refactor(ecma_ast): tighten allocator access to enforce Sync invariant#9278
Merged
Conversation
IWANABETHATGUY
marked this pull request as draft
April 30, 2026 09:13
Merging this PR will not alter performance
Comparing Footnotes
|
IWANABETHATGUY
force-pushed
the
04-30-remove_stmt_infos_from_ecmaview
branch
from
April 30, 2026 09:18
8287925 to
5f96fd2
Compare
This was referenced Apr 30, 2026
Member
Author
How to use the Graphite Merge QueueAdd the label graphite: merge-when-ready to this PR to add it to the merge queue. You must have a Graphite account in order to use the merge queue. Sign up using this link. An organization admin has enabled the Graphite Merge Queue in this repository. Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue. This stack of pull requests is managed by Graphite. Learn more about stacking. |
IWANABETHATGUY
force-pushed
the
04-30-remove_stmt_infos_from_ecmaview
branch
from
April 30, 2026 09:20
5f96fd2 to
b01d243
Compare
IWANABETHATGUY
force-pushed
the
04-30-ecmaast_safety_guard
branch
2 times, most recently
from
April 30, 2026 10:24
4b699e1 to
f8421ea
Compare
IWANABETHATGUY
marked this pull request as ready for review
April 30, 2026 10:43
graphite-app
Bot
changed the base branch from
04-30-remove_stmt_infos_from_ecmaview
to
graphite-base/9278
May 5, 2026 06:00
graphite-app
Bot
force-pushed
the
graphite-base/9278
branch
from
May 5, 2026 06:04
b01d243 to
45adf2b
Compare
graphite-app
Bot
force-pushed
the
04-30-ecmaast_safety_guard
branch
from
May 5, 2026 06:04
f8421ea to
ac7c73a
Compare
graphite-app
Bot
force-pushed
the
04-30-ecmaast_safety_guard
branch
from
May 5, 2026 06:05
ac7c73a to
b16882e
Compare
✅ Deploy Preview for rolldown-rs canceled.
|
h-a-n-a
approved these changes
May 5, 2026
Member
Author
Merge activity
|
#9278) Stacked on #9276. Closed #9242 Replaces `EcmaAst::allocator(&self) -> &Allocator` with `with_fields(&mut self, |fields| ...)`, a closure-based accessor that bundles read-only access to `source`/`source_type`/`allocator`/`comments`/`program`. The `&mut self` receiver makes the soundness invariant of `unsafe impl Sync for EcmaAst` locally checkable. ## Why `oxc::allocator::Allocator` is `!Sync` (it holds `Cell<NonNull<u8>>` and `Cell<Option<NonNull<ChunkFooter>>>` for bumpalo''s bump pointer). The `unsafe impl Sync for EcmaAst {}` is sound only by convention: `&EcmaAst` is treated as read-only at runtime. But `pub fn allocator(&self) -> &Allocator` punched a hole in that — anyone with a shared `&EcmaAst` (e.g., a rayon `par_iter` worker) could call `ast.allocator()` and then `Allocator::alloc` (which mutates internal `Cell`s through `&self`), racing with another worker. `Sync` cannot be removed — it''s required by parallel chunk rendering in `render_chunk_to_assets.rs` and indirectly by `anyhow::Error::new(SendError<ModuleLoaderMsg>)` in `file_emitter.rs`. So the goal is to make the unsoundness statically harder to reach. ## Changes - `EcmaAst::with_fields(&mut self, |fields| ...)` is the only public way to obtain `&Allocator`. Built on the existing `ProgramCell::with_mut`, reborrowed `&mut Program → &Program`. - `pub fn allocator(&self)` removed. The 3 callers all migrate cleanly: - `clone_with_another_arena` reads `self.program.borrow_owner().allocator.used_bytes()` directly. - `ecma_module_view_factory::create_ecma_view` wraps the `AstScanner::new` + `scanner.scan` block in `ast.with_fields(...)`. - `runtime_module_task::make_ecma_ast` does the same. - `unsafe impl Send for EcmaAst {}` and `unsafe impl Sync for EcmaAst {}` now have `// SAFETY:` blocks spelling out the invariant and naming the call sites that depend on `Sync`. ## Verification - `cargo check --workspace --all-targets` clean. - `cargo clippy --workspace --all-targets -- --deny warnings` clean. - `cargo test -p rolldown --test integration -- --skip ''hmr''` — all 1666 non-HMR integration tests pass. - `rg -n ''ast\.allocator\(\)'' crates/` — zero results.
