• Leszek Swirski's avatar
    Reland^2 "[serializer] Allocate during deserialization" · c4a062a9
    Leszek Swirski authored
    This is a reland of 28a30c57
    which was a reland of 5d7a29c9
    
    The crashes were from calling RegisterDeserializerFinished on a null
    Isolate pointer, for a deserializer that was never initialised
    (specifically, ReadOnlyDeserializer when ROHeap is shared).
    
    Original change's description:
    > Reland "[serializer] Allocate during deserialization"
    >
    > This is a reland of 5d7a29c9
    >
    > This reland shuffles around the order of checks in Heap::AllocateRawWith
    > to not check the new space addresses until it's known that this is a new
    > space allocation. This fixes an UBSan failure during read-only space
    > deserialization, which happens before the new space is initialized.
    >
    > It also fixes some issues discovered by --stress-snapshot, around
    > serializing ThinStrings (which are now elided as part of serialization),
    > handle counts (I bumped the maximum handle count in that check), and
    > clearing map transitions (the map backpointer field needed a Smi
    > uninitialized value check).
    >
    > Original change's description:
    > > [serializer] Allocate during deserialization
    > >
    > > This patch removes the concept of reservations and a specialized
    > > deserializer allocator, and instead makes the deserializer allocate
    > > directly with the Heap's Allocate method.
    > >
    > > The major consequence of this is that the GC can now run during
    > > deserialization, which means that:
    > >
    > >   a) Deserialized objects are visible to the GC, and
    > >   b) Objects that the deserializer/deserialized objects point to can
    > >      move.
    > >
    > > Point a) is mostly not a problem due to previous work in making
    > > deserialized objects "GC valid", i.e. making sure that they have a valid
    > > size before any subsequent allocation/safepoint. We now additionally
    > > have to initialize the allocated space with a valid tagged value -- this
    > > is a magic Smi value to keep "uninitialized" checks simple.
    > >
    > > Point b) is solved by Handlifying the deserializer. This involves
    > > changing any vectors of objects into vectors of Handles, and any object
    > > keyed map into an IdentityMap (we can't use Handles as keys because
    > > the object's address is no longer a stable hash).
    > >
    > > Back-references can no longer be direct chunk offsets, so instead the
    > > deserializer stores a Handle to each deserialized object, and the
    > > backreference is an index into this handle array. This encoding could
    > > be optimized in the future with e.g. a second pass over the serialized
    > > array which emits a different bytecode for objects that are and aren't
    > > back-referenced.
    > >
    > > Additionally, the slot-walk over objects to initialize them can no
    > > longer use absolute slot offsets, as again an object may move and its
    > > slot address would become invalid. Now, slots are walked as relative
    > > offsets to a Handle to the object, or as absolute slots for the case of
    > > root pointers. A concept of "slot accessor" is introduced to share the
    > > code between these two modes, and writing the slot (including write
    > > barriers) is abstracted into this accessor.
    > >
    > > Finally, the Code body walk is modified to deserialize all objects
    > > referred to by RelocInfos before doing the RelocInfo walk itself. This
    > > is because RelocInfoIterator uses raw pointers, so we cannot allocate
    > > during a RelocInfo walk.
    > >
    > > As a drive-by, the VariableRawData bytecode is tweaked to use tagged
    > > size rather than byte size -- the size is expected to be tagged-aligned
    > > anyway, so now we get an extra few bits in the size encoding.
    > >
    > > Bug: chromium:1075999
    > > Change-Id: I672c42f553f2669888cc5e35d692c1b8ece1845e
    > > Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/2404451
    > > Commit-Queue: Leszek Swirski <leszeks@chromium.org>
    > > Reviewed-by: Jakob Gruber <jgruber@chromium.org>
    > > Reviewed-by: Ulan Degenbaev <ulan@chromium.org>
    > > Cr-Commit-Position: refs/heads/master@{#70229}
    >
    > Bug: chromium:1075999
    > Change-Id: Ibc77cc48b3440b4a28b09746cfc47e50c340ce54
    > Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/2440828
    > Commit-Queue: Leszek Swirski <leszeks@chromium.org>
    > Auto-Submit: Leszek Swirski <leszeks@chromium.org>
    > Reviewed-by: Ulan Degenbaev <ulan@chromium.org>
    > Reviewed-by: Jakob Gruber <jgruber@chromium.org>
    > Cr-Commit-Position: refs/heads/master@{#70267}
    
    Tbr: jgruber@chromium.org,ulan@chromium.org
    Bug: chromium:1075999
    Change-Id: Iaa8dc54895866ada0e34a7c9e8fff9ae1cb13f2d
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/2444991Reviewed-by: 's avatarUlan Degenbaev <ulan@chromium.org>
    Commit-Queue: Leszek Swirski <leszeks@chromium.org>
    Cr-Commit-Position: refs/heads/master@{#70279}
    c4a062a9
Name
Last commit
Last update
..
