<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>205086</bug_id>
          
          <creation_ts>2019-12-10 14:49:38 -0800</creation_ts>
          <short_desc>Worklist::deleteCancelledPlansForVM() should not assume that a cancelled plan is ready for deletion.</short_desc>
          <delta_ts>2019-12-10 17:45:39 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>JavaScriptCore</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Mark Lam">mark.lam</reporter>
          <assigned_to name="Mark Lam">mark.lam</assigned_to>
          <cc>ews-watchlist</cc>
    
    <cc>keith_miller</cc>
    
    <cc>msaboff</cc>
    
    <cc>saam</cc>
    
    <cc>tzagallo</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1597357</commentid>
    <comment_count>0</comment_count>
    <who name="Mark Lam">mark.lam</who>
    <bug_when>2019-12-10 14:49:38 -0800</bug_when>
    <thetext>Another thread may still have a reference to the cancelled plan and hasn&apos;t released it yet.

&lt;rdar://problem/57795002&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1597423</commentid>
    <comment_count>1</comment_count>
      <attachid>385319</attachid>
    <who name="Mark Lam">mark.lam</who>
    <bug_when>2019-12-10 16:57:34 -0800</bug_when>
    <thetext>Created attachment 385319
proposed patch.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1597430</commentid>
    <comment_count>2</comment_count>
      <attachid>385319</attachid>
    <who name="Saam Barati">saam</who>
    <bug_when>2019-12-10 17:02:01 -0800</bug_when>
    <thetext>Comment on attachment 385319
proposed patch.

View in context: https://bugs.webkit.org/attachment.cgi?id=385319&amp;action=review

&gt; Source/JavaScriptCore/dfg/DFGWorklist.cpp:310
&gt;      HashSet&lt;RefPtr&lt;Plan&gt;&gt; removedPlans;

this shouldn&apos;t be a HashSet, right?

&gt; Source/JavaScriptCore/dfg/DFGWorklist.cpp:318
&gt; +        removedPlans.add(WTFMove(plan));

isn&apos;t this easier to just append only when ref count is 1?

like:
Plan* plan = m_cancelledPlansPendingDestruction[I].get();
if (plan-&gt;refCount() == 1) removedPlans.append(...)

and remove the +1 ref in the above code</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1597432</commentid>
    <comment_count>3</comment_count>
      <attachid>385319</attachid>
    <who name="Mark Lam">mark.lam</who>
    <bug_when>2019-12-10 17:05:43 -0800</bug_when>
    <thetext>Comment on attachment 385319
proposed patch.

View in context: https://bugs.webkit.org/attachment.cgi?id=385319&amp;action=review

&gt;&gt; Source/JavaScriptCore/dfg/DFGWorklist.cpp:310
&gt;&gt;      HashSet&lt;RefPtr&lt;Plan&gt;&gt; removedPlans;
&gt; 
&gt; this shouldn&apos;t be a HashSet, right?

This should be a HashSet because (as I explained offline previously for the original patch) there&apos;s a chance that the GC thread cancels the plan and appends it to m_cancelledPlansPendingDestruction, and then the compiler thread sees it and appends it to m_cancelledPlansPendingDestruction again before the mutator can iterate m_cancelledPlansPendingDestruction.  As a result, the same plan may show up in m_cancelledPlansPendingDestruction more than once, but we only want to add it to removedPlans once.

&gt;&gt; Source/JavaScriptCore/dfg/DFGWorklist.cpp:318
&gt;&gt; +        removedPlans.add(WTFMove(plan));
&gt; 
&gt; isn&apos;t this easier to just append only when ref count is 1?
&gt; 
&gt; like:
&gt; Plan* plan = m_cancelledPlansPendingDestruction[I].get();
&gt; if (plan-&gt;refCount() == 1) removedPlans.append(...)
&gt; 
&gt; and remove the +1 ref in the above code

Good point.  I will change the fix.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1597433</commentid>
    <comment_count>4</comment_count>
      <attachid>385319</attachid>
    <who name="Mark Lam">mark.lam</who>
    <bug_when>2019-12-10 17:07:51 -0800</bug_when>
    <thetext>Comment on attachment 385319
proposed patch.

