<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>157864</bug_id>
          
          <creation_ts>2016-05-18 15:18:15 -0700</creation_ts>
          <short_desc>Code that null checks the VM pointer before any use should ref the VM.</short_desc>
          <delta_ts>2016-05-19 14:04:16 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>JavaScriptCore</component>
          <version>WebKit Local Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Mark Lam">mark.lam</reporter>
          <assigned_to name="Mark Lam">mark.lam</assigned_to>
          <cc>benjamin</cc>
    
    <cc>commit-queue</cc>
    
    <cc>fpizlo</cc>
    
    <cc>ggaren</cc>
    
    <cc>keith_miller</cc>
    
    <cc>msaboff</cc>
    
    <cc>saam</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1194448</commentid>
    <comment_count>0</comment_count>
    <who name="Mark Lam">mark.lam</who>
    <bug_when>2016-05-18 15:18:15 -0700</bug_when>
    <thetext>Specifically, in JSLock::willReleaseLock() and HeapTimer::timerDidFire().  Otherwise, there&apos;s no guarantee that the VM won&apos;t be deleted after the null check.

Patch coming.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1194451</commentid>
    <comment_count>1</comment_count>
    <who name="Mark Lam">mark.lam</who>
    <bug_when>2016-05-18 15:21:28 -0700</bug_when>
    <thetext>&lt;rdar://problem/26129156&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1194466</commentid>
    <comment_count>2</comment_count>
      <attachid>279304</attachid>
    <who name="Mark Lam">mark.lam</who>
    <bug_when>2016-05-18 15:45:45 -0700</bug_when>
    <thetext>Created attachment 279304
proposed patch.

Still need to run tests.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1194467</commentid>
    <comment_count>3</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2016-05-18 15:48:00 -0700</bug_when>
    <thetext>Attachment 279304 did not pass style-queue:


ERROR: Source/JavaScriptCore/runtime/JSLock.cpp:180:  &apos;vm&apos; is incorrectly named. It should be named &apos;protector&apos; or &apos;protectedVm&apos;.  [readability/naming/protected] [4]
Total errors found: 1 in 4 files


If any of these errors are false positives, please file a bug against check-webkit-style.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1194469</commentid>
    <comment_count>4</comment_count>
      <attachid>279304</attachid>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2016-05-18 15:49:04 -0700</bug_when>
    <thetext>Comment on attachment 279304
proposed patch.

Nice!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1194475</commentid>
    <comment_count>5</comment_count>
      <attachid>279304</attachid>
    <who name="Keith Miller">keith_miller</who>
    <bug_when>2016-05-18 15:54:31 -0700</bug_when>
    <thetext>Comment on attachment 279304
proposed patch.

View in context: https://bugs.webkit.org/attachment.cgi?id=279304&amp;action=review

&gt; Source/JavaScriptCore/ChangeLog:3
&gt; +        Code that need to null check the VM pointer before use should ref the VM.

I think this would be less confusing as &quot;Code that null checks the VM pointer before any use should ref the VM.&quot;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1194476</commentid>
    <comment_count>6</comment_count>
      <attachid>279304</attachid>
    <who name="Keith Miller">keith_miller</who>
    <bug_when>2016-05-18 15:55:00 -0700</bug_when>
    <thetext>Comment on attachment 279304
proposed patch.

r=me too.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1194502</commentid>
    <comment_count>7</comment_count>
    <who name="Mark Lam">mark.lam</who>
    <bug_when>2016-05-18 16:27:10 -0700</bug_when>
    <thetext>(In reply to comment #5)
&gt; Comment on attachment 279304 [details]
&gt; proposed patch.
&gt; 
&gt; View in context:
&gt; https://bugs.webkit.org/attachment.cgi?id=279304&amp;action=review
&gt; 
&gt; &gt; Source/JavaScriptCore/ChangeLog:3
&gt; &gt; +        Code that need to null check the VM pointer before use should ref the VM.
&gt; 
&gt; I think this would be less confusing as &quot;Code that null checks the VM
&gt; pointer before any use should ref the VM.&quot;