OWNERS Loading commit data...
allocation-site-inl.h Loading commit data...
allocation-site-scopes-inl.h Loading commit data...
allocation-site-scopes.h Loading commit data...
allocation-site.h Loading commit data...
allocation-site.tq Loading commit data...
api-callbacks-inl.h Loading commit data...
api-callbacks.h Loading commit data...
api-callbacks.tq Loading commit data...
arguments-inl.h Loading commit data...
arguments.h Loading commit data...
arguments.tq Loading commit data...
backing-store.cc Loading commit data...
backing-store.h Loading commit data...
bigint.cc Loading commit data...
bigint.h Loading commit data...
cell-inl.h Loading commit data...
cell.h Loading commit data...
cell.tq Loading commit data...
class-definitions-tq-deps-inl.h Loading commit data...
code-inl.h Loading commit data...
code-kind.cc Loading commit data...
code-kind.h Loading commit data...
code.cc Loading commit data...
code.h Loading commit data...
code.tq Loading commit data...
compilation-cache-inl.h Loading commit data...
compilation-cache.h Loading commit data...
compressed-slots-inl.h Loading commit data...
compressed-slots.h Loading commit data...
contexts-inl.h Loading commit data...
contexts.cc Loading commit data...
contexts.h Loading commit data...
contexts.tq Loading commit data...
data-handler-inl.h Loading commit data...
data-handler.h Loading commit data...
data-handler.tq Loading commit data...
debug-objects-inl.h Loading commit data...
debug-objects.cc Loading commit data...
debug-objects.h Loading commit data...
debug-objects.tq Loading commit data...
descriptor-array-inl.h Loading commit data...
descriptor-array.h Loading commit data...
descriptor-array.tq Loading commit data...
dictionary-inl.h Loading commit data...
dictionary.h Loading commit data...
elements-inl.h Loading commit data...
elements-kind.cc Loading commit data...
elements-kind.h Loading commit data...
elements.cc Loading commit data...
elements.h Loading commit data...
embedder-data-array-inl.h Loading commit data...
embedder-data-array.cc Loading commit data...
embedder-data-array.h Loading commit data...
embedder-data-array.tq Loading commit data...
embedder-data-slot-inl.h Loading commit data...
embedder-data-slot.h Loading commit data...
feedback-cell-inl.h Loading commit data...
feedback-cell.h Loading commit data...
feedback-cell.tq Loading commit data...
feedback-vector-inl.h Loading commit data...
feedback-vector.cc Loading commit data...
feedback-vector.h Loading commit data...
feedback-vector.tq Loading commit data...
field-index-inl.h Loading commit data...
field-index.h Loading commit data...
field-type.cc Loading commit data...
field-type.h Loading commit data...
fixed-array-inl.h Loading commit data...
fixed-array.h Loading commit data...
fixed-array.tq Loading commit data...
foreign-inl.h Loading commit data...
foreign.h Loading commit data...
foreign.tq Loading commit data...
frame-array-inl.h Loading commit data...
frame-array.h Loading commit data...
free-space-inl.h Loading commit data...
free-space.h Loading commit data...
free-space.tq Loading commit data...
function-kind.h Loading commit data...
function-syntax-kind.h Loading commit data...
hash-table-inl.h Loading commit data...
hash-table.h Loading commit data...
heap-number-inl.h Loading commit data...
heap-number.h Loading commit data...
heap-number.tq Loading commit data...
heap-object-inl.h Loading commit data...
heap-object.h Loading commit data...
heap-object.tq Loading commit data...
instance-type-inl.h Loading commit data...
instance-type.h Loading commit data...
internal-index.h Loading commit data...
intl-objects.cc Loading commit data...
intl-objects.h Loading commit data...
intl-objects.tq Loading commit data...
