jdk17u-dev icon indicating copy to clipboard operation
jdk17u-dev copied to clipboard

8331735: UpcallLinker::on_exit races with GC when copying frame anchor

Open gnu-andrew opened this issue 7 months ago • 6 comments
trafficstars

Partial backport of a fix for a race condition in code adapted from JavaCallWrapper for the FFM API. This is more visible in 22 and later, where FFM is fully supported and the OpenType implementation using HarfBuzz has been ported to use it.

However, the copy in the native state seems to have been introduced as far back as JDK-8269240 in 17 when the JavaCallWrapper code was ported to what was then universalUpcallHandler.cpp. That fix to ::on_exit is included here.

The other hunk in the 24 and 21u versions is omitted as the ::on_entry method has not been modified by JDK-8272526 which is what moved the thread exception handling to native code.


Progress

  • [ ] Change must be properly reviewed (1 review required, with at least 1 Reviewer)
  • [x] Change must not contain extraneous whitespace
  • [x] Commit message must refer to an issue
  • [ ] JDK-8286875 needs maintainer approval
  • [ ] JDK-8331735 needs maintainer approval

Issues

  • JDK-8331735: UpcallLinker::on_exit races with GC when copying frame anchor (Bug - P3)
  • JDK-8286875: ProgrammableUpcallHandler::on_entry/on_exit access thread fields from native (Bug - P4)

Reviewing

Using git

Checkout this PR locally:
$ git fetch https://git.openjdk.org/jdk17u-dev.git pull/3434/head:pull/3434
$ git checkout pull/3434

Update a local copy of the PR:
$ git checkout pull/3434
$ git pull https://git.openjdk.org/jdk17u-dev.git pull/3434/head

Using Skara CLI tools

Checkout this PR locally:
$ git pr checkout 3434

View PR using the GUI difftool:
$ git pr show -t 3434

Using diff file

Download this PR as a diff file:
https://git.openjdk.org/jdk17u-dev/pull/3434.diff

Using Webrev

Link to Webrev Comment

gnu-andrew avatar Apr 03 '25 22:04 gnu-andrew

:wave: Welcome back andrew! A progress list of the required criteria for merging this PR into master will be added to the body of your pull request. There are additional pull request commands available for use with this pull request.

bridgekeeper[bot] avatar Apr 03 '25 22:04 bridgekeeper[bot]

@gnu-andrew This change now passes all automated pre-integration checks.

ℹ️ This project also has non-automated pre-integration requirements. Please see the file CONTRIBUTING.md for details.

After integration, the commit message for the final commit will be:

8331735: UpcallLinker::on_exit races with GC when copying frame anchor
8286875: ProgrammableUpcallHandler::on_entry/on_exit access thread fields from native

Reviewed-by: mbalao

You can use pull request commands such as /summary, /contributor and /issue to adjust it as needed.

At the time when this comment was updated there had been 1 new commit pushed to the master branch:

  • 729b0c7aa59d7b2e53cdaa8b4a1631962951f8d8: 8352649: [17u] guarantee(is_result_safe || is_in_asgct()) failed inside AsyncGetCallTrace

Please see this link for an up-to-date comparison between the source branch of this pull request and the master branch. As there are no conflicts, your changes will automatically be rebased on top of these commits when integrating. If you prefer to avoid this automatic rebasing, please check the documentation for the /integrate command for further details.

➡️ To integrate this PR with the above commit message to the master branch, type /integrate in a new comment.

openjdk[bot] avatar Apr 03 '25 22:04 openjdk[bot]

This backport pull request has now been updated with issues from the original commit.

openjdk[bot] avatar Apr 03 '25 22:04 openjdk[bot]

/issue remove 8343144

gnu-andrew avatar Apr 03 '25 22:04 gnu-andrew

@gnu-andrew Removing additional issue from issue list: 8343144.

openjdk[bot] avatar Apr 03 '25 22:04 openjdk[bot]

Webrevs

mlbridge[bot] avatar Apr 03 '25 22:04 mlbridge[bot]

⚠️ @gnu-andrew This change is now ready for you to apply for maintainer approval. This can be done directly in each associated issue or by using the /approval command.

openjdk[bot] avatar Apr 05 '25 01:04 openjdk[bot]

Thanks Martin.

/approval request Partial backport of a fix for a race condition in the FFM API. Can lead to crashes when the FFM code manipulates a frame anchor in native mode, which the GC does not expect to happen. Fix is to move the frame anchor copying to Java mode, where the GC will wait for the thread to get to a safepoint. Risk to other code is low as the UpcallLinker is only used by FFM, which is in incubation in 17u.

gnu-andrew avatar Apr 05 '25 03:04 gnu-andrew

@gnu-andrew 8331735: The approval request has been created successfully. 8286875: The approval request has been created successfully.

openjdk[bot] avatar Apr 05 '25 03:04 openjdk[bot]

/approval request Partial backport of a fix for a race condition in the FFM API. Can lead to crashes when the FFM code manipulates a frame anchor in native mode, which the GC does not expect to happen. Fix is to move the frame anchor copying to Java mode, where the GC will wait for the thread to get to a safepoint. Risk to other code is low as the UpcallLinker is only used by FFM, which is in incubation in 17u. Patch has been reviewed by Martin Balao.

gnu-andrew avatar Apr 05 '25 03:04 gnu-andrew

@gnu-andrew 8331735: The approval request has been updated successfully. 8286875: The approval request has been updated successfully.

openjdk[bot] avatar Apr 05 '25 03:04 openjdk[bot]

/integrate

gnu-andrew avatar Apr 08 '25 14:04 gnu-andrew

Going to push as commit 8ea7310b57403f20ac8b0c6e13ecd67e0360c9c1. Since your change was applied there have been 23 commits pushed to the master branch:

  • ac00cd26889308164704d8bc902102c2f7486c9a: 8329261: G1: interpreter post-barrier x86 code asserts index size of wrong buffer
  • 9ef3fb480ec1511caac3d409ca7eda8fedf43bb1: 8352716: (tz) Update Timezone Data to 2025b
  • 7a29de5fd6670bfecfd616777cb90946f338076c: 8271419: Refactor test code for modifying CDS archive contents
  • ... and 20 more: https://git.openjdk.org/jdk17u-dev/compare/bb103d7d0914f90e85eb5f87831ffef1de536072...master

Your commit was automatically rebased without conflicts.

openjdk[bot] avatar Apr 08 '25 14:04 openjdk[bot]

@gnu-andrew Pushed as commit 8ea7310b57403f20ac8b0c6e13ecd67e0360c9c1.

:bulb: You may see a message that your pull request was closed with unmerged commits. This can be safely ignored.

openjdk[bot] avatar Apr 08 '25 14:04 openjdk[bot]