Skip to content

Inefficient or invalid free object creation in gc_heap::make_unused_array for large sizes on HOST_64BIT #119424

Description

@Alikhalesi

Description

In gc_heap::make_unused_array, when HOST_64BIT is enabled and the object size exceeds 4 GB—such that the size is represented entirely in the high DWORD (e.g., size = 17179869160)—the first call to SetFree(size) results in the creation of a free object with Array::m_NumComponents = 0.

This occurs because SetFree internally casts the size to a uint32_t, truncating the high DWORD. As a result:

A free object is created with len = 0, which is misleading or invalid.

Immediately afterward, the function correctly splits the large object into multiple valid chunks using the proper logic.

Additionally, for certain sizes like 34359738393, the low DWORD is 1, causing the first free object to be created with len = 1, which is inefficient. Ideally, the allocation should begin with a chunk size of UINT32_MAX to maximize utilization.

Potential Fix:

The initial call to SetFree(size) can be skipped entirely when HOST_64BIT is defined, as the subsequent logic already handles large object sizes correctly.

#ifndef HOST_64BIT
((CObjectHeader*)x)->SetFree(size);
#endif

Alternatively, conditionally call SetFree only when size <= UINT32_MAX.

I'd like to take ownership of this issue and work on a fix. Assigning it to myself if that's okay.

Metadata

Metadata

Assignees

Type

No type

Projects

Status
No status

Relationships

None yet

Development

No branches or pull requests

Issue actions