js-array-buffer-inl.h Loading commit data...
js-array-buffer.cc Loading commit data...
js-array-buffer.h Loading commit data...
js-array-buffer.tq Loading commit data...
js-array-inl.h Loading commit data...
js-array.h Loading commit data...
js-array.tq Loading commit data...
js-break-iterator-inl.h Loading commit data...
js-break-iterator.cc Loading commit data...
js-break-iterator.h Loading commit data...
js-collator-inl.h Loading commit data...
js-collator.cc Loading commit data...
js-collator.h Loading commit data...
js-collection-inl.h Loading commit data...
js-collection-iterator.h Loading commit data...
js-collection-iterator.tq Loading commit data...
js-collection.h Loading commit data...
js-collection.tq Loading commit data...
js-date-time-format-inl.h Loading commit data...
js-date-time-format.cc Loading commit data...
js-date-time-format.h Loading commit data...
js-display-names-inl.h Loading commit data...
js-display-names.cc Loading commit data...
js-display-names.h Loading commit data...
js-function-inl.h Loading commit data...
js-function.cc Loading commit data...
js-function.h Loading commit data...
js-generator-inl.h Loading commit data...
js-generator.h Loading commit data...
js-generator.tq Loading commit data...
js-list-format-inl.h Loading commit data...
js-list-format.cc Loading commit data...
js-list-format.h Loading commit data...
js-locale-inl.h Loading commit data...
js-locale.cc Loading commit data...
js-locale.h Loading commit data...
js-number-format-inl.h Loading commit data...
js-number-format.cc Loading commit data...
js-number-format.h Loading commit data...
js-objects-inl.h Loading commit data...
js-objects.cc Loading commit data...
js-objects.h Loading commit data...
js-objects.tq Loading commit data...
js-plural-rules-inl.h Loading commit data...
js-plural-rules.cc Loading commit data...
js-plural-rules.h Loading commit data...
js-promise-inl.h Loading commit data...
js-promise.h Loading commit data...
js-promise.tq Loading commit data...
js-proxy-inl.h Loading commit data...
js-proxy.h Loading commit data...
js-proxy.tq Loading commit data...
js-regexp-inl.h Loading commit data...
js-regexp-string-iterator-inl.h Loading commit data...
js-regexp-string-iterator.h Loading commit data...
js-regexp-string-iterator.tq Loading commit data...
js-regexp.cc Loading commit data...
js-regexp.h Loading commit data...
js-regexp.tq Loading commit data...
js-relative-time-format-inl.h Loading commit data...
js-relative-time-format.cc Loading commit data...
js-relative-time-format.h Loading commit data...
js-segment-iterator-inl.h Loading commit data...
js-segment-iterator.cc Loading commit data...
js-segment-iterator.h Loading commit data...
js-segmenter-inl.h Loading commit data...
js-segmenter.cc Loading commit data...
js-segmenter.h Loading commit data...
js-segments-inl.h Loading commit data...
js-segments.cc Loading commit data...
js-segments.h Loading commit data...
js-weak-refs-inl.h Loading commit data...
js-weak-refs.h Loading commit data...
js-weak-refs.tq Loading commit data...
keys.cc Loading commit data...
keys.h Loading commit data...
layout-descriptor-inl.h Loading commit data...
layout-descriptor.cc Loading commit data...
layout-descriptor.h Loading commit data...
literal-objects-inl.h Loading commit data...
literal-objects.cc Loading commit data...
literal-objects.h Loading commit data...
literal-objects.tq Loading commit data...
lookup-cache-inl.h Loading commit data...
lookup-cache.cc Loading commit data...
lookup-cache.h Loading commit data...
lookup-inl.h Loading commit data...
lookup.cc Loading commit data...
lookup.h Loading commit data...
managed.cc Loading commit data...
managed.h Loading commit data...
map-inl.h Loading commit data...
map-updater.cc Loading commit data...
map-updater.h Loading commit data...
map.cc Loading commit data...
map.h Loading commit data...
map.tq Loading commit data...
maybe-object-inl.h Loading commit data...
maybe-object.h Loading commit data...
microtask-inl.h Loading commit data...
microtask.h Loading commit data...
microtask.tq Loading commit data...
module-inl.h Loading commit data...
module.cc Loading commit data...
module.h Loading commit data...
module.tq Loading commit data...
name-inl.h Loading commit data...