I&apos;ll make the change.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1194933</commentid>
    <comment_count>8</comment_count>
    <who name="Mark Lam">mark.lam</who>
    <bug_when>2016-05-19 14:03:35 -0700</bug_when>
    <thetext>The patch has passed the layout tests and JSC tests on x86_64.  I also did an ad hoc smoke test by running a few apps with it on ARM64.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1194934</commentid>
    <comment_count>9</comment_count>
    <who name="Mark Lam">mark.lam</who>
    <bug_when>2016-05-19 14:04:16 -0700</bug_when>
    <thetext>Landed in r201180: &lt;http://trac.webkit.org/r201180&gt;.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>279304</attachid>
            <date>2016-05-18 15:45:45 -0700</date>
            <delta_ts>2016-05-18 15:55:00 -0700</delta_ts>
            <desc>proposed patch.</desc>
            <filename>bug-157864.patch</filename>
            <type>text/plain</type>
            <size>3736</size>
            <attacher name="Mark Lam">mark.lam</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9KYXZhU2NyaXB0Q29yZS9DaGFuZ2VMb2cKPT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291
cmNlL0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkocmV2aXNpb24gMjAxMTAxKQorKysgU291cmNl
L0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDI4IEBA
CisyMDE2LTA1LTE4ICBNYXJrIExhbSAgPG1hcmsubGFtQGFwcGxlLmNvbT4KKworICAgICAgICBD
b2RlIHRoYXQgbmVlZCB0byBudWxsIGNoZWNrIHRoZSBWTSBwb2ludGVyIGJlZm9yZSB1c2Ugc2hv
dWxkIHJlZiB0aGUgVk0uCisgICAgICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVn
LmNnaT9pZD0xNTc4NjQKKworICAgICAgICBSZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKwor
ICAgICAgICBKU0xvY2s6OndpbGxSZWxlYXNlTG9jaygpIGFuZCBIZWFwVGltZXI6OnRpbWVyRGlk
RmlyZSgpIG5lZWQgdG8gcmVmZXJlbmNlIHRoZSBWTQorICAgICAgICB0aHJvdWdoIGEgUmVmUHRy
LiAgT3RoZXJ3aXNlLCB0aGVyZSdzIG5vIGd1YXJhbnRlZSB0aGF0IHRoZSBWTSB3b24ndCBiZSBk
ZWxldGVkCisgICAgICAgIGFmdGVyIHRoZWlyIG51bGwgY2hlY2tzLgorCisgICAgICAgICogYnl0
ZWNvZGUvQ29kZUJsb2NrLmg6CisgICAgICAgIChKU0M6OkNvZGVCbG9jazo6dm0pOgorICAgICAg
