• mlippautz's avatar
    Revert of [heap] Clean up stale store buffer entries for aborted pages.... · d4fc4a8c
    mlippautz authored
    Revert of [heap] Clean up stale store buffer entries for aborted pages. (patchset #4 id:60001 of https://codereview.chromium.org/1493653002/ )
    
    Reason for revert:
    Not completely correct fix.
    
    Original issue's description:
    > [heap] Clean up stale store buffer entries for aborted pages.
    >
    > 1.  Let X be the aborted slot (slot in an evacuated object in an aborted page)
    > 2.  Assume X contains pointer to Y and Y is in the new space, so X is in the
    >     store buffer.
    > 3.  Store buffer rebuilding will not filter out X (it checks InNewSpace(Y)).
    > 4.  The current mark-sweep finishes. The slot X is in free space and is also in
    >     the store buffer.
    > 5.  A string of length 9 "abcdefghi" is allocated in the new space. The string
    >     looks like |MAP|LENGTH|hgfedcba|NNNNNNNi| in memory, where NNNNNNN is
    >     previous garbage. Let's assume that NNNNNNN0 was pointing to a new space
    >     object before.
    > 6.  Scavenge happens.
    > 7.  Slot X is still in free space and in store buffer. [It causes scavenge of
    >     the object Y in
    >     store_buffer()->IteratePointersToNewSpace(&Scavenger::ScavengeObject). But
    >     it is not important].
    > 8.  Our string is promoted and is allocated over the slot X, such that NNNNNNNi
    >     is written in X.
    > 9.  The scavenge finishes.
    > 9.  Another scavenge starts.
    > 10. We crash in
    >     store_buffer()->IteratePointersToNewSpace(&Scavenger::ScavengeObject) when
    >     processing slot X, because it doesn't point to valid map.
    >
    > BUG=chromium:524425,chromium:564498
    > LOG=N
    > R=hpayer@chromium.org, ulan@chromium.org
    >
    > Committed: https://crrev.com/2e7eea4aef3403969fe885e30f892d46253b3572
    > Cr-Commit-Position: refs/heads/master@{#32495}
    
    TBR=hpayer@chromium.org,ulan@chromium.org
    NOPRESUBMIT=true
    NOTREECHECKS=true
    NOTRY=true
    BUG=chromium:524425,chromium:564498
    
    Review URL: https://codereview.chromium.org/1489243004
    
    Cr-Commit-Position: refs/heads/master@{#32504}
    d4fc4a8c
Name
Last commit
Last update
..
OWNERS Loading commit data...
array-buffer-tracker.cc Loading commit data...
array-buffer-tracker.h Loading commit data...
gc-idle-time-handler.cc Loading commit data...
gc-idle-time-handler.h Loading commit data...
gc-tracer.cc Loading commit data...
gc-tracer.h Loading commit data...
heap-inl.h Loading commit data...
heap.cc Loading commit data...
heap.h Loading commit data...
incremental-marking-inl.h Loading commit data...
incremental-marking-job.cc Loading commit data...
incremental-marking-job.h Loading commit data...
incremental-marking.cc Loading commit data...
incremental-marking.h Loading commit data...
mark-compact-inl.h Loading commit data...
mark-compact.cc Loading commit data...
mark-compact.h Loading commit data...
memory-reducer.cc Loading commit data...
memory-reducer.h Loading commit data...
object-stats.cc Loading commit data...
object-stats.h Loading commit data...
objects-visiting-inl.h Loading commit data...
objects-visiting.cc Loading commit data...
objects-visiting.h Loading commit data...
scavenge-job.cc Loading commit data...
scavenge-job.h Loading commit data...
scavenger-inl.h Loading commit data...
scavenger.cc Loading commit data...
scavenger.h Loading commit data...
slots-buffer.cc Loading commit data...
slots-buffer.h Loading commit data...
spaces-inl.h Loading commit data...
spaces.cc Loading commit data...
spaces.h Loading commit data...
store-buffer-inl.h Loading commit data...
store-buffer.cc Loading commit data...
store-buffer.h Loading commit data...