• Ulan Degenbaev's avatar
    Make Map::instance_type accessors atomic · 4d07f3f2
    Ulan Degenbaev authored
    This fixes a false positive TSAN report where an object transitions to
    a new map in StoreIC. The scenario:
    1) Object a transitions from map1 to a newly created map2 in runtime.
       The map is installed with a release-store.
    2) Object b transitions from map1 to map2 in StoreIC in generated code
       that is not visible to TSAN.
    3) Concurrent marker visits object b and loads it map with an acquire
       load.
    
    Since TSAN does not see the store in step (2) it thinks that the map
    loaded in (3) is freshly allocated and is not guarded by a release
    store.
    
    Bug: v8:11353
    Change-Id: Ifcace9edff987761a4098d3fdfb98c6190f1ee1e
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/2682641Reviewed-by: 's avatarDominik Inführ <dinfuehr@chromium.org>
    Commit-Queue: Ulan Degenbaev <ulan@chromium.org>
    Cr-Commit-Position: refs/heads/master@{#72578}
    4d07f3f2
Name
Last commit
Last update
..
api Loading commit data...
asmjs Loading commit data...
ast Loading commit data...
base Loading commit data...
builtins Loading commit data...
codegen Loading commit data...
common Loading commit data...
compiler Loading commit data...
compiler-dispatcher Loading commit data...
d8 Loading commit data...
date Loading commit data...
debug Loading commit data...
deoptimizer Loading commit data...
diagnostics Loading commit data...
execution Loading commit data...
extensions Loading commit data...
flags Loading commit data...
handles Loading commit data...
heap Loading commit data...
ic Loading commit data...
init Loading commit data...
inspector Loading commit data...
interpreter Loading commit data...
json Loading commit data...
libplatform Loading commit data...
libsampler Loading commit data...
logging Loading commit data...
numbers Loading commit data...
objects Loading commit data...
parsing Loading commit data...
profiler Loading commit data...
protobuf Loading commit data...
regexp Loading commit data...
roots Loading commit data...
runtime Loading commit data...
sanitizer Loading commit data...
snapshot Loading commit data...
strings Loading commit data...
tasks Loading commit data...
third_party Loading commit data...
torque Loading commit data...
tracing Loading commit data...
trap-handler Loading commit data...
utils Loading commit data...
wasm Loading commit data...
zone Loading commit data...
DEPS Loading commit data...
DIR_METADATA Loading commit data...
OWNERS Loading commit data...