[JSC] DFG::CommonData modification by DFG reallyAdd should be guarded by CodeBlock's lock
Created attachment 381354 [details] Patch
<rdar://problem/56404068>
Created attachment 381356 [details] Patch
Comment on attachment 381356 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=381356&action=review r=me. > Source/JavaScriptCore/dfg/DFGDesiredGlobalProperties.cpp:69 > + watchpointSet.add(watchpoint); Why not WTFMove(watchpoint) here too? > JSTests/stress/dfg-really-add-locking.js:1 > +//@ runDefault("--collectContinuously=1", "--useGenerationalGC=0") How long does this test take to run? if it's a slow test, then consider adding "//@ slow!" here too.
Comment on attachment 381356 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=381356&action=review >> Source/JavaScriptCore/dfg/DFGDesiredGlobalProperties.cpp:69 >> + watchpointSet.add(watchpoint); > > Why not WTFMove(watchpoint) here too? Fixed. >> JSTests/stress/dfg-really-add-locking.js:1 >> +//@ runDefault("--collectContinuously=1", "--useGenerationalGC=0") > > How long does this test take to run? if it's a slow test, then consider adding "//@ slow!" here too. It takes not so much time, but to make more reliable, I need to add more iterations. I'll add `for (var i = 0; i < 10; ++i)` while adding `slow!`. But even though, reliable reproduce is requiring much more repeated test runs.
Committed r251321: <https://trac.webkit.org/changeset/251321>