Skip to content
Browse files

8235305: Corrupted oops embedded in nmethods due to parallel modifica…

…tion during optional evacuation

During optional evacuation it is possible that G1 modifies oops embedded in nmethods in parallel. One source are oop* gathered by a previous evacuation phase in the optional roots, the other the region's strong code roots list. Since these oops may be unaligned on x64, this can result in them being corrupted. The fix is to not gather embedded oops in the optional roots list as the strong code roots list contains them already.

Co-authored-by: Erik Osterlund <>
Co-authored-by: Stefan Johansson <>
Co-authored-by: Stefan Karlsson <>
Reviewed-by: sjohanss, stefank
  • Loading branch information
4 people committed Jan 22, 2020
1 parent f7165c3 commit e3c7f43298f9861fb2fce2dd58fef13d347e7c67
@@ -152,7 +152,8 @@ class G1ParCopyHelper : public OopClosure {

enum G1Barrier {
G1BarrierNoOptRoots // Do not collect optional roots.

enum G1Mark {
@@ -246,7 +246,7 @@ void G1ParCopyClosure<barrier, do_mark_object>::do_oop_work(T* p) {
} else {
if (state.is_humongous()) {
} else if (state.is_optional()) {
} else if ((barrier != G1BarrierNoOptRoots) && state.is_optional()) {

@@ -40,13 +40,22 @@ class G1SharedClosures {
G1ParCopyClosure<G1BarrierNone, Mark> _oops;
G1ParCopyClosure<G1BarrierCLD, Mark> _oops_in_cld;
// We do not need (and actually should not) collect oops from nmethods into the
// optional collection set as we already automatically collect the corresponding
// nmethods in the region's strong code roots set. So set G1BarrierNoOptRoots in
// this closure.
// If these were present there would be opportunity for multiple threads to try
// to change this oop* at the same time. Since embedded oops are not necessarily
// word-aligned, this could lead to word tearing during update and crashes.
G1ParCopyClosure<G1BarrierNoOptRoots, Mark> _oops_in_nmethod;

G1CLDScanClosure _clds;
G1CodeBlobClosure _codeblobs;

G1SharedClosures(G1CollectedHeap* g1h, G1ParScanThreadState* pss, bool process_only_dirty) :
_oops(g1h, pss),
_oops_in_cld(g1h, pss),
_oops_in_nmethod(g1h, pss),
_clds(&_oops_in_cld, process_only_dirty),
_codeblobs(pss->worker_id(), &_oops, needs_strong_processing()) {}
_codeblobs(pss->worker_id(), &_oops_in_nmethod, needs_strong_processing()) {}

0 comments on commit e3c7f43

Please sign in to comment.