Skip to content

fix(allocator): fix UB in Arena::grow_zeroed#21739

Merged
graphite-app[bot] merged 1 commit intomainfrom
om/04-24-fix_allocator_fix_ub_in_arena_grow_zeroed_
Apr 25, 2026
Merged

fix(allocator): fix UB in Arena::grow_zeroed#21739
graphite-app[bot] merged 1 commit intomainfrom
om/04-24-fix_allocator_fix_ub_in_arena_grow_zeroed_

Conversation

@overlookmotel
Copy link
Copy Markdown
Member

@overlookmotel overlookmotel commented Apr 25, 2026

Implementation of grow_zeroed method of allocator_api2::alloc::Allocator trait for Arena created a &mut [u8] covering the tail end of a new allocation which may contain uninitialized bytes. This is UB.

Fix this by using NonNull::write_bytes to zero the bytes instead.

Same fix submitted to bumpalo: fitzgen/bumpalo#321

Copy link
Copy Markdown
Member Author

overlookmotel commented Apr 25, 2026


How to use the Graphite Merge Queue

Add either label to this PR to merge it via the merge queue:

  • 0-merge - adds this PR to the back of the merge queue
  • hotfix - for urgent changes, fast-track this PR to the front of the merge queue

You must have a Graphite account in order to use the merge queue. Sign up using this link.

An organization admin has enabled the Graphite Merge Queue in this repository.

Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue.

This stack of pull requests is managed by Graphite. Learn more about stacking.

@codspeed-hq
Copy link
Copy Markdown

codspeed-hq Bot commented Apr 25, 2026

Merging this PR will not alter performance

✅ 48 untouched benchmarks
⏩ 3 skipped benchmarks1


Comparing om/04-24-fix_allocator_fix_ub_in_arena_grow_zeroed_ (b9bf239) with main (1b97124)2

Open in CodSpeed

Footnotes

  1. 3 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports.

  2. No successful run was found on main (b9bf239) during the generation of this report, so 1b97124 was used instead as the comparison base. There might be some changes unrelated to this pull request in this report.

@overlookmotel overlookmotel self-assigned this Apr 25, 2026
@overlookmotel overlookmotel added A-allocator Area - Allocator C-bug Category - Bug labels Apr 25, 2026
@overlookmotel overlookmotel marked this pull request as ready for review April 25, 2026 09:35
Copilot AI review requested due to automatic review settings April 25, 2026 09:35
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Fixes undefined behavior in Arena’s allocator_api2::alloc::Allocator::grow_zeroed implementation by avoiding creation of a mutable slice over potentially uninitialized bytes and instead zeroing the tail via raw-pointer writes.

Changes:

  • Replace &mut [u8] tail-zeroing with NonNull::write_bytes on the tail region.
  • Add safety documentation explaining why the raw-pointer approach is required.

Comment thread crates/oxc_allocator/src/arena/alloc_impl.rs
@graphite-app
Copy link
Copy Markdown
Contributor

graphite-app Bot commented Apr 25, 2026

Merge activity

Implementation of `grow_zeroed` method of `allocator_api2::alloc::Allocator` trait for `Arena` created a `&mut [u8]` covering the tail end of a new allocation which may contain uninitialized bytes. This is UB.

Fix this by using `NonNull::write_bytes` to zero the bytes instead.

Same fix submitted to `bumpalo`: fitzgen/bumpalo#321
@graphite-app graphite-app Bot force-pushed the om/04-24-refactor_allocator_chunkrawiter_yield_nonnull_pointers branch from 4288517 to 8fd3746 Compare April 25, 2026 11:23
@graphite-app graphite-app Bot force-pushed the om/04-24-fix_allocator_fix_ub_in_arena_grow_zeroed_ branch from cecb127 to b9bf239 Compare April 25, 2026 11:23
Base automatically changed from om/04-24-refactor_allocator_chunkrawiter_yield_nonnull_pointers to main April 25, 2026 11:28
@graphite-app graphite-app Bot merged commit b9bf239 into main Apr 25, 2026
37 checks passed
@graphite-app graphite-app Bot deleted the om/04-24-fix_allocator_fix_ub_in_arena_grow_zeroed_ branch April 25, 2026 11:29
camc314 pushed a commit that referenced this pull request Apr 27, 2026
### 💥 BREAKING CHANGES

