This is because cached unlinked baseline JIT code would retain a pointer to those counters. Hence, the UnlinkedCodeBlock should do the add /remove of the counters instead. rdar://83571235
Created attachment 440157 [details] proposed patch.
Created attachment 440158 [details] proposed patch.
Comment on attachment 440158 [details] proposed patch. View in context: https://bugs.webkit.org/attachment.cgi?id=440158&action=review r=me > Source/JavaScriptCore/bytecode/UnlinkedCodeBlock.h:144 > + void finalize(); Suggestion: “finalize” has some common meaning in cells, typically meaning doing some finalization work at the end of GC. Because of that, I’m not a fan of this name. And right now, it’s only doing one very specific thing. I suggest giving it a specific name to match the specific thing it’s doing.
Thanks for the review. (In reply to Saam Barati from comment #4) > > Source/JavaScriptCore/bytecode/UnlinkedCodeBlock.h:144 > > + void finalize(); > > Suggestion: “finalize” has some common meaning in cells, typically meaning > doing some finalization work at the end of GC. Because of that, I’m not a > fan of this name. And right now, it’s only doing one very specific thing. I > suggest giving it a specific name to match the specific thing it’s doing. I've renamed it to initializeLoopHintExecutionCounter(), and changed it to be called only when Options::returnEarlyFromInfiniteLoopsForFuzzing() is true.
Created attachment 440160 [details] patch for landing.
Committed r283567 (242532@main): <https://commits.webkit.org/242532@main> All reviewed patches have been landed. Closing bug and clearing flags on attachment 440160 [details].