RFR: 8371216: oopDesc::print_value_on breaks if klass is garbage
Paul Hübner
phubner at openjdk.org
Fri Nov 7 09:16:32 UTC 2025
Hi all,
The `oopDesc::print_value_on` function checks if an oop is a string, and if so just prints the raw string. To do this, it needs to read the `klass()`. If the `klass()` reads garbage, one of many assertion errors is likely triggered.
For example, if G1's verification finds problematic oops, it will attempt to print them. If these oops have garbage (incorrect or racey) klasses, this will cause an assertion error, fail fast, and VM crash. G1 never finishes printing, which may make debugging more difficult. The developer can/will be made aware in other ways if the `klass()` is garbage, for example by being told that it is not in the metaspace.
We observed the above in Valhalla and already patched it there.
Testing: tiers 1-5 on Linux (x64, AArch64), macOS (x64, AArch64), Windows (x64).
-------------
Commit messages:
- Print oop without klass asserts.
Changes: https://git.openjdk.org/jdk/pull/28190/files
Webrev: https://webrevs.openjdk.org/?repo=jdk&pr=28190&range=00
Issue: https://bugs.openjdk.org/browse/JDK-8371216
Stats: 9 lines in 3 files changed: 8 ins; 0 del; 1 mod
Patch: https://git.openjdk.org/jdk/pull/28190.diff
Fetch: git fetch https://git.openjdk.org/jdk.git pull/28190/head:pull/28190
PR: https://git.openjdk.org/jdk/pull/28190
More information about the hotspot-dev
mailing list