- 502e804 ast: [**BREAKING**] Reduce size of `TSTypePredicateName`
(#21711) (overlookmotel)
- 5651539 ast: [**BREAKING**] Reduce size of `JSXExpression` (#21710)
(overlookmotel)
- c44e280 ast: [**BREAKING**] Reduce size of `ArrayExpressionElement`
(#21709) (overlookmotel)
- c5b3deb syntax: [**BREAKING**] Remove `CommentNodeId` (#21679)
(overlookmotel)

### 🚀 Features

- b738a39 allocator: Add `Allocator::cursor_ptr` method (#21773)
(overlookmotel)
- 678767e ast: Generate node_id accessors for AST enum wrappers (#21653)
(camc314)
- f091d77 minifier: Inline constant spread elements into arrays (#21095)
(Armano)

### 🐛 Bug Fixes

- 0d608c2 minifier: Preserve raw CR in template literals (#21645)
(Dunqing)
- a889ea9 minifier: Track pure functions in DCE mode (#21722) (Dunqing)
- 674dfac allocator: `Arena` retry allocation when chunk size approaches
maximum (#21777) (overlookmotel)
- f130cc0 allocator: Fix arithmetic overflow in
`Arena::new_chunk_memory_details` (#21745) (overlookmotel)
- b9bf239 allocator: Fix UB in `Arena::grow_zeroed` (#21739)
(overlookmotel)
- d2b9389 allocator: Clippy warning when building without `testing`
feature (#21681) (camc314)
- 503dc86 codegen: Map sourcemaps from visible output starts (#21662)
(Dunqing)
- c92bd3b transformer: Use SPAN for synthesized helper calls to prevent
comment misattribution (#21578) (Dunqing)
- 0d80441 codegen: Add mapping before printing `#` for private ident
(#21619) (camc314)

### ⚡ Performance

- 9fa362e napi/parser: Do not generate tokens except in tests (#21811)
(overlookmotel)
- 0044392 allocator: Reduce branches when allocating new chunk (#21776)
(overlookmotel)
- 7896bd0 allocator: `Allocator::used_bytes` do not use chunk iterator
(#21771) (overlookmotel)
- a5c562f allocator: Remove check in `Arena::new_chunk_memory_details`
(#21750) (overlookmotel)
- 35bbe1f allocator: `Arena` use unchecked size round up where
guaranteed no overflow (#21743) (overlookmotel)
- ffe229b allocator: Remove unnecessary check from
`Arena::try_alloc_layout_slow_impl` (#21732) (overlookmotel)
- 72fece5 allocator: Use `NonNull::offset_from_unsigned` in
`Arena::chunk_capacity` (#21731) (overlookmotel)
- cab32ae ast: Add `#[inline(always)]` to `node_id` methods on enums
with all variants unboxed (#21707) (overlookmotel)
- b179688 parser: Allocate `TriviaBuilder` comments in the arena
(#21512) (Boshen)
- 2290f31 lexer: Fix perf of `Token::set_*` methods on Rust 1.95.0
(#21659) (overlookmotel)
- 1b58029 allocator: Move code into cold path in `Arena::alloc_layout`
(#21622) (overlookmotel)
- 3cf7cef allocator: Reduce instructions on allocation hot path (#21510)
(overlookmotel)

### 📚 Documentation

- ce65070 data_structures: Document why `as_ref` and `as_mut` on
`NonNullConst` and `NonNullMut` take `self` (#21800) (overlookmotel)
- 93b7dbd allocator: Improve doc comments for `ChunkFooter` (#21733)
(overlookmotel)
- 295db8d transformer: Fix comment (#21717) (overlookmotel)
- 5c93af8 ast: Add comments explaining `#[inline(always)]` to `node_id`
methods on enums (#21706) (overlookmotel)
- e4cea25 transform: Use the `node:` namespace in the example (#19998)
(루밀LuMir)

### 🛡️ Security

- d8076c9 deps: Update rolldown (#21639) (renovate)

Co-authored-by: Boshen <1430279+Boshen@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

A-allocator Area - Allocator C-bug Category - Bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants