Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: e71d94bd49e0f2b3dbc7516c47bd4c46efc344cb
      
https://github.com/WebKit/WebKit/commit/e71d94bd49e0f2b3dbc7516c47bd4c46efc344cb
  Author: Keith Miller <[email protected]>
  Date:   2026-09-29 (Tue, 29 Sep 2026)

  Changed paths:
    M Source/WTF/wtf/ReadWriteLock.cpp
    M Source/WTF/wtf/ReadWriteLock.h
    M Tools/TestWebKitAPI/Tests/WTF/ReadWriteLock.cpp

  Log Message:
  -----------
  ReadWriteLock should allow writers to delete the lock
https://bugs.webkit.org/show_bug.cgi?id=325611
rdar://188673600

Reviewed by Dan Hecht.

ReadWriteLock's last reader could write to the lock after the writer it was
draining for had acquired it:

- readUnlock()'s exchangeAdd, which brings the out count to the drain target,
  is what lets the draining writer in. After that, readUnlockSlow() still runs
  unparkOne(), and its callback does
  m_readersOut.exchangeAnd(~s_writerDrainParkedBit).
- The interleaving:
  1. The writer spins out and CASes the drain-parked bit and the drain target
     into m_readersOut.
  2. The last reader's exchangeAdd sees outCount == drainTarget and heads into
     readUnlockSlow(), but is preempted before it takes the bucket lock.
  3. The writer's parkConditionally() validation sees the target reached and
     doesn't park. The writer returns from writeLock(), finishes, and frees
     the object that holds the lock.
  4. The reader's callback still runs, because it runs even when nothing was
     dequeued, and does an atomic AND on freed memory.

Once the writer has set the drain-parked bit, it now waits for the last
reader to clear it rather than for the count to reach the target. The clear
is the reader's last access to the lock, so a writer may destroy the lock as
soon as it has acquired it, matching POSIX's rule for mutexes. Readers get no
such guarantee: a releasing writer still touches the lock after letting
readers in. The header comment now documents both. The fast paths are
unchanged.

Test: Tools/TestWebKitAPI/Tests/WTF/ReadWriteLock.cpp
Canonical link: https://commits.webkit.org/322227@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to