ICAoSlNDOjpDb2RlQmxvY2s6OnNldFZNKTogRGVsZXRlZC4KKyAgICAgICAgLSBOb3QgdXNlZCwg
YW5kIHN1Z2dlc3RzIHRoYXQgaXQgY2FuIGJlIGNoYW5nZWQgZHVyaW5nIHRoZSBsaWZldGltZSBv
ZiB0aGUKKyAgICAgICAgICBDb2RlQmxvY2sgKHdoaWNoIHNob3VsZCBub3QgYmUpLgorCisgICAg
ICAgICogaGVhcC9IZWFwVGltZXIuY3BwOgorICAgICAgICAoSlNDOjpIZWFwVGltZXI6OnRpbWVy
RGlkRmlyZSk6CisgICAgICAgICogcnVudGltZS9KU0xvY2suY3BwOgorICAgICAgICAoSlNDOjpK
U0xvY2s6OndpbGxSZWxlYXNlTG9jayk6CisgICAgICAgIC0gU3RvcmUgdGhlIFZNIHBvaW50ZXIg
aW4gYSBSZWZQdHIgZmlyc3QsIGFuZCBudWxsIGNoZWNrIHRoZSBSZWZQdHIgaW5zdGVhZCBvZgor
ICAgICAgICAgIHRoZSByYXcgVk0gcG9pbnRlci4gIFRoaXMgbWFrZXMgdGhlIG51bGwgY2hlY2sg
YSBzdHJvbmcgZ3VhcmFudGVlIHRoYXQgdGhlCisgICAgICAgICAgVk0gcG9pbnRlciBpcyB2YWxp
ZCB3aGlsZSB0aGVzZSBmdW5jdGlvbnMgYXJlIHVzaW5nIGl0LgorCiAyMDE2LTA1LTE4ICBZdXN1
a2UgU3V6dWtpICA8dXRhdGFuZS50ZWFAZ21haWwuY29tPgogCiAgICAgICAgIFtFUzZdIE5hbWVz
cGFjZSBvYmplY3QgcmUtZXhwb3J0IHNob3VsZCBiZSBoYW5kbGVkIGFzIGxvY2FsIGV4cG9ydApJ
bmRleDogU291cmNlL0phdmFTY3JpcHRDb3JlL2J5dGVjb2RlL0NvZGVCbG9jay5oCj09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT0KLS0tIFNvdXJjZS9KYXZhU2NyaXB0Q29yZS9ieXRlY29kZS9Db2RlQmxvY2suaAkocmV2aXNp
b24gMjAxMTAxKQorKysgU291cmNlL0phdmFTY3JpcHRDb3JlL2J5dGVjb2RlL0NvZGVCbG9jay5o
CSh3b3JraW5nIGNvcHkpCkBAIC0zNDAsOCArMzQwLDcgQEAgcHVibGljOgogICAgIEV4ZWN1dGFi
bGVCYXNlKiBvd25lckV4ZWN1dGFibGUoKSBjb25zdCB7IHJldHVybiBtX293bmVyRXhlY3V0YWJs
ZS5nZXQoKTsgfQogICAgIFNjcmlwdEV4ZWN1dGFibGUqIG93bmVyU2NyaXB0RXhlY3V0YWJsZSgp
IGNvbnN0IHsgcmV0dXJuIGpzQ2FzdDxTY3JpcHRFeGVjdXRhYmxlKj4obV9vd25lckV4ZWN1dGFi
bGUuZ2V0KCkpOyB9CiAKLSAgICB2b2lkIHNldFZNKFZNKiB2bSkgeyBtX3ZtID0gdm07IH0KLSAg
ICBWTSogdm0oKSB7IHJldHVybiBtX3ZtOyB9CisgICAgVk0qIHZtKCkgY29uc3QgeyByZXR1cm4g
bV92bTsgfQogCiAgICAgdm9pZCBzZXRUaGlzUmVnaXN0ZXIoVmlydHVhbFJlZ2lzdGVyIHRoaXNS
ZWdpc3RlcikgeyBtX3RoaXNSZWdpc3RlciA9IHRoaXNSZWdpc3RlcjsgfQogICAgIFZpcnR1YWxS
ZWdpc3RlciB0aGlzUmVnaXN0ZXIoKSBjb25zdCB7IHJldHVybiBtX3RoaXNSZWdpc3RlcjsgfQpJ
bmRleDogU291cmNlL0phdmFTY3JpcHRDb3JlL2hlYXAvSGVhcFRpbWVyLmNwcAo9PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
Ci0tLSBTb3VyY2UvSmF2YVNjcmlwdENvcmUvaGVhcC9IZWFwVGltZXIuY3BwCShyZXZpc2lvbiAy