View in context: https://bugs.webkit.org/attachment.cgi?id=385319&amp;action=review

&gt;&gt;&gt; Source/JavaScriptCore/dfg/DFGWorklist.cpp:318
&gt;&gt;&gt; +        removedPlans.add(WTFMove(plan));
&gt;&gt; 
&gt;&gt; isn&apos;t this easier to just append only when ref count is 1?
&gt;&gt; 
&gt;&gt; like:
&gt;&gt; Plan* plan = m_cancelledPlansPendingDestruction[I].get();
&gt;&gt; if (plan-&gt;refCount() == 1) removedPlans.append(...)
&gt;&gt; 
&gt;&gt; and remove the +1 ref in the above code
&gt; 
&gt; Good point.  I will change the fix.

I take this back.  Because the plan can appear in m_cancelledPlansPendingDestruction more than once, this scheme won&apos;t work.  We have to filter it through the HashSet.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1597449</commentid>
    <comment_count>5</comment_count>
      <attachid>385319</attachid>
    <who name="Saam Barati">saam</who>
    <bug_when>2019-12-10 17:34:42 -0800</bug_when>
    <thetext>Comment on attachment 385319
proposed patch.

View in context: https://bugs.webkit.org/attachment.cgi?id=385319&amp;action=review

&gt; Source/JavaScriptCore/dfg/DFGWorklist.cpp:323
&gt;          RELEASE_ASSERT(plan-&gt;stage() == Plan::Cancelled);

should we make this a debug assert like before?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1597453</commentid>
    <comment_count>6</comment_count>
    <who name="Mark Lam">mark.lam</who>
    <bug_when>2019-12-10 17:42:37 -0800</bug_when>
    <thetext>(In reply to Saam Barati from comment #5)
&gt; Comment on attachment 385319 [details]
&gt; proposed patch.
&gt; 
&gt; View in context:
&gt; https://bugs.webkit.org/attachment.cgi?id=385319&amp;action=review
&gt; 
&gt; &gt; Source/JavaScriptCore/dfg/DFGWorklist.cpp:323
&gt; &gt;          RELEASE_ASSERT(plan-&gt;stage() == Plan::Cancelled);
&gt; 
&gt; should we make this a debug assert like before?

