Two build 264 crashes on macOS 26.5.1 hit AppKit's non-finite-frame
trap (_NSViewValidateGeometry) on AVKit's PiP sample-buffer host view
during a routine layout pass. The NaN is produced inside AVKit from
geometry we feed it - either the manual PiP window resize around a
video switch or an infinite container rect copied into the sample
buffer layer frame.
Add a sanitizedGeometry helper that rejects NaN/infinite or degenerate
rects and apply it at every layer/window geometry write in the bridge
(updateLayerFrame variants, moveLayer, updateVideoAspectRatio,
resizePiPWindow, updateLayerFrameToMatchPiPWindow). Rejected writes are
logged with their call site so the actual source can be identified when
it reproduces, instead of crashing on the next CATransaction commit.
Switching videos during active PiP left the window at the old video's
size with white space around the new content, for two reasons:
- MPV reports the new video's width and height as separate property
events while the old values are kept across switches, so a transient
mixed size (new width with old height) could reach the PiP capture
path and AVKit sized the window from that frame. Coalesce the PiP
capture-size/aspect update with a short debounce so only settled
dimensions are used.
- On macOS nothing told AVKit about the new aspect: unlike iOS, the
bridge never flushed the sample buffer renderer on an aspect change
during active PiP, and AVKit doesn't resize the macOS PiP window on
its own. Flush the renderer, reset the format description, and
resize the PiP window to the new aspect ratio explicitly.