• Clemens Backes's avatar
    [asm] Fix use-after-free in ZoneVectors · 7887ae6f
    Clemens Backes authored
    The AsmParser kept pointers into ZoneVectors, which were accessed even
    after those vector might have grown. For regular vectors, this would be
    a use-after-free; with ZoneVectors it is technically allowed, since the
    old memory stays alive. This will change with
    https://crrev.com/c/2302895, which zaps zone memory which is
    deallocated. Eventually, we might want to reuse large deallocations in
    zone memory, hence this "use after free" needs to be fixed.
    
    This CL fixes the issue by explicitly re-allocating in the zone instead
    of using ZoneVectors. This makes sure that the old memory stays alive.
    This is kind of a quick-fix, but since asm.js is more or less deprecated
    anyway (in favor of Wasm), it's OK if this code does not profit from
    future ZoneVector memory re-use optimizations.
    
    Drive-by: Move field initializers to the field declaration.
    
    R=ishell@chromium.org
    
    Bug: v8:10717
    Change-Id: I56c1feb49d05080e78a6620273b55b4e18156254
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/2304581Reviewed-by: 's avatarIgor Sheludko <ishell@chromium.org>
    Commit-Queue: Clemens Backes <clemensb@chromium.org>
    Cr-Commit-Position: refs/heads/master@{#68917}
    7887ae6f
Name
Last commit
Last update
..
api Loading commit data...
asmjs Loading commit data...
ast Loading commit data...
base Loading commit data...
builtins Loading commit data...
codegen Loading commit data...
common Loading commit data...
compiler Loading commit data...
compiler-dispatcher Loading commit data...
d8 Loading commit data...
date Loading commit data...
debug Loading commit data...
deoptimizer Loading commit data...
diagnostics Loading commit data...
execution Loading commit data...
extensions Loading commit data...
flags Loading commit data...
handles Loading commit data...
heap Loading commit data...
ic Loading commit data...
init Loading commit data...
inspector Loading commit data...
interpreter Loading commit data...
json Loading commit data...
libplatform Loading commit data...
libsampler Loading commit data...
logging Loading commit data...
numbers Loading commit data...
objects Loading commit data...
parsing Loading commit data...
profiler Loading commit data...
protobuf Loading commit data...
regexp Loading commit data...
roots Loading commit data...
runtime Loading commit data...
sanitizer Loading commit data...
snapshot Loading commit data...
strings Loading commit data...
tasks Loading commit data...
third_party Loading commit data...
torque Loading commit data...
tracing Loading commit data...
trap-handler Loading commit data...
utils Loading commit data...
wasm Loading commit data...
zone Loading commit data...
DEPS Loading commit data...
OWNERS Loading commit data...