name.h Loading commit data...
name.tq Loading commit data...
object-list-macros.h Loading commit data...
object-macros-undef.h Loading commit data...
object-macros.h Loading commit data...
objects-body-descriptors-inl.h Loading commit data...
objects-body-descriptors.h Loading commit data...
objects-definitions.h Loading commit data...
objects-inl.h Loading commit data...
objects.cc Loading commit data...
objects.h Loading commit data...
oddball-inl.h Loading commit data...
oddball.h Loading commit data...
oddball.tq Loading commit data...
ordered-hash-table-inl.h Loading commit data...
ordered-hash-table.cc Loading commit data...
ordered-hash-table.h Loading commit data...
ordered-hash-table.tq Loading commit data...
osr-optimized-code-cache-inl.h Loading commit data...
osr-optimized-code-cache.cc Loading commit data...
osr-optimized-code-cache.h Loading commit data...
primitive-heap-object-inl.h Loading commit data...
primitive-heap-object.h Loading commit data...
primitive-heap-object.tq Loading commit data...
promise-inl.h Loading commit data...
promise.h Loading commit data...
promise.tq Loading commit data...
property-array-inl.h Loading commit data...
property-array.h Loading commit data...
property-array.tq Loading commit data...
property-cell-inl.h Loading commit data...
property-cell.h Loading commit data...
property-cell.tq Loading commit data...
property-descriptor-object-inl.h Loading commit data...
property-descriptor-object.h Loading commit data...
property-descriptor-object.tq Loading commit data...
property-descriptor.cc Loading commit data...
property-descriptor.h Loading commit data...
property-details.h Loading commit data...
property.cc Loading commit data...
property.h Loading commit data...
prototype-info-inl.h Loading commit data...
prototype-info.h Loading commit data...
prototype-info.tq Loading commit data...
prototype-inl.h Loading commit data...
prototype.h Loading commit data...
regexp-match-info.h Loading commit data...
regexp-match-info.tq Loading commit data...
scope-info.cc Loading commit data...
scope-info.h Loading commit data...
scope-info.tq Loading commit data...
script-inl.h Loading commit data...
script.h Loading commit data...
script.tq Loading commit data...
shared-function-info-inl.h Loading commit data...
shared-function-info.cc Loading commit data...
shared-function-info.h Loading commit data...
shared-function-info.tq Loading commit data...
slots-atomic-inl.h Loading commit data...
slots-inl.h Loading commit data...
slots.h Loading commit data...
smi-inl.h Loading commit data...
smi.h Loading commit data...
source-text-module.cc Loading commit data...
source-text-module.h Loading commit data...
source-text-module.tq Loading commit data...
stack-frame-info-inl.h Loading commit data...
stack-frame-info.cc Loading commit data...
stack-frame-info.h Loading commit data...
stack-frame-info.tq Loading commit data...
string-comparator.cc Loading commit data...
string-comparator.h Loading commit data...
string-inl.h Loading commit data...
string-set-inl.h Loading commit data...
string-set.h Loading commit data...
string-table-inl.h Loading commit data...
string-table.cc Loading commit data...
string-table.h Loading commit data...
string.cc Loading commit data...
string.h Loading commit data...
string.tq Loading commit data...
struct-inl.h Loading commit data...
struct.h Loading commit data...
struct.tq Loading commit data...
synthetic-module.cc Loading commit data...
synthetic-module.h Loading commit data...
synthetic-module.tq Loading commit data...
tagged-field-inl.h Loading commit data...
tagged-field.h Loading commit data...
tagged-impl-inl.h Loading commit data...
tagged-impl.cc Loading commit data...
tagged-impl.h Loading commit data...
tagged-index.h Loading commit data...
tagged-value-inl.h Loading commit data...
tagged-value.h Loading commit data...
template-objects-inl.h Loading commit data...
template-objects.cc Loading commit data...
template-objects.h Loading commit data...
template-objects.tq Loading commit data...
template.tq Loading commit data...
templates-inl.h Loading commit data...
templates.h Loading commit data...
transitions-inl.h Loading commit data...
transitions.cc Loading commit data...
transitions.h Loading commit data...
type-hints.cc Loading commit data...
type-hints.h Loading commit data...
value-serializer.cc Loading commit data...
value-serializer.h Loading commit data...
visitors.cc Loading commit data...
visitors.h Loading commit data...