I&apos;ll change this to a debug assert.  I also added a comment explaining how we can have the same cancelled plan appear more than once in m_cancelledPlansPendingDestruction, and why we need to filter it through the HashSet.  The fact that you asked about it shows that we&apos;ll probably forget about this detail in the future.  Hence, a comment is needed to document it for posterity.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1597456</commentid>
    <comment_count>7</comment_count>
    <who name="Mark Lam">mark.lam</who>
    <bug_when>2019-12-10 17:45:39 -0800</bug_when>
    <thetext>Thanks for the review.  Landed in r253358: &lt;http://trac.webkit.org/r253358&gt;.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>385319</attachid>
            <date>2019-12-10 16:57:34 -0800</date>
            <delta_ts>2019-12-10 17:34:42 -0800</delta_ts>
            <desc>proposed patch.</desc>
            <filename>bug-205086.patch</filename>
            <type>text/plain</type>
            <size>4012</size>
            <attacher name="Mark Lam">mark.lam</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9KYXZhU2NyaXB0Q29yZS9DaGFuZ2VMb2cKPT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291
cmNlL0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkocmV2aXNpb24gMjUzMzU0KQorKysgU291cmNl
L0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDM2IEBA
CisyMDE5LTEyLTEwICBNYXJrIExhbSAgPG1hcmsubGFtQGFwcGxlLmNvbT4KKworICAgICAgICBX
b3JrbGlzdDo6ZGVsZXRlQ2FuY2VsbGVkUGxhbnNGb3JWTSgpIHNob3VsZCBub3QgYXNzdW1lIHRo
YXQgYSBjYW5jZWxsZWQgcGxhbiBpcyByZWFkeSBmb3IgZGVsZXRpb24uCisgICAgICAgIGh0dHBz
Oi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0yMDUwODYKKyAgICAgICAgPHJkYXI6
Ly9wcm9ibGVtLzU3Nzk1MDAyPgorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEp
LgorCisgICAgICAgIENvbnNpZGVyIHRoaXMgcmFjZSBzY2VuYXJpbzoKKyAgICAgICAgMS4gVGhl
IERGRyB0aHJlYWQgZmluZHMgYSBwbGFuIGFuZCBzdGFydGVkIGNvbXBpbGluZywgYW5kIGl0J3Mg
aG9sZGluZyBhIHJlZiB0bworICAgICAgICAgICB0aGUgcGxhbiB3aGlsZSBpdCdzIGNvbXBpbGlu
Zy4KKyAgICAgICAgMi4gVGhlIEdDIHRocmVhZCBkaXNjb3ZlcnMgdGhhdCB3ZSBubyBsb25nZXIg
bmVlZCB0aGUgcGxhbiBhbmQgY2FuY2VscyBpdC4KKyAgICAgICAgMy4gQWZ0ZXIgdGhlIHBsYW4g
aXMgY2FuY2VsbGVkIGJ1dCB3aGlsZSB0aGUgREZHIHRocmVhZCBpcyBzdGlsbCBjb21waWxpbmcs
