• Pierre Langlois's avatar
    [cctest][heap] Do not rely on page limit for full space simulation. · 01dbc9f6
    Pierre Langlois authored
    This reverts https://chromium-review.googlesource.com/c/v8/v8/+/2372545
    in favour of different solution. In order to simulate filling up a page,
    it's not suitable to look at the limit() since there might be observers
    that have lowered it, so the page will not actually be full.
    
    Instead, let's relax the CHECK() in CreatePadding() to not look at the
    limit() but all available space.
    
    For instance, the test-heap/Regress978156 cctest uses FillCurrentPage()
    to fill the current page. However if there's an observer on the current
    page, it will not be filled entirely and the test will fail. This works
    because by default, when the new space is empty, the scavenger observer
    happens to be on the second page of the space. However if one changes
    the V8 page size to 512k, then it fails.
    
    This can be reproduced as such:
    
        # Make sure the scavenge trigger is on the first page.
        ./cctest test-heap/Regress978156  --scavenge-task-trigger=10
    
        # Stress marking adds random observers to trigger incremental
        # marking.
        ./cctest test-heap/Regress978156  --stress-marking=100
    
    This issue also causes crashes when using the %SimulateNewspaceFull()
    runtime test function, as found by fuzzing and you can find more details
    in the bug.
    
    Bug: v8:10808, v8:9906, chromium:1122848
    Change-Id: Ie043ae0a1d3754d2423cb5d97f2b3e1ee860e5c8
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/2401427Reviewed-by: 's avatarUlan Degenbaev <ulan@chromium.org>
    Commit-Queue: Pierre Langlois <pierre.langlois@arm.com>
    Cr-Commit-Position: refs/heads/master@{#69805}
    01dbc9f6
Name
Last commit
Last update
..
api Loading commit data...
asmjs Loading commit data...
ast Loading commit data...
base Loading commit data...
builtins Loading commit data...
codegen Loading commit data...
common Loading commit data...
compiler Loading commit data...
compiler-dispatcher Loading commit data...
d8 Loading commit data...
date Loading commit data...
debug Loading commit data...
deoptimizer Loading commit data...
diagnostics Loading commit data...
execution Loading commit data...
extensions Loading commit data...
flags Loading commit data...
handles Loading commit data...
heap Loading commit data...
ic Loading commit data...
init Loading commit data...
inspector Loading commit data...
interpreter Loading commit data...
json Loading commit data...
libplatform Loading commit data...
libsampler Loading commit data...
logging Loading commit data...
numbers Loading commit data...
objects Loading commit data...
parsing Loading commit data...
profiler Loading commit data...
protobuf Loading commit data...
regexp Loading commit data...
roots Loading commit data...
runtime Loading commit data...
sanitizer Loading commit data...
snapshot Loading commit data...
strings Loading commit data...
tasks Loading commit data...
third_party Loading commit data...
torque Loading commit data...
tracing Loading commit data...
trap-handler Loading commit data...
utils Loading commit data...
wasm Loading commit data...
zone Loading commit data...
DEPS Loading commit data...
OWNERS Loading commit data...