — so this wrapper matters only in dev / panic = "unwind" builds.
The barrier deadlock the caught panic would otherwise cause bites exactly
those non-abort builds (plus clean early-returns and hung threads, which this
wrapper does not touch — the drain covers those).