IHRoZQorICAgICAgICAgICBtdXRhdG9yIHRocmVhZCBjYWxscyBXb3JrbGlzdDo6ZGVsZXRlQ2Fu
Y2VsbGVkUGxhbnNGb3JWTSgpLgorCisgICAgICAgICAgIFdvcmtsaXN0OjpkZWxldGVDYW5jZWxs
ZWRQbGFuc0ZvclZNKCkgd2FzIGFzc3VtaW5nIHRoYXQgYnkgdGhlIHRpbWUgaXQgaXMKKyAgICAg
ICAgICAgY2FsbGVkLCBXb3JrbGlzdDo6bV9jYW5jZWxsZWRQbGFuc1BlbmRpbmdEZXN0cnVjdGlv
biB3aWxsIGNvbnRhaW4gdGhlIGxhc3QgcmVmCisgICAgICAgICAgIHRvIHRoZSBjYW5jZWxsZWQg
cGxhbi4gIEhvd2V2ZXIsIHRoaXMgaXMgYW4gaW5jb3JyZWN0IGFzc3VtcHRpb24sIGFuZCB0aGUK
KyAgICAgICAgICAgYXNzZXJ0aW9uIHRoZXJlIHRoYXQgYXNzZXJ0cyByZWZDb3VudCA9PSAxIHdp
bGwgZmFpbC4KKworICAgICAgICBUaGlzIHBhdGNoIGZpeGVzIFdvcmtsaXN0OjpkZWxldGVDYW5j
ZWxsZWRQbGFuc0ZvclZNKCkgdG8gYXBwZW5kIHRoZSBjYW5jZWxsZWQKKyAgICAgICAgcGxhbiBi
YWNrIGludG8gbV9jYW5jZWxsZWRQbGFuc1BlbmRpbmdEZXN0cnVjdGlvbiBpZiBpdHMgcmVmQ291
bnQgaXMgbm90IDEKKyAgICAgICAgKGltcGx5aW5nIHRoYXQgdGhlIGNvbXBpbGVyIHRocmVhZCBz
dGlsbCBoYXMgYSByZWYgdG8gaXQpLCBhbmQgZGVmZXIgZGVsZXRpb24gb2YKKyAgICAgICAgdGhl
IHBsYW4gdG8gYSBzdWJzZXF1ZW50IGNhbGwgdG8gZGVsZXRlQ2FuY2VsbGVkUGxhbnNGb3JWTSgp
LgorCisgICAgICAgIFRoaXMgcGF0Y2ggYWxzbyBhZGRzIGEgV1RGTW92ZSB0byBXb3JrbGlzdDo6
cmVtb3ZlRGVhZFBsYW5zKCkgd2hlbiB3ZSBhcHBlbmQgdGhlCisgICAgICAgIGNhbmNlbGxlZCBw
bGFuIHRvIG1fY2FuY2VsbGVkUGxhbnNQZW5kaW5nRGVzdHJ1Y3Rpb24gdGhlcmUuICBUaGlzIHNh
dmVzIHVzIG9uZQorICAgICAgICB1bm5lY2Vzc2FyeSByZWYgYW5kIGRlcmVmIG9mIHRoZSBwbGFu
LgorCisgICAgICAgICogZGZnL0RGR1dvcmtsaXN0LmNwcDoKKyAgICAgICAgKEpTQzo6REZHOjpX
b3JrbGlzdDo6ZGVsZXRlQ2FuY2VsbGVkUGxhbnNGb3JWTSk6CisgICAgICAgIChKU0M6OkRGRzo6
V29ya2xpc3Q6OnJlbW92ZURlYWRQbGFucyk6CisKIDIwMTktMTItMTAgIFNhYW0gQmFyYXRpICA8
c2JhcmF0aUBhcHBsZS5jb20+CiAKICAgICAgICAgbWV0aG9kT2ZHZXR0aW5nQVZhbHVlUHJvZmls
ZUZvciBzaG91bGQgcmV0dXJuIGFyZ3VtZW50IHZhbHVlIHByb2ZpbGVzIGV2ZW4gd2hlbiBub2Rl
IGFuZCBvcGVyYW5kTm9kZSBhcmUgdGhlIHNhbWUgb3JpZ2luCkluZGV4OiBTb3VyY2UvSmF2YVNj
cmlwdENvcmUvZGZnL0RGR1dvcmtsaXN0LmNwcAo9PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBTb3VyY2UvSmF2YVNj
cmlwdENvcmUvZGZnL0RGR1dvcmtsaXN0LmNwcAkocmV2aXNpb24gMjUzMzE5KQorKysgU291cmNl
L0phdmFTY3JpcHRDb3JlL2RmZy9ERkdXb3JrbGlzdC5jcHAJKHdvcmtpbmcgY29weSkKQEAgLTMw
Nyw5ICszMDcsNyBAQCB2b2lkIFdvcmtsaXN0Ojp3YWl0VW50aWxBbGxQbGFuc0ZvclZNQXJlCiB2
b2lkIFdvcmtsaXN0OjpkZWxldGVDYW5jZWxsZWRQbGFuc0ZvclZNKExvY2tIb2xkZXImLCBWTSYg
