Skip to content

Commit db82899

Browse files
committed
Disable use of Linux memory protection keys
V8's default thread-isolated allocator has a bug on x64 Linux. It uses memory protection keys (see `man 7 pkeys`) to write-protect JIT code memory but in a way that is currently incompatible with how we use threads. Specifically, pkey permissions are inherited by child threads. Threads that are not descendants of the thread that allocates the pkey default to "no permissions" for that pkey. Concretely, if thread A creates the v8::Platform (and the pkey) and write-protects memory, then later thread B tries to access that memory, it segfaults due to the lack of permissions. The fix on V8's side is conceptually easy - call pkey_set(PKEY_DISABLE_WRITE) before accessing the memory, to flip the permissions from "none" to "can read" - but until it's actually fixed, disable thread-isolation. Fixes: rubyjs/mini_racer#300 Refs: https://issues.chromium.org/issues/360909072
1 parent e7e17d2 commit db82899

File tree

2 files changed

+18
-0
lines changed

2 files changed

+18
-0
lines changed

libexec/extract-node

+1
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,7 @@ cd "${src}/node-v${version}"
3232
#patch -p1 < "${top}"/patch/gyp-libv8_monolith.patch
3333
#patch -p1 < "${top}"/patch/py2-icutrim.patch
3434
#patch -p1 < "${top}"/patch/py2-genv8constants.patch
35+
patch -p1 < "${top}"/patch/v8-disable-pkey.patch
3536

3637
# TODO: the following still fails on py3 so the above one forcing py2 is needed
3738
# patch -p1 < ../../py3-genv8constants.patch

patch/v8-disable-pkey.patch

+17
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
diff --git a/deps/v8/src/base/build_config.h b/deps/v8/src/base/build_config.h
2+
index 9ed4c8f102..dfca698506 100644
3+
--- a/deps/v8/src/base/build_config.h
4+
+++ b/deps/v8/src/base/build_config.h
5+
@@ -35,11 +35,8 @@
6+
#define V8_HAS_PTHREAD_JIT_WRITE_PROTECT 0
7+
#endif
8+
9+
-#if defined(V8_OS_LINUX) && defined(V8_HOST_ARCH_X64)
10+
-#define V8_HAS_PKU_JIT_WRITE_PROTECT 1
11+
-#else
12+
+// disabled, see https://issues.chromium.org/issues/360909072
13+
#define V8_HAS_PKU_JIT_WRITE_PROTECT 0
14+
-#endif
15+
16+
#if defined(V8_TARGET_ARCH_IA32) || defined(V8_TARGET_ARCH_X64)
17+
#define V8_TARGET_ARCH_STORES_RETURN_ADDRESS_ON_STACK true

0 commit comments

Comments
 (0)