From 00f510dbfe117631123c18f2f9d5eb22a4e9f69f Mon Sep 17 00:00:00 2001 From: Gundepalli Sravani Date: Tue, 4 Aug 2026 22:41:37 +0530 Subject: [PATCH] deps: V8: cherry-pick ea9c016f26ad Original commit message: AIX: Fix race condition in DecommitPages The current implementation of DecommitPages could lead to a race condition where another thread maps the same region of memory right after we unmap it. This is currently causing test failures on Node.js: https://github.com/nodejs/node/issues/62647 As a workaround we avoid unmapping the address space and instead mark the region as inaccessible using mprotect. We originally considered using madvise to release physical memory, but it is a no-op on AIX and was omitted from this implementation. IT:105 Change-Id: I8271a562be2e7ebcb685a2dd3b7425a38bebe1c9 Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8193436 Reviewed-by: Anton Bikineev Commit-Queue: Milad Farazmand Reviewed-by: Milad Farazmand Cr-Commit-Position: refs/heads/main@{#109206} Refs: https://github.com/v8/v8/commit/ea9c016f26ad274ab86595e8d3fc8712378706dd Signed-off-by: Richard Lau --- common.gypi | 2 +- deps/v8/src/base/platform/platform-aix.cc | 27 +---------------------- 2 files changed, 2 insertions(+), 27 deletions(-) diff --git a/common.gypi b/common.gypi index 151e92c15839..609172e46939 100644 --- a/common.gypi +++ b/common.gypi @@ -42,7 +42,7 @@ # Reset this number to 0 on major V8 upgrades. # Increment by one for each non-official patch applied to deps/v8. - 'v8_embedder_string': '-node.54', + 'v8_embedder_string': '-node.55', ##### V8 defaults for Node.js ##### diff --git a/deps/v8/src/base/platform/platform-aix.cc b/deps/v8/src/base/platform/platform-aix.cc index ed4b59133875..40097395f4e4 100644 --- a/deps/v8/src/base/platform/platform-aix.cc +++ b/deps/v8/src/base/platform/platform-aix.cc @@ -171,34 +171,9 @@ bool OS::DecommitPages(void* address, size_t size) { // with MAP_FIXED will fail and return -1 unless the application has requested // SPEC1170 compliant behaviour: // https://www.ibm.com/docs/en/aix/7.3?topic=m-mmap-mmap64-subroutine - // Therefore in case if failure we need to unmap the address before trying to - // map it again. The downside is another thread could place another mapping at - // the same address after the munmap but before the mmap, therefore a CHECK is - // also added to assure the address is mapped successfully. Refer to the - // comments under https://crrev.com/c/3010195 for more details. -#define MMAP() \ - mmap(address, size, PROT_NONE, MAP_FIXED | MAP_ANONYMOUS | MAP_PRIVATE, -1, 0) DCHECK_EQ(0, reinterpret_cast(address) % CommitPageSize()); DCHECK_EQ(0, size % CommitPageSize()); - void* ptr; - // Try without mapping first. - ptr = MMAP(); - if (ptr != address) { - DCHECK_EQ(ptr, MAP_FAILED); - // Returns 0 when successful. - if (munmap(address, size)) { - return false; - } - // Try again after unmap. - ptr = MMAP(); - // If this check fails it's most likely due to a racing condition where - // another thread has mapped the same address right before we do. - // Since this could cause hard-to-debug issues, potentially with security - // impact, and we can't recover from this, the best we can do is abort the - // process. - CHECK_EQ(ptr, address); - } -#undef MMAP + if (mprotect(address, size, PROT_NONE) != 0) return false; return true; }