Skip to content

[v24.x] deps: V8: cherry-pick ea9c016f26ad - #66570

Closed
richardlau wants to merge 1 commit into
nodejs:v24.x-stagingfrom
richardlau:v24.x-bp-v8-decommitpages
Closed

richardlau wants to merge 1 commit into
nodejs:v24.x-stagingfrom
richardlau:v24.x-bp-v8-decommitpages

Conversation

@richardlau

@richardlau richardlau commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Original commit message:

AIX: Fix race condition in DecommitPages

The current implementation of DecommitPages could lead to a race
condition where another thread maps the same region of memory right after we unmap it.

This is currently causing test failures on Node.js:
https://github.com/nodejs/node/issues/62647

As a workaround we avoid unmapping the address space and instead
mark the region as inaccessible using mprotect. We originally
considered using madvise to release physical memory, but it is a
no-op on AIX and was omitted from this implementation.
IT:105

Change-Id: I8271a562be2e7ebcb685a2dd3b7425a38bebe1c9
Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8193436
Reviewed-by: Anton Bikineev <bikineev@chromium.org>
Commit-Queue: Milad Farazmand <mfarazma@ibm.com>
Reviewed-by: Milad Farazmand <mfarazma@ibm.com>
Cr-Commit-Position: refs/heads/main@{#109206}

Refs: v8/v8@ea9c016
Refs: #62647


This is a backport of the referenced upstream V8 commit. It is similar to, but slightly different, to the change that landed on main/v26.x under #61898 (that PR is semver-major but this particular change is not). (The difference is due to madvise being a no-op on AIX so was dropped from the upstream V8 CL.)

Original commit message:

    AIX: Fix race condition in DecommitPages

    The current implementation of DecommitPages could lead to a race
    condition where another thread maps the same region of memory right after we unmap it.

    This is currently causing test failures on Node.js:
    nodejs#62647

    As a workaround we avoid unmapping the address space and instead
    mark the region as inaccessible using mprotect. We originally
    considered using madvise to release physical memory, but it is a
    no-op on AIX and was omitted from this implementation.
    IT:105

    Change-Id: I8271a562be2e7ebcb685a2dd3b7425a38bebe1c9
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8193436
    Reviewed-by: Anton Bikineev <bikineev@chromium.org>
    Commit-Queue: Milad Farazmand <mfarazma@ibm.com>
    Reviewed-by: Milad Farazmand <mfarazma@ibm.com>
    Cr-Commit-Position: refs/heads/main@{#109206}

Refs: v8/v8@ea9c016
Signed-off-by: Richard Lau <richard.lau@ibm.com>
@richardlau richardlau added aix Issues and PRs related to the AIX platform. v24.x Issues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch. labels Oct 7, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/gyp
  • @nodejs/security-wg
  • @nodejs/v8-update

@nodejs-github-bot nodejs-github-bot added build Issues and PRs related to Node.js builds or CI infrastructure. needs-ci PRs that need a full CI run. v8 engine Issues and PRs related to the V8 dependency. labels Oct 7, 2026
@aduh95 aduh95 added author ready PRs with CI started, the required approvals, and no outstanding review comments. request-ci Add this label to start a Jenkins CI on a PR. Only starts once the PR has an approving review. labels Oct 10, 2026
@github-actions github-actions Bot removed the request-ci Add this label to start a Jenkins CI on a PR. Only starts once the PR has an approving review. label Oct 10, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@aduh95

aduh95 commented Oct 11, 2026

Copy link
Copy Markdown
Contributor

Landed in b8db004

aduh95 pushed a commit that referenced this pull request Oct 11, 2026
Original commit message:

    AIX: Fix race condition in DecommitPages

    The current implementation of DecommitPages could lead to a race
    condition where another thread maps the same region of memory right after we unmap it.

    This is currently causing test failures on Node.js:
    #62647

    As a workaround we avoid unmapping the address space and instead
    mark the region as inaccessible using mprotect. We originally
    considered using madvise to release physical memory, but it is a
    no-op on AIX and was omitted from this implementation.
    IT:105

    Change-Id: I8271a562be2e7ebcb685a2dd3b7425a38bebe1c9
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8193436
    Reviewed-by: Anton Bikineev <bikineev@chromium.org>
    Commit-Queue: Milad Farazmand <mfarazma@ibm.com>
    Reviewed-by: Milad Farazmand <mfarazma@ibm.com>
    Cr-Commit-Position: refs/heads/main@{#109206}

Refs: v8/v8@ea9c016
Signed-off-by: Richard Lau <richard.lau@ibm.com>
PR-URL: #66570
Refs: #62647
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95 aduh95 closed this Oct 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aix Issues and PRs related to the AIX platform. author ready PRs with CI started, the required approvals, and no outstanding review comments. build Issues and PRs related to Node.js builds or CI infrastructure. needs-ci PRs that need a full CI run. v8 engine Issues and PRs related to the V8 dependency. v24.x Issues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants