How to reproduce:
1. Open the attached “IN-151222.zip” project
2. In the top menu bar, go to Repro → SnapshotIntegrity → Run - C1 corrupt image
3. Observe the crash
Actual result: The Editor crashes
Expected result: The Editor does not crash
Reproducible with: 6000.6.0b9, 6000.7.0a5
Could not test with: 6000.0.0f1, 6000.0.82f1, 6000.3.22f1, 6000.5.10f1 (the snapshot API (PhysicsWorld.Snapshot, CreateSnapshot, ApplySnapshot) was introduced in 6000.6)
Reproducible on: 26.6.1 (25G76) (M3 Max)
Not reproducible on: No other environments tested
Note: Documentation - https://docs.unity3d.com/6000.6/Documentation/ScriptReference/Unity.U2D.Physics.PhysicsWorld.Snapshot.html
First few lines of the stack trace:
#0 0x00000102c082a4 in b2DynamicTree_GetHeight(b2DynamicTree const*)
#1 0x00000102b225f0 in PhysicsCore2D::PhysicsWorld::GetCounters(PhysicsCore2D::PhysicsWorld)
#2 0x00000102c24214 in Scripting2D_CUSTOM_PhysicsWorld_GetCounters(PhysicsCore2D::PhysicsWorld const&, b2Counters&)
#3 0x0000045b141448 in (wrapper managed-to-native) Unity.U2D.Physics.Scripting2D:PhysicsWorld_GetCounters_Injected (Unity.U2D.Physics.PhysicsWorld&,Unity.U2D.Physics.PhysicsWorld/WorldCounters&) [
{0x9a015b8d0}
+ 0x90] (0x45b1413b8 0x45b1414cc) [0x16b3b6a80 - Unity Child Domain]
#4 0x0000045b1412ec in Unity.U2D.Physics.Scripting2D:PhysicsWorld_GetCounters (Unity.U2D.Physics.PhysicsWorld) [
{0x9a015b798}
+ 0x5c] (0x45b141290 0x45b141334) [0x16b3b6a80 - Unity Child Domain]
#5 0x0000045b1411fc in Unity.U2D.Physics.PhysicsWorld:get_counters () [
{0x9a31ead70}
+ 0x7c] [/Users/bokken/build/output/unity/unity/Modules/PhysicsCore2D/Scripting/PhysicsWorld.cs :: 2537u] (0x45b141180 0x45b141230) [0x16b3b6a80 - Unity Child Domain]