dm0pCiB7CiAgICAgUkVMRUFTRV9BU1NFUlQodm0uY3VycmVudFRocmVhZElzSG9sZGluZ0FQSUxv
Y2soKSk7Ci0jaWYgIUFTU0VSVF9ESVNBQkxFRAogICAgIEhhc2hTZXQ8UmVmUHRyPFBsYW4+PiBy
ZW1vdmVkUGxhbnM7Ci0jZW5kaWYKIAogICAgIGZvciAoc2l6ZV90IGkgPSAwOyBpIDwgbV9jYW5j
ZWxsZWRQbGFuc1BlbmRpbmdEZXN0cnVjdGlvbi5zaXplKCk7ICsraSkgewogICAgICAgICBSZWZQ
dHI8UGxhbj4gcGxhbiA9IG1fY2FuY2VsbGVkUGxhbnNQZW5kaW5nRGVzdHJ1Y3Rpb25baV07CkBA
IC0zMTcsMTggKzMxNSwxNSBAQCB2b2lkIFdvcmtsaXN0OjpkZWxldGVDYW5jZWxsZWRQbGFuc0Zv
clZNCiAgICAgICAgICAgICBjb250aW51ZTsKICAgICAgICAgbV9jYW5jZWxsZWRQbGFuc1BlbmRp
bmdEZXN0cnVjdGlvbltpLS1dID0gbV9jYW5jZWxsZWRQbGFuc1BlbmRpbmdEZXN0cnVjdGlvbi5s
YXN0KCk7CiAgICAgICAgIG1fY2FuY2VsbGVkUGxhbnNQZW5kaW5nRGVzdHJ1Y3Rpb24ucmVtb3Zl
TGFzdCgpOwotI2lmICFBU1NFUlRfRElTQUJMRUQKLSAgICAgICAgcmVtb3ZlZFBsYW5zLmFkZChw
bGFuKTsKLSNlbmRpZgorICAgICAgICByZW1vdmVkUGxhbnMuYWRkKFdURk1vdmUocGxhbikpOwog
ICAgIH0KIAotI2lmICFBU1NFUlRfRElTQUJMRUQKICAgICB3aGlsZSAoIXJlbW92ZWRQbGFucy5p
c0VtcHR5KCkpIHsKICAgICAgICAgUmVmUHRyPFBsYW4+IHBsYW4gPSByZW1vdmVkUGxhbnMudGFr
ZUFueSgpOwogICAgICAgICBSRUxFQVNFX0FTU0VSVChwbGFuLT5zdGFnZSgpID09IFBsYW46OkNh
bmNlbGxlZCk7Ci0gICAgICAgIFJFTEVBU0VfQVNTRVJUKHBsYW4tPnJlZkNvdW50KCkgPT0gMSk7
CisgICAgICAgIGlmIChwbGFuLT5yZWZDb3VudCgpID4gMSkKKyAgICAgICAgICAgIG1fY2FuY2Vs
bGVkUGxhbnNQZW5kaW5nRGVzdHJ1Y3Rpb24uYXBwZW5kKFdURk1vdmUocGxhbikpOwogICAgIH0K
LSNlbmRpZgogfQogCiB2b2lkIFdvcmtsaXN0OjpyZW1vdmVBbGxSZWFkeVBsYW5zRm9yVk0oVk0m
IHZtLCBWZWN0b3I8UmVmUHRyPFBsYW4+LCA4PiYgbXlSZWFkeVBsYW5zKQpAQCAtNDU5LDcgKzQ1
NCw3IEBAIHZvaWQgV29ya2xpc3Q6OnJlbW92ZURlYWRQbGFucyhWTSYgdm0pCiAgICAgICAgICAg
ICAgICAgUmVmUHRyPFBsYW4+IHBsYW4gPSBtX3BsYW5zLnRha2UoKml0ZXIpOwogICAgICAgICAg
ICAgICAgIHBsYW4tPmNhbmNlbCgpOwogICAgICAgICAgICAgICAgIGlmICghaXNJbk11dGF0b3Ip
Ci0gICAgICAgICAgICAgICAgICAgIG1fY2FuY2VsbGVkUGxhbnNQZW5kaW5nRGVzdHJ1Y3Rpb24u
YXBwZW5kKHBsYW4pOworICAgICAgICAgICAgICAgICAgICBtX2NhbmNlbGxlZFBsYW5zUGVuZGlu
Z0Rlc3RydWN0aW9uLmFwcGVuZChXVEZNb3ZlKHBsYW4pKTsKICAgICAgICAgICAgIH0KICAgICAg
ICAgICAgIERlcXVlPFJlZlB0cjxQbGFuPj4gbmV3UXVldWU7CiAgICAgICAgICAgICB3aGlsZSAo
IW1fcXVldWUuaXNFbXB0eSgpKSB7Cg==
</data>
<flag name="review"
          id="401160"
          type_id="1"
          status="+"
          setter="saam"
    />
          </attachment>
      

    </bug>

</bugzilla>