Bug 90639 - JSString::tryHashConstLock() fails to get exclusive lock
Summary: JSString::tryHashConstLock() fails to get exclusive lock
Alias: None
Product: WebKit
Classification: Unclassified
Component: JavaScriptCore (show other bugs)
Version: 528+ (Nightly build)
Hardware: Unspecified Unspecified
: P2 Normal
Assignee: Michael Saboff
Depends on:
Reported: 2012-07-05 15:21 PDT by Michael Saboff
Modified: 2012-07-05 17:04 PDT (History)
0 users

See Also:

Patch (1.26 KB, patch)
2012-07-05 15:30 PDT, Michael Saboff
oliver: review+
Details | Formatted Diff | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Saboff 2012-07-05 15:21:28 PDT
The code in JSString::tryHashConstLock() can return true when another thread currently has the lock.

    unsigned currentFlags = m_flags;    
    unsigned newFlags = currentFlags | HashConstLock;

    if (!WTF::weakCompareAndSwap(&m_flags, currentFlags, newFlags))
        return false;

    return true;

It may be the case that m_flags, and therefore currentFlags has the HashConstLock bit set, but there isn't a check for that in the code after setting currentFLags.

This can be remedied by adding:

    if (currentFlags & HashConstLock)
        return false;

after the assignment to currentFlags.
Comment 1 Michael Saboff 2012-07-05 15:30:46 PDT
Created attachment 150994 [details]
Comment 2 Michael Saboff 2012-07-05 17:04:18 PDT
Committed r121928: <http://trac.webkit.org/changeset/121928>