MDExMDEpCisrKyBTb3VyY2UvSmF2YVNjcmlwdENvcmUvaGVhcC9IZWFwVGltZXIuY3BwCSh3b3Jr
aW5nIGNvcHkpCkBAIC04MCw5ICs4MCw5IEBAIHZvaWQgSGVhcFRpbWVyOjp0aW1lckRpZEZpcmUo
Q0ZSdW5Mb29wVGkKICAgICBKU0xvY2sqIGFwaUxvY2sgPSBzdGF0aWNfY2FzdDxKU0xvY2sqPihj
b250ZXh0KTsKICAgICBhcGlMb2NrLT5sb2NrKCk7CiAKLSAgICBWTSogdm0gPSBhcGlMb2NrLT52
bSgpOwotICAgIC8vIFRoZSBWTSBoYXMgYmVlbiBkZXN0cm95ZWQsIHNvIHdlIHNob3VsZCBqdXN0
IGdpdmUgdXAuCisgICAgUmVmUHRyPFZNPiB2bSA9IGFwaUxvY2stPnZtKCk7CiAgICAgaWYgKCF2
bSkgeworICAgICAgICAvLyBUaGUgVk0gaGFzIGJlZW4gZGVzdHJveWVkLCBzbyB3ZSBzaG91bGQg
anVzdCBnaXZlIHVwLgogICAgICAgICBhcGlMb2NrLT51bmxvY2soKTsKICAgICAgICAgcmV0dXJu
OwogICAgIH0KQEAgLTk4LDcgKzk4LDcgQEAgdm9pZCBIZWFwVGltZXI6OnRpbWVyRGlkRmlyZShD
RlJ1bkxvb3BUaQogICAgICAgICBSRUxFQVNFX0FTU0VSVF9OT1RfUkVBQ0hFRCgpOwogCiAgICAg
ewotICAgICAgICBKU0xvY2tIb2xkZXIgbG9ja2VyKHZtKTsKKyAgICAgICAgSlNMb2NrSG9sZGVy
IGxvY2tlcih2bS5nZXQoKSk7CiAgICAgICAgIGhlYXBUaW1lci0+ZG9Xb3JrKCk7CiAgICAgfQog
CkluZGV4OiBTb3VyY2UvSmF2YVNjcmlwdENvcmUvcnVudGltZS9KU0xvY2suY3BwCj09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT0KLS0tIFNvdXJjZS9KYXZhU2NyaXB0Q29yZS9ydW50aW1lL0pTTG9jay5jcHAJKHJldmlzaW9u
IDIwMTEwMSkKKysrIFNvdXJjZS9KYXZhU2NyaXB0Q29yZS9ydW50aW1lL0pTTG9jay5jcHAJKHdv
cmtpbmcgY29weSkKQEAgLTE3NywxMSArMTc3LDEyIEBAIHZvaWQgSlNMb2NrOjp1bmxvY2soaW50
cHRyX3QgdW5sb2NrQ291bnQKIAogdm9pZCBKU0xvY2s6OndpbGxSZWxlYXNlTG9jaygpCiB7Ci0g
ICAgaWYgKG1fdm0pIHsKLSAgICAgICAgbV92bS0+ZHJhaW5NaWNyb3Rhc2tzKCk7CisgICAgUmVm
UHRyPFZNPiB2bSA9IG1fdm07CisgICAgaWYgKHZtKSB7CisgICAgICAgIHZtLT5kcmFpbk1pY3Jv
dGFza3MoKTsKIAotICAgICAgICBtX3ZtLT5oZWFwLnJlbGVhc2VEZWxheWVkUmVsZWFzZWRPYmpl
Y3RzKCk7Ci0gICAgICAgIG1fdm0tPnNldFN0YWNrUG9pbnRlckF0Vk1FbnRyeShudWxscHRyKTsK
KyAgICAgICAgdm0tPmhlYXAucmVsZWFzZURlbGF5ZWRSZWxlYXNlZE9iamVjdHMoKTsKKyAgICAg
ICAgdm0tPnNldFN0YWNrUG9pbnRlckF0Vk1FbnRyeShudWxscHRyKTsKICAgICB9CiAKICAgICBp
ZiAobV9lbnRyeUF0b21pY1N0cmluZ1RhYmxlKSB7Cg==
</data>
<flag name="review"
          id="303364"
          type_id="1"
          status="+"
          setter="keith_miller"
    />
          </attachment>
      

    </bug>

</bugzilla>