Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions patches/mimalloc/theap-cache-aba.patch
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
--- a/src/theap.c
+++ b/src/theap.c
@@ -670,6 +670,14 @@ void _mi_heap_detach_theaps( mi_heap_t* heap ) {
else { mi_assert_internal(theap->tld->theaps == theap); theap->tld->theaps = theap->tnext; }
theap->tnext = theap->tprev = NULL;
theap->tld = NULL;
+ // Also clear `heap` (as `_mi_tld_detach_theaps` does). The owning thread's
+ // `_mi_theap_cached` can still point at this theap, and `_mi_heap_theap` only
+ // compares `theap->heap` with the requested heap: if a later `mi_heap_new` reuses
+ // this heap's address, a stale `heap` would hand that thread this detached theap,
+ // whose pages are destroyed (an ABA on the heap address). Doing it while holding the
+ // tld lock is safe: the thread is not in `mi_thread_theaps_done` for this theap, and
+ // the theap is no longer in the tld list for a later pass.
+ mi_atomic_store_ptr_release(mi_heap_t, &theap->heap, NULL);
mi_lock_release(&tld->theaps_lock);
}
else {
7 changes: 7 additions & 0 deletions scripts/build/deps/mimalloc.ts
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,13 @@ export const mimalloc: Dependency = {
commit: MIMALLOC_COMMIT,
}),

// oven-sh/mimalloc#25: a heap delete must clear `theap->heap` on the theaps
// it detaches, or a thread's cached theap matches a new heap created at the
// same address and allocates from destroyed pages (oven-sh/mimalloc#26 has
// the regression test). CI stand-in only: this becomes a pin bump once those
// PRs are merged, and the patch does not apply on top of #25.
patches: ["patches/mimalloc/theap-cache-aba.patch"],

build: cfg => {
// ─── Override behavior (global malloc replacement) ───
// ASAN: OFF — ASAN interceptors must see the real malloc.
Expand Down
Loading