From bb547a1b557471ca6535fa258b520c6074b1cc56 Mon Sep 17 00:00:00 2001 From: roytam1 Date: Sun, 12 Mar 2023 21:39:55 +0800 Subject: [PATCH] Reverting rev b7e45308 and 9824659d again as I can still get a crash in `RegExpShared::finalize(FreeOp* fop)` --- js/src/gc/Heap.h | 3 +++ js/src/vm/RegExpObject.cpp | 16 ++++++---------- js/src/vm/RegExpObject.h | 7 +++---- 3 files changed, 12 insertions(+), 14 deletions(-) diff --git a/js/src/gc/Heap.h b/js/src/gc/Heap.h index 9f030135e7..14604d3bbe 100644 --- a/js/src/gc/Heap.h +++ b/js/src/gc/Heap.h @@ -340,6 +340,9 @@ class TenuredCell : public Cell static MOZ_ALWAYS_INLINE void writeBarrierPost(void* cellp, TenuredCell* prior, TenuredCell* next); + // Default implementation for kinds that don't require finalization. + void finalize(FreeOp* fop) {} + // Default implementation for kinds that don't require fixup. void fixupAfterMovingGC() {} diff --git a/js/src/vm/RegExpObject.cpp b/js/src/vm/RegExpObject.cpp index 61baadef81..556b2e4413 100644 --- a/js/src/vm/RegExpObject.cpp +++ b/js/src/vm/RegExpObject.cpp @@ -952,6 +952,12 @@ RegExpShared::RegExpShared(JSAtom* source, RegExpFlag flags) numNamedCaptures_(0), groupsTemplate_(nullptr) {} +RegExpShared::~RegExpShared() +{ + for (size_t i = 0; i < tables.length(); i++) + js_delete(tables[i]); +} + void RegExpShared::traceChildren(JSTracer* trc) { @@ -972,16 +978,6 @@ RegExpShared::discardJitCode() comp.jitCode = nullptr; } -void -RegExpShared::finalize(FreeOp* fop) -{ - for (auto& comp : compilationArray) - js_free(comp.byteCode); - for (size_t i = 0; i < tables.length(); i++) - js_free(tables[i]); - tables.~JitCodeTables(); -} - /* static */ bool RegExpShared::compile(JSContext* cx, MutableHandleRegExpShared re, HandleLinearString input, CompilationMode mode, ForceByteCodeEnum force) diff --git a/js/src/vm/RegExpObject.h b/js/src/vm/RegExpObject.h index 4f35908087..9a4cc01c5f 100644 --- a/js/src/vm/RegExpObject.h +++ b/js/src/vm/RegExpObject.h @@ -121,6 +121,7 @@ class RegExpShared : public gc::TenuredCell uint8_t* byteCode; RegExpCompilation() : byteCode(nullptr) {} + ~RegExpCompilation() { js_free(byteCode); } bool compiled(ForceByteCodeEnum force = DontForceByteCode) const { return byteCode || (force == DontForceByteCode && jitCode); @@ -148,8 +149,7 @@ class RegExpShared : public gc::TenuredCell } // Tables referenced by JIT code. - using JitCodeTables = Vector; - JitCodeTables tables; + Vector tables; /* Internal functions. */ RegExpShared(JSAtom* source, RegExpFlag flags); @@ -172,7 +172,7 @@ class RegExpShared : public gc::TenuredCell } public: - ~RegExpShared() = delete; + ~RegExpShared(); // Execute this RegExp on input starting from searchIndex, filling in // matches if specified and otherwise only determining if there is a match. @@ -222,7 +222,6 @@ class RegExpShared : public gc::TenuredCell void traceChildren(JSTracer* trc); void discardJitCode(); - void finalize(FreeOp* fop); static size_t offsetOfSource() { return offsetof(RegExpShared, source);