graphite-app
Bot
force-pushed
the
04-30-ecmaast_safety_guard
branch
from
May 5, 2026 09:39
98752a7 to
dd5fe11
Compare
Merged
shulaoda
added a commit
that referenced
this pull request
May 7, 2026
## [1.0.0] - 2026-05-07 ### 🐛 Bug Fixes - dev/lazy: lazily compiled modules should be watched (#9301) by @h-a-n-a - implement dynamic dominator merge logic (#9270) by @TheAlexLichter - dev: apply __toCommonJS interop when CJS requires ESM in HMR finalizer (#9261) by @h-a-n-a ### 🚜 Refactor - ecma_ast: tighten allocator access to enforce Sync invariant (#9278) by @IWANABETHATGUY - scan_stage: remove stmt_infos field from EcmaView (#9276) by @IWANABETHATGUY - link_stage: detach stmt_infos from EcmaView (#9274) by @IWANABETHATGUY - link_stage: detach depended_runtime_helper from EcmaView to remove unsafe (#9265) by @IWANABETHATGUY - link_stage: remove unsafe in determine_module_exports_kind (#9253) by @IWANABETHATGUY ### 📚 Documentation - getting-started: remove RC warning for 1.0.0 release (#9310) by @shulaoda - getting-started: update version references for 1.0.0 release (#9309) by @shulaoda - add Vite+ tab to getting-started snippets (#9285) by @shulaoda - lazy-barrel: clarify own-exports behavior for import-then-export records (#9298) by @shulaoda - restructure top navigation around Learn vs Reference (#9284) by @shulaoda - builtin-plugins: add bundle analyzer plugin docs (#9292) by @shulaoda - design doc for reference_needed_symbols (#9264) by @IWANABETHATGUY ### ⚡ Performance - devtools: write logs on a background thread (#9219) by @IWANABETHATGUY ### ⚙️ Miscellaneous Tasks - mark esbuild/ts/parameter_props_use_define_for_class_fields_true as passed (#9308) by @sapphi-red - deps: upgrade oxc to 0.129.0 (#9297) by @shulaoda - deps: update rollup submodule for tests to v4.60.3 (#9294) by @sapphi-red - deps: update test262 submodule for tests (#9295) by @sapphi-red - ai: add rolldown REPL decode skill (#9245) by @Dunqing
pull Bot
pushed a commit
to olrtg/rolldown
that referenced
this pull request
May 7, 2026
## [1.0.0] - 2026-05-07 ### 🐛 Bug Fixes - dev/lazy: lazily compiled modules should be watched (rolldown#9301) by @h-a-n-a - implement dynamic dominator merge logic (rolldown#9270) by @TheAlexLichter - dev: apply __toCommonJS interop when CJS requires ESM in HMR finalizer (rolldown#9261) by @h-a-n-a ### 🚜 Refactor - ecma_ast: tighten allocator access to enforce Sync invariant (rolldown#9278) by @IWANABETHATGUY - scan_stage: remove stmt_infos field from EcmaView (rolldown#9276) by @IWANABETHATGUY - link_stage: detach stmt_infos from EcmaView (rolldown#9274) by @IWANABETHATGUY - link_stage: detach depended_runtime_helper from EcmaView to remove unsafe (rolldown#9265) by @IWANABETHATGUY - link_stage: remove unsafe in determine_module_exports_kind (rolldown#9253) by @IWANABETHATGUY ### 📚 Documentation - getting-started: remove RC warning for 1.0.0 release (rolldown#9310) by @shulaoda - getting-started: update version references for 1.0.0 release (rolldown#9309) by @shulaoda - add Vite+ tab to getting-started snippets (rolldown#9285) by @shulaoda - lazy-barrel: clarify own-exports behavior for import-then-export records (rolldown#9298) by @shulaoda - restructure top navigation around Learn vs Reference (rolldown#9284) by @shulaoda - builtin-plugins: add bundle analyzer plugin docs (rolldown#9292) by @shulaoda - design doc for reference_needed_symbols (rolldown#9264) by @IWANABETHATGUY ### ⚡ Performance - devtools: write logs on a background thread (rolldown#9219) by @IWANABETHATGUY ### ⚙️ Miscellaneous Tasks - mark esbuild/ts/parameter_props_use_define_for_class_fields_true as passed (rolldown#9308) by @sapphi-red - deps: upgrade oxc to 0.129.0 (rolldown#9297) by @shulaoda - deps: update rollup submodule for tests to v4.60.3 (rolldown#9294) by @sapphi-red - deps: update test262 submodule for tests (rolldown#9295) by @sapphi-red - ai: add rolldown REPL decode skill (rolldown#9245) by @Dunqing Co-authored-by: shulaoda <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Stacked on #9276.
Closed #9242
Replaces
EcmaAst::allocator(&self) -> &Allocatorwithwith_fields(&mut self, |fields| ...), a closure-based accessor that bundles read-only access tosource/source_type/allocator/comments/program. The&mut selfreceiver makes the soundness invariant ofunsafe impl Sync for EcmaAstlocally checkable.Why
oxc::allocator::Allocatoris!Sync(it holdsCell<NonNull<u8>>andCell<Option<NonNull<ChunkFooter>>>for bumpalo''s bump pointer). Theunsafe impl Sync for EcmaAst {}is sound only by convention:&EcmaAstis treated as read-only at runtime. Butpub fn allocator(&self) -> &Allocatorpunched a hole in that — anyone with a shared&EcmaAst(e.g., a rayonpar_iterworker) could callast.allocator()and thenAllocator::alloc(which mutates internalCells through&self), racing with another worker.Synccannot be removed — it''s required by parallel chunk rendering inrender_chunk_to_assets.rsand indirectly byanyhow::Error::new(SendError<ModuleLoaderMsg>)infile_emitter.rs. So the goal is to make the unsoundness statically harder to reach.Changes
EcmaAst::with_fields(&mut self, |fields| ...)is the only public way to obtain&Allocator. Built on the existingProgramCell::with_mut, reborrowed&mut Program → &Program.pub fn allocator(&self)removed. The 3 callers all migrate cleanly:clone_with_another_arenareadsself.program.borrow_owner().allocator.used_bytes()directly.ecma_module_view_factory::create_ecma_viewwraps theAstScanner::new+scanner.scanblock inast.with_fields(...).runtime_module_task::make_ecma_astdoes the same.unsafe impl Send for EcmaAst {}andunsafe impl Sync for EcmaAst {}now have// SAFETY:blocks spelling out the invariant and naming the call sites that depend onSync.Verification
cargo check --workspace --all-targetsclean.cargo clippy --workspace --all-targets -- --deny warningsclean.cargo test -p rolldown --test integration -- --skip ''hmr''— all 1666 non-HMR integration tests pass.rg -n ''ast\.allocator\(\)'' crates/— zero results.