Repository navigation
parallel/test-domain-error-types can crash if GC timings get unlucky #28275
Copy link
Copy link
Closed
Labels
confirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.domainIssues and PRs related to the domain subsystem.Issues and PRs related to the domain subsystem.
Description
Activity
added on Jun 19, 2019
domainIssues and PRs related to the domain subsystem.Issues and PRs related to the domain subsystem.
confirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.
Thanks for the bug report, this is something I definitely missed.
I can’t reproduce the issue without a debug build, so testing this out is going to take a while, but something like this might help:
diff --git a/lib/domain.js b/lib/domain.js
index b2ffed2741bc..3dc56c179aca 100644
--- a/lib/domain.js
+++ b/lib/domain.js
@@ -73,13 +73,18 @@ const asyncHook = createHook({
if (current !== undefined) { // Enter domain for this cb
// We will get the domain through current.get(), because the resource
// object's .domain property makes sure it is not garbage collected.
+ // However, we do need to make the reference to the domain non-weak,
+ // so that it cannot be garbage collected before the after() hook.
+ current.incRef();
current.get().enter();
}
},
after(asyncId) {
const current = pairing.get(asyncId);
if (current !== undefined) { // Exit domain for this cb
- current.get().exit();
+ const domain = current.get();
+ current.decRef();
+ domain.exit();
}
},
destroy(asyncId) {
diff --git a/src/node_util.cc b/src/node_util.cc
index 518865fe5368..fa39583b04ba 100644
--- a/src/node_util.cc
+++ b/src/node_util.cc
@@ -189,12 +189,26 @@ class WeakReference : public BaseObject {
args.GetReturnValue().Set(weak_ref->target_.Get(isolate));
}
+ static void IncRef(const FunctionCallbackInfo<Value>& args) {
+ WeakReference* weak_ref = Unwrap<WeakReference>(args.Holder());
+ if (weak_ref->reference_count_ == 0) weak_ref->target_.ClearWeak();
+ weak_ref->reference_count_++;
+ }
+
+ static void DecRef(const FunctionCallbackInfo<Value>& args) {
+ WeakReference* weak_ref = Unwrap<WeakReference>(args.Holder());
+ CHECK_GE(weak_ref->reference_count_, 1);
+ weak_ref->reference_count_--;
+ if (weak_ref->reference_count_ == 0) weak_ref->target_.SetWeak();
+ }
+
SET_MEMORY_INFO_NAME(WeakReference)
SET_SELF_SIZE(WeakReference)
SET_NO_MEMORY_INFO()
private:
Global<Object> target_;
+ uint64_t reference_count_ = 0;
};
static void GuessHandleType(const FunctionCallbackInfo<Value>& args) {
@@ -294,6 +308,8 @@ void Initialize(Local<Object> target,
weak_ref->InstanceTemplate()->SetInternalFieldCount(1);
weak_ref->SetClassName(weak_ref_string);
env->SetProtoMethod(weak_ref, "get", WeakReference::Get);
+ env->SetProtoMethod(weak_ref, "incRef", WeakReference::IncRef);
+ env->SetProtoMethod(weak_ref, "decRef", WeakReference::DecRef);
target->Set(context, weak_ref_string,
weak_ref->GetFunction(context).ToLocalChecked()).Check();
Actually, I think this may have been caused by #26211 because the domain is now no longer kept alive through the domain stack. I’ll open a PR with the above suggestion, it does seem to resolve the issue.
added a commit that references this issue on Jun 20, 2019
added a commit that references this issue on Jul 25, 2019
added a commit that references this issue on Jul 27, 2019
added a commit that references this issue on Aug 2, 2019
Metadata
Metadata
Assignees
Labels
confirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.domainIssues and PRs related to the domain subsystem.Issues and PRs related to the domain subsystem.
It appears that the
TickObjectused forprocess.nextTickcan die between the tick callback and the tick'safterhook (possibly only in the case where the callback throws an exception), in which case there is no longer a strong reference to the tick's domain and theWeakReferenceto the domain can die (on an unlucky GC run). Then, theexit()call indomain.jswill be called on undefined, and will crash.Depending on the desired semantics, either
current.get()in theafter()call should check theWeakReference, or theTickObjectresource/domain should be kept strongly alive until after theafterhook.Reproducible by manually setting a tighter GC interval and stressing compaction on a debug node build: