| Index: src/objects.cc
|
| diff --git a/src/objects.cc b/src/objects.cc
|
| index e37f6d1b2592a84f11d0fa1b7748b768d185e1c5..ca9e3963a8bb57f48fa1e945ac740b68b20128f1 100644
|
| --- a/src/objects.cc
|
| +++ b/src/objects.cc
|
| @@ -9012,8 +9012,7 @@ AllocationMemento* AllocationMemento::FindForJSObject(JSObject* object) {
|
| // involves carefully checking the object immediately after the JSArray
|
| // (if there is one) to see if it's an AllocationMemento.
|
| if (FLAG_track_allocation_sites && object->GetHeap()->InNewSpace(object)) {
|
| - // TODO(mvstanton): CHECK to diagnose chromium bug 284577, remove after.
|
| - CHECK(object->GetHeap()->InToSpace(object));
|
| + ASSERT(object->GetHeap()->InToSpace(object));
|
| Address ptr_end = (reinterpret_cast<Address>(object) - kHeapObjectTag) +
|
| object->Size();
|
| if ((ptr_end + AllocationMemento::kSize) <=
|
| @@ -9023,15 +9022,20 @@ AllocationMemento* AllocationMemento::FindForJSObject(JSObject* object) {
|
| reinterpret_cast<Map**>(ptr_end);
|
| if (*possible_allocation_memento_map ==
|
| object->GetHeap()->allocation_memento_map()) {
|
| - Address ptr_object = reinterpret_cast<Address>(object);
|
| - // TODO(mvstanton): CHECK to diagnose chromium bug 284577, remove after.
|
| - // If this check fails it points to the very unlikely case that we've
|
| - // misinterpreted a page header as an allocation memento. Follow up
|
| - // with a real fix.
|
| - CHECK(Page::FromAddress(ptr_object) == Page::FromAddress(ptr_end));
|
| AllocationMemento* memento = AllocationMemento::cast(
|
| reinterpret_cast<Object*>(ptr_end + kHeapObjectTag));
|
| - return memento;
|
| +
|
| + // TODO(mvstanton): because of chromium bug 284577, put extra care
|
| + // into validating that the memento points to a valid AllocationSite.
|
| + // This check is expensive so remove it asap. Also, this check
|
| + // HIDES bug 284577, so it must be disabled to debug/diagnose.
|
| + Object* site = memento->allocation_site();
|
| + Heap* heap = object->GetHeap();
|
| + if (heap->InOldPointerSpace(site) &&
|
| + site->IsHeapObject() &&
|
| + HeapObject::cast(site)->map() == heap->allocation_site_map()) {
|
| + return memento;
|
| + }
|
| }
|
| }
|
| }
|
|
|